The paper introduces Unsupervised Graph Collective Anomaly Detection (UGCAD), a framework that uses a variational graph autoencoder to learn graph representations of IoT network traffic and then enhances clustering to group nodes. UGCAD identifies collective anomalies by aggregating normal clusters and applying anomaly scores to the refined groups. Experiments on CICIoT2023 and ToN-IoT datasets show that UGCAD outperforms traditional and state‑of‑the‑art clustering‑based CAD methods in both clustering quality and anomaly detection accuracy.
By Dalila Khettaf, Djamel Djenouri, Zeinab Rezaeifar, Youcef Djenouri
arXiv:2510. 26307v3 Announce Type: replace-cross Abstract: Anomaly detection is a critical task in cybersecurity, where identifying insider threats, access violations, and coordinated attacks is essential for ensuring system resilience.
By Laura Jiang, Reza Ryan, Qian Li, Nasim Ferdosian
arXiv:2511. 17113v3 Announce Type: replace-cross Abstract: Network Intrusion Detection Systems (NIDS) are essential tools for detecting network attacks and intrusions.
By Georgios Anyfantis, Pere Barlet-Ros
FoundAna is a GNN‑assisted foundation model designed for graph anomaly detection across diverse datasets. It combines a GNN component with a transformer encoder enhanced by four positional encodings to capture both local and global structure, using reconstruction errors as anomaly scores. Experiments on nine benchmark datasets from financial, social, and citation networks show that FoundAna consistently outperforms state‑of‑the‑art baselines.
By Suprim Nakarmi, Chahana Dahal, Yue Zhao, Junggab Son, Zuobin Xiong
The paper introduces a statistical feature augmentation technique that encodes behavioral interaction statistics into the input space for dynamic graph anomaly detection. Experiments on Reddit, Wikipedia, and MOOC datasets across seven models—both continuous-time and discrete-time—show that this augmentation consistently improves detection performance compared to models trained on original embeddings. The enriched input also facilitates fine-grained post-hoc analysis of behavioral importance, linking classical network analysis with deep learning.
By Philipp Schlinge, Jean-Luc Schnipper, Martin Atzmueller
arXiv:2602. 20019v2 Announce Type: replace-cross Abstract: Dynamic graph anomaly detection is critical for many real-world applications but remains challenging due to the scarcity of labeled anomalies.
By Yuxing Tian, Yiyan Qi, Fengran Mo, Weixu Zhang, Jian Guo, Jian-Yun Nie