Skip to content
Open access

Ensemble Anomaly Detection with Quantile-Based Traffic Segmentation for Telecommunication Call Detail Records

Aug 2026 · bit-Tech · 0 citations

Abstract

​​Anomaly detection in telecommunication traffic data plays a critical role in identifying fraudulent activities, network misuse, and abnormal usage patterns. Conventional approaches that perform anomaly detection globally or per business category often fail to account for the inherent heterogeneity of traffic patterns across different customer groups, leading to high false-positive rates and missed detections. This study proposes an ensemble anomaly detection framework that incorporates quantile-based traffic segmentation on Call Detail Record (CDR) data. The proposed methodology first segments customers into three traffic groups Low, Medium, and High based on the quantile distribution of total call duration and call count. Subsequently, four anomaly detection algorithms from distinct algorithmic families COPOD (copula-based), ECOD (distribution-based), Isolation Forest (isolation-based), and KNN (distance-based) are applied independently within each traffic segment. The individual model outputs are then aggregated through an Ensemble Vote mechanism, which counts the number of models flagging each observation as anomalous, and an Ensemble Score, which combines normalized anomaly scores weighted by the vote ratio. Experiments conducted on a real-world CDR dataset comprising 142,924 aggregated daily customer records demonstrate that the segmentation-based approach produces more contextually relevant anomaly detections compared to global detection methods. The ensemble strategy achieves high inter-model agreement, with label correlations ranging from 0.72 to 0.95, confirming the robustness of the multi-perspective detection. The results indicate that 1,777 observations (1.24%) were flagged by at least one model, while 946 observations (0.66%) received unanimous agreement from all four models, representing the most critical anomalies warranting further investigation.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.