$K^4$: Online Log Anomaly Detection Via Unsupervised Typicality Learning
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | , , , , , |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2025
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
| _version_ | 1866915994447904768 |
|---|---|
| author | Chen, Weicong Singh, Vikash Rahmani, Zahra Ganguly, Debargha Hariri, Mohsen Chaudhary, Vipin |
| author_facet | Chen, Weicong Singh, Vikash Rahmani, Zahra Ganguly, Debargha Hariri, Mohsen Chaudhary, Vipin |
| contents | Existing Log Anomaly Detection (LogAD) methods are often slow, dependent on error-prone parsing, and use unrealistic evaluation protocols. We introduce $K^4$, an unsupervised and parser-independent framework for high-performance online detection. $K^4$ transforms arbitrary log embeddings into compact four-dimensional descriptors (Precision, Recall, Density, Coverage) using efficient k-nearest neighbor (k-NN) statistics. These descriptors enable lightweight detectors to accurately score anomalies without retraining. Using a more realistic online evaluation protocol, $K^4$ sets a new state-of-the-art (AUROC: 0.995-0.999), outperforming baselines by large margins while being orders of magnitude faster, with training under 4 seconds and inference as low as 4 $μ$s. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2507_20051 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | $K^4$: Online Log Anomaly Detection Via Unsupervised Typicality Learning Chen, Weicong Singh, Vikash Rahmani, Zahra Ganguly, Debargha Hariri, Mohsen Chaudhary, Vipin Machine Learning Computation and Language Distributed, Parallel, and Cluster Computing Existing Log Anomaly Detection (LogAD) methods are often slow, dependent on error-prone parsing, and use unrealistic evaluation protocols. We introduce $K^4$, an unsupervised and parser-independent framework for high-performance online detection. $K^4$ transforms arbitrary log embeddings into compact four-dimensional descriptors (Precision, Recall, Density, Coverage) using efficient k-nearest neighbor (k-NN) statistics. These descriptors enable lightweight detectors to accurately score anomalies without retraining. Using a more realistic online evaluation protocol, $K^4$ sets a new state-of-the-art (AUROC: 0.995-0.999), outperforming baselines by large margins while being orders of magnitude faster, with training under 4 seconds and inference as low as 4 $μ$s. |
| title | $K^4$: Online Log Anomaly Detection Via Unsupervised Typicality Learning |
| topic | Machine Learning Computation and Language Distributed, Parallel, and Cluster Computing |
| url | https://arxiv.org/abs/2507.20051 |