{"id":"https://openalex.org/W4407639226","doi":"https://doi.org/10.1109/tnsm.2025.3542595","title":"DRLLog: Deep Reinforcement Learning for Online Log Anomaly Detection","display_name":"DRLLog: Deep Reinforcement Learning for Online Log Anomaly Detection","publication_year":2025,"publication_date":"2025-02-17","ids":{"openalex":"https://openalex.org/W4407639226","doi":"https://doi.org/10.1109/tnsm.2025.3542595"},"language":"en","primary_location":{"id":"doi:10.1109/tnsm.2025.3542595","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnsm.2025.3542595","pdf_url":null,"source":{"id":"https://openalex.org/S173527311","display_name":"IEEE Transactions on Network and Service Management","issn_l":"1932-4537","issn":["1932-4537","2373-7379"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Network and Service Management","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5056068917","display_name":"Junwei Zhou","orcid":"https://orcid.org/0000-0002-6094-1203"},"institutions":[{"id":"https://openalex.org/I4210123088","display_name":"Wuhan Technology and Business University","ror":"https://ror.org/0348f9w08","country_code":"CN","type":"education","lineage":["https://openalex.org/I4210123088"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Junwei Zhou","raw_affiliation_strings":["Sanya Science and Education Innovation Park, School of Computer Science and Artificial Intelligence, Wuhan University of Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"Sanya Science and Education Innovation Park, School of Computer Science and Artificial Intelligence, Wuhan University of Technology, Wuhan, China","institution_ids":["https://openalex.org/I4210123088"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103189091","display_name":"Yuyang Gao","orcid":"https://orcid.org/0000-0002-8045-2001"},"institutions":[{"id":"https://openalex.org/I196699116","display_name":"Wuhan University of Technology","ror":"https://ror.org/03fe7t173","country_code":"CN","type":"education","lineage":["https://openalex.org/I196699116"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuyang Gao","raw_affiliation_strings":["School of Computer and Artificial Intelligence, Wuhan University of Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Computer and Artificial Intelligence, Wuhan University of Technology, Wuhan, China","institution_ids":["https://openalex.org/I196699116"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5039626779","display_name":"Ying Zhu","orcid":"https://orcid.org/0000-0002-2534-290X"},"institutions":[{"id":"https://openalex.org/I196699116","display_name":"Wuhan University of Technology","ror":"https://ror.org/03fe7t173","country_code":"CN","type":"education","lineage":["https://openalex.org/I196699116"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ying Zhu","raw_affiliation_strings":["School of Computer and Artificial Intelligence, Wuhan University of Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Computer and Artificial Intelligence, Wuhan University of Technology, Wuhan, China","institution_ids":["https://openalex.org/I196699116"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5116295953","display_name":"Xiangtian Yu","orcid":"https://orcid.org/0009-0000-0142-0064"},"institutions":[{"id":"https://openalex.org/I196699116","display_name":"Wuhan University of Technology","ror":"https://ror.org/03fe7t173","country_code":"CN","type":"education","lineage":["https://openalex.org/I196699116"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiangtian Yu","raw_affiliation_strings":["School of Computer and Artificial Intelligence, Wuhan University of Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Computer and Artificial Intelligence, Wuhan University of Technology, Wuhan, China","institution_ids":["https://openalex.org/I196699116"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5108054841","display_name":"Yanchao Yang","orcid":"https://orcid.org/0000-0002-2447-7917"},"institutions":[{"id":"https://openalex.org/I196699116","display_name":"Wuhan University of Technology","ror":"https://ror.org/03fe7t173","country_code":"CN","type":"education","lineage":["https://openalex.org/I196699116"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yanchao Yang","raw_affiliation_strings":["School of Computer and Artificial Intelligence, Wuhan University of Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Computer and Artificial Intelligence, Wuhan University of