Sequential Feature Explanations for Anomaly Detection

by   Md Amran Siddiqui, et al.

In many applications, an anomaly detection system presents the most anomalous data instance to a human analyst, who then must determine whether the instance is truly of interest (e.g. a threat in a security setting). Unfortunately, most anomaly detectors provide no explanation about why an instance was considered anomalous, leaving the analyst with no guidance about where to begin the investigation. To address this issue, we study the problems of computing and evaluating sequential feature explanations (SFEs) for anomaly detectors. An SFE of an anomaly is a sequence of features, which are presented to the analyst one at a time (in order) until the information contained in the highlighted features is enough for the analyst to make a confident judgement about the anomaly. Since analyst effort is related to the amount of information that they consider in an investigation, an explanation's quality is related to the number of features that must be revealed to attain confidence. One of our main contributions is to present a novel framework for large scale quantitative evaluations of SFEs, where the quality measure is based on analyst effort. To do this we construct anomaly detection benchmarks from real data sets along with artificial experts that can be simulated for evaluation. Our second contribution is to evaluate several novel explanation approaches within the framework and on traditional anomaly detection benchmarks, offering several insights into the approaches.


page 1

page 2

page 3

page 4


(1 + ε)-class Classification: an Anomaly Detection Method for Highly Imbalanced or Incomplete Data Sets

Anomaly detection is not an easy problem since distribution of anomalous...

AKM^2D : An Adaptive Framework for Online Sensing and Anomaly Quantification

In point-based sensing systems such as coordinate measuring machines (CM...

Is AUC the best measure for practical comparison of anomaly detectors?

The area under receiver operating characteristics (AUC) is the standard ...

Sequential anomaly detection with sampling constraints

The problem of sequential anomaly detection is considered, where multipl...

Improved histogram-based anomaly detector with the extended principal component features

In this era of big data, databases are growing rapidly in terms of the n...

An Anomaly Contribution Explainer for Cyber-Security Applications

In this paper, we introduce Anomaly Contribution Explainer or ACE, a too...

Reduction of Monitoring Register on Software Defined Networks

Characterization of data network monitoring registers allows for reducti...

Please sign up or login with your details

Forgot password? Click here to reset