Skip to main navigation Skip to search Skip to main content

KeAD: Knowledge-enhanced Graph Attention Network for Accurate Anomaly Detection

  • Yi Li
  • , Zhangbing Zhou
  • , Pu Sun
  • , Shuiguang Deng
  • , Xiao Sun
  • , Xiao Xue
  • , Sami Yangui
  • , Walid Gaaloul

Research output: Contribution to journalArticlepeer-review

Abstract

Anomaly detection has emerged as one of the core research topics to support workflow applications across domains. To differentiate anomalies from normal patterns of workflows, Graph Neural Networks (GNNs) models have been introduced. These models leverage time series data to construct graph structures, in order to explicitly capture task dependencies among industrial Internet of Things (IoT) devices, and thus, to identify deviations from predicted behaviours as anomalies. However, existing forecasting-based anomaly detection methods may not accurately detect certain anomalies, as they rely solely on historical sensory data while seldom considering the valuable information embedded in domain knowledge. To address this limitation, this paper proposes a Knowledge-enhanced graph attention-based Anomaly Detection (KeAD) method. Specifically, a knowledge-enhanced graph structure is constructed by incorporating domain-specific knowledge to represent spatio-temporal dependencies between IoT devices. Based on which, a knowledge-enhanced graph attention-based forecasting network is developed to predict the future behaviours of IoT devices. Anomalies, such as those caused by cyber-attacks in workflows, are detected by analyzing deviations from these predicted behaviours in conjunction with domain-specific knowledge. A case study is presented, along with extensive experiments conducted on publicly available datasets. Evaluation results demonstrate that KeAD outperforms the state-of-the-art techniques in terms of anomaly detection accuracy.

Original languageEnglish
Pages (from-to)2172-2187
Number of pages16
JournalIEEE Transactions on Services Computing
Volume18
Issue number4
DOIs
Publication statusPublished - 1 Jan 2025

Keywords

  • Anomaly detection
  • Internet of Things
  • domain knowledge
  • spatio-temporal dependency
  • time series forecasting

Fingerprint

Dive into the research topics of 'KeAD: Knowledge-enhanced Graph Attention Network for Accurate Anomaly Detection'. Together they form a unique fingerprint.

Cite this