Skip to main navigation Skip to search Skip to main content

LogMUSE: Log Anomaly Detection via Multi-Scale Semantic Representation

  • Mengyao Liu
  • , Tianbo Wang*
  • , Yuan Zhao
  • , Chunhe Xia
  • , Yingming Zeng
  • , Yuan Tao
  • *Corresponding author for this work
  • Beihang University
  • CAS - Institute of Computing Technology
  • Ministry of Public Security of the People's Republic of China

Research output: Contribution to journalArticlepeer-review

Abstract

Logs serve as an effective data source for recording and judging system states and abnormal events in complex systems. Current deep learning-based methods have proven effective in detecting anomalies in these system logs. However, existing anomaly detection methods, which predominantly rely on template-based and global window-based approaches, still face challenges in terms of flexibility and practicality. Template-based methods, while widely adopted for their simplicity and efficiency, overlook parameter information and fail to capture the true execution semantics. And global window-based methods, despite their effectiveness in modeling global dependencies, cannot simultaneously capture both global and local dependencies, leading to the obscuration of important local features. To address these issues, we propose a Log anomaly detection method based on MUlti-scale SEmantic representation, LogMUSE. Specifically, LogMUSE obtains template and parameter information through log parsing, employs a pre-trained Bidirectional Encoder Representations from Transformers (BERT) model for template semantic embedding, and enhances log entry representations via cross-attention mechanisms to effectively capture different parameter features under the same template. Additionally, we design the multi-scale Transformer model to capture global and local anomaly patterns, which enable fixed-length log sequences to focus on features at different scales. Extensive experiments on real-world benchmark datasets, including BGL, Thunderbird and Spirit, show that LogMUSE outperforms existing methods in log anomaly detection, achieving F1-scores of 98.62%, 94.32%, and 99.20% respectively. These results surpass the performance of current state-of-the-art methods and demonstrate the strong generalization across different system scenarios.

Original languageEnglish
JournalIEEE Transactions on Services Computing
DOIs
StateAccepted/In press - 2026

Keywords

  • anomaly detection
  • deep learning
  • Log analysis
  • log parsing
  • multi-scale

Fingerprint

Dive into the research topics of 'LogMUSE: Log Anomaly Detection via Multi-Scale Semantic Representation'. Together they form a unique fingerprint.

Cite this