Interpretable Anomaly and Drift Detection with Gaussian Mixture Models

📅 2026-07-18
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work proposes a unified and interpretable Gaussian Mixture Model (GMM) framework for simultaneously performing anomaly detection and distribution drift identification in data streams. The approach automatically selects the number of mixture components via the Bayesian Information Criterion, initializes components using k-means, and sets anomaly thresholds by combining negative log-likelihood with Extreme Value Theory. Drift intensity is quantified by the proportion of data not covered by existing components. Each alert is accompanied by an intuitive explanation: anomalies correspond to points significantly deviating from known mechanisms (3–10σ from the nearest cluster), while drift reflects an increasing proportion of observations governed by previously unseen mechanisms. Evaluated on seven benchmarks, the method matches state-of-the-art performance in anomaly detection and achieves drift detection accuracy comparable to Maximum Mean Discrepancy (MMD) when novel mechanisms emerge, with all outputs remaining inherently interpretable.
📝 Abstract
We revisit Gaussian Mixture Models (GMMs) as a lightweight, interpretable tool for anomaly detection and, in particular, for detecting distributional drift in data streams. We make three practical choices explicit and evaluate them on seven public benchmarks. First, the number of mixture components is selected automatically by the Bayesian Information Criterion, initialised by k-means, removing the need to fix it in advance. Second, individual observations are scored by their negative log-likelihood under a GMM fitted to normal data, with thresholds set at a target false-alarm rate using Extreme Value Theory. Third, the same interpretable model extends to distributional drift: each Gaussian component is a named "regime," and the fraction of a stream window that matches no regime -- its unexplained mass -- is a drift signal that is itself the explanation. We benchmark this against a model-free kernel two-sample test (Maximum Mean Discrepancy, MMD) and against two GMM-to-GMM divergences (a closed-form Cauchy-Schwarz divergence and a matching-based KL surrogate). Across seven benchmarks ranging from 3 to 64 dimensions and five random splits, the GMM point detector is competitive with -- though rarely more accurate than -- Isolation Forest, Local Outlier Factor, one-class SVM, ECOD, COPOD and an autoencoder, while uniquely yielding an interpretable model. For drift, MMD is the strongest pure detector, but the interpretable unexplained-mass statistic matches it when anomalies form novel regimes (and honestly fails, as MMD does not, when drift is a pure re-weighting of existing regimes). Every alarm is explainable: anomalies lie a median of 3-10 sigma outside their nearest regime vs. about 1 sigma for normal points, and a drift alarm reports the fraction of the window matching no known regime. All code and experiments are released.
Problem

Research questions and friction points this paper is trying to address.

anomaly detection
distributional drift
interpretable models
data streams
Gaussian Mixture Models
Innovation

Methods, ideas, or system contributions that make the work stand out.

Gaussian Mixture Models
Interpretable Anomaly Detection
Distributional Drift
Unexplained Mass
Extreme Value Theory
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
B
Behnam Asadi