IIMEEE / RESEARCH
Behavioral Anomaly Screening for Prepaid Metering
Manuscript in preparation • Not submitted for authority acknowledgement or journal publication
This project investigates a screening approach that combines prepaid recharge behavior with metering-record integrity checks. Its purpose is to identify unusual records for review and field verification, rather than to establish theft or cyberattack outcomes.
Public research abstract
This project investigates an interpretable screening framework for unusual prepaid electricity transaction patterns. Descriptive features of recharge frequency, variability, inactivity and reactivation are considered alongside independent record-integrity checks. Complementary unsupervised approaches, including Isolation Forest and Local Outlier Factor, may support prioritization of records for investigation. Anomaly scores are review signals, not proof of theft, tampering or cyberattack. Without independently confirmed ground-truth cases, detection accuracy and case prevalence cannot be established; operational use would require subsequent validation and appropriate human review.
Research question
Unusual recharge patterns can arise from many causes, including changes in activity, affordability, transaction timing, or record errors. A useful screening process needs both contextual behavioral analysis and independent integrity checks.
Approach
Behavioral features describe recharge activity, variability, dormancy, reactivation, and peer differences. Isolation Forest and Local Outlier Factor provide complementary unsupervised signals, while a separate rule layer checks record integrity. The combined evidence supports review prioritization and subsequent verification.

Research highlights
- Combines global and local unsupervised anomaly signals.
- Keeps record-integrity checks visible alongside behavioral analysis.
- Treats screening outputs as review indicators requiring independent verification.
Illustrative simulation — synthetic, not empirical

Intended application
The research explores how routine transaction records can support structured metering-integrity review where confirmed labels and detailed telemetry are limited.
Scope and limitations
Confirmed tampering labels are unavailable, so theft-detection accuracy, precision, and recall are not established. Separation of score-defined groups is not independent validation of fraud detection. Unusual behavior and identity conflicts may have legitimate or administrative explanations.
Disclosure: The illustrations use invented demonstration data. No consumer-level data, operational case details, confirmed anomaly labels, real fitted-model performance results, or unreleased manuscript are disclosed. Public release remains subject to coauthor, data-owner and intended-journal permissions.