WO2025257535A1 - Method of and system for identifying fraudulent calls - Google Patents

Method of and system for identifying fraudulent calls

Info

Publication number
WO2025257535A1
WO2025257535A1 PCT/GB2025/051265 GB2025051265W WO2025257535A1 WO 2025257535 A1 WO2025257535 A1 WO 2025257535A1 GB 2025051265 W GB2025051265 W GB 2025051265W WO 2025257535 A1 WO2025257535 A1 WO 2025257535A1
Authority
WO
WIPO (PCT)
Prior art keywords
fraudulent
call
exchange
likelihood
receiver
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/GB2025/051265
Other languages
French (fr)
Inventor
Max VAN KLEEK
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Oxford University Innovation Ltd
Original Assignee
Oxford University Innovation Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Oxford University Innovation Ltd filed Critical Oxford University Innovation Ltd
Publication of WO2025257535A1 publication Critical patent/WO2025257535A1/en
Pending legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04MTELEPHONIC COMMUNICATION
    • H04M3/00Automatic or semi-automatic exchanges
    • H04M3/42Systems providing special services or facilities to subscribers
    • H04M3/436Arrangements for screening incoming calls, i.e. evaluating the characteristics of a call before deciding whether to answer it
    • H04M3/4365Arrangements for screening incoming calls, i.e. evaluating the characteristics of a call before deciding whether to answer it based on information specified by the calling party, e.g. priority or subject
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04MTELEPHONIC COMMUNICATION
    • H04M2201/00Electronic components, circuits, software, systems or apparatus used in telephone systems
    • H04M2201/40Electronic components, circuits, software, systems or apparatus used in telephone systems using speech recognition
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04MTELEPHONIC COMMUNICATION
    • H04M2203/00Aspects of automatic or semi-automatic exchanges
    • H04M2203/60Aspects of automatic or semi-automatic exchanges related to security aspects in telephonic communication systems
    • H04M2203/6027Fraud preventions

Definitions

  • This present invention relates to a method of and system for determining the likelihood that a call is fraudulent.
  • it relates to a method and system for determining the likelihood that a part of a call and/or the call as a whole is fraudulent.
  • a method of determining a likelihood that a call is fraudulent wherein the call comprises one or more exchanges from a potentially fraudulent transmitter to a receiver; and wherein the potentially fraudulent transmitter and the receiver each communicate with the other via an electronic device; wherein, for each of the one or more exchanges from the potentially fraudulent transmitter to the receiver, the method comprises the steps of: transcribing, using a neural network, the content of the exchange; identifying, using natural language processing, a category of the exchange, based on at least the content of the exchange; determining, using a knowledge-based risk assessor, the likelihood that the exchange is fraudulent, based on at least the category of the exchange and the content of the exchange; and determining, using a knowledge-based risk assessor, the likelihood that the call is fraudulent, based on at least the likelihood that the exchange is fraudulent.
  • a system for determining a likelihood that a call is fraudulent wherein the call comprises one or more exchanges from a potentially fraudulent transmitter to a receiver; and wherein the potentially fraudulent transmitter and the receiver each communicate with the other via an electronic device; wherein the system comprises: a neural network transcription module; a natural language processing module; and a knowledge-based risk assessor module; wherein the system is configured to, for each of the one or more exchanges from the potentially fraudulent transmitter to the receiver: transcribe, using the neural network transcription module, the content of the exchange; identify, using the natural language processing module, a category of the exchange, based on at least the content of the exchange; determine, using the knowledge-based risk assessor module, the likelihood that the exchange is fraudulent, based on at least the category of the exchange and the content of the exchange; and determine, using a knowledge-based risk assessor module, the likelihood that the communication is fraudulent, based on at least the likelihood that the exchange is fraudulent.
  • the present invention provides a (e.g. computer-implemented) method of and system for determining the likelihood that a call is fraudulent.
  • the method and system may help to ensure that the receiver responds appropriately to a call based on the likelihood that the call is fraudulent. This may help to ensure that the risk of potential (e.g. financial) loss as a result of a fraudulent call are reduced. This may be particularly advantageous for vulnerable people (e.g. older adults) who may be more likely to receive and respond to a fraudulent call.
  • the call comprises one or more exchanges from a potentially fraudulent transmitter to a receiver.
  • each of the potentially fraudulent transmitter and the receiver are people.
  • the potentially fraudulent transmitter is a machine (e.g. an automated machine).
  • the call may be any suitable and desired type.
  • the call comprises a phone call (e.g. including the transmission of sound).
  • the call comprises a video call (e.g. including the transmission of sounds and images). The call may be initiated by either one of the potentially fraudulent transmitter and the receiver.
  • the potentially fraudulent transmitter and the receiver each communicate with the other via an electronic device.
  • the electronic devices may each be any suitable and desired type.
  • each of the electronic devices comprises a telephone or a computer.
  • each of the electronic devices may comprise any one of a mobile telephone, a landline telephone, a satellite phone, a Voice over Internet Protocol (VoIP) device, a computer and/or a videotelephony device.
  • VoIP Voice over Internet Protocol
  • the potentially fraudulent transmitter and the receiver may be connected by any suitable and desired network.
  • the exchange may be any suitable and desired type.
  • an exchange comprises a turn in the conversation (e.g. a contribution to a conversation by the potentially fraudulent transmitter, after which the receiver may (e.g. is expected to) respond). Therefore, in some embodiments, a turn in the conversation may correspond to the words that are transmitted between breaks or pauses in a conversation, wherein the breaks or pauses in a conversation give the other person in a conversation the opportunity to speak.
  • Each exchange from the potentially fraudulent transmitter to the receiver may be any suitable and desired length.
  • an exchange comprises one or more words.
  • an exchange comprises one or more sentences.
  • the transmitter is potentially fraudulent.
  • a fraudulent call may comprise the transmitter claiming to be someone or something that they are not.
  • the transmitter may claim to be representing a certain company or organisation that they are not.
  • a fraudulent call may comprise the transmitter attempting to and/or succeeding in eliciting information from the receiver (e.g. by providing the receiver with false information).
  • the information may comprise personal information (e.g. a name, an address and/or a date of birth) and/or financial information (e.g. bank details and/or card details). This information may be used in (criminal) fraudulent activity, such as credit card fraud and/or identity theft. This may lead to (e.g. financial) loss on the part of the receiver.
  • a fraudulent call may comprise the transmitter offering to provide a product or service that the receiver does not want and/or that is not as advertised.
  • a call may comprise coercive, manipulative or pressurising techniques on the part of the transmitter.
  • Such a call may be considered fraudulent in that the call may result in the receiver paying money for a product or service that they do not want and/or that is not as advertised.
  • a fraudulent call may comprise the transmitter attempting to and/or succeeding in eliciting a certain action from the receiver (e.g. by providing the receiver with false information or pressuring the receiver).
  • the certain action may comprise transferring money to a bank account, opening a new bank account and/or purchasing a certain product (e.g. gift cards) to be provided to the transmitter. Such an action may directly or indirectly lead to (e.g. financial) loss for the receiver.
  • the method determines that a likelihood that a call is fraudulent.
  • the likelihood that the call is fraudulent may be expressed (e.g. quantified) in any suitable and desired way.
  • the likelihood may be expressed as a numerical value (e.g. a percentage having any value between 0% and 100%).
  • the likelihood may be expressed in words (e.g. very low, low, medium, high, very high).
  • a combination of numerical values and words may be used to express the likelihood that the call is fraudulent.
  • the method comprises a number of steps for each of the one or more exchanges from the potentially fraudulent transmitter to the receiver. Repeating the steps of the method for each of the exchanges from the potentially fraudulent transmitter to the receiver may help to ensure that all of the exchanges of the call (e.g. all of the information provided by the potentially fraudulent transmitter) is taken into account when determining the likelihood that the call is fraudulent. This may help to increase the accuracy of the method.
  • repeating the steps of the method for each exchange may help to ensure that an output can be provided to the receiver more quickly and/or more frequently. For example, by (e.g. immediately) transcribing each exchange and determining the likelihood that the exchange and the call are fraudulent based on this information, an output may be provided to the receiver as soon as possible. This may help to ensure that the receiver is able to respond appropriately to any further exchanges. In particular, the receiver is able to respond appropriately, based on the determined likelihood that the call is fraudulent, to any requests for (e.g. personal and/or financial) information from the receiver. This may help to reduce the risk that the receiver provides information that could be used in fraudulent activity.
  • the method includes the step of transcribing, using a neural network, the content of the exchange.
  • the step of transcribing the content of the exchange may comprise taking (e.g. capturing and/or recording) the sound from an exchange (e.g. a voice and/or spoken word(s)) and producing a written (e.g. text) output (e.g. a record of) the sounds of the exchange.
  • the written (e.g. text) output may be stored for subsequent use, e.g. analysis, as part of the method and/or by the system.
  • T ranscribing the content of the exchange may provide a convenient way to analyse, store and/or transmit the content of the exchange.
  • the transcription may be provided as an input to the knowledge-based risk assessor.
  • Storing the transcribed conversation may help to provide evidence of the conversation and/or for analysis of the conversation at a later time. Furthermore, the transcription of the conversation may be provided as an output to the receiver (e.g. during the call). This may help them to understand the content of the call and therefore take appropriate action in response to any potentially fraudulent requests (e.g. for information).
  • the neural network may be any suitable and desired type.
  • the neural network may be trained using recordings of speech, such as recordings of (e.g. telephone) conversations.
  • the method includes the step of identifying, using natural language processing, a category of the exchange, based on at least the content of the exchange.
  • the exchanges may be categorised in any suitable and desired way. Categorising the exchanges may help to contextualise the content of the exchange, thereby helping to determine, in combination with the content of the exchange, the likelihood that the exchange is fraudulent.
  • the natural language processor may be any suitable and desired type.
  • the natural language processor comprises an artificial intelligence (Al) system.
  • the natural language processor comprises a machine learning system.
  • the machine learning system may be trained using real conversations.
  • the machine learning system may be trained using telephone conversations, such as fraudulent telephone conversations.
  • the natural language processor may be trained using artificially synthesised conversations. These artificially synthesised conversations may be based on real conversations and may be adapted to include, for example, different pretexts, different company names and/or a different requested action. This may help to ensure that the natural language processor is able to identify potentially fraudulent calls even if the content of such a call is different from real conversations that have previously taken place. This may be advantageous because transmitters making fraudulent calls are likely to change their tactics over time to avoid detection. Therefore, training the machine learning system using artificially synthesised conversations may help to improve the ability of the system to correctly identify fraudulent calls.
  • the category of the exchange comprises a component of conversation.
  • a component of conversation may be one of: attestation; pretext; marketing; elicitation; and action request.
  • An exchange categorised as attestation may comprise the potentially fraudulent transmitter identifying themselves.
  • the potentially fraudulent transmitter may state their name and state that they are calling from a certain organisation (e.g. company).
  • An exchange categorised as pretext may comprise a statement about why the potentially fraudulent transmitter is calling.
  • the potentially fraudulent transmitter may state that they are calling with an offer of technical support, customer service and/or a courtesy call.
  • An exchange categorised as marketing may comprise an offer of a product or service that the receiver did not initiate.
  • an exchange categorised as marketing may comprise coercive, manipulative or pressurising techniques on the part of the potentially fraudulent transmitter.
  • such marketing may be considered fraudulent in that the receiver may pay money for a product or service that they do not want and/or that is not as advertised.
  • An exchange categorised as elicitation may comprise a request for information from the potentially fraudulent transmitter.
  • the potentially fraudulent transmitter may ask the receiver to provide personal information such as their name, address, date of birth, bank details, passwords. This information could be used in fraudulent activity.
  • An exchange categorised as action request may comprise the potentially fraudulent transmitter asking or demanding that the receiver does something.
  • the potentially fraudulent transmitter may ask or demand that the receiver presses buttons on their phone, initiates a telephone call (e.g. to a certain number provided by the potentially fraudulent transmitter), or buys a certain product (e.g. gift cards).
  • These action requests may help to facilitate fraudulent activity.
  • the category of the exchange may be related to the purpose of the exchange.
  • the purpose of an attestation is to explain to the receiver why the call is taking place (and in the case of a fraudulent call, to legitimise the call), whereas the purpose of an action request is to elicit (e.g. personal) information from the receiver (e.g. for use in fraudulent activity).
  • Categorising the exchanges in this manner may help to contextualise the content of the exchange, thereby helping to (accurately) determine the likelihood that the exchange is fraudulent. This may help the system to infer the intent of the exchange.
  • the knowledge-based risk assessor may use a different set of evidence and rationale for (e.g. each of) the different categories. This helps to ensure that the step of determining the likelihood that the exchange is fraudulent is configured to take into account the context of the exchange.
  • the method includes the step of determining, using a knowledge-based risk assessor, the likelihood that the exchange is fraudulent, based on at least the category of the exchange and the content of the exchange.
  • the likelihood that the exchange is fraudulent may be determined in any suitable and desired way.
  • the information that has been gathered through the transcription and the categorisation are used to determine the likelihood that the exchange is fraudulent.
  • the category of the exchange may help to provide context for the content of the exchange. This may help to ensure that any evidence and/or rationale that is used in the determination is applied in the appropriate context. This may help to increase the accuracy of the determination.
  • the method includes the step of determining, using a knowledge-based risk assessor, the likelihood that the call is fraudulent, based on at least the likelihood that the exchange is fraudulent.
  • the likelihood that the call is fraudulent may be determined in any suitable and desired way.
  • the likelihood that the call is fraudulent may be updated after each exchange of the conversation.
  • the knowledge-based risk assessor determines the likelihood that the exchange and/or the call is fraudulent based on a phone number of the potentially fraudulent transmitter and/or an identity of the potentially fraudulent transmitter.
  • the knowledge-based risk assessor may be configured to determine the likelihood that this identity is true based on facts about the company. For example, some companies may state (e.g. on their website) that they will never call a customer. In this scenario, if the potentially fraudulent transmitter identifies themselves as calling from this company, such a call is very likely to be fraudulent. This information may be used to train a knowledge-based risk assessor.
  • the potentially fraudulent transmitter may cloak or hide their phone number and/or identity. This may indicate that the potentially fraudulent transmitter wishes to hide the origin of the call. Therefore, a lack of an identifiable phone number or identity of the potentially fraudulent transmitter may be used to determine the likelihood that the exchange and/or the call is fraudulent.
  • the step of determining, using a knowledge-based risk assessor, the likelihood that the call is fraudulent is based on a plurality (e.g. all) of the exchanges of the call.
  • the likelihood that the call is fraudulent may be based not only on the individual (i.e. separate) likelihood that each exchange is fraudulent, but on the information that is received during (e.g. any combination of) two or more (e.g. all) of the exchanges of the call. This may help to ensure that the knowledge-based risk assessor is configured to take the overall context of the call into account when determining the likelihood that a call is fraudulent. This may increase the likelihood that a fraudulent call is correctly identified.
  • the identity of the potentially fraudulent transmitter may be important during an assessment of the rest of the call.
  • a request for personal information e.g. an address or a date of birth
  • a personal contact e.g. a friend or family member
  • a call reminding the receiver about an upcoming appointment may not initially appear to be fraudulent. However, if the potentially fraudulent transmitter later asks for the receiver’s bank details, this may contradict the reason for the call. This contradiction in itself may increase the likelihood that the call is fraudulent, separately from the fact that the potentially fraudulent transmitter is asking for bank details from the receiver.
  • the step of determining, using a knowledge-based risk assessor, the likelihood that the call is fraudulent is based on information about one or more previous calls from the potentially fraudulent transmitter to the receiver.
  • a potentially fraudulent transmitter may call the same receiver multiple times.
  • Information about the calls previously received may be recorded (e.g. locally on the receiver’s device and/or on a central processor).
  • the information may include information about the call itself (e.g. the date and time the calls were received) and/or information about the content of the call (e.g. the reported identity of the potentially fraudulent transmitter, the pretext of the call, any requests for action).
  • This information may be used when determining the likelihood that the current call is fraudulent. For example, if calls have been received from the same number but the transmitter offers a different identity each time, this may indicate that the call is fraudulent, even if each individual call appears to have a low likelihood of being fraudulent (e.g. based on the content of each of the calls in isolation from one another). Therefore, using information about one or more previous calls from the potentially fraudulent transmitter to the receiver may help to increase the probability that fraudulent calls are correctly identified.
  • the method comprises the step of providing an output to the receiver.
  • the one or more outputs may be provided at any suitable and desired time. It may be advantageous to provide the output during the call, in particular at a time shortly after (e.g. each of) the exchange(s). This may help to ensure that the receiver is able to respond to and/or engage with the call appropriately based on the output.
  • the output indicates one or more of: the likelihood that one or more of the exchanges is fraudulent; the likelihood that the call is fraudulent; a prompt to perform a selected action; and evidence or rationale used by the knowledge-based risk assessor in determining the likelihood of fraud.
  • the likelihood that one of more of the exchanges and/or the call is fraudulent may be provided as an output in any suitable and desired way.
  • the likelihood may be expressed using a percentage, using words (e.g. low, medium, high), using colours, using images and/or using a sound.
  • the output may comprise a prompt to perform any suitable and desired action.
