Interactive Anomaly Detection on Attributed Networks

Интерактивное обнаружение аномалий в атрибутированных сетях
Kaize Ding, Jundong Li, Huan Liu
2019-01-30

GraphUCBattributed networkscontextual banditinteractive anomaly detectionmulti-armed bandit
Performing anomaly detection on attributed networks concerns with finding nodes whose patterns or behaviors deviate significantly from the majority of reference nodes. Its success can be easily found in many real-world applications such as network intrusion detection, opinion spam detection and system fault diagnosis, to name a few. Despite their empirical success, a vast majority of existing efforts are overwhelmingly performed in an unsupervised scenario due to the expensive labeling costs of ground truth anomalies. In fact, in many scenarios, a small amount of prior human knowledge of the data is often effortless to obtain, and getting it involved in the learning process has shown to be effective in advancing many important learning tasks. Additionally, since new types of anomalies may constantly arise over time especially in an adversarial environment, the interests of human expert could also change accordingly regarding to the detected anomaly types. It brings further challenges to conventional anomaly detection algorithms as they are often applied in a batch setting and are incapable to interact with the environment. To tackle the above issues, in this paper, we investigate the problem of anomaly detection on attributed networks in an interactive setting by allowing the system to proactively communicate with the human expert in making a limited number of queries about ground truth anomalies. Our objective is to maximize the true anomalies presented to the human expert after a given budget is used up. Along with this line, we formulate the problem through the principled multi-armed bandit framework and develop a novel collaborative contextual bandit algorithm, named GraphUCB. In particular, our developed algorithm: (1) explicitly models the nodal attributes and node dependencies seamlessly in a joint framework; and (2) handles the exploration-exploitation dilemma when querying anomalies of different types. Extensive experiments on real-world datasets show the improvement of the proposed algorithm over the state-of-the-art algorithms.
1
Experiments on real-world datasets are reported to demonstrate the effectiveness of the proposed interactive approach, although specific results are not provided in the abstract.
2
GraphUCB addresses the exploration–exploitation tradeoff when selecting anomaly queries across different anomaly types.
3
It introduces GraphUCB, a collaborative contextual bandit algorithm that models node attributes and network dependencies jointly.
4
The objective is to maximize the number of true anomalies presented to human experts after exhausting the query budget.
5
The paper formulates anomaly detection on attributed networks as an interactive process where systems query human experts under a limited labeling budget.

anomaly detection on attributed networks in an interactive human-in-the-loop setting

interactive identification and querying of anomalous nodes, including modeling nodal attributes, node dependencies, and anomaly-type exploration–exploitation under a limited query budget

Publication Details
Publication Date
2019-01-30
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Kaize Ding
Jundong Li
Huan Liu
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat →
Make a presentation
100%