Transformer-Based Semantic Log Modeling for Robust and Explainable Cloud Security Analytics
Abstract
This paper addresses the challenges of diverse data sources, complex structures, and hidden abnormal behaviors in cloud-based log environments by proposing a Transformer-based method for fine-grained log analysis and intrusion detection. The method builds a unified representation framework for multi-source logs and integrates a multi-dimensional context-aware mechanism to capture deep semantic relationships across different log types and enhance the modeling of cross-source behavioral paths. An attention-guided interpretation module is introduced to enable saliency-based localization and visual analysis of abnormal events, improving interpretability and controllability during detection. The modeling process combines source-type embeddings, positional encoding, and a global attention mechanism to establish a cross-time and cross-dimensional information fusion strategy, effectively representing long-term dependencies and key features in log sequences. In various sensitivity analysis experiments, the model shows strong stability and robustness under different learning rates, structural depths, sequence lengths, and anomaly ratios. Extensive experimental results demonstrate that the proposed method outperforms mainstream models across multiple metrics, achieving accurate detection while enabling automatic identification and focus on key events, thus providing strong support for efficient log modeling and intelligent security protection in cloud platforms.