HYDRA: نهج مدفوع بالهرمية متعددة المستويات للكشف عن الشذوذ بشكل موثوق في السلاسل الزمنية
HYDRA: A Multi-Level Hierarchy-Driven Approach for Robust Anomaly Detection in Time Series

شارك:
المجلة: Proceedings of the ACM on Management of Data، المجلد: 4، العدد: 3
DOI: https://doi.org/10.1145/3802074
تاريخ النشر: 2026-05-18
المؤلف: Mingyi Huang وآخرون
الموضوع الرئيسي: تقنيات الكشف عن الشذوذ وتطبيقاتها

نظرة عامة

يقدم القسم نظرة عامة على HYDRA، وهو نهج جديد متعدد المستويات هرمي وغير خاضع للإشراف لاكتشاف الشذوذ في السلاسل الزمنية. على الرغم من التقدم في الشبكات العصبية، لا تزال طرق التنقيب عن البيانات التقليدية تنافسية ولكن لها قيود ملحوظة، مثل صعوبة الطرق المعتمدة على التباين مع الشذوذ المتكرر وفشل تقنيات التجميع في التقاط الانحرافات الدقيقة. تعتمد كلا الطريقتين بشكل كبير على حساب المسافة، الذي يتأثر بتطبيع البيانات، وعادة ما يستخدم تطبيع z-score. بينما يمكن أن يعزز التطبيع قابلية اكتشاف الشذوذ، إلا أنه قد يقمع أيضًا الشذوذ المدفوع بالسعة، مما يبرز الحاجة إلى اختيار دقيق لخطط التطبيع.

تتعامل HYDRA مع هذه التحديات من خلال دمج نقاط القوة في الطرق المعتمدة على المسافة مع تقليل الاعتماد على التطبيع الصريح. تستخدم كاشف أقرب جار تقريبي خفيف الوزن لاختيار تسلسلات فرعية تمثيلية، وتبني تمثيلات متعددة الدقة للسلاسل الزمنية، وتقدم آلية تجميع هرمية لجمع أدلة الشذوذ عبر مقاييس مختلفة. يمكّن هذا التصميم HYDRA من اكتشاف مجموعة واسعة من أنواع الشذوذ، من التباينات القصيرة والمعزولة إلى الانحرافات الطويلة والمستمرة. تظهر التقييمات الشاملة على 40 مجموعة بيانات من معيار TSB-AD أن HYDRA تحقق أداءً رائدًا، متفوقة على 40 خوارزمية منافسة مع الحفاظ على قابلية التوسع للتسلسلات الطويلة جدًا. يؤكد المؤلفون على الإمكانات للتحسينات المستقبلية، بما في ذلك استكشاف مقاييس التشابه غير الإقليدية وطرق التكيف للبيانات المتدفقة.

مقدمة

تناقش مقدمة ورقة البحث أهمية بيانات السلاسل الزمنية عبر تطبيقات متنوعة، مع التأكيد على الدور الحاسم لاكتشاف الشذوذ في السلاسل الزمنية (TSAD) في تحديد الأحداث النادرة ولكن المؤثرة في مجالات مثل المراقبة الصناعية والمالية والرعاية الصحية. يبرز المؤلفون التحديات التي تطرحها الزيادة في حجم وتنوع بيانات السلاسل الزمنية، مما يعقد دقة وموثوقية طرق اكتشاف الشذوذ. على الرغم من التقدم في الشبكات العصبية، لا تزال تقنيات التنقيب عن البيانات التقليدية، وخاصة الطرق المعتمدة على المسافة مثل Matrix Profile (MP) وKMeansAD وNormA، تنافسية بسبب فعاليتها وقابلية توسيعها. ومع ذلك، تواجه هذه الطرق قيودًا، مثل الضعف أمام التلوث الناتج عن الشذوذ والاعتماد على افتراضات معينة للشذوذ، مما يقيد قابليتها للتعميم عبر سلوكيات الشذوذ المتنوعة.

يقترح المؤلفون إطارًا موحدًا، HYDRA، الذي يهدف إلى دمج نقاط القوة في الطرق الحالية مع معالجة أوجه القصور فيها. يشيرون إلى أن تقنيات التطبيع الحالية، وخاصة تطبيع z-score، يمكن أن تخفي عن غير قصد الشذوذ المدفوع بالسعة بينما تستفيد من الشذوذ القائم على الشكل، مما يبرز الحاجة إلى استراتيجيات معالجة مسبقة أكثر قابلية للتكيف. تشير نتائج التقييم إلى أن HYDRA تظهر أداءً قويًا عبر مجالات متنوعة، مما يلتقط بفعالية كل من الشذوذ المحلي والشذوذ الهيكلي المماثل، مما يظهر قابليتها للتكيف وفعاليتها في التطبيقات الواقعية.

طرق

في قسم الطرق، يحدد المؤلفون تقييمًا تجريبيًا شاملاً مصممًا لتقييم فعالية وموثوقية وقابلية توسيع نهجهم المقترح. يتم هيكلة التقييم في عدة أقسام فرعية: يوضح القسم 5.1 إعداد التجربة، بما في ذلك مجموعات البيانات المستخدمة، والمقارنات الأساسية، والمعايير للتقييم. يقدم القسم 5.2 نتائج الدقة العامة مع تحليل الدلالة الإحصائية للتحقق من النتائج.

علاوة على ذلك، يستكشف القسم 5.3 أداء الطريقة عبر مجالات الشذوذ المختلفة، مع تسليط الضوء على قابليتها للتكيف مع أنواع الشذوذ المختلفة. يفحص القسم 5.4 تأثير استراتيجيات التطبيع على استقرار الكشف والحساسية لتغيرات الحجم. يحلل القسم 5.5 آثار المعلمات الحرجة مثل طول التسلسل الفرعي، وعمق الهيكل الهرمي، واستراتيجيات التقريب. أخيرًا، يقيم القسم 5.6 قابلية توسيع وقت التشغيل للطريقة عند تطبيقها على مجموعات بيانات كبيرة. بشكل جماعي، توفر هذه التجارب فهمًا شاملاً لأداء الإطار، مما يظهر عموميته وكفاءته وموثوقيته عبر ظروف وإعدادات معلمات متنوعة.

نتائج

في هذا القسم، يقدم المؤلفون تقييمهم لمقاييس الدقة لاكتشاف الشذوذ، مع التأكيد على استخدام حجم المنطقة تحت المنحنى للدقة والاسترجاع (VUS-PR) كمقياس رئيسي. يستند هذا الاختيار إلى استقلالية عتبة VUS-PR وموثوقيته ضد عدم المحاذاة وعدم توازن الفئات، وهي مشكلات شائعة في مهام اكتشاف الشذوذ. يجادل المؤلفون بأن مقاييس أخرى، مثل AUC-PR وAUC-ROC وStandard-F1 (F1)، قد تكون عرضة للتحيزات بسبب اعتمادها على عتبات معينة أو تعديلات نقطية.

يتضمن حساب VUS-PR مجموعة من أطوال المخازن \( B \) التي تستخدم لتوسيع نطاق الشذوذ. لكل طول مخزن \( b \in B \)، يتم حساب منحنى الدقة والاسترجاع (PR) المدرك للنطاق، مما ينتج عنه منطقة \( AP_b \). يتم تعريف VUS-PR بعد ذلك على أنه متوسط المنطقة عبر جميع أطوال المخازن، معبرًا عنه رسميًا كـ \( VUS-PR = \frac{1}{|B|} \sum_{b \in B} AP_b \). تلتقط هذه المقياس بشكل فعال أداء النموذج عبر عتبات وأطوال مخازن متغيرة، مما يجعلها مقياسًا شاملاً لتقييم أنظمة اكتشاف الشذوذ.

مناقشة

في هذا القسم، يقدم المؤلفون نهج مدفوع بالهرمية لاكتشاف الشذوذ القوي (HYDRA)، وهو طريقة جديدة مصممة لتعزيز اكتشاف الشذوذ في السلاسل الزمنية من خلال معالجة القيود في النماذج الحالية. يستخدم HYDRA إطارًا هرميًا يسهل اختيار التسلسلات الفرعية على مستوى، مما ينقي تدريجيًا مجموعة من التسلسلات الفرعية التمثيلية لتقليل التلوث الناتج عن الشذوذ. تبني هذه الطريقة تمثيلات متعددة الدقة للبيانات المدخلة، مما يسمح باكتشاف كل من الانحرافات المحلية الدقيقة والاختلالات الهيكلية الأوسع. من خلال تجميع الأدلة عبر مستويات مختلفة، يتصالح HYDRA بشكل فعال مع التباينات في المقياس ويقلل من الحساسية لافتراضات التجميع، مما يحسن من موثوقيته ضد تلوث الشذوذ.

يبرز المؤلفون أن النماذج الحالية، مثل MP وNormA، غالبًا ما تواجه صعوبة مع الشذوذ المتكرر وتتطلب بيانات تدريب نظيفة، مما يحد من قابليتها للتطبيق في السيناريوهات الواقعية. في المقابل، فإن HYDRA خالية من التدريب وخفيفة المعلمات، وتظهر أداءً رائدًا عبر مجموعات بيانات متنوعة مع الحفاظ على قابلية التوسع للسلاسل الزمنية الطويلة. توضح الورقة عملية الاختيار الهرمي، التي لا تقمع فقط التعتيم القائم على أقرب جار بين الشذوذ المماثل ولكن تضمن أيضًا أن تظل مجموعة المرجع طبيعية في الغالب، مما يعزز دقة الكشف. تشير التقييمات الشاملة إلى أن HYDRA تتفوق باستمرار على النماذج الأخرى، مما يثبت فعاليتها وموثوقيتها في سياقات اكتشاف الشذوذ المتنوعة.

