Outlier edge detection using random graph generation models and applications

Outliers are samples that are generated by different mechanisms from other normal data samples. Graphs, in particular social network graphs, may contain nodes and edges that are made by scammers, malicious programs or mistakenly by normal users. Detecting outlier nodes and edges is important for data mining and graph analytics. However, previous research in the field has merely focused on detecting outlier nodes. In this article, we study the properties of edges and propose effective outlier edge detection algorithm. The proposed algorithms are inspired by community structures that are very common in social networks. We found that the graph structure around an edge holds critical information for determining the authenticity of the edge. We evaluated the proposed algorithms by injecting outlier edges into some real-world graph data. Experiment results show that the proposed algorithms can effectively detect outlier edges. In particular, the algorithm based on the Preferential Attachment Random Graph Generation model consistently gives good performance regardless of the test graph data. More important, by analyzing the authenticity of the edges in a graph, we are able to reveal underlying structure and properties of a graph. Thus, the proposed algorithms are not limited in the area of outlier edge detection. We demonstrate three different applications that benefit from the proposed algorithms: (1) a preprocessing tool that improves the performance of graph clustering algorithms; (2) an outlier node detection algorithm; and (3) a novel noisy data clustering algorithm. These applications show the great potential of the proposed outlier edge detection techniques. They also address the importance of analyzing the edges in graph mining—a topic that has been mostly neglected by researchers.


INTRODUCTION
G RAPHS are an important data representation, which have been extensively used in many scientific fields such as data mining, bioinformatics, multimedia content retrieval and computer vision.For several hundred years, scientists have been enthusiastic about graph theory and its applications [1].Since the revolution of the computer technologies and the Internet, graph data have become more and more important because many of the "big" data are naturally formed in a graph structure or can be transformed into graphs.
Outliers almost always happen in real-world graphs.Outliers in a graph can be outlier nodes or outlier edges.For example, outlier nodes in a social network graph may include: scammers who steal users' personal information; fake accounts that manipulate the reputation management system; or spammers who send free and mostly false advertisements [2], [3].Researchers have been working on algorithms to detect these malicious outlier nodes in graphs [4], [5], [6], [7].Outlier edges are also common in graphs.They can be edges that are generated by outlier nodes, or unintentional links made by normal users or the system.Outlier edges are not only harmful but also greatly increase the system complexity and degrade the performance of graph mining algorithms.In this paper, we will show that • Honglei Zhang and Moncef Gabbouj are with the Department of Signal Processing, Tampere University of Technology, Tampere, Finland E-mail: honglei.zhang@tut.fi,moncef.gabbouj@tut.fi.• Serkan Kiranyaz is with the Electrical Engineering Department, College of Engineering, Qatar University, Qatar, e-mail: mkiranyaz@qu.edu.qa.
the performance of the community detection algorithms can be greatly improved when a small amount of outlier edges are removed.Outlier edge detection can also help evaluate and monitor the behavior of end users and further identify the malicious entities.However, in contrast to the focus on the outlier node detection, there have been very few studies on outlier edge detection.
In this paper, we present novel outlier edge detection algorithms.Our proposed algorithms use the clustering property of social network graphs to detect outlier edges.The outlier score of an edge is determined by the difference of the actual number of edges and the expected number of edges that link the two groups of nodes that are around the edge.We use random graph generation models to predict the number of edges between the two groups of nodes.We evaluated the proposed algorithms using injected edges in real-world graph data.
Further more, we show the great potentials of the outlier edge detection technique in the areas of graph mining and pattern recognition.We demonstrate three different applications that are based on the proposed algorithms: 1) a preprocessing tool for graph clustering algorithms; 2) an outlier node detection algorithm; 3) a novel noisy data clustering algorithm.
The rest of the paper is organized as follows: the prior art is reviewed in Section 2; the methodology to detect outlier edges is in Section 3; evaluation of the proposed algorithms are given in Section 4; various applications that use or benefit from outlier edge detection algorithms are presented in Section 5; and finally, conclusions and future directions are included in Section 6.

