SlideShare a Scribd company logo
Location:
QuantUniversity Meetup
June 23rd 2016
Boston MA
Anomaly Detection
Techniques and Best Practices
2016 Copyright QuantUniversity LLC.
Presented By:
Sri Krishnamurthy, CFA, CAP
www.QuantUniversity.com
sri@quantuniversity.com
2
Slides and Code available at:
http://www.analyticscertificate.com/Anomaly/
- Analytics Advisory services
- Custom training programs
- Architecture assessments, advice and audits
• Founder of QuantUniversity LLC. and
www.analyticscertificate.com
• Advisory and Consultancy for Financial Analytics
• Prior Experience at MathWorks, Citigroup and
Endeca and 25+ financial services and energy
customers (Shell, Firstfuel Software etc.)
• Regular Columnist for the Wilmott Magazine
• Author of forthcoming book
ā€œFinancial Modeling: A case study approachā€
published by Wiley
• Charted Financial Analyst and Certified Analytics
Professional
• Teaches Analytics in the Babson College MBA
program and at Northeastern University, Boston
Sri Krishnamurthy
Founder and CEO
4
5
Quantitative Analytics and Big Data Analytics Onboarding
• Trained more than 500 students in
Quantitative methods, Data Science
and Big Data Technologies using
MATLAB, Python and R
• Launching the Analytics Certificate
Program later in Fall
(MATLAB version also available)
7
• July
ā–« 11th : QuantUniversity’s 2nd meetup
ļ‚– Topic : Quantitative methods topic : TBD
ā–« 18th and 19th : 2-day workshop on Anomaly Detection
ļ‚– Registration and pricing details at www.analyticscertificate.com/Anomaly
• August
ā–« 8th : QuantUniversity meetup
ā–« 14-20th : ARPM in New York www.arpm.co
ļ‚– QuantUniversity presenting on Model Risk on August 14th
ā–« 18-21st : Big-data Bootcamp http://globalbigdataconference.com/68/boston/big-
data-bootcamp/event.html
Events of Interest
8
• July
ā–« Anomaly Detection Workshop
ā–« ARPM-prep seminar – Date TBD
• August
ā–« Model Evaluation : Metrics, Scaling and Best Practices
• September
ā–« What’s missing ? Best practices in missing data analysis
QuantUniversity’s Summer workshop series
9
What is anomaly detection?
• Anomalies or outliers are data points that appear to deviate
markedly from expected outputs.
• It is the process of finding patterns in data that don’t
conform to a prior expected behavior.
• Anomaly detection is being employed more increasingly in
the presence of big data that is captured by sensors(IOT),
social media platforms, huge networks, etc. including
energy systems, medical devices, banking, network
intrusion detection, etc.
10
11
• Fraud Detection
• Stock market
• E-commerce
Examples
12
1. Graphical approach
2. Statistical approach
3. Machine learning approach
Three methodologies to Anomaly Detection
13
 Boxplot
 Scatter plot
 Adjusted quantile plot
Anomaly Detection Methods
• Most outlier detection methods generate an output
that are:
ā–« Real-valued outlier scores: quantifies the tendency of a
data point being an outlier by assigning a score or
probability to it.
ā–« Binary labels: result of using a threshold to convert
outlier scores to binary labels, inlier or outlier.
14
Graphical approaches
• Statistical tails are most commonly used for one dimensional
distributions, although the same concept can be applied to
multidimensional case.
• It is important to understand that all extreme values are outliers
but the reverse may not be true.
• For instance in one dimensional dataset of
{1,3,3,3,50,97,97,97,100}, observation 50 equals to mean and isn’t
considered as an extreme value, but since this observation is the
most isolated point, it should be considered as an outlier.
15
Box plot
• A standardized way of displaying the
variation of data based on the five
number summary, which includes
minimum, first quartile, median, third
quartile, and maximum.
• This plot does not make any assumptions
of the underlying statistical distribution.
• Any data not included between the
minimum and maximum are considered
as an outlier.
16
Boxplot
17
See Graphical_Approach.R
Side-by-side boxplot for each variable
Scatter plot
• Scatter plots plot pairs of data to show the correlation between typically two
numerical variables.
• An outlier is defined as a data point that doesn't seem to fit with the rest of the
data points.
• In scatterplots, outliers of either intersection or union sets of two variables can
be shown.
18
Scatterplot
19
See Graphical_Approach.R
Scatterplot of Sepal.Width and Sepal.Length
20
• In statistics, a Q–Q plot is a probability plot, which is a graphical
method for comparing two probability distributions by plotting their
quantiles against each other.
• If the two distributions being compared are similar, the points in the
Q–Q plot will approximately lie on the line y = x.
Q-Q plot
Source: Wikipedia
Adjusted quantile plot
• This plot identifies possible multivariate outliers by calculating the Mahalanobis
distance of each point from the center of the data.
