IEEE Trans Vis Comput Graph. 2018 Jan;24(1):215-225. doi: 10.1109/TVCG.2017.2744898. Epub 2017 Aug 29.
Finding patterns in graphs has become a vital challenge in many domains from biological systems, network security, to finance (e.g., finding money laundering rings of bankers and business owners). While there is significant interest in graph databases and querying techniques, less research has focused on helping analysts make sense of underlying patterns within a group of subgraph results. Visualizing graph query results is challenging, requiring effective summarization of a large number of subgraphs, each having potentially shared node-values, rich node features, and flexible structure across queries. We present VIGOR, a novel interactive visual analytics system, for exploring and making sense of query results. VIGOR uses multiple coordinated views, leveraging different data representations and organizations to streamline analysts sensemaking process. VIGOR contributes: (1) an exemplar-based interaction technique, where an analyst starts with a specific result and relaxes constraints to find other similar results or starts with only the structure (i.e., without node value constraints), and adds constraints to narrow in on specific results; and (2) a novel feature-aware subgraph result summarization. Through a collaboration with Symantec, we demonstrate how VIGOR helps tackle real-world problems through the discovery of security blindspots in a cybersecurity dataset with over 11,000 incidents. We also evaluate VIGOR with a within-subjects study, demonstrating VIGOR's ease of use over a leading graph database management system, and its ability to help analysts understand their results at higher speed and make fewer errors.
在生物系统、网络安全到金融等许多领域,发现图形中的模式已经成为一个至关重要的挑战(例如,发现银行家和企业主的洗钱团伙)。虽然人们对图形数据库和查询技术非常感兴趣,但很少有研究关注帮助分析师理解一组子图结果中的潜在模式。可视化图形查询结果具有挑战性,需要有效地总结大量子图,每个子图都可能具有共享的节点值、丰富的节点特征和跨查询的灵活结构。我们提出了 VIGOR,这是一种新颖的交互式可视化分析系统,用于探索和理解查询结果。VIGOR 使用多个协调视图,利用不同的数据表示和组织来简化分析师的理解过程。VIGOR 做出了以下贡献:(1)基于范例的交互技术,分析师可以从特定的结果开始,然后放宽约束以找到其他类似的结果,或者仅从结构(即没有节点值约束)开始,并添加约束以缩小特定结果的范围;(2)新颖的特征感知子图结果汇总。通过与赛门铁克的合作,我们展示了 VIGOR 如何通过在一个拥有超过 11000 个事件的网络安全数据集中发现安全盲点来帮助解决现实世界中的问题。我们还通过一项被试内研究来评估 VIGOR,展示了 VIGOR 在使用领先的图形数据库管理系统方面的易用性,以及它帮助分析师更快地理解结果并减少错误的能力。