X-AddGraph is presented, a strictly post-hoc explainability framework built on a Dual Spatial-Temporal Attribution (DSTA) mechanism whose three components are each aligned with one of AddGraph's architectural modules: a gradient-based relevance attribution over the current adjacency structure (spatial), a direct reading of the contextual attention weights already computed during inference (short-term temporal), and a gradient rollback through the recurrent hidden states (long-term temporal).
Abstract
Deep learning detectors for anomalies in dynamic graphs have reached strong accuracy, yet they remain opaque: when an edge is flagged, the analyst receives a score but no reason. This opacity is untenable in the cooperative, regulated information systems where such detectors are deployed, where automated decisions must be auditable and trustworthy. We address this gap for AddGraph, the foundational GCN+GRU framework for edge-level anomaly detection in dynamic graphs, which to our knowledge has never been equipped with any form of explainability. We present a strictly post-hoc explainability framework, X-AddGraph, built on a Dual Spatial-Temporal Attribution (DSTA) mechanism whose three components are each aligned with one of AddGraph's architectural modules: a gradient-based relevance attribution over the current adjacency structure (spatial), a direct reading of the contextual attention weights already computed during inference (short-term temporal, at zero additional cost), and a gradient rollback through the recurrent hidden states (long-term temporal). Because the detector is frozen, detection performance is preserved exactly (Delta AUC = 0, verified empirically to ten decimal places). On the UCI Message benchmark, our trained AddGraph baseline reaches an average per-snapshot AUC of 0.8705, exceeding the originally published result; X-AddGraph reproduces every score identically while adding explanations where none existed. Evaluated across four edge populations - confident true positives, low-confidence true positives, false positives, and random samples - the long-term attribution identifies historical snapshots carrying significantly more counterfactual signal than random selection (0.127 vs. 0.074), a capability that no spatially-blind explainer can provide. We release our implementation for full reproducibility.
Anomaly detection in dynamic graphs underpins financial fraud analysis, intrusion detection, and platform integrity, where automated decisions require human-interpretable justifications. StrGNN, the strongest performer in recent benchmarks, produces no explanation: when an edge is flagged, the analyst receives only a s...
Iyad Assaad Nekka, H. Seba, Walid Khaled Hidouci et al.· 0 citations
BAD is proposed, an unsupervised framework for anomaly detection in continuous-time dynamic graphs that represents nodes with learnable identity embeddings and performs pairwise compatibility modeling via cross-attention between each destination node and the source’s recent neighbors, enabling direct characterization o...
Jia-Chi Luo, Sha-Meng Wen, Zi-Yan Qiu et al.· Proceedings of the Thirty-Fi...· 0 citations
Industrial information service systems are becoming increasingly complex, and timely anomaly detection and diagnosis are crucial for ensuring the quality of software services. System logs constitute a direct and important source of information for anomaly detection and diagnosis. However, existing methods struggle to s...
Xianlang Hu, Guangsheng Feng, Peng-Xin Li et al.· 2026 International Conferenc...· 0 citations
SimpleCount is proposed, a reference with no parameter fitting that selects one scalar feature per dataset from a fixed pool of counts, recencies, first-occurrence indicators, and count-derived transforms that matches or exceeds SLADE on three of six datasets and exceeds IsoForest on all six.
A statistical feature augmentation method that explicitly encodes behavioral interaction statistics into the input feature space and consistently improves detection performance is proposed, showcasing a promising approach for merging classical network analysis with deep learning.
Philipp Schlinge, Jean-Luc Schnipper, M. Atzmueller· 0 citations
Anomaly detection in building management systems (BMS) presents two challenges: context-agnostic thresholding, in which a single global threshold cannot simultaneously accommodate high-load weekday peaks and low-load weekend periods, and unfaithful temporal attribution, in which explanation maps are decoupled from the...
Chi Minh Hieu Nguyen, Ly-Huynh Phan· International Conference on...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.