A Differentially Private Diffusion Model-based Anomaly Detection System
Open Access DepositedAlthough Fraud detection has significantly improved in recent years, many current models do not prioritize user privacy. As a result, the security of sensitive financial information remains at risk. In response to these limitations, this study introduces a differentially private diffusion model (DPDM) designed for strong classification accuracy and protecting user privacy in large transactional datasets. Our differentially private diffusion model is trained on nonfraudulent transactions with formal differential privacy guarantees. After training, fraudulent transactions are identified using a threshold calculated from the mean and standard deviation of the reconstruction errors. This threshold allows for dynamic adjustments based on the data distribution. The DPDM is benchmarked directly against a standard diffusion model. Additionally, the DPDM is benchmarked indirectly against extreme gradient boosting and support vector machine classifiers. The results of the DPDM for anomaly detection demonstrate remarkable performance
99.98% accuracy, 99.67% recall, a 99.84% F1-score, a 99.93% area under the receiver operating characteristic curve (AUROC), a 0.0033 false negative rate, and a 0.0000 false positive rate. In addition to this, the model’s privacy leakage is assessed through membership inference attacks (MIA) under formal differential privacy, using a nonprivate diffusion model as the baseline. The MIA is performed on the DPDM, which has been trained with a privacy budget of ε =0.105. As a result, the DPDM demonstrates strong privacy guarantees with MIA AUC scores near 0.5. Although the DPDM demonstrates robust privacy protection at lower privacy budgets, its effectiveness decreases as the privacy budget increases. Unlike a probabilistic classifier, our DPDM utilizes a distribution aware thresholding mechanism, therefore, consistently demonstrating high performance even under substantial levels of differential privacy noise. The proposed model performs robustly while mitigating privacy risks. Thus, the proposed model sets the foundation for fraud detection in privacy sensitive domains.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.