build anomaly detection systems

Designs, implements, and evaluates systems that detect, score, and surface anomalous or novel observations and behavioral patterns in data, using statistical and machine‑learning methods (including unsupervised and novelty-detection techniques) and algorithms tailored to time-series, batch, or streaming inputs. Builds the models, algorithms, thresholds, and end-to-end pipelines required for online/real-time or offline anomaly detection deployments, including model selection, evaluation, and integration with downstream alerting or response workflows.

buildanomalydetectionsystems

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
-1.02
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$195K/year
Oct 01, 2026Oct 01, 2026

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

Current time-series anomaly detection research predominantly focuses on static, batch-processing settings, overlooking critical industrial requirements—namely, streaming computation, human-in-the-loop interaction, point-process modeling, conditional anomaly identification, and multi-series collective analysis. Method: This paper systematically identifies five long-neglected industrial challenges and introduces two novel paradigms: *conditional anomalies* and *collective time-series analysis*. We propose an interpretable, interactive, and scalable framework integrating stream processing architecture, interactive feedback mechanisms, point-process statistical modeling, conditional dependency graph learning, and collective clustering techniques. Contribution/Results: Our work establishes a practical industrial adoption roadmap, catalyzes the development of new benchmark datasets and standardized evaluation protocols, and bridges the gap between theoretical research and real-world deployment in time-series anomaly detection.

Addressing gaps in time-series anomaly detectionExploring practical relevance in cloud systemsMotivating research in streaming and human-involved algorithms

Real-time detection of unknown attacks in dynamic network threat environments remains challenging, and conventional offline methods suffer from delayed retraining. Method: This paper investigates unsupervised streaming anomaly detection on process-level security event streams, leveraging the eBPF-collected BETH dataset. We systematically evaluate ten streaming learning algorithms under realistic OS behavioral streams, employing River/scikit-multiflow/creme frameworks. A tailored feature engineering pipeline incorporates process lifecycle semantics and temporal statistics, explicitly fusing event timing and multidimensional features. Evaluation adopts dual metrics: ROC-AUC and end-to-end latency. Contribution/Results: Hoeffding Tree augmented with ADWIN concept drift detection achieves state-of-the-art ROC-AUC (0.92) at millisecond-scale latency—significantly outperforming offline baselines. Our study is the first to empirically demonstrate the critical impact of temporal-feature fusion on detection accuracy and validates the effectiveness and practicality of streaming paradigms for near-real-time identification of previously unseen threats.

Addressing challenges of real-time threat monitoringDetecting anomalies in cybersecurity data streamsEvaluating stream learning algorithms on BETH dataset

This study addresses the challenge of detecting anomalous events in large-scale, high-voltage power grid operational data by systematically evaluating the performance of neural networks, k-nearest neighbors, support vector machines, and unsupervised learning methods under complex contextual conditions. The findings reveal that grid anomalies exhibit strong context dependency. Among the evaluated approaches, neural networks significantly outperform traditional methods in overall detection accuracy, while unsupervised learning algorithms demonstrate superior robustness and efficiency in scenarios involving concurrent multiple anomalies. This work not only validates the advantages of deep learning for anomaly detection in power systems but also highlights the practical value of unsupervised methods when labeled data are scarce and fault patterns are intricately coupled.

Anomaly DetectionMachine LearningOperational Data

We Need to Rethink Benchmarking in Anomaly Detection

Jul 21, 2025
PR
Philipp Röchner
🏛️ University of Mainz | TU Dortmund University | University of Würzburg

Existing anomaly detection benchmarks fail to account for the diversity of anomaly types and application contexts, hindering rigorous algorithm comparison and practical deployment. Method: We propose a scenario-driven evaluation paradigm: (1) constructing a generalizable taxonomy of anomaly scenarios spanning domains such as predictive maintenance and scientific discovery; (2) decoupling detection pipelines into end-to-end and modular component-level analyses; and (3) designing task-specific, interpretable evaluation metrics aligned with scenario objectives. Contribution/Results: Our framework identifies the root cause—benchmark agnosticism toward scenario semantics—that prevents traditional benchmarks from discriminating algorithmic performance meaningfully. It establishes the first evaluation framework for anomaly detection that jointly ensures real-world applicability and scientific rigor, thereby significantly enhancing the validity of algorithmic comparisons and the translational value of research findings.

Current benchmarks lack diversity in real-world anomaly scenariosImproving evaluation with taxonomy-based scenarios and end-to-end analysisRethinking benchmarking due to stagnant anomaly detection progress

Benchmarking Anomaly Detection Algorithms: Deep Learning and Beyond

Feb 11, 2024
SM
Shanay Mehta
🏛️ Birla Institute of Technology and Science | Don Bosco College of Engineering | GE Healthcare

This work addresses class imbalance induced by extreme anomaly sparsity in complex critical systems. We conduct the largest迄今 unbiased benchmark evaluation of anomaly detection algorithms to date, systematically assessing over 100 methods—including classical machine learning, tree-based models (e.g., Isolation Forest, XGBoost), evolutionary optimization approaches, deep autoencoders, one-class SVM, and LOF—across 104 publicly available datasets. Results reveal that deep learning is not universally superior: tree-based and tree-evolutionary methods achieve a mean F1-score gain of 12.3% over deep learning in low-anomaly-rate (<10%), small-sample, and univariate sparse settings, and successfully detect singleton anomalies missed by deep models. These findings challenge the “deep learning panacea” assumption and establish algorithmic suitability—not model complexity—as the primary principle for method selection. The study provides empirically grounded, industry-applicable guidance for anomaly detection algorithm deployment.

