Gradient noise-based dynamic condition diffusion model time series data anomaly detection method and device
Through the dynamic conditional diffusion model of gradient noise and Gaussian noise, the reconstruction error problem of Gaussian noise being unable to distinguish anomalies is solved, and effective detection of trend, seasonal and mixed anomalies is achieved, thereby improving the accuracy of time series anomaly detection.
Patent Information
- Application Number
- CN202510850986.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-06-24
AI Technical Summary
The existing diffusion model has the problem of being unable to distinguish normal and abnormal data in time series anomaly detection due to Gaussian noise, resulting in insufficient reconstruction error, and a single model is difficult to effectively capture different types of abnormal patterns.
The gradient noise-based dynamic conditional diffusion model (GNDC-DM) is used to design trend noise, seasonal noise and mixed anomaly diffusion models. By combining gradient noise and Gaussian noise, the dynamic conditions guide the generation process to detect trend, seasonal and mixed anomalies respectively.
The accuracy of anomaly detection is improved. The normal mode is enhanced by gradient noise, abnormal points are suppressed, and dynamic conditions are generated to be closer to the normal data distribution, which significantly improves the reconstruction error and improves the detection effect of mixed anomalies.
Smart Images

Figure CN120632740A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of time series anomaly detection, and specifically to a method and apparatus for detecting anomalies in time series data based on a dynamic conditional diffusion model with gradient noise. Background Art
[0002] Time series anomaly detection refers to identifying data points in a time series that significantly deviate from normal patterns. This technology is of great significance in practical applications, such as fault detection in industrial systems, identification of financial fraud, automotive fault diagnosis, and early warning of abnormalities in mechanical equipment. Accurately detecting anomalies in time series is crucial for ensuring system operational safety, reducing risks, and avoiding significant economic losses. Due to the high cost of obtaining true labels for abnormal data, detecting anomalies under unsupervised conditions has become one of the main challenges in time series anomaly detection. To this end, researchers have proposed a variety of unsupervised techniques, including autoencoders (AEs), normalized flow models, graph neural networks (GNNs), and Transformer-based models. These methods typically distinguish between normal and abnormal patterns by learning effective representations or reconstruction errors.
[0003] In contrast, generative models aim to learn the underlying distribution of normal time series data, thereby detecting anomalies based on generation quality or likelihood estimation. By capturing normal patterns, these models can accurately reconstruct normal samples, but have difficulty reconstructing anomalous samples, thus identifying anomalies through reconstruction errors. Among generative models, generative adversarial networks (GANs) and variational autoencoders (VAEs) have been widely explored and have the potential to generate realistic time series data. However, these models often suffer from limited generation quality and unstable training, resulting in noisy and unrealistic output data, which affects detection performance. Therefore, in recent years, researchers have proposed time series anomaly detection methods based on diffusion models. These methods have stronger generation capabilities, more stable training processes, and higher-quality sample reconstruction results, making them a powerful alternative for achieving robust anomaly detection.
[0004] Despite some progress, current methods still have two key limitations: (1) Most existing diffusion model methods use Gaussian noise to perturb the input data during the forward diffusion process. However, Gaussian noise does not distinguish between normal and abnormal data, resulting in abnormal data being reconstructed as easily as normal data during the generation process. Reconstruction-based anomaly detection methods rely on smoothing the abnormal points, resulting in large reconstruction errors to identify anomalies. The fundamental reason is that this noise mechanism fails to effectively suppress abnormal patterns, which stems from the spectrum mismatch problem: Gaussian noise has uniform energy distribution in all frequency bands, while anomalies in time series are often concentrated on specific frequencies, such as high-frequency spikes or mid-frequency deviations. Therefore, uniform spectrum perturbations cannot selectively attenuate the frequencies dominated by anomalies, thereby failing to significantly increase the reconstruction error of anomalies. (2) Most methods use a unified detection model to identify different types of anomalies, resulting in poor detection results. Time series anomalies are complex in form, including seasonal anomalies, trend anomalies, and mixed anomalies. A single model structure often learns entangled representations, making it difficult to effectively capture the causal mechanisms behind these different types of anomalies. For example, seasonal anomalies require frequency-sensitive detectors, while trend anomalies rely more on robust baseline estimators. This one-size-fits-all approach is not as good as specialized detectors tailored to specific anomaly types. Summary of the Invention
[0005] The content of this application is used to briefly introduce concepts that will be described in detail in the detailed description section below. The content of this application is not intended to identify key features or essential features of the technical solution for which protection is sought, nor is it intended to limit the scope of the technical solution for which protection is sought.
[0006] Some embodiments of the present application propose a method and apparatus for detecting anomalies in time series data based on a dynamic conditional diffusion model with gradient noise to solve one or more of the technical problems mentioned in the background technology section above.
[0007] In a first aspect, some embodiments of the present application provide a time series data anomaly detection method based on a dynamic conditional diffusion model of gradient noise, the method comprising: determining a GNDC-DM model, wherein the above-mentioned GNDC-DM model comprises: a trend noise diffusion model, a seasonal noise diffusion model, and a mixed anomaly diffusion model; based on the trend noise diffusion model included in the above-mentioned GNDC-DM model, performing trend noise detection processing on the acquired initial industrial equipment data to generate trend noise reduction data; based on the seasonal noise diffusion model included in the above-mentioned GNDC-DM model, performing seasonal noise detection processing on the acquired initial industrial equipment data to generate seasonal noise reduction data; based on the mixed anomaly diffusion model included in the above-mentioned GNDC-DM model, performing mixed anomaly detection processing on the acquired initial industrial equipment data, the above-mentioned trend noise reduction data, and the above-mentioned seasonal noise reduction data to generate equipment noise reduction data.
[0008] In a second aspect, some embodiments of the present application provide a time series data anomaly detection device based on a dynamic conditional diffusion model of gradient noise, the device comprising: a determination unit, configured to determine a GNDC-DM model, wherein the above-mentioned GNDC-DM model comprises: a trend noise diffusion model, a seasonal noise diffusion model, and a mixed anomaly diffusion model; a trend noise detection unit, configured to perform trend noise detection processing on the acquired initial industrial equipment data based on the trend noise diffusion model included in the above-mentioned GNDC-DM model to generate trend noise reduction data; a seasonal noise detection unit, configured to perform seasonal noise detection processing on the acquired initial industrial equipment data based on the seasonal noise diffusion model included in the above-mentioned GNDC-DM model to generate seasonal noise reduction data; a mixed noise detection unit, configured to perform mixed anomaly detection processing on the acquired initial industrial equipment data, the above-mentioned trend noise reduction data, and the above-mentioned seasonal noise reduction data based on the mixed anomaly diffusion model included in the above-mentioned GNDC-DM model to generate equipment noise reduction data.
[0009] In a third aspect, the present application also provides a computer device, comprising a processor, a memory, and a computer program stored in the memory and executable by the processor, wherein when the computer program is executed by the processor, it implements the method described in any implementation of the first aspect.
[0010] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, wherein when the computer program is executed by a processor, the method described in any implementation of the first aspect is implemented.
