From Few-Shot to Zero-Shot: Towards Generalist Graph Anomaly Detection

Graph anomaly detection (GAD) is critical for identifying abnormal nodes in graph-structured data from diverse domains, including cybersecurity and social networks. The existing GAD methods often focus on the learning paradigms of “one-model-for-one-dataset”, requiring dataset-specific training for each dataset to achieve optimal performance. However, this paradigm suffers from limitations, such as high computational and data costs, limited generalization and transferability to new datasets, and challenges in privacy-sensitive scenarios where access to full datasets or sufficient labels is restricted. To address these limitations, we propose a novel generalist GAD paradigm that aims to develop a unified model capable of detecting anomalies on multiple unseen datasets without retraining/fine-tuning or customization. To this end, we propose a few-shot generalist GAD method with three key designs, namely feature <underline>A</underline>lignment, a <underline>R</underline>esidual encoder, and in-<underline>C</underline>ontext learning, abbreviated as ARC. As a generalist approach, ARC only requires a few labeled normal samples during prediction on any unseen graphs. Specifically, ARC consists of three modules: a feature <underline>A</underline>lignment module to unify and align features across datasets, a <underline>R</underline>esidual graph encoder to capture dataset-agnostic anomaly representations, and a cross-attentive in-<underline>C</underline>ontext learning module to score anomalies using few-shot normal context. Building on ARC, we further introduce ARC<inline-formula><tex-math notation="LaTeX">$_{\mathrm{zero}}$</tex-math><alternatives><mml:math><mml:msub><mml:mrow/><mml:mi> zero </mml:mi></mml:msub></mml:math><inline-graphic xlink:href="pan-ieq1-3691902.gif"/></alternatives></inline-formula> for the zero-shot generalist GAD setting, which selects representative pseudo-normal nodes via a pseudo-context mechanism and thus enables fully label-free inference on unseen datasets. Experiments on 17 real-world datasets demonstrate that ARC and ARC<inline-formula><tex-math notation="LaTeX">$_{\mathrm{zero}}$</tex-math><alternatives><mml:math><mml:msub><mml:mrow/><mml:mi> zero </mml:mi></mml:msub></mml:math><inline-graphic xlink:href="pan-ieq2-3691902.gif"/></alternatives></inline-formula> effectively detect anomalies, exhibit strong generalization ability, and perform efficiently under few-shot and zero-shot settings.

Paper

References (75)

Scroll for more · 38 remaining

Similar papers

© 2026 NYSGPT2525 LLC