Organizations: Beihang University, Beijing, China · Beihang Hangzhou Innovation Institute, Hangzhou, China · China University of Geosciences (Beijing), Beijing, China
Time-series anomaly detection (TSAD) identifies deviations from patterns learned from historical data. In non-stationary settings, distribution drift and true anomalies can cause similar local changes, making it difficult to tell whether a deviation reflects abnormality or evolving context. Existing methods typically adapt to detected shifts or learn drift-insensitive representations, but do not resolve this ambiguity. We define this problem as \emph{temporal change disambiguation}: determining whether a local deviation is explained by broader temporal evolution. We introduce MORA, a drift-robust TSAD framework that reconstructs the same local target from paired short- and long-term views. The reconstruction gap measures contextual support for a local deviation, and a data-dependent correction mechanism conservatively adjusts the primary local anomaly score. Context can only reduce the score when it improves reconstruction of the same target. MORA needs neither drift annotations nor online adaptation. Experiments on four TSAD benchmarks show strong robustness to non-stationarity while preserving sensitivity to genuine anomalies.
Figures & tables
Figure 1: Motivation for temporal change disambiguation. (a) Linguistic context resolves the meaning of an ambiguous word. (b) Similarly, a local temporal change may appear anomalous in isolation, while its broader context reveals a coherent transition toward a new operating regime.
Figure 2: Overview of MORA: (a) a shared encoder for local/context windows; (b) dual reconstruction experts yield an explainable gap Δt ; (c) heterogeneous cross-view cues characterize the relation between the two views; (d) a correction router adaptively applies one-sided score correction.
Metric
SMD
Exathlon
ESA
ASD
Domain
Server
Spark
Satellite
Application
Entities
12
8
1
12
Train
304168
88230
12273601
102331
Test
286421
46054
12162077
49448
Dim.
38
19
6
19
Anomaly (%)
5.62
12.75
0.91
4.54
Table 1: Statistics of the four benchmark datasets.
SMD
Exathlon
ESA
ASD
Method
RPA-F1
V-R
V-P
RPA-F1
V-R
V-P
RPA-F1
V-R
V-P
RPA-F1
V-R
V-P
Avg. Rank ↓
IF ( 2012 )
6.02
88.11
42.00
44.54
92.19
72.41
0.09
99.40
64.73
16.92
84.02
33.87
17.125
DAMP ( 2022 )
4.29
50.72
8.08
16.51
53.26
23.36
0.09
50.34
0.92
1.82
52.04
6.58
22.375
RAS ( 2022 )
8.66
73.92
18.12
22.80
81.45
52.20
1.74
87.66
7.85
14.42
83.17
32.48
17.500
LSTM-ED ( 2016 )
30.87
85.60
47.96
51.64
85.28
65.33
47.59
94.92
65.67
24.55
69.35
20.07
9.250
Deep SVDD ( 2018 )
48.20
94.72
62.59
55.79
94.14
76.62
4.05
96.26
41.39
33.01
87.82
47.25
8.750
Table 2: Mean Best RPA-F1 (RPA-F1), VUS-ROC (V-R), and VUS-PR (V-P) results (%) over five runs with different random seeds. The average rank based on Best RPA-F1 is reported in the last column, where a lower value is better.
SMD
Exathlon
ESA
ASD
Avg.
F1
V-R
V-P
F1
V-R
V-P
F1
V-R
V-P
F1
V-R
V-P
F1
V-R
V-P
w/o context
67.16
98.55
87.14
74.81
97.88
89.35
80.68
99.07
77.92
42.34
98.27
85.83
66.25
98.44
85.06
w/o local
51.14
98.37
89.50
74.77
97.98
89.54
88.89
99.47
77.53
22.24
97.59
84.77
59.26
98.35
85.33
Naive fusion
68.45
98.54
87.78
74.77
97.95
89.51
84.62
99.40
78.89
37.44
97.83
84.64
66.32
98.43
85.21
Single head
66.19
98.53
88.17
74.77
97.91
89.47
84.62
99.39
78.64
40.38
98.03
85.25
66.49
98.46
85.39
Homo head
64.80
98.49
88.28
74.74
97.90
89.49
84.62
99.38
78.66
40.28
98.19
85.66
66.11
98.49
85.52
Table 3: Ablation results of mean Best RPA-F1(%), VUS-ROC(V-R)(%), and VUS-PR(V-P)(%) of 5 runs with different seeds.
Figure 3: Window-pair sensitivity of RPA-F1 under different short- and long-window sizes.
Figure 4: Sensitivity results of λ , η , and ρ on SMD and ASD.
Figure 5: Correction on normal vs. anomalous windows. (a) Router response γt . (b) Relative score suppression from γt and the positive reconstruction gap Δt .
