← All selected work

ML · Anomaly detection

HGAD

Graph models for changes across server signals.

Graph and hypergraph anomaly-detection experiments on server monitoring time series, from data preparation to model comparison.

  • Python
  • PyTorch
  • NumPy
  • scikit-learn
ML experiment
Relationships, then reconstructionRelationships, then reconstructionSignal windowsHypergraphAutoencoderAnomaly scoreExperimental pipeline · schematic only

Relationships, then reconstruction

  1. Signal windows

    Server Machine Dataset

  2. Hypergraph

    Build relationships

  3. Autoencoder

    Reconstruct signals

  4. Anomaly score

    Experimental pipeline · schematic only

Conceptual system illustration. Monitoring windows become a hypergraph, the model reconstructs signals, and residuals contribute to anomaly scoring. No measured results are illustrated.

The problem

A server anomaly can involve relationships between signals rather than one unusual reading. This project explores how graph and hypergraph representations capture those relationships in the Server Machine Dataset.

My contribution

Implemented data preparation, graph construction, autoencoder models, anomaly scoring, and batch experiments against several baselines.

Engineering decisions

  • Represent relationships explicitly

    Time-series windows become graph or hypergraph inputs. The hierarchical model uses adaptive edge gates and an autoencoder to reconstruct node features.

  • Compare against simpler alternatives

    Isolation Forest, LSTM autoencoder, and GCN baselines provide context for the hypergraph approach. Batch scripts keep commands, logs, and result summaries together.

  • Explain how a score becomes an anomaly

    The evaluation explores reconstruction, temporal difference, and embedding signals. Threshold selection is part of the method, not an invisible step behind a single performance number.

Delivery & scope

Experimental ML on the Server Machine Dataset. Threshold search selects F1 using test labels, so the evaluation is subject to that tuning rather than an untouched holdout. Monitoring and alerting services have not been deployed.

Explore the source

Code, architecture notes, and delivery details on GitHub.