Intelligent anomaly recognition and intervention processing method, device and equipment and medium

By updating dynamic knowledge graphs and performing feature fusion and causal reasoning in the fields of financial technology and healthcare, the problem of anomaly identification in multi-source data environments is solved, high-precision real-time detection and intervention processing are achieved, and the system's feature expression and decision-making accuracy are improved.

CN120744749APending Publication Date: 2025-10-03PING AN TECH (SHENZHEN) CO LTD
View PDF 0 Cites 25 Cited by

Patent Information

Application Number
CN202510862159.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-25
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

Existing technologies in the fields of financial technology and healthcare have difficulty effectively identifying abnormal behaviors in complex cross-account fund flows and high-frequency streaming data. They lack the ability to integrate multi-source heterogeneous data, and deep learning models lack interpretability and real-time reasoning efficiency, making it difficult to meet the requirements of decision-making transparency and high accuracy.

Method used

By acquiring multi-source data to update the dynamic knowledge graph, extracting text, time series and graph embedding feature vectors, using the gated fusion network for feature fusion, generating preliminary anomaly scores, and determining the reconstruction error through the autoencoder, building a causal graph model for counterfactual reasoning, and generating the final anomaly score and intervention instructions.

Benefits of technology

It achieves real-time, high-precision detection and closed-loop intervention of abnormal behaviors in a multi-source data environment, enhances feature expression capabilities, improves warning accuracy and decision-making interpretability, and improves the ability to recognize complex abnormal patterns.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120744749A_ABST
    Figure CN120744749A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of artificial intelligence, can be applied to business scenes of financial science and technology, medical health and the like, and discloses an intelligent anomaly recognition and intervention processing method, device, equipment and medium. The method comprises the following steps: carrying out feature fusion by using a gating fusion network and generating a preliminary abnormal score, determining a reconstruction error through an auto-encoder and triggering abnormal early warning, calculating a causal effect value of key features in combination with a causal graph model and anti-factual reasoning, and calibrating the abnormal score to generate a final abnormal score and an intervention instruction. And executing an intervention action and recording a result. According to the method, the multi-dimensional feature information and the causal reasoning mechanism are fused, the self-encoder reconstruction error is combined to carry out anomaly judgment, the intervention instruction is generated and executed, closed-loop control of anomaly detection, reasoning analysis and intervention execution is achieved, and the recognition accuracy of complex events and the system response capacity are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence technology, and in particular to an intelligent anomaly identification and intervention processing method, device, equipment and storage medium. Background Art

[0002] In the fintech business sector, traditional anti-fraud risk control methods primarily rely on manually constructed feature engineering and rule-based judgment systems. While such methods have demonstrated certain practicality in initial applications, their limitations are becoming increasingly prominent in the face of rapidly evolving fraud methods. In particular, when dealing with new types of fraud gangs with complex cross-account fund flow relationships, traditional models struggle to capture deep temporal correlations and structural features from raw transaction data, resulting in low fraud identification efficiency and narrow coverage. Furthermore, the maintenance of rule systems often lags behind the evolution cycle of fraudulent behavior. When faced with complex behavioral patterns such as dynamic IP jumps and false identity combinations, static rules often fail to update the identification logic in a timely manner, leaving blind spots in risk identification.

[0003] In the healthcare business, abnormal event identification typically relies on rule matching based on indicator thresholds and static models set by expert experience, making it difficult to effectively adapt to the dynamic changes in patient behavior data and device operation data. Faced with high-frequency streaming data such as electrocardiograms, vital signs, or device logs collected in real time, existing systems lack the ability to deeply analyze time series patterns and potential causal relationships, which affects the timely discovery and response to sudden health abnormalities or device risk events. In addition, because medical data often comes from complex sources, including electronic medical records, wearable device monitoring data, clinical diagnostic records, etc., existing systems are insufficient in their ability to integrate multi-source heterogeneous data, which can easily lead to information fragmentation and context disconnection, affecting the accuracy of global judgments.

