Interpretable, Multidimensional, Multimodal Anomaly Detection with Negative Sampling for Detection of Device Failure
John Sipple
Abstract
Complex devices are connected daily and eagerly generate vast streams of multidimensional state measurements. These devices often operate in distinct modes based on external conditions (day/night, occupied/vacant, etc.), and to prevent complete or partial system outage, we would like to recognize as early as possible when these devices begin to operate outside the normal modes. Unfortunately, it is often impractical or impossible to predict failures using rules or supervised machine learning, because failure modes are too complex, devices are too new to adequately characterize in a specific environment, or environmental change puts the device into an unpredictable condition. We propose an unsupervised anomaly detection method that creates a negative sample from the positive, observed sample, and trains a classifier to distinguish between positive and negative samples. Using the Contraction Principle, we explain why such a classifier ought to establish suitable decision boundaries between normal and anomalous regions, and show how Integrated Gradients can attribute the anomaly to specific variables within the anomalous state vector. We have demonstrated that negative sampling with random forest or neural network classifiers yield significantly higher AUC scores than Isolation Forest, One Class SVM, and Deep SVDD, against (a) a synthetic dataset with dimensionality ranging between 2 and 128, with 1, 2, and 3 modes, and with and without noise dimensions; (b) four standard benchmark datasets; and (c) a multidimensional, multimodal dataset from real climate control devices. Finally, we describe how negative sampling with neural network classifiers have been successfully deployed at large scale to predict failures in real time in over 15,000 climate-control and power meter devices in 145 Google office buildings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers8
- Rethinking Graph Neural Networks for Anomaly DetectionJianheng Tang, Jiajin Li, Ziqi Gao, Jia LiICML 2022 · 365 citations
- LUNAR: Unifying Local Outlier Detection Methods via Graph Neural NetworksAdam Goodge, Bryan Hooi, See-Kiong Ng, Wee Siong NgAAAI 2022 · 144 citations
- Outlier Detection for Streaming Task Assignment in CrowdsourcingYan Zhao, Xuanhao Chen, Liwei Deng, Tung Kieu et al.WWW 2022 · 32 citations
- Interpreting Unsupervised Anomaly Detection in Security via Rule ExtractionRuoyu Li, Qing Li, Yu Zhang, Dan Zhao et al.NeurIPS 2023 · 18 citations
- Weakly Supervised Anomaly Detection via Knowledge-Data AlignmentHaihong Zhao, Chenyi Zi, Yang Liu, Chen Zhang et al.WWW 2024 · 17 citations
Related papers
- Unsupervised Anomaly Detection on Microservice Traces through Graph VAEZhe Xie, Haowen Xu, Wenxiao Chen, Wanxue Li et al.WWW 2023 · 44 citations
- Understanding the Feature Norm for Out-of-Distribution DetectionJaewoo Park, Jacky Chen Long Chai, Jaeho Yoon, Andrew Beng Jin TeohICCV 2023 · 27 citations
- Facade: High-Precision Insider Threat Detection Using Deep Contextual Anomaly DetectionAlex Kantchelian, Casper Neo, Ryan Stevens, Hyungwon Kim et al.USENIX Security 2026
- MAD-SGCN: Multivariate Anomaly Detection with Self-learning Graph Convolutional NetworksPanpan Qi, Dan Li, See-Kiong NgICDE 2022 · 26 citations
- A Stitch in Time Saves Nine: Enabling Early Anomaly Detection with Correlation AnalysisYihao Ang, Qiang Huang, Anthony K. H. Tung, Zhiyong HuangICDE 2023 · 6 citations
