Chapter Four · failure evidence

What Anomaly Detection got wrong, from 73 dissertations

The records document recurring failures and practical challenges encountered across machine learning and statistical anomaly detection techniques. Across varied domains, models frequently suffer from excessive false alarms, vulnerability to stealthy adversaries, poor generalization to unseen faults, and performance degradation from lossy feature representations. These records come from PhD theses at 24 institutions, 2021 to 2026. Each links to its thesis. They were extracted by language models reading the full text, so treat each as a lead to read, not a verdict.

Deep generative and reconstruction models struggle with latent constraints and faithful anomaly scoring

18 theses · 11 institutions

Unsupervised autoencoders and generative architectures often overfit to nominal or synthetic data, over-smooth extreme values, and generate false positive artifacts along anatomical boundaries. Imposing latent regularization constraints degrades reconstruction fidelity and discriminability, leading these complex architectures to be repeatedly outperformed by simpler baselines such as isolation forests.

Tried and failed

imposing latent space regularisation constraints applied to out-of-distribution detection via reconstruction error. Outcome: worse than baseline. Reason: latent constraints degrade reconstruction fidelity compared to unconstrained autoencoders, reducing anomaly detection discriminability

Learning Representations Toward the Understanding of Out-of-Distribution for Neural Networks · Georgia Tech

Tried and failed

non-linear autoencoders for dimensionality reduction applied to unsupervised anomaly detection. Outcome: worse than baseline. Reason: non-regularized non-linear dimensionality reduction degraded performance compared to linear methods like PCA

On the Effectiveness of Dimensionality Reduction for Unsupervised Structural Health Monitoring Anomaly Detection · Virginia Tech

Tried and failed

analytic KL-divergence instead of latent adversarial training applied to unsupervised visual anomaly detection. Outcome: worse than baseline. Reason: analytic KL approximation degraded representation quality compared to adversarial latent matching for anomaly scoring

Exploring variability in medical imaging · Imperial

Tried and failed

L2 regularization on autoencoder dimensionality reduction applied to unsupervised anomaly detection. Reason: higher regularization penalties caused underfitting and unpredictable performance degradation

On the Effectiveness of Dimensionality Reduction for Unsupervised Structural Health Monitoring Anomaly Detection · Virginia Tech

Tried and failed

Transformer architecture alone for anomaly detection applied to time-series anomaly detection. Outcome: worse than baseline. Reason: Standalone Transformer encoder underperformed recurrent neural network architectures in sequential state anomaly detection

An assessment of deep cyber-physical situational awareness of power system using real-time testbed · Texas Tech

Tried and failed

deep autoencoding Gaussian mixture model applied to time series anomaly detection. Outcome: worse than baseline. Reason: achieved poor F1 scores on standard benchmarks using high anomaly score thresholds

Wavelet probabilistic neural networks for temporal data analysis · Imperial

Tried and failed

reconstruction-based neural autoencoders applied to time series anomaly detection. Outcome: did not generalise. Reason: models over-smoothed extreme values or erroneously fit out-of-range outlier points

Machine Learning Systems for Unsupervised Time Series Anomaly Detection · MIT

Tried and failed

variational auto-encoders for counterfactual generation applied to anomaly repair and explanation. Outcome: worse than baseline. Reason: struggled to generate high-quality repairs compared to diffusion models

Reliable Anomaly Detection with Explanation and Feedback · Penn

Tried and failed

variational autoencoder anomaly detection applied to semiconductor fabrication process monitoring. Outcome: overfit. Reason: overfitting on nominal training data caused high reconstruction error on unseen nominal runs, degrading classification

Applications of Probabilistic Machine Learning Models to Semiconductor Fabrication · MIT

Tried and failed

batch normalization applied to autoencoder anomaly detection. Reason: did not improve anomaly detection performance during model development

Developing AI Systems for Monitoring Heterogeneous Mental Health Disorders · Cornell

Lost to a baseline

Random Forest beat Autoencoders on pointwise anomaly detection accuracy (RF: 0.963 vs AE: 0.937) and F1-score (RF: 0.967 vs AE: 0.953)

An AI and data-driven approach to unwanted network traffic inspection · IRIS - POLITO - prod

Lost to a baseline

VAE + DoSE (AUROC 0.698) and One-Class SVM (AUROC 0.605) lost to baseline Isolation Forest (AUROC 0.850) on anomaly detection.

