graph anomaly detection

Design and build models, algorithms, and pipelines that detect, score, and rank anomalous nodes, edges, subgraphs, or entire graphs in graph-structured data by leveraging topology, node/edge attributes, and temporal information. This includes methods that operate without labeled anomalies (zero-shot), generalize across datasets or domains (cross-domain / generalized GAD), and produce ranked or scored outputs for downstream alerting or analyst review.

graphanomalydetection

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.43
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

This work addresses the limited generalization of existing graph anomaly detection models in cross-domain settings, which often stems from their reliance on source-domain-specific features and structural patterns. To overcome this challenge, the authors propose AlignGAD, a novel framework that enables zero-shot cross-domain graph anomaly detection without requiring any labeled or unlabeled data from the target domain. AlignGAD achieves this by aligning node features in the spectral domain to unify heterogeneous representations and normalize graph signals, constructing cluster-aware graph views, and aggregating anomaly evidence through multi-view node reconstruction discrepancies. Grounded in spectral graph theory, feature alignment, graph clustering, and multi-view self-supervised learning, AlignGAD demonstrates superior cross-domain generalization, significantly outperforming state-of-the-art methods across multiple real-world datasets.

cross-domaingeneralizationgraph anomaly detection

Zero-shot Generalist Graph Anomaly Detection with Unified Neighborhood Prompts

Oct 18, 2024
CN
Chaoxi Niu
🏛️ University of Technology Sydney | Singapore Management University

Existing graph anomaly detection (GAD) methods rely on single-dataset training and suffer from poor zero-shot generalization across graphs. This paper proposes the first zero-shot universal GAD framework, enabling cross-dataset transfer without retraining or fine-tuning on target graphs. Methodologically, it introduces: (1) a novel zero-shot universal detection paradigm; (2) a unified anomaly score grounded in normalized node attribute predictability; and (3) a transferable unified neighborhood prompting mechanism that integrates coordinate-level projection-space normalization with implicit attribute prediction modeling. Evaluated on multiple real-world graph datasets, the method achieves significant performance gains over diverse baselines under the universal detection setting, while maintaining strong competitiveness under conventional single-dataset training. The framework thus bridges the gap between domain-specific GAD and practical deployment across heterogeneous graph domains.

Develops zero-shot generalist graph anomaly detectionEliminates need for dataset-specific model trainingUses unified neighborhood prompts for cross-dataset generalization

This work addresses the limitations of traditional graph anomaly detection methods, which are constrained by the “one dataset, one model” paradigm and heavily rely on extensive labeled data, thereby hindering generalization. The authors propose ARC and its zero-shot variant ARC_zero—unified frameworks enabling few-shot and zero-shot cross-dataset anomaly detection without dataset-specific customization. These frameworks integrate a feature alignment module, a residual GNN encoder, and cross-attention-based contextual learning, augmented by a pseudo-normal node selection strategy to effectively align cross-graph features and produce anomaly scores. Extensive evaluation across 17 real-world graph datasets demonstrates that the proposed approach achieves strong generalization and high detection performance under both few-shot and zero-shot settings.

Cross-Dataset GeneralizationFew-Shot LearningGeneralist Model

How to use Graph Data in the Wild to Help Graph Anomaly Detection?

Jun 04, 2025
YC
Yuxuan Cao
🏛️ Zhejiang University | Fudan University | WeChat AI | Tencent | Emory University | Finvolution Group

Addressing key challenges in graph anomaly detection—including label scarcity, ambiguous anomaly definitions, and difficulty in modeling normal distribution—this paper proposes Wild-GAD, the first framework to enable cross-domain knowledge transfer using large-scale, heterogeneous “in-the-wild” graph data. Methodologically, it introduces (i) a unified graph database (UniWildGraph) and a shared feature space; (ii) an external graph selection criterion balancing representativeness and diversity; and (iii) an unsupervised transfer learning detection paradigm. Evaluated on six real-world datasets, Wild-GAD achieves average improvements of +18% in AUC-ROC and +32% in AUC-PR over state-of-the-art methods. This work establishes a scalable, annotation-free general enhancement paradigm for low-resource graph anomaly detection.

Addressing label scarcity and ill-defined anomalies in graph dataDeveloping criteria for selecting optimal external graph datasetsUtilizing external graph data to improve anomaly detection

ARC: A Generalist Graph Anomaly Detector with In-Context Learning

May 27, 2024
YL
Yixin Liu
🏛️ Griffith University | Guangxi University | La Trobe University | The Hong Kong Polytechnic University

Existing graph anomaly detection methods suffer from poor generalizability, requiring costly retraining for each new dataset. This work proposes the first zero-shot cross-domain transfer framework for graph anomaly detection, enabling real-time identification of anomalous nodes on unseen graphs using only a few normal samples. Our approach comprises three core innovations: (1) a context-aware learning paradigm tailored to graph structures; (2) a smoothness-aware feature alignment module that enhances cross-domain distribution consistency; and (3) a self-neighbor residual graph neural network coupled with a cross-attention context scoring mechanism, jointly modeling local anomaly sensitivity and global semantic dependencies. Evaluated across diverse benchmark datasets spanning multiple domains, our method significantly outperforms state-of-the-art approaches—achieving up to a 12.6% improvement in detection accuracy—while eliminating the need for task-specific training during inference. The framework thus delivers both strong generalizability and high computational efficiency.