• Multi-dimensional Mahalanobis distance between vectors x and y in š‘… š‘› can be
formulated as:
d(x,y) = x āˆ’ y TSāˆ’1(x āˆ’ y)
where x and y are random vectors of the same distribution with the covariance
matrix S.
• An outlier is defined as a point with a distance larger than some pre-
determined value.
21
Adjusted quantile plot
• Before applying this method and many other parametric
multivariate methods, first we need to check if the data is
multivariate normally distributed using different
multivariate normality tests, such as Royston, Mardia, Chi-
square, univariate plots, etc.
• In R, we use the ā€œmvoutlierā€ package, which utilizes
graphical approaches as discussed above.
22
Adjusted quantile plot
23
Min-Max normalization before diving into analysis
Multivariate normality test
Outlier Boolean vector identifies the
outliers
Alpha defines maximum thresholding proportion
See Graphical_Approach.R
Adjusted quantile plot
24
See Graphical_Approach.R
Mahalanobis distances
Covariance matrix
Adjusted quantile plot
25
See Graphical_Approach.R
26
 Hypothesis testing (Grubb’s test)
 Scores
Grubbs’ test
• Test for outliers for univariate data sets assumed to come from a normally
distributed population.
• Grubbs' test detects one outlier at a time. This outlier is expunged from the
dataset and the test is iterated until no outliers are detected.
• This test is defined for the following hypotheses:
H0: There are no outliers in the data set
H1: There is exactly one outlier in the data set
• The Grubbs' test statistic is defined as:
27
Grubbs’ test
28
See Statistical_Approach.R
The above function repeats the Grubbs’ test until it finds
all the outliers within the data.
Grubbs’ test
29
See Statistical_Approach.R
Histogram of normal observations vs outliers)
Scores
• Scores quantifies the tendency of a data point being an outlier by assigning it a
score or probability.
• The most commonly used scores are:
ā–« Normal score:
š‘„ š‘– āˆ’š‘€š‘’š‘Žš‘›
š‘ š‘”š‘Žš‘›š‘‘š‘Žš‘Ÿš‘‘ š‘‘š‘’š‘£š‘–š‘Žš‘”š‘–š‘œš‘›
ā–« T-student score:
(š‘§āˆ’š‘ š‘žš‘Ÿš‘” š‘›āˆ’2 )
š‘ š‘žš‘Ÿš‘”(š‘§āˆ’1āˆ’š‘”2)
ā–« Chi-square score:
š‘„ š‘– āˆ’š‘€š‘’š‘Žš‘›
š‘ š‘‘
2
ā–« IQR score: š‘„3-š‘„1
• By using ā€œscoreā€ function in R, p-values can be returned instead of scores.
30
Scores
31
See Statistical_Approach.R
ā€œtypeā€ defines the type of the score, such as
normal, t-student, etc.
ā€œprob=1ā€ returns the corresponding p-value.
Scores
32
See Statistical_Approach.R
By setting ā€œprobā€ to any specific value, logical vector
returns the data points, whose probabilities are
greater than this cut-off value, as outliers.
By setting ā€œtypeā€ to IQR, all values lower than first
and greater than third quartiles are considered and
difference between them and nearest quartile
divided by IQR is calculated.
33
• Anomaly Detection
ā–« Seasonal Hybrid ESD (S-H-ESD) builds upon the Generalized ESD test for
detecting anomalies.
ā–« Anomaly detection referring to point-in-time anomalous data points that
could be global or local. A local anomaly is one that occurs inside a seasonal
pattern; Could be +ve or –ve.
ā–« More details here: https://github.com/twitter/AnomalyDetection
• Breakout Detection
ā–« A breakout is characterized in this package by two steady states and an
intermediate transition period that could be sudden or gradual
ā–« Uses the E-Divisive with Medians algorithm; Can detect one or multiple
breakouts in a given time series and employs energy statistics to detect
divergence in mean. More details here:
(https://blog.twitter.com/2014/breakout-detection-in-the-wild )
Twitter packages
Ref: http://www.itl.nist.gov/div898/handbook/eda/section3/eda35h3.htm
34
• Twitter-R-Anomaly Detection tutorial.ipyb
Demo
35
 Linear regression
 Piecewise/ segmented regression
 Clustering-based approaches
Linear regression
• Linear regression investigates the linear relationships between variables and
predict one variable based on one or more other variables and it can be
formulated as:
š‘Œ = š›½0 + ą·
š‘–=1
š‘
š›½š‘– š‘‹š‘–
where Y and š‘‹š‘– are random variables, š›½š‘– is regression coefficient and š›½0 is a
constant.
• In this model, ordinary least squares estimator is usually used to minimize the
difference between the dependent variable and independent variables.
36
Piecewise/segmented regression
• A method in regression analysis, in which the independent variable is
partitioned into intervals to allow multiple linear models to be fitted to data for
different ranges.
