Event Sequence Anomaly Detection for Fraud Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional telecommunication fraud detection technologies face challenges in correlating event timings and information across multiple systems, leading to time-consuming and error-prone manual reviews, and are ineffective in detecting new fraud schemes due to reliance on aged fraud labels.
Innovation Solution
An event sequence anomaly detection system utilizing a semi-supervised machine learning platform to automate the analysis of communication event sequences across multiple modalities, determining fraudulent sequences through machine learning models and sending notifications based on anomaly scores.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual review of data across multiple systems is performed, then fraud detection accuracy can be improved through human analysis, but detection time increases significantly and error rates rise
Solution Approach 1:
The patent replaces manual mechanical review processes with automated machine learning models that analyze event sequences. The system uses supervised learning algorithms to automatically detect fraudulent patterns across multiple communication systems, eliminating the need for human analysts to manually correlate data while maintaining high detection accuracy and reducing time loss.
Solution Approach 2:
The patent introduces an intermediary event sequence analysis layer that automatically correlates events across different communication systems. This intermediary system processes raw event data from multiple sources, applies fraud detection algorithms, and generates detection results, serving as a bridge between raw data and final fraud determination without requiring manual intervention.
2Ease of manufacture
If supervised models rely on aged fraud labels, then model training becomes simpler with available data, but effectiveness decreases for detecting new fraud schemes
Solution Approach 1:
The patent implements dynamic fraud detection by continuously updating machine learning models with new fraud patterns as they emerge. The system adapts to evolving fraud schemes by incorporating real-time feedback and retraining models with recent fraud examples, ensuring both ease of training through automated processes and high adaptability to new threats.
Solution Approach 2:
The patent incorporates feedback mechanisms where detection results and new fraud patterns are fed back into the model training process. This continuous feedback loop allows the system to learn from new fraud schemes automatically, maintaining ease of training through automated data collection while improving adaptability to emerging threats through iterative model updates.
3Productivity
If automated event sequence analysis is implemented, then detection speed and real-time capability improve, but system complexity increases
Solution Approach 1:
The patent segments the fraud detection system into modular components: event data collection modules, sequence analysis modules, machine learning model modules, and output generation modules. This segmentation enables automated real-time detection while managing complexity through modular design, where each component performs a specific function and can be independently optimized or replaced.
Data Source
AI summary
Data stream based event sequence anomaly detection for mobility customer fraud analysis is presented herein. A system obtains a sequence of events comprising respective modalities of communication that correspond to a subscriber identity associated with a communication service—the sequence of events having occurred within a defined period. Based on defined classifiers representing respective fraudulent sequences of events, the system determines, via a group of machine learning models corresponding to respective machine learning processes, whether the sequence of events satisfies a defined condition with respect to likelihood of representing a fraudulent sequence of events of the respective fraudulent sequences of events. In response to the sequence of events being determined to satisfy the defined condition, the system sends, via a user interface of the system, a notification indicating that the sequence of events has been determined to represent the fraudulent sequence of events.


