LogNLI: Reframing Log Anomaly Detection as Natural Language Inference with Adversarial Augmentation
编号:52
访问权限:仅限参会人
更新:2026-10-04 23:27:19 浏览:17次
In-person
摘要
Log anomaly detection is dominated by binary classifiers that are structurally unable to express uncertainty about novel patterns, i.e. events that are suspicious but match no known anomaly template. We propose LogNLI, which reframes the task as three-class Natural Language Inference (NLI): a rolling baseline window serves as the premise and the target window as the hypothesis; ENTAILMENT, NEUTRAL, and CONTRADICTION map to normal, novel-anomaly, and anomalous outcomes. The NLI three-way softmax can be interpreted as a Dempster–Shafer mass function [1], with NEUTRAL as the ignorance mass m(Θ), yielding calibrated belief intervals at no extra cost. Zero-shot DeBERTa-v3-large achieves 93.2% novel coverage on held-out novel-template (L3) windows in HDFS vs. 0% for any binary system, at the cost of a 63.5% false-novel rate on easy anomalies. Fine-tuning achieves a leak-free F1(CON) = 0.633 ± 0.001 (3 seeds), below the DeepLog [2] baseline; a routing ensemble of the two reaches F1 = 0.871 vs. 0.579 for DeepLog alone on the same 6,683 blocks. A generative Qwen3.5-4B LoRA [3], [4] achieves F1(L3) = 0.743, +0.210 over DeBERTa on novel-template anomalies. We release a 170,752-pair LogNLI benchmark with three ANLI-parallel difficulty levels (L1–L3).
关键词
log anomaly detection,natural language inference,novel anomaly detection,Large Language Models,Dempster-Shafer theory
稿件作者
Quang-Dung Dang
Posts and Telecommunications Institute of Technology
Quang-Dai Tran
Posts and Telecommunications Institute of Technology
发表评论