A Log Anomaly Detection Method Based on the Pre-Training and Fine-Tuning Framework
Guangming Li, Jiaqing Mo, Gang Zhou, Cheng Li · 2025
The anomaly detection method based on system logs can serve as an effective approach to maintain computer systems. Currently, a large number of excellent log anomaly detection methods have emerged. However, these methods usually rely on the template features in each log or combine template features with sequence information for anomaly detection, overlooking the important role of parameter features. Additionally, it is widely recognized that training a model from scratch in a new domain within a real industrial environment is both time-consuming and labor-intensive. In this paper, we introduce a novel log anomaly detection method, named LogPara, which leverages a self-attention enhanced Gated Recurrent Unit (GRU). Our approach begins by transforming each log into a corresponding semantic vector that encapsulates both parameter and template features. We propose a two-stage training objective: first, we train the model on a source domain to enable it to learn the shared features; subsequently, we fine-tune the model on the target domain to optimize its performance and reduce deployment costs. We evaluated the effectiveness of the proposed method using three real-world datasets, and the results demonstrate its superior performance in log anomaly detection.