Towards Meaningful Anomaly Detection: The Effect of Counterfactual Explanations on the Investigation of Anomalies in Multivariate Time Series

02/07/2023
by   Max Schemmer, et al.
0

Detecting rare events is essential in various fields, e.g., in cyber security or maintenance. Often, human experts are supported by anomaly detection systems as continuously monitoring the data is an error-prone and tedious task. However, among the anomalies detected may be events that are rare, e.g., a planned shutdown of a machine, but are not the actual event of interest, e.g., breakdowns of a machine. Therefore, human experts are needed to validate whether the detected anomalies are relevant. We propose to support this anomaly investigation by providing explanations of anomaly detection. Related work only focuses on the technical implementation of explainable anomaly detection and neglects the subsequent human anomaly investigation. To address this research gap, we conduct a behavioral experiment using records of taxi rides in New York City as a testbed. Participants are asked to differentiate extreme weather events from other anomalous events such as holidays or sporting events. Our results show that providing counterfactual explanations do improve the investigation of anomalies, indicating potential for explainable anomaly detection in general.

READ FULL TEXT
research
03/21/2022

Diverse Counterfactual Explanations for Anomaly Detection in Time Series

Data-driven methods that detect anomalies in times series data are ubiqu...
research
06/26/2019

Visual Anomaly Detection in Event Sequence Data

Anomaly detection is a common analytical task that aims to identify rare...
research
01/20/2022

Effective Anomaly Detection in Smart Home by Integrating Event Time Intervals

Smart home IoT systems and devices are susceptible to attacks and malfun...
research
11/18/2022

Rare Yet Popular: Evidence and Implications from Labeled Datasets for Network Anomaly Detection

Anomaly detection research works generally propose algorithms or end-to-...
research
03/31/2022

SIERRA: Ranking Anomalous Activities in Enterprise Networks

An enterprise today deploys multiple security middleboxes such as firewa...
research
09/14/2021

Anomaly Attribution of Multivariate Time Series using Counterfactual Reasoning

There are numerous methods for detecting anomalies in time series, but t...

Please sign up or login with your details

Forgot password? Click here to reset