PREVIOUS WORK
Outliers are data instances that are markedly different from the rest of the data [8].Outliers are often located outside (mostly far way) from the normal data points when presented in an appropriate feature space.It is also commonly assumed that the number of outliers is much less than the number of normal data points.
Outlier detection in graph data includes outlier node detection and outlier edge detection.Noble and Cook studied substructures of graphs and used the Minimum Description Length technique to detect unusual patterns in a graph [5].Xu et al. considered nodes that marginally connect to a structure (or community) as outliers [9].They used a searching strategy to group the nodes that share many common neighbors into communities.The nodes that are not tightly connected to any community are classified as outliers.Gao et al. also studied the roles of the nodes in communities [10].Nodes in a community tend to have similar attributes.Using the Hidden Markov Random Field technique as a generative model, they were able to detect the nodes that are abnormal in their community.Akoglu et al. detected outlier nodes using the near-cliques and stars, heavy vicinities and dominant heavy links properties of the ego-network-the induced network formed by a focal node and its direct neighbors [11].They observed that some pairs of the features of normal nodes follow a power law and defined an outlier score function that measures the deviation of a node from the normal patterns.Dai et al. detected outlier nodes in bipartite graphs using mutual agreements between nodes [6].
In contrast to proliferative research on outlier node detection, there have been very few studies on outlier edge detection in graphs.Chakrabarti detected outlier edges by partitioning nodes into groups using the Minimum Description Length technique [12].Edges that link the nodes from different groups are considered as outliers.These edges are also called weak links or weak ties in literature [13].Obviously this method has severe limitations.First, one shall not classify all weak links as outliers since they are part of the normal graph data.Second, many outlier edges do not happen between the groups.Finally, many graphs do not contain easily partitionable groups.
Detection of missing edges (or link prediction) is the opposite technique of outlier edge detection.These algorithms find missing edges between pairs of nodes in a graph.They are critical in recommendation systems, especially in ecommerce industry and social network service industry [14], [15].Such algorithms evaluate similarities between each pair of nodes.A pair of nodes with high similarity score is likely to be connected by an edge.One may use the similarity scores to detect outlier edges.The edges whose two end nodes have a low similarity score are likely to be the outlier edges.However, in practice, these similarity scores do not give satisfactory performance if one uses them to detect outlier edges.

Notation
Let G(V, E) denote a graph with a set of nodes V and a set of edges E. In this article, we consider undirected, unweighted graphs that do not contain self-loops.We use lower case a, b, c, etc., to represent nodes.Let ab denote the edge that connects nodes a and b.Because our graph G is undirected, ab and ba represent the same edge.Let N a be the set of neighboring nodes of node a, such that N a = {x|x ∈ V, xa ∈ E}.Let S a = N a ∪{a} (i.e. S a contains node a and its neighboring nodes).Let k a be the degree of node a, so that k a = |N a |.Let A be the adjacency matrix of graph G. Let n = |V | be the number of nodes and m = |E| be the number of edges of graph G.
Freeman defines the ego-network as the induced subgraph that contains a focal node and all of its neighboring nodes together with edges that link these nodes [16].To study the properties of an edge, we define the edge-egonetwork as follows: Definition 1.An edge-ego-network is the induced subgraph that contains the two end nodes of an edge, all neighboring nodes of these two end nodes and all edges that link these nodes.
Let G ab = G (V ab , E ab ) denote the edge-ego-network of edge ab, where V ab = S a ∪ S b and E ab = {xy|x ∈ V ab , y ∈ V ab and xy ∈ E}.

Motivation
Graphs representing real-world data, in particular social network graphs, often exhibit the clustering property-nodes tend to form highly dense groups in a graph [17].For example, if two people have many friends in common, they are likely to be friends too.Therefore, it is common for social network services to recommend new connections to a user using this clustering property [14].As a consequence, social network graphs display an even stronger clustering property compared to other graphs.New connections to a node may be recommended from the set of neighboring nodes with the highest number of common neighbors to the given node.The common neighbors (CN) score of node a and node b is defined as CN score is the basis of many node similarity scores that have been used to find missing edges [14].Some common similarity indices are: • Salton index or cosine similarity (Salton) • Jaccard index (Jaccard) • Hub promoted index (HPI) • Hub depressed index (HDI) Next we shall investigate how to detect outlier edges in a social network using the clustering property.According to this property, if two people are friends, they are likely to have many common friends or their friends are also friends of each other.If two people are linked by an edge, but do not share any common friends and neither do their friends know each other, we have good reason to suspect that the link between them is an outlier.So, when node a and node b are connected by edge ab, there should be edges connect the nodes in set S a and the nodes in set S b .However, the number of connections should depend on the number of nodes in these two groups.Let us consider the different cases as shown in Fig. 1.
In these four cases, edge ab is likely to be a normal edge in case (d) because nodes a and b share common neighboring nodes c and d, and there are connections between neighboring nodes of a and those of b.In the case of (a), (b) and (c), |N a ∩ N b | = 0, which implies that nodes a and b do not share any common neighboring nodes.However edge ab in case (c) is more likely to be an outlier edge because nodes a and b have each many neighboring nodes but there is no connection between any two of these neighboring nodes.In case (a) and (b) we do not have enough information to judge whether edge ab is an outlier edge or not.If we apply the node similarity scores to detect outlier edges, we find that S CN = 0 for cases (a), (b) and (c).Thus, the node similarity scores defined by Eqs. ( 1), ( 2), (3), ( 4) and (5) all equal to 0. For this reason, these node similarity scores cannot effectively detect outlier edges.
In case (c), edge ab is likely to be an outlier edge because the expected number of edges between node a together with its neighboring nodes and node b together with its neighboring nodes is high, whereas the actual number of edges is low.So, according to the clustering property, we propose the following definition for the edge outlier score: Definition 2. The outlier score of an edge is defined as the difference between the number of actual edges and the expected value of the number of edges that link the two sets of neighboring nodes of the two end nodes of the given edge.That is: where m ab is the actual number of edges that links the two sets of nodes-one set is node a together with its neighboring nodes and the other set is node b together with its neighboring nodes, and e ab is the expected number of edges that link the aforementioned two sets of nodes.
We can rank the edges by their edge outlier scores defined in Eq. ( 6).The edges with low scores are more likely to be outlier edges in a graph.
Let α (S, T ) = ab|a ∈ S, b ∈ T and ab ∈ E denote the number of edges that links the nodes in sets S and T .We suppose the graph G is generated by a random graph generation model.Let (S, T ) denote the expected value of the number of edges that links the nodes in sets S and T by the generation model.Section 3.4 describes two generation models and the functions of calculating (S, T ).Obviously α (S, T ) and (S, T ) are symmetric functions.That is:

Schemes of Node Neighborhood Sets
For a ego-network, Coscia and Rossetti showed the importance of removing the focal node and all edges that link to it when studying the properties of ego-networks [18].
It is more complicate to study the properties of an edgeego-network since there are two ending nodes and two sets of neighboring nodes involved.Considering the common nodes of the neighboring nodes and the end nodes of the edge being investigated, we now define four schemes that capture different configurations of these two sets.
Let S a\b = S a \ {b} be the set of nodes that contains node a and its neighboring nodes except node b.Let N a\b = N a \ {b} be the set of nodes that contains the neighboring nodes of a except node b.Obviously S a\b = N a\b ∪ {a}.Fig. 2 shows the edge-ego-network G ab and the two sets of nodes S a\b and S b\a corresponding to case (d) in Fig. 1.
We first define two sets of nodes that are related to node a and its neighboring nodes: N a\b and S a\b .Next, we define two sets of nodes that are related to node b and its neighboring nodes with regard to the sets of nodes N a\b and S a\b : S b\a \S a\b and S b\a .In Fig. 2 Based on the set pairs of nodes a and b, we define the following four schemes and their meanings in the case of a social network graph.We use superscript ( 1), ( 2), ( 3) and ( 4) to indicate the four schemes respectively.For the edge-ego-network G ab shown in Fig. 2, scheme 1 examines edges ef , cb and db; scheme 2 examines edges ef , ec, cb, cd, dc and db; scheme 3 examines edges ab, ef , cb and db; scheme 4 examines edges ab, ac, ad, ef , ec, cb, db, dc and cd.
Next we study the symmetric property of these four schemes.
The proof of this theorem is given in appendix.Theorem 4 shows that the number of edges that link the nodes from the two groups defined in scheme 2 and scheme 4 are symmetric.That is the values remains the same if the two end nodes are switched.We can use m a,b instead of Eq. 7.

Theorem 5. P
a,b , R a,b = P b,a This theorem can be directly derived from a,b = P a,b .Note scheme 4 is symmetric in calculating both of the actual and expected number of edges of the two groups.

Expected Number of Edges Between Two Sets of Nodes
With the four schemes described above, we get the number of edges that connect nodes from the two sets using Eq. 7. To calculate the outlier score of an edge by Eq. ( 6), we should find the expected number of edges between these two sets of nodes.Next we will use random graph generation models to determine the expected number of edges between these two sets of nodes.

Erd ős-Rényi Random Graph Generation Model
The Erdős-Rényi model, often referred as G(n, m) model, is a basic random graph generation model [19].It generates a graph of n nodes and m edges by randomly connecting two nodes by an edge and repeat this procedure until the graph contains m edges.
Suppose we have n nodes in an urn and predefined two sets of nodes S and T .We randomly pick two nodes from the urn.Note, the intersection of sets S and T may not be empty.The probability of picking the first node from set S\T is |S|−|S∩T | n and the probability of picking the first node from set S ∩ T is |S∩T |  n .If the first node is from set S, the probability of picking the second node from set T is Since the graph is undirected, we may also pick up a node from set T first and then pick up the second node from set S. So, the probability that we generate an edge that connects a node set S and a node from set T by randomly picking is: We repeat this procedure m times to generate a graph, where m is the number of edges in graph G.The expected number of edges that connect the nodes in set S and the nodes in set T is: Note, here we ignore the duplicate edges during this procedure.This has little impact on the final results for realworld graphs where m n(n − 1).In Eq. ( 10), let where d G is the density (or fill) of graph G. Next we will find the expected number of edges under the four schemes defined in Section 3.3.Since edge ab is already fixed, we should repeat the random procedure m−1 times.For real-world graphs where m 1, we can safely approximate m − 1 by m.Now we can apply Eq. ( 10) under the four schemes.Let k a and k b be the degrees of nodes a and b.Let k ab = |N a ∩ N b | be the number of common neighboring nodes of nodes a and b.The expected number of edges for each scheme is: • Scheme 2: • Scheme 3: • Scheme 4: e

