Skip to main content

Conformal Anomaly Detection

Project description

Logo


Python codecov

Conformal Anomaly Detection

Thresholds for anomaly detection are often arbitrary and lack theoretical guarantees about the anomalies they identify. nonconform wraps your favorite anomaly detection model from PyOD (see Supported Estimators) and transforms its raw anomaly scores into statistically valid $p$-values. It applies principles from conformal prediction to the setting of one-class classification, enabling anomaly detection with provable statistical guarantees and a controlled false discovery rate.

Note: The methods in nonconform assume that training and test data are exchangeable. Therefore, the package is not suited for data with spatial or temporal autocorrelation unless such dependencies are explicitly handled in preprocessing or model design.

:hatching_chick: Getting Started

Installation via PyPI:

pip install nonconform

Note: The following examples use the built-in datasets. Install with pip install nonconform[data] to run these examples. (see Optional Dependencies)

Classical (Conformal) Approach

Example: Detecting anomalies with Isolation Forest on the Shuttle dataset. The approach splits data for calibration, trains the model, then converts anomaly scores to p-values by comparing test scores against the calibration distribution.

from pyod.models.iforest import IForest
from scipy.stats import false_discovery_control

from nonconform.strategy import Split
from nonconform.detection import ConformalDetector
from nonconform.utils.data import load, Dataset
from nonconform.utils.stat import false_discovery_rate, statistical_power

x_train, x_test, y_test = load(Dataset.SHUTTLE, setup=True, seed=42)

estimator = ConformalDetector(
 detector=IForest(behaviour="new"), strategy=Split(n_calib=1_000), seed=42)

estimator.fit(x_train)

estimates = estimator.predict(x_test)
decisions = false_discovery_control(estimates, method='bh') <= 0.2

print(f"Empirical False Discovery Rate: {false_discovery_rate(y=y_test, y_hat=decisions)}")
print(f"Empirical Statistical Power (Recall): {statistical_power(y=y_test, y_hat=decisions)}")

Output:

Empirical False Discovery Rate: 0.18
Empirical Statistical Power (Recall): 0.99

:hatched_chick: Advanced Methods

Two advanced approaches are implemented that may increase the power of a conformal anomaly detector:

  • A KDE-based (probabilistic) approach that models the calibration scores to achieve continuous $p$-values in contrast to the standard empirical distribution function.
  • A weighted approach that prioritizes calibration scores by their similarity to the test batch at hand and is more robust to covariate shift between test and calibration data. Maybe combine with the probabilistic approach.

Probabilistic Conformal Approach:

estimator = ConformalDetector(
        detector=HBOS(),
        strategy=Split(n_calib=1_000),
        estimation=Probabilistic(n_trials=10),  # KDE Tuning Trials
        seed=1,
    )

Weighed Conformal Anomaly Detection:

# Weighted conformal (with covariate shift handling):
from nonconform.detection.weight import LogisticWeightEstimator

estimator = ConformalDetector(
 detector=IForest(behaviour="new"), strategy=Split(n_calib=1_000), weight_estimator=LogisticWeightEstimator(seed=42), seed=42)

Note: Weighted procedures require weighted FDR control for statistical validity (see weighted_bh() or weighted_false_discovery_control()).

Beyond Static Data

While primarily designed for static (single-batch) applications, the library supports streaming scenarios through BatchGenerator() and OnlineGenerator(). For statistically valid FDR control in streaming data, use the optional onlineFDR dependency, which implements appropriate statistical methods.

Citation

If you find this repository useful for your research, please cite the following papers:

Leave-One-Out-, Bootstrap- and Cross-Conformal Anomaly Detectors
@inproceedings{Hennhofer2024,
 title        = {{ Leave-One-Out-, Bootstrap- and Cross-Conformal Anomaly Detectors }}, author       = {Hennhofer, Oliver and Preisach, Christine}, year         = 2024, month        = {Dec}, booktitle    = {2024 IEEE International Conference on Knowledge Graph (ICKG)}, publisher    = {IEEE Computer Society}, address      = {Los Alamitos, CA, USA}, pages        = {110--119}, doi          = {10.1109/ICKG63256.2024.00022}, url          = {https://doi.ieeecomputersociety.org/10.1109/ICKG63256.2024.00022}}
Testing for Outliers with Conformal p-Values
@article{Bates2023,
 title        = {Testing for outliers with conformal p-values}, author       = {Bates,  Stephen and Candès,  Emmanuel and Lei,  Lihua and Romano,  Yaniv and Sesia,  Matteo}, year         = 2023, month        = feb, journal      = {The Annals of Statistics}, publisher    = {Institute of Mathematical Statistics}, volume       = 51, number       = 1, doi          = {10.1214/22-aos2244}, issn         = {0090-5364}, url          = {http://dx.doi.org/10.1214/22-AOS2244}}

