ABSTRACT
Abstract
The disclosed embodiments include computer-implemented systems and methods that dynamically profile behavior using trained machine-learning or artificial-intelligence processes. For example, an apparatus may obtain a data element associated with an exchange of data, and based on an application of a trained machine-learning or artificial-intelligence process to an input dataset associated with the data element, the apparatus may generate behavioral profile data that includes a range of expected deviations from an expected value of the parameter during a temporal interval. Based on a determination that the range of expected deviations fails to include the first parameter value, the apparatus may perform operations that prioritize the position of the data element within the alert queue, and transmit, to a device, a notification that includes the data element and information characterizing the prioritized position of the data element within the alert queue.
Description
CROSS-REFERENCE TO RELATED APPLICATION
This application claims the benefit of priority under 35 U.S.C. § 119(e) to prior U.S. Application No. 63/255,293, filed Oct. 13, 2021, the disclosure of which is incorporated by reference herein to its entirety.
TECHNICAL FIELD
The disclosed embodiments generally relate to computer-implemented systems and processes that dynamically profile behavior using trained machine-learning or artificial-intelligence process.
BACKGROUND
Today, financial institutions provision a variety of financial products and services to customers, and monitor transactions involving these financial products or services to identify, and mitigate potential instances of fraudulent activity. In many instances, representatives of the financial institution inspected queues of transaction data associated with potentially fraudulent activity to identify, and flag, those transaction that represent actual instances of fraudulent activity.
SUMMARY
In some examples, an apparatus includes a memory storing instructions, a communications interface, and at least coupled to the memory and the communications interface. The at least one processor is configured to execute the instructions to obtain a data element associated with an exchange of data. The data element includes a first value of a parameter of the data exchange, and the data element may be disposed at a corresponding position within an alert queue. The at least one processor is further configured to execute the instructions to, based on the application of a trained machine-learning or artificial-intelligence process to an input dataset associated with the data element, generate behavioral profile data that includes a range of expected deviations from an expected value of the parameter during a temporal interval. The at least one processor is further configured to execute the instructions to, based on a determination that the range of expected deviations fails to include the first parameter value, perform operations that prioritize the position of the data element within the alert queue. The at least one processor is further configured to execute the instructions to transmit, to a device via the communications interface, a notification that includes the data element and information characterizing the prioritized position of the data element within the alert queue.
In other examples, a computer-implemented method includes obtaining, using at least one processor, a data element associated with an exchange of data. The data element includes a first value of a parameter of the data exchange, and the data element is disposed at a corresponding position within an alert queue. The computer-implemented method includes, based on an application of a trained machine-learning or artificial-intelligence process an input dataset associated with the data element, generating, using the at least one processor, behavioral profile data that includes a range of expected deviations from an expected value of the parameter during a temporal interval. The computer-implemented method includes, based on a determination that the range of expected deviations fails to include the first parameter value, performing operations, using the at least one processor, that prioritize the position of the data element within the alert queue. The computer-implemented method also includes, transmitting, using the at least one processor and to a device, a notification that includes the data element and information characterizing the prioritized position of the data element within the alert queue.
In various examples, a tangible, non-transitory computer-readable medium storing instructions that, when executed by at least one processor, causes the at least one processor to perform a method that includes obtaining a data element associated with an exchange of data. The data element includes a first value of a parameter of the data exchange, and the data element is disposed at a corresponding position within an alert queue. Based on an application of a trained machine-learning or artificial-intelligence process an input dataset associated with the data element, the method includes generating behavioral profile data that includes a range of expected deviations from an expected value of the parameter during a temporal interval. Based on a determination that the range of expected deviations fails to include the first parameter value, the method includes performing operations that prioritize the position of the data element within the alert queue. The method also includes transmitting, to a device, a notification that includes the data element and information characterizing the prioritized position of the data element within the alert queue.
It is to be understood that both the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the invention, as claimed. Further, the accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate aspects of the present disclosure and together with the description, serve to explain principles of the disclosed exemplary embodiments, as set forth in the accompanying claims.
BRIEF DESCRIPTION OF THE DRAWINGS
FIGS. 1 A and 1 B are block diagrams illustrating portions of an exemplary computing environment, in accordance with some exemplary embodiments.
FIG. 1 C is a diagram of an exemplary timeline for adaptively training a machine-learning or artificial intelligence process, in accordance with some exemplary embodiments.
FIGS. 2 A and 2 B are block diagrams illustrating additional portions of the exemplary computing environment, in accordance with some exemplary embodiments.
FIG. 3 is a flowchart of an exemplary process for adaptively training a machine learning or artificial intelligence process, in accordance with some exemplary embodiments.
FIG. 4 is a flowchart of an exemplary process for dynamically prioritizing elements of queued data in accordance with adaptively predicted behavioral profiles, in accordance with some exemplary embodiments.
FIG. 5 is a flowchart of an exemplary process for detecting instances of potentially fraudulent activity based on adaptively predicted behavioral profiles, in accordance with some exemplary embodiments
Like reference numbers and designations in the various drawings indicate like elements.
DETAILED DESCRIPTION
Modern financial institutions offer a variety of financial products or financial services to their customers, both through in-person branch banking and through various digital channels. In some instances, computing systems operated by these financial institutions may maintain, within corresponding data repositories, elements of customer-specific data that identify and characterize the each these customers, interactions between these customers and the financial institution, and an engagement of these customers with not only the financial products or services provisioned by the financial institution, but also one or more access products that facilitate the customer interaction with the financial institution via corresponding digital channels. Further, decisions to provision one or more of the financial products or services to these customers, decisions to authorize an execution of transaction involving financial products held by these customers, and in some instances, decisions to authorize requested engagements between these customers and the access products provisioned by the financial institution, may be informed by corresponding elements of the customer-specific data.
By way of example, a financial institution may issue, to a particular customer, a financial product available to participate in exchanges of data involving corresponding counterparties, such as, but not limited to, a credit-card account available to fund transactions involving corresponding one of the counterparties, or a deposit account, such as a checking account, available to fund or receive proceeds from these transactions. The transactions may include, among other things, purchase transactions, bill-payment transactions, electronic funds transfer (EFT) transfers (e.g., payroll deposits, etc.), peer-to-peer (P2P) transfers or transactions, or real-time payment (RTP) transactions, and in some instances, the computing systems associated with the financial institution may receive, or intercept, transaction data identifying and characterizing a transaction initiated by, or involving, the particular customer and a corresponding one of the issued financial products, e.g., as a portion of a request for authorization received from a computing system associated with or operated by a payment processing network or payment rail. In some examples, and prior to authorizing the initiated transaction in accordance with portions of the received or intercepted data, the computing system of the financial institution may perform operations that parse the received or incepted data and determine whether the initiated transaction represents an instance of potential fraud involving the particular customer or the corresponding financial product.
Further, and as described herein, the financial institution may also provision one or more access products that facilitate interactions between the customers and the financial institution via corresponding digital channels, and examples of these access products include, but are not limited to mobile applications, web-based online banking platforms, or voice-based banking platforms accessible to the customers via corresponding computing devices or systems. In some instances, the computing systems of the financial institution may receive, via one of the provisioned access products, elements of request data that identify and characterize a requested interaction between the particular customer and the financial institution (e.g., based on data generated by a provisioned mobile application executed at a device operable by the particular customer, etc.). The requested interaction may include, among other things, a request to access elements of confidential data characterizing one or more financial products held by the particular customer (e.g. a balance or outstanding payment associated with a credit-card account, etc.), a request to modify one or more authentication credentials of the particular customer (e.g., a request to modify an alphanumeric password, etc.), or a request to modify an identifier of the customer device that participates in a two-factor authentication process (e.g., a request to update a telephone number of the customer device, etc.). In some instances, and prior to authorizing the requested interaction, the computing systems of the financial institution may also perform operations that parse the request data and determine whether the requested interaction represents an instance of potential fraud involving the particular customer or the access product.
To determine whether the initiated transaction, and additionally, or alternatively, the requested interaction, represents an instance of potential fraud, the computing systems of the financial institution may apply one or more predetermined fraud detection rules to respective elements of the transaction data and/or the request data. For example, the one or more predetermined fraud detection rules may specify that the initiated transaction represents an instance of potential fraud when a transaction value associated with the initiated transaction exceeds a predetermined, threshold transaction value. The one or more predetermined fraud detection rules may also specify that the initiated transaction represents an instance of potential fraud when a transaction velocity associated with the particular customer and/or the corresponding financial product (e.g., that reflects the initiated transaction) exceeds a predetermined threshold velocity, or that the requested interaction represents an instance of potential fraud when an interaction velocity associated with the particular customer and/or the corresponding access product (e.g., that reflects the requested interaction) exceeds a predetermined threshold velocity.
