{ "cells": [ { "cell_type": "markdown", "metadata": {}, "source": [ "# Generating synthetic payments data\n", "\n", "In this notebook, we'll build up a very simple simulator to generate payments data corresponding to legitimate and fraudulent transactions. (There are many ways you could improve this generator and we'll call some of them out.) We'll start by building up some functionality to run simulations in general.\n", "\n", "## An (extremely) basic discrete-event simulation framework\n", "\n", "The next function is all you need to run simple discrete-event simulations. Here's how to use it:\n", "\n", "- you'll define several streams of events, each of which is modeled by a Python generator,\n", "- each event stream generator will `yield` a tuple consisting of *an offset* (the amount of time that has passed since the last event of that type) and *a result* (an arbitrary Python value associated with the event),\n", "- the generator produced by the `simulate` function will yield the next event from all event streams indefinitely." ] }, { "cell_type": "code", "execution_count": 1, "metadata": {}, "outputs": [], "source": [ "import heapq\n", "\n", "def simulate(event_generators, initial_time=0):\n", " pq = []\n", " for event in event_generators:\n", " offset, result = next(event)\n", " heapq.heappush(pq, (offset + initial_time, result, event))\n", " \n", " while True:\n", " timestamp, result, event = heapq.heappop(pq)\n", " offset, next_result = next(event)\n", " heapq.heappush(pq, (timestamp + offset, next_result, event))\n", " yield (timestamp, result)" ] }, { "cell_type": "markdown", "metadata": {}, "source": [ "It may be easier to see how this works with an example. In the next three cells, we \n", "\n", "1. define a generator for event streams, which samples interarrival times from a Poisson distribution and returns a predefined string as the result at each event,\n", "2. set up a simulation with four streams, each of which has a different distribution of interarrival times and value, and\n", "3. take the first twenty events from the simulation" ] }, { "cell_type": "code", "execution_count": 2, "metadata": {}, "outputs": [], "source": [ "from scipy import stats\n", "\n", "def bedrockstream(mu, name):\n", " while True:\n", " offset, = stats.poisson.rvs(mu, size=1)\n", " yield (offset, name)" ] }, { "cell_type": "code", "execution_count": 3, "metadata": {}, "outputs": [], "source": [ "sim = simulate([bedrockstream(10, \"fred\"), \n", " bedrockstream(12, \"betty\"), \n", " bedrockstream(20, \"wilma\"), \n", " bedrockstream(35, \"barney\")])" ] }, { "cell_type": "code", "execution_count": 4, "metadata": { "scrolled": true }, "outputs": [ { "name": "stdout", "output_type": "stream", "text": [ "(9, 'fred')\n", "(12, 'betty')\n", "(13, 'fred')\n", "(22, 'betty')\n", "(22, 'wilma')\n", "(26, 'barney')\n", "(30, 'betty')\n", "(32, 'fred')\n", "(40, 'betty')\n", "(40, 'wilma')\n", "(41, 'fred')\n", "(48, 'fred')\n", "(53, 'betty')\n", "(60, 'fred')\n", "(63, 'betty')\n", "(65, 'wilma')\n", "(69, 'barney')\n", "(73, 'betty')\n", "(76, 'fred')\n", "(87, 'betty')\n" ] } ], "source": [ "for i in range(20):\n", " print(next(sim))" ] }, { "cell_type": "markdown", "metadata": {}, "source": [ "## Modeling transactions\n", "\n", "The first problem we have to do is to decide what data we'll generate for each transaction. Some interesting possibilities include:\n", "\n", "- user ID\n", "- merchant ID\n", "- merchant type\n", "- transaction amount (assuming a single currency)\n", "- card entry mode (e.g., contactless, chip and pin, swipe, card manually keyed, or online transaction)\n", "- foreign transaction (whether or not the user's home country matches the country in which the transaction is taking place)\n", "\n", "We'll also generate a label for each transaction (`legitimate` or `fraud`). We'll start with a very basic user event stream generator: all of the transactions we generate will be legitimate, and we won't do anything particularly interesting with most of the fields." ] }, { "cell_type": "code", "execution_count": 5, "metadata": {}, "outputs": [], "source": [ "import numpy as np\n", "MERCHANT_COUNT = 20000\n", "\n", "# a small percentage of merchants account for most transactions\n", "COMMON_MERCHANT_COUNT = MERCHANT_COUNT // 21\n", "\n", "common_merchants = np.random.choice(MERCHANT_COUNT, \n", " size=COMMON_MERCHANT_COUNT, \n", " replace=True)\n", "\n", "def basic_user_stream(user_id, mu):\n", " favorite_merchants = np.random.choice(common_merchants,\n", " size=len(common_merchants) // 5)\n", " while True:\n", " amount = 100.00\n", " entry = \"chip_and_pin\"\n", " foreign = False\n", " \n", " merchant_id, = np.random.choice(favorite_merchants, size=1)\n", " offset, = stats.poisson.rvs(mu, size=1)\n", " result = {\n", " \"user_id\": user_id,\n", " \"amount\": amount,\n", " \"merchant_id\": merchant_id,\n", " \"entry\": entry,\n", " \"foreign\": foreign\n", " }\n", " yield (offset, (\"legitimate\", *result.values()))" ] }, { "cell_type": "code", "execution_count": 6, "metadata": {}, "outputs": [], "source": [ "sim = simulate([basic_user_stream(1, 700), basic_user_stream(2, 105), basic_user_stream(3, 40)])" ] }, { "cell_type": "code", "execution_count": 7, "metadata": {}, "outputs": [ { "name": "stdout", "output_type": "stream", "text": [ "(43, ('legitimate', 3, 100.0, 12937, 'chip_and_pin', False))\n", "(85, ('legitimate', 3, 100.0, 12531, 'chip_and_pin', False))\n", "(104, ('legitimate', 2, 100.0, 9627, 'chip_and_pin', False))\n", "(133, ('legitimate', 3, 100.0, 11515, 'chip_and_pin', False))\n", "(176, ('legitimate', 3, 100.0, 3011, 'chip_and_pin', False))\n", "(218, ('legitimate', 2, 100.0, 19708, 'chip_and_pin', False))\n", "(221, ('legitimate', 3, 100.0, 17109, 'chip_and_pin', False))\n", "(259, ('legitimate', 3, 100.0, 8559, 'chip_and_pin', False))\n", "(310, ('legitimate', 3, 100.0, 842, 'chip_and_pin', False))\n", "(323, ('legitimate', 2, 100.0, 18709, 'chip_and_pin', False))\n", "(347, ('legitimate', 3, 100.0, 2361, 'chip_and_pin', False))\n", "(396, ('legitimate', 3, 100.0, 2589, 'chip_and_pin', False))\n", "(431, ('legitimate', 2, 100.0, 19497, 'chip_and_pin', False))\n", "(435, ('legitimate', 3, 100.0, 11085, 'chip_and_pin', False))\n", "(460, ('legitimate', 3, 100.0, 14329, 'chip_and_pin', False))\n", "(498, ('legitimate', 3, 100.0, 16310, 'chip_and_pin', False))\n", "(533, ('legitimate', 2, 100.0, 18873, 'chip_and_pin', False))\n", "(537, ('legitimate', 3, 100.0, 7115, 'chip_and_pin', False))\n", "(579, ('legitimate', 3, 100.0, 16801, 'chip_and_pin', False))\n", "(620, ('legitimate', 3, 100.0, 5686, 'chip_and_pin', False))\n" ] } ], "source": [ "for i in range(20):\n", " print(next(sim))" ] }, { "cell_type": "markdown", "metadata": {}, "source": [ "## Exercise: some quick improvements\n", "\n", "1. Users don't always just buy things from a few favorite merchants. Change `basic_user_stream` so that they occasionally buy from any merchant.\n", "2. Most people buy many inexpensive things and relatively few expensive things. Use this insight to generate (more) realistic transaction amounts.\n", "3. Some small percentage of online sales will be foreign transactions. When a user is traveling abroad, nearly all of his or her transactions will be foreign transactions. Add some state to `basic_user_stream` to model occasional international travel." ] }, { "cell_type": "markdown", "metadata": {}, "source": [ "## Building a better transaction stream\n", "\n", "We'll start by building a generator to build a mixture model we can use to make several kinds of transactions: small, medium, and large." ] }, { "cell_type": "code", "execution_count": 8, "metadata": {}, "outputs": [], "source": [ "def transaction_amounts(means, percentages, distribution=None):\n", " size = 256\n", " \n", " if distribution is None:\n", " distribution = lambda m, sz: stats.gamma.rvs(a=1.1, scale=min(m, 750), loc=m, size=sz)\n", " \n", " while True:\n", " streams = [distribution(m * 100, size) for m in means]\n", " stream = np.floor(np.choose(np.random.choice(len(means), p=percentages, size=size), streams)) / 100\n", " \n", " yield from stream" ] }, { "cell_type": "code", "execution_count": 9, "metadata": {}, "outputs": [ { "data": { "text/plain": [ "array([1., 2., 3.])" ] }, "execution_count": 9, "metadata": {}, "output_type": "execute_result" } ], "source": [ "a = np.array([1.1,2.1,3.5])\n", "np.floor(a)" ] }, { "cell_type": "markdown", "metadata": {}, "source": [ "Let's plot a histogram of some simulated transaction amounts sampled from three distributions with means corresponding to three kinds of purchases: a latte, take-out for lunch, and a pair of Levi's." ] }, { "cell_type": "code", "execution_count": 