IP Library Granted Patent US 12,505,447
Granted Patent B2
US 12,505,447 · App. 17/872,045 · Granted Dec 23, 2025

Method and system for validating financial events and security events

Inventors: Zachary Richard Dahlgren (Gretna, NE); Uri Rivner (Kidron, IL); Oren Kedem (Tel Aviv, IL)
Assignee: Refine Intelligence Ltd.
G06Q20/4016G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,447
App. No.
17/872,045
Granted
Dec 23, 2025
Kind
B2
Abstract

Methods and systems provide for approaching end-users, collecting their information as it relates to a specific suspect event or set of events, for security events, such as financial events and computer security events, and then applying an Artificial Intelligence (AI) model, to a given security event, to analyze the provided information, to investigate the event or set of events, for validation.

Claims (56)

1 . A method for validating financial or security events which are determined to be potentially fraudulent comprising:

generating, by a computer system, an alert that a financial or security event initiated by a user is potentially fraudulent, wherein the user is a customer of a financial institution associated with the computer system, wherein event comprises a financial transaction;

obtaining, by the computer system, a plurality of data points associated with the alert, wherein the data points comprise data specific to the user and specific to the user's financial account with the financial institution and further comprise a transaction category and an alert category, wherein the transaction comprises a request by the user to initiate or accept a funds transfer;

based on the output of the first model, prompting the user, by the computer system, via the determined digital communication channel, to provide context for the funds transfer in the form of answers to one or more dynamic interactive questions about the funds transfer, the one or more interactive questions selected using a decision tree that selects a next question based at least in part on an answer received in response to a previous question, wherein the decision tree comprises a second machine learning model trained on the life stories and user profiles of a large population of other users associated with security events and transactions having the same transaction category as that of the alert,

wherein the context and user answers are augmented and enriched by the second model based on the training;

applying, by the computer system, the context and user answers associated with the funds transfer transaction to a third machine learning model comprising a validation model, wherein the third model is trained by conducting a user vs population analysis in which a plurality of event features calculated based on user life stories and profile data, account data, alert data and transactional data are compared, wherein the training uses a cluster module to generate a baseline model for user behavior for determining anomalous behavior, wherein the cluster module uses a distance-based feature analysis as applied to features calculated for a population of prior users associated with events in the same specific transaction category and used as baseline data for the population for the specific transaction category, wherein the baseline data includes user age range and median, transfer amount range and median, and account age range and median, wherein the baseline data is continually recalculated and added to the population baseline model that takes as input a labeled data set comprising data from past alerts that have been cleared as genuine activities, wherein as a result of the user vs population analysis a baseline deviation is calculated for the funds transfer;

generating, by the computer system using the validation machine learning model, based on the baseline deviation of the funds transfer transaction, a risk score for the funds transfer transaction;

based on the risk score and one or more other parameters associated with the alert, approving or declining, by the computer system, the funds transfer transaction or initiating, by the computer system, further manual review of the request associated with the funds transfer transaction;

provisionally adding, by the computer system, the plurality of event features associated with the funds transfer transaction to the population baseline model;

obtaining, by the computer system, feedback indicating whether the transaction was in fact a fraudulent event; and

responsive to the feedback indicating that the event was in fact a fraudulent event, removing, by the computer system, the plurality of transaction features from the population baseline model.

2 . The method of claim 1 , wherein the first model is further trained with data based on previous transactions between other users and the financial institution.

3 . The method of claim 1 , wherein the data specific to the user and specific to the user's financial account include one or more of: a name of the user, a phone number of the user, an account number of the user, an origin or destination bank account number for a bank transfer initiated by the user, a transfer amount for a bank transfer initiated by the user and a history of alerts that were previously generated in response to transactions initiated by the user.

4 . The method of claim 1 , wherein the data points further comprise data specific to other users and is obtained from any one or more of the following sources: a profile of the user or a profile of one or more users having a similar profile to that of the user, previous user inquiries for the user, transaction history for the user or transaction history for one or more users having a similar profile to that of the user, and alerts that were previously generated for users having a similar profile to that of the user.

5 . The method of claim 1 , further comprising:

updating, by the computer system, a profile of the user based on one or more of the answers.

6 . The method of claim 1 ,

wherein the risk score is indicative of the likelihood of the alert being generated in response to a fraudulent event, wherein the risk score further includes one or more metrics, and wherein the approving or declining is responsive to applying

one or more predetermined rules to the one or more metrics.

