Обнаружение аномалий
Выделить немногие странные случаи среди массы нормальных
Полный текст статьи представлен на английском; заголовок и аннотация локализованы.
ЧТО ЭТО ЗА ВОЗМОЖНОСТЬ
Takes data records or time series and outputs how far each deviates from the norm, or a flag. It usually works with few or no labelled anomalies, modelling what normal looks like and calling deviations anomalous. Unlike text classification the anomaly classes are not fixed, and in training you often do not know what an anomaly looks like at all.
Как это устроено
Unsupervised routes model normal data: autoencoders flag large reconstruction errors, isolation forests treat easily isolated points as anomalous, and statistical methods fit a distribution and score low-probability points. Time series often use a predictive framing, taking the residual between actual and forecast values as the score. With a few labels, semi-supervised or contrastive learning takes over, and cost-sensitive thresholds balance misses against false alarms.
Примеры продуктов
3NeMo
2019Набор инструментов для обучения и настройки больших моделей
Hugging Face Hub
2016Открытый узел моделей и наборов данных
Transformers
2018Единый API для загрузки и обучения готовых моделей
Связанные организации
Типичное применение
- Early warning for equipment and production-line faults
- Spotting oddity in transactions and money laundering
- Intrusion and abnormal-traffic monitoring
- Quality sampling and data-entry error catching
Как её оценивают
- AUROC
- Threshold-free ranking quality, usable on heavily imbalanced data
- PR-AUC
- More informative than AUROC when anomalies are extremely rare
- Detection delay
- Time from onset to alert, key in real-time settings
Границы и трудности
- With so few anomalies a small threshold change spikes false alarms, and operators quickly go numb to them
- Concept drift marks normal behaviour as anomalous, and seasonality or business change demands continual recalibration
- In high dimensions with correlated features distance-based measures break down, diluting the gaps between normal points
Концепции в основе
Обучение без учителя
Без ответов структура должна проступить из самих данных — и само «хорошо» приходится определять заново
Вероятность и распределения
Модель не выдаёт «ответ», а даёт степень уверенности для каждого возможного ответа
Оценка модели и кросс-валидация
Точность — самый обманчивый показатель: ошибётесь в оценке, и рухнет всё остальное