Q330 : Hybrid Unsupervised-Supervised Approach for Simbox Fraud Detection in Telecom
Thesis > Central Library of Shahrood University > Computer Engineering > MSc > 2025
Authors:
[Author], [Supervisor]
Abstarct: Due to the massive volume of transactions and the high economic value of its services, the telecommunications industry has consistently been a primary target of fraudulent activities. One of the most common and damaging forms of fraud in this sector is the misuse of SIM Box devices, which enables the bypassing of legitimate international call termination rates. This practice not only imposes substantial financial losses on operators but also degrades network quality and jeopardizes overall system security. Detecting and mitigating such fraud presents a significant challenge, as fraudulent activities are typically concealed within legitimate Call Detail Records (CDRs) and often exhibit behavioral patterns similar to those of normal subscribers. Consequently, the development of real-time, accurate, and scalable fraud detection systems is an unavoidable necessity. The main challenge in building such systems lies in the inherently imbalanced nature of the data, where fraudulent instances (the minority class) are vastly outnumbered by legitimate calls (the majority class). Traditional machine learning models tend to perform poorly under these conditions, as they are biased toward the majority class and struggle to identify rare fraud cases. To overcome this limitation, this study proposes a novel hybrid approach for SIM Box fraud detection using call detail records. The proposed model combines the unsupervised anomaly detection capability of Isolation Forest with the high classification accuracy of the supervised XGBoost model. Initially, Isolation Forest is employed to screen anomalous behaviors and generate an anomaly score, which is subsequently injected as an enhanced feature into XGBoost to improve performance on imbalanced data. Isolation Forest is an unsupervised algorithm that operates by rapidly isolating anomalies using random trees and is well suited for the initial detection stage due to its high efficiency on large-scale CDR data. XGBoost, as a powerful classifier, effectively learns fraudulent patterns through class weighting and gradient-baxsed optimization. This multi-stage approach not only leverages the strengths of both models but also achieves a well-balanced trade-off between precision and recall by incorporating the anomaly score as an informative feature. Experimental results on the public Telecom CDR Fraud Dataset (Kaggle) demonstrate the superiority of the proposed hybrid model. The model achieved a precision of 81%, a recall of 97%, an F1-score of 89%, and a ROC-AUC of 97.33%, showing a significant improvement in accuracy and class balance compared to standalone Isolation Forest and XGBoost models. These results confirm the operational potential of the proposed approach for real-time fraud alert systems in telecommunications networks.
Keywords:
#Keywords: SIM Box Fraud #Isolation Forest #XGBoost #Imbalanced Data #CDR Analysis #Anomaly Detection #Hybrid Approach #Fraud Detection. Keeping place: Central Library of Shahrood University
Visitor: