An AI Security Agent for Banking: Multi-Vector Fraud and AML Detection Across Retail and Corporate Accounts

📅 2026-06-16
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the dual challenges banks face from signature-based fraud—such as card-not-present transactions and account takeovers—and behavioral financial crimes, including layering money laundering and business email compromise, which traditional rule-based engines struggle to detect effectively. To tackle this, the authors propose an AI-powered security agent for both retail and corporate accounts, featuring a novel three-component architecture that fuses transaction streams and session streams in parallel. The framework integrates LSTM-based temporal modeling, statistical threshold monitoring, and account relationship graph networks to enable joint detection of multi-vector fraud and anti-money laundering threats. Experimental results on synthetic data demonstrate F1 scores of 0.787 and 0.867 for transaction and session streams, respectively, significantly outperforming rule-based baselines and standalone LSTM models, while achieving 96.6% authentication accuracy with critical response latency under 0.43 milliseconds.
📝 Abstract
Banks simultaneously face signature-based fraud (card-not-present attacks, account takeover, ATM cloning) and behavioural financial crime (structuring, layering, mule networks, business email compromise) -- two threat families with fundamentally different detection requirements. Static rule engines that reliably catch brute-force and high-velocity events are structurally blind to business-email-compromise (BEC) payment redirection, session hijacking, and money-laundering layering, which are engineered to appear indistinguishable from legitimate activity at the individual transaction or session level. This paper presents an AI security agent for retail and corporate banking that addresses this gap through a three-component fusion architecture operating on two parallel event streams: a transaction stream (card fraud, ACH/wire fraud, AML categories) and a session stream (account takeover, session hijacking, SIM-swap, insider abuse). Each stream combines an LSTM sequence model capturing per-account behavioural history, a statistical velocity/threshold monitor, and a graph/network module capturing account-counterparty relationship patterns (fan-in, fan-out, pass-through ratio) for money-laundering detection. Experiments on a synthetic event log of 237,669 transactions and 113,508 sessions across 13 threat categories and 3,470 simulated accounts demonstrate overall F1 of 0.787 (transaction stream) and 0.867 (session stream) for the proposed model, versus 0.562/0.733 for a rule-based baseline and 0.655/0.713 for an LSTM-only baseline. The agent includes a customer-facing transaction-verification chatbot (96.6% identity verification accuracy, 86.8% mass-reset attack detection) and an analyst case-summary assistant (99.3% action-recommendation F1), with Critical-tier automated response latency under 0.43 ms at the 95th percentile.
Problem

Research questions and friction points this paper is trying to address.

fraud detection
anti-money laundering
behavioral financial crime
account takeover
business email compromise
Innovation

Methods, ideas, or system contributions that make the work stand out.

AI Security Agent
Multi-Vector Fraud Detection
Fusion Architecture
Graph-Based AML
Behavioral Sequence Modeling
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
J
Joseph Walusimbi
Dept. of Electronics and Computer Engineering, Soroti University, Soroti, Uganda
J
Joshua Benjamin Ssentongo
Dept. of Electronics and Computer Engineering, Soroti University, Soroti, Uganda