TY - JOUR
T1 - LogMUSE
T2 - Log Anomaly Detection via Multi-Scale Semantic Representation
AU - Liu, Mengyao
AU - Wang, Tianbo
AU - Zhao, Yuan
AU - Xia, Chunhe
AU - Zeng, Yingming
AU - Tao, Yuan
N1 - Publisher Copyright:
© 2008-2012 IEEE.
PY - 2026
Y1 - 2026
N2 - Logs serve as an effective data source for recording and judging system states and abnormal events in complex systems. Current deep learning-based methods have proven effective in detecting anomalies in these system logs. However, existing anomaly detection methods, which predominantly rely on template-based and global window-based approaches, still face challenges in terms of flexibility and practicality. Template-based methods, while widely adopted for their simplicity and efficiency, overlook parameter information and fail to capture the true execution semantics. And global window-based methods, despite their effectiveness in modeling global dependencies, cannot simultaneously capture both global and local dependencies, leading to the obscuration of important local features. To address these issues, we propose a Log anomaly detection method based on MUlti-scale SEmantic representation, LogMUSE. Specifically, LogMUSE obtains template and parameter information through log parsing, employs a pre-trained Bidirectional Encoder Representations from Transformers (BERT) model for template semantic embedding, and enhances log entry representations via cross-attention mechanisms to effectively capture different parameter features under the same template. Additionally, we design the multi-scale Transformer model to capture global and local anomaly patterns, which enable fixed-length log sequences to focus on features at different scales. Extensive experiments on real-world benchmark datasets, including BGL, Thunderbird and Spirit, show that LogMUSE outperforms existing methods in log anomaly detection, achieving F1-scores of 98.62%, 94.32%, and 99.20% respectively. These results surpass the performance of current state-of-the-art methods and demonstrate the strong generalization across different system scenarios.
AB - Logs serve as an effective data source for recording and judging system states and abnormal events in complex systems. Current deep learning-based methods have proven effective in detecting anomalies in these system logs. However, existing anomaly detection methods, which predominantly rely on template-based and global window-based approaches, still face challenges in terms of flexibility and practicality. Template-based methods, while widely adopted for their simplicity and efficiency, overlook parameter information and fail to capture the true execution semantics. And global window-based methods, despite their effectiveness in modeling global dependencies, cannot simultaneously capture both global and local dependencies, leading to the obscuration of important local features. To address these issues, we propose a Log anomaly detection method based on MUlti-scale SEmantic representation, LogMUSE. Specifically, LogMUSE obtains template and parameter information through log parsing, employs a pre-trained Bidirectional Encoder Representations from Transformers (BERT) model for template semantic embedding, and enhances log entry representations via cross-attention mechanisms to effectively capture different parameter features under the same template. Additionally, we design the multi-scale Transformer model to capture global and local anomaly patterns, which enable fixed-length log sequences to focus on features at different scales. Extensive experiments on real-world benchmark datasets, including BGL, Thunderbird and Spirit, show that LogMUSE outperforms existing methods in log anomaly detection, achieving F1-scores of 98.62%, 94.32%, and 99.20% respectively. These results surpass the performance of current state-of-the-art methods and demonstrate the strong generalization across different system scenarios.
KW - anomaly detection
KW - deep learning
KW - Log analysis
KW - log parsing
KW - multi-scale
UR - https://www.scopus.com/pages/publications/105041367473
U2 - 10.1109/TSC.2026.3700403
DO - 10.1109/TSC.2026.3700403
M3 - 文章
AN - SCOPUS:105041367473
SN - 1939-1374
JO - IEEE Transactions on Services Computing
JF - IEEE Transactions on Services Computing
ER -