Anomaly Detection in the Open World: Normality Shift Detection, Explanation, and Adaptation
Dongqi Han, Zhiliang Wang, Wenqi Chen, Kai Wang, Rui Yu, Su Wang, Han Zhang, Zhihua Wang, Minghui Jin, Jiahai Yang, Xingang Shi, Xia Yin
摘要
Concept drift is one of the most frustrating challenges for learning-based security applications built on the closeworld assumption of identical distribution between training and deployment. Anomaly detection, one of the most important tasks in security domains, is instead immune to the drift of abnormal behavior due to the training without any abnormal data (known as zero-positive), which however comes at the cost of more severe impacts when normality shifts. However, existing studies mainly focus on concept drift of abnormal behaviour and/or supervised learning, leaving the normality shift for zero-positive anomaly detection largely unexplored.
In this work, we are the first to explore the normality shift for deep learning-based anomaly detection in security applications, and propose OWAD, a general framework to detect, explain, and adapt to normality shift in practice. In particular, OWAD outperforms prior work by detecting shift in an unsupervised fashion, reducing the overhead of manual labeling, and providing better adaptation performance through distribution-level tackling. We demonstrate the effectiveness of OWAD through several realistic experiments on three security-related anomaly detection applications with long-term practical data. Results show that OWAD can provide better adaptation performance of normality shift with less labeling overhead. We provide case studies to analyze the normality shift and provide operational recommendations for security applications. We also conduct an initial real-world deployment on a SCADA security system.
1 Normality shift intuitively refers to the change of distribution of normal data (detailed definition is in §II-C). In this paper, we interchangeably use terms "drift" and "shift". We tend to use "normality shift" as a whole term.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper20
- AOC-IDS: Autonomous Online Framework with Contrastive Learning for Intrusion DetectionXinchen Zhang, Running Zhao, Zhihan Jiang, Zhicong Sun 等INFOCOM 2024 · 被引用 27 次
- Continual Learning with Strategic Selection and Forgetting for Network Intrusion DetectionXinchen Zhang, Running Zhao, Zhihan Jiang, Handi Chen 等INFOCOM 2025 · 被引用 26 次
- Understanding and Bridging the Gap Between Unsupervised Network Representation Learning and Security AnalyticsJiacen Xu, Xiaokui Shu, Zhou LiS&P 2024 · 被引用 14 次
- Enhancing Network Attack Detection with Distributed and In-Network Data Collection SystemSeyed Mohammad Mehdi Mirnajafizadeh, Ashwin Raam Sethuram, David Mohaisen, DaeHun Nyang 等USENIX Security 2024 · 被引用 12 次
- Facing Anomalies Head-On: Network Traffic Anomaly Detection via Uncertainty-Inspired Inter-Sample DifferencesXinglin Lian, Chengtai Cao, Yan Liu, Xovee Xu 等WWW 2025 · 被引用 11 次
它引用的顶会 Paper19
- DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep LearningMin Du, Feifei Li, Guineng Zheng, Vivek SrikumarCCS 2017 · 被引用 1,823 次
- WILDS: A Benchmark of in-the-Wild Distribution ShiftsPang Wei Koh, Shiori Sagawa, Henrik Marklund, Sang Michael Xie 等ICML 2021 · 被引用 1,773 次
- Kitsune: An Ensemble of Autoencoders for Online Network Intrusion DetectionYisroel Mirsky, Tomer Doitshman, Yuval Elovici, Asaf ShabtaiNDSS 2018 · 被引用 945 次
- MaMaDroid: Detecting Android Malware by Building Markov Chains of Behavioral ModelsEnrico Mariconti, Lucky Onwuzurike, Panagiotis Andriotis, Emiliano De Cristofaro 等NDSS 2017 · 被引用 471 次
- TESSERACT: Eliminating Experimental Bias in Malware Classification across Space and TimeFeargus Pendlebury, Fabio Pierazzi, Roberto Jordaney, Johannes Kinder 等USENIX Security 2019 · 被引用 441 次
相关 Paper
- DeepAID: Interpreting and Improving Deep Learning-based Anomaly Detection in Security ApplicationsDongqi Han, Zhiliang Wang, Wenqi Chen, Ying Zhong 等CCS 2021 · 被引用 108 次
- CAShift: Benchmarking Log-Based Cloud Attack Detection under Normality ShiftJiongchi Yu, Xiaofei Xie, Qiang Hu, Bowen Zhang 等FSE 2025 · 被引用 1 次
- Zero-Shot Anomaly Detection via Batch NormalizationAodong Li, Chen Qiu, Marius Kloft, Padhraic Smyth 等NeurIPS 2023 · 被引用 7 次
- Lifelong Anomaly Detection Through UnlearningMin Du, Zhi Chen, Chang Liu, Rajvardhan Oak 等CCS 2019 · 被引用 145 次
- Anomaly Detection under Distribution ShiftTri Cao, Jiawen Zhu, Guansong PangICCV 2023 · 被引用 54 次