In some instances, described herein, the transaction velocity associated with the particular customer and/or the corresponding financial product may represent a number of discrete transactions involving the particular customer and/or the corresponding financial product initiated (or authorized and executed) across one or more temporal intervals, e.g., a temporal interval of one hour, twelve hours, twenty-four hours, etc. Further, the interaction velocity associated with the particular customer and/or the corresponding access product may represent a number of discrete, requested interactions with the financial institution that involve the particular customer and the corresponding access product during one or more temporal intervals, such as, but not limited to, the exemplary temporal intervals described herein.
The one or more predetermined fraud detection rules may also specify that the initiated transaction, or the requested interaction, represents an instance of potential fraud when a distance between a geographic location associated with the initiated transaction or the requested interaction (e.g., a geographic location of corresponding counterparty, a geographic location of the particular customer, etc.) and a geographic location associated with one or more prior, authorized transactions or interactions exceeds a predetermined threshold distance. The disclosed embodiments are, however, not limited to these exemplary, predetermined fraud detection rules, and on other instances, the computing systems of the financial institution may determine that the initiated transaction, or the requested interaction, represents an instance of potential fraud based an application of any additional, or alternate, predetermined rule to the respective elements of the transaction data and/or the request data that would be appropriate to the initiated transaction or the requested interaction.
Based on a determination that that initiated transaction, and additionally, or alternatively, the requested interaction, represents an instance of potential fraud, the computing systems of the financial institution may perform operations that suspend any subsequent authorization of a respective one of the initiated transaction or requested interaction, and that generate elements of alert data that identify and characterize the instance of potential fraud associated with the respective one of the initiated transaction or the requested interaction. The computing systems of the financial institution may also perform operations that prioritize, or rank, certain of the queued elements of alert data, which identify and characterize initiated transactions or requested interactions associated with instances of potential fraudulent activity, in accordance with one or more predetermined prioritization rules. By way of example, predetermined prioritization rules may prioritize, or rank, the queued elements of alert data associated with the initiated, and potentially fraudulent, transactions in accordance with an amount by which corresponding ones of the transaction values (e.g., as specified within elements of alert data) exceeds the predetermined, threshold transaction value described herein.
Additionally, in some examples, the predetermined prioritization rules may prioritize, or rank, the queued elements of alert data associated with the potentially fraudulent transactions and
CROSS-REFERENCE TO RELATED APPLICATION
This application claims the benefit of priority under 35 U.S.C. § 119(e) to prior U.S. Application No. 63/255,293, filed Oct. 13, 2021, the disclosure of which is incorporated by reference herein to its entirety.
TECHNICAL FIELD
The disclosed embodiments generally relate to computer-implemented systems and processes that dynamically profile behavior using trained machine-learning or artificial-intelligence process.
BACKGROUND
Today, financial institutions provision a variety of financial products and services to customers, and monitor transactions involving these financial products or services to identify, and mitigate potential instances of fraudulent activity. In many instances, representatives of the financial institution inspected queues of transaction data associated with potentially fraudulent activity to identify, and flag, those transaction that represent actual instances of fraudulent activity.
SUMMARY
In some examples, an apparatus includes a memory storing instructions, a communications interface, and at least coupled to the memory and the communications interface. The at least one processor is configured to execute the instructions to obtain a data element associated with an exchange of data. The data element includes a first value of a parameter of the data exchange, and the data element may be disposed at a corresponding position within an alert queue. The at least one processor is further configured to execute the instructions to, based on the application of a trained machine-learning or artificial-intelligence process to an input dataset associated with the data element, generate behavioral profile data that includes a range of expected deviations from an expected value of the parameter during a temporal interval. The at least one processor is further configured to execute the instructions to, based on a determination that the range of expected deviations fails to include the first parameter value, perform operations that prioritize the position of the data element within the alert queue. The at least one processor is further configured to execute the instructions to transmit, to a device via the communications interface, a notification that includes the data element and information characterizing the prioritized position of the data element within the alert queue.
In other examples, a computer-implemented method includes obtaining, using at least one processor, a data element associated with an exchange of data. The data element includes a first value of a parameter of the data exchange, and the data element is disposed at a corresponding position within an alert queue. The computer-implemented method includes, based on an application of a trained machine-learning or artificial-intelligence process an input dataset associated with the data element, generating, using the at least one processor, behavioral profile data that includes a range of expected deviations from an expected value of the parameter during a temporal interval. The computer-implemented method includes, based on a determination that the range of expected deviations fails to include the first parameter value, performing operations, using the at least one processor, that prioritize the position of the data element within the alert queue. The computer-implemented method also includes, transmitting, using the at least one processor and to a device, a notification that includes the data element and information characterizing the prioritized position of the data element within the alert queue.
In various examples, a tangible, non-transitory computer-readable medium storing instructions that, when executed by at least one processor, causes the at least one processor to perform a method that includes obtaining a data element associated with an exchange of data. The data element includes a first value of a parameter of the data exchange, and the data element is disposed at a corresponding position within an alert queue. Based on an application of a trained machine-learning or artificial-intelligence process an input dataset associated with the data element, the method includes generating behavioral profile data that includes a range of expected deviations from an expected value of the parameter during a temporal interval. Based on a determination that the range of expected deviations fails to include the first parameter value, the method includes performing operations that prioritize the position of the data element within the alert queue. The method also includes transmitting, to a device, a notification that includes the data element and information characterizing the prioritized position of the data element within the alert queue.
It is to be understood that both the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the invention, as claimed. Further, the accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate aspects of the present disclosure and together with the description, serve to explain principles of the disclosed exemplary embodiments, as set forth in the accompanying claims.
BRIEF DESCRIPTION OF THE DRAWINGS
FIGS. 1 A and 1 B are block diagrams illustrating portions of an exemplary computing environment, in accordance with some exemplary embodiments.
FIG. 1 C is a diagram of an exemplary timeline for adaptively training a machine-learning or artificial intelligence process, in accordance with some exemplary embodiments.
FIGS. 2 A and 2 B are block diagrams illustrating additional portions of the exemplary computing environment, in accordance with some exemplary embodiments.
FIG. 3 is a flowchart of an exemplary process for adaptively training a machine learning or artificial intelligence process, in accordance with some exemplary embodiments.
FIG. 4 is a flowchart of an exemplary process for dynamically prioritizing elements of queued data in accordance with adaptively predicted behavioral profiles, in accordance with some exemplary embodiments.
FIG. 5 is a flowchart of an exemplary process for detecting instances of potentially fraudulent activity based on adaptively predicted behavioral profiles, in accordance with some exemplary embodiments
Like reference numbers and designations in the various drawings indicate like elements.
DETAILED DESCRIPTION
Modern financial institutions offer a variety of financial products or financial services to their customers, both through in-person branch banking and through various digital channels. In some instances, computing systems operated by these financial institutions may maintain, within corresponding data repositories, elements of customer-specific data that identify and characterize the each these customers, interactions between these customers and the financial institution, and an engagement of these customers with not only the financial products or services provisioned by the financial institution, but also one or more access products that facilitate the customer interaction with the financial institution via corresponding digital channels. Further, decisions to provision one or more of the financial products or services to these customers, decisions to authorize an execution of transaction involving financial products held by these customers, and in some instances, decisions to authorize requested engagements between these customers and the access products provisioned by the financial institution, may be informed by corresponding elements of the customer-specific data.
By way of example, a financial institution may issue, to a particular customer, a financial product available to participate in exchanges of data involving corresponding counterparties, such as, but not limited to, a credit-card account available to fund transactions involving corresponding one of the counterparties, or a deposit account, such as a checking account, available to fund or receive proceeds from these transactions. The transactions may include, among other things, purchase transactions, bill-payment transactions, electronic funds transfer (EFT) transfers (e.g., payroll deposits, etc.), peer-to-peer (P2P) transfers or transactions, or real-time payment (RTP) transactions, and in some instances, the computing systems associated with the financial institution may receive, or intercept, transaction data identifying and characterizing a transaction initiated by, or involving, the particular customer and a corresponding one of the issued financial products, e.g., as a portion of a request for authorization received from a computing system associated with or operated by a payment processing network or payment rail. In some examples, and prior to authorizing the initiated transaction in accordance with portions of the received or intercepted data, the computing system of the financial institution may perform operations that parse the received or incepted data and determine whether the initiated transaction represents an instance of potential fraud involving the particular customer or the corresponding financial product.
