Privacy-Preserving Fraud Intelligence for Kenya's Account-to-Account Payment Ecosystem
Abstract
This whitepaper proposes a privacy-preserving federated graph intelligence architecture for fraud detection across Kenya’s account-to-account payment ecosystem, using PesaLink as the principal infrastructure context. The research addresses a structural limitation of institution-level fraud detection: fraudulent activity such as account takeover, mule networks, smurfing, layering and rapid cash-out may span multiple financial institutions, while the underlying customer and transaction data remain subject to institutional control, privacy obligations and regulatory safeguards. The proposed architecture combines bank-local heterogeneous graph inference, temporal graph modelling, Graph Neural Networks (GNNs), federated learning, differential privacy (DP-SGD), secure aggregation, confidential computing, hardware attestation and zero-knowledge proofs. Raw transaction graphs remain within participating institutions, while protected model updates support collaborative learning. A bounded two-hop live inference architecture limits the initial production neighbourhood to 166 nodes, linking graph complexity to deterministic memory, latency and replay requirements. The framework separates live inference, federated learning and audit planes, with a sub-50 ms pilot latency objective for bank-edge scoring. A permissioned ledger records narrowly scoped integrity evidence rather than customer transactions or dense model data. The proposed regulatory evidence architecture includes separate privacy-accounting and model-integrity surfaces for oversight without exposing raw customer information. The paper further develops the infrastructure, networking, governance and commercial requirements for implementation. A ring-fenced consortium vehicle, ProjectCo, is proposed to finance, procure, operate and govern the shared utility. The financial model assumes KES 660 million in CAPEX, financed under a working 70% debt/30% equity structure. Using a 2024 banking-sector cyber-fraud loss baseline of approximately KES 1.594 billion, an 80% target reduction corresponds to approximately KES 1.275 billion in modelled annual fraud-loss reduction. The model distinguishes direct ProjectCo financial returns from wider sector economic benefits. Rather than proposing immediate automated deployment, the whitepaper defines an incremental implementation pathway progressing from synthetic benchmarking and participant-local replay through coordinated testing, shadow operation, assisted scoring and ultimately active scoring, subject to model-performance, latency, privacy, resilience, governance and customer-impact gates. Overall, the work presents an integrated framework connecting graph-based financial crime detection, privacy-preserving machine learning, cryptographic assurance, high-performance edge infrastructure, regulatory evidence, consortium governance and project finance. Its broader contribution is a design pattern for collaborative intelligence where useful risk signals span institutional boundaries but sensitive underlying data cannot simply be centralised.