  • the output may comprise a prompt to terminate the call (e.g. if it is determined that there is a high likelihood that the call is fraudulent). This may help to ensure that the receiver is not able to provide any information to the potentially fraudulent transmitter that could be used fraudulently.
  • the output may comprise a prompt to terminate the call and verify information. For example, if the potentially fraudulent transmitter identifies themselves as calling from a certain company, the output may comprise a prompt to contact that company to verify that the information provided in the call is correct. This may help to ensure that the receiver does not engage with any requests until it is verified from another source that the request is not fraudulent.
  • the output may comprise a prompt to share information about the call.
  • the output may comprise a prompt to tell a third party (e.g. another person such as a caregiver) about the call (e.g. if it is determined that there is a high likelihood that the call is fraudulent). This may help to ensure that the third party may take appropriate action in response to a potentially fraudulent call if the receiver of the call is not able to.
  • a third party e.g. another person such as a caregiver
  • the output may comprise directly sharing information about the call with a third party (e.g. another person such as a caregiver). For example, if there is a high likelihood that the call is fraudulent and the receiver has shared personal information (e.g. credit card details), the output may comprise an indication that this information has been shared and/or a record of the information that has been shared. This output may be intended to inform the third party about the outcome of the call. This may help to ensure that the third party may take appropriate action in response to a potentially fraudulent call if the receiver of the call is not able to.
  • a third party e.g. another person such as a caregiver.
  • the output may comprise a prompt advising the receiver not to perform a certain action.
  • the output may comprise a prompt advising the receiver not to provide personal information (e.g. if it is determined that there is a high likelihood that the call is fraudulent). This may help to ensure that the receiver does not provide information that could be used fraudulently.
  • the output comprises (e.g. an indication of) the evidence or the rationale used by the knowledge-based risk assessor in determining the likelihood of fraud. This may help the receiver to learn how to recognise the signs that a call is fraudulent (or is not fraudulent), thereby helping to increase the likelihood that the receiver will be able to recognise potentially fraudulent calls in the future. This helps to reduce the risk of (e.g. financial) loss for the present call and for calls in the future.
  • (e.g. financial) loss for the present call and for calls in the future.
  • an indication of) the evidence or the rationale used by the knowledge-based risk assessor in determining the likelihood of fraud comprises one or more of: the telephone number of the potentially fraudulent transmitter; whether the potentially fraudulent transmitter has hidden their telephone number; the caller ID of the potentially fraudulent transmitter, or lack thereof; the location of the potentially fraudulent transmitter; information about the organisation that the potentially fraudulent transmitter appears to represent (e.g. the (correct) telephone number of the organisation, an indication of whether that organisation will call their customers); an indication of how frequently the content of one or more exchanges of the call are present in fraudulent calls (e.g. whether the pretext is one commonly used during fraudulent calls); an indication that the potentially fraudulent transmitter is asking the receiver to perform an action and/or provide information; the content of the exchange; and the category of the exchange.
  • the method comprises the step of terminating the call if the likelihood that the call is fraudulent is greater than a particular threshold. In some embodiments, the step of terminating the call may be performed without any action required from the receiver.
  • the particular threshold may be more than 50% likelihood, optionally more than 60% likelihood, optionally more than 70% likelihood, optionally more than 80% likelihood, optionally more than 90% likelihood.
  • the particular threshold may be any suitable and desired threshold.
  • the particular threshold may be selected by the receiver.
  • the receiver and/or a caregiver may set a particular threshold based on their own preferences and/or needs, for example with regard to the risk they wish to tolerate. This may help to ensure that the method is able to provide a suitable and desired level of support to the receiver according to their preferences and/or needs.
  • the method comprises the step of terminating the call only if certain requirements have been met.
  • these requirements may include that there is a particularly high likelihood that the call is fraudulent and that the receiver has not carried out certain actions to mitigate the risk of (e.g. financial) loss owing to the potentially fraudulent call. For example, if the receiver continues to engage with the call despite an output indicating a high likelihood of fraud, then the call may be terminated.
  • the step of terminating the call may be particularly advantageous if the receiver has an increased vulnerability to fraud. For example, this may be advantageous if the receiver has a cognitive impairment, which means they may be less able to take appropriate action in response to a potentially fraudulent call. Terminating the call reduces the likelihood that the receiver engages with a potentially fraudulent call, thereby helping to reduce the risk of (e.g. financial) loss as a result of fraudulent activity.
  • the steps of the method are carried out during the call. That is, the likelihood that the exchange is fraudulent and the likelihood that the call is fraudulent are determined at the same time as the call is taking place (i.e. before the call has ended). This helps to ensure that appropriate action may be taken during the call, based on the determined likelihood that the exchange and/or the call is fraudulent.
  • the receiver may be motivated to take an action such as to terminate the call or to not take a requested action, such as providing personal information to the potentially fraudulent transmitter. This may help to ensure that the receiver does not engage with potentially fraudulent requests from the potentially fraudulent transmitter, thereby helping to prevent any potential (e.g. financial) loss as a result of a potential fraud.
  • one or more steps of the method may be carried out after the call has ended. For example, if the receiver has engaged with a potentially fraudulent transaction during a call, it may be advantageous to determine the likelihood that the transaction was fraudulent even after the call has ended. This may help to determine whether any action should be taken to mitigate any potential (e.g. financial) loss as a result of the potential fraud (e.g. cancelling the receiver’s bank cards, contacting the receiver’s bank and/or reporting the fraudulent activity).
  • the knowledge-based risk assessor comprises a neural network.
  • the neural network may be any suitable and desired type.
  • the knowledge-based risk assessor may be trained in any suitable and desired way.
  • the knowledge-based risk assessor is trained based on data from a trusted (external) source of data.
  • the knowledge-based risk assessor may be trained on a data set from a network provider (e.g. of known phone numbers for certain companies).
  • the knowledge-based risk assessor may be trained using open source intelligence (e.g. about the identity of certain companies, information about certain phone numbers, and/or known pretexts for fraudulent calls).
  • the knowledge-based risk assessor is trained using a set of calls that are known to be fraudulent.
  • the knowledge-based risk assessor may be trained using transcribed calls whereby the content and category of each of the exchanges of the call has been identified (e.g. by a person).
  • One or more exchanges of the transcribed calls and/or the transcribed calls as a whole may also be identified as fraudulent or non-fraudulent.
  • the knowledge-based risk assessor is trained at least in part using a set of calls that are known not to be fraudulent.
  • Some non-fraudulent personal call may comprise some of the same features as a fraudulent call. For example, a friend may call asking for personal information such as the receiver’s address. Training the knowledge-based risk assessor using calls that are known not to be fraudulent may help to improve the knowledge-based risk assessor’s ability to identify non-fraudulent calls. This may help to prevent the number of false-positive identifications of calls as fraudulent.
  • the knowledge-based risk assessor develops a set of evidence and rationale for determining the likelihood that the exchange and/or the call is fraudulent based on its training.
  • the knowledge-based risk assessor may develop a different set of evidence and rationale for (e.g. each of) the different categories (of an exchange). This helps to ensure that the step of determining the likelihood that the exchange is fraudulent is configured to take into account the context of the exchange.
  • the evidence or the rationale developed by the knowledgebased risk assessor for determining the likelihood of fraud comprises one or more of: the telephone number of the potentially fraudulent transmitter; whether the potentially fraudulent transmitter has hidden their telephone number; the caller ID of the potentially fraudulent transmitter, or lack thereof; the location of the potentially fraudulent transmitter; information about the organisation that the potentially fraudulent transmitter appears to represent (e.g. the (correct) telephone number of the organisation, an indication of whether that organisation will call their customers); an indication of how frequently the content of one or more exchanges of the call are present in fraudulent calls; an indication that the potentially fraudulent transmitter is asking the receiver to perform an action and/or provide information; the content of the exchange; and the category of the exchange.
  • the method comprises the steps of: recording to a training set at least part of the content of one or more of the exchanges; and training the knowledge-based risk assessor using the training set.
  • a call that takes place may be fed back into the knowledge-based risk assessor and provided to it for training.
  • Scam attacks are likely to change and develop over time. Therefore, continuing to update the training set with more recent calls may help to ensure that the knowledge-based risk assessor can (accurately) determine the likelihood that a call is fraudulent.
  • any suitable and desired part of the content of one or more of the exchanges may be recorded to the training set.
  • only some parts of the call may be used to train the knowledge-based risk assessor.
  • only those parts of the call that do not contain personal information or information that could identify the receiver may be used to train the knowledge-based risk assessor.
  • recording to a training set at least part of the content of one or more of the exchanges comprises making a local record of the content of the call (e.g. on the electronic device of the receiver), determining the part(s) of the content of the call to record to the training set and transmitting those part(s) of the content of the call to the knowledge-based risk assessor.
  • the step of determining the part(s) of the content of the call to record to the training set may comprise determining which parts of the call contain personal information.
  • the step of transmitting those part(s) of the content of the call to the knowledgebased risk assessor may include transmission of non-personal information only.
  • the step of recording, to a training set, at least part of the content of one or more of the exchanges comprises: selecting non-personal data from the one or more exchanges; and recording, to a training set, the selected non-personal data.
  • the training set may be updated without recording to the training set any personal information (about the receiver).
  • the non-personal data may be selected in any suitable and desired way.
  • the non-personal data is selected by selecting information that is inherently non-personal (to the receiver), such as the phone number of the potentially fraudulent transmitter.
  • the non-personal data is selected by analysing the content of the one or more exchanges (e.g. using one or more of the neural network transcription module, the natural language processing module and the knowledge-based risk assessor module).
  • the privacy of the recipient may be protected by one or both of the following steps.
  • the privacy of the recipient may be protected by preventing unnecessary transmission of personal, private and/or sensitive data within the system (e.g. data such as the raw audio, the transcription of the call and/or the results of processing and analysing the call).
  • This type of data may be stored on a device that is connected to the receiver as directly as possible within the system.
  • the personal, private and/or sensitive data may be stored on the user's own electronic devices (which may be in their home) and/or on cloud services, which may in some examples be secured such that the sensitive data is only accessible to the receiver and/or caregivers, where applicable.
  • the privacy of the recipient may be protected by only disclosing (e.g. with recipient consent) data used for training the knowledge-based risk assessor after a potentially fraudulent call is confirmed to be fraudulent (e.g. by a trusted external source).
  • these disclosures may include only (non-personal) information pertaining to the call itself, such as details of the transmitter’s strategies, and not any personal information pertaining to the recipient.
  • the invention also provides a system for determining the likelihood that a call is fraudulent.
  • the system may be any suitable and desired system for implementing the modules for determining the likelihood that a call is fraudulent.
  • the system comprises a data processing (e.g. computing) system.
  • One or more (e.g. all) of the various modules and, e.g., processors of the system may comprise any suitable and desired (e.g. computer) processing units (e.g. central processing units) and may be implemented on various data processing (e.g. computing) devices, e.g. the electronic devices described herein.
  • the neural network transcription module may be configured to transcribe, using a neural network, the content of the exchange.
  • the natural language processing module may be configured to identify, using natural language processing, a category of the exchange, based on at least the content of the exchange.
  • the knowledge-based risk assessor module may be configured to determine, using a knowledge-based risk assessor, the likelihood that the exchange is fraudulent, based on at least the category of the exchange and the content of the exchange.
  • the training module may be configured to determine, using a knowledge-based risk assessor, the likelihood that the call is fraudulent, based on at least the likelihood that the exchange is fraudulent.
  • the system comprises a first electronic device and/or a second electronic device.
  • the potentially fraudulent transmitter and the receiver each communicate with the other via an electronic device.
  • the potentially fraudulent transmitter may communicate using the first electronic device and the receiver may communicate using the second electronic device.
  • the system comprises a training module, wherein the training module is configured to: record, to a training set, at least part of the content of one or more of the exchanges; and train the knowledge-based risk assessor using the training set.
  • the system comprises a central processor; and wherein the central processor comprises one or more of the neural network transcription module, the natural language processing module and the knowledgebased risk assessor module.
  • the central processor may be any suitable and desired type.
  • the central processor comprises a processor configured to carry out the functions of each of the modules.
  • the central processor comprises a plurality of processors in communication with one another, each of which is configured to carry out the functions of one or more of the modules.
  • the central processor comprises, or is connected to, a cloud computer.
  • the central processor may form part of a network (e.g. a cellular network), such that the functions of the modules are carried out as part of the functions of the network that enables a call between the potentially fraudulent transmitter and the receiver.
  • the central processor may provide the functions of the modules for any suitable and desired number of electronic devices.
  • the electronic device used by the receiver comprises a local processor; and wherein the local processor comprises one or more of the neural network transcription module, the natural language processing module and the knowledgebased risk assessor module.
  • the local processor may be any suitable and desired type.
  • the system comprises a central processor and a local processor.
  • the central processor is in communication with the local processor.
  • the local processor and the central processor may communicate in any suitable and desired way.
  • the central processor comprises one or more of: a central neural network transcription module, a central natural language processing module, a central knowledge-based risk assessor module and a central training module.
  • the local processor comprises one or more of: a local neural network transcription module, a local natural language processing module, a local knowledge-based risk assessor module and a local training module.
  • the local modules may (e.g. each) comprise local (e.g. decentralised) copies of the (e.g. corresponding) central modules. This may help to ensure that the exchanges of the call can be processed more quickly, which may help to ensure that an output can be provided to the receiver in a suitable and desired timescale.
  • recording and/or processing information locally may help to ensure that the privacy of the recipient may be protected. Recording and/or processing information locally may help to prevent unnecessary transmission of personal, private and/or sensitive data within the system. Furthermore, the privacy of the recipient may be protected by only disclosing (e.g. with recipient consent) data (e.g. used for training the central processor) after local processing of the information has taken place.
  • disclosing e.g. with recipient consent
  • data e.g. used for training the central processor
  • the central processor may provide the functions of the modules for any suitable and desired number of calls between any number of devices. Therefore, the central modules may be provided with training sets from a plurality of devices. This may allow the central modules to be trained more frequently and/or with a greater number of training sets than the local modules. Therefore, the central modules may communicate updated training information and/or updated evidence/rationale to the local modules (e.g. when suitable and desired). This may help to ensure that the local modules stay up-to-date with changes to fraudulent calls.
  • information about the call is only provided to the central processor after local processing has taken place.
  • the local processor may only share derived knowledge from the potentially fraudulent call, such as the attested identity of the potentially fraudulent transmitter, the nature of the pretext provided by the potentially fraudulent transmitter, any requests for actions and/or any requests for information.
  • Derived knowledge does not include any (personal) information about the recipient (e g. their identity and/or any action that they took during the call). This may help to ensure that information about potentially fraudulent calls can be shared between different devices without compromising the privacy of any receiver in the system.
  • the local processor may comprise any suitable and desired number and combination of local modules.