Further, and as described herein, the financial institution may also provision one or more access products that facilitate interactions between the customers and the financial institution via corresponding digital channels, and examples of these access products include, but are not limited to mobile applications, web-based online banking platforms, or voice-based banking platforms accessible to the customers via corresponding computing devices or systems. In some instances, the computing systems of the financial institution may receive, via one of the provisioned access products, elements of request data that identify and characterize a requested interaction between the particular customer and the financial institution (e.g., based on data generated by a provisioned mobile application executed at a device operable by the particular customer, etc.). The requested interaction may include, among other things, a request to access elements of confidential data characterizing one or more financial products held by the particular customer (e.g. a balance or outstanding payment associated with a credit-card account, etc.), a request to modify one or more authentication credentials of the particular customer (e.g., a request to modify an alphanumeric password, etc.), or a request to modify an identifier of the customer device that participates in a two-factor authentication process (e.g., a request to update a telephone number of the customer device, etc.). In some instances, and prior to authorizing the requested interaction, the computing systems of the financial institution may also perform operations that parse the request data and determine whether the requested interaction represents an instance of potential fraud involving the particular customer or the access product.
To determine whether the initiated transaction, and additionally, or alternatively, the requested interaction, represents an instance of potential fraud, the computing systems of the financial institution may apply one or more predetermined fraud detection rules to respective elements of the transaction data and/or the request data. For example, the one or more predetermined fraud detection rules may specify that the initiated transaction represents an instance of potential fraud when a transaction value associated with the initiated transaction exceeds a predetermined, threshold transaction value. The one or more predetermined fraud detection rules may also specify that the initiated transaction represents an instance of potential fraud when a transaction velocity associated with the particular customer and/or the corresponding financial product (e.g., that reflects the initiated transaction) exceeds a predetermined threshold velocity, or that the requested interaction represents an instance of potential fraud when an interaction velocity associated with the particular customer and/or the corresponding access product (e.g., that reflects the requested interaction) exceeds a predetermined threshold velocity.
In some instances, described herein, the transaction velocity associated with the particular customer and/or the corresponding financial product may represent a number of discrete transactions involving the particular customer and/or the corresponding financial product initiated (or authorized and executed) across one or more temporal intervals, e.g., a temporal interval of one hour, twelve hours, twenty-four hours, etc. Further, the interaction velocity associated with the particular customer and/or the corresponding access product may represent a number of discrete, requested interactions with the financial institution that involve the particular customer and the corresponding access product during one or more temporal intervals, such as, but not limited to, the exemplary temporal intervals described herein.
The one or more predetermined fraud detection rules may also specify that the initiated transaction, or the requested interaction, represents an instance of potential fraud when a distance between a geographic location associated with the initiated transaction or the requested interaction (e.g., a geographic location of corresponding counterparty, a geographic location of the particular customer, etc.) and a geographic location associated with one or more prior, authorized transactions or interactions exceeds a predetermined threshold distance. The disclosed embodiments are, however, not limited to these exemplary, predetermined fraud detection rules, and on other instances, the computing systems of the financial institution may determine that the initiated transaction, or the requested interaction, represents an instance of potential fraud based an application of any additional, or alternate, predetermined rule to the respective elements of the transaction data and/or the request data that would be appropriate to the initiated transaction or the requested interaction.
Based on a determination that that initiated transaction, and additionally, or alternatively, the requested interaction, represents an instance of potential fraud, the computing systems of the financial institution may perform operations that suspend any subsequent authorization of a respective one of the initiated transaction or requested interaction, and that generate elements of alert data that identify and characterize the instance of potential fraud associated with the respective one of the initiated transaction or the requested interaction. The computing systems of the financial institution may also perform operations that prioritize, or rank, certain of the queued elements of alert data, which identify and characterize initiated transactions or requested interactions associated with instances of potential fraudulent activity, in accordance with one or more predetermined prioritization rules. By way of example, predetermined prioritization rules may prioritize, or rank, the queued elements of alert data associated with the initiated, and potentially fraudulent, transactions in accordance with an amount by which corresponding ones of the transaction values (e.g., as specified within elements of alert data) exceeds the predetermined, threshold transaction value described herein.
Additionally, in some examples, the predetermined prioritization rules may prioritize, or rank, the queued elements of alert data associated with the potentially fraudulent transactions and requested interactions based on an amount by which a corresponding transaction or interaction velocity exceeds the predetermined threshold transaction or interaction velocity described herein. In some instances, and through the application of the one or more predetermined prioritization rules to the queued elements of alert data associated with the potentially fraudulent transactions and requested interactions, the computing systems of the financial institution may re-order the queued elements of alert data in an attempt to prioritize those queued elements of alert data associated with initiated transactions or requested interactions that represent likely instances of actual fraudulent activity, e.g., for further review and analysis by representatives of the financial institution.
Further, the computing systems of the financial institution may perform operations that transmit a portion of the elements of alert data maintained within the alert queue, which identify and characterize initiated transactions and/or requested interaction that represent determined instances of potential fraud, to a device operable by a representative of the financial institution, e.g., in accordance with a predetermined schedule, such as, but not limited to, on an hourly or a daily basis. As described herein, the representative device may receive the portion of the elements of alert data, and may execute one or more application programs, such as a web browser, that presents the elements of alert data within one or more display screens of a digital interface, such as a browser window. In some instances, representative may review the presented elements of alert data associated with each of the initiated transactions or requested interactions associated with instances of potential fraud, and determine, based on personal experience or intuition, or based on one or more of the predetermined fraud detection rules (e.g., based on transaction value, transaction or interaction velocity, etc.), whether the potentially fraudulent initiated transaction or requested interaction represents an actual instance of fraudulent activity.
In some instances, existing processes prioritizing elements of alert data associated with potentially fraudulent transactions or interactions within a corresponding alert queue, which rely on predetermined, fraud detection rules and corresponding value, distance, or velocity threshold, and existing processes for detecting actual instances of fraudulent activity associated with these potentially fraudulent transactions or interactions, which rely on an intuition or an experience of a representative of the financial institution, may be incapable of accounting for time-varying changes in an expected transactional or spending behavior of the customers of the financial institution across multiple temporal intervals, much less for any time-varying changes in a behavior of these customers during interactions with corresponding access products throughout these temporal intervals. Further, many of the rule-based processes for prioritizing the elements of alert data, and many of the subjective processes for detecting actual instances of fraudulent activity, may also be incapable of assessing whether a potentially fraudulent transaction involving a customer, or a potentially fraudulent non-financial interaction between the customer and the financial institution, represents an expected, and as such, acceptable, deviation from an expected behavior of that customer during a corresponding temporal interval.
In some examples, described herein, the computing systems of the financial institution may perform operations that train adaptively a machine-learning or artificial-intelligence process to predict, for a customer of the financial institution, an expected, customer-specific value of one or more targeted transaction or interaction parameters that characterize a behavior of the customer during a temporal interval, and additionally, or alternatively, a range of expected deviation from each of these customer-specific values of the transaction or interaction parameters during the temporal interval, using training datasets associated with a first prior temporal interval (e.g., a âtrainingâ interval), and using validation datasets associated with a second, and distinct, prior temporal interval (e.g., an out-of-time âvalidationâ interval). As described herein, the training and validation datasets may include, but are not limited to, values of adaptively selected features obtained, extracted, or derived from the maintained elements of customer-specific data that identify and characterize the each these customers, interactions between these customers and the financial institution, and an engagement of these customers with not only the financial products or services provisioned by the financial institution, but also one or more access products that facilitate the customer interaction with the financial institution via corresponding digital channels.
The machine-learning or artificial-intelligence process may, for example, include an ensemble or decision-tree process, such as a gradient-boosted decision-tree process (e.g., an XGBoost process). Further, in some examples, the machine-learning or artificial-intelligence process may include, but are not limited to, a clustering process, an unsupervised learning process (e.g., a k-means algorithm, a mixture model, a hierarchical clustering algorithm, etc.), a semi-supervised learning process, a supervised learning process, or a statistical process (e.g., a multinomial logistic regression model, etc.). The trained machine-learning or artificial-intelligence process may also include, among other things, a random decision forest, an artificial neural network, a deep neural network, or an association-rule process (e.g., an Apriori algorithm, an Eclat algorithm, or an FP-growth algorithm).
Further, in some instances, the expected, customer-specific values for the targeted transactional or interaction parameters, and additionally, or alternatively, the expected deviations from these expected, customer-specific values, may establish collectively a behavioral profile for the customer. The behavioral profile for the customer may, for example, characterize an expected transaction- or interaction-specific behavior of the customer during the temporal interval, and in some instances, may establish a ânormalâ or âbaselineâ behavior of that customer. Further, the expected deviations specified within the behavioral profile for the customer may establish, individually or collectively, a magnitude of a variation from the expected behavior that would be consistent with that expected behavior, and would not represent an instance of anomalous behavior inconsistent with the expected values of the targeted transactional or interaction parameters, e.g., as specified within the behavioral profile of that customer.