• This model can be applied when there are ā€˜breakpoints’ and clearly two
different linear relationships in the data with a sudden, sharp change in
directionality. Below is a simple segmented regression for data with two
breakpoints:
š‘Œ = š¶0 + šœ‘1 š‘‹ š‘‹ < š‘‹1
š‘Œ = š¶1 + šœ‘2 š‘‹ š‘‹ > š‘‹1
where Y is a predicted value, X is an independent variable, š¶0 and š¶1 are
constant values, šœ‘1 and šœ‘2 are regression coefficients, and š‘‹1 and š‘‹2 are
breakpoints.
37
38
Anomaly detection vs Supervised learning
Piecewise/segmented regression
• For this example, we use ā€œsegmentedā€ package in R to first illustrate piecewise
regression for two dimensional data set, which has a breakpoint around z=0.5.
39
See Piecewise_Regression.R
ā€œpmaxā€ is used for parallel maximization to
create different values for y.
Piecewise/segmented regression
• Then, we use linear regression to predict y values for each segment of z.
40
See Piecewise_Regression.R
Piecewise/segmented regression
• Finally, the outliers can be detected for each segment by setting some rules for
residuals of model.
41
See Piecewise_Regression.R
Here, we set the rule for the residuals corresponding to z
less than 0.5, by which the outliers with residuals below
0.5 can be defined as outliers.
Clustering-based approaches
• These methods are suitable for unsupervised anomaly detection.
• They aim to partition the data into meaningful groups (clusters) based on the
similarities and relationships between the groups found in the data.
• Each data point is assigned a degree of membership for each of the clusters.
• Anomalies are those data points that:
ā–« Do not fit into any clusters.
ā–« Belong to a particular cluster but are far away from the cluster centroid.
ā–« Form small or sparse clusters.
42
Clustering-based approaches
• These methods partition the data into k clusters by assigning each data point to
its closest cluster centroid by minimizing the within-cluster sum of squares
(WSS), which is:
ą·
š‘˜=1
š¾
ą·
š‘–āˆˆš‘† š‘˜
ą·
š‘—=1
š‘ƒ
(š‘„š‘–š‘— āˆ’ šœ‡ š‘˜š‘—)2
where š‘† š‘˜ is the set of observations in the kth cluster and šœ‡ š‘˜š‘— is the mean of jth
variable of the cluster center of the kth cluster.
• Then, they select the top n points that are the farthest away from their nearest
cluster centers as outliers.
43
44
Anomaly Detection vs Unsupervised Learning
Clustering-based approaches
• ā€œKmodā€ package in R is used to show the application of K-means model.
45
In this example the number of clusters is defined
through bend graph in order to pass to K-mod
function.
See Clustering_Approach.R
Clustering-based approaches
46
See Clustering_Approach.R
K=4 is the number of clusters and L=10 is
the number of outliers
Clustering-based approaches
47
See Clustering_Approach.R
Scatter plots of normal and outlier data points
Summary
48
We have covered Anomaly detection
Introduction  Definition of anomaly detection and its importance in energy systems
 Different types of anomaly detection methods: Statistical, graphical and machine
learning methods
Graphical approach  Graphical methods consist of boxplot, scatterplot, adjusted quantile plot and symbol
plot to demonstrate outliers graphically
 The main assumption for applying graphical approaches is multivariate normality
 Mahalanobis distance methods is mainly used for calculating the distance of a point
from a center of multivariate distribution
Statistical approach  Statistical hypothesis testing includes of: Chi-square, Grubb’s test
 Statistical methods may use either scores or p-value as threshold to detect outliers
Machine learning approach  Both supervised and unsupervised learning methods can be used for outlier detection
 Piece wised or segmented regression can be used to identify outliers based on the
residuals for each segment
 In K-means clustering method outliers are defined as points which have doesn’t belong
to any cluster, are far away from the centroids of the cluster or shaping sparse clusters
(MATLAB version also available)
www.analyticscertificate.com
50
Q&A
Slides, code and details about the Anomaly detection workshop
at: http://www.analyticscertificate.com/Anomaly/
Thank you!
Members &
Sri Krishnamurthy, CFA, CAP
Founder and CEO
QuantUniversity LLC.
srikrishnamurthy
www.QuantUniversity.com
Contact
Information, data and drawings embodied in this presentation are strictly a property of QuantUniversity LLC. and shall not be
distributed or used in any other publication without the prior written consent of QuantUniversity LLC.
51

More Related Content

PDF
Anomaly detection: Core Techniques and Advances in Big Data and Deep Learning
PDF
Anomaly detection : QuantUniversity Workshop
PDF
Outlier analysis for Temporal Datasets
PDF
Anomaly detection
PDF
Anomaly detection
PDF
Machine learning meetup
PDF
Scaling Analytics with Apache Spark
PDF
Missing data handling
Anomaly detection: Core Techniques and Advances in Big Data and Deep Learning
Anomaly detection : QuantUniversity Workshop
Outlier analysis for Temporal Datasets
Anomaly detection
Anomaly detection
Machine learning meetup
Scaling Analytics with Apache Spark
Missing data handling

What's hot (18)

PDF
Credit risk meetup
PPTX
Outlier analysis and anomaly detection
PDF
An Introduction to Anomaly Detection
PDF
Ds for finance day 2
PPTX
Anomaly Detection for Real-World Systems
PPTX
Missing Data and data imputation techniques
PPTX
Anomaly Detection Technique
PDF
Anomaly Detection: A Survey
PDF
Ds for finance day 3
PPTX
Anomaly Detection
PPTX
Statistical Approaches to Missing Data
PPTX
Missing Data and Causes
PDF
Cold-Start Management with Cross-Domain Collaborative Filtering and Tags
PPTX
Supervised learning
PDF
Parsimonious and Adaptive Contextual Information Acquisition in Recommender S...