[0004] In the field of pan-intelligent anomaly detection technology, although some deep learning models possess end-to-end learning capabilities, these models often lack interpretability and struggle to meet the stringent requirements for decision transparency in financial and healthcare scenarios. In particular, in compliance scenarios requiring tracing back to explain why the current event is considered an anomaly, existing technologies cannot effectively support the extraction of key decision paths and the clear expression of causal logic. Furthermore, when processing high-frequency, real-time data, traditional models suffer from low reasoning efficiency. This is particularly true in large-scale deployment scenarios, where low-latency, high-accuracy judgments within strict time windows are difficult to achieve, limiting their real-time application value. Existing models also have limited collaborative modeling capabilities for multimodal data features and lack mechanisms for unified modeling and effective integration of structured knowledge, time series features, and unstructured information, further impacting the ability to identify complex anomaly patterns. Summary of the Invention

[0005] The main purpose of the present invention is to provide an intelligent anomaly identification and intervention processing method, device, equipment and storage medium, aiming to solve the technical problem of how to adaptively integrate dynamic knowledge graphs, temporal features and text semantics in a multi-source data environment, and realize real-time and high-precision anomaly detection and closed-loop intervention based on causal reasoning.

[0006] To achieve the above objectives, the present invention provides an intelligent anomaly identification and intervention processing method, comprising:

[0007] Acquire multi-source data and update the dynamic knowledge graph based on the multi-source data;

[0008] Acquire entity association information based on the updated dynamic knowledge graph, and extract text feature vectors, time series feature vectors, and graph embedding feature vectors based on the entity association information;

[0009] The text feature vector, the time series feature vector and the graph embedding feature vector are fused into a fused feature vector through a gated fusion network;

[0010] generating a preliminary anomaly score based on the fused feature vector;

[0011] Inputting the fused feature vector into an autoencoder to determine a reconstruction error, and generating an abnormal warning signal when the reconstruction error exceeds a dynamic threshold;

[0012] In response to the abnormal warning signal, a causal graph model is constructed and the causal effect value of the key feature is determined through counterfactual reasoning;

[0013] calibrating the preliminary anomaly score using the causal effect value to generate a final anomaly score and an anomaly intervention instruction;

[0014] Execute the abnormal intervention instruction and record the instruction execution result.

[0015] Furthermore, to achieve the above objectives, the present invention provides an intelligent anomaly identification and intervention processing device, comprising:

[0016] A graph updating module, configured to acquire multi-source data and update a dynamic knowledge graph based on the multi-source data;

[0017] A feature extraction module is used to obtain entity association information based on the updated dynamic knowledge graph, and to extract text feature vectors, time series feature vectors, and graph embedding feature vectors based on the entity association information;

[0018] A feature fusion module, configured to fuse the text feature vector, the time series feature vector, and the graph embedding feature vector into a fused feature vector through a gated fusion network;

[0019] a preliminary anomaly scoring module, configured to generate a preliminary anomaly score based on the fused feature vector;

[0020] An anomaly detection module, configured to input the fused feature vector into an autoencoder to determine a reconstruction error, and generate an anomaly warning signal when the reconstruction error exceeds a dynamic threshold;

[0021] A causal analysis module, configured to construct a causal graph model in response to the abnormal warning signal and determine the causal effect value of the key feature through counterfactual reasoning;

[0022] an anomaly intervention generating module, configured to calibrate the preliminary anomaly score using the causal effect value to generate a final anomaly score and an anomaly intervention instruction;

[0023] An instruction execution module is used to execute the abnormal intervention instruction and record the instruction execution result.

[0024] Furthermore, to achieve the above-mentioned purpose, the present invention also provides a computer device, which includes a memory, a processor, and an intelligent anomaly identification and intervention processing program stored in the memory and capable of running on the processor. When the intelligent anomaly identification and intervention processing program is executed by the processor, the steps of the intelligent anomaly identification and intervention processing method described above are implemented.

