REPLICAWATCHER: Training-less Anomaly Detection in Containerized Microservices
Asbat El Khairi, Marco Caselli, Andreas Peter, Andrea Continella
Abstract
—Despite its detection capabilities against previously unseen threats, anomaly detection suffers from critical limitations, which often prevent its deployment in real-world settings. In fact, anomaly-based intrusion detection systems rely on comprehensive pre-established baselines for effectively identifying suspicious activities. Unfortunately, prior research showed that these baselines age and gradually lose their effectiveness over time, especially in dynamic deployments such as microservices-based environments, where the concept of “normality” is frequently redefined due to shifting operational conditions. This scenario reinforces the need for periodic retraining to uphold optimal performance — a process that proves challenging, particularly in the context of security applications. We propose a novel, training-less approach to monitoring microservices-based environments. Our system, R EPLI - CA W ATCHER , observes the behavior of identical container instances (i.e., replicas ) and detects anomalies without requiring prior training. Our key insight is that replicas, adopted for fault tolerance or scalability reasons, execute analogous tasks and exhibit similar behavioral patterns, which allow anomalous containers to stand out as a notable deviation from their corresponding replicas, thereby serving as a crucial indicator of security threats. The results of our experimental evaluation show that our approach is resilient against normality shifts and maintains its effectiveness without the necessity for retraining. Besides, despite not relying on a training phase, R EPLICA W ATCHER performs comparably to state-of-the-art, training-based solutions, achieving an average precision of 91.08% and recall of 98.35%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 422091cf-0054-4242-83e6-2d3b6a3567e0Cited by top-tier papers4
- Detecting and Explaining Anomalies Caused by Web Tamper Attacks via Building Consistency-based NormalityYifan Liao, Ming Xu, Yun Lin, Xiwen Teoh et al.ASE 2024 · 1 citation
- CAShift: Benchmarking Log-Based Cloud Attack Detection under Normality ShiftJiongchi Yu, Xiaofei Xie, Qiang Hu, Bowen Zhang et al.FSE 2025 · 1 citation
- Kintsugi: Empowering LLMs to Mitigate Web Vulnerabilities via Runtime Policy InjectionYihao Peng, Zizhen Zhu, Jiatian Hu, Jiaxu Wang et al.USENIX Security 2026
- MINES: Explainable Anomaly Detection through Web API Invariant InferenceWenjie Zhang, Yun Lin, Chun Fung Amos Kwok, Xiwen Teoh et al.ICSE 2026
Builds on5
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen et al.NDSS 2019 · 411 citations
- CADE: Detecting and Explaining Concept Drift Samples for Security ApplicationsLimin Yang, Wenbo Guo, Qingying Hao, Arridhana Ciptadi et al.USENIX Security 2021 · 241 citations
- Automatic Policy Generation for Inter-Service Access Control of MicroservicesXing Li, Yan Chen, Zhiqiang Lin, Xiao Wang et al.USENIX Security 2021 · 64 citations
- Custos: Practical Tamper-Evident Auditing of Operating Systems Using Trusted ExecutionRiccardo Paccagnella, Pubali Datta, Wajih Ul Hassan, Adam Bates et al.NDSS 2020
- Anomaly Detection in the Open World: Normality Shift Detection, Explanation, and AdaptationDongqi Han, Zhiliang Wang, Wenqi Chen, Kai Wang et al.NDSS 2023
Related papers
- APIECHO: Training-Less Anomaly Detection via Intra-API Behavioral Comparison for Web ApplicationsYihao Peng, Yiming Wu, Du Wu, Shouling Ji et al.S&P 2026
- Twin Graph-Based Anomaly Detection via Attentive Multi-Modal Learning for Microservice SystemJun Huang, Yang Yang, Hang Yu, Jianguo Li et al.ASE 2023 · 32 citations
- LARA: A Light and Anti-overfitting Retraining Approach for Unsupervised Time Series Anomaly DetectionFeiyi Chen, Zhen Qin, Mengchu Zhou, Yingying Zhang et al.WWW 2024 · 18 citations
- DeepTraLog: Trace-Log Combined Microservice Anomaly Detection through Graph-based Deep LearningChenxi Zhang, Xin Peng, Chaofeng Sha, Ke Zhang et al.ICSE 2022 · 163 citations
- Cross-System Categorization of Abnormal Traces in Microservice-Based Systems via Meta-LearningYuqing Wang, Mika V. Mäntylä, Serge Demeyer, Mutlu Beyazit et al.FSE 2025