Optimising data collection strategies in cyber security to address bias · Imperial

Lost to a baseline

On CIFAR-10 anomaly set {4,5,6,7,8}, standard Autoencoder achieved 60.8 AUROC while the proposed method achieved 54.0 AUROC.

Robust and Cross-Domain Anomaly Detection and Mitigation · unevada

Lost to a baseline

On MVTec AD anomaly detection, standard DeepSVDD achieved 72.2% AUC and DROCC achieved 74.5% AUC, beating the generative baseline AnoGAN (50.3% AUC).

Few Shot Anomaly Detection and Segmentation in Medical Imaging · Research Repository UCD

Considered and rejected

Considered and rejected: Rejected relying solely on reconstruction error for point anomaly detection, requiring variational auto-encoders with regularized latent spaces instead.

Topics of deep learning in security and compression · OpenBU

Tried and failed

generative image-to-image translation for anomaly detection applied to medical imaging lesion detection. Reason: over-correction at normal anatomical boundaries and vessels generated false-positive artifact hotspots in anomaly maps

HYBRID INTELLIGENCE FRAMEWORK FOR PATHOLOGICAL LIVER SEGMENTATION AND LESION DETECTION IN DIAGNOSTIC CT IMAGING · Penn

Tried and failed

training temporary autoencoders on small shifted batches applied to continual anomaly detection under distribution shift. Outcome: overfit. Reason: training standalone models solely on small drifted batches led to severe overfitting and poor generalization

Mitigating distribution shift and label noise in deep neural network based network intrusion detection systems · Imperial

Tried and failed

MLP-based variational autoencoder applied to cross-dataset structural anomaly detection. Outcome: did not generalise. Reason: model overfitted to source structure distributions and failed on unseen structural data

Machine learning tools for identifying structural artifacts in data · Imperial

Tried and failed

fast anomaly GAN for anomaly detection applied to network intrusion detection. Outcome: unstable. Reason: large instability between benign and anomaly detection F1 scores across datasets

Detecting Irregular Network Activity with Adversarial Learning and Expert Feedback · Virginia Tech

Complex architectures and ensembling strategies fail to outperform simpler algorithmic baselines

15 theses · 10 institutions

Complex modeling choices like standalone transformers, naive Boolean logic combinations, and specialized neural networks degraded detection accuracy compared to standard baselines like random forests. Training modifications such as continuous stochastic weight averaging or omitting instance noise also introduced severe training instability and overfitting across operating environments.

Tried and failed

augmenting training set sampling dynamically applied to multivariate statistical process control anomaly detection. Outcome: worse than baseline. Reason: training set corruption by undetected false-negative observations

Automated monitoring of test-taking behavior in online assessments · UT Austin

Tried and failed

Boolean logic ensemble combination of anomaly detectors applied to multi-model anomaly detection fusion. Outcome: worse than baseline. Reason: OR logic inflated false positive rates while AND logic caused unacceptable missed detections

Tenko++: Next-Gen Lightweight Intrusion Detection with Context-Aware Anomaly Scoring · Virginia Tech

Tried and failed

random sampling of reference comparison sets applied to pairwise anomaly detection in authentication logs. Outcome: worse than baseline. Reason: yielded low F1 scores (38% to 43%) on test sets

Characterizing and Detecting Password Guessing Attacks · Cornell

Lost to a baseline

Time-invariant SPC anomaly detector lost to all benchmark methods across all datasets, achieving only 0.21% and 0.54% TPR at 1% FPR on plasma etch recipes.

Applications of Probabilistic Machine Learning Models to Semiconductor Fabrication · MIT

Lost to a baseline

Classifiers trained on full trace features (accuracy 0.71) were outperformed on Linux kernel 4.15.0-91 anomaly detection by optimal phase classifiers (0.80) and classifier ensembles (0.64).

