Siyang Lu

dblp:205/8775 · DBLP profile ↗
← Back
19ranked-venue papers
4as first author
17since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 8 · 1 first-author · 7 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 TraceHG: An Unsupervised Dual-View Framework for Microservice Anomaly Detection
abstract
Traces and logs record the behaviors and interactions between microservices, making them indispensable for diagnosing system anomalies. However, the intricate and flexible architecture of microservices presents significant challenges for automated anomaly detection. Existing approaches often struggle to capture the internal dynamics and correlations among microservices, which limits their ability to comprehensively detect anomalies arising from synchronous or asynchronous calls. Therefore, we categorize three prevalent anomaly paradigms in microservice systems: intra-service, inter-service, and joint anomalies. To address these challenges, we propose a novel unsupervised learning framework for dual-view anomaly detection, named TraceHG. Specifically, it constructs the trace graph composed of logs, response times, and traces. Besides, TraceHG utilizes hypergraph transformation to establish two views, providing comprehensive information in microservices. Furthermore, we introduce a dual-view framework that leverages both a hypergraph-view and a graph-view encoders to explicitly learn associations among microservices. These two views, employing graph and HGNNs, capture representations of internal dynamics, invocations, and their associated contexts in microservices. By constructing two minimized hyperspheres and measuring the distances from their centers in the latent space, we identify anomalies based on the anomaly scores. Extensive experiments on public benchmark datasets demonstrate that the proposed framework outperforms several state-of-the-art baselines in microservice anomaly detection.
Ningning Han, Siyang Lu, Zaichao Lin, Xin Luo 0001
IEEE Trans. Serv. Comput.2
2025 HeRF-AD: Robust Anomaly Detection for Software Systems via Heterogeneous Representation Fusion
Xiaoman Tan, Siyang Lu
ICA3PP (4)3
2024 Perturbing Attention Gives You More Bang for the Buck: Subtle Imaging Perturbations That Efficiently Fool Customized Diffusion Models
abstract
Diffusion models (DMs) embark a new era of generative modeling and offer more opportunities for efficient generating high-quality and realistic data samples. However, their widespread use has also brought forth new challenges in model security, which motivates the creation of more effective adversarial attackers on DMs to understand its vulnerability. We propose CAAT, a simple but generic and efficient approach that does not require costly training to effectively fool latent diffusion models (LDMs). The approach is based on the observation that cross-attention layers exhibits higher sensitivity to gradient change, allowing for leveraging subtle perturbations on published images to significantly corrupt the generated images. We show that a subtle perturbation on an image can significantly impact the cross-attention layers, thus changing the mapping between text and image during the fine-tuning of customized diffusion models. Extensive experiments demonstrate that CAAT is compatible with diverse diffusion models and out-performs baseline attack methods in a more effective (more noise) and efficient (twice as fast as Anti-DreamBooth and Mist) manner.
Jingyao Xu 0001, Yuetong Lu, Yandong Li, Siyang Lu, Dongdong Wang 0011, Wei Xiang 0007
CVPR4
2024 GLADformer: A Mixed Perspective for Graph-Level Anomaly Detection
Fan Xu 0009, Nan Wang 0015, Hao Wu 0094, Xuezhi Wen, Dalin Zhang 0003, Siyang Lu, Binyong Li, Wei Gong 0001, Hai Wan, Xibin Zhao
ECML/PKDD (6)6
2024 An Unsupervised Gradient-Based Approach for Real-Time Log Analysis From Distributed Systems
abstract
We consider the problem of real-time log anomaly detection for distributed system with deep neural networks by unsupervised learning. There are two challenges in this problem, including detection accuracy and analysis efficacy. To tackle these two challenges, we propose GLAD, a simple yet effective approach mining for anomalies in distributed systems. To ensure detection accuracy, we exploit the gradient features in a well-calibrated deep neural network and analyze anomalous pattern within log files. To improve the analysis efficacy, we further integrate one-class support vector machine (SVM) into anomalous analysis, which significantly reduces the cost of anomaly decision boundary delineation. This effective integration successfully solves both accuracy and efficacy in real-time log anomaly detection. Also, since anomalous analysis is based upon unsupervised learning, it significantly reduces the extra data labeling cost. We conduct a series of experiments to justify that GLAD has the best comprehensive performance balanced between accuracy and efficiency, which implies the advantage in tackling practical problems. The results also reveal that GLAD enables effective anomaly mining and consistently outperforms state-of-the-art methods on both recall and F1 scores.
