{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T02:01:13Z","timestamp":1778896873448,"version":"3.51.4"},"reference-count":61,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2023,10,14]],"date-time":"2023-10-14T00:00:00Z","timestamp":1697241600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2023,11,30]]},"abstract":"<jats:p>\n            Machine learning (ML) models are vulnerable to adversarial machine learning (AML) attacks. Unlike other contexts, the fraud detection domain is characterized by inherent challenges that make conventional approaches hardly applicable. In this article, we extend the application of AML techniques to the fraud detection task by studying poisoning attacks and their possible countermeasures. First, we present a novel approach for performing poisoning attacks that overcomes the fraud detection domain-specific constraints. It generates fraudulent candidate transactions and tests them against a machine learning-based\n            <jats:italic>Oracle<\/jats:italic>\n            , which simulates the target fraud detection system aiming at evading it. Misclassified fraudulent candidate transactions are then integrated into the target detection system\u2019s training set, poisoning its model and shifting its decision boundary. Second, we propose a novel approach that extends the adversarial training technique to mitigate AML attacks: During the training phase of the detection system, we generate artificial frauds by modifying random original legitimate transactions; then, we include them in the training set with the correct label. By doing so, we instruct our model to recognize evasive transactions before an attack occurs. Using two real bank datasets, we evaluate the security of several state-of-the-art fraud detection systems by deploying our poisoning attack with different degrees of attacker\u2019s knowledge and attacking strategies. The experimental results show that our attack works even when the attacker has minimal knowledge of the target system. Then, we demonstrate that the proposed countermeasure can mitigate adversarial attacks by reducing the stolen amount of money up to 100%.\n          <\/jats:p>","DOI":"10.1145\/3613244","type":"journal-article","created":{"date-parts":[[2023,8,8]],"date-time":"2023-08-08T12:02:21Z","timestamp":1691496141000},"page":"1-35","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["Fraud Detection under Siege: Practical Poisoning Attacks and Defense Strategies"],"prefix":"10.1145","volume":"26","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2570-1957","authenticated-orcid":false,"given":"Tommaso","family":"Paladini","sequence":"first","affiliation":[{"name":"Dipartimento di Elettronica, Informazione e Bioingegneria (DEIB), Politecnico di Milano, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-6466-0115","authenticated-orcid":false,"given":"Francesco","family":"Monti","sequence":"additional","affiliation":[{"name":"Dipartimento di Elettronica, Informazione e Bioingegneria (DEIB), Politecnico di Milano, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0925-2306","authenticated-orcid":false,"given":"Mario","family":"Polino","sequence":"additional","affiliation":[{"name":"Dipartimento di Elettronica, Informazione e Bioingegneria (DEIB), Politecnico di Milano, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8284-6074","authenticated-orcid":false,"given":"Michele","family":"Carminati","sequence":"additional","affiliation":[{"name":"Dipartimento di Elettronica, Informazione e Bioingegneria (DEIB), Politecnico di Milano, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4710-5283","authenticated-orcid":false,"given":"Stefano","family":"Zanero","sequence":"additional","affiliation":[{"name":"Dipartimento di Elettronica, Informazione e Bioingegneria (DEIB), Politecnico di Milano, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,10,14]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2016.04.007"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/MLSP.2019.8918896"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2021.100402"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2015.12.030"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/591"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/1128817.1128824"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.3103\/S1060992X15030030"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2010.08.008"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"e_1_3_2_11_2","article-title":"Security