The Community for Technology Leaders
Green Image
Issue No. 03 - March (2014 vol. 26)
ISSN: 1041-4347
pp: 577-594
Massimiliano Albanese , Dept. of Appl. Inf. Technol., George Mason Univ., Fairfax, VA, USA
Cristian Molinaro , DIMES Dept., Univ. della Calabria, Cosenza, Italy
Fabio Persia , Dipt. di Ing. Elettr. e Tecnol. dell'Inf., Univ. di Napoli Federico II, Naples, Italy
Antonio Picariello , Dipt. di Ing. Elettr. e Tecnol. dell'Inf., Univ. di Napoli Federico II, Naples, Italy
V. S. Subrahmanian , Dept. of Comput. Sci., Univ. of Maryland, College Park, MD, USA
There are numerous applications where we wish to discover unexpected activities in a sequence of time-stamped observation data-for instance, we may want to detect inexplicable events in transactions at a website or in video of an airport tarmac. In this paper, we start with a known set A of activities (both innocuous and dangerous) that we wish to monitor. However, in addition, we wish to identify “unexplained” subsequences in an observation sequence that are poorly explained (e.g., because they may contain occurrences of activities that have never been seen or anticipated before, i.e., they are not in A). We formally define the probability that a sequence of observations is unexplained (totally or partially) w.r.t. A. We develop efficient algorithms to identify the top-k Totally and partially unexplained sequences w.r.t. A. These algorithms leverage theorems that enable us to speed up the search for totally/partially unexplained sequences. We describe experiments using real-world video and cyber-security data sets showing that our approach works well in practice in terms of both running time and accuracy.
Monitoring, Hidden Markov models, Computer security, Algorithm design and analysis, Correlation, Stochastic processes, Airports

M. Albanese, C. Molinaro, F. Persia, A. Picariello and V. S. Subrahmanian, "Discovering the Top-k Unexplained Sequences in Time-Stamped Observation Data," in IEEE Transactions on Knowledge & Data Engineering, vol. 26, no. 3, pp. 577-594, 2014.
204 ms
(Ver 3.3 (11022016))