IP Library › Granted Patent US 12,505,446
Granted Patent B2
US 12,505,446 · App. 17/831,199 · Granted Dec 23, 2025

Triaging alerts using machine learning

Inventors: Ahmad Naser Eddin (Oporto, PT); Jacopo Bono (Esposende, PT); João Tiago Barriga Negra Ascensão (Lisbon, PT); Pedro Gustavo Santos Rodrigues Bizarro (Lisbon, PT)
Assignee: Feedzai—Consultadoria e Inovação Tecnológica, S.A.
G06Q20/4016G06Q20/382H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,446
App. No.
17/831,199
Filed
Jun 2, 2022
Granted
Dec 23, 2025
Kind
B2
Art Unit
3698
USPC
705/64
Abstract

In various embodiment, a process for triaging alerts using machine learning includes receiving data associated with transactions and using computer processor(s) to analyze the received data using rule(s) to automatically identify potentially suspicious activities. The process includes scoring each of the identified potentially suspicious activities using a machine learning model and based at least in part on analysis results of the rule(s) associated with the identified potentially suspicious activities, and triaging the identified potentially suspicious activities including by determining an action to take with respect to at least a portion of the identified potentially suspicious activities based at least in part on the scoring. In various embodiments, a process for training a machine learning model to triage alerts includes configuring the machine learning model, and receiving training data. The process includes using computer processor(s) and the received training data to train the machine learning model to score potentially suspicious activities.

Claims (74)

1 . A method, comprising:

receiving data associated with transactions;

using one or more computer processors to analyze the received data using one or more rules to automatically identify potentially suspicious activities;

configuring a machine learning model;

receiving training data;

enriching the training data including by:

obtaining a graph snapshot of a prior time period;

updating the graph snapshot including by removing edges of a graph data representation of the transactions that no longer fall within at least one sliding window and adding at least one new edge corresponding to a current time period;

determining a graph feature for every node with an event in a target day for at least a portion of the received data; and

determining a node property feature including by:

performing a random walk that ends in response to at least one of:

reaching a known illicit node or an absence of available connections; and

calculating a metric associated with a comparison of successful random walks with respect to a total number of random walks, wherein a successful random walk ends in reaching the known illicit node;

using the one or more computer processors and the enriched training data to train the machine learning model to evaluate potentially suspicious activities;

scoring each of the identified potentially suspicious activities based at least in part on an output of the trained machine learning model and analysis results of the one or more rules associated with the identified potentially suspicious activities; and

triaging the identified potentially suspicious activities including by determining an action to take with respect to at least a portion of the identified potentially suspicious activities based at least in part on the scoring of each of the identified potentially suspicious activities.

2 . The method of claim 1 , further comprising extracting a first set of features and a second set of features associated with the received data, wherein:

the first set of features is used to analyze the received data using the one or more rules to automatically identify potentially suspicious activities, and

the second set of features is used to score each of the identified potentially suspicious activities using the machine learning model.

3 . The method of claim 1 , wherein triaging the identified potentially suspicious activities includes changing a priority of at least one of the identified potentially suspicious activities.

4 . The method of claim 1 , further comprising:

determining a scored list of the identified potentially suspicious activities; and

providing the scored list of the identified potentially suspicious activities.

5 . The method of claim 4 , further comprising:

receiving feedback associated with the scored list of the identified potentially suspicious activities; and

updating the machine learning model based on the received feedback.

6 . The method of claim 1 , further comprising:

determining an explanation for a decision associated with the triaging; and

providing the explanation.

7 . The method of claim 6 , wherein providing the explanation includes initially providing a second-level explanation that includes a grouping of features that belong to a same concept or semantic group.

8 . The method of claim 7 , wherein:

providing the explanation further includes providing a first-level explanation after providing the second-level explanation; and

the first-level explanation includes features and associated contributions used by the machine learning model to determine the decision associated with the automatic triaging.

9 . A system, comprising:

a processor configured to:

receive data associated with transactions;

use one or more computer processors to analyze the received data using one or more rules to automatically identify potentially suspicious activities;

configure a machine learning model;

receive training data;

enrich the training data including by:

obtaining a graph snapshot of a prior time period;

updating the graph snapshot including by removing edges of a graph data representation of the transactions that no longer fall within at least one sliding window and adding at least one new edge corresponding to a current time period;

determine a graph feature for every node with an event in a target day for at least a portion of the received data; and

determine a node property feature including by:

performing a random walk that ends in response to at least one of:

reaching a known illicit node or an absence of available connections; and

calculating a metric associated with a comparison of successful random walks with respect to a total number of random walks, wherein a successful random walk ends in reaching the known illicit node;

train, using the enriched training data, the machine learning model to evaluate potentially suspicious activities;

score each of the identified potentially suspicious activities based at least in part on an output of the trained machine learning model and analysis results of the one or more rules associated with the identified potentially suspicious activities; and

triage the identified potentially suspicious activities including by determining an action to take with respect to at least a portion of the identified potentially suspicious activities based at least in part on the scoring of each of the identified potentially suspicious activities; and

a memory coupled to the processor and configured to provide the processor with instructions.

