arXiv:2607. 01305v1 Announce Type: cross Abstract: Intrusion Detection Systems (IDSs) are essential for monitoring network traffic and identifying malicious activities in modern cyber-physical, Internet of Things (IoT), enterprise, and distributed network environments.
By Jiefei Liu, Abu Saleh Md Tayeen, Pratyay Kumar, Qixu Gong, Wenbin Jiang, Huiping Cao, Satyajayant Misra, Jayashree Harikumar
The paper introduces a deep positive‑unlabeled anomaly detection framework that combines positive‑unlabeled learning with deep models such as autoencoders and deep support vector data descriptions. It addresses the issue of contaminated unlabeled data by approximating anomaly scores for normal data using both unlabeled and labeled anomaly samples, allowing training without labeled normal data. The authors provide a theoretical generalization error bound and demonstrate improved detection performance over existing methods on several datasets.
By Hiroshi Takahashi, Tomoharu Iwata, Atsutoshi Kumagai, Yuuki Yamanaka
The paper introduces a novel zero‑shot anomaly detection framework for multivariate IoT traffic data that combines adversarial learning and contrastive loss within a sequence‑based Variational Autoencoder. It achieves domain‑invariant latent representations and semantically structured embeddings without labeled data, using encoder/decoder adaptor layers to align feature distributions and a destination‑based segmentation strategy to model real‑world communication patterns. The method is evaluated on six diverse datasets across 44 transfer scenarios, showing strong zero‑shot generalization and competitive performance against a contrastive domain‑adaptation baseline in heterogeneous, privacy‑constrained IoT environments.
By Mahshid Rezakhani, Tolunay Seyfi, Fatemeh Afghah
The paper introduces a statistical feature augmentation technique that encodes behavioral interaction statistics into the input space for dynamic graph anomaly detection. Experiments on Reddit, Wikipedia, and MOOC datasets across seven models—both continuous-time and discrete-time—show that this augmentation consistently improves detection performance compared to models trained on original embeddings. The enriched input also facilitates fine-grained post-hoc analysis of behavioral importance, linking classical network analysis with deep learning.
By Philipp Schlinge, Jean-Luc Schnipper, Martin Atzmueller
arXiv:2507. 15584v2 Announce Type: replace Abstract: Despite the continuous proposal of new anomaly detection algorithms and extensive benchmarking efforts, progress seems to stagnate, with only minor performance differences between established baselines and new algorithms.
By Philipp R\"ochner, Simon Kl\"uttermann, Kevin Kammler, Franz Rothlauf, Emmanuel M\"uller, Daniel Schl\"or
The paper introduces a GAN‑based framework for detecting DDoS attacks that are designed to evade traditional security systems. It combines Random Forests, Deep Neural Ensembles, and Transformer models trained on the CICDDoS2019 dataset with synthetic adversarial traffic generated by a WGAN‑GP. Experiments show that this hybrid training significantly improves detection accuracy and resilience against unseen adversarial traffic, and real‑world tests confirm its practical effectiveness.
By Makram Chehayeb, Walid Fahs, Amina Rizk, Rida Khatoun, Omran Berjawi