{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,7]],"date-time":"2026-06-07T07:57:06Z","timestamp":1780819026769,"version":"3.54.1"},"reference-count":65,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2023,3,7]],"date-time":"2023-03-07T00:00:00Z","timestamp":1678147200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Information Science and Technology Institute at Los Alamos National Laboratory (LANL) through its Cyber Research school, by the Laboratory Directed Research and Development program of LANL","award":["20190020DR and 20210043DR"],"award-info":[{"award-number":["20190020DR and 20210043DR"]}]},{"name":"LANL Institutional Computing Program","award":["89233218CNA000001"],"award-info":[{"award-number":["89233218CNA000001"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2023,3,31]]},"abstract":"<jats:p>Distinguishing malicious anomalous activities from unusual but benign activities is a fundamental challenge for cyber defenders. Prior studies have shown that statistical user behavior analysis yields accurate detections by learning behavior profiles from observed user activity. These unsupervised models are able to generalize to unseen types of attacks by detecting deviations from normal behavior without knowledge of specific attack signatures. However, approaches proposed to date based on probabilistic matrix factorization are limited by the information conveyed in a two-dimensional space. Non-negative tensor factorization, however, is a powerful unsupervised machine learning method that naturally models multi-dimensional data, capturing complex and multi-faceted details of behavior profiles. Our new unsupervised statistical anomaly detection methodology matches or surpasses state-of-the-art supervised learning baselines across several challenging and diverse cyber application areas, including detection of compromised user credentials, botnets, spam e-mails, and fraudulent credit card transactions.<\/jats:p>","DOI":"10.1145\/3519602","type":"journal-article","created":{"date-parts":[[2022,4,12]],"date-time":"2022-04-12T11:03:23Z","timestamp":1649761403000},"page":"1-28","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":12,"title":["General-purpose Unsupervised Cyber Anomaly Detection via Non-negative Tensor Factorization"],"prefix":"10.1145","volume":"4","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4362-0256","authenticated-orcid":false,"given":"Maksim E.","family":"Eren","sequence":"first","affiliation":[{"name":"Advanced Research in Cyber Systems, Los Alamos National Laboratory, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2515-3647","authenticated-orcid":false,"given":"Juston S.","family":"Moore","sequence":"additional","affiliation":[{"name":"Advanced Research in Cyber Systems, Los Alamos National Laboratory, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7707-0838","authenticated-orcid":false,"given":"Erik","family":"Skau","sequence":"additional","affiliation":[{"name":"Information Sciences, Los Alamos National Laboratory, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8463-9252","authenticated-orcid":false,"given":"Elisabeth","family":"Moore","sequence":"additional","affiliation":[{"name":"Information Sciences, Los Alamos National Laboratory, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1421-3643","authenticated-orcid":false,"given":"Manish","family":"Bhattarai","sequence":"additional","affiliation":[{"name":"Theoretical Division, Los Alamos National Laboratory, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6223-8570","authenticated-orcid":false,"given":"Gopinath","family":"Chennupati","sequence":"additional","affiliation":[{"name":"Alexa, Amazon, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8636-4603","authenticated-orcid":false,"given":"Boian S.","family":"Alexandrov","sequence":"additional","affiliation":[{"name":"Theoretical Division, Los Alamos National Laboratory, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,3,7]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"2019. Cost of a Data Breach Report . Technical Report. IBM. Retrieved from https:\/\/www.accenture.com\/_acnmedia\/PDF-96\/Accenture-2019-Cost-of-Cybercrime-Study-Final.pdf."},{"key":"e_1_3_2_3_2","unstructured":"2019. Insider Threat Report . Technical Report. Verizon. 71 pages. Retrieved from https:\/\/enterprise.verizon.com\/resources\/reports\/insider-threat-report\/."