Detail výsledku

An Empirical Study of a PCA-Based Multivariate Framework for Interpretable Log Anomaly Detection

SETINSKÝ, J.; ŽÁDNÍK, M. An Empirical Study of a PCA-Based Multivariate Framework for Interpretable Log Anomaly Detection. In 2025 21st International Conference on Network and Service Management (CNSM). New York: IEEE, 2025. p. 1-6. ISBN: 978-3-903176-75-1.
Typ
článek ve sborníku konference
Jazyk
angličtina
Autoři
Abstrakt

Effective anomaly detection is crucial for increasingly complex system logs, yet current methods often face challenges with labeled data reliance, high computational costs, or limited interpretability. This paper empirically applies an established Multivariate Statistical Network Monitoring (MSNM) framework, which leverages Principal Component Analysis (PCA) with D and Q statistics, to the log anomaly detection domain. We evaluate its performance on three benchmark datasets (HDFS, BGL, Thunderbird), focusing on its semi-supervised nature (requiring only normal operational data), computational efficiency, interpretability via count vector feature contributions, and ease of deployment. Our results demonstrate competitive F1 scores comparable to some supervised and deep learning methods, maintaining low computational overhead without GPU dependency. Furthermore, its strong interpretability is showcased through case studies, identifying specific log event patterns causing anomalies. This study highlights the MSNM framework's potential as a practical, efficient, and interpretable solution for log anomaly detection.

Rok
2025
Strany
6
Sborník
2025 21st International Conference on Network and Service Management (CNSM)
Konference
21st International Conference on Network and Service Management
ISBN
978-3-903176-75-1
Vydavatel
IEEE
Místo
New York
DOI
BibTeX
@inproceedings{BUT198980,
  author="Jiří {Setinský} and Martin {Žádník}",
  title="An Empirical Study of a PCA-Based Multivariate
Framework for Interpretable Log Anomaly
Detection",
  booktitle="2025 21st International Conference on Network and Service Management (CNSM)",
  year="2025",
  pages="6",
  publisher="IEEE",
  address="New York",
  doi="10.23919/CNSM67658.2025.11297507",
  isbn="978-3-903176-75-1"
}
Projekty
Application-specific HW/SW architectures and their applications, VUT, Vnitřní projekty VUT, FIT-S-23-8141, zahájení: 2023-03-01, ukončení: 2026-02-28, řešení
Pracoviště
Nahoru