Minquan Wang, Siyang Lu, Sizhe Xiao, Dongdong Wang 0011, Wei Xiang 0007, Ningning Han, Liqiang Wang 0001
Int. J. Cooperative Inf. Syst.2
2023 Probing Handwritten Manchu Word Recognition Foundation Model
abstract
Currently, there are several handwriting recognition models available that effectively address the challenge of Handwritten Text Recognition (HTR). However, majority of tasks require downstream training tailored for specific handwritten datasets. Relying solely on the foundation model may lead to subpar recognition performance. This problem is also encountered in Manchu handwritten text recognition. To overcome this challenge, researchers have been exploring different methods, such as data augmentation through image transformations. However, the existing fine-tuning datasets do not provide sufficient coverage of characters, which can result in weaker feature extraction and limit the improvement of the model. Additionally, creating a large-scale Manchu handwritten dataset is cost-prohibitive and challenging. In light of these constraints, we propose a novel approach that involves training a foundation model using existing large-scale datasets. This is achieved by freezing certain feature layers and conducting probing with the specific characteristics of Manchu handwritten scripts. This approach aims to enrich character features and improve diverse feature extraction capabilities of the model, which can enhance the generalization capabilities of the model to small-scale Manchu handwritten datasets. The experimental results demonstrate that our probing strategy achieves superior performance compared to the state-of-the-art AMRE foundation model. Furthermore, we conducted an ablation study and additional analyses to examine the effectiveness of the probing approach and uncover the underlying modeling patterns.
Siyang Lu, Wei Xiang 0007, Yingjun Qi
ICPADS2
2023 TransFlowLog: Log Anomaly Detection Based on Transformer Encoder and Interflow Decoder
abstract
Logs are valuable resources that record the health status of systems. Analyzing logs to uncover and investigate abnormal behaviors has become an essential approach of ensuring system security. However, some potential anomalies may be missed when performing log anomaly detection, and even a seemingly insignificant abnormal behavior can lead to a series of severe anomalies or continuous negative impact on the performance of systems. Therefore, the reliability and security of systems are facing significant challenges. To address this issue, in this study, we propose TransFlowLog, an Encoder-Decoder architecture-based approach for log anomaly detection. It utilizes the Transformer Encoder, a state-of-the-art sequence modeling technique, to comprehensively understand contextual relationships using self-attention mechanism. Moreover, we introduce the Interflow Decoder, which considers information exchange between channels in embedded log sequences. The Interflow Decoder enhances the features encoded by the Transformer Encoder in both sequence and channel dimensions, thereby capturing interdependence between different channels. Comparative experiments conducted on three real-world datasets demonstrate the effectiveness of the proposed method, as it achieves higher F1-score and reduces the number of false negatives.
Zaichao Lin, Siyang Lu, Ningning Han, Dongdong Wang 0011, Wei Xiang 0007, Mingquan Wang
ICPADS2
2023 Class-Adaptive Threshold for Class Imbalanced Semi-Supervised Learning
abstract
The recently proposed class-imbalanced semi-supervised learning (CISSL) algorithms achieved impressive performance by effectively leveraging unlabeled data. However, these algorithms often rely on a pre-defined fixed confidence threshold to filter unlabeled data during training, which overlooks the varying learning dynamics across different classes in class-imbalanced scenarios. Consequently, valuable data could be discarded, leading to degraded performance on minority classes. To tackle this issue, we introduce a novel method called Class-Adaptive Threshold (CAT), which dynamically defines and adjusts the confidence threshold based on the learning status of each class. The core idea of CAT is to iteratively update the thresholds for different classes at each time step, enabling us to fully exploit valuable information that would otherwise be ignored using fixed threshold algorithms. Importantly, CAT does not introduce any additional inference processes. In our experiments, the proposed algorithm achieves state-of-the-art performance on various class-imbalanced datasets. Furthermore, we show that CAT can be seamlessly integrated into the renowned CISSL algorithm, resulting in a remarkable boost in their performance.
