IP Library Granted Patent US 12,531,878
Granted Patent B2
US 12,531,878 · App. 18/522,000 · Granted Jan 20, 2026

Detection and mitigation of automated account generation using artificial intelligence

Inventors: Suhas Hoskote Muralidhar (Bothell, WA); Prasanna Sridhar (South San Francisco, CA); Charlotte Gils (Otterburn Park, CA)
Assignee: Stripe, Inc.
H04L63/1408G06Q40/02H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,531,878
App. No.
18/522,000
Granted
Jan 20, 2026
Kind
B2
Abstract

Disclosed herein are systems and methods for detecting automated account generation requests. An example method includes receiving an application programming interface (API) request to generate a new user account. The method then includes executing a machine learning model to predict a likelihood of the API request having been generated automatically using one or more programming protocols. The machine learning model may be trained using historic requests known to have been generated using a machine or a programming/algorithm. When the machine learning model determines that the API request is likely to have been machine-made, the method includes executing an additional security protocol associated with the new user account.

Claims (41)

1 . A method comprising:

receiving, by a server via an application programming interface (API), an API request to generate a new user account, the API request comprising at least one user identifier and at least one user attribute;

executing, by the server using the at least one user identifier and the at least one user attribute, a machine learning model to predict a likelihood of the API request having been generated automatically using one or more programming protocols,

wherein the machine learning model has been trained using a training dataset comprising a set of training user accounts known to have been generated via the one or more programming protocols and their corresponding attributes, and

wherein the machine learning model executes a clustering protocol and calculates a distance between the API request and a cluster comprising at least a subset of the set of training user accounts,

wherein the distance is correlated to the likelihood of the API request having been generated automatically; and

in response to the likelihood of the API request satisfying a threshold, executing, by the server, an additional security protocol associated with the new user account, wherein the threshold indicates a sensitivity level associated with new user accounts being generated by human users.

2 . The method of claim 1 , wherein the additional security protocol is a two-factor authentication.

3 . The method of claim 1 , wherein the additional security protocol is presenting an authentication protocol to determine whether the new user account was created by a human user.

4 . The method of claim 1 , wherein the at least one user attribute is a time difference between a first timestamp for receipt of the API request and a second timestamp for receipt of a second API request.

5 . The method of claim 1 , wherein the server executes the machine learning model at a predetermined time subsequent to receiving the API request.

6 . The method of claim 1 , wherein the at least one user attribute is at least one of a phone number, a physical address, or an IP address associated with the API request.

7 . The method of claim 1 , further comprising:

denying, by the server, generation of the new user account as a non-human created account.

8 . A non-transitory machine-readable storage medium having computer-executable instructions stored thereon that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receive, via an application programming interface (API), an API request to generate a new user account, the API request comprising at least one user identifier and at least one user attribute;

execute, using the at least one user identifier and the at least one user attribute, a machine learning model to predict a likelihood of the API request having been generated automatically using one or more programming protocols,

wherein the machine learning model has been trained using a training dataset comprising a set of training user accounts known to have been generated via the one or more programming protocols and their corresponding attributes, and

wherein the machine learning model executes a clustering protocol and calculates a distance between the API request and a cluster comprising at least a subset of the set of training user accounts,

wherein the distance is correlated to the likelihood of the API request having been generated automatically; and

in response to the likelihood of the API request satisfying a threshold, executing an additional security protocol associated with the new user account, wherein the threshold indicates a sensitivity level associated with new user accounts being generated by human users.

9 . The non-transitory machine-readable storage medium of claim 8 , wherein the additional security protocol is a two-factor authentication.

10 . The non-transitory machine-readable storage medium of claim 8 , wherein the additional security protocol is presenting an authentication protocol to determine whether the new user account was created by a human user.

11 . The non-transitory machine-readable storage medium of claim 8 , wherein the at least one user attribute is a time difference between a first timestamp for receipt of the API request and a second timestamp for receipt of a second API request.

12 . The non-transitory machine-readable storage medium of claim 8 , wherein the instructions are further configured to cause the one or more processors to execute the machine learning model at a predetermined time subsequent to receiving the API request.

13 . The non-transitory machine-readable storage medium of claim 8 , wherein the at least one user attribute is at least one of a phone number, a physical address, or an IP address associated with the API request.

14 . The non-transitory machine-readable storage medium of claim 8 , wherein the instructions are further configured to cause the one or more processors to:

deny generation of the new user account as a non-human created account.

15 . A system comprising a processor configured to:

receive, via an application programming interface (API), an API request to generate a new user account, the API request comprising at least one user identifier and at least one user attribute;

execute, using the at least one user identifier and the at least one user attribute, a machine learning model to predict a likelihood of the API request having been generated automatically using one or more programming protocols,

wherein the machine learning model has been trained using a training dataset comprising a set of training user accounts known to have been generated via the one or more programming protocols and their corresponding attributes, and

wherein the machine learning model executes a clustering protocol and calculates a distance between the API request and a cluster comprising at least a subset of the set of training user accounts,

wherein the distance is correlated to the likelihood of the API request having been generated automatically; and

in response to the likelihood of the API request satisfying a threshold, executing an additional security protocol associated with the new user account, wherein the threshold indicates a sensitivity level associated with new user accounts being generated by human users.

16 . The system claim 15 , wherein the additional security protocol is a two-factor authentication.

17 . The system of claim 15 , wherein the additional security protocol is presenting an authentication protocol to determine whether the new user account was created by a human user.

18 . The system of claim 15 , wherein the at least one user attribute is a time difference between a first timestamp for receipt of the API request a second timestamp for receipt of a second API request.

19 . The system of claim 15 , wherein the processor is further configured to:

cause the one or more processors to execute the machine learning model at a predetermined time subsequent to receiving the API request.

20 . The system of claim 15 , wherein the at least one user attribute is at least one of a phone number, a physical address, or an IP address associated with the API request.

Assignments (3)
CHANGE OF NAME Recorded Jan 7, 2026
From: STRIPE, INC.
To: STRIPE, LLC
Reel/Frame 074264/0807 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2024
From: ACLARIS WATER INNOVATIONS GMBH, LINDAU, ZWEIGNIEDERLASSUNG REBSTEIN
To: ACLARIS GMBH, LINDAU, ZWEIGNIEDERLASSUNG REBSTEIN
Reel/Frame 068396/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2023
From: MURALIDHAR, SUHAS HOSKOTE; SRIDHAR, PRASANNA; GILS, CHARLOTTE
To: STRIPE, INC.
Reel/Frame 065689/0989 →
Continuity (1)
Related Publication 20250175471A1 · May 29, 2025
References Cited (7)
US 11463475B1 · Colon · 2022 [cited by examiner]
US 20180046475A1 · Wei · 2018 [cited by examiner]
US 20210233162A1 · Hockey · 2021 [cited by examiner]
US 20220345457A1 · Jeffords · 2022 [cited by examiner]
US 20230057849A1 · Scott · 2023 [cited by examiner]
US 20230199025A1 · Xu · 2023 [cited by examiner]
US 20230316280A1 · Sardari · 2023 [cited by examiner]