Multi-Level Clustering for Anomaly Detection in Financial Accounts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity and sophistication of money laundering techniques involving online payment accounts and virtual currencies pose challenges for detection and prevention, as criminals use multiple small transactions across various accounts and foreign jurisdictions with fewer regulations, making it difficult for authorities to detect illegal activities.
Innovation Solution
A risk detection system applies multi-level clustering at scale to unlabeled data to analyze account activity, generating clustering models that assign accounts to peer groups and compute scatteredness scores to identify anomalous behavior, thereby detecting unusual or illegal transactions effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional single-level clustering is used to detect anomalies in financial accounts, then the detection process is simple, but the accuracy and ability to detect sophisticated money laundering techniques deteriorates
Solution Approach 1:
The patent applies multi-level clustering that segments accounts into peer groups at multiple hierarchical levels. The first level clusters accounts into peer groups based on transactional behavior patterns, and the second level further segments these peer groups into sub-peers. This segmentation enables more precise anomaly detection by analyzing accounts at different levels of granularity, resolving the contradiction between detection accuracy and system complexity.
Solution Approach 2:
The patent introduces a new dimension of analysis by computing scatteredness scores that measure the dispersion of accounts within peer groups and sub-peers. This scatteredness metric provides an additional dimension for anomaly detection beyond traditional single-level clustering, improving detection accuracy for sophisticated money laundering schemes while maintaining manageable system complexity through structured computation.
2Productivity
If comprehensive analysis of all account transactions is performed to detect money laundering, then detection completeness improves, but processing time and computational resources worsen
Solution Approach 1:
The multi-level clustering system segments the large set of accounts into hierarchical peer groups and sub-peers, enabling the system to process and analyze data in manageable chunks rather than treating all accounts uniformly. This segmentation significantly improves processing efficiency by allowing parallel computation and reducing the computational burden on any single analysis operation.
Solution Approach 2:
The system computes scatteredness scores for accounts based on their position within peer groups and sub-peers, focusing computational resources on accounts that show anomalous scattering patterns rather than uniformly processing all transaction data. This partial action approach maintains detection effectiveness while reducing overall processing time and resource consumption.
3Reliability
If traditional anomaly detection methods are used, then false-positive results occur frequently, but implementing sophisticated multi-level clustering increases system complexity
Solution Approach 1:
By segmenting accounts into peer groups and sub-peers based on transactional behavior patterns, the system creates more homogeneous groups that reduce false-positive anomaly detections. The hierarchical segmentation allows for more precise characterization of normal behavior patterns, improving detection reliability without requiring overly complex analysis methods.
Solution Approach 2:
The patent introduces scatteredness scores as a new parameter that measures the dispersion of accounts within peer groups. This parameter change provides a simple yet effective metric for identifying anomalous behavior, improving detection reliability through a straightforward computational approach rather than complex multi-parameter analysis.
Data Source
AI summary
Methods, systems, and computer program products for applying multi-level clustering at scale to unlabeled data for anomaly detection and security are disclosed. A computer-implemented method may include receiving transactional data associated with a plurality of user accounts, analyzing the transactional data of the accounts in view of a clustering model, associating each of the accounts with one of multiple peer groups from the clustering model, detecting anomalous account behavior in a peer group in view of a scatteredness score computed for each account in the peer group where each scatteredness score is computed based on a neighborhood of accounts in the peer group determined for each respective account of the peer group, and creating a report comprising account and scatteredness score information for one or more of the accounts in the peer group associated with detected anomalous account behavior.


