about
MStream outperforms scikit-learn algorithms in anomaly detection (arxiv.org)
5 points by adamnemecek on Sep 24, 2020 | hide | past | pdf | 4 comments on HN

In plain words: A streaming checker that watches records with several attributes—both labels and numbers—and flags odd groups as they arrive, tracking how the attributes relate. It processes each record in constant time and memory, and outperformed the best existing detectors on four network-attack datasets.

Abstract · MSTREAM: Fast Anomaly Detection in Multi-Aspect Streams

Given a stream of entries in a multi-aspect data setting i.e., entries having multiple dimensions, how can we detect anomalous activities in an unsupervised manner? For example, in the intrusion detection setting, existing work seeks to detect anomalous events or edges in dynamic graph streams, but this does not allow us to take into account additional attributes of each entry. Our work aims to define a streaming multi-aspect data anomaly detection framework, termed MSTREAM which can detect unusual group anomalies as they occur, in a dynamic manner. MSTREAM has the following properties: (a) it detects anomalies in multi-aspect data including both categorical and numeric attributes; (b) it is online, thus processing each record in constant time and constant memory; (c) it can capture the correlation between multiple aspects of the data. MSTREAM is evaluated over the KDDCUP99, CICIDS-DoS, UNSW-NB 15 and CICIDS-DDoS datasets, and outperforms state-of-the-art baselines.

Siddharth Bhatia, Arjit Jain, Pan Li, Ritesh Kumar, Bryan Hooi
arXiv:2009.08451 · cs.LG, cs.AI, stat.ML · submitted Sep 17, 2020 · updated Mar 30, 2021
abstract · pdf · html · The Web Conference (WWW), 2021

add comment on HN

Hi, I am one of the authors of the work. MStream detects anomalies, intrusions, DoS and DDoS attacks in real time and constant memory. It is built on top of MIDAS (https://github.com/Stream-AD/MIDAS/) and works in a multi-aspect data setting i.e., entries having multiple dimensions such as event-log data, multi-attributed graphs etc. MStream is two orders of magnitude faster while achieving higher accuracy on several publicly available datasets.

Github Repository: https://github.com/Stream-AD/MStream

Awesome work. Would you say this is the state of the art for real-time anomaly detection ?
MStream and MIDAS are more accurate than previous baselines for unsupervised anomaly detection. However, there can be scenarios where some labels (ground truth information) are known. In such cases, a semi-supervised algorithm might work better. We are currently working towards building a semi-supervised approach for anomaly detection in real-time.

To the best of my knowledge, MStream and MIDAS are the fastest and detect anomalies in real-time.

Auspex Labs is using MIDAS as part of our scoring for risk detection in network flow analysis.

https://www.auspex-labs.com/