Skip to content

7-Signal Scoring Model & Mathematical Formulation ​

Engine File: anant-engine/src/graph/MuleScorer.cpp
Theoretical Framework: Bayesian Noisy-OR Causal Gates + Two-Stage Calibrated AML Ranking


Scoring Model Flowchart ​

7-Signal Bayesian Scoring Architecture


Why Bayesian Noisy-OR Fusion (Over Linear Weighting)? ​

In traditional anti-money laundering (AML) architectures, risk scores are computed as linear weighted sums:

Score=∑i=1nwi⋅Si

The Fatal Flaw of Linear Models in Cyber-Fraud ​

Consider a sophisticated money mule:

  • 100% of outgoing funds are converted to Binance/P2P crypto.
  • Operates exclusively from a Russian/Cambodian bulletproof proxy (185.220.x.x).
  • Connects through an automated headless script emulator (Linux_Script).
  • However, because the account was rented only recently, it has an average transaction count, balanced fan degree, and moderate velocity.

In a linear weighting model, the low or zero values of other signals mathematically dilute the decisive cyber and terminal indicators. The account receives a mediocre score (e.g. 42 / 100) and escapes automated police freezing orders.

The Noisy-OR Solution ​

In causal probabilistic graph modeling, distinct behavioral anomalies represent independent causal fraud mechanisms. If any strong indicator is definitively activated, the probability of the account being a laundering conduit surges toward certainty.

Mathematically, we model the survival probability Survive (the probability that the account is innocent across all observed signals):

Survive=∏i=17(1−Pi)wi

The probability of fraud is the complement of innocence:

Pmule=1−Survive=1−∏i=17(1−Pi)wiMule Score=100×Pmule∈[0.0,100.0]

Where:

  • Pi∈[0.0,1.0] is the normalized probability output by Signal i.
  • wi>0 is the empirical reliability weight assigned to Signal i.

The 7 Behavioral & Structural Signals ​

Summary Weights Matrix ​

SignalMathematical SymbolWeight (wi)CategoryCore Behavior Captured
Terminal Cash-Out RatioPterminal0.35StrongPercentage of funds diverted into Crypto/P2P/ATM cashouts
Cyber Automation FingerprintPcyber0.35StrongNon-human browser automation (emulators) & offshore IPs
Turnover Conservation RatioPturnover0.30StrongSymmetrical pass-through ratio (min/max volume balance)
Temporal VelocityPvelocity0.20MediumContinuous exponential decay matching of transfers in <30 mins
Dormancy Burst IndexPburst0.15MediumSleeper accounts with sudden spikes or <24h throwaways
Counterparty AsymmetryPasymmetry0.10ContextualBipartite disjointness between sender set and receiver set
Structural Fan PatternPfan0.10ContextualDegree product and relay fan balance with merchant suppression

Detailed Mathematical Formulations ​

1. Turnover Conservation Ratio (Pturnover) ​

  • Concept: Legitimate retail customers retain funds, save money, or draw balances gradually. Mule accounts act as flow-through conduits: money entered must leave rapidly, leaving near-zero residual balance.
  • Formula:TCR=min(Total Outflow,Total Inflow)max(Total Outflow,Total Inflow)Pturnover=σ(TCR,μ=0.85,s=15.0)=11+exp⁡(−15.0×(TCR−0.85))
  • Characteristics: The steep sigmoid ensures accounts with retention ratio <70% yield near 0.0, while accounts with pass-through >90% ramp up to 0.80−1.00.

2. Terminal Cash-Out Ratio (Pterminal) ​

  • Concept: Money laundering syndicates exit formal banking into irreversible, pseudonymous crypto exchange rails (P2P desks, USDT, Binance, OTC escrow).
  • Extraction: Scans narration strings for keywords:is_terminal=Narration LIKE (′%CRYPTO%′∨′%P2P%′∨′%WALLET%′∨′%USDT%′∨′%BINANCE%′∨′%OTC%′)
  • Formula:Pterminal={∑t∈OutterminalAmount(t)Total Outflowif Total Outflow>00.0otherwise

3. Cyber Automation Fingerprint (Pcyber) ​

  • Concept: Syndicates run automated headless bot scripts (Web_Emulator, Linux_Script) routed through offshore bulletproof proxy ranges (185.x.x.x and 194.x.x.x).
  • Formula:script_ratio=Count(txns with Device∈{’Web_Emulator’,’Linux_Script’})Total Txn Countforeign_ratio=Count(txns with IP∈{185.∗,194.∗})Total Txn CountPcyber_base=max(script_ratio,foreign_ratio)
  • Synergy Multiplier: If both script ratio and foreign IP ratio exceed 40%:Pcyber={min(1.0,Pcyber_base×1.25)if script_ratio>0.4∧foreign_ratio>0.4Pcyber_baseotherwise

