RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    주파수 성분 분석 및 대조학습을 활용한 로그-메트릭 멀티모달 트랜스포머 기반 네트워크 이상 분류 = Network Anomaly Classification Using a Log-Metric Multimodal Transform with Frequency-Domain Analysis and Contrastive Learning

    한글로보기

    https://www.riss.kr/link?id=T17389684

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    현대 네트워크 시스템이 발전해감에 따라 구조적 복잡성이 지속해서 증가하고 있 다. 이에 따라 네트워크 오류 진단은 더욱 높은 성능과 정교함을 요구하는 정밀 분 석 작업으로 변화하고 있으나, 기존의 로그 기반 규칙 분석이나 단일 모달 시계열 기반 진단 기법만으로는 복잡한 장애 원인을 실시간으로 파악하는 데 한계가 존재 하였다. 이러한 배경으로 인해 본 연구는 텍스트 기반 로그와 수치형 메트릭의 정 보를 복합적으로 활용하는 멀티모달 학습 기반 네트워크 진단 모델을 제안한다. 본 학위논문은 이를 위해 LO2(Light-OAuth2) 데이터셋을 기반으로, 로그 임베딩의 방 향성·순차성 손실 문제를 해결하기 위한 FFT 기반 로그 임베딩 안정화 기법, 로그– 메트릭 간 의미적 연관성을 학습하기 위한 대조학습 기반 관계 학습 구조 및 서비 스별 로그 토큰을 독립적으로 유지하는 8-token Transformer를 중심으로 하는 멀 티모달 진단 모델을 설계하였다. FFT는 임베딩된 로그 벡터의 고주파 잡음을 제거 하고 반복 패턴 및 급격한 변화 패턴을 주파수 영역에서 분리함으로써 로그 특유의 이벤트 흐름을 안정적으로 반영하도록 설계되었다. 또한 대조학습은 동일 시점의 로그–메트릭 쌍을 긍정 관계로, 다른 시점의 임의 조합을 부정 관계로 학습시킴으 로써, 서비스 이벤트의 인과적 구조를 모델이 내재적으로 학습할 수 있도록 하였다. 실험은 모달리티 별 모델 성능 비교(단일 MLP, 2-token Transformer, 8-token Transformer), Dropout 및 Gaussian Noise 기반 강건성 평가, 대조학습 적용 여 부를 중심으로 수행하였다. 그 결과 8-token Transformer는 전체 54개 OAuth2 오류 클래스를 대상으로 가장 우수한 성능을 보였으며, 로그를 하나의 평균 토큰으 로 축약하는 2-token 모델 및 단일 벡터 기반 MLP에 비해 크게 향상된 결과를 확 인하였다. 특히 8-token 모델은 입력 로그 일부가 제거되거나 노이즈가 주입된 환 경에서도 2-token 대비 월등한 강건성을 유지하는 것을 확인하였으며, 서비스별 토 큰 구조가 정보 손실을 분산시키고 self-attention을 통해 일부 정보를 보완할 수 있음을 보여주었다. 대조학습 적용 시 특정 오류 클래스에서 precision 및 recall이 개선되는 등 멀티모달 관계 정렬 효과도 확인되었다. 결과적으로 본 학위논문은 네 트워크 로그의 주파수 기반 구조적 특징을 활용한 FFT 임베딩, 로그–메트릭 관계 를 학습하는 대조학습 구조, 서비스 단위 토큰화 전략을 결합한 새로운 멀티모달 Transformer 모델을 제안하였으며, 이는 기존 로그 또는 메트릭 단일 기반 접근 대비 높은 정확도와 강건성을 동시에 확보하였다. 본 성과는 향후 디지털 트윈 네 트워크, 자가 진단형 지능형 네트워크(autonomous network) 및 실시간 장애 예측 시스템 개발을 위한 핵심 기반 기술로 활용될 수 있다.
    번역하기

    현대 네트워크 시스템이 발전해감에 따라 구조적 복잡성이 지속해서 증가하고 있 다. 이에 따라 네트워크 오류 진단은 더욱 높은 성능과 정교함을 요구하는 정밀 분 석 작업으로 변화하고 ...

