Krone: Hierarchical and Modular Log Anomaly Detection
Lei Ma, Jinyang Liu, Tieying Zhang, Peter M. VanNostrand, Dennis M. Hofmann, Lei Cao, Elke A. Rundensteiner, Jianjun Chen
Abstract
Log anomaly detection is crucial for uncovering system failures and security risks. Although logs originate from nested component executions with clear boundaries, this structure is lost when stored as flat sequences. Hence, state-of-theart methods risk missing true dependencies within executions while learning spurious ones across unrelated events. We propose KRONE, the first hierarchical anomaly detection framework that automatically derives execution hierarchies from flat logs for modular multi-level anomaly detection. At its core, the KRONE Log Abstraction Model models log data by extracting the application-specific semantic hierarchical structure. This hierarchy is then leveraged by KRONE to recursively decompose log sequences into multi-levels of coherent execution chunks, i.e., KRONE Seqs, transforming sequence-level detection into a set of modular KRONE Seq-level detection tasks. For each test KRONE Seq, KRONE adopts a hybrid modular detection mechanism that routes between an efficient level-independent Local-Context detector that rapidly filters normal KRONE Seqs, and a Nested-Aware detector that incorporates cross-level semantic dependencies; augmented with LLM-based anomaly detection and explanation. KRONE optimizes the modular detection tasks along the hierarchy with cached result reuse and early-exit optimization strategies. Experiments on three public benchmarks and one industrial dataset from ByteDance Cloud demonstrate the comprehensive improvement of KRONE, on accuracy (42.49% → 87.98%), F-1 of same detector with or without hierarchy), dataefficiency (data space 117.3× ↓), resource-efficieny (43.7× ↓) and interpretability. KRONE improves F1-score by 10.07% (82.76% → 92.83%) over prior methods, while reducing LLM usage to 1.1%-3.3% of the test data size.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on15
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Chain-of-Thought Prompting Elicits Reasoning in Large Language ModelsJason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma et al.NeurIPS 2022 · 22,562 citations
- DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep LearningMin Du, Feifei Li, Guineng Zheng, Vivek SrikumarCCS 2017 · 1,823 citations
- Self-Consistency Improves Chain of Thought Reasoning in Language ModelsXuezhi Wang, Jason Wei, Dale Schuurmans, Quoc V. Le et al.ICLR 2023 · 681 citations
- Rethinking the Role of Demonstrations: What Makes In-Context Learning Work?Sewon Min, Xinxi Lyu, Ari Holtzman, Mikel Artetxe et al.EMNLP 2022 · 634 citations
Related papers
- Substructure-aware Log Anomaly DetectionYanni Tang, Zhuoxing Zhang, Kaiqi Zhao, Lanting Fang et al.VLDB 2025 · 4 citations
- LogFormer: A Pre-train and Tuning Pipeline for Log Anomaly DetectionHongcheng Guo, Jian Yang, Jiaheng Liu, Jiaqi Bai et al.AAAI 2024 · 68 citations
- CoorLog: Efficient-Generalizable Log Anomaly Detection via Adaptive Coordinator in Software EvolutionPei Xiao, Chiming Duan, Minghua He, Tong Jia et al.ASE 2025 · 3 citations
- Pluto: Sample Selection for Robust Anomaly Detection on Polluted Log DataLei Ma, Lei Cao, Peter M. VanNostrand, Dennis M. Hofmann et al.SIGMOD 2025 · 3 citations
- DeepTraLog: Trace-Log Combined Microservice Anomaly Detection through Graph-based Deep LearningChenxi Zhang, Xin Peng, Chaofeng Sha, Ke Zhang et al.ICSE 2022 · 163 citations