Physical side channels in embedded hardware security : analysis and defenses · UT Austin

Tried and failed

logistic loss in classification-based level set estimation applied to unsupervised anomaly detection. Outcome: worse than baseline. Reason: non-zero asymptotic loss degraded performance compared to hinge loss

Statistical Learning Theory of Deep Neural Networks: A Generalization Viewpoint · Georgia Tech

Lost to a baseline

LSTM-Node2vec achieved 0.682581 anomaly detection AUC on Contact dataset, losing to dyngraph2vecAERNN (0.76226) and dyngraph2vecAE (0.732996)

Learning Effective Embeddings for Dynamic Graphs and Quantifying Graph Embedding Interpretability · YorkSpace

Tried and failed

continuous stochastic weight averaging applied to anomaly detection in medical images. Outcome: unstable. Reason: training instability severely degraded anomaly detection scores compared to discrete checkpoint averaging

Machine learning for outlier detection in medical imaging · Imperial

Tried and failed

training density estimators without instance noise regularization applied to tabular categorical anomaly detection. Outcome: overfit. Reason: omitting instance noise achieved lower training loss but degraded test generalization

A Framework for Automated Discovery and Analysis of Suspicious Trade Records · Virginia Tech

Lost to a baseline

DiffUnc without SAM achieved lower FPR95 (0.282) than with SAM (0.514) on RUGD anomaly detection.

Human-Inspired Methods for Extending Advances in Computer Vision to Data- and Compute-Constrained Environments · MIT

Lost to a baseline

On MNIST anomaly detection with N=2 and N=5 reference shots, IGD achieved 80.1% and 83.4% AUC, outperforming DeepSVDD (75.9% and 78.8%) and DROCC (64.3% and 70.3%).

Few Shot Anomaly Detection and Segmentation in Medical Imaging · Research Repository UCD

Lost to a baseline

ML-II was beaten by MAP-II estimate on subtle damage detection (10% stiffness reduction), where ML-II anomaly scores failed to cleanly separate distributions

Anomaly Detection in the Vibration of Wind Turbine Blades using Gaussian Process Regression · Carleton University Institutional Repository

Considered and rejected

Considered and rejected: Rejected data augmentation for industrial anomaly detection due to risks of overfitting and need for complex augmentation strategies.

Neuro-Symbolic Integration in Artificial Intelligence and its Applications · IRIS - POLITO - prod

Tried and failed

deep neural networks for time-series anomaly detection applied to network traffic anomaly detection. Outcome: did not generalise. Reason: severe overfitting caused performance collapse across operational modes, locations, and time periods

Anomaly detection for IoT environments · Imperial

Tried and failed

Single decision tree classification applied to anomaly detection in time-series measurements. Outcome: worse than baseline. Reason: Lacked ensemble averaging, resulting in lower detection accuracy across all tree depths compared to random forest

Protection and Cybersecurity of Inverter-Based Resources · Virginia Tech

Anomaly detectors suffer from excessive false alarms due to nominal variations and rigid contamination thresholds

13 theses · 10 institutions

Detectors frequently trigger false positive alarms when benign operating workloads, background noise, or contaminated baseline data mimic anomaly patterns. Rigid mechanisms like fixed contamination percentages and forced cluster counts further inflate false alarm rates under nominal conditions where no actual anomalies exist.

Tried and failed

missing signal anomaly detection applied to industrial control system anomaly detection. Reason: monitoring missing signals alone caused high false positives without adjusting detection thresholds

Detection and Forensic Analysis of Modern ICS Attacks Via Correlating Scada Host Operations with Physical Behavior · Georgia Tech

Tried and failed

performance counter machine learning anomaly detection applied to microarchitectural attack detection. Outcome: did not generalise. Reason: high false positive rates on benign workloads structurally mimicking attack patterns

Towards microarchitectural side-channel security for modern applications—a case for many-domain processors · UT Austin

Tried and failed

hidden Markov model for anomaly detection applied to combustion instability detection. Outcome: did not generalise. Reason: excessive false positive rate classifying normal conditions as anomalies