[0025] Furthermore, to achieve the above-mentioned purpose, the present invention also provides a computer-readable storage medium, on which an intelligent anomaly identification and intervention processing program is stored. When the intelligent anomaly identification and intervention processing program is executed by a processor, the steps of the intelligent anomaly identification and intervention processing method as described above are implemented.

[0026] Beneficial effects: The present invention relates to the field of artificial intelligence technology and can be applied to business scenarios such as financial technology and medical health. It discloses an intelligent anomaly identification and intervention processing method, device, equipment and medium, including: obtaining multi-source data, updating a dynamic knowledge graph based on the multi-source data; obtaining entity association information based on the updated dynamic knowledge graph, and extracting text feature vectors, time series feature vectors and graph embedding feature vectors; fusing the above feature vectors into a fused feature vector through a gated fusion network to generate a preliminary anomaly score; inputting the fused feature vector into an autoencoder, calculating the reconstruction error, and generating an anomaly warning signal when it exceeds a dynamic threshold; constructing a causal graph model, determining the causal effect value of the key feature through counterfactual reasoning; calibrating the preliminary anomaly score based on the causal effect value, generating a final anomaly score and an anomaly intervention instruction; executing the anomaly intervention instruction and recording the instruction execution results. The present invention enhances the feature expression capability of anomaly identification by fusing three types of features: text, time series and graph embedding; improves the warning accuracy by the dynamic threshold recognition mechanism of the reconstruction error; introduces a causal graph model and a counterfactual reasoning mechanism to improve the interpretability and accuracy of anomaly decision-making. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] The present invention will be further described below with reference to the accompanying drawings and embodiments, in which:

[0028] Figure 1 A schematic diagram of an application environment of an intelligent anomaly identification and intervention processing method according to an embodiment of the present invention;

[0029] Figure 2 This is a flow chart of an embodiment of the intelligent abnormality identification and intervention processing method of the present invention;

[0030] Figure 3 This is a functional module diagram of a preferred embodiment of the intelligent abnormality identification and intervention processing device of the present invention;

[0031] Figure 4 A schematic diagram of the structure of a computer device according to an embodiment of the present invention;

[0032] Figure 5 FIG. 2 is another structural diagram of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0033] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0034] The intelligent abnormality identification and intervention processing method provided by the embodiment of the present invention can be applied in Figure 1 In an application environment, the user end communicates with the server end through a network. The server end can obtain multi-source data through the user end, and update the dynamic knowledge graph based on the multi-source data; obtain entity association information based on the updated dynamic knowledge graph, and extract text feature vectors, time series feature vectors and graph embedding feature vectors; fuse the above feature vectors into a fused feature vector through a gated fusion network to generate a preliminary anomaly score; input the fused feature vector into the autoencoder, calculate the reconstruction error, and generate an abnormal warning signal when it exceeds the dynamic threshold; construct a causal graph model, and determine the causal effect value of the key feature through counterfactual reasoning; calibrate the preliminary anomaly score based on the causal effect value, generate the final anomaly score and abnormal intervention instruction; execute the abnormal intervention instruction and record the instruction execution result. The present invention enhances the feature expression ability of anomaly identification by fusing three types of features: text, time series and graph embedding; improves the warning accuracy by the dynamic threshold recognition mechanism of reconstruction error; introduces the causal graph model and counterfactual reasoning mechanism to improve the interpretability and accuracy of abnormal decision-making. Among them, the user end can be but is not limited to various personal computers, laptops, smart phones, tablets and portable wearable devices. The server end can be implemented with an independent server or a server cluster consisting of multiple servers. The present invention is described in detail below through specific examples.

[0035] See also Figure 2 , Figure 2 This is a flow chart of an embodiment of the intelligent anomaly identification and intervention processing method provided by the present invention. It should be noted that although the logical order is shown in the flow chart, in some cases, the steps shown or described may be performed in a different order than here.