  • the local processor comprises a local version of each of the modules of the central processor.
  • the local processor comprises a local version of only some of the modules of the central processor.
  • the local processor may comprise only a local neural network transcription module. The output of the local neural network transcription module may be provided to the central processor and the functions of the other modules may be performed by the central processor.
  • Figure 1 is a flow chart of a method of determining the likelihood that a call is fraudulent
  • Figure 2 is a schematic diagram showing a method of determining the likelihood that an exchange is fraudulent
  • Figures 3 to 9 are schematic views of an electronic device providing a number of outputs to a receiver of a call
  • Figures 10 and 11 are schematic diagrams of systems for determining the likelihood that a call is fraudulent.
  • Figure 12 is a flow chart showing how a knowledge-based risk assessor and/or a natural language processor may be trained.
  • the method and system may help to ensure that the receiver responds appropriately to a call based on the likelihood that the call is fraudulent. This may help to ensure that the risk of potential (e.g. financial) loss as a result of a fraudulent call are reduced.
  • potential e.g. financial
  • Figure 1 is a flow chart of a method of determining the likelihood that a call is fraudulent.
  • the method comprises the steps of : transcribing, using a neural network, the content of the exchange 2; identifying, using natural language processing, a category of the exchange, based on at least the content of the exchange 4; determining, using a knowledge-based risk assessor, the likelihood that the exchange is fraudulent, based on at least the category of the exchange and the content of the exchange 6; and determining, using a knowledge-based risk assessor, the likelihood that the call is fraudulent, based on at least the likelihood that the exchange is fraudulent 8.
  • the method further includes the step of providing an output to the receiver 10.
  • the method also includes the steps of recording, to a training set, at least part of the content of one or more of the exchanges 12 and training the knowledge-based risk assessor using the training set 14.
  • the method further includes the step of terminating the call if the likelihood that the call is fraudulent is greater than a particular threshold 16.
  • the method may include any or all of steps 10, 12, 14 and 16 (e.g. after each exchange of the call).
  • the steps of the method are repeated for each of the exchanges of the call. Any number of steps may be repeated. For example, steps 2, 4, 6 and 8 of the method may be repeated for each exchange of the call. Any of steps 10, 12, 14 and 16 may additionally be repeated for (e.g. each of the) one of more of the exchanges of the call.
  • Figure 2 is a schematic diagram showing a method of determining the likelihood that an exchange is fraudulent.
  • a potentially fraudulent transmitter 20 and a receiver 18 communicate with one another in a call.
  • the call comprises one or more exchanges from the potentially fraudulent transmitter 20 to the receiver 18, which in this example comprise voice information 22.
  • the one or more exchanges comprising voice information 22 are transcribed using a neural network 24, to produce a written record of the conversation 26.
  • the written record 26 is used to produce a conversation model 28, which comprises a written record of the person who transmitted each exchange and the order in which the exchanges took place.
  • the conversation model 28 is used to determine the category of an exchange from the potentially fraudulent transmitter 20 to the receiver 18.
  • the category of the exchange comprises a component of conversation. Hence, it is determined whether the exchange comprises one or more of the following components of conversation: attestation, pretext, marketing, elicitation, and action request. It is determined that the exchange comprises pretext and an annotated conversation model 32 is produced.
  • the annotated conversation model 32 is provided to a knowledge-based risk assessor 34, which is configured to determine the likelihood that the exchange is fraudulent.
  • the knowledge-based risk assessor 34 provides an output of a risk score 36, which may be indicative of the likelihood that the exchange is fraudulent and an indication of the evidence/justifi cation 38 used in the determination.
  • Figures 3 to 9 are schematic views of an electronic device 40 providing a number of outputs to a receiver of a call. In the examples of Figures 3 to 9, a call has been received by the electronic device 40. Figures 3 to 9 show sequential examples of the various outputs that may be provided as the call progresses.
  • the electronic device 40 is a telephone, for example a landline telephone, having a screen 42 configured to display one or more outputs. However, it will be understood that the electronic device 40 may be any suitable and desired type.
  • Figure 3 shows the screen 42 as part of an electronic device 40, while Figures 4 to 9 show only the screen 42.
  • Figure 3 shows an example of the outputs that may initially be provided when a call is received by the electronic device 40.
  • a number of outputs are provided.
  • a first output 44 comprises information about the call.
  • the first output 44 includes the phone number (in this example, the phone number is unknown), the caller ID (in this example, there is no caller ID), the location of the potentially fraudulent transmitter, the time of the call, the date of the call and the duration of the call.
  • a second output 46 comprises a transcription of the call.
  • the transcription is provided for exchanges from both the receiver (on the left hand side of the screen) and the potentially fraudulent transmitter (on the right hand side of the screen).
  • the transcription may be provided by the neural network transcription module.
  • a third output 48 comprises an indication of the likelihood that the call is fraudulent.
  • the likelihood is expressed as a percentage (in a numerical form and on a scale) and in words (e.g. scam likely, scam certain). In Figure 3, an initial indication of the likelihood may have been determined before the first exchange has taken place.
  • This initial likelihood may be based on the information about the call indicated in the first output.
  • a fourth output 50 comprises an analysis of certain features of the call.
  • This output may comprise one or more pieces of evidence or rationale used by the knowledgebased risk assessor in determining the likelihood that the call is fraudulent.
  • the evidence/rationale is that the number is cloaked.
  • a fifth output 52 comprises a prompt to perform a selected action.
  • the prompts are in the form of buttons (‘Ask for Help’, ‘End Call’ and ‘Erase Call Record’).
  • the option of ending the call is highlighted as a recommended action.
  • Providing a prompt for a certain action may be based at least on the likelihood that the call is fraudulent.
  • Figures 4 and 5 show examples of the outputs that may be provided after a first exchange from the potentially fraudulent transmitter to the receiver.
  • the second output 46 has been updated to include a transcription of the first exchange from the potentially fraudulent transmitter to the receiver.
  • the sixth output 54 comprises an analysis of certain features of the exchange from the potentially fraudulent transmitter to the receiver. This output may comprise one or more pieces of evidence or rationale used by the knowledge-based risk assessor in determining the likelihood that the exchange is fraudulent.
  • the sixth output 54 is provided to inform the receiver that the company mentioned by the potentially fraudulent transmitter would never call the receiver.
  • One or more of the outputs may be updated as the call takes place, preferably as soon as possible during the call.
  • the second output 46 may be updated as soon as possible after the exchange and the third, fourth, fifth and sixth outputs 48, 50, 52, 54 may be updated as soon as possible after the steps of determining the likelihood that the exchange and/or the call is fraudulent have been completed. Ensuring that the receiver is provided with an output as soon as possible may help to ensure that they can respond appropriately to any further exchanges during the call.
  • Figures 6 and 7 show examples of the outputs that may be provided after a second exchange from the potentially fraudulent transmitter to the receiver.
  • the second output 46 has been updated to include a transcription of the second exchange from the potentially fraudulent transmitter to the receiver.
  • the third and fourth outputs 48, 50 have been updated based on the second exchange. The likelihood that the call is fraudulent has increased and new analysis is provided.
  • the fifth output 52 remains the same after the second exchange. However, it will be understood that any of the outputs may be updated if suitable and desired.
  • Figures 8 and 9 show examples of the outputs that may be provided after a third exchange from the potentially fraudulent transmitter to the receiver.
  • the second output 46 has been updated to include a transcription of the third exchange from the potentially fraudulent transmitter to the receiver.
  • the third, fourth and fifth outputs 48, 50, 52 remain the same after the third exchange. However, it will be understood that any of the outputs may be updated if suitable and desired.
  • the sixth output 54 has been updated based on the third exchange.
  • the analysis further includes a prompt to perform a selected action (to end the call).
  • FIGS. 10 and 11 are schematic diagrams of systems for determining the likelihood that a call is fraudulent.
  • the system comprises a central processor 56.
  • the central processor 56 comprises a neural network transcription module 58, a natural language processing module 60, a knowledge-based risk assessor module 62 and a training module 64.
  • the neural network transcription module 58 is configured to transcribe, using a neural network, the content of the exchange.
  • the natural language processing module 60 is configured to identify, using natural language processing, a category of the exchange, based on at least the content of the exchange.
  • the knowledgebased risk assessor module 62 is configured to determine, using a knowledgebased risk assessor, the likelihood that the exchange is fraudulent, based on at least the category of the exchange and the content of the exchange.
  • the training module 64 is configured to determine, using a knowledge-based risk assessor, the likelihood that the call is fraudulent, based on at least the likelihood that the exchange is fraudulent.
  • the central processor 56 may be any suitable and desired type.
  • the central processor 56 comprises a processor configured to carry out the functions of each of the modules 58, 60, 62, 64.
  • the central processor 56 comprises a plurality of processors in communication with one another, each of which is configured to carry out the functions of one or more of the modules 58, 60, 62, 64.
  • the central processor 56 comprises, or is connected to, a cloud computer.
  • the central processor 56 may form part of a network (e.g. a cellular network), such that the functions of the modules 58, 60, 62, 64 are carried out as part of the functions of the network that enables a call between the potentially fraudulent transmitter and the receiver.
  • the central processor 56 is in communication with a first electronic device 66a and a second electronic device 66b.
  • the potentially fraudulent transmitter and the receiver each communicate with the other via an electronic device.
  • the potentially fraudulent transmitter may communicate using the first electronic device 66a and the receiver may communicate using the second electronic device 66b.
  • the first and second electronic devices 66a, 66b may each be configured to communicate information to the central processor 56, such as sound information (e.g. the voices of the potentially fraudulent transmitter and the receiver respectively), the phone number, the caller and/or the location of the potentially fraudulent transmitter and the receiver respectively.
  • sound information e.g. the voices of the potentially fraudulent transmitter and the receiver respectively
  • the central processor 56 may be configured to provide one or more outputs to the second electronic device 66b.
  • the central processor 56 may provide one or more of: the likelihood that one or more of the exchanges is fraudulent; the likelihood that the call is fraudulent; a prompt to perform a selected action; and evidence or rationale used by the knowledge-based risk assessor module 62 in determining the likelihood of fraud.
  • the central processor 56 may be in communication with any suitable and desired number of electronic devices.
  • the central processor 56 may provide the functions of the modules 58, 60, 62, 64 for any suitable and desired number of calls between any number of devices.
  • the system comprises a central processor 156.
  • the central processor 156 comprises a central neural network transcription module 158, a central natural language processing module 160, a central knowledge-based risk assessor module 162 and a central training module 164.
  • the central processor 156 may be any suitable and desired type, as discussed above (e.g. in relation to Figure 10).
  • the central processor 156 is in communication with a first electronic device 166a and a second electronic device 166b.
  • the potentially fraudulent transmitter and the receiver each communicate with the other via an electronic device.
  • the potentially fraudulent transmitter communicates using the first electronic device 166a and the receiver communicates using the second electronic device 166b.
  • the second electronic device 166b comprises a local processor 256.
  • the local processor 256 comprises a local neural network transcription module 158, a local natural language processing module 160, a local knowledge-based risk assessor module 162 and a local training module 164.
  • the local modules 258, 260, 262, 264 may comprise local (e.g. decentralised) copies of the central modules 158, 160, 162, 164. This may help to ensure that the exchanges of the call can be processed more quickly, which may help to ensure that an output can be provided to the receiver in a suitable and desired timescale.
  • the central processor 156 may provide the functions of the modules 158, 160, 162, 164 for any suitable and desired number of calls between any number of devices. Therefore, the central modules 158, 160, 162, 164 may be provided with training sets from a plurality of devices. This may allow the central modules 158, 160, 162, 164 to be trained more frequently and/or with a greater number of training sets than the local modules 258, 260, 262, 264. Therefore, the central modules 158, 160, 162, 164 may communicate updated training information and/or updated evidence/rationale to the local modules 258, 260, 262, 264 when suitable and desired. This may help to ensure that the local modules 258, 260, 262, 264 stay up- to-date with any changes to fraudulent calls.
  • Recording and/or processing information on the local processor 256 may help to ensure that the privacy of the receiver may be protected.
  • the privacy of the recipient may be protected by only sending information to the central processor 156 after local processing of the information has taken place.
  • Local processing may include the steps of redacting personal information and/or extracting non-personal information about the call (e.g. the key named entities, the details of the pretext, the elicited details and/or any requested actions).
  • the local processor 256 may send the processed (non-personal) information to the central processor 156 to ensure that the central processor receives updated training information without loss of privacy to the receiver.
  • the local processor 256 comprises a local version of all of the modules of the central processor 156, it will be understood that the local processor 256 may comprise any suitable and desired number and combination of local modules.
  • the local processor 256 may comprise only a local neural network transcription module 258.
  • the output of the local neural network transcription module 258 may be provided to the central processor 156 and the functions of the other modules may be performed by the central processor 156.
  • the first and second electronic devices 166a, 166b may each be configured to communicate information to the central processor 156, as described above (e.g. in relation to Figure 10).
  • the information provided by the second electronic device 166b may depend upon the local modules that are present on the local processor 256.
  • the central processor 156 may be configured to provide one or more outputs to the second electronic device 166b, as described above (e.g. in relation to Figure 10). The outputs provided by the second electronic device 166b may depend upon the local modules that are present on the local processor 256. In addition, the central processor 156 may be configured to provide updates from the central modules 158, 160, 162, 164 to the local modules 258, 260, 262, 264.
  • Figure 12 is a flow chart showing how a knowledge-based risk assessor and/or a natural language processor may be trained.
  • a transcript of a new potentially fraudulent conversation is provided.
  • the transcript includes analysis of the content of the call, which may be provided by a person.
  • the transcript may include an indication that the call is likely to be fraudulent.
  • personal information is redacted from the transcript. This may include information such as the name of the receiver, the phone number of the receiver and/or information provided by the receiver during the call.
  • information about the content of the potentially fraudulent call is extracted from the transcript by natural language processing (NLP).
  • NLP natural language processing
  • the information may be suitable for determining the likelihood that the call is fraudulent.
  • the information may include one or more of: the key named entities 306; the pretext details 308; the elicited details 310 and the call-to-action 312.
  • the internal knowledge base and natural language processing classifiers are updated (based on the information extracted at step 304).
  • the internal knowledge base may be a database for storing information about (potentially) fraudulent calls.
  • the natural language processing classifiers may map an incoming call to certain categories, for example corresponding to the likelihood that the call is fraudulent. Updating the internal knowledge base and the classifiers may help to ensure that the system is configured to correctly identify potentially fraudulent calls even if the transmitters adapt their techniques over time.
  • the intelligence sharing network may be any type of network (e.g. a cloud computing network and/or a communication over the internet).
  • the intelligence sharing network may be configured to provide a connection between local processors performing one or more steps of the method.
  • steps 300, 302, 304 and 314 are carried out on a local processor (e.g. of a first handset)
  • the intelligence sharing network is provided to ensure that information from the local processor is shared with other local processors (e.g. of other handsets). This may help to ensure that all of the local processors connected by the intelligence sharing network are able to access the new information, thereby helping to ensure that all of the local processors perform equally well at identifying fraudulent calls.
  • the embodiments discussed above provide a (e.g. computer-implemented) method of and system for determining the likelihood that a call is fraudulent.
  • the method and system may help to ensure that the receiver responds appropriately to a call based on the likelihood that the call is fraudulent. This may help to ensure that the risk of potential (e.g. financial) loss as a result of a fraudulent call are reduced. This may be particularly advantageous for vulnerable people (e.g. older adults) who may be more likely to receive and respond to a fraudulent call.

