Reducing Trace-Complexity Bias in Microservice Anomaly Scoring via Weighted Residual Service Trace Vectors

Distributed trace anomaly scoring must distinguish unusual service-path latency behavior from structural differences among traces. However, raw Service Trace Vector (STV) scores may increase with trace size and feature occupancy, potentially prioritizing structurally larger traces even when no anomaly has been injected. We evaluate this structural score dependence on held-out, non-injected traces from three TrainTicket configurations using five train–test splits per configuration. Raw STV + Isolation Forest scores show strong mean Pearson correlations with service count (r=0.868), span count (r=0.820), and the number of observed STV features (r=0.960). Local Outlier Factor closely reproduces this dependence, whereas One-Class SVM reduces its Pearson magnitude, indicating a representation–scorer interaction rather than an effect specific to Isolation Forest. We propose WR-STV, which applies clipped feature-wise standardized residuals and log-frequency reliability weighting. Validation selects k=1; therefore, the final configuration scores each trace using its maximum reliability-weighted residual. WR-STV reduces the mean Pearson correlations with service and span count to 0.296 and 0.238, respectively. Under the original controlled 30×, three-span perturbation setting, WR-STV improves within-dataset ROC-AUC from 0.605 to 0.814. An expanded 1.10×–30× study shows that subtle perturbations remain difficult and that ranking performance generally increases with severity. WR-STV requires approximately 0.022 ms of mean batched scoring time per trace, approximately 16× lower than the evaluated Isolation Forest baselines. These results support WR-STV for reducing structural score dependence in controlled STV-visible latency ranking; they do not establish performance for naturally occurring incidents or non-latency anomaly types.

Authors

Institutions

Publication Details

Journal
Informatics
Published
2026-10-09
DOI
https://doi.org/10.3390/informatics13100167
Primary Topic
Software System Performance and Reliability
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Reducing Trace-Complexity Bias in Microservice Anomaly Scoring via Weighted Residual Service Trace Vectors

Murali Krishna Enduri, Pavan Kumar Ramina
Informatics
Software System Performance and Reliability
article

Reducing Trace-Complexity Bias in Microservice Anomaly Scoring via Weighted Residual Service Trace Vectors

Murali Krishna Enduri, Pavan Kumar Ramina
article en

Abstract

Distributed trace anomaly scoring must distinguish unusual service-path latency behavior from structural differences among traces. However, raw Service Trace Vector (STV) scores may increase with trace size and feature occupancy, potentially prioritizing structurally larger traces even when no anomaly has been injected. We evaluate this structural score dependence on held-out, non-injected traces from three TrainTicket configurations using five train–test splits per configuration. Raw STV + Isolation Forest scores show strong mean Pearson correlations with service count (r=0.868), span count (r=0.820), and the number of observed STV features (r=0.960). Local Outlier Factor closely reproduces this dependence, whereas One-Class SVM reduces its Pearson magnitude, indicating a representation–scorer interaction rather than an effect specific to Isolation Forest. We propose WR-STV, which applies clipped feature-wise standardized residuals and log-frequency reliability weighting. Validation selects k=1; therefore, the final configuration scores each trace using its maximum reliability-weighted residual. WR-STV reduces the mean Pearson correlations with service and span count to 0.296 and 0.238, respectively. Under the original controlled 30×, three-span perturbation setting, WR-STV improves within-dataset ROC-AUC from 0.605 to 0.814. An expanded 1.10×–30× study shows that subtle perturbations remain difficult and that ranking performance generally increases with severity. WR-STV requires approximately 0.022 ms of mean batched scoring time per trace, approximately 16× lower than the evaluated Isolation Forest baselines. These results support WR-STV for reducing structural score dependence in controlled STV-visible latency ranking; they do not establish performance for naturally occurring incidents or non-latency anomaly types.

InformaticsVol. 13(10)
SRM University (IN)
Openalex Percentile: Top 11%
Software System Performance and Reliability
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Reducing Trace-Complexity Bias in Microservice Anomaly Scoring via Weighted Residual Service Trace Vectors — Murali Krishna Enduri, Pavan Kumar Ramina · Informatics (2026) | TGRS Research Map | TGRS