Federated Anomaly Detection With Oblivious Privacy Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anomaly detection systems face challenges in integrating heterogeneous data from multiple parties while preserving privacy, particularly in the context of financial transactions, due to regulatory and security constraints.
Innovation Solution
A federated learning approach using secure multi-party computation and oblivious transfer protocols allows an anomaly detector computer to train a machine learning model with data from account management computers without revealing private account flag data, by generating masked model updates and adding noise to protect privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If federated learning is used to integrate data from multiple parties, then model accuracy is improved, but privacy protection becomes challenging due to heterogeneous data architecture
Solution Approach 1:
The patent introduces an intermediary mechanism (secure multi-party computation protocol) that enables collaboration between SWIFT and banks without direct data exchange. The anomaly detector computer generates model updates that are processed through cryptographic protocols, allowing accurate anomaly detection while preventing任何一方 from accessing others' private data.
Solution Approach 2:
The patent transforms the data exchange paradigm by changing the parameter of what is exchanged: instead of exchanging raw data or model weights directly, the system exchanges cryptographically transformed model updates through oblivious transfer and secure aggregation protocols, maintaining both accuracy and privacy.
2Ease of manufacture
If centralized machine learning model is deployed using SWIFT's data, then model training is simplified, but additional information from banks cannot be integrated
Solution Approach 1:
The patent segments the centralized training process into distributed components: SWIFT holds the anomaly detector model, while individual banks contribute their own data and compute local model updates. This segmentation allows integration of heterogeneous data sources while maintaining training feasibility through coordinated distributed computation.
Solution Approach 2:
The patent creates a universal federated learning framework that can accommodate multiple data sources (SWIFT and multiple banks) with different data architectures. The secure aggregation protocol and oblivious transfer mechanism provide multi-functional capabilities to handle various data types and privacy requirements simultaneously.
3Measurement precision
If private data from multiple parties is integrated into machine learning models, then model performance is enhanced, but privacy violations occur
Solution Approach 1:
The patent converts the potential harm of data exposure into benefit by using the same data that could violate privacy as input to secure multi-party computation protocols. The account flag data from banks, which could reveal sensitive information, is instead used to select model updates through oblivious transfer, transforming a privacy risk into an accuracy enhancement.
Solution Approach 2:
The patent introduces cryptographic intermediaries (secure aggregation protocol, oblivious transfer mechanism) that mediate between the need for private data integration and privacy protection. These intermediaries enable model performance enhancement while preventing direct access to sensitive account information.
Data Source
AI summary
Methods and systems for performing federated private anomaly detection are disclosed. An anomaly detector computer can collaborate with an aggregator computer and an account management computer in order to train machine learning models, which can be used to classify events as not fraudulent or fraudulent. The anomaly detector computer can obliviously use private information (e.g., account flags and account flag values) held by the account management computer to train and use the machine learning models, such that the anomaly detector does not become aware of the account flags or account flags values. Such a system can be used, for example, for the detection and prevention of financial crime. The anomaly detector computer can use the account flag information possessed by the account management computer to identify fraudulent events performed by customers of the organization operating the account management computer.


