High-Throughput Stream Processing, Temporal VAE Behavioral Drift Detection & Morphic Graph Community Intelligence
Key Capabilities β’ Architecture β’ Visual Intelligence β’ Fraud Typologies β’ Quick Start β’ API Reference β’ Deployment
This is an enterprise-grade, sub-second anti-money laundering (AML) and mule account detection platform designed for real-time banking environments. By synthesizing temporal behavioral deep learning (PyTorch LSTM-VAE) with dynamic graph community clustering (Neo4j + NetworkX Louvain) over an event-driven Kafka backbone, SentinelMule uncovers hidden mule syndicates, money laundering layering, and smurfing rings before funds exit the banking perimeter.
Incoming Transactions (20+ TPS)
β³ Apache Kafka Stream
βββ Temporal VAE (PyTorch): Sub-10ms Behavioral Drift Detection
βββ Graph Ingestion & Louvain (Neo4j): Multi-Hop Community Ring Detection
β³ Real-Time WebSocket Alerts β Interactive Cytoscape & React SOC Dashboard
Real-time alert streaming, anomaly scoring, and portfolio risk distribution.
π Visual Components Breakdown (Click to collapse/expand)
| Visual Module | Technology | Functional Capability |
|---|---|---|
| π¨ Live Alert Stream | Socket.IO + Redis |
Instant push notifications of flagged accounts with anomaly drift score, typology classification, and millisecond timestamps. |
| π₯ Portfolio Risk Heatmap | React + CSS Grid |
64-cell interactive matrix tracking live behavioral volatility. Clicking any cell opens deep account telemetry and recent transactions. |
| πΈοΈ Mule Network Graph | Cytoscape.js + Neo4j |
Interactive force-directed topological graph rendering Louvain-detected mule rings, hub nodes, and illicit fund routing. |
| 𧬠Behavioral DNA Modal | FastAPI + NumPy |
16-dimensional latent space vector comparison contrasting standard user baseline against active transaction burst. |
mindmap
root((Realtime-anti-mule-solution))
Temporal Deep Learning
PyTorch LSTM-VAE
Sequential Embedding Latent Space
Dynamic 90th Percentile Drift Thresholding
Sub-10ms Inference Time
Morphic Graph Analytics
Neo4j Persistent Graph Database
Louvain Modularity Clustering
Hub-and-Spoke & Ring Topology Detection
Cross-Account Edge Aggregation
Real-Time Streaming Backbone
Apache Kafka Event Broker
Redis In-Memory State & Ring Buffers
Bidirectional Socket.IO WebSockets
20+ TPS Synthetic Ingestion Engine
Production-Grade Architecture
9 Container Docker Compose Mesh
GKE Kubernetes Manifests & Ingress
GitHub Actions Automated CI/CD
Zero-Downtime Rolling Deployments
- β±οΈ Sub-Second Latency: Processes, scores, and visualizes transactions in under 50 milliseconds end-to-end.
- π§ Zero-Day Typology Detection: Unsupervised Temporal VAE detects novel mule behaviors without relying solely on rigid rule sets.
- π Graph Sybil Defense: Detects distributed smurfing rings where individual transactions fall under conventional regulatory reporting thresholds.
- π Unified Analyst Cockpit: Single-pane dashboard combining temporal drift analytics, interactive network graphs, and automated audit trails.
