Unsupervised Risk Engine for Adaptive Fraud Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current risk engine technologies rely on manual feedback, which is impractical in many use cases, and have limited update frequency, making them inefficient in adapting to real-life changes, especially in unsupervised environments like enterprise authentication.
Innovation Solution
An unsupervised risk assessment method that uses a probabilistic framework for calculating risk scores based on user-independent and user-dependent frequency values, allowing for instant self-updating and multi-level behavioral history analysis without explicit feedback.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual feedback (case management) is used for risk engine updates, then model accuracy can be maintained through professional analysis, but the system becomes impractical for unsupervised environments and deployment is limited
Solution Approach 1:
The risk engine performs self-learning through automated unsupervised anomaly detection algorithms that continuously analyze transaction patterns and update risk models without requiring manual feedback from security professionals. The system autonomously identifies emerging fraud patterns and adapts its risk assessment criteria in real-time, enabling deployment in unsupervised environments while maintaining accurate risk evaluation
Solution Approach 2:
The system transitions from static periodic model updates to dynamic real-time adaptation by continuously processing transaction streams and automatically adjusting risk parameters. The risk engine dynamically learns from incoming data flows, allowing it to respond immediately to new fraud patterns without waiting for manual intervention or scheduled recalibration cycles
2Stability of the object's composition
If periodic model updates are performed, then model stability is maintained, but the speed of reaction to real-life changes is limited
Solution Approach 1:
The risk engine implements continuous learning by processing transaction data in real-time streams rather than batch processing during periodic updates. The unsupervised anomaly detection algorithms continuously analyze patterns, update risk scores, and adapt models without interruption, ensuring both stability through consistent processing and rapid adaptation to emerging threats
Solution Approach 2:
The system performs preliminary risk assessment using baseline models and then continuously refines predictions based on incoming transaction patterns. By maintaining running statistics and pre-computed risk indicators that are continuously updated, the system prepares adaptive responses in advance while maintaining operational stability
3Productivity
If organization-wide patterns are used for risk assessment, then broad security coverage is achieved, but user-specific behavioral patterns are not taken into consideration
Solution Approach 1:
The risk engine segments risk analysis into multiple hierarchical levels: organization-wide patterns provide baseline security coverage, while user-specific behavioral patterns are analyzed separately to detect individual anomalies. The system maintains distinct statistical models for different user profiles, allowing simultaneous broad coverage and precise user-specific detection without conflating the two analysis dimensions
Data Source
AI summary
A method of protecting a computer system from fraudulent use includes collecting and aggregating sets of risk predictor values for user-initiated events into user-specific aggregations and organization-wide aggregations, and in response to a current event initiated by a user, generating a risk indicator as a combination of a user-specific indicator and an organization-wide indicator based on current event parameters and the user-specific and organization-wide aggregations. Based on the risk indicator indicating that the current event may be a fraudulent use, a protective control action is taken (such as denying or modifying a requested access) to protect the computer system.


