IP Library › Granted Patent US 12,556,569
Granted Patent B2
US 12,556,569 · App. 18/259,335 · Granted Feb 17, 2026

Method and system for automated fraud risk detection in a monitored system

Inventor: Hakima Berdouz Qrichi Aniba (Paris, FR)
Assignee: Commissariat à l'énergie atomique et aux énergies alternatives
H04L63/1433H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,569
App. No.
18/259,335
Granted
Feb 17, 2026
Kind
B2
Abstract

The invention relates to a method and a system for the automated detection of the risk of fraud in a monitored system, based on data streams generated by said monitored system and characterizing events performed or generated by operators in said monitored system. The method includes: a pre-processing ( 30 - 38 ) of at least one set of data recorded over a period of time, so as to obtain a subset of critical events associated with an operator; the iterative application of a first parameterized estimation process ( 52,56 ) for a risk of fraud, so as to obtain a first legitimacy score and a first associated probability of occurrence; the iterative application of a second parameterized estimation process ( 54,58 ) for a risk of fraud, so as to obtain a second legitimacy score and a second associated probability of occurrence, and the comparison ( 60 ) of the results of said first and second processes, for determining ( 64 ) whether said operator is a legitimate operator or a fraudulent operator.

Claims (36)

1 . A method for the automated detection of the risk of fraud in a monitored system, from data streams generated by said monitored system and characterizing events, either performed or generated by operators in said monitored system, the method being implemented by a computation processor and comprising:

A) pre-processing of at least one set of data recorded over a period of time, so as to obtain a subset of critical events associated with an operator,

B) iterative application of a first parameterized process of estimation of the risk of fraud, the parameters of said first parameterized process being obtained by learning on a first database representative of events performed or generated by legitimate operators, on at least part of said subset of critical events, for obtaining a first legitimacy score and a first associated probability of occurrence;

C) iterative application of a second parameterized process of estimation of the risk of fraud, the parameters of said second process being obtained by learning on a second database representative of events carried out or generated by fraudulent operators, on at least part of said subset of critical events, for obtaining a second legitimacy score and a second associated probability of occurrence, and

(D) comparison of the results of said first process and said second process, for determining whether said operator is a legitimate operator or a fraudulent operator,

the method further comprising successive iterations of the application of said first parameterized process and of said second parameterized process, the first parameterized process being applied to distinct parts of said subset of critical events until validation of a first convergence criterion, the second parameterized process being applied to distinct parts of said subset of critical events until validation of a second convergence criterion.

2 . The method according to claim 1 , wherein said pre-processing comprises a determination of events from said recorded data, a computation of a signature of each event of at least a portion of said events, said signature being representative of the risk of malfunction of the monitored system following said event.

3 . The method according to claim 2 , wherein said pre-processing further comprises a determination of a subset of critical events the signature of which is greater than a predetermined risk threshold.

4 . The method according to claim 2 , wherein the computation of a signature of each event is performed according to past events, by a logistical regression method.

5 . The method according to claim 1 , wherein, following the implementation of steps A) to C) on a set of data recorded over said period of time, called first period of time, step D) implements a third convergence criterion, and in case of lack of convergence according to the third convergence criterion, the method comprises an iteration of steps A) to D) on another set of data recorded over a second period of time, situated in the past with respect to said first period of time.

6 . The method according to claim 1 , wherein the parameters of said first parameterized process are obtained by a supervised learning ( 46 ).

7 . The method according to claim 1 , wherein the parameters of said second parameterized process are obtained by an unsupervised learning ( 48 ).

8 . The method according to claim 1 , further comprising a preliminary step of classification of said events into a plurality of classes, and the application of steps A) to D) for at least one class of events.

9 . A computer program comprising software instructions which, when executed by a programmable electronic system, implement a method of automated detection of the risk of fraud in a monitored system according to claim 1 .

10 . The method according to claim 1 , further comprising a preliminary step of classification of said events into a plurality of classes, and the application of steps A) to D) for at least one class of events.

11 . A system for the automated detection of the risk of fraud in a monitored system, based on data streams generated by said monitored system and characterizing events, either performed or generated by operators in said monitored system, comprising at least one computation processor configured for implementing:

A) a module for pre-processing at least one set of data recorded over a period of time, so as to obtain a subset of critical events associated with an operator,

B) a module for iterative application of a first parameterized process of estimating the risk of fraud, the parameters of said first parameterized process being obtained by learning on a first database representative of events performed or generated by legitimate operators, on at least part of said subset of critical events, for obtaining a first legitimacy score and a first associated probability of occurrence;

C) a module for iterative application of a second parameterized process for estimating the risk of fraud, the parameters of said second process being obtained by learning on a second database representative of events carried out or generated by fraudulent operators, on at least part of said subset of critical events, for obtaining a second legitimacy score and a second associated probability of occurrence,

D) a module for comparing the results of said first process and second process, for determining whether said operator is a legitimate operator or a fraudulent operator,

the system being configured to implement successive iterations of the module for the application of said first parameterized process and of the module for application of said second parameterized process, the first parameterized process being applied to distinct parts of said subset of critical events until validation of a first convergence criterion, the second parameterized process being applied to distinct parts of said subset of critical events until validation of a second convergence criterion.

