Auto-Adaptive Anomaly Detection for Click Fraud Streams

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing technologies lack an effective method to detect click fraud in Pay-Per-Click advertising models, as they rely on ambiguous indicators and lack clear fraud tags, making it difficult to identify anomalous behavior indicative of fraud.

Innovation Solution

An auto-adaptive anomaly detection system that uses multiple-entity profiling to define normal visitor behavior for each advertiser's site, scoring clicks based on conversion rates, and employing a judgmental model to rank traffic as pathological, with a panel of experts providing a sanity check, and incorporating IP address and campaign ID profiles to identify clusters with low conversion rates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional fraud detection methods are used in PPC advertising, then the system is simple to operate, but the measurement precision of fraud detection is poor due to ambiguous indicators and lack of clear fraud tags

Engineering Contradiction:
Improvefraud detection precisionVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the detection system into multiple independent modules: IP address profiling module, campaign ID profiling module, conversion rate analysis module, and anomaly detection module. Each module processes specific aspects of click data independently, then combines results to achieve comprehensive fraud detection with high precision while maintaining operational simplicity through modular architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces multiple new dimensions for analyzing click data beyond traditional binary fraud/legitimate classification. It adds temporal dimension (conversion rates over time), spatial dimension (geographic distribution of IP addresses), and behavioral dimension (campaign performance patterns), creating a multi-dimensional detection space that significantly improves measurement precision

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If multiple-entity profiling is implemented to define normal visitor behavior, then the detection accuracy improves, but the loss of time for data processing increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing baseline profiles for normal visitor behavior, IP address patterns, and campaign performance metrics before fraud detection is needed. These profiles are built from historical data and continuously updated, enabling rapid real-time detection without extensive processing during actual fraud identification

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The multiple-entity profiling system is designed to automatically learn and update normal behavior patterns from incoming data streams without requiring manual intervention. The system self-adjusts its baselines and thresholds based on observed traffic patterns, reducing both processing time and operational overhead while maintaining high detection accuracy

Inventive Principle:
Principle #25Self-service

3Reliability

If conversion rates are used as the primary indicator for fraud detection, then the detection reliability improves, but the difficulty of detecting and measuring fraud decreases due to potential manipulation of conversion metrics

Engineering Contradiction:
Improvefraud detection reliabilityVSAvoidfraud identification difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent merges multiple independent indicators into a comprehensive fraud detection framework: IP address profiling (geographic and temporal patterns), campaign ID analysis (performance anomalies), conversion rate monitoring, and click behavior analysis. By combining these diverse indicators through a weighted scoring system, the system achieves high reliability while maintaining the ability to detect sophisticated fraud that might manipulate any single metric

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system introduces an intermediary anomaly scoring mechanism that translates complex multi-dimensional data into a standardized fraud probability score. This intermediary layer processes raw data from multiple sources, applies statistical analysis and machine learning models, and outputs a unified reliability metric that is both accurate and interpretable, bridging the gap between complex detection and simple decision-making

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10497034B2Auto adaptive anomaly detection system for streams
Publication Date: 2019.12.03 FAIR ISAAC & CO INC
  • US10497034B2 patent drawing
  • US10497034B2 patent drawing
  • US10497034B2 patent drawing

AI summary

A computer-implemented method and system for detecting fraud in electronic commerce traffic are disclosed. A global conversion rate is defined that represents activity related to a purchase made or proxy activity executed during electronic commerce traffic to a commercial website that is indicative of non-fraud activity. Subsets of the electronic commerce traffic to a commercial website are monitored for clusters of activity having a conversion rate that is lower than a global conversion rate by a threshold margin. A number of user-initiated input signals from an input device to navigate from each of one or more affiliate websites to the commercial website, and a number of conversions generated from each of the one or more affiliate websites, are registered by a computer for analysis.