[0011] The aforementioned embodiments of the present application have the following beneficial effects: Through the time series data anomaly detection method based on a dynamic conditional diffusion model based on gradient noise, some embodiments of the present application propose a dynamic conditional diffusion model (GNDC-DM) based on gradient noise for time series anomaly detection. This framework designs three dedicated detection channels, one for detecting trend anomalies, one for detecting seasonal anomalies, and one for detecting mixed anomalies. In the trend and seasonal channels, gradient noise is introduced as an alternative to traditional Gaussian noise. This noise design effectively attenuates outliers, thereby amplifying the reconstruction error of outliers and improving detection performance. This noise consists of two components: a gradient-guided noise that enhances normal trends (or seasonal patterns); and a random Gaussian component that maintains sample diversity. The gradient component leverages the characteristic that outliers typically deviate from the normal trend (or seasonal pattern) of their surroundings in the gradient direction. By aligning with the normal gradient, it naturally suppresses abnormal fluctuations. The Gaussian component introduces appropriate randomness to prevent the model from falling into deterministic bias while maintaining sample diversity. By integrating these two components, the noise design proposed in this application minimizes perturbations to the normal pattern during the reconstruction process while systematically migrating outliers toward the normal manifold, effectively suppressing anomalies while robustly preserving the normal structure. In the mixed channel, this application dynamically combines trend noise and seasonal noise at each time step, using them as a conditional guided diffusion model for time series reconstruction. By aligning the generated data to normal trend and seasonal patterns, this design effectively suppresses anomalous components along these two dimensions, making mixed anomalies easier to distinguish and detect. Unlike static conditions (such as global trends or seasonal averages), this method dynamically synchronizes the generation process with the temporal characteristics of the input data by gradually extracting trend and seasonal information at each time step. This design ensures consistency of the generated output within a local area and more closely matches the distribution of normal data. Ultimately, data points containing mixed anomalies tend to produce larger errors in the reconstruction, making detection based on reconstruction scores more effective. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] The above and other features, advantages, and aspects of the various embodiments of the present application will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that the elements and components are not necessarily drawn to scale.
[0013] Figure 1 is a flowchart of some embodiments of a method for detecting anomalies in time series data based on a dynamic conditional diffusion model of gradient noise according to the present application; Figure 2 2 is an architecture diagram of a GNDC-DM model for detecting anomaly in time series data based on a dynamic conditional diffusion model with gradient noise according to the present application; Figure 3 1 is a schematic structural diagram of some embodiments of a device for detecting anomalies in time series data based on a dynamic conditional diffusion model of gradient noise according to the present application; Figure 4 is a schematic diagram of the structure of a computer device suitable for implementing some embodiments of the present application; Figure 5 is a schematic diagram describing some data sets for experimental verification of the time series data anomaly detection method based on the dynamic conditional diffusion model of gradient noise according to the present application; Figure 6 is a schematic diagram showing the performance comparison between GNDC-DM according to the present application and the baseline method on four datasets; Figure 7 This is a schematic diagram comparing the F1 scores of different components; Figure 8 It is based on the preset trend seasonal conditions of this application Schematic diagram of parameter impact analysis; Figure 9 are two key hyperparameters in the formula of trend gradient noise according to this application and Schematic diagram of the impact analysis. DETAILED DESCRIPTION
[0014] The following will describe embodiments of the present application in more detail with reference to the accompanying drawings. Although certain embodiments of the present application are shown in the accompanying drawings, it should be understood that the present application can be implemented in various forms and should not be construed as being limited to the embodiments described herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present application. It should be understood that the drawings and embodiments of the present application are for illustrative purposes only and are not intended to limit the scope of protection of the present application.
[0015] It should also be noted that, for ease of description, only the parts related to the invention are shown in the drawings. In the absence of conflict, the embodiments and features in the embodiments of this application can be combined with each other.
[0016] It should be noted that the concepts of "first" and "second" mentioned in this application are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0017] It should be noted that the modifications of "one" and "multiple" mentioned in this application are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".
[0018] The names of the messages or information exchanged between multiple devices in the embodiments of the present application are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0019] The present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments.
[0020] Figure 1 A process 100 of some embodiments of a method for detecting anomalies in time series data using a dynamic conditional diffusion model of gradient noise according to the present application is shown. The method for detecting anomalies in time series data using a dynamic conditional diffusion model of gradient noise includes the following steps: Step 101: Determine the GNDC-DM model.
[0021] In some embodiments, the execution subject of the time series data anomaly detection method based on the dynamic conditional diffusion model of gradient noise can determine the GNDC-DM model. The above-mentioned GNDC-DM model includes: trend noise diffusion model, seasonal noise diffusion model, and mixed anomaly diffusion model. For example, the overall framework of the GNDC-DM (dynamic conditional diffusion model based on gradient noise) model can refer to Figure 2 , Figure 2 The architecture diagram of the GNDC-DM model of the time series data anomaly detection method based on the dynamic conditional diffusion model of gradient noise in this application is shown. Therefore, a three-channel anomaly detection architecture is innovatively proposed, which detects trend anomalies, seasonal anomalies and mixed anomalies in time series respectively through customized diffusion models. Specifically: (1) Trend / seasonal diffusion model: A customized gradient noise function is designed, and the noise is derived from the feature learning of normal trend and seasonal pattern. Compared with Gaussian noise, it can selectively destroy the abnormal components in trend and seasonal signals. Gradient noise is gradually added in the forward process to make the noisy data converge to normal behavior. Through this strong prior constraint, the normal trend and seasonal components are reconstructed in the reverse process. (2) Mixed anomaly diffusion model: The information of fused trend noise and seasonal noise is used as a dynamic condition to guide the generation process. Gradient noise is also added in the forward process; a dynamic condition adjustment mechanism with time step adaptation is implemented in the reverse generation stage. Compared with static conditions, dynamic conditions can enhance the expression of normal information in time series and significantly improve the quality of normal data generation.
[0022] Step 102 : Based on the trend noise diffusion model included in the GNDC-DM model, trend noise detection processing is performed on the acquired initial industrial equipment data to generate trend noise reduction data.
[0023] In some embodiments, the execution entity may perform trend noise detection processing on the acquired initial industrial equipment data based on the trend noise diffusion model included in the GNDC-DM model to generate trend noise reduction data. The initial industrial equipment data may be acquired from a terminal device via a wired connection or a wireless connection. Here, the initial industrial equipment data may be data of an industrial device. For example, the industrial equipment may be, but is not limited to: equipment of an industrial system, a car, or mechanical equipment. For example, the initial industrial equipment data may be, but is not limited to: MSL (Mars Science Laboratory), SMD (Server Machine Dataset), SWaT (Secure Water Treatment), or PSM (Pooled Server Metrics).
[0024] Optionally, the initial industrial equipment data is decomposed to generate initial trend data, initial season data, and initial mixed data.
[0025] In some embodiments, the execution entity may decompose the initial industrial equipment data to generate initial trend data, initial seasonal data, and initial mixed data. In practice, the initial industrial equipment data is usually decomposed into three core components: initial trend data, initial seasonal data, and initial mixed data, as shown in the following formula: , in, represents the initial industrial equipment data, represents the initial trend data, represents the initial seasonal data, Represents the initial mixed data.
[0026] In practice, the above-mentioned execution entity can decompose the initial industrial equipment data through the following steps to generate initial trend data, initial seasonal data, and initial mixed data: In the first step, the initial industrial equipment data is decomposed using the following formula to generate initial trend data: , in, represents the coefficient, , represents the average step length, Indicates the serial number.
[0027] In the second step, the initial industrial equipment data and initial trend data are subjected to a second decomposition process using the following formula to generate initial seasonal data: , in, Represents the LOESS (loess) smoothing function.
