Score
Design and build models, algorithms, and pipelines that detect, score, and rank anomalous nodes, edges, subgraphs, or entire graphs in graph-structured data by leveraging topology, node/edge attributes, and temporal information. This includes methods that operate without labeled anomalies (zero-shot), generalize across datasets or domains (cross-domain / generalized GAD), and produce ranked or scored outputs for downstream alerting or analyst review.
Graph anomaly detection (GAD) is critical for security, finance, and other domains, yet existing GNN-based approaches lack systematic organization and a unified analytical framework. To address this, we propose the first comprehensive analysis paradigm grounded in three orthogonal dimensions: GNN backbone design, proxy task construction, and anomaly scoring. We introduce a fine-grained taxonomy comprising 13 categories, decoupling model architecture into backbone networks, pretraining objectives, and anomaly criteria. Integrating GNNs, self-supervised learning, contrastive learning, reconstruction modeling, and multi-scale representation, we establish a reproducible benchmarking suite. Our open-source, continuously updated repository unifies state-of-the-art datasets and algorithms, accompanied by empirical performance comparisons. The study exposes intrinsic limitations of current methods and identifies six key open challenges—providing both theoretical guidance and practical foundations for future GAD research.
This work addresses the limited generalization of existing graph anomaly detection models in cross-domain settings, which often stems from their reliance on source-domain-specific features and structural patterns. To overcome this challenge, the authors propose AlignGAD, a novel framework that enables zero-shot cross-domain graph anomaly detection without requiring any labeled or unlabeled data from the target domain. AlignGAD achieves this by aligning node features in the spectral domain to unify heterogeneous representations and normalize graph signals, constructing cluster-aware graph views, and aggregating anomaly evidence through multi-view node reconstruction discrepancies. Grounded in spectral graph theory, feature alignment, graph clustering, and multi-view self-supervised learning, AlignGAD demonstrates superior cross-domain generalization, significantly outperforming state-of-the-art methods across multiple real-world datasets.
Existing graph anomaly detection (GAD) methods rely on single-dataset training and suffer from poor zero-shot generalization across graphs. This paper proposes the first zero-shot universal GAD framework, enabling cross-dataset transfer without retraining or fine-tuning on target graphs. Methodologically, it introduces: (1) a novel zero-shot universal detection paradigm; (2) a unified anomaly score grounded in normalized node attribute predictability; and (3) a transferable unified neighborhood prompting mechanism that integrates coordinate-level projection-space normalization with implicit attribute prediction modeling. Evaluated on multiple real-world graph datasets, the method achieves significant performance gains over diverse baselines under the universal detection setting, while maintaining strong competitiveness under conventional single-dataset training. The framework thus bridges the gap between domain-specific GAD and practical deployment across heterogeneous graph domains.
This work addresses the limitations of traditional graph anomaly detection methods, which are constrained by the “one dataset, one model” paradigm and heavily rely on extensive labeled data, thereby hindering generalization. The authors propose ARC and its zero-shot variant ARC_zero—unified frameworks enabling few-shot and zero-shot cross-dataset anomaly detection without dataset-specific customization. These frameworks integrate a feature alignment module, a residual GNN encoder, and cross-attention-based contextual learning, augmented by a pseudo-normal node selection strategy to effectively align cross-graph features and produce anomaly scores. Extensive evaluation across 17 real-world graph datasets demonstrates that the proposed approach achieves strong generalization and high detection performance under both few-shot and zero-shot settings.
Addressing key challenges in graph anomaly detection—including label scarcity, ambiguous anomaly definitions, and difficulty in modeling normal distribution—this paper proposes Wild-GAD, the first framework to enable cross-domain knowledge transfer using large-scale, heterogeneous “in-the-wild” graph data. Methodologically, it introduces (i) a unified graph database (UniWildGraph) and a shared feature space; (ii) an external graph selection criterion balancing representativeness and diversity; and (iii) an unsupervised transfer learning detection paradigm. Evaluated on six real-world datasets, Wild-GAD achieves average improvements of +18% in AUC-ROC and +32% in AUC-PR over state-of-the-art methods. This work establishes a scalable, annotation-free general enhancement paradigm for low-resource graph anomaly detection.
Existing graph anomaly detection methods suffer from poor generalizability, requiring costly retraining for each new dataset. This work proposes the first zero-shot cross-domain transfer framework for graph anomaly detection, enabling real-time identification of anomalous nodes on unseen graphs using only a few normal samples. Our approach comprises three core innovations: (1) a context-aware learning paradigm tailored to graph structures; (2) a smoothness-aware feature alignment module that enhances cross-domain distribution consistency; and (3) a self-neighbor residual graph neural network coupled with a cross-attention context scoring mechanism, jointly modeling local anomaly sensitivity and global semantic dependencies. Evaluated across diverse benchmark datasets spanning multiple domains, our method significantly outperforms state-of-the-art approaches—achieving up to a 12.6% improvement in detection accuracy—while eliminating the need for task-specific training during inference. The framework thus delivers both strong generalizability and high computational efficiency.
This work addresses the challenge of generalizing graph anomaly detection to unseen domains, which is hindered by significant discrepancies in feature semantics and dimensionality across domains. To this end, the authors propose OWLEYE, the first framework enabling zero-shot cross-domain graph anomaly detection. OWLEYE preserves domain-specific semantics through cross-domain feature alignment, captures shared structural and attribute patterns via multi-domain multi-modal dictionary learning, and computes unsupervised, context-aware anomaly scores using a truncated attention-based reconstruction mechanism. Notably, the model requires no retraining on target domains and demonstrates superior performance over existing methods across multiple real-world graph datasets, exhibiting strong generalization capability and scalability.
This work addresses the challenge of cross-domain graph anomaly detection, where domain shift often leads to feature misalignment and severely limits model generalization—particularly due to the pronounced anomaly disassortativity (AD) phenomenon, wherein anomalous nodes exhibit distinct connectivity patterns compared to normal ones. The paper formally defines and quantifies AD for the first time and introduces a test-time adaptive graph foundation model that, after a single training phase, generalizes effectively across diverse real-world graph domains without retraining. By integrating graph neural networks, explicit modeling of anomaly disassortativity, and a universal detection architecture, the proposed method achieves state-of-the-art performance across 14 real-world datasets, significantly improving cross-domain anomaly detection accuracy.
Unsupervised graph anomaly detection fails when both node attributes and structural information are simultaneously missing. Method: We propose the first unified framework robust to multi-value missingness. It employs a dual-path encoder to independently reconstruct attributes and structure, thereby preventing cross-view error propagation. In the joint latent space, we introduce latent-space regularization and joint reconstruction learning, and innovatively design a hard negative sample generation strategy based on latent-space sampling to mitigate anomaly masking caused by imputation and sharpen the decision boundary between normal and anomalous distributions. Results: Extensive experiments on seven benchmark datasets demonstrate that our method significantly outperforms existing unsupervised graph anomaly detection approaches and maintains strong robustness across varying missingness rates.
This work addresses the challenge of anomaly detection in dynamic graphs, where labeled anomalies are scarce, leading to weak discriminability in unsupervised methods and limited generalization in semi-supervised approaches. To overcome this, the authors propose a model-agnostic framework that encodes residual representations to capture deviations between current interactions and historical context. They introduce a concentric hypersphere-based constrained loss to confine normal sample representations within a bounded region and employ a normalized flow-based dual-boundary optimization strategy to model the likelihood distribution of normal data. By leveraging limited labeled data while preserving strong generalization to unseen anomalies, the method consistently outperforms existing approaches across multiple evaluation settings, demonstrating its effectiveness, robustness, and balanced trade-off between discrimination and generalization.
This work addresses the limitations of existing unsupervised graph anomaly detection methods, which often rely on homophily assumptions and thus underperform on heterophilous graphs. The authors propose NK-GAD, a novel framework that, for the first time, uncovers two key properties in attribute-heterophilous graphs: the convergence of attribute similarity distributions among connected nodes and distinctive patterns in spectral energy variation. Leveraging these insights, NK-GAD introduces a neighbor knowledge enhancement mechanism that employs a joint encoder to integrate information from both similar and dissimilar neighbors. The framework further incorporates neighbor reconstruction, central node aggregation, and dual attribute–structure decoders to enable collaborative reconstruction for effective anomaly detection. Evaluated on seven benchmark datasets, NK-GAD achieves an average AUC improvement of 3.29%, significantly outperforming current state-of-the-art methods.