القيود

تظهر قيود إطار اكتشاف الشذوذ HYDRA، كما هو موضح في الشكل 14b، حالتين رئيسيتين للفشل عند مقارنتها بالمعايير الرائدة (SOTA)، NormA وMP. في الحالة الأولى، تؤدي التباين الكبير في السلوك الطبيعي إلى تنقية غير فعالة للنماذج الطبيعية بواسطة HYDRA، مما يؤدي إلى تضخم المسافات الزوجية بين التسلسلات الطبيعية وزيادة حدوث الإيجابيات الكاذبة. تتفاقم هذه المشكلة لكل من NormA وMP، اللتين تواجهان أيضًا صعوبات تحت افتراضات مماثلة منتهكة، مما يؤدي إلى تدهور الفصل بين توزيعات الدرجات الطبيعية والشاذة.

تحدث وضعية الفشل الثانية عندما تظهر الشذوذ كاضطرابات منخفضة السعة مع اهتزازات عالية التردد، مما يتسبب في وجود اختلافات طفيفة فقط يمكن اكتشافها بواسطة مقاييس المسافة الإقليدية. ينتج عن ذلك تباين ضعيف في درجات الشذوذ عبر HYDRA وMP وNormA، مما يبرز قيدًا شائعًا لطرق المسافة المعتمدة على الزمن عند معالجة الشذوذ المحلي طيفيًا أو عالي التردد. على الرغم من هذه التحديات، يظهر التصميم الهرمي متعدد الدقة لـ HYDRA وعدًا كإطار قوي لاكتشاف الشذوذ. يمكن أن يعزز العمل المستقبلي HYDRA من خلال دمج مجموعة أوسع من الاستدلالات لاكتشاف الشذوذ، وخاصة تلك المعتمدة على التباينات في المجال الترددي، لتحديد الشذوذ الاهتزازي أو المتذبذب بشكل أفضل الذي يكون أكثر وضوحًا في المجال الطيفي.

Journal: Proceedings of the ACM on Management of Data, Volume: 4, Issue: 3
DOI: https://doi.org/10.1145/3802074
Publication Date: 2026-05-18
Author(s): Mingyi Huang et al.
Primary Topic: Anomaly Detection Techniques and Applications

Overview

The section presents an overview of HYDRA, a novel multilevel hierarchical and unsupervised approach for time-series anomaly detection. Despite advancements in neural networks, traditional data mining methods remain competitive but have notable limitations, such as discord-based methods struggling with repeated anomalies and clustering techniques failing to capture fine-grained deviations. Both approaches depend heavily on distance computation, which is influenced by data normalization, typically using z-score normalization. While normalization can enhance anomaly detectability, it may also suppress amplitude-driven anomalies, highlighting the need for careful selection of normalization schemes.

HYDRA addresses these challenges by integrating the strengths of distance-based methods while minimizing reliance on explicit normalization. It employs a lightweight approximate nearest-neighbor detector for selecting representative subsequences, constructs multi-resolution representations of time series, and introduces a hierarchical ensemble mechanism to aggregate anomaly evidence across different scales. This design enables HYDRA to effectively detect a wide range of anomaly types, from short, isolated discords to long, persistent deviations. Extensive evaluations on 40 datasets from the TSB-AD benchmark demonstrate that HYDRA achieves state-of-the-art performance, outperforming 40 competing algorithms while maintaining scalability for ultra-long sequences. The authors emphasize the potential for future enhancements, including the exploration of non-Euclidean similarity measures and adaptive methods for streaming data.

Introduction

The introduction of the research paper discusses the significance of time-series data across various applications, emphasizing the critical role of time-series anomaly detection (TSAD) in identifying rare but impactful events in fields such as industrial monitoring, finance, and healthcare. The authors highlight the challenges posed by the increasing volume and heterogeneity of time-series data, which complicates the accuracy and robustness of anomaly detection methods. Despite advancements in neural networks, traditional data mining techniques, particularly distance-based approaches like Matrix Profile (MP), KMeansAD, and NormA, remain competitive due to their effectiveness and scalability. However, these methods face limitations, such as vulnerability to anomaly-induced contamination and reliance on specific anomaly assumptions, which restrict their generalizability across diverse anomaly behaviors.

