arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.15559cs.LGcs.AI

动态图异常检测器的带精确保留的摊销事后解释

Amortised Post-Hoc Explanation with Exact Preservation for Dynamic Graph Anomaly Detectors

Iyad Assaad Nekka, Hamida Seba, Walid Khaled Hidouci, Karima Amrouche

首次发表
浏览论文内容

中文总结 AI 辅助

本文针对动态图异常检测器StrGNN缺乏解释的问题,提出X-StrGNN事后解释层,可精确保留检测性能且成本低,通过对比归因策略验证了其稳定性与效果。

中文摘要 AI 辅助

动态图中的异常检测是金融欺诈分析、入侵检测和平台完整性的基础,自动化决策需要人类可解释的理由。StrGNN是近期基准测试中表现最强的模型,它不生成解释:当一条边被标记时,分析人员仅会收到一个分数。由于不存在归因向量,StrGNN的解释指标未被定义。本文填补了这一空白。我们提出X-StrGNN,这是一个事后解释层,它包装了已训练且固定的StrGNN,并为每条被标记的边输出双重归因:结构归因,识别包围子图中哪些上下文交互推动了决策;时间归因,识别哪个历史快照承载了信号。两种归因都是乘法掩码,在未解释的传递中均为1,因此该层是精确的直通层:检测结果以机器精度被保留,经验证而非断言(Delta AUC = 0.0000,Delta AP = 0.0000,Delta P@100 = 0.0000)。归因每条边耗时0.66毫秒,这使得对整个警报列表进行解释是可行的。我们针对该架构开展了首个受控的归因策略设计研究,在同一协议、同一预算和三个随机种子下,比较梯度归因、逐实例掩码优化和摊销参数化三种策略。X-StrGNN达到最高稳定性(0.913),成本比逐实例优化低268倍,其时间归因(1.601,而测得的随机下限为0.973)明显优于其 ablation 对照组,而成本最高的逐实例优化策略则低于该随机下限。代码、协议和分随机种子的测量结果已公开。

英文摘要

Anomaly detection in dynamic graphs underpins financial fraud analysis, intrusion detection, and platform integrity, where automated decisions require human-interpretable justifications. StrGNN, the strongest performer in recent benchmarks, produces no explanation: when an edge is flagged, the analyst receives only a score. Explanation metrics are undefined for StrGNN because no attribution vector exists. This paper closes that gap. We present X-StrGNN, a post-hoc explanation layer that wraps a trained, frozen StrGNN and emits, for every flagged edge, dual attributions: a structural attribution identifying which contextual interactions in the enclosing subgraph drove the decision, and a temporal attribution identifying which historical snapshot carried the signal. Both attributions are multiplicative masks identically one in the unexplained pass, so the layer is an exact pass-through: detection is preserved to machine precision, verified rather than asserted (Delta AUC = 0.0000, Delta AP = 0.0000, Delta P@100 = 0.0000). Attribution costs 0.66 ms per edge, making explanation of an entire alarm list feasible. We conduct the first controlled design study of attribution strategies for this architecture, comparing gradient attribution, per-instance mask optimisation, and amortised parameterisation under one protocol, one budget, and three seeds. X-StrGNN attains the highest stability (0.913) at 268x lower cost than per-instance optimisation, and its temporal attribution (1.601 against a measured random floor of 0.973) is separably better than its ablated control, while per-instance optimisation - the most expensive strategy - falls below that floor. Code, protocol, and per-seed measurements are released.

发表机构

  • National higher School of Computer Science (ESI)(国家计算机科学高等学校(ESI))
  • Université Claude Bernard Lyon(里昂第一大学(克洛德·贝尔纳里昂大学))

机构由 AI 辅助整理,请以论文原文为准。

↑