ARES: Anomaly Recognition Model For Edge Streams
Simone Mungari, Albert Bifet, Giuseppe Manco, Bernhard Pfahringer
Abstract
Many real-world scenarios involving streaming information can be represented as temporal graphs, where data flows through dynamic changes in edges over time. Anomaly detection in this context has the objective of identifying unusual temporal connections within the graph structure. Detecting edge anomalies in real time is crucial for mitigating potential risks. Unlike traditional anomaly detection, this task is particularly challenging due to concept drifts, large data volumes, and the need for real-time response. To face these challenges, we introduce ARES, an unsupervised anomaly detection framework for edge streams. ARES combines Graph Neural Networks (GNNs) for feature extraction with Half-Space Trees (HST) for anomaly scoring. GNNs capture both spike and burst anomalous behaviors within streams by embedding node and edge properties in a latent space, while HST partitions this space to isolate anomalies efficiently. ARES operates in an unsupervised way without the need for prior data labeling. To further validate its detection capabilities, we additionally incorporate a simple yet effective supervised thresholding mechanism. This approach leverages statistical dispersion among anomaly scores to determine the optimal threshold using a minimal set of labeled data, ensuring adaptability across different domains. We validate ARES through extensive evaluations across several real-world cyber-attack scenarios, comparing its performance against existing methods while analyzing its space and time complexity. The code used to perform the experiments is publicly available at https://github.com/AnomalyRecognitionModelForEdgeStreams/ARES.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 63705e9e-a00c-44be-b250-7e52cf8b715cBuilds on5
- Rethinking Graph Neural Networks for Anomaly DetectionJianheng Tang, Jiajin Li, Ziqi Gao, Jia LiICML 2022 · 365 citations
- Midas: Microcluster-Based Detector of Anomalies in Edge StreamsSiddharth Bhatia, Bryan Hooi, Minji Yoon, Kijung Shin et al.AAAI 2020 · 118 citations
- Sketch-Based Anomaly Detection in Streaming GraphsSiddharth Bhatia, Mohit Wadhwa, Kenji Kawaguchi, Neil Shah et al.KDD 2023 · 23 citations
- SLADE: Detecting Dynamic Anomalies in Edge Streams without Labels via Self-Supervised LearningJongha Lee, Sunwoo Kim, Kijung ShinKDD 2024 · 21 citations
- Mining Persistent Activity in Continually Evolving NetworksCaleb Belth, Xinyi Zheng, Danai KoutraKDD 2020 · 19 citations
Related papers
- MStream: Fast Anomaly Detection in Multi-Aspect StreamsSiddharth Bhatia, Arjit Jain, Pan Li, Ritesh Kumar et al.WWW 2021 · 69 citations
- Mitigating Anomaly Hallucination: A Model-Agnostic Framework for Unsupervised Anomaly Detection on Dynamic GraphsYingxuan Li, Yuanyuan Xu, Xuemin Lin, Ying ZhangKDD 2026
- Fine-Grained Anomaly Detection on Dynamic Graphs via Attention AlignmentDong Chen, Xiang Zhao, Weidong XiaoICDE 2024 · 8 citations
- BAG: Benchmarking Anomaly Detection on Dynamic GraphsFengrui Hua, Yiyan Qi, Zikai Wei, Yuxing Tian et al.AAAI 2026
- STGAN: Detecting Host Threats via Fusion of Spatial-Temporal Features in Host Provenance GraphsAnyuan Sang, Xuezheng Fan, Li Yang, Yuchen Wang et al.WWW 2025 · 6 citations