Trustworthy deep learning for cyber-physical systems · Iowa State

Tried and failed

density and isolation-based anomaly detection applied to oil production time series anomaly detection. Reason: algorithms rigidly flagged arbitrary fixed contamination percentages, generating high false positive rates

Enhanced Oil Field Data-Wrangling using Machine Learning · Texas Tech

Tried and failed

support vector machine for anomaly detection applied to multivariate time series fault diagnosis. Reason: produced false positives under nominal operating conditions, incorrectly triggering mitigation procedures

A Methodology for the Selection and Integration of Self-Healing Architectures in Human Habitation Design · Georgia Tech

Tried and failed

low statistical threshold anomaly detection applied to sediment core grain size anomalies. Outcome: no signal. Reason: background signal noise caused false positive anomaly detections at lower standard deviation thresholds

Environmental Drivers of Coastal Evolution · MIT

Tried and failed

autoregressive anomaly detection with contaminated training data applied to hydraulic sewer surcharge detection. Outcome: did not generalise. Reason: fitting the model on baseline data containing pre-existing anomalies causes high false positive rates

Sensor-driven flood risk monitoring in levee-protected floodplains and urban storm sewer networks · Cornell

Considered and rejected

Considered and rejected: Rejected machine learning / anomaly-based IDS due to high false-positive rates in operational technology environments.

Design, implementation, and field-testing of distributed intrusion detection system for smart grid SCADA network · Iowa State

Considered and rejected

Considered and rejected: Rejected standalone ESN and deep neural architectures due to lack of interpretability, inability to enforce hard logical constraints, and high false positive rates in anomaly detection.

Enhancing Logical Reasoning and Temporal Dynamics in Complex Systems through Hybrid Logical Neural and Echo State Networks · unevada

Considered and rejected

Considered and rejected: Rejected k-means clustering for constellation anomaly detection because it forces fixed k clusters, leading to false positives when no anomaly exists.

Design of a Co-Orbital Threat Identification System · Virginia Tech

Considered and rejected

Considered and rejected: Fixed geometric thresholding for crack detection was rejected in favor of unsupervised anomaly detection due to sensitivity to manual parameter tuning across scenes.

3D Segmentation and Damage Analysis from Robotic Scans of Disaster Sites · Georgia Tech

Considered and rejected

Considered and rejected: Rejected manual thresholding of roll rate (omega_x) crossings for anomaly side classification due to susceptibility to sensor noise and overfitting to specific anomaly shapes.

Autonomous Ground Vehicle Guidance and Mapping in Challenging Terrains by using On-Board Vibration Measurements · Queens University Institutional Repository

Tried and failed

isolation forest on noisy time series features applied to physiological anomaly detection. Outcome: did not generalise. Reason: unacceptable false alarm rates when applied to noisier real-world dataset

Self-Aware Machine Learning for Chronic Pathology Monitoring on Wearable Devices · EPFL

Dimensionality reduction and feature transformations discard critical anomaly signatures

13 theses · 10 institutions

Compacting inputs through principal component analysis, coarse discretization, or autoencoder compression discards subtle variance directions and spectral signatures required to separate anomalies from nominal states. In unsupervised tabular settings, ranking metrics and unselected noisy features prioritize common high-variance artifacts while masking true anomalous shifts.

Tried and failed

shallow unsupervised anomaly detection algorithms applied to subtle network traffic anomaly detection. Outcome: no signal. Reason: algorithms fail to capture subtle anomaly signatures in complex high-dimensional traffic patterns

Detecting Irregular Network Activity with Adversarial Learning and Expert Feedback · Virginia Tech

Tried and failed

missing data imputation indicator feature engineering applied to time series anomaly detection. Outcome: no signal. Reason: imputed missing data features failed to discriminate anomaly states from normal baseline days

Developing AI Systems for Monitoring Heterogeneous Mental Health Disorders · Cornell

Tried and failed

reconstruction and one-class anomaly detection methods applied to time-series sensor anomaly detection. Outcome: no signal. Reason: anomalies overlapped with nominal distribution support or concentrated near the nominal mean