10, "metadata": {}, "outputs": [ { "data": { "application/javascript": [ "var spec = {\"config\": {\"view\": {\"width\": 400, \"height\": 300}, \"mark\": {\"tooltip\": null}}, \"data\": {\"url\": \"altair-data-47347fa42bcb1dbb2e27c10723e8f3a7.json\", \"format\": {\"type\": \"json\"}}, \"mark\": \"bar\", \"encoding\": {\"x\": {\"type\": \"quantitative\", \"bin\": {\"maxbins\": 100}, \"field\": \"amounts\"}, \"y\": {\"type\": \"quantitative\", \"aggregate\": \"count\"}}, \"$schema\": \"https://vega.github.io/schema/vega-lite/v3.4.0.json\"};\n", "var opt = {};\n", "var type = \"vega-lite\";\n", "var id = \"b26bae69-2d22-4cf3-95e3-923754f7dc1e\";\n", "\n", "var output_area = this;\n", "\n", "require([\"nbextensions/jupyter-vega/index\"], function(vega) {\n", " var target = document.createElement(\"div\");\n", " target.id = id;\n", " target.className = \"vega-embed\";\n", "\n", " var style = document.createElement(\"style\");\n", " style.textContent = [\n", " \".vega-embed .error p {\",\n", " \" color: firebrick;\",\n", " \" font-size: 14px;\",\n", " \"}\",\n", " ].join(\"\\\\n\");\n", "\n", " // element is a jQuery wrapped DOM element inside the output area\n", " // see http://ipython.readthedocs.io/en/stable/api/generated/\\\n", " // IPython.display.html#IPython.display.Javascript.__init__\n", " element[0].appendChild(target);\n", " element[0].appendChild(style);\n", "\n", " vega.render(\"#\" + id, spec, type, opt, output_area);\n", "}, function (err) {\n", " if (err.requireType !== \"scripterror\") {\n", " throw(err);\n", " }\n", "});\n" ], "text/plain": [ "<vega.vegalite.VegaLite at 0x1a22144940>" ] }, "metadata": { "jupyter-vega": "#b26bae69-2d22-4cf3-95e3-923754f7dc1e" }, "output_type": "display_data" }, { "data": { "text/plain": [] }, "execution_count": 10, "metadata": {}, "output_type": "execute_result" }, { "data": { "image/png": "" }, "metadata": { "jupyter-vega": "#b26bae69-2d22-4cf3-95e3-923754f7dc1e" }, "output_type": "display_data" } ], "source": [ "import pandas as pd\n", "\n", "import altair as alt\n", "alt.renderers.enable('notebook')\n", "alt.data_transformers.enable('json')\n", "\n", "amt = transaction_amounts([5, 15, 50], [0.5, 0.35, 0.15])\n", "amounts = [next(amt) for i in range(80000)]\n", "\n", "source = pd.DataFrame({\"amounts\": amounts})\n", "\n", "alt.Chart(source).mark_bar().encode(\n", " alt.X(\"amounts\", bin=alt.Bin(maxbins=100)),\n", " y='count()'\n", ")" ] }, { "cell_type": "markdown", "metadata": {}, "source": [ "We can also plot a broader distribution of transactions:" ] }, { "cell_type": "code", "execution_count": 11, "metadata": {}, "outputs": [ { "data": { "application/javascript": [ "var spec = {\"config\": {\"view\": {\"width\": 400, \"height\": 300}, \"mark\": {\"tooltip\": null}}, \"data\": {\"url\": \"altair-data-4ebf890e7ffb72c9c50f1b8de668d36a.json\", \"format\": {\"type\": \"json\"}}, \"mark\": \"bar\", \"encoding\": {\"x\": {\"type\": \"quantitative\", \"bin\": {\"maxbins\": 100}, \"field\": \"amounts\"}, \"y\": {\"type\": \"quantitative\", \"aggregate\": \"count\"}}, \"$schema\": \"https://vega.github.io/schema/vega-lite/v3.4.0.json\"};\n", "var opt = {};\n", "var type = \"vega-lite\";\n", "var id = \"539bf5d1-909a-4cf6-9154-c8da3b78dfb5\";\n", "\n", "var output_area = this;\n", "\n", "require([\"nbextensions/jupyter-vega/index\"], function(vega) {\n", " var target = document.createElement(\"div\");\n", " target.id = id;\n", " target.className = \"vega-embed\";\n", "\n", " var style = document.createElement(\"style\");\n", " style.textContent = [\n", " \".vega-embed .error p {\",\n", " \" color: firebrick;\",\n", " \" font-size: 14px;\",\n", " \"}\",\n", " ].join(\"\\\\n\");\n", "\n", " // element is a jQuery wrapped DOM element inside the output area\n", " // see http://ipython.readthedocs.io/en/stable/api/generated/\\\n", " // IPython.display.html#IPython.display.Javascript.__init__\n", " element[0].appendChild(target);\n", " element[0].appendChild(style);\n", "\n", " vega.render(\"#\" + id, spec, type, opt, output_area);\n", "}, function (err) {\n", " if (err.requireType !== \"scripterror\") {\n", " throw(err);\n", " }\n", "});\n" ], "text/plain": [ "<vega.vegalite.VegaLite at 0x1a225162b0>" ] }, "metadata": { "jupyter-vega": "#539bf5d1-909a-4cf6-9154-c8da3b78dfb5" }, "output_type": "display_data" }, { "data": { "text/plain": [] }, "execution_count": 11, "metadata": {}, "output_type": "execute_result" }, { "data": { "image/png": "" }, "metadata": { "jupyter-vega": "#539bf5d1-909a-4cf6-9154-c8da3b78dfb5" }, "output_type": "display_data" } ], "source": [ "amt = transaction_amounts([5, 10, 15, 20, 50, 100], \n", " [0.35, 0.25, 0.15, 0.1, 0.1, 0.05])\n", "amounts = [next(amt) for i in range(40000)]\n", "\n", "source = pd.DataFrame({\"amounts\": amounts})\n", "\n", "alt.Chart(source).mark_bar().encode(\n", " alt.X(\"amounts\", bin=alt.Bin(maxbins=100)),\n", " y='count()',\n", ")" ] }, { "cell_type": "markdown", "metadata": {}, "source": [ "Next up, we'll make a generator to create the entry types:" ] }, { "cell_type": "code", "execution_count": 12, "metadata": {}, "outputs": [], "source": [ "def legitimate_entry_types():\n", " size = 256\n", " \n", " entry_types = [\"contactless\", \"chip_and_pin\", \"swipe\", \"manual\", \"online\"]\n", " entry_probs = [0.25,0.2,0.15,0.05,0.35]\n", "\n", " while True:\n", " stream = [entry_types[i] for i in np.random.choice(len(entry_types), p=entry_probs, size=size)]\n", " yield from stream" ] }, { "cell_type": "markdown", "metadata": {}, "source": [ "...and one for selecting merchants (primarily a user's favorite merchants):" ] }, { "cell_type": "code", "execution_count": 13, "metadata": {}, "outputs": [], "source": [ "def merchant_stream(common_merchants, all_merchants, fav_percentage=0.2, probs=[0.6,0.37,0.03]):\n", " favorite_merchants = np.random.choice(common_merchants,\n", " size=int(len(common_merchants) * fav_percentage))\n", " merchants = [favorite_merchants, common_merchants, all_merchants]\n", " while True:\n", " pool = merchants[np.random.choice(len(merchants), p=probs)]\n", " yield int(np.random.choice(pool))" ] }, { "cell_type": "markdown", "metadata": {}, "source": [ "We can combine all of these to generate a stream of legitimate activity for a single user:" ] }, { "cell_type": "code", "execution_count": 56, "metadata": {}, "outputs": [], "source": [ "def legitimate_user_stream(user_id, transactions_per_day=12, amount_means=[20,100,500], amount_probs=[0.9,0.075,0.025]):\n", " amounts = transaction_amounts(amount_means, amount_probs)\n", " entry_types = legitimate_entry_types()\n", " merchants = merchant_stream(common_merchants, np.arange(MERCHANT_COUNT))\n", " \n", " SECONDS_PER_DAY = 86400\n", " loc = SECONDS_PER_DAY // transactions_per_day\n", " p = 1 / (loc / 10)\n", "\n", " while True:\n", " amount = next(amounts)\n", " entry = next(entry_types)\n", " foreign = entry == \"online\" and np.random.choice([True, False], p=[0.4, 0.6])\n", " \n", " merchant_id = next(merchants)\n", " offset, = stats.geom.rvs(p=p, loc=loc, size=1)\n", " result = {\n", " \"user_id\": user_id,\n", " \"amount\": amount,\n", " \"merchant_id\": merchant_id,\n", " \"entry\": entry,\n", " \"foreign\": foreign\n", " }\n", " yield (offset, (\"legitimate\", *result.values()))" ] }, { "cell_type": "code", "execution_count": 57, "metadata": { "scrolled": false }, "outputs": [ { "name": "stdout", "output_type": "stream", "text": [ "(7408, ('legitimate', 1, 26.34, 13610, 'contactless', False))\n", "(7417, ('legitimate', 2, 27.82, 1445, 'chip_and_pin', False))\n", "(7895, ('legitimate', 3, 20.94, 1456, 'chip_and_pin', False))\n", "(14735, ('legitimate', 1, 23.31, 514, 'contactless', False))\n", "(15296, ('legitimate', 3, 103.68, 2930, 'contactless', False))\n", "(15397, ('legitimate', 2, 24.56, 14863, 'online', True))\n", "(22482, ('legitimate', 1, 24.43, 14887, 'online', False))\n", "(23033, ('legitimate', 2, 20.01, 10007, 'contactless', False))\n", "(23812, ('legitimate', 3, 106.4, 3699, 'contactless', False))\n", "(30717, ('legitimate', 1, 37.06, 11025, 'online', False))\n", "(32080, ('legitimate', 2, 23.45, 16013, 'manual', False))\n", "(33635, ('legitimate', 3, 20.17, 16846, 'swipe', False))\n", "(38367, ('legitimate', 1, 23.7, 5183, 'chip_and_pin', False))\n", "(39723, ('legitimate', 2, 22.04, 16275, 'online', False))\n", "(41180, ('legitimate', 3, 23.9, 5793, 'online', True))\n", "(46503, ('legitimate', 1, 25.06, 10416, 'online', False))\n", "(47127, ('legitimate', 2, 24.0, 6489, 'swipe', False))\n", "(50501, ('legitimate', 3, 40.52, 15992, 'online', True))\n", "(54701, ('legitimate', 2, 21.15, 246, 'contactless', False))\n", "(56336, ('legitimate', 1, 29.68, 6719, 