When Model Meets New Normals: Test-time Adaptation for Unsupervised Time-series Anomaly Detection (2312.11976v2)
Abstract: Time-series anomaly detection deals with the problem of detecting anomalous timesteps by learning normality from the sequence of observations. However, the concept of normality evolves over time, leading to a "new normal problem", where the distribution of normality can be changed due to the distribution shifts between training and test data. This paper highlights the prevalence of the new normal problem in unsupervised time-series anomaly detection studies. To tackle this issue, we propose a simple yet effective test-time adaptation strategy based on trend estimation and a self-supervised approach to learning new normalities during inference. Extensive experiments on real-world benchmarks demonstrate that incorporating the proposed strategy into the anomaly detector consistently improves the model's performance compared to the baselines, leading to robustness to the distribution shifts.
- Practical Approach to Asynchronous Multivariate Time Series Anomaly Detection and Localization. In Proc. the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD).
- USAD: UnSupervised Anomaly Detection on Multivariate Time Series. In Proc. the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD).
- LOF: Identifying Density-Based Local Outliers. In Proceedings of the 2000 ACM SIGMOD International Conference on Management of Data, May 16-18, 2000, Dallas, Texas, USA.
- Anomaly Detection under Distribution Shift. CoRR, abs/2303.13845.
- Improving test-time adaptation via shift-agnostic weight regularization and nearest source prototypes. In Proc. of the European Conference on Computer Vision (ECCV), 440–458. Springer.
- BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. In Burstein, J.; Doran, C.; and Solorio, T., eds., Proc. of The Annual Conference of the North American Chapter of the Association for Computational Linguistics (NAACL).
- AnoShift: A Distribution Shift Benchmark for Unsupervised Anomaly Detection. In NeurIPS.
- Domain-adversarial training of neural networks. The journal of machine learning research, 17(1): 2096–2030.
- TadGAN: Time Series Anomaly Detection Using Generative Adversarial Networks. In 2020 IEEE International Conference on Big Data (IEEE BigData 2020), Atlanta, GA, USA, December 10-13, 2020, 33–43. IEEE.
- LUNAR: Unifying Local Outlier Detection Methods via Graph Neural Networks. In Proc. the AAAI Conference on Artificial Intelligence (AAAI).
- In Search of Lost Domain Generalization. In Proc. the International Conference on Learning Representations (ICLR).
- MADGAN: unsupervised medical anomaly detection GAN using multiple adjacent brain MRI slice reconstruction. BMC Bioinform., 22-S(2): 31.
- Detecting Spacecraft Anomalies Using LSTMs and Nonparametric Dynamic Thresholding. In Proc. the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD).
- Towards a Rigorous Evaluation of Time-Series Anomaly Detection. In Proc. the AAAI Conference on Artificial Intelligence (AAAI).
- Reversible Instance Normalization for Accurate Time-Series Forecasting against Distribution Shift. In Proc. the International Conference on Learning Representations (ICLR).
- Revisiting Time Series Outlier Detection: Definitions and Benchmarks. In Proc. the Advances in Neural Information Processing Systems (NeurIPS).
- Do we really need to access the source data? source hypothesis transfer for unsupervised domain adaptation. In International Conference on Machine Learning, 6028–6039. PMLR.
- Detection and identification of sensor anomaly for aerospace applications. In 2016 Annual Reliability and Maintainability Symposium (RAMS), 1–6. IEEE.
- Generative Adversarial Active Learning for Unsupervised Outlier Detection. IEEE Trans. Knowl. Data Eng., 32(8): 1517–1528.
- Non-stationary Transformers: Exploring the Stationarity in Time Series Forecasting. In NeurIPS.
- LSTM-based Encoder-Decoder for Multi-sensor Anomaly Detection. CoRR, abs/1607.00148.
- SWaT: a water treatment testbed for research and training on ICS security. In 2016 International Workshop on Cyber-physical Systems for Smart Water Networks, CySWater@CPSWeek 2016, Vienna, Austria, April 11, 2016.
- Muth, J. F. 1960. Optimal properties of exponentially weighted forecasts. Journal of the american statistical association, 55(290): 299–306.
- Efficient test-time model adaptation without forgetting. In Proc. the International Conference on Machine Learning (ICML), 16888–16905. PMLR.
- Deep Learning for Anomaly Detection: A Review. ACM Comput. Surv., 54(2): 38:1–38:38.
