
International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
Gayatri
![]()

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
Gayatri
Dayanand Navare, Payal Subhash Rathod, Vedashri Keshavrao Dhane, Jayesh Ashok Dhumal , Prof. Swati
Gaikwad
Dept. of Computer Science & Engineering (AI & ML) Bharat College of Engineering Badlapur, India - 421503
Abstract - The rapid growth of the Unified Payments Interface (UPI) has transformed digital payments in India by enabling fast, secure, and real-timemoneytransfers. However, the increasing use of UPI has also led to a rise in fraudulent activities such as phishing attacks, fake applications, social engineering, and unauthorized access to accounts [4]. The system analyzes transaction details such as transaction amount, frequency, and user behavior to identifysuspicious or abnormal activities. Machine learning algorithms including Random Forest, Logistic Regression, and XGBoost are used to classify transactions as legitimate or fraudulent [2],[10]. The proposed model also includes an alert system that notifies users or authorities whensuspicious transactions aredetected. This approach helps in early detection of fraud, reduces financial losses, and improves user trust in digital payment systems [4],[8]. The system is scalable and can be integrated into existing UPI platforms to make digital transactions safer and more reliable.
Keywords - UPI, Fraud Detection, Machine Learning, Random Forest, XGBoost, Digital Payment Security, Transaction Analysis.
Digital payment systems have grown rapidly in India, especially with the introduction of the Unified Payments Interface(UPI).UPIallowsuserstotransfermoneyinstantly using mobile devices, making digital transactions fast, simple,andconvenient.However,theincreasinguseofUPI hasalsoledtoariseinfraudulentactivitiessuchasphishing, faketransactions,andunauthorizedaccountaccess[4].
This project proposes a fraud detection system called UPI Fraud Detection, which uses Machine Learning to analyze UPItransactiondata.Machinelearningalgorithmssuchas RandomForestandXGBoostareusedtoclassifytransactions asgenuineorfraudulent[2],[10].
The main objectives of this project are:
To analyze UPI transaction data and detect abnormal patterns[8].
To apply machine learning algorithms for predicting fraudulenttransactions[4].
Toevaluatetheperformanceofthemodelusingmetrics suchasaccuracy,precision,recall,andF1-score[10]. The expected outcome of this system is early detection of fraudandimprovedsecurityfordigitaltransactions,which
willhelpreducefinanciallossesandincreaseusertrustin digitalpaymentplatforms[4],[8].
N.K.KanakarajuandS.S.Sreedhar(2023)usedRandom Forest and SVM for behavioral fraud detection in UPI transaction metadata and achieved high accuracy in identifyingknownfraudpatterns.However,themodel mainlyfocusedonknownfraudbehaviors.
A. Dhoke and N. Jaiswal (2019) applied Logistic Regression and Random Forest for financial fraud classification and found Random Forest to be more effective in handling class imbalance. However, the study focused on credit card fraud rather than UPIspecificfraud.
S. Gupta and B. Giri (2020) used NLP techniques to identify phishing triggers in digital communication channels,improvingthedetectionofsocialengineering tactics. However, the study did not directly address transaction-levelUPIfraud.
P. Kumar and R. Singh (2020) studied QR phishing (Quishing) using Computer Vision and URL Analysis, emphasizingtheneedforautomatedQRverificationin mobileapps.However,thestudyfocusedmainlyonQRrelatedthreats.
NPCI Guidelines (2024) defined rule-based UPI safety measures, including the ₹1 lakh transaction limit, to improveregulatorysafety.However,theseguidelinesdo notprovidemachinelearning-basedfraudprediction.
TheproposedsystemarchitectureforUPIfrauddetection begins with collecting transaction details such as amount, time, UPI ID, device, and location. The collected data undergoespreprocessingstepsincludingcleaning,encoding, andnormalizationtoprepareitforanalysis