'contactless', False))\n", "(58156, ('legitimate', 3, 29.24, 5845, 'chip_and_pin', False))\n", "(62027, ('legitimate', 2, 67.74, 9116, 'online', False))\n", "(63942, ('legitimate', 1, 55.43, 7243, 'online', True))\n", "(66610, ('legitimate', 3, 26.01, 3793, 'online', False))\n", "(69469, ('legitimate', 2, 20.74, 15659, 'chip_and_pin', False))\n", "(72172, ('legitimate', 1, 26.66, 8324, 'contactless', False))\n", "(74762, ('legitimate', 3, 53.7, 8038, 'online', False))\n", "(77407, ('legitimate', 2, 33.29, 10216, 'online', False))\n", "(79896, ('legitimate', 1, 24.05, 6882, 'chip_and_pin', False))\n", "(85155, ('legitimate', 3, 21.09, 1165, 'contactless', False))\n", "(85846, ('legitimate', 2, 38.8, 18234, 'online', False))\n", "(87770, ('legitimate', 1, 23.84, 15444, 'manual', False))\n", "(92374, ('legitimate', 3, 33.8, 6678, 'contactless', False))\n", "(94397, ('legitimate', 2, 22.36, 11625, 'contactless', False))\n", "(95623, ('legitimate', 1, 31.35, 1931, 'chip_and_pin', False))\n", "(99798, ('legitimate', 3, 20.59, 17237, 'online', False))\n", "(102388, ('legitimate', 2, 23.29, 1454, 'online', True))\n", "(103733, ('legitimate', 1, 21.25, 6196, 'contactless', False))\n", "(109406, ('legitimate', 3, 46.19, 7625, 'chip_and_pin', False))\n", "(111226, ('legitimate', 2, 33.2, 3635, 'online', True))\n", "(112057, ('legitimate', 1, 26.88, 1814, 'online', False))\n", "(118591, ('legitimate', 2, 26.45, 5441, 'chip_and_pin', False))\n", "(119379, ('legitimate', 3, 20.39, 12698, 'online', False))\n", "(119828, ('legitimate', 1, 24.02, 9389, 'online', True))\n", "(125842, ('legitimate', 2, 504.72, 5406, 'manual', False))\n", "(126603, ('legitimate', 3, 25.77, 18420, 'online', False))\n", "(127339, ('legitimate', 1, 62.57, 13248, 'chip_and_pin', False))\n", "(134049, ('legitimate', 3, 126.85, 18892, 'chip_and_pin', False))\n", "(134202, ('legitimate', 2, 38.84, 11808, 'swipe', False))\n", "(134937, ('legitimate', 1, 28.23, 4106, 'contactless', False))\n", "(142161, ('legitimate', 3, 23.37, 3161, 'contactless', False))\n", "(142264, ('legitimate', 2, 23.88, 13441, 'chip_and_pin', False))\n", "(142312, ('legitimate', 1, 22.66, 5307, 'contactless', False))\n", "(149536, ('legitimate', 3, 27.97, 7900, 'contactless', False))\n", "(151041, ('legitimate', 2, 21.13, 7186, 'online', False))\n", "(151394, ('legitimate', 1, 22.09, 11444, 'chip_and_pin', False))\n", "(157247, ('legitimate', 3, 35.36, 3533, 'online', False))\n", "(158603, ('legitimate', 2, 20.87, 5612, 'online', False))\n", "(160414, ('legitimate', 1, 20.96, 424, 'contactless', False))\n", "(165536, ('legitimate', 3, 508.73, 16609, 'swipe', False))\n", "(165983, ('legitimate', 2, 20.16, 5057, 'contactless', False))\n", "(169245, ('legitimate', 1, 23.78, 5742, 'swipe', False))\n", "(173460, ('legitimate', 2, 28.95, 16882, 'chip_and_pin', False))\n", "(173586, ('legitimate', 3, 26.02, 19339, 'online', True))\n", "(176649, ('legitimate', 1, 30.67, 2212, 'swipe', False))\n", "(180847, ('legitimate', 2, 20.72, 246, 'swipe', False))\n", "(181084, ('legitimate', 3, 20.86, 3069, 'contactless', False))\n", "(184682, ('legitimate', 1, 505.5, 2496, 'contactless', False))\n", "(188350, ('legitimate', 3, 103.24, 19011, 'manual', False))\n", "(189235, ('legitimate', 2, 45.69, 10007, 'contactless', False))\n", "(192379, ('legitimate', 1, 118.27, 252, 'chip_and_pin', False))\n", "(197203, ('legitimate', 2, 29.57, 18014, 'chip_and_pin', False))\n", "(197558, ('legitimate', 3, 39.76, 3487, 'swipe', False))\n", "(200216, ('legitimate', 1, 28.31, 11096, 'online', False))\n", "(204529, ('legitimate', 2, 100.96, 6489, 'contactless', False))\n", "(205066, ('legitimate', 3, 27.36, 17660, 'contactless', False))\n", "(207775, ('legitimate', 1, 24.28, 13593, 'contactless', False))\n", "(212956, ('legitimate', 3, 25.29, 1346, 'swipe', False))\n", "(213482, ('legitimate', 2, 512.4, 19042, 'contactless', False))\n", "(215476, ('legitimate', 1, 30.84, 2496, 'chip_and_pin', False))\n", "(220385, ('legitimate', 3, 21.0, 8362, 'online', False))\n", "(221307, ('legitimate', 2, 21.04, 16058, 'chip_and_pin', False))\n", "(222724, ('legitimate', 1, 30.93, 15809, 'swipe', False))\n", "(227959, ('legitimate', 3, 30.53, 3988, 'contactless', False))\n", "(229982, ('legitimate', 1, 28.6, 668, 'online', True))\n", "(229993, ('legitimate', 2, 31.82, 14860, 