MEDIANAMA
Technology and policy in India
“As Rahul Vatts [Airtel] also pointed out, that within a telecom domain, they don’t have any visibility of the digital platform or the messaging platform. So the fraud is moving across the domain. So the responsibility has to be fixed and shared also. So, I think while fixing the responsibility within the multiple sectors,” said the Telecom Regulatory Authority of India’s (TRAI) Joint Advisor, Sanjay Kumar.
“We do require a sector-wise, an ecosystem-wise approach to be really able to address because there are many signals which we are generating. There is a large amount of data which we are generating. And so there is a potential for us to really create an envelope of safety around the customer,” said Rahul Vatts, Chairman of COAI and Director of Corporate Affairs at Airtel. Both Airtel and TRAI, along with the UK’s British High Commission members, spoke at the COAI’s event on AI and telecom.
Why TRAI’s push for signal sharing from internet-based messaging platforms: “When the fraud starts from the communication layer, a telco can see only the part which is traveling within that communication layer. And the later part has to be seen by the respective OTT player of that messaging platform and the banking platform if the transaction has happened. But that is the only one part, that the detecting the signal within the domain is the only one part. The core requirement is that you need to share those signals across the sectors,” said Sanjay Kumar.
“Until and unless you don’t share these signals across the sectors, there cannot be any creditable detrance against for the foresters.” — TRAI
TRAI’s attempts at intelligence sharing across sectors: In an attempt to solve these cross-sectoral intelligence sharing issues, he stated that TRAI formulated a Joint Committee of Regulators (JoCR). This TRAI-led committee has DoT, MeitY, RBI, SEBI, and IRDAI as their members. “Over the years, due to the evolution of fraud and spam, we have evolved from a platform to discuss mutual items of concern only to a platform on which we are right now working to set up processes that enable frequent sharing of intelligence across sectors”, Sanjay Kumar said.
“The final objective is to evolve into a platform where the AI signals can be shared across the operator on the real-time basis,” said TRAI’s Joint Advisor.
“Fraudsters don’t only take the resources from one telco or the two telcos; they take the resources from the OTT players or the messaging platform providers as well. They take the resources from the banks as well. If your action is taken within the domain only, then there would be no effective... As a regulator, we are trying to ensure that all the sectors take an action on that forestry that is detected using the AI signals. So that is our path to evolve from our strategy from an outcome sector to a strategy which works across the sectors,” he reiterated.
Airtel pushes for spam controls at the receiver end too: “We have also shared some data with the regulator earlier to show that some of the blacklisted entities, which we found out on the DLT system were actually generating so much spam, were actually those entities which actually had no subscribers of their own. There was full incentive for them to spam the entire ecosystem because absolutely there is no incentive for them not to because there is no terminating thing available,” said Vats.
“There is absolutely no control at the terminating end of the operator to be able to control this spam effectively.” – Rahul Vats, Airtel
“The way we manage content needs to take shift, shift from the originating end to the terminating end. Because the terminating operator should get the flexibility to choose that if somebody is trying to spam a subscriber who belongs to that network, he should have the flexibility to be able to address how he addresses this spam,” he stated.
What are the signals Airtel uses to identify a potential spammer or scammer? “Are you having too many outgoing calls? Are you having too many incoming calls? Are you calling across the country on a single day? Where are you calling from? And so around 250 of such parameters, we combined to create our own AI score, and the result of that was quite evident to everybody,” said Rahul Vats.
“We were able to look at more than 1 trillion records, and we were able to tag nearly 2.5 billion calls and 1.5 billion SMS as suspected scam/fraud signals, which gives an additional data point to the customer to decide whether he wants to entertain that call or not. This is very powerful, and this is real-time, because this number It can change every day. It can change based on the calling patterns of the people. So, this is as real-time as you can get about it,” said Vats.
Out of 100 calls or the messages in India, all of which are tagged as a suspected call or a message, only 0.004 out of 100 complaints are filed. So it is not even 1%; it is 0.004 out of 100 calls and messages; only 0.004 complaints are filed. So, this data tells us that the existing traditional approach will not work in the modern world, where fraud has become very sophisticated and very complex.” – TRAI’s Joint Advisor
“Any fraudulent transaction today may start on a telco system, but actually culminates on a digital platform,” Kumar reiterated after speaking about OTP-related scams. He stated that Airtel shows an alert when the user attempts to enter an OTP while on an ongoing call. He then spoke about Airtel’s partnership with Google’s RCS messages.
