Detecting bad activity.
WHAT MAKES IT DISTINCTIVE
The adversary adapts Positives are rare Decisions must be fast False positives harm legitimate users
WHAT THAT MEANS FOR MODELLING
Models decay faster than elsewhere, because the behaviour changes deliberately.
WHAT TO PLAN
Frequent retraining, and rapid rule deployment for new patterns.
WHY RULES ALONGSIDE MODELS
A newly observed pattern can be blocked immediately, while retraining takes time.
WHAT FEATURES TYPICALLY MATTER
Velocity: activity rate over short windows
Deviation from the account's own history Device and connection characteristics Relationships between accounts Time-of-day patterns
WHY RELATIONSHIP FEATURES MATTER
Fraud is frequently organised, and shared attributes reveal it.
WHAT TO BE CAREFUL WITH
Features the adversary can trivially change Feedback loops, where blocked activity never produces labels
WHAT THAT SECOND POINT MEANS
You never learn whether blocked cases were actually fraudulent.
WHAT TO DO ABOUT IT
Allow a small random sample through, where the risk permits.
WHAT TO MEASURE
The false positive rate, explicitly and continuously.
WHAT TO PROVIDE
A fast review path for wrongly blocked users.