Characteristic decomposition enhancement-based graph anomaly detection method
By calculating the feature decomposition of the adjacency matrix of the graph and combining the node feature matrix, the graph data information is optimized, and the existing graph abnormality detection methods ignore neighborhood information is solved, which improves detection performance and adapts to various methods.
Patent Information
- Application Number
- CN202510198072.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-05-23
AI Technical Summary
Existing graph anomaly detection methods ignore neighborhood information contained in the eigenvectors, resulting in poor performance on the actual data set.
By calculating the feature decomposition of the adjacency matrix of the graph, selecting the feature vectors related to the larger eigenvalues to capture important structural information in the graph, and combining the node feature matrix to optimize the information of the graph data, and integrating it into existing methods for abnormal detection.
By using neighbor information in the feature vector, the degree of abnormality of nodes is linearly increased, the performance of graph abnormality detection is improved, and a variety of graph abnormality detection methods are adapted.
Smart Images

Figure CN120030390A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to graph anomaly detection, and in particular to a graph anomaly detection method based on feature decomposition enhancement. Background Art
[0002] Graph anomaly detection is a method for identifying abnormal nodes, edges or subgraphs in graph data. In complex networks such as social networks, communication networks and biological networks, they can discover abnormal behaviors or structures, conduct problem troubleshooting and early warning of potential threats. Graph anomaly detection has received widespread attention. The current mainstream graph anomaly detection algorithms are mainly as follows:
[0003] The most commonly used graph anomaly detection method is the graph autoencoder, which converts graph data into node embeddings and detects the degree of anomaly by evaluating the difference between the reconstructed information and the original data. DOMINANT proposed by Liu in "Deep anomaly detection on attributed networks" in 2019. AnomalyDAE proposed by Fan et al. in "Anomalydae: Dual Autoencoder for Anomaly Detection on Attributed Networks" in 2020 uses dual autoencoders with attention mechanisms to capture the interaction between network structure and node attributes for anomaly detection. GAAN proposed by Chen et al. in "Generative Adversarial Attributed Network Anomaly Detection" in 2020 adopts a generative adversarial framework, combining generators, encoders and discriminators, and uses reconstruction errors and confidence to detect anomalies. CoLA proposed by Liu et al. in "Anomaly Detection on Attributed Networks via Contrastive Self-Supervised Learning" in 2022 introduces a self-supervised learning framework that uses instance pair sampling and contrastive learning based on graph neural networks to enhance scalability and effectively detect anomalies. CONAD proposed by Xu et al. in "Contrastive Attributed Network Anomaly Detection with Data Augmentation" in 2022 integrates human knowledge of anomaly types through data augmentation and Siamese GNN encoder with contrastive loss, achieving excellent performance on real-world datasets. GAD-NR proposed by Roy et al. in "GAD-NR: Graph Anomaly Detection via Neighborhood Reconstruction" in 2024 uses neighborhood reconstruction to capture local structure, own properties, and neighborhood properties, and is good at detecting various anomaly types in datasets. However, most existing graph anomaly detection methods ignore the neighborhood information contained in the feature vector, which usually leads to poor performance on real datasets. Summary of the invention
[0004] In view of the problems existing in the prior art, the purpose of the present invention is to propose a graph anomaly detection method based on eigendecomposition enhancement. This is a new plug-and-play method that uses the neighbor information encoded in the eigenvector of the adjacency matrix to enhance the performance of existing methods in graph anomaly detection. Theoretical analysis of eigenvectors shows that the components of the eigenvector of each node can be represented by the linear average of the eigenvectors of its corresponding neighbors. In addition, it is proved that merging eigenvectors will linearly increase the degree of abnormality of the node, providing a theoretical basis for using graph information in anomaly detection. By combining eigenvectors and node feature matrices, the information of graph data is optimized and integrated into existing methods, and finally the final prediction result is given. The present invention can also help to better design graph anomaly monitoring methods in complex scenarios, improve the performance of existing methods, and can be adapted to a variety of graph anomaly detection methods.
