IP Library Granted Patent US 12694414
Granted Patent B2
US 12694414 · App. 18/464,762 · Granted Jul 28, 2026

Systems and methods for detecting malicious activity

Inventors: Jennifer Kwok (Brooklyn, NY); Martin Figueroa-Ramirez (Silver Spring, MD); Susan Hogan (Alexandria, VA); Tara Ann Hickey (Herndon, VA)
Assignee: Capital One Services, LLC
G06Q30/0185G06Q20/354G06Q20/4016
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12694414
App. No.
18/464,762
Granted
Jul 28, 2026
Kind
B2
Abstract

Systems and methods for detecting abusive behavior. In some aspects, a method includes receiving first transfer data for a first transfer associated with a second category of resources and a first indication whether the first transfer is associated with abusive behavior. The first transfer data may be processed using a first machine learning model to generate a first prediction regarding whether the first transfer is associated with abusive behavior. In response to determining that the first prediction does not match the first indication, the first machine learning model may be updated to generate a second machine learning model for the second category of resources. The method may include receiving second transfer data for a second transfer associated with a second category of resources and processing the second transfer data using the second machine learning model to generate a second prediction regarding whether the second transfer is associated with abusive behavior.

Claims (56)

1 . A system for detecting malicious network activity in resource transfers, the system comprising:

one or more processors; and

one or more non-transitory, computer-readable media comprising instructions that, when executed by the one or more processors, causes operations comprising:

receiving a training dataset comprising (1) transfer data for a plurality of transfers of a first category of resources and (2) corresponding indications regarding whether a transfer is associated with malicious network activity with respect to an entity involved in the transfer;

training, based on the training dataset, a first machine learning model for the first category of resources to predict whether a transfer is associated with malicious network activity with respect to an entity involved in the transfer;

receiving first transfer data for a first transfer associated with a second category of resources and a first indication whether the first transfer is associated with malicious network activity with respect to an entity involved in the first transfer;

processing the first transfer data using the first machine learning model to generate a first prediction regarding whether the first transfer is associated with malicious network activity with respect to an entity involved in the first transfer;

updating the first machine learning model, based on the first prediction and the first indication, to generate a second machine learning model, using the first transfer data and the first indication, for the second category of resources to predict whether a transfer is associated with malicious network activity with respect to an entity involved in the transfer;

receiving second transfer data for a second transfer associated with the second category of resources;

executing the second machine learning model based on the second transfer data to generate a second prediction regarding whether the second transfer is associated with malicious network activity with respect to an entity involved in the second transfer; and

in response to the second prediction indicating that the second transfer is associated with malicious network activity, preventing authentication of the second transfer by disabling virtual authentication data associated with the first transfer.

2 . The system of claim 1 , wherein the instructions cause the one or more processors to perform operations comprising:

receiving, via a user interface, a user input indicating authorization for authentication of the second transfer; and

in response to receiving the user input, transmitting a second command for enabling authentication of the second transfer.

3 . A method for detecting malicious activity in resource transfers, the method comprising:

receiving first transfer data for a first transfer associated with a second category of resources and a first indication whether the first transfer is associated with malicious network activity with respect to an entity involved in the first transfer;

processing the first transfer data using a first machine learning model for a first category of resources to generate a first prediction regarding whether the first transfer is associated with malicious network activity with respect to an entity involved in the first transfer;

updating the first machine learning model, based on the first prediction and the first indication, to generate a second machine learning model for the second category of resources to predict whether a transfer is associated with malicious network activity with respect to an entity involved in the transfer;

receiving second transfer data for a second transfer associated with the second category of resources; and

executing the second transfer data using the second machine learning model based on the second transfer data to generate a second prediction regarding whether the second transfer is associated with malicious network activity with respect to an entity involved in the second transfer.

4 . The method of claim 3 , further comprising:

receiving a training dataset comprising (1) transfer data for a plurality of transfers of the first category of resources and (2) corresponding indications regarding whether a transfer is associated with malicious network activity with respect to an entity involved in the transfer; and

training, based on the training dataset, the first machine learning model for the first category of resources to predict whether a transfer is associated with malicious network activity with respect to an entity involved in the transfer.