evaluation of pattern classifiers under attack","volume":"1709","author":"Biggio Battista","year":"2017","unstructured":"Battista Biggio, Giorgio Fumera, and Fabio Roli. 2017. Security evaluation of pattern classifiers under attack. CoRR abs\/1709.00609 (2017).","journal-title":"CoRR"},{"key":"e_1_3_2_12_2","volume-title":"29th International Conference on Machine Learning","author":"Biggio Battista","year":"2012","unstructured":"Battista Biggio, Blaine Nelson, and Pavel Laskov. 2012. Poisoning attacks against support vector machines. In 29th International Conference on Machine Learning. icml.cc\/Omnipress. Retrieved from http:\/\/icml.cc\/2012\/papers\/880.pdf"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2018.07.023"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.1999.809773"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-93411-2_10"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.04.002"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/3178370"},{"key":"e_1_3_2_18_2","first-page":"285","volume-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses","author":"Carminati Michele","year":"2020","unstructured":"Michele Carminati, Luca Santini, Mario Polino, and Stefano Zanero. 2020. Evasion attacks against banking fraud detection systems. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses, Manuel Egele and Leyla Bilge (Eds.). USENIX Association, 285\u2013300. Retrieved from https:\/\/www.usenix.org\/conference\/raid2020\/presentation\/carminati"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60080-2_17"},{"key":"e_1_3_2_20_2","unstructured":"CEUR Workshop Proceedings Workshop on Artificial Intelligence Safety 2021 (SafeAI\u201921) co-located with the 35th AAAI Conference on Artificial Intelligence (AAAI\u201921) 2808 Francesco Cartella Orlando Anuncia\u00e7\u00e3o Yuki Funabiki Daisuke Yamaguchi Toru Akishita Olivier Elshocht Hu\u00e1scar Espinoza John Alexander McDermid Xiaowei Huang Mauricio Castillo-Effen Xin Cynthia Chen Jos\u00e9 Hern\u00e1ndez-Orallo Se\u00e1n \u00d3 h\u00c9igeartaigh Richard Mallah Adversarial attacks for tabular data: Application to fraud detection and imbalanced data 2021"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2021.3052950"},{"key":"e_1_3_2_22_2","first-page":"321","volume-title":"28th USENIX Security Symposium","author":"Demontis Ambra","year":"2019","unstructured":"Ambra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski, Battista Biggio, Alina Oprea, Cristina Nita-Rotaru, and Fabio Roli. 2019. Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks. In 28th USENIX Security Symposium, Nadia Heninger and Patrick Traynor (Eds.). USENIX Association, 321\u2013338. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/demontis"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/TASL.2013.2244083"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/1124772.1124861"},{"key":"e_1_3_2_25_2","unstructured":"Jonas Geiping Liam Fowl Gowthami Somepalli Micah Goldblum Michael Moeller and Tom Goldstein. 2021. What Doesn\u2019t Kill You Makes You Robust(er): Adversarial Training against Poisons and Backdoors. arXiv:2102.13624"},{"key":"e_1_3_2_26_2","volume-title":"Dark Web Price Index 2020","author":"Gomez Miguel","year":"2020","unstructured":"Miguel Gomez. 2020. Dark Web Price Index 2020. Retrieved from https:\/\/www.privacyaffairs.com\/dark-web-price-index-2020\/"},{"key":"e_1_3_2_27_2","unstructured":"Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. Retrieved from http:\/\/arxiv.org\/abs\/1412.6572"},{"key":"e_1_3_2_28_2","article-title":"On the (statistical) detection of adversarial examples","volume":"1702","author":"Grosse Kathrin","year":"2017","unstructured":"Kathrin Grosse, Praveen Manoharan, Nicolas Papernot, Michael Backes, and Patrick D. McDaniel. 