Malicious anomalous activity detection is a fundamental challenge for cyber security systems. Both tensor decomposition under statistical framework with CANDECOMP-PARAFAC alternating Poisson regression (CP-APR) and normalizing flows have proven to be powerful unsupervised machine learning methods that model multi-dimensional data and capture complex and multi-faceted details of behavior profiles in cyber security applications. In this study, we propose Hybrid Latent-Structural Fusion (HLSF), a weighted anomaly fusion framework integrating CP-APR structural anomaly scores with latent-space density scores derived from normalizing flows. In our experiments, we show that the HLSF framework improves anomaly detection performance on a dataset of real-world compromised user credentials collected from the large enterprise network of Los Alamos National Laboratory (LANL) during a red-teaming exercise, compared with using CP-APR or normalizing flows alone.
cyber anomaly detection, non-negative tensor factorization, unsupervised learning, normalizing flows
Perez, D.M., Eren, M.E., & Kaiser, B.E. (2026). Hybrid Latent-Structural Fusion (HLSF) for Cyber Anomaly Detection.
@inproceedings{Perez2026HybridLF,
title={Hybrid Latent-Structural Fusion (HLSF) for Cyber Anomaly Detection},
author={Dorianis M. Perez and Maksim Ekin Eren and Bryan E. Kaiser},
year={2026},
url={https://api.semanticscholar.org/CorpusID:290394698}
}