TRAI’s shift from traditional spam reporting to fraud prevention: “We [TRAI] are trying to see the fraud not as an event, but as a journey. A journey which starts from a telecom network moves to the digital platform, a messaging platform, and terminates on a banking platform,” said TRAI Sanjay Kumar. He further explained what the earlier traditional method meant: “In the traditional approach, we generally wait for an event to take place that is a filing a complaint from the customer or a victim. And then only the whole ecosystem, which consists of the TRAI, DoT, lawful law enforcement agencies, et cetera, they got activated. So, it is basically the traditional approach is basically event-based.”
He then briefly referred to TRAI’s February guidelines (pdf) that mandate the telcos to share AI-powered fraud-related intelligence with other telcos.
Under TRAI’s fraud/spam AI-signal sharing mandate, he said, “Every telco is supposed to scan all the calls and messages and share the AI signals with the upstream telecom service provider, which is connected with the coordinator of that call or the message.”
” So, a telco gets the AI signals from the other telcos, and based on that, that telco is supposed to identify the fraudster and then take an enforcement action,” he added.
“Now we have moved to a six-stage process,” TRAI’s executive explained:
“This is just a process we have already moved to, and we are hoping that we will continue to add more and more steps as we move forward,” Kumar added.
Why rule-based systems don’t work anymore and how AI can help: How do you make sense of all the signals that are coming from different sectors? Sanjeev Kumar Singh from the Department of Telecommunications (DoT) asked after explaining how a typical online fraud takes place with false identities.
“It is humanly not possible. Artificial intelligence only can work on this. The third important characteristic of the digital frauds is that the modus operandi keeps changing. With the evolving technology, the fraudsters themselves are using artificial intelligence, so how do you counter that? Any rule-based system will not work. You will have to understand that if you make any rule-based system, since the modus operandi will change, the fraudsters can easily play under the radar. Artificial intelligence can help you understand in the real-time, the patterns, and then can change the decision making in real-time. That is where the artificial intelligence comes in,” the Deputy Direct General of DoT Sanjeev explained.
How AI is integrated into DoT’s fraud prevention systems: “We designed an ASTRA system, which is an artificial intelligence-based system which detects, based on the demographic data and the facial deduplication, whether this connection is being taken on a fake force document. That’s where the suspicious signal AI is being used to generate suspicious signals. We also use that internationally because generally what happens is a lot of these frauds happen from international scam compounds, and those calls come from there with spoofed calls so that they look genuine; they look like this is an Indian number. We have worked on that. Our CIOR system helped to prevent these spoofed calls from entering into the country. In real-time, they are being stopped at the gateway. AI also helps there.”
Sanchaar Saathi as a crowdsourced data for validation: “We also created a crowdsourcing mechanism where, through the Sanchaar Saathi platform, we have asked citizens to share the data with us. So whatever is suspicious call, they get, they share that data with us so that whatever signals we are getting from our own analysis gets validated through whatever the citizens are telling us,” said Singh. He later said that AI systems will work on these collective signals.
“We designed a couple of things, a digital intelligence platform where we can share these signals. Most importantly, a financial fraud risk indicator (FRI), which actually sends the risk signal based on a mobile number or a telecom resource to the banking sector. And using that, they can either give the alert to the citizen or can stop transactions. And we probably said that last week itself since it launched; this was 15 months ago; we launched this. And this FRI has been able to prevent around Rs 50 billions of suspect fraud transactions. This is a huge success, I would say,” he claimed, addressing the DoT’s tool.
DPDP Act may not stop spam, says DoT’s executive: “As far as the DPDP Act is concerned, it does not deal with spam or something. It deals with data protection and data sharing. Might result in some reduction in spam. I don’t know how it’s going to unfold… There are certain limits on data sharing; maybe it can reduce spam to some level. But can I say with confidence there is any direct correlation? I, personally, don’t see that,” said Singh in response to an audience question.
