Key Takeaways & Executive Findings
- •• Provides a comprehensive taxonomy of deep anomaly detection models in AIOps, categorizing them into four methodological groups with special attention to LLM-based techniques. • Reviews applications across network traffic monitoring, system log analysis, cloud/edge service provisioning, and IoT security, bridging algorithmic research and practical deployment. • Highlights the limitations of black-box deep learning models in operational settings, emphasizing the need for explainable and robust AD systems. • Identifies future research directions, including integrating LLMs for multimodal anomaly detection and improving generalization to heterogeneous temporal data.
Abstract
The advancement of the fifth generation (5G) mobile communication and Internet of Things (IoT) has facilitated the development of intelligent applications, but has also rendered these networks increasingly complex and vulnerable to various targeted attacks. Numerous anomaly detection (AD) models, particularly those using deep learning technologies, have been proposed to monitor and identify network anomalous events. However, the implementation of these models poses challenges for network operators due to lacking expert knowledge of these black-box systems. In this study, we present a comprehensive review of current AD models and methods in the field of communication networks. We categorize these models into four methodological groups based on their underlying principles and structures, with particular emphasis on the role of recent promising large language models (LLMs) in the field of AD. Additionally, we provide a detailed discussion of the models in the following four application areas: network traffic monitoring, networking system log analysis, cloud and edge service provisioning, and IoT security. Based on these application requirements, we examine the current challenges and offer insights into future research directions, including robustness, explainability, and the integration of LLMs for AD.
1. Introduction
The advent of the fifth generation (5G) and the convergence of artificial intelligence have revolutionized Internet applications, enabling a symbiotic relationship between the physical and digital realms, and further ushering in an era of digital and intelligent transformation across various sectors (Zhang P et al., 2019; IMT-2030 (6G) Promotion Group, 2021). However, this transformation brings unprecedented challenges to network management due to the increasingly complex network structures, the vast volume of network traffic, and the multitude of connected devices required for these intelligent applications.
Recent incidents, such as the border gateway protocol (BGP) routing error by Abrams (2020), widespread outages by Heinle (2022) and KYODO NEWS (2022), and cellular phone outage across US by Montgomery (2024), indicate the susceptible vulnerabilities of current network management systems. Thus, there is an urgent demand for transition from traditional human-centric management to intelligent and automatic operational management technologies, which can ensure secure and efficient network performance. In this context, the concept of artificial intelligence for information technology (IT) operations (AIOps) (Dang YN et al., 2019) has been proposed to manage the complexity and scale of modern Internet systems. AIOps aims to develop automated anomaly detection (AD) models capable of processing complex, voluminous data streams, identifying emergent patterns of anomalies, and remaining resilient against the ever-changing landscape of network threats.
The emergence of large language models (LLMs) has introduced novel solutions for AIOps development. Recent studies show that LLMs excel in pattern recognition and reasoning across complex token sequences. Beyond traditional natural language tasks, LLMs can integrate text and time-series data to effectively perform time-series forecasting and AD (Su et al., 2024). Time-LLM (Jin et al., 2024b) demonstrates remarkable performance in time-series forecasting tasks by reprogramming time-series data into textual formats suitable for LLMs and leveraging meticulously crafted text prompts. To address time-series AD, TS-BERT (Dang WX et al., 2021) introduces the pretraining and fine-tuning paradigm, effectively overcoming the challenge of modeling long-range dependencies. As demonstrated in Fig. 1, the regular procedure of AD in AIOps for secure communication system monitoring can be divided into data collection, data preparation and representation, data analysis and fusion, and pattern recognition and decision-making. Although several survey papers (Cook et al., 2020; Li G and Jung, 2023; Zhong et al., 2023; Su et al., 2024) have reviewed the implementation of AD models, they either lack comprehensive coverage of technologies, such as recent LLM-based methods, or do not describe application-specific details. The scope of this study is to provide a comprehensive review of current AD models, especially deep learning models, including those based on LLMs, and to introduce their specific applications in the field of wireless communication networks.
Loading authentic research manuscript (Pages 1–5)...