10 . The system of claim 9 , wherein the processor is further configured to extract a first set of features and a second set of features associated with the received data, wherein:

the first set of features is used to analyze the received data using the one or more rules to automatically identify potentially suspicious activities, and

the second set of features is used to score each of the identified potentially suspicious activities using the machine learning model.

11 . A non-transitory computer readable medium storing computer instructions, when executed by a processor, causes the processor to:

receive data associated with transactions;

use one or more computer processors to analyze the received data using one or more rules to automatically identify potentially suspicious activities;

configure a machine learning model;

receive training data;

enrich the training data including by:

obtaining a graph snapshot of a prior time period;

updating the graph snapshot including by removing edges of a graph data representation that no longer fall within at least one sliding window and adding at least one new edge corresponding to a current time period;

determine a graph feature for every node with an event in a target day for at least a portion of the received data; and

determine a node property feature including by:

performing a random walk that ends in response to at least one of: reaching a known illicit node or an absence of available connections; and

calculating a metric associated with a comparison of successful random walks with respect to a total number of random walks, wherein a successful random walk ends in reaching the known illicit node;

train, using the enriched training data, the machine learning model to evaluate potentially suspicious activities;

score each of the identified potentially suspicious activities based at least in part on an output of the trained machine learning model and analysis results of the one or more rules associated with the identified potentially suspicious activities; and

triage the identified potentially suspicious activities including by determining an action to take with respect to at least a portion of the identified potentially suspicious activities based at least in part on the scoring of each of the identified potentially suspicious activities.

12 . The method of claim 1 , further comprising:

determining that at least one identified potentially suspicious activity is different from a previously-identified potentially suspicious activity;

form a set of potentially suspicious activities;

re-configure the machine learning model in response to a determination that a threshold amount of labeled data has been gathered for the formed set of potentially suspicious activities; and