    현대 네트워크 시스템이 발전해감에 따라 구조적 복잡성이 지속해서 증가하고 있 다. 이에 따라 네트워크 오류 진단은 더욱 높은 성능과 정교함을 요구하는 정밀 분 석 작업으로 변화하고 있으나, 기존의 로그 기반 규칙 분석이나 단일 모달 시계열 기반 진단 기법만으로는 복잡한 장애 원인을 실시간으로 파악하는 데 한계가 존재 하였다. 이러한 배경으로 인해 본 연구는 텍스트 기반 로그와 수치형 메트릭의 정 보를 복합적으로 활용하는 멀티모달 학습 기반 네트워크 진단 모델을 제안한다. 본 학위논문은 이를 위해 LO2(Light-OAuth2) 데이터셋을 기반으로, 로그 임베딩의 방 향성·순차성 손실 문제를 해결하기 위한 FFT 기반 로그 임베딩 안정화 기법, 로그– 메트릭 간 의미적 연관성을 학습하기 위한 대조학습 기반 관계 학습 구조 및 서비 스별 로그 토큰을 독립적으로 유지하는 8-token Transformer를 중심으로 하는 멀 티모달 진단 모델을 설계하였다. FFT는 임베딩된 로그 벡터의 고주파 잡음을 제거 하고 반복 패턴 및 급격한 변화 패턴을 주파수 영역에서 분리함으로써 로그 특유의 이벤트 흐름을 안정적으로 반영하도록 설계되었다. 또한 대조학습은 동일 시점의 로그–메트릭 쌍을 긍정 관계로, 다른 시점의 임의 조합을 부정 관계로 학습시킴으 로써, 서비스 이벤트의 인과적 구조를 모델이 내재적으로 학습할 수 있도록 하였다. 실험은 모달리티 별 모델 성능 비교(단일 MLP, 2-token Transformer, 8-token Transformer), Dropout 및 Gaussian Noise 기반 강건성 평가, 대조학습 적용 여 부를 중심으로 수행하였다. 그 결과 8-token Transformer는 전체 54개 OAuth2 오류 클래스를 대상으로 가장 우수한 성능을 보였으며, 로그를 하나의 평균 토큰으 로 축약하는 2-token 모델 및 단일 벡터 기반 MLP에 비해 크게 향상된 결과를 확 인하였다. 특히 8-token 모델은 입력 로그 일부가 제거되거나 노이즈가 주입된 환 경에서도 2-token 대비 월등한 강건성을 유지하는 것을 확인하였으며, 서비스별 토 큰 구조가 정보 손실을 분산시키고 self-attention을 통해 일부 정보를 보완할 수 있음을 보여주었다. 대조학습 적용 시 특정 오류 클래스에서 precision 및 recall이 개선되는 등 멀티모달 관계 정렬 효과도 확인되었다. 결과적으로 본 학위논문은 네 트워크 로그의 주파수 기반 구조적 특징을 활용한 FFT 임베딩, 로그–메트릭 관계 를 학습하는 대조학습 구조, 서비스 단위 토큰화 전략을 결합한 새로운 멀티모달 Transformer 모델을 제안하였으며, 이는 기존 로그 또는 메트릭 단일 기반 접근 대비 높은 정확도와 강건성을 동시에 확보하였다. 본 성과는 향후 디지털 트윈 네 트워크, 자가 진단형 지능형 네트워크(autonomous network) 및 실시간 장애 예측 시스템 개발을 위한 핵심 기반 기술로 활용될 수 있다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Modern networked systems have grown increasingly complex due to the expansion of ultra-high-speed communication infrastructures, the widespread use of OTT and social media platforms, and the large-scale proliferation of cloud and mobile services. As a result, network fault diagnosis has evolved into a precision-critical task that demands both high accuracy and interpretability. Traditional approaches—such as rule-based log inspection or single-modality time-series analysis—are no longer sufficient for identifying complex failure causes in real time. Against this backdrop, this study proposes a multimodal learning–based
    network diagnostic model that jointly integrates text-based logs and numerical metrics. Building on the LO2 (Light-OAuth2) dataset, this study develops (1) an FFT-enhanced log-embedding stabilization method designed to mitigate the loss of directionality and sequential structure inherent in text embeddings, (2) a contrastive-learning–based relational modeling framework for learning semantic associations between logs and metrics, and (3) a multimodal diagnostic model centered on an 8-token Transformer architecture that preserves each service-specific log stream as an independent token. The FFT module removes high-frequency noise from log embeddings and decomposes repetitive and abrupt-change patterns in the frequency domain, thereby stabilizing the representation of event flows characteristic of OAuth2 service logs. Meanwhile, contrastive learning treats log–metric pairs from the same timestamp as positive pairs and randomly mismatched combinations as negative pairs, enabling the model to implicitly learn causal structures underlying service events. Experiments were conducted across three input configurations (single-vector MLP, 2-token Transformer, and 8-token Transformer), along with robustness evaluations using dropout and Gaussian noise, and comparative analysis with and without contrastive learning. Results show that the 8-token Transformer achieved the strongest performance, obtaining 0.69 accuracy and a 0.69 macro F1-score across all 54 OAuth2 error classes. This substantially outperformed the 2-token model—which collapses seven service logs into a single averaged log token (accuracy 0.64)—and the single-vector MLP baseline (accuracy 0.38). Notably, the 8-token architecture also demonstrated superior robustness when portions of the log input were dropped or corrupted by noise, confirming that service-specific token preservation distributes information loss and allows self-attention mechanisms to recover missing contextual cues. Incorporating contrastive learning further improved precision and recall in several error categories, highlighting its usefulness for multimodal representation alignment. In summary, this study presents a new multimodal Transformer-based diagnostic model that combines FFT-driven structural enhancement of log embeddings, contrastive learning of log–metric relationships, and a service-level tokenization strategy. The proposed model achieves higher accuracy and robustness than conventional log-only or metric-only approaches. These results indicate that the method provides a strong foundation for future applications in digital-twin networks, autonomous self-diagnosing network architectures, and real-time fault prediction systems.
    번역하기

    Modern networked systems have grown increasingly complex due to the expansion of ultra-high-speed communication infrastructures, the widespread use of OTT and social media platforms, and the large-scale proliferation of cloud and mobile services. As a...

