Home / Journals / CMC / Online First / doi:10.32604/cmc.2026.082491
Special Issues
Table of Content

Open Access

ARTICLE

A Two-Stage Adversarial Defense Architecture for Robust Fraud Detection on Imbalanced Financial Data

Mohammed Saad Javeed1, Jannatul Maua2, Muhammad Firoz Mridha3, Hashibul Ahsan Shoaib4, Taro Suzuki5, Jungpil Shin5,*
1 Information Science, Trine University, Allen Park, MI, USA
2 Department of Computer Science and Engineering, Bangladesh University of Business and Technology, Dhaka, Bangladesh
3 Department of Computer Science, American International University-Bangladesh (AIUB), Dhaka, Bangladesh
4 Information Technology, St. Francis College, Brooklyn, NY, USA
5 School of Computer Science and Engineering, The University of Aizu, Aizu-Wakamatsu, Japan
* Corresponding Author: Jungpil Shin. Email: email

Computers, Materials & Continua https://doi.org/10.32604/cmc.2026.082491

Received 17 March 2026; Accepted 01 June 2026; Published online 13 August 2026

Abstract

As artificial intelligence becomes increasingly embedded in financial systems, ensuring the security and robustness of these models is critical, particularly in sensitive tasks like credit card fraud detection. Despite their predictive success, deep learning models remain vulnerable to adversarial examples: subtly manipulated inputs that can mislead classification outcomes. Unlike existing approaches that typically rely on either adversarial training or standalone input filtering, this paper proposes a unified dual-defense framework that jointly integrates adversarial training with a denoising autoencoder (DAE)-based filtering mechanism, specifically designed for imbalanced tabular financial data under adversarial conditions. Using a real-world, imbalanced credit card transaction dataset of 284,807 transactions, the proposed method achieves superior performance on clean data with an accuracy of 0.991, F1-score of 0.872, and Area Under the Precision–Recall Curve (AUC-PR) of 0.952. Under adversarial conditions, the framework maintains robustness, achieving an F1-score of 0.648 against Fast Gradient Sign Method (FGSM) and 0.610 against Projected Gradient Descent (PGD) attacks, outperforming baseline models by margins of >0.10 in F1. In contrast to prior work that primarily focuses on predictive performance or single-defense strategies, the proposed approach explicitly targets adversarial robustness in financial fraud detection through a complementary integration of defense mechanisms. Ablation studies confirm the complementary effect of adversarial training and DAE-based filtering, while detection analysis shows an adversarial detection accuracy of 87.8%. These findings highlight the practicality of hybrid defense strategies for improving the trustworthiness of AI systems in finance.

Keywords

Adversarial attacks; denoising autoencoder; credit card fraud detection; financial AI systems; robust machine learning; adversarial defense; deep learning
  • 411

    View

  • 33

    Download

  • 0

    Like

Share Link