Every marketplace listing carries three synthetic features a real brand-protection crawler would extract: image/logo similarity to the authentic asset s ∈ [0,1], price deviation from MSRP p ∈ [−1,1] (negative = suspiciously cheap), and seller-trust score t ∈ [0,1] (account age, ratings, verification).
risk = σ( 2.6·(1 − s) + w·2.2·max(0, −p) + 1.6·(1 − t) − 2.4 )
flag listing ⇔ risk ≥ threshold
The left panel plots every listing on a trust (x) vs. risk-score (y) plane — a decision-space view rather than the raw 3D feature cube. The dashed line is the current threshold: cross it and a listing drifts into the quarantine bin. The right panel sweeps that same threshold from 0 to 1 across every listing the crawler has actually scanned so far and traces the resulting ROC curve (true-positive rate vs. false-positive rate), with the current operating point marked and its area (AUC) reported live — the standard way a real detection team grades a classifier independently of any one threshold choice.
- Risk threshold — raising it trades recall for precision; the operating-point dot on the ROC curve slides down-left as you raise it.
- Price-anomaly weight (w) — how much a suspiciously low price counts toward risk, independent of imagery.
- ROC AUC — the probability a randomly drawn true counterfeit outranks a randomly drawn genuine listing by risk score; 0.5 is a coin flip, 1.0 is a perfect ranking.
Real-world relevance: this mirrors OSINT brand-monitoring pipelines — automated crawlers score marketplace and social-media listings, and only ones crossing a risk threshold are escalated for a human-reviewed takedown request; ROC/AUC is exactly how such a detector's threshold is chosen and reported.