He also then added that the consent framework is already stated in the Section 28 of Telecommunication Act.
“The DPDP Act does not supersede any of the provisions of any other act. It is only in addition. Where there are specific provisions in the acts of a sectoral act, they will prevail.” – Sanjeev Kumar Singh, DDG, DoT.
In response to the same question, TRAI’s executive said, “There’s a provision of consent and the consent manager in the DPDP Act, and we also have a provision for taking consent before you start making promotional calls. So, these are the two overlapping concepts within a DPDP and our regulation (TCCCPR, 2018). But our consent start is limited to the making of a promotional call or making a call to the customer, whereas the DPDP Act starts once you establish a call and then start collecting the data. So these are two consent to the jurisdiction are different. Still, while framing all the future regulations, we are concerned, and we are taking specific care that our regulations remain compliant with the DPDP Act.”
What is the AI-led scam issues in the UK?
“Over the last financial year, we’ve seen almost a 400% increase in AI-enabled frauds that have been reported to the government.” – Jez Stanley, First Secretary of Illicit Finance and Serious Organized Crime Network at the British High Commission.
“We’ve seen an eightfold increase in losses associated just with AI-enabled fraud,” Stanley added. He then stated a few varieties of AI deepfake-led impersonation frauds, like ‘fake kidnaps, CEO-based scams, and romance scams.’
Stanley also stated that their AI Security Institute and National Crime Agency are working on AI solutions in the law enforcement of cybercrimes. The British High Commission’s director for development, climate, science & technology, Sarah Cooper, moderated this discussion.
Read about the UK-India memorandum against fraud here.
Also Read:
For You
MediaNama’s issue brief examines whether age verification and social media restrictions can protect children in India without creating disproportionate privacy risks.
MediaNama is the premier source of information and analysis on Technology Policy in India. More about MediaNama, and contact information, here.
© 2024 Mixed Bag Media Pvt. Ltd.
source
Technology and policy in India
“As Rahul Vatts [Airtel] also pointed out, that within a telecom domain, they don’t have any visibility of the digital platform or the messaging platform. So the fraud is moving across the domain. So the responsibility has to be fixed and shared also. So, I think while fixing the responsibility within the multiple sectors,” said the Telecom Regulatory Authority of India’s (TRAI) Joint Advisor, Sanjay Kumar.
“We do require a sector-wise, an ecosystem-wise approach to be really able to address because there are many signals which we are generating. There is a large amount of data which we are generating. And so there is a potential for us to really create an envelope of safety around the customer,” said Rahul Vatts, Chairman of COAI and Director of Corporate Affairs at Airtel. Both Airtel and TRAI, along with the UK’s British High Commission members, spoke at the COAI’s event on AI and telecom.
Why TRAI’s push for signal sharing from internet-based messaging platforms: “When the fraud starts from the communication layer, a telco can see only the part which is traveling within that communication layer. And the later part has to be seen by the respective OTT player of that messaging platform and the banking platform if the transaction has happened. But that is the only one part, that the detecting the signal within the domain is the only one part. The core requirement is that you need to share those signals across the sectors,” said Sanjay Kumar.
“Until and unless you don’t share these signals across the sectors, there cannot be any creditable detrance against for the foresters.” — TRAI
TRAI’s attempts at intelligence sharing across sectors: In an attempt to solve these cross-sectoral intelligence sharing issues, he stated that TRAI formulated a Joint Committee of Regulators (JoCR). This TRAI-led committee has DoT, MeitY, RBI, SEBI, and IRDAI as their members. “Over the years, due to the evolution of fraud and spam, we have evolved from a platform to discuss mutual items of concern only to a platform on which we are right now working to set up processes that enable frequent sharing of intelligence across sectors”, Sanjay Kumar said.
“The final objective is to evolve into a platform where the AI signals can be shared across the operator on the real-time basis,” said TRAI’s Joint Advisor.
