Unsupervised Online Detection of Pipe Blockages and Leakages in Water Distribution Networks Jin Li1,2, Kleanthis Malialis1, Stelios G. Vrachimis1, and Marios M. Polycarpou1,2 Abstract— Water Distribution Networks (WDNs), critical to public well-being and economic stability, face challenges such as pipe blockages and background leakages, exacerbated by operational constraints such as data non-stationarity and limited labeled data. This paper proposes an unsupervised, online learning framework that aims to detect two types of faults in WDNs: pipe blockages, modeled as collective anomalies, and background leakages, modeled as concept drift. Our approach combines a Long Short-Term Memory Variational Autoencoder (LSTM-VAE) with a dual drift detection mechanism, enabling robust detection and adaptation under non-stationary conditions. Its lightweight, memory-efficient design enables real-time, edge-level monitoring. Experiments on two realistic WDNs show that the proposed approach consistently outperforms strong baselines in detecting anomalies and adapting to recurrent drift, demonstrating its effectiveness in unsupervised event detection for dynamic WDN environments. Index Terms— water distribution networks, water leakage, pipe blockage, anomaly detection, concept drift, autoencoders I. INTRODUCTION In the face of climate change, drinking water scarcity is expected to worsen. A reliable Water Distribution Network (WDN) [1] requires automated monitoring for early event detection to ensure supply consistency. Data-driven event detection methods that use pressure sensors, favored for their low cost, present challenges due to unlabeled events and fluctuating operating conditions, such as pipe cracks (background leakages). On the other hand, faults like pipe blockages, due to debris or valve malfunctions, significantly impact pressure. In other words, background leakages in WDNs cause minor pressure shifts, while pipe blockages trigger significant changes. The vast majority of existing data-driven methods treat the problem of event detection as anomaly detection, and, typically, assume the existence of only one type of anomaly, for example, only pipe blockage or only leakages, but not both [2], [3]. Furthermore, most anomaly detection methods 1KIOS Research and Innovation Center of Excellence, University of Cyprus, Nicosia, Cyprus 2Department of Electrical and Computer Engineering, University of Cyprus, Nicosia, Cyprus li.jin, malialis.kleanthis, vrachimis.stelios,
[email protected] ORCID: {0000-0002-3534-524X, 0000-0003-3432-7434, 0000-00018862-5205, 0000-0001-6495-9171} This paper was supported by the European Research Council (ERC) under grant agreement No 951424 (Water-Futures), the European Union’s Horizon 2020 research and innovation programme under grant agreement No 739551 (KIOS CoE), and the Republic of Cyprus through the Deputy Ministry of Research, Innovation and Digital Policy. rely on signatures or labeled data (i.e., the ground truth), which are difficult to obtain in real time for WDNs. If a group of related data exhibits anomalies relative to the entire dataset, it is termed collective anomalies. Individually, these data instances may not be considered anomalies, but their occurrence together as a collection is deemed anomalous [4]. For example, the pressure values of nodes during a pipe blockage can be considered as collective anomalies, as these values partially fall within the normal range. This study focuses on the simultaneous detection of changes in operating conditions and anomalies in WDN. We introduce a new approach aimed at addressing the challenges associated with the detection of these events. The key contributions of this work are as follows: 1) We propose an unsupervised online framework for detecting pipe blockages (anomalies) and water leakages (concept drift) in water networks, combining LSTM Variational AutoEncoder (LSTM-VAE) with dual drift detection, and enabling lightweight edge deployment for real-time, distributed fault monitoring. 2) We evaluate two realistic WDNs and demonstrate that our method effectively detects pipe blockages amid background leakages, outperforming strong baselines and state-of-the-art approaches. The paper is organized as follows: Sec. II reviews related work; Sec. III outlines the problem and method; Sec. IV and Sec. V cover the experimental setup and results; Sec. VI discusses and concludes and outlines future work. II. RELATED WORK A. Concept drift adaptation Data nonstationarity poses a significant challenge in certain streaming applications, often stemming from concept drift, which signifies a change in the underlying joint probability distribution. Approaches to adapt to concept drift are often classified as passive or active [5]. Passive methods implicitly address drift using incremental learning, which is the continuous adaptation of the model without complete re-training [6]. In this category, methods can be categorized into memory-based and ensemble methods. Memory-based algorithms utilize a memory component to retain a set of recent examples on which the classifier is trained [7], [8]; Ensemble methods, on the other hand, consist of a set of classifiers that can be dynamically added or removed based on their performance [9]. 2025 6th International Conference on Control and Fault-Tolerant Systems (SysTol) October 6-8 2025. Ayia Napa, Cyprus 978-1-6654-5771-2/25/$31.00 ©2025 IEEE 271 2025 6th International Conference on Control and Fault-Tolerant Systems (SysTol) | 978-1-6654-5771-2/25/$31.00 ©2025 IEEE | DOI: 10.1109/SYSTOL66549.2025.11267371 Authorized licensed use limited to: University of Cyprus. Downloaded on December 04,2025 at 09:53:48 UTC from IEEE Xplore. Restrictions apply.
