arXiv:2606. 12673v1 Announce Type: cross Abstract: Cross-domain graph anomaly detection (GAD) aims to identify abnormal nodes in unseen target graphs, showing strong potential in real-world applications with heterogeneous graph data.
By Phan Nguyen, Dat Cao, Hien Chu, Khue Hoang
arXiv:2602. 20019v2 Announce Type: replace-cross Abstract: Dynamic graph anomaly detection is critical for many real-world applications but remains challenging due to the scarcity of labeled anomalies.
By Yuxing Tian, Yiyan Qi, Fengran Mo, Weixu Zhang, Jian Guo, Jian-Yun Nie
arXiv:2511. 22078v2 Announce Type: replace Abstract: Many real-world scenarios involving streaming information can be represented as temporal graphs, where data flows through dynamic changes in edges over time.
By Simone Mungari, Albert Bifet, Giuseppe Manco, Bernhard Pfahringer
arXiv:2511. 17113v3 Announce Type: replace-cross Abstract: Network Intrusion Detection Systems (NIDS) are essential tools for detecting network attacks and intrusions.
By Georgios Anyfantis, Pere Barlet-Ros
The paper introduces a statistical feature augmentation technique that encodes behavioral interaction statistics into the input space for dynamic graph anomaly detection. Experiments on Reddit, Wikipedia, and MOOC datasets across seven models—both continuous-time and discrete-time—show that this augmentation consistently improves detection performance compared to models trained on original embeddings. The enriched input also facilitates fine-grained post-hoc analysis of behavioral importance, linking classical network analysis with deep learning.
By Philipp Schlinge, Jean-Luc Schnipper, Martin Atzmueller
arXiv:2505. 21285v5 Announce Type: replace Abstract: This work proposes a framework LGKDE that learns kernel density estimation for graphs.
By Xudong Wang, Ziheng Sun, Chris Ding, Jicong Fan
FoundAna is a GNN‑assisted foundation model designed for graph anomaly detection across diverse datasets. It combines a GNN component with a transformer encoder enhanced by four positional encodings to capture both local and global structure, using reconstruction errors as anomaly scores. Experiments on nine benchmark datasets from financial, social, and citation networks show that FoundAna consistently outperforms state‑of‑the‑art baselines.
By Suprim Nakarmi, Chahana Dahal, Yue Zhao, Junggab Son, Zuobin Xiong
arXiv:2609.15483v1 Announce Type: new
Abstract: Unsupervised multivariate time series anomaly detection methods typically identify anomalies through forecasting, reconstruction, or representation dis...
By Zepeng Zhang, Fuad Khuri, Keivan Faghih Niresi, Olga Fink
The paper introduces an unsupervised hypergraph neural network designed to detect anomalous hyperedges—higher-order associations that deviate from typical patterns. Unlike conventional graph methods that capture only pairwise relationships, this approach leverages hypergraphs to model associations among any number of entities. Experiments on real-life datasets show the model effectively identifies unusual hyperedges without requiring labeled data.
By Md. Tanvir Alam, Md. Mahmudur Rahman, Md. Fahim Arefin, Chowdhury Farhan Ahmed, Zisan Mahmud, Md. Sadman Sakib, Carson K. Leung
arXiv:2609.36765v1 Announce Type: new
Abstract: Multivariate time series anomaly detection typically relies on evaluating discrepancies between observations and outputs produced by models trained on...
By Zepeng Zhang, Jhony H. Giraldo, Wenbin Wang, Olga Fink
DDGAD introduces a novel approach to graph anomaly detection that focuses on the disagreement between node-wise and contextual estimates rather than on their combined state. By adapting the Adapt-Then-Combine framework, DDGAD generates separate node-wise and neighborhood-dependent estimates, accumulating their pre-consensus disagreement across iterations to identify anomalies. The method is theoretically grounded with graph-spectral and source-response analyses, and empirical results on six benchmarks demonstrate superior AUROC performance compared to existing techniques.
By Yuxin Yang, Limei Hu, Feng Chen
arXiv:2608. 15965v1 Announce Type: new Abstract: Progress in streaming, edge-level graph anomaly detection (GAD) has been marked by increasingly elaborate architectures, from count-min-sketch chi square tests to memory-augmented attention networks.
By Omair Shafi Ahmed, Zohair Shafi