Optional Dependencies

For additional features, you might need optional dependencies:

  • pip install nonconform[data] - Includes pyarrow for loading example data (via remote download)
  • pip install nonconform[deep] - Includes deep learning dependencies (PyTorch)
  • pip install nonconform[fdr] - Includes advanced FDR control methods (online-fdr)
  • pip install nonconform[dev] - Includes development tools documentation tools
  • pip install nonconform[all] - Includes all optional dependencies

Please refer to the pyproject.toml for details.

Supported Estimators

Only anomaly estimators suitable for unsupervised one-class classification are supported. Since detectors are trained exclusively on normal data, threshold parameters are automatically set to minimal values.

Models that are currently supported include:

  • Angle-Based Outlier Detection (ABOD)
  • Autoencoder (AE)
  • Cook's Distance (CD)
  • Copula-based Outlier Detector (COPOD)
  • Deep Isolation Forest (DIF)
  • Empirical-Cumulative-distribution-based Outlier Detection (ECOD)
  • Gaussian Mixture Model (GMM)
  • Histogram-based Outlier Detection (HBOS)
  • Isolation-based Anomaly Detection using Nearest-Neighbor Ensembles (INNE)
  • Isolation Forest (IForest)
  • Kernel Density Estimation (KDE)
  • k-Nearest Neighbor (kNN)
  • Kernel Principal Component Analysis (KPCA)
  • Linear Model Deviation-base Outlier Detection (LMDD)
  • Local Outlier Factor (LOF)
  • Local Correlation Integral (LOCI)
  • Lightweight Online Detector of Anomalies (LODA)
  • Locally Selective Combination of Parallel Outlier Ensembles (LSCP)
  • GNN-based Anomaly Detection Method (LUNAR)
  • Median Absolute Deviation (MAD)
  • Minimum Covariance Determinant (MCD)
  • One-Class SVM (OCSVM)
  • Principal Component Analysis (PCA)
  • Quasi-Monte Carlo Discrepancy Outlier Detection (QMCD)
  • Rotation-based Outlier Detection (ROD)
  • Subspace Outlier Detection (SOD)
  • Scalable Unsupervised Outlier Detection (SUOD)

Contact

Bug reporting: https://github.com/OliverHennhoefer/nonconform/issues


Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

nonconform-0.95.1.tar.gz (428.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

nonconform-0.95.1-py3-none-any.whl (72.9 kB view details)

Uploaded Python 3

File details

Details for the file nonconform-0.95.1.tar.gz.

File metadata

  • Download URL: nonconform-0.95.1.tar.gz
  • Upload date:
  • Size: 428.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.1

File hashes

Hashes for nonconform-0.95.1.tar.gz
Algorithm Hash digest
SHA256 186975360d88b37b7bd8489095908cadfa0d2c8f858ee347190c971409889667
MD5 a95f8ebac16f8ece0283196ce625c63d
BLAKE2b-256 fa03c6efd263958038b788a01ac35299f357409eab0f75b6d91e6e098e4a88b7

See more details on using hashes here.

File details

Details for the file nonconform-0.95.1-py3-none-any.whl.

File metadata

  • Download URL: nonconform-0.95.1-py3-none-any.whl
  • Upload date:
  • Size: 72.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.1

File hashes

Hashes for nonconform-0.95.1-py3-none-any.whl
Algorithm Hash digest
SHA256 388cb3f6752d7966b3b97ffd5ec8f349341b42b2dbeb6d2f34aa49a1c22c1ede
MD5 644d0da725e52c05eedb0539cd822499
BLAKE2b-256 099e88dfc250ecb029e19ce362c610680c26c9c7816802b3c3656979ee696220

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page