Return
ilLog: Incremental Learning Based Anomaly Detection From Evolving System Logs
DOI:10.1109/tdsc.2026.3690744.png)
Abstract
En 中文
Log anomaly detection (LAD) is of paramount importance to enhance the reliability and stability of software systems. Current state-of-the-art LAD suffers a significant performance degradation when dealing with consistently evolving log events caused by system updates. To build a reliable LAD model under the context of log data evolution, we propose an incremental learning-based method for LAD, namely ilLog, to avoid catastrophic forgetting of previously learned knowledge while continuously updating the model for better detection when processing the evolving log events. In particular, we design a novel entropy-driven sorting algorithm for real log sample replay, which enables the preservation of old knowledge via storing representative samples with discrete sequence features from previous tasks. Additionally, we introduce a Halton-based low discrepancy sequence to better approximate the sliced Cramér distance between the probability distributions of two models, thus enhancing the model learning capability. Based on a standard incremental learning protocol setting, we evaluate the newly proposed ilLog method on three publicly available datasets. Experimental results demonstrate that our approach achieves the best performance compared to SOTA LAD methods and models by applying existing IL-based methods in evolving software systems.
Keywords:
Log anomaly detection
incremental learning
information entropy
Quasi-Monte Carlo
Journal
IF:
7.5
Papers:
2.4K
Citations:
9.6K

