<p>Commonly adopted anomaly detection frameworks in security systems typically rely on natural time cycles to construct a single dynamic graph, which enables the unified detection of diverse anomalies. However, different anomalous behaviors exhibit distinct temporal distribution patterns, causing behavior patterns to fragment across graph snapshots. This leads to the behavior pattern confounding problem and complicates the balancing of the heterophily ratio and the anomaly proportion within each snapshot. We formally analyze the causes of this issue and propose DiffGAD, a dynamic graph diffusion-based anomaly detection framework. By utilizing heat diffusion, we identify time windows that capture the most discriminative behavior patterns for constructing adaptive dynamic graphs. Based on this, we enable inter- and intra-diffusion through a dynamized Perona-Malik (PM) equation. Ultimately, anomaly detection is achieved by penalizing similarity to the natural time cycle-based dynamic graph. Experiments in network intrusion and anonymous traffic detection scenarios show that DiffGAD outperforms state-of-the-art (SOTA) methods and detects anomalies effectively even at a low proportion. Compared to the best-performing baselines, it mitigates the performance drop in unified detection by over 50% relative to separate detection. Case studies on simulated and public datasets provide insights into DiffGAD’s superior performance.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Adaptive dynamic graphs for anomaly detection via inter- and intra-diffusion

  • Ziqi Yuan,
  • Haoyi Zhou,
  • Qingyun Sun

摘要

Commonly adopted anomaly detection frameworks in security systems typically rely on natural time cycles to construct a single dynamic graph, which enables the unified detection of diverse anomalies. However, different anomalous behaviors exhibit distinct temporal distribution patterns, causing behavior patterns to fragment across graph snapshots. This leads to the behavior pattern confounding problem and complicates the balancing of the heterophily ratio and the anomaly proportion within each snapshot. We formally analyze the causes of this issue and propose DiffGAD, a dynamic graph diffusion-based anomaly detection framework. By utilizing heat diffusion, we identify time windows that capture the most discriminative behavior patterns for constructing adaptive dynamic graphs. Based on this, we enable inter- and intra-diffusion through a dynamized Perona-Malik (PM) equation. Ultimately, anomaly detection is achieved by penalizing similarity to the natural time cycle-based dynamic graph. Experiments in network intrusion and anonymous traffic detection scenarios show that DiffGAD outperforms state-of-the-art (SOTA) methods and detects anomalies effectively even at a low proportion. Compared to the best-performing baselines, it mitigates the performance drop in unified detection by over 50% relative to separate detection. Case studies on simulated and public datasets provide insights into DiffGAD’s superior performance.