Skip to content
Conference

FLMLog: A Federated LLM Framework for Unified Online Log Anomaly Detection

2026 · Poster Volume 0008 The 2026 Twenty-Second International Conference on Intelligent Computing July 23-26, 2026 Toronto, Canada · pp. 886-897 · 0 citations

TL;DR

A unified online log anomaly detection framework, FLMLog, which is based on federated Learning and large language model, and adopts a prefix-aware in-context learning (ICL) refinement strategy, which achieves an improvement in prefix caching efficiency.

Abstract

Anomaly detection plays a pivotal role in ensuring the reliability of modern large-scale distributed systems. However, traditional log anomaly detection systems are centralized, which poses the risk of privacy leakage during data transmission. Previous research mainly focuses on single-domain logs,requiring domain-specific models and retraining, which limits flexibility and scalability. Significant advancements have been made by Large Language Models (LLMs) in the domains of natural language understanding and automated content creation. However,they still face persistent problems, including substantial computational costs and inadequate availability of training data. The combination of Federated Learning (FL) and LLMs (federated LLMs) offers a solution by leveraging distributed data while protecting privacy, which positions it as an ideal choice for sensitive domains. In this paper, we propose a unified online log anomaly detection framework, FLMLog, which is based on federated Learning and large language model. To enhance the operational efficiency, the FLMLog framework adopts a prefix-aware in-context learning (ICL) refinement strategy. This strategy is specifically designed to refine both the selection of in-context examples and the per-mutation order of these examples, thereby achieving an improvement in prefix caching efficiency. Our experiments demonstrate that the FLMLog framework is rigorously evaluated on five publicly available production log datasets, and the results show that it achieves superior comprehen-sive performance, outperforming state-of-the-art methods in F1-score on four out of five datasets with remarkable improvements.

View source

Similar papers

Aug 2026

FedSE-1DSqueezeNet: a lightweight federated intrusion detection system for Internet of Things

FedSE-1DSqueezeNet is proposed, a lightweight federated IDS tailored for resource-constrained IoT environments, designed to optimize feature extraction efficiency under strict resource constraints and achieves detection accuracy exceeding that of state-of-the-art models.

Qi Zhou, Xuechun Mao, Ying Chen · 0 citations
Review Aug 2026

Federated Prompt Learning: A Unified Framework, Empirical Analysis, and Future Directions

A comprehensive survey of federated prompt learning (FPL) is presented to review recent advances in integrating the federated learning paradigm and large language models, while discussing security, privacy, and robustness issues and summarizing existing defense mechanisms.

Qinglin Yang, Chen Qiu, Hongyu Zhang et al. · 0 citations
Sep 2026

Scalable and Adaptive Log-based Anomaly Detection: A Synergistic Approach

System logs are critical for software reliability. While many automated log-based anomaly detection methods exist, they often falter in large-scale cloud systems due to high resource consumption and poor adaptability to evolving logs. In this paper, we present SeaLog, an accurate, lightweight, and adaptive log-based anomaly detection framework that synergistically integrates the efficiency of traditional data-driven methods with the zero/few-shot learning ability of large language models (LLMs). SeaLog consists of a lightweight detection agent and a backbone analyzer. The detection agent utilizes an n-gram probabilistic tree (NPT) for efficient anomaly detection. The backbone analyzer employs an LLM enhanced by in-context learning (ICL) to provide accurate and adaptive predictions, especially for unseen log data. Both components continuously benefit from anomalies confirmed by on-site engineers. We evaluate SeaLog on three public datasets (BGL, Thunderbird, and HDFS) and an industrial dataset, with multiple LLM backbones, including open-source models, to assess its robustness to model choice. SeaLog achieves strong effectiveness across all datasets (F1 scores of 0.949–0.999), runs 2× to 5× faster, and consumes only 5% to 41% of the memory resources. Furthermore, we have successfully deployed SeaLog in Huawei Cloud, from which we share our insights and experiences during this deployment.

Jinyang Liu, Junjie Huang, Zhihan Jiang et al. · 0 citations
Review Aug 2026

Federated Learning for Large Language Models: Opportunities, Challenges, and Open Research Directions

This survey provides a comprehensive overview of existing research at the intersection of LLMs and FL, and outlines promising future research directions to advance the scalability, efficiency, and ethical deployment of LLMs in federated settings, paving the way for more trustworthy and privacy-preserving natural language processing systems.

Fatiha Ait Baali, Chaima Lhasnaoui, Addi Ait-Mlouk et al. · 0 citations
Review Open access Aug 2026

A review of federated learning: architectures, challenges, and targeted solutions

A review of federated learning through a structured taxonomy that covers its core architectural paradigms, major learning types, model training approaches, and aggregation mechanisms, and analyzes the principal challenges confronting FL, including privacy and security risks, statistical and system heterogeneity, communication constraints, and global model divergence.

Mahdiyeh Velaei, Hosna Ghahramani, Ali Ghaffari et al. · 0 citations
Open access Aug 2026

FedVAR: Prototype-aligned federated framework for Video Anomaly Recognition

In the era of Industrial Internet of Things (IIoT) and Cyber-Physical Systems (CPS), Federated Learning (FL) offers a promising decentralized intelligence paradigm for Video Anomaly Recognition (VAR). This task is vital for maintaining high-fidelity Digital Twins and ensuring safety in mission-critical environments. However, the inherent data heterogeneity across distributed edge clients leads to a fundamental challenge known as semantic misalignment, where clients learn divergent feature representations of"normal"and"abnormal"events. The problem becomes particularly pronounced in VAR, where the presence of diverse and fine-grained anomaly categories leads each client to develop distinct semantic interpretations of abnormality. Existing federated methods primarily focus on binary anomaly detection and fail to address this misalignment, preventing effective fine-grained recognition. In this paper, we introduce FedVAR, a weakly-supervised FL framework explicitly designed for VAR. Leveraging the rich representations of Vision-Language Models (VLMs), FedVAR employs a prototype-based alignment mechanism that creates a shared semantic anchor for all clients to re-center and align their visual and textual feature spaces. This process enforces a consistent representation of"normality"across the decentralized network, directly mitigating semantic misalignment and enabling robust prompt-learning of anomaly direction vectors with minimal communication overhead. We conduct extensive experiments on challenging benchmarks under various non-IID data partitioning schemes, unseen domains, and novel anomaly classes. The results demonstrate that FedVAR consistently outperforms state-of-the-art federated baselines, establishing a robust framework for distributed intelligence in video-based CPS.

Ghani Haider, Majid Kundroo, Boyun Eom et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.