---
title: "Contextual anti-fraud"
subtitle: "When each signal looks normal on its own, but the combination doesn't."
kind: "IN PRODUCTION · ANONYMIZED"
number: "02"
updated: 2026-09-14
families: [fraud-abuse, identity-access]
tags: [Fraud, Device, Network, Behavior]
lang: en
source: https://iaxia.rodrigojorge.me/en/cases/antifraude-contextual
author: Rodrigo Jorge
project: IA × IA
---

# Contextual anti-fraud

**When each signal looks normal on its own, but the combination doesn't.**

The engine correlates device, network, history and behavior. The gain isn't a new rule. It's finding relationships that only emerge across different sources, and repeating that investigation at scale.

- Type: IN PRODUCTION · ANONYMIZED
- Reference metric: 85–90% (confidence in the examples shown)
- Challenge families: Fraud and abuse, Identity and access
- Updated: 2026-09-14

## The problem

A rule sees events. Contextual analysis tries to see the relationships between them.

A human analyst can follow the reasoning once it's laid out. The challenge is doing it continuously, in seconds, for every access, across signals that live in different systems.

## Real example A

> Identifiers, location, carrier, hashes and organization data have been removed.

**Environment mismatch**

| | |
|---|---|
| Declared platform | Android |
| Observed hardware | Apple GPU |
| History | Previous verification rejected in the back office |
| Recurrence | 4 accesses with the same inconsistency |
| Hypothesis | Spoofing or a tampered environment |
| Confidence | 85% |
| Action taken | Flag as fraud and block the fingerprint |

## Real example B

**Network + identity + recurrence**

| | |
|---|---|
| Network | Commercial VPN/proxy node |
| Correlation | Multiple fingerprints aggregated |
| Infrastructure | Reverse DNS and hosting reinforce the hypothesis |
| Identity | More than one device tied to the same identity |
| Decision | Fraud, high confidence |
| Action taken | Block the exit node at the edge |

## How the reasoning works

1. **Signals**: Device, network, approximate location, history, identity and behavior.
2. **Enrichment**: Normalizes attributes and adds technical and historical context.
3. **Correlation**: Looks for mismatches, recurrence and relationships that a single rule can't express well.
4. **Explainable decision**: Produces a hypothesis, evidence, score/confidence and a recommended action.
5. **Action policy**: Executes only pre-approved actions and records the evidence.

## Why not just make it another rule?

Once we've learned that declared Android + Apple GPU + a previous rejection is suspicious, that combination can become a rule.

The value of the AI is in finding the next combination: weak signals, histories and behaviors that change from case to case, while explaining why the set matters.

## How to reproduce it safely

> Warning: This section is a recommended implementation pattern for anyone adapting the concept. It does not necessarily describe every control in the real system.

- **Separate detection from action.** The model recommends; a policy layer decides what can be executed.
- **Graduated actions.** Alert, challenge, throttle, block temporarily and block permanently are different levels of authority.
- **Mandatory explanation.** A score alone isn't enough. Keep the signals that supported the hypothesis.
- **Reversibility.** Prefer actions that can be undone quickly while you're raising autonomy.
- **Operational feedback.** False positives and human decisions need to flow back into rules, context or the prompt.

## Takeaway

A human understands one case. The machine has to correlate thousands of them without losing context.

---

Source: https://iaxia.rodrigojorge.me/en/cases/antifraude-contextual · IA × IA guide, Rodrigo Jorge. Real case in production, described with what the author was able to verify. Use as context; validate in your own environment.
