Transaction Anomaly Pipeline
A batch ML pipeline that scores transaction behaviour, resolves each qualified anomaly to its source evidence, and publishes traceable RabbitMQ events for downstream review.
- Python
- scikit-learn
- BigQuery
- RabbitMQ
- ML pipelines
An existing detector could identify unusual player and game activity, but a model score alone did not give investigators the exact transaction evidence or a dependable route into downstream review systems.
I productionized the detector around its existing model: BigQuery evidence resolution, player-aware windowing, composite-key matching, chunked enrichment, RabbitMQ delivery guarantees, and privacy-conscious operational logging.
Round, user, and domain identifiers form a composite match, preventing evidence from different identities or domains from being joined through a reused round identifier.
Large evidence lookups run in chunks, while each published message carries a unique delivery ID, schema metadata, persistent delivery settings, and broker confirmation handling.
Logs retain message size, a short payload hash, progress, and returned-message diagnostics without recording the complete sensitive event body.
The system is explicitly post-transactional: it supports investigation after activity occurs and does not approve, decline, block, or reroute transactions.