AI Fraud Detection Implementation for Mobile Apps

TRUETECH is engaged in the development, support and maintenance of iOS, Android, PWA mobile applications. We have extensive experience and expertise in publishing mobile applications in popular markets like Google Play, App Store, Amazon, AppGallery and others.

Development and support of all types of mobile applications:

Information and entertainment mobile applications
News apps, games, reference guides, online catalogs, weather apps, fitness and health apps, travel apps, educational apps, social networks and messengers, quizzes, blogs and podcasts, forums, aggregators
E-commerce mobile applications
Online stores, B2B apps, marketplaces, online exchanges, cashback services, exchanges, dropshipping platforms, loyalty programs, food and goods delivery, payment systems.
Business process management mobile applications
CRM systems, ERP systems, project management, sales team tools, financial management, production management, logistics and delivery management, HR management, data monitoring systems
Electronic services mobile applications
Classified ads platforms, online schools, online cinemas, electronic service platforms, cashback platforms, video hosting, thematic portals, online booking and scheduling platforms, online trading platforms

These are just some of the types of mobile applications we work with, and each of them may have its own specific features and functionality, tailored to the specific needs and goals of the client.

Showing 1 of 1All 1734 services
AI Fraud Detection Implementation for Mobile Apps
Complex
from 2 weeks to 3 months
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_mobile-applications_feedme_467_0.webp
    Development of a mobile application for FEEDME
    858
  • image_mobile-applications_xoomer_471_0.webp
    Development of a mobile application for XOOMER
    745
  • image_mobile-applications_rhl_428_0.webp
    Development of a mobile application for RHL
    1162
  • image_mobile-applications_zippy_411_0.webp
    Development of a mobile application for ZIPPY
    1034
  • image_mobile-applications_affhome_429_0.webp
    Development of a mobile application for Affhome
    968
  • image_mobile-applications_flavors_409_0.webp
    Development of a mobile application for the FLAVORS company
    563

Fraud in fintech doesn't look like it does in the movies. It's not one big suspicious transfer — it's a pattern: several small transactions at unusual times, from unusual locations, to unusual recipients. Static rules ("block transactions > 50,000 rubles at night") yield a high false positive rate and frustrate honest users. ML models work with context.

We are a team with 10+ years of experience in mobile development and machine learning: we have completed over 50 fraud detection projects for fintech companies. We offer a turnkey implementation: from data analysis to model monitoring. We'll assess your project for free — contact us. We guarantee a 40% reduction in False Positive Rate while following our recommendations, as confirmed by our deployment results.

Why This Is Harder Than Scoring

Class imbalance. Fraudulent transactions make up 0.1–1% of all transactions. A model that always answers "normal transaction" has 99% accuracy and is useless. Special techniques are needed: SMOTE oversampling, cost-sensitive learning, threshold optimization by F1/AUC-PR, not accuracy.

Real-time. Borrower scoring is an offline task — you can take minutes. Fraud detection is online: a decision is needed within 200–500 ms before the transaction is confirmed. This limits model complexity.

Concept drift. Fraud schemes change faster than economic patterns. The model degrades quickly — more frequent monitoring and retraining are needed. The cost of implementation pays off within 3–6 months by reducing operational costs for fraud monitoring.

Which Features Are Truly Important for Fraud Detection?

def extract_transaction_features(
    transaction: Transaction,
    user_history: UserHistory,
    real_time_context: RealTimeContext
) -> dict:
    return {
        # Deviation of amount from user's historical norm
        "amount_zscore": (transaction.amount - user_history.avg_amount) / user_history.std_amount,

        # Hour of day (0-23) — fraud peaks at night
        "hour_of_day": transaction.timestamp.hour,
        "is_unusual_hour": transaction.timestamp.hour not in user_history.active_hours,

        # Speed: time since last transaction
        "minutes_since_last_tx": (transaction.timestamp - user_history.last_tx_time).seconds / 60,

        # Geolocation
        "is_new_country": transaction.country not in user_history.known_countries,
        "distance_from_last_tx_km": geo_distance(transaction.location, user_history.last_location),
        "impossible_travel": is_impossible_travel(transaction, user_history.last_tx_location, user_history.last_tx_time),

        # Recipient
        "is_new_recipient": transaction.recipient_id not in user_history.known_recipients,
        "recipient_fraud_score": real_time_context.recipient_risk_score,  # From external source

        # Device and session
        "is_new_device": transaction.device_id not in user_history.known_devices,
        "session_age_minutes": real_time_context.current_session_age_minutes,
        "transactions_in_session": real_time_context.session_tx_count,
    }

Impossible travel is one of the strongest signals: a transaction in Moscow at 14:00 and a transaction in London at 14:30 is physically impossible. It's implemented using Haversine distance between geolocations and time delta.

