AI and fraud prevention. 6 chapters and a final quiz.
How artificial intelligence became the core of payment fraud detection. The raw material (features and weak signals), how models evolved (rules, gradient boosting, graphs), real-time scoring at authorization, and the trade-off between fraud losses and false declines. Then the chargeback feedback loop, the generative AI counterattack by fraudsters (deepfakes, AI-assisted fraud), the tooling landscape, and the governance of an automated decision model (explainability, GDPR, the AI Act).
Quantify the cost of payment fraud and understand why rules alone are no longer enough
Describe the raw material of a detection engine: transactional, velocity, behavioral, and graph features
Map the main model families, from rules engines to gradient boosting (GBM) and graph/network analysis, and know when to combine them
Master real-time scoring at authorization and the precision/recall trade-off between fraud losses and false declines
Chapter 1. The cost of fraud and the limits of rules.
Payment fraud covers transactions the account holder did not authorize, as well as those they authorized because they were manipulated. Two reports give a sense of scale, one global and one European. According to the Nilson Report (2024), global card fraud losses reached $33.83 billion in 2023, and the firm projects cumulative losses of more than $400 billion over the next decade. In Europe, the joint ECB/EBA report on payment fraud (August 2024) puts total fraud at €4.3 billion in 2022 across all payment instruments. Broken down by acceptance channel, fraud is clearly concentrated. Card fraud is overwhelmingly card-not-present (remote payments), which accounts for nearly 79% of card fraud by value in the EEA.
🔑
Why AI, and not just rules?
A rules engine (“if amount > €3,000 and country ≠ country of issue, then block”) is readable, auditable, and instant. But its logic is static, generic, and easy to get around. A fraudster who finds a threshold by trial and error then keeps their transactions just below it. Meanwhile, a rule written for a fraud pattern already observed declines legitimate cardholders whose habits have changed. AI addresses these limits in three ways: it learns combinations of signals, adapts to new patterns, and scores a probability instead of making a binary call.
$33.83B
global card fraud losses in 2023
Nilson Report, 2024
€4.3B
total payment fraud in the EEA in 2022 (all instruments)
ECB/EBA, Report on Payment Fraud, August 2024
≈ 79 %
card-not-present share of card fraud value (EEA)
ECB/EBA, 2024
< 0,05 %
target fraud rate on SCA/3DS-authenticated transactions, far below the rate on unauthenticated ones
ECB/EBA, 2024
Strong authentication moved fraud elsewhere; it didn't eliminate it
In Europe, PSD2 and strong customer authentication (SCA), rolled out through 3-D Secure, sharply reduced fraud on authenticated transactions. Other markets rely on different authentication mechanisms. Fraud moved to flows outside the scope of SCA. These include cross-border transactions with an acquirer outside the EEA, merchant-initiated transactions (MITs), and transactions exempted under transaction risk analysis (TRA). Two other routes bypass authentication without having to defeat it. Social engineering leads cardholders to authenticate a payment they believe is legitimate, and account takeover puts the account holder's authentication factors in the fraudster's hands. SCA did not solve the problem. A single checkpoint at the start of the customer journey no longer covers these cases. Detection must therefore score every transaction continuously: before, during, and after authorization.
Rule: fixed, explicit logic and a binary decision, easy to get around once the threshold is known
Statistical/ML model: learns correlations across thousands of transactions and produces a continuous risk score
In practice, you combine both: rules handle known patterns and regulatory requirements (sanctions lists, limits), while the model handles nuanced and novel cases
🎯 Quick question
Why is a rules engine alone no longer enough to fight payment fraud?
Chapter 2. Features: the raw material of detection.
A feature is a numerical variable that describes one aspect of a transaction and serves as input to the model. All the features for a transaction make up its feature vector: the transaction expressed as tens or hundreds of numerical variables. Feature quality determines 80% of performance, far more than the choice of algorithm. Features fall into a few broad families. Many only become meaningful over time and across the network.
💳
Transactional
Amount, currency, MCC (merchant category code), channel (POS/CNP), time, card type. The raw transaction data: necessary, but rarely sufficient.
⏱️
Velocity
Number of transactions on this card in the past hour, number of different cards on this device today. The most predictive signal, since fraud often comes in bursts.
🖐️
Behavioral/biometric
Typing speed, how the phone is held, navigation path, usual times of activity. Behavioral biometrics detects an impostor even with valid credentials.
🕸️
Graph/network
Links between this card, email address, device, or IP and entities already known to be fraudulent. A hidden link between accounts is often the best clue.
ℹ️
Aggregate feature engineering: where detection is won
Rolling aggregates count or average events over a time window that moves with the observation date. Features built this way are the most predictive, ahead of raw values read from the transaction. Examples: “difference between this amount and the cardholder's average order value over the past 30 days,” “number of distinct countries on this card in 24 hours,” and “share of declines on this device this week.” Computing these aggregates in a few milliseconds or less, at authorization time, is as much an engineering problem as a data science one.
Device fingerprinting and behavioral fingerprints
A device fingerprint identifies a device without a cookie by combining browser configuration, screen resolution, time zone, fonts, and sensors. The same device fingerprint showing up on different cards is a classic red flag. Behavioral biometrics models how the user interacts: typing speed, how they hold the phone, and how they navigate. A fraudster who has the username and password rarely reproduces the account holder's gestures. Both signals are passive. They add no friction for legitimate customers.
Card type
Example feature
What it catches
Transactional
Amount / cardholder's average order value (ratio)
Unusually large purchase for this profile
Velocity
No. of card transactions in the past hour
Burst of card testing attempts
Behavioral
Typing rhythm and touch pressure
Impostor with stolen credentials
Device
No. of distinct cards seen on this device / 24 hrs
Fraudster's device cycling through stolen cards
Graph
Distance to an entity already flagged as fraudulent
Organized network, fraud ring
Example features by family and their predictive power
🎯 Quick question
Why are velocity and graph features often more predictive than raw transaction features?
Chapter 3. Models: rules, gradient boosting, and graphs.
Fraud detection in production runs several models at once, organized as a stack of complementary layers. Each layer answers a different question and covers the others' blind spots. None of them covers everything on its own. That's why vendors talk about a “decision engine” rather than an “algorithm.”
A typical fraud decision engine stack
Layer 1: rules
Hard filters: sanctions lists, limits, country blocks, blocklists
Known patterns and regulatory requirements; immediate binary decision
➜
Layer 2: supervised model (GBM)
Fraud probability score based on the feature vector
The statistical core: XGBoost, LightGBM, gradient boosting
➜
Layer 3: graph analysis
Detects networks and relational anomalies
Organized fraud, rings, linked entities
➜
Layer 4: unsupervised/anomaly detection
Flags never-before-seen behavior (new fraud)
Safety net for patterns with no label history
➜
Payment orchestration
Combines scores into a decision: approve, decline, or challenge (step-up)
Thresholds calibrated to business cost
Why gradient boosting (GBM) dominates
Gradient-boosted trees (GBM), implemented as XGBoost and LightGBM, are the most widely used approach in fraud detection, ahead of deep neural networks and single decision trees. The method builds hundreds of decision trees in sequence, each correcting the errors of the one before. Three properties explain its dominance. It excels on tabular, heterogeneous data (numerical + categorical) and handles missing values natively. It tolerates extreme class imbalance, since fraud is often less than 1% of transactions. And it lends itself to explainability through SHAP values, which show which features pushed the score up.
⚠️
The class imbalance trap
If 0.5% of transactions are fraudulent, a model that always predicts “no fraud” reaches 99.5% accuracy while catching none of it. Accuracy measures the share of correct predictions, and that share is dominated by the majority class as soon as one class becomes rare. Accuracy is therefore never used to judge a fraud model. Fraud models are evaluated on metrics suited to imbalanced data: precision, recall, and the area under the precision-recall curve (PR-AUC), and above all the real business cost of each error.
Graphs: seeing organized fraud
Graph analysis represents the entities in the payment system as a network and looks for fraud in the links between them. A GBM scores a transaction almost in isolation. It doesn't use the fact that a card, a disposable email address, and a device all belong to the same money mule ring. The model is built from nodes and edges: nodes are cards, accounts, devices, and IP addresses; edges are shared transactions. You then look for suspicious substructures, such as densely connected clusters, accounts linked to an entity already known to be fraudulent, or risk spreading from one neighbor to the next. Graph neural networks (GNNs) automate this analysis. This layer is what distinguishes opportunistic fraud, such as a stolen card, from industrial-scale fraud, such as a money laundering operation.
