Worked case · Controlled response · 12 figures

Authenticated but deceived sender

Separate unauthorized access from deception

Figure 01 / 12

The evaluated population

The evaluated population — Authenticated but deceived sender. Count; one closed observation cohort. Exact values are in the figure data below.
Count; one closed observation cohort

The cohort contains 28,000 authorized transfer attempts, of which 196 have the defined synthetic outcome: Synthetic scam-loss outcome. The outcome is known by construction here. In production, label uncertainty and selection must be recorded separately.

Figure data and text version
OutcomeCount
Synthetic scam-loss outcome196
Other labeled outcomes27,804

The real customer can use the real device and still send money because an attacker supplied a false story. Login success does not settle the payment’s intent.

Evaluate recipient context, behavioral changes, and the timing of a useful intervention.

All amounts, rates, capacity limits, and outcomes in this case are synthetic. The three conditions are separate assumptions for comparison. A better result in the response condition is not measured proof that the proposed control causes that improvement. The figures expose the calculation and its limits; a real deployment needs its own evidence.

Read the result

The rule flags 503 of 28,000 authorized transfer attempts. Of those flags, 169 meet the synthetic target, giving 33.6% precision. It misses 27 target events. Under the stated cost assumptions, residual loss and operating friction total $79,576. The important result is the connection between the population, action, capacity, and outcome—not one isolated score.

Model inputs and calculated values

Inputs below are the case-specific values. Each figure states the condition-specific assumptions and units used in its calculation. Calculated values are rounded for display.

InputValue
population28,000
prevalence0.007
severity2,600
reviewCost12
margin10
Calculated valueResult
population28,000
positive196
negative27,804
tp169
fp334
fn27
tn27,470
loss70,200
severity2,600
precision33.6
recall86.22
Figure 02 / 12

Four outcomes of the rule

Four outcomes of the rule — Authenticated but deceived sender. Counts; rows are actual labels, columns are actions. Exact values are in the figure data below.
Counts; rows are actual labels, columns are actions

The rule flags 169 synthetic positives and 334 negatives. It misses 27 positives. A flagged item is a decision to intervene; it is not proof of fraud, a legal prohibition, or any other real-world conclusion.

Figure data and text version
Known outcomeFlaggedNot flagged
Synthetic scam-loss outcome16927
Other outcome33427,470
Figure 03 / 12

Three rates with different denominators

Three rates with different denominators — Authenticated but deceived sender. Rates within this cohort. Exact values are in the figure data below.
Rates within this cohort

Precision is 33.6%, recall is 86.22%, and the false-positive rate is 1.2%. Changing the denominator changes the meaning. This record keeps each numerator attached to the population from which it came.

Figure data and text version
MetricNumeratorDenominatorResult
Precision16950333.6%
Recall16919686.22%
False-positive rate33427,8041.2%
Figure 04 / 12

Precision changes with prevalence

Precision changes with prevalence — Authenticated but deceived sender. Percent; fixed conditional detection rates. Exact values are in the figure data below.
Percent; fixed conditional detection rates

This sensitivity plot holds recall at 86% and false-positive rate at 1.2%, then changes prevalence. It is an algebraic comparison, not a forecast. Even unchanged detection quality can produce a very different review queue when the base rate changes. Horizontal positions are the labeled observations or scenarios; equal spacing does not imply equal numerical increments.

Figure data and text version
Assumed prevalencePrecision %
0.1%6.69
0.5%26.48
1%41.99
2%59.39
5%79.04
10%88.84
Figure 05 / 12

The threshold trade-off

The threshold trade-off — Authenticated but deceived sender. Count in the same cohort. Exact values are in the figure data below.
Count in the same cohort

Six illustrative score bands use a stated pair of detection rates. Lower sensitivity can reduce false alarms but miss more target events. These points do not come from a trained model and do not establish the best operating threshold. Horizontal positions are the labeled observations or scenarios; equal spacing does not imply equal numerical increments.

Figure data and text version
Score bandTrue positivesFalse positives
Band 11924,171
Band 21842,224
Band 3169973
Band 4141334
Band 598111
Band 64928
Figure 06 / 12

A transparent loss-and-friction calculation

A transparent loss-and-friction calculation — Authenticated but deceived sender. Illustrative USD; expected cost under stated intervention assumptions. Exact values are in the figure data below.
Illustrative USD; expected cost under stated intervention assumptions

At $2600 severity per missed synthetic positive, residual loss is $70,200. Review costs $6,036; lost contribution on false alarms is $3,340. The calculation assumes intervention prevents all flagged-positive loss and each false alarm loses the stated contribution. Relax those assumptions before applying it to a real policy.

