Models with an adversary
Value and harm models describe customers who are behaving naturally. Fraud and integrity models describe customers who are trying not to be described. That changes everything about how they are built: the patterns shift as soon as they are detected, the labels are adversarially incomplete, and the cost of a false positive (blocking a legitimate customer) is as real as the cost of a miss. This lesson covers the families of abuse an operator faces and the modelling approaches that hold up against them.
The families of abuse
Bonus abuse. Exploiting promotions: claiming a welcome bonus through multiple accounts, hedging bonus wagering across operators, using low-variance play to grind wagering requirements at minimal risk, arbitraging boosted odds. Among the most common, and the most tolerated at the margin; the modelling question is where the line between clever and abusive sits, and it is a policy decision.
Multi-accounting. One person operating several accounts, to claim bonuses repeatedly, evade limits or exclusions, or launder through a chain. Detection is entity resolution: linking accounts through shared devices, payment instruments, addresses, behavioural fingerprints and network patterns.
Payment fraud. Stolen cards, account takeover, friendly fraud (a cardholder disputing a legitimate transaction they made, here a chargeback on a genuine deposit), and the use of the operator as a way to cash out stolen payment credentials.
Money laundering. Covered in the compliance courses from the obligation side; from the modelling side, it is transaction pattern detection. The Gambling Commission's anti-money laundering guidance for casinos lists the patterns to look for: deposits withdrawn with little or no play, multiple accounts opened to hide spending or stay under due diligence thresholds, frequently changed bank accounts, stolen payment details, and high spend on low-risk bets such as red and black at roulette. Mismatches between payment instruments and identity belong on the same list.
Collusion and chip dumping. In poker and peer-to-peer products, players transferring value to each other through deliberate losses; poker platforms shared by several operators make chip dumping a recognised laundering route. Detection is on hand histories and network structure.
Suspicious betting. Betting patterns that suggest a sporting event is being manipulated or that a customer has inside information. The operator's duty is to detect and report, not to investigate the sport, and the detection is on market and account anomalies. In Britain, betting licensees must report information they suspect relates to an offence to the Gambling Commission, and information suggesting a breach of a sport's betting rules to that sport's governing body (licence condition 15.1.2).
Advantage play. Customers exploiting genuine pricing errors, promotional misconfigurations or game weaknesses. Not fraud, and not something a model should conflate with it, but the same tooling surfaces it.
Modelling approaches
Rules first. Every operator runs rules: velocity checks (too many deposits, registrations or bonus claims from one device or IP in a window), matching checks (payment instrument already on another account), threshold checks (withdrawal larger than N times deposits with less than M turnover). Rules are transparent, fast, and easy to explain to a regulator or a customer, and they catch the unsophisticated majority. Their weakness is that they are static and adversaries learn them.
Supervised models learn from confirmed cases: gradient-boosted classifiers on features describing the account, its devices, its payments, its play and its network. They catch patterns rules miss and they rank cases for review. Their weakness is label quality: confirmed fraud is a biased sample of all fraud (the operator only confirms what it catches), and models trained on it reproduce the blind spots.
Anomaly detection flags behaviour unusual relative to the population or the customer's own history, without a label: isolation forests, which exploit the fact that anomalies are few and different and so are separated from the rest of the data in fewer random splits, autoencoders, density estimates on the feature layer. It catches novel patterns and generates a high volume of false positives, so it is used to surface cases for review rather than to act automatically.
Graph and network models. Accounts, devices, payment instruments, addresses and IPs form a graph, and fraud rings show up as densely connected components, shared instruments across many accounts, or chains of transfers. Community detection and link analysis are among the most effective tools against organised multi-accounting and laundering, and hard to evade, because the adversary has to change everything that links accounts, not just the behaviour of one.
Behavioural biometrics. How a customer types, swipes, moves a mouse and navigates is individual. Models on these signals detect account takeover (the behaviour changes) and multi-accounting (the same behaviour appears on different accounts). Powerful, and subject to data protection constraints that vary by market: under the EU GDPR, personal data resulting from specific technical processing of behavioural characteristics that allows the unique identification of a person is biometric data, and processing it for that purpose is a special category that is prohibited unless an exception applies.
In practice the layers stack: rules for speed and explainability, supervised models for ranking, anomaly detection and graphs for what the first two miss, and a review team that turns cases into labels.
Suspicious betting, specifically
Sports integrity monitoring looks for betting that is inconsistent with the market: unusually large stakes on low-profile events, sharp price movement without a public reason, concentration of money on a specific in-play occurrence, betting from accounts with no history in that sport or region, patterns across accounts that suggest coordination, and bets that win against the closing line at rates no model can explain. Operators share alerts through integrity associations so that a pattern invisible at one book becomes visible across many: in 2026 the International Betting Integrity Association's alert platform draws on more than 90 operator members.
The modelling discipline is the one the sports integrity course states: a pattern is a hypothesis about a market, not a finding about a person. The output is a report describing the betting, not a conclusion about the sport.
The cost of being wrong
A false negative lets abuse through; a false positive blocks a legitimate customer, delays their withdrawal, or closes their account. The second is a regulatory and reputational cost, and a customer whose withdrawal is withheld without adequate grounds has grounds for a complaint that can be taken beyond the operator. In Britain, for example, a remote operator may not make a withdrawal conditional on information it could reasonably have requested earlier, and a complaint unresolved after eight weeks can go to an alternative dispute resolution service that is free to the customer. Thresholds are therefore set on expected cost, not on accuracy alone, and the review team exists because the models cannot be trusted to act unilaterally above a modest level of intervention.
The operational pattern that works: automated action for high-confidence, low-impact decisions (decline a bonus claim, add a deposit delay); automated hold plus mandatory review for high-impact decisions (withhold a withdrawal, restrict an account); human decision for closures. In the EU, a person has the right not to be subject to a decision based solely on automated processing that significantly affects them (GDPR Article 22), which is one more reason the high-impact decisions keep a human in the loop. Every automated action is logged with the model version and the features that drove it, so it can be explained and reversed.
Adversarial drift
Fraud models tend to decay faster than models of natural behaviour. As soon as a rule or a model changes the adversary's success rate, the adversary changes behaviour. Monitoring for drift is therefore continuous: the distribution of scores, the rate of confirmed cases per flagged case, the emergence of clusters the model does not score highly, and feedback from the review team on what the new patterns look like. Retraining cadences are short, and the review team's qualitative reports are as important as the metrics.
Sharing the layer
Fraud, AML and responsible gambling models use the same feature layer and often flag the same customers, for different reasons. A customer who cancels withdrawals and deposits from multiple cards may be laundering, may be a victim of account takeover, or may be chasing losses. The models should be separate (their objectives differ) and their outputs should be visible together, so that the review team sees the whole picture of an account rather than three disconnected alerts. The next lesson turns from describing customers to changing the product they see, and how to know whether the change worked.