Technology, Wuhan, China","institution_ids":["https://openalex.org/I196699116"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102746341","display_name":"Cheng Tan","orcid":"https://orcid.org/0000-0002-2110-9529"},"institutions":[{"id":"https://openalex.org/I196699116","display_name":"Wuhan University of Technology","ror":"https://ror.org/03fe7t173","country_code":"CN","type":"education","lineage":["https://openalex.org/I196699116"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Cheng Tan","raw_affiliation_strings":["School of Computer and Artificial Intelligence, Wuhan University of Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Computer and Artificial Intelligence, Wuhan University of Technology, Wuhan, China","institution_ids":["https://openalex.org/I196699116"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5016677170","display_name":"Jianwen Xiang","orcid":"https://orcid.org/0000-0001-8440-4181"},"institutions":[{"id":"https://openalex.org/I196699116","display_name":"Wuhan University of Technology","ror":"https://ror.org/03fe7t173","country_code":"CN","type":"education","lineage":["https://openalex.org/I196699116"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jianwen Xiang","raw_affiliation_strings":["School of Computer and Artificial Intelligence, Wuhan University of Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Computer and Artificial Intelligence, Wuhan University of Technology, Wuhan, China","institution_ids":["https://openalex.org/I196699116"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5056068917"],"corresponding_institution_ids":["https://openalex.org/I4210123088"],"apc_list":null,"apc_paid":null,"fwci":3.3873,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.90902299,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":95,"max":96},"biblio":{"volume":"22","issue":"3","first_page":"2382","last_page":"2395"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7480601072311401},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.7446368932723999},{"id":"https://openalex.org/keywords/reinforcement-learning","display_name":"Reinforcement learning","score":0.6629942059516907},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5071728229522705},{"id":"https://openalex.org/keywords/anomaly","display_name":"Anomaly (physics)","score":0.47848743200302124},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.3203366994857788},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.3202453553676605}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7480601072311401},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.7446368932723999},{"id":"https://openalex.org/C97541855","wikidata":"https://www.wikidata.org/wiki/Q830687","display_name":"Reinforcement learning","level":2,"score":0.6629942059516907},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5071728229522705},{"id":"https://openalex.org/C12997251","wikidata":"https://www.wikidata.org/wiki/Q567560","display_name":"Anomaly (physics)","level":2,"score":0.47848743200302124},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3203366994857788},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3202453553676605},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C26873012","wikidata":"https://www.wikidata.org/wiki/Q214781","display_name":"Condensed matter physics","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tnsm.2025.3542595","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnsm.2025.3542595","pdf_url":null,"source":{"id":"https://openalex.org/S173527311","display_name":"IEEE Transactions on Network and Service Management","issn_l":"1932-4537","issn":["1932-4537","2373-7379"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Network and Service Management","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G5796742757","display_name":null,"funder_award_id":"2022YFB3104001","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"}],"funders":[{"id":"https://openalex.org/F4320335777","display_name":"National Key Research and Development Program of