Skip to main content
Have a personal or library account? Click to login
Hierarchical Anomaly Detection and SHAP-Based Root-Cause Attribution for Robotic Process Automation Workflows Cover

Hierarchical Anomaly Detection and SHAP-Based Root-Cause Attribution for Robotic Process Automation Workflows

Open Access
|Jul 2026

Abstract

Nowadays detecting anomalies is very important for automated business processes to proactively mitigate process failures. Useful data for identifying possible causes for irregularities and anomalous behavior is generated by the Robotic Process Automation (RPA) workflows logs. Most of the implementations in this area, however, summarize and analyze generated data at run level which doesn’t allow the differentiation of the problems caused by issues with external environment from those associated with the internal process logic. To support a more detailed analysis of the root cause, the paper proposes a hierarchical framework with two tiers for monitoring RPA workflows. Each tier is focused on detecting anomalies at different levels (run-level and process-level) and then the outcome from both tiers is integrated in a mapping layer to more clearly identify the root cause for the anomaly. The proposed framework is validated with a synthetic dataset comprising 10,000 runs generated in a controlled environment to simulate real world scenarios. At Tier 1, the framework implements Isolation Forest and feed-forward Autoencoder to detect anomalies at run-level. Process-level anomalies associated with unusual durations and sequence patterns are detected at tier 2 using Z-score statistics and a Long Short-Term Memory Autoencoder. The mapping layer combines results obtained from both tiers into four diagnostic states - Normal, Environment Stress, Latent Logic Issue and Systemic Failure. To support interpretation of the results, an explanation layer is added using SHAPley additive explanations. The analysis of main drivers for anomalies is used to calculate External Influence Index, which separates the contribution of external factors from those related to internal process-related patterns.

For injected anomalies, the best models achieved ROC-AUC values close to 0.96. At the process level, Z-score and LSTM-based scores showed moderate but statistically significant agreement, with Pearson’s r = 0.55 and p < 0.001. These results suggest that the two process-level methods capture related but not identical patterns. To further evaluate the framework feasibility, a pilot test on 325 runs of a university process is implemented. The results confirmed that the two-tier approach can reveal consistent anomaly patterns without ground-truth label, while the External Influence Index can determine source of detected anomalies. Results from both experiments suggest that the framework provides a more informative view than a single-level monitoring.

Language: English
Page range: 538 - 552
Published on: Jul 16, 2026
In partnership with: Paradigm Publishing Services
Publication frequency: 1 issue per year

© 2026 Yanka ALEKSANDROVA, Mihail RADEV, Mila GEORGIEVA, Desislava KOLEVA, published by Bucharest University of Economic Studies
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.