Published 2025-04-30
How to Cite

This work is licensed under a Creative Commons Attribution 4.0 International License.
Abstract
With the large-scale deployment of cloud native and distributed systems, operating environments have become highly dynamic and structurally complex. Traditional anomaly detection methods based on a single observation source struggle to fully capture system-level abnormal behavior. This paper focuses on intelligent operations scenarios and proposes a unified anomaly modeling approach for multi-source system observations. Anomalies are characterized and identified from the perspective of overall system operating states. Logs, metrics, and call traces are taken as inputs. Heterogeneous information is fused into a shared representation space through unified mapping to form a comprehensive description of system behavior. On this basis, state evolution modeling is introduced to capture continuous temporal changes. Anomalies are then measured through state consistency deviation. This avoids information fragmentation caused by the independent modeling of different observation sources. The framework preserves the complementary nature of each source while ensuring consistent and stable anomaly decisions. Anomalies are naturally expressed as deviations from normal operating trajectories. Comparative analysis shows that the proposed method achieves stronger overall discrimination capability and higher result consistency. This confirms the effectiveness of combining unified state modeling with temporal constraints for anomaly identification in complex systems. The proposed approach provides a unified perspective for system-level anomaly modeling with multi-source observations in intelligent operations. It improves the reliability and practical applicability of anomaly detection in complex distributed systems.