Wei Xiang 0007, Siyang Lu, Weiwei Xing
ICPADS4
2023 The Art of Deception: Black-box Attack Against Text-to-Image Diffusion Model
abstract
With the rise of Foundation models, Text-to-Image models, as one of its important branches, have been increasingly applied. While focusing on the impressive generation capabilities of these models, it is also crucial to pay attention to the robustness of the models against attacks. In this paper, we shift our focus towards studying the vulnerability of Text-to-Image (T2I) models. To this end, we propose a black-box attack method and demonstrate that T2I models are susceptible to adversarial text attacks. Specifically, this method can disrupt T2I models by making subtle modifications to the model’s input (i.e., prompt) without accessing the model parameters, resulting in the generation of incorrect images. It is worth mentioning that we discovered the ability to switch different types of tokenizers within this black-box framework to handle text, furthermore, this attack framework can be applied to target different versions of T2I models. The experiments indicate that the images generated through adversarial text exhibit noticeable errors. We also employ CLIP score, a metric used to evaluate the similarity between images and image descriptions, to assess the results. The findings demonstrate a significant decrease in the visual-textual similarity after the model is subjected to attacks. Additionally, we have identified a specific type of error that T2I models tend to make when facing attacks – when confronted with unrecognizable text, the model often interprets it as human-related content. This paper not only highlights the vulnerability of T2I models to adversarial text attacks but also further discusses potential methods that could enhance the robustness of these attack techniques. This provides a valuable reference for future research directions in this field.
Yuetong Lu, Jingyao Xu 0001, Yandong Li, Siyang Lu, Wei Xiang 0007, Wei Lu 0010
ICPADS4
2023 SemLog: A Semantics-based Approach for Anomaly Detection in Big Data System Logs
abstract
Syslog-based anomaly detection is crucial for protecting the systems from malicious attacks or malfunctions. System logs are semi-structured text messages printed by logging statements to record the system’s run-time status, involving rich semantic information. However, the existing BERT-based log anomaly detection method is based on the log key sequence, does not consider the semantics of the log data, and discards the variable part, resulting in a high rate of missed detection. In this paper, we propose SemLog, a self-supervised framework for log anomaly detection based on BERT. By incorporating log semantics and variables and employing multi-feature fusion, we mitigate the independent assumption issue in the Masked Language Modeling model. The experimental results on three benchmarks show that SemLog achieves high performance compared with the state-of-the-art approaches for anomaly detection.
Xiaoman Tan, Ningning Han, Siyang Lu, Dongdong Wang 0011
ICPADS3
2023 Ensemble Distillation for Out-of-distribution Detection
abstract
Out-of-distribution detection is critical to a reliable application of deep neural networks. To reduce model uncertainty, we propose a simple yet effective approach of ensemble knowledge distillation. We blend ensemble model and knowledge distillation to improve model generalization on indomain recognition, thereby yielding accurate and robust out-of-distribution detection. The former effectively expands data recognition feature space, while the latter further regularizes the model through knowledge distillation, enhancing in-domain feature recognition. This effective integration successfully yields lower model uncertainty on in-domain feature recognition and improves anomaly detection in a more scalable manner. We justify our approach through extensive experiments on various benchmarks, demonstrating its significant improvement in out- of-distribution detection. We validate our approach with a variety of up-to-date DNNs, like Vision Transformer.
