RIDGE (Residual-Informed Diagnosis from Graph-Structured Evidence) is a two-stage temporal graph neural network architecture for root cause analysis (RCA) in computer networks. A probabilistic emulator forecasts the next telemetry snapshot in a fault-free network. Comparing the observations with that forecast produces residuals in units of the emulator's predictive uncertainty. An RCA model reads histories of these residual graphs, ranks candidates comprising the no-fault case, devices, and links, and classifies the fault category. Contents Each archive extracts into the artifact root that the code reads through its artifacts/ symlink. ridge-v1.0.0-stage1-dataset.zip: the raw dataset of 4,000 emulated network episodes, extracting to stage1-dataset/. Includes the generation provenance, the run manifest, the timing validation, and the exploratory analysis outputs. ridge-v1.0.0-stage2-normal.zip : the normal-emulator training windows, extracting to stage2-normal/. 209,145 windows with history length 6 and horizon 1, train-only normalization, and run-level splits of 2800/600/600. ridge-v1.0.0-stage4-residual-standardized.zip : the standardized residual windows, extracting to stage4-residual-standardized/. 316,000 windows built with the Stage 3 checkpoint. ridge-v1.0.0-stage4-residual-raw.zip : the matched raw-telemetry arm, extracting to stage4-residual-raw/. The same windows, labels, and splits, with the emulator skipped. ridge-v1.0.0-checkpoints.zip : the trained emulator (stage3-emulator/best_normal_emulator.pt) and the nine RCA checkpoints (stage5-rca-{standardized,raw,nograph}-seed{42,43,44}/best.pt), with their training histories and feature schemas. ridge-v1.0.0-evaluations.zip : the test-split evaluations, the per-seed aggregates, and the threshold baseline, extracting to stage6-evaluations/, stage6-aggregates/, and stage6-threshold-baseline/. ridge-v1.0.0-run-logs.zip : the per-stage console logs, exit codes, and wall-clock metadata for the campaign. stage1_generation_profile.json : the fully resolved Stage 1 generation configuration, readable without downloading an archive. MANIFEST.md and SHA256SUMS.txt : the archive inventory and checksums. The Dataset The 4,000 episodes were generated in a Mininet emulation running FRRouting under randomized traffic, with faults injected through tc and Open vSwitch. The composition is 2,000 healthy episodes and 500 each of drain, fiber_cut, link_degradation, and link_flap. No episode failed. Generation used seed 42 across 14 workers, on a 16-core CPU host with Python 3.12.3 and PyTorch 2.11.0+cu128, and took roughly 27 to 30 hours. Each episode covers 180 seconds at a 2-second telemetry cadence, recording node, interface, queue, route, neighbor, host, and ping statistics as CSV, with the topology and the run metadata as JSON. Provenance All telemetry was generated in an emulated network and contains no production or personal data. The absolute host paths, process identifiers, and generating hostname that the pipeline wrote into manifest.csv, the .meta files, and the simulator logs are preserved as produced.
Jakub Jeck· Zenodo (CERN European Organi...· 0 citations
RIDGE (Residual-Informed Diagnosis from Graph-Structured Evidence) is a two-stage temporal graph neural network architecture for root cause analysis (RCA) in computer networks. A probabilistic emulator forecasts the next telemetry snapshot in a fault-free network. Comparing the observations with that forecast produces residuals in units of the emulator's predictive uncertainty. An RCA model reads histories of these residual graphs, ranks candidates comprising the no-fault case, devices, and links, and classifies the fault category. Contents Each archive extracts into the artifact root that the code reads through its artifacts/ symlink. ridge-v1.0.0-stage1-dataset.zip: the raw dataset of 4,000 emulated network episodes, extracting to stage1-dataset/. Includes the generation provenance, the run manifest, the timing validation, and the exploratory analysis outputs. ridge-v1.0.0-stage2-normal.zip : the normal-emulator training windows, extracting to stage2-normal/. 209,145 windows with history length 6 and horizon 1, train-only normalization, and run-level splits of 2800/600/600. ridge-v1.0.0-stage4-residual-standardized.zip : the standardized residual windows, extracting to stage4-residual-standardized/. 316,000 windows built with the Stage 3 checkpoint. ridge-v1.0.0-stage4-residual-raw.zip : the matched raw-telemetry arm, extracting to stage4-residual-raw/. The same windows, labels, and splits, with the emulator skipped. ridge-v1.0.0-checkpoints.zip : the trained emulator (stage3-emulator/best_normal_emulator.pt) and the nine RCA checkpoints (stage5-rca-{standardized,raw,nograph}-seed{42,43,44}/best.pt), with their training histories and feature schemas. ridge-v1.0.0-evaluations.zip : the test-split evaluations, the per-seed aggregates, and the threshold baseline, extracting to stage6-evaluations/, stage6-aggregates/, and stage6-threshold-baseline/. ridge-v1.0.0-run-logs.zip : the per-stage console logs, exit codes, and wall-clock metadata for the campaign. stage1_generation_profile.json : the fully resolved Stage 1 generation configuration, readable without downloading an archive. MANIFEST.md and SHA256SUMS.txt : the archive inventory and checksums. The Dataset The 4,000 episodes were generated in a Mininet emulation running FRRouting under randomized traffic, with faults injected through tc and Open vSwitch. The composition is 2,000 healthy episodes and 500 each of drain, fiber_cut, link_degradation, and link_flap. No episode failed. Generation used seed 42 across 14 workers, on a 16-core CPU host with Python 3.12.3 and PyTorch 2.11.0+cu128, and took roughly 27 to 30 hours. Each episode covers 180 seconds at a 2-second telemetry cadence, recording node, interface, queue, route, neighbor, host, and ping statistics as CSV, with the topology and the run metadata as JSON. Provenance All telemetry was generated in an emulated network and contains no production or personal data. The absolute host paths, process identifiers, and generating hostname that the pipeline wrote into manifest.csv, the .meta files, and the simulator logs are preserved as produced.
Jakub Jeck· Zenodo (CERN European Organi...· 0 citations