[0036] like Figure 2 As shown, the intelligent anomaly identification and intervention processing method proposed by the present invention includes the following steps:

[0037] S10, acquiring multi-source data, and updating a dynamic knowledge graph based on the multi-source data;

[0038] In this embodiment, obtaining multi-source data includes the operation of collecting information from different sources and different structural forms. The scope of multi-source data can include structured data, semi-structured data and unstructured data. Structured data, such as transaction tables, medical record tables, behavior log tables, etc. in relational databases, have stable data fields and clear entity identifiers; semi-structured data, such as real-time monitoring records in JSON format or user reports in XML format, have flexible but parsable data hierarchies; unstructured data includes text reports, image files, voice recordings, etc., which need to be pre-processed through a dedicated parsing model. The collection process needs to build a unified data access interface and design a distributed data collection process for the access protocols of each data source (such as HTTP, FTP, JDBC, Kafka, etc.). To ensure timeliness, the data collection module can integrate a timestamp synchronization mechanism and configure the data sampling frequency or change the trigger strategy.

[0039] Based on the acquired data content, data preprocessing operations need to be performed to achieve field alignment, noise removal, encoding conversion, etc., to ensure the semantic consistency and calculation accuracy of subsequent processing. For problems such as inconsistent data dimensions, format conflicts, missing values, etc., feature mapping, data reduction, interpolation filling and other algorithms can be used. After completing the basic cleaning, further identify entity sets with related meanings based on the application scenario, including but not limited to user accounts, patient identification, medical equipment numbers, transfer channel identification, etc. Each type of entity should be equipped with a unique identification code, basic attribute fields and time tags.

[0040] The process of updating the dynamic knowledge graph depends on the parsing results of the aforementioned entity data. A dynamic knowledge graph refers to a graph structure model that can be updated in real time as the data stream changes. The graph model uses nodes to represent entities and edges to represent the relationship between entities, and each edge and node carries semantic information. The update operation includes two directions: one is to add new nodes and edges, and the other is to make temporal corrections to existing node attributes or edge weights. In the implementation, ontology constraint rules can be constructed to constrain the legitimacy of entity categories and relationship types. At the same time, the data structure of the knowledge graph can be maintained through a graph database (such as Neo4j, JanusGraph) or a graph computing framework (such as DGL, PyG). During the update process, lifecycle management strategies need to be designed for data of different timeliness, such as setting entity timeout mechanisms and dynamic calculation rules for relationship confidence, to avoid information overload or redundant diffusion in the graph.

[0041] After the graph structure is generated, it is necessary to use the inference engine to strengthen the entity relationship, such as mining indirect associations through path sampling algorithms, or using nested graph convolution models to generate contextual structured representations. At the same time, the ability to introduce external information sources is a key link in graph updates. External information may come from blacklist libraries, exception notification systems, regulatory instruction release channels, etc. In order to ensure the scalability of the system, a pluggable interface structure should be designed so that new information can directly participate in graph fusion as external entities or external edges. In dealing with the computational overhead of graph updates, graph partitioning technology can be introduced to divide the entire graph into several subgraphs, and incremental calculations are only performed on the local subgraphs where updates occur, thereby reducing the overall computational load.

[0042] By building a unified data access bus, we can coordinate multi-source data access and introduce a data type recognition mechanism to automatically distribute data to the corresponding parsing modules. For structured data, field extraction and format standardization can be performed directly through the ETL pipeline. For unstructured data, NLP engines or OCR modules can be used to extract entities and perform semantic annotation. For time-series sensor data, time window slicing technology can be used for standardization.

[0043] Industry ontology dictionaries can be constructed for data types across different industries and combined with rule engines to assist in graph updates, further improving the accuracy of entity recognition within the graph. Graph neural networks can also be used to populate node attributes. When new data emerges but entity information is incomplete, the structure can be completed by sharing features from neighboring nodes. A dynamic backtracking mechanism for edge weights can also be designed for real-time, high-frequency updates. This ensures that edge weights reflect not only the current state but also historical activity, enhancing the ability to express behavioral trends.

