fraud

Designs, builds, or analyzes models, rule systems, and operational pipelines to detect, prevent, and investigate deceptive or illegitimate behaviors, transactions, accounts, and actors. Work includes feature engineering, anomaly and network analysis, scoring and alerting systems, labeling and evaluation methods, and monitoring for real-time and batch detection and response.

fraud

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.07
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$216K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

Current automated detection tools struggle to meet regulatory practice demands due to insufficient transparency, interpretability, and the inability to map findings to specific legal provisions, resulting in a disconnect between academic research and enforcement applications. Through in-depth interviews with nine regulatory practitioners and an analysis integrating regulatory workflows with technical feasibility, this study systematically uncovers, from a regulatory perspective, the practical barriers to deploying automated tools for identifying deceptive designs. The work proposes a human-in-the-loop compliance review framework that is user-need-driven, supports the entire investigative workflow, and aligns both research and regulatory objectives, offering critical guidance for developing automated detection systems that genuinely meet real-world enforcement requirements.

automated detectiondark patternsdeceptive design patterns

High false-positive rates and low signal-to-noise ratios in Network Intrusion Detection System (NIDS) rules severely impede Security Operations Center (SOC) efficacy. Method: Through empirical analysis of commercial SOC rule sets, expert interviews, and alarm log modeling, this study quantitatively characterizes the relationship between design factors—including proxy detection, alert throttling, and differentiation of successful versus failed behaviors—and noise generation. Contribution/Results: We derive six actionable, empirically grounded NIDS rule quality principles and propose a novel rule trade-off framework that jointly optimizes coverage and specificity. Deployment of this framework reduces SOC alert noise significantly, decreasing analyst workload by approximately 37% while preserving threat detection capability. This work delivers the first evidence-based, quantitative design guide for NIDS rule engineering—bridging a critical gap between theoretical security models and operational SOC practice.

Alert RulesCybersecurityOperational Efficiency

FAA Framework: A Large Language Model-Based Approach for Credit Card Fraud Investigations

Jun 13, 2025
SS
Shaun Shuster
🏛️ Ben-Gurion University of the Negev

Rising e-commerce fraud has overwhelmed manual investigation processes, causing delayed responses and alert fatigue. This paper introduces the first multimodal large language model (MLLM)-based automation framework tailored for credit card fraud investigations. Our approach innovatively integrates task planning (Chain-of-Thought + ReAct), dynamic code execution, OCR, and visual reasoning over transaction graphs to enable end-to-end autonomous execution of a standardized seven-step investigative workflow: alert parsing → evidence collection → cross-source reasoning → report generation. The framework ensures interpretability and strict adherence to financial regulatory requirements. Evaluated on 500 real-world cases, it fully completes all seven analytical steps on average, achieves >92% accuracy in critical conclusions, significantly improves investigation efficiency, and substantially reduces both false negatives and analyst cognitive load.

Addressing alert fatigue from excessive transaction monitoring alertsAutomating credit card fraud investigations to reduce analyst workloadGenerating reliable explanatory reports using multi-modal LLMs

Existing anti-money laundering (AML) systems rely on statistical anomaly detection, erroneously treating money laundering as “abnormal behavior,” despite its frequent manifestation as covert, repetitive, and highly consistent patterns. This work proposes a paradigm shift—from entity-centric anomaly identification to detecting semantically grounded, predefined money laundering patterns within directed transaction networks. Methodologically, we integrate subgraph analysis, semantic role modeling, and behavioral stability assessment. Our core contributions are twofold: (i) introducing *behavioral consistency* as the fundamental discriminative criterion, and (ii) formally defining *pattern vulnerability*—the sensitivity of laundering patterns to local attribute perturbations—to jointly characterize their semantic robustness and structural sensitivity. Experiments demonstrate substantial improvements in detecting covert, structured money laundering activities, advancing AML from isolated alert generation toward pattern-essence-driven detection logic.

Analyze pattern fragility and semantic robustnessDetect money laundering patterns in transaction networksFocus on behavioral consistency over anomaly detection

Network Analytics for Anti-Money Laundering - A Systematic Literature Review and Experimental Evaluation

May 29, 2024
BD
Bruno Deprez
🏛️ KU Leuven | University of Antwerp | University of Southampton

Anti-money laundering (AML) research leveraging network analysis (NA) is fragmented, lacking systematic surveys and comparable empirical evaluations. Method: We conduct the first large-scale systematic literature review covering 97 papers and an accompanying empirical study. We propose the first structured taxonomy for NA-AML, develop a reproducible and extensible standardized benchmark, and uniformly evaluate three representative method classes—handcrafted features, random-walk-based embeddings (DeepWalk, Node2Vec), and graph neural networks (GNNs)—on public AML datasets. Contribution/Results: Our findings show that NA significantly improves money laundering detection performance; however, GNNs exhibit limited robustness under class imbalance and complex graph topologies. Moreover, existing open-source AML datasets suffer from representativeness bias. This work establishes a theoretical framework, an evaluation paradigm, and open-source tools for NA-AML, thereby advancing method standardization and reproducible research.

Addresses fragmented research on network analytics for anti-money laundering.Evaluates and compares performance of network analytics methods.Highlights challenges in applying deep learning and open-source data.

Latest Papers

What's happening recently
View more

This study addresses the lack of empirical evidence on key operational metrics—such as latency, cost, fairness, and adversarial robustness—for deploying large language models (LLMs) in trust and safety workflows like fraud detection and content moderation. Through a systematic literature review of 49 operationally relevant studies, the authors propose the FORTE role framework and a minimal deployment evidence checklist encompassing dimensions like latency budgets and per-decision costs to structurally evaluate LLM roles and evidence completeness in real-world settings. The analysis reveals a structural imbalance in existing work: while content moderation exhibits relatively comprehensive operational evidence, fraud detection suffers from severe gaps. The paper concludes by outlining critical directions for empirical research necessary to support reliable LLM deployment in high-stakes applications.

deploymentfraud detectionLLMs

This study addresses the dual challenges banks face from signature-based fraud—such as card-not-present transactions and account takeovers—and behavioral financial crimes, including layering money laundering and business email compromise, which traditional rule-based engines struggle to detect effectively. To tackle this, the authors propose an AI-powered security agent for both retail and corporate accounts, featuring a novel three-component architecture that fuses transaction streams and session streams in parallel. The framework integrates LSTM-based temporal modeling, statistical threshold monitoring, and account relationship graph networks to enable joint detection of multi-vector fraud and anti-money laundering threats. Experimental results on synthetic data demonstrate F1 scores of 0.787 and 0.867 for transaction and session streams, respectively, significantly outperforming rule-based baselines and standalone LSTM models, while achieving 96.6% authentication accuracy with critical response latency under 0.43 milliseconds.

account takeoveranti-money launderingbehavioral financial crime

This study addresses the challenge of detecting coordinated multi-account fraud under high transaction volumes by proposing a hierarchical, auditable fraud detection pipeline that integrates gradient-boosted trees, graph-based structural features, autoencoder-derived anomaly signals, TreeSHAP explanations, and an LLM-driven investigative agent, complemented by a disagreement-based escalation review mechanism. It presents the first systematic evaluation of the synergistic effectiveness of graph features, anomaly detection, and LLM agents in realistic fraud scenarios. Experimental results demonstrate that graph features substantially enhance fraud ranking performance in the medium-risk segment and achieve 100% recall in fraud ring detection. Although the LLM agent generates plausible explanations, its decision accuracy falls below that of threshold-based methods; however, its errors are effectively flagged through the disagreement-based escalation mechanism.

auditable AIexplainabilityfraud detection