Graph Anomaly Detection as Dynamical Transport: Training-Free Scoring via Empirical Bayes
Abstract
Node-level graph anomaly detection (GAD) identifies nodes whose attributes and interactions deviate from dominant graph regularities. Existing GAD models usually encode normality and anomaly scoring indirectly through architectures, message passing, reconstruction or contrastive objectives, and tuned score families. This entangles graph trust (how strongly graph structure should define normality), graph-spectral weighting, and anomaly-score choice, yielding scores that are costly, opaque, and unstable across graph regimes. We propose EB-GAD (Empirical-Bayes GAD), a training-free framework that models normality as graph-aware generalized Ornstein--Uhlenbeck (GOU) relaxation toward a graph-filtered template. Empirical Bayes fits the graph precision and template from the residual-field likelihood; the GOU then turns scoring into closed-form transport cost from a feature-neutral node to its observed endpoint along graph-spectral relaxation. Sweeping relaxation horizon and endpoint tolerance yields a \emph{transport bank}: equilibrium Mahalanobis scoring is one limit, while finite-horizon transport-energy and scale-normalized ratio scores reveal anomalies that static equilibrium scoring can mask. A label-free selector chooses the anomaly-score family from feature homophily, edge density, and feature dimension, then ranks candidates by fitted-null KS distance and rank-stability across neighboring transport configurations. On 11 benchmarks including financial fraud networks with up to 3.7M nodes, EB-GAD achieves the best or tied-best AUROC on 9 of 11 datasets; on the largest graph, eigendecomposition and scoring finish in about six minutes.