Preferential Attachment Random Graph Generation Model
The Erdős-Rényi model generates graphs that are lacking some important properties of real-world data, in particular the power law of the degree distribution [1].Next we introduce a random graph generation model using a preferential attachment mechanism that generates a random graph in which degrees of each node are known.Our preferential attachment random graph generation model (PA model) is closely related to the modularity measurement that evaluates the community structure in a graph.Newman defines the modularity value as the difference of the actual number of edges and the expected number of edges of two communities [20].The way of calculating the expected number of edges between two communities follows preferential attachment mechanism instead of using the Erdős-Rényi model.
In the Erdős-Rényi model, each node is picked with the same probability.However, by the preferential attachment mechanism, the nodes with high degrees are picked with high probabilities.Thus an edge is more likely to link nodes with a high degree.
We can apply the preferential attachment strategy to generate a random graph with n nodes, m edges and each node has a predefined degree value.We first break each edge into two ends and put all the 2m ends into an urn.A node with degree k will have k entities in the urn.At each round, we randomly pick two ends (one at a time with substitution) from the urn, link them with an edge and put them back into the urn.We repeat this procedure m times.We call this procedure Preferential Attachment Random Graph Generation model, or PA model in short.Note, we may generate duplicate edges or even self-loops with this procedure.Thus the expected number of edges estimated by this model is higher than a model that does not generate duplication edges and self-loops.This defect can be ignored when k a and k b are small.Later we will show a method that can compensate this bias, especially when k a and k b are large.
If we have two nodes a and b, the probability that an edge is formed in each round is: Then the expected number of edges that link the nodes a and b after m iterations is: If we have two sets of nodes S and T , the expected number of edges that link the nodes in set S and the nodes in set T is: Applying Eq. ( 18) to the four schemes defined in Section 3.3, we get the expected number of edges for each scheme is

Edge Outlier Score
We may apply Eqs. ( 19), ( 20), (21) or (22) to Eq. ( 6) to calculate the outlier score of an edge.As mentioned in Section 3.4.2, the PA model generates graphs with duplicate edges and self-loops.Thus the estimated expected number of edges that link two sets of nodes are higher than an accurate model.The gap is even more significant when the number of edges is large.To compensate for this bias, we refine the edge outlier score function for the PA model as where γ > 1.The power function of the first term increases the value, especially when m ab is large.This eventually compensates the bias introduced in the second term.In practice, we normally choose γ = 2.

Matrix of Degree Products
1) or ( 22), we should find the sum of k a k b for every pair of nodes in the corresponding edge-ego-network.We can store the values of k a k b for every pair of nodes to prevent unnecessary multiplication operations and thus reduce the processing time.However, storing this information would require a storage space in the order of n 2 , which is not applicable when n is large.We observe that we do not need to calculate the product of the degrees for every pair of nodes in graph G. What we need is the pair of nodes that appear together in every edge-egonetwork.
The distance of two nodes in a graph is defined as the length of the shortest path between them.It is easy to see that the maximum distance of two nodes in an edge-egonetwork is 3. Next, we use the property of the adjacency matrix to find the pairs of nodes that appear together in edge-ego-networks.
Let d ij be the distance of node i and node j.Let B(k) = A k , where A is the adjacency matrix of graph G and k is a natural number.Let B ij (k) be the element of the matrix B(k).Then B ij (k) is the number of walks with length k between node i and node j.If B ij (k) = 0, there is no walk with length k between nodes i and j.
there exists at least one path with length k from node i to node j.Since a path of a graph is a walk between two nodes without repeating nodes, there exists at least one walk with length k between the node i and the node j.So B ij (k) = 0.
According to Theorem 7, to find the pairs of nodes with a distance of 3 or less, we need to find the nonzero elements in matrix K(3).Let I be the indicator matrix whose elements indicate whether the distance between a pair of nodes is equal to or less than 3.Such that: Let matrix D denote the degree matrix whose diagonal elements are the degree of each node, that is: where • denotes the Hadamard product of two matrices.The value of the nonzero elements in matrix E is the expected number of edges between the two nodes under the PA model.Using matrix E, we can easily calculate the edge outlier score for each scheme.For example the outlier score of the edge ab using scheme 1 and the score function defined by Eq. ( 6) is: b,a j∈R (1) b,a

