高级检索

    面向物联网终端的云边协同日志异常检测技术

    Log Anomaly Detection Technology for IoT Terminal Devices

    • 摘要: 随着物联网终端设备在工业控制、智能交通、智能家居和智慧医疗等场景中的广泛部署,边缘侧持续产生海量半结构化日志。现有方法要么依赖日志模板ID和浅层序列模型,难以建模复杂语义;要么依赖大规模预训练模型,难以满足终端设备对实时性与资源消耗的约束。针对上述问题,本文提出一种面向物联网终端设备的日志异常检测技术。首先,设计基于BERT与Llama的语义增强检测模型,采用正则替换与窗口化建模抑制动态参数噪声,通过语义投影模块实现编码器和解码器表示空间对齐,并利用三阶段微调提升序列级异常判别能力。其次,构建面向终端设备的云边协同检测框架,提出两阶段置信度蒸馏与时延敏感动态路由策略,使边缘小模型承担大部分低成本检测任务,仅将低置信度样本上传云端大模型复核在HDFS、BGL和Thunderbird公开数据集上的实验表明,所提语义检测模型的F1值分别达到99.7%、91.6%和96.6%;云边协同框架在保持95.5%总体F1值的同时,仅需平均26.6%的云端路由比例,相当于降低73.4%的大模型调用量。

       

      Abstract: With the widespread deployment of IoT terminal devices in scenarios such as industrial control, intelligent transportation, smart homes, and smart healthcare, massive amounts of semi-structured logs are continuously generated at the edge. Existing methods either rely on log template IDs and shallow sequence models, making it difficult to model complex semantics, or rely on large-scale pre-trained models, which cannot meet the constraints of real-time performance and resource consumption of terminal devices. To address these issues, this paper proposes a log anomaly detection technology for IoT terminal devices. First, a semantic enhancement detection model based on BERT and Llama is designed, employing regularization replacement and windowing modeling to suppress dynamic parameter noise. A semantic projection module is used to align the representation spaces of the encoder and decoder, and a three-stage fine-tuning method is used to improve the sequence-level anomaly detection capability. Second, a cloud-edge collaborative detection framework for terminal devices is constructed, proposing a two-stage confidence distillation and latency-sensitive dynamic routing strategy. This allows the small edge model to undertake most of the low-cost detection tasks, with only low-confidence samples uploaded to the large cloud model for verification. Our experiments on the public datasets HDFS, BGL, and Thunderbird show that the proposed semantic detection model achieves F1 scores of 99.7%, 91.6%, and 96.6%, respectively. The cloud-edge collaborative framework maintains an overall F1 score of 95.5% while requiring only an average cloud routing ratio of 26.6%, which is equivalent to reducing the amount of large model calls by 73.4%.

       

    /

    返回文章
    返回