arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

EvoCause:基于大语言模型引导的因果图进化的根本原因分析

EvoCause: LLM-Guided Evolution of Causal Graphs for Root Cause Analysis

Lei Zan, Keli Zhang, Shifeng Xie, Jiale Zheng, Zehao Xiao, Zhiwei Dong, Ke Zhang, Ruichu Cai, Malik Tiomoko, Lujia Pan

arXiv 2607.27290首次发表:更新:

AI 中文总结

EvoCause 用 LLM 优化因果图以提升电信等系统的根本原因分析性能,发布了 TeleRCA 基准,在合成数据和真实网络数据上均优于基线方法。

AI 中文摘要

现代电信、云及微服务系统在组件故障时会发出关联的告警级联,根本原因分析(RCA)旨在识别引发每个级联的少量告警。常见方法是从观测日志中学习因果图,并预测每个事件诱导子图中的所有零入度告警,但学习到的图是固定的,无法利用历史事件的专家诊断信息。EvoCause 闭合了这一循环:专家标签约束哪些告警应为源节点,但不指定满足这些约束所需的边编辑;EvoCause 使用大语言模型(LLM)提出语义合理的图编辑,同时确定性代码验证节点身份和无环性,并在标记对齐集上保留最优图。测试时,优化后的图可单独生成透明预测,无需调用 LLM。我们还发布了 TeleRCA——来自生产电信网络的专家标注基准,包含 485681 条告警事件,涉及 194 种告警类型、5621 个资源。在合成数据上,以 PC 因果发现算法初始化的 EvoCause 优于未优化的 PC 基线,将节点 F1、案例 EM、图 F1 分别提升 11.59、9.40、4.59 个百分点,同时将标准化汉明距离(nSHD)降低 0.2379;在 TeleRCA 上,将可读告警标题替换为匿名标识符使节点 F1 和案例 EM 分别降低 6.12 和 8.04 个百分点,表明告警名称信息有助于图优化。

英文摘要

Modern telecommunication, cloud, and microservice systems emit correlated alarm cascades when components fail. Root cause analysis (RCA) aims to identify the small set of alarms that initiate each cascade. A common approach learns a causal graph from observational logs and predicts all zero-in-degree alarms in each incident-induced subgraph. However, the learned graph remains fixed and cannot benefit from expert diagnoses of historical incidents. We close this loop with EvoCause. Expert labels constrain which alarms should be source nodes but do not specify the edge edits needed to satisfy those constraints. EvoCause uses a large language model (LLM) to propose semantically plausible graph edits, while deterministic code validates node identities and acyclicity and retains the best graph on a labeled alignment set. At test time, the refined graph alone produces transparent predictions without an LLM call. We also release TeleRCA, an expert-annotated benchmark from a production telecommunication network containing $485{,}681$ alarm events spanning $194$ alarm types over $5{,}621$ resources. On synthetic data, EvoCause initialized with the PC causal discovery algorithm outperforms the unrefined PC baseline, raising Node F1, Case EM, and Graph F1 by $11.59$, $9.40$, and $4.59$ percentage points, respectively, while reducing nSHD by $0.2379$. On TeleRCA, replacing human-readable alarm titles with anonymous identifiers lowers Node F1 and Case EM by $6.12$ and $8.04$ percentage points, respectively, indicating that alarm-name information contributes to graph refinement.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