{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/121978"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/121978","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Closed-loop network anomaly detection","abstract":"Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2024-03-01 without embargo terms","abstract_html":"Submission original under an indefinite embargo labeled &#x27;Open Access&#x27;. The submission was exported from vireo on 2024-03-01 without embargo terms","abstract_has_math":false,"creators":["Zhou, Qinghai"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Tong, Hanghang","Sun, Jimeng","Zhai, ChengXiang","Chau, Duen Horng"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2023,"date_issued":"2023-12","date_published":"2023-12","updated_at":"2026-07-22T22:25:00Z","subjects":["Data Mining","Graph Mining","Anomaly Detection","Graph Neural Networks"],"languages":["en","eng"],"rights":["Copyright 2023 Qinghai Zhou"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/2142/121978","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Tong, Hanghang","Sun, Jimeng","Zhai, ChengXiang","Chau, Duen Horng"]},{"key":"dc:creator","label":"Author","values":["Zhou, Qinghai"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2023-12","2023-11-14"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Data Mining","Graph Mining","Anomaly Detection","Graph Neural Networks"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en","eng"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2023 Qinghai Zhou"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/2142/121978"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2024-03-01 without embargo terms","The student, Qinghai Zhou, accepted the attached license on 2023-11-10 at 18:19.","The student, Qinghai Zhou, submitted this Dissertation for approval on 2023-11-10 at 18:19.","This Dissertation was approved for publication on 2023-11-14 at 14:16.","DSpace SAF Submission Ingestion Package generated from Vireo submission #19904 on 2024-03-01 at 13:14:17","Anomalies are defined as rare observations that significantly deviate from the majority. In recent years, with the networked data becoming ubiquitous, network anomaly detection (NAD), which aims to identify the rare objects in networks, has attracted remarkable attentions in a variety of high-impact applications, ranging from social network analysis (e.g., social spammer detection), online review system (e.g., opinion spam detection) to financial fraud (e.g., credit card fraud detection). Generally speaking, an NAD algorithm is composed of three major components, including (1) networks, (2) supervision, and (3) users. The vast majority of existing NAD techniques have been developed to take networks and supervision as input and deliver the detection results (e.g., a top-k list) to the end user. Despite tremendous advances being achieved, three key challenges remain. First (rich networks), real-world networks are often sourced from multiple instances or dynamically evolving, whereas the majority of existing NAD approaches are designed for single or multiple static aligned network(s). It remains nascent how to detect anomalies in rich (e.g., multiple, dynamic) networks. Second (weak supervision), the existing NAD methods are predominately developed in an unsupervised manner due to lack of supervision. Nevertheless, it has not been well studied on how to leverage low-cost weak supervision (e.g., limited number of labels, labels in coarse granularity) to design supervised algorithms. Third (user interaction), existing methods primarily regard the users as the passive receiving end of an NAD algorithm. It is imperative on how to bring the users into the NAD loop to boost both the interpretability and detection accuracy. The close interactions between the key challenges in NAD naturally necessitate four major tasks, namely predicting, auditing, augmenting and interpreting. First, predicting aims to advance the detection performance in complex networks by mining the crucial knowledge from weak supervised signals. Second, the auditing task studies how user-based anomalous activities and the corresponding alterations on graphs impact the network systems. Third, augmenting correlates users and networks, and explores reinforcing the supervision and network information, to improve NAD algorithms. The goal of interpreting is to help the end users understand the outcome of mining techniques through quantitative uncertainty estimation and intuitive visual explanations. The theme of my Ph.D. research is to collectively address the above key challenges in network anomaly detection through the four major tasks, including predicting, auditing, augmenting and interpreting. Specifically, for predicting, we have developed GDN to learn anomalous patterns from limited labeled anomalies and Meta-GDN which realizes effective meta-knowledge transfer across multiple networks by equipping GDN with a meta learning algorithm. In addition, we design a generic framework, Wedge which is capable of identifying node-level anomalies given coarse-grained subgraph supervision. Second, for auditing, we have designed a family of scalable algorithms, Admiring to analyze the impact of anomalous activities on multi-network systems, to graph learning results. Furthermore, we develop Attent, a generic influence-based query strategy to actively obtain user feedback. Third, for augmenting, we develop G-ADAM, a mixup-based NAD approach that can augment the original limited training data by adaptively interpolating data instances in the embedding space. Moreover, we have studied the problem of dynamically optimizing the user net- work (e.g., teams) with reinforcement learning. For the interpreting task, we have proposed JuryGCN, which is the first frequentist-based approach to quantify node uncertainty of graph convolutional network without model training. JuryGCN has demonstrated superiority in both active learning on node classification and semi-supervised node classification, and achieves the best effectiveness and lowest memory usage than the competitors. We also develop Extra, an interactive visualization tool, to provide intuitive visual explanations for results in the team recommendation scenario."