in response to re-configuring the machine learning model, retraining the machine learning model to more accurately analyze potentially suspicious activities compared with a machine learning model that has not been re-trained.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2022
From: EDDIN, AHMAD NASER; BONO, JACOPO; ASCENSÃO, JOÃO TIAGO BARRIGA NEGRA; BIZARRO, PEDRO GUSTAVO SANTOS RODRIGUES
To: FEEDZAI - CONSULTADORIA E INOVAÇÃO TECNOLÓGICA, S.A.
Reel/Frame 060769/0327 →
Continuity (2)
Provisional Application 63278196 · Nov 11, 2021
Related Publication 20230147934A1 · May 11, 2023
References Cited (106)
US 10515366B1 · Gorelik · 2019 [cited by applicant]
US 10740399B1 · Eksombatchai · 2020 [cited by applicant]
US 10778706B1 · Lee · 2020 [cited by applicant]
US 11263703B2 · Juban · 2022 [cited by applicant]
US 11328301B2 · Butvinik · 2022 [cited by applicant]
US 11593622B1 · Gandhi · 2023 [cited by applicant]
US 11640609B1 · Shoumaker · 2023 [cited by applicant]
US 11704673B1 · Drapeau · 2023 [cited by applicant]
US 20120059858A1 · Jackson, Jr. · 2012 [cited by applicant]
US 20130018796A1 · Kolhatkar · 2013 [cited by examiner]
US 20140143110A1 · Qin · 2014 [cited by applicant]
US 20150134512A1 · Mueller · 2015 [cited by applicant]
US 20150161622A1 · Hoffmann · 2015 [cited by applicant]
US 20150293994A1 · Kelly · 2015 [cited by applicant]
US 20150294028A1 · Bose · 2015 [cited by applicant]
US 20160171732A1 · Glover · 2016 [cited by applicant]
US 20160203488A1 · Guerrero · 2016 [cited by examiner]
US 20170053294A1 · Yang · 2017 [cited by applicant]
US 20170140382A1 · Chari · 2017 [cited by applicant]
US 20170169174A1 · Yeung · 2017 [cited by applicant]
US 20170178136A1 · Groarke · 2017 [cited by applicant]
US 20170178139A1 · Gieseke · 2017 [cited by applicant]
US 20180196694A1 · Banerjee · 2018 [cited by applicant]
US 20180197128A1 · Carstens · 2018 [cited by applicant]
US 20180330258A1 · Harris · 2018 [cited by applicant]
US 20190087821A1 · Jia · 2019 [cited by examiner]
US 20190132344A1 · Lem · 2019 [cited by applicant]
US 20190164173A1 · Liu · 2019 [cited by applicant]
US 20190266528A1 · Cheng · 2019 [cited by applicant]
US 20190286655A1 · Leskovec · 2019 [cited by applicant]
US 20190377819A1 · Filliben · 2019 [cited by applicant]
US 20190378050A1 · Edkin · 2019 [cited by applicant]
US 20200036821A1 · Liu · 2020 [cited by applicant]
US 20200081445A1 · Stetson · 2020 [cited by applicant]
US 20200090003A1 · Marques · 2020 [cited by applicant]
US 20200110761A1 · Cooper · 2020 [cited by applicant]
US 20200142957A1 · Patra · 2020 [cited by applicant]
US 20200160121A1 · Parasrampuria · 2020 [cited by applicant]
US 20200210833A1 · Xu · 2020 [cited by applicant]
US 20200226512A1 · Epstein · 2020 [cited by applicant]
US 20200320534A1 · Yerradoddi · 2020 [cited by applicant]
US 20200349586A1 · Deng · 2020 [cited by applicant]
US 20200364366A1 · Kundu · 2020 [cited by applicant]
US 20200380376A1 · Jain · 2020 [cited by applicant]
US 20210012346A1 · Walters · 2021 [cited by applicant]
US 20210014124A1 · Rossi · 2021 [cited by applicant]
US 20210019762A1 · Bosnjakovic · 2021 [cited by applicant]
US 20210027145A1 · Li · 2021 [cited by applicant]
US 20210049171A1 · Ziauddin · 2021 [cited by applicant]
US 20210049225A1 · Chang · 2021 [cited by applicant]
US 20210065245A1 · Resheff · 2021 [cited by applicant]
US 20210067549A1 · Chen · 2021 [cited by applicant]
US 20210158161A1 · Louizos · 2021 [cited by applicant]
US 20210176262A1 · Harris · 2021 [cited by applicant]
US 20210192376A1 · Sarferaz · 2021 [cited by examiner]
US 20210209604A1 · Wang · 2021 [cited by applicant]
US 20210233080A1 · Shekhar · 2021 [cited by applicant]
US 20210303783A1 · Misra · 2021 [cited by applicant]
US 20210311952A1 · Jain · 2021 [cited by applicant]
US 20210334811A1 · Gu · 2021 [cited by applicant]
US 20210334822A1 · Pati · 2021 [cited by applicant]
US 20210334896A1 · Sarshogh · 2021 [cited by applicant]
US 20210374754A1 · Pandian · 2021 [cited by applicant]
US 20220020026A1 · Wadhwa · 2022 [cited by applicant]
US 20220101327A1 · Arora · 2022 [cited by applicant]
US 20220121891A1 · Au · 2022 [cited by applicant]
US 20220129871A1 · Rodgers · 2022 [cited by applicant]
US 20220138502A1 · Li · 2022 [cited by applicant]
US 20220172211A1 · Muthuswamy · 2022 [cited by applicant]
US 20220188837A1 · Assefa · 2022 [cited by applicant]
US 20220247662A1 · Chen · 2022 [cited by applicant]
US 20220300903A1 · Huang · 2022 [cited by applicant]
US 20220405860A1 · Juban · 2022 [cited by examiner]
US 20230013392A1 · Xu · 2023 [cited by applicant]
US 20230107703A1 · Zhang · 2023 [cited by examiner]
Camino et al., Finding Suspicious Activities in Financial Transactions and Distributed Ledgers, IEEE International Conference on Data Mining Workshop, pp. 787-796, 2011. [cited by applicant]