Landscapes

  • Engineering & Computer Science (AREA)
  • Signal Processing (AREA)
  • Telephonic Communication Services (AREA)

Abstract

A method of and system for determining the likelihood that a call is fraudulent. The call includes one or more exchanges from a potentially fraudulent transmitter to a receiver. The potentially fraudulent transmitter and the receiver each communicate with the other via an electronic device. For each of the one or more exchanges from the potentially fraudulent transmitter to the receiver, the method includes the steps of: • transcribing, using a neural network, the content of the exchange; • identifying, using natural language processing, a category of the exchange, based on at least the content of the exchange; • determining, using a knowledge-based risk assessor, the likelihood that the exchange is fraudulent, based on at least the category of the exchange and the content of the exchange; and • determining, using a knowledge-based risk assessor, the likelihood that the call is fraudulent, based on at least the likelihood that the exchange is fraudulent.

Description

Method of and system for identifying fraudulent calls
This present invention relates to a method of and system for determining the likelihood that a call is fraudulent. In particular, it relates to a method and system for determining the likelihood that a part of a call and/or the call as a whole is fraudulent.
Telephone fraud accounts for one of the most significant crimes in the UK, in terms of frequency, impact and pervasiveness. According to UK government figures, fraud accounts for around 40% of all crime in England and Wales, with an estimated 3.2 million offences each year. The estimated cost of fraud to society is £6.8 billion per year in England and Wales.
While criminals are increasingly targeting all segments of the population, older and vulnerable adults have tended to be the primary target and the worst affected. This demographic not only have the most at stake, but also often possess the weakest defences against such attempts, making the average success rates much higher for this group than others. This demographic also includes many who prefer using phone calls as their primary means of keeping in touch with relatives and accessing vital services such as doctors.
It is an object of the present invention to provide a method of and system for identifying fraudulent phone calls.
According to a first aspect, there is provided a method of determining a likelihood that a call is fraudulent, wherein the call comprises one or more exchanges from a potentially fraudulent transmitter to a receiver; and wherein the potentially fraudulent transmitter and the receiver each communicate with the other via an electronic device; wherein, for each of the one or more exchanges from the potentially fraudulent transmitter to the receiver, the method comprises the steps of: transcribing, using a neural network, the content of the exchange; identifying, using natural language processing, a category of the exchange, based on at least the content of the exchange; determining, using a knowledge-based risk assessor, the likelihood that the exchange is fraudulent, based on at least the category of the exchange and the content of the exchange; and determining, using a knowledge-based risk assessor, the likelihood that the call is fraudulent, based on at least the likelihood that the exchange is fraudulent.
According to a second aspect, there is provided a system for determining a likelihood that a call is fraudulent, wherein the call comprises one or more exchanges from a potentially fraudulent transmitter to a receiver; and wherein the potentially fraudulent transmitter and the receiver each communicate with the other via an electronic device; wherein the system comprises: a neural network transcription module; a natural language processing module; and a knowledge-based risk assessor module; wherein the system is configured to, for each of the one or more exchanges from the potentially fraudulent transmitter to the receiver: transcribe, using the neural network transcription module, the content of the exchange; identify, using the natural language processing module, a category of the exchange, based on at least the content of the exchange; determine, using the knowledge-based risk assessor module, the likelihood that the exchange is fraudulent, based on at least the category of the exchange and the content of the exchange; and determine, using a knowledge-based risk assessor module, the likelihood that the communication is fraudulent, based on at least the likelihood that the exchange is fraudulent.
The present invention provides a (e.g. computer-implemented) method of and system for determining the likelihood that a call is fraudulent. The method and system may help to ensure that the receiver responds appropriately to a call based on the likelihood that the call is fraudulent. This may help to ensure that the risk of potential (e.g. financial) loss as a result of a fraudulent call are reduced. This may be particularly advantageous for vulnerable people (e.g. older adults) who may be more likely to receive and respond to a fraudulent call.
The features discussed herein in relation to the method apply equally to the system and vice versa.
The call comprises one or more exchanges from a potentially fraudulent transmitter to a receiver. In some embodiments, each of the potentially fraudulent transmitter and the receiver are people. In some embodiments, the potentially fraudulent transmitter is a machine (e.g. an automated machine).
The call may be any suitable and desired type. In some embodiments, the call comprises a phone call (e.g. including the transmission of sound). In some embodiments, the call comprises a video call (e.g. including the transmission of sounds and images). The call may be initiated by either one of the potentially fraudulent transmitter and the receiver.
The potentially fraudulent transmitter and the receiver each communicate with the other via an electronic device. The electronic devices may each be any suitable and desired type.
In some embodiments, each of the electronic devices comprises a telephone or a computer. For example, each of the electronic devices may comprise any one of a mobile telephone, a landline telephone, a satellite phone, a Voice over Internet Protocol (VoIP) device, a computer and/or a videotelephony device. The potentially fraudulent transmitter and the receiver may be connected by any suitable and desired network.
The exchange may be any suitable and desired type. In some embodiments, an exchange comprises a turn in the conversation (e.g. a contribution to a conversation by the potentially fraudulent transmitter, after which the receiver may (e.g. is expected to) respond). Therefore, in some embodiments, a turn in the conversation may correspond to the words that are transmitted between breaks or pauses in a conversation, wherein the breaks or pauses in a conversation give the other person in a conversation the opportunity to speak.
Each exchange from the potentially fraudulent transmitter to the receiver may be any suitable and desired length. In some embodiments, an exchange comprises one or more words. In some embodiments, an exchange comprises one or more sentences.
The transmitter is potentially fraudulent. A fraudulent call may comprise the transmitter claiming to be someone or something that they are not. For example, the transmitter may claim to be representing a certain company or organisation that they are not.
A fraudulent call may comprise the transmitter attempting to and/or succeeding in eliciting information from the receiver (e.g. by providing the receiver with false information). The information may comprise personal information (e.g. a name, an address and/or a date of birth) and/or financial information (e.g. bank details and/or card details). This information may be used in (criminal) fraudulent activity, such as credit card fraud and/or identity theft. This may lead to (e.g. financial) loss on the part of the receiver.
A fraudulent call may comprise the transmitter offering to provide a product or service that the receiver does not want and/or that is not as advertised. In some embodiments, such a call may comprise coercive, manipulative or pressurising techniques on the part of the transmitter. Such a call may be considered fraudulent in that the call may result in the receiver paying money for a product or service that they do not want and/or that is not as advertised.
A fraudulent call may comprise the transmitter attempting to and/or succeeding in eliciting a certain action from the receiver (e.g. by providing the receiver with false information or pressuring the receiver). The certain action may comprise transferring money to a bank account, opening a new bank account and/or purchasing a certain product (e.g. gift cards) to be provided to the transmitter. Such an action may directly or indirectly lead to (e.g. financial) loss for the receiver. The method determines that a likelihood that a call is fraudulent. The likelihood that the call is fraudulent may be expressed (e.g. quantified) in any suitable and desired way. In some embodiments, the likelihood may be expressed as a numerical value (e.g. a percentage having any value between 0% and 100%). In some embodiments, the likelihood may be expressed in words (e.g. very low, low, medium, high, very high). In some embodiments, a combination of numerical values and words may be used to express the likelihood that the call is fraudulent.
The method comprises a number of steps for each of the one or more exchanges from the potentially fraudulent transmitter to the receiver. Repeating the steps of the method for each of the exchanges from the potentially fraudulent transmitter to the receiver may help to ensure that all of the exchanges of the call (e.g. all of the information provided by the potentially fraudulent transmitter) is taken into account when determining the likelihood that the call is fraudulent. This may help to increase the accuracy of the method.
Furthermore, when the steps of the method are carried out during the call, repeating the steps of the method for each exchange may help to ensure that an output can be provided to the receiver more quickly and/or more frequently. For example, by (e.g. immediately) transcribing each exchange and determining the likelihood that the exchange and the call are fraudulent based on this information, an output may be provided to the receiver as soon as possible. This may help to ensure that the receiver is able to respond appropriately to any further exchanges. In particular, the receiver is able to respond appropriately, based on the determined likelihood that the call is fraudulent, to any requests for (e.g. personal and/or financial) information from the receiver. This may help to reduce the risk that the receiver provides information that could be used in fraudulent activity.
The method includes the step of transcribing, using a neural network, the content of the exchange. The step of transcribing the content of the exchange may comprise taking (e.g. capturing and/or recording) the sound from an exchange (e.g. a voice and/or spoken word(s)) and producing a written (e.g. text) output (e.g. a record of) the sounds of the exchange. The written (e.g. text) output may be stored for subsequent use, e.g. analysis, as part of the method and/or by the system. T ranscribing the content of the exchange may provide a convenient way to analyse, store and/or transmit the content of the exchange. In particular, the transcription may be provided as an input to the knowledge-based risk assessor. Storing the transcribed conversation may help to provide evidence of the conversation and/or for analysis of the conversation at a later time. Furthermore, the transcription of the conversation may be provided as an output to the receiver (e.g. during the call). This may help them to understand the content of the call and therefore take appropriate action in response to any potentially fraudulent requests (e.g. for information).
The neural network may be any suitable and desired type. In some embodiments, the neural network may be trained using recordings of speech, such as recordings of (e.g. telephone) conversations.
The method includes the step of identifying, using natural language processing, a category of the exchange, based on at least the content of the exchange. The exchanges may be categorised in any suitable and desired way. Categorising the exchanges may help to contextualise the content of the exchange, thereby helping to determine, in combination with the content of the exchange, the likelihood that the exchange is fraudulent.
The natural language processor may be any suitable and desired type. In some embodiments, the natural language processor comprises an artificial intelligence (Al) system. In some embodiments, the natural language processor comprises a machine learning system. The machine learning system may be trained using real conversations. In some embodiments, the machine learning system may be trained using telephone conversations, such as fraudulent telephone conversations.
In some examples, the natural language processor may be trained using artificially synthesised conversations. These artificially synthesised conversations may be based on real conversations and may be adapted to include, for example, different pretexts, different company names and/or a different requested action. This may help to ensure that the natural language processor is able to identify potentially fraudulent calls even if the content of such a call is different from real conversations that have previously taken place. This may be advantageous because transmitters making fraudulent calls are likely to change their tactics over time to avoid detection. Therefore, training the machine learning system using artificially synthesised conversations may help to improve the ability of the system to correctly identify fraudulent calls.
In some embodiments, the category of the exchange comprises a component of conversation. For example, a component of conversation may be one of: attestation; pretext; marketing; elicitation; and action request.
An exchange categorised as attestation may comprise the potentially fraudulent transmitter identifying themselves. For example, the potentially fraudulent transmitter may state their name and state that they are calling from a certain organisation (e.g. company).
An exchange categorised as pretext may comprise a statement about why the potentially fraudulent transmitter is calling. For example, the potentially fraudulent transmitter may state that they are calling with an offer of technical support, customer service and/or a courtesy call.
An exchange categorised as marketing may comprise an offer of a product or service that the receiver did not initiate. In some embodiments, an exchange categorised as marketing may comprise coercive, manipulative or pressurising techniques on the part of the potentially fraudulent transmitter. In some embodiments, such marketing may be considered fraudulent in that the receiver may pay money for a product or service that they do not want and/or that is not as advertised.
An exchange categorised as elicitation may comprise a request for information from the potentially fraudulent transmitter. For example, the potentially fraudulent transmitter may ask the receiver to provide personal information such as their name, address, date of birth, bank details, passwords. This information could be used in fraudulent activity.
An exchange categorised as action request may comprise the potentially fraudulent transmitter asking or demanding that the receiver does something. For example, the potentially fraudulent transmitter may ask or demand that the receiver presses buttons on their phone, initiates a telephone call (e.g. to a certain number provided by the potentially fraudulent transmitter), or buys a certain product (e.g. gift cards). These action requests may help to facilitate fraudulent activity.
Hence, in some embodiments, the category of the exchange may be related to the purpose of the exchange. For example, the purpose of an attestation is to explain to the receiver why the call is taking place (and in the case of a fraudulent call, to legitimise the call), whereas the purpose of an action request is to elicit (e.g. personal) information from the receiver (e.g. for use in fraudulent activity).
Categorising the exchanges in this manner may help to contextualise the content of the exchange, thereby helping to (accurately) determine the likelihood that the exchange is fraudulent. This may help the system to infer the intent of the exchange.
In some embodiments, the knowledge-based risk assessor may use a different set of evidence and rationale for (e.g. each of) the different categories. This helps to ensure that the step of determining the likelihood that the exchange is fraudulent is configured to take into account the context of the exchange.
The method includes the step of determining, using a knowledge-based risk assessor, the likelihood that the exchange is fraudulent, based on at least the category of the exchange and the content of the exchange. The likelihood that the exchange is fraudulent may be determined in any suitable and desired way.
The information that has been gathered through the transcription and the categorisation are used to determine the likelihood that the exchange is fraudulent. The category of the exchange may help to provide context for the content of the exchange. This may help to ensure that any evidence and/or rationale that is used in the determination is applied in the appropriate context. This may help to increase the accuracy of the determination.
The method includes the step of determining, using a knowledge-based risk assessor, the likelihood that the call is fraudulent, based on at least the likelihood that the exchange is fraudulent. The likelihood that the call is fraudulent may be determined in any suitable and desired way. The likelihood that the call is fraudulent may be updated after each exchange of the conversation.
In some embodiments, the knowledge-based risk assessor determines the likelihood that the exchange and/or the call is fraudulent based on a phone number of the potentially fraudulent transmitter and/or an identity of the potentially fraudulent transmitter.
For example, if the potentially fraudulent transmitter identifies themselves using a company name, the knowledge-based risk assessor may be configured to determine the likelihood that this identity is true based on facts about the company. For example, some companies may state (e.g. on their website) that they will never call a customer. In this scenario, if the potentially fraudulent transmitter identifies themselves as calling from this company, such a call is very likely to be fraudulent. This information may be used to train a knowledge-based risk assessor.
Similarly, many companies make their telephone numbers publicly available. If the potentially fraudulent transmitter identifies themselves as calling from a company but their telephone number does not match the publicly available telephone number, such a call may have a higher likelihood of being fraudulent. This information may be used to train a knowledge-based risk assessor.
In some examples, the potentially fraudulent transmitter may cloak or hide their phone number and/or identity. This may indicate that the potentially fraudulent transmitter wishes to hide the origin of the call. Therefore, a lack of an identifiable phone number or identity of the potentially fraudulent transmitter may be used to determine the likelihood that the exchange and/or the call is fraudulent.
In some embodiments, the step of determining, using a knowledge-based risk assessor, the likelihood that the call is fraudulent is based on a plurality (e.g. all) of the exchanges of the call.
That is, the likelihood that the call is fraudulent may be based not only on the individual (i.e. separate) likelihood that each exchange is fraudulent, but on the information that is received during (e.g. any combination of) two or more (e.g. all) of the exchanges of the call. This may help to ensure that the knowledge-based risk assessor is configured to take the overall context of the call into account when determining the likelihood that a call is fraudulent. This may increase the likelihood that a fraudulent call is correctly identified.
For example, the identity of the potentially fraudulent transmitter may be important during an assessment of the rest of the call. In the context of a call from a company, a request for personal information (e.g. an address or a date of birth) may indicate fraudulent activity. However, the same request from a personal contact (e.g. a friend or family member) may not indicate fraudulent activity. Hence, it may be advantageous to update the likelihood that the call is fraudulent after further exchanges (e.g. after each exchange) of the call, based not on the most recent exchange but on further (e.g. all of the) exchanges of the call.
In another example, a call reminding the receiver about an upcoming appointment (e.g. a doctor’s appointment) may not initially appear to be fraudulent. However, if the potentially fraudulent transmitter later asks for the receiver’s bank details, this may contradict the reason for the call. This contradiction in itself may increase the likelihood that the call is fraudulent, separately from the fact that the potentially fraudulent transmitter is asking for bank details from the receiver.
In some examples, the step of determining, using a knowledge-based risk assessor, the likelihood that the call is fraudulent is based on information about one or more previous calls from the potentially fraudulent transmitter to the receiver.
A potentially fraudulent transmitter may call the same receiver multiple times. Information about the calls previously received may be recorded (e.g. locally on the receiver’s device and/or on a central processor). The information may include information about the call itself (e.g. the date and time the calls were received) and/or information about the content of the call (e.g. the reported identity of the potentially fraudulent transmitter, the pretext of the call, any requests for action).
