Semi-supervised Streaming Anomaly Detection Using Next Activity Prediction: STAMP

Files

Access status: Embargo until 2026-11-21 , 978-3-032-26363-6_23.pdf (525.98 KB)

Publication date

2026-05-21

Authors

Lee, SuhwanORCID 0000-0001-8089-0960ISNI 0000000512552045
Lu, XixiISNI 0000000492910684
Reijers, Hajo A.ORCID 0000-0001-9634-5852ISNI 0000000037238136

Editors

Wecel, Krzysztof
Repa, Václav

Advisors

Supervisors

Document Type

Part of book

License

taverne

Abstract

Business process execution can deviate from expected behavior, resulting in anomalous events or cases. Detecting such anomalies is important for ensuring compliance, reducing risks, and improving process reliability. Existing research has mainly addressed this problem in offline settings using unsupervised learning approaches. However, such approaches detect anomalies retrospectively on complete logs and do not leverage the anomaly labels provided by domain experts. In this paper, we propose STAMP, an approach for Semi-supervised sTreaming AnoMaly detection using next activity Prediction. STAMP integrates a next-activity prediction model with an anomaly classification model trained on a limited number of anomaly labels from domain experts. Both models are continuously updated in a streaming setting to capture recent process executions. We evaluate STAMP on benchmark event logs generated with three different noise levels. Our findings demonstrate that STAMP can improve recall in early anomaly detection compared with a fixed-threshold baseline while requiring only a modest number of labeled anomalies. These findings show how semi-supervised learning can leverage scarce expert feedback for anomaly detection in streaming process monitoring.

Keywords

Anomaly detection, Event streams, Predictive process monitoring, Process Mining, Taverne, Management Information Systems, Control and Systems Engineering, Business and International Management, Information Systems, Modelling and Simulation, Information Systems and Management

Citation

Lee, S, Lu, X & Reijers, H A 2026, Semi-supervised Streaming Anomaly Detection Using Next Activity Prediction : STAMP. in K Wecel & V Repa (eds), Business Information Systems - 26th International Conference, BIS 2026, Proceedings. Lecture Notes in Business Information Processing, vol. 584 LNBIP, Springer, pp. 306-318, 26th International Conference on Business Information Systems, BIS 2026, Prague, Czech Republic, 10/06/26. https://doi.org/10.1007/978-3-032-26363-6_23, conference