7 . The method of claim 1 , wherein the answers are augmented and enriched at least in part using one or more of: third party checks of at least certain ones of the answers, and data obtained in response to an analysis of a behavior of the user when providing one or more of the answers.

8 . The method of claim 7 , wherein the behavior of the user is determined by performing intent analysis on input provided by the user.

9 . The method of claim 2 , wherein the first model is further trained to initiate an inquiry in respect of at least some transactions

for which no alert was generated.

10 . A system for validating financial or security events security events which are determined to be potentially fraudulent comprising:

a processor; and

a memory device on which is stored one or more computer-executable instructions that when executed by the processor cause the processor to perform steps comprising:

generating an alert that a financial or security event initiated by a user is potentially fraudulent, wherein the user is a customer of a financial institution associated with the computer system, wherein event comprises a financial transaction,

obtaining a plurality of data points associated with the alert, wherein the data points comprise data specific to the user and specific to the user's financial account with the financial institution and further comprise a transaction category and an alert category, wherein the transaction comprises a request by the user to initiate or accept a funds transfer,

based on the output of the first model, prompting the user, via the determined digital communication channel, to provide context for the funds transfer in the form of answers to one or more dynamic interactive questions about the funds transfer, the one or more interactive questions selected using a decision tree that selects a next question based at least in part on an answer received in response to a previous question, wherein the decision tree comprises a second machine learning model trained on the life stories and user profiles of a large population of other users associated with security events and transactions having the same transaction category as that of the alert, wherein the context and user answers are augmented and enriched by the second model based on the training,

applying the context and user answers associated with the funds transfer transaction to a third machine learning model comprising a validation model, wherein the third model is trained by conducting a user vs population analysis in which a plurality of event features calculated based on user life stories and profile data, account data, alert data and transactional data are compared, wherein the training uses a cluster module to generate a baseline model for user behavior for determining anomalous behavior, wherein the cluster module uses a distance-based feature analysis as applied to features calculated for a population of prior users associated with events in the same specific transaction category and used as baseline data for the population for the specific transaction category, wherein the baseline data includes user age range and median, transfer amount range and median, and account age range and median, wherein the baseline data is continually recalculated and added to the population baseline model that takes as input a labeled data set comprising data from past alerts that have been cleared as genuine activities, wherein as a result of the user vs population analysis a baseline deviation is calculated for the funds transfer,

generating, using the validation machine learning model, based on the baseline deviation of the funds transfer transaction, a risk score for the funds transfer transaction,

based on the risk score and one or more other parameters associated with the alert, approving or declining the funds transfer transaction or initiating further manual review of the request associated with the funds transfer transaction,

provisionally adding the plurality of event features associated with the funds transfer transaction to the population baseline model,

obtaining feedback indicating whether the transaction was in fact a fraudulent event, and

responsive to the feedback indicating that the event was in fact a fraudulent event, removing the plurality of transaction features from the population baseline model.

11 . The system of claim 10 , wherein the first model is further trained with data based on previous transactions between other users and the financial institution.

12 . The system of claim 10 , wherein the data specific to the user and specific to the user's financial account include one or more of: a name of the user, a phone number of the user, an account number of the user, an origin or destination bank account number for a bank transfer initiated by the user, a transfer amount for a bank transfer initiated by the user and a history of alerts that were previously generated in response to transactions initiated by the user.

13 . The system of claim 10 , wherein the data points further comprise data specific to other users and is obtained from any one or more of the following sources: a profile of the user or a profile of one or more users having a similar profile to that of the user, previous user inquiries for the user, transaction history for the user or transaction history for one or more users having a similar profile to that of the user, and alerts that were previously generated for users having a similar profile to that of the user.

14 . The system of claim 10 , the steps further comprising:

updating a profile of the user based on one or more of the answers.

15 . The system of claim 10 ,

wherein the risk score is indicative of the likelihood of the alert being generated in response to a fraudulent event, wherein the risk score further includes one or more metrics, and wherein the approving or declining is responsive to applying

one or more predetermined rules to the one or more metrics.

16 . The system of claim 10 , wherein the answers are augmented and enriched at least in part using one or more of: third party checks of at least certain ones of the answers, and data obtained in response to an analysis of a behavior of the user when providing one or more of the answers.

17 . The system of claim 16 , wherein the behavior of the user is determined by performing intent analysis on input provided by the user.

18 . A non-transitory computer-readable medium on which is stored instructions for a processor to validate financial or security events which are determined to be potentially fraudulent that, when executed by the processor, cause the processor to perform steps of:

generating an alert that a financial or security event initiated by a user is potentially fraudulent, wherein the user is a customer of a financial institution associated with the computer system, wherein event comprises a financial transaction;

obtaining a plurality of data points associated with the alert, wherein the data points comprise data specific to the user and specific to the user's financial account with the financial institution and further comprise a transaction category and an alert category, wherein the transaction comprises a request by the user to initiate or accept a funds transfer;

based on the output of the first model, prompting the user, via the determined digital communication channel, to provide context for the funds transfer in the form of answers to one or more dynamic interactive questions about the funds transfer, the one or more interactive questions selected using a decision tree that selects a next question based at least in part on an answer received in response to a previous question, wherein the decision tree comprises a second machine learning model trained on the life stories and user profiles of a large population of other users associated with security events and transactions having the same transaction category as that of the alert,

wherein the context and user answers are augmented and enriched by the second model based on the training;

applying the context and user answers associated with the funds transfer transaction to a third machine learning model comprising a validation model, wherein the third model is trained by conducting a user vs population analysis in which a plurality of event features calculated based on user life stories and profile data, account data, alert data and transactional data are compared, wherein the training uses a cluster module to generate a baseline model for user behavior for determining anomalous behavior, wherein the cluster module uses a distance-based feature analysis as applied to features calculated for a population of prior users associated with events in the same specific transaction category and used as baseline data for the population for the specific transaction category, wherein the baseline data includes user age range and median, transfer amount range and median, and account age range and median, wherein the baseline data is continually recalculated and added to the population baseline model that takes as input a labeled data set comprising data from past alerts that have been cleared as genuine activities, wherein as a result of the user vs population analysis a baseline deviation is calculated for the funds transfer;

generating, using the validation machine learning model, based on the baseline deviation of the funds transfer transaction, a risk score for the funds transfer transaction;

based on the risk score and one or more other parameters associated with the alert, approving or declining the funds transfer transaction or initiating further manual review of the request associated with the funds transfer transaction;

provisionally adding the plurality of event features associated with the funds transfer transaction to the population baseline model;

obtaining feedback indicating whether the transaction was in fact a fraudulent event; and

responsive to the feedback indicating that the event was in fact a fraudulent event, removing the plurality of transaction features from the population baseline model.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Mar 4, 2024
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: REFINE INTELLIGENCE, INC.
Reel/Frame 066631/0402 →
SECURITY INTEREST Recorded Feb 22, 2023
From: REFINE INTELLIENCE, INC.
To: SILICON VALLEY BANK
Reel/Frame 062767/0803 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2022
From: DAHLGREN, ZACHARY RICHARD; RIVNER, URI; KEDEM, OREN
To: REFINE INTELLIGENCE LTD.
Reel/Frame 060601/0909 →
Continuity (2)
Provisional Application 63225842 · Jul 26, 2021
Related Publication 20230032963A1 · Feb 2, 2023
References Cited (19)
US 11019090B1 · Smith · 2021 [cited by examiner]
US 11706337B1 · Mitchem · 2023 [cited by examiner]
US 11775979B1 · Burger · 2023 [cited by examiner]
US 20060282660A1 · Varghese · 2006 [cited by examiner]
US 20100114776A1 · Weller · 2010 [cited by examiner]
US 20120109821A1 · Barbour · 2012 [cited by examiner]
US 20200034842A1 · Ponniah · 2020 [cited by examiner]
US 20200065809A1 · Elfeky · 2020 [cited by examiner]
US 20210073371A1 · Semichev · 2021 [cited by examiner]
US 20210103838A1 · Yuan · 2021 [cited by examiner]
US 20210312035A1 · Semichev · 2021 [cited by examiner]
US 20230325852A1 · Ma · 2023 [cited by examiner]
US 20240135383A1 · Dutt · 2024 [cited by examiner]
US 20240265405A1 · Kramme · 2024 [cited by examiner]
CN 114285942 · 2025 [cited by examiner]
WO WO2006118968A2 · 2006 [cited by examiner]
Guraieb, “Does There Have to Be a Tradeoff Between Fraud Prevention and Customer Experience,” Live Webinar, Is Your Onboarding Process Truly Future-Proof, 2021 (Year: 2021). [cited by examiner]
Tertychnyi et al., Detecting Group Behavior for Anti-Money Laundering With Incomplete Network Information, IEEE International Conference on big Data, 2022 (Year: 2022). [cited by examiner]
Thisarani et al., “Artificial Intelligence for Futuristic Banking,” IEEE International Conference on Engineering Technology and Innovation, 2021 (Year: 2021). [cited by examiner]
Cited By (1)
US 12,645,838