System and method for a workflow orchestration platform for fraud detection
Embodiments of a decision analytics system with a workflow orchestration system is described herein. The decision analytics system can receive historical transaction data that can be used to train a machine learning algorithm of the workflow orchestration system. Based on one or more attributes associated with the historical transaction data, the machine learning algorithm can generate clusters of the historical transaction data and identify a backing application (for example, identity or fraud risk services) for the clusters for identifying fraudulent or potentially fraudulent transactions.
1 . A system for generating and executing an automated fraud detection workflow, the system comprising:
a processor;
a memory; and
computer code stored in the memory, wherein the computer code, when retrieved from the memory and executed by the processor, causes the processor to:
electronically access transaction data associated with a plurality of consumers and a time range;
electronically access a plurality of executable fraud detection applications configured to provide fraud detection analyses, wherein each of the plurality of executable fraud detection applications are configured to conduct fraud detection analysis based on specific transaction data attributes;
generate a first cluster by:
inputting into a machine learning model, the transaction data, wherein the machine learning model has been trained based on historical transaction data, and
receiving, from the machine learning model, an output comprising the first cluster, wherein the first cluster comprises a first plurality of transactions, and wherein the first cluster is associated with one or more first clustering criteria;
assign a first executable fraud detection application of the plurality of executable fraud detection applications to the first cluster based on a likelihood that the first executable fraud detection application more accurately identifies fraud for the first cluster than any other executable fraud detection application of the plurality of executable fraud detection applications;
in response to determining that the first executable fraud detection application does not satisfy a stopping criterion, generate a second cluster different from the first cluster, wherein the second cluster comprises a subset of transactions of the first plurality of transactions, wherein the second cluster is associated with one or more second clustering criteria, and wherein the stopping criterion comprises at least one parameter pertaining to performance or a maximum number of fraud detection applications, wherein the at least one parameter pertaining to performance comprises an accuracy threshold for detecting potentially fraudulent transactions;
assign a second executable fraud detection application of the plurality of executable fraud detection applications to the second cluster;
in response to determining that the second executable fraud detection application satisfies the stopping criterion, generate a fraud detection workflow comprising the first executable fraud detection application and the second executable fraud detection application;
in response to receiving a first transaction and determining that the first transaction satisfies the one or more first clustering criteria and the one or more second clustering criteria, execute the fraud detection workflow to determine a likelihood that the first transaction may be fraudulent; and
based on execution of the fraud detection workflow, identify the first transaction as potentially fraudulent.
2 . The system of claim 1 , wherein the transaction data includes one or more of an email address, geographic data, internet service provider data, age range, or device information.
3 . The system of claim 1 , wherein the transaction data attributes comprise one or more of consumer profile information, device information, or transaction information.
4 . The system of claim 3 , wherein the one or more first clustering criteria comprise one or more transaction data attributes.
5 . The system of claim 1 , wherein the computer code, when retrieved from the memory and executed by the processor further causes the processor to:
in response to determining that the first executable fraud detection application does not satisfy the stopping criterion, generate a third cluster, different from the first cluster and the second cluster, wherein the third cluster comprises a subset of transactions of the first plurality of transactions, and wherein the third cluster is associated with one or more third clustering criteria; and
assign a third executable fraud detection application of the plurality of executable fraud detection applications the third cluster.
6 . The system of claim 5 , wherein the computer code, when retrieved from the memory and executed by the processor further causes the processor to:
in response to determining that the third executable fraud detection application does not satisfy the stopping criterion,
generate a fourth cluster; and
assign a fourth executable fraud detection application of the plurality of executable fraud detection applications to the fourth cluster.
7 . The system of claim 1 , wherein a first criterion of the one or more first clustering criteria is at least one of user information, device information, or transaction information.
8 . The system of claim 1 , wherein the machine learning model is an unsupervised learning machine learning model.
9 . The system of claim 1 , wherein the computer code, when retrieved from the memory and executed by the processor further causes the processor to assign the first executable fraud detection application to the first cluster based on a greedy algorithm.
10 . The system of claim 1 , wherein the plurality of executable fraud detection applications are associated with one or more of: identity verification, device intelligence, email intelligence, document verification, behavioral biometrics, phone intelligence, social media data, or alternative identity data.
11 . The system of claim 1 , wherein to execute the fraud detection workflow, the computer code, when retrieved from the memory and executed by the processor further causes the processor to:
execute the first executable fraud detection application and the second executable fraud detection application.