4. Multi-Window Temporal Velocity (Pvelocity) ​

  • Concept: Rapid fund transit. Stolen funds typically transit a mule node within 3 to 15 minutes before the victim can freeze their account.
  • Algorithm (Continuous Bipartite Temporal Matching):
    1. For each incoming transaction tin=(Ain,τin), scan subsequent outgoing transactions tout=(Aout,τout).
    2. Search horizon: Δt=τout−τin∈[0,7200 s] (2-hour ceiling).
    3. Exponential decay half-life τhalf=1800.0 s (30 minutes):time_score=exp⁡(−Δt1800.0)
    4. Amount match factor (rewards 1-to-1 matching while tolerating fee cuts):amount_match=max(0.0,1.0−|Aout−Ain|max(Ain,1.0))
    5. Combined score per transaction pair:score=time_score×(0.3+0.7×amount_match)
    6. Anti-Double-Counting: Uses an out_used bitmask so each outgoing transaction matches at most once.
    7. Coverage Penalty:coverage=Matched VolumeTotal InflowPvelocity=(∑score×AinMatched Volume)×min(1.0,coverage0.60)

5. Dormancy Burst Index (Pburst) ​

  • Concept: Mules are either burner throwaways (<24 hours active) or compromised sleeper accounts (dormant for weeks, then laundering a massive volume spike in 24 hours).
  • Formulation:
    • Case 1: Disposable Burner Mule:Span=last_seen−first_seenIf Span≤86,400 s (24h)∧Txns≥3⟹Pburst=0.70
    • Case 2: Sleeper Spike (Span≥7 days): Two-pointer sliding window computes maximum volume concentrated in any 24h window:peak_24h=maxt∑t≤τi≤t+86400AmountiPburst=σ(peak_24hTotal Volume,μ=0.60,s=10.0)

6. Counterparty Asymmetry (Pasymmetry) ​

  • Concept: Legitimate business and social contacts have overlapping bipartite networks. Mules receive funds from victims/aggregators (Set S) and send forward to disjoint distributors/terminals (Set R), with zero overlap (S∩R=∅).
  • Formula:J(S,R)=|S∩R||S∪R|Pasymmetry=(1.0−J(S,R))×0.5
  • High-Degree Guardrail: Only evaluated if (in_degree+out_degree)≤40. High-volume commercial hubs naturally have disjoint sets, so this signal is excluded for high-degree accounts.

7. Structural Fan Pattern (Pfan) ​

  • Concept: Relay conduits exhibit balanced in/out degree with moderate degree products (smurfing multiplexing).
  • Formula:fan_balance=min(in_deg,out_deg)max(in_deg,out_deg)degree_prod=in_deg×out_degdegree_sig=σ(degree_prod,μ=4.0,s=0.5)Pfan=degree_sig×fan_balance
  • Merchant Suppression: If in_degree>30∧out_degree>30 and the account has no script device, no foreign IP, and no terminal marker, Pfan is attenuated by 90% (Pfan←Pfan×0.10), completely shielding high-volume merchants.

The Calibrated Two-Stage AML Gate Pipeline ​

To guarantee 100% recall on fraud mules and 0% false positives on clean citizens, the engine executes a calibrated two-stage gate:

                  ┌──────────────────────────────────────────────┐
                  │ Compute Base Flow Evidence:                  │
                  │ flow_evidence = 0.40·P_pt + 0.40·P_term      │
                  │               + 0.20·P_cyber                 │
                  └──────────────────────┬───────────────────────┘
                                         │
                                         ▼
                     /────────────────────────────────────────\
                    <  (P_cyber > 0.05) OR (P_terminal > 0.05) >
                     \────────────────────────────────────────/
                                    /          \
                         YES       /            \      NO
                                  ▼              ▼
           ┌────────────────────────────┐    ┌───────────────────────────┐
           │     GATE 1: FRAUD TRACK    │    │    GATE 2: CLEAN TRACK    │
           │                            │    │                           │
           │ vol_factor = σ(log10(vol)) │    │ Score = clamp(            │
           │ rank_factor = 0.35·flow    │    │   flow_evidence · 25,     │
           │   + 0.30·P_cyber           │    │   0, 28                   │
           │   + 0.20·P_terminal        │    │ )                         │
           │   + 0.15·vol_factor        │    │                           │
           │                            │    │ Output: 0.0 – 28.0        │
           │ Score = 72.0 +             │    │ (Zero citizen freezes)    │
           │   clamp(rank,0,1) · 26.5   │    └───────────────────────────┘
           │                            │
           │ Output: 72.0 – 98.5        │
           └────────────────────────────┘

Numerical Stability Guardrails ​

  1. Overshoot Clamping: All signal probabilities are strictly clamped to [0.0,1.0] before computing powers, preventing negative bases in std::pow.
  2. Boundary Saturation Early-Exit: If any signal achieves p≥1.0, survival probability instantly collapses to 0.0 and breaks out of the loop early, bypassing fractional power computation.
  3. Fail-Safe NaN Protection: If an arithmetic division anomaly produces an IEEE-754 NaN, the engine defaults mule_prob to 1.0 (Score = 100.0), ensuring suspicious edge cases are flagged for manual police audit rather than escaping silently.

Project Anant — Advanced Financial Forensics & High-Throughput AML Analytics