A Novel GPT-Based Framework for Anomaly Detection in System Logs

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Zeng, Yin, Wenjie, Li, Xiaoqi
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911218284888064
author Zhang, Zeng
Yin, Wenjie
Li, Xiaoqi
author_facet Zhang, Zeng
Yin, Wenjie
Li, Xiaoqi
contents Identification of anomalous events within system logs constitutes a pivotal element within the frame- work of cybersecurity defense strategies. However, this process faces numerous challenges, including the management of substantial data volumes, the distribution of anomalies, and the precision of con- ventional methods. To address this issue, the present paper puts forward a proposal for an intelligent detection method for system logs based on Genera- tive Pre-trained Transformers (GPT). The efficacy of this approach is attributable to a combination of structured input design and a Focal Loss op- timization strategy, which collectively result in a substantial enhancement of the performance of log anomaly detection. The initial approach involves the conversion of raw logs into event ID sequences through the use of the Drain parser. Subsequently, the Focal Loss loss function is employed to address the issue of class imbalance. The experimental re- sults demonstrate that the optimized GPT-2 model significantly outperforms the unoptimized model in a range of key metrics, including precision, recall, and F1 score. In specific tasks, comparable or superior performance has been demonstrated to that of the GPT-3.5 API.
format Preprint
id arxiv_https___arxiv_org_abs_2510_16044
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A Novel GPT-Based Framework for Anomaly Detection in System Logs
Zhang, Zeng
Yin, Wenjie
Li, Xiaoqi
Cryptography and Security
Machine Learning
Identification of anomalous events within system logs constitutes a pivotal element within the frame- work of cybersecurity defense strategies. However, this process faces numerous challenges, including the management of substantial data volumes, the distribution of anomalies, and the precision of con- ventional methods. To address this issue, the present paper puts forward a proposal for an intelligent detection method for system logs based on Genera- tive Pre-trained Transformers (GPT). The efficacy of this approach is attributable to a combination of structured input design and a Focal Loss op- timization strategy, which collectively result in a substantial enhancement of the performance of log anomaly detection. The initial approach involves the conversion of raw logs into event ID sequences through the use of the Drain parser. Subsequently, the Focal Loss loss function is employed to address the issue of class imbalance. The experimental re- sults demonstrate that the optimized GPT-2 model significantly outperforms the unoptimized model in a range of key metrics, including precision, recall, and F1 score. In specific tasks, comparable or superior performance has been demonstrated to that of the GPT-3.5 API.
title A Novel GPT-Based Framework for Anomaly Detection in System Logs
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2510.16044