Open Access
ARTICLE
A Two-Stage Adversarial Defense Architecture for Robust Fraud Detection on Imbalanced Financial Data
1 Information Science, Trine University, Allen Park, MI, USA
2 Department of Computer Science and Engineering, Bangladesh University of Business and Technology, Dhaka, Bangladesh
3 Department of Computer Science, American International University-Bangladesh (AIUB), Dhaka, Bangladesh
4 Information Technology, St. Francis College, Brooklyn, NY, USA
5 School of Computer Science and Engineering, The University of Aizu, Aizu-Wakamatsu, Japan
* Corresponding Author: Jungpil Shin. Email:
Computers, Materials & Continua 2026, 89(2), 69 https://doi.org/10.32604/cmc.2026.082491
Received 17 March 2026; Accepted 01 June 2026; Issue published 15 September 2026
Abstract
As artificial intelligence becomes increasingly embedded in financial systems, ensuring the security and robustness of these models is critical, particularly in sensitive tasks like credit card fraud detection. Despite their predictive success, deep learning models remain vulnerable to adversarial examples: subtly manipulated inputs that can mislead classification outcomes. Unlike existing approaches that typically rely on either adversarial training or standalone input filtering, this paper proposes a unified dual-defense framework that jointly integrates adversarial training with a denoising autoencoder (DAE)-based filtering mechanism, specifically designed for imbalanced tabular financial data under adversarial conditions. Using a real-world, imbalanced credit card transaction dataset of 284,807 transactions, the proposed method achieves superior performance on clean data with an accuracy of , F1-score of , and Area Under the Precision–Recall Curve (AUC-PR) of . Under adversarial conditions, the framework maintains robustness, achieving an F1-score of against Fast Gradient Sign Method (FGSM) and against Projected Gradient Descent (PGD) attacks, outperforming baseline models by margins of 0.10 in F1. In contrast to prior work that primarily focuses on predictive performance or single-defense strategies, the proposed approach explicitly targets adversarial robustness in financial fraud detection through a complementary integration of defense mechanisms. Ablation studies confirm the complementary effect of adversarial training and DAE-based filtering, while detection analysis shows an adversarial detection accuracy of . These findings highlight the practicality of hybrid defense strategies for improving the trustworthiness of AI systems in finance.Keywords
Cite This Article
Copyright © 2026 The Author(s). Published by Tech Science Press.This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.


Submit a Paper
Propose a Special lssue
View Full Text
Download PDF
Downloads
Citation Tools