Active methods rely on explicitly identifying changes in the data distribution to initiate an adaptation mechanism [5]. Two primary categories of detection mechanisms are investigated: statistical tests and threshold-based mechanisms. Statistical tests monitor the statistical characteristics of the generated data, while threshold-based mechanisms observe prediction errors and compare them to a predefined threshold. Hybrid methods, such as HAREBA [10], are proposed to combine the strengths of both active and passive methods. Another work [11] also employs an autoencoder and leverages on the advantages of both incremental learning and drift detection based on the Mann-Whitney U Test. The method proposed in this paper uses unsupervised drift detection. B. Anomaly detection Several traditional machine learning techniques have been suggested for anomaly detection, notably the Local Outlier Factor (LOF) [12] and the Isolation Forest (iForest) algorithm [13]. LOF gauges the local density of data points to pinpoint outliers, while iForest prioritizes isolating anomalies over characterizing normal behavior. By forming an ensemble of trees, iForest discerns anomalies by their relatively shorter average path lengths within the trees. Collective anomalies are anomalous sequences where individual points may appear normal [14], requiring temporal pattern recognition. Methods like DiFF-RF [15] and [16] address them but may confuse anomalies with concept drift. The unsupervised VAE4AS [17] detects anomalous sequences in non-stationary i.i.d. data. Our work builds upon VAE4AS by adapting it for WDNs, handling non-stationary time series with an LSTM-VAE, and tackling topologydependent fault propagation. C. Anomaly detection in WDNs Few studies have addressed pipe blockage detection using data-driven methods. Yuhan et al. [2] propose a lightweight threshold-based approach triggered when real-time flow drops below levels estimated from historical flow and rainfall data. While simple, it requires both flow and rainfall measurements, limiting applicability in sparsely instrumented networks. In contrast, pipe burst detection has received more attention, as both bursts and blockages cause pressure changes. Relevant methods include PCA with Hotelling’s T2 [18], an ensemble CNN using statistical features [19], and a GCN-based framework leveraging WDN structure [20]. More broadly, leak detection methods in pipeline monitoring are typically classified into two categories: those relying on directly measurable quantities (e.g., inflows, outflows, pressures, temperatures) and those based on non-measurable internal states or model parameters, which require modeling and estimation techniques [3]. Comprehensive reviews of these approaches can be found in [3], [21]. Research gap. The previously mentioned methods rely on the assumption that only a single type of anomalous event occurs, while the rest of the network operates under stationary background conditions. However, they do not account for the coexistence of faults with potential background leakages, which is the focus of this work. Considering the pressure changes induced by these events, we propose an online, unsupervised method that detects pipe blockages as collective anomalies and simultaneously detects and adapts to background leakage-induced variations as concept drift, setting it apart from existing approaches. III. PROBLEM FORMULATION AND PROPOSED METHOD WDNs are modeled as graphs, where nodes represent junctions and undirected edges represent pipes. A graph G= (V, E)consists of node set Vand edge set E, with each edge ei,j = (vi, vj)∈E,i=j. Pressure sensors are commonly used due to their low cost and ease of deployment. As full sensor coverage is impractical, only N < |V|sensors are installed. At time t, the input signals from all sensors are represented as xt∈RN={xt 1, . . . , xt N}, where xt i corresponds to the measurements from sensor i. Fig. 1 shows a simplified example with four sensors placed on six nodes. This study detects pipe blockages and background leakage using pressure sensor data, formulating them as anomaly detection (AD) and drift detection (DD) tasks, respectively. Each sensor iis equipped with its own detectors (ADi, DDi), as illustrated by the orange boxes in Fig. 1, with no communication between sensors, enabling fully decentralized edge deployment for scalable and low-latency fault detection. At each time step t, each detector only accesses its local reading xt i. Node-level detection mechanisms for AD and DD are detailed in the following sections. The overview of the proposed method design is shown in Fig. 2, which corresponds to the orange box in Fig. 1. To simplify equation notation, we use xt, ytinstead of xt i, yt i to represent the input and its corresponding label for each arriving instance at time t. The prediction part is displayed in blue. The system first observes the instance xtat time t, and the LSTM-VAE-based model outputs a prediction ˆyt∈ {0,1}. If the instance is classified