本文へスキップ
AI図鑑

異常検知

大量の正常データから異質な少数を見つける

データとドキュメント中級 #40
入力表テキスト

本ページの本文は英語で提供されています。タイトルと導入は日本語化されています。

この能力とは何か

Takes data records or time series and outputs how far each deviates from the norm, or a flag. It usually works with few or no labelled anomalies, modelling what normal looks like and calling deviations anomalous. Unlike text classification the anomaly classes are not fixed, and in training you often do not know what an anomaly looks like at all.

技術的にどう実現するか

Unsupervised routes model normal data: autoencoders flag large reconstruction errors, isolation forests treat easily isolated points as anomalous, and statistical methods fit a distribution and score low-probability points. Time series often use a predictive framing, taking the residual between actual and forecast values as the score. With a few labels, semi-supervised or contrastive learning takes over, and cost-sensitive thresholds balance misses against false alarms.

代表的な製品

3

関連する組織

代表的な用途

  • Early warning for equipment and production-line faults
  • Spotting oddity in transactions and money laundering
  • Intrusion and abnormal-traffic monitoring
  • Quality sampling and data-entry error catching

どう評価するか

AUROC
Threshold-free ranking quality, usable on heavily imbalanced data
PR-AUC
More informative than AUROC when anomalies are extremely rare
Detection delay
Time from onset to alert, key in real-time settings

限界と難しさ

  • With so few anomalies a small threshold change spikes false alarms, and operators quickly go numb to them
  • Concept drift marks normal behaviour as anomalous, and seasonality or business change demands continual recalibration
  • In high dimensions with correlated features distance-based measures break down, diluting the gaps between normal points

背景にある概念