Skip to content

Unsupervised Anomaly Detection in Dynamic Graphs via Compatibility Modeling and Boundary Learning

· 0 citations · 42 references

TL;DR

BAD is proposed, an unsupervised framework for anomaly detection in continuous-time dynamic graphs that represents nodes with learnable identity embeddings and performs pairwise compatibility modeling via cross-attention between each destination node and the source’s recent neighbors, enabling direct characterization of context-dependent deviations without requiring attributes.

View source

Similar papers

Book Open access Jul 2026

Retrieval-Augmented Contrastive Learning for Dynamic Graph Anomaly Detection

DGRA-CL transforms dynamic graphs into temporal sequences, employs time- and context-aware contrastive learning to learn normal node behavior patterns, retrieves similar normal exemplars from a training pool under a strict causality constraint, and fuses them via similarity-weighted aggregation to construct baseline representations.

Kamal Berahmand, S. Forouzandeh, Mehrnoush Mohammadi et al. · 2 citations
Open access Aug 2026

PRA-TAM: prototype-regularised residual affinity maximisation for unsupervised graph anomaly detection

Graph anomaly detection plays a critical role in identifying irregular patterns in complex networked data arising in domains such as social networks, e-commerce systems, and cybersecurity. Existing approaches, particularly affinity-based methods, have demonstrated promising performance by leveraging local neighbourhood consistency. However, they often rely on a single anomaly indicator and lack an explicit mechanism to model normal behaviour, limiting their ability to detect subtle, heterogeneous anomalies. To address these challenges, this paper proposes a novel framework, prototype-regularised residual affinity maximisation (PRA-TAM), for unsupervised graph anomaly detection. The proposed method extends affinity-based learning by introducing a prototype-guided normality modelling mechanism that captures dominant patterns of normal nodes in the latent space using a compact set of learnable prototypes. In addition, a residual inconsistency calibration strategy is developed to quantify deviations across the feature, embedding, and neighbourhood spaces, enabling a more comprehensive assessment of node abnormality. To further enhance robustness, a lightweight multi-view learning strategy based on fixed graph truncation is employed to capture structural variations without introducing additional computational complexity. Extensive experiments across multiple benchmark datasets, including Facebook, ACM, Amazon, and YelpChi, demonstrate that the proposed method achieves competitive AUROC and AUPRC performance while demonstrating robust performance across multiple benchmark datasets and remains competitive on YelpChi. The results highlight the effectiveness of integrating affinity learning with prototype modelling and residual-based scoring for improved anomaly detection performance. The proposed framework is computationally efficient, scalable, and well-suited to real-world graph anomaly detection applications characterised by complex, heterogeneous data distributions.

Wasim Khan, Sujit R. Wakchaure, G. R. Bombale et al. · 0 citations
Open access 2026

Beyond Simple Aggregation: Decoupling Frequency-Aware Representation Learning and Gradient Boosting for Graph Anomaly Detection

In knowledge-intensive systems such as cybersecurity and financial risk control, graph data encode business rules, interaction constraints, and risk propagation paths through entities and relations. As a result, supervised graph anomaly detection (GAD) goes beyond conventional attribute outlier identification and becomes a problem of discovering anomalous structural behavior patterns. Under such conditions, the area under the precision–recall curve (AUPRC) better reflects practical risk-control objectives. From a mechanistic perspective, fixed neighborhood aggregation in end-to-end graph neural networks (GNNs) exhibits a low-pass bias in graph signal processing terms. At the same time, joint training tightly couples structural representation learning with a shallow classifier head of limited capacity, making high-curvature nonlinear decision boundaries difficult to learn under extreme imbalance and creating a capacity mismatch. However, upstream feature construction remains constrained by fixed low-pass operators, which creates spectral conflict because a strong classifier receives weak features. More importantly, structural camouflage is often common, whereas feature spectra may shift either left or right, leading to structural-spectral decoupling and spectral divergence. To address spectral conflict and capacity mismatch, we propose TAFH (Task-Aware Frequency Hybrid) for graph anomaly detection. TAFH explicitly decomposes multi-hop neighborhood propagation into low-frequency smooth components and high-frequency residual components, and then constructs an adaptive band-pass response through learnable hop weighting and node-level gated routing. To reduce objective drift under class imbalance, TAFH introduces a lightweight proxy head with a proxy objective, including a focal-loss variant, to inject hard-sample and minority-class preferences into representation learning. On the discrimination side, gradient boosted decision trees (XGBoost) provide high-capacity nonlinear interaction modeling through a decoupled boosting interface. Across five benchmark datasets (Reddit, YelpChi, Amazon, Tolokers, and Questions), TAFH consistently improves AUPRC over the strong baseline built from XGBoost and fixed neighborhood aggregation, with absolute gains from +1.12% to +6.35% and relative gains from 1.88% to 19.75%. These results show that supervised GAD can be cast as a coordinated process of structural knowledge encoding, adaptive frequency enhancement, and discriminative knowledge learning.

Yanhong Hu, Tingli Yan · 0 citations
Open access Aug 2026

Local anomaly detection via subgraph embedding on multivariate data streams

The results indicate that entropy-based subgraph embedding can improve local anomaly detection performance, although the model does not achieve the best value for every metric on every dataset.

Gen Li, Jason J. Jung · 0 citations
#machine learning Preprint Sep 2026

Statistical Feature Augmentation for Anomaly Detection in Dynamic Graphs

Dynamic networks are being applied in many domains, from social media to logistics systems, each with their own set of special characteristics. A model employed on this type of data must capture the duality between temporal/structural and feature-based information. Yet state-of-the-art deep learning models often struggle to learn especially short-term behavioral interaction signals, such as sender intensity or interaction inertia, directly from raw event streams. To address this gap, we propose a statistical feature augmentation method that explicitly encodes behavioral interaction statistics into the input feature space. We evaluate our proposed method on an anomaly detection task across three real-world datasets (Reddit, Wikipedia, MOOC) and seven models spanning both continuous-time and discrete-time architectures. As a baseline, we apply the same models trained on the original embeddings. Our results show, that augmentation consistently improves detection performance. Beyond performance, the enriched input enables fine-grained post-hoc analysis of behavioral importance, since each statistic occupies a dedicated input dimension. In particular, this work showcases a promising approach for merging classical network analysis with deep learning.

Philipp Schlinge, Jean-Luc Schnipper, Martin Atzmueller · 0 citations

Graph Anomaly Detection via Feature Selection with Local Topological Residuals

LTRGAD is proposed, a two-stage GAD framework that performs feature selection based on local feature-topological residuals (LTR) and effectively introduces topological information while preserving the original local anomalous patterns, enabling more accurate local anomaly detection.

Yazheng Zhao, Nannan Wu, Hao Yin et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.