Figure 6: Detection performance of MORA across entity groups with different PSI levels.
Figure 7: Visualization on SMD. From top to bottom: raw input, local and corrected scores, and score reduction Stloc−St . Red regions denote ground-truth anomalies, blue regions indicate non-anomalous intervals where correction is activated.
Time series anomaly detection (TSAD) is essential for maintaining the reliability and security of IoT-enabled service systems. Existing methods require training one specific model for each dataset, which exhibits limited generalization capability across different target datasets, hindering anomaly detection performance in various scenarios with scarce training data. To address this limitation, foundation models have emerged as a promising direction. However, existing approaches either repurpose large language models (LLMs) or construct largescale time series datasets to develop general anomaly detection foundation models, and still face challenges caused by severe cross-modal gaps or in-domain heterogeneity. In this paper, we investigate the applicability of large-scale vision models to TSAD. Specifically, we adapt a visual Masked Autoencoder (MAE) pretrained on ImageNet to the TSAD task. However, directly transferring MAE to TSAD introduces two key challenges: overgeneralization and limited local perception. To address these challenges, we propose VAN-AD, a novel MAE-based framework for TSAD. To alleviate the over-generalization issue, we design an Adaptive Distribution Mapping Module (ADMM), which maps the reconstruction results before and after MAE into a unified statistical space to amplify discrepancies caused by abnormal patterns. To overcome the limitation of local perception, we further develop a Normalizing Flow Module (NFM), which combines MAE with normalizing flow to estimate the probability density of the current window under the global distribution. Extensive experiments on nine real-world datasets demonstrate that VAN-AD consistently outperforms existing state-of-the-art methods across multiple evaluation metrics.We make our code and datasets available at https://github.com/PenyChen/VAN-AD.
PengYu Chen, Shang Wan, Xiaohou Shi +3
School of Computer Science (National Pilot Software Engineering School), Beijing University of Posts and Telecommunications, Beijing 100876, China · China Telecom Research Institute Beijing, China · Department of Computer Science, Missouri University of Science and Technology, Rolla, MO 65409 USA
Time-series anomaly detection (TSAD) is difficult to generalize across datasets because heterogeneous temporal dynamics imply different notions of normality and favor different detection criteria. While time-series foundation models provide transferable representations, coupling them with a fixed anomaly-scoring mechanism can overlook this variation. This motivates a different perspective on foundation-model-based TSAD: using foundation models to coordinate specialized anomaly criteria rather than directly imposing a universal one. Based on this view, we propose \textbf{TS-Router}, a generalist-representation, specialist-detection framework that estimates the relative competence of heterogeneous anomaly detectors from pretrained temporal representations and selects suitable specialists for each target series. To avoid relying on specialist-performance labels from real tasks, we derive soft competence supervision from specialists' relative performance on labeled simulated tasks. At deployment, routing requires no target anomaly labels, and only the selected specialists are fitted unsupervisedly on the target series. We bound Top-k set-competence regret under representation coverage and conditional competence stability. Across 16 real-world benchmarks and four complementary evaluation metrics, TS-Router achieves the best overall average rank. Controlled ablations with multiple frozen TSFM encoders further support the use of pretrained representations for competence estimation and adaptive specialist selection. The code is available at https://anonymous.4open.science/r/TS-Router-D8FF.
Tian Lan, Yifei Gao, Yimeng Lu +6
Department of Industrial Engineering Tsinghua University · Huawei · Datadog AI Research Paris, France
Time series anomaly detection (TSAD) remains challenging not only because anomaly labels are scarce, but also because temporal anomalies are highly context-dependent. Existing methods often rely on unsupervised objectives or surrogate abnormal patterns, providing limited supervision for context-dependent normal--anomalous distinctions. We propose Context-Anchored Pair Supervision (CAPS), a supervision-recovery framework for TSAD. CAPS views ideal anomaly supervision as a matched comparison between normal and anomalous outcomes under the same temporal context, and seeks to recover such supervision without target-domain anomaly labels. Using simulated normal--anomalous pairs, CAPS learns structure and anomaly-semantic representations through reconstruction, background consistency, and within-pair counterfactual recombination. The resulting anomaly representations form a continuous semantic space with coarse modes and induce a sampleable multimodal prior. CAPS conditionally realizes sampled semantics as residual-form effects on target reference trajectories. The resulting context-anchored normal--anomalous counterparts provide temporal supervision for discriminative detector learning. Experiments on nine datasets show that CAPS achieves the strongest aggregate performance across all four evaluation metrics among the compared methods, while complementary ablations and transfer analyses support the roles of context anchoring, semantic disentanglement, and conditional realization.
Yifei Gao, Tian Lan, Yimeng Lu +5
Department of Industrial Engineering, Tsinghua University · Huawei