[0044] Example: In the healthcare business, for multi-dimensional medical process data, heterogeneous data such as outpatient registration information, electronic medical records, medical imaging analysis results, and medical staff operation logs can be collected in real time, and integrated with patient risk level notification information from external medical supervision platforms. Through a unified entity extraction and relationship construction mechanism, patients, doctors, diseases, treatment methods, equipment calls, etc. are used as nodes, and weighted edges are established according to the order of data occurrence and interaction frequency to construct an evolvable graph structure. When receiving new image annotation results or medical abnormalities, the system can automatically incorporate new entity relationships, such as diagnostic confidence associations, semantic bridges between lesion labels, etc., and update the connection structure in the graph, so that potential misdiagnosis or equipment misuse risks can be discovered through the changing trends of local relationships in the graph before the patient shows obvious symptoms.

[0045] In the field of financial technology business, when facing cross-platform account operation behaviors, it is necessary to collect multi-source data in real time from payment flows, account authentication logs, device fingerprints, behavioral trajectories, and external judicial notices. The system abstracts users, devices, transaction channels, IP addresses, risk labels, etc. as entity nodes in the graph, and constructs multiple edges between entities through event triggering and behavior co-occurrence frequency. If a user performs high-frequency transactions in a short period of time through a new device, the system will identify their behavioral mutations through the graph structure of device-user-transaction path, and automatically update the external label attributes and historical behavior paths of the user node after introducing judicial notification information. This process realizes the dynamic correction of the graph structure after the addition of new data, thereby providing a higher structural confidence basis for anomaly inference, supporting the subsequent fusion feature construction stage to more accurately reflect the potential abnormal trends of transaction changes.

[0046] This embodiment uses multi-source data and implements a structured update graph structure, so that when the system faces complex changes in behavioral patterns, it can promptly incorporate new entities and relationships, dynamically reflect the evolution of risk factors, and thus improve the real-time and comprehensiveness of downstream anomaly identification.

[0047] S20, acquiring entity association information based on the updated dynamic knowledge graph, and extracting text feature vectors, time series feature vectors, and graph embedding feature vectors based on the entity association information;

[0048] In this embodiment, after being updated, the dynamic knowledge graph forms a structured representation containing multiple entities, multiple relationships, and multimodal attributes. To obtain a high-quality representation that can be used for subsequent anomaly identification, it is necessary to parse the local subgraph related to the current object to be analyzed and extract entity association information with contextual significance and temporal evolution value. Entity association information refers to the set of related entities and their edge relationship structure that can be traversed from the target entity through one or more hops. This includes dimensions such as semantic connections, behavioral co-occurrence, and event associations.

[0049] To construct a multimodal feature representation based on entity association information, text data must first be embedded and encoded. Extracting text feature vectors relies on obtaining natural language descriptions from attribute fields of the target entity or adjacent entities, such as event logs, user comments, and medical diagnosis records. This textual content is then fed into a language model to calculate semantic representations. This is typically done using deep pre-trained language models such as BERT and RoBERTa to generate fixed-dimensional text embeddings that represent the entity's contextual position at the semantic level.

[0050] For attributes such as behaviors, events, and operations that have a temporal dimension, time series feature vectors are used for modeling. Continuous event sequences with timestamps, such as transaction behaviors, treatment processes, and login records, are extracted from entity attributes. These sequences are then constructed in chronological order and fed into a recurrent neural network, such as an LSTM or GRU. This extracts a time series representation vector that captures long-term dependencies, serving as the modeling result for the entity's dynamic evolution path.

[0051] At the structural level, graph neural networks are used to perform graph embedding to model the topological relationships and semantic propagation paths between entities. With the target entity at the center, a subgraph structure is constructed between it and its neighboring nodes. This subgraph is then fed into the graph neural network for propagation and aggregation operations, resulting in a graph embedding feature vector. This process combines information such as edge type, edge weight, adjacency structure, and entity type to reflect the relative position and structural role of entities in the graph structure.

