System Log Anomaly Detection With Noise-Contrastive Learning and Pattern Feature
Pengcheng Luo, Dengke Deng, Mingfeng Xie, Genke Yang, Jian Chu, Boon‐Hee Soong, Chau Yuen · IEEE Transactions on Network Science and Engineering · 2025
System logs play a critical role in identifying security threats such as network attacks, unauthorized access, and system vulnerabilities. Recent research has focused on extracting sequences of security-related events from large-scale log data and applying deep learning methods for anomaly detection. These methods achieve anomaly detection by designing an auxiliary training task that predicts the next event. However, the inconsistency between the task of event prediction and the goal of anomaly detection limits their performance. In this paper, we introduce a noise-contrastive learning approach that introduces synthetic noise as a training signal, enabling the model to directly discriminate between normal and anomalous samples. Our approach also includes an ensemble model, STrees, and a novel feature engineering method named pattern feature. By modeling the relationships among events under normal conditions, these methods allow the model to capture contextual dependencies in log event sequences, thereby improving its ability to detect potential anomalies. Specifically, this approach achieves a recall for the anomaly class that is at least 7.3% higher compared to models that utilize only sequence features. Experimental results demonstrate that our model improves anomaly-class recall by at least 10.8% over advanced log anomaly detection methods while achieving more accurate detection on most datasets. These results highlight the effectiveness of our approach in learning discriminative decision boundaries between normal and anomalous event sequence patterns