arXiv:2606. 28970v1 Announce Type: cross Abstract: Unsupervised tabular anomaly detection requires methods that are accurate, robust across heterogeneous datasets, and computationally efficient.
By Quanling Zhao, Jiaying Yang, Ye Tian, Josh Victoria, Zhijun Wang, Pietro Mercati, Onat Gungor, Tajana Rosing
The paper investigates whether the performance of anomaly detection systems can be predicted without labeled anomalies. For kNN-based detectors, it derives a lower bound on AUC that links detection performance to the separation and variance of inlier and outlier scores, and uses this to analyze how density variation, intrinsic dimensionality, and domain mismatch affect score variability. The authors introduce pseudo‑anomaly probes that provide a reference for estimating relative score separation, and demonstrate through experiments on DCASE benchmarks that these probes enable anomaly‑free model selection to outperform conventional development‑set selection, especially under domain shift.
By Kevin Wilkinghoff, Zheng-Hua Tan
GLASS is a graph‑level anomaly detection framework that aligns graph and language representations on a unit hypersphere to achieve cross‑domain transferability. It constructs a Graph Descriptor Prompt to encode local, global, and semantic graph properties, and uses a multi‑slice soft cosine objective to unify graph and text embeddings. Anomaly scoring is performed via spherical density estimation with von Mises‑Fisher kernels, enabling zero‑shot detection and few‑shot adaptation across twelve benchmarks and three meta‑domains, outperforming recent GLAD baselines.
By Xudong Wang, Chris Ding, Tongxin Li, Jicong Fan
arXiv:2602. 03293v2 Announce Type: replace Abstract: Unsupervised anomaly detection stands as an important problem in machine learning.
By Pritam Kar, Rahul Bordoloi, Olaf Wolkenhauer, Saptarshi Bej
arXiv:2512. 22179v3 Announce Type: replace Abstract: Detecting previously unseen attacks remains a major challenge for machine learning-based intrusion detection systems.
By Rajeeb Thapa Chhetri, Saurab Thapa, Avinash Kumar, Zhixiong Chen
The paper proposes a new unsupervised safety detection method for large language models that relies on anomaly detection rather than supervised training on unsafe data. By leveraging local sparsity in a linear representation space obtained via a sparse autoencoder, the authors develop a framework for locally masked SAE-based anomaly detection, providing theoretical support and empirical validation across multiple architectures and datasets. When calibrated with only 1% out-of-distribution data, the method achieves near‑optimal performance while using just 1–2% of SAE neurons for computation.
By Xin Chen, Gil Kur, Alexander Shevchenko, Andreas Krause
arXiv:2606. 13754v1 Announce Type: new Abstract: Anomaly detection is a fundamental component of intelligent systems with applications in healthcare, cybersecurity, smart grids, and IoT environments.
By Ghazal Ghajari, Elaheh Ghajari, Ashutosh Ghimire, Saeid Ataei, Faris Alsulami, Fathi Amsaad
The paper introduces methods for monotonic anomaly detection, focusing on anomalies that exhibit high (or low) attribute values rather than arbitrary deviations. It proposes an asymmetrical distance measure using a ramp function for distance-based methods and a modified path length algorithm for Isolation Forest. Experiments on synthetic and real-life datasets demonstrate improved detection performance on datasets with monotonic attributes.
By Oliver Urs Lenz, Matthijs van Leeuwen
The paper introduces Interpretable Multi-Hypersphere Deep Anomaly Detection (IMHD-AD), a method that builds a separate hypersphere for each known normal class in a shared feature space. By embedding class-specific centers and radii into the final network layer and applying target-inside/non-target-outside constraints, IMHD-AD jointly optimizes these parameters with the shared representation. The model uses the minimum signed boundary score across hyperspheres to decide open-set acceptance or rejection, offering a geometric explanation for each decision, and demonstrates superior AUC performance on MNIST, Fashion-MNIST, and CIFAR-10 compared to existing methods.
By Zhiji Yang, Fangyong Wang, Yue Li, Xianli Pan, Jianhua Zhao
arXiv:2511. 22078v2 Announce Type: replace Abstract: Many real-world scenarios involving streaming information can be represented as temporal graphs, where data flows through dynamic changes in edges over time.
By Simone Mungari, Albert Bifet, Giuseppe Manco, Bernhard Pfahringer
arXiv:2606. 18833v1 Announce Type: new Abstract: This paper introduces a semi-supervised clustering framework grounded in the statistical duality between grouping principles and anomaly detection.
By Nassir Mohammad
The paper proposes a novel unsupervised safety detection method for large language models that relies on local sparsity in a linear representation space recovered via a sparse autoencoder. By masking SAE neurons based on shared active support among nearby points, the authors develop a locally masked anomaly detection framework with theoretical backing. Experiments across multiple architectures and datasets—including capability‑testing and safety‑specific sets—show that using only 1–2% of SAE neurons and a small amount of out‑of‑distribution data yields near‑optimal safety detection performance.