EVALUATION OF THE PROPOSED ALGORITHMS
In this section we evaluate the performance of the proposed outlier edge detection algorithms.Due to the availability of the datasets with identified outlier edges, we generate test data by injecting outlier edges to real-world graphs.This experimental setup is efficient to evaluate algorithms that detect outliers.We also evaluate the proposed outlier detection algorithms by measuring the change of some important graph properties when outlier edges are removed.In next section, we will show that the proposed algorithms are not only effective in simulated data but also powerful in solving real-world problems in many areas.We first inject edges to a real-world graph data by randomly picking two nodes from the graph and linking them with an edge, if they are not linked.The injected edges are formed randomly, and thus they do not follow any underlying rule that generated the real-world graph.An outlier edge detection algorithm returns the outlier score of each edge.Given a threshold value, the edges with lower scores are classified as outliers.
With multiple algorithms, we vary the threshold value and record the true positive rates and the false positive rates of each algorithm.We use the receiver operating characteristic (ROC) curve-a plot of true positive rates against false positive rates at various threshold values-to subjectively compare the performance of different algorithms.We also calculate the area under the ROC curve (AUC) value to quantitatively evaluate the competing algorithms.

Comparison of Different Combinations of the Proposed Algorithm
The proposed algorithm involves two random graph generation models and four schemes.Two outlier score functions are proposed for the PA Model.With the first experiment, we study the performance of different combinations using real-world graph data.
We take the Brightkite graph data as the test graph [21].Brightkite is a social network service in which users share their location information with their friends.The Brightkite graph contains 58, 228 nodes and 214, 708 edges.The data was received from the KONECT graph data collection [22].
We injected 1, 000 random "false" edges to the graph data.If an algorithm yields the same outlier scores to multiple edges, we randomly order these edges.We compare the detection results of the algorithms using the Erdős-Rényi (ER) model and the PA model with the combination of the four schemes explained in Section 3.3 and the two score functions defined in Eqs. ( 6) and (23).Table 1 shows the AUC values of the ROC curves of all combinations.Bold font indicates the best score among all of them.From the experimental results, we see that the performance of the PA model with score function defined by Eq. ( 23) is clearly better than that of the score function defined by Eq. ( 6).The term m γ in Eq. ( 23) increases the value even more when m is large.After the bias of the PA model is corrected, the performance of the outlier edge detection algorithm is greatly improved.The choice of the score function defined by Eqs. 6 and 23 has little impact to the ER model based algorithms.
The results also show that the combination of the PA model and the score function defined by Eq. ( 23) is superior than other combinations by a significant margin.Scheme 2 gives better performance than the other schemes, especially for ER Model based algorithms.In the rest of this paper, we use scheme 2 for the ER Model based algorithm.With the combination of the PA Model and the score function defined by Eq. 23, the difference between each scheme is insignificant.Because of the symmetric property of scheme 4, we use it for the PA model with the score function defined by Eq. 23.

Comparison of Outlier Edge Detection Algorithms
In this section we perform comparative evaluation of the proposed outlier edge detection algorithms against other algorithms.All test graphs originate from the KONECT graph data collection.Table 2 shows some parameters of the test graph data.The density of a graph is defined in Eq. (11).GCC, which stands for the global clustering coefficient, is a measure of clustering property of a graph.It is the ratio of the number of closed triangles and the number of connected triplet nodes.The higher GCC value is, the stronger clustering property a graph has.We compared the performance of the two proposed algorithms (ER model combined with scheme 2 and the score function defined by Eq. ( 6) and PA model combined with scheme 4 and the score function defined by Eq. ( 23)) with three other algorithms that use node similarity scores for missing edge detection.We use the Jaccard Index and Hub Promoted Index (HPI) as defined in Eqs. ( 3) and (4).We also use the Preferential Attachment Index (PAI) that is another missing edge detection metric that works for outlier edge detection.The PAI for edge ab is defined as Fig. 3 shows the ROC curves of different algorithms on the Brightkite graph data.For reference, the figure also shows an algorithm that randomly orders the edges by giving random scores to each edge.As Fig. 3 shows, the ROC curve of the algorithm that gives random scores is roughly a straight line from the origin to the top right corner.This line indicates that the algorithm cannot distinguish between an outlier edge and a normal edge, which is expected.The ROC curve of an algorithm that can detect outlier edges should be a curve above this straight line, as all algorithms used in this experiment.As mentioned in Section 3.2, the Jaccard Index and HPI both use the number of common neighbors.Thus their scores are all 0 for edges that connect two end nodes that do not share any common neighbors.In real-world graphs, a large amount of edges have a Jaccard Index or HPI value 0, especially for graphs that contain many low degree nodes.
The PAI value is the product of the degrees of the two end nodes of an edge.Sorting edges with their PAI values just puts the edges with low degree end nodes to the front.The figure shows that the PAI value can detect outlier edges with fairly good performance.This indicates that most of the injected edges connecting the nodes with low degrees.Considering most of the nodes in a real-world graph are low degree nodes, this is an expected behavior.
Fig. 3 indicates that the proposed outlier edge detection algorithms are clearly superior to the competing algorithms.The algorithm based on the PA model performs better than the one based on the ER model .
Table 3 shows the AUC values of the ROC curves on all test graph data.Bold font shows the best AUC values for each test graph.