as normal (ˆyt= 0), its encoding is added to movNfor statistical testing. If the instance is classified as anomalous (ˆyt= 1), anomalous instances’ encodings are appended to sliding windows movAN for distance-based testing. In cases of drift presence, normal instances affected by drift may be classified as normal or anomalous by the current classifier, depending on the similarity between drifted data and normal data. Considering this, two drift detection (DD) methods, DD1 and DD2, are introduced, with details provided in a subsequent section. Upon the activation of an alarm flag by any DD, a new LSTM-VAE model is instantiated and trained accordingly. A. Detecting pipe blockages In this study, we view the problem of detecting pipe blockages as an anomaly detection problem. Model. Autoencoders are effective for anomaly detection by learning to reconstruct normal data with minimal error. However, standard VAEs assume independent and i.i.d. data, 272 Authorized licensed use limited to: University of Cyprus. Downloaded on December 04,2025 at 09:53:48 UTC from IEEE Xplore. Restrictions apply.
limiting their ability to model temporal dependencies in timeseries data. To address this, we integrate a VAE with LSTM networks, replacing the feed-forward layers with LSTM to capture sequential patterns. LSTM, introduced in [22], mitigates vanishing gradients in recurrent networks through gating mechanisms, enabling effective modeling of long-term dependencies. By incorporating LSTM into VAE, our model learns a structured latent space that preserves temporal correlations. A VAE models the latent distribution q(z|x)as a multivariate Gaussian, regularized via Kullback-Leibler (KL) divergence. The total loss function consists of reconstruction loss and KL divergence, formulated as: lV AE(x, ˆx) = lAE(x, ˆx) + β·lKL(x),(1) where lAE(x, ˆx)is the reconstruction loss between input x and output ˆx, and βis a weighting coefficient that balances the reconstruction and regularization terms. Unlike standard VAEs that reconstruct steps independently, LSTM-VAEs use past data to better detect temporal anomalies. We enhance adaptability by integrating drift detection to guide lV AE, boosting robustness in dynamic settings. The LSTM-VAE assumes anomalies yield higher loss than normal data. An adaptive threshold θt, set as the maximum training loss, is used for detection. When an alarm is triggered, θtis updated with new data. An instance xt+∆ is flagged as anomalous if its cumulative loss and that of preceding values exceed θt. This is applied iteratively over sliding windows to generate predictions. B. Detecting water leakages The problem of detecting water leakages is viewed as a concept drift detection problem. Specifically, we employ a dual drift detection (DD) mechanism consisting of both a statistical test (DD1) and a distance-based approach (DD2). DD1: Statistical test. The KS test, a non-parametric method, avoids distributional assumptions. Given refN and movNcontaining dlatent layer windows, where refN={reflatent1, ..., reflatentd}and movN= {movlatent1, ..., movlatentd}, we apply the KS test to each dimension i. This test measures the maximum disparity between their cumulative distributions, providing a statistical metric [23]. The p-value is determined as: pvalue = 2 ∞ X i=1 (−1)i−1e−2i2γ2 where, γ=pNeff + 0.12 + 0.11 √Neff KSdis KSdis = max |F(reflatenti)−F(movlatenti)|, Neff =W2 drift 2Wdrift (2) Two flags, flagwarn and flagalarm, are established to indicate concept drift. The warning flag signals potential drift, while the alarm flag confirms actual drift, rejecting the Fig. 1: Placement of the proposed method in a simplified WDN example. Fig. 2: Overview of the proposed method. null hypothesis (H0) in favor of the alternative hypothesis (H1). The thresholds satisfy Pwarn > Palarm. DD2: Distance-based. The Euclidean distance between refAN and movAN determines drift, as defined in Eq. (3) and Eq. (4). Here, refANij and movANij denote elements at the i-th row and j-th column of refAN and movAN , respectively. Each row represents a point in multi-dimensional space, while each column corresponds to a specific feature. The threshold DISthre is set offline. DIS(refAN , movAN ) = v u u t n X i=1 m X j=1 (refANij −movANij )2 (3) flag =alarm if DIS(refAN , movAN )> DISthre (4) The warning mechanism applies only to DD1. If flagwarn is raised but not flagalarm, instances are stored in movwarn. To reduce false alarms, if flagwarn persists beyond expiry_time without triggering flagalarm, it is reset, and movwarn is cleared. When an alarm is activated, an autoencoder is retrained using movwarn or 500 post-alarm instances, depending on the drift detector. The threshold is updated accordingly, and the windows movN,movwarn, and movAN are cleared, resetting all flags. The reference window refNis then repopulated with new normal instances. 273 Authorized licensed use limited to: University of Cyprus. Downloaded on December 04,2025 at 09:53:48 UTC from IEEE Xplore. Restrictions apply.
