arXiv Machine Learning

Hybrid Latent-Structural Fusion (HLSF) for Cyber Anomaly Detection

arXiv:2607. 18479v1 Announce Type: new Abstract: Malicious anomalous activity detection is a fundamental challenge for cyber security systems.

arXiv AI
Jun 12

ASTER: Latent Pseudo-Anomaly Generation for Unsupervised Time-Series Anomaly Detection

arXiv:2604. 13924v3 Announce Type: replace-cross Abstract: Time-series anomaly detection (TSAD) is critical in domains such as industrial monitoring, healthcare, and cybersecurity, but it remains challenging due to rare and heterogeneous anomalies and the scarcity of labelled data.

By Romain Hermary, Samet Hicsonmez, Dan Pineau, Abd El Rahman Shabayek, Djamila Aouada
arXiv Machine Learning
Aug 27

Multi-Modal Anomaly Detection: A Survey

The paper surveys Multi‑Modal Anomaly Detection (MMAD), a field that identifies rare abnormal events across heterogeneous data sources used in safety‑critical domains like industrial inspection and cybersecurity. It formalizes MMAD, outlines five core characteristics, and categorizes existing methods into normality‑assumption and anomaly‑assumption paradigms, highlighting how foundation models are reshaping the field. The survey also compiles benchmarks, evaluation protocols, and identifies open problems for developing robust, adaptive, and interpretable MMAD systems.

By Xudong Mou, Zexin Wu, Chuan Luo, Shiru Chen, Xudong Liu, Chunming Hu, Renyu Yang
arXiv Machine Learning
Aug 20

Online Conformal Anomaly Detection with Prediction-Powered Data Acquisition

Online Conformal Anomaly Detection with Prediction-Powered Data Acquisition introduces C-PP-COAD, a framework that uses synthetic calibration data to reduce reliance on real-world calibration while maintaining assumption-free false discovery rate control. The method wraps any anomaly detection algorithm, converting its scores into conformal p-values for online testing. Experiments on synthetic and real datasets—including thyroid dysfunction, O‑RAN conflict, 5G intrusion, and UE throughput degradation—show that C-PP-COAD preserves FDR guarantees while significantly cutting the need for real calibration data.

By Amirmohammad Farzaneh, Osvaldo Simeone
arXiv Machine Learning
Jul 31

ARES: Anomaly Recognition Model For Edge Streams

arXiv:2511. 22078v2 Announce Type: replace Abstract: Many real-world scenarios involving streaming information can be represented as temporal graphs, where data flows through dynamic changes in edges over time.

By Simone Mungari, Albert Bifet, Giuseppe Manco, Bernhard Pfahringer
arXiv Machine Learning
Sep 24

CAST: Context- and Anomaly Structure-Conditioned Time Series Anomaly Generation

CAST is a framework for generating anomalous time series that addresses the scarcity and heterogeneity of anomaly data. It uses a two‑stage approach: pretraining on abundant normal data to learn system dynamics, then finetuning with anomaly structure representations to capture diverse anomaly morphologies. Experiments on real‑world datasets show that CAST outperforms existing methods in both generation quality and downstream task performance.

By Haochen Zhang, Jie Peng, Songyuan Sui, Yu-Chao Huang, Xiangqi Zhu, Tianlong Chen
arXiv Machine Learning
Sep 22

Clustering-Based Collective Anomaly Detection in IoT Systems: A Graph Neural Network Approach

The paper introduces Unsupervised Graph Collective Anomaly Detection (UGCAD), a framework that uses a variational graph autoencoder to learn graph representations of IoT network traffic and then enhances clustering to group nodes. UGCAD identifies collective anomalies by aggregating normal clusters and applying anomaly scores to the refined groups. Experiments on CICIoT2023 and ToN-IoT datasets show that UGCAD outperforms traditional and state‑of‑the‑art clustering‑based CAD methods in both clustering quality and anomaly detection accuracy.

By Dalila Khettaf, Djamel Djenouri, Zeinab Rezaeifar, Youcef Djenouri
arXiv Machine Learning
Sep 23

Can We Predict Anomaly Detection Performance from Embedding-Space Geometry?

The paper investigates whether the performance of anomaly detection systems can be predicted without labeled anomalies. For kNN-based detectors, it derives a lower bound on AUC that links detection performance to the separation and variance of inlier and outlier scores, and uses this to analyze how density variation, intrinsic dimensionality, and domain mismatch affect score variability. The authors introduce pseudo‑anomaly probes that provide a reference for estimating relative score separation, and demonstrate through experiments on DCASE benchmarks that these probes enable anomaly‑free model selection to outperform conventional development‑set selection, especially under domain shift.

By Kevin Wilkinghoff, Zheng-Hua Tan
arXiv Machine Learning
Jul 3

Fast and Accurate Anomaly Detection in Time Series

arXiv:2607. 02046v1 Announce Type: new Abstract: Anomaly detection is a critical and evolving field in Machine Learning, with applications targeting different domains such as cybersecurity, finance, healthcare, manufacturing and IoT (Internet of Things) systems.

By Emanuele Mele, Massimo Cafaro, Angelo Coluccia, Italo Epicoco