Explainable Deep Learning Approach: Interpretation Between Detection and Root Cause Analysis of Distributed Log Anomalies with TLAN-EX

Authors

  • Iman Nasir University of Gujrat
  • Seemab Firdous University of Gujrat, Pakistan

DOI:

https://doi.org/10.32350/icr.61.01

Keywords:

Temporal logical Model, Anomaly detection, post-hoc attribution, Distributed system Logs, Explainable AI, Deep Learning, TCN-Transformer

Abstract

The deeper analysis into modern distributed banking environments has discovered that nowadays distributed log is facing challenges. This is because transaction data comes from multiple networked nodes, which makes a complete system behavior check difficult. This shows how complications grow when multiple system components produce logs at the same time. This gives rise to data inconsistencies that cause anomaly detection to be more difficult. The detection systems used nowadays show lower reliability due to high log volumes and logs that do not follow the standard format, and events showing no clear order, due to which the system raises alarms and fails to catch the real anomalies. Research into log anomaly detection by using Deep Learning (DL) models has shown positive results. However, distributed systems make it hard and difficult for real-life implementation. The current sequence models used in anomaly detection systems only identify one pattern type at a time between short-term and long-term patterns. This results in lower accuracy when different nodes produce dependent log data. The existing detection methods fail to give post-hoc explanations. This makes it hard for the analysts to understand the causes of anomalies, their starting point, and the cause. The current research is based on previous researches. The study implemented the TCN-Transformer hybrid system, which would be able to find patterns at both short and long-time scales in distributed log data. The system employs Parameter Entity Labeling (PEL) to enhance the working and quality of the preprocessing operations of the logs. The model adds three new elements, which include a post-hoc attribution module through SHAP and Integrated Gradients, a propagation analysis layer, and an overhead evaluation module. The model would result in improving the transparency and performance and might be able to cope with the issues as they arise. The designed (TLAN-EX) Temporal-Logical Attention Network with Explainability model has the capability to achieve high accuracy and present clear explanations and low response time. The study revealed that the hybrid learning approach assists in enhancing multi-node anomaly detection and SHAP and Integrated Gradients help to justify the causes of anomalies. The propagation analysis is used to demonstrate the spread of system anomalies between nodes to indicate the detailed working pattern of the system. The system is analyzed to be at its optimal level as the model is highly functioning when the system is considered to be handling high traffic. The upgraded explanation capabilities and speed of detection of the model depict improved detection results and suit well in distributed financial systems.

Downloads

Download data is not yet available.
0

References

[1] M. Lyu, H. H. Gharakheili, and V. Sivaraman, “A Survey on Enterprise Network Security: Asset Behavioral Monitoring and Distributed Attack Detection,” Jun. 2023, doi: 10.1109/ACCESS.2024.3419068.

[2] N. S. Musa, N. M. Mirza, S. H. Rafique, A. M. Abdallah, and T. Murugan, “Machine Learning and Deep Learning Techniques for Distributed Denial of Service Anomaly Detection in Software Defined Networks - Current Research Solutions,” IEEE Access, vol. 12, pp. 17982–18011, 2024, doi: 10.1109/ACCESS.2024.3360868.

[3] “Cloud_Network_Anomaly_Detection_Using_Machine_and_Deep_Learning_Techniques_Recent_Research_Advancements”.

[4] A. Dehlaghi-Ghadim, M. H. Moghadam, A. Balador, and H. Hansson, “Anomaly Detection Dataset for Industrial Control Systems,” May 2023, [Online]. Available: http://arxiv.org/abs/2305.09678

[5] P. Han, H. Li, G. Xue, and C. Zhang, “Distributed system anomaly detection using deep learning-based log analysis,” Comput Intell, vol. 39, no. 3, pp. 433–455, Jun. 2023, doi: 10.1111/coin.12573.

[6] T. Sutthipanyo, T. Lamsan, W. Thawornsusin, and W. Susutti, “Log-Based Anomaly Detection Using CNN Model with Parameter Entity Labeling for Improving Log Preprocessing Approach,” in IEEE Region 10 Annual International Conference, Proceedings/TENCON, Institute of Electrical and Electronics Engineers Inc., 2023, pp. 914–919. doi: 10.1109/TENCON58879.2023.10322478.

[7] J. Shen, R. Tie, Z. Li, B. Liu, Z. Fan, and J. Lu, “Neural Network-Based Log Anomaly Detection Algorithm for 6G Wireless Integrated Cyber-Physical System,” Wirel Pers Commun, 2024, doi: 10.1007/s11277-024-11218-9.

[8] P. Ryciak, K. Wasielewska, and A. Janicki, “Anomaly Detection in Log Files Using Selected Natural Language Processing Methods,” Applied Sciences (Switzerland), vol. 12, no. 10, May 2022, doi: 10.3390/app12105089.

[9] N. Liao and Z. Liu, “Log Anomaly Detection Method Based on Transformer and Temporal Convolutional Networks,” IEEE Access, vol. 13, pp. 68547–68560, 2025, doi: 10.1109/ACCESS.2025.3561669.

[10] R. Ben Said, Z. Sabir, and I. Askerzade, “CNN-BiLSTM: A Hybrid Deep Learning Approach for Network Intrusion Detection System in Software Defined Networking with Hybrid Feature Selection,” vol. XX, 2017, doi: 10.1109/ACCESS.2022.Doi.

[11] S. Yan et al., “Log-Based Anomaly Detection with Transformers Pre-Trained on Large-Scale Unlabeled Data,” IEEE International Conference on Communications, pp. 2059–2064, 2024, doi: 10.1109/ICC51166.2024.10623067.

[12] S. Lundberg, S. M. Lundberg, P. G. Allen, and S.-I. Lee, “A Unified Approach to Interpreting Model Predictions,” 2017, doi: 10.48550/arXiv.1705.07874.

[13] M. Sundararajan, A. Taly, and Q. Yan, “Axiomatic Attribution for Deep Networks,” Jun. 2017, [Online]. Available: http://arxiv.org/abs/1703.01365

[14] A. Vaswani et al., “Attention Is All You Need,” 2023.

[15] Z. Yang and I. G. Harris, “LogLLaMA: Transformer-based log anomaly detection with LLaMA,” Mar. 2025, [Online]. Available: http://arxiv.org/abs/2503.14849

Downloads

Published

2026-06-25

How to Cite

Nasir Mehmood, I., & Firdous, S. (2026). Explainable Deep Learning Approach: Interpretation Between Detection and Root Cause Analysis of Distributed Log Anomalies with TLAN-EX. Innovative Computing Review, 6(1). https://doi.org/10.32350/icr.61.01

Issue

Section

Articles