Computer Science ›› 2026, Vol. 53 ›› Issue (9): 405-413.doi: 10.11896/jsjkx.250900033

• Information Security • Previous Articles     Next Articles

Research on Log Anomaly Prediction Method for Log Sequence Graph Construction Guided byReinforcement Learning

XIA Bin1, SU Jinya1, CAO Junmin2, XIAO Junwen1, SUN Guozi1   

  1. 1 School of Computer Science,Nanjing University of Posts and Telecommunications,Nanjing 210003,China
    2 CASIC Space Engineering Development Co.,Ltd.,Wuhan 430000,China
  • Received:2025-09-03 Revised:2025-12-11 Online:2026-09-15 Published:2026-09-10
  • About author:XIA Bin,born in 1989,Ph.D,associate professor,is a member of CCF(No.B6091M).His main research interests include reinforcement learning,multi-agent system,and AI for IT operations.
    SUN Guozi,born in 1972,Ph.D,professor,is a member of CCF(No.12099D).His main research interests include blockchain forensics,digital forensics,and digital investigation.
  • Supported by:
    General Program of the National Natural Science Foundation of China(62472234).

Abstract: In the operation of large-scale software systems,anomalies such as hardware failures,malicious attacks,and module compatibility conflicts can easily lead to service interruptions and system crashes.Although logs provide key evidence for anomaly analysis,they still face multiple challenges:1)Traditional machine learning methods rely solely on event count vectors,ignoring the temporal dependencies and topological structures of log sequences;2)Deep learning methods are limited by the existing patterns in the training set,resulting in weak generalization capabilities,and they cannot model complex dependency relationships;3)Existing reinforcement learning methods suffer from issues such as Q-value overestimation and single reward mechanisms,failing to conduct forward-looking prediction and grading of abnormal sequences.To address the above challenges,a reinforcement learning-based solution is proposed.Firstly,it constructs a log sequence graph model based on a double deep Q-Network-under the condition of using only normal log samples and is guided by the experience replay mechanism and prior knowledge,the model structurally models the long-term dependencies of logs through sequence graphs,which breaks the reliance of existing reinforcement learning methods on a single state vector and solves the problems of Q-value overestimation and insufficient generalization.Secondly,it designs an anomaly prediction model based on a dueling deep Q-Network—through an adversarial learning mechanism and a multi-dimensional reward function,combined with an anomaly grading mechanism,the model achieves accurate prediction and grading of future abnormal sequences,which solves the limitation of traditional methods that “only detect but not predict” and provides sufficient response time for operation and maintenance.

Key words: Log anomaly prediction, Reinforcement learning, Double deep Q-Network, Dueling deep Q-Network, Log sequence graph

CLC Number: 