[0028] In the third step, the initial industrial equipment data, initial trend data, and initial seasonal data are decomposed using the following formula to generate initial mixed data: .
[0029] It should be noted that the above wireless connection methods may include but are not limited to 3G / 4G connection, WiFi connection, Bluetooth connection, WiMAX connection, Zigbee connection, UWB (ultra wideband) connection, and other wireless connection methods currently known or to be developed in the future.
[0030] Since trend anomalies in time series data refer to subsequences that significantly deviate from the overall trend, this application uses a diffusion model with gradient noise to reconstruct trend data and then identifies outliers based on the reconstruction error.
[0031] In order to detect trend anomalies, this application converts data so that both normal points and abnormal points exhibit normal behavior patterns, and then identifies anomalies by analyzing reconstruction errors (the larger the error, the higher the possibility of anomalies). Inspired by the excellent performance of the diffusion model in related tasks, this application adopts a diffusion-based reconstruction method: the forward process constructs a prior distribution by perturbing the trend data with gradient noise, and the reverse diffusion process optimizes the prior to generate a reconstructed trend. Traditional diffusion models usually use Gaussian white noise to destroy the original data, but this method does not adequately suppress the influence of abnormal points. For this reason, this application innovatively introduces a gradient noise mechanism, which can obtain a smoother reconstruction trend, thereby causing abnormal points to produce a larger reconstruction error.
[0032] Inspired by the successful application of specific noise in graph data, this application proposes a novel gradient noise mechanism to suppress anomalous feature information. This noise mechanism shifts the data distribution toward a normal pattern, reconstructing outliers into normal values while maintaining the consistency of the original normal values. As a result, outliers exhibit a larger reconstruction error during reconstruction, making them more effectively identifiable.
[0033] Anomalies in time series usually manifest as sudden fluctuations that deviate from the overall trend, with their gradient directions significantly different from the surrounding data. Noise generated based on the gradient direction can enhance the underlying trend of normal points while weakening the influence of anomalies. To effectively suppress anomalies in the trend, this application converts standard Gaussian noise into gradient noise through the following two key constraints: (1) Direction constraint: aligning the noise with the local gradient direction to capture the local dynamic characteristics of the time series; (2) Randomness constraint: introducing Gaussian noise to maintain the diversity of generated samples.
[0034] In practice, the execution entity may perform trend noise detection processing on the acquired initial industrial equipment data based on the trend noise diffusion model included in the GNDC-DM model through the following steps to generate trend noise reduction data: The first step is to determine the trend gradient noise based on preset constraints and Gaussian noise. The preset constraints may include directional constraints and random constraints. The directional constraint may be to align the noise with the local gradient direction to capture the local dynamic characteristics of the time series. The random constraint may be to introduce Gaussian noise to maintain the diversity of the generated samples. The trend gradient noise may be: , in, represents the trend gradient noise, represents a trend time series, Representing time series The gradient, express The module length, To prevent A small constant introduced to ensure numerical stability due to division errors near zero, represents Gaussian noise, , represents the modulus of Gaussian noise, and represents an adjustable hyperparameter, which is used to control the relative contribution ratio of the gradient-guided noise component and the random noise component. For example, It can be 0.1. It can be 0.3. It can be 0.7.
[0035] The second step is to determine the target trend noise data sequence based on the preset trend forward diffusion formula, using the trend gradient noise and the initial industrial equipment data. The preset trend forward diffusion formula is: , in, Indicates the first Target trend noise data, Indicates the serial number, , represents the number of iterations, , , represents the preset variance scheduling parameter, Indicates the initial trend data corresponding to the initial industrial equipment data, for example, It can be 0.15.
[0036] Since the gradient trend noise obtained by the trend gradient noise formula will force the data to converge to normal data, the abnormal information in the prior distribution is significantly weakened after the forward diffusion process.
[0037] The third step is to determine the trend loss function corresponding to the trend noise diffusion model based on the target trend noise data sequence. The trend loss function can be: , in, represents the trend loss function, Express expectations, Indicated by the parameter Parameterized denoising neural network, express The parameter collection in .
[0038] Trend data reconstruction requires the use of a denoising neural network to eliminate prior noise and generate clean data. In order to better learn the normal distribution of trends, this application uses the U-Net (convolutional network for biomedical image segmentation) architecture based on the LDM (Latent Diffusion Model) to implement the denoising network. . Unlike the dynamic conditional denoising network in hybrid anomaly detection that relies on external conditions such as trends and seasonality, trend anomaly detection focuses on learning the normal sample distribution without additional conditional constraints. To this end, this application removes the conditional component in the original LDM design and instead introduces a self-attention mechanism. This mechanism can effectively capture long-range dependencies in the sequence, enabling the network to gain a global understanding of the trend structure. Given that normal data usually dominates in anomaly detection tasks, the use of long-range dependencies can enhance the network's ability to model normal patterns, thereby amplifying the reconstruction error of anomalies and ultimately improving anomaly detection performance.
[0039] Optionally, the execution entity may adjust the trend noise diffusion model based on the trend loss function using a preset adjustment algorithm. For example, the preset adjustment algorithm may be, but is not limited to, one of the following: an Adam optimizer algorithm, a backpropagation algorithm, or a stochastic gradient algorithm.
[0040] The fourth step is to determine the trend noise reduction data based on the preset trend reverse growth formula using the above trend noise diffusion model and the above target trend noise data sequence.
[0041] In practice, the execution entity may determine the trend noise reduction data by following the steps below based on a preset trend reverse growth formula, using the trend noise diffusion model and the target trend noise data sequence: The first step is to determine the number of trend iterations. In practice, the execution entity may determine the number of iterations as the number of trend iterations.
[0042] In the second step, the last target trend noise data in the target trend noise data sequence is determined as the transit trend noise data.
[0043] In the third step, based on the number of trend iterations and the transit trend noise data, the following trend iteration steps are performed: The first sub-step is to determine the trend denoised data based on the preset trend reverse growth formula, using the above trend noise diffusion model and the transit trend noise data. The preset trend reverse growth formula is: , in, represents trend denoised data, represents transit trend noise data; The second sub-step is to determine the difference between the number of trend iterations and a preset iteration value as the target number of trend iterations. For example, the preset iteration value may be 1.
[0044] In step 4, in response to determining that the target number of trend iterations satisfies a preset trend iteration condition, the target number of trend iterations is determined as the trend iteration number, and the trend denoised data is determined as the transit trend noise data for re-execution of the above trend iteration step. The preset trend iteration condition may be: the target number of trend iterations is 0.
[0045] In a fifth step, in response to determining that the target trend iteration number does not satisfy a preset trend iteration condition, the trend denoised data is determined as trend noise reduction data.
[0046] Step 103 : Based on the seasonal noise diffusion model included in the GNDC-DM model, seasonal noise detection processing is performed on the acquired initial industrial equipment data to generate seasonal noise reduction data.
[0047] In some embodiments, the execution entity may perform seasonal noise detection processing on the acquired initial industrial equipment data based on the seasonal noise diffusion model included in the GNDC-DM model to generate seasonal noise reduction data.
[0048] In practice, the execution entity may perform seasonal noise detection processing on the acquired initial industrial equipment data based on the seasonal noise diffusion model included in the GNDC-DM model to generate seasonal noise reduction data through the following steps: The first step is to determine seasonal gradient noise based on preset constraints and Gaussian noise. The specific implementation of determining seasonal gradient noise based on preset constraints and Gaussian noise and the resulting technical effects can be referred to step 102 in the above embodiment and will not be repeated here.
