Structured data
Anomaly detection
fraud alerts, system monitoring, quality control
Flag unusual events with few or no labelled examples.
Probability & Bayes
Foundations
Every anomaly score is a density estimate in disguise.
Frame the problem
Frame
What counts as anomalous, the daily alert budget, and who reviews.
Exploring the data
Labeling & data collection
Data & labels
Go unsupervised only if labels truly do not exist. A few labelled incidents change the approach.
Create features
Represent
Rolling statistics and deviations from expected.
Temporal splits & backtesting
Split
Temporal, with known incidents in the test period.
Anomaly detection
Autoencoders
Classical time series
Model
Isolation forest first. Autoencoder reconstruction for high dimensions. Forecast residuals for time series.
Train
Nothing unusual here.
Evaluating without labels
Evaluate offline
Precision at the alert budget. Time-to-catch on known incidents.
Evaluate online
Nothing unusual here.
Serving & release
Monitor & retrain
Labeling & data collection
Ship & monitor
Thresholds drift; recalibrate. Reviewed alerts become labels: graduate to supervised.
Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.