'contactless', False))\n", "(235512, ('legitimate', 3, 21.28, 15992, 'online', True))\n", "(237810, ('legitimate', 2, 29.77, 1230, 'online', False))\n", "(238666, ('legitimate', 1, 504.4, 3692, 'online', True))\n", "(243136, ('legitimate', 3, 20.24, 17933, 'swipe', False))\n", "(245076, ('legitimate', 2, 21.5, 17403, 'online', False))\n", "(245949, ('legitimate', 1, 26.43, 4230, 'chip_and_pin', False))\n", "(252278, ('legitimate', 3, 25.47, 16385, 'contactless', False))\n", "(252788, ('legitimate', 2, 52.09, 10364, 'manual', False))\n", "(253948, ('legitimate', 1, 28.78, 5559, 'online', False))\n", "(259832, ('legitimate', 3, 26.82, 3609, 'online', False))\n", "(261967, ('legitimate', 2, 32.88, 4520, 'contactless', False))\n", "(262236, ('legitimate', 1, 32.44, 12607, 'chip_and_pin', False))\n", "(268436, ('legitimate', 3, 29.85, 4470, 'chip_and_pin', False))\n", "(269421, ('legitimate', 2, 106.69, 13441, 'contactless', False))\n", "(269873, ('legitimate', 1, 41.98, 15691, 'contactless', False))\n", "(275774, ('legitimate', 3, 24.62, 6038, 'contactless', False))\n", "(277318, ('legitimate', 1, 35.63, 19450, 'contactless', False))\n", "(277332, ('legitimate', 2, 32.76, 18482, 'contactless', False))\n", "(283273, ('legitimate', 3, 25.61, 14506, 'swipe', False))\n", "(284747, ('legitimate', 2, 24.7, 19941, 'contactless', False))\n", "(284982, ('legitimate', 1, 25.8, 1687, 'chip_and_pin', False))\n", "(292247, ('legitimate', 2, 32.02, 12572, 'chip_and_pin', False))\n", "(292247, ('legitimate', 3, 35.65, 6103, 'online', False))\n", "(293384, ('legitimate', 1, 21.23, 6951, 'contactless', False))\n", "(299467, ('legitimate', 3, 21.07, 12314, 'swipe', False))\n", "(301881, ('legitimate', 1, 47.21, 12819, 'chip_and_pin', False))\n", "(303674, ('legitimate', 2, 119.57, 16187, 'contactless', False))\n", "(307710, ('legitimate', 3, 41.32, 2372, 'chip_and_pin', False))\n", "(309106, ('legitimate', 1, 50.33, 3049, 'online', False))\n", "(310999, ('legitimate', 2, 32.22, 7243, 'chip_and_pin', False))\n", "(315847, ('legitimate', 3, 103.78, 5981, 'manual', False))\n", "(316497, ('legitimate', 1, 24.68, 12179, 'contactless', False))\n", "(318545, ('legitimate', 2, 511.94, 16924, 'chip_and_pin', False))\n", "(323253, ('legitimate', 3, 21.5, 6678, 'contactless', False))\n", "(323919, ('legitimate', 1, 27.27, 2528, 'swipe', False))\n", "(326344, ('legitimate', 2, 27.39, 16801, 'chip_and_pin', False))\n", "(331786, ('legitimate', 1, 32.29, 2281, 'online', True))\n", "(332684, ('legitimate', 3, 20.9, 10314, 'manual', False))\n", "(334392, ('legitimate', 2, 31.83, 9484, 'contactless', False))\n", "(339065, ('legitimate', 1, 106.69, 6837, 'online', False))\n", "(339936, ('legitimate', 3, 26.63, 16160, 'chip_and_pin', False))\n", "(341934, ('legitimate', 2, 33.69, 5310, 'chip_and_pin', False))\n", "(349037, ('legitimate', 1, 511.87, 3692, 'online', True))\n", "(349293, ('legitimate', 2, 25.25, 4267, 'chip_and_pin', False))\n", "(350517, ('legitimate', 3, 31.55, 19941, 'swipe', False))\n", "(357456, ('legitimate', 2, 65.74, 8800, 'swipe', False))\n", "(358139, ('legitimate', 3, 29.95, 10574, 'online', False))\n", "(358779, ('legitimate', 1, 29.55, 4891, 'chip_and_pin', False))\n", "(365006, ('legitimate', 2, 32.75, 4450, 'chip_and_pin', False))\n", "(365994, ('legitimate', 1, 24.27, 10308, 'online', True))\n", "(366124, ('legitimate', 3, 22.98, 10314, 'online', True))\n", "(372957, ('legitimate', 2, 27.0, 7432, 'swipe', False))\n", "(374466, ('legitimate', 1, 23.7, 18341, 'contactless', False))\n", "(374528, ('legitimate', 3, 119.87, 2584, 'manual', False))\n", "(380483, ('legitimate', 2, 503.49, 4106, 'online', False))\n", "(381714, ('legitimate', 1, 30.13, 5816, 'online', True))\n", "(382130, ('legitimate', 3, 26.39, 16047, 'online', True))\n", "(388980, ('legitimate', 1, 23.19, 6837, 'online', False))\n", "(389251, ('legitimate', 2, 20.77, 17311, 'chip_and_pin', False))\n", "(389639, ('legitimate', 3, 33.21, 17958, 'contactless', False))\n", "(396658, ('legitimate', 2, 27.58, 3049, 'chip_and_pin', False))\n", "(397381, ('legitimate', 3, 37.64, 5727, 'online', False))\n", "(397460, ('legitimate', 1, 21.6, 16876, 'chip_and_pin', False))\n", "(404077, ('legitimate', 2, 25.54, 3629, 'manual', False))\n", "(405068, ('legitimate', 1, 26.02, 11128, 'manual', False))\n", "(406224, ('legitimate', 3, 39.71, 2483, 'contactless', False))\n", "(412038, ('legitimate', 2, 33.57, 16461, 'chip_and_pin', False))\n", "(412614, ('legitimate', 1, 23.49, 1661, 'chip_and_pin', False))\n", "(414364, ('legitimate', 3, 26.73, 12191, 'swipe', False))\n", "(419392, ('legitimate', 2, 22.42, 5365, 'contactless', False))\n", "(420493, ('legitimate', 1, 108.5, 1814, 'contactless', False))\n", "(422400, ('legitimate', 3, 20.81, 12050, 'chip_and_pin', False))\n", "(427471, ('legitimate', 2, 27.65, 7645, 'online', False))\n", "(427824, ('legitimate', 1, 23.95, 572, 'chip_and_pin', False))\n", "(429892, ('legitimate', 3, 25.62, 9158, 'chip_and_pin', False))\n", "(435210, ('legitimate', 1, 24.28, 7578, 'manual', False))\n", "(435570, ('legitimate', 2, 24.04, 3629, 'swipe', False))\n", "(438726, ('legitimate', 3, 25.96, 18059, 'swipe', False))\n", "(443073, ('legitimate', 2, 20.15, 10725, 'online', False))\n", "(443128, ('legitimate', 1, 36.46, 8127, 'chip_and_pin', False))\n", "(445967, ('legitimate', 3, 26.79, 2372, 'online', False))\n", "(450456, ('legitimate', 2, 101.42, 15816, 'manual', False))\n", "(450638, ('legitimate', 1, 503.23, 5413, 'online', False))\n", "(453343, ('legitimate', 3, 25.16, 6041, 'online', False))\n", "(457708, ('legitimate', 2, 36.5, 7186, 'contactless', False))\n", "(458310, ('legitimate', 1, 33.48, 5612, 'online', False))\n", "(463065, ('legitimate', 3, 32.81, 12032, 'online', False))\n", "(465102, ('legitimate', 2, 21.96, 12725, 'chip_and_pin', False))\n", "(465878, ('legitimate', 1, 20.72, 19871, 'online', True))\n", "(470780, ('legitimate', 3, 105.6, 16625, 'contactless', False))\n", "(472344, ('legitimate', 2, 25.47, 4528, 'chip_and_pin', False))\n", "(473167, ('legitimate', 1, 101.71, 9143, 'contactless', False))\n", "(478163, ('legitimate', 3, 22.72, 3699, 'online', False))\n", "(480534, ('legitimate', 2, 40.94, 3049, 'manual', False))\n", "(480652, ('legitimate', 1, 22.85, 9919, 'chip_and_pin', False))\n", "(485478, ('legitimate', 3, 100.75, 15320, 'contactless', False))\n", "(488027, ('legitimate', 2, 24.07, 13593, 'online', False))\n", "(488537, ('legitimate', 1, 32.04, 13248, 'online', True))\n", "(493245, ('legitimate', 3, 66.43, 18993, 'contactless', False))\n", "(495539, ('legitimate', 2, 32.47, 6961, 'contactless', False))\n", "(495922, ('legitimate', 1, 500.17, 477, 'chip_and_pin', False))\n", "(501083, ('legitimate', 3, 36.05, 12179, 'online', False))\n", "(502958, ('legitimate', 2, 22.06, 12725, 'contactless', False))\n", "(503456, ('legitimate', 1, 23.54, 9356, 'online', False))\n", "(510238, ('legitimate', 2, 21.05, 11004, 'swipe', False))\n", "(511615, ('legitimate', 1, 21.76, 9898, 'manual', False))\n", "(512643, ('legitimate', 3, 27.02, 517, 'online', True))\n", "(517608, ('legitimate', 2, 28.52, 7133, 'online', True))\n", "(520154, ('legitimate', 3, 23.75, 9567, 'online', True))\n", "(520813, ('legitimate', 1, 21.69, 18244, 'online', False))\n", "(525036, ('legitimate', 2, 112.76, 7052, 'online', False))\n", "(527715, ('legitimate', 3, 26.02, 15397, 'swipe', False))\n", "(528490, ('legitimate', 1, 24.67, 4087, 'chip_and_pin', False))\n", "(532894, ('legitimate', 2, 39.96, 3629, 'chip_and_pin', False))\n" ] } ], "source": [ "sim = simulate([legitimate_user_stream(1), \n", " legitimate_user_stream(2), \n", " legitimate_user_stream(3)])\n", "\n", "for i in range(200):\n", " print(next(sim))" ] }, { "cell_type": "markdown", "metadata": {}, "source": [ "## Simulating fraud\n", "\n", "We'll start with some basic assumptions: \n", "\n", "1. fraudulent transactions are equally likely to happen at any arbitrary merchant,\n", "2. fraudulent transactions are typically for small dollar amounts,\n", "3. fraudulent transactions are rare overall, but when they occur, several will occur close together,\n", "4. fraudulent transactions are far more likely to be certain entry types (manual or online) or foreign transactions, and\n", "5. fraudulent transactions occur without regard for the user's typical schedule.\n", "\n", "These will guide the design of a fraudulent transaction generator.