},{"key":"e_1_3_2_4_2","unstructured":"2020. Cyber Espionage Report . Technical Report. Verizon. Retrieved from https:\/\/www.verizon.com\/business\/resources\/reports\/cyber-espionage-report\/."},{"key":"e_1_3_2_5_2","doi-asserted-by":"crossref","unstructured":"2020. Data Breach Investigations Report 2020 . Technical Report. Verizon. Retrieved from https:\/\/enterprise.verizon.com\/resources\/reports\/dbir\/.","DOI":"10.1016\/S1361-3723(20)30059-2"},{"key":"e_1_3_2_6_2","unstructured":"2020. Mandiant Security Effectiveness Report . Technical Report. FireEye. Retrieved from https:\/\/www.accenture.com\/_acnmedia\/PDF-96\/Accenture-2019-Cost-of-Cybercrime-Study-Final.pdf."},{"key":"e_1_3_2_7_2","unstructured":"2020. State of Malware Report . Technical Report. Malwarebytes Labs. Retrieved from https:\/\/www.accenture.com\/_acnmedia\/PDF-96\/Accenture-2019-Cost-of-Cybercrime-Study-Final.pdf."},{"key":"e_1_3_2_8_2","doi-asserted-by":"crossref","first-page":"203","DOI":"10.1007\/978-1-84800-046-9_11","volume-title":"Survey of Text Mining II","author":"Allan Edward G.","year":"2008","unstructured":"Edward G. Allan, Michael R. Horvath, Christopher V. Kopek, Brian T. Lamb, Thomas S. Whaples, and Michael W. Berry. 2008. Anomaly detection using nonnegative matrix factorization. In Survey of Text Mining II. Springer, 203\u2013217."},{"key":"e_1_3_2_9_2","unstructured":"Brett W. Bader Tamara G. Kolda et\u00a0al. 2017. MATLAB Tensor Toolbox Version 3.0-dev. Retrieved from https:\/\/gitlab.com\/tensors\/tensor_toolbox."},{"issue":"2","key":"e_1_3_2_10_2","article-title":"Random search for hyper-parameter optimization.","volume":"13","author":"Bergstra James","year":"2012","unstructured":"James Bergstra and Yoshua Bengio. 2012. Random search for hyper-parameter optimization.J. Mach. Learn. Res. 13, 2 (2012).","journal-title":"J. Mach. Learn. Res."},{"key":"e_1_3_2_11_2","first-page":"1","volume-title":"IEEE High Performance Extreme Computing Conference (HPEC)","author":"Bhattarai Manish","year":"2020","unstructured":"Manish Bhattarai, Gopinath Chennupati, Erik Skau, Raviteja Vangara, Hristo Djidjev, and Boian S. Alexandrov. 2020. Distributed non-negative tensor train decomposition. In IEEE High Performance Extreme Computing Conference (HPEC). IEEE, 1\u201310."},{"key":"e_1_3_2_12_2","unstructured":"Manish Bhattarai Ben Nebgen Erik Skau Maksim Eren Gopinath Chennupati Raviteja Vangara Hristo Djidjev John Patchett Jim Ahrens and Boian Alexandrov. 2021. pyDNMFk: Python Distributed Non Negative Matrix Factorization. Retrieved from https:\/\/github.com\/lanl\/pyDNMFk."},{"key":"e_1_3_2_13_2","volume-title":"Innovate for Cyber Resilience","author":"Bissell K.","year":"2020","unstructured":"K. Bissell, R. LaSalle, and P. D. Cin. 2020. Innovate for Cyber Resilience. Technical Report. Accenture, Ponemon Institute."},{"key":"e_1_3_2_14_2","volume-title":"The Cost of Cybercrime","author":"Bissell K.","year":"2019","unstructured":"K. Bissell and L. Ponemon. 2019. The Cost of Cybercrime. Technical Report. Accenture, Ponemon Institute. Retrieved from https:\/\/www.accenture.com\/_acnmedia\/PDF-96\/Accenture-2019-Cost-of-Cybercrime-Study-Final.pdf."},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/CYBERSEC.2016.017"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2894358"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.3390\/fi12100177"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-44848-9_15"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611974973.11"},{"issue":"9","key":"e_1_3_2_20_2","first-page":"1","article-title":"Distributed non-negative matrix factorization with determination of the number of latent features","volume":"76","author":"Chennupati Gopinath","year":"2020","unstructured":"Gopinath Chennupati, Raviteja Vangara, Erik Skau, Hristo Djidjev, and Boian Alexandrov. 2020. Distributed non-negative matrix factorization with determination of the number of latent features. J. Supercomput. 76, 9 (2020), 1\u201331.","journal-title":"J. Supercomput."},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1137\/110859063"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1142\/9781786345646_009"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/1571941.1572114"},{"key":"e_1_3_2_24_2","volume-title":"SIAM International Conference on Data Mining","author":"Ding Kaize","year":"2019","unstructured":"Kaize Ding, Jundong Li, Rohit Bhanushali, and Huan Liu. 2019. Deep anomaly detection on attributed networks. In SIAM International Conference on Data Mining."