Unsupervised Machine Learning for Electronic Activity Pattern Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Detecting malicious or unsecure electronic activities in a computer system is often inaccurate, resource-intensive, and complex due to the variability in user electronic activities.

Innovation Solution

A computer-based system utilizing unsupervised machine learning techniques, specifically principal component analysis and isolation forest models, to detect unsecure electronic activity patterns by processing transaction data and outputting notifications through a graphical user interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional detection methods are used to identify malicious electronic activities, then detection coverage is achieved, but detection accuracy deteriorates and resource consumption increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent replaces traditional rule-based and signature-based detection mechanisms with unsupervised machine learning models (isolation forest, clustering algorithms) that automatically learn patterns from electronic activity data. This substitution enables the system to achieve high detection accuracy without requiring extensive manual rule configuration and maintenance, thereby reducing computational resources while improving precision in identifying malicious activities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system transforms raw electronic activity data into standardized feature vectors with consistent dimensions and scales, enabling efficient processing by machine learning models. By normalizing parameters such as transaction amounts, frequencies, and temporal patterns, the system achieves accurate detection with reduced computational complexity compared to processing raw, unnormalized data.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional detection methods are used to identify malicious electronic activities, then detection coverage is achieved, but system complexity increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex rule-based detection systems with unsupervised machine learning models that automatically adapt to new attack patterns. The isolation forest and clustering algorithms learn from historical data and continuously improve detection reliability without requiring manual updates to detection rules, thereby maintaining high reliability while reducing operational complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The machine learning models perform self-training and self-optimization by automatically learning from incoming electronic activity data. The system continuously refines its detection capabilities through unsupervised learning, adapting to new malicious patterns without human intervention, which maintains high detection reliability while minimizing the complexity of system maintenance and updates.

Inventive Principle:
Principle #25Self-service

3Speed

If real-time detection is implemented to identify malicious activities promptly, then response time is improved, but computational resource consumption increases

Engineering Contradiction:
Improveresponse timeVSAvoidcomputational resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The patent segments the electronic activity detection process into distinct stages: data collection, feature extraction, anomaly scoring using isolation forest, and pattern recognition through clustering. This segmentation allows real-time processing of critical features while performing more computationally intensive analysis on subsets of data, achieving prompt detection responses with optimized resource utilization at each stage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial analysis on all incoming data by computing anomaly scores using isolation forest, and applies more resource-intensive clustering algorithms only to data points that exceed certain thresholds. This selective application of computational resources enables real-time detection of obvious anomalies while conserving resources for deeper analysis of suspicious but not immediately obvious patterns.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11734610B2Computer based system for detecting electronic activity patterns and methods of use thereof
Publication Date: 2023.08.22 AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC
  • US11734610B2 patent drawing
  • US11734610B2 patent drawing
  • US11734610B2 patent drawing

AI summary

At least some embodiments are directed to an exemplary computer-based electronic activity tracking system that detects activity patterns receiving data values that represent at least one electronic activity. The exemplary electronic activity tracking system includes a detector of unsecure electronic activities that identifies electronic activity patterns performed by a user or non-person entity. The detector of unsecure electronic activities utilizes unsupervised machine learning techniques to detect the electronic activity patterns. The detected electronic activity patterns correspond to unsecure or malicious electronic activities. The electronic activity tracking system outputs notifications indicative of identified unsecure or malicious activity patterns and identifies entities associated with such unsecure or malicious activity patterns. The exemplary electronic activity tracking system implements a graphical user interface operated from a client computing device. The graphical user interface enables a user of the client computing device to perform actions upon the detection of the unsecure or malicious activity patterns.