Temporal Logical Attention Network for Log-Based Anomaly Detection in Distributed Systems

Сеть временного логического внимания для обнаружения аномалий на основе журналов в распределённых системах
Yang Liu, Shaochen Ren, Xuran Wang, Mengjie Zhou
2024-12-12

Temporal Logical Attention Networkadaptive threshold strategydistributed system logslog-based anomaly detectionmulti-scale feature extraction
Detecting anomalies in distributed systems through log analysis remains challenging due to the complex temporal dependencies between log events, the diverse manifestation of system states, and the intricate causal relationships across distributed components. This paper introduces a TLAN (Temporal Logical Attention Network), a novel deep learning framework that integrates temporal sequence modeling with logical dependency analysis for robust anomaly detection in distributed system logs. Our approach makes three key contributions: (1) a temporal logical attention mechanism that explicitly models both time-series patterns and logical dependencies between log events across distributed components, (2) a multi-scale feature extraction module that captures system behaviors at different temporal granularities while preserving causal relationships, and (3) an adaptive threshold strategy that dynamically adjusts detection sensitivity based on system load and component interactions. Extensive experiments on a large-scale synthetic distributed system log dataset show that TLAN outperforms existing methods by achieving a 9.4% improvement in F1-score and reducing false alarms by 15.3% while maintaining low latency in real-time detection. The framework demonstrates particular effectiveness in identifying complex anomalies that involve multiple interacting components and cascading failures. Through comprehensive empirical analysis and case studies, we validate that TLAN can effectively capture both temporal patterns and logical correlations in log sequences, making it especially suitable for modern distributed architectures. Our approach also shows strong generalization capability across different system scales and deployment scenarios, supported by thorough ablation studies and performance evaluations.
1
A multi-scale feature extraction module captures system behaviors at different temporal granularities while preserving causal relationships.
2
An adaptive threshold strategy adjusts detection sensitivity according to system load and component interactions.
3
Its temporal logical attention mechanism models time-series patterns and cross-component logical dependencies between log events.
4
On a large-scale synthetic dataset, TLAN improved F1-score by 9.4% and reduced false alarms by 15.3% while maintaining low real-time detection latency.
5
TLAN integrates temporal sequence modeling with logical dependency analysis to detect anomalies in distributed-system logs.

Distributed system logs and the underlying distributed-system behavior across interacting components

Temporal patterns, logical and causal dependencies, multi-scale behaviors, and cascading-failure anomalies for real-time log-based detection

Publication Details
Publication Date
2024-12-12
Journal
Publisher
ISSN
Cited by
38
Access Type
Author Information
Authors
Yang Liu
Shaochen Ren
Xuran Wang
Mengjie Zhou
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%