[0049] In the second step, based on the preset seasonal forward diffusion formula, the target seasonal noise data sequence is determined using the seasonal gradient noise and the initial industrial equipment data. The preset seasonal forward diffusion formula is: , in, represents the first target seasonal noise data, represents the initial seasonal data corresponding to the initial industrial equipment data, represents seasonal gradient noise.
[0050] The third step is to determine the seasonal loss function corresponding to the seasonal noise diffusion model based on the target seasonal noise data sequence. The specific implementation method and technical effects of determining the seasonal loss function corresponding to the seasonal noise diffusion model based on the target seasonal noise data sequence can be referred to step 102 in the above embodiment and will not be repeated here.
[0051] Optionally, the execution entity may adjust the seasonal noise diffusion model based on the seasonal loss function through the preset adjustment algorithm.
[0052] The fourth step is to determine the seasonal noise reduction data based on the preset seasonal inverse growth formula using the seasonal noise diffusion model and the target seasonal noise data sequence.
[0053] In practice, the execution entity may determine the seasonal noise reduction data by using the seasonal noise diffusion model and the target seasonal noise data sequence based on a preset seasonal inverse growth formula through the following steps: The first step is to determine the number of seasonal iterations. In practice, the execution entity may determine the number of iterations as the number of seasonal iterations.
[0054] In the second step, the last target seasonal noise data in the target seasonal noise data sequence is determined as the transit seasonal noise data.
[0055] In the third step, based on the number of seasonal iterations and the transit seasonal noise data, the following seasonal iteration steps are performed: The first sub-step is to determine the seasonal denoised data based on the preset seasonal inverse growth formula, using the above seasonal noise diffusion model and the transit seasonal noise data. The preset seasonal inverse growth formula is: , in, represents seasonal denoised data, represents the transit season noise data, represents a denoising neural network.
[0056] In the second sub-step, the difference between the number of seasonal iterations and the preset iteration value is determined as the target number of seasonal iterations.
[0057] In step 4, in response to determining that the target seasonal iteration number satisfies a preset seasonal iteration condition, the target seasonal iteration number is determined as the seasonal iteration number, and the seasonal denoised data is determined as the transit seasonal noise data for re-execution of the above seasonal iteration step. The preset seasonal iteration condition may be that the target seasonal iteration number is 0.
[0058] In a fifth step, in response to determining that the target seasonal iteration number does not satisfy a preset seasonal iteration condition, the seasonal denoised data is determined as seasonal noise reduction data.
[0059] Therefore, for the seasonal component, this application adopts a similar process to reconstruct the data. First, refer to the processing method of trend gradient noise to convert Gaussian noise into seasonal gradient noise. Then, in the forward diffusion process, the customized noise is used to reconstruct the seasonal data. conduct Step perturbation, and finally get the prior distribution ——This processing method is symmetrical with the preset trend forward diffusion formula corresponding to the trend component. Trained to eliminate Finally, in the reverse process, by Iterative removal of priors Remove the noise in , and generate clean seasonal data.
[0060] Step 104 : Based on the mixed anomaly diffusion model included in the GNDC-DM model, mixed anomaly detection processing is performed on the acquired initial industrial equipment data, trend noise reduction data, and seasonal noise reduction data to generate equipment noise reduction data.
[0061] In some embodiments, the execution entity may perform mixed anomaly detection processing on the acquired initial industrial equipment data, the trend noise reduction data, and the seasonal noise reduction data based on the mixed anomaly diffusion model included in the GNDC-DM model to generate equipment noise reduction data.
[0062] Because time series typically contain multiple complex components, mixed anomalies often coexist in the data, in addition to trend terms and seasonal anomalies. To detect such anomalies, this application designs a time series diffusion model with dynamic conditions. In the reverse process, dynamic conditions extracted from the decomposed trend terms and seasonal components are introduced to guide the generation of the reconstructed time series. Mixed anomalies are then identified by calculating the reconstruction error between the generated sequence and the original input. A larger error indicates a higher likelihood of anomalous behavior.
[0063] Denoising diffusion probability models (DDPMs) have demonstrated a powerful ability to accurately model data distributions in generative tasks. However, existing anomaly detection methods often rely on static conditional mechanisms. These static conditions lack the flexibility to provide targeted, step-by-step guidance during the generative process, making them difficult to adapt to the complex dynamics of time series data, ultimately resulting in suboptimal anomaly detection performance for time series data.
[0064] To address this limitation, this application proposes a dynamic conditional mechanism that integrates noise signals from trend terms and seasonal components during the generation process. This dynamic condition guides the diffusion model to generate time series data that conforms to normal patterns. Specifically, at each time step in the iterative generation process, this application diffuses the trend term and seasonal component separately to obtain trend noise and seasonal noise corresponding to the same moment - these noise components mainly reflect the characteristics of normal data. By combining them into dynamic conditions, the model can be effectively guided to generate time series values that conform to normal behavior. This design ensures that the trend signal and the seasonal signal (both of which are aligned with the normal direction) serve as guiding conditions for time synchronization, which not only matches the temporal structure characteristics of the data, but also guides the generation process towards a normal distribution.
[0065] In practice, the execution entity may perform mixed anomaly detection processing on the acquired initial industrial equipment data, the trend noise reduction data, and the seasonal noise reduction data based on the mixed anomaly diffusion model included in the GNDC-DM model through the following steps to generate equipment noise reduction data: The first step is to determine the mixed gradient noise based on the preset constraints and Gaussian noise. The specific implementation of determining the mixed gradient noise based on the preset constraints and Gaussian noise and the resulting technical effects can be referred to step 102 in the above embodiment and will not be repeated here.
[0066] The second step is to determine a target mixed noise data sequence based on a preset mixed forward diffusion formula, using the mixed gradient noise and the initial industrial equipment data. The specific implementation and technical effects of determining the target mixed noise data sequence based on the preset mixed forward diffusion formula, using the mixed gradient noise and the initial industrial equipment data, can be found in step 102 of the above embodiment and will not be further described here.
[0067] Therefore, the diffusion process of the time series basically follows the trend forward process of the preset trend forward diffusion formula. Specifically, the time series data sampled from the real distribution ,go through The disturbance of step gradient noise (refer to the treatment method of trend gradient noise) finally obtains the representation after destruction .
[0068] The third step is to determine the mixed loss function corresponding to the mixed anomaly diffusion model based on the initial industrial equipment data, the target mixed noise data sequence, the target trend noise data sequence corresponding to the trend noise reduction data, and the target seasonal noise data sequence corresponding to the seasonal noise reduction data. The mixed loss function is: , in, represents the mixed loss function, Express expectations, represents the initial mixed data corresponding to the initial industrial equipment data, Indicated by The parameterized denoising neural network has the following input: , the condition variable is and , represents the first target mixed noise data, Indicates the first Target trend noise data, represents the first target seasonal noise data.
[0069] Denoising Network for Time Series Data , this application introduces dynamic conditional guidance to learn the distribution of normal data. In each step of the denoising process, the prediction output of the previous step is As input, the trend term corresponding to the same time step is used and seasonal items The noise is predicted as a conditional variable. Subsequently, the predicted noise is used to generate the time series data of the previous time step. Therefore, the dynamic conditions at each time step vary with the corresponding time step. These dynamic conditions not only ensure consistency across time steps, but also incorporate components with normal directions, effectively guiding the network to reconstruct time series data that conforms to normal patterns.
[0070] Optionally, the execution entity may adjust the mixed anomaly diffusion model based on the mixed loss function through the preset adjustment algorithm.
[0071] The fourth step is to determine the cross attention model included in the above-mentioned mixed abnormal diffusion model based on the preset trend seasonal condition, wherein the preset trend seasonal condition is: , in, Indicates the preset trend seasonal conditions, Represents the weight coefficient, which is used to dynamically adjust the contribution ratio of trend term and seasonal term in condition generation, for example, It can be 0.4.
[0072] Among them, the cross attention model is: , in, represents the cross attention model, represents the query vector, Indicates that the condition is embedded through the embedding layer The converted Represents the embedding vector length, Represents the dimension, , Indicates the key, , represents the temporal input representation of each layer’s cross attention, Represents a value, , represents the query matrix, represents the bond matrix, represents the value matrix, 、 and All of them are matrix weight parameters to be learned.
[0073] However, the time series components in the real world are often not quantitatively distributed, which means that using equal proportions of trend terms and seasonal terms as generation conditions may not be able to effectively support the time series generation task. In order to make the conditional mechanism more in line with the real time series characteristics, this application preprocesses the trend and seasonal components before inputting them into the denoising network to ensure that each component can more efficiently and collaboratively guide sequence generation. Specifically, this application achieves this goal by dynamically adjusting the contribution weights of trend terms and seasonal terms in conditional guidance. The generation process of this conditional guidance can be formally expressed as the above-mentioned preset trend seasonal conditions.
[0074] In each time steps, preset trend seasonal conditions Guide input data through cross-attention mechanism This application adopts the U-Net architecture based on LDM (Latent Diffusion Model) as the diffusion network, and enhances it through cross attention to gradually integrate the preset trend seasonal conditions. Integrate into the denoising process. To achieve this integration, this application uses an embedding layer to transform the condition Convert to , where the dimension and time series representation Alignment. The cross-attention mechanism that integrates the conditions is shown in the above formula. This mechanism enables the model to dynamically focus on the conditions The most relevant timing patterns in the dataset are found, thus more accurately generating reconstructed sequences that conform to the normal distribution.
[0075] Output of the Cross-Attention Mechanism It will be used as the input of the subsequent U-Net module. Specifically, the query vector Generated by the condition, which contains The trend and seasonal noise after time step mixing; the key and value are respectively and Calculate, where Represents the temporal input representation of each layer’s cross attention. With timing key When both are in normal state, the similarity between them is high, making the value The attention weight during weighted summation increases significantly; on the contrary, if Normal Abnormal,reduction in similarity will cause the weight to decrease sharply.,This mechanism effectively suppresses abnormal information in the time series,,forcing the network to focus on learning the pattern features of,normal time series.
[0076] The fifth step is to determine the equipment noise reduction data based on the preset mixed inverse growth formula, using the above-mentioned mixed anomaly diffusion model and the above-mentioned target mixed noise data sequence.
[0077] In practice, the execution entity may determine the device noise reduction data based on a preset mixed inverse growth formula, using the mixed anomaly diffusion model and the target mixed noise data sequence through the following steps: The first step is to determine the number of hybrid iterations. In practice, the execution entity may determine the number of iterations as the number of hybrid iterations.
[0078] In the second step, the last target mixed noise data in the target mixed noise data sequence is determined as the transit mixed noise data.
[0079] In the third step, based on the number of mixing iterations and the intermediate mixed noise data, the following mixing iteration steps are performed: The first sub-step is to determine the mixed denoised data based on the preset mixed inverse growth formula, using the above-mentioned mixed anomaly diffusion model and the transit mixed noise data. The preset mixed inverse growth formula is: , in, represents mixed denoised data, represents the transit mixed noise data, represents the first Target trend denoised data, represents the first Target seasonal denoised data. The target trend denoised data sequence is determined by each trend denoised data and the target trend noise data sequence. The target seasonal denoised data sequence is determined by each seasonal denoised data and the target seasonal noise data sequence. Here, the target trend denoised data sequence is determined by the following steps: First, each trend denoised data sequence determined in the above trend iteration step is Add to the target trend denoising data sequence, where the target trend denoising data sequence is initially empty. Then, the last target trend noise data in the target trend noise data sequence is determined as the first target trend noise data in the target trend denoising data sequence. Here, the target seasonal denoised data sequence is determined by the following steps: First, the seasonal denoised data determined in the above seasonal iteration step are Add to the target seasonal denoised data sequence, where the target seasonal denoised data sequence is initially empty. Then, the last target seasonal noise data in the target seasonal noise data sequence is determined as the first target seasonal denoised data sequence. denoised data for each target season.
[0080] In the second sub-step, the difference between the number of mixing iterations and the preset iteration value is determined as the target number of mixing iterations.
[0081] In step 4, in response to determining that the target number of mixing iterations satisfies a preset iteration condition, the target number of mixing iterations is determined as the mixing iteration number, and the mixed denoised data is determined as the transit mixed noise data for performing the above-mentioned mixing iteration step again. The preset iteration condition may be that the target number of mixing iterations is 0.
[0082] In a fifth step, in response to determining that the target number of mixing iterations does not satisfy a preset iteration condition, the mixed denoised data is determined as mixed denoised data.
[0083] This application can be tested using the following formula: Since the distinction between abnormal and normal time series is based on reconstruction error, the larger the error, the higher the possibility of abnormality. For mixed anomalies in time series, this application provides the following definition: , in, represents the mixed anomaly score, represents the original time series data, represents the generated time series data, Indicates the length of the time series. At the same time, the time series in the above formula Replace with trend item and seasonal items , calculate the trend anomaly score respectively and seasonal anomaly scores Then, by integrating the mixed anomaly score, trend anomaly score, and seasonal anomaly score, we get the final overall anomaly score: , in, represents the overall abnormality score, 、 and represents the balancing hyperparameter. For example, It can be 0.3, It can be 0.3, It can be 0.4.
[0084] Based on previous research work, this application calculates the threshold based on training data. Given training data , the corresponding decision threshold is: , in, represents the decision threshold, express The average value calculation function of , it is determined to be an abnormal sample; otherwise, it is determined to be a normal sample.
[0085] The aforementioned embodiments of the present application have the following beneficial effects: Through the time series data anomaly detection method based on a dynamic conditional diffusion model based on gradient noise, some embodiments of the present application propose a dynamic conditional diffusion model (GNDC-DM) based on gradient noise for time series anomaly detection. This framework designs three dedicated detection channels, one for detecting trend anomalies, one for detecting seasonal anomalies, and one for detecting mixed anomalies. In the trend and seasonal channels, gradient noise is introduced as an alternative to traditional Gaussian noise. This noise design effectively attenuates outliers, thereby amplifying the reconstruction error of outliers and improving detection performance. This noise consists of two components: a gradient-guided noise that enhances normal trends (or seasonal patterns); and a random Gaussian component that maintains sample diversity. The gradient component leverages the characteristic that outliers typically deviate from the normal trend (or seasonal pattern) of their surroundings in the gradient direction. By aligning with the normal gradient, it naturally suppresses abnormal fluctuations. The Gaussian component introduces appropriate randomness to prevent the model from falling into deterministic bias while maintaining sample diversity. By integrating these two components, the noise design proposed in this application minimizes perturbations to the normal pattern during the reconstruction process while systematically migrating outliers toward the normal manifold, effectively suppressing anomalies while robustly preserving the normal structure. In the mixed channel, this application dynamically combines trend noise and seasonal noise at each time step, using them as a conditional guided diffusion model for time series reconstruction. By aligning the generated data to normal trend and seasonal patterns, this design effectively suppresses anomalous components along these two dimensions, making mixed anomalies easier to distinguish and detect. Unlike static conditions (such as global trends or seasonal averages), this method dynamically synchronizes the generation process with the temporal characteristics of the input data by gradually extracting trend and seasonal information at each time step. This design ensures consistency of the generated output within a local area and more closely matches the distribution of normal data. Ultimately, data points containing mixed anomalies tend to produce larger errors in the reconstruction, making detection based on reconstruction scores more effective.
