What the person meant
Pay a known merchant or send money to the person they trust.
PRIVACY-SAFE ADVERSARIAL LAB / INDIA
MAYA creates controlled payment worlds where a bounded attacker searches for detector blind spots—then turns every valid miss into a stronger test for the defense.
MAYA lives in the gap between appearance and reality.
RED × BLUE / VERIFIED REPLAY
Red probes a frozen defense. Blue intercepts what it recognizes. Switch to the hardened policy to replay the same failure after it becomes training data.
Allowed probes become hardening data.
Animated particles illustrate the run; the counters come from the pinned artifact. This reproduced search evaluates 96 candidates—it does not claim millions were executed.
THE MAYA PRINCIPLE / CONTINUITY OVER STORIES
A payment can be authenticated and still be deceptive. MAYA asks whether three independently observable facts continue to agree.
Pay a known merchant or send money to the person they trust.
The beneficiary, endpoint, amount, device, and timing presented at approval.
How the receiving identity holds, spends, or fans out the money afterward.
The intent, instruction, and receiving identity tell the same story.
The transaction looks normal in isolation. Its identity continuity does not.
INTERACTIVE CASE FILE / APP → MULE FAN-OUT
Select each phase. The payment world, attacker budget, policy, and evaluation split stay fixed; only the tested strategy and hardened decision change.
ADVERSARIAL LOOP
ROUND 01 · FROZEN BASELINE
The obvious strategy is stopped. That result becomes the red search’s starting point, not the project’s conclusion.
THE HARDENING RESULT / HELD-OUT POPULATION
The useful outcome is not a perfect score. MAYA recovered the selected evasion—and measured the added friction instead of hiding it.
| Measure | Baseline | Hardened | Change |
|---|---|---|---|
| Scenario detection | 16.7% | 100.0% | +83.3 pp |
| Fraud-event recall | 36.1% | 100.0% | +63.9 pp |
| Value-weighted recall | 48.8% | 100.0% | +51.2 pp |
| False-positive rate | 0.10% | 1.10% | +1.00 pp |
| Legitimate value held | ₹514.93 | ₹6,008.63 | +₹5,493.70 |
Controlled, deterministic evaluation with an evidence-linked mechanism. This one-family mechanism test establishes laboratory behavior—not production prevalence, calibration, or bank-scale performance.
SHARED DECISION PATH / TWO DECEPTIONS
APP fan-out and merchant-QR substitution compile, execute, and reach the same payer-side authorization boundary through one feature contract.
| Mechanism | Rule recall | Shared recall | Scenarios caught | Controls held |
|---|---|---|---|---|
| APP → mule fan-out | 0.0% | 66.7% | 12 / 12 | 0 / 12 |
| Merchant QR substitution | 100.0% | 100.0% | 12 / 12 | 0 / 12 |
Zero false positives means 0 of 48 legitimate requests in this controlled population. It is evidence for the paired mechanism test, not a low-FPR production claim.
REMOVE THE IDEA / MEASURE WHAT BREAKS
We restricted MAYA to request-local fields, kept the same split, and reran the detector. Then we restored history and endpoint continuity.
QR SUBSTITUTION Transaction-only recall 0.0% → continuity-aware 100.0%.
ATTACK ATLAS / RESEARCH BEFORE SIMULATION
Every simulated mechanism begins as a documented fraud pattern. Hypotheses about an AI-enabled extension remain explicitly separated from direct evidence.
10 documented vectors
9 documented vectors
8 documented vectors
7 documented vectors
6 documented vectors
Atlas snapshot 2026-08-20. “AI extension” means the fraud pattern is documented while the GenAI role remains a bounded research hypothesis.
UNDER THE LAB / ONE CLOSED LOOP
Research-backed payment deception patterns
Typed actions, constraints, and private truth
A stateful ledger with valid money movement
Bounded counterexample search with coarse feedback
Causal features scored before authorization
Disjoint tests, paired controls, honest trade-offs
BUILT BY / SOLO SUBMISSION
Design, research, simulation, defense engineering, and the very necessary coffee.