04
Post-transaction monitoring

Transaction Anomaly Pipeline

A batch ML pipeline that scores transaction behaviour, resolves each qualified anomaly to its source evidence, and publishes traceable RabbitMQ events for downstream review.

Case study
  • Python
  • scikit-learn
  • BigQuery
  • RabbitMQ
  • ML pipelines
01 / Context
Problem

An existing detector could identify unusual player and game activity, but a model score alone did not give investigators the exact transaction evidence or a dependable route into downstream review systems.

My work

I productionized the detector around its existing model: BigQuery evidence resolution, player-aware windowing, composite-key matching, chunked enrichment, RabbitMQ delivery guarantees, and privacy-conscious operational logging.

02 / Architecture
01BigQuery transaction batch
0225-transaction behaviour windows
03Isolation Forest + domain rules
04Composite-key evidence enrichment
05Persistent RabbitMQ events
03 / Key decisions
01

Round, user, and domain identifiers form a composite match, preventing evidence from different identities or domains from being joined through a reused round identifier.

02

Large evidence lookups run in chunks, while each published message carries a unique delivery ID, schema metadata, persistent delivery settings, and broker confirmation handling.

03

Logs retain message size, a short payload hash, progress, and returned-message diagnostics without recording the complete sensitive event body.

04

The system is explicitly post-transactional: it supports investigation after activity occurs and does not approve, decline, block, or reroute transactions.

04 / Screenshots