12 . A method for the automated detection of the risk of fraud in a monitored system, from data streams generated by said monitored system and characterizing events, either performed or generated by operators in said monitored system, the method being implemented by a computation processor and comprising:

A) pre-processing of at least one set of data recorded over a period of time, so as to obtain a subset of critical events associated with an operator, said pre-processing comprising a determination of events from said recorded data, a computation of a signature of each event of at least a portion of said events, said signature being representative of the risk of malfunction of the monitored system following said event, the computation of the signature of each event being performed according to past events, by a logistical regression method,

B) iterative application of a first parameterized process of estimation of the risk of fraud, the parameters of said first parameterized process being obtained by learning on a first database representative of events performed or generated by legitimate operators, on at least part of said subset of critical events, for obtaining a first legitimacy score and a first associated probability of occurrence;

C) iterative application of a second parameterized process of estimation of the risk of fraud, the parameters of said second process being obtained by learning on a second database representative of events carried out or generated by fraudulent operators, on at least part of said subset of critical events, for obtaining a second legitimacy score and a second associated probability of occurrence,

(D) comparison of the results of said first process and said second process, for determining whether said operator is a legitimate operator or a fraudulent operator.

13 . The method according to claim 12 , wherein said pre-processing further comprises a determination of a subset of critical events the signature of which is greater than a predetermined risk threshold.

14 . The method according to claim 12 , comprising successive iterations of the application of said first and second processes, the first process being applied to distinct parts of said subset of critical events until validation of a first convergence criterion, the second process being applied to distinct parts of said subset of critical events until validation of a second convergence criterion.

15 . The method according to claim 12 , wherein, following the implementation of steps A) to C) on a set of data recorded over said period of time, called first period of time, step D) implements a third convergence criterion, and in case of lack of convergence according to the third convergence criterion, the method comprises an iteration of steps A) to D) on another set of data recorded over a second period of time, situated in the past with respect to said first period of time.

16 . The method according to claim 12 , wherein the parameters of said first parameterized process are obtained by a supervised learning.

17 . The method according to claim 12 , wherein the parameters of said second parameterized process are obtained by an unsupervised learning.

18 . A system for the automated detection of the risk of fraud in a monitored system, from data streams generated by said monitored system and characterizing events, either performed or generated by operators in said monitored system, the system comprising a at least one computation processor configured for implementing:

A) a module for pre-processing of at least one set of data recorded over a period of time, so as to obtain a subset of critical events associated with an operator, said pre-processing comprising a determination of events from said recorded data, a computation of a signature of each event of at least a portion of said events, said signature being representative of the risk of malfunction of the monitored system following said event, the computation of the signature of each event being performed according to past events, by a logistical regression method,

B) a module for iterative application of a first parameterized process of estimation of the risk of fraud, the parameters of said first parameterized process being obtained by learning on a first database representative of events performed or generated by legitimate operators, on at least part of said subset of critical events, for obtaining a first legitimacy score and a first associated probability of occurrence;

C) a module for iterative application of a second parameterized process of estimation of the risk of fraud, the parameters of said second process being obtained by learning on a second database representative of events carried out or generated by fraudulent operators, on at least part of said subset of critical events, for obtaining a second legitimacy score and a second associated probability of occurrence,

(D) a module for comparing the results of said first process and of said second process, for determining whether said operator is a legitimate operator or a fraudulent operator.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2023
From: BERDOUZ QRICHI ANIBA, HAKIMA
To: COMMISSARIAT À L'ÉNERGIE ATOMIQUE ET AUX ÉNERGIES ALTERNATIVES
Reel/Frame 064059/0293 →
Priority Claims (1)
FR 20 14184 · Dec 28, 2020 · national
Continuity (1)
Related Publication 20240056471A1 · Feb 15, 2024
References Cited (14)
US 10009358B1 · Xie et al. · 2018 [cited by applicant]
US 20160196615A1 · Yen · 2016 [cited by examiner]
US 20190311367A1 · Reddy · 2019 [cited by examiner]
US 20240152926A1 · Musunuru · 2024 [cited by examiner]
US 20250029101A1 · Williams · 2025 [cited by examiner]
US 20250148469A1 · Wirthlin · 2025 [cited by examiner]
CN 111047428A · 2020 [cited by examiner]
CN 111552680A · 2020 [cited by applicant]
EP 3553713A1 · 2019 [cited by applicant]
WO WO2012075323A1 · 2012 [cited by examiner]
WO WO2016011363A1 · 2016 [cited by examiner]
WO WO2023128865A2 · 2023 [cited by examiner]
International Search Report issued Feb. 16, 2022 in PCT/EP2021/087710 filed on Dec. 28, 2021 2 pages. [cited by applicant]
French Search Report issued Sep. 6, 2021 in French Application 20 14184 filed on Dec. 28, 2020 3 pages (with English Translation of Categories of Cited Documents). [cited by applicant]