A web-based collaborative decision support system for mobile payment security risk assessment
The rapid expansion of mobile payment services has exposed third-party platforms to heterogeneous, cross-layer security threats that traditional risk assessment tools capture only partially. Existing approaches fall into two camps: some rest on subjective expert judgment that is never refined against evidence, while others deploy purely data-driven classifiers whose outputs managers cannot interpret. This study proposes a web-based collaborative decision support system (CDSS) for mobile payment security (MPS) risk assessment. It couples a three-cluster indicator system, grounded in a four-layer threat taxonomy, with a hybrid analytical engine that combines fuzzy analytic network process (ANP), entropy weighting, and a back-propagation neural network, while a rule-based and case-based reasoning module translates the composite security risk value (SRV) into actionable strategies through a five-tier color-coded mapping. We implemented the prototype on a B/S architecture using PHP, MySQL, and Apache and validated it against transactional data from a regional Chinese third-party payment platform serving over 90,000 merchants, supplemented by two public benchmark datasets. The framework achieves 94.3% accuracy and 0.962 AUC, outperforming classical AHP, fuzzy comprehensive evaluation, and SVM baselines, with the widest margins on cross-layer contagion and user-behavior risk categories. Response latency stays below 2.5 s under 200 concurrent users, and scoring consistency holds across two orders of magnitude in sample size. A white-box stress test additionally characterises how the pipeline behaves under adversarial input manipulation: risk-grade assignments survive in more than 95% of cases at the mildest gradient budget and degrade gradually thereafter, more slowly than the SVM baseline but without any guarantee against a determined attacker. The evidence therefore supports practical viability inside the operating envelope of a regional payment ecosystem, while the single-site validation and the adversarial exposure reported here mark the limits of that claim.
Authors
- Yanfei Deng (ORCID: https://orcid.org/0000-0001-7924-9447)
- Lei Xu
Institutions
- Xihua University (CN)
- Southwest Minzu University (CN)
Publication Details
- Journal
- Scientific Reports
- Published
- 2026-09-14
- DOI
- https://doi.org/10.1038/s41598-026-71157-2
- Primary Topic
- Access Control and Trust
- Type
- article
- Field-Weighted Citation Impact
- 0.00
Funders
- Southwest Minzu University