Unit content
Anomaly detection
Anomaly detection identifies examples that are unusual relative to a reference population. Unlike ordinary classification, anomalous cases may be rare, diverse or poorly labeled.
One approach assigns each example an anomaly score based on estimated density: observations with very low $p(x)$ are considered unusual. Another uses distance to nearby examples or to a learned representation of normal data.
Suppose sensor vectors from healthy machines form a dense region. A new vector far from that region can receive a high anomaly score even if no labeled example of that particular failure mode was seen during training.
A threshold converts anomaly scores into alerts. This creates the same precision-recall tradeoff as other rare-event decisions: a lower threshold catches more unusual cases but raises more false alarms.
“Rare” and “bad” are not synonyms. A legitimate new operating regime can look anomalous, while a common fault may not. Evaluation should therefore use realistic anomalies when available and should treat distribution shift as a separate possibility.
Anomaly detection is useful precisely when modeling normal structure is easier than enumerating every abnormal class.