arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

理解基于大语言模型的日志异常检测:性能、效率与鲁棒性的实证研究

Towards Understanding LLM-Based Log Anomaly Detection: An Empirical Study of Performance, Efficiency, and Robustness

Bin Li, Dongdong Wang, Siyang Lu

arXiv 2609.31371首次发表:更新:

发表机构

Beijing Jiaotong University; University of Florida(北京交通大学; 佛罗里达大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究通过三个公开数据集上的系统实验,探究大语言模型在日志异常检测中的适应策略、架构、规模与量化对性能、效率和鲁棒性的影响,揭示性能差异与实用考量。

AI 中文摘要

大语言模型(LLMs)在日志异常检测中展现出有前景的性能,但其适应策略、架构和部署配置如何影响检测效果仍未被充分理解。为探究这些因素,我们在三个公开日志数据集上进行了系统的实证分析,考察了不同的适应策略、模型架构、参数规模和量化设置。我们的结果揭示了不同适应策略间存在显著的性能差异,而模型规模扩展在不同数据集上带来的检测增益各不相同。我们进一步观察到,检测精度相当的模型其计算成本可能差异显著,且低比特量化在评估配置下基本保持了检测性能。最后,我们考察了在不同扰动水平下,检测对结构噪声、语义噪声和标签噪声的鲁棒性。这些发现为基于LLM的日志异常检测的性能、效率和鲁棒性提供了实证见解,强调了超越传统以准确性为导向的评估的实际考量。

英文摘要

Large language models (LLMs) have demonstrated promising performance in log anomaly detection, yet how their adaptation strategies, architectures, and deployment configurations affect detection effectiveness remains insufficiently understood. To investigate these factors, we conduct a systematic empirical analysis across three public log datasets, examining different adaptation strategies, model architectures, parameter scales, and quantization settings. Our results reveal substantial performance differences across adaptation strategies, while model scaling yields varying detection gains across datasets. We further observe that models with comparable detection accuracy can exhibit markedly different computational costs, and that low-bit quantization largely preserves detection performance in the evaluated configurations. Finally, we examine detection robustness under structural, semantic, and label noise at different perturbation levels. These findings provide empirical insights into the performance, efficiency, and robustness of LLM-based log anomaly detection, highlighting practical considerations beyond conventional accuracy-oriented evaluation.

Comments6 pages, 2 figures, 3 tables. Submitted to IEEE ICASSP 2027

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