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072

1) Transaction Data collection: The system collects important transaction details such as transaction amount, time, user ID, device information, and transaction frequency. These parameters are used as inputfeaturesforfrauddetection[10].
2) Machine Learning Analysis The collected transaction data is processed using machine learning algorithms such as Random Forest to analyze patterns and classifytransactionsaslegitimateorfraudulent[4],[10].
3) QR Code and Integrity Verification: The system analyzes QR code images using an image processing pipeline that includes grayscale conversion and binarization. This helps verify the authenticity of the transactionenvironmentanddetecthigh-riskQRcodes.
4) SMSPhishingDetection&Reporting:TheSMSanalysis module scans message text using pattern matching techniquestodetectsuspiciouskeywordssuchasOTPor KYC.Thesystemthencompilestheresultsandgenerates areportfortheuser[5].
Although not visible in the source code logic, the deployment environment relies on specific Python structuresidentifiedintheprojectdirectory:
Thesystemisdevelopedusingthe Python programming language withlibrariessuchas NumPy, Pandas,Scikitlearn, and image processing tools for data analysis, machinelearningimplementation,andQRcodeprocessing [2],[5].
1) TheimplementationoftheUPIFraudDetectionsystem isdividedintothreedistinctmodules:UPITransaction Integrity,QRCodeAnalysis,andSMSPhishingDetection.
2) Model Training: A dataset containing 6 key features (UPI length, special characters, suspicious keywords, amount,devicemismatch,andlocationmismatch)was usedtotrainaRandomForestmodel[4],[10].
3) In this phase, a hybrid logic mechanism was implementedtoenhancetheefficiencyandreliabilityof thefrauddetectionsystem.Apre-processingfilterwas developed to intercept any transaction exceeding 100,000 INR,whichisbeyondthestandardtransaction limitdefinedformostUPItransactions.Thisrule-based filteringmechanismensuresthattransactionsviolating predefined logical constraints are immediately flagged withoutbeingprocessedbythemachinelearningmodel [4]. By applying this preliminary validation step, the system reduces unnecessary computational overhead andimprovestheoverallperformanceofthemodel.
4) Vision&NLPintegration.
5) ImplementationofOpenCVforimagepreprocessingand PyZbarforQRdecoding.TheSMSmodulewasbuiltusing keyword-frequency[5].
6) D. Security Correlation: Establishing a dependency where the check_app_integrityfunction istriggered by theanalyze_QR_coderesult.
The system relies on specific algorithmic logic for data processing:
Random Forest Classifier
RandomForestisanensemblelearningalgorithmthatbuilds multiple decision trees and combines their results to improve prediction accuracy. It is used to analyze the sixfeature transaction vector and classify transactions as legitimateorfraudulentwhilereducingoverfitting[4],[10].

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
The Aho–Corasick algorithm is used in the SMS analysis moduletodetectsuspiciouskeywordssuchas“KYC”,“OTP”, and “Blocked”. This helps identify potential phishing or fraudulentmessagesquickly[5].
Image Processing Pipeline
TheimageprocessingpipelineprocessesQRcodeimagesby applyinggrayscaleconversionandbinarization.Thesesteps improvetheaccuracyofQRcodedecodingeveninlow-light orunclearscanningconditions.Thesepreprocessingsteps improvetheaccuracyofQRcodedecoding,especiallyunder challenging conditions such as low-light environments or blurred scans. The processed image is then decoded to extract transaction information, which can be further analyzedforpotentialfraud
Python 3.10+ :Theprimaryprogramminglanguagefor backendlogic.
Flask : A micro-web framework used for routing and sessionmanagement.
Scikit-learn :ForimplementingtheMachineLearning pipelineandmodelserialization.
OpenCV-Python :Tohandleimageprocessingtasksfor theQRscanner.
PyZbar :FordecodingthedataencodedwithintheQR symbols.
FPDF :Forgeneratingprofessional,encoded-safePDF securityreports.
Jinja2 :Thetemplatingengineusedtorenderdynamic HTMLcontent.
1) DashboardModule:TheDashboardmoduleactsasthe maininterfaceofthesystemandprovidesanoverviewof theprojectfunctionalities.Itservesastheentrypointfor users to access different modules and monitor system operations
2) UPI Transaction QR Integrity Module: This module collectstransaction-relatedmetadatasuchastransaction amount,userdetails,anddeviceinformationtocalculate the risk probability. It also scans QR code images and verifies the environment trust level; if a QR code is detectedas high risk [4], [10].
3) SMSModule:AsandboxwhereuserscanpasteSMStext tocheckforphishingindicators[5].
4) Report Generation Module: Collects all "Session Results"andcompilesthemintoadownloadablePDFfor theuser'srecords.




