Generating Local Explanations of Network Anomalies via Score Decomposition
published: Nov. 7, 2016, recorded: August 2016, views: 1048
Report a problem or upload filesIf you have found a problem with this lecture or would like to send us extra material, articles, exercises, etc., please use our ticket system to describe your request and upload the data.
Enter your e-mail into the 'Cc' field, and we will keep you updated with your request's status.
An important application in network analysis is the detection of anomalous events in a network time series. These events could merely be times of interest in the network timeline or they could be examples of malicious activity or network malfunction. Once a set of events are identified by the anomaly detection algorithm, a more detailed examination of the graph at these times can reveal important details about the behavior of the network. In this paper we use the score decomposition of the global anomaly score of reported anomalies in several dynamic networks to identify the regions of most anomalous behavior and provide interpretations as to the nature of the anomalous events. We also define a new version of the Graph Edit Distance and Clustering Coefficient statistics which are better at finding the local explanations for anomalous behavior.
Link this pageWould you like to put a link to this lecture on your homepage?
Go ahead! Copy the HTML snippet !