Deep Learning or Classical Machine Learning? An Empirical Study on Log-Based Anomaly Detection
Boxi Yu, Jiayi Yao, Qiuai Fu, Zhiqing Zhong, Haotian Xie, Yaoliang Wu, Yuchi Ma, Pinjia He
Abstract
While deep learning (DL) has emerged as a powerful technique, its benefits must be carefully considered in relation to computational costs. Specifically, although DL methods have achieved strong performance in log anomaly detection, they often require extended time for log preprocessing, model training, and model inference, hindering their adoption in online distributed cloud systems that require rapid deployment of log anomaly detection service. This paper investigates the superiority of DL methods compared to simpler techniques in log anomaly detection. We evaluate basic algorithms (e.g., KNN, SLFN) and DL approaches (e.g., CNN) on five public log anomaly detection datasets (e.g., HDFS). Our findings demonstrate that simple algorithms outperform DL methods in both time efficiency and accuracy. For instance, on the Thunderbird dataset, the K-nearest neighbor algorithm trains 1,000 times faster than NeuralLog while achieving a higher F1-Score by 0.0625. We also identify three factors contributing to this phenomenon, which are: (1) redundant log preprocessing strategies, (2) dataset simplicity, and (3) the nature of binary classification in log anomaly detection. To assess the necessity of DL, we propose LightAD, an architecture that optimizes training time, inference time, and performance score. With automated hyper-parameter tuning, LightAD allows * Pinjia He is the corresponding author.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f7a4d1db-9c93-4d77-8e3e-42bd67e91fb9Cited by top-tier papers1
Ask how each one uses itBuilds on8
- DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep LearningMin Du, Feifei Li, Guineng Zheng, Vivek SrikumarCCS 2017 · 1,823 citations
- Log-based Anomaly Detection Without Log ParsingVan-Hoang Le, Hongyu ZhangASE 2021 · 249 citations
- Semi-supervised Log-based Anomaly Detection via Probabilistic Label EstimationLin Yang, Junjie Chen, Zan Wang, Weijing Wang et al.ICSE 2021 · 216 citations
- Guidelines for Assessing the Accuracy of Log Message Template Identification TechniquesZanis Ali Khan, Donghwan Shin, Domenico Bianculli, Lionel C. BriandICSE 2022 · 77 citations
- SEAL: Storage-efficient Causality Analysis on Enterprise Logs with Query-friendly CompressionPeng Fei, Zhou Li, Zhiying Wang, Xiao Yu et al.USENIX Security 2021 · 45 citations
Related papers
- A Critical Review of Common Log Data Sets Used for Evaluation of Sequence-Based Anomaly Detection TechniquesMax Landauer, Florian Skopik, Markus WurzenbergerFSE 2024 · 44 citations
- Log-based Anomaly Detection with Deep Learning: How Far Are We?Van-Hoang Le, Hongyu ZhangICSE 2022 · 212 citations
- ADA: Adaptive Deep Log Anomaly DetectorYali Yuan, Sripriya Srikant Adhatarao, Mingkai Lin, Yachao Yuan et al.INFOCOM 2020 · 58 citations
- Efficient Zero-Shot and Label-free Log Anomaly Detection for Resource-Constrained SystemsZuohan Wu, Jiachuan Wang, Libin Zheng, Yongqi Zhang et al.ICDE 2026
- LogOnline: A Semi-Supervised Log-Based Anomaly Detector Aided with Online Learning MechanismXuheng Wang, Jiaxing Song, Xu Zhang, Junshu Tang et al.ASE 2023 · 12 citations