International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072


Fig. 3. Outputs&Results
9. FUTURE SCOPE
Deep Learning (LSTM): To analyze the sequence of user transactions to find "low-and-slow" fraud patterns- vide automatedforecastingandtrendanalysisontheuploaded data[7].
Voice Phishing (Vishing) Detection: Adding a module to record and analyze audio calls for fraudulent speech patterns.
Blockchain Ledger: Storing the "Fraudulent UPI IDs" on a privateblockchaintopreventscammersfromdeletingtheir history.
10. CONCLUSIONS
This project successfully demonstrates that a Hybrid Approach is the most effective way to secure UPI transactions. By combining the "Intelligence" of Machine Learning with the "Strictness" of Banking Rules, we have createdasystemthatisbothsmartandcompliant[4],[10]. TheinclusionofQRandSMSanalysismodulesensuresthat
theuserisprotectedfromtheentirelifecycleofamodern digitalpaymentscam[5].
ACKNOWLEDGEMENT (Optional)
Theauthorwouldliketoexpresstheirsinceregratitudeto Prof.SwatiGaikwad(ProjectCoordinator)forherinvaluable guidance,continuousencouragement,andtechnicalsupport throughout the development of the UPI Fraud Detection system. We also extend our thanks to Prof. Vijaylakshmi Tadkal (Head of Department, Computer Science & Engineering-AI&ML)forprovidingthenecessaryacademic resources and laboratory facilities at Bharat College of Engineering,Badlapur. Finally,wethanktheUniversityofMumbaiforprovidingthe curriculumplatformthatmotivatedthisresearchwork.
1. N. K. Kanakaraju and S. S. Sreedhar, "Fraud Detection in UPI Transactions using Machine LearningAlgorithms,"inProc.7thIEEEInt.Conf.on Computing Methodologies and Communication (ICCMC), 2023, pp. 452-457. doi: 10.1109/ICCMC56507.2023.10128542
2. Dhoke and N. Jaiswal, "A Comparative Study of MachineLearningAlgorithmsforCreditCardFraud Detection,"Int.J.Comput.Appl.,vol.182,no.48,pp. 24-29, Jan. 2019. Available: https://www.ijcaonline.org/archives/volume182/n umber48/dhoke-2019-ijca-918641.pdf
3. S.GuptaandB.Giri,"AReviewofPhishingDetection TechniquesbasedonMachineLearning,"Int.J.Adv. Res.Comput.Sci.,vol.11,no.2,pp.112-118,Mar. 2020. Available: http://www.ijarcs.info/index.php/Ijarcs/article/vie w/6565
4. P.KumarandR.Singh,"QRCodeSecurity:ASurvey of Phishing and Malicious Attacks," J. Inf. Secur. Appl., vol. 51, p. 102443, Apr. 2020. doi: 10.1016/j.jisa.2020.102443
5. National Payments Corporation of India (NPCI), "UPI Product Statistics and Safety Awareness Guidelines," 2024. [Online]. Available: https://www.npci.org.in/what-we-do/upi/productstatistics

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072


Gayatri Navare
Currently pursuing Bachelor of Engineering in Computer Science (AIML) from Bharat College Of Engineering, Maharashtra, India. Interested in Data Analyst, MIS Analyst, Business Analyst, Dashboard Analyst as well as Python Programming, Artificial IntelligenceandMachineLearning.
Payal Rathod
Currently pursuing Bachelor of Engineering in Computer Science (AIML) from Bharat College Of Engineering, Maharashtra, India. Interested in Cyber Security and EthicalHackingaswellasPython Programming and Artificial Intelligence.
Vedashri Dhane


Currently pursuing Bachelor of Engineering in Computer Science (AIML) from Bharat College Of Engineering, Maharashtra, India. Interested in Cybersecurity, Data AnalysisandPowerBIDashboard andNetworking.
Jayesh Dhumal
Currently pursuing Bachelor of Engineering in Computer Science (AIML) from Bharat College Of Engineering, Maharashtra, India. InterestedinArtificialIntelligence, MachineLearning and as well as skillfulinDataAnalysis.