    Modern networked systems have grown increasingly complex due to the expansion of ultra-high-speed communication infrastructures, the widespread use of OTT and social media platforms, and the large-scale proliferation of cloud and mobile services. As a result, network fault diagnosis has evolved into a precision-critical task that demands both high accuracy and interpretability. Traditional approaches—such as rule-based log inspection or single-modality time-series analysis—are no longer sufficient for identifying complex failure causes in real time. Against this backdrop, this study proposes a multimodal learning–based
    network diagnostic model that jointly integrates text-based logs and numerical metrics. Building on the LO2 (Light-OAuth2) dataset, this study develops (1) an FFT-enhanced log-embedding stabilization method designed to mitigate the loss of directionality and sequential structure inherent in text embeddings, (2) a contrastive-learning–based relational modeling framework for learning semantic associations between logs and metrics, and (3) a multimodal diagnostic model centered on an 8-token Transformer architecture that preserves each service-specific log stream as an independent token. The FFT module removes high-frequency noise from log embeddings and decomposes repetitive and abrupt-change patterns in the frequency domain, thereby stabilizing the representation of event flows characteristic of OAuth2 service logs. Meanwhile, contrastive learning treats log–metric pairs from the same timestamp as positive pairs and randomly mismatched combinations as negative pairs, enabling the model to implicitly learn causal structures underlying service events. Experiments were conducted across three input configurations (single-vector MLP, 2-token Transformer, and 8-token Transformer), along with robustness evaluations using dropout and Gaussian noise, and comparative analysis with and without contrastive learning. Results show that the 8-token Transformer achieved the strongest performance, obtaining 0.69 accuracy and a 0.69 macro F1-score across all 54 OAuth2 error classes. This substantially outperformed the 2-token model—which collapses seven service logs into a single averaged log token (accuracy 0.64)—and the single-vector MLP baseline (accuracy 0.38). Notably, the 8-token architecture also demonstrated superior robustness when portions of the log input were dropped or corrupted by noise, confirming that service-specific token preservation distributes information loss and allows self-attention mechanisms to recover missing contextual cues. Incorporating contrastive learning further improved precision and recall in several error categories, highlighting its usefulness for multimodal representation alignment. In summary, this study presents a new multimodal Transformer-based diagnostic model that combines FFT-driven structural enhancement of log embeddings, contrastive learning of log–metric relationships, and a service-level tokenization strategy. The proposed model achieves higher accuracy and robustness than conventional log-only or metric-only approaches. These results indicate that the method provides a strong foundation for future applications in digital-twin networks, autonomous self-diagnosing network architectures, and real-time fault prediction systems.

    더보기

    목차 (Table of Contents)

    • 1. 서론 1
    • 가. 연구의 배경 및 목적 1
    • 2. 학습 데이터 소개 5
    • 가. 적합한 네트워크 데이터 선정의 필요성 5
    • 1) 기술적 측면에서의 필요성 5
    • 1. 서론 1
    • 가. 연구의 배경 및 목적 1
    • 2. 학습 데이터 소개 5
    • 가. 적합한 네트워크 데이터 선정의 필요성 5
    • 1) 기술적 측면에서의 필요성 5
    • 2) 산업 및 경제적 측면에서의 필요성 5
    • 3) 정책적 측면에서의 필요성 6
    • 4) LO2 데이터셋의 필요성 6
    • 나. LO2 네트워크 데이터셋 구성 요소 6
    • 1) LO2 데이터셋 구성 요소 6
    • 2) LO2 데이터의 활용 목적 9
    • 다. 네트워크 데이터 분석 및 전처리 10
    • 1) 네트워크 log 데이터 전처리 과정 소개 10
    • 2) 로그의 윈도우 기반 데이터 구조화 11
    • 3. 모델 소개 13
    • 가. 로그 및 메트릭 데이터의 차원 설계 13
    • 나. 시계열 데이터 Fast Fourier Transform 연산 및 복원 14
    • 다. 선형 변환 기반 차원 축소 16
    • 라. 멀티모달 분류 모델: 8-Token Transformer 17
    • 1) 입력 토큰 구성 17
    • 2) Transformer 인코더 구조 17
    • 4. 실험 결과 21
    • 가. 멀티모달 데이터 Transform Token 구조별 성능 비교 22
    • 1) 전체 성능 비교 22
    • 나. Dropout 및 Noise 주입 기반 모델 강건성 비교 37
    • 다. 대조학습을 통한 임의의 관계 학습 실험 39
    • 5. 결론 및 향후계획 43
    • 가. 결론 43
    • 나. 향후 계획 43
    • 참고문헌 45
    • Abstract(영문초록) 48
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