500 rub
Journal Neurocomputers №4 for 2026 г.
Article in number:
Evaluation of neural network methods for detecting anomalies in the logs of systems with a microservice architecture
Type of article: scientific article
DOI: https://doi.org/10.18127/j19998554-202604-05
UDC: 303.732.4
Authors:

E.A. Shamarina1, A.I. Guseva2, S.D. Kulik3
1–3 National Research Nuclear University MEPhI (Moscow, Russia)

1 ek-polit@yandex.ru, 2 aiguseva@mephi.ru, 3 sedmik@mail.ru

Abstract:

Analyzing logs generated by microservice systems is becoming a crucial task for ensuring operational stability and predictability. The rapid growth of services, the diversity of log formats, the high level of noise in the data, and the constant fluctuations in the data flow complicate the application of traditional analysis methods based on static rules, regular expressions, and manual event classification. Modern machine learning methods are one of the most promising solutions for quickly adapting to changing log structures. Selecting optimal neural network architectures for the conditions typical of microservice systems remains a pressing issue: large event flows, data heterogeneity, response time constraints, and the need for resilience to format changes.

The goal of the article is to conduct an experimental test of neural network models for automatic classification and detection of anomalies in microservice system logs.

The study have analyzed five neural network models trained on a common subset of approximately 800 logs containing three event types: normal, error, and anomaly. All models have been trained under identical conditions and evaluated using precision, recall, and F1-score metrics. The LSTM model demonstrated consistent average performance (F1 = 0.83), confidently identifying patterns in log sequences but occasionally missing rare anomalies. The CNN model identified a wider range of errors due to local text features (recall = 0.82) but was inferior in accuracy (precision = 0.76). The transformer-like model demonstrated comparable results (F1 = 0.81), but its quality was limited by the small volume of training data. The autoencoder demonstrated high accuracy (precision = 0.94) but low recall (recall = 0.46), which is typical for models that work only with normal logs and respond primarily to pronounced text deviations. The best result has been achieved by the multimodal model (F1 = 0.86), which combines log text and numerical metrics (latency, retries, db_latency). This approach allowed for consideration of both the semantic component of messages and infrastructure parameters, improving the detection of complex anomalies. This result is consistent with international studies, where multimodal architectures demonstrate a 15–25% accuracy advantage over similar models. The results of the study can be used in the development and implementation of automated monitoring systems for microservice architectures, ensuring an increase in the speed of error and anomaly detection, as well as facilitating the selection of the most appropriate neural network model for a specific operating environment, based on logging features, load, and response time requirements.

Pages: 54-67
For citation

Shamarina E.A., Guseva A.I., Kulik S.D. Evaluation of neural network methods for detecting anomalies in the logs of systems with a microservice architecture // Neurocomputers. 2026. V. 28. № 4. P. 54–67. DOI: https://doi.org/10.18127/j19998554-202604-05

References
  1. Microservices architecture market report by component (solutions, service), deployment type (on-premises, cloud-based), organization size (large enterprises, small and medium-sized enterprises), industry vertical (BFSI, manufacturing, retail and E-commerce, IT and telecom, healthcare, government, and others), and region 2025-2033. 2025.
  2. KITRUM. Is microservice architecture still a trend? [Elektronnyj resurs]. URL: https://kitrum.om/blog/is-microservice-architecture-still-a-trend/ (data obrashcheniya: 28.10.2025).
  3. Shkodyrev V.P., Yagafarov K.I., Bashtovenko V.A. et al. The overview of anomaly detection methods in data streams. Proceedings of the Second Conference on Software Engineering and Information Management (SEIM-2017). Saint Petersburg, Russia. 2017. P. 7 [Elektronnyj resurs]. URL: https://ceur-ws.org/Vol-1864/paper_33.pdf (data obrashcheniya: 28.11.2025).
  4. D'yakonov A.G., Golovina A.M. Vyyavlenie anomalij v rabote mekhanizmov metodami mashinnogo obucheniya. Trudy XIX Mezhdunar. konf. «Analitika i upravlenie dannymi v oblastyakh s intensivnym ispol'zovaniem dannykh». Moskva. 2017. S. 389–396. (in Russian)
  5. Shcheglevatykh R.V., Sysoev A.S. Matematicheskaya model' obnaruzheniya anomal'nykh nablyudenij s ispol'zovaniem analiza chuvst­vitel'nosti nejronnoj seti. Modelirovanie, optimizatsiya i informatsionnye tekhnologii. 2020. T. 8. № 1. Id 725 [Elektronnyj resurs]. URL: https://moit.vivt.ru/wp-content/uploads/2020/02/ScheglevatychSysoev_1_20_1.pdf. (in Russian)
  6. Wang S., Balarezo J.F., Kandeepan S. et al. Machine learning in network anomaly detection: Survey. IEEE Access. 2021. V. 9. DOI: 10.1109/ACCESS.2021.3126834.
  7. Ardabili S., Mosavi A., Várkonyi-Kóczy A.R. Advances in machine learning modeling reviewing hybrid and ensemble methods. International conference on global research and education. Cham: Springer International Publishing. 2019. P. 215–227.
  8. Shkodyrev V.P., Yagafarov K.I., Bashtovenko V.A. i dr. Obzor metodov obnaruzheniya anomalij v potokakh dannykh. Sb. trudov Shestnadtsatoj Mezhdunar. konf. «Upravlenie razvitiem krupnomasshtabnykh sistem (MLSD'2023). M.: Institut problem upravleniya im. V.A. Trapeznikova RAN. 2023. S. 763–767. DOI: 10.25728/mlsd.2023.0763. (in Russian)
  9. Zhuravlev V.V. Obzor razlichnykh algoritmov mashinnogo obucheniya v zadachakh obnaruzheniya i ispravleniya oshibok dannykh. Universum: tekhnicheskie nauki: Elektron. nauch. zhurnal. 2024. № 8 (125). DOI: 10.32743/UniTech.2024.125.8.18127. (in Russian)
  10. Shelukhin O.I., Kostin D.V. Monitoring anomal'nykh sostoyanij komp'yuternykh sistem sredstvami intellektual'nogo analiza dannykh sistemnykh zhurnalov. Nejrokomp'yutery: razrabotka, primenenie. 2020. T. 22. № 2. S. 53–65. (in Russian)
  11. Li Y., Chen X., Jin R. et al. Deep autoencoding models for unsupervised anomaly detection in system logs. arXiv:1804.04488v1. 2019.
  12. Lu S., Wei L. Detecting anomaly in big data system logs using convolutional neural network. IEEE 16th International Conference on Dependable, Autonomic and Secure Computing. Athens, Greece. 2018. P. 151–158.
  13. Du M., Li F., Zheng G. et al. DeepLog: Anomaly detection and diagnosis from system logs through deep learning. Proceedings of the ACM Conference on Computer and Communications Security (CCS). 2017.
  14. Guo H., Li Z., Zhao J. et al. LogBERT: Log anomaly detection via BERT. International Joint Conference on Neural Networks (IJCNN). Shenzhen, China. 2021. P. 1–8.
  15. Xu W., Jiang J., Wang C. et al. Multi-modal anomaly detection using logs and system metrics. 2022.
  16. Sakurada M., Yairi T. Anomaly detection using autoencoders. Proceedings of the MLSDA 2014 2nd Workshop on Machine Learning for Sensory Data Analysis. 2014. P. 4–11.
  17. Liu F.T., Ting K.M., Zhou Z.-H. Isolation Forest. Eighth IEEE International Conference on Data Mining. Pisa, Italy. 2008. P. 413–422.
  18. Yumoto S., Kitsukawa T., Moro A. et al. Anomaly detection from images in pipes using GAN. Robomech Journal. 2023. № 10. DOI: 10.1186/s40648-023-00246-y.
  19. Zhilenkov A.A., Silkin A.A., Serebryakov M.Yu., Kolesova S.V. Sravnitel'nyj analiz sistem glubokogo obucheniya s podkrepleniem i sistem obucheniya s uchitelem. Izvestiya TulGU. Tekhnicheskie nauki. 2022. № 10. S. 109–112. (in Russian)
  20. Dubrovina A.I. Gibridnyj metod modelirovaniya sistem iskusstvennogo intellekta dlya vyyavleniya kiberatak. Vestnik Dagestanskogo gosudarstvennogo tekhnicheskogo universiteta. Tekhnicheskie nauki. 2025. T. 52. № 2. S. 81–89. DOI: 10.21822/2073-6185-2025-52-2-81-89. (in Russian)
Date of receipt: 15.01.2026
Approved after review: 20.02.2026
Accepted for publication: 29.06.2026