Back to results

University of Tennessee at Chattanooga

Log file anomaly detection using knowledge graphs and graph neural networks

Abstract

dc:description.abstract

Log files contain valuable information for detecting abnormal behavior. To detect anomalies, researchers have proposed representing log files as knowledge graphs (KGs) and using KG completion (KGC) techniques to predict new facts. However, current research in this area is limited, and there is no end-to-end system that includes both KG generation and KGC for log-based anomaly detection. In this study, we present an end-to-end system that utilizes graph neural networks (GNNs) and KGC to detect anomalies in log files. The proposed system has two main components. The first component employs templates to generate a KG from logs that capture normal behavior. The second component applies KG embedding models enhanced with GNN layers to the generated KG and employs KGC to determine suspiciousness of new information through binary classification. We evaluated the proposed method using two public datasets with standard KGC metrics. The experimental results demonstrate its promising potential.

Degree

thesis:*
Grantor dc:publisher
University of Tennessee at Chattanooga

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Payne, Lucas
Contributors dc:contributor
  • Xie, Mengjun
  • Qin, Hong; Yang, Li
  • College of Engineering and Computer Science

Subjects

dc:subject × 3

Rights

dc:rights
Language dc:language
English, eng

Identifiers

dc:identifier.*
Repository record dc:identifier
https://scholar.utc.edu/theses/829
OAI identifier oai:identifier
oai:scholar.utc.edu:theses-2010

Chain of custody

source
Harvested from
University of Tennessee - Chattanooga
Base URL
scholar.utc.edu/do/oai/
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Payne, Lucas. Log file anomaly detection using knowledge graphs and graph neural networks. University of Tennessee at Chattanooga, https://scholar.utc.edu/theses/829