[0052] Through the above operations, three types of heterogeneous feature representations can be obtained, covering the semantic, temporal and structural modalities respectively, providing a highly expressive information basis for subsequent fusion and anomaly recognition.

[0053] During implementation, you can prioritize obtaining the target node's adjacent entities and their connections through the graph database query interface. Preprocess the text content in its attribute fields, including stop word removal, word segmentation, and spelling correction, and then input it into the language representation model in a unified encoding format. For multilingual scenarios, you can also select a model that supports cross-language embedding alignment for representation extraction.

[0054] For time series data, a sliding window mechanism can be used to extract fixed-length time series segments, or the window length can be dynamically adjusted to adapt to changes in behavior density, and then input into a pre-trained sequence modeling network for training or fine-tuning.

[0055] During graph embedding calculations, different graph neural network architectures such as GCN, GraphSAGE, and GAT can be used. For large-scale graphs, to reduce memory consumption and computational burden, local subgraphs can be constructed through sampling strategies, such as using neighbor sampling or importance sampling mechanisms, to improve model convergence speed and feature stability.

[0056] Regularization and dimensionality reduction can also be performed on the three types of feature vectors separately, such as using LayerNorm or PCA, to ensure the consistency and fusion feasibility of the feature dimensions of each modality and avoid information redundancy or bias amplification.

[0057] Example: In the healthcare business domain, the system extracts patients from electronic health records as target entities and further obtains multiple doctors, treatment plans, and examination results that have temporal co-occurrence relationships with the patient. By extracting free text from the medical record and embedding it, combining it with time series modeling of medication usage sequences and generating graph embedding vectors based on the graph structure of disease nodes, the system ultimately constructs a three-dimensional embedding of semantics, behavior, and structure for the patient, supporting the identification of potential misdiagnosis risks.

[0058] In the fintech business sector, the system targets a specific transaction account and retrieves its first-hop device entity, historical transaction objects, and corresponding behavior time series from the graph. At the text layer, the free fields entered in the account application form are parsed and encoded into embedding vectors. At the time series layer, the account's transaction amount over the past 48 hours is modeled. At the graph layer, a graph neural network is used to extract structural path information between the account and other fraudulent accounts. This ultimately forms a multimodal feature representation, supporting subsequent identification and decision-making for suspicious account behavior.

[0059] This embodiment effectively enhances the ability to express complex entity relationships by acquiring contextual information related to the target entity based on the updated knowledge graph and extracting feature vectors from the semantic, temporal, and structural dimensions. This mechanism preserves the original contextual semantics and behavioral paths in scenarios with heterogeneous data structures and diverse information sources, improving the anomaly detection model's ability to perceive underlying patterns and enabling more refined and discriminatory risk expression.

[0060] S30, fusing the text feature vector, the time series feature vector, and the graph embedding feature vector into a fused feature vector through a gated fusion network;

[0061] In this embodiment, the gated fusion network is used to process the nonlinear coupling relationship between heterogeneous modal features. It has a learnable selective mechanism and can dynamically adjust the weight distribution of information flow between multiple feature vectors. The text feature vector is usually derived from the embedded representation of the semantic content of the entity by the language model, the time series feature vector expresses the behavioral evolution trend of the entity, and the graph embedding feature vector depicts the propagation relationship of the entity in the structural space. The three types of feature vectors have significant differences in information source, representation dimension, timeliness and relevance. If they are directly spliced ​​together, it is easy to cause modal conflict and information redundancy, affecting the subsequent modeling effect.

[0062] The gating mechanism applies gating weights to each input feature class by introducing a weight control module, typically designed as a sigmoid-activated control gate unit. This unit learns the importance score for each modality based on the current input feature context, thereby adjusting the contribution of each feature during the fusion process. Residual connections, layer normalization, and nonlinear activation modules are introduced into the network structure to maintain numerical stability and expressive richness.

