about
K^4: Online Log Anomaly Detection via Unsupervised Typicality Learning (arxiv.org)
3 points by barthelomew on Jul 30, 2025 | hide | past | pdf | 1 comment on HN

In plain words: Each log is turned into four scores describing how typical it looks next to its nearest neighbors, letting a tiny detector flag odd logs without parsing or retraining. It beats usual detectors with 0.995–0.999 AUROC, training in seconds and scoring logs in microseconds.

Abstract · $K^4$: Online Log Anomaly Detection Via Unsupervised Typicality Learning

Existing Log Anomaly Detection (LogAD) methods are often slow, dependent on error-prone parsing, and use unrealistic evaluation protocols. We introduce $K^4$, an unsupervised and parser-independent framework for high-performance online detection. $K^4$ transforms arbitrary log embeddings into compact four-dimensional descriptors (Precision, Recall, Density, Coverage) using efficient k-nearest neighbor (k-NN) statistics. These descriptors enable lightweight detectors to accurately score anomalies without retraining. Using a more realistic online evaluation protocol, $K^4$ sets a new state-of-the-art (AUROC: 0.995-0.999), outperforming baselines by large margins while being orders of magnitude faster, with training under 4 seconds and inference as low as 4 $μ$s.

Weicong Chen, Vikash Singh, Zahra Rahmani, Debargha Ganguly, Mohsen Hariri, Vipin Chaudhary
arXiv:2507.20051 · cs.LG, cs.CL, cs.DC · submitted Jul 26, 2025
abstract · pdf · html

add comment on HN

> Abstract: [...] (K^4) transforms arbitrary log embeddings into compact four-dimensional descriptors (Precision, Recall, Density, Coverage) using efficient k-nearest neighbor (k-NN) statistics. These descriptors enable lightweight detectors to accurately score anomalies without retraining. Using a more realistic online evaluation protocol, sets a new state-of-the-art (AUROC: 0.995-0.999), outperforming baselines by large margins while being orders of magnitude faster, with training under 4 seconds and inference as low as 4 us.