PPTX
Chapter 10 Anomaly Detection
PPTX
Credit card fraud detection using python machine learning
PDF
Hybrid Solution of the Cold-Start Problem in Context-Aware Recommender Systems
Credit risk meetup
Outlier analysis and anomaly detection
An Introduction to Anomaly Detection
Ds for finance day 2
Anomaly Detection for Real-World Systems
Missing Data and data imputation techniques
Anomaly Detection Technique
Anomaly Detection: A Survey
Ds for finance day 3
Anomaly Detection
Statistical Approaches to Missing Data
Missing Data and Causes
Cold-Start Management with Cross-Domain Collaborative Filtering and Tags
Supervised learning
Parsimonious and Adaptive Contextual Information Acquisition in Recommender S...
Chapter 10 Anomaly Detection
Credit card fraud detection using python machine learning
Hybrid Solution of the Cold-Start Problem in Context-Aware Recommender Systems
Ad

Viewers also liked (20)

PDF
Deep learning - Part I
PPTX
Deep learning Tutorial - Part II
PDF
Deep learning and Apache Spark
PPTX
PyGotham 2016
PPTX
The definition of normal - An introduction and guide to anomaly detection.
PPTX
Anomaly detection in deep learning (Updated) English
PDF
Svm map reduce_slides
PDF
Large scale logistic regression and linear support vector machines using spark
PDF
A System for Denial of Service Attack Detection Based On Multivariate Corelat...
Ā 
DOCX
a system for denial-of-service attack detection based on multivariate correla...
PPTX
Enterprise architecture-career-path
PPTX
Depth based app
PPTX
Anomaly detection
ODP
Local Outlier Factor
ODP
Outliers
PPTX
Statistical Analysis of Left-Censored Geochemical Data
PDF
Class Outlier Mining
PPTX
Outliers, the story of success
PPTX
Outliers -Story of Success by Malcolm Gladwell
PPTX
"Outliers" - Malcolm Gladwell Book Review
Deep learning - Part I
Deep learning Tutorial - Part II
Deep learning and Apache Spark
PyGotham 2016
The definition of normal - An introduction and guide to anomaly detection.
Anomaly detection in deep learning (Updated) English
Svm map reduce_slides
Large scale logistic regression and linear support vector machines using spark
A System for Denial of Service Attack Detection Based On Multivariate Corelat...
Ā 
a system for denial-of-service attack detection based on multivariate correla...
Enterprise architecture-career-path
Depth based app
Anomaly detection
Local Outlier Factor
Outliers
Statistical Analysis of Left-Censored Geochemical Data
Class Outlier Mining
Outliers, the story of success
Outliers -Story of Success by Malcolm Gladwell
"Outliers" - Malcolm Gladwell Book Review
Ad

Similar to Anomaly detection Meetup Slides (20)

PDF
Data_Analytics_for_IoT_Solutions.pptx.pdf
PPTX
computer application in pharmaceutical research
PPT
EXPLORATORY DATA ANALYSIS and ANALYSIS.ppt
PPT
EXPLORATORY DATA ANALYSIS FOR BEGINNERS AND STUDENTS
PPTX
Unit 3 – AIML.pptx
PDF
IT-601 Lecture Notes-UNIT-2.pdf Data Analysis
PDF
Data Analytics Tools presentation having different DA tools
PDF
Descriptive Analytics: Data Reduction
PPT
Clustering in Machine Learning: A Brief Overview.ppt
PPTX
Basic geostatistics
PDF
76a15ed521b7679e372aab35412ab78ab583436a-1602816156135.pdf
PDF
KIT-601 Lecture Notes-UNIT-2.pdf
PPTX
Descriptive Analysis.pptx
PDF
The RuLIS approach to outliers (Marcello D'Orazio,FAO)
Ā 
PPT
3 DM Classification HFCS kilometres .ppt
PPTX
Research methodology Regression Modeling.pptx
PPTX
DA//////////////////////////////////////// Unit 2.pptx
PPT
Spsshelp 100608163328-phpapp01
PPTX
chi_square test.pptx
PPTX
statistical remodelling in pharmaceutical research and developmnent by aina b...
