StreamPFN: Prior-Fitted Dynamic Graph Anomaly Detection from Synthetic Event Processes
Abstract
Dynamic graph anomaly detection (DGAD) flags abnormal edges in evolving networks, such as network intrusions and online fraud. Existing detectors either learn what an anomaly is from real graphs or encode it in fixed rules. However, simple anomaly signals change meaning across graphs: the same signal ranks anomalies above normal edges on some graphs and below them on others. A new graph also has no labels, so a frozen detector must infer from its unlabeled context which evidence to trust. We propose StreamPFN, a prior-fitted detector trained only on synthetic event streams. First, a synthetic prior generates normal processes, labeled anomalies, benign patterns that resemble them and varied recording conventions, and lets some attacks begin in the unlabeled prefix of a stream. Then, a graph-agnostic encoding describes each edge by its relations to recent edges and by relative time scales, so one transformer can score graphs it has never seen. Finally, a parameter-free gate compares an edge with the prefix when an attack dominates its recent history. On fourteen datasets, StreamPFN has the highest zero-shot AUROC on every dataset. On the seven datasets with real anomalies it averages 85.6%, compared with 59.9% for the best published baseline. Code is available at https://anonymous.4open.science/r/StreamPFN-DE6D/.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.