Explainable Anomaly Detection via Expectation Surfaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current AI algorithms used in Anti-Money Laundering (AML) regimes provide predictions/detections of suspicious activities but fail to offer sufficient explanations, leading to skepticism among investigators and regulators, and a lack of trust in AI systems.

Innovation Solution

The development of a computer-implemented method that generates explanations for AI algorithm outputs by using an Expectation Surface, which provides an expected value range for features contributing to anomaly detection, thereby offering insights into why specific features led to the detection of suspicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional AI algorithms are used for anomaly detection in AML, then detection accuracy is improved, but explainability deteriorates leading to skepticism and lack of trust

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidexplanatory information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent introduces expectation surfaces as an intermediary component that bridges the gap between the AI anomaly detection model and human investigators. The expectation surface computes expected value ranges for input features and generates natural language explanations that mediate between the black-box model output and human understanding, thereby maintaining detection accuracy while improving explainability and trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If AI systems provide detailed explanations for anomaly detections, then trust and understanding are improved, but system complexity increases

Engineering Contradiction:
Improvetrust in AI systemVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the explanation generation process into distinct modular components: (1) expectation surface computation module that calculates expected value ranges, (2) feature importance analysis module that identifies contributing factors, and (3) natural language generation module that formulates explanations. This segmentation allows each component to be developed and optimized independently, managing overall system complexity while providing comprehensive explanations.

Inventive Principle:
Principle #1Segmentation

3Productivity

If conventional AI algorithms are used in AML, then false positives are reduced, but investigators still lack understanding of detection drivers

Engineering Contradiction:
Improveinvestigation efficiencyVSAvoiddetection driver information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where the expectation surface continuously provides explanatory information back to investigators about the drivers behind anomaly detections. By analyzing the difference between actual feature values and expected value ranges, the system generates feedback explanations that highlight which features contributed most to the anomaly score, enabling investigators to quickly understand detection rationale without manual analysis.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250086638A1Systems and methods for anomaly detection using explainable machine learning algorithms
Publication Date: 2025.03.13 HAWK AI GMBH
  • US20250086638A1 patent drawing
  • US20250086638A1 patent drawing
  • US20250086638A1 patent drawing

AI summary

The platforms, systems and methods provided herein may provide explanations for AI algorithm outputs to facilitate efficiency and trust for a user. More specifically, the platforms, systems and methods provided herein may provide anomaly detection using explainable machine learning algorithms. Provided here is a computer-implemented method for providing explanations for AI algorithm outputs, comprising: (a) receiving transaction log data; (b) identifying anomalous transactions based at least in part on the transaction log data; (c) generating an expectation surface for one or more anomalous transactions; and (d) generating explanations for the anomalous transactions based at least in part on the expectation surface.