Skip to content
Conference

Explainable Service-Oriented Investigative Intelligence for Automated Digital Evidence Prioritization in Cyber-Financial Crime

Jul 2026 · International Symposium on Service Oriented Software Engineering · pp. 9-16 · 0 citations · 18 references

Abstract

This paper proposes an explainable, service-oriented investigative intelligence architecture for national-level cyber-financial crime investigations in law-enforcement environments. The revised architecture specifies concrete service contracts for heterogeneous evidence ingestion, schema normalization, graph-based community analytics, outcome-aware prioritization, and explainable AI (XAI) decision support. It further introduces policy-driven, multi-tenant customization so that different investigative units and crime types can configure feature weights, alert thresholds, data-access rules, and explanation granularity without changing the core service fabric. To strengthen implementation clarity, the paper details the priority inference and XAI service design, including feature-group scoring, model-version control, local and global explanation generation, provenance linkage, and audit logging tied to chain-of-custody records. The evaluation is grounded in more than 2,500 cyber-financial crime cases and is expanded beyond manual comparison to include heuristic, graph-only, and classifier-only baselines, stratified holdout validation, statistical significance testing, and a reproducibility pathway based on anonymized schemas, synthetic benchmark generation, and shareable service-level protocols. The results indicate that EIIA substantially improves top-N concentration of high-impact indicators, reduces time-to-identification, and supports legally defensible, auditable investigative decision-making. Rather than claiming a new fraud-detection algorithm, this work contributes a reference architecture for operationalizing established graph analytics and XAI techniques as composable, trustworthy investigative services under stringent legal and data-governance constraints.

View source

Similar papers

Conference Jul 2026

LLM Fine-Tuned Threat Intelligence Summarization Agent for CVE Report Automation

In this paper, an intelligent cyber threat intelligence framework involving automated vulnerability severity assessment, contextual risk interpretation and generation of mitigation recommendation is presented. The proposed system has been designed to analyze the CVE-related description of vulnerabilities and the security metadata related to them, classify the level of severity of the threat and estimate its relevance to risk with the help of a transformer-based natural language processing model. To build contextual awareness beyond classification, it adds a retrieval-augmented mechanism to recognize semantically similar vulnerability records for contextual evidence-based threat interpretation. It is additionally fortified with vulnerability analysis, like CVE retrieval, client qualifications, record following, and even visualisation as a web application platform. The two processes, one involving the severities of the transformers, and the other the retrieval of threat intelligence and mitigation advice, into a single operational flow, thus reducing the manual reliance on Vulnerability Triage and aiding security analysts in prioritizing cyber risks. The proposed framework allows for the automatic processing of textual information on vulnerabilities and the comparison of such information and a contextual analysis with previous vulnerabilities discovered. Unlike conventional vulnerability assessment approaches that perform severity classification independently of contextual threat interpretation, the proposed framework integrates transformer-based semantic analysis, retrieval-augmented vulnerability intelligence, cyber-risk estimation, and mitigation recommendation generation within a unified analytical workflow. By combining predictive language modelling with contextual vulnerability retrieval, the framework supports evidence-driven cyber threat analysis and structured decision support for security analysts. The proposed architecture provides a scalable approach for automated vulnerability prioritization and contextual cyber threat intelligence that is suitable for modern cybersecurity operations involving large volumes of vulnerability reports.

Someru Kuruva Giriraju, Shaik Khaja Baba, F. Mahammad et al. · 0 citations
Aug 2026

Engineering Explainable Artificial Intelligence Frameworks for Risk-Based Internal Auditing across Digitally Transformed Banking Infrastructures Globally.

This study engineers an Explainable Artificial Intelligence Risk-Based Internal Auditing Framework integrating multi-source banking data, dynamic risk scoring, anomaly detection, control-risk mapping, explainability mechanisms, and human-in-the-loop validation.

