Incremental anomaly detection approach for characterizing unusual profiles

  • Authors:
  • Yi Fang;Olufemi A. Omitaomu;Auroop R. Ganguly

  • Affiliations:
  • Department of Computer Science, Purdue University, West Lafayette, IN;Oak Ridge National Laboratory, Oak Ridge, TN;Oak Ridge National Laboratory, Oak Ridge, TN

  • Venue:
  • Sensor-KDD'08 Proceedings of the Second international conference on Knowledge Discovery from Sensor Data
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

The detection of unusual profiles or anomalous behavioral characteristics from sensor data is especially complicated in security applications where the threat indicators may or may not be known in advance. Predictive modeling of massive volumes of historical data can yield insights on usual or baseline profiles, which in turn can be utilized to isolate unusual profiles when new data are observed in real-time. Thus, an incremental anomaly detection approach is proposed. This is a two-stage approach in which the first stage processes the available historical data and develops statistics that are in turn used by the second stage in characterizing the new incoming data for real-time decisions. The first stage adopts a mixture model of probabilistic principal component analyzers to quantify each historical observation by probabilistic measures. The second stage is a chi-square based anomaly detection approach that utilizes the probabilistic measures obtained in the first stage to determine if the incoming data is an anomaly. The proposed anomaly detection approach performs satisfactorily on simulated and benchmark datasets. The approach is also illustrated in the context of detecting commercial trucks that may pose safety and security risk. It is able to consistently identified trucks with anomalous features in the scenarios investigated.