Aug 2026· Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2· pp. 1862-1873· 0 citations· 23 references
Abstract
Recently, semi-supervised graph anomaly detection (GAD) has garnered increasing attention under a challenging setting where only a limited number of normal nodes are labeled during training. To better exploit the limited normal supervision and compensate for the absence of real anomaly labels, existing methods often adopt a single, uniform anomaly modeling and pseudo-anomaly generation strategy applied across the entire graph, while overlooking the inherent heterogeneity among communities in graph data. Consequently, the generated pseudo-anomalies exhibit limited diversity and specificity, failing to represent the complex distributions of real-world anomalies. To address this challenge, we propose CR-Aug, a novel Community Risk-Guided Adaptive Augmentation framework, which is designed to overcome this limitation by leveraging community-specific prior knowledge more effectively. It comprises two core components: Community Risk Profiling (CRP) and Risk-Guided Synthesis (RGS). Specifically, CRP quantifies community-level risks by measuring the affinity discrepancy between the labeled normal subset and the overall community. Guided by the derived risk scores, RGS then dynamically adapts the generation process through risk-weighted sampling and adaptive mixing. This strategy facilitates the synthesis of diverse pseudo-anomalies, thereby providing the classifier with more discriminative supervisory signals. Extensive experiments on multiple benchmark datasets demonstrate that CR-Aug significantly outperforms state-of-the-art semi-supervised GAD methods, validating the effectiveness of incorporating community-level risk profiles.
A novel framework, Generate and Filter graph learning for Graph Anomaly Detection (GFGAD), which generates a diverse set of synthetic anomalies with enriched feature and structural information to balance the data distribution and significantly outperforms state-of-the-art baselines.
Mengyu Li, Yonghao Liu, Ximing Li et al.· IEEE Transactions on Pattern...· 0 citations
Graph anomaly detection plays a critical role in identifying irregular patterns in complex networked data arising in domains such as social networks, e-commerce systems, and cybersecurity. Existing approaches, particularly affinity-based methods, have demonstrated promising performance by leveraging local neighbourhood consistency. However, they often rely on a single anomaly indicator and lack an explicit mechanism to model normal behaviour, limiting their ability to detect subtle, heterogeneous anomalies. To address these challenges, this paper proposes a novel framework, prototype-regularised residual affinity maximisation (PRA-TAM), for unsupervised graph anomaly detection. The proposed method extends affinity-based learning by introducing a prototype-guided normality modelling mechanism that captures dominant patterns of normal nodes in the latent space using a compact set of learnable prototypes. In addition, a residual inconsistency calibration strategy is developed to quantify deviations across the feature, embedding, and neighbourhood spaces, enabling a more comprehensive assessment of node abnormality. To further enhance robustness, a lightweight multi-view learning strategy based on fixed graph truncation is employed to capture structural variations without introducing additional computational complexity. Extensive experiments across multiple benchmark datasets, including Facebook, ACM, Amazon, and YelpChi, demonstrate that the proposed method achieves competitive AUROC and AUPRC performance while demonstrating robust performance across multiple benchmark datasets and remains competitive on YelpChi. The results highlight the effectiveness of integrating affinity learning with prototype modelling and residual-based scoring for improved anomaly detection performance. The proposed framework is computationally efficient, scalable, and well-suited to real-world graph anomaly detection applications characterised by complex, heterogeneous data distributions.
Wasim Khan, Sujit R. Wakchaure, G. R. Bombale et al.· International Journal of Dat...· 0 citations
GDAE is proposed, a multi-task self-supervised one-class anomaly detection framework for network traffic graphs, with strong stability and efficiency, offering a new pathway for lightweight, robust self-supervised one-class intrusion detection.
Ji Zhao, Damin Zhang, Tian-Yi Wang et al.· Journal of King Saud Univers...· 0 citations
DGRA-CL transforms dynamic graphs into temporal sequences, employs time- and context-aware contrastive learning to learn normal node behavior patterns, retrieves similar normal exemplars from a training pool under a strict causality constraint, and fuses them via similarity-weighted aggregation to construct baseline representations.
Kamal Berahmand, S. Forouzandeh, Mehrnoush Mohammadi et al.· Annual International ACM SIG...· 2 citations
A novel transferable graph prompt attack, called TGPA, is proposed, which shifts the attack paradigm by introducing a hierarchical structural decoupling mechanism, which reduces the performance of pre-trained graph models with graph prompts by up to 28.9%, while guaranteeing robustness, stealthiness, and transferability.
Ju Jia, Haonan Wang, Tian Wu et al.· Neural Networks· 0 citations
BAD is proposed, an unsupervised framework for anomaly detection in continuous-time dynamic graphs that represents nodes with learnable identity embeddings and performs pairwise compatibility modeling via cross-attention between each destination node and the source’s recent neighbors, enabling direct characterization of context-dependent deviations without requiring attributes.
Jia-Chi Luo, Sha-Meng Wen, Ziyan Qiu et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.