Yemitunde Oyeyemi · 0 citations
Open access Aug 2026

Enhancing cybersecurity with Explainable Artificial Intelligence: technical framework and applications in training labs

Cyberattacks are growing in complexity, and machine-learning-based intrusion detection systems (IDS) are increasingly adopted to support scalable threat monitoring. However, high-performing models can be operationally difficult to deploy when their decisions are not interpretable or auditable. This paper studies explainability as a decision-support component in an IDS workflow rather than as a purely visual add-on. Using the UNSW-NB15 benchmark, we compare three widely used classifiers—Random Forest (RF), Decision Tree (DT), and Support Vector Machine (SVM)—and then analyse the strongest performer (RF) with post-hoc explainability tools: Local Interpretable Model-Agnostic Explanations (LIME) and Shapley Additive Explanations (SHAP). RF achieved 95.3% accuracy (precision 94.8%, recall 96.1%, F1-score 95.4%), exceeding DT and SVM on the same split. LIME and SHAP consistently highlighted traffic-volume and duration-related features (e.g., destination bytes, source bytes, and flow duration) as influential drivers of intrusion predictions, providing actionable hypotheses for analyst triage and policy refinement. We further discuss how explanation outputs can be operationalized in cybersecurity training labs through auditable “rationale artifacts,” while clarifying that any observed reduction in false positives should be interpreted as the outcome of explanation-guided interventions (e.g., threshold tuning and triage rule adjustments) rather than a direct causal effect of generating explanations. Finally, we outline necessary research extensions—controlled baselines, robustness testing, and explanation stability/faithfulness analysis—to ensure reliable deployment of LIME/SHAP in safety-critical IDS settings.

Ahmad Almufarreh, Ashfaq Ahmad, Muhammad Arshad et al. · 0 citations
Open access Aug 2026

Engineering Decision-Grade Intelligence: Designing Preventive Validation Systems for Public-Funded Institutions

Public-funded institutions operate under increasing pressure to demonstrate accountability, transparency, and measurable impact. Despite the widespread collection of programmatic and financial data, many institutions lack formally engineered systems that ensure information used in funding, compliance, and strategic decisions is validated, comparable, and decision ready. This paper introduces the concept of Decision-Grade Intelligence (DGI) and presents a preventive validation framework for institutions managing public or grant-administered resources. The study distinguishes reactive audit correction from preventive validation embedded within institutional data architecture. It proposes a structured systems model integrating data integrity controls, governance checkpoints, comparability standards, and decision-support calibration mechanisms prior to executive action. By applying engineering principles of precision, reliability, and optimization to institutional analytics environments, the framework seeks to reduce downstream accountability failures, improper allocations, and corrective expenditures. The paper further proposes measurable indicators of institutional validation maturity and outlines implementation pathways adaptable across nonprofit, publicsector–adjacent, and hybrid governance contexts. By reframing accountability as an engineering systems challenge rather than a reporting function, this research contributes a cross-sector model for strengthening public trust, fiscal stewardship, and long-term institutional sustainability

Odinaka-olisa James Okonkwo · 0 citations
Sep 2026

A unified architecture for sanctions intelligence in digital asset markets

Sanctions compliance in digital asset markets raises challenges that differ materially from those encountered in traditional financial systems. Public blockchains introduce pseudonymity, indirect exposure, timing effects, and a rapidly evolving landscape of cross-chain movement and decentralised finance activity that complicate the use of entity-centric screening approaches. In practice, virtual asset service providers often address these challenges through fragmented tooling and bespoke logic that is difficult to govern, explain, or scale. This paper presents a unified architecture for sanctions intelligence in digital asset markets. The architecture integrates blockchain data, sanctions designations, analytical enrichment, and governance controls within a modular system design. Rather than proposing a new detection algorithm, the paper focuses on architectural principles that support consistent risk interpretation, explainable decisions, and regulatory defensibility across diverse blockchain environments. Sanctions intelligence is organised into distinct but integrated layers covering data ingestion, enrichment, risk propagation, decision orchestration, and auditability. A lightweight and interpretable risk propagation model is used to demonstrate how indirect exposure, temporal sensitivity, and designation severity can be operationalised without reliance on opaque techniques. The paper also addresses practical deployment considerations within virtual asset service providers, including alert handling, investigator transparency, and supervisory oversight. By offering an implementation-agnostic reference architecture grounded in operational realities, this work provides a foundation for practitioners, system designers, and regulators evaluating scalable and auditable approaches to sanctions compliance in digital asset markets. This article is also included in The Business & Management Collection which can be accessed at http://hstalks.com.business/.

Unknown authors · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.