Robust Fraud Transaction Detection: A Two-Player Game Approach
Qi Tan, Yi Zhao, Laizhong Cui, Qi Li, Ming Zhu, Xing Fu, Weiqiang Wang, Xiaotong Lin, Ke Xu
Abstract
ABA Banking Journal's report 1 , the corporate cost caused by fraudulent activities will exceed 57.147 billion by 2033 [31] . However, traditional fraud detection systems cannot keep up with the fast evolving fraud activities. Specifically, fraudsters are constantly developing new tactics to evade ML-based detection systems [18], [21], leading to more sophisticated and stealthy fraud activities. These tactics are rooted in the deliberately falsified features in fraud transactions, which cause detection systems to misclassify them into benign transactions. Worse still, fraudsters can employ advanced techniques to detect vulnerabilities in the detection system, leading to more effective methods to falsify features. The act of falsifying transaction features to bypass detection mechanisms can be formalized as executing adversarial attacks against targeted detection systems. Yet, there are three distinct characteristics in falsifying the features of fraud activities: (i) the perturbations are unrestricted. Transactions are constituted with monetary features (e.g., Transfer Amount, Register Capital) or temporal features (e.g., Days After Certified), these features are not restricted in small intervals; (ii) the falsification process is resource consuming. Unlike adversarial examples in the image or language field, which only changes pixels or semantics, falsifying features in fraud detection consumes resources (e.g., falsifying the feature of Days After Certified takes substantial time to maintain accounts); (iii) the fraudsters are profit-driven. Since fraudsters aim to get illegal profits from fraud activities as much as possible, the variation of profits exhibits a profound influence on their fraud behaviors (e.g., over 60% of the fraudsters gave up to purchase new accounts
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on31
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- TabNet: Attentive Interpretable Tabular LearningSercan Ö. Arik, Tomas PfisterAAAI 2021 · 2,148 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
Related papers
- Towards Collaborative Anti-Money Laundering Among Financial InstitutionsZhihua Tian, Yuan Ding, Xiang Yu, Enchao Gong et al.WWW 2025 · 2 citations
- Gotta Detect 'Em All: Fake Base Station and Multi-Step Attack Detection in Cellular NetworksKazi Samin Mubasshir, Imtiaz Karim, Elisa BertinoUSENIX Security 2025
- Targeting Borderline Fraudsters: Multi-View Hypergraph Fraud Detection with LLM-Guided Contrastive LearningRui Ou, Kun Zhu, Nana Zhang, Jiangtong Li et al.AAAI 2026
- Improving Robustness of ML Classifiers against Realizable Evasion Attacks Using Conserved FeaturesLiang Tong, Bo Li, Chen Hajaj, Chaowei Xiao et al.USENIX Security 2019 · 95 citations
- How to Cover up Anomalous Accesses to Electronic Health RecordsXiaojun Xu, Qingying Hao, Zhuolin Yang, Bo Li et al.USENIX Security 2023