(a) ZJ network 31 25 16 10 13 6 29 23 22 3 7 Blocked Pipe Leakage Sensor (b) Hanoi network Fig. 3: Illustration of Hanoi and ZJ network. C. Computational analysis The method uses five memory buffers: refNand movN (each of size Wdrift) store normal instances for drift detection during prediction via the KS test; refAN and movAN (each of size Wdistance) store anomalies for the anomaly distance test; movwarn (size Wwarn) buffers post-drift data for model training, which is only triggered when flag alarm is raised. At each time step, the LSTM-VAE performs lightweight forward inference to compute Eq. 4. This buffer-based design ensures low memory and compute overhead, making the approach suitable for efficient edge deployment. IV. EXPERIMENTAL SETUP A. Water Distributions Networks Hanoi network and ZJ network. The Hanoi network [24] is a benchmark WDN with 32 nodes, 34 pipes, and one reservoir. The Zhi Jiang (ZJ) network [25] in eastern China, represents a real WDN with 164 pipes, 113 demand nodes, 50 primary loops, and a reservoir with a fixed 45 m head. Fig. 3 provides an overview, with black arrows indicating initial water flow directions. B. Datasets We generate two scenarios with the Hanoi and ZJ networks, each spanning one year with 30-minute sampling, yielding 17,520 data points. Gaussian noise N(0,0.01) is added to all sensors. The dataset for pipe blockages is generated using WNTR [26], an advanced open-source tool for WDN resilience analysis. Leakage simulation follows the LeakDB method [27], using historical demand data. Pipe blockages are simulated by intermittently closing and opening pipes. Pressure measurements at nodes serve as key anomaly indicators. Pipe blockages occur at timesteps 20003000 and 8000-9000, while background leakages occur from 5000-15000. In Hanoi, pipe 7 is blocked and node 14 leaks (hole diameter = 8.9cm); in ZJ, pipe 104 is blocked and node 77 leaks (hole diameter = 3.0cm). Pressure sensors are blue; black-labeled nodes are for analysis, red-labeled ones downstream of blockages for comparison. Blockages and leakages are shown in Fig. 3. Data pre-processing. We apply Seasonal and Trend decomposition using Loess (STL) [28] to split one-year historical data into trend, seasonality, and residual components. For each arriving point, the corresponding trend and residual from historical data are subtracted to preserve seasonality. The STL period is set to 336 (one week). We assume that the seasonal component remains stationary over the one-year period, without accounting for potential external influences. C. Compared methods We compare the proposed method with three other methods, iForest++, LOF++, and VAE4AS. The first two are classical anomaly detection methods and VAE4AS is a method dealing with anomalous sequences. iForest++ [13]: A state-of-the-art anomaly detection method as described in Section II-B. To adapt to drift, incremental learning is adopted after every 1000 instances. LOF++ [12]: Another popular method to compare. Details are provided in Section II-B. To adapt to drift, incremental learning is adopted after every 1000 instances. VAE4AS [17]: In this comparison, the parameter settings remain identical to those recommended in the original paper. Proposed method: As described in Section III. For reproducibility, the hyper-parameters of the proposed method are provided in Table I. For VAE4AS and the proposed method, parameters are set as: Wwarn = 1000,Wdrift = 200,Wdistance = 50, Palarm = 0.0001 and 0.001, and expiry_time = 100. Retraining epochs are 500. D. Performance metrics and evaluation method The geometric mean is a robust and widely accepted metric for imbalanced classification [29], defined as G-mean = √R+×R−, where R+=TP/P is the recall of the positive class, R−=TN/N is the recall (or specificity) of the negative class. G-mean is insensitive to class imbalance and favors high, balanced recall values. We adopt prequential evaluation with a fading factor of 0.99, which converges to Bayes error under stationarity and removes the need for a holdout set [30]. G-mean is computed per time step and averaged over 10 runs; error bars show standard error. 274 Authorized licensed use limited to: University of Cyprus. Downloaded on December 04,2025 at 09:53:48 UTC from IEEE Xplore. Restrictions apply.
TABLE I: Hyper-parameter values for the proposed method Learning rate Hidden layers Mini-batch size Dropout rate Timestep Weight initializer Optimizer Hidden activation Num. epochs Output activation Loss function Hanoi and ZJ 0.001 [8, 2] 64 0.1 10 He Normal Adam Leaky ReLU 100 Softmax Square Error TABLE II: Detection performance per node (True positives at downstream nodes of pipe blockages highlighted in red) N23 N29 N31 N16 N25 N13 N10 N6 N3 N22 Pipe 7 blocked True Positive 314 147 288 991 685 1000 1000 0 0 182 False Positive 349 82 82 174 337 82 0 0 0 198 Pipe 23 blocked True Positive 1000 1000 1000 990 1000 121 173 69 0 55 False Positive 349 82 82 174 337 82 0 0 0 198 (a) Reconstruction of LSTM-VAE (b) Reconstruction of VAE Fig. 4: Reconstruction of LSTM-VAE and VAE. (a) Node 10 (b) Node 13 Fig. 5: Performance of iForest++, LOF++, VAE4AS and the proposed method with the Hanoi network. (a) Node 29 (b) Node 30 Fig. 6: Performance of iForest++, LOF++, VAE4AS and the proposed method with the ZJ network. V. EXPERIMENTAL RESULTS A. Role of the model component We compare VAE and LSTM-VAE to highlight the latter’s strength in time-series modeling. Both models are trained on 5000 normal data points and validated on 2000 points from node 16 in Hanoi (outlined in Section IV-A). In Fig. 4a, the small reconstruction loss results in overlapping curves, making differences less visible. In contrast, Fig. 4b shows a larger loss. These results indicate that LSTM-VAE captures temporal dependencies more effectively than VAE, which lacks temporal modeling and yields poorer reconstructions. B. Role of the drift detector We evaluate the proposed method on the first 5000 instances in two Hanoi scenarios, where pipes 7 and 23 are blocked (timesteps 2000–3000) without leakage. Table II reports per-node results, with red-highlighted true positives corresponding to downstream nodes of the blockage, which show higher classification accuracy. Combining flow direction (Fig. 1) with detection results reveals more anomalies at downstream nodes. This pattern may guide blocked pipe localization. While such node-level differences suggest potential for fault isolation, we focus on overall detection performance, leaving localization to future work. C. Comparative study We compare iForest++, LOF++, VAE4AS, and the proposed method. Empirical analysis shows that downstream nodes of blocked pipes yield the best classification due to significant pressure differences. Thus, we select these nodes for the comparative study. Leakage (timesteps 5000-15000) represents recurrent drift, while blockages occur at 20003000 and 8000-9000. Collective anomalies are marked in red, with data generation details in Section IV-A. As shown in Fig.5 and Fig.6, the proposed method outperforms the baselines. The performance at different nodes is influenced by the extent to which their pressure is affected by the blockage. In the ZJ network, due to its more complex topology—such as a higher degree of pipe interconnectivity—and the greater distance between some nodes and the blockage location, the performance (Fig.6) is lower compared to that in the Hanoi network (Fig.5). Additionally, the presence of alternative flow paths caused by pipe splitting further weakens the blockage impact on downstream nodes in the ZJ network. Retraining points are indicated in the figures. G-mean drops at concept drift events (background leakage at 5000 and 15000) and recovers after retraining, highlighting the drift’s impact. Our method accurately detects drift without false alarms, maintaining G-mean above 0.7 on ZJ and over 275 Authorized licensed use limited to: University of Cyprus. Downloaded on December 04,2025 at 09:53:48 UTC from IEEE Xplore. Restrictions apply.
0.9 on Hanoi. In contrast, VAE4AS is unstable, iForest++ fluctuates around 0.7, and LOF++ performs well on Hanoi but degrades on ZJ. Overall, our method outperforms others, demonstrating robust anomaly detection and adaptation to concept drift in non-stationary environments. VI. DISCUSSION AND CONCLUSIONS We propose a label-free, data-driven method for pipe blockage detection under changing WDN conditions, where background leakages manifest as gradual pressure shifts (concept drift) and blockages cause abrupt changes (collective anomalies). Our method adopts a decentralized architecture suitable for edge deployment, with one LSTMVAE per sensor processing local 1D time series. This design supports real-time, scalable anomaly detection close to the data source, reducing latency and communication overhead. Although resource use may rise in large systems, sparse sensor placement in real-world WDNs limits the number of models and keeps computational cost low. Detection performance depends on sensor coverage—blockages near unsensored areas may be missed. However, leveraging network topology and flow direction can help reduce this risk. Experiments on realistic Hanoi and ZJ networks show our approach outperforms strong baselines, with LSTM-VAE capturing temporal patterns and enabling cross-node anomaly detection. While the method demonstrates potential for fault isolation, further work is needed to validate its effectiveness. Additionally, beyond background leakage, future work will address long-term factors like climate change, which may alter WDN behavior. REFERENCES [1] D. G. Eliades, K. Malialis, S. Vrachimis, and M. M. Polycarpou, “Smart water networks as cyber-physical-socio-environmental systems,” IEEE Transactions on Industrial Cyber-Physical Systems, 2024. [2] C. Yuhan, L. Mei, Q. Yiwu, W. Qingquan, L. Chu, L. Manchun et al., “Rapid blockage diagnosis and early warning of urban drainage pipe network,” in IOP Conference Series: Earth and Environmental Science, vol. 676, no. 1. IOP Publishing, 2021, p. 012106. [3] T. Al Qahtani, M. S. Yaakob, N. Yidris, S. Sulaiman, and K. A. Ahmad, “A review on water leakage detection method in the water distribution network,” Journal of Advanced Research in Fluid Mechanics and Thermal Sciences, vol. 68, no. 2, pp. 152–163, 2020. [4] V. Chandola, A. Banerjee, and V. Kumar, “Anomaly detection: A survey,” ACM Computing Surveys (CSUR), vol. 41, no. 3, pp. 1–58, 2009. [5] G. Ditzler, M. Roveri, C. Alippi, and R. Polikar, “Learning in nonstationary environments: A survey,” IEEE Computational Intelligence Magazine, vol. 10, no. 4, pp. 12–25, 2015. [6] V. Losing, B. Hammer, and H. Wersing, “Incremental on-line learning: A review and comparison of state of the art algorithms,” Neurocomputing, vol. 275, pp. 1261–1274, 2018. [7] G. Widmer and M. Kubat, “Learning in the presence of concept drift and hidden contexts,” Machine Learning, vol. 23, no. 1, pp. 69–101, 1996. [8] K. Malialis, C. G. Panayiotou, and M. M. Polycarpou, “Online learning with adaptive rebalancing in nonstationary environments,” IEEE Transactions on Neural Networks and Learning Systems, 2020. [9] L. L. Minku and X. Yao, “Ddd: A new ensemble approach for dealing with concept drift,” IEEE Transactions on Knowledge and Data Engineering, vol. 24, no. 4, pp. 619–633, 2011. [10] K. Malialis, M. Roveri, C. Alippi, C. G. Panayiotou, and M. M. Polycarpou, “A hybrid active-passive approach to imbalanced nonstationary data stream classification,” in 2022 IEEE Symposium Series on Computational Intelligence (SSCI). IEEE, 2022, pp. 1021–1027. [11] J. Li, K. Malialis, and M. M. Polycarpou, “Autoencoder-based anomaly detection in streaming data with incremental learning and concept drift adaptation,” in 2023 International Joint Conference on Neural Networks (IJCNN). IEEE, 2023, pp. 1–8. [12] M. M. Breunig, H. Kriegel, R. T. Ng, and J. Sander, “Lof: identifying density-based local outliers,” in Proceedings of the 2000 ACM SIGMOD International Conference on Management of Data, 2000, pp. 93–104. [13] F. T. Liu, K. M. Ting, and Z. Zhou, “Isolation forest,” in 2008 eighth IEEE International Conference on Data Mining. IEEE, 2008, pp. 413–422. [14] M. Ahmed and A.-S. K. Pathan, “Deep learning for collective anomaly detection,” International Journal of Computational Science and Engineering, vol. 21, no. 1, pp. 137–145, 2020. [15] P.-F. Marteau, “Random partitioning forest for point-wise and collective anomaly detection—application to network intrusion detection,” IEEE Transactions on Information Forensics and Security, vol. 16, pp. 2157–2172, 2021. [16] J. Rosenberger, K. Müller, A. Selig, M. Bühren, and D. Schramm, “Extended kernel density estimation for anomaly detection in streaming data,” Procedia CIRP, vol. 112, pp. 156–161, 2022. [17] J. Li, K. Malialis, C. G. Panayiotou, and M. M. Polycarpou, “Unsupervised incremental learning with dual concept drift detection for identifying anomalous sequences,” in 2024 International Joint Conference on Neural Networks (IJCNN). IEEE, 2024, pp. 1–8. [18] C. Palau, F. Arregui, and M. Carlos, “Burst detection in water networks using principal component analysis,” Journal of Water Resources Planning and Management, vol. 138, no. 1, pp. 47–54, 2012. [19] S. Kim, S. Jun, and D. Jung, “Ensemble cnn model for effective pipe burst detection in water distribution systems,” Water Resources Management, vol. 36, no. 13, pp. 5049–5061, 2022. [20] A. Zanfei, A. Menapace, B. M. Brentan, M. Righetti, and M. Herrera, “Novel approach for burst detection in water distribution systems based on graph neural networks,” Sustainable Cities and Society, vol. 86, p. 104090, 2022. [21] M. R. Islam, S. Azam, B. Shanmugam, and D. Mathur, “A review on current technologies and future direction of water leakage detection in water distribution network,” IEEE Access, vol. 10, pp. 107 177– 107 201, 2022. [22] S. Hochreiter and J. Schmidhuber, “Long short-term memory,” Neural computation, vol. 9, no. 8, pp. 1735–1780, 1997. [23] T. Nitta, Y. Shi, T. Hirakawa, T. Yamashita, and H. Fujiyoshi, “Detecting data drift with ks test using attention map,” in Asian Conference on Pattern Recognition. Springer, 2023, pp. 68–80. [24] O. Fujiwara and D. B. Khang, “A two-phase decomposition method for optimal design of looped water distribution networks,” Water Resources Research, vol. 26, no. 4, pp. 539–549, 1990. [25] F. Zheng, A. R. Simpson, and A. C. Zecchin, “A combined nlpdifferential evolution algorithm approach for the optimization of looped water distribution systems,” Water Resources Research, vol. 47, no. 8, 2011. [26] K. A. Klise, M. Bynum, D. Moriarty, and R. Murray, “A software framework for assessing the resilience of drinking water systems to disasters with an example earthquake case study,” Environmental Modelling & Software, vol. 95, pp. 420–431, 2017. [27] S. G. Vrachimis, M. S. Kyriakou et al., “Leakdb: a benchmark dataset for leakage diagnosis in water distribution networks:(146),” in WDSA/CCWI Joint Conference Proceedings, vol. 1, 2018. [28] R. B. Cleveland, W. S. Cleveland, J. E. McRae, and I. Terpenning, “Stl: A seasonal-trend decomposition,” J. Off. Stat, vol. 6, no. 1, pp. 3–73, 1990. [29] Y. Sun, M. S. Kamel, and Y. Wang, “Boosting for learning multiple classes with imbalanced class distribution,” in International Conference on Data Mining. IEEE, 2006, pp. 592–602. [30] J. Gama, R. Sebastião, and P. P. Rodrigues, “On evaluating stream learning algorithms,” Machine Learning, vol. 90, no. 3, pp. 317–346, 2013. 276 Authorized licensed use limited to: University of Cyprus. Downloaded on December 04,2025 at 09:53:48 UTC from IEEE Xplore. Restrictions apply.