Professional Documents
Culture Documents
Anomaly Analysis For DIA
Anomaly Analysis For DIA
Auroop R. Ganguly
Olufemi A. Omitaomu
GIST Group
CSE Division
Oak Ridge National Laboratory
Managed by UT-Battelle
for the Department of Energy
Offline Analysis of Disparate Data
Leads to Faster and More Reliable
Real-Time Decisions
Consequences Action Additional Data
Hypothesis Generation
Stream of
New Data
2 Managed by UT-Battelle
for the Department of Energy
Two Distinct Case Studies
3 Managed by UT-Battelle
for the Department of Energy
Online Detection of Anomaly, Change
and Change Point from Space-Time Data
Problem Statement: Develop approaches that
can detect anomalies, change and change point
from time series and spatial data in an online
mode for application in threat cognizance and
remote sensing.
Technical Approach: Methods motivated from
statistical process control detect large outliers
and sustained anomalies or change in space
and time, and methods motivated by simulated
annealing detect change points.
Benefit: Real-time change or anomaly analysis
in distributed applications; Examples in threat
cognizance and remote sensing.
4 Managed by UT-Battelle
for the Department of Energy
Remote Sensing Change Detection
Student Collaborators
Nagendra Singh1, ORAU
Veeraraghavan Vijayaraj1, ORAU
Neil Feierabend1, ORAU
David T Potere1, ORAU
1: CSED Post-Master
5 Managed by UT-Battelle
for the Department of Energy
State of the Art in Online KD
Alarm Generation via Adaptive Metrics
6 Managed by UT-Battelle
for the Department of Energy
Ganguly and
Fang, 2006 Special Session: Sensor-Cyber Networks for Homeland Defense
7 Managed by UT-Battelle
for the Department of Energy
Domain
Remotely Sensed Land Cover and Wal-Mart
Data sets
– 16-day NDVI Composites (UMD)
– Wal-Mart data for validation (Potere et al., 2006)
Case study
– 3 Wal-Mart Stores (CA, ME, NC)
– Space: “Construction”, “bordering”, “background”
– Time: “Groundbreaking”; “Store Opening”
8 Managed by UT-Battelle
for the Department of Energy
Wal-Mart’s Spread
1962 - 2004
10 Managed by UT-Battelle
Courtesy: Feierebend et al., 2006 (AAG)
for the Department of Energy
All 3 Sites Courtesy: Feierebend et al., 2006 (AAG)
Indicates
Opening
Date
11 Managed by UT-Battelle
for the Department of Energy
Method
Online Change Detection
Reference Model
– Difference of the Time Series (“Wal-Mart” vs. “Background”)
– Cube Root Transform for Variance Stabilization
– Transformed, Difference Time Series: IID and Gaussian
Results
– CA store: Groundbreaking available Near perfect validation
– ME, NC Stores: Groundbreaking not available
Approximate match
– Experiments consistent with expectations
13 Managed by UT-Battelle
for the Department of Energy
Conclusion: Online Performance
Computational Complexity
– Alarm Generation: O(1) or constant time
– Change-Point Detection: O(1) to O(n)
– Parameter Updates: O(1)
Online Updates
– New Severity Metric requires the following:
Current Severity metric
New Data
14 Managed by UT-Battelle
for the Department of Energy
Anomaly analysis from heterogeneous
data for transportation security
Problem Statement: Provide an end user with
the ability to make fast and reliable decisions
on whether a truck at a weigh station
represents a plausible security threat, for
example, owing to camouflaged illicit
radioactive materials, by using historical truck
data and new truck information from disparate
sensors.
Technical Approach: A multivariate statistical
characterization of trucks based on analysis of
archived historical information in an offline
mode, and an online analysis of new truck data,
helps detect potential anomalous behavior
from heterogeneous sensor data.
Benefit: Reduces false alarms without
Offline analysis of normal behavior compromising on the probability of detection,
informs online anomaly analysis, which is leading to greater potential for ensuring
presented in a usable form to end-users transportation security without disrupting
commerce.
15 Managed by UT-Battelle
for the Department of Energy
Transportation Security Team
1: CSED Post-Master
2: CSED Post-Doc
3: Univ. PhD Student
16 Managed by UT-Battelle
for the Department of Energy
Case Study: Weigh Station Inspection Process
Other Data/Metadata
– Image Data (e.g., truck image and license plate)
– Text Data (e.g., cargo manifest)
– Combined Image and Text Data (e.g., drivers license)
18 Managed by UT-Battelle
for the Department of Energy
Offline Anomaly in Static Scale Data
19 Managed by UT-Battelle
for the Department of Energy
Online Anomaly in Static Scale Data
20 Managed by UT-Battelle
for the Department of Energy
Novel Approach for Denoising Signals
21 Managed by UT-Battelle
for the Department of Energy
Anomaly in Radiation Signals
the data
CASE 1 CASE 2
Gross Counts
0.6 0.6
0.4 0.4
0
0.2
CASE 3
0.15 0.2 0 0.05 0.1
CASE 4
0.15 0.2
turn:
0.8 0.8
Gross Counts
0.6 0.6
0.4 0.4
CASE 5
0.15 0.2
0
0 0.05 0.1
ALL CASES
0.15 0.2
0.8 0.8
0.6 0.6
CASE 2
0.4 0.4 CASE 3
networks
22 Managed by UT-Battelle
for the Department of Energy
Offline Analysis of Disparate Data
Leads to Faster and More Reliable
Real-Time Decisions
Consequences Action Additional Data
Hypothesis Generation
Stream of
New Data
23 Managed by UT-Battelle
for the Department of Energy
Demonstration: ADRAT
24 Managed by UT-Battelle
for the Department of Energy