Chen et al., Machine Learning Techniques for Anti-money Laundering (AML) Solutions in Suspicious Transaction Detection: A Review, Springer, Knowl Inf Syst, 2018. [cited by applicant]
Hu et al., “Characterizing and Detecting Money Laundering Activities on the Bitcoin Network”, Dec. 27, 2019. [cited by applicant]
Jullum et al., Detecting Money Laundering Transactions with Machine Learning, Journal of Money Laundering Control, vol. 23, No. 1, pp. 173-186, 2020. [cited by applicant]
Ke et al., LightGBM: A Highly Efficient Gradient Boosting Decision Tree, 31st Conference on Neural Information Processing Systems (NIPS 2017), Long Beach, CA, USA. [cited by applicant]
Keyan et al., An Improved Support-Vector Network Model for Anti-Money Laundering, International Conference on Management of e-Commerce and e-Government, pp. 193-196, 2011. [cited by applicant]
Lannoo et al., Anti-Money Laundering in the EU: Time to Get Serious, CEPS-ECRI Task Force Report, 2021. [cited by applicant]
Larik et al., Clustering Based Anomalous Transaction Reporting, Procedia Computer Science 3, Science Direct, pp. 606-610, 2011. [cited by applicant]
Li et al., Intelligent Anti-Money Laundering Solution Based Upon Novel Community Detection in Massive Transaction Networks on Spark, 5th International Conference on Advanced Cloud and Big Data, pp. 176-181, 2017. [cited by applicant]
Liu et al., A Scan Statistics Based Suspicious Transaction Detection Model for Anti-Money Laundering (AML) in Financial Institutions, International Conference on Multimedia Communications, pp. 210-213, 2010. [cited by applicant]
Lorenz et al., Machine Learning Methods to Detect Money Laundering in the Bitcoin Blockchain in the Presence of Label Security, ICAIF, Oct. 15-16, 2020. [cited by applicant]
Oliveira et al., GuiltyWalker: Distance to Illicit Nodes in the Bitcoin Network, Association for Machine Learning, KDD, pp. 1-5, 2021. [cited by applicant]
Savage et al., Detection of Money Laundering Groups Using Supervised Learning in Networks, pp. 1-11, Elsevier, 2016. [cited by applicant]
Shokry et al., Counter Terrorism Finance by Detecting Money Laundering Hidden Networks Using Unsupervised Machine Learning Algorithm, International Conferences ICT, Society and Human Beings, pp. 89-97, 2020. [cited by applicant]
Tiwari et al., A Review of Money Laundering Literature: The State of Research in Key Areas, Pacific Accounting Review, vol. 32, No. 2, pp. 271-303, 2020. [cited by applicant]
Weber et al., “Anti-Money Laundering in Bitcoin: Experimenting with Graph Convolutional Networks for Financial Forensics”, Jul. 2019. [cited by applicant]
Weber et al., Scalable Graph Learning for Anti-Money Laundering: A First Look, NeurIPS Workshop on Challenges and Workshops for AI in Financial Services, pp. 1-7, 2018. [cited by applicant]
Xingrong Luo, Suspicious Transaction Detection for Anti-Money Laundering, International Journal of Security and its Applications, vol. 8, No. 2, pp. 157-166, 2014. [cited by applicant]
Yang et al., DBSCAN Clustering Algorithm Applied to Identify Suspicious Financial Transactions, International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery, pp. 60-65, 2014. [cited by applicant]
Zhang et al., Machine Learning and Sampling Scheme: An Empirical Study of Money Laundering Detection, Computational Economics, pp. 1043-1063, 2019. [cited by applicant]
Alarab et al., “Comparative Analysis Using Supervised Learning Methods for Anti-Money Laundering in Bitcoin”, 2020 Association for Computing Machinery, Jun. 19, 2020. [cited by applicant]
Bhagat et al., “Node Classification in Social Networks”, Jan. 17, 2011. [cited by applicant]
Claudio Bellei, “The Elliptic Data Set: opening up machine learning on the blockchain”, Aug. 6, 2019. [cited by applicant]
Grover et al., “node2vec: Scalable Feature Learning for Networks”, Jul. 3, 2016. [cited by applicant]
Hagberg et al., “Exploring Network Structure, Dynamics, and Function Using Networkx”, Proceedings/Talk SCIPY 2008, 2008. [cited by applicant]
Hassan et al., “Random-Walk Term Weighting for Improved Text Classification”, 2006. [cited by applicant]
Lorenz et al., “Machine Learning methods to detect money laundering in the Bitcoin blockchain in the presence of label scarcity”, Oct. 15, 2020. [cited by applicant]
Pedregosa et al., “Scikit-learn: Machine Learning in Python”, Journal of Machine Learning Research, 2011. [cited by applicant]
Perozzi et al., “DeepWalk: Online Learning of Social Representations”, 2014. [cited by applicant]
Satoshi Nakamoto, “Bitcoin: A Peer-to-Peer Electronic Cash System”, 2008. [cited by applicant]
Petit et al., Random walks on dense graphs and graphons, arXiv preprint arXiv: 1909.11776v2, May 19, 2020, 22 pages. [cited by applicant]