Ajou University repository

Temporal Decay Loss for Adaptive Log Anomaly Detection in Cloud Environments
  • Jilcha, Lelisa Adeba ;
  • Kim, Deuk Hun ;
  • Kwak, Jin
Citations

SCOPUS

1

Citation Export

DC Field Value Language
dc.contributor.authorJilcha, Lelisa Adeba-
dc.contributor.authorKim, Deuk Hun-
dc.contributor.authorKwak, Jin-
dc.date.issued2025-05-01-
dc.identifier.issn1424-8220-
dc.identifier.urihttps://aurora.ajou.ac.kr/handle/2018.oak/38334-
dc.identifier.urihttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=105004921479&origin=inward-
dc.description.abstractLog anomaly detection in cloud computing environments is essential for maintaining system reliability and security. While sequence modeling architectures such as LSTMs and Transformers have been widely employed to capture temporal dependencies in log messages, their effectiveness deteriorates in zero-shot transfer scenarios due to distributional shifts in log structures, terminology, and event frequencies, as well as minimal token overlap across datasets. To address these challenges, we propose an effective detection approach integrating a domain-specific pre-trained language model (PLM) fine-tuned on cybersecurity-adjacent data with a novel loss function, Loss with Decaying Factor (LDF). LDF introduces an exponential time decay mechanism into the training objective, ensuring a dynamic balance between historical context and real-time relevance. Unlike traditional sequence models that often overemphasize outdated information and impose high computational overhead, LDF constrains the training process by dynamically weighing log messages based on their temporal proximity, thereby aligning with the rapidly evolving nature of cloud computing environments. Additionally, the domain-specific PLM mitigates semantic discrepancies by improving the representation of log data across heterogeneous datasets. Extensive empirical evaluations on two supercomputing log datasets demonstrate that this approach substantially enhances cross-dataset anomaly detection performance. The main contributions of this study include: (1) the introduction of a Loss with Decaying Factor (LDF) to dynamically balance historical context with real-time relevance; and (2) the integration of a domain-specific PLM for enhancing generalization in zero-shot log anomaly detection across heterogeneous cloud environments.-
dc.description.sponsorshipThis work was supported by the National Research Foundation of Korea (NRF) grant funded by the Korea government (MSIT) (No. 2021R1A2C2011391) and supported by the Institute of Information & Communications Technology Planning & Evaluation (IITP) grant funded by the Korea government (MSIT) (No. 2024-00400302, Development of Cloud Deep Defense Security Framework Technology for a Safe Cloud Native Environment).-
dc.language.isoeng-
dc.publisherMultidisciplinary Digital Publishing Institute (MDPI)-
dc.subject.meshAdaptive detection-
dc.subject.meshAnomaly detection-
dc.subject.meshCloud-computing-
dc.subject.meshLanguage model-
dc.subject.meshLog preprocessing-
dc.subject.meshLoss with decaying factor-
dc.subject.meshPretrained language model-
dc.subject.meshShot detection-
dc.subject.meshTemporal decay-
dc.subject.meshTemporal decay loss-
dc.subject.meshTemporal dependency-
dc.subject.meshZero-shot detection-
dc.titleTemporal Decay Loss for Adaptive Log Anomaly Detection in Cloud Environments-
dc.typeArticle-
dc.citation.number9-
dc.citation.titleSensors-
dc.citation.volume25-
dc.identifier.bibliographicCitationSensors, Vol.25 No.9-
dc.identifier.doi10.3390/s25092649-
dc.identifier.pmid40363089-
dc.identifier.scopusid2-s2.0-105004921479-
dc.identifier.urlhttp://www.mdpi.com/journal/sensors-
dc.subject.keywordadaptive detection-
dc.subject.keywordanomaly detection-
dc.subject.keywordcloud computing-
dc.subject.keywordLDF-
dc.subject.keywordlog preprocessing-
dc.subject.keywordpretrained language model-
dc.subject.keywordtemporal decay loss-
dc.subject.keywordtemporal dependency-
dc.subject.keywordzero-shot detection-
dc.type.otherArticle-
dc.identifier.pissn14248220-
dc.subject.subareaAnalytical Chemistry-
dc.subject.subareaInformation Systems-
dc.subject.subareaAtomic and Molecular Physics, and Optics-
dc.subject.subareaBiochemistry-
dc.subject.subareaInstrumentation-
dc.subject.subareaElectrical and Electronic Engineering-
Show simple item record

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

KWAK, JIN Image
KWAK, JIN곽진
Department of Cyber Security
Read More

Total Views & Downloads

File Download

  • There are no files associated with this item.