IP Library Granted Patent US 11,087,334
Granted Patent B1
US 11,087,334 · App. 15/478,511 · Granted Aug 10, 2021

Method and system for identifying potential fraud activity in a tax return preparation system, at least partially based on data entry characteristics of tax return content

Inventors: Kyle McEachern (San Diego, CA); Brent Rambo (San Diego, CA)
Assignee: Intuit Inc.
G06Q30/0185G06N20/00G06Q40/123H04L51/046H04L63/0272H04L63/0876H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,087,334
App. No.
15/478,511
Granted
Aug 10, 2021
Kind
B1
Abstract

Stolen identity refund fraud is one of a number of types of Internet-centric crime (i.e., cybercrime) that includes the unauthorized use of a person's or business' identity information to file a tax return in order to illegally obtain a tax refund from, for example, a state or federal revenue service. Because fraudsters use legitimate identity information to create user accounts in tax return preparation systems, it can be difficult to detect stolen identity refund fraud activity. Methods and systems of the present disclosure identify and address potential fraud activity. The methods and systems analyze data entry characteristics of tax return content that is provided to a tax return preparation system to identify potential fraud activity and perform one or more risk reduction actions in response to identifying the potential fraud activity.

Claims (36)

1. A system for using machine-learning to identify and delay or prevent submission of fraudulent content, the system configured to perform operations comprising:

generating training set data indicating characteristics of fraudulent content previously submitted to the system using stolen identity information;

using a machine-learning technique to train an analytics model to identify, based on the training set data, correlations between the characteristics of fraudulent content previously submitted to the system and characteristics of new content received by the system;

receiving new content from a system user, wherein the new content includes a set of data entry characteristics indicating ones of a plurality of user experience pages accessed by the system user;

using the analytics model trained by the machine-learning technique to:

detect one or more indications that the new content is being submitted using stolen identity information based on the set of data entry characteristics indicating that the system user visited the ones of the plurality of user experience pages in a specific order;

generate a risk score that quantifies a likelihood that the new content is being submitted using stolen identity information based on the detected indications; and

determine that the new content is fraudulent based on the risk score exceeding a risk score threshold; and

initiating at least one action to delay or prevent a submission of the new content.

2. The system of claim 1 , wherein the operations further include:

determining whether the new content is entered manually or by using a script.

3. The system of claim 1 , wherein the operations further include:

determining a number of risk categories related to the one or more indications.

4. The system of claim 1 , wherein training the analytics model is based on an artificial neural network.

5. A method for using machine-learning to identify and delay or prevent submission of fraudulent content, the method performed by a system and comprising:

generating training set data indicating characteristics of fraudulent content previously submitted to the system using stolen identity information;

using a machine-learning technique to train an analytics model to identify, based on the training set data, correlations between the characteristics of fraudulent content previously submitted to the system and characteristics of new content received by the system;

receiving new content from a system user, wherein the new content includes a set of data entry characteristics indicating ones of a plurality of user experience pages accessed by the system user;

using the analytics model trained by the machine-learning technique to:

detect one or more indications that the new content is being submitted using stolen identity information based on the set of data entry characteristics indicating that the system user visited the ones of the plurality of user experience pages in a specific order;

generate a risk score that quantifies a likelihood that the new content is being submitted using stolen identity information based on the detected indications; and

determine that the new content is fraudulent based on the risk score exceeding a risk score threshold; and

initiating at least one action to delay or prevent a submission of the new content.

6. The method of claim 5 , further comprising:

determining whether the new content is entered manually or by using a script.

7. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors of a system for using machine-learning to identify and delay or prevent submission of fraudulent content causes the system to perform operations comprising:

generating training set data indicating characteristics of fraudulent content previously submitted to the system using stolen identity information;

using a machine-learning technique to train an analytics model to identify, based on the training set data, correlations between the characteristics of fraudulent content previously submitted to the system and characteristics of new content received by the system;

receiving new content from a system user, wherein the new content includes a set of data entry characteristics indicating ones of a plurality of user experience pages accessed by the system user;

using the analytics model trained by the machine-learning technique to:

detect one or more indications that the new content is being submitted using stolen identity information based on the set of data entry characteristics indicating that the system user visited the ones of the plurality of user experience pages in a specific order;

generate a risk score that quantifies a likelihood that the new content is being submitted using stolen identity information based on the detected indications; and

determine that the new content is fraudulent based on the risk score exceeding a risk score threshold; and

initiating at least one action to delay or prevent a submission of the new content.

8. The computer-readable medium of claim 7 , wherein execution of the instructions causes the system to perform operations further including:

determining whether the new content is entered manually or by using a script.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2017
From: MCEACHERN, KYLE; RAMBO, BRENT
To: INTUIT INC.
Reel/Frame 041844/0326 →
Cited By (4)
US 12,299,694 US 12,309,152 US 12,430,646 US 12,455,978