Change of Graph Properties
The proposed outlier edge detection algorithms are based on the clustering property of graphs.Since outlier edges are defined as edges that do not follow the clustering property, removing them should increase the coefficients that measure this property.On the other hand, some outlier edges (also called weak links in this aspect) serves an important role to connect remote nodes or nodes from different communities.
Removing such edges should also extensively increase the distance of the two end nodes.Thus the coefficients that measure the distance between the nodes of a graph shall increase when outlier edges are removed.In this experiment, we verify these changes caused by the removal of the detected outlier edges.The global clustering coefficient (GCC) and the average local clustering coefficient (ALCC) are the de facto measures of the clustering property of graphs.GCC is defined in Section 4.2.Local clustering coefficient (LCC) is the ratio of the number of edges that connect neighboring nodes of a node and the number of all possible edges that connect these neighboring nodes.The LCC of node a can be expressed as ALCC is the average of the local clustering coefficients of all nodes in the graph.We use diameter, the 90-percentile effective diameter (ED) and the mean shortest path (MSP) length as distance measures between the nodes in a graph.Diameter is the maximum shortest path length between any two nodes in a graph.90-percentile effective diameter is the number of edges that are needed on average to reach 90% of other nodes.The mean shortest path length is the average of the shortest path length between each pair of nodes in the graph.Note, if the graph is not connected, we measure the diameter, ED and MSP of the largest component in the graph.
In this experiment, we removed 5% of the edges with the lowest outlier score.Table 4 shows the GCC, ALCC, Diameter, ED and MSP values before and after the outlier edges were removed.For comparison, we also calculated values of these coefficients after same amount of edges are randomly removed 5% from the graph.The results show that removing the detected outlier edges clearly increases the GCC and ALCC values, while random edge removal slightly decreases the values.This confirms the enhancement of the clustering property after outlier edges are removed.The diameter, ED and MSP values all increase when the detected outlier edges were removed.This increase is much more significant than when random edges were removed.This also confirms the theoretical prediction.

APPLICATIONS
In this section, we demonstrate various applications that benefit from the proposed outlier edge detection algorithms.In these applications, we use the algorithm of the PA model combined with scheme 4 and the score function defined by Eq. 23.

Impact on Graph Clustering Algorithms
Graph clustering is an important task in graph mining [29], [30], [31].It aims to find clusters in a graph-a group of nodes in which the number of inner links between the nodes inside the group is much higher than that between the nodes inside the group and those outside the group.Many techniques have been proposed to solve this problem [32], [33], [34], [35].
The proposed outlier edge detection algorithms are based on the graph clustering property.They find edges that link the nodes in different clusters.These edges are also called weak links in the literature.With the proposed techniques, we can now remove detected outlier edges before applying a graph clustering algorithm.This should improve the graph clustering accuracy and reduce the computational time.
In this application, we evaluate the performance impact of the proposed outlier edge detection technique on different graph clustering algorithms.We use simulated graph data with cluster structures as used in [34], [36], [37], [38].We generated test graphs of 512 nodes.The average degree of each node is 24.The generated cluster size varies from 16 to 256.Let d out be the average number of edges that link a node from the cluster to nodes outside the cluster.Let d be the average degree of the node.Let µ = dout d be the parameter that indicates the strength of the clustering structure.The smaller µ is, the stronger the clustering structure is in the graph.We varied µ from 0.2 to 0.5.Note, when µ = 0.5, the graph has a very weak clustering structure, i.e. a node inside the cluster has an equal number of edges that link it to other nodes inside and outside the cluster.
We use the Normalized Mutual Information (NMI) to evaluated the accuracy of a graph clustering algorithm.The NMI value is between 0 and 1.The larger the NMI value is, the more accurate the graph clustering result is.An NMI value of 1 indicates that the clustering result matches the ground truth.More details of the NMI metric can be found in [33], [39].
We first apply graph clustering algorithms to the test graph data and record their NMI values and computational time.Then we remove 5% of the detected outlier edges from the test graph data, and apply these graph clustering algorithms again to the new graph and record their NMI values and computational time.The differences of the NMI values and the computational time show the impact of the outlier edge removal on the graph clustering algorithms.
We repeated the experiment 10 times and calculated the average performance.Table 5 shows the NMI values before and after outlier edges were removed.The first number in each cell shows the NMI values of the clustering result on the original graph and the second number shows the NMI values of the clustering result on the graph after the outlier edges were removed.The results show that outlier edge removal improves the accuracy of most graph clustering algorithms.The clustering accuracy of the SLM algorithm and the Louvain algorithm decrease slightly in some cases.
Table 7 shows the computational time changes in percentage before and after outlier edges are removed.Negative values indicate that the computational time is decreased.
These results show that outlier edge removal decreases the computational time of most algorithms used in the experiment.In some cases, SLM and the Louvain algorithms show significant gains in computation time.Note further that the increase of the computational time in the Infomap algorithm leads to a crucial improvement of the clustering accuracy.

