Rethinking Spatio-Temporal Anomaly Detection: A Vision for Causality-Driven Cybersecurity
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866909684052525056 |
|---|---|
| author | Malarkkan, Arun Vignesh Bai, Haoyue Wang, Xinyuan Kaushik, Anjali Wang, Dongjie Fu, Yanjie |
| author_facet | Malarkkan, Arun Vignesh Bai, Haoyue Wang, Xinyuan Kaushik, Anjali Wang, Dongjie Fu, Yanjie |
| contents | As cyber-physical systems grow increasingly interconnected and spatially distributed, ensuring their resilience against evolving cyberattacks has become a critical priority. Spatio-Temporal Anomaly detection plays an important role in ensuring system security and operational integrity. However, current data-driven approaches, largely driven by black-box deep learning, face challenges in interpretability, adaptability to distribution shifts, and robustness under evolving system dynamics. In this paper, we advocate for a causal learning perspective to advance anomaly detection in spatially distributed infrastructures that grounds detection in structural cause-effect relationships. We identify and formalize three key directions: causal graph profiling, multi-view fusion, and continual causal graph learning, each offering distinct advantages in uncovering dynamic cause-effect structures across time and space. Drawing on real-world insights from systems such as water treatment infrastructures, we illustrate how causal models provide early warning signals and root cause attribution, addressing the limitations of black-box detectors. Looking ahead, we outline the future research agenda centered on multi-modality, generative AI-driven, and scalable adaptive causal frameworks. Our objective is to lay a new research trajectory toward scalable, adaptive, explainable, and spatially grounded anomaly detection systems. We hope to inspire a paradigm shift in cybersecurity research, promoting causality-driven approaches to address evolving threats in interconnected infrastructures. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2507_08177 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Rethinking Spatio-Temporal Anomaly Detection: A Vision for Causality-Driven Cybersecurity Malarkkan, Arun Vignesh Bai, Haoyue Wang, Xinyuan Kaushik, Anjali Wang, Dongjie Fu, Yanjie Machine Learning Artificial Intelligence Emerging Technologies Neural and Evolutionary Computing F.2.2, I.2.7, I.2.4, I.2.1 As cyber-physical systems grow increasingly interconnected and spatially distributed, ensuring their resilience against evolving cyberattacks has become a critical priority. Spatio-Temporal Anomaly detection plays an important role in ensuring system security and operational integrity. However, current data-driven approaches, largely driven by black-box deep learning, face challenges in interpretability, adaptability to distribution shifts, and robustness under evolving system dynamics. In this paper, we advocate for a causal learning perspective to advance anomaly detection in spatially distributed infrastructures that grounds detection in structural cause-effect relationships. We identify and formalize three key directions: causal graph profiling, multi-view fusion, and continual causal graph learning, each offering distinct advantages in uncovering dynamic cause-effect structures across time and space. Drawing on real-world insights from systems such as water treatment infrastructures, we illustrate how causal models provide early warning signals and root cause attribution, addressing the limitations of black-box detectors. Looking ahead, we outline the future research agenda centered on multi-modality, generative AI-driven, and scalable adaptive causal frameworks. Our objective is to lay a new research trajectory toward scalable, adaptive, explainable, and spatially grounded anomaly detection systems. We hope to inspire a paradigm shift in cybersecurity research, promoting causality-driven approaches to address evolving threats in interconnected infrastructures. |
| title | Rethinking Spatio-Temporal Anomaly Detection: A Vision for Causality-Driven Cybersecurity |
| topic | Machine Learning Artificial Intelligence Emerging Technologies Neural and Evolutionary Computing F.2.2, I.2.7, I.2.4, I.2.1 |
| url | https://arxiv.org/abs/2507.08177 |