Anomaly Detection in Dynamic Systems Using Weak Estimators

被引:29
作者
Zhan, Justin
Oommen, B. John [1 ]
Crisostomo, Johanna [2 ]
机构
[1] Carleton Univ, Sch Comp Sci, Ottawa, ON K1S 5B6, Canada
[2] Carnegie Mellon Univ, Pittsburgh, PA 15213 USA
基金
美国国家科学基金会;
关键词
Design; Algorithms; Performance; Anomaly detection; dynamic systems; weak estimator;
D O I
10.1145/1993083.1993086
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Anomaly detection involves identifying observations that deviate from the normal behavior of a system. One of the ways to achieve this is by identifying the phenomena that characterize "normal" observations. Subsequently, based on the characteristics of data learned from the "normal" observations, new observations are classified as being either "normal" or not. Most state-of-the-art approaches, especially those which belong to the family of parameterized statistical schemes, work under the assumption that the underlying distributions of the observations are stationary. That is, they assume that the distributions that are learned during the training (or learning) phase, though unknown, are not time-varying. They further assume that the same distributions are relevant even as new observations are encountered. Although such a "stationarity" assumption is relevant for many applications, there are some anomaly detection problems where stationarity cannot be assumed. For example, in network monitoring, the patterns which are learned to represent normal behavior may change over time due to several factors such as network infrastructure expansion, new services, growth of user population, and so on. Similarly, in meteorology, identifying anomalous temperature patterns involves taking into account seasonal changes of normal observations. Detecting anomalies or outliers under these circumstances introduces several challenges. Indeed, the ability to adapt to changes in nonstationary environments is necessary so that anomalous observations can be identified even with changes in what would otherwise be classified as "normal" behavior. In this article we propose to apply a family of weak estimators for anomaly detection in dynamic environments. In particular, we apply this theory to spam email detection. Our experimental results demonstrate that our proposal is both feasible and effective for the detection of such anomalous emails.
引用
收藏
页数:16
相关论文
共 50 条
  • [21] A survey on anomaly detection for technical systems using LSTM networks
    Lindemann, Benjamin
    Maschler, Benjamin
    Sahlab, Nada
    Weyrich, Michael
    COMPUTERS IN INDUSTRY, 2021, 131
  • [22] Development of Monitoring Systems for Anomaly Detection Using ASTD Specifications
    Chaymae, El Jabri
    Marc, Frappier
    Thibaud, Ecarot
    Pierre-Martin, Tardif
    THEORETICAL ASPECTS OF SOFTWARE ENGINEERING, TASE 2022, 2022, 13299 : 274 - 289
  • [23] Anomaly Detection in Manufacturing Systems Using Structured Neural Networks
    Liu, Jie
    Guo, Jianlin
    Orlik, Philip
    Shibata, Masahiko
    Nakahara, Daiki
    Mii, Satoshi
    Takac, Martin
    2018 13TH WORLD CONGRESS ON INTELLIGENT CONTROL AND AUTOMATION (WCICA), 2018, : 175 - 180
  • [24] Anomaly detection using invariant rules in Industrial Control Systems
    Zhu, Qilin
    Ding, Yulong
    Jiang, Jie
    Yang, Shuang-Hua
    CONTROL ENGINEERING PRACTICE, 2025, 154
  • [25] ANOMALY DETECTION FOR CYBER-PHYSICAL SYSTEMS USING TRANSFORMERS
    Ma, Yuliang
    Morozov, Andrey
    Ding, Sheng
    PROCEEDINGS OF ASME 2021 INTERNATIONAL MECHANICAL ENGINEERING CONGRESS AND EXPOSITION (IMECE2021), VOL 13, 2021,
  • [26] A Dependable Monitoring Mechanism Combining Static and Dynamic Anomaly Detection for Network Systems
    Wang, GuiPing
    Chen, ShuYu
    Zhou, Zhen
    Lin, MingWei
    INTERNATIONAL JOURNAL OF FUTURE GENERATION COMMUNICATION AND NETWORKING, 2014, 7 (01): : 1 - 18
  • [27] MADneSs: A Multi-Layer Anomaly Detection Framework for Complex Dynamic Systems
    Zoppi, Tommaso
    Ceccarelli, Andrea
    Bondavalli, Andrea
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (02) : 796 - 809
  • [28] Dynamic Data Abstraction-Based Anomaly Detection for Industrial Control Systems
    Cho, Jake
    Gong, Seonghyeon
    ELECTRONICS, 2024, 13 (01)
  • [29] A dynamic modeling approach for anomaly detection using stochastic differential equations
    Rajabzadeh, Yalda
    Rezaie, Amir Hossein
    Amindavar, Hamidreza
    DIGITAL SIGNAL PROCESSING, 2016, 54 : 1 - 11
  • [30] Dynamic video anomaly detection and localization using sparse denoising autoencoders
    Narasimhan, Medhini G.
    Kamath, Sowmya S.
    MULTIMEDIA TOOLS AND APPLICATIONS, 2018, 77 (11) : 13173 - 13195