[0005] In order to achieve the above object, the technical solution adopted by the present invention is as follows:
[0006] A graph anomaly detection method based on eigendecomposition enhancement calculates the vector of the eigendecomposition of the graph adjacency matrix. Select eigenvectors associated with larger eigenvalues to capture important structural information in the graph, thereby improving the performance of anomaly detection. By selecting some eigenvectors, a balance is achieved between retaining structural information and reducing complexity, improving the anomaly detection effect and reducing costs; by combining eigenvectors and node feature matrices, the information of graph data is optimized and integrated into existing methods to give abnormal results. The specific steps are as follows:
[0007] Step (1): Read the graph data and obtain the node feature matrix and graph adjacency matrix in the dataset;
[0008] Step 1.1) Basic concept of graph
[0009] The figure is represented as in Represents a node set, there are n nodes, and A∈{0,1} n×n is the graph adjacency matrix. Represents the node feature matrix, where d is the dimension of the node feature. For the i-th node v in the graph i , Indicates v i The graph information of the graph adjacency matrix A contains its structural information. Since A is a symmetric matrix, let the eigendecomposition result be And U=(u 1 ,u 2 ,…,u n ),in Then Λ=diag(λ 1 ,λ 2 ,......,λ n) is a diagonal matrix, where λ i is the i-th eigenvalue of A, u i is the i-th eigenvector of A.
[0010] Step 1.2) Content and proof of Theorem 1: For the eigenvector u of the adjacency matrix A i , whose jth vector component u i,j Equal to node v j The linear average of the vectors corresponding to the neighboring nodes of . Theorem 1 reveals the approximate relationship between anomaly detection and adjacency matrix graph.
[0011] The proof process is as follows:
[0012] Assumptions Because Au i =λ i u i ,so,
[0013]
[0014] in, represents the j-th row vector of A; Indicates u i The kth component of .
[0015] After the proof, Theorem 1 holds.
[0016] Step 1.3) Neighborhood anomaly score definition;
[0017] Definition: Node v i The abnormal score of neighbor information is For a normal node v i , whose characteristics are usually similar to those of its neighbor nodes, while those of abnormal nodes are different. This deviation is called the abnormality of neighbor information. i Neighborhood information anomaly score The higher the probability that the node is abnormal, the higher the probability that the node is abnormal. For example, for graph convolution, for the i-th eigenvector u of the adjacency matrix i , the encoder is formalized as:
[0018]
[0019] The decoder obtains the reconstructed feature vector u′ i , the process is formalized as:
[0020]
[0021] This also shows The approximate relationship between the eigenvector components of the adjacency matrix and these eigenvector components can be used to calculate the neighbor information abnormality.
[0022] Step 1.4) Theorem 2 content and proof: The insertion of eigenvectors has a linearly increasing effect on the degree of abnormality of neighbor information. For a positive integer m, the matrix consisting of eigenvectors corresponding to m eigenvalues of any size in For U m The jth eigenvalue of any size in The corresponding eigenvectors are The proof is as follows:
[0023] Using mathematical induction, we first prove that the basic case m = 1 holds. have:
[0024]
[0025] Among them, X′ represents the reconstructed prediction of the node feature matrix X obtained by the encoder and decoder, Represents the pair obtained by the encoder and decoder Reconstruction prediction of Represents eigenvalues of any size The corresponding eigenvector;
[0026] Therefore, the conclusion holds when m = 1. Then, assume that the conclusion is true when m = s, for a matrix consisting of s arbitrary eigenvectors have
[0027]
[0028] So, for have
[0029]
[0030] Among them, U′ s and Respectively represent U s and The reconstructed prediction values from the encoder and decoder are is the s+1th eigenvalue of any size The corresponding eigenvector;
[0031] Therefore, the conclusion holds. In summary, Theorem 2 holds for all positive integers m. Therefore, the addition of eigenvectors has a linearly increasing effect on the degree of abnormality of neighborhood information.
[0032] Step (2): Calculate the eigendecomposition of the graph adjacency matrix and select the corresponding eigenvectors based on some eigenvalues
[0033] Step 2.1) Perform eigendecomposition on the adjacency matrix A To extract graph information. According to Theorem 1, the eigenvector of the adjacency matrix can contain neighbor information, and each vector component reflects the linear average of its neighbor nodes. To exploit this feature, a subset of feature vectors is selected as the representation of neighbor information, namely
[0034] Step 2.2) According to Theorem 2, in the message passing graph learning anomaly detection method, selecting any feature vector will increase the node υ i The mismatch between the abnormal node and its neighbors is used to increase the degree of anomaly. For example, when using graph convolution or similar message passing operators, this representation will amplify the mismatch between the abnormal node and its neighbors, thereby improving the anomaly detection performance.
