Unsupervised Contextual Anomaly Detection for Database Systems
Sainan Li, Qilei Yin, Guoliang Li, Qi Li, Zhuotao Liu, Jinwei Zhu
Abstract
Abnormal data access operations in database systems always hap-pen, which are typically incurred by misoperations or attacks, though these systems are enforced with strict access control policies. However, prior arts only focus on detecting abnormal data accesses by utilizing known attack patterns or identifying behaviors significantly deviated from normal behaviors. They cannot capture stealthy abnormal data access operations that are similar to normal ones. In this paper, we propose a novel unsupervised anomaly detection system UCAD, which aims to detect abnormal data access operations, by comparing operation's semantics with their contextual intent. However, it is non-trivial to obtain accurate semantics of operations for intent analysis because (i) the same operation may exhibit diverse semantics under different operation contexts and (ii) different operation sequences could have identical semantics due to heterogeneous user access patterns. To address this issue, we develop a new transformer model called Trans-DAS for UCAD. Trans-DAS learns the semantics of individual operations by utilizing the attention mechanism that analyzes the relevance between any pair of operations in sequence, and captures the contextual intent of operations inferred from the contexts. Specifically, Trans-DAS utilizes a particular embedding layer to embed the semantics of individual operations without the operation order information and a masking mechanism that allows Trans-DAS to learn the semantics according to the bidirectional contexts. Also, we define a new training objective for Trans-DAS to enlarge the difference among the embedded semantics. Furthermore, in order to effectively utilize Trans-DAS for detection, we develop two modules in UCAD, i.e., a data preprocessing module that allows Trans-DAS to accurately learn the normal semantic information by removing noisy data, and an anomaly detection module that learns the semantic information for intent comparison. We evaluate the performance of UCAD on real-world data traces under different settings (e.g., varied parameters and hybrid datasets). The results demonstrate that UCAD achieves the average F1-score of 0.94 in two scenarios, which significantly outperform baselines, and shows robustness to hybrid data and good transferability to different tasks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- METER: A Dynamic Concept Adaptation Framework for Online Anomaly DetectionJiaqi Zhu, Shaofeng Cai, Fang Deng, Beng Chin Ooi et al.VLDB 2024 · 18 citations
- Learning from Limited Heterogeneous Training Data: Meta-Learning for Unsupervised Zero-Day Web Attack Detection across Web DomainsPeiyang Li, Ye Wang, Qi Li, Zhuotao Liu et al.CCS 2023 · 13 citations
- Pluto: Sample Selection for Robust Anomaly Detection on Polluted Log DataLei Ma, Lei Cao, Peter M. VanNostrand, Dennis M. Hofmann et al.SIGMOD 2025 · 3 citations
Builds on8
- DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep LearningMin Du, Feifei Li, Guineng Zheng, Vivek SrikumarCCS 2017 · 1,823 citations
- Log2vec: A Heterogeneous Graph Embedding Based Approach for Detecting Cyber Threats within EnterpriseFucheng Liu, Yu Wen, Dongxue Zhang, Xihe Jiang et al.CCS 2019 · 314 citations
- Tiresias: Predicting Security Events Through Deep LearningYun Shen, Enrico Mariconti, Pierre-Antoine Vervier, Gianluca StringhiniCCS 2018 · 180 citations
- Lifelong Anomaly Detection Through UnlearningMin Du, Zhi Chen, Chang Liu, Rajvardhan Oak et al.CCS 2019 · 145 citations
- A Reinforced Generation of Adversarial Examples for Neural Machine TranslationWei Zou, Shujian Huang, Jun Xie, Xinyu Dai et al.ACL 2020 · 66 citations
Related papers
- Learning Semantic Context from Normal Samples for Unsupervised Anomaly DetectionXudong Yan, Huaidong Zhang, Xuemiao Xu, Xiaowei Hu et al.AAAI 2021 · 210 citations
- Log-based Anomaly Detection Without Log ParsingVan-Hoang Le, Hongyu ZhangASE 2021 · 249 citations
- ICAD-LLM: One-for-All Anomaly Detection via In-Context Learning with Large Language ModelsZhongyuan Wu, Jingyuan Wang, Zexuan Cheng, Yilong Zhou et al.AAAI 2026 · 1 citation
- LogFormer: A Pre-train and Tuning Pipeline for Log Anomaly DetectionHongcheng Guo, Jian Yang, Jiaheng Liu, Jiaqi Bai et al.AAAI 2024 · 68 citations
- TranAD: Deep Transformer Networks for Anomaly Detection in Multivariate Time Series DataShreshth Tuli, Giuliano Casale, Nicholas R. JenningsVLDB 2022 · 930 citations
