JuicyScore: Extending Anti-Fraud Scoring and Device Authentication with a Generalized Cluster-Graph Approach


Distributed attacks and fraud farms have expanded the requirements for modern anti-fraud systems: it is no longer enough to assess an individual device or the infrastructure in which it operates. It is equally important to understand how sessions, devices, and other entities are connected — and how probable those connections are.
Mature systems address this challenge by extending their functionality. Analysis begins with the device, user behavior, and the technical environment. These signals are then used to identify probable relationships between sessions, devices, and other entities and to build cluster-level context. At the next level, this context is applied to investigations, alerting, scoring enhancement, and other operational anti-fraud scenarios.
Each successive layer does not replace the previous one; it adds context and strengthens protection. In this article, we explain how this approach is implemented at JuicyScore and the role cluster-graph analysis plays within it.
Anti-fraud has long since evolved beyond a simple set of rules and become a measurable factor in the resilience of online businesses. To understand the scale of the challenge, it is enough to look at industry research. According to ACFE, organizations lose around 5% of their revenue to fraud. PwC reports that 46% of companies worldwide experienced economic crime between 2020 and 2022. In the UK alone, the cost of fraud to society was estimated at £14.4 billion in 2023–2024. The scale of automation is also significant: according to Akamai, approximately 42% of web traffic consists of automated sessions, with 65% of those bots classified as malicious.
In this environment, a simple principle applies: the more economically justified layers of protection a system has, the more resilient it becomes. This is also likely to remain the direction in which the anti-fraud industry evolves, alongside continued adherence to compliance requirements, standards, and certifications.
JuicyScore builds its anti-fraud model around multiple parameters and predictors combined across several layers of analysis. The core layer is anti-fraud scoring, which returns a risk score reflecting the expected level of risk.
The next layer is patented probabilistic device authentication. It estimates the probability that different sessions belong to the same device and provides a controllable level of confidence that sessions belong to the same device context when the probability of association is high.
This logic is implemented through the JuicyDevID parameter. It provides device authentication with 99.5–99.9%+ uniqueness in clean traffic and helps reduce authentication errors. At the same time, the system is resilient to a broad range of baseline noise, including browser changes, private browsing modes, browser API spoofing and modification, device settings resets, geolocation changes, as well as manipulation of performance characteristics, storage, network topology, and graphical artifacts.
The internationally patented approach takes into account a broad range of signals and noise factors and employs a wide range of mathematical methods, from gradient descent to cluster-based association and self-learning neural networks. Importantly, combining a high level of uniqueness with the ability to account for a very broad range of potential noise factors makes it possible to minimize both Type I and Type II errors. High noise resilience and high uniqueness significantly increase the informativeness of statistical conclusions and metrics calculated on the basis of JuicyDevID.
In addition, JuicyScore and JuicyID have long included another layer with 70–80%+ uniqueness: the browser hash.
Our products continue to evolve, making it useful to introduce additional layers of protection and filtering. In our case, this is JuicyClusterID, which provides session association or uniqueness at the 90–95%+ level. The approach combines the patented method and mechanism used for probabilistic JuicyDevID with publicly known mathematical techniques, while lowering the uniqueness and accuracy threshold and expanding the available context. As specified in the patent, session relationships can be identified not only through device context but also through behavioral patterns or risk profiles. The calculation follows a session-to-array of sessions model.
The patented method and mechanism are not limited to the analysis of a single device. They assess the probability of relationships between data descriptors originating from different online sessions, contexts, and sets of noise factors. Where the probability of association is high, such sessions can be attributed to the same or highly similar devices; at more moderate levels of association, they can be attributed to a group or cluster of devices or sessions.
It is important to note that both of these areas — device intelligence and digital risk management — have been actively developed at JuicyScore since 2015, and the number of association technologies is likely to increase significantly in the near future. We are also preparing a number of additional solutions in this area for release in future versions of the JuicyScore and JuicyID APIs. Their deployment into the production environment will depend on the evolution of digital risks and the emergence of relevant mitigation scenarios.
To understand the role of the cluster layer, it is useful to look at how anti-fraud systems arrived at this point historically. Early anti-fraud approaches were built around individual signals: IP address, phone number, form parameters, device, and on-page behavior.
