SGALAD: Subgraph-Guided Adaptation for Log Anomaly Detection Across Domains
Abstract
Cross-system log anomaly detection must handle changing event vocabularies, dependencies, and anomaly distributions with few target labels. We present SGALAD (Subgraph-Guided Adaptation for Log Anomaly Detection), which learns local event subgraphs and adapts a frozen graph representation. It selects seed events, refines neighborhoods, and fuses local features through attention. Target adaptation updates a projection, classifier, and domain discriminator while preserving the source-trained extractor. On BGL-to-Thunderbird and Thunderbird-to-BGL transfer, SGALAD achieves 10-shot F1 of and , exceeding size-matched random-subgraph adaptation by 7.90 and 5.50 points. Across 5, 10, and 20 labeled windows per class, it outperforms full GNN fine-tuning. SGALAD updates 0.06 million parameters (4.8% of the full-GNN trainable count), with approximately 8.6–8.8 times shorter measured adaptation time. Fixed-representation discrepancy and fixed-feature estimation bounds motivate both design choices. These results support learned local selection for efficient cross-system adaptation.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.