flowchart TB
subgraph INGESTION["1. Ingestion Layer"]
GEN["Synthetic Data Generator<br/>(20+ TPS / 5% Fraud Injection)"]
KAFKA_RAW[("Kafka Topic:<br/>transactions.raw")]
GEN -->|Produces TXNs| KAFKA_RAW
end
subgraph ANALYTICS["2. Dual-Engine Intelligence Layer"]
subgraph TEMPORAL["Temporal AI Engine"]
DETECTOR["Anomaly Detector<br/>(PyTorch LSTM-VAE)"]
KAFKA_RAW -->|Consumes| DETECTOR
DETECTOR -->|Encodes 16-D Vector| REDIS_BASE[("Redis:<br/>baseline:{id}")]
DETECTOR -->|Computes Drift| REDIS_DRIFT[("Redis:<br/>drift:{id}")]
end
subgraph GRAPH["Graph Analytics Engine"]
ANALYZER["Graph Analyzer<br/>(Louvain Clustering)"]
NEO4J[("Neo4j Graph DB<br/>Nodes & Edges")]
KAFKA_RAW -->|Persists Edges| ANALYZER
ANALYZER <-->|Cypher Queries| NEO4J
ANALYZER -->|Extracts Clusters| REDIS_CLUST[("Redis:<br/>morphic:cluster_*")]
end
end
subgraph BUS["3. Event Broadcast Layer"]
KAFKA_ALERTS[("Kafka Topic:<br/>alerts.generated")]
KAFKA_GRAPH[("Kafka Topic:<br/>graph.updates")]
DETECTOR -->|Emits Alert| KAFKA_ALERTS
ANALYZER -->|Emits Topology| KAFKA_GRAPH
end
subgraph API_SERV["4. Gateway & Application Layer"]
API["FastAPI Backend & Socket.IO Gateway<br/>(Port 8000)"]
KAFKA_ALERTS -->|Listens| API
KAFKA_GRAPH -->|Listens| API
REDIS_DRIFT -->|Reads| API
REDIS_CLUST -->|Reads| API
NEO4J -->|Sub-graph Queries| API
end
subgraph PRESENTATION["5. SOC Presentation Layer"]
DASH["React 18 + Cytoscape.js SPA<br/>(Nginx Reverse Proxy :3000)"]
API <-->|REST APIs + WebSockets| DASH
USER(("Fraud Investigator")) <--> DASH
end
classDef gcp fill:#e8f0fe,stroke:#4285f4,stroke-width:2px;
classDef comp fill:#f1f8e9,stroke:#558b2f,stroke-width:2px;
classDef storage fill:#fff3e0,stroke:#e65100,stroke-width:2px;
class INGESTION,ANALYTICS,BUS,API_SERV,PRESENTATION comp;
class KAFKA_RAW,KAFKA_ALERTS,KAFKA_GRAPH,REDIS_BASE,REDIS_DRIFT,REDIS_CLUST,NEO4J storage;
This is pre-configured with mathematical heuristics and deep representations to capture the most complex money laundering patterns:
| Typology Code | Typology Name | Structural Signature | Detection Mechanism |
|---|---|---|---|
GAT |
Gather-and-Transfer | Many dispersed accounts funneling money into a single aggregator hub. | Graph in-degree anomaly + high volume temporal drift. |
DMR |
Dormant Account Resurrection | Account inactive for >180 days suddenly transacting large sums. | Extreme VAE latent reconstruction error against historical baseline. |
RBF |
Rapid Burst Fan-out (Smurfing) | Single high-value deposit split into dozens of sub-threshold transfers within minutes. | Graph out-degree velocity + burst rate deviation. |
CAL |
Circular Asset Layering | Fund routing through |
Neo4j Cypher cycle detection & Louvain modularity clusters. |
AEV |
Atmosphere Velocity Drift | Transactions originating from impossible geographic or device hops. | Feature vector deviation across location, velocity, and time-of-day. |
The entire solution runs as 9 coordinated microservices:
.