Which algorithm dominates fraud detection on tabular transaction data, and why?
Chapter 4. Real-time scoring and the false-positive trade-off.
Real-time scoring means computing a risk score while the authorization itself is in progress. The score must be produced before the authorization request goes out to the network, which leaves a latency budget of a few tens of milliseconds. The entire pipeline has to fit in that window: fetching rolling aggregates, computing features, running model inference, and applying rules. This is a real-time engineering problem as much as a data science one, requiring a low-latency feature store, compiled models, and cached velocity counters.
🔑
The real hidden cost: false declines
A false decline is the decision engine's rejection of a legitimate transaction. Where you set the threshold determines the balance between the two possible errors. Lowering it catches more fraud (better recall) but declines more legitimate customers (more false positives). A false decline often costs more than the fraud itself: the margin lost on the sale, the frustrated customer who goes to a competitor, and the hit to customer lifetime value. An engine's performance is therefore judged on the balance between fraud prevented and revenue preserved, not on the amount of fraud blocked alone.
Precision, recall, and the decision threshold
Model says FRAUD
Model says LEGITIMATE
Actually fraud
True positive (fraud prevented) ✅
False negative (fraud loss, chargeback to come) ❌
Actually legitimate
False positive (false decline, lost sale and customer) ⚠️
True negative (frictionless transaction) ✅
Understanding a fraud model's errors
Recall: the share of actual fraud that gets caught, to be maximized without letting false positives explode
Precision: the share of alerts that are actual fraud; low precision overwhelms manual review teams
The threshold is not a technical setting: it is a business decision that reflects what a euro of fraud costs compared with a euro of lost sales
Manual review (3DS challenge, step-up, customer call) is the third option between approving and declining: it turns doubt into an informed decision
Production engines split the score range into several bands instead of using a single threshold. Above a high score, the transaction is declined automatically; below a low score, it is approved without friction; in the gray zone, it gets an authentication step-up or a review. This segmentation reduces friction for the vast majority of legitimate transactions and focuses verification effort on doubtful cases. Because fraud patterns change, the band boundaries are constantly recalibrated. That recalibration relies on confirmed fraud and declines assessed after the fact, which only the feedback loop provides.
🎯 Quick question
Why isn't a fraud engine judged solely on how much fraud it blocks?
Chapter 5. The feedback loop: chargebacks and labels.
Labels are the “fraud” or “legitimate” tags attached to transactions after the fact, and they are what a supervised model learns from. This ground truth arrives late and incomplete. Its main source is the chargeback (a disputed transaction reversed through the card network). Network reports supplement it by passing on fraud declared by issuers: TC40 at Visa and SAFE (System to Avoid Fraud Effectively) at Mastercard. Both sources have one thing in common. They describe the transaction after the fact, and only once a third party has reported it: the cardholder who disputes it or the issuer who declares it.
⚠️
Label latency: training one step behind
A fraud chargeback can arrive weeks or even months after the transaction, and the decision stays unconfirmed that whole time. This latency has two consequences for model training. Retraining covers a period that is already out of date, since fraud methods have changed in the meantime. And a recent transaction that hasn't been disputed yet can't be assumed legitimate: it may be fraud still awaiting its label. An evaluation that counts these transactions as legitimate examples overstates the model's performance.
The virtuous cycle and where it leaks
The continuous learning loop
Model
Scores and decides in real time
Approve / decline / step-up
➜
Reality
The outcome emerges later
Chargeback, TC40/SAFE, or silence
➜
Labeling
Transactions are labeled after the fact
Confirmed fraud vs. presumed legitimate
➜
Retraining
The model learns from new cases
Then thresholds are recalibrated
Two phenomena limit how well this loop works. Biased feedback arises because the true outcome is only known for approved transactions. A declined transaction produces neither a chargeback nor a confirmation, so the model gets no information about unjustified declines. Drift comes from changes in both the transaction mix and fraud tactics, which erode the performance of a model left unchanged. Both call for active labeling campaigns and ongoing monitoring of the alert rate, realized precision, and feature distributions.
