RAD:规则增强型关系异常检测
RAD: Rule-Augmented Relational Anomaly Detection
浏览论文内容
中文总结 AI 辅助
研究人员针对关系异常检测中展平数据丢失结构及难融入符号证据的问题,提出RAD方法,结合图表示学习与规则信号,在多基准任务中较现有方法取得更优异常检测性能。
中文摘要 AI 辅助
异常检测常应用于存储在关系型数据库中的数据,但大多数现有方法需要将多个表展平为单个特征矩阵。这种展平会模糊实体身份、模式结构和多跳依赖关系,限制了对依赖关系上下文而非孤立特征值的异常的检测。除了保留关系结构外,关系异常检测还提出了一个额外挑战:如何将符号行为证据融入学习到的关系表示中。为解决这些挑战,我们研究关系异常检测,其目标是识别多表数据库中的异常实体或事件。我们提出RAD,一种规则增强型关系异常检测器,它将异质图表示学习与精细的符号规则信号相结合。RAD从待评分实体或事件的展平摘要上的随机森林路径中推导候选规则,将其细化为紧凑可解释的谓词,将得到的规则特征注入图模型,并使用基于重构和成对排序的监督学习异常分数。为评估该设置,我们引入了一个关系异常检测基准,涵盖三个场景:LANL网络安全事件检测以及从Amazon和H&M关系数据库衍生的两个意外用户流失异常任务。实验表明,在自然类别不平衡条件下,RAD相较于展平表格检测器和关系基线方法提升了异常排序性能,在整个基准测试中在AUROC和AUPRC上取得最佳平均排名。消融实验显示,直接规则注入和基于排序的监督是性能的关键贡献因素,而边重构并非始终有益。我们的代码和数据可在以下网址获取:this https URL。
英文摘要
Anomaly detection is often applied to data stored in relational databases, yet most existing methods require flattening multiple tables into a single feature matrix. This flattening can obscure entity identity, schema structure, and multi-hop dependencies, limiting the detection of anomalies that depend on relational context rather than isolated feature values. Beyond preserving relational structure, relational anomaly detection raises an additional challenge: how to incorporate symbolic behavioral evidence into learned relational representations. To address these challenges, we study relational anomaly detection, where the goal is to identify anomalous entities or events in a multi-table database. We propose RAD, a rule-augmented relational anomaly detector that combines heterogeneous graph representation learning with refined symbolic rule signals. RAD derives candidate rules from random-forest paths over flattened summaries of the entities or events being scored, refines them into compact interpretable predicates, injects the resulting rule features into the graph model, and learns anomaly scores using reconstruction-based and pairwise-ranking supervision. To evaluate this setting, we introduce a relational anomaly detection benchmark spanning three settings: LANL cybersecurity event detection and two unexpected user-churn anomaly tasks derived from Amazon and H&M relational databases. Experiments show that RAD improves anomaly ranking over flattened tabular detectors and relational baselines under natural class imbalance, achieving the best average rank on AUROC and AUPRC across the benchmark. Ablations show that direct rule injection and ranking-based supervision are key contributors to performance, while edge reconstruction is not uniformly beneficial. Our code and data are available at: https://github.com/noahd15/RAD_RelationalAnomalyDetection.
发表机构
- Vanderbilt University(范德堡大学)
机构由 AI 辅助整理,请以论文原文为准。