arXiv:2507.19806cs.SEcs.AI2025-07被引 9

无需目标系统标注日志,实现跨系统异常检测

From Few-Label to Zero-Label: An Approach for Cross-System Log-Based Anomaly Detection with Meta-Learning

  • 基于元学习构建系统无关表示,不依赖目标端标签
  • 在三个数据集上表现接近有少量标签时的顶尖方法
  • 适合无标签日志的冷启动场景,如新系统监控

日志异常检测对保障软件系统稳定可靠至关重要。现有方法依赖大量标注日志,在实际应用中面临挑战。跨系统迁移成为关键方向,当前先进方法仅需目标系统少量标注日志即可取得良好效果。但当标注日志不足时,仍受冷启动问题影响。为此,本文探索一种新颖且少被研究的设定:零标签跨系统日志异常检测,即目标系统日志完全无标注。为此提出FreeLog,一种系统无关的表示元学习方法,彻底消除对目标系统标注日志的需求,实现零标签条件下的跨系统异常检测。在三个公开日志数据集上的实验表明,FreeLog性能可媲美依赖少量目标系统标注数据的先进方法。

原文摘要 · Abstract (English)

Log anomaly detection plays a critical role in ensuring the stability and reliability of software systems. However, existing approaches rely on large amounts of labeled log data, which poses significant challenges in real-world applications. To address this issue, cross-system transfer has been identified as a key research direction. State-of-the-art cross-system approaches achieve promising performance with only a few labels from the target system. However, their reliance on labeled target logs makes them susceptible to the cold-start problem when labeled logs are insufficient. To overcome this limitation, we explore a novel yet underexplored setting: zero-label cross-system log anomaly detection, where the target system logs are entirely unlabeled. To this end, we propose FreeLog, a system-agnostic representation meta-learning method that eliminates the need for labeled target system logs, enabling cross-system log anomaly detection under zero-label conditions. Experimental results on three public log datasets demonstrate that FreeLog achieves performance comparable to state-of-the-art methods that rely on a small amount of labeled data from the target system.

日志异常检测元学习零样本

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。