2017. On the (statistical) detection of adversarial examples. CoRR abs\/1702.06280 (2017).","journal-title":"CoRR"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/2046684.2046692"},{"issue":"4","key":"e_1_3_2_30_2","first-page":"1503","article-title":"Comparison and analysis of logistic regression, na\u00efve Bayes and KNN machine learning algorithms for credit card fraud detection","volume":"13","year":"2021","unstructured":"Fayaz Itoo, Meenakshi, and Satwinder Singh. 2021. Comparison and analysis of logistic regression, na\u00efve Bayes and KNN machine learning algorithms for credit card fraud detection. Int. J. Inf. Technol. 13, 4 (2021), 1503\u20131511.","journal-title":"Int. J. Inf. Technol."},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2012.05.018"},{"key":"e_1_3_2_33_2","first-page":"7961","volume-title":"35th AAAI Conference on Artificial Intelligence, 33rd Conference on Innovative Applications of Artificial Intelligence11th Symposium on Educational Advances in Artificial Intelligence","author":"Jia Jinyuan","year":"2021","unstructured":"Jinyuan Jia, Xiaoyu Cao, and Neil Zhenqiang Gong. 2021. Intrinsic certified robustness of bagging against data poisoning attacks. In 35th AAAI Conference on Artificial Intelligence, 33rd Conference on Innovative Applications of Artificial Intelligence11th Symposium on Educational Advances in Artificial Intelligence. AAAI Press, 7961\u20137969. Retrieved from https:\/\/ojs.aaai.org\/index.php\/AAAI\/article\/view\/16971"},{"key":"e_1_3_2_34_2","volume-title":"Global Banking Fraud Survey.","year":"2019","unstructured":"KPMG. 2019. Global Banking Fraud Survey. Retrieved from https:\/\/assets.kpmg\/content\/dam\/kpmg\/xx\/pdf\/2019\/05\/global-banking-fraud-survey.pdf"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1155\/2014\/252797"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2014.09.005"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3167699"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2805680"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00095"},{"key":"e_1_3_2_41_2","article-title":"Deep learning applied to NLP","volume":"1703","author":"Lopez Marc Moreno","year":"2017","unstructured":"Marc Moreno Lopez and Jugal Kalita. 2017. Deep learning applied to NLP. CoRR abs\/1703.03091 (2017).","journal-title":"CoRR"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359810"},{"key":"e_1_3_2_43_2","volume-title":"Statistical Reports on Payment Card Fraud (Italian Version)","author":"Economy Italian Ministry of","year":"2021","unstructured":"Italian Ministry of Economy and Finance. 2021. Statistical Reports on Payment Card Fraud (Italian Version). Technical Report. Retrieved from https:\/\/www.dt.mef.gov.it\/export\/sites\/sitodt\/modules\/documenti_it\/antifrode_mezzi_pagamento\/antifrode_mezzi_pagamento\/Rapporto-statistico-sulle-frodi-con-le-carte-di-pagamento-edizione-2021.pdf"},{"issue":"32","key":"e_1_3_2_44_2","article-title":"Credit card fraud detection using neural network","volume":"1","author":"Patidar Raghavendra","year":"2011","unstructured":"Raghavendra Patidar and Lokesh Sharma. 2011. Credit card fraud detection using neural network. Int. J. Soft Comput. Eng. 1 (2011), 32\u201338.","journal-title":"Int. J. Soft Comput. Eng."},{"key":"e_1_3_2_45_2","unstructured":"Andrea Paudice Luis Mu\u00f1oz-Gonz\u00e1lez Andr\u00e1s Gy\u00f6rgy and Emil C. Lupu. 2018. Detection of Adversarial Training Examples in Poisoning Attacks through Anomaly Detection. arXiv:1802.03041"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-13453-2_1"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00073"},{"key":"e_1_3_2_48_2","series-title":"Italian Conference on Cybersecurity (ITASEC\u201922)","first-page":"135","volume":"3260","author":"Rodr\u00edguez Javier Fern\u00e1ndez","year":"2022","unstructured":"Javier Fern\u00e1ndez Rodr\u00edguez, Michele Papale, Michele Carminati, and Stefano Zanero. 2022. A natural language processing approach for financial fraud detection. In Italian Conference on Cybersecurity (ITASEC\u201922)(CEUR Workshop Proceedings, Vol. 3260), Camil Demetrescu and Alessandro Mei (Eds.). CEUR-WS.org, 135\u2013149. Retrieved from http:\/\/ceur-ws.org\/Vol-3260\/paper10.pdf"},{"key":"e_1_3_2_49_2","first-page":"442","volume-title":"World Congress on Engineering","author":"Sahin Y.","year":"2010","unstructured":"Y. Sahin and Ekrem Duman. 