🤖 AI Summary
This paper addresses the problem of sequential anomaly detection in a multi-process dynamic system: normal processes remain perpetually in a zero (quiescent) state, whereas anomalous processes evolve their latent states over time according to a Markov chain; observations are obtained only by sequentially probing a subset of processes, and each probe’s outcome depends stochastically on the probed process’s current latent state. Departing from conventional i.i.d. observation assumptions, we introduce, for the first time, a hidden Markov model (HMM) into this sequential search framework. We propose ADHM—an adaptive probing algorithm that jointly models latent-state evolution and observation uncertainty via Bayesian belief updating and statistical evidence accumulation. We establish its asymptotic optimality and derive a fundamental oracle lower bound on detection delay. Simulation results demonstrate that, under strict false-alarm probability constraints, ADHM reduces the average detection time by 32% compared to state-of-the-art methods.
📝 Abstract
We address the problem of detecting an anomalous process among a large number of processes. At each time t, normal processes are in state zero (normal state), while the abnormal process may be in either state zero (normal state) or state one (abnormal state), with the states being hidden. The transition between states for the abnormal process is governed by a Markov chain over time. At each time step, observations can be drawn from a selected subset of processes. Each probed process generates an observation depending on its hidden state, either a typical distribution under state zero or an abnormal distribution under state one. The objective is to design a sequential search strategy that minimizes the expected detection time, subject to an error probability constraint. In contrast to prior works that assume i.i.d. observations, we address a new setting where anomalies evolve according to a hidden Markov model. To this end, we propose a novel algorithm, dubbed Anomaly Detection under Hidden Markov model (ADHM), which dynamically adapts the probing strategy based on accumulated statistical evidence and predictive belief updates over hidden states. ADHM effectively leverages temporal correlations to focus sensing resources on the most informative processes. The algorithm is supported by an asymptotic theoretical foundation, grounded in an oracle analysis that characterizes the fundamental limits of detection under the assumption of a known distribution of the hidden states. In addition, the algorithm demonstrates strong empirical performance, consistently outperforming existing methods in extensive simulations.