Temporal Logical Attention Network for Log-Based Anomaly Detection in Distributed Systems
Сеть временного логического внимания для обнаружения аномалий на основе журналов в распределённых системах
2024-12-12
SCID: 54.1/qjtvh8wy
Discuss with AI
Temporal Logical Attention Networkadaptive threshold strategydistributed system logslog-based anomaly detectionmulti-scale feature extraction
Figures from the paper
Abstract (AI)
Detecting anomalies in distributed systems through log analysis remains challenging due to the complex temporal dependencies between log events, the diverse manifestation of system states, and the intricate causal relationships across distributed components. This paper introduces a TLAN (Temporal Logical Attention Network), a novel deep learning framework that integrates temporal sequence modeling with logical dependency analysis for robust anomaly detection in distributed system logs. Our approach makes three key contributions: (1) a temporal logical attention mechanism that explicitly models both time-series patterns and logical dependencies between log events across distributed components, (2) a multi-scale feature extraction module that captures system behaviors at different temporal granularities while preserving causal relationships, and (3) an adaptive threshold strategy that dynamically adjusts detection sensitivity based on system load and component interactions. Extensive experiments on a large-scale synthetic distributed system log dataset show that TLAN outperforms existing methods by achieving a 9.4% improvement in F1-score and reducing false alarms by 15.3% while maintaining low latency in real-time detection. The framework demonstrates particular effectiveness in identifying complex anomalies that involve multiple interacting components and cascading failures. Through comprehensive empirical analysis and case studies, we validate that TLAN can effectively capture both temporal patterns and logical correlations in log sequences, making it especially suitable for modern distributed architectures. Our approach also shows strong generalization capability across different system scales and deployment scenarios, supported by thorough ablation studies and performance evaluations.
Key Findings
1
A multi-scale feature extraction module captures system behaviors at different temporal granularities while preserving causal relationships.
2
An adaptive threshold strategy adjusts detection sensitivity according to system load and component interactions.
3
Its temporal logical attention mechanism models time-series patterns and cross-component logical dependencies between log events.
4
On a large-scale synthetic dataset, TLAN improved F1-score by 9.4% and reduced false alarms by 15.3% while maintaining low real-time detection latency.
5
TLAN integrates temporal sequence modeling with logical dependency analysis to detect anomalies in distributed-system logs.
Research Object
Distributed system logs and the underlying distributed-system behavior across interacting components
Research Subject
Temporal patterns, logical and causal dependencies, multi-scale behaviors, and cascading-failure anomalies for real-time log-based detection
Publication Details
Publication Date
2024-12-12
Journal
Publisher
ISSN
Cited by
38
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest