Log anomaly detection plays a crucial role in maintaining the security and reliability of Internet of Things devices. Unsupervised deep learning methods have made significant progress in anomaly detection by modeling normal log sequences. However, the approach of only considering the normal patterns of sequences leads to limited generalization ability of the model. To address this problem, we propose GRLog to enhance the performance and generalization ability of anomaly detection models based on log sequences. First, we introduce auxiliary datasets to enhance the model’s ability to represent log sequences when learning the local and global information of log sequences based on Transformer. Second, we propose a similar log detection method to handle previously unseen logs. GRLog achieves higher F1 scores on three public datasets and their evolution datasets, which shows that our proposed model can better detect anomalies in log sequences and effectively address log evolution.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Generalizable and Robust Log Anomaly Detection Based on Transformer

  • Zhaoyang Lou,
  • Xiaolin Chai,
  • Ce Shang,
  • Yan Sun

摘要

Log anomaly detection plays a crucial role in maintaining the security and reliability of Internet of Things devices. Unsupervised deep learning methods have made significant progress in anomaly detection by modeling normal log sequences. However, the approach of only considering the normal patterns of sequences leads to limited generalization ability of the model. To address this problem, we propose GRLog to enhance the performance and generalization ability of anomaly detection models based on log sequences. First, we introduce auxiliary datasets to enhance the model’s ability to represent log sequences when learning the local and global information of log sequences based on Transformer. Second, we propose a similar log detection method to handle previously unseen logs. GRLog achieves higher F1 scores on three public datasets and their evolution datasets, which shows that our proposed model can better detect anomalies in log sequences and effectively address log evolution.