[0086] Further references Figure 3 As an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a time series data anomaly detection device based on a dynamic conditional diffusion model of gradient noise. These embodiments of the time series data anomaly detection device based on a dynamic conditional diffusion model of gradient noise are similar to Figure 1 Corresponding to the method embodiments shown, the time series data anomaly detection device based on the dynamic conditional diffusion model of gradient noise can be specifically applied to various electronic devices.
[0087] like Figure 3As shown, in some embodiments, the time series data anomaly detection device 300 based on the dynamic conditional diffusion model of gradient noise includes: a determination unit 301, a trend noise detection unit 302, a seasonal noise detection unit 303 and a mixed noise detection unit 304. Among them, the determination unit 301 is configured to determine the GNDC-DM model, wherein the above-mentioned GNDC-DM model includes: a trend noise diffusion model, a seasonal noise diffusion model, and a mixed anomaly diffusion model; the trend noise detection unit 302 is configured to perform trend noise detection processing on the acquired initial industrial equipment data based on the trend noise diffusion model included in the above-mentioned GNDC-DM model to generate trend noise reduction data; the seasonal noise detection unit 303 is configured to perform seasonal noise detection processing on the acquired initial industrial equipment data based on the seasonal noise diffusion model included in the above-mentioned GNDC-DM model to generate seasonal noise reduction data; the mixed noise detection unit 304 is configured to perform mixed anomaly detection processing on the acquired initial industrial equipment data, the above-mentioned trend noise reduction data and the above-mentioned seasonal noise reduction data based on the mixed anomaly diffusion model included in the above-mentioned GNDC-DM model to generate equipment noise reduction data.
[0088] It can be understood that the various units described in the time series data anomaly detection device 300 based on the dynamic conditional diffusion model of gradient noise are similar to those in the reference Figure 1 Therefore, the operations, features and beneficial effects described above for the method are also applicable to the time series data anomaly detection device 300 based on the dynamic conditional diffusion model of gradient noise and the units included therein, and will not be repeated here.
[0089] This application also provides a computer device 400. Figure 4 As shown, computer device 400 includes a bus 401, a processor 402, a memory 403, and a communication interface 404. Processor 402, memory 403, and communication interface 404 communicate with each other via bus 401. Computer device 400 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in computer device 400.
[0090] The bus 401 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 4The bus 401 may include a path for transmitting information between various components of the computer device 400 (eg, the memory 403, the processor 402, and the communication interface 404).
[0091] The processor 402 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0092] The memory 403 may include a volatile memory, such as a random access memory (RAM). The memory 403 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0093] Memory 403 stores executable program code, which processor 402 executes to implement the functions of the aforementioned determination unit, trend noise detection unit, seasonal noise detection unit, and mixed noise detection unit, thereby implementing the aforementioned method for detecting anomalies in time series data using a dynamic conditional diffusion model with gradient noise. In other words, memory 403 stores instructions for executing the aforementioned method for detecting anomalies in time series data using a dynamic conditional diffusion model with gradient noise.
[0094] The communication interface 404 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computer device 400 and other devices or a communication network.
[0095] An embodiment of the present application also provides a chip, which includes a processor and a data interface. The processor reads instructions stored in a memory through the data interface to execute the above-mentioned time series data anomaly detection method based on the dynamic conditional diffusion model of gradient noise.
[0096] Embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium can be any available medium capable of being stored by a computing device, or a data storage device such as a data center that contains one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, hard disk, or magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to execute the above-described method for detecting anomalies in time series data using a dynamic conditional diffusion model based on gradient noise.
[0097] Figure 5 This is a schematic diagram describing some data sets for experimental verification of the time series data anomaly detection method based on the dynamic conditional diffusion model with gradient noise in this application.
[0098] like Figure 5 As shown in the figure, this application evaluates the effectiveness of the GNDC-DM model on four publicly available and widely used time series anomaly detection benchmark datasets: MSL (Mars Science Laboratory), SMD (Server Machine Dataset), SWaT (Secure Water Treatment), and PSM (Pooled Server Metrics).
[0099] This application conducts a comprehensive evaluation of GNDC-DM by comparing it with several baseline methods from different categories: (1) Clustering-based methods (such as DeepSVDD (Deep Support Vector Data Description), THOC (Temporal Hierarchy Open Clustering), and ITAD (Industrial Time-series Anomaly Detection)) group data sequences into clusters and detect anomalies by measuring their distance to the cluster. (2) Prediction-based models (such as LSTM (Long Short-Term Memory) and CL-MPPCA (Clustered Mixtures of Probabilistic Principal Component Analyzers)) train a prediction model, estimate future values based on a context window of previous observations, and label anomalies based on the difference between the predicted and actual values. (3) Reconstruction-based methods (such as LSTM-VAE (Long Short-Term Memory Variational Autoencoder), BeatGAN (Beat Generative Adversarial Network), OmniAnomaly (Omnidirectional Anomaly Detection), ATransformer (Anomaly-aware Transformer), and TFMAE (Transformer-based Masked Autoencoder) encode subsequences of normal training time series into a latent space, reconstruct the sequence, and use the reconstruction error to detect anomalies. (4) Filling-based methods (such as DiffAD (Diffusion-based Anomaly Detection) and ImDiffusion (Implicit Diffusion Model)) estimate missing values through filling techniques and identify anomalies based on the size of the estimation error.
[0100] The experiments were conducted using PyTorch (a deep learning framework) and a single NVIDIA RTX 24GB GPU. All datasets were optimized using the Adam optimizer with default parameters and an initial learning rate of The batch size is set to 16. The number of diffusion steps of GNDC-DM is set to 100. The hyperparameters and detection thresholds of the baseline model are adjusted according to the settings of the original study.
[0101] Figure 6 Schematic diagram of the performance comparison between GNDC-DM according to the present application and the baseline method on four datasets.
[0102] Figure 6 The performance of GNDC-DM against baseline methods on multiple datasets in terms of precision (P), recall (R), and F1 score (balanced F-score) is demonstrated. All results are averaged across multiple runs to ensure robustness. GNDC-DM achieves the highest average F1 score across the four datasets, outperforming the baseline methods and demonstrating its effectiveness in time series anomaly detection. Specifically, our model achieves F1 scores of 95.27% and 95.34% on the SMD and MSL datasets, respectively. This improvement is attributed to our decoupled anomaly detection modeling approach, which effectively captures multiple anomaly types and improves performance. Results on industrial datasets further validate the practical applicability of GNDC-DM. On the SWaT and PSM datasets, our method achieves F1 scores of 97.77% and 98.07%, respectively, setting new benchmarks in the field. GNDC-DM successfully reduces anomalous components in time series using gradient noise while maintaining a good precision-recall balance.
