Explainable Ensemble Detection of Mobile-Money Transaction Anomalies: An M-PESA Case Study

Authors

  • Nyaata Kenan Co-operative University of Kenya
  • David Muriuki Co-operative University of Kenya
  • Anthony Luvanda National Defence University – Kenya

Keywords:

mobile money fraud; anomaly detection; social engineering; explainable AI; stacking ensemble

Abstract

the unauthorized transactions that follow may leave observable signatures in transaction records. This study implements and evaluates an Explainable Stacking Ensemble Machine Learning (XSEML) model for detecting transaction anomalies informed by documented social-engineering behaviour. The model combines Isolation Forest, XGBoost and Random Forest as base learners with a Logistic Regression meta-learner trained on out-of-fold predictions, and SHAP for instance-level explanation. An exploratory sequential mixed-methods design was used: a structured document review of cybersecurity reporting (2022–2025) identified four behavioural themes informing feature engineering. The model was trained and tested on a publicly available synthetic M-PESA dataset of 120,000 transactions (2.93% fraudulent). On an untouched 30% test set (36,000 transactions; 1,053 fraudulent) the ensemble achieved 98.8% accuracy, 89.8% precision, 65.5% recall, F1 = 0.758 and ROC-AUC = 0.831. Comparison against seven baselines with McNemar tests and bootstrap confidence intervals shows the ensemble significantly outperforming a 2σ rule (ΔF1 = +0.639, 95% CI [0.615, 0.664]) but significantly underperforming a tuned XGBoost classifier (ΔF1 = −0.026, 95% CI [−0.034, −0.019]; McNemar p < 0.001). Direct testing shows transaction month carries the highest SHAP attribution yet contributes almost nothing to discrimination (permutation AUC drop 0.0014; ablation ΔF1 = −0.002; χ² = 11.96, p = 0.367). More consequentially, a single hand-written threshold on the amount-to-balance ratio achieves perfect precision and F1 = 0.791, exceeding every model tested, because no legitimate transaction among 116,490 exceeds a ratio of 0.90. The dataset's fraud labels therefore appear rule-generated, and the evaluation is circular. We report this, rather than the performance figures, as the principal finding, and conclude that synthetic mobile-money datasets require explicit label-provenance auditing before they can support detection claims. The framework detects transaction anomalies consistent with social-engineering attack patterns; it does not detect social-engineering attacks.

References

Boen, C. (2025). M-Pesa transactions fraud [Data set]. Kaggle. https://www.kaggle.com/datasets/calebboen/mpesa-transactions-fraud

Braun, V., & Clarke, V. (2006). Using thematic analysis in psychology. Qualitative Research in Psychology, 3(2), 77–101.

Central Bank of Kenya. (2025). FinAccess survey 2025: Digital financial services and fraud trends. Central Bank of Kenya.

Creswell, J. W., & Plano Clark, V. L. (2018). Designing and conducting mixed methods research (3rd ed.). SAGE Publications.

GSMA. (2024). Mobile money fraud landscape in Sub-Saharan Africa 2024. GSM Association.

Kotut, L., Stanley, C., Kimani, S., Mbindyo, P., & Chen, J. (2025). Understanding exploitation disparities in mobile money fraud in Kenya. Proceedings of the ACM on Human-Computer Interaction, 9(CSCW1), Article 45.

Lundberg, S. M., & Lee, S.-I. (2017). A unified approach to interpreting model predictions. Advances in Neural Information Processing Systems, 30, 4765–4774.

Mambina, I. S., Ndibwile, J. D., & Michael, K. F. (2022). Classifying Swahili smishing attacks for mobile money users: A machine-learning approach. IEEE Access, 10, 83061–83074.

Safaricom PLC. (2025). Annual report and financial statements for the year ended 31 March 2025. Safaricom PLC.

Sarker, S., & Shukla, A. (2023). Research design in machine learning-based fraud detection: A systematic review. Computers & Security, 125, Article 103112.

Schmitt, M. (2024). Digital deception: Generative AI in social engineering and phishing attacks. Artificial Intelligence Review, 57(4), Article 89.

Serianu. (2025). Africa cybersecurity report 2025: Kenya country profile. Serianu Limited.

TransUnion. (2025). H1 2025 digital fraud trends report: Africa focus. TransUnion.

Uddin, K. M. M., Rahman, M. M., & Islam, M. R. (2025). Explainable machine learning for phishing site detection using ensemble methods. IET Journal of Engineering, 2025(1), Article e70110.

Vennela, A. (2026). Intelligent cybersecurity systems for phishing attack detection in mobile financial services. Computers & Electrical Engineering, 112, 109–125.

Wolpert, D. H. (1992). Stacked generalization. Neural Networks, 5(2), 241–259.

Downloads

Published

2026-09-30

How to Cite

Nyaata Kenan, David Muriuki, & Anthony Luvanda. (2026). Explainable Ensemble Detection of Mobile-Money Transaction Anomalies: An M-PESA Case Study. African Journal of Education,Science and Technology (AJEST), 8(4), 277–287. Retrieved from https://ajest.org/index.php/ajest/article/view/1043

Issue

Section

Articles

Similar Articles

<< < 2 3 4 5 6 7 8 9 10 11 > >> 

You may also start an advanced similarity search for this article.