PCLog: 近端策略优化与行为克隆自适应日志异常检测
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

TP311

基金项目:

湖北省重点研发基金(2025BEB012)


PCLog: Adaptive Log Anomaly Detection Based on Proximal Policy Optimization and Behavior Cloning
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    日志数据记录了系统的运行状态、用户行为及错误信息. 基于日志的异常检测可快速识别潜在的安全风险或性能瓶颈, 提升运维效率, 助力故障诊断. 然而, 现有的日志异常检测方法仍面临诸多挑战, 如无法有效适应系统升级引起的日志模式变化, 缺乏高效反馈机制导致难以持续保持检测性能等. 为此, 提出一种日志异常检测框架PCLog, 采用强化学习方法中的近端策略优化(proximal policy optimization, PPO)算法进行模型训练. 该方案将检测模型视为智能体, 日志对应的语义向量视为状态, 事件视为动作, 通过最大化正常序列的累计奖励来学习系统的正常行为模式从而实现异常检测. 此外, 当检测性能下降时, PCLog可通过收集错误预测的样本作为专家示范数据, 并结合模仿学习中的行为克隆方法, 最大化专家数据的对数似然, 从而使模型更有效地逼近专家行为, 实现模型的自适应修正, 有效减少误报率, 提升系统长期运行的可靠性. 在HDFS、BGL与OpenStack这3大公开日志数据集上的实验结果表明, PCLog相较于现有方法表现更优, 具备较强的动态日志模式适应能力.

    Abstract:

    Log data record system operating status, user behavior, and error information. Log-based anomaly detection enables the rapid identification of potential security risks or performance bottlenecks, thereby enhancing operational efficiency and facilitating fault diagnosis. However, existing log anomaly detection methods still face several challenges, including the inability to effectively adapt to log pattern changes caused by system updates and the lack of efficient feedback mechanisms to consistently maintain detection performance. To address these issues, this study proposes a log anomaly detection framework, PCLog, which adopts the proximal policy optimization (PPO) algorithm from reinforcement learning for model training. In the proposed framework, the detection model is formulated as an agent, semantic vectors of logs are regarded as states, and events are treated as actions. By maximizing the cumulative rewards of normal sequences, normal system behavior patterns are learned to enable anomaly detection. In addition, when detection performance decreases, PCLog collects mispredicted samples as expert demonstration data and integrates behavior cloning from imitation learning to maximize the log-likelihood of expert data. This mechanism enables the model to more effectively approximate expert behavior, achieve adaptive self-correction, reduce false positives, and enhance long-term reliability. Experimental results on three public log datasets, HDFS, BGL, and OpenStack, show that PCLog outperforms existing methods and exhibits high adaptability to dynamic log patterns.

    参考文献
    相似文献
    引证文献
引用本文

周俊伟,胡淼,王春龙,杜亚娟,谈诚. PCLog: 近端策略优化与行为克隆自适应日志异常检测.软件学报,2026,37(7):2831-2848

复制
相关视频

分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2025-09-07
  • 最后修改日期:2025-10-20
  • 录用日期:
  • 在线发布日期: 2025-12-26
  • 出版日期: 2026-07-06
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号