This worked well while fraud remained relatively simple and relied on recurring indicators. The first references to graph- and cluster-based approaches in anti-fraud analytics appeared approximately between 1999 and 2004, in research on credit fraud, relationships between transaction participants, and the detection of recurring structures in fraudulent activity. A more established graph-based and fraud-ring context emerged between 2005 and 2010, as the focus shifted from an individual transaction to networks of related transactions, participants, devices, and channels.
Graph- and cluster-based methods became more prominent in online fraud and fintech anti-fraud between 2013 and 2018, driven by the widespread adoption of device-level signals, automation, cross-product attacks, and infrastructure-based fraud. From 2018 onward, graph and cluster analysis has increasingly become a standard layer in mature anti-fraud systems, extending the focus from point-in-time scoring to the analysis of connected infrastructure, activity waves, and relationships across devices.
The approach is implemented as a multi-layered framework. At the first stage, technical and behavioral signals are collected for each session, including device and browser parameters, network characteristics, language, clicks, environmental anomalies, and other session context. The level of noise is assessed separately through markers of automation, remote access, botnet activity, rooted devices, factory resets, suspicious scripts, and other signals.
Probabilistic signals are then used to establish persistent authentication of a device or a related group of devices — not as an absolute determination, but as a controllable level of confidence that sessions are likely to belong to the same device context.
Three association layers in JuicyScore make it possible to analyze activity at different levels of precision and progressively refine identified anomalies.
For example, if repeated devices already identified through JuicyDevID with 99.5–99.9%+ uniqueness are removed from the traffic flow, the remaining traffic can be further analyzed for spikes and suspicious segments using browser_hash and JuicyClusterID, which operates in a session-to-array of sessions format.
The JuicyScore team uses these segments to further refine association models: significant JuicyClusterID clusters help refine JuicyDevID, while segments with a high browser_hash value or high risk scores help refine JuicyClusterID. Previously identified repeated devices and clusters are progressively excluded from the analysis in order to identify new areas of connected activity.
At present, variables based on the generalized cluster-graph approach are available in the production Advanced Parameters section for API16, released in 2024, and API17, released in 2025. They will also be included in all subsequent versions of the JuicyScore API.
According to our estimates, six variables associated with generalized cluster-graph analysis account for 7–25% of the API’s total informativeness. At the same time, a comparable level of informativeness can be achieved through anti-fraud scoring and the ten IDX1–IDX10 indices, which are also a form of scoring. We leave clients free to choose the most appropriate format for using these tools.
To assess automation, randomization, and artificial noise, JuicyScore uses a broad range of technical markers. These include:
These represent only part of the signal set used to assess the technical context and noise level of a session.
At the same time, it is important to maintain the correct hierarchy of signals: the cluster layer complements rather than replaces noise-resilient JuicyDevID and the core anti-fraud scoring layer:
This does not diminish the value of the cluster layer. Rather, it clarifies its role: cluster markers are not intended to replace core anti-fraud scoring, but to provide additional operational context for the “heavy” risk tail of traffic.
In practice, the cluster layer is particularly useful in several specific scenarios:
The cluster layer should be used carefully as risk context rather than as an automatic rejection mechanism. Thresholds should differ across MFIs, banks, insurance companies, gambling services, airlines, and other online businesses.
Dynamics are a key signal: growth in activity over a defined number of days, expansion into new verticals, and synchronized applications across multiple companies. This strengthens scoring, device authentication, and operational decision-making.
The anti-fraud industry is following a clear trajectory: from evaluating individual signals and infrastructure to assessing relationships between signals and sessions. Scoring answers the question of how risky an application or session is. Probabilistic device authentication indicates whether we are dealing with the same device. Cluster-graph analysis further strengthens these first two layers.
None of these layers replaces another. A mature anti-fraud system combines them into a single architecture in which each layer addresses its own class of risks while reinforcing the others. The result is a mature anti-fraud architecture capable of operating effectively both under normal conditions and during complex distributed attacks.

Modern web applications use dynamic interfaces based on the DOM (Document Object Model).

The future of Device ID in the digital world

Despite the hype surrounding LLMs, their application in risk management requires a measured and critical assessment. What are the real use cases, the key limitations, and the reasons why generative models cannot directly replace traditional fraud prevention approaches?
Get a live session with our specialist who will show how your business can detect fraud attempts in real time.
Learn how unique device fingerprints help you link returning users and separate real customers from fraudsters.
Get insights into the main fraud tactics targeting your market — and see how to block them.
Phone:+971 50 371 9151
Email:sales@juicyscore.ai
Our dedicated experts will reach out to you promptly