Aug 2026· Discover Computing· Vol 29· 0 citations· 23 references
TL;DR
The results indicate that entropy-based subgraph embedding can improve local anomaly detection performance, although the model does not achieve the best value for every metric on every dataset.
Abstract
This study addresses the crucial challenge of local anomaly detection in multivariate data streams, which is essential for applications such as fault detection and damage localization in industrial contexts. Traditional approaches often neglect two critical aspects: the significance of relational features in assessing similarity and the necessity of pinpointing specific data streams that exhibit abnormal patterns. To address these gaps, we introduce a novel subgraph embedding-based method. Our approach constructs dynamic graphs to model relational features and identifies anomalies by detecting subgraphs within these graphs. The core innovation lies in an entropy-based transformer integrated with an autoencoder, which maps subgraphs into a low-dimensional space to effectively discriminate abnormal subgraphs. Experiments on EEG and industrial datasets show that the proposed model achieves average F1-score improvements of 0.07 and 0.105 over the compared baselines, respectively. The results indicate that entropy-based subgraph embedding can improve local anomaly detection performance, although the model does not achieve the best value for every metric on every dataset.
LTRGAD is proposed, a two-stage GAD framework that performs feature selection based on local feature-topological residuals (LTR) and effectively introduces topological information while preserving the original local anomalous patterns, enabling more accurate local anomaly detection.
Yazheng Zhao, Nannan Wu, Hao Yin et al.· 0 citations
BAD is proposed, an unsupervised framework for anomaly detection in continuous-time dynamic graphs that represents nodes with learnable identity embeddings and performs pairwise compatibility modeling via cross-attention between each destination node and the source’s recent neighbors, enabling direct characterization of context-dependent deviations without requiring attributes.
Jia-Chi Luo, Sha-Meng Wen, Ziyan Qiu et al.· 0 citations
Dynamic networks are being applied in many domains, from social media to logistics systems, each with their own set of special characteristics. A model employed on this type of data must capture the duality between temporal/structural and feature-based information. Yet state-of-the-art deep learning models often struggle to learn especially short-term behavioral interaction signals, such as sender intensity or interaction inertia, directly from raw event streams. To address this gap, we propose a statistical feature augmentation method that explicitly encodes behavioral interaction statistics into the input feature space. We evaluate our proposed method on an anomaly detection task across three real-world datasets (Reddit, Wikipedia, MOOC) and seven models spanning both continuous-time and discrete-time architectures. As a baseline, we apply the same models trained on the original embeddings. Our results show, that augmentation consistently improves detection performance. Beyond performance, the enriched input enables fine-grained post-hoc analysis of behavioral importance, since each statistic occupies a dedicated input dimension. In particular, this work showcases a promising approach for merging classical network analysis with deep learning.
Philipp Schlinge, Jean-Luc Schnipper, Martin Atzmueller· 0 citations
Graph anomaly detection plays a critical role in identifying irregular patterns in complex networked data arising in domains such as social networks, e-commerce systems, and cybersecurity. Existing approaches, particularly affinity-based methods, have demonstrated promising performance by leveraging local neighbourhood consistency. However, they often rely on a single anomaly indicator and lack an explicit mechanism to model normal behaviour, limiting their ability to detect subtle, heterogeneous anomalies. To address these challenges, this paper proposes a novel framework, prototype-regularised residual affinity maximisation (PRA-TAM), for unsupervised graph anomaly detection. The proposed method extends affinity-based learning by introducing a prototype-guided normality modelling mechanism that captures dominant patterns of normal nodes in the latent space using a compact set of learnable prototypes. In addition, a residual inconsistency calibration strategy is developed to quantify deviations across the feature, embedding, and neighbourhood spaces, enabling a more comprehensive assessment of node abnormality. To further enhance robustness, a lightweight multi-view learning strategy based on fixed graph truncation is employed to capture structural variations without introducing additional computational complexity. Extensive experiments across multiple benchmark datasets, including Facebook, ACM, Amazon, and YelpChi, demonstrate that the proposed method achieves competitive AUROC and AUPRC performance while demonstrating robust performance across multiple benchmark datasets and remains competitive on YelpChi. The results highlight the effectiveness of integrating affinity learning with prototype modelling and residual-based scoring for improved anomaly detection performance. The proposed framework is computationally efficient, scalable, and well-suited to real-world graph anomaly detection applications characterised by complex, heterogeneous data distributions.
Wasim Khan, Sujit R. Wakchaure, G. R. Bombale et al.· International Journal of Dat...· 0 citations
A novel framework, Generate and Filter graph learning for Graph Anomaly Detection (GFGAD), which generates a diverse set of synthetic anomalies with enriched feature and structural information to balance the data distribution and significantly outperforms state-of-the-art baselines.
Mengyu Li, Yonghao Liu, Ximing Li et al.· IEEE Transactions on Pattern...· 0 citations
Anomaly detection in complex time-series data is a fundamental task in fields such as financial monitoring, industrial systems, and intelligent forecasting. Existing methods often suffer from limited adaptability when simultaneously handling local transient anomalies and global structural anomalies, especially under varying contamination levels and heterogeneous data distributions. To address this issue, this paper proposes a local-global collaborative anomaly detection framework named EWC-LOFAD, which combines local kernel regression residual analysis with adaptive density clustering. A local linear regression model with generalized cross-validation (GCV) bandwidth selection is used to capture short-term fluctuations, while an adaptive DBSCAN mechanism detects global structural outliers. An entropy-weighted fusion strategy is further introduced to dynamically balance local and global anomaly information. Experimental results on synthetic datasets with varying anomaly rates demonstrate that EWC-LOFAD competitively outperforms several benchmark methods including Isolation Forest, Local Outlier Factor, and DBSCAN, achieving up to 40.3% improvement in F1-score under low contamination settings and achieving a high precision of 0.9837 at a 10% contamination level. Applied to exchange rate data, EWC-LOFAD not only identifies anomalies detected by LOF, Isolation Forest, One-Class SVM and DBSCAN, but also reveals hidden anomalies associated with major financial events. Further validation via synthetic anomaly injection on real datasets demonstrates that EWC-LOFAD achieves superior precision, recall and F1-score, verifying its reliability, robustness and practical applicability in complex real-world time series analysis.
Rui Liu, Ziqi Zhou, Shiqi Zhou et al.· Engineering Research Express· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.