# Real-World Anomaly Detection for FinTech Transactions

## 1. Problem Statement
## 2. Dataset Loading and Exploration
## 3. Feature Engineering
## 4. Experiment 1: One-Class SVM (Failed)
## 5. Experiment 2: Autoencoder (Partially Successful)
## 6. Experiment 3: Isolation Forest (Final Model)
## 7. Model Comparison and Selection
## 8. Final Observations and Production Considerations


In [1]:
import pandas as pd

df = pd.read_csv("fraudTest.csv")
df.head()

Unnamed: 0.1,Unnamed: 0,trans_date_trans_time,cc_num,merchant,category,amt,first,last,gender,street,...,lat,long,city_pop,job,dob,trans_num,unix_time,merch_lat,merch_long,is_fraud
0,0,2020-06-21 12:14:25,2291163933867244,fraud_Kirlin and Sons,personal_care,2.86,Jeff,Elliott,M,351 Darlene Green,...,33.9659,-80.9355,333497,Mechanical engineer,1968-03-19,2da90c7d74bd46a0caf3777415b3ebd3,1371816865,33.986391,-81.200714,0
1,1,2020-06-21 12:14:33,3573030041201292,fraud_Sporer-Keebler,personal_care,29.84,Joanne,Williams,F,3638 Marsh Union,...,40.3207,-110.436,302,"Sales professional, IT",1990-01-17,324cc204407e99f51b0d6ca0055005e7,1371816873,39.450498,-109.960431,0
2,2,2020-06-21 12:14:53,3598215285024754,"fraud_Swaniawski, Nitzsche and Welch",health_fitness,41.28,Ashley,Lopez,F,9333 Valentine Point,...,40.6729,-73.5365,34496,"Librarian, public",1970-10-21,c81755dbbbea9d5c77f094348a7579be,1371816893,40.49581,-74.196111,0
3,3,2020-06-21 12:15:15,3591919803438423,fraud_Haley Group,misc_pos,60.05,Brian,Williams,M,32941 Krystal Mill Apt. 552,...,28.5697,-80.8191,54767,Set designer,1987-07-25,2159175b9efe66dc301f149d3d5abf8c,1371816915,28.812398,-80.883061,0
4,4,2020-06-21 12:15:17,3526826139003047,fraud_Johnston-Casper,travel,3.19,Nathan,Massey,M,5783 Evan Roads Apt. 465,...,44.2529,-85.017,1126,Furniture designer,1955-07-06,57ff021bd3f328f8738bb535c302a31b,1371816917,44.959148,-85.884734,0


In [3]:
df.shape
df.columns
df["is_fraud"].value_counts()


is_fraud
0    553574
1      2145
Name: count, dtype: int64

Observation:
- Dataset is highly imbalanced
- Fraud rate is less than 1%, which reflects real-world fintech scenarios
- This justifies the use of anomaly detection models


In [4]:
import pandas as pd

df = pd.read_csv("fraudTest.csv")

print(df.columns)

Index(['Unnamed: 0', 'trans_date_trans_time', 'cc_num', 'merchant', 'category',
       'amt', 'first', 'last', 'gender', 'street', 'city', 'state', 'zip',
       'lat', 'long', 'city_pop', 'job', 'dob', 'trans_num', 'unix_time',
       'merch_lat', 'merch_long', 'is_fraud'],
      dtype='object')


In [6]:
df = df.rename(columns={
    "trans_num": "transaction_id",
    "cc_num": "card_number",
    "trans_date_trans_time": "timestamp",
    "amt": "amount",
    "merchant": "merchant_id",
    "category": "merchant_category",
    "merch_lat": "merchant_lat",
    "merch_long": "merchant_long"
})


In [7]:
df["customer_id"] = ["CUST_" + str(i % 100000).zfill(5) for i in range(len(df))]

In [8]:
import hashlib

df["card_number"] = df["card_number"].astype(str).apply(
    lambda x: "CARD_" + hashlib.sha256(x.encode()).hexdigest()[:10]
)

In [9]:
df["timestamp"] = pd.to_datetime(df["timestamp"])

df["hour"] = df["timestamp"].dt.hour
df["day_of_week"] = df["timestamp"].dt.weekday
df["month"] = df["timestamp"].dt.month

In [11]:
import numpy as np
df["customer_lat"] = np.random.uniform(8.0, 37.0, len(df))
df["customer_long"] = np.random.uniform(68.0, 97.0, len(df))

In [12]:
from math import radians, sin, cos, sqrt, atan2

def haversine(lat1, lon1, lat2, lon2):
    R = 6371
    lat1, lon1, lat2, lon2 = map(radians, [lat1, lon1, lat2, lon2])
    dlat = lat2 - lat1
    dlon = lon2 - lon1
    a = sin(dlat/2)**2 + cos(lat1)*cos(lat2)*sin(dlon/2)**2
    return 2 * R * atan2(sqrt(a), sqrt(1-a))

df["distance_from_home"] = df.apply(
    lambda r: haversine(
        r["customer_lat"], r["customer_long"],
        r["merchant_lat"], r["merchant_long"]
    ),
    axis=1
)


In [13]:
conditions = [
    (df["is_fraud"] == 1) & (df["distance_from_home"] > 100),
    (df["is_fraud"] == 1) & (df["amount"] > 100000),
    (df["is_fraud"] == 1)
]

choices = [
    "account_takeover",
    "card_cloning",
    "merchant_collusion"
]

df["fraud_type"] = np.select(conditions, choices, default="none")

In [14]:
df = df[[
    "transaction_id",
    "customer_id",
    "card_number",
    "timestamp",
    "amount",
    "merchant_id",
    "merchant_category",
    "merchant_lat",
    "merchant_long",
    "is_fraud",
    "fraud_type",
    "hour",
    "day_of_week",
    "month",
    "distance_from_home"
]]


In [15]:
print(df.columns)
print(df.head())

Index(['transaction_id', 'customer_id', 'card_number', 'timestamp', 'amount',
       'merchant_id', 'merchant_category', 'merchant_lat', 'merchant_long',
       'is_fraud', 'fraud_type', 'hour', 'day_of_week', 'month',
       'distance_from_home'],
      dtype='object')
                     transaction_id customer_id      card_number  \
0  2da90c7d74bd46a0caf3777415b3ebd3  CUST_00000  CARD_cc6c29f3a6   
1  324cc204407e99f51b0d6ca0055005e7  CUST_00001  CARD_b47e8dca60   
2  c81755dbbbea9d5c77f094348a7579be  CUST_00002  CARD_9abc4462b4   
3  2159175b9efe66dc301f149d3d5abf8c  CUST_00003  CARD_66e686f7ff   
4  57ff021bd3f328f8738bb535c302a31b  CUST_00004  CARD_551125038a   

            timestamp  amount                           merchant_id  \
0 2020-06-21 12:14:25    2.86                 fraud_Kirlin and Sons   
1 2020-06-21 12:14:33   29.84                  fraud_Sporer-Keebler   
2 2020-06-21 12:14:53   41.28  fraud_Swaniawski, Nitzsche and Welch   
3 2020-06-21 12:15:15   60.05       

In [16]:
print(df.shape)

(555719, 15)
