Appearance
7-Signal Scoring Model & Mathematical Formulation
Engine File:
anant-engine/src/graph/MuleScorer.cpp
Theoretical Framework: Bayesian Noisy-OR Causal Gates + Two-Stage Calibrated AML Ranking
Scoring Model Flowchart

Why Bayesian Noisy-OR Fusion (Over Linear Weighting)?
In traditional anti-money laundering (AML) architectures, risk scores are computed as linear weighted sums:
The Fatal Flaw of Linear Models in Cyber-Fraud
Consider a sophisticated money mule:
- 100% of outgoing funds are converted to Binance/P2P crypto.
- Operates exclusively from a Russian/Cambodian bulletproof proxy (
185.220.x.x). - Connects through an automated headless script emulator (
Linux_Script). - However, because the account was rented only recently, it has an average transaction count, balanced fan degree, and moderate velocity.
In a linear weighting model, the low or zero values of other signals mathematically dilute the decisive cyber and terminal indicators. The account receives a mediocre score (e.g. 42 / 100) and escapes automated police freezing orders.
The Noisy-OR Solution
In causal probabilistic graph modeling, distinct behavioral anomalies represent independent causal fraud mechanisms. If any strong indicator is definitively activated, the probability of the account being a laundering conduit surges toward certainty.
Mathematically, we model the survival probability
The probability of fraud is the complement of innocence:
Where:
is the normalized probability output by Signal . is the empirical reliability weight assigned to Signal .
The 7 Behavioral & Structural Signals
Summary Weights Matrix
| Signal | Mathematical Symbol | Weight ( | Category | Core Behavior Captured |
|---|---|---|---|---|
| Terminal Cash-Out Ratio | 0.35 | Strong | Percentage of funds diverted into Crypto/P2P/ATM cashouts | |
| Cyber Automation Fingerprint | 0.35 | Strong | Non-human browser automation (emulators) & offshore IPs | |
| Turnover Conservation Ratio | 0.30 | Strong | Symmetrical pass-through ratio ( | |
| Temporal Velocity | 0.20 | Medium | Continuous exponential decay matching of transfers in | |
| Dormancy Burst Index | 0.15 | Medium | Sleeper accounts with sudden spikes or | |
| Counterparty Asymmetry | 0.10 | Contextual | Bipartite disjointness between sender set and receiver set | |
| Structural Fan Pattern | 0.10 | Contextual | Degree product and relay fan balance with merchant suppression |
Detailed Mathematical Formulations
1. Turnover Conservation Ratio ( )
- Concept: Legitimate retail customers retain funds, save money, or draw balances gradually. Mule accounts act as flow-through conduits: money entered must leave rapidly, leaving near-zero residual balance.
- Formula:
- Characteristics: The steep sigmoid ensures accounts with retention ratio
yield near , while accounts with pass-through ramp up to .
2. Terminal Cash-Out Ratio ( )
- Concept: Money laundering syndicates exit formal banking into irreversible, pseudonymous crypto exchange rails (P2P desks, USDT, Binance, OTC escrow).
- Extraction: Scans narration strings for keywords:
- Formula:
3. Cyber Automation Fingerprint ( )
- Concept: Syndicates run automated headless bot scripts (
Web_Emulator,Linux_Script) routed through offshore bulletproof proxy ranges (185.x.x.xand194.x.x.x). - Formula:
- Synergy Multiplier: If both script ratio and foreign IP ratio exceed
:
4. Multi-Window Temporal Velocity ( )
- Concept: Rapid fund transit. Stolen funds typically transit a mule node within 3 to 15 minutes before the victim can freeze their account.
- Algorithm (Continuous Bipartite Temporal Matching):
- For each incoming transaction
, scan subsequent outgoing transactions . - Search horizon:
(2-hour ceiling). - Exponential decay half-life
(30 minutes): - Amount match factor (rewards 1-to-1 matching while tolerating fee cuts):
- Combined score per transaction pair:
- Anti-Double-Counting: Uses an
out_usedbitmask so each outgoing transaction matches at most once. - Coverage Penalty:
- For each incoming transaction
5. Dormancy Burst Index ( )
- Concept: Mules are either burner throwaways (
hours active) or compromised sleeper accounts (dormant for weeks, then laundering a massive volume spike in 24 hours). - Formulation:
- Case 1: Disposable Burner Mule:
- Case 2: Sleeper Spike (
): Two-pointer sliding window computes maximum volume concentrated in any 24h window:
- Case 1: Disposable Burner Mule:
6. Counterparty Asymmetry ( )
- Concept: Legitimate business and social contacts have overlapping bipartite networks. Mules receive funds from victims/aggregators (Set
) and send forward to disjoint distributors/terminals (Set ), with zero overlap ( ). - Formula:
- High-Degree Guardrail: Only evaluated if
. High-volume commercial hubs naturally have disjoint sets, so this signal is excluded for high-degree accounts.
7. Structural Fan Pattern ( )
- Concept: Relay conduits exhibit balanced in/out degree with moderate degree products (smurfing multiplexing).
- Formula:
- Merchant Suppression: If
and the account has no script device, no foreign IP, and no terminal marker, is attenuated by ( ), completely shielding high-volume merchants.
The Calibrated Two-Stage AML Gate Pipeline
To guarantee 100% recall on fraud mules and 0% false positives on clean citizens, the engine executes a calibrated two-stage gate:
┌──────────────────────────────────────────────┐
│ Compute Base Flow Evidence: │
│ flow_evidence = 0.40·P_pt + 0.40·P_term │
│ + 0.20·P_cyber │
└──────────────────────┬───────────────────────┘
│
▼
/────────────────────────────────────────\
< (P_cyber > 0.05) OR (P_terminal > 0.05) >
\────────────────────────────────────────/
/ \
YES / \ NO
▼ ▼
┌────────────────────────────┐ ┌───────────────────────────┐
│ GATE 1: FRAUD TRACK │ │ GATE 2: CLEAN TRACK │
│ │ │ │
│ vol_factor = σ(log10(vol)) │ │ Score = clamp( │
│ rank_factor = 0.35·flow │ │ flow_evidence · 25, │
│ + 0.30·P_cyber │ │ 0, 28 │
│ + 0.20·P_terminal │ │ ) │
│ + 0.15·vol_factor │ │ │
│ │ │ Output: 0.0 – 28.0 │
│ Score = 72.0 + │ │ (Zero citizen freezes) │
│ clamp(rank,0,1) · 26.5 │ └───────────────────────────┘
│ │
│ Output: 72.0 – 98.5 │
└────────────────────────────┘Numerical Stability Guardrails
- Overshoot Clamping: All signal probabilities are strictly clamped to
before computing powers, preventing negative bases in . - Boundary Saturation Early-Exit: If any signal achieves
, survival probability instantly collapses to and breaks out of the loop early, bypassing fractional power computation. - Fail-Safe NaN Protection: If an arithmetic division anomaly produces an IEEE-754
NaN, the engine defaultsmule_probto(Score = ), ensuring suspicious edge cases are flagged for manual police audit rather than escaping silently.