},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2018.02.006"},{"key":"e_1_3_2_26_2","article-title":"Temporal link prediction using matrix and tensor factorizations","volume":"1005","author":"Dunlavy Daniel M.","year":"2011","unstructured":"Daniel M. Dunlavy, Tamara G. Kolda, and Evrim Acar. 2011. Temporal link prediction using matrix and tensor factorizations. ArXiv abs\/1005.4006 (2011).","journal-title":"ArXiv"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISI49825.2020.9280524"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1080\/10556788.2015.1009977"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1002\/sapm192761164"},{"key":"e_1_3_2_30_2","unstructured":"Arjun Joshua. 2018. Predicting Fraud in Financial Payment Services. Retrieved from https:\/\/www.kaggle.com\/arjunjoshua\/predicting-fraud-in-financial-payment-services."},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/3297280.3297415"},{"key":"e_1_3_2_32_2","volume-title":"Machine Learning Methods for Malware Detection","year":"2020","unstructured":"Kaspersky. 2020. Machine Learning Methods for Malware Detection. Technical Report."},{"key":"e_1_3_2_33_2","first-page":"1037","article-title":"HiCS: High contrast subspaces for density-based outlier ranking","author":"Keller Fabian","year":"2012","unstructured":"Fabian Keller, Emmanuel M\u00fcller, and Klemens B\u00f6hm. 2012. HiCS: High contrast subspaces for density-based outlier ranking. In IEEE 28th International Conference on Data Engineering. 1037\u20131048.","journal-title":"IEEE 28th International Conference on Data Engineering"},{"key":"e_1_3_2_34_2","volume-title":"International Joint Conferences on Artificial Intelligence","author":"Kieu Tung","year":"2019","unstructured":"Tung Kieu, B. Yang, Chenjuan Guo, and Christian S. Jensen. 2019. Outlier detection for time series with recurrent autoencoder ensembles. In International Joint Conferences on Artificial Intelligence."},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/GlobalSIP.2018.8646694"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1137\/07070111X"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1145\/1081870.1081891"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1038\/44565"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1002\/cem.1244"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/2133360.2133363"},{"key":"e_1_3_2_41_2","unstructured":"E. A. Lopez-Rojas Ahmad Elmir and S. Axelsson. 2016. PaySim: A financial mobile money simulator for fraud detection."},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.11.004"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.3390\/app10051775"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICASERT.2019.8934495"},{"key":"e_1_3_2_45_2","doi-asserted-by":"crossref","first-page":"91","DOI":"10.1109\/CNS.2019.8802833","volume-title":"IEEE Conference on Communications and Network Security (CNS)","author":"Nguyen Quoc Phong","year":"2019","unstructured":"Quoc Phong Nguyen, Kar Wai Lim, Dinil Mon Divakaran, Kian Hsiang Low, and Mun Choon Chan. 2019. GEE: A gradient-based explainable variational autoencoder for network anomaly detection. In IEEE Conference on Communications and Network Security (CNS). IEEE, 91\u201399."},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/3439950"},{"key":"e_1_3_2_47_2","article-title":"Graph link prediction in computer networks using Poisson matrix factorisation","volume":"2001","author":"Passino Francesco Sanna","year":"2020","unstructured":"Francesco Sanna Passino, Melissa J. M. Turcotte, and Nicholas A. Heard. 2020. Graph link prediction in computer networks using Poisson matrix factorisation. CoRR abs\/2001.09456 (2020).","journal-title":"CoRR"},{"key":"e_1_3_2_48_2","first-page":"8024","volume-title":"Advances in Neural Information Processing Systems 32","author":"Paszke Adam","year":"2019","unstructured":"Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, Alban Desmaison, Andreas Kopf, Edward Yang, Zachary DeVito, Martin Raison, Alykhan Tejani, Sasank Chilamkurthy, Benoit Steiner, Lu Fang, Junjie Bai, and Soumith Chintala. 