arXiv:2607.18289cs.LGcs.AI2026-07

构建可复现的持续异常检测基准框架,解决任务划分混乱问题。

Towards Principled Continual Anomaly Detection: A Systematic Framework and Benchmark Scenarios

论文配图:Towards Principled Continual Anomaly Detection: A Systematic Framework and Benchmark Scenarios
图 1 · 摘自论文原文
  • 从现有数据中系统提取候选任务并筛选不适配项
  • 设计合理顺序暴露多样演化动态,生成5个可用基准场景
  • 适用于网络安全领域,帮助评估模型持续学习能力

持续异常检测(CAD)研究模型如何在数据分布演化的环境中保持对已观测模式的识别能力。然而,当前的CAD基准严重依赖于任务定义、过滤、排序与验证方式。在表格数据领域,任务边界通常未提供,任意划分可能导致不可学习、冗余或过度可迁移的任务,掩盖真实的持续学习行为。为此,我们提出一个从现有表格异常检测数据集中系统构建可复现基准场景的框架。该框架能发现候选任务,剔除不适用任务,并推导出能揭示多样化演化动态的合理排序。基于此框架,我们从三个大规模网络安全异常检测数据集构建了五个可用于基准测试的场景,涵盖单数据集与多数据集两种CAD设置。

原文摘要 · Abstract (English)

Continual anomaly detection (CAD) studies how models can adapt to evolving data distributions while retaining performance on previously observed regimes. CAD benchmarks, however, depend critically on how tasks are defined, filtered, ordered, and validated. In tabular domains, task boundaries are rarely given, and arbitrary splits can create unlearnable, redundant, or overly transferable tasks that obscure genuine continual-learning behavior. To this end, we introduce a systematic framework for reproducible benchmark scenario design from existing tabular anomaly-detection datasets. The framework discovers candidate tasks, filters unsuitable tasks, and derives principled orderings that expose diverse dynamics. The framework allows us to deliver five benchmark-ready scenarios from three large-scale cybersecurity anomaly detection datasets, yielding both single-dataset and multi-dataset CAD settings.

异常检测持续学习网络安全基准测试

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。