Multi-Aspect Mining and Anomaly Detection for Heterogeneous Tensor Streams
Soshi Kakio, Yasuko Matsubara, Ren Fujiwara, Yasushi Sakurai
Abstract
Analysis and anomaly detection in event tensor streams consisting of timestamps and multiple attributes -such as communication logs (time, IP address, packet length)-are essential tasks in data mining. While existing tensor decomposition and anomaly detection methods provide useful insights, they face the following two limitations. (i) They cannot handle heterogeneous tensor streams, which comprises both categorical attributes (e.g., IP address) and continuous attributes (e.g., packet length). They typically require either discretizing continuous attributes or treating categorical attributes as continuous, both of which distort the underlying statistical properties of the data. Furthermore, incorrect assumptions about the distribution family of continuous attributes often degrade the model's performance. (ii) They discretize timestamps, failing to track the temporal dynamics of streams (e.g., trends, abnormal events), which makes them ineffective for detecting anomalies at the group level, referred to as "group anomalies" (e.g, DoS attacks). To address these challenges, we propose HeteroComp, a method for continuously summarizing heterogeneous tensor streams into "components " representing latent groups in each attribute and their temporal dynamics, and detecting group anomalies. Our method employs Gaussian process priors to model unknown distributions of continuous attributes, and temporal dynamics, which directly estimate probability densities from data. Extracted components give concise but effective summarization, enabling accurate group anomaly detection. Extensive experiments on real datasets demonstrate that HeteroComp outperforms the state-of-the-art algorithms for group anomaly detection accuracy, and its computational time does not depend on the data stream length. CCS Concepts • Information systems → Data stream mining; • Computing methodologies → Factorization methods.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on13
- Midas: Microcluster-Based Detector of Anomalies in Edge StreamsSiddharth Bhatia, Bryan Hooi, Minji Yoon, Kijung Shin et al.AAAI 2020 · 118 citations
- MStream: Fast Anomaly Detection in Multi-Aspect StreamsSiddharth Bhatia, Arjit Jain, Pan Li, Ritesh Kumar et al.WWW 2021 · 69 citations
- Adaptive Model Pooling for Online Deep Anomaly Detection from a Complex Evolving Data StreamSusik Yoon, Youngjun Lee, Jae-Gil Lee, Byung Suk LeeKDD 2022 · 39 citations
- MemStream: Memory-Based Streaming Anomaly DetectionSiddharth Bhatia, Arjit Jain, Shivin Srivastava, Kenji Kawaguchi et al.WWW 2022 · 33 citations
- Sketch-Based Anomaly Detection in Streaming GraphsSiddharth Bhatia, Mohit Wadhwa, Kenji Kawaguchi, Neil Shah et al.KDD 2023 · 23 citations
Related papers
- Fast and Multi-aspect Mining of Complex Time-stamped Event StreamsKota Nakamura, Yasuko Matsubara, Koki Kawabata, Yuhei Umeda et al.WWW 2023 · 13 citations
- Fast and Accurate Element-Level Streaming CP Decomposition for Higher-Order TensorsJeongyoung Lee, SeungJoo Lee, U. KangICDE 2026 · 2 citations
- NMMF-Stream: A Fast and Accurate Stream-Processing Scheme for Network Monitoring Data RecoveryKun Xie, Ruotian Xie, Xin Wang, Gaogang Xie et al.INFOCOM 2022 · 12 citations
- Expectile Tensor Completion to Recover Skewed Network Monitoring DataKun Xie, Siqi Li, Xin Wang, Gaogang Xie et al.INFOCOM 2021 · 6 citations
- Cluster-Aware Causal Mixer for Online Anomaly Detection in Multivariate Time SeriesMd Mahmuddun Nabi Murad, Yasin YilmazICML 2026 · 2 citations