\n", "\n", "WIP" ] }, { "cell_type": "code", "execution_count": null, "metadata": {}, "outputs": [], "source": [ "def fraud_entry_types():\n", " size = 256\n", " \n", " entry_types = [\"contactless\", \"chip_and_pin\", \"swipe\", \"manual\", \"online\"]\n", " entry_probs = [0.05,0.05,0.05,0.35,0.5]\n", "\n", " while True:\n", " stream = [entry_types[i] for i in np.random.choice(len(entry_types), p=entry_probs, size=size)]\n", " yield from stream\n", "\n", "def fraudulent_user_stream(user_id, transactions_per_day=12, amount_means=[5,10,20], amount_probs=[0.2, 0.2, 0.6]):\n", " amounts = transaction_amounts(amount_means, amount_probs)\n", " entry_types = fraud_entry_types()\n", " \n", " SECONDS_PER_DAY = 86400\n", " loc = SECONDS_PER_DAY // transactions_per_day * 10\n", " p = 1 / (loc / 10)\n", "\n", " while True:\n", " fraud_delay, = np.floor(stats.gamma.rvs(a=6.4, loc=SECONDS_PER_DAY * 90, scale=SECONDS_PER_DAY, size=1))\n", " fraud_delay = int(fraud_delay)\n", " \n", " amount = next(amounts)\n", " entry = next(entry_types)\n", " foreign = np.random.choice([True, False], p=[0.4, 0.6])\n", " \n", " merchant_id = np.random.choice(MERCHANT_COUNT)\n", " offset, = stats.geom.rvs(p=p, loc=loc, size=1)\n", " result = {\n", " \"user_id\": user_id,\n", " \"amount\": amount,\n", " \"merchant_id\": merchant_id,\n", " \"entry\": entry,\n", " \"foreign\": foreign\n", " }\n", " yield (offset, (\"legitimate\", *result.values()))" ] }, { "cell_type": "code", "execution_count": 47, "metadata": {}, "outputs": [ { "data": { "application/javascript": [ "var spec = {\"config\": {\"view\": {\"width\": 400, \"height\": 300}, \"mark\": {\"tooltip\": null}}, \"data\": {\"url\": \"altair-data-2c9575e01c9b7e4d9e0aa3f58e38ef6a.json\", \"format\": {\"type\": \"json\"}}, \"mark\": \"bar\", \"encoding\": {\"x\": {\"type\": \"quantitative\", \"bin\": {\"maxbins\": 100}, \"field\": \"amounts\"}, \"y\": {\"type\": \"quantitative\", \"aggregate\": \"count\"}}, \"$schema\": \"https://vega.github.io/schema/vega-lite/v3.4.0.json\"};\n", "var opt = {};\n", "var type = \"vega-lite\";\n", "var id = \"f82732d0-479c-4e0c-a372-e380559c68ec\";\n", "\n", "var output_area = this;\n", "\n", "require([\"nbextensions/jupyter-vega/index\"], function(vega) {\n", " var target = document.createElement(\"div\");\n", " target.id = id;\n", " target.className = \"vega-embed\";\n", "\n", " var style = document.createElement(\"style\");\n", " style.textContent = [\n", " \".vega-embed .error p {\",\n", " \" color: firebrick;\",\n", " \" font-size: 14px;\",\n", " \"}\",\n", " ].join(\"\\\\n\");\n", "\n", " // element is a jQuery wrapped DOM element inside the output area\n", " // see http://ipython.readthedocs.io/en/stable/api/generated/\\\n", " // IPython.display.html#IPython.display.Javascript.__init__\n", " element[0].appendChild(target);\n", " element[0].appendChild(style);\n", "\n", " vega.render(\"#\" + id, spec, type, opt, output_area);\n", "}, function (err) {\n", " if (err.requireType !== \"scripterror\") {\n", " throw(err);\n", " }\n", "});\n" ], "text/plain": [ "<vega.vegalite.VegaLite at 0x1a225165c0>" ] }, "metadata": { "jupyter-vega": "#f82732d0-479c-4e0c-a372-e380559c68ec" }, "output_type": "display_data" }, { "data": { "text/plain": [] }, "execution_count": 47, "metadata": {}, "output_type": "execute_result" }, { "data": { "image/png": "" }, "metadata": { "jupyter-vega": "#f82732d0-479c-4e0c-a372-e380559c68ec" }, "output_type": "display_data" } ], "source": [ "source = pd.DataFrame({\"amounts\": stats.gamma.rvs(a=6.4, loc=86400 * 90, scale=80000, size=10000)})\n", "\n", "alt.Chart(source).mark_bar().encode(\n", " alt.X(\"amounts\", bin=alt.Bin(maxbins=100)),\n", " y='count()'\n", ")" ] }, { "cell_type": "code", "execution_count": 50, "metadata": {}, "outputs": [ { "data": { "text/plain": [ "1.2" ] }, "execution_count": 50, "metadata": {}, "output_type": "execute_result" } ], "source": [ "sum([0.05,0.05,0.25,0.5,0.35])" ] }, { "cell_type": "code", "execution_count": 53, "metadata": {}, "outputs": [ { "data": { "text/plain": [ "False" ] }, "execution_count": 53, "metadata": {}, "output_type": "execute_result" } ], "source": [ "np.random.choice([True, False], p=[0.3, 0.7])" ] }, { "cell_type": "code", "execution_count": null, "metadata": {}, "outputs": [], "source": [] } ], "metadata": { "kernelspec": { "display_name": "Python 3", "language": "python", "name": "python3" }, "language_info": { "codemirror_mode": { "name": "ipython", "version": 3 }, "file_extension": ".py", "mimetype": "text/x-python", "name": "python", "nbconvert_exporter": "python", "pygments_lexer": "ipython3", "version": "3.7.3" } }, "nbformat": 4, "nbformat_minor": 2 }