Fraud and Abuse Models Print

  • machinelearningengineering, machine, firewall, guide, howto, solution, zillionkinghost, hosting
  • 0

Detecting bad activity.

WHAT MAKES IT DISTINCTIVE

The adversary adapts Positives are rare Decisions must be fast False positives harm legitimate users

WHAT THAT MEANS FOR MODELLING

Models decay faster than elsewhere, because the behaviour changes deliberately.

WHAT TO PLAN

Frequent retraining, and rapid rule deployment for new patterns.

WHY RULES ALONGSIDE MODELS

A newly observed pattern can be blocked immediately, while retraining takes time.

WHAT FEATURES TYPICALLY MATTER

Velocity: activity rate over short windows

Deviation from the account's own history Device and connection characteristics Relationships between accounts Time-of-day patterns

WHY RELATIONSHIP FEATURES MATTER

Fraud is frequently organised, and shared attributes reveal it.

WHAT TO BE CAREFUL WITH

Features the adversary can trivially change Feedback loops, where blocked activity never produces labels

WHAT THAT SECOND POINT MEANS

You never learn whether blocked cases were actually fraudulent.

WHAT TO DO ABOUT IT

Allow a small random sample through, where the risk permits.

WHAT TO MEASURE

The false positive rate, explicitly and continuously.

WHAT TO PROVIDE

A fast review path for wrongly blocked users.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot