We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.SE

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Software Engineering

Title: LogLG: Weakly Supervised Log Anomaly Detection via Log-Event Graph Construction

Abstract: Fully supervised log anomaly detection methods suffer the heavy burden of annotating massive unlabeled log data. Recently, many semi-supervised methods have been proposed to reduce annotation costs with the help of parsed templates. However, these methods consider each keyword independently, which disregards the correlation between keywords and the contextual relationships among log sequences. In this paper, we propose a novel weakly supervised log anomaly detection framework, named LogLG, to explore the semantic connections among keywords from sequences. Specifically, we design an end-to-end iterative process, where the keywords of unlabeled logs are first extracted to construct a log-event graph. Then, we build a subgraph annotator to generate pseudo labels for unlabeled log sequences. To ameliorate the annotation quality, we adopt a self-supervised task to pre-train a subgraph annotator. After that, a detection model is trained with the generated pseudo labels. Conditioned on the classification results, we re-extract the keywords from the log sequences and update the log-event graph for the next iteration. Experiments on five benchmarks validate the effectiveness of LogLG for detecting anomalies on unlabeled log data and demonstrate that LogLG, as the state-of-the-art weakly supervised method, achieves significant performance improvements compared to existing methods.
Comments: 12 pages
Subjects: Software Engineering (cs.SE); Artificial Intelligence (cs.AI); Machine Learning (cs.LG)
Cite as: arXiv:2208.10833 [cs.SE]
  (or arXiv:2208.10833v5 [cs.SE] for this version)

Submission history

From: Hongcheng Guo [view email]
[v1] Tue, 23 Aug 2022 09:32:19 GMT (5040kb,D)
[v2] Thu, 25 Aug 2022 06:42:18 GMT (186kb,D)
[v3] Tue, 6 Sep 2022 02:36:58 GMT (0kb,I)
[v4] Thu, 2 Feb 2023 09:17:52 GMT (1494kb,D)
[v5] Tue, 11 Apr 2023 07:46:32 GMT (744kb,D)

Link back to: arXiv, form interface, contact.