[0063] The feature fusion process typically consists of two stages. The first is inter-modal alignment, which performs dimensional alignment and scale normalization operations to enable subsequent calculations of the three modal features in the same space. The second stage is dynamic weighted fusion, which sums the three features according to the modal weights output by the gating mechanism to generate a fused feature vector of uniform dimensionality. The fused features incorporate both semantic abstraction capabilities and the ability to describe behavioral trends and perceive structural position, making them suitable for downstream modeling tasks requiring high-dimensional representations.

[0064] This network structure can significantly enhance the complementary and collaborative capabilities between features, and fully stimulate the collaborative relationship between multi-source information when data heterogeneity is strong and single modality expression is insufficient.

[0065] In a specific implementation, a multilayer perceptron can be selected as a gated subnetwork, which receives text feature vectors, time series feature vectors, and graph embedding feature vectors and outputs their weight scalars. The weight vectors are normalized and then used in the weighted fusion process of each feature. To prevent feature dimensionality mismatch, a linear mapping layer can be used to convert all features to a uniform dimension.

[0066] The gating structure can also be implemented based on the attention mechanism. This involves constructing a three-input attention calculation module that calculates the relative attention weight of each feature type relative to the remaining modalities, resulting in a dynamically adjusted fusion representation. The gating mechanism can also be replaced with a gated recurrent unit to introduce temporal state memory, making it suitable for scenarios where temporal order dominates the feature representation.

[0067] After feature fusion, you can further integrate a Dropout module to enhance robustness, or use BatchNorm to accelerate model convergence. For high-dimensional vector outputs, you can also add a dimensionality reduction module after the fusion layer, such as PCA or a self-attention compression unit, to compress redundant information.

[0068] Example: In the healthcare sector, a patient's text medical history, time series monitoring indicators, and medical graph embeddings are used as three types of feature input into a gated fusion network. The system dynamically adjusts the fusion ratio based on the changing importance of each type of information at different disease stages. For example, in the acute stage, time series data is given greater weight; in the recovery stage, text descriptions are more critical. The fusion results are used to identify recovery deviations and assist in the development of personalized treatment plans.

[0069] In the fintech sector, an account's historical transaction descriptions, recent transaction sequences, and fund flow graph embeddings are fed into a fusion network. The model automatically identifies whether current behavior is more dependent on structural paths or evolving trends. For example, structural embeddings have a greater impact on newly activated accounts, while time-series transaction patterns are more influential for active accounts. The fused vectors are used to generate anomaly scores and drive the decision engine to implement interception actions.

[0070] This embodiment dynamically weights multimodal features through a gated fusion network, avoiding the information bias and redundancy issues associated with traditional feature concatenation, and achieving more discriminative feature aggregation results. This structure automatically adjusts the fusion ratio of different information sources based on the current input feature state, ensuring that the fused vector has greater representational consistency and contextual adaptability in expressing semantics, behavioral patterns, and structural topology, significantly improving the accuracy and generalization of subsequent anomaly detection.

[0071] S40, generating a preliminary anomaly score based on the fused feature vector;

[0072] In this embodiment, the fused feature vector is a high-dimensional dense representation constructed from information from multiple heterogeneous sources in a unified expression space, typically possessing complex semantic and structural properties. Before performing anomaly detection on this vector, a scoring mechanism is established to map it to quantify its degree of deviation from the normal distribution. The result of this mapping is the preliminary anomaly score. The preliminary anomaly score is a numerical expression used to characterize the degree of deviation between the current object behavior state and the known normal pattern. It is usually defined within a specified numerical range, such as the range from 0 to 1 or -1 to 1, where the boundary values ​​are often associated with high-risk events.

[0073] The generation of a preliminary anomaly score relies on a trained discriminant model that extracts sensitive dimensions from high-dimensional fused representations, effectively characterizing risk indicators under nonlinear relationships. The input is a fused feature vector, and the output is a scalar score. This model can be constructed based on a feedforward neural network, consisting of several linear layers, nonlinear activation functions, and regularization mechanisms. Some implementations may also incorporate a residual structure to enhance expressiveness.

