Skip to content
Preprint

Dual Spatial-Temporal Attribution: Architecture-Aligned Post-Hoc Explainability for Recurrent Graph Anomaly Detection

Aug 2026 · 0 citations · 16 references
Computer Science

TL;DR

X-AddGraph is presented, a strictly post-hoc explainability framework built on a Dual Spatial-Temporal Attribution (DSTA) mechanism whose three components are each aligned with one of AddGraph's architectural modules: a gradient-based relevance attribution over the current adjacency structure (spatial), a direct reading of the contextual attention weights already computed during inference (short-term temporal), and a gradient rollback through the recurrent hidden states (long-term temporal).

Abstract

Deep learning detectors for anomalies in dynamic graphs have reached strong accuracy, yet they remain opaque: when an edge is flagged, the analyst receives a score but no reason. This opacity is untenable in the cooperative, regulated information systems where such detectors are deployed, where automated decisions must be auditable and trustworthy. We address this gap for AddGraph, the foundational GCN+GRU framework for edge-level anomaly detection in dynamic graphs, which to our knowledge has never been equipped with any form of explainability. We present a strictly post-hoc explainability framework, X-AddGraph, built on a Dual Spatial-Temporal Attribution (DSTA) mechanism whose three components are each aligned with one of AddGraph's architectural modules: a gradient-based relevance attribution over the current adjacency structure (spatial), a direct reading of the contextual attention weights already computed during inference (short-term temporal, at zero additional cost), and a gradient rollback through the recurrent hidden states (long-term temporal). Because the detector is frozen, detection performance is preserved exactly (Delta AUC = 0, verified empirically to ten decimal places). On the UCI Message benchmark, our trained AddGraph baseline reaches an average per-snapshot AUC of 0.8705, exceeding the originally published result; X-AddGraph reproduces every score identically while adding explanations where none existed. Evaluated across four edge populations - confident true positives, low-confidence true positives, false positives, and random samples - the long-term attribution identifies historical snapshots carrying significantly more counterfactual signal than random selection (0.127 vs. 0.074), a capability that no spatially-blind explainer can provide. We release our implementation for full reproducibility.

View source

Similar papers

Preprint Aug 2026

Amortised Post-Hoc Explanation with Exact Preservation for Dynamic Graph Anomaly Detectors

Anomaly detection in dynamic graphs underpins financial fraud analysis, intrusion detection, and platform integrity, where automated decisions require human-interpretable justifications. StrGNN, the strongest performer in recent benchmarks, produces no explanation: when an edge is flagged, the analyst receives only a s...

Iyad Assaad Nekka, H. Seba, Walid Khaled Hidouci et al. · 0 citations
Conference Open access Sep 2026

Unsupervised Anomaly Detection in Dynamic Graphs via Compatibility Modeling and Boundary Learning

BAD is proposed, an unsupervised framework for anomaly detection in continuous-time dynamic graphs that represents nodes with learnable identity embeddings and performs pairwise compatibility modeling via cross-attention between each destination node and the source’s recent neighbors, enabling direct characterization o...

Jia-Chi Luo, Sha-Meng Wen, Zi-Yan Qiu et al. · 0 citations
Conference Aug 2026

When Logs Are No Longer Just Sequences: A Multi-view Bidirectional Graph Convolutional Network for Anomaly Detection

Industrial information service systems are becoming increasingly complex, and timely anomaly detection and diagnosis are crucial for ensuring the quality of software services. System logs constitute a direct and important source of information for anomaly detection and diagnosis. However, existing methods struggle to s...

Xianlang Hu, Guangsheng Feng, Peng-Xin Li et al. · 0 citations
#edge computing Preprint Aug 2026

Beat the Counter First: A Baseline for Temporal-Graph Anomaly Detectors

SimpleCount is proposed, a reference with no parameter fitting that selects one scalar feature per dataset from a fixed pool of counts, recencies, first-occurrence indicators, and count-derived transforms that matches or exceeds SLADE on three of six datasets and exceeds IsoForest on all six.

Omair Shafi Ahmed, Zohair Shafi · 0 citations
#machine learning Preprint Sep 2026

Statistical Feature Augmentation for Anomaly Detection in Dynamic Graphs

A statistical feature augmentation method that explicitly encodes behavioral interaction statistics into the input feature space and consistently improves detection performance is proposed, showcasing a promising approach for merging classical network analysis with deep learning.

Philipp Schlinge, Jean-Luc Schnipper, M. Atzmueller · 0 citations
Conference Aug 2026

TRACE: Temporal Reconstruction with Aligned Context Explanations for anomaly detection in building energy systems

Anomaly detection in building management systems (BMS) presents two challenges: context-agnostic thresholding, in which a single global threshold cannot simultaneously accommodate high-load weekday peaks and low-load weekend periods, and unfaithful temporal attribution, in which explanation maps are decoupled from the...

Chi Minh Hieu Nguyen, Ly-Huynh Phan · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.