Skip to content

FoundAna: A GNN-assisted Foundation Model for Graph Anomaly Detection

Sep 2026 · 0 citations · 42 references
Computer Science

TL;DR

FindAna is introduced, a GNN-assisted Foundation Model for Graph Anomaly Detection - the first foundation model framework designated for generalizable, cross-graph anomaly detection by combining GNNs and transformers.

Abstract

Graph anomaly detection aims to identify graph structures (e.g., nodes, edges, or subgraphs) that deviate significantly from expected patterns, which supports critical applications in fraud detection, spam identification, network intrusion, etc. Despite the growing methods in the field, existing approaches follow a one-model-per-dataset paradigm, limiting their transferability across diverse real-world scenarios due to task heterogeneity, label scarcity, and domain variability. In this work, we introduce FoundAna, a GNN-assisted Foundation Model for Graph Anomaly Detection - the first foundation model framework designated for generalizable, cross-graph anomaly detection by combining GNNs and transformers. FoundAna integrates an anomaly detection-specific GNN component with a standard transformer encoder augmented by four complementary positional encodings, which enable the model to capture both local and global structural information. Specifically, the positional encoding enriched node representations are passed through attribute and adjacency decoders, and the reconstruction errors serve as the anomaly score. Extensive experiments on nine benchmark datasets spanning financial, social, and citation network domains demonstrate that FoundAna consistently outperforms state-of-the-art baselines. The code implementation and Supplementary materials are here: https://github.com/FoundAna331/FoundAna.

View source

Similar papers

Open access Aug 2026

Generate and Filter: A GNN-Based Approach for Graph Anomaly Detection.

A novel framework, Generate and Filter graph learning for Graph Anomaly Detection (GFGAD), which generates a diverse set of synthetic anomalies with enriched feature and structural information to balance the data distribution and significantly outperforms state-of-the-art baselines.

Mengyu Li, Yonghao Liu, Xi-Ming Li et al. · 0 citations
Preprint Aug 2026

ProTAGAD: A Foundation Model for TAG Anomaly Detection with Decoupled Topological and Textual Prototypes

This work introduces a novel foundation model for TAG anomaly detection featuring decoupled topological and textual prototypes and constructs dual prototype banks to independently model structural normality and semantic consistency, effectively isolating anomaly cues that are otherwise diluted during coupled aggregatio...

Ziyang Wang, Liwen Wu, Cheng Xie et al. · 0 citations
Open access 2026

DMGCRL: Dynamic Multi-Scale Graph Contrastive Representation Learning for Network Intrusion Detection

Dynamic Multiscale Graph Contrastive Representation Learning (DMGCRL), a self-supervised framework that hierarchically models network intrusions at different levels, is proposed, which consistently outperforms SOTA methods in network intrusion detection.

Raeed Al-Sabri, Abdullatif Albaseer, Mohamed M. Abdallah et al. · 0 citations
Sep 2026

Dual-Encoder Graph Anomaly Detection via Structural–Attribute Consistency Learning

Static graph anomaly detection is important in applications such as cybersecurity, fraud detection, and social network analysis. However, detecting anomalies in attributed graphs remains challenging because of complex graph structures and limited labeled data. Existing methods often focus on either structural informati...

Hessa O. Alharbi, Hedia Zardi · 0 citations
Conference Open access Sep 2026

Graph Anomaly Detection via Feature Selection with Local Topological Residuals

LTRGAD is proposed, a two-stage GAD framework that performs feature selection based on local feature-topological residuals (LTR) and effectively introduces topological information while preserving the original local anomalous patterns, enabling more accurate local anomaly detection.

Ya-Zheng Zhao, Nan-Nan Wu, Hao Yin et al. · 0 citations
Open access Sep 2026

Isolating Graph Topology from Model Architecture in GNN-Based Fraud Detection: An Empirical Framework

Graph topology and model architecture are routinely co-designed in GNN-based fraud detection, making it impossible to attribute performance gains to either component. We address this by fixing the training loop, features, and evaluation protocol while independently varying the graph construction strategy and GNN archit...

Roya Amiri, Sardar F. Jaf · 0 citations

Related blog posts

Microsoft Research Blog Sep 30, 2026

Forecasting space weather risks on power grids

Extreme space-weather events can damage power systems on Earth and degrade GPS accuracy and satellite operations. A new machine learning system can predict where damage is likely to occur 30-60 minutes before a storm arrives. The post Forecasting space weather risks on power grids appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.