Result Details

An Empirical Study of a PCA-Based Multivariate Framework for Interpretable Log Anomaly Detection

SETINSKÝ, J.; ŽÁDNÍK, M. An Empirical Study of a PCA-Based Multivariate Framework for Interpretable Log Anomaly Detection. In 2025 21st International Conference on Network and Service Management (CNSM). New York: IEEE, 2025. p. 1-6. ISBN: 978-3-903176-75-1.
Type
conference paper
Language
English
Authors
Abstract

Effective anomaly detection is crucial for increasingly complex system logs, yet current methods often face challenges with labeled data reliance, high computational costs, or limited interpretability. This paper empirically applies an established Multivariate Statistical Network Monitoring (MSNM) framework, which leverages Principal Component Analysis (PCA) with D and Q statistics, to the log anomaly detection domain. We evaluate its performance on three benchmark datasets (HDFS, BGL, Thunderbird), focusing on its semi-supervised nature (requiring only normal operational data), computational efficiency, interpretability via count vector feature contributions, and ease of deployment. Our results demonstrate competitive F1 scores comparable to some supervised and deep learning methods, maintaining low computational overhead without GPU dependency. Furthermore, its strong interpretability is showcased through case studies, identifying specific log event patterns causing anomalies. This study highlights the MSNM framework's potential as a practical, efficient, and interpretable solution for log anomaly detection.

Published
2025
Pages
6
Proceedings
2025 21st International Conference on Network and Service Management (CNSM)
Conference
21st International Conference on Network and Service Management
ISBN
978-3-903176-75-1
Publisher
IEEE
Place
New York
DOI
BibTeX
@inproceedings{BUT198980,
  author="Jiří {Setinský} and Martin {Žádník}",
  title="An Empirical Study of a PCA-Based Multivariate
Framework for Interpretable Log Anomaly
Detection",
  booktitle="2025 21st International Conference on Network and Service Management (CNSM)",
  year="2025",
  pages="6",
  publisher="IEEE",
  address="New York",
  doi="10.23919/CNSM67658.2025.11297507",
  isbn="978-3-903176-75-1"
}
Projects
Application-specific HW/SW architectures and their applications, BUT, Vnitřní projekty VUT, FIT-S-23-8141, start: 2023-03-01, end: 2026-02-28, running
Departments
Back to top