The authors propose a unified framework, HYDRA, which aims to integrate the strengths of existing methods while addressing their shortcomings. They note that current normalization techniques, particularly z-score normalization, can inadvertently obscure amplitude-driven anomalies while benefiting shape-based anomalies, underscoring the need for more adaptable preprocessing strategies. Evaluation results indicate that HYDRA demonstrates robust performance across various domains, effectively capturing both localized and structurally similar anomalies, thereby showcasing its adaptability and effectiveness in real-world applications.

Methods

In the Methods section, the authors outline a comprehensive experimental evaluation designed to assess the effectiveness, robustness, and scalability of their proposed approach. The evaluation is structured into several subsections: Section 5.1 details the experimental setup, including the datasets used, baseline comparisons, and the metrics for evaluation. Section 5.2 presents the overall accuracy results along with a statistical significance analysis to validate the findings.

Further, Section 5.3 explores the method’s performance across various anomaly domains, highlighting its adaptability to different types of anomalies. Section 5.4 examines the influence of normalization strategies on the stability of detection and sensitivity to magnitude variations. Section 5.5 analyzes the effects of critical parameters such as subsequence length, hierarchical depth, and approximation strategies. Lastly, Section 5.6 assesses the method’s runtime scalability when applied to large datasets. Collectively, these experiments provide a comprehensive understanding of the framework’s performance, showcasing its generality, efficiency, and robustness across diverse conditions and parameter settings.

Results

In this section, the authors present their evaluation of accuracy measures for anomaly detection, emphasizing the use of Volume Under the Curve for Precision-Recall (VUS-PR) as the primary metric. This choice is based on VUS-PR’s threshold-independence and its robustness against misalignment and class imbalance, which are common issues in anomaly detection tasks. The authors argue that other metrics, such as AUC-PR, AUC-ROC, and Standard-F1 (F1), may be susceptible to biases due to their reliance on specific thresholds or point adjustments.

The calculation of VUS-PR involves a set of buffer lengths \( B \) that are used to extend anomaly ranges. For each buffer length \( b \in B \), the range-aware Precision-Recall (PR) curve is computed, yielding an area \( AP_b \). The VUS-PR is then defined as the average area across all buffer lengths, formally expressed as \( VUS-PR = \frac{1}{|B|} \sum_{b \in B} AP_b \). This metric effectively captures the model’s performance across varying thresholds and buffer lengths, making it a comprehensive measure for evaluating anomaly detection systems.

Discussion

In this section, the authors introduce the HierarchY-Driven Approach for Robust Anomaly Detection (HYDRA), a novel method designed to enhance time series anomaly detection by addressing limitations in existing models. HYDRA employs a hierarchical framework that facilitates level-wise subsequence selection, progressively refining a set of representative subsequences to minimize contamination from anomalies. This method constructs multi-resolution representations of the input data, allowing for the detection of both fine-grained local deviations and broader structural irregularities. By aggregating evidence across different levels, HYDRA effectively reconciles variations in scale and reduces sensitivity to clustering assumptions, thereby improving robustness against anomaly contamination.

The authors highlight that existing models, such as MP and NormA, often struggle with recurring anomalies and require clean training data, which limits their applicability in real-world scenarios. In contrast, HYDRA is training-free and parameter-light, demonstrating state-of-the-art performance across various datasets while maintaining scalability for long time series. The paper outlines the hierarchical selection process, which not only suppresses nearest-neighbor masking among similar anomalies but also ensures that the reference set remains predominantly normal, thus enhancing detection accuracy. Comprehensive evaluations indicate that HYDRA consistently outperforms other models, validating its effectiveness and robustness in diverse anomaly detection contexts.

Limitations

The limitations of the HYDRA anomaly detection framework, as illustrated in Figure 14b, reveal two primary failure cases when compared to state-of-the-art (SOTA) baselines, NormA and MP. In the first case, the significant heterogeneity of normal behavior leads to ineffective purification of normal prototypes by HYDRA, resulting in inflated pairwise distances among normal sequences and an increased incidence of false positives. This issue is compounded for both NormA and MP, which also struggle under similar violated assumptions, leading to degraded separation between normal and anomalous score distributions.

The second failure mode occurs when anomalies present as low-amplitude perturbations with high-frequency jitter, causing only minor discrepancies detectable by Euclidean distance metrics. This results in weak contrast in anomaly scores across HYDRA, MP, and NormA, underscoring a common limitation of time-domain, distance-based approaches when addressing spectrally localized or high-frequency anomalies. Despite these challenges, HYDRA’s multi-resolution hierarchical design shows promise as a robust anomaly detection framework. Future work could enhance HYDRA by integrating a wider array of anomaly detection heuristics, particularly those based on frequency-domain discrepancies, to better identify oscillatory or jittering anomalies that are more pronounced in the spectral domain.

شارك: