LOGNET: A Knowledge Distillation-Based Model for Log Anomaly Detection

Kun Yu, Yuanyuan Huang, Linshan Zhang, Jun Lv, Jiazhong Lu · 2024

Due to the diverse nature of attack forms, supervised log anomaly detection models require a large volume of labeled data, making the annotation process time-consuming and labor-intensive. Conversely, unsupervised log anomaly detection models often struggle to effectively capture log features and accurately identify anomalous logs. To address these challenges, this study constructs a collaborative learning framework and proposes the LogNet model. This framework enables mutual learning between two distinct models, enhancing their performance synergistically. In the LogNet model, log data is first converted into directed graphs, leveraging the strengths of Graph Convolutional Networks (GCN) and Graph Attention Networks (GAT). Through collaborative learning, the two models guide each other, boosting their detection capabilities. The effectiveness of LogNet is validated on five public datasets, with experimental results demonstrating that LogNet significantly outperforms traditional models in malicious log detection, achieving up to a 4 % improvement in accuracy.

Read the paper · More papers on PaperTik