Outlier Node Detection in Social Network Graphs
As mentioned in Section 2, many algorithms have been proposed to detect outlier nodes in a graph.In this section we present a technique to detect outlier nodes using the proposed outlier edge detection algorithm.
In a social network service, if a user generates many links that do not follow the clustering property, we have good reasons to suspect that the user is a scammer.To detect this type of outlier nodes, we can first detect outlier edges.Then we find nodes that are the end points of these outlier edges.Nodes that are linked to many outlier edges are likely to be outlier nodes.
In this application, we use Brightkite data for outlier node detection.In the experiment, we rank the edges according to their outlier scores.We take the first 1000 edges as outlier edges and rank each node according to the number of outlier edges that it is connected to.
Table 8 shows the top 8 detected outlier nodes: the node ID, the number of outlier edges that the node links, the degree of the node, the rank of the degree among all nodes and LCC values of the node.
The results show that the detected outlier nodes tend to have large degree values.In particular, the LCC values of the detected outlier nodes are extremely low comparing to the ALCC value (0.172) of the graph.This shows that the neighboring nodes of the detected outlier nodes have very weak clustering property.

Clustering of Noisy Data
Clustering is one of the most important tasks in machine learning [43].During the last decades, many algorithms have been proposed, i.e. [44], [45], [46].The task becomes more challenging when noise is present in the data.Many algorithms, especially connectivity-based clustering algorithms, fail over such data.In this section we present a robust clustering algorithm that uses the proposed outlier edge detection techniques to find correct clusters in noisy data.
Graph algorithms have been successfully used in clustering problems [47], [48].To cluster the data, we first build a mutual k-nearest neighbor (MKNN) graph [49], [50].Let x 1 , x 2 , . . ., x n ∈ R d be the data points, where n is the number of data points and d is the dimension of the data.Let d(x i , x j ) be the distance between two data points x i and x j .Let N k (x i ) be the set of data points that are the k-nearest neighbors of the data point x i with respect to the predefined distance measure d (x i , x j ).Therefore, the cardinality of the set N k (x i ) is k.A MKNN graph is built in the following way.The nodes in the MKNN graph are the data points.Two nodes x i and x j are connected if x i ∈ N k (x j ) and x j ∈ N k (x i ).The constructed MKNN graph is unweighted and undirected.
With a proper distance function, data points in a cluster are close to each other whereas data points in different clusters are far away from each other.Thus, in the constructed MKNN graph, a node is likely to be linked to other nodes in the same cluster while the links between the nodes in different clusters are relatively less.This indicates that the MKNN graph has the clustering property similar to social network graphs.
Outlier data points are normally far away from the normal data points.Some outlier nodes form isolated small components in the MKNN graph.However, the outlier nodes that fall between the clusters form bridges that connect different clusters.These bridges greatly degrade the performance of connectivity-based clustering algorithms, such as single-linkage clustering algorithm and completelinkage clustering algorithm [43].
Based on these observations, we propose a hierarchical clustering algorithm by iteratively removing edges (weak links) according to their outlier scores.When a certain amount of outlier edges is removed, different clusters form separate large connected components-a connected component in a graph that contains a large proportion of the nodes, and it is straightforward to find them in the graph.A breadth-first search or a depth-first search algorithm can find all connected components in a graph with the complexity of O(n), where n is the number of nodes.At each iteration step, we find large connected components in the MKNN graph and the data points that do not belong to any large connected components are classified as outliers.
Using the proposed algorithm, we cluster a dataset taken from [51].As the Fig. 4 shows, the proposed algorithm cannot only classify outliers and normal data points but also find clusters in the data points.As more and more edges are removed from the MKNN graph, the number of clusters increases.
Next we show how to determine the true number of clusters.Table 9 shows the number of removed edges and the number of detected clusters of this dataset.As the result shows, removing a small amount of edges is enough to find correct clusters in the data.One has to remove a large amount of edges to break a genuine cluster into smaller components.We can simply define a threshold and stop the iteration if the number of clusters does not increase any more.
To illustrate the performance of the proposed clustering algorithm, we use synthetic data that are both noisy and challenging.Fig. 5 shows the test datasets.We used tools from [52] to generate the normal data points and added random data points as noise.In our experiments, we use the Euclidean distance function.The number of nearest neighbors is 30.At each iteration step, we remove 0.1% of total number of edges according to their outlier scores.A large connected component is a component whose size is larger than 5% of the total number of nodes.The clustering termination threshold is set as 10% of the total number of edges.
We compare the proposed clustering algorithm with the k-means [43], the average-linkage (a-link) [43], the normalized cuts (N-Cuts) [53] and the graph degree linkage (GDL) [46] clustering algorithms.Since the competing algorithms cannot detect the number of clusters, we use the value from the ground truth.Table 10 shows the NMI scores of the proposed algorithm and the competing algorithms.The results show that the k-means and the average linkage clustering algorithms fail on complex-shaped clusters.GDL and the proposed algorithms are all graph-based clustering algorithms.They are able to find clusters with arbitrary shapes.From the NMI scores, the proposed algorithm is clearly superior to the competing clustering algorithms.

