KRONE derives semantic execution hierarchies from flat logs to enable modular multi-level anomaly detection with hybrid local and nested-aware detectors plus limited LLM use, delivering 10% F1 gains and over 100x data efficiency on benchmarks and industrial data.
Spell: Streaming parsing of system event logs
2 Pith papers cite this work. Polarity classification is still indexing.
years
2026 2representative citing papers
FAME achieves F1 of 98.16 on BGL and 99.95 on Thunderbird for message-level log anomaly detection using at most K=100 labels per template, reducing annotation effort by 76x while detecting anomalies from unseen EventIDs.
citing papers explorer
-
KRONE: Scalable LLM-Augmented Log Anomaly Detection via Hierarchical Abstraction
KRONE derives semantic execution hierarchies from flat logs to enable modular multi-level anomaly detection with hybrid local and nested-aware detectors plus limited LLM use, delivering 10% F1 gains and over 100x data efficiency on benchmarks and industrial data.
-
FAME: Failure-Aware Mixture-of-Experts for Message-Level Log Anomaly Detection
FAME achieves F1 of 98.16 on BGL and 99.95 on Thunderbird for message-level log anomaly detection using at most K=100 labels per template, reducing annotation effort by 76x while detecting anomalies from unseen EventIDs.