COMPUTER SCIENCE, ARTIFICIAL INTELLIGENCE AND SYSTEMS ANALYSIS

Information Technology for Automated Detection of Software Faults Based on Formalized Projection of Execution Trajectories and Integration of Logs and Metrics

Authors

Vinnytsia National Technical University ROR
Vinnytsia National Technical University ROR

Keywords

automated software testing information technology log analysis quality metrics machine learning anomaly detection behavioral modeling microservices architecture

Abstract

This paper investigates the problem of automated software faults detection under conditions where formal analysis ensures interpretability but is not always sufficiently complete or computationally feasible, while log-only and metrics-only approaches capture behavioral deviations but do not guarantee consistency with formally specified execution properties.

For the first time, an information technology for automated software faults detection is proposed, in which execution logs are interpreted as a formalized projection of program execution trajectories, and machine learning methods are used to approximate execution properties defined within an integrated framework of “static signals – execution model – logs/metrics – feature space – behavioral model – decision induction”.

The proposed approach integrates invariant, log-based, metric, and dynamic features and transforms the problem from isolated analysis of event logs or metric time series into a task of consistent recognition of defective execution modes.

Experimental verification was conducted on the open LO2 dataset, which combines event logs and execution metrics in a microservices environment. The obtained results demonstrate that the integrated model, as an implementation of the proposed information technology, achieves an F1-score of 0.742, outperforming the corresponding log-based baseline model (0.657) and the metrics-based baseline model (0.593).

The area under the ROC curve is 0.892, indicating higher overall discriminative capability of the model in distinguishing between normal and defective execution modes. Cohen’s kappa coefficient equals 0.661, confirming better agreement between automated decisions and the reference annotations.

The practical effect is manifested in more than a twofold reduction in the proportion of cases requiring expert interpretation, as well as in a significant decrease in the analysis time per case.

An ablation study further shows that log-based and invariant components contribute the most to detection performance, while metric and dynamic features serve a stabilizing and refining role.

3 0

How to Cite

[1]
“Information Technology for Automated Detection of Software Faults Based on Formalized Projection of Execution Trajectories and Integration of Logs and Metrics”, Вісник ВПІ, no. 4, pp. 67–82, Oct. 2026, doi: 10.31649/1997-9266-2026-187-4-67-82.

Author Biographies

F. B. Huralnyk, Vinnytsia National Technical University

Post-Graduate Student of the Chair of Computer Control Systems

V. V. Kovtun, Vinnytsia National Technical University

Dr Sc. (Eng.), Professor, Head of the Chair of Computer Control Systems

References

[1] M. Du, F. Li, G. Zheng, and V. Srikumar, “DeepLog,” in Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 1285-1298, 2017. https://doi.org/10.1145/3133956.3134015 .
[2] W. Meng, et al., “LogAnomaly: Unsupervised Detection of Sequential and Quantitative Anomalies in Unstructured Logs,” Proceedings of the Twenty-Eighth International Joint Conference on Artificial Intelligence, pp. 4739-4745, 2019. https://doi.org/10.24963/ijcai.2019/658 .
[3] X. Zhang, et al., “Robust log-based anomaly detection on unstable log data,” in Proceedings of the 27th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, pp. 807-817, 2019. https://doi.org/10.1145/3338906.3338931 .
[4] S. Hashemi, and M. Mäntylä, “OneLog: towards end-to-end software log anomaly detection,” Automated Software Engineering, vol. 31, no. 2, 2024. https://doi.org/10.1007/s10515-024-00428-x .
[5] S. Chen, and H. Liao, “BERT-Log: Anomaly Detection for System Logs Based on Pre-trained Language Model,” Applied Artificial Intelligence, vol. 36, no. 1, 2022. https://doi.org/10.1080/08839514.2022.2145642 .
[6] S. Zhang, et al., “End-to-End AutoML for Unsupervised Log Anomaly Detection,” in Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering, 2024. https://doi.org/10.1145/3691620.3695535 .
[7] J. Audibert, P. Michiardi, F. Guyard, S. Marti, and M. A. Zuluaga, “USAD,” in Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, pp. 3395-3404, 2020. https://doi.org/10.1145/3394486.3403392 .
[8] S. Tuli, G. Casale, and N. R. Jennings, “TranAD,” Proceedings of the VLDB Endowment, vol. 15, no. 6, pp. 1201-1214, 2022. https://doi.org/10.14778/3514061.3514067 .
[9] D. Li, D. Chen, B. Jin, L. Shi, J. Goh, and S.-K. Ng, “MAD-GAN: Multivariate Anomaly Detection for Time Series Data with Generative Adversarial Networks,” Lecture Notes in Computer Science, pp. 703-716, 2019. https://doi.org/10.1007/978-3-030-30490-4_56 .
[10] A. Aziz, and K. Munir, “Anomaly Detection in Logs Using Deep Learning,” IEEE Access, vol. 12, pp. 176124-176135, 2024. https://doi.org/10.1109/access.2024.3506332 .
[11] S. He, T. Deng, B. Chen, R. Simon Sherratt, and J. Wang, “Unsupervised Log Anomaly Detection Method Based on Multi-Feature,” Computers, Materials & Continua, vol. 76, no. 1, pp. 517-541, 2023. https://doi.org/10.32604/cmc.2023.037392 .

Most read articles by the same author(s)

1 2 > >>