arXiv:2512. 22179v3 Announce Type: replace Abstract: Detecting previously unseen attacks remains a major challenge for machine learning-based intrusion detection systems.
By Rajeeb Thapa Chhetri, Saurab Thapa, Avinash Kumar, Zhixiong Chen
arXiv:2409. 08521v2 Announce Type: replace-cross Abstract: In cybersecurity practice, new forms of cyberattacks continuously emerge, deliberately designed to evade defense systems that rely on previously observed behaviors.
By Tian-Yi Zhou, Matthew Lau, Jizhou Chen, Wenke Lee, Xiaoming Huo
arXiv:2604. 13924v3 Announce Type: replace-cross Abstract: Time-series anomaly detection (TSAD) is critical in domains such as industrial monitoring, healthcare, and cybersecurity, but it remains challenging due to rare and heterogeneous anomalies and the scarcity of labelled data.
By Romain Hermary, Samet Hicsonmez, Dan Pineau, Abd El Rahman Shabayek, Djamila Aouada
arXiv:2607. 18289v1 Announce Type: cross Abstract: Continual anomaly detection (CAD) studies how models can adapt to evolving data distributions while retaining performance on previously observed regimes.
By Kamil Faber, Mateusz Smendowski, Roberto Corizzo
The paper surveys Multi‑Modal Anomaly Detection (MMAD), a field that identifies rare abnormal events across heterogeneous data sources used in safety‑critical domains like industrial inspection and cybersecurity. It formalizes MMAD, outlines five core characteristics, and categorizes existing methods into normality‑assumption and anomaly‑assumption paradigms, highlighting how foundation models are reshaping the field. The survey also compiles benchmarks, evaluation protocols, and identifies open problems for developing robust, adaptive, and interpretable MMAD systems.
By Xudong Mou, Zexin Wu, Chuan Luo, Shiru Chen, Xudong Liu, Chunming Hu, Renyu Yang
arXiv:2510. 26307v3 Announce Type: replace-cross Abstract: Anomaly detection is a critical task in cybersecurity, where identifying insider threats, access violations, and coordinated attacks is essential for ensuring system resilience.
By Laura Jiang, Reza Ryan, Qian Li, Nasim Ferdosian
Online Conformal Anomaly Detection with Prediction-Powered Data Acquisition introduces C-PP-COAD, a framework that uses synthetic calibration data to reduce reliance on real-world calibration while maintaining assumption-free false discovery rate control. The method wraps any anomaly detection algorithm, converting its scores into conformal p-values for online testing. Experiments on synthetic and real datasets—including thyroid dysfunction, O‑RAN conflict, 5G intrusion, and UE throughput degradation—show that C-PP-COAD preserves FDR guarantees while significantly cutting the need for real calibration data.
By Amirmohammad Farzaneh, Osvaldo Simeone
arXiv:2511. 22078v2 Announce Type: replace Abstract: Many real-world scenarios involving streaming information can be represented as temporal graphs, where data flows through dynamic changes in edges over time.
By Simone Mungari, Albert Bifet, Giuseppe Manco, Bernhard Pfahringer
CAST is a framework for generating anomalous time series that addresses the scarcity and heterogeneity of anomaly data. It uses a two‑stage approach: pretraining on abundant normal data to learn system dynamics, then finetuning with anomaly structure representations to capture diverse anomaly morphologies. Experiments on real‑world datasets show that CAST outperforms existing methods in both generation quality and downstream task performance.
By Haochen Zhang, Jie Peng, Songyuan Sui, Yu-Chao Huang, Xiangqi Zhu, Tianlong Chen
The paper introduces Unsupervised Graph Collective Anomaly Detection (UGCAD), a framework that uses a variational graph autoencoder to learn graph representations of IoT network traffic and then enhances clustering to group nodes. UGCAD identifies collective anomalies by aggregating normal clusters and applying anomaly scores to the refined groups. Experiments on CICIoT2023 and ToN-IoT datasets show that UGCAD outperforms traditional and state‑of‑the‑art clustering‑based CAD methods in both clustering quality and anomaly detection accuracy.
By Dalila Khettaf, Djamel Djenouri, Zeinab Rezaeifar, Youcef Djenouri
The paper investigates whether the performance of anomaly detection systems can be predicted without labeled anomalies. For kNN-based detectors, it derives a lower bound on AUC that links detection performance to the separation and variance of inlier and outlier scores, and uses this to analyze how density variation, intrinsic dimensionality, and domain mismatch affect score variability. The authors introduce pseudo‑anomaly probes that provide a reference for estimating relative score separation, and demonstrate through experiments on DCASE benchmarks that these probes enable anomaly‑free model selection to outperform conventional development‑set selection, especially under domain shift.
By Kevin Wilkinghoff, Zheng-Hua Tan
arXiv:2607. 02046v1 Announce Type: new Abstract: Anomaly detection is a critical and evolving field in Machine Learning, with applications targeting different domains such as cybersecurity, finance, healthcare, manufacturing and IoT (Internet of Things) systems.
By Emanuele Mele, Massimo Cafaro, Angelo Coluccia, Italo Epicoco