This information may be used when determining the likelihood that the current call is fraudulent. For example, if calls have been received from the same number but the transmitter offers a different identity each time, this may indicate that the call is fraudulent, even if each individual call appears to have a low likelihood of being fraudulent (e.g. based on the content of each of the calls in isolation from one another). Therefore, using information about one or more previous calls from the potentially fraudulent transmitter to the receiver may help to increase the probability that fraudulent calls are correctly identified.
In some embodiments, for (e.g. each of the) one or more exchanges from the potentially fraudulent transmitter to the receiver, the method comprises the step of providing an output to the receiver.
The one or more outputs may be provided at any suitable and desired time. It may be advantageous to provide the output during the call, in particular at a time shortly after (e.g. each of) the exchange(s). This may help to ensure that the receiver is able to respond to and/or engage with the call appropriately based on the output.
In some embodiments, the output indicates one or more of: the likelihood that one or more of the exchanges is fraudulent; the likelihood that the call is fraudulent; a prompt to perform a selected action; and evidence or rationale used by the knowledge-based risk assessor in determining the likelihood of fraud.
The likelihood that one of more of the exchanges and/or the call is fraudulent may be provided as an output in any suitable and desired way. For example, the likelihood may be expressed using a percentage, using words (e.g. low, medium, high), using colours, using images and/or using a sound.
The output may comprise a prompt to perform any suitable and desired action. For example, the output may comprise a prompt to terminate the call (e.g. if it is determined that there is a high likelihood that the call is fraudulent). This may help to ensure that the receiver is not able to provide any information to the potentially fraudulent transmitter that could be used fraudulently.
The output may comprise a prompt to terminate the call and verify information. For example, if the potentially fraudulent transmitter identifies themselves as calling from a certain company, the output may comprise a prompt to contact that company to verify that the information provided in the call is correct. This may help to ensure that the receiver does not engage with any requests until it is verified from another source that the request is not fraudulent.
The output may comprise a prompt to share information about the call. For example, if the receiver is vulnerable, the output may comprise a prompt to tell a third party (e.g. another person such as a caregiver) about the call (e.g. if it is determined that there is a high likelihood that the call is fraudulent). This may help to ensure that the third party may take appropriate action in response to a potentially fraudulent call if the receiver of the call is not able to.
In some examples, the output may comprise directly sharing information about the call with a third party (e.g. another person such as a caregiver). For example, if there is a high likelihood that the call is fraudulent and the receiver has shared personal information (e.g. credit card details), the output may comprise an indication that this information has been shared and/or a record of the information that has been shared. This output may be intended to inform the third party about the outcome of the call. This may help to ensure that the third party may take appropriate action in response to a potentially fraudulent call if the receiver of the call is not able to.
The output may comprise a prompt advising the receiver not to perform a certain action. For example, the output may comprise a prompt advising the receiver not to provide personal information (e.g. if it is determined that there is a high likelihood that the call is fraudulent). This may help to ensure that the receiver does not provide information that could be used fraudulently.
In some embodiments, the output comprises (e.g. an indication of) the evidence or the rationale used by the knowledge-based risk assessor in determining the likelihood of fraud. This may help the receiver to learn how to recognise the signs that a call is fraudulent (or is not fraudulent), thereby helping to increase the likelihood that the receiver will be able to recognise potentially fraudulent calls in the future. This helps to reduce the risk of (e.g. financial) loss for the present call and for calls in the future. In some embodiments, (e.g. an indication of) the evidence or the rationale used by the knowledge-based risk assessor in determining the likelihood of fraud comprises one or more of: the telephone number of the potentially fraudulent transmitter; whether the potentially fraudulent transmitter has hidden their telephone number; the caller ID of the potentially fraudulent transmitter, or lack thereof; the location of the potentially fraudulent transmitter; information about the organisation that the potentially fraudulent transmitter appears to represent (e.g. the (correct) telephone number of the organisation, an indication of whether that organisation will call their customers); an indication of how frequently the content of one or more exchanges of the call are present in fraudulent calls (e.g. whether the pretext is one commonly used during fraudulent calls); an indication that the potentially fraudulent transmitter is asking the receiver to perform an action and/or provide information; the content of the exchange; and the category of the exchange.
In some embodiments, the method comprises the step of terminating the call if the likelihood that the call is fraudulent is greater than a particular threshold. In some embodiments, the step of terminating the call may be performed without any action required from the receiver.
In some embodiments, the particular threshold may be more than 50% likelihood, optionally more than 60% likelihood, optionally more than 70% likelihood, optionally more than 80% likelihood, optionally more than 90% likelihood.
The particular threshold may be any suitable and desired threshold. In some embodiments, the particular threshold may be selected by the receiver. For example, the receiver and/or a caregiver, if applicable, may set a particular threshold based on their own preferences and/or needs, for example with regard to the risk they wish to tolerate. This may help to ensure that the method is able to provide a suitable and desired level of support to the receiver according to their preferences and/or needs.
In some embodiments, the method comprises the step of terminating the call only if certain requirements have been met. In particular, these requirements may include that there is a particularly high likelihood that the call is fraudulent and that the receiver has not carried out certain actions to mitigate the risk of (e.g. financial) loss owing to the potentially fraudulent call. For example, if the receiver continues to engage with the call despite an output indicating a high likelihood of fraud, then the call may be terminated.
In some embodiments, the step of terminating the call (e.g. without any input from a receiver) may be particularly advantageous if the receiver has an increased vulnerability to fraud. For example, this may be advantageous if the receiver has a cognitive impairment, which means they may be less able to take appropriate action in response to a potentially fraudulent call. Terminating the call reduces the likelihood that the receiver engages with a potentially fraudulent call, thereby helping to reduce the risk of (e.g. financial) loss as a result of fraudulent activity.
In some embodiments, the steps of the method are carried out during the call. That is, the likelihood that the exchange is fraudulent and the likelihood that the call is fraudulent are determined at the same time as the call is taking place (i.e. before the call has ended). This helps to ensure that appropriate action may be taken during the call, based on the determined likelihood that the exchange and/or the call is fraudulent.
For example, if it is determined that there is a high likelihood that the exchange and/or the call is fraudulent, the receiver may be motivated to take an action such as to terminate the call or to not take a requested action, such as providing personal information to the potentially fraudulent transmitter. This may help to ensure that the receiver does not engage with potentially fraudulent requests from the potentially fraudulent transmitter, thereby helping to prevent any potential (e.g. financial) loss as a result of a potential fraud. In some embodiments, one or more steps of the method may be carried out after the call has ended. For example, if the receiver has engaged with a potentially fraudulent transaction during a call, it may be advantageous to determine the likelihood that the transaction was fraudulent even after the call has ended. This may help to determine whether any action should be taken to mitigate any potential (e.g. financial) loss as a result of the potential fraud (e.g. cancelling the receiver’s bank cards, contacting the receiver’s bank and/or reporting the fraudulent activity).
In some embodiments, the knowledge-based risk assessor comprises a neural network. The neural network may be any suitable and desired type.
The knowledge-based risk assessor may be trained in any suitable and desired way. In some examples, the knowledge-based risk assessor is trained based on data from a trusted (external) source of data. For example, the knowledge-based risk assessor may be trained on a data set from a network provider (e.g. of known phone numbers for certain companies). In some examples, the knowledge-based risk assessor may be trained using open source intelligence (e.g. about the identity of certain companies, information about certain phone numbers, and/or known pretexts for fraudulent calls).
In some embodiments, the knowledge-based risk assessor is trained using a set of calls that are known to be fraudulent. For example, the knowledge-based risk assessor may be trained using transcribed calls whereby the content and category of each of the exchanges of the call has been identified (e.g. by a person). One or more exchanges of the transcribed calls and/or the transcribed calls as a whole may also be identified as fraudulent or non-fraudulent.
In some examples, the knowledge-based risk assessor is trained at least in part using a set of calls that are known not to be fraudulent. Some non-fraudulent personal call may comprise some of the same features as a fraudulent call. For example, a friend may call asking for personal information such as the receiver’s address. Training the knowledge-based risk assessor using calls that are known not to be fraudulent may help to improve the knowledge-based risk assessor’s ability to identify non-fraudulent calls. This may help to prevent the number of false-positive identifications of calls as fraudulent. In some embodiments, during training, the knowledge-based risk assessor develops a set of evidence and rationale for determining the likelihood that the exchange and/or the call is fraudulent based on its training.
In some embodiments, the knowledge-based risk assessor may develop a different set of evidence and rationale for (e.g. each of) the different categories (of an exchange). This helps to ensure that the step of determining the likelihood that the exchange is fraudulent is configured to take into account the context of the exchange.
In some embodiments, the evidence or the rationale developed by the knowledgebased risk assessor for determining the likelihood of fraud comprises one or more of: the telephone number of the potentially fraudulent transmitter; whether the potentially fraudulent transmitter has hidden their telephone number; the caller ID of the potentially fraudulent transmitter, or lack thereof; the location of the potentially fraudulent transmitter; information about the organisation that the potentially fraudulent transmitter appears to represent (e.g. the (correct) telephone number of the organisation, an indication of whether that organisation will call their customers); an indication of how frequently the content of one or more exchanges of the call are present in fraudulent calls; an indication that the potentially fraudulent transmitter is asking the receiver to perform an action and/or provide information; the content of the exchange; and the category of the exchange.
In some embodiments, the method comprises the steps of: recording to a training set at least part of the content of one or more of the exchanges; and training the knowledge-based risk assessor using the training set. Hence, a call that takes place may be fed back into the knowledge-based risk assessor and provided to it for training. Scam attacks are likely to change and develop over time. Therefore, continuing to update the training set with more recent calls may help to ensure that the knowledge-based risk assessor can (accurately) determine the likelihood that a call is fraudulent.
Any suitable and desired part of the content of one or more of the exchanges may be recorded to the training set. In some examples, only some parts of the call may be used to train the knowledge-based risk assessor. In particular, only those parts of the call that do not contain personal information or information that could identify the receiver may be used to train the knowledge-based risk assessor.
In some embodiments, recording to a training set at least part of the content of one or more of the exchanges comprises making a local record of the content of the call (e.g. on the electronic device of the receiver), determining the part(s) of the content of the call to record to the training set and transmitting those part(s) of the content of the call to the knowledge-based risk assessor.
The step of determining the part(s) of the content of the call to record to the training set may comprise determining which parts of the call contain personal information. The step of transmitting those part(s) of the content of the call to the knowledgebased risk assessor may include transmission of non-personal information only.
In some examples, the step of recording, to a training set, at least part of the content of one or more of the exchanges comprises: selecting non-personal data from the one or more exchanges; and recording, to a training set, the selected non-personal data.
By selecting non-personal data from the one or more exchanges, the training set may be updated without recording to the training set any personal information (about the receiver).
The non-personal data may be selected in any suitable and desired way. In some examples, the non-personal data is selected by selecting information that is inherently non-personal (to the receiver), such as the phone number of the potentially fraudulent transmitter. In some examples, the non-personal data is selected by analysing the content of the one or more exchanges (e.g. using one or more of the neural network transcription module, the natural language processing module and the knowledge-based risk assessor module).
In some examples, the privacy of the recipient may be protected by one or both of the following steps. First, the privacy of the recipient may be protected by preventing unnecessary transmission of personal, private and/or sensitive data within the system (e.g. data such as the raw audio, the transcription of the call and/or the results of processing and analysing the call). This type of data may be stored on a device that is connected to the receiver as directly as possible within the system. For example, the personal, private and/or sensitive data may be stored on the user's own electronic devices (which may be in their home) and/or on cloud services, which may in some examples be secured such that the sensitive data is only accessible to the receiver and/or caregivers, where applicable.
Second, the privacy of the recipient may be protected by only disclosing (e.g. with recipient consent) data used for training the knowledge-based risk assessor after a potentially fraudulent call is confirmed to be fraudulent (e.g. by a trusted external source). Furthermore, these disclosures may include only (non-personal) information pertaining to the call itself, such as details of the transmitter’s strategies, and not any personal information pertaining to the recipient.
As outlined in the second aspect, the invention also provides a system for determining the likelihood that a call is fraudulent.
The system may be any suitable and desired system for implementing the modules for determining the likelihood that a call is fraudulent. In some embodiments, the system comprises a data processing (e.g. computing) system. One or more (e.g. all) of the various modules and, e.g., processors of the system may comprise any suitable and desired (e.g. computer) processing units (e.g. central processing units) and may be implemented on various data processing (e.g. computing) devices, e.g. the electronic devices described herein. The neural network transcription module may be configured to transcribe, using a neural network, the content of the exchange. The natural language processing module may be configured to identify, using natural language processing, a category of the exchange, based on at least the content of the exchange. The knowledge-based risk assessor module may be configured to determine, using a knowledge-based risk assessor, the likelihood that the exchange is fraudulent, based on at least the category of the exchange and the content of the exchange. The training module may be configured to determine, using a knowledge-based risk assessor, the likelihood that the call is fraudulent, based on at least the likelihood that the exchange is fraudulent.
In some embodiments, the system comprises a first electronic device and/or a second electronic device. The potentially fraudulent transmitter and the receiver each communicate with the other via an electronic device. For example, the potentially fraudulent transmitter may communicate using the first electronic device and the receiver may communicate using the second electronic device.
In some embodiments, the system comprises a training module, wherein the training module is configured to: record, to a training set, at least part of the content of one or more of the exchanges; and train the knowledge-based risk assessor using the training set.
In some embodiments, the system comprises a central processor; and wherein the central processor comprises one or more of the neural network transcription module, the natural language processing module and the knowledgebased risk assessor module.
The central processor may be any suitable and desired type. In some embodiments, the central processor comprises a processor configured to carry out the functions of each of the modules. In some embodiments, the central processor comprises a plurality of processors in communication with one another, each of which is configured to carry out the functions of one or more of the modules. In some embodiments, the central processor comprises, or is connected to, a cloud computer. In some embodiments, the central processor may form part of a network (e.g. a cellular network), such that the functions of the modules are carried out as part of the functions of the network that enables a call between the potentially fraudulent transmitter and the receiver. The central processor may provide the functions of the modules for any suitable and desired number of electronic devices.
In some embodiments, the electronic device used by the receiver comprises a local processor; and wherein the local processor comprises one or more of the neural network transcription module, the natural language processing module and the knowledgebased risk assessor module. The local processor may be any suitable and desired type.
In some embodiments, the system comprises a central processor and a local processor. In some embodiments, the central processor is in communication with the local processor. The local processor and the central processor may communicate in any suitable and desired way.
In some embodiments, the central processor comprises one or more of: a central neural network transcription module, a central natural language processing module, a central knowledge-based risk assessor module and a central training module. The local processor comprises one or more of: a local neural network transcription module, a local natural language processing module, a local knowledge-based risk assessor module and a local training module.
The local modules may (e.g. each) comprise local (e.g. decentralised) copies of the (e.g. corresponding) central modules. This may help to ensure that the exchanges of the call can be processed more quickly, which may help to ensure that an output can be provided to the receiver in a suitable and desired timescale.
Furthermore, recording and/or processing information locally, at least initially, may help to ensure that the privacy of the recipient may be protected. Recording and/or processing information locally may help to prevent unnecessary transmission of personal, private and/or sensitive data within the system. Furthermore, the privacy of the recipient may be protected by only disclosing (e.g. with recipient consent) data (e.g. used for training the central processor) after local processing of the information has taken place. These disclosures may only include non-personal information pertaining to the call itself, such as details of the callers' strategies, and not any personal information pertaining to the recipient.
The central processor may provide the functions of the modules for any suitable and desired number of calls between any number of devices. Therefore, the central modules may be provided with training sets from a plurality of devices. This may allow the central modules to be trained more frequently and/or with a greater number of training sets than the local modules. Therefore, the central modules may communicate updated training information and/or updated evidence/rationale to the local modules (e.g. when suitable and desired). This may help to ensure that the local modules stay up-to-date with changes to fraudulent calls.
In some examples, in order to preserve users' confidentiality, information about the call is only provided to the central processor after local processing has taken place. For example, the local processor may only share derived knowledge from the potentially fraudulent call, such as the attested identity of the potentially fraudulent transmitter, the nature of the pretext provided by the potentially fraudulent transmitter, any requests for actions and/or any requests for information. Derived knowledge does not include any (personal) information about the recipient (e g. their identity and/or any action that they took during the call). This may help to ensure that information about potentially fraudulent calls can be shared between different devices without compromising the privacy of any receiver in the system.
