面向可泛化动态图异常检测的在线测试时适应
Online Test-Time Adaptation for Generalizable Dynamic Graph Anomaly Detection
- The Hong Kong Polytechnic University(香港理工大学)
- Institute of Information Processing and Automation, Zhejiang University of Technology(浙江工业大学信息处理与自动化研究所)
- University of Illinois at Chicago (UIC)(伊利诺伊大学芝加哥分校)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
针对可泛化动态图异常检测现有方法的局限,提出OTTA-DGAD方法,通过时序自图提取动态原型并结合内存缓冲区,在10个真实世界数据集上实现了最优性能。
AI中文摘要:
可泛化动态图异常检测(DGAD)使预训练检测器无需高昂的再训练成本即可识别未见目标域中的异常。但现有方法常因两点失效:一是主要依赖域无关模式,遗漏不断演化的域特定模式;二是假设可获取完整目标域数据,而更实际的在线测试时适应场景中,目标数据以无标签块的形式顺序到达。为解决这些局限,我们将在线测试时适应形式化为可泛化DGAD问题,并提出OTTA-DGAD方法。OTTA-DGAD首先从时序自图中提取动态原型(即正常与异常模式的演化表示)并存储于内存缓冲区;该缓冲区选择性保留预训练所用源域间共享的通用模式,同时纳入目标域的新模式。异常评分器随后将传入边表示与这些原型比对,以识别通用及域特定异常。适应过程中,OTTA-DGAD通过基于置信度的检测识别出的可靠伪标签更新内存缓冲区,还利用前序块保留的相关表示丰富每个目标块,弥补数据顺序到达导致的信息损失。在严格的先测试后适应OTTA设置下开展的大量实验,于来自不同领域的10个真实世界数据集上展现出了最先进的性能。
英文摘要:
Generalizable dynamic graph anomaly detection (DGAD) enables pretrained detectors to identify anomalies in unseen target domains without costly retraining. However, existing methods often fail for two reasons. First, they mainly rely on domain-agnostic patterns and miss domain-specific patterns that keep evolving. Second, they assume access to the full target domain data, whereas in more practical online test-time adaptation settings, target data arrive sequentially in unlabeled chunks. To address these limitations, we formulate online test-time adaptation for generalizable DGAD and propose OTTA-DGAD. OTTA-DGAD first extracts dynamic prototypes, i.e., evolving representations of normal and anomalous patterns, from temporal ego-graphs and stores them in a memory buffer. The buffer selectively retains general patterns shared across the source domains used for pretraining while incorporating new patterns from the target domain. An anomaly scorer then compares incoming edge representations against these prototypes to identify both general and domain-specific anomalies. During adaptation, OTTA-DGAD updates the memory buffer using reliable pseudo-labels identified through confidence-based detection. It further enriches each target chunk with relevant representations retained from previous chunks, compensating for information loss resulting from the sequential arrival of data. Extensive experiments under strict test-then-adapt OTTA settings demonstrate state-of-the-art performance on ten real-world datasets from diverse domains.