Latest Findings · ASI Lab

LogRoBERTa: Hybrid Language Model Detects Log Anomalies Without a Parser

RoBERTa plus an attention-based BiLSTM and a DPP-selected training set beats state-of-the-art baselines on four benchmark datasets using only 0.42% of logs for training.

Yicheng Sun, Jacky Keung, Zhen Yang, Shuo Liu, Hi Kuen Yu
Agentic Software Intelligence Research Lab · Department of Computer Science, City University of Hong Kong
Automated Software Engineering · 2026

Anomaly detection in software logs usually leans on time-consuming log parsers. LogRoBERTa discards the parser entirely, pairing RoBERTa's contextual embeddings with an attention-based BiLSTM. A Determinantal Point Process (DPP) sampler builds a small, diverse labeled set — just 20,000 logs on BGL (0.42% of the dataset). Across HDFS, BGL, Thunderbird, and Spirit it outperforms state-of-the-art baselines including three fully supervised models, stays strong on low-resource data, and cuts runtime by roughly a third.

Improving anomaly detection in software logs through hybrid language modeling and reduced reliance on parser
Fig. 6. The performance of models on six low-resource datasets.

Why it matters

We propose LogRoBERTa, an innovative anomaly detection model that eliminates the need for a parser. LogRoBERTa creates a stable and diverse labeled training set using the Determinantal Point Process (DPP) method, needing only a small amount of labeled data. The hybrid language model is based on RoBERTa's architecture, combined with an attention-based BiLSTM... Experiments on four widely used datasets demonstrate that LogRoBERTa outperforms state-of-the-art benchmark models—including three fully supervised approaches—without relying on a dedicated log parser.

Key findings

LogRoBERTa

What it means for practitioners

For teams maintaining log-based monitoring, a dedicated log parser is not a hard requirement for accurate anomaly detection. LogRoBERTa shows that a hybrid pre-trained language model plus an attention-based BiLSTM, trained on a small, deliberately diverse subset of logs, can match or beat parser-driven approaches while cutting preprocessing time substantially. The key practical lever is the diversity of the labeled subset (template coverage), not its raw size — so invest annotator effort in a diverse sample (via DPP or k-center greedy) rather than labeling the entire log stream.

Get the paper & cite it

Download full PDF ↓ View at DOI

Official citation: Yicheng Sun, Jacky Keung, Zhen Yang, Shuo Liu, Hi Kuen Yu (2026). Improving anomaly detection in software logs through hybrid language modeling and reduced reliance on parser. Automated Software Engineering. DOI: 10.1007/s10515-025-00548-y.

Anomaly detection Empirical software engineering Software log analysis Log parsing Hybrid language model Large language model