Certain of these exemplary processes, which adaptively train and validate a machine-learning or artificial-intelligence process using customer-specific training and validation datasets associated with respective training and validation periods, and which apply the trained and validated machine-learning or artificial-intelligence process to additional customer-specific input datasets, may enable the one or more of the FI computing systems to predict, in real-time, expected customer-specific values of a targeted set of transactional or interaction parameters during a temporal interval, and the expected deviations from these customer-specific values of the transactional or interaction parameters during the temporal interval. These exemplary processes described herein in addition to, or as an alternate to, existing queue-prioritization and fraud-detection processes that rely on predetermined prioritization or fraud-detection rules, or on an intuition or an experience of a representative of the financial institution, and the implementation of one or more of these exemplary processes may enhance or âboostâ an effectiveness of these existing queue-prioritization and fraud-detection processes in differentiating between instances of potential fraud that fall within the expected deviations of the normal or baseline behavior of the customer (and as such, fail to represent instances of actual fraud), and those instances of potential fraud that fall outside the expected deviations of the normal or baseline behavior of the customer during the predetermined temporal interval (as such, represent instances of actual fraud involving the provisioned financial products or access products).
A. Exemplary Processes for Adaptively Training Machine Learning or Artificial Intelligence Processes within Distributed Computing Environments
FIGS. 1 A and 1 B illustrate components of an exemplary computing environment 100 , in accordance with some exemplary embodiments. For example, as illustrated in FIG. 1 A , computing environment 100 may include one or more source systems 102 , such as, but not limited to, source system 102 A, source system 102 B, source system 102 C, and one or more computing systems associated with, or operated by, a financial institution, such as a financial institution (FI) computing system 130 , In some instances, each of source systems 102 (including source systems 102 A, source system 102 B, and source system 102 C, etc.) and FI computing system 130 , may be interconnected through one or more communications networks, such as communications network 120 . Examples of communications network 120 include, but are not limited to, a wireless local area network (LAN), e.g., a âWi-Fiâ network, a network utilizing radio-frequency (RF) communication protocols, a Near Field Communication (NFC) network, a wireless Metropolitan Area Network (MAN) connecting multiple wireless LANs, and a wide area network (WAN), e.g., the Internet.
In some examples, each of source systems 102 (including source systems 102 A, source system 102 B, and source system 102 C) and FI computing system 130 may represent a computing system that includes one or more servers and tangible, non-transitory memories storing executable code and application modules. Further, the one or more servers may each include one or more processors, which may be configured to execute portions of the stored code or application modules to perform operations consistent with the disclosed embodiments. For example, the one or more processors may include a central processing unit (CPU) capable of processing a single operation (e.g., a scalar operations) in a single clock cycle. Further, each of source systems 102 (including source systems 102 A, source system 102 B, and source system 102 C) and FI computing system 130 may also include a communications interface, such as one or more wireless transceivers, coupled to the one or more processors for accommodating wired or wireless internet communication with other computing systems and devices operating within computing environment 100 .
Further, in some instances, source systems 102 (including source systems 102 A, source system 102 B, and source system 102 C) and FI computing system 130 may each be incorporated into a respective, discrete computing system. In additional, or alternate, instances, one or more of source systems 102 (including source system 102 A and source system 102 B) and FI computing system 130 may correspond to a distributed computing system having a plurality of interconnected, computing components distributed across an appropriate computing network, such as communications network 120 of FIG. 1 A . For example, FI computing system 130 may correspond to a distributed or cloud-based computing cluster associated with and maintained by the financial institution, although in other examples, FI computing system 130 may correspond to a publicly accessible, distributed or cloud-based computing cluster, such as a computing cluster maintained by Microsoft Azureâ¢, Amazon Web Servicesâ¢, Google Cloudâ¢, or another third-party provider.
In some instances, FI computing system 130 may include a plurality of interconnected, distributed computing components, such as those described herein (not illustrated in FIG. 1 A ), which may be configured to implement one or more parallelized, fault-tolerant distributed computing and analytical processes (e.g., an Apache Spark⢠distributed, cluster-computing framework, a Databricks⢠analytical platform, etc.). Further, and in addition to the CPUs described herein, the distributed computing components of FI computing system 130 may also include one or more graphics processing units (GPUs) capable of processing thousands of operations (e.g., vector operations) in a single clock cycle, and additionally, or alternatively, one or more tensor processing units (TPUs) capable of processing hundreds of thousands of operations (e.g., matrix operations) in a single clock cycle. Through an implementation of the parallelized, fault-tolerant distributed computing and analytical protocols described herein, the distributed computing components of FI computing system 130 may perform any of the exemplary processes described herein, to ingest elements of data associated with the customers of the financial institution, including elements of customer-profile, transaction, and non-financial interaction data associated with these customers, to preprocess the ingested data elements, and to store the preprocessed data elements within an accessible data repository (e.g., within a portion of a distributed file system, such as a Hadoop distributed file system (HDFS)).
Further, and through an implementation of the parallelized, fault-tolerant distributed computing and analytical protocols described herein, the distributed components of FI computing system 130 may perform operations in parallel that not only train adaptively a machine-learning or artificial-intelligence process (e.g., the gradient-boosted, decision-tree process described herein) using corresponding training and validation datasets extracted from temporally distinct subsets of the preprocessed data elements, but also apply the adaptively trained machine-learning or artificial-intelligence process to customer-specific input datasets and generate, in real time, elements of behavioral profile data indicative of an expected, customer-specific value of one or more targeted transaction or interaction parameters that characterize a behavior of corresponding ones of the customers during a temporal interval, and additionally, or alternatively, a range of expected deviations from each of the expected customer-specific values of the targeted transaction or interaction parameters during the temporal interval.
As described herein, the expected, customer-specific values for the targeted transaction or interaction parameters during the temporal interval, and additionally, or alternatively, the ranges of expected deviations from these customer-specific values of the transaction or financial interaction parameters (e.g., as specified within the elements of behavioral profile data), may establish collectively a behavioral profile for corresponding ones of the customers, which may be valid throughout the temporal interval. By way of example, and for a particular customer of the financial institution, the elements of behavioral profile data characterize an expected behavior of the particular customer during the temporal interval, and the ranges of expected deviations specified within the elements of behavioral profile data for the particular customer may establish, individually or collectively, a magnitude of a variation from the expected behavior that would be consistent with that expected behavior, and that would not represent an instance of anomalous behavior inconsistent with the expected behavior.
Further, when coupled to many existing, rule-based processes for prioritizing queues of potentially fraudulent transactions, or existing, subjective processes categorizing a potentially fraudulent transaction as an instance of actual fraud, the elements of behavioral profiling data characterizing the particular customer of the financial institution may enhance or âboostâ an effectiveness of these existing queue-prioritization and fraud-detection processes in differentiating between instances of potential fraud that fall within the expected deviations of the normal or baseline behavior of the particular customer during the temporal interval (and as such, fail to represent instances of actual fraud involving the financial products or access products provisioned by the financial institution), and those instances of potential fraud that fall outside the expected deviations of the normal or baseline behavior of the particular customer during the temporal interval, and as such, represent instances of actual fraud involving the provisioned financial products or access products. The implementation of the parallelized, fault-tolerant distributed computing and analytical protocols described herein across the one or more GPUs or TPUs included within the distributed components of FI computing system 130 may, in some instances, accelerate the training, and the post-training deployment, of the machine-learning or artificial-intelligence process when compared to a training and deployment of the machine-learning or artificial-intelligence process across comparable clusters of CPUs capable of processing a single operation per clock cycle.
Referring back to FIG. 1 A , each of source systems 102 may maintain, within corresponding tangible, non-transitory memories, a data repository that includes confidential data associated with the customers of the financial institution. For example, internal source system 102 A may be associated with, or operated by, the financial institution, and may maintain, within the corresponding one or more tangible, non-transitory memories, a source data repository 103 that includes one or more elements of customer data 104 A, account data 104 B, and transaction data 104 C. In some instances, customer data 104 A may include a plurality of data records associated with, and characterizing, corresponding ones of the customers of the financial institution. By way of example, and for a particular customer of the financial institution, the data records of customer data 104 A may include, but are not limited to, one or more unique customer identifiers (e.g., an alphanumeric character string, such as a login credential, a customer name, etc.), residence data (e.g., a street address, etc.), other elements of contact data (e.g., a mobile number, an email address, etc.), values of demographic parameters that characterize the particular customer (e.g., ages, occupations, marital status, etc.), and other data characterizing the relationship between the particular customer and the financial institution. Further, customer data 104 A may also include, for the particular customer, multiple data records that include corresponding elements of temporal data (e.g., a time or date stamp, etc.), and the multiple data records may establish, for the particular customer, a temporal evolution in the customer residence or a temporal evolution in one or more of the demographic parameter values.
