Foundations · Common Data Science & ML Tasks

Anomaly detection

Anomaly detection identifies observations that are unusual relative to normal behaviour or the learned data distribution. The important practical question is not only how the technique is defined, but what assumptions it introduces, which data are allowed to influence it, and how its effect should be validated on unseen evidence.

Reference lessonPython exampleVisual explanation
Intuition first

What this concept means in practice

Anomaly detection identifies observations that are unusual relative to normal behaviour or the learned data distribution. The important practical question is not only how the technique is defined, but what assumptions it introduces, which data are allowed to influence it, and how its effect should be validated on unseen evidence.

The practical value of Anomaly detection comes from understanding both the transformation and the boundary around it: what information is allowed to enter, what assumption is being made, and how you know the result is still valid after the transformation.

A beginner-friendly way to reason about it is to start with a tiny case where the correct result can be checked independently. Once the mechanism is clear, scale the exact same reasoning to larger tables, pipelines or models.

PurposeUse when rare unusual cases matter and labelled anomalies are scarce.
MechanismEstimate density, isolation, reconstruction error or neighbourhood deviation and convert it into an anomaly score.
EvidenceInspect intermediate and final output; compare with an independent expectation.
Main cautionAn anomaly is not automatically an error or fraud; thresholds require domain validation.
Mechanism

Trace the operation from input to decision

Estimate density, isolation, reconstruction error or neighbourhood deviation and convert it into an anomaly score.

1Input→
2Apply rule→
3Inspect state→
4Validate→
5Use result
Key rule
x → anomaly score → threshold
Visual explanation

Make the structure visible

The interactive view uses a concept-specific plot when the topic maps naturally to one; otherwise it uses a workflow view instead of leaving a broken placeholder.

Loading visual…
Practical example

Where you would use it

Flag unusual network traffic or manufacturing sensor readings.

Use when
Use when rare unusual cases matter and labelled anomalies are scarce.
Pitfall

What can make the result misleading

Watch out
An anomaly is not automatically an error or fraud; thresholds require domain validation.

A useful diagnostic question is: Could the same code still run successfully if the analytical assumption were wrong? If yes, add an explicit validation check rather than relying on execution success.

Implementation

Miniature Python example

Keep the example small enough that you can inspect each stage manually.

Python
# Purpose: demonstrate Anomaly detection with a small, inspectable example.
# Follow the comments and printed stages to connect each operation with its result.
# Import the library or helper used in this example.
# Step 1 — Import the module so its functions/classes are available to the rest of this example.
import pandas as pd

# Create a small labelled dataset that is easy to inspect by eye.
# Step 2 — Construct `df` as a tabular object with named columns for inspectable analysis.
df = pd.DataFrame({
    "group": ["A","A","B","B","C","C","A","B","C","A","B","C"],
    "value": [12,15,14,18,17,21,19,20,24,22,23,27],
    "quality": [0.72,0.75,0.70,0.78,0.76,0.82,0.80,0.81,0.86,0.83,0.84,0.88]
})
# Print this intermediate result so you can verify the workflow step by step.
# Step 3 — Display the current value explicitly so the result/state can be inspected during execution.
print("STEP 1 · Miniature data shape:", df.shape)
# Print this intermediate result so you can verify the workflow step by step.
# Step 4 — Display the current value explicitly so the result/state can be inspected during execution.
print("STEP 1 · Columns:", df.columns.tolist())
# Store this intermediate value with a descriptive name for the next step.
# Step 5 — Split rows into groups so the following aggregation/transformation can be computed per group.
summary = df.groupby("group").agg(rows=("value","size"), mean_value=("value","mean"), mean_quality=("quality","mean"))
# Print this intermediate result so you can verify the workflow step by step.
# Step 6 — Display the current value explicitly so the result/state can be inspected during execution.
print("STEP 2 · Group summary:\n", summary.round(3).to_string())
# Print this intermediate result so you can verify the workflow step by step.
# Step 7 — Display the current value explicitly so the result/state can be inspected during execution.
print("STEP 3 · Overall mean value:", round(df["value"].mean(), 2))
# Print this intermediate result so you can verify the workflow step by step.
# Step 8 — Display the current value explicitly so the result/state can be inspected during execution.
print("STEP 3 · Lesson focus: Anomaly detection")
Expected / illustrative output
STEP 1 · Miniature data shape: (12, 3)
STEP 1 · Columns: ['group', 'value', 'quality']
STEP 2 · Group summary:
        rows  mean_value  mean_quality
group                                
A         4       17.00         0.775
B         4       18.75         0.782
C         4       22.25         0.830
STEP 3 · Overall mean value: 19.33
STEP 3 · Lesson focus: Anomaly detection
Implementation checklist

Before you move on

  • Can you state what data or object enters the operation?
  • Can you explain what changes and what must remain invariant?
  • Have you checked the result on a tiny case you can verify independently?
  • Have you considered the main failure mode described above?
  • Can the operation be reproduced from code/formulas and documented assumptions?