Scoring conventions reorder adaptation policies in streaming anomaly detection

A streaming anomaly detector whose input distribution moves has to decide when to rebuild itself. We compare four answers to that question, holding everything else fixed: never rebuild, learn continuously, rebuild on a schedule, and rebuild when a drift detector fires. Scoring the same runs under four published conventions produces four different winners. One configuration places 8th of 10 under point-wise F1 and 2nd under the composite F-score on identical predictions; every one of the 10 strategies changes rank between those two conventions, and the largest single move is 6 places. The comparison runs over 10 seeds and the 15 labelled source recordings of SKAB, with paired Wilcoxon tests and Holm correction, and it crosses the two factors the usual presentation confounds: the anomaly model and the adaptation policy. Half-Space Trees and Isolation Forest are compared against three classical detectors (Local Outlier Factor, one-class SVM, minimum covariance determinant). Whether a strategy beats the trivial policy of flagging every row is itself convention-dependent: 7 of 10 clear it point-wise, 10 of 10 under the composite score, 3 of 10 under range-based scoring. On a third dataset, a subset of the UCR Anomaly Archive built expressly to replace benchmarks its authors judged flawed, the adaptation question stops mattering. No policy separates from the others, the static classical detectors match anything with a rebuild schedule, and under the archive's own threshold-free criterion the best of the ten strategies puts its peak score inside the labelled window on 12% of series, with the field averaging 6%. Every table and figure regenerates from the committed result files; the manuscript contains no hand-typed numbers. Code, logs and the full experimental grid are at GitHub

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-05
DOI
https://doi.org/10.5281/zenodo.22333127
Primary Topic
Anomaly Detection Techniques and Applications
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

Scoring conventions reorder adaptation policies in streaming anomaly detection

Dhruvil Shah
Zenodo (CERN European Organization for Nuclear Research)
Anomaly Detection Techniques and Applications
preprint

Scoring conventions reorder adaptation policies in streaming anomaly detection

Dhruvil Shah
preprint en

Abstract

A streaming anomaly detector whose input distribution moves has to decide when to rebuild itself. We compare four answers to that question, holding everything else fixed: never rebuild, learn continuously, rebuild on a schedule, and rebuild when a drift detector fires. Scoring the same runs under four published conventions produces four different winners. One configuration places 8th of 10 under point-wise F1 and 2nd under the composite F-score on identical predictions; every one of the 10 strategies changes rank between those two conventions, and the largest single move is 6 places. The comparison runs over 10 seeds and the 15 labelled source recordings of SKAB, with paired Wilcoxon tests and Holm correction, and it crosses the two factors the usual presentation confounds: the anomaly model and the adaptation policy. Half-Space Trees and Isolation Forest are compared against three classical detectors (Local Outlier Factor, one-class SVM, minimum covariance determinant). Whether a strategy beats the trivial policy of flagging every row is itself convention-dependent: 7 of 10 clear it point-wise, 10 of 10 under the composite score, 3 of 10 under range-based scoring. On a third dataset, a subset of the UCR Anomaly Archive built expressly to replace benchmarks its authors judged flawed, the adaptation question stops mattering. No policy separates from the others, the static classical detectors match anything with a rebuild schedule, and under the archive's own threshold-free criterion the best of the ten strategies puts its peak score inside the labelled window on 12% of series, with the field averaging 6%. Every table and figure regenerates from the committed result files; the manuscript contains no hand-typed numbers. Code, logs and the full experimental grid are at GitHub

Zenodo (CERN European Organization for Nuclear Research)
Life in Land
Anomaly Detection Techniques and Applications
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Scoring conventions reorder adaptation policies in streaming anomaly detection — Dhruvil Shah · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS