HLSF Improves Cyber Anomaly Detection with Fusion Framework

Dorianis M. Perez, Maksim E. Eren, Bryan E. Kaiser· July 22, 2026 View original

Summary

This study proposes Hybrid Latent-Structural Fusion (HLSF), a weighted anomaly fusion framework that integrates tensor decomposition (CP-APR) structural anomaly scores with normalizing flow-derived latent-space density scores. HLSF significantly improves cyber anomaly detection performance on real-world compromised user credentials.

Detecting malicious anomalous activity is a persistent challenge in cybersecurity. Both tensor decomposition methods, like CANDECOMP-PARAFAC alternating Poisson regression (CP-APR), and normalizing flows have shown promise as unsupervised machine learning techniques for modeling multi-dimensional data and capturing complex behavioral profiles. This research introduces the Hybrid Latent-Structural Fusion (HLSF) framework, which combines the strengths of these two distinct approaches. HLSF integrates structural anomaly scores derived from CP-APR with latent-space density scores obtained from normalizing flows, using a weighted fusion mechanism. Experiments conducted on a dataset of real-world compromised user credentials from Los Alamos National Laboratory (LANL) demonstrated that the HLSF framework significantly enhances anomaly detection performance. It outperformed using CP-APR or normalizing flows in isolation, indicating that the fusion of structural and latent-space insights provides a more robust and accurate detection capability for cyber threats.

Why it matters

Cybersecurity professionals can leverage HLSF to build more effective and accurate anomaly detection systems, crucial for identifying sophisticated cyber threats and protecting sensitive enterprise networks.

How to implement this in your domain

  1. 1Evaluate the HLSF framework for enhancing your organization's existing cyber anomaly detection systems.
  2. 2Implement tensor decomposition (e.g., CP-APR) to extract structural anomaly scores from your network data.
  3. 3Integrate normalizing flows to derive latent-space density scores, capturing subtle behavioral deviations.
  4. 4Develop a weighted fusion mechanism to combine these scores, optimizing for improved detection rates and reduced false positives.

Who benefits

CybersecurityGovernmentBFSIIT ServicesCritical Infrastructure

Key takeaways

  • HLSF fuses structural and latent-space anomaly scores for superior detection.
  • It combines tensor decomposition (CP-APR) with normalizing flows.
  • The framework significantly improves cyber anomaly detection performance.
  • Fusion of diverse unsupervised methods enhances robustness against threats.

Original post by Dorianis M. Perez, Maksim E. Eren, Bryan E. Kaiser

"arXiv:2607.18479v1 Announce Type: new Abstract: Malicious anomalous activity detection is a fundamental challenge for cyber security systems. Both tensor decomposition under statistical framework with CANDECOMP-PARAFAC alternating Poisson regression (CP-APR) and normalizing flows…"

View on X

Originally posted by Dorianis M. Perez, Maksim E. Eren, Bryan E. Kaiser on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses