A peer-to-peer marketplace has a fundamental fraud asymmetry that single-sided platforms don't face. In a standard e-commerce transaction, fraud originates from one direction: the buyer. In a P2P marketplace, fraud can originate from either direction, and the fraud type changes depending on which side is acting fraudulently.
A fraudulent buyer may use stolen payment credentials, file false item-not-received disputes, or attempt to extract goods and issue chargebacks. A fraudulent seller may list items they don't have, conduct phantom transactions to inflate feedback scores, or coordinate with a compromised buyer account to generate fraudulent payouts. These are different attack patterns, they require different detection approaches, and a scoring system that only looks at one side of the transaction misses half the risk surface.
The two-sided scoring problem
The core challenge in P2P marketplace fraud detection is that the transaction decision requires evaluating both participants. A transaction between a high-trust buyer and a high-trust seller has a low risk profile. A transaction where either participant scores low for behavioral trust warrants scrutiny, but the appropriate response may differ depending on which side the anomaly originates from.
Traditional fraud systems score the transaction, not the participants. They apply rules to the transaction attributes: payment method, item value, shipping destination, account age. These signals don't distinguish between buyer-side and seller-side risk. A high-value transaction might score elevated risk because the payment method is new, without considering that the seller account has a consistent behavioral history of legitimate high-value listings.
Buyer-side behavioral signals
Buyer fraud in P2P marketplaces typically exhibits specific behavioral patterns that differ from legitimate purchase behavior. A buyer operating with stolen credentials navigates differently: they go directly to high-value item categories, select items without the comparison browsing typical of genuine purchase intent, and often have session warm-up patterns that indicate automation or script-driven selection.
Dispute-fraud buyers behave differently. Their session behavior may be indistinguishable from legitimate buyers at the purchase stage. The signal emerges in their post-purchase behavior patterns and in the network relationship between their account and accounts with prior dispute history. Graph scoring, which looks at shared device identifiers, payment methods, or communication patterns across accounts, can surface these relationships even when the individual session behavior is clean.
Seller-side behavioral signals
Seller fraud often involves listing manipulation: creating fraudulent listings, inflating prices to extract excessive marketplace fees, or generating artificial transaction volume through coordinated buyer accounts. The behavioral signature is in the listing creation sessions: how listings are created, how quickly, the pattern of item selection and pricing, and whether the listing behavior is consistent with a seller who has genuine inventory knowledge.
Phantom inventory fraud, where a seller lists items they do not have, typically shows different session patterns than legitimate sellers. Legitimate sellers building listings spend time on description text, adjust prices against market comps, and show the browsing patterns of someone who knows their inventory. Phantom inventory listings show high velocity, low session engagement per listing, and often share pricing patterns that suggest automated price setting rather than manual entry.
Aggregating at the transaction level
Once both sides have behavioral trust scores, the transaction risk is a function of both. Several combination approaches are useful depending on the platform's fraud exposure.
The simplest is a minimum-score threshold: if either participant's trust score is below a threshold, the transaction receives elevated scrutiny. This catches the case where one side is a known fraud vector even when the other side is high-trust. The limitation is that it can generate false positives on legitimate transactions where one participant is new and has a low trust score due to limited behavioral history rather than suspicious behavior.
A more nuanced approach uses the joint score to distinguish between low-trust-due-to-novelty and low-trust-due-to-anomaly. A new account's trust score should be interpreted differently from an established account's score that has recently dropped due to behavioral changes. The signal combination at the transaction level can weight these differently.
The colluding account detection problem
P2P marketplace fraud rings often involve coordinated buyer and seller accounts that transact with each other to generate artificial reputation. Both accounts in a colluding pair may have individually clean behavioral sessions. The signal is in their transaction relationship: a buyer and seller that transact together significantly more than the platform's baseline account-pairing distribution, particularly when the transactions follow a timing pattern that suggests coordination rather than organic marketplace activity.
Network graph scoring applied to the transaction relationship graph can identify coordinated pairs even when individual account scores are clean. This is a detection layer that operates above the individual session level, looking at the structure of platform interactions rather than the behavior within any single session.