Defending the Pipeline: Engineering Secure, Real-Time AI Fraud Detection Systems
Main Article Content
Abstract
Real-time fraud detection services are placed in the critical path of card authorisation and need to return a decision approve-or-decline in under one hundred milliseconds. Running a machine learning model in this critical path increases detection quality‚ but also attack surface․ In addition to the model itself‚ the scoring interface‚ feature store and label feedback loop are new attack targets in an ML-powered fraud system. Previous work has considered detection accuracy and pipeline security in isolation‚ and the cost of security controls within the authorisation window is poorly understood․ Here‚ we present STREAM-Guard‚ a four-layer pipeline․ These include ingestion-layer salted tokenisation‚ cryptographically verified provenance‚ differentially private and adversarially regularized training and behavioral rate limiting at the inference gateway‚ subject to a latency budget model that divides the authorization window between these controls․ In addition‚ a provenance admission rule bounds the share of poisoned records that reach the offline feature store․ Evaluated on 284‚807 transactions made with European cards‚ and with multiple replays of synthetic streams with varying speeds (up to 5‚000 transactions per second)‚ STREAM-Guard achieved an AUC-PR of 0․851 (99th percentile latency: 42․1 ms)‚ compared to 0․834 (29․0 ms) for a baseline gradient boosting approach with no security hardening․ By securing the pipeline‚ 0․024 AUC-PR was lost under 10 percent label-poisoning abuse‚ as opposed to 0․212 when the pipeline was not secured․ The advantage of membership inference dropped by 0․058․ In practice‚ with homomorphic inference taking 1․42 s per decision‚ this task is infeasible at that rate․