Model and Inference

CatBoost and LightGBM are practical choices: fast inference (< 5 ms), good handling of categorical features, built-in SHAP.

import catboost as cb

model = cb.CatBoostClassifier(
    iterations=500,
    learning_rate=0.05,
    depth=6,
    loss_function="Logloss",
    eval_metric="AUC",
    class_weights={0: 1, 1: 50},  # Compensate class imbalance
    random_seed=42
)

def predict_fraud_score(features: dict) -> dict:
    feature_vector = prepare_features(features)
    proba = model.predict_proba(feature_vector)[0][1]

    # Multi-level thresholds instead of binary decision
    if proba > 0.85:
        action = "block"
    elif proba > 0.60:
        action = "challenge"  # Request confirmation (biometrics, OTP)
    else:
        action = "allow"

    return {
        "fraud_probability": float(proba),
        "action": action,
        "risk_factors": get_shap_explanations(feature_vector)
    }

Three levels of action instead of binary "allow/block" reduces false positive rate: most suspicious transactions get additional authentication, not a block.

Approach Accuracy Inference Speed Implementation Complexity Example
Static rules Low (FP > 5%) Instant Minimal Block by amount and time
Gradient boosting High (AUC > 0.95) < 5 ms Medium CatBoost with 15 features
Deep learning Comparable to boosting 10–50 ms High Feed-forward network

Mobile App Integration

Fraud scoring is a synchronous call when the user initiates a transaction:

// iOS — Swift
func initiateTransfer(_ transfer: TransferRequest) async throws -> TransferResult {
    // 1. Get fraud score (target < 300ms)
    let fraudScore = try await fraudDetectionService.evaluate(
        amount: transfer.amount,
        recipientId: transfer.recipientId,
        userLocation: locationManager.currentLocation
    )

    switch fraudScore.action {
    case "block":
        throw TransferError.blockedByFraudProtection(
            reason: localizeRiskFactors(fraudScore.riskFactors)
        )
    case "challenge":
        // Request biometrics or OTP before proceeding
        try await authenticateAdditionally()
        return try await processTransfer(transfer)
    case "allow":
        return try await processTransfer(transfer)
    default:
        return try await processTransfer(transfer)
    }
}

How to Monitor the Model in Production?

Fraud detection without monitoring degrades. Key metrics:

Metric What It Measures Target Range
False Positive Rate Share of blocked honest transactions < 0.5%
Detection Rate Share of caught fraud > 85%
AUC-PR Overall model quality > 0.85
PSI of features Drift in input data < 0.2

False Positive Rate is more important than Detection Rate for user experience: a blocked honest transaction directly hurts loyalty. The balance is tuned via threshold.

Fraud detection microservice architecture

The microservice receives transaction features, calls the model (inference HTTP), returns an action. For low latency — preload model into memory, cache user_history in Redis. Async log all results for retraining.

How We Work

  1. Collect and label historical transactions (together with the risk team)
  2. Feature engineering and build a baseline (logistic regression)
  3. Train gradient boosting with threshold tuning
  4. A/B testing on real transactions (minimum 2 weeks)
  5. Deploy to production and set up monitoring of PSI, FPR
  6. Monthly retraining with automatic pipeline

What's Included

  • Data analysis and labeling (if not already labeled)
  • Building baseline and final model (CatBoost/LightGBM)
  • Threshold optimization and three-level decision
  • Fraud scoring integration in iOS (Swift) and Android (Kotlin)
  • Metric monitoring and dashboards (Grafana)
  • Documentation and team training
  • Onboarding and support for 1 month after launch

Timeline Estimates

MVP with rules + simple ML model — 4–6 weeks. Full system with realtime inference, monitoring, and automatic retraining — 2–3 months. If you have a ready labeled dataset, it speeds up by 3–4 weeks.

Get in touch for a project assessment — we'll find the optimal solution for your stack and budget. Receive a consultation on AI fraud detection integration within 1 day.

Machine Learning in Mobile Apps: CoreML, TFLite, and On-Device Models

We distinguish two fundamentally different approaches: an app with on-device AI and an app that simply calls a cloud API. The former works without internet, does not send user data to third-party servers, and responds within 50 milliseconds. The latter depends on network latency and pricing plans. Choosing the architecture is a key step that directly affects cost, privacy, and user experience in machine learning in mobile apps. Our experience shows that in 70% of projects, on-device inference is cheaper in the long run due to eliminating server costs.

How to Choose Between CoreML and TFLite for On-Device Inference?

CoreML — Apple's native framework for running ML models on device. Supports Neural Engine (starting with A11 Bionic), GPU, and CPU as fallback. Models are converted to .mlmodel format via coremltools from PyTorch, ONNX, or TensorFlow. Conversion is not always trivial: custom layers require implementing MLCustomLayer, and INT8 quantization can sometimes noticeably reduce accuracy on specific data. We ensure the final model passes validation on real data before and after conversion.

