[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-120833-en":3,"doc-seo-120833-105":31,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},120833,16904993612988,"Olivia Brown","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","A machine learning-based framework for anomaly detection - Thesis accepted","Fraudsters increasingly exploit modern technology and digital payment systems, making anomalous behaviour harder to identify with narrow, fragmented detection methods. A machine learning-based anomaly detection framework is proposed to combine multiple approaches in transactional settings through a unified pipeline. The method uses neural architecture search across candidate autoencoders, evaluates models with thresholding via a balanced score, and applies Gaussian scaling to normalise anomaly scores to [0,1]. Network-based features are added using social network analysis, with Shapley values quantifying contributions, and a self-organising map uncovering anomalous clusters and feature contributions, followed by visual and what-if analysis for sensitivity testing, implemented and validated on real transactional data to improve anomaly detection.","A machine learning-based framework for  \nanomaly detection  \nRS Ball  \n [orcid.org](orcid.org/0000-0001-7076-6157)[/](orcid.org/0000-0001-7076-6157)[0000-0001-7076-6157](orcid.org/0000-0001-7076-6157)  \nThesis accepted in fulfilment of the requirements for the degree  \nDoctor of Philosophy in Computer and Information Sciences with Computer Science and Information Systems at the North  \nWest University  \nPromoter: Prof HA Krüger  \nCo-promoter: Prof L Drevin  \nGraduation May 2023  \n35484446  \nAcknowledgements  \nFirstly, I would like to thank my Promoter, Prof Hennie Kruger, as well as my Copromoter, Prof Lynette Drevin, for their tireless e✛orts and support of this study. I am extremely grateful for Prof Kruger✬s willingness to revise countless versions of this work. This study would not have been possible without his endless guidance and support.  \nI would also like to thank my family for all their patience with and support of my studies, especially my wife, Ricki-lee, my son, Carter, and my daughter, Mila. Thankyou for allowing me to undertake this commitment. I love you all very much.  \nLastly, I✬d like to thank my parents; my father, Richard, and my mother, Lynette, for instilling in me the importance of a good education. Thank you for all your sacri✜cesand support over the years.  \nAbstract  \nWith the expansion of modern technology and the increased adoption of digital payment methods, fraudsters are becoming more sophisticated in their approach. Organisations attempting to mitigate fraudulent attacks can leverage their data to drive systems dedicated to detecting anomalous behaviour. Unfortunately, the techniques used to detect anomalies are often fragmented, focussing on solving a very speci✜c detection problem. In this study, a machine learning-based framework for anomaly detection is proposed that aims to combine multiple machine learning approaches to detect anomalies in transactional systems.  \nThe proposed framework includes a uni✜ed approach for combining aspects of the anomaly detection process into a singular pipeline. The approach begins with a neural architecture search, where multiple candidate autoencoder architectures are randomly simulated to determine an optimal architecture con✜guration. An optimal architecture is determined by evaluating each model with a proposed thresholding algorithm, which calculates the optimal threshold, using a balanced score. The output of the optimal architecture is then transformed from raw anomaly scores into a more manageable score in the range [0,1] through the application of Gaussian scaling. This approach is validated on a public data set for illustration purposes, followed by the application of the approach to a real-world transactional data set.  \nSocial network analysis is then introduced to the study, by taking network data and calculating network metrics to generate a feature set for augmenting the initial realworld transactional features. These network metrics capture the behaviours that link users together within a transactional system. Computing the Shapley values of the autoencoder output returns the feature contribution of the network metrics to determine their impact on the model✬s ability to detect anomalies. The combined network metrics and transactional feature set are then used to train a self-organising map to surface clusters of anomalous activity not detectable through the autoencoder, as well as to provide an additional approach to feature contribution through the exploration of the anomalous cluster weights.  \nFinally, the various modelling approaches are combined into a proposed anomaly detection framework. The framework includes aspects of visual analysis and whatif analysis, which provides practitioners with an interface to analyse the outputs of the various machine learning techniques and to perform sensitivity analysis by inputting various classi✜cation costs and conducting threshold changes. The ✜nal proposed framework was implemented in a real-wor","cbCaiawsKpkNa7BM","https://ap.wps.com/l/cbCaiawsKpkNa7BM","pdf",9822106,2,1,351,"English","en",105,"# Acknowledgements\n# Abstract\n# List of Figures\n# List of Tables\n# List of Algorithms\n# List of Acronyms\n# 1 Introduction and problem contextualisation\n## 1.1 Chapter introduction\n## 1.2 Research topics\n## 1.3 Problem statement and research question\n## 1.4 Research aims and objectives\n## 1.5 Data collection\n## 1.6 Computing environment\n## 1.7 Research methodology\n## 1.8 Ethical considerations\n## 1.9 Thesis layout and summary of contributions\n## 1.10 Chapter conclusion\n# 2 Literature review: Fraud and anomaly detection\n## 2.1 Chapter introduction\n## 2.2 Introduction to credit card","[{\"question\":\"What is the main goal of the proposed anomaly detection framework?\",\"answer\":\"To detect anomalous behaviour in transactional systems by combining multiple machine learning approaches into a unified pipeline, improving anomaly detection performance in fraud-related contexts.\"},{\"question\":\"How does the framework select and evaluate the autoencoder architecture?\",\"answer\":\"It performs neural architecture search by simulating candidate autoencoder architectures, then evaluates each model using a thresholding algorithm that calculates an optimal threshold via a balanced score.\"},{\"question\":\"What role do social network analysis and Shapley values play?\",\"answer\":\"Social network analysis derives network metrics to augment transactional features, and Shapley values are computed from the autoencoder output to measure each network metric’s feature contribution toward anomaly detection.\"}]","A machine learning-based framework for anomaly detection - Thesis accepted | PDF",1785732263,885,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":29},"a-machine-learning-based-framework-for-anomaly-detection-thesis-accepted","",{"@graph":37,"@context":86},[38,54,69],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,48,51],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":20},"https://docshare.wps.com/document/","Document",{"item":49,"name":12,"@type":44,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":44,"position":53},"https://docshare.wps.com/document/a-machine-learning-based-framework-for-anomaly-detection-thesis-accepted/120833/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":42,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05","2026-08-03",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What is the main goal of the proposed anomaly detection framework?","Question",{"text":76,"@type":77},"To detect anomalous behaviour in transactional systems by combining multiple machine learning approaches into a unified pipeline, improving anomaly detection performance in fraud-related contexts.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the framework select and evaluate the autoencoder architecture?",{"text":81,"@type":77},"It performs neural architecture search by simulating candidate autoencoder architectures, then evaluates each model using a thresholding algorithm that calculates an optimal threshold via a balanced score.",{"name":83,"@type":74,"acceptedAnswer":84},"What role do social network analysis and Shapley values play?",{"text":85,"@type":77},"Social network analysis derives network metrics to augment transactional features, and Shapley values are computed from the autoencoder output to measure each network metric’s feature contribution toward anomaly detection.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":47,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":47,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]