Graph Neural Network Anomaly Detection in Banking Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for anomaly detection in banking systems are inadequate in identifying complex and new patterns of cybersecurity threats, are costly to implement, and vulnerable to variations in threats, as they rely on hand-coded rules and statistical expectations, which are time-consuming and inefficient.

Innovation Solution

A Graph Neural Network (GNN) system is implemented to monitor and classify patterns of activity in banking systems by representing information flow as a graph, using deep learning algorithms to recognize security risks and unwanted activities in real-time, while ensuring data security and minimizing false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If traditional hand-coded statistical methods are used for anomaly detection, then implementation cost and time are reduced, but detection accuracy for complex and new threat patterns deteriorates

Engineering Contradiction:
Improveimplementation costVSAvoiddetection accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent replaces traditional mechanical hand-coding of statistical rules with an automated machine learning system. The system automatically learns anomaly detection patterns from historical data without requiring manual programming of statistical formulas, thereby eliminating the trade-off between implementation effort and detection capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs self-learning by automatically training on historical banking transaction data to identify anomaly patterns. It continuously improves its detection capabilities without external intervention, automatically adapting to new threat patterns while maintaining low implementation costs.

Inventive Principle:
Principle #25Self-service

2Device complexity

If hand-coded rules are used to detect cybersecurity threats, then system complexity is reduced, but adaptability to new and varying threats deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidthreat pattern adaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system transitions from static hand-coded rules to dynamic machine learning models that continuously adapt to new threat patterns. The model retrains on incoming data, automatically updating its detection patterns to match evolving cybersecurity threats while maintaining manageable system complexity through automated processes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes its detection parameters dynamically by learning from data rather than using fixed hand-coded thresholds. This allows the system to adapt to varying threat patterns automatically, adjusting its sensitivity and detection criteria based on learned patterns without increasing operational complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traditional statistical methods are used for anomaly detection, then false positives are reduced through simple thresholds, but detection of complex activity patterns deteriorates

Engineering Contradiction:
Improvefalse positive rateVSAvoidcomplex pattern detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The machine learning system performs multiple functions simultaneously: it detects both simple and complex anomaly patterns while maintaining controlled false positive rates. The unified model handles diverse threat types without requiring separate detection mechanisms, improving both reliability and detection capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces learned feature representations as intermediaries between raw transaction data and anomaly detection decisions. These intermediate representations capture complex patterns while maintaining interpretability, allowing the system to detect sophisticated threats without generating excessive false positives.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12130928B2Method and system for anamoly detection in the banking system with graph neural networks (GNNs)
Publication Date: 2024.10.29 SANKALP PANDEY
  • US12130928B2 patent drawing
  • US12130928B2 patent drawing
  • US12130928B2 patent drawing

AI summary

A method and system for anomaly detection in the banking system with graph network of a plurality of interconnected gateways. The system continuously monitors a plurality of gateways, data flows related to and executed at a first gateway of the plurality of gateways, the gateway data flows including at least one or more of gateways in a network.