A Deep Learning Approach to State Estimation and Bad Data Detection · Cornell

Tried and failed

coarse discretization of continuous physical states applied to cyber-physical system anomaly detection. Outcome: worse than baseline. Reason: coarse quantization degraded state representation fidelity, reducing true positive detection rates compared to continuous precision

Detection and Forensic Analysis of Modern ICS Attacks Via Correlating Scada Host Operations with Physical Behavior · Georgia Tech

Considered and rejected

Considered and rejected: Frequency-domain feature extraction for ICS anomaly detection, rejected due to inability to detect short-duration anomalies requiring long time windows

Robust Anomaly Detection in Critical Infrastructure · IRIS - UNITN - prod

Tried and failed

deep out-of-distribution detection models applied to tabular anomaly detection. Outcome: worse than baseline. Reason: deep VAE and density-based models underperformed simple Isolation Forest on engineered tabular features

Optimising data collection strategies in cyber security to address bias · Imperial

Lost to a baseline

Autoencoder and PCA dimensionality reduction were both beaten by raw feature representation (no dimensionality reduction) across all anomaly detection models (e.g., IF Top 100: 10.8 raw vs 6.6 autoencoder vs 0.2 PCA).

THE EFFECTIVENESS OF MACHINE LEARNING-BASED ANOMALY DETECTION ALGORITHMS APPLIED TO DEFENSE CONTRACT FINANCIAL DATA · Calhoun

Tried and failed

dimensionality reduction feature preprocessing applied to unsupervised anomaly detection on spectral features. Outcome: worse than baseline. Reason: compression discards subtle anomaly-discriminating spectral signatures needed for novelty detection

On the Effectiveness of Dimensionality Reduction for Unsupervised Structural Health Monitoring Anomaly Detection · Virginia Tech

Tried and failed

heuristic anomaly detection on interaction logs applied to identifying reinforcement learning cyberattackers. Outcome: no signal. Reason: noisy and short interaction traces prevented reliable discrimination between attackers and benign users

Communication and generalization in multi-agent learning · UT Austin

Tried and failed

individual acoustic emission statistical feature thresholding applied to mechanical wear anomaly detection. Outcome: no signal. Reason: features showed inconsistent and non-monotonic trends across damage progression states

Practical and generally applicable condition based maintenance (CBM) system for mud pump · UT Austin

Tried and failed

training anomaly detection on unselected high-dimensional features applied to structural damage severity estimation. Outcome: no signal. Reason: irrelevant features and environmental noise masked the monotonic degradation signal in the anomaly metric

Data-Driven Structural Health Monitoring of Wind Turbine Blades under Operational and Environmental Variability · Research Repository UCD

Tried and failed

PCA dimensionality reduction before one-class SVM applied to anomaly detection from sensor data. Outcome: worse than baseline. Reason: Nominal-only PCA bases discarded variance directions critical for distinguishing faulty signals

Applications of Probabilistic Machine Learning Models to Semiconductor Fabrication · MIT

Tried and failed

Isolation Forest anomaly detection on tabular features applied to time-series photometric anomaly detection. Reason: Unsupervised ranking prioritized common high-variance outliers and measurement artifacts over rare scientific phenomena of interest

Needles in the Haystack: Unsupervised Methods of Anomaly Detection in Astronomical Surveys · Harvard

Supervised anomaly detection fails due to severe label scarcity and poor generalization to unseen anomalies

9 theses · 7 institutions

Supervised classifiers cannot reliably detect novel anomalies because they depend on exhaustive labeled attack data that is rarely available in real-world systems. When trained on imperfect, scarce, or synthetic anomaly labels, these models overfit and perform near random on unseen attack variants.

Tried and failed

supervised classification on compromised account labels applied to authentication log anomaly detection. Reason: classifiers yielded poor precision due to noisy or imperfect ground-truth attack labels

Characterizing and Detecting Password Guessing Attacks · Cornell

Tried and failed

One-Class SVM and feedforward autoencoders applied to sequential anomaly detection in logs. Outcome: did not generalise. Reason: Unable to reliably detect anomalies without supervised attack knowledge for tuning hyperparameters

Data-driven Algorithms for Critical Detection Problems: From Healthcare to Cybersecurity Defenses · Virginia Tech

Considered and rejected

Considered and rejected: Rejected supervised anomaly detection methods (logistic regression, kNN, SVM) due to inability to generalize to unseen anomaly types and lack of labeled data

Toward an Automated Real-Time Anomaly Detection Engine in Microservice Architectures · Carleton University Institutional Repository

Considered and rejected

Considered and rejected: Rejected fully supervised anomaly detection for cross-domain and medical imaging tasks due to extreme class imbalance and lack of exhaustive anomaly labels.