Weeks to months
typical delay between a transaction and the chargeback that labels it
Card networks (dispute rules)
< 1 %
typical fraud prevalence among transactions, an extreme label imbalance
Industry estimate
TC40 / SAFE
Visa/Mastercard fraud reporting feeds, which supplement chargebacks
Visa / Mastercard
🎯 Quick question
What is the main flaw in a chargeback-based feedback loop?
Chapter 6. Fraudsters' generative AI, tools, and governance.
Generative AI refers to models that can produce text, images, voice, and video. Fraudsters use AI too, and generative AI has industrialized their arsenal. It lets them write flawless, personalized phishing messages at scale, create synthetic identities, get past KYC checks with deepfakes (face and voice), and automate entire campaigns. Malicious models sold on the dark web, such as FraudGPT and WormGPT (2023), lower the technical barrier. A scammer with no coding skills can now build a fraud kit with a few prompts.
🎭
KYC deepfakes
A synthetic face or voice used to pass a video ID check or carry out a bank vishing call. Deepfake attempts in onboarding flows have surged since 2023.
👤
Synthetic identities
Real and fabricated data combined to create a “customer” who doesn't exist, open accounts, and build up a history before cashing out (bust-out).
🎣
Industrialized phishing
Generative AI writes convincing lures, error-free, in any language, in unlimited volume. Social engineering now operates at a new scale.
🗣️
AI-assisted APP fraud
Authorized push payment fraud. Victims make the payment themselves, manipulated by a scenario that AI makes hyperrealistic.
$40B
in US fraud losses attributable to generative AI expected in 2027 (vs. $12.3 billion in 2023)
Deloitte Center for Financial Services, 2024
≈ +900%/yr
increase in deepfake incidents detected in some onboarding flows (2022→2023)
Sumsub, Identity Fraud Report 2023
2023
FraudGPT and WormGPT appear on the dark web
Cybersecurity researchers, 2023
ℹ️
The arms race
Every new offensive capability meets a countermeasure. Deepfake detection analyzes liveness and generation artifacts, and passive signals (device, behavioral biometrics) are beyond the impostor's control. Institutions share intelligence on money mules and the scenarios they observe. Fraud detection is an adversarial field: the defensive model and the attacker each evolve in response to the other. A model left as is loses performance as attackers shift tactics.
The tooling landscape
Selected AI fraud detection vendorsVisaMastercardSASASStripeNVNVIDIA
The market includes the card networks (Visa, Mastercard), which score at the network level, and e-commerce specialists (Forter, Signifyd, Riskified, Sift, Ravelin, SEON). Then come AML/banking fraud platforms (Feedzai, Featurespace, NICE Actimize, SAS) and components built into PSPs (Radar at Stripe). Consolidation is accelerating. Visa's acquisition of Featurespace (announced in 2024, completed in 2025) shows how scoring is being vertically integrated into the networks themselves.
Governing an automated decision model
Goal
Requirement
Framework / best practice
Explainability
Justify each decline (top contributing features)
SHAP, model documentation, coded decline reason
Automated decisions
Put safeguards around declines that significantly affect the individual
GDPR Art. 22: right to human intervention and to contest the decision
Regulatory status
Determine whether the system is “high risk”
AI Act: fraud detection is explicitly excluded from high risk (unlike credit scoring)
Non-discrimination
Avoid indirect bias (proxies for ethnic origin, neighborhood)
Fairness testing, monitoring decline rates by segment
Robustness / drift
Detect degradation and adversarial attacks
Continuous monitoring, retraining, red teaming
The pillars of fraud engine governance
🔑
A commonly misunderstood point of law
Under the EU AI Act (in force since August 1, 2024, with “high-risk” obligations applying from August 2, 2026), credit scoring is classified as high risk. Financial fraud detection is explicitly excluded. This exclusion concerns only the high-risk classification; it doesn't exempt you from governance. GDPR Article 22 still governs any fully automated decision with a significant effect, such as blocking a payment or closing an account, and requires transparency, a right to human intervention, and the ability to contest the decision.
🎯 Quick question
How does the EU AI Act treat an AI system for payment fraud detection?