The proposed method (FraudFox) provides solutions to adversarial attacks in a resource constrained environment. We focus on questions like the following: How suspicious is `Smith', trying to buy \$500 shoes, on Monday 3am? How to merge the risk scores, from a handful of risk-assessment modules (`oracles') in an adversarial environment? More importantly, given historical data (orders, prices, and what-happened afterwards), and business goals/restrictions, which transactions, like the `Smith' transaction above, which ones should we `pass', versus send to human investigators? The business restrictions could be: `at most $x$ investigations are feasible', or `at most \$$y$ lost due to fraud'. These are the two research problems we focus on, in this work. One approach to address the first problem (`oracle-weighting'), is by using Extended Kalman Filters with dynamic importance weights, to automatically and continuously update our weights for each 'oracle'. For the second problem, we show how to derive an optimal decision surface, and how to compute the Pareto optimal set, to allow what-if questions. An important consideration is adaptation: Fraudsters will change their behavior, according to our past decisions; thus, we need to adapt accordingly. The resulting system, \method, is scalable, adaptable to changing fraudster behavior, effective, and already in \textbf{production} at Amazon. FraudFox augments a fraud prevention sub-system and has led to significant performance gains.
翻译:所提出的方法(FraudFox)为资源受限环境中的对抗性攻击提供了解决方案。我们关注以下问题:在周一凌晨3点试图购买500美元鞋子的“Smith”有多可疑?如何在对抗性环境中合并来自少数风险评估模块(“预言机”)的风险评分?更重要的是,给定历史数据(订单、价格及后续发生的情况)以及业务目标/限制,对于像上述“Smith”交易这样的交易,哪些应“通过”,哪些应发送给人工调查员?业务限制可能包括:“最多可进行$x$次调查”或“因欺诈造成的损失最多为$y$美元”。这些是我们在本工作中重点研究的两个问题。针对第一个问题(“预言机加权”),一种方法是使用带有动态重要性权重的扩展卡尔曼滤波器,自动且持续地更新每个“预言机”的权重。对于第二个问题,我们展示了如何推导最优决策曲面,以及如何计算帕累托最优集,以支持假设性分析。一个重要的考量是适应性:欺诈者会根据我们过去的决策改变其行为;因此,我们需要相应地适应。由此产生的系统\method具有可扩展性,能适应不断变化的欺诈者行为,高效且已在亚马逊投入**生产**使用。FraudFox增强了欺诈预防子系统,并带来了显著的性能提升。