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Closed-loop network anomaly detection"]}]}],"canonical_facts":{"dc:contributor":["Tong, Hanghang","Sun, Jimeng","Zhai, ChengXiang","Chau, Duen Horng"],"dc:creator":["Zhou, Qinghai"],"dc:date":["2023-12","2023-11-14"],"dc:description":["Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2024-03-01 without embargo terms","The student, Qinghai Zhou, accepted the attached license on 2023-11-10 at 18:19.","The student, Qinghai Zhou, submitted this Dissertation for approval on 2023-11-10 at 18:19.","This Dissertation was approved for publication on 2023-11-14 at 14:16.","DSpace SAF Submission Ingestion Package generated from Vireo submission #19904 on 2024-03-01 at 13:14:17","Anomalies are defined as rare observations that significantly deviate from the majority. In recent years, with the networked data becoming ubiquitous, network anomaly detection (NAD), which aims to identify the rare objects in networks, has attracted remarkable attentions in a variety of high-impact applications, ranging from social network analysis (e.g., social spammer detection), online review system (e.g., opinion spam detection) to financial fraud (e.g., credit card fraud detection). Generally speaking, an NAD algorithm is composed of three major components, including (1) networks, (2) supervision, and (3) users. The vast majority of existing NAD techniques have been developed to take networks and supervision as input and deliver the detection results (e.g., a top-k list) to the end user. Despite tremendous advances being achieved, three key challenges remain. First (rich networks), real-world networks are often sourced from multiple instances or dynamically evolving, whereas the majority of existing NAD approaches are designed for single or multiple static aligned network(s). It remains nascent how to detect anomalies in rich (e.g., multiple, dynamic) networks. Second (weak supervision), the existing NAD methods are predominately developed in an unsupervised manner due to lack of supervision. Nevertheless, it has not been well studied on how to leverage low-cost weak supervision (e.g., limited number of labels, labels in coarse granularity) to design supervised algorithms. Third (user interaction), existing methods primarily regard the users as the passive receiving end of an NAD algorithm. It is imperative on how to bring the users into the NAD loop to boost both the interpretability and detection accuracy. The close interactions between the key challenges in NAD naturally necessitate four major tasks, namely predicting, auditing, augmenting and interpreting. First, predicting aims to advance the detection performance in complex networks by mining the crucial knowledge from weak supervised signals. Second, the auditing task studies how user-based anomalous activities and the corresponding alterations on graphs impact the network systems. Third, augmenting correlates users and networks, and explores reinforcing the supervision and network information, to improve NAD algorithms. The goal of interpreting is to help the end users understand the outcome of mining techniques through quantitative uncertainty estimation and intuitive visual explanations. The theme of my Ph.D. research is to collectively address the above key challenges in network anomaly detection through the four major tasks, including predicting, auditing, augmenting and interpreting. Specifically, for predicting, we have developed GDN to learn anomalous patterns from limited labeled anomalies and Meta-GDN which realizes effective meta-knowledge transfer across multiple networks by equipping GDN with a meta learning algorithm. In addition, we design a generic framework, Wedge which is capable of identifying node-level anomalies given coarse-grained subgraph supervision. Second, for auditing, we have designed a family of scalable algorithms, Admiring to analyze the impact of anomalous activities on multi-network systems, to graph learning results. Furthermore, we develop Attent, a generic influence-based query strategy to actively obtain user feedback. Third, for augmenting, we develop G-ADAM, a mixup-based NAD approach that can augment the original limited training data by adaptively interpolating data instances in the embedding space. Moreover, we have studied the problem of dynamically optimizing the user net- work (e.g., teams) with reinforcement learning. For the interpreting task, we have proposed JuryGCN, which is the first frequentist-based approach to quantify node uncertainty of graph convolutional network without model training. JuryGCN has demonstrated superiority in both active learning on node classification and semi-supervised node classification, and achieves the best effectiveness and lowest memory usage than the competitors. We also develop Extra, an interactive visualization tool, to provide intuitive visual explanations for results in the team recommendation scenario."],"dc:format":["application/pdf"],"dc:identifier":["https://hdl.handle.net/2142/121978"],"dc:language":["en","eng"],"dc:rights":["Copyright 2023 Qinghai Zhou"],"dc:subject":["Data Mining","Graph Mining","Anomaly Detection","Graph Neural Networks"],"dc:title":["Closed-loop network anomaly detection"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:00Z"}