“Fraudsters don’t only take the resources from one telco or the two telcos; they take the resources from the OTT players or the messaging platform providers as well. They take the resources from the banks as well. If your action is taken within the domain only, then there would be no effective... As a regulator, we are trying to ensure that all the sectors take an action on that forestry that is detected using the AI signals. So that is our path to evolve from our strategy from an outcome sector to a strategy which works across the sectors,” he reiterated.
Airtel pushes for spam controls at the receiver end too: “We have also shared some data with the regulator earlier to show that some of the blacklisted entities, which we found out on the DLT system were actually generating so much spam, were actually those entities which actually had no subscribers of their own. There was full incentive for them to spam the entire ecosystem because absolutely there is no incentive for them not to because there is no terminating thing available,” said Vats.
“There is absolutely no control at the terminating end of the operator to be able to control this spam effectively.” – Rahul Vats, Airtel
“The way we manage content needs to take shift, shift from the originating end to the terminating end. Because the terminating operator should get the flexibility to choose that if somebody is trying to spam a subscriber who belongs to that network, he should have the flexibility to be able to address how he addresses this spam,” he stated.
What are the signals Airtel uses to identify a potential spammer or scammer? “Are you having too many outgoing calls? Are you having too many incoming calls? Are you calling across the country on a single day? Where are you calling from? And so around 250 of such parameters, we combined to create our own AI score, and the result of that was quite evident to everybody,” said Rahul Vats.
“We were able to look at more than 1 trillion records, and we were able to tag nearly 2.5 billion calls and 1.5 billion SMS as suspected scam/fraud signals, which gives an additional data point to the customer to decide whether he wants to entertain that call or not. This is very powerful, and this is real-time, because this number It can change every day. It can change based on the calling patterns of the people. So, this is as real-time as you can get about it,” said Vats.
Out of 100 calls or the messages in India, all of which are tagged as a suspected call or a message, only 0.004 out of 100 complaints are filed. So it is not even 1%; it is 0.004 out of 100 calls and messages; only 0.004 complaints are filed. So, this data tells us that the existing traditional approach will not work in the modern world, where fraud has become very sophisticated and very complex.” – TRAI’s Joint Advisor
“Any fraudulent transaction today may start on a telco system, but actually culminates on a digital platform,” Kumar reiterated after speaking about OTP-related scams. He stated that Airtel shows an alert when the user attempts to enter an OTP while on an ongoing call. He then spoke about Airtel’s partnership with Google’s RCS messages.
TRAI’s shift from traditional spam reporting to fraud prevention: “We [TRAI] are trying to see the fraud not as an event, but as a journey. A journey which starts from a telecom network moves to the digital platform, a messaging platform, and terminates on a banking platform,” said TRAI Sanjay Kumar. He further explained what the earlier traditional method meant: “In the traditional approach, we generally wait for an event to take place that is a filing a complaint from the customer or a victim. And then only the whole ecosystem, which consists of the TRAI, DoT, lawful law enforcement agencies, et cetera, they got activated. So, it is basically the traditional approach is basically event-based.”
He then briefly referred to TRAI’s February guidelines (pdf) that mandate the telcos to share AI-powered fraud-related intelligence with other telcos.
Under TRAI’s fraud/spam AI-signal sharing mandate, he said, “Every telco is supposed to scan all the calls and messages and share the AI signals with the upstream telecom service provider, which is connected with the coordinator of that call or the message.”
” So, a telco gets the AI signals from the other telcos, and based on that, that telco is supposed to identify the fraudster and then take an enforcement action,” he added.
“Now we have moved to a six-stage process,” TRAI’s executive explained:
“This is just a process we have already moved to, and we are hoping that we will continue to add more and more steps as we move forward,” Kumar added.
Why rule-based systems don’t work anymore and how AI can help: How do you make sense of all the signals that are coming from different sectors? Sanjeev Kumar Singh from the Department of Telecommunications (DoT) asked after explaining how a typical online fraud takes place with false identities.
“It is humanly not possible. Artificial intelligence only can work on this. The third important characteristic of the digital frauds is that the modus operandi keeps changing. With the evolving technology, the fraudsters themselves are using artificial intelligence, so how do you counter that? Any rule-based system will not work. You will have to understand that if you make any rule-based system, since the modus operandi will change, the fraudsters can easily play under the radar. Artificial intelligence can help you understand in the real-time, the patterns, and then can change the decision making in real-time. That is where the artificial intelligence comes in,” the Deputy Direct General of DoT Sanjeev explained.