CONCLUSIONS
In real-world graphs, in particular social network graphs, there are edges generated by scammers, malicious programs or mistakenly by normal users and the system.Detecting these outlier edges and removing them will not only improve the efficiency of graph mining and analytics, but also help identify harmful entities.In this article, we introduce outlier edge detection algorithms based on two random graph generation models.We define four schemes that represent relationships of two nodes and the groups of their neighboring nodes.We combine the schemes with the two random graph generation models and investigate the proposed algorithms theoretically.We tested the proposed outlier edge detection algorithms by experiments on real-world graphs.The experimental results show that our proposed algorithms can effectively identify the injected edges in real-world graphs.We compared the performance of our proposed algorithms with other outlier edge detection algorithms.The proposed algorithms, especially the algorithm based on the PA model, give consistently good results regardless of the test graph data.We also evaluated the changes of graph properties caused by the removal of the detected outlier edges.The experimental results show an increase in both the clustering coefficients and the increase of the distance between the nodes in the graph.This is coherent with the theoretical predictions.
Further more, we demonstrate the potential of the outlier edge detection using three different applications.When used with the graph clustering algorithms, removing outlier edges from the graph not only improves the clustering accuracy but also reduces the computational time.This indicates that the proposed algorithms are powerful preprocessing tools for graph mining.When used for detecting outlier nodes in social network graphs, we can successfully find outlier nodes whose behavior deviates dramatically from that of normal nodes.We also present a clustering algorithm that is based on the edge outlier scores.The clustering algorithm can efficiently find true data clusters by excluding noises from the data.
Outlier edge detection has great potentials in numerous Big Data applications.In the future, we will apply the proposed outlier edge detection algorithms in applications in other fields, for example computer vision and content-based multimedia retrieval in the Big Visual Data.We observed that nodes and edges outside edge-ego-network also contain valuable information in outlier detection.However, using this information dramatically increases the computational cost.We will work on fast algorithms that can efficiently use the structural information of the whole graph.
Proof: Let A be the adjacency matrix of an unweighted and undirected graph G.We have α(S, T ) = i∈S j∈T A ij .Given S ∩ T = ∅,

Theorem 3 .
α (S, T ) = α (T, S) and (S, T ) = (T, S).Let P a,b and R a,b be the two sets of nodes that are related to end nodes a and b.Node set R a,b depends on set P a,b .The actual number of edges and the expected number of edges of the sets of nodes related to the two end nodes may vary when we switch the end nodes a and b.We use the following equations to calculate m ab and e ab : m ab = 1 2 (α (P a,b , R a,b ) + α (P b,a , R b,a )) ; a,b , R a,b ) + (P b,a , R b,a )) .
, N a\b = {c, d, e, g, h}, S a\b = {a, c, d, e, g, h}, S b\a \S a\b = {b, f, i, j} and S b\a = {b, c, d, f, i, j}.In the case of a social network graph, N a\b would consist of friends of user (node) a except b; S a\b consists of a and friends of a except b; S b\a \S a\b consists of b and friends of b except a and those who are friends of a; S b\a consists of b and friends of b except a.

Fig. 2 . 1 •
Fig. 2. The sets of the nodes of the edge-ego-network G ab in the case (d) of Fig. 1

Fig. 3 .
Fig. 3. ROC curve of different algorithms on the Brightkite graph data

TABLE 1 AUC
Values of the ROC Curves Using Brightkite Graph Data

TABLE 3
consistently good performance regardless of the test graph data.The experiment also shows the correlation between the performance of the algorithms that are based on the random graph generation model and the GCC value of the test graph.For example, the ER model and PA model algorithms works better on Facebook-Wosn and Brightkite graph data, which have high GCC values as shown in Table2.Performance of the ER model algorithm degrades considerably on graphs with a very low GCC value, such as the twitter-icwsm graph.This result agrees with the fact that both the ER model and the PA model algorithms use the clustering property of graphs.We also observe that PAI works better on graphs with low GCC values.We estimate that these graphs contain many star structures and two nodes with low degrees are rarely linked by an edge.The large number of claw count (28 billion) and small number of triangle count (38k) in twitter-icwsm graph data partially confirm our estimation.
The comparison results show that the PA model algo-rithm gives

TABLE 4 Graph
Properties Changes After Noise Edges Removal

TABLE 5 The
NMI Values Before and After Outlier Edges Were Removed

Table 6
shows the NMI value changes in percentage.A positive value indicates that the NMI value has increased.

TABLE 9
Percentage of the Removed Edges and the Number of Detected Clusters