Merchant specific machine learning model for fraud detection
A server computer system for detecting a fraudulent electronic transaction may be configured to receive a transaction associated with a merchant. The system processes the transaction with a first machine learning model that is trained specific to the merchant, to obtain a first fraud detection, and processes the transaction with a second machine learning model that is trained based on a plurality of merchants, to obtain a second fraud detection. The system detects fraud associated with the transaction based on the first fraud detection and the second fraud detection. In response to detecting the fraud that is associated with the transaction, the system blocks the transaction.
1 . A method performed by a server computer system for detecting a fraudulent electronic request, comprising:
detecting, by the server computer system over a computer network, increased fraud activity associated with an entity,
in accordance with the detected increased fraud activity satisfying a first threshold, training, by the server computer system, a portable first machine learning model with first training data that corresponds to the increased fraud activity of the entity;
receiving, by the server computer system, a request associated with the entity;
selecting, by the server computer system, the portable first machine learning model from a plurality of machine learning models that are each trained with the first training data that is specific to a respective entity associated with the request;
processing, by the server computer system, the request with the portable first machine learning model, to obtain a first fraud detection;
processing, by the server computer system, the request with a second machine learning model that is trained based on second training data that is associated with a plurality of entities, wherein the second training data occurs over a second time span that is greater than a first time span that the first training data occurs over, to obtain a second fraud detection;
detecting, by the server computer system, fraud associated with the request based on the first fraud detection and the second fraud detection;
responsive to detecting the fraud that is associated with the request, blocking the request by the server computer system;
tracking, by the server computer system, a quantity of requests blocked by the portable first machine learning model for the entity;
responsive to determining that the quantity of requests that are blocked by the portable first machine learning model exceeds a second threshold, automatically deprecating, by the server computer system, the portable first machine learning model for the entity; and
processing, by the server computer system, a subsequent request for the entity using the second machine learning model.
2 . The method of claim 1 , wherein the fraud is detected based on the first fraud detection being positive or the second fraud detection being positive.
3 . The method of claim 1 , further comprising:
responsive to determining that the quantity of requests that are blocked by the portable first machine learning model exceeds the second threshold, disabling blocking of a future request associated with the entity.
4 . The method of claim 1 , wherein the first training data comprises a plurality of first past requests from the entity that the portable first machine learning model is applied with respect to.
5 . The method of claim 4 , wherein the second training data comprises a plurality of second past requests from the plurality of entities.
6 . The method of claim 1 , wherein a duration associated with the first training data starts when the increased fraud activity satisfies the first threshold, and ends when the increased fraud activity does not satisfy the first threshold.
7 . The method of claim 1 , wherein the first training data is more recent than the second training data.
8 . The method of claim 1 , wherein the detecting of the increased fraud activity and the training of the portable first machine learning model are performed by the server computer system without a human input.
9 . A non-transitory computer readable storage medium storing instructions, which when executed by a server computer system, cause the computer system to perform operations for detecting a fraudulent electronic request, the operations comprising:
detecting, by the server computer system over a computer network, increased fraud activity associated with an entity,
in accordance with the detected increased fraud activity satisfying a first threshold, training, by the server computer system, a portable first machine learning model with first training data that corresponds to the increased fraud activity of the entity;
receiving, by the server computer system, a request associated with the entity;
selecting, by the server computer system, the portable first machine learning model from a plurality of machine learning models that are each trained with first training data that is specific to a respective entity associated with the request;
processing, by the server computer system, the request with the portable first machine learning model, to obtain a first fraud detection;
processing, by the server computer system, the request with a second machine learning model that is trained based on second training data that is associated with a plurality of entities, wherein the second training data occurs over a second time span that is greater than a first time span that the first training data occurs over, to obtain a second fraud detection;
detecting, by the server computer system, fraud associated with the request based on the first fraud detection and the second fraud detection;
responsive to detecting the fraud that is associated with the request, blocking the request by the server computer system;
tracking, by the server computer system, a quantity of requests blocked by the portable first machine learning model for the entity;
responsive to determining that the quantity of requests that are blocked by the portable first machine learning model exceeds a second threshold, automatically deprecating, by the server computer system, the portable first machine learning model for the entity; and
processing, by the server computer system, a subsequent request for the entity using the second machine learning model.
10 . The non-transitory computer readable storage medium of claim 9 , wherein the fraud is detected based on the first fraud detection being positive or the second fraud detection being positive.
11 . The non-transitory computer readable storage medium of claim 9 , wherein the operations further comprise:
responsive to determining that the quantity of requests that are blocked by the portable first machine learning model exceeds the second threshold, disabling blocking of a future request associated with the entity.
12 . The non-transitory computer readable storage medium of claim 9 , wherein the first training data comprises a plurality of first past requests from the entity that the portable first machine learning model is applied with respect to.
13 . The non-transitory computer readable storage medium of claim 12 , wherein the second training data comprises a plurality of second past requests from the plurality of entities.
14 . The non-transitory computer readable storage medium of claim 9 , wherein a duration associated with the first training data starts when the increased fraud activity satisfies the first threshold, and ends when the increased fraud activity does not satisfy the first threshold.
15 . A server computer system for detecting a fraudulent electronic request, the server computer system comprising:
a memory; and
one or more processors coupled with the memory configured to cause the server computer system to perform operations, comprising:
detecting over a computer network, increased fraud activity associated with an entity;
in accordance with the detected increased fraud activity satisfying a first threshold, training a portable first machine learning model with first training data that corresponds to the increased fraud activity of the entity;
receiving a request associated with the entity;
selecting the portable first machine learning model from a plurality of machine learning models that are each trained with first training data that is specific to a respective entity associated with the request;
processing the request with the portable first machine learning model, to obtain a first fraud detection;
processing the request with a second machine learning model that is trained based on second training data that is associated with a plurality of entities, wherein the second training data occurs over a second time span that is greater than a first time span that the first training data occurs over, to obtain a second fraud detection;
detecting fraud associated with the request based on the first fraud detection and the second fraud detection;
responsive to detecting the fraud that is associated with the request, blocking the request;
tracking a quantity of requests blocked by the portable first machine learning model for the entity;
responsive to determining that the quantity of requests that are blocked by the portable first machine learning model exceeds a second threshold, automatically deprecating the portable first machine learning model for the entity; and
processing a subsequent request for the entity using the second machine learning model.
16 . The server computer system of claim 15 , wherein the fraud is detected based on the first fraud detection being positive or the second fraud detection being positive.
17 . The server computer system of claim 15 , wherein the operations further comprise:
responsive to determining that the quantity of requests that are blocked by the portable first machine learning model exceeds the second threshold, disabling blocking of a future request associated with the entity.
18 . The server computer system of claim 17 , wherein the first training data comprises a plurality of first past requests from the entity that the portable first machine learning model is applied with respect to.
19 . The server computer system of claim 18 , wherein the second training data comprises a plurality of second past requests from the plurality of entities.
20 . The server computer system of claim 15 , wherein a duration associated with the first training data starts when the increased fraud activity satisfies the first threshold, and ends when the increased fraud activity does not satisfy the first threshold.