2010. Detecting credit card fraud by decision trees and support vector machines. In World Congress on Engineering. International Association of Engineers, 442\u2013447."},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2007.03.025"},{"key":"e_1_3_2_51_2","first-page":"3517","volume-title":"Annual Conference on Neural Information Processing Systems","author":"Steinhardt Jacob","year":"2017","unstructured":"Jacob Steinhardt, Pang Wei Koh, and Percy Liang. 2017. Certified defenses for data poisoning attacks. In Annual Conference on Neural Information Processing Systems, Isabelle Guyon, Ulrike von Luxburg, Samy Bengio, Hanna M. Wallach, Rob Fergus, S. V. N. Vishwanathan, and Roman Garnett (Eds.). 3517\u20133529. Retrieved from https:\/\/proceedings.neurips.cc\/paper\/2017\/hash\/9d7311ba459f9e45ed746755a32dcd11-Abstract.html"},{"key":"e_1_3_2_52_2","first-page":"1299","volume-title":"27th USENIX Security Symposium","author":"Suciu Octavian","year":"2018","unstructured":"Octavian Suciu, Radu Marginean, Yigitcan Kaya, Hal Daum\u00e9 III, and Tudor Dumitras. 2018. When does machine learning fail? Generalized transferability for evasion and poisoning attacks. In 27th USENIX Security Symposium, William Enck and Adrienne Porter Felt (Eds.). USENIX Association, 1299\u20131316. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/suciu"},{"key":"e_1_3_2_53_2","unstructured":"Mahito Sugiyama and Karsten M. Borgwardt. 2013. Rapid Distance-based Outlier Detection via Sampling. 467\u2013475. Retrieved from https:\/\/proceedings.neurips.cc\/paper\/2013\/hash\/d296c101daa88a51f6ca8cfc1ac79b50-Abstract.html"},{"key":"e_1_3_2_54_2","volume-title":"ISTR - Financial Threats Review 2017","year":"2017","unstructured":"Symantec. 2017. ISTR - Financial Threats Review 2017. Retrieved from https:\/\/docs.broadcom.com\/doc\/istr-financial-threats-review-2017-en"},{"key":"e_1_3_2_55_2","volume-title":"2nd International Conference on Learning Representations","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In 2nd International Conference on Learning Representations, Yoshua Bengio and Yann LeCun (Eds.). Retrieved from http:\/\/arxiv.org\/abs\/1312.6199"},{"key":"e_1_3_2_56_2","unstructured":"Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian J. Goodfellow and Rob Fergus. 2014. Intriguing Properties of Neural Networks. Retrieved from http:\/\/arxiv.org\/abs\/1312.6199"},{"key":"e_1_3_2_57_2","volume-title":"Annual Conference on Neural Information Processing Systems","author":"Tram\u00e8r Florian","year":"2020","unstructured":"Florian Tram\u00e8r, Nicholas Carlini, Wieland Brendel, and Aleksander Madry. 2020. On adaptive attacks to adversarial example defenses. In Annual Conference on Neural Information Processing Systems, Hugo Larochelle, Marc\u2019Aurelio Ranzato, Raia Hadsell, Maria-Florina Balcan, and Hsuan-Tien Lin (Eds.). Retrieved from https:\/\/proceedings.neurips.cc\/paper\/2020\/hash\/11f38f8ecd71867b42433548d1078e38-Abstract.html"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/BigDataSecurity-HPSC-IDS.2016.79"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10618-008-0116-z"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICNSC.2018.8361343"},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCEA50009.2020.00122"}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3613244","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3613244","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:46:18Z","timestamp":1750178778000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3613244"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,14]]},"references-count":61,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,11,30]]}},"alternative-id":["10.1145\/3613244"],"URL":"https:\/\/doi.org\/10.1145\/3613244","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"value":"2471-2566","type":"print"},{"value":"2471-2574","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,10,14]]},"assertion":[{"value":"2023-01-04","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-07-25","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-10-14","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}