  • TP393
[1] ZHU J,HE S,LIU J,et al.Tools and bencharks for automated log parsing[C] //2019 IEEE/ACM 41st International Confe-rence on Software Engineering:Software Engineering in Practice(ICSE-SEIP).IEEE,2019:121-130.
[2] YUAN Y,ADHATARAO S S,LIN M,et al.Ada:Adaptive deep log anomaly detector[C] //IEEE INFOCOM 2020-IEEE Conference on Computer Communications.IEEE,2020:2449-2458.
[3] YAN L,XIA W.Survey on Log AnomalyDetection Based on Machine Learning[J].Computer Systems & Applications,2022,31(9):57-69.
[4] ZHANG X,XU Y,LIN Q,et al.Robust log-based anomaly detection on unstable log data[C] //Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Confe-rence and Symposium on the Foundations of Software Enginee-ring.2019:807-817.
[5] HUANG Z,XU W,YU K.Bidirectional lstm-crf models for se-quence tagging[J].arXiv:1508.01991,2015.
[6] XIA B,BAI Y,YIN J,et al.Loggan:a log-level generative adversarial network for anomaly detection using permutation event modeling[J].Information Systems Frontiers,2021,23:285-298.
[7] GOODFELLOW I,POUGET-ABADIE J,MIRZA M,et al.Ge-nerative adversarial nets[C] //Advances in Neural Information Processing Systems.2014.
[8] MENG W,LIU Y,ZHANG S,et al.Logclass:Anomalous logidentification and classification with partial labels[J].IEEE Transactions on Network and Service Management,2021,18(2):1870-1884.
[9] VAARANDI R,PIHELGAS M.Logcluster-a data clusteringand pattern mining algorithm for event logs[C] //2015 11th International Conference on Network and Service Management(CNSM).IEEE,2015:1-7.
[10] WITTKOPP T,ACKER A,NEDELKOSKI S,et al.A2log:attentive augmented log anomaly detection[J].arXiv:2109.09537,2021.
[11] DU M,LI F,ZHENG G,et al.Deeplog:Anomaly detection and diagnosis from system logs through deep learning[C] //Procee-dings of the 2017 ACM SIGSAC Conference on Computer and Communications Security.2017:1285-1298.
[12] MENG W,LIU Y,ZHU Y,et al.Loganomaly:Unsupervised detection of sequential and quantitative anomalies in unstructured logs[C] //IJCAI.2019:4739-4745.
[13] MNIH V,KAVUKCUOGLU K,SILVER D,et al.Human-level control through deep reinforcement learning[J].Nature,2015,518(7540):529-533.
[14] JOHN D C,MIAO Y J,PENG D Y,et al.Evolving Reinforcement Learning Algorithms[C] //ICLR 2021.2021.
[15] GUO H X,YUAN S H,WU X T.LogBERT:Log Anomaly Detection Via BERT[C] //IEEE International Joint Conference on Neural Network.2021.
[16] XIONG Y Y,CAI S F.Improving Log-Based Anomaly Detection Through Learned Adaptive Filter[J].arXiv:2504.02994,2025.
[17] HAN X,YUAN S H,MOHAMED T.LogGPT:Log Anomaly Detection Via GPT[C] //2023 IEEE International Conference on Big Data.2023:1117-1122.
[18] ZHOU J W,GAO Y Y,ZHU Y et al.DRLLog:Deep Reinforcement Learning for Online Log Anomaly Detection[J].IEEE Transactions on Network and Service Management,2025,22(3):2382-2395.
[19] HE P,ZHU J,ZHENG Z,et al.Drain:An online log parsing approach with fixed depth tree[C] //2017 IEEE International Conference on Web Services(ICWS).IEEE,2017:33-40.
[20] ZHU J,HE S,HE P,et al.Loghub:A large collection of system log datasets for ai-driven log analytics[C] //2023 IEEE 34th International Symposium on Software Reliability Engineering(ISSRE).IEEE,2023:355-366.
[21] ZHU J M,HE S L,HE P J,et al.Loghub:A Large Collection of System Log Datasets for AI-drivenLog Analytics[C] //IEEE International Symposium on Software Reliability Engineering(ISSRE).2023:355-366.
[22] LOU J G,FU Q,YANG S Q,et al.Mining Invariants from Console Logs for System Problem Detection[C] //USENIX Annual Technical Conference.2010:24.
[23] GUO H C,YANG J,LIU J H,et al.LogFormer:A Pre-train and Tuning Pipeline for Log Anomaly Detection[C] //AAAI Confe-rence on Artificial Intelligence.2024:135-143.
[1] WEI Debin, WANG Xinrui, YANG Li, PAN Chengsheng. DTD3-AQM:Satellite Network Queue Management Algorithm Based on Information Timeliness [J]. Computer Science, 2026, 53(9): 375-384.
[2] LIAN Zhaoyang, SI Bailu. Optimization in Cross-field of Manufacturing and Transportation by Combining Reinforcement Learning and Artificial Hummingbird Algorithm [J]. Computer Science, 2026, 53(8): 307-315.
[3] HE Yulin, XIAO Youqi, YANG Zhenyu, HUANG Zhexue, CUI Laizhong. Adaptive Frequency Tuning Approach for Spark Clusters [J]. Computer Science, 2026, 53(8): 71-84.
[4] WANG Hongguang, JIANG Yiming, LIU Xiajun, BAI Luxin. Self-adaptive Load Balancing Strategy Based on Reinforcement Learning for SDSN [J]. Computer Science, 2026, 53(7): 336-342.
[5] SHANG Kefeng, ZHANG Dan, ZHUAN Sunying, LI Dandan, LIU Yan, ZHU Kaige. Multi-party Inter-satellite Collaborative Computing Offloading Algorithm for Time-varying Topologies and Dynamic Heterogeneous Resources [J]. Computer Science, 2026, 53(7): 354-362.
[6] PAN Jiahao, FENG Xiang, YU Huiqun. SM-PHT:Robust,Scalable,and Efficient Method for Multi-task Reinforcement Learning [J]. Computer Science, 2026, 53(4): 366-376.
[7] ZHENG Cheng, BAN Qingqing. Knowledge-assisted and Reinforced Syntax-driven for Aspect-based Sentiment Analysis [J]. Computer Science, 2026, 53(4): 406-414.
[8] GONG Jing, YANG Yufa, ZHENG Yifan, SUN Zhixin. Multi-objective Intelligent Warehousing Path Planning Based on Conflict Free Path Algorithm [J]. Computer Science, 2026, 53(4): 88-100.
[9] LIU Jiaqi, WANG Yujie, XIANG Guodu, YU Kui, CAO Fuyuan. Long-term Causal Effect Estimation Based on Deep Reinforcement Learning [J]. Computer Science, 2026, 53(4): 235-244.
[10] ZHAI Jie, LI Yanhao, CHEN Lexuan, GUO Weibin. Dynamic Recommendation of Personalized Hands-on Learning Materials Based on LightweightEducational LLMs [J]. Computer Science, 2026, 53(2): 48-56.
[11] LI Fang, YUAN Baochun, SHEN Hang, WANG Tianjing, BAI Guangwei. Deep Reinforcement Learning-based Aircraft Task Offloading in Low Earth Orbit Satellite Networks [J]. Computer Science, 2026, 53(2): 406-415.
[12] WANG Haoyan, LI Chongshou, LI Tianrui. Reinforcement Learning Method for Solving Flexible Job Shop Scheduling Problem Based onDouble Layer Attention Network [J]. Computer Science, 2026, 53(1): 231-240.
[13] DUAN Pengting, WEN Chao, WANG Baoping, WANG Zhenni. Collaborative Semantics Fusion for Multi-agent Behavior Decision-making [J]. Computer Science, 2026, 53(1): 252-261.
[14] WAN Shenghua, XU Xingye, GAN Le, ZHAN Dechuan. Pre-training World Models from Videos with Generated Actions by Multi-modal Large Models [J]. Computer Science, 2026, 53(1): 51-57.
[15] ZHU Shihao, PENG Kexing, MA Tinghuai. Graph Attention-based Grouped Multi-agent Reinforcement Learning Method [J]. Computer Science, 2025, 52(9): 330-336.
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!