arXiv:2606. 12673v1 Announce Type: cross Abstract: Cross-domain graph anomaly detection (GAD) aims to identify abnormal nodes in unseen target graphs, showing strong potential in real-world applications with heterogeneous graph data.
By Phan Nguyen, Dat Cao, Hien Chu, Khue Hoang
arXiv:2606. 00304v1 Announce Type: new Abstract: Graph anomaly detection methods aim to distinguish anomalous nodes.
By Yilin Liu, Hongchao Zhang, Taylor T. Johnson, Ahmad F. Taha, Meiyi Ma
RINSE (Robust Iterative Normality Self-Estimation) is a gradient‑free framework for zero‑shot graph anomaly detection that keeps a source‑trained detector fixed while iteratively estimating target normality, calibrating representations, and assessing evidence reliability on unseen target graphs. It identifies a reliable subset of low‑residual target nodes to build a trimmed target‑aware normality model and fuses complementary anomaly evidence through reliability‑gated rank fusion and encoder ensembling. Across eight unseen target graphs, RINSE achieves the highest average AUPRC under two preprocessing protocols, with ablation and sensitivity analyses supporting its combined design.
By Taufikur Rahman Fuad, Md Abrar Jahin, Amir Hussain
arXiv:2505. 21285v5 Announce Type: replace Abstract: This work proposes a framework LGKDE that learns kernel density estimation for graphs.
By Xudong Wang, Ziheng Sun, Chris Ding, Jicong Fan
arXiv:2608. 12441v1 Announce Type: cross Abstract: Deep learning detectors for anomalies in dynamic graphs have reached strong accuracy, yet they remain opaque: when an edge is flagged, the analyst receives a score but no reason.
By Iyad Assaad Nekka, Hamida Seba, Khaled Walid Hidouci, Karima Amrouche
arXiv:2608. 16018v1 Announce Type: cross Abstract: Graph anomaly detection aims to identify nodes that deviate from normal behavioral patterns within graphs.
By Junxin Lu, Jing Zhao, Shiliang Sun
The paper introduces Unsupervised Graph Collective Anomaly Detection (UGCAD), a framework that uses a variational graph autoencoder to learn graph representations of IoT network traffic and then enhances clustering to group nodes. UGCAD identifies collective anomalies by aggregating normal clusters and applying anomaly scores to the refined groups. Experiments on CICIoT2023 and ToN-IoT datasets show that UGCAD outperforms traditional and state‑of‑the‑art clustering‑based CAD methods in both clustering quality and anomaly detection accuracy.
By Dalila Khettaf, Djamel Djenouri, Zeinab Rezaeifar, Youcef Djenouri
FoundAna is a GNN‑assisted foundation model designed for graph anomaly detection across diverse datasets. It combines a GNN component with a transformer encoder enhanced by four positional encodings to capture both local and global structure, using reconstruction errors as anomaly scores. Experiments on nine benchmark datasets from financial, social, and citation networks show that FoundAna consistently outperforms state‑of‑the‑art baselines.
By Suprim Nakarmi, Chahana Dahal, Yue Zhao, Junggab Son, Zuobin Xiong
GLASS is a graph‑level anomaly detection framework that aligns graph and language representations on a unit hypersphere to achieve cross‑domain transferability. It constructs a Graph Descriptor Prompt to encode local, global, and semantic graph properties, and uses a multi‑slice soft cosine objective to unify graph and text embeddings. Anomaly scoring is performed via spherical density estimation with von Mises‑Fisher kernels, enabling zero‑shot detection and few‑shot adaptation across twelve benchmarks and three meta‑domains, outperforming recent GLAD baselines.
By Xudong Wang, Chris Ding, Tongxin Li, Jicong Fan
arXiv:2608. 10699v1 Announce Type: cross Abstract: Text-Attributed Graphs (TAGs), endowed with abundant textual content along with topological structures, have emerged as a versatile backbone for real-world anomaly detection spanning large language model security, social network moderation, and cyber threat identification.
By Ziyan Wang, Liwen Wu, Cheng Xie, Song Gao, Zhenli He, Xin Jin
arXiv:2602. 20019v2 Announce Type: replace-cross Abstract: Dynamic graph anomaly detection is critical for many real-world applications but remains challenging due to the scarcity of labeled anomalies.
By Yuxing Tian, Yiyan Qi, Fengran Mo, Weixu Zhang, Jian Guo, Jian-Yun Nie
arXiv:2511. 17113v3 Announce Type: replace-cross Abstract: Network Intrusion Detection Systems (NIDS) are essential tools for detecting network attacks and intrusions.
By Georgios Anyfantis, Pere Barlet-Ros