ML · Anomaly detection
HGAD
Graph models for changes across server signals.
Graph and hypergraph anomaly-detection experiments on server monitoring time series, from data preparation to model comparison.
Relationships, then reconstruction
Signal windows
Server Machine Dataset
Hypergraph
Build relationships
Autoencoder
Reconstruct signals
Anomaly score
Experimental pipeline · schematic only
The problem
A server anomaly can involve relationships between signals rather than one unusual reading. This project explores how graph and hypergraph representations capture those relationships in the Server Machine Dataset.
My contribution
Implemented data preparation, graph construction, autoencoder models, anomaly scoring, and batch experiments against several baselines.
Engineering decisions
Represent relationships explicitly
Time-series windows become graph or hypergraph inputs. The hierarchical model uses adaptive edge gates and an autoencoder to reconstruct node features.
Compare against simpler alternatives
Isolation Forest, LSTM autoencoder, and GCN baselines provide context for the hypergraph approach. Batch scripts keep commands, logs, and result summaries together.
Explain how a score becomes an anomaly
The evaluation explores reconstruction, temporal difference, and embedding signals. Threshold selection is part of the method, not an invisible step behind a single performance number.
Delivery & scope
Experimental ML on the Server Machine Dataset. Threshold search selects F1 using test labels, so the evaluation is subject to that tuning rather than an untouched holdout. Monitoring and alerting services have not been deployed.
Explore the source
Code, architecture notes, and delivery details on GitHub.