An Empirical Study of a PCA-Based Multivariate Framework for Interpretable Log Anomaly Detection
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F63839172%3A_____%2F25%3A10133839" target="_blank" >RIV/63839172:_____/25:10133839 - isvavai.cz</a>
Alternative codes found
RIV/00216305:26230/26:0198980
Result on the web
<a href="http://dx.doi.org/10.23919/CNSM67658.2025.11297507" target="_blank" >http://dx.doi.org/10.23919/CNSM67658.2025.11297507</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.23919/CNSM67658.2025.11297507" target="_blank" >10.23919/CNSM67658.2025.11297507</a>
Alternative languages
Result language
angličtina
Original language name
An Empirical Study of a PCA-Based Multivariate Framework for Interpretable Log Anomaly Detection
Original language description
Effective anomaly detection is crucial for increasingly complex system logs, yet current methods often face challenges with labeled data reliance, high computational costs, or limited interpretability. This paper empirically applies an established Multivariate Statistical Network Monitoring (MSNM) framework, which leverages Principal Component Analysis (PCA) with D and Q statistics, to the log anomaly detection domain. We evaluate its performance on three benchmark datasets (HDFS, BGL, Thunderbird), focusing on its semi-supervised nature (requiring only normal operational data), computational efficiency, interpretability via count vector feature contributions, and ease of deployment. Our results demonstrate competitive F1 scores comparable to some supervised and deep learning methods, maintaining low computational overhead without GPU dependency. Furthermore, its strong interpretability is showcased through case studies, identifying specific log event patterns causing anomalies. This study highlights the MSNM framework's potential as a practical, efficient, and interpretable solution for log anomaly detection.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
—
OECD FORD branch
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Result continuities
Project
<a href="/en/project/LM2023054" target="_blank" >LM2023054: e-Infrastructure CZ</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Others
Publication year
2025
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
Proceedings of the 2025 21st International Conference on Network and Service Management (CNSM)
ISBN
978-3-903176-75-1
ISSN
2165-963X
e-ISSN
—
Number of pages
6
Pages from-to
—
Publisher name
IEEE
Place of publication
NEW YORK
Event location
Bologna, Italy
Event date
Oct 27, 2025
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
—