Data_Analytics_for_IoT_Solutions.pptx.pdf
computer application in pharmaceutical research
EXPLORATORY DATA ANALYSIS and ANALYSIS.ppt
EXPLORATORY DATA ANALYSIS FOR BEGINNERS AND STUDENTS
Unit 3 – AIML.pptx
IT-601 Lecture Notes-UNIT-2.pdf Data Analysis
Data Analytics Tools presentation having different DA tools
Descriptive Analytics: Data Reduction
Clustering in Machine Learning: A Brief Overview.ppt
Basic geostatistics
76a15ed521b7679e372aab35412ab78ab583436a-1602816156135.pdf
KIT-601 Lecture Notes-UNIT-2.pdf
Descriptive Analysis.pptx
The RuLIS approach to outliers (Marcello D'Orazio,FAO)
Ā 
3 DM Classification HFCS kilometres .ppt
Research methodology Regression Modeling.pptx
DA//////////////////////////////////////// Unit 2.pptx
Spsshelp 100608163328-phpapp01
chi_square test.pptx
statistical remodelling in pharmaceutical research and developmnent by aina b...

More from QuantUniversity (20)

PDF
AI in Finance and Retirement Systems: Insights from the EBRI-Milken Institute...
PDF
Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitig...
PDF
EU Artificial Intelligence Act 2024 passed !
PDF
Managing-the-Risks-of-LLMs-in-FS-Industry-Roundtable-TruEra-QuantU.pdf
PDF
PYTHON AND DATA SCIENCE FOR INVESTMENT PROFESSIONALS
PDF
Qu for India - QuantUniversity FundRaiser
PDF
Ml master class for CFA Dallas
PDF
Algorithmic auditing 1.0
PDF
Towards Fairer Datasets: Filtering and Balancing the Distribution of the Peop...
PDF
Machine Learning: Considerations for Fairly and Transparently Expanding Acces...
PDF
Seeing what a gan cannot generate: paper review
PDF
AI Explainability and Model Risk Management
PDF
Algorithmic auditing 1.0
PDF
Machine Learning in Finance: 10 Things You Need to Know in 2021
PDF
Bayesian Portfolio Allocation
PDF
The API Jungle
PDF
Explainable AI Workshop
PDF
Constructing Private Asset Benchmarks
PDF
Machine Learning Interpretability
PDF
Responsible AI in Action
AI in Finance and Retirement Systems: Insights from the EBRI-Milken Institute...
Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitig...
EU Artificial Intelligence Act 2024 passed !
Managing-the-Risks-of-LLMs-in-FS-Industry-Roundtable-TruEra-QuantU.pdf
PYTHON AND DATA SCIENCE FOR INVESTMENT PROFESSIONALS
Qu for India - QuantUniversity FundRaiser
Ml master class for CFA Dallas
Algorithmic auditing 1.0
Towards Fairer Datasets: Filtering and Balancing the Distribution of the Peop...
Machine Learning: Considerations for Fairly and Transparently Expanding Acces...
Seeing what a gan cannot generate: paper review
AI Explainability and Model Risk Management
Algorithmic auditing 1.0
Machine Learning in Finance: 10 Things You Need to Know in 2021
Bayesian Portfolio Allocation
The API Jungle
Explainable AI Workshop
Constructing Private Asset Benchmarks
Machine Learning Interpretability
Responsible AI in Action

Recently uploaded (20)

PPTX
1_Introduction to advance data techniques.pptx
PPTX
05. PRACTICAL GUIDE TO MICROSOFT EXCEL.pptx
PPTX
Supervised vs unsupervised machine learning algorithms
PPTX
Introduction to Knowledge Engineering Part 1
PPT
Quality review (1)_presentation of this 21
PPT
Miokarditis (Inflamasi pada Otot Jantung)
PPT
Chapter 3 METAL JOINING.pptnnnnnnnnnnnnn
PPT
Chapter 2 METAL FORMINGhhhhhhhjjjjmmmmmmmmm
PPTX
DISORDERS OF THE LIVER, GALLBLADDER AND PANCREASE (1).pptx
PPTX
Data_Analytics_and_PowerBI_Presentation.pptx
PDF
Galatica Smart Energy Infrastructure Startup Pitch Deck
PPTX
Introduction to Firewall Analytics - Interfirewall and Transfirewall.pptx
PPTX
Major-Components-ofNKJNNKNKNKNKronment.pptx
PPTX
Introduction-to-Cloud-ComputingFinal.pptx
PPTX
advance b rammar.pptxfdgdfgdfsgdfgsdgfdfgdfgsdfgdfgdfg
PPTX
STUDY DESIGN details- Lt Col Maksud (21).pptx
PPTX
Moving the Public Sector (Government) to a Digital Adoption
PDF
Master Databricks SQL with AccentFuture – The Future of Data Warehousing
PDF
The Rise of Impact Investing- How to Align Profit with Purpose
1_Introduction to advance data techniques.pptx
05. PRACTICAL GUIDE TO MICROSOFT EXCEL.pptx
Supervised vs unsupervised machine learning algorithms
Introduction to Knowledge Engineering Part 1
Quality review (1)_presentation of this 21
Miokarditis (Inflamasi pada Otot Jantung)
Chapter 3 METAL JOINING.pptnnnnnnnnnnnnn
Chapter 2 METAL FORMINGhhhhhhhjjjjmmmmmmmmm
DISORDERS OF THE LIVER, GALLBLADDER AND PANCREASE (1).pptx
Data_Analytics_and_PowerBI_Presentation.pptx
Galatica Smart Energy Infrastructure Startup Pitch Deck
Introduction to Firewall Analytics - Interfirewall and Transfirewall.pptx
Major-Components-ofNKJNNKNKNKNKronment.pptx
Introduction-to-Cloud-ComputingFinal.pptx
advance b rammar.pptxfdgdfgdfsgdfgsdgfdfgdfgsdfgdfgdfg
STUDY DESIGN details- Lt Col Maksud (21).pptx
Moving the Public Sector (Government) to a Digital Adoption
Master Databricks SQL with AccentFuture – The Future of Data Warehousing
The Rise of Impact Investing- How to Align Profit with Purpose

Anomaly detection Meetup Slides

  • 1. Location: QuantUniversity Meetup June 23rd 2016 Boston MA Anomaly Detection Techniques and Best Practices 2016 Copyright QuantUniversity LLC. Presented By: Sri Krishnamurthy, CFA, CAP www.QuantUniversity.com [email protected]
  • 2. 2 Slides and Code available at: http://www.analyticscertificate.com/Anomaly/
  • 3. - Analytics Advisory services - Custom training programs - Architecture assessments, advice and audits
  • 4. • Founder of QuantUniversity LLC. and www.analyticscertificate.com • Advisory and Consultancy for Financial Analytics • Prior Experience at MathWorks, Citigroup and Endeca and 25+ financial services and energy customers (Shell, Firstfuel Software etc.) • Regular Columnist for the Wilmott Magazine • Author of forthcoming book ā€œFinancial Modeling: A case study approachā€ published by Wiley • Charted Financial Analyst and Certified Analytics Professional • Teaches Analytics in the Babson College MBA program and at Northeastern University, Boston Sri Krishnamurthy Founder and CEO 4
  • 5. 5 Quantitative Analytics and Big Data Analytics Onboarding • Trained more than 500 students in Quantitative methods, Data Science and Big Data Technologies using MATLAB, Python and R • Launching the Analytics Certificate Program later in Fall
  • 6. (MATLAB version also available)
  • 7. 7 • July ā–« 11th : QuantUniversity’s 2nd meetup ļ‚– Topic : Quantitative methods topic : TBD ā–« 18th and 19th : 2-day workshop on Anomaly Detection ļ‚– Registration and pricing details at www.analyticscertificate.com/Anomaly • August ā–« 8th : QuantUniversity meetup ā–« 14-20th : ARPM in New York www.arpm.co ļ‚– QuantUniversity presenting on Model Risk on August 14th ā–« 18-21st : Big-data Bootcamp http://globalbigdataconference.com/68/boston/big- data-bootcamp/event.html Events of Interest
  • 8. 8 • July ā–« Anomaly Detection Workshop ā–« ARPM-prep seminar – Date TBD • August ā–« Model Evaluation : Metrics, Scaling and Best Practices • September ā–« What’s missing ? Best practices in missing data analysis QuantUniversity’s Summer workshop series
  • 9. 9
  • 10. What is anomaly detection? • Anomalies or outliers are data points that appear to deviate markedly from expected outputs. • It is the process of finding patterns in data that don’t conform to a prior expected behavior. • Anomaly detection is being employed more increasingly in the presence of big data that is captured by sensors(IOT), social media platforms, huge networks, etc. including energy systems, medical devices, banking, network intrusion detection, etc. 10
  • 11. 11 • Fraud Detection • Stock market • E-commerce Examples
  • 12. 12 1. Graphical approach 2. Statistical approach 3. Machine learning approach Three methodologies to Anomaly Detection
  • 13. 13  Boxplot  Scatter plot  Adjusted quantile plot
  • 14. Anomaly Detection Methods • Most outlier detection methods generate an output that are: ā–« Real-valued outlier scores: quantifies the tendency of a data point being an outlier by assigning a score or probability to it. ā–« Binary labels: result of using a threshold to convert outlier scores to binary labels, inlier or outlier. 14
  • 15. Graphical approaches • Statistical tails are most commonly used for one dimensional distributions, although the same concept can be applied to multidimensional case. • It is important to understand that all extreme values are outliers but the reverse may not be true. • For instance in one dimensional dataset of {1,3,3,3,50,97,97,97,100}, observation 50 equals to mean and isn’t considered as an extreme value, but since this observation is the most isolated point, it should be considered as an outlier. 15
