构建首个云环境上下文异常检测大规模基准,融合日志与指标数据。
Towards Generalizable Context-aware Anomaly Detection: A Large-scale Benchmark in Cloud Environments
- 设计跨模态一致的合成异常场景,覆盖28种真实故障模式。
- 引入1,252个标注案例,支持多模态上下文异常检测与定位。
- 提出基于符号验证的LLM代理,可泛化到其他数据集,适合运维系统开发者。
云环境中的异常检测至关重要但极具挑战。现有上下文级基准通常仅关注指标或日志,且标注不可靠;多数方法聚焦单一模态的点异常,忽略上下文信号,实用性受限。构建结合指标与日志的上下文异常基准难度高:真实服务器复现异常常不可行或有风险,而合成数据难以保证跨模态一致性。本文提出CloudAnoBench,一个大规模云环境上下文异常基准,包含28种异常场景和16种欺骗性正常场景,共1,252个标注案例,约20万条日志与指标记录。相比已有基准,其具有更高模糊性和难度,导致现有机器学习方法及基础LLM提示表现不佳。为验证其价值,我们进一步提出CloudAnoAgent——一种结合符号验证的LLM代理,能有效融合多模态信息。该系统在CloudAnoBench上显著提升异常检测与场景识别性能,并展现出对已有数据集的良好泛化能力。CloudAnoBench与CloudAnoAgent共同为云系统中上下文感知异常检测奠定基础。
原文摘要 · Abstract (English)
Anomaly detection in cloud environments remains both critical and challenging. Existing context-level benchmarks typically focus on either metrics or logs and often lack reliable annotation, while most detection methods emphasize point anomalies within a single modality, overlooking contextual signals and limiting real-world applicability. Constructing a benchmark for context anomalies that combines metrics and logs is inherently difficult: reproducing anomalous scenarios on real servers is often infeasible or potentially harmful, while generating synthetic data introduces the additional challenge of maintaining cross-modal consistency. We introduce CloudAnoBench, a large-scale benchmark for context anomalies in cloud environments, comprising 28 anomalous scenarios and 16 deceptive normal scenarios, with 1,252 labeled cases and roughly 200,000 log and metric entries. Compared with prior benchmarks, CloudAnoBench exhibits higher ambiguity and greater difficulty, on which both prior machine learning methods and vanilla LLM prompting perform poorly. To demonstrate its utility, we further propose CloudAnoAgent, an LLM-based agent enhanced by symbolic verification that integrates metrics and logs. This agent system achieves substantial improvements in both anomaly detection and scenario identification on CloudAnoBench, and shows strong generalization to existing datasets. Together, CloudAnoBench and CloudAnoAgent lay the groundwork for advancing context-aware anomaly detection in cloud systems. Project Page: https://jayzou3773.github.io/cloudanobench-agent/
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。