The paper introduces Unsupervised Graph Collective Anomaly Detection (UGCAD), a framework that uses a variational graph autoencoder to learn graph representations of IoT network traffic and then enhances clustering to group nodes. UGCAD identifies collective anomalies by aggregating normal clusters and applying anomaly scores to the refined groups. Experiments on CICIoT2023 and ToN-IoT datasets show that UGCAD outperforms traditional and state‑of‑the‑art clustering‑based CAD methods in both clustering quality and anomaly detection accuracy.
By Dalila Khettaf, Djamel Djenouri, Zeinab Rezaeifar, Youcef Djenouri
arXiv:2510. 26307v3 Announce Type: replace-cross Abstract: Anomaly detection is a critical task in cybersecurity, where identifying insider threats, access violations, and coordinated attacks is essential for ensuring system resilience.
By Laura Jiang, Reza Ryan, Qian Li, Nasim Ferdosian
arXiv:2511. 17113v3 Announce Type: replace-cross Abstract: Network Intrusion Detection Systems (NIDS) are essential tools for detecting network attacks and intrusions.
By Georgios Anyfantis, Pere Barlet-Ros
FoundAna is a GNN‑assisted foundation model designed for graph anomaly detection across diverse datasets. It combines a GNN component with a transformer encoder enhanced by four positional encodings to capture both local and global structure, using reconstruction errors as anomaly scores. Experiments on nine benchmark datasets from financial, social, and citation networks show that FoundAna consistently outperforms state‑of‑the‑art baselines.
By Suprim Nakarmi, Chahana Dahal, Yue Zhao, Junggab Son, Zuobin Xiong
The paper introduces a statistical feature augmentation technique that encodes behavioral interaction statistics into the input space for dynamic graph anomaly detection. Experiments on Reddit, Wikipedia, and MOOC datasets across seven models—both continuous-time and discrete-time—show that this augmentation consistently improves detection performance compared to models trained on original embeddings. The enriched input also facilitates fine-grained post-hoc analysis of behavioral importance, linking classical network analysis with deep learning.
By Philipp Schlinge, Jean-Luc Schnipper, Martin Atzmueller
arXiv:2602. 20019v2 Announce Type: replace-cross Abstract: Dynamic graph anomaly detection is critical for many real-world applications but remains challenging due to the scarcity of labeled anomalies.
By Yuxing Tian, Yiyan Qi, Fengran Mo, Weixu Zhang, Jian Guo, Jian-Yun Nie
arXiv:2606. 17109v1 Announce Type: cross Abstract: Given their effectiveness in modeling the relational structure among network traffic flows, graph neural networks (GNNs) have been widely adopted in network intrusion detection systems (NIDSs).
By Jianli Dai, Guangwei Wu, Jiacheng Li, Weiping Wang, An He, Xinjun Xiao
arXiv:2507. 15584v2 Announce Type: replace Abstract: Despite the continuous proposal of new anomaly detection algorithms and extensive benchmarking efforts, progress seems to stagnate, with only minor performance differences between established baselines and new algorithms.
By Philipp R\"ochner, Simon Kl\"uttermann, Kevin Kammler, Franz Rothlauf, Emmanuel M\"uller, Daniel Schl\"or
arXiv:2602.06859v3 Announce Type: replace-cross
Abstract: Graph Anomaly Detection (GAD) aims to identify irregular patterns in graph data, and recent works have explored zero-shot generalist GAD to e...
By Xinyu Zhao, Qingyun Sun, Jiayi Luo, Xingcheng Fu, Jianxin Li
arXiv:2606. 12673v1 Announce Type: cross Abstract: Cross-domain graph anomaly detection (GAD) aims to identify abnormal nodes in unseen target graphs, showing strong potential in real-world applications with heterogeneous graph data.
By Phan Nguyen, Dat Cao, Hien Chu, Khue Hoang
arXiv:2606. 00304v1 Announce Type: new Abstract: Graph anomaly detection methods aim to distinguish anomalous nodes.
By Yilin Liu, Hongchao Zhang, Taylor T. Johnson, Ahmad F. Taha, Meiyi Ma
arXiv:2608. 15965v1 Announce Type: new Abstract: Progress in streaming, edge-level graph anomaly detection (GAD) has been marked by increasingly elaborate architectures, from count-min-sketch chi square tests to memory-augmented attention networks.
By Omair Shafi Ahmed, Zohair Shafi