arXiv AI

RagGAD: Rationale-Aware Conditional Gaussian Mixture Normalizing Flow for Unsupervised Graph Anomaly Detection

arXiv:2608. 16018v1 Announce Type: cross Abstract: Graph anomaly detection aims to identify nodes that deviate from normal behavioral patterns within graphs.

arXiv Machine Learning
Sep 22

DDGAD: Disagreement-Driven Graph Anomaly Detection via Adapt-Then-Combine

DDGAD introduces a novel approach to graph anomaly detection that focuses on the disagreement between node-wise and contextual estimates rather than on their combined state. By adapting the Adapt-Then-Combine framework, DDGAD generates separate node-wise and neighborhood-dependent estimates, accumulating their pre-consensus disagreement across iterations to identify anomalies. The method is theoretically grounded with graph-spectral and source-response analyses, and empirical results on six benchmarks demonstrate superior AUROC performance compared to existing techniques.

By Yuxin Yang, Limei Hu, Feng Chen
arXiv AI
Aug 12

ProTAGAD: A Foundation Model for TAG Anomaly Detection with Decoupled Topological and Textual Prototypes

arXiv:2608. 10699v1 Announce Type: cross Abstract: Text-Attributed Graphs (TAGs), endowed with abundant textual content along with topological structures, have emerged as a versatile backbone for real-world anomaly detection spanning large language model security, social network moderation, and cyber threat identification.

By Ziyan Wang, Liwen Wu, Cheng Xie, Song Gao, Zhenli He, Xin Jin
arXiv AI
Sep 3

RINSE: Robust Target-Time Normality Estimation for Zero-Shot Graph Anomaly Detection

RINSE (Robust Iterative Normality Self-Estimation) is a gradient‑free framework for zero‑shot graph anomaly detection that keeps a source‑trained detector fixed while iteratively estimating target normality, calibrating representations, and assessing evidence reliability on unseen target graphs. It identifies a reliable subset of low‑residual target nodes to build a trimmed target‑aware normality model and fuses complementary anomaly evidence through reliability‑gated rank fusion and encoder ensembling. Across eight unseen target graphs, RINSE achieves the highest average AUPRC under two preprocessing protocols, with ablation and sensitivity analyses supporting its combined design.

By Taufikur Rahman Fuad, Md Abrar Jahin, Amir Hussain
arXiv Machine Learning
Sep 22

Clustering-Based Collective Anomaly Detection in IoT Systems: A Graph Neural Network Approach

The paper introduces Unsupervised Graph Collective Anomaly Detection (UGCAD), a framework that uses a variational graph autoencoder to learn graph representations of IoT network traffic and then enhances clustering to group nodes. UGCAD identifies collective anomalies by aggregating normal clusters and applying anomaly scores to the refined groups. Experiments on CICIoT2023 and ToN-IoT datasets show that UGCAD outperforms traditional and state‑of‑the‑art clustering‑based CAD methods in both clustering quality and anomaly detection accuracy.

By Dalila Khettaf, Djamel Djenouri, Zeinab Rezaeifar, Youcef Djenouri