Next-Generation Payment Fraud Intelligence with Large Language Models and Event-Driven Architectures
Abstract
Payment fraud detection at scale must reconcile three pressures: the streaming nature of transaction events, the cost-sensitivity of false alerts, and the practical need for models that can be trained and refreshed on commodity hardware. Recent work has explored advanced text representation models and event-driven architectures as separate research threads, yet relatively few reproducible studies have examined their combination in CPU-only settings. This paper presents a focused, lightweight framework that (i) computes streaming per-user rolling-window features over a chronological event log without future-information leakage, and (ii) augments them with lightweight text representations designed to approximate some subword robustness properties commonly associated with modern pretrained language models, instantiated via character n-gram TF-IDF followed by Truncated Singular Value Decomposition. Using a controlled event stream calibrated to representative fraud patterns—amount anomalies, velocity attacks, geographic and device shifts, and obfuscated merchant memos—we benchmark three feature configurations and two classifiers under a strict chronological hold-out. Adding event-driven features lifts PR-AUC from 0.470 to 0.749, and adding language-aware text representations lifts it further to 0.862; the corresponding F1 climbs from 0.517 to 0.830. The full pipeline trains in under one minute on a single CPU. We position the approach as a practical, language-aware baseline against which heavier pretrained encoders may be compared.