Dongdong Wang 0011, Jingyao Xu 0001, Siyang Lu, Wei Xiang 0007, Liqiang Wang 0001
ICPADS3
2023 Black-box attacks against log anomaly detection with adversarial examples
abstract
Deep neural networks (DNNs) have been widely employed to solve log anomaly detection and outperform a range of conventional methods. They have attained such striking success because they can usually explore and extract semantic information from a large volume of log data, which helps to infer complex log anomaly patterns more accurately. Despite its success in generalization accuracy, this data-driven approach can still suffer from a high vulnerability to adversarial attacks , which severely limits its practical use. To address this issue, several studies have proposed anomaly detectors to equip neural networks to improve their robustness. These anomaly detectors are built based on effective adversarial attack methods. Therefore, effective adversarial attack approaches are important for developing more efficient anomaly detectors, thereby improving neural network robustness. In this study, we propose two strong and effective black-box attackers, an attention-based and a gradient-based attacker, to defeat three target systems: MLP, AutoEncoder , and DeepLog. Our approach facilitates the generation of more effective adversarial examples with the help of the analysis of vulnerable logkeys. The proposed attention-based attacker leverages attention weights to achieve vulnerable logkeys and derive adversarial examples, which are implemented using our previously developed attention-based convolutional neural network model . The proposed gradient-based attacker calculates gradients based on potential vulnerable logkeys to seek an optimal adversarial sample. The experimental results showed that these two approaches significantly outperformed the state-of-the-art attacker model log anomaly mask (LAM). In particular, owing to its optimization, the proposed gradient-based attacker approach can significantly increase the misclassification rate on three target models, yields a 70% successful attack rate on DeepLog and greatly exceeds the baseline by 52%.
Siyang Lu, Mingquan Wang, Dongdong Wang 0011, Wei Xiang 0007, Sizhe Xiao, Ningning Han, Liqiang Wang 0001
Inf. Sci.1
2023 SSDLog: a semi-supervised dual branch model for log anomaly detection
abstract
Abstract With versatility and complexity of computer systems, warning and errors are inevitable. To effectively monitor system’s status, system logs are critical. To detect anomalies in system logs, deep learning is a promising way to go. However, abnormal system logs in the real world are often difficult to collect, and effectively and accurately categorize the logs is an even time-consuming project. Thus, the data incompleteness is not conducive to the deep learning for this practical application. In this paper, we put forward a novel semi-supervised dual branch model that alleviate the need for large scale labeled logs for training a deep system log anomaly detector. Specifically, our model consists of two homogeneous networks that share the same parameters, one is called weak augmented teacher model and the other is termed as strong augmented student model. In the teacher model, the log features are augmented with small Gaussian noise, while in the student model, the strong augmentation is injected to force the model to learn a more robust feature representation with the guidance of teacher model provided soft labels. Furthermore, to further utilize unlabeled samples effectively, we propose a flexible label screening strategy that takes into account the confidence and stability of pseudo-labels. Experimental results show favorable effect of our model on prevalent HDFS and Hadoop Application datasets. Precisely, with only 30% training data labeled, our model can achieve the comparable results as the fully supervised version.
Siyang Lu, Ningning Han, Mingquan Wang, Wei Xiang 0007, Zaichao Lin, Dongdong Wang 0011
World Wide Web (WWW)1
2022 AMRE: An Attention-Based CRNN for Manchu Word Recognition on a Woodblock-Printed Dataset
Siyang Lu, Mingquan Wang, Wei Xiang 0007, Yingjun Qi
ICONIP (2)2
2022 3LPR: A three-stage label propagation and reassignment framework for class-imbalanced semi-supervised learning
abstract
Semi-supervised learning (SSL) has been studied widely in standard benchmark datasets; however, real-world data often exhibit class-imbalanced distributions, which pose significant challenges for deep semi-supervised models. To address this issue, we design a three-stage learning framework, 3LPR, by combining unsupervised feature extraction, graph-based Label Propagation, and mixed data augmentation (MDA)-based label Reassignment. Specifically, we first explore the performance of supervised and unsupervised learning for feature extraction of class-imbalanced data and then establish our first stage of feature extraction through unsupervised learning. Then, we adopt graph network-based offline label propagation and sieving to effectively expand the labeled set to overcome the excessive label bias in the classifier during the training process. Finally, we propose a label reassignment (LRA) algorithm for class-imbalanced semi-supervised learning (CISSL) to train the expanded dataset, where the MDA strategy is adopted but with the label reassigned. The experimental results demonstrate that the proposed 3LPR framework for CISSL outperforms other state-of-the-art methods on various datasets.
Xiangyuan Kong, Wei Xiang 0007, Siyang Lu, Weiwei Xing, Wei Lu 0010
Knowl. Based Syst.5
2021 SODA: A Semantics-Aware Optimization Framework for Data-Intensive Applications Using Hybrid Program Analysis
abstract
In the era of data explosion, a growing number of data-intensive computing frameworks, such as Apache Hadoop and Spark, have been proposed to handle the massive volume of unstructured data in parallel. Since programming models provided by these frameworks allow users to specify complex and diversified user-defined functions (UDFs) with predefined operations, the grand challenge of tuning up entire system performance arises if programmers do not fully understand the semantics of code, data, and runtime systems. In this paper, we design a holistic semantics-aware (optimization for data-intensive applications using hybrid program analysis (SODA) to assist programmers to tune performance issues. SODA is a two-phase framework: the offline phase is a static analysis that analyzes code and performance profiling data from the online phase of prior executions to generate a parameterized and instrumented application; the online phase is a dynamic analysis that keeps track of the application's execution and collects runtime information of data and system. Extensive experimental results on four real-world Spark applications show that SODA can gain up to 60%, 10%, 8%, faster than its original implementation, with the three proposed optimization strategies, i.e., cache management, operation reordering, and element pruning, respectively.
BingBing Rao, Zixia Liu, Hong Zhang 0047, Siyang Lu, Liqiang Wang 0001
CLOUD4
2021 FMixCutMatch for semi-supervised deep learning
Wei Xiang 0007, Xiaotao Wei, Xiangyuan Kong, Siyang Lu, Weiwei Xing, Wei Lu 0010
Neural Networks4
2019 LADRA: Log-based abnormal task detection and root-cause analysis in big data processing with Spark
Siyang Lu, Wei Xiang 0007, BingBing Rao, Byung-Chul Tak, Long Wang 0003, Liqiang Wang 0001
Future Gener. Comput. Syst.1
2017 Log-based Abnormal Task Detection and Root Cause Analysis for Spark
abstract
Application delays caused by abnormal tasks arecommon problems in big data computing frameworks. Anabnormal task in Spark, which may run slowly withouterror or warning logs, not only reduces its resident node'sperformance, but also affects other nodes' efficiency.Spark log files report neither root causes of abnormal tasks,nor where and when abnormal scenarios happen. AlthoughSpark provides a “speculation” mechanism to detect stragglertasks, it can only detect tailed stragglers in each stage. Sincethe root causes of abnormal happening are complicated, thereare no effective ways to detect root causes.This paper proposes an approach to detect abnormality andanalyzes root causes using Spark log files. Unlike commononline monitoring or analysis tools, our approach is a pureoff-line method that can analyze abnormality accurately. Ourapproach consists of four steps. First, a parser preprocessesraw log files to generate structured log data. Second, ineach stage of Spark application, we choose features relatedto execution time and data locality of each task, as well asmemory usage and garbage collection of each node. Third,based on the selected features, we detect where and whenabnormalities happen. Finally, we analyze the problems usingweighted factors to decide the probability of root causes. In thispaper, we consider four potential root causes of abnormalities,which include CPU, memory, network, and disk. The proposedmethod has been tested on real-world Spark benchmarks.To simulate various scenario of root causes, we conductedinterference injections related to CPU, memory, network,and Disk. Our experimental results show that the proposedapproach is accurate on detecting abnormal tasks as well asfinding the root causes
Siyang Lu, BingBing Rao, Wei Xiang 0007, Byung-Chul Tak, Long Wang 0003, Liqiang Wang 0001
ICWS1