Assessing algorithm adaptability in real-world univariate anomaly scenariosComparing classical ML and DL methods for imbalance dataEvaluating diverse ML-based anomaly detection algorithms comprehensively

Latest Papers

What's happening recently
View more

Industrial anomaly detection is often hindered by the extreme scarcity of fault samples, leading to suboptimal model performance and limited generalization. This work addresses this challenge by constructing a problem-agnostic hyperspherical synthetic dataset to systematically evaluate 14 anomaly detection algorithms—including kNN, LOF, XGBOD, SVM, and CatBoost—under rigorously controlled conditions across varying fault rates (0.05%–20%) and training set sizes. The study quantitatively demonstrates for the first time that unsupervised methods achieve optimal performance when fewer than 20 fault samples are available; semi-supervised and supervised approaches significantly outperform others with 30–50 fault samples; and further increasing normal samples yields diminishing returns. Additionally, feature dimensionality is found to critically influence the efficacy of semi-supervised methods, thereby clarifying the operational boundaries of each algorithmic category.

anomaly detectionclass imbalancefaulty data scarcity

This work addresses the challenge that existing unsupervised methods struggle to reliably detect subtle and noisy anomalies in complex time series, often being misled by noise in normal samples and missing near-normal anomalies. To overcome this limitation, we propose a novel unsupervised anomaly detection framework that integrates active learning: it enhances temporal dependency modeling through a masked time series reconstruction feedback mechanism and employs a minimax optimization strategy to differentially treat normal and anomalous samples, thereby improving robustness against noise and weak anomalies. Extensive experiments across four multivariate time series datasets and seven backbone models demonstrate that our method achieves an average AUC improvement of 12.39%, significantly outperforming current unsupervised approaches.

active learningnoise contaminationsubtle anomalies

This study addresses the challenges in time series anomaly detection posed by extreme class imbalance and scarce labeled data, which hinder supervised approaches and lead to high false positive rates in unsupervised methods. To overcome these limitations, the authors propose an unsupervised detection framework that integrates Haar discrete wavelet transform with a tailored t-test. By decomposing the signal across multiple scales and applying statistically grounded significance testing, the method effectively identifies anomalies without requiring labeled data. This work is the first to synergistically combine Haar wavelets with theoretically justified t-tests, substantially reducing false positives while enhancing detection accuracy. Extensive experiments on 343 real-world datasets demonstrate that the proposed approach outperforms current state-of-the-art unsupervised and self-supervised methods in both detection speed and accuracy.

anomaly detectionclass imbalancefalse positive rate

Segmentation over Complexity: Evaluating Ensemble and Hybrid Approaches for Anomaly Detection in Industrial Time Series

Oct 30, 2025
EM
Emilio Mastriani
🏛️ INAF | Osservatorio Astrofisico di Catania

This study addresses the challenges of severe class imbalance and temporal uncertainty in multivariate time-series anomaly detection for steam turbines. We systematically evaluate ensemble and hybrid approaches, proposing a lightweight segmentation-based ensemble model that integrates change-point detection, clustering-based substructure representation, and Random Forest/XGBoost—without relying on complex feature engineering or hybrid architectures. Experimental results demonstrate that this streamlined approach significantly outperforms sophisticated methods in robustness, interpretability, and deployment efficiency: it achieves an AUC-ROC of 0.976, an F1-score of 0.41, and guarantees 100% early anomaly detection within the prescribed time window. Our key contribution lies in empirically establishing that, in real-world industrial settings, jointly optimizing segmentation strategy and model simplicity yields greater practical value than architectural complexity alone.

Addressing data imbalance and temporal uncertainty in turbine monitoringComparing hybrid models with simple ensemble methods on time seriesEvaluating advanced feature engineering for industrial anomaly detection

This work proposes GDME, a novel framework addressing the limitations of existing online anomaly detection methods in industrial systems, where heterogeneous streaming time series exhibit diverse and rapidly evolving patterns. GDME dynamically maintains a pool of models, constructs a graph to capture inter-model relationships, and adaptively selects an optimal subset for ensemble learning through community detection. By monitoring structural changes in the graph, the framework effectively detects concept drift and enhances adaptability to data evolution. Integrating unsupervised learning, dynamic graph modeling, and online ensemble strategies, GDME achieves up to a 24% average performance improvement over state-of-the-art online methods and static ensemble baselines across seven heterogeneous datasets, while maintaining favorable computational efficiency.

concept driftheterogeneous dataonline anomaly detection

Hot Scholars

ZZ

Zhenhong Zhou

Nanyang Technological University
Large Language ModelAI SafetyLLM Safety
KY

Kwok-Yan Lam

Nanyang Technological University
CybersecurityPrivacy-Preserving technologiesDigital TrustDistributing systems
MZ

Mian Zou

City University of Hong Kong
computer visionmultimedia forensics
KM

Kede Ma

Associate Professor of Computer Science, City University of Hong Kong
Image ProcessingComputational VisionComputational PhotographyMultimedia Forensics