Online Adaptive Anomaly Thresholding with Confidence Sequences
Sophia Huiwen Sun, Abishek Sankararaman, Balakrishnan Narayanaswamy
Abstract
Selecting appropriate thresholds for anomaly detection in online, unsupervised settings is a challenging task, especially in the presence of data distribution shifts. Addressing these challenges is critical in many practical large scale systems, such as infrastructure monitoring and network intrusion detection. This paper proposes an algorithm that connects online thresholding with constructing confidence sequences achieving (1) adaptive online threshold selection robust to distribution shifts, (2) statistical guarantees on false positive and false negative rates without any distributional assumptions, and (3) improved performance when given relevant offline data to warm-start the online algorithm, while having bounded degradation if the offline data is irrelevant. We complement our theoretical results with empirical evidence that our method outperforms commonly used baselines across synthetic and real world datasets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3824154b-e388-4466-94e6-4216f2235fedBuilds on14
- Kitsune: An Ensemble of Autoencoders for Online Network Intrusion DetectionYisroel Mirsky, Tomer Doitshman, Yuval Elovici, Asaf ShabtaiNDSS 2018 · 945 citations
- Anomaly Detection in Time Series: A Comprehensive EvaluationSebastian Schmidl, Phillip Wenig, Thorsten PapenbrockVLDB 2022 · 578 citations
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen et al.NDSS 2019 · 411 citations
- DROCC: Deep Robust One-Class ClassificationSachin Goyal, Aditi Raghunathan, Moksh Jain, Harsha Vardhan Simhadri et al.ICML 2020 · 202 citations
- Detecting Credential Spearphishing in Enterprise SettingsGrant Ho, Aashish Sharma, Mobin Javed, Vern Paxson et al.USENIX Security 2017 · 94 citations
Related papers
- When Model Meets New Normals: Test-Time Adaptation for Unsupervised Time-Series Anomaly DetectionDongmin Kim, Sunghyun Park, Jaegul ChooAAAI 2024 · 43 citations
- Tracking the risk of a deployed model and detecting harmful distribution shiftsAleksandr Podkopaev, Aaditya RamdasICLR 2022 · 36 citations
- SEAD: Unsupervised Ensemble of Streaming Anomaly DetectorsSaumya Gaurang Shah, Abishek Sankararaman, Balakrishnan Narayanaswamy, Vikramank Y. SinghICML 2025
- ReCATS: Replay-Free Continual Anomaly Detection for Non-Stationary Multivariate Time SeriesQiuyang Li, Qian Ma, Zhongming Yao, Shikai Guo et al.KDD 2026
- SAND: Streaming Subsequence Anomaly DetectionPaul Boniol, John Paparrizos, Themis Palpanas, Michael J. FranklinVLDB 2021 · 128 citations