  • 16. Box plot • A standardized way of displaying the variation of data based on the five number summary, which includes minimum, first quartile, median, third quartile, and maximum. • This plot does not make any assumptions of the underlying statistical distribution. • Any data not included between the minimum and maximum are considered as an outlier. 16
  • 18. Scatter plot • Scatter plots plot pairs of data to show the correlation between typically two numerical variables. • An outlier is defined as a data point that doesn't seem to fit with the rest of the data points. • In scatterplots, outliers of either intersection or union sets of two variables can be shown. 18
  • 20. 20 • In statistics, a Q–Q plot is a probability plot, which is a graphical method for comparing two probability distributions by plotting their quantiles against each other. • If the two distributions being compared are similar, the points in the Q–Q plot will approximately lie on the line y = x. Q-Q plot Source: Wikipedia
  • 21. Adjusted quantile plot • This plot identifies possible multivariate outliers by calculating the Mahalanobis distance of each point from the center of the data. • Multi-dimensional Mahalanobis distance between vectors x and y in š‘… š‘› can be formulated as: d(x,y) = x āˆ’ y TSāˆ’1(x āˆ’ y) where x and y are random vectors of the same distribution with the covariance matrix S. • An outlier is defined as a point with a distance larger than some pre- determined value. 21
  • 22. Adjusted quantile plot • Before applying this method and many other parametric multivariate methods, first we need to check if the data is multivariate normally distributed using different multivariate normality tests, such as Royston, Mardia, Chi- square, univariate plots, etc. • In R, we use the ā€œmvoutlierā€ package, which utilizes graphical approaches as discussed above. 22
  • 23. Adjusted quantile plot 23 Min-Max normalization before diving into analysis Multivariate normality test Outlier Boolean vector identifies the outliers Alpha defines maximum thresholding proportion See Graphical_Approach.R
  • 24. Adjusted quantile plot 24 See Graphical_Approach.R Mahalanobis distances Covariance matrix
  • 25. Adjusted quantile plot 25 See Graphical_Approach.R
  • 26. 26  Hypothesis testing (Grubb’s test)  Scores
  • 27. Grubbs’ test • Test for outliers for univariate data sets assumed to come from a normally distributed population. • Grubbs' test detects one outlier at a time. This outlier is expunged from the dataset and the test is iterated until no outliers are detected. • This test is defined for the following hypotheses: H0: There are no outliers in the data set H1: There is exactly one outlier in the data set • The Grubbs' test statistic is defined as: 27
  • 28. Grubbs’ test 28 See Statistical_Approach.R The above function repeats the Grubbs’ test until it finds all the outliers within the data.
  • 29. Grubbs’ test 29 See Statistical_Approach.R Histogram of normal observations vs outliers)
  • 30. Scores • Scores quantifies the tendency of a data point being an outlier by assigning it a score or probability. • The most commonly used scores are: ā–« Normal score: š‘„ š‘– āˆ’š‘€š‘’š‘Žš‘› š‘ š‘”š‘Žš‘›š‘‘š‘Žš‘Ÿš‘‘ š‘‘š‘’š‘£š‘–š‘Žš‘”š‘–š‘œš‘› ā–« T-student score: (š‘§āˆ’š‘ š‘žš‘Ÿš‘” š‘›āˆ’2 ) š‘ š‘žš‘Ÿš‘”(š‘§āˆ’1āˆ’š‘”2) ā–« Chi-square score: š‘„ š‘– āˆ’š‘€š‘’š‘Žš‘› š‘ š‘‘ 2 ā–« IQR score: š‘„3-š‘„1 • By using ā€œscoreā€ function in R, p-values can be returned instead of scores. 30
  • 31. Scores 31 See Statistical_Approach.R ā€œtypeā€ defines the type of the score, such as normal, t-student, etc. ā€œprob=1ā€ returns the corresponding p-value.
  • 32. Scores 32 See Statistical_Approach.R By setting ā€œprobā€ to any specific value, logical vector returns the data points, whose probabilities are greater than this cut-off value, as outliers. By setting ā€œtypeā€ to IQR, all values lower than first and greater than third quartiles are considered and difference between them and nearest quartile divided by IQR is calculated.
