PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 29, 2026Computers, materials & continua/Computers, materials & continua (Print)0 citationsOpen Access

Explainable Anomaly Detection for System Logs in Distributed Environments

View Full Paper
ZGZhaojun GuWYWenlong YueCLChunbo Liu

Key Points

  • The research aims to develop a lightweight and explainable framework for detecting anomalies in distributed system logs.
  • Proposes a framework named FedXLog utilizing federated learning
  • Implements hierarchical feature extraction for heterogeneous logs
  • Introduces Federated Gradient Trajectory Aggregation algorithm for improved explainability
  • Constructs lightweight models through knowledge distillation
  • Integrates hash feature alignment for globally consistent explanations
  • Achieves high detection accuracy in identifying anomalies
  • Demonstrates effective lightweight deployment in distributed scenarios
  • Successfully identifies key features influencing decision-making
  • Locates typical root causes of anomalies in operational contexts
  • Optimized specifically for the unique characteristics of distributed logs

Abstract

Anomaly detection in system logs is a critical technical means for identifying potential faults and security risks. In distributed environments, traditional deep learning-based log anomaly detection methods often suffer from shortcomings in transparency, computational overhead, and data privacy protection. To address these issues, this paper proposes a federated learning-driven lightweight and explainable log anomaly detection framework named FedXLog. The framework adapts to heterogeneous logs through hierarchical feature extraction, introduces the Federated Gradient Trajectory Aggregation algorithm (FedGradTrace) to enhance the explainability of the parameter aggregation process, constructs lightweight models using knowledge distillation, and achieves globally consistent explanatory capabilities by integrating hash feature alignment. Experimental results demonstrate that FedXLog possesses the dual advantages of high detection accuracy and lightweight deployment for heterogeneous logs in distributed scenarios. It can effectively identify key decision-making features and locate typical root causes of anomalies. Notably, the framework has been specifically optimized for the unique characteristics of distributed logs. Distinguished from general federated explainable methods, it can directly support abnormal root cause localization in Operations and Maintenance scenarios. This further verifies the application value of scenario-specific adaptation of federated learning in the field of log analysis, thereby expanding the scope of application of explainable log anomaly detection.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Gu et al. (2026) studied this question.

synapsesocial.com/papers/69c8c277de0f0f753b39cb86https://doi.org/10.32604/cmc.2026.077388
Ask AI
Helpful
Bookmark
Share
View Full Paper