The local processor may comprise any suitable and desired number and combination of local modules. In some embodiments, the local processor comprises a local version of each of the modules of the central processor. In some embodiments, the local processor comprises a local version of only some of the modules of the central processor. For example, the local processor may comprise only a local neural network transcription module. The output of the local neural network transcription module may be provided to the central processor and the functions of the other modules may be performed by the central processor.
Certain embodiments of the present invention will now be described, by way of example only, with reference to the accompanying drawings in which: Figure 1 is a flow chart of a method of determining the likelihood that a call is fraudulent;
Figure 2 is a schematic diagram showing a method of determining the likelihood that an exchange is fraudulent;
Figures 3 to 9 are schematic views of an electronic device providing a number of outputs to a receiver of a call;
Figures 10 and 11 are schematic diagrams of systems for determining the likelihood that a call is fraudulent; and
Figure 12 is a flow chart showing how a knowledge-based risk assessor and/or a natural language processor may be trained.
Certain embodiments of a method of and system for determining the likelihood that a call is fraudulent are discussed below. The method and system may help to ensure that the receiver responds appropriately to a call based on the likelihood that the call is fraudulent. This may help to ensure that the risk of potential (e.g. financial) loss as a result of a fraudulent call are reduced.
Figure 1 is a flow chart of a method of determining the likelihood that a call is fraudulent.
For each of one or more exchanges from the potentially fraudulent transmitter to the receiver, the method comprises the steps of : transcribing, using a neural network, the content of the exchange 2; identifying, using natural language processing, a category of the exchange, based on at least the content of the exchange 4; determining, using a knowledge-based risk assessor, the likelihood that the exchange is fraudulent, based on at least the category of the exchange and the content of the exchange 6; and determining, using a knowledge-based risk assessor, the likelihood that the call is fraudulent, based on at least the likelihood that the exchange is fraudulent 8.
As shown in Figure 1 , the method further includes the step of providing an output to the receiver 10. The method also includes the steps of recording, to a training set, at least part of the content of one or more of the exchanges 12 and training the knowledge-based risk assessor using the training set 14. The method further includes the step of terminating the call if the likelihood that the call is fraudulent is greater than a particular threshold 16. The method may include any or all of steps 10, 12, 14 and 16 (e.g. after each exchange of the call).
When the call comprises more than one exchange, the steps of the method are repeated for each of the exchanges of the call. Any number of steps may be repeated. For example, steps 2, 4, 6 and 8 of the method may be repeated for each exchange of the call. Any of steps 10, 12, 14 and 16 may additionally be repeated for (e.g. each of the) one of more of the exchanges of the call.
Figure 2 is a schematic diagram showing a method of determining the likelihood that an exchange is fraudulent.
A potentially fraudulent transmitter 20 and a receiver 18 communicate with one another in a call. The call comprises one or more exchanges from the potentially fraudulent transmitter 20 to the receiver 18, which in this example comprise voice information 22.
The one or more exchanges comprising voice information 22 are transcribed using a neural network 24, to produce a written record of the conversation 26. The written record 26 is used to produce a conversation model 28, which comprises a written record of the person who transmitted each exchange and the order in which the exchanges took place.
The conversation model 28 is used to determine the category of an exchange from the potentially fraudulent transmitter 20 to the receiver 18. The category of the exchange comprises a component of conversation. Hence, it is determined whether the exchange comprises one or more of the following components of conversation: attestation, pretext, marketing, elicitation, and action request. It is determined that the exchange comprises pretext and an annotated conversation model 32 is produced.
The annotated conversation model 32 is provided to a knowledge-based risk assessor 34, which is configured to determine the likelihood that the exchange is fraudulent. The knowledge-based risk assessor 34 provides an output of a risk score 36, which may be indicative of the likelihood that the exchange is fraudulent and an indication of the evidence/justifi cation 38 used in the determination.
Any or all of the steps of Figure 2 may be repeated for one or more of the exchanges of a call.
Figures 3 to 9 are schematic views of an electronic device 40 providing a number of outputs to a receiver of a call. In the examples of Figures 3 to 9, a call has been received by the electronic device 40. Figures 3 to 9 show sequential examples of the various outputs that may be provided as the call progresses.
The electronic device 40 is a telephone, for example a landline telephone, having a screen 42 configured to display one or more outputs. However, it will be understood that the electronic device 40 may be any suitable and desired type. Figure 3 shows the screen 42 as part of an electronic device 40, while Figures 4 to 9 show only the screen 42.
The outputs shown in Figures 3 to 9 are exemplary. It will be understood that any suitable and desired output may be provided. The content of the output may vary depending on the content of the call and therefore on the likelihood that the call is fraudulent.
Figure 3 shows an example of the outputs that may initially be provided when a call is received by the electronic device 40. A number of outputs are provided. A first output 44 comprises information about the call. The first output 44 includes the phone number (in this example, the phone number is unknown), the caller ID (in this example, there is no caller ID), the location of the potentially fraudulent transmitter, the time of the call, the date of the call and the duration of the call.
A second output 46 comprises a transcription of the call. The transcription is provided for exchanges from both the receiver (on the left hand side of the screen) and the potentially fraudulent transmitter (on the right hand side of the screen). The transcription may be provided by the neural network transcription module. A third output 48 comprises an indication of the likelihood that the call is fraudulent. The likelihood is expressed as a percentage (in a numerical form and on a scale) and in words (e.g. scam likely, scam certain). In Figure 3, an initial indication of the likelihood may have been determined before the first exchange has taken place.
This initial likelihood may be based on the information about the call indicated in the first output.
A fourth output 50 comprises an analysis of certain features of the call. This output may comprise one or more pieces of evidence or rationale used by the knowledgebased risk assessor in determining the likelihood that the call is fraudulent. The evidence/rationale is that the number is cloaked.
A fifth output 52 comprises a prompt to perform a selected action. The prompts are in the form of buttons (‘Ask for Help’, ‘End Call’ and ‘Erase Call Record’). The option of ending the call is highlighted as a recommended action. Providing a prompt for a certain action (in this example, ending the call) may be based at least on the likelihood that the call is fraudulent.
Figures 4 and 5 show examples of the outputs that may be provided after a first exchange from the potentially fraudulent transmitter to the receiver. In Figure 4, the second output 46 has been updated to include a transcription of the first exchange from the potentially fraudulent transmitter to the receiver.
In Figure 5, the third and fourth outputs have been updated based on the first exchange. The likelihood that the call is fraudulent has increased and new analysis is provided. The fifth output 52 remains the same after the first exchange. However, it will be understood that any of the outputs may be updated if suitable and desired.
Furthermore, a sixth output 54 is provided in Figure 5. The sixth output 54 comprises an analysis of certain features of the exchange from the potentially fraudulent transmitter to the receiver. This output may comprise one or more pieces of evidence or rationale used by the knowledge-based risk assessor in determining the likelihood that the exchange is fraudulent. The sixth output 54 is provided to inform the receiver that the company mentioned by the potentially fraudulent transmitter would never call the receiver. One or more of the outputs may be updated as the call takes place, preferably as soon as possible during the call. For example, the second output 46 may be updated as soon as possible after the exchange and the third, fourth, fifth and sixth outputs 48, 50, 52, 54 may be updated as soon as possible after the steps of determining the likelihood that the exchange and/or the call is fraudulent have been completed. Ensuring that the receiver is provided with an output as soon as possible may help to ensure that they can respond appropriately to any further exchanges during the call.
Figures 6 and 7 show examples of the outputs that may be provided after a second exchange from the potentially fraudulent transmitter to the receiver. In Figure 6, the second output 46 has been updated to include a transcription of the second exchange from the potentially fraudulent transmitter to the receiver. Furthermore, the third and fourth outputs 48, 50 have been updated based on the second exchange. The likelihood that the call is fraudulent has increased and new analysis is provided. The fifth output 52 remains the same after the second exchange. However, it will be understood that any of the outputs may be updated if suitable and desired.
In Figure 7, the sixth output 54 has been updated based on the second exchange. New analysis is provided based on the content of the second exchange.
Figures 8 and 9 show examples of the outputs that may be provided after a third exchange from the potentially fraudulent transmitter to the receiver. In Figure 8, the second output 46 has been updated to include a transcription of the third exchange from the potentially fraudulent transmitter to the receiver. The third, fourth and fifth outputs 48, 50, 52 remain the same after the third exchange. However, it will be understood that any of the outputs may be updated if suitable and desired.
In Figure 8, the sixth output 54 has been updated based on the third exchange. The analysis further includes a prompt to perform a selected action (to end the call).
The first output 44 remains the same in each of Figures 3-9. However, it will be understood that the first output may be updated at any time if suitable and desired. Figures 10 and 11 are schematic diagrams of systems for determining the likelihood that a call is fraudulent.
In the example of Figure 10, the system comprises a central processor 56. The central processor 56 comprises a neural network transcription module 58, a natural language processing module 60, a knowledge-based risk assessor module 62 and a training module 64.
The neural network transcription module 58 is configured to transcribe, using a neural network, the content of the exchange. The natural language processing module 60 is configured to identify, using natural language processing, a category of the exchange, based on at least the content of the exchange. The knowledgebased risk assessor module 62 is configured to determine, using a knowledgebased risk assessor, the likelihood that the exchange is fraudulent, based on at least the category of the exchange and the content of the exchange. The training module 64 is configured to determine, using a knowledge-based risk assessor, the likelihood that the call is fraudulent, based on at least the likelihood that the exchange is fraudulent.
The central processor 56 may be any suitable and desired type. In some embodiments, the central processor 56 comprises a processor configured to carry out the functions of each of the modules 58, 60, 62, 64. In some embodiments, the central processor 56 comprises a plurality of processors in communication with one another, each of which is configured to carry out the functions of one or more of the modules 58, 60, 62, 64. In some embodiments, the central processor 56 comprises, or is connected to, a cloud computer. In some embodiments, the central processor 56 may form part of a network (e.g. a cellular network), such that the functions of the modules 58, 60, 62, 64 are carried out as part of the functions of the network that enables a call between the potentially fraudulent transmitter and the receiver.
The central processor 56 is in communication with a first electronic device 66a and a second electronic device 66b. The potentially fraudulent transmitter and the receiver each communicate with the other via an electronic device. For example, the potentially fraudulent transmitter may communicate using the first electronic device 66a and the receiver may communicate using the second electronic device 66b.
The first and second electronic devices 66a, 66b may each be configured to communicate information to the central processor 56, such as sound information (e.g. the voices of the potentially fraudulent transmitter and the receiver respectively), the phone number, the caller and/or the location of the potentially fraudulent transmitter and the receiver respectively.
The central processor 56 may be configured to provide one or more outputs to the second electronic device 66b. For example, the central processor 56 may provide one or more of: the likelihood that one or more of the exchanges is fraudulent; the likelihood that the call is fraudulent; a prompt to perform a selected action; and evidence or rationale used by the knowledge-based risk assessor module 62 in determining the likelihood of fraud.
Although only two electronic devices 66a, 66b are shown, it will be understood that the central processor 56 may be in communication with any suitable and desired number of electronic devices. For example, if the central processor 56 forms part of a (e.g. cellular) network, the central processor 56 may provide the functions of the modules 58, 60, 62, 64 for any suitable and desired number of calls between any number of devices.
In the example of Figure 11, the system comprises a central processor 156. The central processor 156 comprises a central neural network transcription module 158, a central natural language processing module 160, a central knowledge-based risk assessor module 162 and a central training module 164.
The central processor 156 may be any suitable and desired type, as discussed above (e.g. in relation to Figure 10).
The central processor 156 is in communication with a first electronic device 166a and a second electronic device 166b. The potentially fraudulent transmitter and the receiver each communicate with the other via an electronic device. The potentially fraudulent transmitter communicates using the first electronic device 166a and the receiver communicates using the second electronic device 166b.
The second electronic device 166b comprises a local processor 256. The local processor 256 comprises a local neural network transcription module 158, a local natural language processing module 160, a local knowledge-based risk assessor module 162 and a local training module 164.
The local modules 258, 260, 262, 264 may comprise local (e.g. decentralised) copies of the central modules 158, 160, 162, 164. This may help to ensure that the exchanges of the call can be processed more quickly, which may help to ensure that an output can be provided to the receiver in a suitable and desired timescale.
The central processor 156 may provide the functions of the modules 158, 160, 162, 164 for any suitable and desired number of calls between any number of devices. Therefore, the central modules 158, 160, 162, 164 may be provided with training sets from a plurality of devices. This may allow the central modules 158, 160, 162, 164 to be trained more frequently and/or with a greater number of training sets than the local modules 258, 260, 262, 264. Therefore, the central modules 158, 160, 162, 164 may communicate updated training information and/or updated evidence/rationale to the local modules 258, 260, 262, 264 when suitable and desired. This may help to ensure that the local modules 258, 260, 262, 264 stay up- to-date with any changes to fraudulent calls.
Recording and/or processing information on the local processor 256, at least initially, may help to ensure that the privacy of the receiver may be protected. The privacy of the recipient may be protected by only sending information to the central processor 156 after local processing of the information has taken place. Local processing may include the steps of redacting personal information and/or extracting non-personal information about the call (e.g. the key named entities, the details of the pretext, the elicited details and/or any requested actions). The local processor 256 may send the processed (non-personal) information to the central processor 156 to ensure that the central processor receives updated training information without loss of privacy to the receiver. Although in this embodiment the local processor 256 comprises a local version of all of the modules of the central processor 156, it will be understood that the local processor 256 may comprise any suitable and desired number and combination of local modules. For example, the local processor 256 may comprise only a local neural network transcription module 258. The output of the local neural network transcription module 258 may be provided to the central processor 156 and the functions of the other modules may be performed by the central processor 156.
The first and second electronic devices 166a, 166b may each be configured to communicate information to the central processor 156, as described above (e.g. in relation to Figure 10). The information provided by the second electronic device 166b may depend upon the local modules that are present on the local processor 256.
The central processor 156 may be configured to provide one or more outputs to the second electronic device 166b, as described above (e.g. in relation to Figure 10). The outputs provided by the second electronic device 166b may depend upon the local modules that are present on the local processor 256. In addition, the central processor 156 may be configured to provide updates from the central modules 158, 160, 162, 164 to the local modules 258, 260, 262, 264.
Figure 12 is a flow chart showing how a knowledge-based risk assessor and/or a natural language processor may be trained. At step 300, a transcript of a new potentially fraudulent conversation is provided. In some examples, the transcript includes analysis of the content of the call, which may be provided by a person. For example, the transcript may include an indication that the call is likely to be fraudulent.
At step 302, personal information is redacted from the transcript. This may include information such as the name of the receiver, the phone number of the receiver and/or information provided by the receiver during the call.
At step 304, information about the content of the potentially fraudulent call is extracted from the transcript by natural language processing (NLP). The information may be suitable for determining the likelihood that the call is fraudulent. For example, the information may include one or more of: the key named entities 306; the pretext details 308; the elicited details 310 and the call-to-action 312.
At step 314, the internal knowledge base and natural language processing classifiers are updated (based on the information extracted at step 304). The internal knowledge base may be a database for storing information about (potentially) fraudulent calls. The natural language processing classifiers may map an incoming call to certain categories, for example corresponding to the likelihood that the call is fraudulent. Updating the internal knowledge base and the classifiers may help to ensure that the system is configured to correctly identify potentially fraudulent calls even if the transmitters adapt their techniques over time.
At step 316, the updated internal knowledge base and natural language processing classifiers are provided to the intelligence sharing network. The intelligence sharing network may be any type of network (e.g. a cloud computing network and/or a communication over the internet). The intelligence sharing network may be configured to provide a connection between local processors performing one or more steps of the method. In particular, if steps 300, 302, 304 and 314 are carried out on a local processor (e.g. of a first handset), the intelligence sharing network is provided to ensure that information from the local processor is shared with other local processors (e.g. of other handsets). This may help to ensure that all of the local processors connected by the intelligence sharing network are able to access the new information, thereby helping to ensure that all of the local processors perform equally well at identifying fraudulent calls.
It will therefore be understood that the embodiments discussed above provide a (e.g. computer-implemented) method of and system for determining the likelihood that a call is fraudulent. The method and system may help to ensure that the receiver responds appropriately to a call based on the likelihood that the call is fraudulent. This may help to ensure that the risk of potential (e.g. financial) loss as a result of a fraudulent call are reduced. This may be particularly advantageous for vulnerable people (e.g. older adults) who may be more likely to receive and respond to a fraudulent call.

