The paper introduces ADAEN, a hybrid framework combining dual autoencoder architectures with an attention layer to prioritize salient features in anomaly detection.
It integrates adversarial training with ranking-based prioritization and active learning, using GAN-generated augmentations to reduce labeled data requirements.
Empirical results demonstrate significant improvements in anomaly scoring and ranking across diverse operating systems, highlighting its applicability in real-world security contexts.
The Attention Adversarial Dual AutoEncoder (ADAEN) is a hybrid neural anomaly detection framework introduced for highly imbalanced detection tasks such as advanced persistent threat (APT) identification in security provenance trace data. ADAEN integrates dual autoencoder architectures, an attention mechanism, adversarial learning, ranking-based prioritization, and a data-efficient active learning loop with generative augmentation to achieve superior anomaly prioritization with minimal labeled data requirements (Benabderrahmane et al., 25 Nov 2025).
1. Dual AutoEncoder Architecture
ADAEN consists of two feed-forward autoencoders (AEs), denoted AE₁ and AE₂. AE₁ functions as a generator focusing on capturing core data characteristics, while AE₂ serves as a complementary refiner/discriminator, promoting distinct but compatible latent representations. Formally, let X={x(i)}i=1m with x(i)∈Rd. Each AE maps x∈Rd to a latent code z∈Rk and reconstructs it:
zj=fθj(x)=σ(We(j)x+be(j)),
x^j=gϕj(zj)=σ(Wd(j)zj+bd(j)),j=1,2
Each network uses LeakyReLU activations, batch normalization, and dropout. The loss for each AE is its mean squared reconstruction error:
Lrecj=∣X∣1x∈X∑∥x−gϕj(fθj(x))∥22
Total reconstruction loss is a weighted combination:
Lrec=αLrec1+(1−α)Lrec2,α=0.5
2. Attention Mechanism
ADAEN incorporates an attention layer between AE₁’s encoder and decoder to enhance focus on salient features or temporal slices of the latent code, z1∈RT×k. For each slice hi∈Rk and context vector x(i)∈Rd0, compute attention weights:
x(i)∈Rd1
The attended summary x(i)∈Rd2 is:
x(i)∈Rd3
This vector x(i)∈Rd4 is input to the decoder, enabling adaptive emphasis on features relevant for reconstruction, and consequently anomaly discrimination.
3. Adversarial Training Regime
ADAEN introduces an adversarial game where a discriminator x(i)∈Rd5 (parameterized as a 3-layer MLP) aims to separate genuine data from reconstructed outputs of AE₁ and AE₂. The adversarial losses are:
Discriminator:
x(i)∈Rd6
Generator (AE₁, AE₂):
x(i)∈Rd7
The overall objective combines reconstruction and adversarial losses via hyperparameter x(i)∈Rd8 (x(i)∈Rd9):
x∈Rd0
Optimization alternates between minimizing x∈Rd1 (updating x∈Rd2 with AE parameters fixed) and minimizing x∈Rd3 (updating AE parameters with x∈Rd4 fixed).
4. Anomaly Scoring and Ranking
During inference, ADAEN computes an anomaly score for each x∈Rd5:
x∈Rd6
Samples are sorted in descending order by x∈Rd7, producing a ranked anomaly list. Evaluation prioritizes high-fidelity ranking, employing normalized discounted cumulative gain (nDCG):
x∈Rd8
where x∈Rd9 is the anomaly label and z∈Rk0 is the ideal z∈Rk1.
5. Active Learning with Data Augmentation
To address limited labeled anomaly data, ADAEN incorporates an active learning protocol:
Train ADAEN on initial labeled set z∈Rk2 (all normals).
Score unlabeled pool z∈Rk3 by z∈Rk4.
Set threshold z∈Rk5 at the z∈Rk6-th percentile of z∈Rk7.
Optimization uses Adam (lr=Lrecj=∣X∣1x∈X∑∥x−gϕj(fθj(x))∥220-Lrecj=∣X∣1x∈X∑∥x−gϕj(fθj(x))∥221, Lrecj=∣X∣1x∈X∑∥x−gϕj(fθj(x))∥222=0.5, Lrecj=∣X∣1x∈X∑∥x−gϕj(fθj(x))∥223=0.999), batch size 128, and early stopping with patience 10 on validation Lrecj=∣X∣1x∈X∑∥x−gϕj(fθj(x))∥224.
7. Application Context and Empirical Results
ADAEN targets extreme class-imbalance settings, exemplified by APT detection where attacks comprise as little as 0.004% of events in provenance trace databases (DARPA Transparent Computing). Empirical evaluation spans Android, Linux, BSD, and Windows datasets under two distinct attack scenarios. Adoption of the ranking- and active-learning-enhanced protocol yields significant improvements in detection rates and ranking metrics (nDCG), outperforming previous approaches in prioritizing true anomalies with reduced labeling overhead. A plausible implication is that such an architecture facilitates deployment in real-world security infrastructure with minimal manual annotation requirements (Benabderrahmane et al., 25 Nov 2025).
“Emergent Mind helps me see which AI papers have caught fire online.”
Philip
Creator, AI Explained on YouTube
Sign up for free to explore the frontiers of research
Discover trending papers, chat with arXiv, and track the latest research shaping the future of science and technology.Discover trending papers, chat with arXiv, and more.