Cointime

Download App
iOS & Android

A Feature Engineering Case Study in Consistency and Fraud Detection

Validated Venture

Main Takeaways

  • As the world’s largest crypto exchange, it’s crucial we have a risk detection system that is fast yet doesn’t compromise on accuracy. 
  • The challenge we encountered was ensuring our models always used up-to-date information, especially when detecting suspicious account activity in real-time. 
  • To achieve stronger feature consistency and greater production speed, we now make reasonable assumptions about our data and combine our batch and streaming pipelines. 

Discover how our feature engineering pipeline creates strong, consistent features to detect fraudulent withdrawals on the Binance platform. 

Inside our machine learning (ML) pipeline — which you can learn more about in a previous article — we recently built an automated feature engineering pipeline that funnels raw data into reusable online features that can be shared across all risk-related models. 

In the process of building and testing this pipeline, our data scientists encountered an intriguing feature consistency problem: How do we create accurate sets of online features that dynamically change over time?

Consider this real-world scenario: A crypto exchange — in this case, Binance — is trying to detect fraudulent withdrawals before money leaves the platform. One possible solution is to add a feature to your model that detects time lapsed since the user’s last specific operation (e.g., log in or bind mobile). It would look something like this:

user_id|last_bind_google_time_diff_in_days|...

1|3.52|...

The Challenge of Implementation

The number of keys required to calculate and update features in an online feature store is impractical. Using a streaming pipeline, such as Flink, would be impossible since it can only calculate users with records coming into Kafka at the present moment. 

As a compromise, we could use a batch pipeline and accept some delay. Let’s say a model can fetch features from an online feature store and perform real-time inference in around one hour. At the same time, if it takes one hour for a feature store to finish calculating and ingesting data, the batch pipeline would — in theory — solve the problem.

Unfortunately, there’s one glaring issue: using such a batch pipeline is highly time-consuming. This makes finishing within one hour unfeasible when you’re the world’s largest crypto exchange dealing with approximately a hundred million users and a TPS limit for writes.  

We’ve found that the best practice is to make assumptions about our users, thereby shrinking the amount of data going into our feature store. 

Easing the Issue With Practical Assumptions

Online features are ingested in real-time and are constantly changing because they represent the most up-to-date version of an environment. With active Binance users, we cannot afford to use models with outdated features.

It’s imperative that our system flags any suspicious withdrawals as soon as possible. Any added delay, even by a few minutes, means more time for a malicious actor to get away with their crimes. 

So, for the sake of efficiency, we assume recent logins hold relatively higher risk:

  • We find (250 days + 0.125[3/24 delay] day) produces relatively smaller errors than (1 day +  0.125[3/24 delay] day).
  • Most operations won’t exceed a certain threshold; let’s say 365 days. To save time and computing resources, we omit users who haven’t logged in for over a year. 

Our Solution

We use lambda architecture, which entails a process where we combine batch and streaming pipelines, to achieve stronger feature consistency.

What does the solution look like conceptually?

  • Batch Pipeline: Performs feature engineering for a massive user base.
  • Streaming Pipeline: Remedies batch pipeline delay time for recent logins.

What if a record is ingested into the online feature store between the delay time in batch ingestion?

Our features still maintain strong consistency even when records are ingested during the one-hour batch ingestion delay period. This is because the online feature store we use at Binance returns the latest value based on the event_time you specify when retrieving the value.

Comments

All Comments

Recommended for you

  • DMDAO Burns Nearly 35,000 Tokens Over the Past 7 Days, Bringing Total DMD Burned to Over 716,000

    On September 3, 2026, the latest on-chain data monitoring showed that from August 28 to September 3, 2026, the DMDAO distributed market-making protocol ecosystem maintained a high and stable level of activity, with a cumulative 34,928.27 DMD burned over the past 7 days.

  • Trump Shares Op-Ed Claiming He is Winning the War Against Iran

    On August 29, U.S. President Trump shared a commentary article from the New York Post on Truth Social on Saturday, which stated that he is winning the war against Iran and should maintain the current strategy. The title of the article Trump shared read: 'Trump is Winning the War Against Iran - Stay the Course.'

  • Morgan Stanley: 2028 as a Key Observation Point for Global Memory Competition Landscape

    On August 29, Morgan Stanley pointed out that the rise of Chinese memory manufacturers should not be viewed merely as a technological catch-up or low-cost substitution; what is truly noteworthy is that their production capacity may gradually become large enough to alter the supply structure of the global memory market. Changxin Technology and Yangtze Memory Technologies are currently entering the mainstream product market and gradually extending into high-profit markets such as HBM, high-end server DRAM, and enterprise SSDs. Morgan Stanley considers 2028 as an important observation point for the global memory competition landscape. From 2026 to 2027, demand for AI servers, capacity crowding of advanced wafers by HBM, import substitution, and the time required for customer certification may absorb most of the new supply from Chinese memory manufacturers. By 2028, as Chinese manufacturers expand production, the additional capacity from Samsung, SK Hynix, and Micron, which had previously initiated expansions, will also be released. At that time, the supply variables in the global memory market will significantly increase. Morgan Stanley estimates that Changxin's DRAM monthly production capacity will rise from 180,000 wafers in 2025 to 300,000 in 2026, accounting for approximately 13% of global DRAM wafer capacity and about 11% of bit shipments; by 2028, it is expected to further increase to 500,000 wafers, and by 2031, it could reach 800,000 wafers. If the expansion proceeds smoothly, Changxin's global DRAM bit shipment market share could approach 15% by 2030, and it may even have the opportunity to surpass Micron in production capacity around 2028, becoming the third-largest DRAM supplier in the world.

  • US Spot Ethereum ETF Sees Net Inflow of $102.17 Million Yesterday

    On August 29, according to monitoring by Trader T, the US spot Ethereum ETF recorded a net inflow of $102.17 million yesterday.

  • US Spot Ethereum ETF Sees Net Inflow of $102.17 Million

    On August 29, according to monitoring by Trader T, the US spot Ethereum ETF experienced a net inflow of $102.17 million yesterday.

  • US Spot Bitcoin ETF Sees Net Outflow of $201.81 Million

    On August 29, according to monitoring by Trader T, the US spot Bitcoin ETF experienced a net outflow of $201.81 million yesterday.

  • US Spot Bitcoin ETF Sees Net Outflow of $201.81 Million Yesterday

    On August 29, according to monitoring by Trader T, the US spot Bitcoin ETF experienced a net outflow of $201.81 million yesterday.

  • BTC Surpasses $78,000

    Market data shows that BTC has surpassed $78,000, currently priced at $78,009.49. The 24-hour decline has narrowed to 3.23%. Due to significant market fluctuations, please ensure proper risk management.

  • BTC Surpasses $78,000

    Market data shows that BTC has surpassed $78,000, currently priced at $78,009.49, with a 24-hour decline narrowing to 3.23%. The market is experiencing significant volatility, so please ensure proper risk management.

  • BTC Briefly Drops Below $77,000

    Market data shows that BTC briefly fell below $77,000, currently reported at $77,694, with a 24-hour decline of 3.3%. The market is experiencing significant volatility, so please ensure proper risk management.