Account data 1048 may also include a plurality of data records that identify and characterize one or more financial products or financial instruments issued by the financial institution to corresponding ones of the customers. For example, the data records of account data 104 B may include, for each of the financial products issued to corresponding ones of the customers, one or more identifiers of the financial product or instrument (e.g., an account number, expiration data, card-security-code, etc.), one or more unique customer identifiers (e.g., an alphanumeric character string, such as a login credential, a customer name, etc.), and additional information characterizing a balance or current status of the financial product or instrument (e.g., payment due dates or amounts, delinquent accounts statuses, etc.). Examples of these financial products or financial instruments may include, but are not limited to, one or more deposit accounts issued to corresponding ones of the customers (e.g., a savings account, a checking account, etc.), one or more brokerage or retirements accounts issued to corresponding ones of the customers by the financial institutions, and one or more secured credit products issued to corresponding ones of the customers by the financial institution. The financial products or financial instruments may also include one or more credit products issued to corresponding ones of the customers by the financial institution, and examples of these unsecured credit products may include, but are not limited to, a credit-card account or a line-of-credit.
Transaction data 104 C may include data records that identify, and characterize one or more initiated, settled, or cleared transactions involving respective ones of the customers and corresponding ones of the financial products or instruments held by the customers. Examples of these transactions include, but are not limited to, purchase transactions, bill-payment transactions, electronic funds transfers (e.g., payroll deposits, etc.), currency conversions, purchases of securities, derivatives, or other tradeable instruments, electronic funds transfer (EFT) transactions, peer-to-peer (P2P) transfers or transactions, or real-time payment (RTP) transactions. For instance, and for a transaction involving a corresponding customer and corresponding financial product or instrument, the data records of transaction data 104 C may include, but are limited to, a customer identifier associated with the corresponding customer (e.g., the alphanumeric character string described herein, etc.), temporal data characterizing a date and/or time associated with the particular transaction, a counterparty identifier associated with a counterparty to the particular transaction (e.g., an alphanumeric character string, a counterparty name, a standard industrial classification (SIC) code, etc.), an identifier of the corresponding financial product or instrument (e.g., a tokenized account number, expiration data, card-security-code, etc.), geographic data characterizing the particular customer and/or the counterparty (e.g., a geographic position of a computing system or device of the customer, a geographic location associated with the counterparty, etc.), and/or values of one or more parameters of the particular transaction (e.g., a transaction amount, an identifier of a good or service involved in the particular transaction, etc.).
Further, and in addition to the data records that identify, and characterize one or more initiated, settled, or cleared transactions involving respective ones of the customers and the corresponding ones of the financial products or instruments, transaction data 104 C may also include data records that identify, and characterize one or more initiated transactions that represent instances of actual fraud involving the respective ones of the customer or the corresponding financial instruments of products held by these customers (e.g., as determined by one or more computing systems of the financial institution (e.g., FI computing system 130 , etc.), or by a representative of the financial institution, using any of the exemplary processes described herein. For instance, and for an initiated transaction that represents an instance of actual fraud, the data records of transaction data 104 C may include, but are limited to, a customer identifier associated with a corresponding customer involved in the initiated transaction (e.g., the alphanumeric character string described herein, etc.), temporal data characterizing a date and/or time associated with the initiated transaction, a counterparty identifier associated with a counterparty to the initiated transaction (e.g., an alphanumeric character string, a counterparty name, a standard industrial classification (SIC) code, etc.), an identifier of a corresponding financial product or instrument involved in the transaction and subject to the actual fraud (e.g., a tokenized account number, expiration data, card-security-code, etc.), geographic data characterizing the particular customer and/or the counterparty (e.g., a geographic position of a computing system or device of the customer, a geographic location associated with the counterparty, etc.), and/or values of one or more parameters of the initiated transaction (e.g., a transaction amount, an identifier of a good or service involved in the particular transaction, etc.).
The disclosed embodiments are, however, not limited to these exemplary elements of customer data 104 A, account data 1046 , or transaction data 104 C. In other instances, source system 102 A may maintain, within source data repository 103 , any addition, or alternate, elements of customer data 104 A, account data 1046 , or transaction data 104 C that identify and characterize the customers of the financial institution, the interactions between the customer and financial institution, and in some instances, interactions between the customers and corresponding products or services offered by the financial institution. Further, although stored in FIG. 1 A within source data repository 103 maintained within the tangible, non-transitory memories of source system 102 A, the exemplary elements of customer data 104 A, account data 1046 , or transaction data 104 C may be maintained by any additional or alternate computing system associated with the financial institution, including, but not limited to, within one or more tangible, non-transitory memories of FI computing system 130 .
Source system 102 B may also be associated with, or operated by, the financial institution, and maintain, within the corresponding one or more tangible, non-transitory memories, a source data repository 105 that includes one or more elements of activity data 106 . In some instances, activity data 106 may include data records that identify and characterize one or more requested and authorized (e.g., âgrantedâ) interactions between the financial institution and the customers of the financial institution, and each of the interactions may be associated with an engagement between a corresponding one of the customers of the financial institution and an access product provisioned by the financial institution, e.g., via a corresponding digital channel. Examples of these access products include, but are not limited to mobile applications (e.g., mobile banking applications), web-based online banking platforms, or voice-based banking platforms provisioned by the financial institution (e.g., via operations performed by FI computing system 130 , etc.) and accessible to the customers via corresponding computing devices or systems.
The requested and authorized interaction may include, among other things, a request by a particular customer to obtain a mobile application associated with the financial institution, or a request by the particular customer to register for access to a digital portal provisioned by the mobile application or by a web-based, mobile banking platform associated with the financial institution. The requested and authorized interactions may also include, but are not limited to, a request to access elements of confidential data characterizing one or more financial products held by the particular customer via an executed mobile application (e.g. a balance or outstanding payment associated with a credit-card account, etc.), a request to modify one or more authentication credentials (e.g., a request to modify an alphanumeric password, etc.), or a request to modify an identifier of the customer device that participates in a two-factor authentication process (e.g., a request to update a telephone number of the customer device, etc.). The disclosed embodiments are, however, not limited to these exemplary interactions, and in other instances, the requested and authorized interaction may any additional, or alternate, interaction between the customers of the financial institution and corresponding ones of the provisioned access products, as described herein.
By way of example, and for a requested and authorized interaction between the financial institution and a particular customer, the elements of activity data 106 may include, but are not limited to, a customer identifier of the particular customer (e.g., an alphanumeric identifier or login credential, a customer name, etc.), a temporal identifier associated with the interaction (e.g., a date and/or time at which the particular customer initiated the interaction, etc.), data characterizing an access product that facilitates the requested and authorized interaction (e.g., an alphanumeric identifier of the mobile application, web-based online banking platform, or voice-based banking platform, etc.), geographic data characterizing the interaction (e.g., a geographic position of a computing system or device of the customer, etc.), and data identifying and characterizing the requested and authorized interaction (e.g., an identifier of an activity associated with the requested and authorized interaction, e.g., a balance request, a request to modify an authentication credential or contact information, etc.).
Further, and in addition to the data records that identify and characterize requested and authorized interactions between the financial institution and corresponding customers of the financial institution, activity data 106 may also include data records that identify, and characterize one or more requested interactions that represent instances of actual fraudulent activity involving the corresponding ones of the customers and/or corresponding ones of the access products (e.g., as determined by one or more computing systems of the financial institution (e.g., FI computing system 130 , etc.), or by a representative of the financial institution, using any of the exemplary processes described herein. For instance, for a reque
CLAIMS
Claims ( 20 )
What is claimed is:
1 . An apparatus, comprising:
a memory storing instructions; a communications interface; and at least one processor coupled to the memory and the communications interface, the at least one processor being configured to execute the instructions to:
obtain a data element associated with an exchange of data, the data element comprising a first value of a parameter of the data exchange, and the data element being disposed at a corresponding position within an alert queue;
based on an application of a trained machine-learning or artificial-intelligence process to an input dataset associated with the data element, generate behavioral profile data that includes a range of expected deviations from an expected value of the parameter during a temporal interval;
based on a determination that the range of expected deviations fails to include the first parameter value, perform operations that prioritize the position of the data element within the alert queue; and
transmit, to a device via the communications interface, a notification that includes the data element and information characterizing the prioritized position of the data element within the alert queue.