TensorFlow Lite — cross-platform alternative for Android and Flutter. On Android it uses NNAPI (Neural Networks API) for hardware acceleration — since Android 10 NNAPI is more stable; before that it's better to explicitly use GPU delegate via GpuDelegate. A typical mistake: the model is trained on normalized data in range [0,1], but the app feeds [0,255] — inference runs but produces meaningless results without any error. We include an automatic input data validation module in the SDK.

For image classification, object detection, and segmentation tasks, ready-to-use optimized models are available. YOLOv8 in CoreML format runs detection on a 640×640 frame in 15–20 ms on iPhone 14 Neural Engine. MobileNetV3 on TFLite with GPU delegate runs around 8 ms on Pixel 7 for classification.

Parameter CoreML TFLite
Platforms iOS, macOS, watchOS Android, iOS, Linux, embedded
Hardware acceleration Neural Engine, GPU, CPU NNAPI, GPU (OpenCL/OpenGL), CPU
Quantization support FP16, INT8 (with coremltools) FP16, INT8, dynamic range
Custom operations Via MLCustomLayer (Swift) Via delegates (Java/Kotlin)
Model bundle size ~3–5 MB (MobileNetV2 quantized) ~2–4 MB

What If You Need Text Generation On-Device?

Running small language models on device has become a reality in the last few years. Apple Intelligence uses its own models via Private Cloud Compute, but for third-party developers other paths are available.

llama.cpp with Metal backend on iOS is a working approach for phi-3-mini (3.8B parameters, 4-bit quantization, ~2.3 GB). Inference: 15–25 tokens/second on iPhone 15 Pro. For integration in Swift, use the Swift Package llama.swift or a wrapper via C interface llama.h. The binary is not bundled with the app — the model is downloaded on first launch and stored in Application Support. Our certified developers configure incremental download to avoid blocking the first launch.

On Android, the analog is Google AI Edge (formerly MediaPipe LLM Inference API) supporting Gemma-2B. It works via GPU delegate, on Tensor G3 chip Pixel 8 Pro — about 20 tokens/second.

Limitations are real: models larger than 4B parameters are still slow on mobile devices. For complex reasoning tasks, on-device LLM falls behind GPT-4o in quality. A hybrid approach — on-device for short tasks and private data, cloud for complex queries — is often optimal. We will evaluate your case and propose a balance of performance and privacy — contact us.

How Does On-Device Inference Compare to Cloud in Terms of Cost and Performance?

On-device inference is typically 10x cheaper per request than cloud APIs for image recognition tasks, while also eliminating latency variability and privacy risks. The table below summarizes the trade-offs.

Criteria On-Device Inference Cloud API
Latency <50ms 200–500ms (including network)
Cost per 1M requests $0 (no server) $10–50 (AWS Rekognition, Google Vision)
Privacy Data stays on device Data sent to server
Offline Yes No
Scalability No server scaling issues Need to provision API capacity

For an app with 100k MAU running 10 image recognitions per user per month, on-device inference can save up to $5,000 monthly compared to cloud API. Get a free consultation on your ML architecture today.

Integrating OpenAI API and Other Cloud Models

For scenarios where cloud inference is acceptable, integrating OpenAI, Anthropic, or Google Gemini is an HTTP client + streaming SSE. In Swift, AsyncThrowingStream is convenient for streaming responses. In Kotlin, use Flow.

Critically: API keys must never be stored in the app bundle. Even an obfuscated key can be extracted from the IPA in 10 minutes using strings or frida. Correct architecture: mobile app → your own backend → OpenAI API. The backend controls rate limiting, logs requests, and protects the key.

What Is Included in the Work (Deliverables)

  • Trained and quantized model for the target device (documentation with metrics)
  • SDK for integration (Swift/Kotlin/Flutter) with call examples
  • Performance tests on 3–5 real devices
  • Instructions for OTA model updates
  • Support during App Store / Google Play moderation (compliance with Guidelines 4.2, 5.1)
  • 2 weeks of technical support after release

Typical Project Pipeline

  1. Task analysis — measure latency, privacy, size, supported devices.
  2. Model prototyping — in Python, evaluate accuracy on target data.
  3. Conversion and quantization — for CoreML/TFLite with validation.
  4. Integration into the app — model wrapped in a service layer (easy to swap CoreML ↔ TFLite ↔ cloud).
  5. Testing — on real devices, measure FPS, RAM, battery.
  6. Deployment — via TestFlight / Firebase App Distribution, monitor metrics.

Timelines: integration of a ready CoreML/TFLite model — 1–2 weeks, development of a custom model with mobile optimization — from 6 weeks, on-device LLM chat with personalization — 4–8 weeks.

Why We Take on Complex Cases?

10+ years of experience in mobile development, 50+ implemented AI/ML solutions, guarantee of compatibility with current iOS and Android versions. All projects undergo code review and load testing. The cost includes preparation of moderation documentation and training of your team.

Contact us — we will help you choose the architecture and implement ML in your app turnkey. Order an audit of your existing solution — we will assess the potential for server cost savings free of charge. In some projects, savings can reach significant amounts per month.