[0035] Step 2.3) In order to balance computational efficiency and detection performance, only the eigenvectors corresponding to the first t largest eigenvalues are selected for testing. First, the first t eigenvalues λ are calculated in descending order by the Arnoldi iteration algorithm. 1 ,λ 2 ,......,λ t and its corresponding eigenvector u 1 ,u 2 ,…,u t . Avoiding the calculation of all eigenvectors reduces the computational complexity.
[0036] Step (3): Add the selected feature vectors to the node feature matrix of the graph for merging. The merged node feature matrix is used in the existing anomaly detection method and optimized.
[0037] Step 3.1) Concatenate the feature vector and the original node feature matrix of the graph X||U t , where U t =(u 1 ,u 2 ,…,u t ), As the new node feature matrix.
[0038] Step 3.2) Select an existing graph anomaly detection method. For existing message passing-based graph anomaly detection methods (such as convolution-based methods), the node feature matrix X is transformed into a low-dimensional embedding Z through the encoder transformation, and the process is formalized as
[0039] H (1) =AX,
[0040] H (2) =A 2 X,
[0041] Z=H (3) =A 3 X,
[0042] The decoder aims to recover the network structure and node features. The structure decoder predicts the adjacency matrix A using the following method:
[0043]
[0044] The decoder of node features expresses the node feature matrix X′ as:
[0045] X′=A 4 X
[0046] The overall loss function is expressed as:
[0047]
[0048] Where α is a hyperparameter used for balancing. The abnormal score of the node is calculated according to the reconstruction error of the node, so that the score of the abnormal node is higher.
[0049] Step 3.2) Use the method in step 3.1 to enhance the node feature X to X||U t , then test and output the enhanced results.
[0050] Compared with the existing methods, the present invention has the following beneficial effects: the present invention is a new plug-and-play method that uses the neighbor information encoded in the eigenvector of the adjacency matrix to enhance the performance of the existing methods on graph anomaly detection. Theoretical analysis of the eigenvector shows that the components of the eigenvector of each node are related to the neighboring nodes. In addition, it is proved that the use of eigenvectors can linearly increase the degree of abnormality of nodes, providing a theoretical basis for using graph information in anomaly detection. By combining eigenvectors and node feature matrices, the information of graph data is optimized and integrated into a variety of existing methods. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 It is the basic framework of the graph anomaly detection method based on feature decomposition enhancement of the present invention. DETAILED DESCRIPTION
[0052] The specific implementation of the present invention is further described below in conjunction with the accompanying drawings and technical solutions.
[0053] In order to make the technical problems solved by the present invention, the technical solutions adopted and the technical effects achieved clearer, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It is understood that the specific embodiments described herein are only used to explain the present invention, rather than to limit the present invention. It should also be noted that, for the convenience of description, only the parts related to the present invention are shown in the accompanying drawings, rather than all the contents.
[0054] The specific implementation of the present invention is divided into four steps: (1) reading graph data and preprocessing; (2) calculating the eigendecomposition of the graph adjacency matrix, and selecting the eigenvectors corresponding to the top t largest eigenvalues, and merging them into the node feature matrix; (3) applying the merged node feature matrix to the existing anomaly detection method and optimizing it;
[0055] The first step is to read the data in the graph dataset and obtain the nodes and adjacency matrix.
[0056] Read the data set and obtain the node feature matrix X and graph adjacency matrix A in the data set.
[0057] The second step is to extract the feature decomposition information and select some feature vectors to add to the node features of the graph.
[0058] 2.1) Using the Arnoldi iteration algorithm, obtain the first t largest eigenvalues λ 1 ,λ 2 ,......,λ t The corresponding eigenvector u 1 ,u 2 ,…,u t .
[0059] 2.2) Combine the feature vector and the original node feature matrix of the graph into X||U t , where U t =(u 1 ,u 2 ,…,u t ) as the new node feature matrix.
[0060] The third step is to transform the new node feature matrix X||U t Apply to existing anomaly detection algorithms and optimize them.
[0061] 3.1) Taking DOMINANT as an example, obtain the reconstructed adjacency matrix A′ and node feature matrix X′.
[0062] 3.2) Calculate the anomaly detection loss function And use Adam optimizer to continuously train and optimize the model.
[0063] 3.4) Obtain the optimized model and output the prediction results of node anomaly detection.
[0064] In combination with the scheme of the present invention, the experimental analysis is carried out as follows:
[0065] This method uses a commonly used public graph dataset containing anomalies and tests the current mainstream graph anomaly detection methods to evaluate the effectiveness of the present invention.
[0066] (1) Introduction to graph anomaly detection dataset
[0067] The performance of this optimized model is tested on 8 public datasets. The detailed information of the datasets is shown in Table 1:
[0068] Table 1 Dataset statistics
[0069] Dataset Nodes Edges Feat Anomalies Ratio Books 1,418 3,695 21 28 1.97% Enron 13,533 176,987 18 5 0.04% Cora 2,708 5,429 1,433 150 5.54% Citeseer 3,327 4,732 3,703 150 4.51% Pubmed 19,717 88,648 500 600 3.04% ACM 16,484 71,980 8,337 597 3.62% BlogCatalog 5,196 171,743 8,189 300 5.77% DBLP 5,484 8,117 6,775 273 4.98%
[0070] The datasets are introduced as follows. Book is a graph dataset from Amazon that uses user-provided labels. The label amazonfail is the label of the outlier, reflecting the different opinions of users on the sales ranking. 28 nodes are marked as abnormal. Enron is a communication network dataset that forms edges between email addresses. Each node has 18 attributes, including summary information about the average length of email content, the number of recipients, and the time interval between emails. Cora, Citeseer, Pubmed, and ACM are all citation networks. Nodes represent articles and edges represent citation relationships. The attributes of each node are bag-of-words representations determined by the size of the dictionary. BlogCatalog is a social network dataset from the BlogCatalog blog sharing platform. Nodes represent users and edges represent relationships. User-generated content, such as blog posts and tagged photos, is used as node features. DBLP is a citation network consisting of 5,484 scientific publications in the DBLP computer science literature. The dataset contains 8,117 edges representing citation relationships, and node features are extracted from article titles.
[0071] (2) Experimental results of this method in mainstream methods
[0072] The experimental results of this method in mainstream methods are shown in Table 2. Tests were conducted on 8 methods, and the evaluation index was ROC-AUC. MLPAE and GCNAE are models that use multi-layer perceptron models and graph convolutional networks as encoders and decoders. Only the node feature matrix is reconstructed, which is usually used as a baseline model for comparison. DOMINANT chooses GCN as the encoder, but reconstructs the adjacency matrix and node features in different ways. AnomalyDAE uses a joint learning method to learn node representation using an attention mechanism. GAAN uses a generative adversarial network to apply to graph anomaly detection tasks. CONAD combines prior knowledge to assist in the discovery of anomalies, while GADNR focuses on communities and local structures to improve the detection of various types of anomalies.
[0073] Table 2 ROC-AUC scores tested on mainstream anomaly detection methods (%)
[0074]
[0075] From the results in Table 2, we can see that the anomaly detection algorithms incorporating this method have achieved improved performance. The results on different graph anomaly detection algorithms and different data sets show the effectiveness and applicability of this method in the field of graph anomaly detection.
[0076] The above-described embodiments merely express the implementation methods of the present invention, but they cannot be understood as limiting the scope of the patent of the present invention. It should be pointed out that for those skilled in the art, several modifications and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention.
Claims
1. A graph anomaly detection method based on feature decomposition enhancement, characterized in that: The following steps are involved: (1) Read graph data and obtain the node feature matrix and graph adjacency matrix in the dataset; (2) Calculate the eigendecomposition of the graph adjacency matrix and select the corresponding eigenvectors based on some eigenvalues; (3) The selected feature vectors are added to the node feature matrix of the graph for merging. The merged node feature matrix is used in the existing anomaly detection method and optimized.
