2026· Poster Volume 0008 The 2026 Twenty-Second International Conference on Intelligent Computing July 23-26, 2026 Toronto, Canada· pp. 886-897· 0 citations
TL;DR
A unified online log anomaly detection framework, FLMLog, which is based on federated Learning and large language model, and adopts a prefix-aware in-context learning (ICL) refinement strategy, which achieves an improvement in prefix caching efficiency.
Abstract
Anomaly detection plays a pivotal role in ensuring the reliability of modern large-scale distributed systems. However, traditional log anomaly detection systems are centralized, which poses the risk of privacy leakage during data transmission. Previous research mainly focuses on single-domain logs,requiring domain-specific models and retraining, which limits flexibility and scalability. Significant advancements have been made by Large Language Models (LLMs) in the domains of natural language understanding and automated content creation. However,they still face persistent problems, including substantial computational costs and inadequate availability of training data. The combination of Federated Learning (FL) and LLMs (federated LLMs) offers a solution by leveraging distributed data while protecting privacy, which positions it as an ideal choice for sensitive domains. In this paper, we propose a unified online log anomaly detection framework, FLMLog, which is based on federated Learning and large language model. To enhance the operational efficiency, the FLMLog framework adopts a prefix-aware in-context learning (ICL) refinement strategy. This strategy is specifically designed to refine both the selection of in-context examples and the per-mutation order of these examples, thereby achieving an improvement in prefix caching efficiency. Our experiments demonstrate that the FLMLog framework is rigorously evaluated on five publicly available production log datasets, and the results show that it achieves superior comprehen-sive performance, outperforming state-of-the-art methods in F1-score on four out of five datasets with remarkable improvements.
FedSE-1DSqueezeNet is proposed, a lightweight federated IDS tailored for resource-constrained IoT environments, designed to optimize feature extraction efficiency under strict resource constraints and achieves detection accuracy exceeding that of state-of-the-art models.
A comprehensive survey of federated prompt learning (FPL) is presented to review recent advances in integrating the federated learning paradigm and large language models, while discussing security, privacy, and robustness issues and summarizing existing defense mechanisms.
Qinglin Yang, Chen Qiu, Hongyu Zhang et al.· 0 citations
System logs are critical for software reliability. While many automated log-based anomaly detection methods exist, they often falter in large-scale cloud systems due to high resource consumption and poor adaptability to evolving logs. In this paper, we present SeaLog, an accurate, lightweight, and adaptive log-based anomaly detection framework that synergistically integrates the efficiency of traditional data-driven methods with the zero/few-shot learning ability of large language models (LLMs). SeaLog consists of a lightweight detection agent and a backbone analyzer. The detection agent utilizes an n-gram probabilistic tree (NPT) for efficient anomaly detection. The backbone analyzer employs an LLM enhanced by in-context learning (ICL) to provide accurate and adaptive predictions, especially for unseen log data. Both components continuously benefit from anomalies confirmed by on-site engineers. We evaluate SeaLog on three public datasets (BGL, Thunderbird, and HDFS) and an industrial dataset, with multiple LLM backbones, including open-source models, to assess its robustness to model choice. SeaLog achieves strong effectiveness across all datasets (F1 scores of 0.949–0.999), runs 2× to 5× faster, and consumes only 5% to 41% of the memory resources. Furthermore, we have successfully deployed SeaLog in Huawei Cloud, from which we share our insights and experiences during this deployment.
Jinyang Liu, Junjie Huang, Zhihan Jiang et al.· ACM Transactions on Software...· 0 citations
This survey provides a comprehensive overview of existing research at the intersection of LLMs and FL, and outlines promising future research directions to advance the scalability, efficiency, and ethical deployment of LLMs in federated settings, paving the way for more trustworthy and privacy-preserving natural language processing systems.
Fatiha Ait Baali, Chaima Lhasnaoui, Addi Ait-Mlouk et al.· Machine-mediated learning· 0 citations
A review of federated learning through a structured taxonomy that covers its core architectural paradigms, major learning types, model training approaches, and aggregation mechanisms, and analyzes the principal challenges confronting FL, including privacy and security risks, statistical and system heterogeneity, communication constraints, and global model divergence.
Mahdiyeh Velaei, Hosna Ghahramani, Ali Ghaffari et al.· Cluster Computing· 0 citations
In the era of Industrial Internet of Things (IIoT) and Cyber-Physical Systems (CPS), Federated Learning (FL) offers a promising decentralized intelligence paradigm for Video Anomaly Recognition (VAR). This task is vital for maintaining high-fidelity Digital Twins and ensuring safety in mission-critical environments. However, the inherent data heterogeneity across distributed edge clients leads to a fundamental challenge known as semantic misalignment, where clients learn divergent feature representations of"normal"and"abnormal"events. The problem becomes particularly pronounced in VAR, where the presence of diverse and fine-grained anomaly categories leads each client to develop distinct semantic interpretations of abnormality. Existing federated methods primarily focus on binary anomaly detection and fail to address this misalignment, preventing effective fine-grained recognition. In this paper, we introduce FedVAR, a weakly-supervised FL framework explicitly designed for VAR. Leveraging the rich representations of Vision-Language Models (VLMs), FedVAR employs a prototype-based alignment mechanism that creates a shared semantic anchor for all clients to re-center and align their visual and textual feature spaces. This process enforces a consistent representation of"normality"across the decentralized network, directly mitigating semantic misalignment and enabling robust prompt-learning of anomaly direction vectors with minimal communication overhead. We conduct extensive experiments on challenging benchmarks under various non-IID data partitioning schemes, unseen domains, and novel anomaly classes. The results demonstrate that FedVAR consistently outperforms state-of-the-art federated baselines, establishing a robust framework for distributed intelligence in video-based CPS.
Ghani Haider, Majid Kundroo, Boyun Eom et al.· Future generations computer...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.