2 . The apparatus of claim 1 , wherein:
the data exchange represents an instance of potentially fraudulent activity; the position of the data element within the alert queue indicates a first likelihood that the data exchange represents an instance of actual fraudulent activity; and the prioritized position of the data element within the alert queue indicates a second likelihood that the data exchange represents the instance of actual fraudulent activity, the second likelihood exceeding the first likelihood.
3 . The apparatus of claim 1 , wherein the data element comprises an identifier of a party associated with the data exchange and the first parameter value.
4 . The apparatus of claim 3 , wherein the at least one processor is further configured to execute the instructions to:
store the behavioral profile data and the party identifier within a portion of the memory; receive, via the communications interface, information characterizing an additional exchange of data, the information comprising the party identifier and a second value of the parameter; obtain the behavioral profile data from the memory based on the party identifier; based on a determination that the range of expected deviations fails to include the second parameter value, determine that the additional data exchange represents an instance of potentially fraudulent activity, and generate an additional data element associated with the additional data exchange, the additional data element being maintained at a corresponding position within the alert queue.
5 . The apparatus of claim 3 , wherein the at least one processor is further configured to execute the instructions to:
obtain the party identifier from the data element, and obtain first interaction data associated with the party identifier from the memory; and generate the input dataset based on elements of the first interaction data.
6 . The apparatus of claim 5 , wherein the at least one processor is further configured to:
obtain (i) one or more parameters that characterize the trained machine-learning or artificial-intelligence process and (ii) data that characterizes a composition of the input dataset; generate the input dataset in accordance with the data that characterizes the composition; and apply the trained machine-learning or artificial-intelligence process to the input dataset in accordance with the one or more parameters.
7 . The apparatus of claim 6 , wherein the at least one processor is further configured to:
based on the data that characterizes the composition, perform operations that at least one of extract a first feature value from the first interaction data or compute a second feature value based on the first feature value; and generate the input dataset based on at least one of the extracted first feature value or the computed second feature value.
8 . The apparatus of claim 5 , wherein the at least one processor is further configured to execute the instructions to:
obtain elements of second interaction data, each of the elements of the second interaction data comprising a temporal identifier associated with a temporal interval; based on the temporal identifiers, determine that a first subset of the elements of the second interaction data are associated with a prior training interval, and that a second subset of the elements of the second interaction data are associated with a prior validation interval; and generate a plurality of training datasets based on corresponding portions of the first subset, and perform operations that train the trained machine-learning or artificial-intelligence process based on the training datasets.
9 . The apparatus of claim 8 , wherein the at least one processor is further configured to execute the instructions to:
generate a plurality of validation datasets based on corresponding portions of the second subset; apply the trained machine-learning or artificial-intelligence process to the plurality of validation datasets, and generate additional elements of output data based on the application of the trained machine-learning or artificial-intelligence process to the plurality of validation datasets; compute one or more validation metrics based on the additional elements of output data; and based on a determined consistency between the one or more validation metrics and a threshold condition, validate the trained machine learning or artificial intelligence process.
10 . The apparatus of claim 1 , wherein:
the data exchange comprises an initiated transaction, and the first parameter value comprises a value of a transaction parameter associated with the initiated transaction; the behavioral profile data comprises an expected value of the transaction parameter during the temporal interval and ranges of expected deviations from the expected value of the transaction parameter during the temporal interval; the at least one processor is further configured to execute the instructions to perform the operations that prioritize the position of the data element within the alert queue based on a determination that the range of expected deviations fails to include the transaction parameter value.
11 . The apparatus of claim 1 , wherein:
the data exchange comprises a requested interaction associated with an access product, and the first parameter value comprises a value of an interaction parameter associated with the requested interaction; the behavioral profile data comprises an expected value of the interaction parameter during the temporal interval and ranges of expected deviations from the expected value during the temporal interval; the at least one processor is further configured to execute the instructions to perform the operations that prioritize the position of the data element within the alert queue based on a determination that the range of expected deviations fails to include the interaction parameter value.
12 . The apparatus of claim 1 , wherein the device is configured to obtain at least the data element and the information characterizing the prioritized position of the data element within the alert queue, present, within a digital interface, a graphical representation of the data element at the prioritized position within the alert queue, and perform operations that confirm that the data exchange represents an instance of actual fraudulent activity.
13 . A computer-implemented method, comprising:
obtaining, using at least one processor, a data element associated with an exchange of data, the data element comprising a first value of a parameter of the data exchange, and the data element being disposed at a corresponding position within an alert queue; based on an application of a trained machine-learning or artificial-intelligence process an input dataset associated with the data element, generating, using the at least one processor, behavioral profile data that includes a range of expected deviations from an expected value of the parameter during a temporal interval; based on a determination that the range of expected deviations fails to include the first parameter value, performing operations, using the at least one processor, that prioritize the position of the data element within the alert queue; and using the at least one processor, transmitting, to a device, a notification that includes the data element and information characterizing the prioritized position of the data element within the alert queue.
14 . The computer-implemented method of claim 13 , wherein:
the data exchange represents an instance of potentially fraudulent activity; the position of the data element within the alert queue indicates a first likelihood that the data exchange represents an instance of actual fraudulent activity; and the prioritized position of the data element within the alert queue indicates a second likelihood that the data exchange represents the instance of actual fraudulent activity, the second likelihood exceeding the first likelihood.
15 . The computer-implemented method of claim 13 , wherein the data element comprises an identifier of a party associated with the data exchange and the first parameter value.
16 . The computer-implemented method of claim 15 , further comprising:
using the at least one processor, store the behavioral profile data and the party identifier within a portion of a data repository; receiving, using the at least one processor, information characterizing an additional exchange of data, the information comprising the party identifier and a second value of the parameter; using the at least one processor, obtaining the behavioral profile data from the data repository based on the party identifier; based on a determination that the range of expected deviations fails to include the second parameter value, determining, using the at least one processor, that the additional data exchange represents an instance of potentially fraudulent activity, and generate an additional data element associated with the additional data exchange using the at least one processor, the additional data element being maintained at a corresponding position within the alert queue.
17 . The computer-implemented method of claim 15 , further comprising:
obtaining, using the at least one processor, first interaction data associated with the party identifier from a data repository; using the at least one processor, obtaining (i) one or more parameters that characterize the trained machine-learning or artificial-intelligence process and (ii) data that characterizes a composition of the input dataset; generating, using the at least one processor, the input dataset based on elements of the first interaction data and in accordance with the data that characterizes the composition; and applying, using the at least one processor, the trained machine-learning or artificial-intelligence process to the input dataset in accordance with the one or more parameters.
18 . The computer-implemented method of claim 17 , further comprising:
obtain elements of second interaction data using the at least one processor, each of the elements of the second interaction data comprising a temporal identifier associated with a temporal interval; based on the temporal identifiers, determining, using the at least one processor, that a first subset of the elements of the second interaction data are associated with a prior training interval, and that a second subset of the elements of the second interaction data are associated with a prior validation interval; and using the at least one processor, generating a plurality of training datasets based on corresponding portions of the first subset, and performing operations that train the trained machine-learning or artificial-intelligence process based on the training datasets.
19 . The computer-implemented method of claim 18 , further comprising:
generating, using the at least one processor, a plurality of validation datasets based on corresponding portions of the second subset; using the at least one processor, applying the trained machine-learning or artificial-intelligence process to the plurality of validation datasets, and generating additional elements of output data based on the application of the trained machine-learning or artificial-intelligence process to the plurality of validation datasets; computing, using the at least one processor, one or more validation metrics based on the additional elements of output data; and based on a determined consistency between the one or more validation metrics and a threshold condition, validating the trained machine-learning or artificial-intelligence process using the at least one processor.
20 . A tangible, non-transitory computer-readable medium storing instructions that, when executed by at least one processor, cause the at least one processor to perform a method, comprising:
obtaining a data element associated with an exchange of data, the data element comprising a first value of a parameter of the data exchange, and the data element being disposed at a corresponding position within an alert queue; based on an application of a trained machine-learning or artificial-intelligence process an input dataset associated with the data element, generating behavioral profile data that includes a range of expected deviations from an expected value of the parameter during a temporal interval; based on a determination that the range of expected deviations fails to include the first parameter value, performing operations that prioritize the position of the data element within the alert queue; and transmitting, to a device, a notification that includes the data element and information characterizing the prioritized position of the data element within the alert queue.