Claims

Claims
1. A method of determining a likelihood that a call is fraudulent, wherein the call comprises one or more exchanges from a potentially fraudulent transmitter to a receiver; and wherein the potentially fraudulent transmitter and the receiver each communicate with the other via an electronic device; wherein, for each of the one or more exchanges from the potentially fraudulent transmitter to the receiver, the method comprises the steps of: transcribing, using a neural network, the content of the exchange; identifying, using natural language processing, a category of the exchange, based on at least the content of the exchange; determining, using a knowledge-based risk assessor, the likelihood that the exchange is fraudulent, based on at least the category of the exchange and the content of the exchange; and determining, using a knowledge-based risk assessor, the likelihood that the call is fraudulent, based on at least the likelihood that the exchange is fraudulent.
2. The method as claimed in claim 1 , wherein each of the electronic devices comprises a telephone or a computer.
3. The method as claimed in claim 1 or 2, wherein the category of the exchange comprises a component of conversation.
4. The method as claimed in claim 1 , 2 or 3, wherein the knowledge-based risk assessor determines the likelihood that the exchange and/or the call is fraudulent based on a phone number of the potentially fraudulent transmitter and/or an identity of the potentially fraudulent transmitter.
5. The method as claimed in any preceding claim, wherein the step of determining, using a knowledge-based risk assessor, the likelihood that the call is fraudulent is based on a plurality of the exchanges of the call.
6. The method as claimed in any preceding claim, wherein the step of determining, using a knowledge-based risk assessor, the likelihood that the call is fraudulent is based on information about one or more previous calls from the potentially fraudulent transmitter to the receiver.
7. The method as claimed in any preceding claim, wherein, for one or more exchanges from the potentially fraudulent transmitter to the receiver, the method comprises the step of providing an output to the receiver.
8. The method as claimed in claim 7, wherein the output indicates one or more of: the likelihood that one or more of the exchanges is fraudulent; the likelihood that the call is fraudulent; a prompt to perform a selected action; and evidence or rationale used by the knowledge-based risk assessor in determining the likelihood of fraud.
9. The method as claimed in any preceding claim, wherein the method comprises the step of terminating the call if the likelihood that the call is fraudulent is greater than a particular threshold.
10. The method as claimed in any preceding claim, wherein the steps of the method are carried out during the call.
11 . The method as claimed in any preceding claim, wherein the knowledgebased risk assessor comprises a neural network.
12. The method as claimed in claim 11 , wherein the knowledge-based risk assessor is trained using a set of calls that are known to be fraudulent.
13. The method as claimed in claim 11 or 12, wherein, during training, the knowledge-based risk assessor develops a set of evidence and rationale for determining the likelihood that the exchange and/or the call is fraudulent based on its training.
14. The method as claimed in claim 11 , 12 or 13, wherein the method comprises the steps of: recording, to a training set, at least part of the content of one or more of the exchanges; and training the knowledge-based risk assessor using the training set.
15. The method as claimed in claim 14, wherein the step of recording, to a training set, at least part of the content of one or more of the exchanges comprises: selecting non-personal data from the one or more exchanges; and recording, to a training set, the selected non-personal data.
16. A system for determining a likelihood that a call is fraudulent, wherein the call comprises one or more exchanges from a potentially fraudulent transmitter to a receiver; and wherein the potentially fraudulent transmitter and the receiver each communicate with the other via an electronic device; wherein the system comprises: a neural network transcription module; a natural language processing module; and a knowledge-based risk assessor module; wherein the system is configured to, for each of the one or more exchanges from the potentially fraudulent transmitter to the receiver: transcribe, using the neural network transcription module, the content of the exchange; identify, using the natural language processing module, a category of the exchange, based on at least the content of the exchange; determine, using the knowledge-based risk assessor module, the likelihood that the exchange is fraudulent, based on at least the category of the exchange and the content of the exchange; and determine, using a knowledge-based risk assessor module, the likelihood that the communication is fraudulent, based on at least the likelihood that the exchange is fraudulent.
17. The system as claimed in claim 16, wherein the system comprises a training module, wherein the training module is configured to: record, to a training set, at least part of the content of one or more of the exchanges; and train the knowledge-based risk assessor using the training set.
18. The system as claimed in claim 16 or 17, wherein the system comprises a central processor; and wherein the central processor comprises one or more of the neural network transcription module, the natural language processing module and the knowledgebased risk assessor module.
19. The system as claimed in claim 16, 17 or 18, wherein the electronic device used by the receiver comprises a local processor; and wherein the local processor comprises one or more of the neural network transcription module, the natural language processing module and the knowledge- based risk assessor module.
20. The system as claimed in claim 19, wherein the central processor is in communication with the local processor.
PCT/GB2025/051265 2024-06-10 2025-06-10 Method of and system for identifying fraudulent calls Pending WO2025257535A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
GBGB2408287.7A GB202408287D0 (en) 2024-06-10 2024-06-10 Method of and system for identifying fraudulent calls
GB2408287.7 2024-06-10

Publications (1)

Publication Number Publication Date
WO2025257535A1 true WO2025257535A1 (en) 2025-12-18

Family

ID=91845286

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/GB2025/051265 Pending WO2025257535A1 (en) 2024-06-10 2025-06-10 Method of and system for identifying fraudulent calls

Country Status (2)

Country Link
GB (1) GB202408287D0 (en)
WO (1) WO2025257535A1 (en)

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20220377171A1 (en) * 2021-05-19 2022-11-24 Mcafee, Llc Fraudulent call detection
US11943387B1 (en) * 2021-05-19 2024-03-26 Sentien Corporation System and method for intercepting and interdicting telephone fraud

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20220377171A1 (en) * 2021-05-19 2022-11-24 Mcafee, Llc Fraudulent call detection
US11943387B1 (en) * 2021-05-19 2024-03-26 Sentien Corporation System and method for intercepting and interdicting telephone fraud

Also Published As

Publication number Publication date
GB202408287D0 (en) 2024-07-24

Similar Documents

Publication Publication Date Title
US11210461B2 (en) Real-time privacy filter
US11343375B2 (en) Systems and methods for automatically conducting risk assessments for telephony communications
US10728384B1 (en) System and method for redaction of sensitive audio events of call recordings
US10043190B1 (en) Fraud detection database
US10623557B2 (en) Cognitive telephone fraud detection
US11943387B1 (en) System and method for intercepting and interdicting telephone fraud
US8254542B2 (en) Phone key authentication
KR102199831B1 (en) Voice phishing prevention system, voice phishing prevention method and recording medium
EP4016355B1 (en) Anonymized sensitive data analysis
US20220294899A1 (en) Protecting user data during audio interactions
CN108510290A (en) Customer information amending method, device, computer equipment and storage medium in call
CN110766442A (en) Client information verification method, device, computer equipment and storage medium
JP2022163463A (en) communication robot
CN109547651A (en) A kind of reminding method, device and computer storage medium
GB2622478A (en) A system and method for understanding and explaining spoken interactions using speech acoustic and linguistic markers
Sharevski et al. (Blind) Users Really Do Heed Aural Telephone Scam Warnings
JP2023038498A (en) Unwanted call countermeasure system
CN112784038B (en) Information identification method, system, computing device and storage medium
CN114157763A (en) Information processing method and device in interactive process, terminal and storage medium
TWI879255B (en) Fraud prevention smart guidance system
Sharevski et al. " You Creep! It Really Worked!": An Empirical Study of Telephone Scams with Cloned Familiar Voices and Trusted Caller IDs
WO2020171040A1 (en) Voice authentication apparatus, voice authentication method and recording medium
US20110044433A1 (en) Method of generating a temporarily limited and/or usage limited means and/or status, method of obtaining a temporarily limited and/or usage limited means and/or status, corresponding system and computer readable medium
US20240388655A1 (en) In-call scam detection
CN118200439A (en) Identification method and device for outbound fraud telephone, storage medium and electronic equipment

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 25731628

Country of ref document: EP

Kind code of ref document: A1