Published October 21, 2025 | Version v1

XTreeAD: Explainable Boosting Trees for Anomaly Detection in Cloud-native Services

  • 1. Nearby Computing S.L. Barcelona, Spain

Description

Cloud-native microservice architectures are increasingly adopted in modern networked systems, including virtualized infrastructures and critical domains such as Healthcare 4.0. Ensuring their reliability requires timely anomaly detection and accurate root-cause analysis (RCA), despite challenges from service-level dependencies and indirect fault propagation. Traditional methods based on statistical thresholds or rule-based heuristics often lack the expressiveness to capture complex metric
interactions and treat RCA as a separate, post hoc task. We propose XTreeAD, an explainable, supervised framework for anomaly detection and root-cause localization in microservicebased systems. XTreeAD uses an XGBoost classifier to detect anomalous system states from monitored performance and resource utilization metrics, and applies SHapley Additive ex-Planations (SHAP) to compute per-service feature attributions. These are aggregated and combined with the service-call graph in a dependency-aware ranking algorithm to identify likely faulty services. Experiments on a public available dataset show that XTreeAD outperforms established baselines in detection precision, localization accuracy, and runtime efficiency.

Files

XTreeAD_Liatsas_NFV_workshop.pdf

Files (516.6 kB)

Name Size Download all
md5:b6b6cd55d23668d00c16b213f4aa6ddb
516.6 kB Preview Download