βββ docker-compose.yml # Complete 9-container local orchestration
βββ start.bat # One-click Windows startup script
βββ k8s/ # Production Kubernetes manifests & Ingress
βββ .github/workflows/ # Automated CI/CD (GCP Artifact Registry + GKE)
βββ scripts/ # Infrastructure automation scripts
βββ services/
βββ api/ # FastAPI + Socket.IO async gateway (Port 8000)
βββ dashboard/ # React 18 + Cytoscape + Nginx SPA (Port 3000)
βββ detector/ # PyTorch LSTM Temporal VAE Worker
βββ graph-analyzer/ # Neo4j & Louvain community clusterer
βββ generator/ # Realistic transaction & fraud stream generator
| Container | Image / Base | Ports | Role |
|---|---|---|---|
dashboard |
node:18-alpine β nginx:alpine |
3000:80 |
Static React SPA with Nginx reverse proxy routing /api and /socket.io. |
api-server |
python:3.9-slim |
8000:8000 |
REST API, OpenAPI docs, and asynchronous Socket.IO event broadcaster. |
anomaly-detector |
python:3.9-slim + PyTorch CPU |
Worker | Real-time latent vector extraction and drift score computation. |
graph-analyzer |
python:3.9-slim + NetworkX |
8080 |
Neo4j graph population and 15-second periodic Louvain clustering. |
data-generator |
python:3.9-slim + Faker |
Worker | High-throughput streaming engine with parameterized fraud typologies. |
kafka |
confluentinc/cp-kafka:7.5.0 |
9092, 29092 |
Distributed streaming event broker with auto topic creation. |
zookeeper |
confluentinc/cp-zookeeper:7.5.0 |
2181 |
Coordination engine for Kafka cluster management. |
redis |
redis:7-alpine |
6379:6379 |
In-memory key-value cache with allkeys-lru eviction policy. |
neo4j |
neo4j:5-community (APOC) |
7474, 7687 |
Property graph database storing accounts, edges, and transaction metadata. |
- Docker Desktop (with WSL2 backend enabled on Windows)
- Git
# Clone the repository
git clone https://github.com/vaishnaviwangalwar-cpu/anti-mule-solution.git
cd anti-mule-solution
# Start all 9 services with a single command
docker compose up --build -d(On Windows, you can also simply double-click start.bat)
| Interface | URL | Credentials |
|---|---|---|
| Interactive SOC Dashboard | http://localhost:3000 | None (Public) |
| Interactive Swagger API Docs | http://localhost:8000/docs | None (Public) |
| Neo4j Graph Browser | http://localhost:7474 | neo4j / password |
To share the live dashboard with judges or remote team members without deploying to cloud providers:
# Run in your PowerShell / Terminal to open a secure HTTPS tunnel
ssh -o StrictHostKeyChecking=no -o ServerAliveInterval=60 -R 80:localhost:3000 nokey@localhost.runThis generates a secure https://<subdomain>.lhr.life address that can be accessed from any phone, laptop, or tablet in real-time.
The API is fully documented using OpenAPI standard at /docs. Below are key endpoints:
GET /api/v1/alerts?page=1&size=20Sample Response (JSON)
{
"alerts": [
{
"account_id": "ACC-000131",
"drift_score": 0.966,
"threshold": 0.850,
"timestamp": "2026-08-25T18:30:00Z",
"type": "RBF"
},
{
"account_id": "ACC-000564",
"drift_score": 0.948,
"threshold": 0.850,
"timestamp": "2026-08-25T18:29:55Z",
"type": "GAT"
}
],
"page": 1,
"size": 20,
"total": 52
}GET /api/v1/heatmapGET /api/v1/graph/clustersGET /api/v1/accounts/ACC-000102/behavioral-dnaGET /healthz # Liveness probe (Returns status: ok)
GET /readyz # Readiness probe (Validates Redis & Neo4j connectivity)SentinelMule includes enterprise-ready Kubernetes manifests and automated GitHub Actions CI/CD pipelines:
k8s/
βββ namespace.yaml # 'antimule' isolated namespace
βββ secrets.yaml # Base64 encrypted secrets
βββ ingress.yaml # GKE Cloud Load Balancer & Ingress routing
βββ kafka/ (kafka.yaml, zookeeper.yaml)
βββ redis/ (redis.yaml)
βββ neo4j/ (neo4j.yaml)
βββ api-server/, dashboard/, anomaly-detector/, graph-analyzer/, data-generator/
Run the included provisioning script in Git Bash / Linux:
./scripts/gcp-setup.sh <YOUR_GCP_PROJECT_ID> us-central1 <YOUR_GITHUB_REPO>Creates GKE Autopilot cluster, Artifact Registry, IAM service accounts, and Workload Identity Federation OIDC.
For the complete cloud deployment manual, refer to DEPLOY.md.
The Temporal VAE models normal transaction dynamics as a sequence of transaction vectors
Where:
- $\mathbb{E}{q\phi(z|X)} [\log p_\theta(X|z)]$ is the reconstruction fidelity of recent user transactions.
-
$D_{KL}$ is the Kullback-Leibler divergence constraining the latent representation to prior$\mathcal{N}(0, I)$ . -
Drift Metric: Calculated as normalized cosine distance between the dynamic baseline vector
$\mu_{\text{baseline}}$ and the current latent embedding$\mu_{\text{active}}$ :
When
This project is licensed under the MIT License β see the LICENSE file for complete details.
- Vaishnavi Wangalwar β Lead Developer & System Architect
β If you found this solution insightful, please star the repository! β