2019. PyTorch: An imperative style, high-performance deep learning library. In Advances in Neural Information Processing Systems 32, H. Wallach, H. Larochelle, A. Beygelzimer, F. d'Alch\u00e9-Buc, E. Fox, and R. Garnett (Eds.). Curran Associates, Inc., 8024\u20138035. Retrieved from http:\/\/papers.neurips.cc\/paper\/9015-pytorch-an-imperative-style-high-performance-deep-learning-library.pdf."},{"key":"e_1_3_2_49_2","first-page":"2825","article-title":"Scikit-learn: Machine learning in Python","volume":"12","author":"Pedregosa Fabian","year":"2011","unstructured":"Fabian Pedregosa, Ga\u00ebl Varoquaux, Alexandre Gramfort, Vincent Michel, Bertrand Thirion, Olivier Grisel, Mathieu Blondel, Peter Prettenhofer, Ron Weiss, Vincent Dubourg, et\u00a0al. 2011. Scikit-learn: Machine learning in Python. J. Mach. Learn. Res. 12, Oct. (2011), 2825\u20132830.","journal-title":"J. Mach. Learn. Res."},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSITech46713.2019.8987531"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1109\/EISIC.2018.00009"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1137\/16M1063708"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.5220\/0006893801410148"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/2783258.2783414"},{"key":"e_1_3_2_55_2","volume-title":"International Conference of Machine Learning","author":"Schein Aaron","year":"2016","unstructured":"Aaron Schein, Mingyuan Zhou, David M. Blei, and Hanna M. Wallach. 2016. Bayesian Poisson Tucker decomposition for learning the structure of international relations. In International Conference of Machine Learning."},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1088\/2632-2153\/aba9ee"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1007\/BF02289464"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISI.2016.7745472"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1142\/9781786345646_001"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA51294.2020.00060"},{"key":"e_1_3_2_61_2","first-page":"1","article-title":"Network intrusion detection using clustering and gradient boosting","author":"Verma Parag","year":"2018","unstructured":"Parag Verma, Shayan Anwar, Shadab Khan, and Sunil B. Mane. 2018. Network intrusion detection using clustering and gradient boosting. In 9th International Conference on Computing, Communication and Networking Technologies (ICCCNT). 1\u20137.","journal-title":"9th International Conference on Computing, Communication and Networking Technologies (ICCCNT)"},{"key":"e_1_3_2_62_2","first-page":"4957","volume-title":"Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017, 4\u20139 December 2017, Long Beach, CA, USA","author":"Volkovs Maksims","year":"2017","unstructured":"Maksims Volkovs, Guang Wei Yu, and Tomi Poutanen. 2017. DropoutNet: Addressing cold start in recommender systems. In Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017, 4\u20139 December 2017, Long Beach, CA, USA. 4957\u20134966. Retrieved from http:\/\/papers.nips.cc\/paper\/7081-dropoutnet-addressing-cold-start-in-recommender-systems."},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1814092116"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1109\/BigData.2017.8258364"},{"key":"e_1_3_2_65_2","doi-asserted-by":"crossref","first-page":"727","DOI":"10.1109\/ICDM.2018.00088","article-title":"Adversarially learned anomaly detection","author":"Zenati Houssam","year":"2018","unstructured":"Houssam Zenati, Manon Romain, Chuan-Sheng Foo, Bruno Lecouat, and Vijay Ramaseshan Chandrasekhar. 2018. Adversarially learned anomaly detection. In IEEE International Conference on Data Mining (ICDM). 727\u2013736.","journal-title":"IEEE International Conference on Data Mining (ICDM)"},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2015.2392756"}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3519602","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3519602","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T17:49:38Z","timestamp":1750268978000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3519602"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,3,7]]},"references-count":65,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2023,3,31]]}},"alternative-id":["10.1145\/3519602"],"URL":"https:\/\/doi.org\/10.1145\/3519602","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,3,7]]},"assertion":[{"value":"2021-09-12","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-02-17","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-03-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}