$K^4$: Online Log Anomaly Detection Via Unsupervised Typicality Learning

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Chen, Weicong, Singh, Vikash, Rahmani, Zahra, Ganguly, Debargha, Hariri, Mohsen, Chaudhary, Vipin
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866915994447904768
author Chen, Weicong
Singh, Vikash
Rahmani, Zahra
Ganguly, Debargha
Hariri, Mohsen
Chaudhary, Vipin
author_facet Chen, Weicong
Singh, Vikash
Rahmani, Zahra
Ganguly, Debargha
Hariri, Mohsen
Chaudhary, Vipin
contents Existing Log Anomaly Detection (LogAD) methods are often slow, dependent on error-prone parsing, and use unrealistic evaluation protocols. We introduce $K^4$, an unsupervised and parser-independent framework for high-performance online detection. $K^4$ transforms arbitrary log embeddings into compact four-dimensional descriptors (Precision, Recall, Density, Coverage) using efficient k-nearest neighbor (k-NN) statistics. These descriptors enable lightweight detectors to accurately score anomalies without retraining. Using a more realistic online evaluation protocol, $K^4$ sets a new state-of-the-art (AUROC: 0.995-0.999), outperforming baselines by large margins while being orders of magnitude faster, with training under 4 seconds and inference as low as 4 $μ$s.
format Preprint
id arxiv_https___arxiv_org_abs_2507_20051
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle $K^4$: Online Log Anomaly Detection Via Unsupervised Typicality Learning
Chen, Weicong
Singh, Vikash
Rahmani, Zahra
Ganguly, Debargha
Hariri, Mohsen
Chaudhary, Vipin
Machine Learning
Computation and Language
Distributed, Parallel, and Cluster Computing
Existing Log Anomaly Detection (LogAD) methods are often slow, dependent on error-prone parsing, and use unrealistic evaluation protocols. We introduce $K^4$, an unsupervised and parser-independent framework for high-performance online detection. $K^4$ transforms arbitrary log embeddings into compact four-dimensional descriptors (Precision, Recall, Density, Coverage) using efficient k-nearest neighbor (k-NN) statistics. These descriptors enable lightweight detectors to accurately score anomalies without retraining. Using a more realistic online evaluation protocol, $K^4$ sets a new state-of-the-art (AUROC: 0.995-0.999), outperforming baselines by large margins while being orders of magnitude faster, with training under 4 seconds and inference as low as 4 $μ$s.
title $K^4$: Online Log Anomaly Detection Via Unsupervised Typicality Learning
topic Machine Learning
Computation and Language
Distributed, Parallel, and Cluster Computing
url https://arxiv.org/abs/2507.20051