[0103] Figure 7 It is a schematic diagram comparing the F1 scores of different components.
[0104] A systematic ablation experiment is conducted to evaluate the effectiveness of each component in GNDC-DM and explore how these components improve the anomaly detection performance. Figure 7 The anomaly detection results of different component combinations on all datasets are summarized. It should be noted that all results in the table use F1 score as the evaluation indicator, and the values are the average of multiple independent experiments. Figure 7 The functions of each component are explained as follows: (i) Noise component: applies gradient noise to the data during the diffusion process; (ii) Trend component: detects trend anomalies through trend decomposition and trend reconstruction; (iii) Season component: detects periodic anomalies through seasonal decomposition and seasonal reconstruction; (iv) Hybrid component: uses hybrid reconstruction method to detect compound anomalies in residual data.
[0105] Figure 7The data shows limited performance improvement when using only gradient noise and hybrid reconstruction components. This suggests that while gradient noise effectively disrupts anomaly patterns (making it more effective than Gaussian noise in detecting them), a single model still struggles to effectively handle diverse anomaly types. However, system performance is significantly improved by introducing trend reconstruction or seasonal reconstruction components—these components specifically target trend- and cyclical anomalies, respectively—to comprehensively optimize overall detection.
[0106] Figure 8 It is based on the preset trend seasonal conditions of this application Schematic diagram of parameter impact analysis.
[0107] Here, this application deeply analyzes the role of key hyperparameters in the two core formulas of GNDC-DM. First, for the above preset trend seasonal conditions Parameters, tested on four datasets with different The precision (P), recall (R) and F1 score under the value. Figure 8 As shown, the SMD and PSM datasets are = 0.6 achieves the best performance - this is due to the characteristics of its server collection data: anomalies mainly manifest as periodic patterns (such as daily server load cycles) and sudden deviations (such as resource contention peaks), so it is necessary to balance the integration detection of time trends and seasonal components. In contrast, the SWaT dataset that records continuous attacks on industrial water treatment systems (such as pump control manipulation across multiple operation cycles) has the best performance at higher The performance of the MSL dataset is better, highlighting the importance of long-term time series dependence. However, the MSL dataset containing transient anomalies caused by random equipment failures (such as sensor drift in Mars environmental data) is =0.4, which peaks at a lower setting that focuses more on statistical outlier detection rather than time series modeling, which is consistent with the sporadic nature of anomalies in this dataset.
[0108] Figure 9 are two key hyperparameters in the formula of trend gradient noise according to this application and Schematic diagram of the impact analysis.
[0109] This application analyzes two key hyperparameters in the formula of trend gradient noise and Sensitivity. Figure 9 As shown in Figure 2, the following important conclusions can be drawn based on the experimental results of four datasets: Influence of parameters: when When the value increases from 0.1 to 0.7, the detection performance of all datasets is significantly improved. This verifies that gradient alignment noise can effectively suppress abnormal signals by strengthening normal time series trends. When the value is too high (>0.7), the performance decreases, indicating that over-reliance on gradient direction will distort the normal data pattern and lead to a decrease in overall detection accuracy.
[0110] Influence of parameters: when When it is in the range of 0.5~0.7, moderate The value can achieve the best balance between the following two aspects: 1) Diversity: Gaussian noise enhances the model’s coverage of abnormal patterns 2) Fidelity: Maintaining the integrity of the temporal characteristics of normal data This shows that a reasonable Gaussian noise level can improve the generalization ability of the model. When the value is too high, excessive randomness will dilute the normal component contribution in the gradient noise, thereby weakening the model's anomaly detection ability.
[0111] Therefore, through the time series data anomaly detection method based on the dynamic conditional diffusion model of gradient noise in some embodiments of this application, a customized solution is provided through three dedicated detection channels (trend-type, periodic-type, and mixed-type anomalies) to address the two core flaws of existing methods (the poor anomaly suppression effect of standard Gaussian noise and the coupling problem of different types of anomaly detection). GNDC-DM, a new time series anomaly detection framework based on the dynamic conditional diffusion model, proposed in this application, combines gradient guidance and random perturbation elements to completely preserve the normal data structure while destroying the anomaly pattern. The dynamic condition strategy adopted by the hybrid channel enables the model to adapt to complex time series patterns, significantly improving the ability to identify complex anomalies. Extensive experiments on multiple real-world datasets have demonstrated that GNDC-DM reaches the state-of-the-art level in both detection accuracy and generalization ability, verifying its effectiveness and robustness.
[0112] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0113] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the protection scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for detecting anomalies in time series data based on a dynamic conditional diffusion model with gradient noise, comprising: Determine a GNDC-DM model, wherein the GNDC-DM model includes: a trend noise diffusion model, a seasonal noise diffusion model, and a mixed anomaly diffusion model; Based on the trend noise diffusion model included in the GNDC-DM model, trend noise detection processing is performed on the acquired initial industrial equipment data to generate trend noise reduction data; Based on the seasonal noise diffusion model included in the GNDC-DM model, seasonal noise detection processing is performed on the acquired initial industrial equipment data to generate seasonal noise reduction data; Based on the mixed anomaly diffusion model included in the GNDC-DM model, mixed anomaly detection processing is performed on the acquired initial industrial equipment data, the trend noise reduction data and the seasonal noise reduction data to generate equipment noise reduction data.
2. The method for detecting anomalies in time series data based on a dynamic conditional diffusion model with gradient noise according to claim 1, wherein: The trend noise diffusion model included in the GNDC-DM model is used to perform trend noise detection processing on the acquired initial industrial equipment data to generate trend noise reduction data, including: Based on the preset constraint conditions and Gaussian noise, the trend gradient noise is determined, where the trend gradient noise is: , in, represents the trend gradient noise, represents a trend time series, Representing time series The gradient, express The module length, To prevent A small constant introduced by a division error near zero, represents Gaussian noise, , represents the modulus of Gaussian noise, and represents an adjustable hyperparameter, which is used to control the relative contribution ratio of the gradient-guided noise component and the random noise component; Based on a preset trend forward diffusion formula, the target trend noise data sequence is determined using the trend gradient noise and the initial industrial equipment data, wherein the preset trend forward diffusion formula is: , in, Indicates the first Target trend noise data, Indicates the serial number, , represents the number of iterations, , , represents the preset variance scheduling parameter, Indicates initial trend data corresponding to initial industrial equipment data; Based on the target trend noise data sequence, a trend loss function corresponding to the trend noise diffusion model is determined, wherein the trend loss function is: , in, represents the trend loss function, Express expectations, Indicated by the parameter Parameterized denoising neural network, express The parameter set in ; Based on a preset trend reverse growth formula, the trend noise diffusion model and the target trend noise data sequence are used to determine trend noise reduction data.
3. The method for detecting anomalies in time series data based on a dynamic conditional diffusion model with gradient noise according to claim 2, wherein: The method of determining the trend noise reduction data based on a preset trend reverse growth formula and utilizing the trend noise diffusion model and the target trend noise data sequence includes: Determine the number of trend iterations; Determine the last target trend noise data in the target trend noise data sequence as the transit trend noise data; Based on the number of trend iterations and the transit trend noise data, the following trend iteration steps are performed: Based on a preset trend reverse growth formula, the trend noise diffusion model and the transit trend noise data are used to determine the trend denoised data, wherein the preset trend reverse growth formula is: , in, represents trend denoised data, represents transit trend noise data; The difference between the trend iteration number and the preset iteration value is determined as the target trend iteration number; In response to determining that the target trend iteration number satisfies a preset trend iteration condition, determining the target trend iteration number as the trend iteration number, and determining the trend denoised data as the transit trend noise data for performing the trend iteration step again; In response to determining that the target trend iteration number does not satisfy a preset trend iteration condition, the trend denoised data is determined to be trend noise reduced data.