US17/707,658
2021-10-13
2022-03-29
Dynamic behavioral profiling using trained machine-learning and artificial-intelligence processes
Pending
US20230113752A1
( en )
Priority Applications (2)
Application Number
Priority Date
Filing Date
Title
US17/707,658
US20230113752A1
( en )
2021-10-13
2022-03-29
Dynamic behavioral profiling using trained machine-learning and artificial-intelligence processes
CA3153811A
CA3153811A1
( en )
2021-10-13
2022-03-30
Dynamic behavioral profiling using trained machine-learning and artificial-intelligence processes
Applications Claiming Priority (2)
Application Number
Priority Date
Filing Date
Title
US202163255293P
2021-10-13
2021-10-13
US17/707,658
US20230113752A1
( en )
2021-10-13
2022-03-29
Dynamic behavioral profiling using trained machine-learning and artificial-intelligence processes
Publications (1)
Publication Number
Publication Date
US20230113752A1
true
US20230113752A1 ( en )
2023-04-13
Family
ID=85797966
Family Applications (1)
Application Number
Title
Priority Date
Filing Date
US17/707,658
Pending
US20230113752A1
( en )
2021-10-13
2022-03-29
Dynamic behavioral profiling using trained machine-learning and artificial-intelligence processes
Country Status (2)
Country
Link
US
( 1 )
US20230113752A1
( en )
CA
( 1 )
CA3153811A1
( en )
Cited By (20)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20230128465A1
( en )
*
2021-10-27
2023-04-27
Bank Of America Corporation
System for enhanced exposure detection in digital channels
US20230137892A1
( en )
*
2021-10-29
2023-05-04
Google Llc
Method for Identifying Anomalous Transactions Using Machine Learning
US20230233793A1
( en )
*
2022-01-25
2023-07-27
Unitedhealth Group Incorporated
Machine learning techniques for parasomnia episode management
US11875109B1
( en )
*
2022-08-05
2024-01-16
Highradius Corporation
Machine learning (ML)-based system and method for facilitating correction of data in documents
US20240177094A1
( en )
*
2022-11-30
2024-05-30
Bank Of America Corporation
Automatic Alert Dispositioning using Artificial Intelligence
US12316715B2
( en )
2023-10-05
2025-05-27
The Toronto-Dominion Bank
Dynamic push notifications
US12399687B2
( en )
2023-08-30
2025-08-26
The Toronto-Dominion Bank
Generating software architecture from conversation
US12437856B2
( en )
2022-01-25
2025-10-07
Unitedhealth Group Incorporated
Machine learning techniques for parasomnia episode management
US20250335911A1
( en )
*
2024-04-24
2025-10-30
Capital One Services, Llc
Qr code payor tracking and repeat payment prevention
US20250373637A1
( en )
*
2024-05-29
2025-12-04
Bank Of America Corporation
system and method for detecting cyber-attacks
US12499241B2
( en )
2023-09-06
2025-12-16
The Toronto-Dominion Bank
Correcting security vulnerabilities with generative artificial intelligence
US12517812B2
( en )
2023-09-06
2026-01-06
The Toronto-Dominion Bank
Security testing based on generative artificial intelligence
US12536264B2
( en )
2024-07-19
2026-01-27
The Toronto-Dominion Bank
Parallel artificial intelligence driven identity checking with biometric prompting
US12541544B2
( en )
2024-03-28
2026-02-03
The Toronto-Dominion Bank
Generating a response for a communication session based on previous conversation content using a large language model
US12541894B2
( en )
2023-08-30
2026-02-03
The Toronto-Dominion Bank
Image modification based on goal progression
US12566541B2
( en )
2023-09-07
2026-03-03
The Toronto-Dominion Bank
Reconfigurable dashboard with moveable modules
US12585435B2
( en )
2023-08-30
2026-03-24
The Toronto-Dominion Bank
Real-time visualization of complex software architecture
US12592301B2
( en )
2023-08-30
2026-03-31
The Toronto-Dominion Bank
Prompt engineering and generative AI for goal-based imagery
US12591559B2
( en )
2024-03-28
2026-03-31
The Toronto-Dominion Back
Contextualized attributes for vectorized data
US12625680B2
( en )
2023-08-30
2026-05-12
The Toronto-Dominion Bank
Creating a model of software architecture
Citations (23)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
WO2000030398A1
( en )
*
1998-11-18
2000-05-25
Lightbridge, Inc.
Event manager for use in fraud detection
US20070124246A1
( en )
*
2000-09-29
2007-05-31
Justin Lawyer
Self-Learning Real-Time Priorization of Fraud Control Actions
US20070203826A1
( en )
*
2006-02-15
2007-08-30
Russell Thomas A
Fraud early warning system and method
US20080270303A1
( en )
*
2007-04-27
2008-10-30
Janice Zhou
Method and system for detecting fraud in financial transactions
US20080270171A1
( en )
*
2007-04-27
2008-10-30
Bryan Price
Method and system for managing caselog fraud and chargeback
US20100051684A1
( en )
*
2008-09-02
2010-03-04
William Lewis-Jennings Powers
Fraud geospeed alerting method and system
US20130024361A1
( en )
*
2011-07-21
2013-01-24
Bank Of America Corporation
Capacity customization for fraud filtering
US20130080368A1
( en )
*
2006-11-07
2013-03-28
Ebay Inc.
Online fraud prevention using genetic algorithm solution
US20140081652A1
( en )
*
2012-09-14
2014-03-20
Risk Management Solutions Llc
Automated Healthcare Risk Management System Utilizing Real-time Predictive Models, Risk Adjusted Provider Cost Index, Edit Analytics, Strategy Management, Managed Learning Environment, Contact Management, Forensic GUI, Case Management And Reporting System For Preventing And Detecting Healthcare Fraud, Abuse, Waste And Errors
US20140089192A1
( en )
*
2012-06-25
2014-03-27
Benjamin Scott Boding
Second level processing system and method
US9148869B2
( en )
*
2013-10-15
2015-09-29
The Toronto-Dominion Bank
Location-based account activity alerts
US9641418B1
( en )
*
2010-08-25
2017-05-02
Arris Enterprises, Inc.
Use of physical location and timing delay in fraud detection
US20200143371A1
( en )
*
2011-02-10
2020-05-07
Paypal, Inc.
Fraud alerting using mobile phone location
US10949850B1
( en )
*
2015-12-30
2021-03-16
Wells Fargo Bank, N.A.
Systems and methods for using location services to detect fraud
US20220006899A1
( en )
*
2020-07-02
2022-01-06
Pindrop Security, Inc.
Fraud importance system
US11379855B1
( en )
*
2018-03-06
2022-07-05
Wells Fargo Bank, N.A.
Systems and methods for prioritizing fraud cases using artificial intelligence
US20220334946A1
( en )
*
2021-03-05
2022-10-20
Sift Science, Inc.
Systems and methods for optimizing a machine learning-informed automated decisioning workflow in a machine learning task-oriented digital threat mitigation platform
US20220351216A1
( en )
*
2016-03-25
2022-11-03
State Farm Mutual Automobile Insurance Company
Identifying false positive geolocation-based fraud alerts
US11514456B1
( en )
*
2015-12-03
2022-11-29
Wells Fargo Bank, N.A.
Intraday alert volume adjustments based on risk parameters
US11605095B1
( en )
*
2020-03-23
2023-03-14
Patreon, Inc.
Systems and methods to facilitate resolution of work items in a fraud resolution workflow
US20230147934A1
( en )
*
2021-11-11
2023-05-11
Feedzai-Consultadoria e Inovaçao Tecnológica, S.A.
Triaging alerts using machine learning
US11722502B1
( en )
*
2017-04-13
2023-08-08
United Services Automobile Association (Usaa)
Systems and methods of detecting and mitigating malicious network activity
US20240259490A1
( en )
*
2010-03-28
2024-08-01
Spriv Llc
Method and system for validating electronic transactions
2022
2022-03-29
US
US17/707,658
patent/US20230113752A1/en
active
Pending
2022-03-30
CA
CA3153811A
patent/CA3153811A1/en
active
Pending
Patent Citations (27)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
WO2000030398A1
( en )
*
1998-11-18
2000-05-25
Lightbridge, Inc.
Event manager for use in fraud detection
US7457401B2
( en )
*
2000-09-29
2008-11-25
Justin Lawyer
Self-learning real-time prioritization of fraud control actions
US20070124246A1
( en )
*
2000-09-29
2007-05-31
Justin Lawyer
Self-Learning Real-Time Priorization of Fraud Control Actions
US20070203826A1
( en )
*
2006-02-15
2007-08-30
Russell Thomas A
Fraud early warning system and method
US20130080368A1
( en )
*
2006-11-07
2013-03-28
Ebay Inc.
Online fraud prevention using genetic algorithm solution
WO2008134039A1
( en )
*
2007-04-27
2008-11-06
Total System Services, Inc.