  • 33. 33 • Anomaly Detection ā–« Seasonal Hybrid ESD (S-H-ESD) builds upon the Generalized ESD test for detecting anomalies. ā–« Anomaly detection referring to point-in-time anomalous data points that could be global or local. A local anomaly is one that occurs inside a seasonal pattern; Could be +ve or –ve. ā–« More details here: https://github.com/twitter/AnomalyDetection • Breakout Detection ā–« A breakout is characterized in this package by two steady states and an intermediate transition period that could be sudden or gradual ā–« Uses the E-Divisive with Medians algorithm; Can detect one or multiple breakouts in a given time series and employs energy statistics to detect divergence in mean. More details here: (https://blog.twitter.com/2014/breakout-detection-in-the-wild ) Twitter packages Ref: http://www.itl.nist.gov/div898/handbook/eda/section3/eda35h3.htm
  • 35. 35  Linear regression  Piecewise/ segmented regression  Clustering-based approaches
  • 36. Linear regression • Linear regression investigates the linear relationships between variables and predict one variable based on one or more other variables and it can be formulated as: š‘Œ = š›½0 + ą· š‘–=1 š‘ š›½š‘– š‘‹š‘– where Y and š‘‹š‘– are random variables, š›½š‘– is regression coefficient and š›½0 is a constant. • In this model, ordinary least squares estimator is usually used to minimize the difference between the dependent variable and independent variables. 36
  • 37. Piecewise/segmented regression • A method in regression analysis, in which the independent variable is partitioned into intervals to allow multiple linear models to be fitted to data for different ranges. • This model can be applied when there are ā€˜breakpoints’ and clearly two different linear relationships in the data with a sudden, sharp change in directionality. Below is a simple segmented regression for data with two breakpoints: š‘Œ = š¶0 + šœ‘1 š‘‹ š‘‹ < š‘‹1 š‘Œ = š¶1 + šœ‘2 š‘‹ š‘‹ > š‘‹1 where Y is a predicted value, X is an independent variable, š¶0 and š¶1 are constant values, šœ‘1 and šœ‘2 are regression coefficients, and š‘‹1 and š‘‹2 are breakpoints. 37
  • 38. 38 Anomaly detection vs Supervised learning
  • 39. Piecewise/segmented regression • For this example, we use ā€œsegmentedā€ package in R to first illustrate piecewise regression for two dimensional data set, which has a breakpoint around z=0.5. 39 See Piecewise_Regression.R ā€œpmaxā€ is used for parallel maximization to create different values for y.
  • 40. Piecewise/segmented regression • Then, we use linear regression to predict y values for each segment of z. 40 See Piecewise_Regression.R
  • 41. Piecewise/segmented regression • Finally, the outliers can be detected for each segment by setting some rules for residuals of model. 41 See Piecewise_Regression.R Here, we set the rule for the residuals corresponding to z less than 0.5, by which the outliers with residuals below 0.5 can be defined as outliers.
  • 42. Clustering-based approaches • These methods are suitable for unsupervised anomaly detection. • They aim to partition the data into meaningful groups (clusters) based on the similarities and relationships between the groups found in the data. • Each data point is assigned a degree of membership for each of the clusters. • Anomalies are those data points that: ā–« Do not fit into any clusters. ā–« Belong to a particular cluster but are far away from the cluster centroid. ā–« Form small or sparse clusters. 42
  • 43. Clustering-based approaches • These methods partition the data into k clusters by assigning each data point to its closest cluster centroid by minimizing the within-cluster sum of squares (WSS), which is: ą· š‘˜=1 š¾ ą· š‘–āˆˆš‘† š‘˜ ą· š‘—=1 š‘ƒ (š‘„š‘–š‘— āˆ’ šœ‡ š‘˜š‘—)2 where š‘† š‘˜ is the set of observations in the kth cluster and šœ‡ š‘˜š‘— is the mean of jth variable of the cluster center of the kth cluster. • Then, they select the top n points that are the farthest away from their nearest cluster centers as outliers. 43
  • 44. 44 Anomaly Detection vs Unsupervised Learning
  • 45. Clustering-based approaches • ā€œKmodā€ package in R is used to show the application of K-means model. 45 In this example the number of clusters is defined through bend graph in order to pass to K-mod function. See Clustering_Approach.R
  • 46. Clustering-based approaches 46 See Clustering_Approach.R K=4 is the number of clusters and L=10 is the number of outliers
  • 47. Clustering-based approaches 47 See Clustering_Approach.R Scatter plots of normal and outlier data points
  • 48. Summary 48 We have covered Anomaly detection Introduction  Definition of anomaly detection and its importance in energy systems  Different types of anomaly detection methods: Statistical, graphical and machine learning methods Graphical approach  Graphical methods consist of boxplot, scatterplot, adjusted quantile plot and symbol plot to demonstrate outliers graphically  The main assumption for applying graphical approaches is multivariate normality  Mahalanobis distance methods is mainly used for calculating the distance of a point from a center of multivariate distribution Statistical approach  Statistical hypothesis testing includes of: Chi-square, Grubb’s test  Statistical methods may use either scores or p-value as threshold to detect outliers Machine learning approach  Both supervised and unsupervised learning methods can be used for outlier detection  Piece wised or segmented regression can be used to identify outliers based on the residuals for each segment  In K-means clustering method outliers are defined as points which have doesn’t belong to any cluster, are far away from the centroids of the cluster or shaping sparse clusters
  • 49. (MATLAB version also available) www.analyticscertificate.com
  • 50. 50 Q&A Slides, code and details about the Anomaly detection workshop at: http://www.analyticscertificate.com/Anomaly/
  • 51. Thank you! Members & Sri Krishnamurthy, CFA, CAP Founder and CEO QuantUniversity LLC. srikrishnamurthy www.QuantUniversity.com Contact Information, data and drawings embodied in this presentation are strictly a property of QuantUniversity LLC. and shall not be distributed or used in any other publication without the prior written consent of QuantUniversity LLC. 51