4. The method for detecting anomalies in time series data based on a dynamic conditional diffusion model with gradient noise according to claim 2, wherein: The seasonal noise diffusion model included in the GNDC-DM model is used to perform seasonal noise detection processing on the acquired initial industrial equipment data to generate seasonal noise reduction data, including: Determine seasonal gradient noise based on preset constraints and Gaussian noise; Based on a preset seasonal forward diffusion formula, the target seasonal noise data sequence is determined using the seasonal gradient noise and the initial industrial equipment data, wherein the preset seasonal forward diffusion formula is: , in, represents the first target seasonal noise data, represents the initial seasonal data corresponding to the initial industrial equipment data, represents seasonal gradient noise; Determining a seasonal loss function corresponding to the seasonal noise diffusion model based on the target seasonal noise data sequence; Based on a preset seasonal inverse growth formula, seasonal noise reduction data is determined using the seasonal noise diffusion model and the target seasonal noise data sequence.
5. The method for detecting anomalies in time series data based on a dynamic conditional diffusion model with gradient noise according to claim 4, wherein: The seasonal noise reduction data is determined based on a preset seasonal inverse growth formula by using the seasonal noise diffusion model and the target seasonal noise data sequence, including: Determine the number of seasonal iterations; The last target season noise data in the target season noise data sequence is determined as the transit season noise data; Based on the seasonal iteration number and the transit seasonal noise data, the following seasonal iteration steps are performed: Based on a preset seasonal inverse growth formula, seasonal denoised data is determined using the seasonal noise diffusion model and the transit seasonal noise data, wherein the preset seasonal inverse growth formula is: , in, represents seasonal denoised data, represents the transit season noise data, represents a denoising neural network; The difference between the number of seasonal iterations and the preset iteration value is determined as the target number of seasonal iterations; In response to determining that the target seasonal iteration number satisfies a preset seasonal iteration condition, determining the target seasonal iteration number as the seasonal iteration number, and determining the seasonal denoised data as the transit seasonal noise data for performing the seasonal iteration step again; In response to determining that the target seasonal iteration number does not satisfy a preset seasonal iteration condition, the seasonal denoised data is determined to be seasonal denoised data.
6. The method for detecting anomalies in time series data based on a dynamic conditional diffusion model with gradient noise according to claim 4, wherein: The hybrid anomaly diffusion model included in the GNDC-DM model is used to perform hybrid anomaly detection processing on the acquired initial industrial equipment data, the trend noise reduction data, and the seasonal noise reduction data to generate equipment noise reduction data, including: Determine the mixed gradient noise based on the preset constraints and Gaussian noise; Based on a preset mixed forward diffusion formula, the target mixed noise data sequence is determined using the mixed gradient noise and the initial industrial equipment data; Based on the initial industrial equipment data, the target mixed noise data sequence, the target trend noise data sequence corresponding to the trend noise reduction data, and the target seasonal noise data sequence corresponding to the seasonal noise reduction data, a mixed loss function corresponding to the mixed anomaly diffusion model is determined, wherein the mixed loss function is: , in, represents the mixed loss function, Express expectations, represents the initial mixed data corresponding to the initial industrial equipment data, Indicated by The parameterized denoising neural network has the following input: , the condition variable is and , represents the first target mixed noise data, Indicates the first Target trend noise data, represents the first Target seasonal noise data; Based on a preset trend seasonal condition, a cross attention model included in the mixed abnormal diffusion model is determined, wherein the preset trend seasonal condition is: , in, Indicates the preset trend seasonal conditions, represents the weight coefficient, Among them, the cross attention model is: , in, represents the cross attention model, represents the query vector, Indicates that the condition is embedded through the embedding layer The converted Represents the embedding vector length, Represents the dimension, , Indicates the key, , represents the temporal input representation of each layer’s cross attention, Represents a value, , represents the query matrix, represents the bond matrix, represents the value matrix; Based on a preset mixed inverse growth formula, the equipment noise reduction data is determined using the mixed anomaly diffusion model and the target mixed noise data sequence.
7. The method for detecting anomalies in time series data based on a dynamic conditional diffusion model with gradient noise according to claim 6, wherein: The method of determining the device noise reduction data based on a preset mixed inverse growth formula and utilizing the mixed anomaly diffusion model and the target mixed noise data sequence includes: Determine the number of mixing iterations; determining the last target mixed noise data in the target mixed noise data sequence as the transit mixed noise data; Based on the number of mixing iterations and the intermediate mixed noise data, the following mixing iteration steps are performed: Based on a preset mixed inverse growth formula, the mixed anomaly diffusion model and the transit mixed noise data are used to determine the mixed denoised data, wherein the preset mixed inverse growth formula is: , in, represents mixed denoised data, represents the transit mixed noise data, represents the first Target trend denoised data, represents the first target seasonal denoised data, wherein the target trend denoised data sequence is determined by each trend denoised data and the target trend noise data sequence, and the target seasonal denoised data sequence is determined by each season denoised data and the target seasonal noise data sequence; The difference between the number of mixing iterations and the preset iteration value is determined as the target number of mixing iterations; In response to determining that the target number of mixing iterations satisfies a preset iteration condition, determining the target number of mixing iterations as the number of mixing iterations, and determining the mixed denoised data as the transit mixed noise data for performing the mixing iteration step again; In response to determining that the target number of mixing iterations does not satisfy a preset iteration condition, the mixed denoised data is determined to be mixed denoised data.
8. A device for detecting anomalies in time series data based on a dynamic conditional diffusion model with gradient noise, comprising: A determination unit is configured to determine a GNDC-DM model, wherein the GNDC-DM model includes: a trend noise diffusion model, a seasonal noise diffusion model, and a mixed anomaly diffusion model; a trend noise detection unit configured to perform trend noise detection processing on the acquired initial industrial equipment data based on the trend noise diffusion model included in the GNDC-DM model to generate trend noise reduction data; a seasonal noise detection unit configured to perform seasonal noise detection processing on the acquired initial industrial equipment data based on the seasonal noise diffusion model included in the GNDC-DM model to generate seasonal noise reduction data; The mixed noise detection unit is configured to perform mixed anomaly detection processing on the acquired initial industrial equipment data, the trend noise reduction data and the seasonal noise reduction data based on the mixed anomaly diffusion model included in the GNDC-DM model to generate equipment noise reduction data.
9. A computer device, wherein: The computer device comprises a processor, a memory, and a computer program stored in the memory and executable by the processor, wherein when the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium, wherein: The computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Time series data anomaly detection method and device
CN116226770A
Network flow prediction system based on time sequence decomposition
CN116992986A
Abnormality detection method based on time series data prediction
CN118171214A
Electric energy meter anomaly detection method and device based on diffusion model
CN118501795A
Abnormality detection method based on multi-scale time convolution network and seasonal decomposition
CN118520396A
Cited By
Time sequence anomaly detection method, electronic equipment and medium
CN121256649A
Industrial control anomaly detection method and system based on dual-path noise adjustment
CN121523311A