Method and system for detecting fraud in financial transactions
US20080270171A1
( en )
*
2007-04-27
2008-10-30
Bryan Price
Method and system for managing caselog fraud and chargeback
US20080270303A1
( en )
*
2007-04-27
2008-10-30
Janice Zhou
Method and system for detecting fraud in financial transactions
US20100051684A1
( en )
*
2008-09-02
2010-03-04
William Lewis-Jennings Powers
Fraud geospeed alerting method and system
US20240259490A1
( en )
*
2010-03-28
2024-08-01
Spriv Llc
Method and system for validating electronic transactions
US9641418B1
( en )
*
2010-08-25
2017-05-02
Arris Enterprises, Inc.
Use of physical location and timing delay in fraud detection
US20200143371A1
( en )
*
2011-02-10
2020-05-07
Paypal, Inc.
Fraud alerting using mobile phone location
US20130024361A1
( en )
*
2011-07-21
2013-01-24
Bank Of America Corporation
Capacity customization for fraud filtering
US20140089192A1
( en )
*
2012-06-25
2014-03-27
Benjamin Scott Boding
Second level processing system and method
US20140081652A1
( en )
*
2012-09-14
2014-03-20
Risk Management Solutions Llc
Automated Healthcare Risk Management System Utilizing Real-time Predictive Models, Risk Adjusted Provider Cost Index, Edit Analytics, Strategy Management, Managed Learning Environment, Contact Management, Forensic GUI, Case Management And Reporting System For Preventing And Detecting Healthcare Fraud, Abuse, Waste And Errors
US9148869B2
( en )
*
2013-10-15
2015-09-29
The Toronto-Dominion Bank
Location-based account activity alerts
US11514456B1
( en )
*
2015-12-03
2022-11-29
Wells Fargo Bank, N.A.
Intraday alert volume adjustments based on risk parameters
US10949850B1
( en )
*
2015-12-30
2021-03-16
Wells Fargo Bank, N.A.
Systems and methods for using location services to detect fraud
US20220351216A1
( en )
*
2016-03-25
2022-11-03
State Farm Mutual Automobile Insurance Company
Identifying false positive geolocation-based fraud alerts
US11687938B1
( en )
*
2016-03-25
2023-06-27
State Farm Mutual Automobile Insurance Company
Reducing false positives using customer feedback and machine learning
US11722502B1
( en )
*
2017-04-13
2023-08-08
United Services Automobile Association (Usaa)
Systems and methods of detecting and mitigating malicious network activity
US11379855B1
( en )
*
2018-03-06
2022-07-05
Wells Fargo Bank, N.A.
Systems and methods for prioritizing fraud cases using artificial intelligence
US11605095B1
( en )
*
2020-03-23
2023-03-14
Patreon, Inc.
Systems and methods to facilitate resolution of work items in a fraud resolution workflow
US20220006899A1
( en )
*
2020-07-02
2022-01-06
Pindrop Security, Inc.
Fraud importance system
US11895264B2
( en )
*
2020-07-02
2024-02-06
Pindrop Security, Inc.
Fraud importance system
US20220334946A1
( en )
*
2021-03-05
2022-10-20
Sift Science, Inc.
Systems and methods for optimizing a machine learning-informed automated decisioning workflow in a machine learning task-oriented digital threat mitigation platform
US20230147934A1
( en )
*
2021-11-11
2023-05-11
Feedzai-Consultadoria e Inovaçao Tecnológica, S.A.
Triaging alerts using machine learning
Non-Patent Citations (2)
* Cited by examiner, â Cited by third party
Title
Kalaiselvi et al., " Credit Card Fraud Detection Using Learning to Rank Approach, " International Conference on Computation of Power, Energy, Information and Communication, 2018 (Year: 2018)
*
Shirgave et al., " A Review On Credit Card Fraud Detection Using Machine Learning, " International Journal of Scientific and Technology Research, Vol. 8, Issue 10, Oct. 2019 (Year: 2019)
*
Cited By (23)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20230128465A1
( en )
*
2021-10-27
2023-04-27
Bank Of America Corporation
System for enhanced exposure detection in digital channels
US20230137892A1
( en )
*
2021-10-29
2023-05-04
Google Llc
Method for Identifying Anomalous Transactions Using Machine Learning
US12217306B2
( en )
*
2021-10-29
2025-02-04
Google Llc
Method for identifying anomalous transactions using machine learning
US12437856B2
( en )
2022-01-25
2025-10-07
Unitedhealth Group Incorporated
Machine learning techniques for parasomnia episode management
US20230233793A1
( en )
*
2022-01-25
2023-07-27
Unitedhealth Group Incorporated
Machine learning techniques for parasomnia episode management
US12496425B2
( en )
*
2022-01-25
2025-12-16
Unitedhealth Group Incorporated
Machine learning techniques for parasomnia episode management
US11875109B1
( en )
*
2022-08-05
2024-01-16
Highradius Corporation
Machine learning (ML)-based system and method for facilitating correction of data in documents
US20240177094A1
( en )
*
2022-11-30
2024-05-30
Bank Of America Corporation
Automatic Alert Dispositioning using Artificial Intelligence
US12399687B2
( en )
2023-08-30
2025-08-26
The Toronto-Dominion Bank
Generating software architecture from conversation
US12625680B2
( en )
2023-08-30
2026-05-12
The Toronto-Dominion Bank
Creating a model of software architecture
US12592301B2
( en )
2023-08-30
2026-03-31
The Toronto-Dominion Bank
Prompt engineering and generative AI for goal-based imagery
US12585435B2
( en )
2023-08-30
2026-03-24
The Toronto-Dominion Bank
Real-time visualization of complex software architecture
US12541894B2
( en )
2023-08-30
2026-02-03
The Toronto-Dominion Bank
Image modification based on goal progression
US12499241B2
( en )
2023-09-06
2025-12-16
The Toronto-Dominion Bank
Correcting security vulnerabilities with generative artificial intelligence
US12517812B2
( en )
2023-09-06
2026-01-06
The Toronto-Dominion Bank
Security testing based on generative artificial intelligence
US12566541B2
( en )
2023-09-07
2026-03-03
The Toronto-Dominion Bank
Reconfigurable dashboard with moveable modules
US12316715B2
( en )
2023-10-05
2025-05-27
The Toronto-Dominion Bank
Dynamic push notifications
US12541544B2
( en )
2024-03-28
2026-02-03
The Toronto-Dominion Bank
Generating a response for a communication session based on previous conversation content using a large language model
US12591559B2
( en )
2024-03-28
2026-03-31
The Toronto-Dominion Back
Contextualized attributes for vectorized data
US12572936B2
( en )
*
2024-04-24
2026-03-10
Capital One Services, Llc
QR code payor tracking and repeat payment prevention
US20250335911A1
( en )
*
2024-04-24
2025-10-30
Capital One Services, Llc
Qr code payor tracking and repeat payment prevention
US20250373637A1
( en )
*
2024-05-29
2025-12-04
Bank Of America Corporation
system and method for detecting cyber-attacks
US12536264B2
( en )
2024-07-19
2026-01-27
The Toronto-Dominion Bank
Parallel artificial intelligence driven identity checking with biometric prompting
Also Published As
Publication number
Publication date
CA3153811A1
( en )
2023-04-13
Similar Documents
Publication
Publication Date
Title
CA3153811A1
( en )
2023-04-13
Dynamic behavioral profiling using trained machine-learning and artificial-intelligence processes
US12619918B2
( en )
2026-05-05
Predicting targeted future engagement using trained artificial intelligence processes
US20220383324A1
( en )
2022-12-01
Dynamic autoscaling of server resources using intelligent demand analytic systems
US20220277227A1
( en )
2022-09-01
Predicting occurrences of targeted classes of events using trained artificial-intelligence processes
US20220327431A1
( en )
2022-10-13
Predicting service-specific attrition events using trained artificial-intelligence processes
US12217011B2
( en )
2025-02-04
Generating adaptive textual explanations of output predicted by trained artificial-intelligence processes
US20250285036A1
( en )
2025-09-11
Prediction of future occurrences of events using adaptively trained artificial-intelligence processes and contextual data
US20220318573A1
( en )
2022-10-06
Predicting targeted, agency-specific recovery events using trained artificial intelligence processes
US20220108069A1
( en )
2022-04-07
Dynamic management of compliance workflow using trained machine-learning and artificial-intelligence processes
US20220327397A1
( en )
2022-10-13
Predicting activity-specific engagement events using trained artificial-intelligence processes
US20220207606A1
( en )
2022-06-30
Prediction of future occurrences of events using adaptively trained artificial-intelligence processes
US11900271B2
( en )
2024-02-13
Self learning data loading optimizat