China","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":39,"referenced_works":["https://openalex.org/W379212275","https://openalex.org/W2107263349","https://openalex.org/W2563351168","https://openalex.org/W2767094836","https://openalex.org/W2914688415","https://openalex.org/W2947815220","https://openalex.org/W2956530858","https://openalex.org/W2963351448","https://openalex.org/W2965838158","https://openalex.org/W3041566370","https://openalex.org/W3084140551","https://openalex.org/W3093426589","https://openalex.org/W3105248300","https://openalex.org/W3105440105","https://openalex.org/W3126389064","https://openalex.org/W3128318087","https://openalex.org/W3129163867","https://openalex.org/W3142047070","https://openalex.org/W3144041472","https://openalex.org/W3170081951","https://openalex.org/W3177323791","https://openalex.org/W3192478068","https://openalex.org/W3212483529","https://openalex.org/W4220747123","https://openalex.org/W4226065059","https://openalex.org/W4280511999","https://openalex.org/W4312454513","https://openalex.org/W4312673899","https://openalex.org/W4362650357","https://openalex.org/W4376288669","https://openalex.org/W4383503926","https://openalex.org/W6631190155","https://openalex.org/W6632550495","https://openalex.org/W6712994927","https://openalex.org/W6731031554","https://openalex.org/W6748304690","https://openalex.org/W6779068807","https://openalex.org/W6791783797","https://openalex.org/W6796581206"],"related_works":["https://openalex.org/W2806741695","https://openalex.org/W4290647774","https://openalex.org/W3189286258","https://openalex.org/W3207797160","https://openalex.org/W3210364259","https://openalex.org/W4300558037","https://openalex.org/W2667207928","https://openalex.org/W2912112202","https://openalex.org/W4377864969","https://openalex.org/W3120251014"],"abstract_inverted_index":{"System":[0],"logs":[1,36],"record":[2],"the":[3,45,75,87,102,121,146,151,169,175,188,195,207],"system\u2019s":[4],"status":[5],"and":[6,15,37,93,118,127,202,217,245,251],"application":[7],"behavior,":[8],"providing":[9],"support":[10],"for":[11,21],"various":[12,95],"system":[13],"management":[14],"diagnostic":[16],"tasks.":[17],"However,":[18],"existing":[19],"methods":[20],"log":[22,78,91,116,131,212],"anomaly":[23,46],"detection":[24,47],"face":[25],"several":[26],"challenges,":[27,52],"including":[28,214],"limitations":[29],"in":[30,39,145,156,225,242,249],"recognizing":[31],"current":[32,122],"types":[33],"of":[34,120,150,168,190,197,223,240],"anomalous":[35,66,191,203],"difficulties":[38],"performing":[40],"online":[41,161,232],"incremental":[42],"updates":[43],"to":[44,64,100,129,153,183,228],"models.":[48],"To":[49],"address":[50],"these":[51],"this":[53,109],"paper":[54],"introduces":[55,136,180],"DRLLog,":[56],"which":[57],"applies":[58],"Deep":[59,70],"Reinforcement":[60],"Learning":[61],"(DRL)":[62],"networks":[63],"detect":[65],"events.":[67],"DRLLog":[68,111,135,179,235],"uses":[69],"Q":[71],"Network":[72],"(DQN)":[73],"as":[74,81,106,254],"agent,":[76],"with":[77,86],"entries":[79],"serving":[80],"reward":[82,103],"signals.":[83],"By":[84],"interacting":[85],"environment":[88],"generated":[89],"from":[90,114],"data":[92,117],"adopting":[94],"action":[96],"behaviors,":[97],"it":[98],"aims":[99],"maximize":[101],"value":[104],"obtained":[105],"feedback.":[107],"Through":[108],"approach,":[110],"achieves":[112,236],"learning":[113,126,187],"historical":[115],"perception":[119],"environment,":[123],"enabling":[124],"continuous":[125],"adaptation":[128,138],"different":[130],"sequence":[132],"patterns.":[133],"Additionally,":[134],"low-rank":[137,142,165],"by":[139],"using":[140],"two":[141],"parameter":[143,166,243],"matrices":[144,167],"fully":[147],"connected":[148],"layer":[149],"DQN":[152],"represent":[154],"changes":[155],"its":[157],"weight":[158],"matrix.":[159],"During":[160,231],"model":[162,170,233],"learning,":[163,234],"only":[164],"are":[171],"updated,":[172],"effectively":[173,193],"reducing":[174],"model\u2019s":[176],"overhead.":[177],"Furthermore,":[178],"focal":[181],"loss":[182],"focus":[184],"more":[185],"on":[186,209],"features":[189],"logs,":[192],"addressing":[194],"issue":[196],"imbalanced":[198],"quantities":[199],"between":[200],"normal":[201],"logs.":[204],"We":[205],"evaluated":[206],"performance":[208],"widely":[210],"used":[211],"datasets,":[213],"HDFS,":[215],"BGL":[216],"ThunderBird,":[218],"showing":[219],"an":[220,237],"average":[221,238],"improvement":[222],"3%":[224],"F1-Score":[226],"compared":[227],"baseline":[229],"methods.":[230],"reduction":[239],"90%":[241],"count":[244],"a":[246],"significant":[247],"decrease":[248],"training":[250],"testing":[252],"time":[253],"well.":[255]},"counts_by_year":[{"year":2025,"cited_by_count":2}],"updated_date":"2026-03-04T09:10:02.777135","created_date":"2025-10-10T00:00:00"}
