The rapid expansion of Internet banking and digital payment services in recent years has led to a significant increase in online fraud, resulting in substantial financial and reputational losses for financial institutions. To address these challenges, banks employ Fraud Detection Systems (FDSs) powered by Machine Learning (ML) models capable of processing large volumes of transactional data in real time. However FDSs became vulnerable to Adversarial Machine Learning (AML) attacks that could evade detection or degrade model performance. This thesis presents a comprehensive benchmarking framework for adversarial attacks against FDSs. The proposed approach systematically examines the performance of various adversarial strategies across different threat models and knowledge levels. The study advances prior research by adapting and implementing several state-of-the-art AML attack algorithms for the tabular data domain of financial transactions, including Universal Greedy, CAA, CAPGD, and MOEVA. A central contribution is the introduction of novel imperceptibility metrics that provide a more realistic evaluation of attack effectiveness by quantifying the subtlety and plausibility of crafted frauds, surpassing conventional metrics based solely on misclassification rates, understanding the impact of adversarial attacks. The framework is validated through extensive experiments involving multiple FDS models and attacker scenarios defined by varying knowledge assumptions, as well as through the assessment of mitigation techniques in realistic settings. Experimental results indicate that gradient-based attacks can generate subtle fraud with minimal perturbations but are less effective than decision-based and search-based attacks, which achieve higher poisoning rates and greater fraud value, respectively, particularly under a one-week update policy. Further findings reveal that, in a more realistic-world scenario, defense techniques only mitigate the effects of adversarial attack, as decision-based prioritize poisoning strength at the expense of higher-value frauds and search-based maximize monetary gain at the cost of subtlety. In summary, this thesis offers a structured, extensible methodology for analyzing adversarial threats in fraud detection, thereby advancing understanding of attacker behavior and supporting the development of more robust, resilient fraud detection systems.
La rapida espansione dell’Internet banking e dei servizi di pagamento digitali negli ultimi anni ha comportato un aumento significativo delle frodi online, causando ingenti perdite finanziarie e reputazionali per le istituzioni finanziarie. Per affrontare queste sfide, le banche adottano Fraud Detection Systems (FDS) basati su modelli di Machine Learning (ML) in grado di elaborare grandi volumi di dati transazionali in tempo reale. Tuttavia, gli FDS sono diventati vulnerabili ad attacchi di Adversarial Machine Learning (AML) in grado di eludere i meccanismi di rilevamento o di degradare le prestazioni dei modelli. Questa tesi presenta un framework di benchmarking completo per gli attacchi avversariali contro gli FDS. L’approccio proposto esamina in maniera sistematica le prestazioni di diverse strategie avversarie attraverso modelli di minaccia. Lo studio estende la ricerca pregressa adattando e implementando diversi algoritmi di AML allo stato dell’arte per il dominio dei dati tabellari delle transazioni finanziarie, tra cui Universal Greedy, CAA, CAPGD e MOEVA. Un contributo centrale consiste nell’introduzione di nuove metriche di impercettibilità che consentono una valutazione più realistica dell’efficacia degli attacchi, quantificando discrezione e plausibilità delle frodi generate, superando le metriche convenzionali basate esclusivamente sui tassi di misclassificazione. Il framework è stato validato mediante una campagna sperimentale estesa, coinvolgendo molteplici modelli di FDS e scenari di attacco, nonché attraverso la valutazione di tecniche di mitigazione in contesti realistici. I risultati sperimentali indicano che gli attacchi gradient-based possono generare frodi impercettibili con perturbazioni minime, ma risultano meno efficaci rispetto agli attacchi decision-based e search-based, i quali raggiungono, rispettivamente, tassi di poisoning più elevati e un valore delle frodi maggiore, in particolare sotto una frequenza di aggiornamento settimanale. Ulteriori evidenze mostrano che, in scenari più realistici, le tecniche di difesa mitigano solo parzialmente gli effetti degli attacchi avversariali, poiché gli attacchi decision-based privilegiano i benefici del poisoning a scapito di frodi di maggior valore, mentre quelli search-based massimizzano il guadagno monetario al costo di una minore impercettibilità. In sintesi, questa tesi propone una metodologia strutturata ed estensibile per l’analisi delle minacce avversarie nei sistemi di rilevamento delle frodi, contribuendo ad approfondire la comprensione del comportamento degli attaccanti e a supportare lo sviluppo di FDS più robusti e resilienti.
AttaXBench: a benchmarking framework for evaluating adversarial attacks against fraud detection systems
GESMUNDO, DAVIDE
2024/2025
Abstract
The rapid expansion of Internet banking and digital payment services in recent years has led to a significant increase in online fraud, resulting in substantial financial and reputational losses for financial institutions. To address these challenges, banks employ Fraud Detection Systems (FDSs) powered by Machine Learning (ML) models capable of processing large volumes of transactional data in real time. However FDSs became vulnerable to Adversarial Machine Learning (AML) attacks that could evade detection or degrade model performance. This thesis presents a comprehensive benchmarking framework for adversarial attacks against FDSs. The proposed approach systematically examines the performance of various adversarial strategies across different threat models and knowledge levels. The study advances prior research by adapting and implementing several state-of-the-art AML attack algorithms for the tabular data domain of financial transactions, including Universal Greedy, CAA, CAPGD, and MOEVA. A central contribution is the introduction of novel imperceptibility metrics that provide a more realistic evaluation of attack effectiveness by quantifying the subtlety and plausibility of crafted frauds, surpassing conventional metrics based solely on misclassification rates, understanding the impact of adversarial attacks. The framework is validated through extensive experiments involving multiple FDS models and attacker scenarios defined by varying knowledge assumptions, as well as through the assessment of mitigation techniques in realistic settings. Experimental results indicate that gradient-based attacks can generate subtle fraud with minimal perturbations but are less effective than decision-based and search-based attacks, which achieve higher poisoning rates and greater fraud value, respectively, particularly under a one-week update policy. Further findings reveal that, in a more realistic-world scenario, defense techniques only mitigate the effects of adversarial attack, as decision-based prioritize poisoning strength at the expense of higher-value frauds and search-based maximize monetary gain at the cost of subtlety. In summary, this thesis offers a structured, extensible methodology for analyzing adversarial threats in fraud detection, thereby advancing understanding of attacker behavior and supporting the development of more robust, resilient fraud detection systems.| File | Dimensione | Formato | |
|---|---|---|---|
|
2025_03_Gesmundo_Tesi.pdf
solo utenti autorizzati a partire dal 22/02/2027
Descrizione: testo tesi
Dimensione
7.44 MB
Formato
Adobe PDF
|
7.44 MB | Adobe PDF | Visualizza/Apri |
|
2025_03_Gesmundo_Executive_Summary.pdf
solo utenti autorizzati a partire dal 22/02/2027
Descrizione: testo executive summary
Dimensione
430.51 kB
Formato
Adobe PDF
|
430.51 kB | Adobe PDF | Visualizza/Apri |
I documenti in POLITesi sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/10589/251978