Unsupervised Risk Engine for Adaptive Fraud Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current risk engine technologies rely on manual feedback, which is impractical in many use cases, and have limited update frequency, making them inefficient in adapting to real-life changes, especially in unsupervised environments like enterprise authentication.

Innovation Solution

An unsupervised risk assessment method that uses a probabilistic framework for calculating risk scores based on user-independent and user-dependent frequency values, allowing for instant self-updating and multi-level behavioral history analysis without explicit feedback.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual feedback (case management) is used for risk engine updates, then model accuracy can be maintained through professional analysis, but the system becomes impractical for unsupervised environments and deployment is limited

Engineering Contradiction:
Improverisk assessment accuracyVSAvoiddeployment flexibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The risk engine performs self-learning through automated unsupervised anomaly detection algorithms that continuously analyze transaction patterns and update risk models without requiring manual feedback from security professionals. The system autonomously identifies emerging fraud patterns and adapts its risk assessment criteria in real-time, enabling deployment in unsupervised environments while maintaining accurate risk evaluation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system transitions from static periodic model updates to dynamic real-time adaptation by continuously processing transaction streams and automatically adjusting risk parameters. The risk engine dynamically learns from incoming data flows, allowing it to respond immediately to new fraud patterns without waiting for manual intervention or scheduled recalibration cycles

Inventive Principle:
Principle #15Dynamics

2Stability of the object's composition

If periodic model updates are performed, then model stability is maintained, but the speed of reaction to real-life changes is limited

Engineering Contradiction:
Improvemodel stabilityVSAvoidadaptation speed
Core Design Contradiction:
Stability of the object's compositionVSSpeed

Solution Approach 1:

The risk engine implements continuous learning by processing transaction data in real-time streams rather than batch processing during periodic updates. The unsupervised anomaly detection algorithms continuously analyze patterns, update risk scores, and adapt models without interruption, ensuring both stability through consistent processing and rapid adaptation to emerging threats

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary risk assessment using baseline models and then continuously refines predictions based on incoming transaction patterns. By maintaining running statistics and pre-computed risk indicators that are continuously updated, the system prepares adaptive responses in advance while maintaining operational stability

Inventive Principle:
Principle #10Preliminary action

3Productivity

If organization-wide patterns are used for risk assessment, then broad security coverage is achieved, but user-specific behavioral patterns are not taken into consideration

Engineering Contradiction:
Improvesecurity coverage efficiencyVSAvoiduser-specific detection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The risk engine segments risk analysis into multiple hierarchical levels: organization-wide patterns provide baseline security coverage, while user-specific behavioral patterns are analyzed separately to detect individual anomalies. The system maintains distinct statistical models for different user profiles, allowing simultaneous broad coverage and precise user-specific detection without conflating the two analysis dimensions

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11373189B2Self-learning online multi-layer method for unsupervised risk assessment
Publication Date: 2022.06.28 EMC IP HLDG CO LLC
  • US11373189B2 patent drawing
  • US11373189B2 patent drawing
  • US11373189B2 patent drawing

AI summary

A method of protecting a computer system from fraudulent use includes collecting and aggregating sets of risk predictor values for user-initiated events into user-specific aggregations and organization-wide aggregations, and in response to a current event initiated by a user, generating a risk indicator as a combination of a user-specific indicator and an organization-wide indicator based on current event parameters and the user-specific and organization-wide aggregations. Based on the risk indicator indicating that the current event may be a fraudulent use, a protective control action is taken (such as denying or modifying a requested access) to protect the computer system.