How AI is integrated into DoT’s fraud prevention systems: “We designed an ASTRA system, which is an artificial intelligence-based system which detects, based on the demographic data and the facial deduplication, whether this connection is being taken on a fake force document. That’s where the suspicious signal AI is being used to generate suspicious signals. We also use that internationally because generally what happens is a lot of these frauds happen from international scam compounds, and those calls come from there with spoofed calls so that they look genuine; they look like this is an Indian number. We have worked on that. Our CIOR system helped to prevent these spoofed calls from entering into the country. In real-time, they are being stopped at the gateway. AI also helps there.”
Sanchaar Saathi as a crowdsourced data for validation: “We also created a crowdsourcing mechanism where, through the Sanchaar Saathi platform, we have asked citizens to share the data with us. So whatever is suspicious call, they get, they share that data with us so that whatever signals we are getting from our own analysis gets validated through whatever the citizens are telling us,” said Singh. He later said that AI systems will work on these collective signals.
“We designed a couple of things, a digital intelligence platform where we can share these signals. Most importantly, a financial fraud risk indicator (FRI), which actually sends the risk signal based on a mobile number or a telecom resource to the banking sector. And using that, they can either give the alert to the citizen or can stop transactions. And we probably said that last week itself since it launched; this was 15 months ago; we launched this. And this FRI has been able to prevent around Rs 50 billions of suspect fraud transactions. This is a huge success, I would say,” he claimed, addressing the DoT’s tool.
DPDP Act may not stop spam, says DoT’s executive: “As far as the DPDP Act is concerned, it does not deal with spam or something. It deals with data protection and data sharing. Might result in some reduction in spam. I don’t know how it’s going to unfold… There are certain limits on data sharing; maybe it can reduce spam to some level. But can I say with confidence there is any direct correlation? I, personally, don’t see that,” said Singh in response to an audience question.
He also then added that the consent framework is already stated in the Section 28 of Telecommunication Act.
“The DPDP Act does not supersede any of the provisions of any other act. It is only in addition. Where there are specific provisions in the acts of a sectoral act, they will prevail.” – Sanjeev Kumar Singh, DDG, DoT.
In response to the same question, TRAI’s executive said, “There’s a provision of consent and the consent manager in the DPDP Act, and we also have a provision for taking consent before you start making promotional calls. So, these are the two overlapping concepts within a DPDP and our regulation (TCCCPR, 2018). But our consent start is limited to the making of a promotional call or making a call to the customer, whereas the DPDP Act starts once you establish a call and then start collecting the data. So these are two consent to the jurisdiction are different. Still, while framing all the future regulations, we are concerned, and we are taking specific care that our regulations remain compliant with the DPDP Act.”
What is the AI-led scam issues in the UK?
“Over the last financial year, we’ve seen almost a 400% increase in AI-enabled frauds that have been reported to the government.” – Jez Stanley, First Secretary of Illicit Finance and Serious Organized Crime Network at the British High Commission.
“We’ve seen an eightfold increase in losses associated just with AI-enabled fraud,” Stanley added. He then stated a few varieties of AI deepfake-led impersonation frauds, like ‘fake kidnaps, CEO-based scams, and romance scams.’
Stanley also stated that their AI Security Institute and National Crime Agency are working on AI solutions in the law enforcement of cybercrimes. The British High Commission’s director for development, climate, science & technology, Sarah Cooper, moderated this discussion.
Read about the UK-India memorandum against fraud here.
Also Read:
For You
- Read Reasoned by Nikhil Pahwa: How AI is changing our world
- Sign up for MediaNama’s Daily Newsletter to receive regular updates
- Sponsor a MediaNama Event
MediaNama’s issue brief examines whether age verification and social media restrictions can protect children in India without creating disproportionate privacy risks.
MediaNama is the premier source of information and analysis on Technology Policy in India. More about MediaNama, and contact information, here.
© 2024 Mixed Bag Media Pvt. Ltd.
source
