Context‐Aware Learning for Robust Anomaly Detection *
Yulei Wu, Jingguo Ge, Tong Li · 2022
Abstract Logs are used to record running states and significant events for a software system, and they have been widely used for anomaly detection. According to our research, most existing methods of anomaly detection ignore the following three important problems, and therefore, they perform poorly on real-world systems. First, with the upgrade of a system, logs will also evolve. Training on the log data of the old system (the one before being upgraded) cannot deal with newly presented logs. Second, logs also show clear characteristics of imbalanced data because the number of samples in different classes varies sharply. Training on imbalanced data makes an anomaly classifier biased toward the majority class, so it is difficult for a classifier to learn to detect anomalies correctly. Third, obtaining labels of log data requires tremendous manpower, especially when only experts can label correctly. In this chapter, we propose a robust context-aware method named AllRobust for log anomaly detection. AllRobust transforms a log event into a vector, which contains not only the semantic information of each word but also the semantics of the region where each word is located. Such rich semantic information enables our method to deal with previous unseen log data and understand imbalanced log data better and deeper. AllRobust combines semisupervised learning to solve the problem of high cost on labels acquisition, and it can not only learn from labeled log data but also from unlabeled log data. We conduct extensive experiments on multiclass and binary imbalanced log datasets. Under supervised learning, the accuracy achieves by AllContext on the multicategory imbalanced log data set is more than twofold of that by a baseline state-of-the-art. After being trained on imbalanced log data, AllRobust achieves an accuracy of 97% on the newly presented logs. Under semisupervised learning, 24 % labels are used for training. As the imbalance ratio of training data vary from 2:1 to 5:1, the recall achieved by AllRobust is 97%, which only decreased by 9%.