Anomaly Detection in Attributed Networks via Residual Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anomaly detection methods in attributed networks rely on prior knowledge of anomaly properties, which is often not available, and struggle to handle heterogeneous data sources and interconnected instances, making it difficult to identify anomalies effectively.

Innovation Solution

A processor-configured learning framework that models residuals of attribute information and its coherence with network information to detect anomalies, using a principled approach that reconstructs attribute information and integrates network modeling to rank anomalies based on residual values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing anomaly detection methods use prior knowledge of anomaly properties, then detection can be performed in specific contexts, but the methods cannot handle various types of anomalies in real-world attributed networks where prior knowledge is not available

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs self-service by automatically learning anomaly detection capabilities from the data itself without requiring external prior knowledge. The neural network learns to identify anomalies by processing attributed network data and generating anomaly scores based on learned patterns, making the system adaptable to various anomaly types while maintaining detection reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes parameters by transforming the input data through a neural network that learns optimal parameter representations. The network adjusts internal parameters (weights and biases) during training to capture different anomaly types, enabling the system to handle diverse anomalies without predefined knowledge while maintaining accurate detection

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If attributed networks use heterogeneous data representations, then rich network representation is achieved, but challenges arise for anomaly detection due to heterogeneity of two data representations

Engineering Contradiction:
Improvenetwork representation richnessVSAvoiddata processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system merges heterogeneous data representations by integrating attribute data and network structure data into a unified neural network model. The network processes both types of data simultaneously through shared layers, combining their representations to enable effective anomaly detection while managing the complexity of handling heterogeneous inputs

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The neural network acts as an intermediary that transforms heterogeneous data representations into a common feature space. The network layers serve as mediators that process different data types (attributes and network structures) and convert them into unified representations that can be jointly analyzed for anomaly detection

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If a principled learning framework models residuals of attribute information and coherence with network information, then anomaly detection performance is improved, but the framework complexity increases compared to baseline methods

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidframework complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The framework segments the anomaly detection task into distinct components: attribute residual modeling and network coherence modeling. These segmented functions are implemented as separate but integrated neural network modules, allowing the system to achieve high detection precision through specialized processing while managing overall framework complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11360928B2Systems and methods for improved anomaly detection in attributed networks
Publication Date: 2022.06.14 THE ARIZONA BOARD OF REGENTS ON BEHALF OF THE UNIV OF ARIZONA
  • US11360928B2 patent drawing
  • US11360928B2 patent drawing
  • US11360928B2 patent drawing

AI summary

A processor is configured with a learning framework to characterize the residuals of attribute information and its coherence with network information for improved anomaly detection.