I. Introduction
To ensure undisrupted web-based services, operators need to closely monitor various KPIs (Key Performance Indicator, such as CPU usages, network throughput, page views, number of online users, and etc), detect anomalies in them, and trigger timely troubleshooting or mitigation. Fig. 1 shows a few KPIs that we studied in this paper. There can be hundreds of thousands to even millions of KPIs to be monitored [1], [2], thus operators need automatic anomaly detection approaches.