Graph Anomaly DetectionModel GeneralizationResource Consumption

Latest Papers

What's happening recently
View more

This work addresses the challenge of generalizing graph anomaly detection to unseen domains, which is hindered by significant discrepancies in feature semantics and dimensionality across domains. To this end, the authors propose OWLEYE, the first framework enabling zero-shot cross-domain graph anomaly detection. OWLEYE preserves domain-specific semantics through cross-domain feature alignment, captures shared structural and attribute patterns via multi-domain multi-modal dictionary learning, and computes unsupervised, context-aware anomaly scores using a truncated attention-based reconstruction mechanism. Notably, the model requires no retraining on target domains and demonstrates superior performance over existing methods across multiple real-world graph datasets, exhibiting strong generalization capability and scalability.

cross-domaingraph anomaly detectiongraph foundation model

This work addresses the challenge of cross-domain graph anomaly detection, where domain shift often leads to feature misalignment and severely limits model generalization—particularly due to the pronounced anomaly disassortativity (AD) phenomenon, wherein anomalous nodes exhibit distinct connectivity patterns compared to normal ones. The paper formally defines and quantifies AD for the first time and introduces a test-time adaptive graph foundation model that, after a single training phase, generalizes effectively across diverse real-world graph domains without retraining. By integrating graph neural networks, explicit modeling of anomaly disassortativity, and a universal detection architecture, the proposed method achieves state-of-the-art performance across 14 real-world datasets, significantly improving cross-domain anomaly detection accuracy.

anomaly disassortativitycross-domain generalizationdomain shift

Towards Multiple Missing Values-resistant Unsupervised Graph Anomaly Detection

Nov 13, 2025
JC
Jiazhen Chen
🏛️ University of Waterloo | Deloitte Consulting | Huazhong University of Science and Technology | Guizhou University | Cheriton School of Computer Science | Guizhou Normal University

Unsupervised graph anomaly detection fails when both node attributes and structural information are simultaneously missing. Method: We propose the first unified framework robust to multi-value missingness. It employs a dual-path encoder to independently reconstruct attributes and structure, thereby preventing cross-view error propagation. In the joint latent space, we introduce latent-space regularization and joint reconstruction learning, and innovatively design a hard negative sample generation strategy based on latent-space sampling to mitigate anomaly masking caused by imputation and sharpen the decision boundary between normal and anomalous distributions. Results: Extensive experiments on seven benchmark datasets demonstrate that our method significantly outperforms existing unsupervised graph anomaly detection approaches and maintains strong robustness across varying missingness rates.

Detecting anomalies in graphs with missing attributes and structureMitigating imputation bias that masks anomalous patternsPreventing cross-view interference between node and edge reconstruction

This work addresses the challenge of anomaly detection in dynamic graphs, where labeled anomalies are scarce, leading to weak discriminability in unsupervised methods and limited generalization in semi-supervised approaches. To overcome this, the authors propose a model-agnostic framework that encodes residual representations to capture deviations between current interactions and historical context. They introduce a concentric hypersphere-based constrained loss to confine normal sample representations within a bounded region and employ a normalized flow-based dual-boundary optimization strategy to model the likelihood distribution of normal data. By leveraging limited labeled data while preserving strong generalization to unseen anomalies, the method consistently outperforms existing approaches across multiple evaluation settings, demonstrating its effectiveness, robustness, and balanced trade-off between discrimination and generalization.

Anomaly DetectionDiscriminative BoundaryDynamic Graph Anomaly Detection

This work addresses the limitations of existing unsupervised graph anomaly detection methods, which often rely on homophily assumptions and thus underperform on heterophilous graphs. The authors propose NK-GAD, a novel framework that, for the first time, uncovers two key properties in attribute-heterophilous graphs: the convergence of attribute similarity distributions among connected nodes and distinctive patterns in spectral energy variation. Leveraging these insights, NK-GAD introduces a neighbor knowledge enhancement mechanism that employs a joint encoder to integrate information from both similar and dissimilar neighbors. The framework further incorporates neighbor reconstruction, central node aggregation, and dual attribute–structure decoders to enable collaborative reconstruction for effective anomaly detection. Evaluated on seven benchmark datasets, NK-GAD achieves an average AUC improvement of 3.29%, significantly outperforming current state-of-the-art methods.

attribute heterophilygraph anomaly detectiongraph neural networks

Hot Scholars

MG

Ming Gong

Key laboratory of quantum information, USTC
quantum informationquantum dottopological quantum phase transitionultracold atoms
JZ

Junyang Zhang

California Institute of Technology, Stanford University, University of California, Irvine
machine learning and ML systemroboticsdigital designsemiconductor
DA

Darine Ameyed

Université du Québec, École de technologie supérieure Montréal
AI SafetyFederated LearningIoT-Cyber-Physical SecurityAmbient Intelligence
RM

Rui Miao

Meta
NetworkingNetworked SystemsDistributed Systems
NK

Nils Köbis

Professor for Human Understanding of Algorithms and Machines, University Duisburg-Essen
CorruptionMachine BehaviorBehavioral EthicsSynthetic Relationships