TY - EJOU
AU - Javeed, Mohammed Saad
AU - Maua, Jannatul
AU - Mridha, Muhammad Firoz
AU - Shoaib, Hashibul Ahsan
AU - Suzuki, Taro
AU - Shin, Jungpil
TI - A Two-Stage Adversarial Defense Architecture for Robust Fraud Detection on Imbalanced Financial Data
T2 - Computers, Materials \& Continua
PY -
VL -
IS -
SN - 1546-2226
AB - As artificial intelligence becomes increasingly embedded in financial systems, ensuring the security and robustness of these models is critical, particularly in sensitive tasks like credit card fraud detection. Despite their predictive success, deep learning models remain vulnerable to adversarial examples: subtly manipulated inputs that can mislead classification outcomes. Unlike existing approaches that typically rely on either adversarial training or standalone input filtering, this paper proposes a unified dual-defense framework that jointly integrates adversarial training with a denoising autoencoder (DAE)-based filtering mechanism, specifically designed for imbalanced tabular financial data under adversarial conditions. Using a real-world, imbalanced credit card transaction dataset of 284,807 transactions, the proposed method achieves superior performance on clean data with an accuracy of 0.991, F1-score of 0.872, and Area Under the Precision–Recall Curve (AUC-PR) of 0.952. Under adversarial conditions, the framework maintains robustness, achieving an F1-score of 0.648 against Fast Gradient Sign Method (FGSM) and 0.610 against Projected Gradient Descent (PGD) attacks, outperforming baseline models by margins of >0.10 in F1. In contrast to prior work that primarily focuses on predictive performance or single-defense strategies, the proposed approach explicitly targets adversarial robustness in financial fraud detection through a complementary integration of defense mechanisms. Ablation studies confirm the complementary effect of adversarial training and DAE-based filtering, while detection analysis shows an adversarial detection accuracy of 87.8%. These findings highlight the practicality of hybrid defense strategies for improving the trustworthiness of AI systems in finance.
KW - Adversarial attacks; denoising autoencoder; credit card fraud detection; financial AI systems; robust machine learning; adversarial defense; deep learning
DO - 10.32604/cmc.2026.082491