arXiv:2604.21889cs.CLcs.AI2026-04ACL被引 1

用大模型+多阶段链接,从海量用户报错中实时发现高危故障。

TingIS: Real-time Risk Event Discovery from Noisy Customer Incidents at Enterprise Scale

论文配图:TingIS: Real-time Risk Event Discovery from Noisy Customer Incidents at Enterprise Scale
图 1 · 摘自论文原文
  • 融合大模型与索引技术,智能合并相似用户报错事件。
  • 日均处理30万条消息,95%高优先级故障可被发现,延迟仅3.5分钟。
  • 适合需要实时故障洞察的大型云服务运维团队。

实时检测与缓解技术异常对大规模云原生服务至关重要,即使几分钟停机也可能导致巨额损失和用户信任下降。尽管用户报错是发现监控未覆盖风险的关键信号,但其数据噪声大、吞吐高且业务语义复杂,提取有效信息极具挑战。本文提出TingIS,一个面向企业级场景的端到端事件发现系统。核心是一个多阶段事件链接引擎,结合高效索引与大语言模型(LLMs),实现事件合并的智能决策,仅凭少量用户描述即可稳定提取可行动作的故障事件。系统还配备级联路由机制实现精准业务归属,以及融合领域知识、统计模式与行为过滤的多维降噪管道。在生产环境部署中,峰值吞吐超2,000条/分钟,日均处理30万条消息,达到P90告警延迟3.5分钟,高优先级事件发现率达95%。基于真实数据构建的基准测试显示,TingIS在路由准确率、聚类质量与信噪比方面显著优于基线方法。

原文摘要 · Abstract (English)

Real-time detection and mitigation of technical anomalies are critical for large-scale cloud-native services, where even minutes of downtime can result in massive financial losses and diminished user trust. While customer incidents serve as a vital signal for discovering risks missed by monitoring, extracting actionable intelligence from this data remains challenging due to extreme noise, high throughput, and semantic complexity of diverse business lines. In this paper, we present TingIS, an end-to-end system designed for enterprise-grade incident discovery. At the core of TingIS is a multi-stage event linking engine that synergizes efficient indexing techniques with Large Language Models (LLMs) to make informed decisions on event merging, enabling the stable extraction of actionable incidents from just a handful of diverse user descriptions. This engine is complemented by a cascaded routing mechanism for precise business attribution and a multi-dimensional noise reduction pipeline that integrates domain knowledge, statistical patterns, and behavioral filtering. Deployed in a production environment handling a peak throughput of over 2,000 messages per minute and 300,000 messages per day, TingIS achieves a P90 alert latency of 3.5 minutes and a 95\% discovery rate for high-priority incidents. Benchmarks constructed from real-world data demonstrate that TingIS significantly outperforms baseline methods in routing accuracy, clustering quality, and Signal-to-Noise Ratio.

事件发现大模型运维智能实时分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。