Fine-Tuning Large Language Models for Anomaly Detection in Distributed System Logs
Book Chapter
Alvarez, G, Gangwani, P, Dwivedi, G et al. (2027). Fine-Tuning Large Language Models for Anomaly Detection in Distributed System Logs
. 685 LNICST 3-22. 10.1007/978-3-032-22542-9_1
Alvarez, G, Gangwani, P, Dwivedi, G et al. (2027). Fine-Tuning Large Language Models for Anomaly Detection in Distributed System Logs
. 685 LNICST 3-22. 10.1007/978-3-032-22542-9_1
Ensuring the reliability and smooth operation of distributed computing systems relies heavily on timely and accurate detection of anomalies in system logs. Conventional machine learning methods often fail to capture the semantic relationships and temporal dependencies embedded in these logs, while prompt-based large language model (LLM) approaches suffer from limited generalization and scalability. This paper proposes a parameter-efficient fine-tuning strategy for LLMs tailored to Hadoop Distributed File System (HDFS) anomaly detection. We propose a novel five-dimensional feature augmentation framework that encodes domain-specific structural, temporal, and operational indicators directly into LLM inputs, enabling models to preserve semantic richness and contextual patterns. By combining domain-aware augmentation with LoRA-based fine-tuning, we establish a scalable and interpretable methodology for detecting anomalies in complex distributed environments. Our results show excellent performance, confirming the effectiveness of this framework for enhancing system reliability and operational monitoring.