2. The method for detecting anomalies in a graph based on feature decomposition enhancement according to claim 1, characterized in that The step (1) comprises: Step 1.1) Basic concept of graph The figure is represented as in Represents a node set, there are n nodes, and A∈{0,1} n×n is the graph adjacency matrix; Represents the node feature matrix, where d is the dimension of the node feature; for the i-th node v in the graph i , Indicates v i The neighborhood node set of the graph adjacency matrix A contains its structural information. Since A is a symmetric matrix, the characteristic decomposition result is And U=(u1,u2,…,u n ),in Then Λ=diag(λ1,λ2,...,λ n ) is a diagonal matrix, where λ i is an eigenvalue of A, u i is the eigenvector of A; Step 1.2) Content and proof of Theorem 1: For the eigenvector u of the adjacency matrix A i , whose jth vector component u i,j Equal to node v j The linear average of the vectors corresponding to the neighboring nodes of; Theorem 1 reveals the approximate relationship between anomaly detection and adjacency matrix graph; The proof process is as follows: set up Because Au i =λ i u i ,so, in, represents the j-th row vector of A; Indicates u i The kth component of ; After the proof, Theorem 1 is established; Step 1.3) Neighborhood anomaly score definition; Definition: Node v i The abnormal score of neighbor information is For a normal node v i , its node features are similar to those of its neighbor nodes, while those of abnormal nodes are different; this deviation is called the abnormality of neighbor information; v i Neighborhood information anomaly score high, the probability that the node is abnormal is high; for graph convolution, for the i-th eigenvector u of the adjacency matrix i , the encoder is formalized as: The decoder obtains the reconstructed feature vector u′ i , the process is formalized as: This also shows The approximate relationship between the eigenvector components of the adjacency matrix, and these eigenvector components can be used to calculate the abnormality of neighbor information; Step 1.4) Theorem 2 content and proof: The insertion of eigenvectors has a linearly increasing effect on the degree of abnormality of neighbor information; for a positive integer m, the matrix consisting of eigenvectors corresponding to m eigenvalues of any size in For U m The jth eigenvalue of any size in The corresponding eigenvectors are The proof is as follows: Using mathematical induction, we first prove that the basic case m = 1 holds; have: Where X′ represents the reconstructed prediction of X obtained by the encoder and decoder, Represents the pair obtained by the encoder and decoder Reconstruction prediction of Represents eigenvalues of any size The corresponding eigenvector; Therefore, the conclusion holds when m = 1; then, assuming that the conclusion is true when m = s, for a matrix consisting of s arbitrary eigenvectors have So, for have Among them, U′ s and Respectively represent U s and The reconstructed prediction values from the encoder and decoder are is the s+1th eigenvalue of any size The corresponding eigenvector; Therefore, the conclusion holds; in summary, Theorem 2 holds for all positive integers m; therefore, the addition of eigenvectors has a linearly increasing effect on the degree of abnormality of neighborhood information.
3. The method for detecting anomalies in a graph based on feature decomposition enhancement according to claim 2, characterized in that: The step (2) specifically includes: Step 2.1) Perform eigendecomposition on the adjacency matrix A To extract graph information; According to Theorem 1, the eigenvector of the adjacency matrix can contain neighbor information, and each vector component reflects the linear average of its neighbor nodes A subset of feature vectors is selected as the representation of neighbor information, namely Step 2.2) According to Theorem 2, in the message passing graph learning anomaly detection method, selecting any feature vector will increase the node v i The mismatch between the information of its neighbors increases the degree of anomaly; Step 2.3) In order to balance the computational efficiency and detection performance, only the eigenvectors corresponding to the first t largest eigenvalues are selected for testing; first, the first t eigenvalues λ1,λ2,......,λ are calculated in descending order by the Arnoldi iteration algorithm. t and its corresponding eigenvectors u1,u2,…,u t ; Avoiding the calculation of all eigenvectors reduces the computational complexity.
4. The method for detecting anomalies in a graph based on feature decomposition enhancement according to claim 3, characterized in that: The step (3) specifically includes: Step 3.1) Concatenate the feature vector and the original node feature matrix of the graph X||U t , where U t =(u1,u2,…,u t ) is the matrix composed of the eigenvectors corresponding to the first t eigenvalues after eigendecomposition. As a new node feature matrix; Step 3.2) Select an existing graph anomaly detection method; for the existing message passing-based graph anomaly detection method, the node feature matrix X is transformed into a low-dimensional embedding Z through the encoder transformation, and the process is formalized as H (1) =AX, H (2) =A 2 X, Z=H (3) =A 3 x, The decoder aims to recover the network structure and node features; the structural decoder predicts the adjacency matrix A using the following method: The decoder represents the node feature matrix x′ as: x′=A 4 X The overall loss function is expressed as: Where α is a hyperparameter used for balancing; the abnormal score of the node is calculated based on the reconstruction error of the node, so that the score of the abnormal node is higher; Step 3.3) Use the method in step 3.1) to enhance the node feature X to X||U t , then test and output the enhanced results.