A clustering-based framework for identifying suspicious trading patterns

K-Means++ clustering framework identifies suspicious trading patterns: spoofing, pump and dump, insider trading, and more. Discover it.

miércoles, 8 de julio de 2026 • 2 min read • Q2BSTUDIO Team

Market manipulation detection with K-Means++

Detecting market manipulation is a growing challenge in modern financial environments, where practices such as spoofing, pump and dump, or insider trading undermine investor confidence and the integrity of trading platforms. In this context, unsupervised clustering-based approaches offer a robust alternative when historical fraud labels are unavailable. A recent study proposes a pipeline that uses K-Means++ to cluster approximately one million financial transactions between 2012 and 2024, combining the resulting partitions with heuristic thresholds defined by market experts. The system identifies 2.02% of operations as suspicious, of which 51.10% correspond to spoofing, 0.10% to pump and dump, 0.55% to insider trading, and 1.43% to fake breakouts, leaving 46.83% unclassified explicitly. Although there is no absolute ground truth, the model's validity is supported by a Silhouette Score of 0.561, indicating a reasonable separation between clusters.

This type of solution based on artificial intelligence and machine learning is not limited to the stock market; any organization handling large volumes of transactional data can benefit from similar frameworks to detect anomalies and fraudulent patterns. Companies like Q2BSTUDIO work on developing artificial intelligence systems for businesses that integrate clustering, classification, and outlier detection techniques within custom software platforms. Additionally, combining with AWS and Azure cloud services allows scaling the processing of millions of records in real time, while business intelligence tools like Power BI facilitate the visualization of results for compliance teams.

Beyond the purely technical model, the practical implementation of a fraud detection framework requires considering pipeline cybersecurity, data governance, and integration with legacy systems. The custom applications we develop at Q2BSTUDIO incorporate AI agent modules that automate the review of suspicious alerts, reducing the workload for analysts. On the other hand, cloud infrastructure ensures the necessary elasticity to process activity spikes, and cybersecurity services protect both sensitive data and algorithms against potential adversarial attacks.

The cited academic article demonstrates that even without training labels, it is possible to build effective monitoring tools. However, the true value arises when that knowledge is transferred to production environments through AI for businesses that not only detect but also explain the reasons behind each alert. At Q2BSTUDIO, for example, we combine clustering techniques with expert systems and customized business rules, all orchestrated from a single custom software platform. For those looking to bring this type of analysis to their organization, we recommend exploring how AI agents can be integrated into existing workflows, improving accuracy and reducing false positives.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.