Figure data and text version
Cost componentUSD
Missed-positive loss70,200
Review cost6,036
False-alarm contribution3,340
Figure 07 / 12

Observed outcomes mature over time

Observed outcomes mature over time — Authenticated but deceived sender. Count; final outcome fixed. Exact values are in the figure data below.
Count; final outcome fixed

The final synthetic positive count is 196. Earlier observations reveal only a stated fraction. Comparing a day-1 cohort with a day-30 cohort would confuse label age with control quality. This curve models observation delay only; it does not change the final outcome. Horizontal positions are the labeled observations or scenarios; equal spacing does not imply equal numerical increments.

Figure data and text version
Days after eventObserved positives
135
369
7118
14161
30196
Figure 08 / 12

Review demand and available capacity

Review demand and available capacity — Authenticated but deceived sender. Items in the cohort window. Exact values are in the figure data below.
Items in the cohort window

The flag count is 503. The comparison capacity is an illustrative 1,120 reviews per cohort window. A mathematical rule can be coherent while its resulting workload exceeds the operating team’s capacity. Capacity is not permission to ignore an applicable mandatory control.

Figure data and text version
Queue measureItems
Flagged for review503
Available capacity1,120
Excess demand0
Figure 09 / 12

A feature is an observation with provenance

A feature is an observation with provenance — Authenticated but deceived sender. Illustrative data contract. Exact values are in the figure data below.
Illustrative data contract

This evidence contract supports separate unauthorized access from deception. A value needs its event time, arrival time, scope, and source. Keeping unavailable evidence distinct from a measured zero prevents an outage from becoming a falsely reassuring feature.

Figure data and text version
FieldExampleMeaning
entity_refAuthenticated but deceived senderSubject of this case
event_time2026-09-18T09:00:00ZWhen the event occurred
received_time2026-09-18T09:00:02ZWhen the system learned it
signal_statusrepairedEvidence quality, not an outcome
label_definitionSynthetic scam-loss outcomeThe target used in these calculations
Figure 10 / 12

Missing evidence changes the observed population

Missing evidence changes the observed population — Authenticated but deceived sender. Count; each row is the same cohort. Exact values are in the figure data below.
Count; each row is the same cohort

The cells show an explicitly constructed completeness profile for three signal groups. The stress condition removes more history and device evidence. Missingness does not prove the target outcome; it changes what the decision process knows.

Figure data and text version
Signal groupAvailableMissing
Identity evidence27,860140
Activity history27,580420
Context signal27,160840
Figure 11 / 12

Evidence, score, and action remain separate

Evidence, score, and action remain separate — Authenticated but deceived sender. Decision lifecycle. Exact values are in the figure data below.
Decision lifecycle

The policy can use separate unauthorized access from deception only within its approved scope. The action record must retain which evidence was available, which model or rule ran, and which action was actually applied. The final action can differ from the score recommendation when a separate constraint applies.

Figure data and text version
StageRecord
ObserveAuthenticated but deceived sender: evidence as of the decision time
EvaluateRule flags 503 of 28,000 authorized transfer attempts
ApplyRecord action, reason, owner, and expiry
ReconcileJoin the action to later outcomes without overwriting history
Figure 12 / 12

What the result cannot establish

What the result cannot establish — Authenticated but deceived sender. Interpretation boundary. Exact values are in the figure data below.
Interpretation boundary

Observed classifications do not reveal every counterfactual. The synthetic labels make arithmetic possible, but production decline data is selected by prior policy. Keep measured outcomes, assumed prevention, and unknown alternatives separate when reporting impact.

Figure data and text version
ClaimEvidence in this caseLimit
Detected target169 known synthetic positives flaggedProduction labels may be delayed or wrong
Prevented lossAssumed 439,400 USDRequires an intervention-effect assumption
Customer impact334 synthetic negatives flaggedNot every flag causes abandonment
Unobserved alternativeOutcome without the actionNeeds a valid evaluation design

Connect the result to the system

Evaluate recipient context, behavioral changes, and the timing of a useful intervention.

Check the population, evidence, permitted action, and actual effect together. A balanced calculation can still use the wrong population; a successful response can still leave an unknown financial outcome. The case’s numerical result applies only to its stated assumptions.

Sources and further reading

The chapter sources support the concepts and scope. They do not prescribe the synthetic model rates.

  1. Nacha: 2026 fraud monitoring, Phase 2
  2. FinCEN: deepfake fraud alert