- A Multimodal Anomaly Detector for Robot-Assisted Feeding Using an LSTM-Based Variational Autoencoder. IEEE Robotics Autom. Lett.
- Anomaly Detection Using Forecasting Methods ARIMA and HWDS. In 32nd International Conference of the Chilean Computer Science Society, SCCC 2013, Temuco, Cautin, Chile, November 11-15, 2013, 63–66. IEEE Computer Society.
- Dataset shift in machine learning. Mit Press.
- A distributed anomaly detection model for wireless sensor networks based on the one-class principal component classifier. Int. J. Sens. Networks, 27(3): 200–214.
- A survey of deep active learning. ACM computing surveys (CSUR), 54(9): 1–40.
- Deep One-Class Classification. In Proc. the International Conference on Machine Learning (ICML).
- A Unifying Review of Deep and Shallow Anomaly Detection. Proc. IEEE, 109(5): 756–795.
- The precision-recall plot is more informative than the ROC plot when evaluating binary classifiers on imbalanced datasets. PloS one, 10(3): e0118432.
- FITNESS: (Fine Tune on New and Similar Samples) to detect anomalies in streams with drift and outliers. In Proc. the International Conference on Machine Learning (ICML).
- Online anomaly detection with concept drift adaptation using recurrent neural networks. In Proceedings of the ACM India Joint International Conference on Data Science and Management of Data, COMAD/CODS 2018, Goa, India, January 11-13, 2018.
- Unsupervised Anomaly Detection with Generative Adversarial Networks to Guide Marker Discovery. In Information Processing in Medical Imaging - 25th International Conference, IPMI 2017, Boone, NC, USA, June 25-30, 2017, Proceedings, volume 10265 of Lecture Notes in Computer Science, 146–157. Springer.
- Support Vector Method for Novelty Detection. In Solla, S. A.; Leen, T. K.; and Müller, K., eds., Proc. the Advances in Neural Information Processing Systems (NeurIPS).
- Timeseries Anomaly Detection using Temporal Hierarchical One-Class Network. In Proc. the Advances in Neural Information Processing Systems (NeurIPS).
- Anomaly Detection for Tabular Data with Internal Contrastive Learning. In Proc. the International Conference on Learning Representations (ICLR).
- ITAD: Integrative Tensor-based Anomaly Detection System for Reducing False Positives of Satellite Systems. In Proc. the ACM Conference on Information and Knowledge Management (CIKM).
- Time series analysis and its applications: With R examples. Springer.
- Navigating the Metric Maze: A Taxonomy of Evaluation Metrics for Anomaly Detection in Time Series. CoRR, abs/2303.01272.
- Robust Anomaly Detection for Multivariate Time Series through Stochastic Recurrent Neural Network. In Proc. the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD).
- Test-Time Training with Self-Supervision for Generalization under Distribution Shifts. In Proc. the International Conference on Machine Learning (ICML).
- Data domain description using support vectors. In 7th European Symposium on Artificial Neural Networks, ESANN 1999, Bruges, Belgium, April 21-23, 1999, Proceedings.
- Tent: Fully Test-Time Adaptation by Entropy Minimization. In Proc. the International Conference on Learning Representations (ICLR).
- A new online anomaly learning and detection for large-scale service of Internet of Thing. Pers. Ubiquitous Comput., 19(7): 1021–1031.
- Continual Test-Time Domain Adaptation. In Proc. of the IEEE conference on computer vision and pattern recognition (CVPR).
- Unsupervised Anomaly Detection via Variational Auto-Encoder for Seasonal KPIs in Web Applications. In Proc. the International Conference on World Wide Web (WWW).
- Anomaly Transformer: Time Series Anomaly Detection with Association Discrepancy. In Proc. the International Conference on Learning Representations (ICLR).
- Unsupervised Domain Adaptation for One-Stage Object Detector Using Offsets to Bounding Box. In Proc. of the European Conference on Computer Vision (ECCV), 691–708. Springer.
- Zinkevich, M. 2003. Online Convex Programming and Generalized Infinitesimal Gradient Ascent. In Proc. the International Conference on Machine Learning (ICML).
- Deep Autoencoding Gaussian Mixture Model for Unsupervised Anomaly Detection. In Proc. the International Conference on Learning Representations (ICLR).
- Unsupervised domain adaptation for semantic segmentation via class-balanced self-training. In Proc. of the European Conference on Computer Vision (ECCV), 289–305.