12 . A computer-implemented method for generating and executing an automated fraud detection workflow, the computer-implemented method comprising:
generating a first cluster, wherein the first cluster comprises transaction data from a first plurality of transactions, and wherein the first cluster is associated with one or more first clustering criteria;
assigning a first executable fraud detection application of a plurality of executable fraud detection applications to the first cluster based on a likelihood that the first executable fraud detection application more accurately identifies fraud for the first cluster than at least one other executable fraud detection application of the plurality of executable fraud detection applications;
in response to determining that the first executable fraud detection application does not satisfy a stopping criterion, generating a second cluster, different from the first cluster, wherein the second cluster comprises a subset of transactions of the first plurality of transactions, wherein the second cluster is associated with one or more second clustering criteria, and wherein the stopping criterion comprises at least one parameter pertaining to performance or a maximum number of fraud detection applications;
assigning a second executable fraud detection application of the plurality of executable fraud detection applications to the second cluster;
in response to determining that the second executable fraud detection application satisfies the stopping criterion, generating a fraud detection workflow comprising the first executable fraud detection application and the second executable fraud detection application;
in response to receiving a first transaction and determining that the first transaction satisfies the one or more first clustering criteria and the one or more second clustering criteria, executing the fraud detection workflow to determine a likelihood that the first transaction may be fraudulent; and
based on execution of the fraud detection workflow, identify the first transaction as potentially fraudulent.
13 . The computer-implemented method of claim 12 , wherein the transaction data includes one or more of an email address, geographic data, internet service provider data, age range, or device information.
14 . The computer-implemented method of claim 12 , wherein each of the plurality of executable fraud detection applications are configured to conduct fraud detection analysis based on specific transaction data attributes, wherein the transaction data attributes comprise one or more of consumer profile information, device information, or transaction information.
15 . The computer-implemented method of claim 14 , wherein the one or more first clustering criteria comprise one or more transaction data attributes.
16 . The computer-implemented method of claim 12 , further comprising:
in response to determining that the first executable fraud detection application does not satisfy the stopping criterion, generating a third cluster, different from the first cluster and the second cluster, wherein the third cluster comprises a subset of transaction of the first plurality of transactions, and wherein the third cluster is associated with one or more third clustering criteria; and
assigning a third executable fraud detection application of the plurality of executable fraud detection applications to the third cluster.
17 . The computer-implemented method of claim 16 , further comprising:
in response to determining that the third executable fraud detection application does not satisfy the stopping criterion, generate a fourth cluster; and
assign a fourth executable fraud detection application of the plurality of executable fraud detection applications to the fourth cluster.
18 . A non-transitory computer storage medium storing computer-executable instructions that, when executed by one or more processors, cause one or more processors to at least:
generate a first cluster, wherein the first cluster comprises transaction data from a first plurality of transactions, and wherein the first cluster is associated with one or more first clustering criteria;
assign a first executable fraud detection application of a plurality of executable fraud detection applications to the first cluster based on a likelihood that the first executable fraud detection application more accurately identifies fraud for the first cluster than at least one other executable fraud detection application of the plurality of executable fraud detection applications;
in response to determining that the first executable fraud detection application does not satisfy a stopping criterion, generate a second cluster, different from the first cluster, wherein the second cluster comprises a subset of transactions of the first plurality of transactions, wherein the second cluster is associated with one or more second clustering criteria, and wherein the stopping criterion comprises at least one parameter pertaining to performance or a maximum number of fraud detection applications;
assign a second executable fraud detection application of the plurality of executable fraud detection applications to the second cluster;
in response to determining that the second executable fraud detection application satisfies the stopping criterion, generate a fraud detection workflow comprising the first executable fraud detection application and the second executable fraud detection application;
in response to receiving a first transaction and determining that the first transaction satisfies the one or more first clustering criteria and the one or more second clustering criteria, execute the fraud detection workflow to determine a likelihood that the first transaction may be fraudulent; and
based on execution of the fraud detection workflow, identify the first transaction as potentially fraudulent.
19 . The non-transitory computer storage medium of claim 18 , wherein to generate the first cluster, the instructions, when executed by one or more processors, cause one or more processors to:
input into a machine learning model, the transaction data, wherein the machine learning model has been trained based on historical transaction data, and
receive, from the machine learning model, an output comprising the first cluster.
20 . The non-transitory computer storage medium of claim 18 , wherein the at least one parameter pertaining to performance comprises an accuracy threshold for detecting potentially fraudulent transactions.