5 . The method of claim 3 , further comprising:

in response to the second prediction indicating that the second transfer is associated with malicious network activity, transmitting a command to prevent authentication of the second transfer.

6 . The method of claim 5 , wherein transmitting the command for preventing authentication of the second transfer comprises disabling virtual authentication data associated with the first transfer.

7 . The method of claim 5 , further comprising:

in response to receiving an indication of a successful execution of the command, transmitting a notification at a device of the entity indicating prevention of authentication of the second transfer.

8 . The method of claim 7 , further comprising:

receiving, via a user interface, a user input indicating authorization for authentication of the second transfer; and

in response to receiving the user input, transmitting a second command for enabling authentication of the second transfer.

9 . The method of claim 8 , further comprising updating, based on the user input, the second machine learning model.

10 . The method of claim 3 , further comprising extracting, from the second transfer data, properties of the second transfer, wherein the properties include resource data and virtual authentication data associated with the second transfer data.

11 . The method of claim 3 , wherein determining that the first prediction does not match the first indication comprises determining that an output probability of the first machine learning model exceeds a threshold probability.

12 . One or more non-transitory, computer-readable media comprising instructions that, when executed by one or more processors, causes operations comprising:

receiving first transfer data for a first transfer associated with a second category of resources and a first indication whether the first transfer is associated with malicious network activity with respect to an entity involved in the first transfer;

processing the first transfer data using a first machine learning model to generate a first prediction regarding whether the first transfer is associated with malicious network activity with respect to an entity involved in the first transfer;

in response to determining that the first prediction does not match the first indication, updating the first machine learning model, based on the first prediction and the first indication, to generate a second machine learning model, using the first transfer data and the first indication, for the second category of resources to predict whether a transfer is associated with malicious network activity with respect to an entity involved in the transfer;

receiving second transfer data for a second transfer associated with the second category of resources; and

executing the second transfer data using the second machine learning model based on the second transfer data to generate a second prediction regarding whether the second transfer is associated with malicious network activity with respect to an entity involved in the second transfer.

13 . The one or more non-transitory, computer-readable media of claim 12 , wherein the instructions cause the one or more processors to perform operations comprising:

receiving a training dataset comprising (1) transfer data for a plurality of transfers of a first category of resources and (2) corresponding indications regarding whether a transfer is associated with malicious network activity with respect to an entity involved in the transfer; and

training, based on the training dataset, the first machine learning model for the first category of resources to predict whether a transfer is associated with malicious network activity with respect to an entity involved in the transfer.

14 . The one or more non-transitory, computer-readable media of claim 13 , wherein the instructions cause the one or more processors to perform operations comprising:

in response to the second prediction indicating that the second transfer is associated with malicious network activity, transmitting a command to prevent authentication of the second transfer.

15 . The one or more non-transitory, computer-readable media of claim 14 , wherein transmitting the command for preventing authentication of the second transfer comprises disabling virtual authentication data associated with the first transfer.

16 . The one or more non-transitory, computer-readable media of claim 14 , wherein the instructions cause the one or more processors to perform operations comprising:

in response to receiving an indication of a successful execution of the command, transmitting a notification at a device of the entity indicating prevention of authentication of the second transfer.

17 . The one or more non-transitory, computer-readable media of claim 16 , wherein the instructions cause the one or more processors to perform operations comprising:

receiving, via a user interface, a user input indicating authorization for authentication of the second transfer; and

in response to receiving the user input, transmitting a second command for enabling authentication of the second transfer.

18 . The one or more non-transitory, computer-readable media of claim 17 , wherein the instructions cause the one or more processors to perform operations comprising updating, based on the user input, the second machine learning model.

19 . The one or more non-transitory, computer-readable media of claim 12 , the instructions cause the one or more processors to perform operations comprising:

extracting, from the second transfer data, properties of the second transfer, wherein the properties include resource data and virtual authentication data associated with the second transfer data.

20 . The one or more non-transitory, computer-readable media of claim 12 , wherein determining that the first prediction does not match the first indication comprises:

determining that an output probability of the first machine learning model exceeds a threshold probability.