Payment Anomaly Detection
How unsupervised ML.NET models watch a national payment portal's transaction and wallet streams — without ever touching the live payment path.
Context
A national payment portal processes transactions and wallet activity at government scale. Fraudulent or abnormal behavior — compromised accounts, unusual transfer patterns, wallet abuse — has to be caught early, but the platform team had no labeled fraud dataset to train on and no appetite for anything that could add latency or risk to the payment flow itself.
Constraints
- Zero impact on the live path — no scoring inline with payments; detection runs in scheduled batches beside the flow, never inside it.
- No labels — no historical fraud tags existed, so supervised approaches were off the table. Detection had to be unsupervised.
- Data stays home — government data never leaves the environment: training on in-house Oracle data, models stored in-database, everything on-prem.
- Multi-pod production — the platform runs across pods, so alerts and retraining need distributed coordination, not single-instance assumptions.
Architecture
light = data. amber: live detection flow · blue: the human-in-the-loop learning cycle
How it flows
- Score in batches, beside the flow. Models train on historical Oracle data and score recent transaction and wallet activity on a schedule — the live payment path never waits on ML.
- Respond in tiers. Low-confidence anomalies land as dashboard flags; stronger signals flag the account; the highest tier can hold activity automatically pending review.
- Alert instantly. Detections publish over Redis Pub/Sub so every pod and every open dashboard sees the alert live — no polling.
- Learn from analysts. Every confirm/dismiss decision is captured and fed into nightly retraining, run under distributed locks so exactly one pod retrains. New models are versioned and stored in-database — rollback is a pointer flip.
Why it's built this way
The interesting constraint wasn't the ML — it was trust. A model that occasionally holds a legitimate government payment is worse than no model. Tiered responses mean the system earns autonomy gradually: it starts by suggesting, and only acts alone at confidence levels analysts have validated. The feedback loop means every analyst decision makes tomorrow's model slightly better — human-in-the-loop as an architecture, not a slogan.