Robust and Cross-Domain Anomaly Detection and Mitigation · unevada

Considered and rejected

Considered and rejected: Rejected machine learning (ML) / deep learning approaches for in-situ anomaly detection due to lack of explainability, need for massive human-tagged training sets, and certification standard barriers (Fixed Process Control).

Multi-Scale Materials Characterization and Analysis of In-Situ Process Monitoring Data towards enabling Multivariate Statistical Process Control in Laser Powder Bed Fusion Metal Additive Manufacturing · Georgia Tech

Tried and failed

deep overparameterized classification on synthetic anomalies applied to unsupervised anomaly detection. Outcome: did not generalise. Reason: achieved zero training loss while overfitting to the synthetic reference distribution rather than learning true density boundaries

Statistical Learning Theory of Deep Neural Networks: A Generalization Viewpoint · Georgia Tech

Considered and rejected

Considered and rejected: Avoided training custom segmentation networks for industrial anomaly detection because anomalies are unlabelled and not predefined.

Neuro-Symbolic Integration in Artificial Intelligence and its Applications · IRIS - POLITO - prod

Tried and failed

empirical risk minimization with halfspace neural networks applied to anomaly and intrusion detection. Outcome: did not generalise. Reason: failed to generalize to unseen attack types, performing near random

Characterizing anomalies for reliable machine learning · Georgia Tech

Tried and failed

supervised data-driven predictive maintenance applied to basic single-asset anomaly detection. Outcome: data insufficient. Reason: insufficient historical labelled failure data for training supervised models

Investigation on Predictive Maintenance Implementation Cost-Efficiency · Cranfield

Residual and threshold-based statistical detectors are easily bypassed by stealthy dynamic adversaries

8 theses · 6 institutions

Stateful residual monitors and innovation-based chi-squared tests fail to detect attacks because intelligent adversaries dynamically modulate perturbations to remain within nominal variance thresholds. Assumptions like Gaussian prediction intervals break down under heterogeneous data distributions, allowing stealthy false data injections to go undetected prior to physical impact.

Tried and failed

CUSUM stateful residual anomaly detection applied to stealthy false data injection attacks. Reason: Simulation-backed stealthy injection attacks bypassed residual accumulation thresholds, yielding extremely high false negative rates.

Achieving Security and Reliability of Industrial Control Systems Using Data-Driven Models Informed by Physical Domain Knowledge · Georgia Tech

Tried and failed

residual-based statistical anomaly detection for ramp attacks applied to cyber-attack detection in physical systems. Reason: increasing attack magnitude made anomalies trivially detectable over time compared to subtle bias attacks

Cyber Security of Grid-Scale Battery Energy Storage Systems using Battery Modeling and Statistical Methods · Texas Tech

Considered and rejected

Considered and rejected: Rejected 3-sigma threshold rule commonly used in time-series anomaly detection because non-IID data heterogeneity makes reconstruction errors wider, allowing malicious updates to slip through.

Anomaly Detection and Attack Mitigation in Federated Learning · YorkSpace

Tried and failed

static threshold-based anomaly detection applied to detecting intermittent Byzantine adversaries in networks. Outcome: did not generalise. Reason: Adversaries dynamically modulate attack rates to remain undetected below fixed detection thresholds.

Trust-Based Algorithms for Resilient Multi-Agent Systems · Harvard

Tried and failed

autoregressive recurrent neural network anomaly detection applied to cyber-physical sensor measurements. Outcome: did not generalise. Reason: Failed to detect attacks before physical impact and was bypassed by valid replayed historical measurements

AI-based Detection Against Cyberattacks in Cyber-Physical Distribution Systems · Virginia Tech

Tried and failed

chi-squared anomaly detection on innovation signals applied to cyber-physical input injection detection. Outcome: no signal. Reason: Intelligently designed malicious inputs bypassed innovation-based chi-squared thresholding without triggering detection.

