The original single-step Decision score used by TCCM is sensitive to contamination, whereas trajectory-based Deviation and Reconstruction scores provide more stable anomaly signals, and Forest-Flow becomes competitive with, and in some cases outperforms, TCCM.
Abstract
Financial anomaly detection often relies on large unlabeled transaction logs, where anomalous samples may already be present during training. Such training-set contamination violates the clean-normal data assumption underlying many anomaly detection methods. Although flow matching has demonstrated strong performance in generative modeling, its robustness in unsupervised tabular anomaly detection remains underexplored. In this work, we study flow-matching-based anomaly detection under contaminated training data by comparing Time-Conditioned Contraction Matching (TCCM) with Forest-Flow and evaluating multiple anomaly scoring functions. Our results show that the choice of anomaly score is critical. The original single-step Decision score used by TCCM is sensitive to contamination, whereas trajectory-based Deviation and Reconstruction scores provide more stable anomaly signals. With these scores, Forest-Flow becomes competitive with, and in some cases outperforms, TCCM. These findings highlight the importance of anomaly scoring for flow-matching methods in financial anomaly detection under severe class imbalance.
Robust anomaly detection in time series remains challenging because sparse abnormal observations, noise contamination, nonlinear dynamics, and long-range temporal dependencies can obscure deviation patterns. This paper proposes the SALK anomaly detection model, which integrates an attention-enhanced long short-term mem...
LLM-Detector is proposed, a framework that utilizes the in-context learning capacity of LLMs for structured, prompt-conditioned scoring synthesis, enabling LLMs to derive anomaly detection logic from structured normal-state knowledge.
Tu Nguyen, Dang Nguyen, T. D. Le et al.· 0 citations
Anomaly detection is an essential part in industrial production which intends to identify anomaly samples and localize anomaly regions. Although current unsupervised anomaly detection methods have achieved excellent performance, they rely on clean and unlabeled normal samples. However, it is rarely satisfied in industr...
Anomaly detection systems are often trained using normal data alone, while model selection and evaluation typically require labeled anomalies. We study whether anomaly detection performance can be predicted without access to anomalous data. For kNN-based detectors, we derive a lower bound on the area under the ROC curv...
BAD is proposed, an unsupervised framework for anomaly detection in continuous-time dynamic graphs that represents nodes with learnable identity embeddings and performs pairwise compatibility modeling via cross-attention between each destination node and the source’s recent neighbors, enabling direct characterization o...
Jia-Chi Luo, Sha-Meng Wen, Zi-Yan Qiu et al.· Proceedings of the Thirty-Fi...· 0 citations
Anomaly detection in telecommunication traffic data plays a critical role in identifying fraudulent activities, network misuse, and abnormal usage patterns. Conventional approaches that perform anomaly detection globally or per business category often fail to account for the inherent heterogeneity of traffic patterns...
Rizqi Akbar Makarim, Ikhsan Tri Yogatama, Irfan Adi Nugroho et al.· bit-Tech· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.