Loader: A Log Anomaly Detector Based on Transformer

子串 计算机科学 异常检测 数据挖掘 算法 模式识别(心理学) 集合(抽象数据类型) 人工智能 程序设计语言
作者
Tong Xiao,Zhe Quan,Zhi-Jie Wang,Yuquan Le,Yunfei Du,Xiangke Liao,Kenli Li,Keqin Li
出处
期刊:IEEE Transactions on Services Computing [Institute of Electrical and Electronics Engineers]
卷期号:16 (5): 3479-3492 被引量:7
标识
DOI:10.1109/tsc.2023.3280575
摘要

Detecting anomalies in logs is crucial for service and system management, since logs are widely used to record the runtime status, and are often the only data available for postmortem analysis. Since anomalies are usually rare in real-world services and systems, a common and feasible practice is to mine or learn normal patterns from logs, and deem those violating the normal patterns as anomalies. As log sequences are a kind of time series data, RNN (Recurrent Neural Network) and its variants have been extensively employed to capture the normal patterns. Nevertheless, the sequential nature of RNN and its variants makes them hard to parallelize and capture long-term dependencies, which may hinder their performance. To address this issue, in this paper we propose Loader, a novel semi-supervised lo g a nomaly d etector based on Transform er , because the Transformer architecture eschews recurrence and is able to draw global dependencies. Loader leverages the Transformer encoder to capture normal patterns from normal log sequences. When detecting, it gives a set of candidate log templates, that may appear after the input log substring under normal conditions. If the template of the actual next log message is not within the candidate set, this implies an anomaly. Previous similar methods select the most possible $k$ log templates as candidates in any case, so the performance is sensitive to $k$ , and it is nontrivial to pick a proper $k$ . To alleviate this, we design a more flexible and robust 'top- $p$ ' algorithm, which determines the candidate set based on the cumulative probability of the most possible log templates. Extensive experiments are conducted based on three public log datasets, the experimental results validate the effectiveness and competitiveness of our approach.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
正直行恶发布了新的文献求助10
1秒前
gmjinfeng完成签到,获得积分0
4秒前
大摸特摸完成签到,获得积分10
4秒前
於伟祺发布了新的文献求助10
6秒前
6秒前
11完成签到,获得积分10
7秒前
mahehivebv111完成签到,获得积分10
8秒前
唠叨的觅海完成签到,获得积分10
8秒前
领导范儿应助徐玉辉采纳,获得10
10秒前
dd完成签到,获得积分10
10秒前
我是老大应助hyl采纳,获得10
11秒前
欢呼洋葱完成签到,获得积分10
11秒前
顺心如风发布了新的文献求助10
11秒前
刘羽萱完成签到,获得积分10
13秒前
14秒前
SciGPT应助刘小孩采纳,获得20
15秒前
17秒前
18秒前
19秒前
19秒前
少吃一口发布了新的文献求助10
20秒前
22秒前
榆树皮面发布了新的文献求助10
22秒前
知性的夏槐完成签到 ,获得积分10
23秒前
刘志萍完成签到 ,获得积分10
23秒前
23秒前
徐玉辉发布了新的文献求助10
24秒前
LXYang完成签到,获得积分10
25秒前
刘小孩完成签到,获得积分10
25秒前
MozzieMiao完成签到 ,获得积分10
26秒前
占易形发布了新的文献求助10
29秒前
lyon完成签到,获得积分10
29秒前
我是老大应助Chow采纳,获得10
30秒前
核桃发布了新的文献求助10
30秒前
31秒前
31秒前
共享精神应助於伟祺采纳,获得10
32秒前
tana98906完成签到 ,获得积分10
34秒前
楼满风发布了新的文献求助10
36秒前
biovhys完成签到,获得积分10
39秒前
高分求助中
The Graphene Handbook (2019 Edition) 800
Signals, Systems, and Signal Processing 610
IEST-RP-CC018: Cleanroom Cleaning and Sanitization: Operating and Monitoring Procedures 600
Fundamentals of Pharmaceutical and Biologics Regulations: A Global Perspective, Second Edition 600
久松真一著作集〈第5巻〉禅と芸術 500
Fundamentals of Modern Mathematics: A Practical Review (Dover Books on Mathematics) 500
Cold War Transcended: Australia's China Policy, 1949-1990 470
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6598686
求助须知:如何正确求助?哪些是违规求助? 8368168
关于积分的说明 17911509
捐赠科研通 5752740
什么是DOI,文献DOI怎么找? 2953813
邀请新用户注册赠送积分活动 1929056
关于科研通互助平台的介绍 1823875