In an implementation, a method for detecting anomalies in textual items is provided. The method includes: receiving a first plurality of textual items by a computing device; training a language model using the received first plurality of textual items by the computing device; after training the language model, receiving a second plurality of textual items by the computing device; calculating a cross-entropy for each textual item in the second plurality of textual items by the computing device using the language model; and detecting an anomaly in at least one of the textual items of the second plurality of textual items by the computing device using the calculated cross-entropies.