Jiayi GUI, Zhongnan MA, Hao ZHOU, Yan SU, Miaoru ZHANG, Ke YU, Xiaofei WU (2025). Deep anomaly detection of temporal heterogeneous data in AIOps: a survey. Frontiers of Information Technology & Electronic Engineering. https://doi.org/10.1631/FITEE_2400467
Research & Educational Purpose Only:The translations, structured abstracts, analytical annotations, and data reports provided by SinoTechIntel are intended exclusively for academic research, internal corporate R&D, and educational benchmarking. They do not constitute formal engineering, chemical safety, legal, or professional advice.
Copyright & Intellectual Property Notice: Original copyright of the underlying source articles and experimental data remains with the respective authors, institutions, and original publishing journals. SinoTechIntel claims intellectual property only over its proprietary translations, analytical syntheses, and AEO structured enhancements in accordance with international fair use and academic citation principles.
Frequently Asked Questions
What is the scope of this survey on deep anomaly detection in AIOps?
This paper provides a comprehensive review of deep learning-based anomaly detection models, including LLM-based methods, and their applications in communication networks. It categorizes models into four methodological groups and discusses four application areas: network traffic monitoring, system log analysis, cloud and edge service provisioning, and IoT security.
What are the main categories of anomaly detection models discussed in the paper?
The models are categorized into four methodological groups based on their underlying principles and structures, with particular emphasis on recent large language model-based approaches for anomaly detection.
Which application areas are covered in the review?
The review covers network traffic monitoring, networking system log analysis, cloud and edge service provisioning, and IoT security, highlighting how deep AD models are applied in these domains.
What future research directions are highlighted in the paper?
Future research directions include improving the robustness and explainability of deep AD models, as well as the integration of large language models to enhance anomaly detection in heterogeneous temporal data.
Why is deep anomaly detection important for modern communication networks?
With the increasing complexity and vulnerability of modern networks, deep anomaly detection provides automated, intelligent monitoring that can identify emergent anomalous patterns, ensuring secure and efficient network performance without heavy reliance on human expertise.
Related Technical Papers & Translations
Design and optimization of a high-efficiency distillation process for cellulosic fuel ethanol integrated with thermal coupling and molecular sieve adsorption
To address the challenges of high energy consumption and prominent costs in the traditional three-columns distillation process for cellulosic fuel ethanol, a distillation—molecular sieve coupling separation process is proposed. This process integrates a three-column (crude distillation column, first distillation column, second distillation column) system with a 3A molecular sieve adsorption deep dehydration unit. A thermal coupling network is constructed via differential pressure design (steam from medium/high-pressure columns as mutual heat sources, reboiler liquid waste heat for feed preheating), and molecular sieve adsorption conditions are optimized. The study first performs a thermodynamic consistency test on the ethanol—water system, determines optimal non-random two-liquid (NRTL) model binary interaction parameters via experimental data regression for Aspen Plus simulation. Aiming at minimum total annual cost (TAC), Aspen Plus is used to optimize process parameters (theoretical tray number, feed location, reflux ratio, side-draw position, etc.). Economic analysis shows this process reduces CO2 emission costs by 27.56%, TAC by 15.58% (to 5.123 × 106 USD·a-1), and increases ethanol purity to >99.6%, providing an effective solution for green, efficient separation.
A cohesion loss model for determining residual strength of deep bedded sandstone
Rock residual strength, as an important input parameter, plays an indispensable role in proposing the reasonable and scientific scheme about stope design, underground tunnel excavation and stability evaluation of deep chambers. Therefore, previous residual strength models of rocks established were reviewed. And corresponding related problems were stated. Subsequently, starting from the effects of bedding and whole life-cycle evolution process, series of triaxial mechanical tests of deep bedded s
Federated model with contrastive learning and adaptive control variates for human activity recognition
Recent attention to privacy issues demands a communication-safe method for training human activity recognition (HAR) models on client activity data. Federated learning (FL) has become a compelling technique to facilitate model training between the server and clients while preserving data privacy. However, classical FL methods often assume independent and identically distributed (IID) data among clients. This assumption does not hold true in practical scenarios. Human activity in real-world scena