arXiv AI

XAInomaly: Explainable and Interpretable Deep Contractive Autoencoder for O-RAN Traffic Anomaly Detection

arXiv:2502. 09194v1 Announce Type: cross Abstract: Generative Artificial Intelligence (AI) techniques have become integral part in advancing next generation wireless communication systems by enabling sophisticated data modeling and feature extraction for enhanced network performance.

arXiv AI
Jul 3

Generative AI and Federated Learning for Intrusion Detection Systems: A Survey

arXiv:2607. 01305v1 Announce Type: cross Abstract: Intrusion Detection Systems (IDSs) are essential for monitoring network traffic and identifying malicious activities in modern cyber-physical, Internet of Things (IoT), enterprise, and distributed network environments.

By Jiefei Liu, Abu Saleh Md Tayeen, Pratyay Kumar, Qixu Gong, Wenbin Jiang, Huiping Cao, Satyajayant Misra, Jayashree Harikumar
arXiv AI
Sep 25

Deep Positive-Unlabeled Anomaly Detection for Contaminated Unlabeled Data

The paper introduces a deep positive‑unlabeled anomaly detection framework that combines positive‑unlabeled learning with deep models such as autoencoders and deep support vector data descriptions. It addresses the issue of contaminated unlabeled data by approximating anomaly scores for normal data using both unlabeled and labeled anomaly samples, allowing training without labeled normal data. The authors provide a theoretical generalization error bound and demonstrate improved detection performance over existing methods on several datasets.

By Hiroshi Takahashi, Tomoharu Iwata, Atsutoshi Kumagai, Yuuki Yamanaka
arXiv Machine Learning
Sep 4

An Adversarial Zero-Shot Learning Approach for Anomaly Detection in Multivariate IoT Traffic Data

The paper introduces a novel zero‑shot anomaly detection framework for multivariate IoT traffic data that combines adversarial learning and contrastive loss within a sequence‑based Variational Autoencoder. It achieves domain‑invariant latent representations and semantically structured embeddings without labeled data, using encoder/decoder adaptor layers to align feature distributions and a destination‑based segmentation strategy to model real‑world communication patterns. The method is evaluated on six diverse datasets across 44 transfer scenarios, showing strong zero‑shot generalization and competitive performance against a contrastive domain‑adaptation baseline in heterogeneous, privacy‑constrained IoT environments.

By Mahshid Rezakhani, Tolunay Seyfi, Fatemeh Afghah
arXiv Machine Learning
Sep 4

Statistical Feature Augmentation for Anomaly Detection in Dynamic Graphs

The paper introduces a statistical feature augmentation technique that encodes behavioral interaction statistics into the input space for dynamic graph anomaly detection. Experiments on Reddit, Wikipedia, and MOOC datasets across seven models—both continuous-time and discrete-time—show that this augmentation consistently improves detection performance compared to models trained on original embeddings. The enriched input also facilitates fine-grained post-hoc analysis of behavioral importance, linking classical network analysis with deep learning.

By Philipp Schlinge, Jean-Luc Schnipper, Martin Atzmueller
arXiv Machine Learning
Jun 19

We Need to Rethink Benchmarking in Anomaly Detection

arXiv:2507. 15584v2 Announce Type: replace Abstract: Despite the continuous proposal of new anomaly detection algorithms and extensive benchmarking efforts, progress seems to stagnate, with only minor performance differences between established baselines and new algorithms.

By Philipp R\"ochner, Simon Kl\"uttermann, Kevin Kammler, Franz Rothlauf, Emmanuel M\"uller, Daniel Schl\"or
arXiv Machine Learning
Sep 17

A GAN-Based Framework for Robust DDoS Attack Detection

The paper introduces a GAN‑based framework for detecting DDoS attacks that are designed to evade traditional security systems. It combines Random Forests, Deep Neural Ensembles, and Transformer models trained on the CICDDoS2019 dataset with synthetic adversarial traffic generated by a WGAN‑GP. Experiments show that this hybrid training significantly improves detection accuracy and resilience against unseen adversarial traffic, and real‑world tests confirm its practical effectiveness.

By Makram Chehayeb, Walid Fahs, Amina Rizk, Rida Khatoun, Omran Berjawi
arXiv AI
Aug 17

Interactive Analysis of Global Explanations using Aggregated Class Activation Maps for Network Data

arXiv:2608. 13575v1 Announce Type: cross Abstract: Recent machine learning (ML) advances have demonstrated that deep learning (DL) achieves impressive results in different application domains, including the classification of computer network traffic to corresponding applications.

By Igor Cherepanov, David Sessler, Alex Ulmer, Felix Wagner, Throsten May, J\"orn Kohlhammer
arXiv Machine Learning
Jul 31

ARES: Anomaly Recognition Model For Edge Streams

arXiv:2511. 22078v2 Announce Type: replace Abstract: Many real-world scenarios involving streaming information can be represented as temporal graphs, where data flows through dynamic changes in edges over time.

By Simone Mungari, Albert Bifet, Giuseppe Manco, Bernhard Pfahringer