Architectures for Hardening Security in Intelligent Cyber-physical Systems · Georgia Tech

Tried and failed

residual-based chi-squared anomaly detection applied to cyber-physical state estimation under false-data injection. Reason: model-informed stealthy false-data injection attacks construct perturbations that lie within expected residual thresholds

Cyber Security of Grid-Scale Battery Energy Storage Systems using Battery Modeling and Statistical Methods · Texas Tech

Considered and rejected

Considered and rejected: Rejected standard Gaussian prediction intervals for time series anomaly scoring because network connection data regularly violates normality assumptions, yielding overly wide and uninformative intervals.

Temporally adaptive monitoring procedures with applications in enterprise cyber-security · Imperial

Tried and failed

parametric hypothesis tests on cross-sensor residual statistics applied to time-delay replay anomaly detection. Outcome: no signal. Reason: residual variance remained within nominal thresholds despite significant time delay between paired signals

Accelerometer Aided GNSS Spoofing Detection Using Wavelet Based Time-Frequency Analysis · Virginia Tech

Left open by the authors

Problems the authors named and did not get to.

Left open

Implement machine learning anomaly detection to detect and flag suspicious trade entities and transactions. Blocker: No specific anomaly detection algorithms, evaluation metrics, or trade transaction datasets are specified.

Can an LLM find its way around a Spreadsheet? · Virginia Tech

Left open

Extend the deep learning framework to anomaly-based detection for identifying novel cyber-physical attacks and system faults. Blocker: None

Online Detection Against Cyberattacks In Cyber-Physical Systems · Georgia Tech

Left open

Investigate why pre-trained classification network latent representations fail to transfer effectively to one-class anomaly detection. Blocker: None

Semi-Supervised Anomaly Detection Using One-Class RBF Networks · Research Repository UCD

Left open

Extend the black-box mimicker distillation technique to anomaly detection methods lacking a high-level variable basis, such as variational autoencoders. Blocker: Lacks specific formulation or target datasets for defining feature selection without an established high-level basis.

Seek and Ye Shall Find: Machine Learning and Searches for New Physics · Scholars' Bank

Left open

Extend flight software intrusion detection and ML-based anomaly detection with adaptive autonomous mitigation mechanisms. Blocker: The unfinished work lacks specific target metrics, algorithms, and design details beyond a broad concept

Engineering Cyber Resilience in Spacecraft Flight Software: A Threat-Informed Architecture and Evaluation · JScholarship

Left open

Develop techniques to minimize false positive alarms in the state machine anomaly detection framework. Blocker: No specific approach, mathematical formulation, or baseline target is specified

A state machine approach for network intrusion detection · Iowa State

Left open

Evaluate anomaly detection sensitivity to stealthy, benign-resembling network attacks using richer network data representations. Blocker: Lacks specific data representations, attack scenarios, or performance targets

Diagnosis and Mitigation of Evolving Threats for Sustainable Security · Research Repository UCD

Left open

Evaluate the CAAD model against a broader variety of sophisticated network anomaly types. Blocker: No specific anomaly types, benchmark datasets, or performance criteria are defined

Detecting Irregular Network Activity with Adversarial Learning and Expert Feedback · Virginia Tech

Left open

Develop and evaluate methods for controlling false positive rates in dynamic graph anomaly detection beyond the Benjamini-Hochberg procedure. Blocker: None

Statistical Inference on Time Series of Graphs · JScholarship

Left open

Develop and test risk management and anomaly detection techniques for safeguarding against fraudulent or erroneous trades in algorithmic trading. Blocker: None

Knowledge Graphs, Automatic Feature Engineering and Machine Learning in Algorithmic Trading for Financial Markets · IRIS - UNICAM - prod

Checking a claim in this area?

We can run the same search on any method or claim. If nothing turns up, we will say so, and that proves nothing on its own.