arXiv AI

A Zero-shot Generalized Graph Anomaly Detection Framework via Node Reconstruction

arXiv:2606. 12673v1 Announce Type: cross Abstract: Cross-domain graph anomaly detection (GAD) aims to identify abnormal nodes in unseen target graphs, showing strong potential in real-world applications with heterogeneous graph data.

arXiv Machine Learning
Sep 22

DDGAD: Disagreement-Driven Graph Anomaly Detection via Adapt-Then-Combine

DDGAD introduces a novel approach to graph anomaly detection that focuses on the disagreement between node-wise and contextual estimates rather than on their combined state. By adapting the Adapt-Then-Combine framework, DDGAD generates separate node-wise and neighborhood-dependent estimates, accumulating their pre-consensus disagreement across iterations to identify anomalies. The method is theoretically grounded with graph-spectral and source-response analyses, and empirical results on six benchmarks demonstrate superior AUROC performance compared to existing techniques.

By Yuxin Yang, Limei Hu, Feng Chen
arXiv Machine Learning
Sep 17

FoundAna: A GNN-assisted Foundation Model for Graph Anomaly Detection

FoundAna is a GNN‑assisted foundation model designed for graph anomaly detection across diverse datasets. It combines a GNN component with a transformer encoder enhanced by four positional encodings to capture both local and global structure, using reconstruction errors as anomaly scores. Experiments on nine benchmark datasets from financial, social, and citation networks show that FoundAna consistently outperforms state‑of‑the‑art baselines.

By Suprim Nakarmi, Chahana Dahal, Yue Zhao, Junggab Son, Zuobin Xiong
arXiv AI
Sep 3

RINSE: Robust Target-Time Normality Estimation for Zero-Shot Graph Anomaly Detection

RINSE (Robust Iterative Normality Self-Estimation) is a gradient‑free framework for zero‑shot graph anomaly detection that keeps a source‑trained detector fixed while iteratively estimating target normality, calibrating representations, and assessing evidence reliability on unseen target graphs. It identifies a reliable subset of low‑residual target nodes to build a trimmed target‑aware normality model and fuses complementary anomaly evidence through reliability‑gated rank fusion and encoder ensembling. Across eight unseen target graphs, RINSE achieves the highest average AUPRC under two preprocessing protocols, with ablation and sensitivity analyses supporting its combined design.

By Taufikur Rahman Fuad, Md Abrar Jahin, Amir Hussain
arXiv AI
Aug 28

Feature Transformation Enhanced Jacobi Polynomial Graph Filtering for Graph Anomaly Detection

The paper introduces JPGFN, a graph anomaly detection method that enhances frequency-domain filtering with a Feature Separation Transformation Network to capture fine-grained node features, an adaptive Jacobi polynomial graph filtering module to better model complex frequency-domain characteristics, and a node label constraint module to leverage label information. These components address limitations of static filters, attribute importance neglect, and insufficient label use found in existing approaches. Experiments on real-world datasets show that JPGFN outperforms mainstream methods.

By Xiang Wang, Zhijun Cheng, Zhenyu Meng
arXiv Machine Learning
Sep 22

Clustering-Based Collective Anomaly Detection in IoT Systems: A Graph Neural Network Approach

The paper introduces Unsupervised Graph Collective Anomaly Detection (UGCAD), a framework that uses a variational graph autoencoder to learn graph representations of IoT network traffic and then enhances clustering to group nodes. UGCAD identifies collective anomalies by aggregating normal clusters and applying anomaly scores to the refined groups. Experiments on CICIoT2023 and ToN-IoT datasets show that UGCAD outperforms traditional and state‑of‑the‑art clustering‑based CAD methods in both clustering quality and anomaly detection accuracy.

By Dalila Khettaf, Djamel Djenouri, Zeinab Rezaeifar, Youcef Djenouri
arXiv Machine Learning
Jul 31

ARES: Anomaly Recognition Model For Edge Streams

arXiv:2511. 22078v2 Announce Type: replace Abstract: Many real-world scenarios involving streaming information can be represented as temporal graphs, where data flows through dynamic changes in edges over time.

By Simone Mungari, Albert Bifet, Giuseppe Manco, Bernhard Pfahringer
arXiv Machine Learning
Sep 7

GLASS: Graph-Language Alignment with Spherical Scoring for Transferable Graph-Level Anomaly Detection

GLASS is a graph‑level anomaly detection framework that aligns graph and language representations on a unit hypersphere to achieve cross‑domain transferability. It constructs a Graph Descriptor Prompt to encode local, global, and semantic graph properties, and uses a multi‑slice soft cosine objective to unify graph and text embeddings. Anomaly scoring is performed via spherical density estimation with von Mises‑Fisher kernels, enabling zero‑shot detection and few‑shot adaptation across twelve benchmarks and three meta‑domains, outperforming recent GLAD baselines.

By Xudong Wang, Chris Ding, Tongxin Li, Jicong Fan