[0074] Furthermore, the logic for generating the initial anomaly score must ensure transferability across different scenarios and cannot rely on specific feature dimension locations. Therefore, a parameter-sharing structure or attention mechanism should be employed during modeling to enable the model to automatically focus on key subregions within the current fusion vector. This score serves as a pre-judgment indicator for subsequent anomaly intervention and causal calibration mechanisms, and is the earliest quantitative signal generated in the risk control process.

[0075] In the specific implementation, a three-layer perceptron structure can be used as the initial anomaly score generation model. The fused feature vector is input and passed through a linear mapping, a ReLU activation function, and a Dropout layer, ultimately outputting the anomaly score via a Sigmoid function. To enhance expressiveness, a multi-head attention mechanism can also be introduced, enabling the model to identify the interactions between the feature dimensions in the fused vector and use the weighted results as the basis for score generation.

[0076] The fused vector can also be remodeled using graph convolutional or Transformer encoder structures to generate more contextually interpretable score outputs. In some scenarios with high latency requirements, sparsely connected shallow network models can be used to accelerate inference efficiency, and batch normalization can be introduced to improve stability.

[0077] Furthermore, during the model training phase, a contrastive loss function with labeled supervision signals can be used to incorporate historical information comparing abnormal and normal samples, guiding the model to generate scores with greater discriminability and interpretability. After training is complete, the model is loaded into the inference system to enable real-time scoring of fused feature vectors.

[0078] Example: In the healthcare sector, when the system integrates inputs including medical records, real-time serial data from monitoring devices, and the location of the patient's symptom map, the model generates a preliminary anomaly score based on the fused feature vector to identify sudden changes in acute physiological indicators or the risk of complex complications. For example, if a high-risk postoperative patient experiences atypical fluctuations in their fused features, the system generates an anomaly score above the warning threshold, triggering the subsequent multi-source causal interpretation module.

[0079] In the fintech sector, a user's transaction behavior, frequency, and account network structure are integrated into a feature vector. The system then scores it and identifies the degree of deviation from normal customer behavior patterns. For example, if a user conducts multiple high-value transactions during an inactive period, and their account graph is located near identified fraud nodes, the model will score it and generate a high outlier value, which will be used to drive further risk intervention processes.

[0080] This embodiment establishes an anomaly scoring model that closely maps to the fused vector features, transforming complex, high-dimensional expressions into intuitive, discernible numerical results, enabling the system to detect potential anomalies early. This mechanism avoids manual decision-making based on fixed rules or specific thresholds, and can more flexibly adapt to changing scenarios and data distribution drift, significantly improving the timeliness and accuracy of detection. It also provides a quantitative basis for subsequent operations such as causal calibration and intervention instruction generation.

[0081] S50, inputting the fused feature vector into an autoencoder to determine a reconstruction error, and generating an abnormal warning signal when the reconstruction error exceeds a dynamic threshold;

[0082] In this embodiment, the fused feature vector, the result of integrating multidimensional information via a gating mechanism in the previous step, possesses complex semantic fusion properties across text representation, temporal dependencies, and graph structures. Before being used for anomaly detection, it must be processed through a neural network structure with reconstruction capabilities to extract the underlying patterns within the data and perform restoration verification. This structure is known as an autoencoder.

[0083] An autoencoder is an unsupervised learning model whose basic structure consists of an encoder and a decoder. The encoder compresses high-dimensional input and maps it into a low-dimensional latent representation, while the decoder reconstructs the original input based on this latent representation. The entire model is trained to minimize the reconstruction error between input and output. This error reflects the model's ability to fit the current data. A large error indicates that the sample is difficult for the trained model to accurately reconstruct, suggesting that the sample may be rare or potentially abnormal.

[0084] In practical applications, reconstruction error is typically measured using Euclidean distance, cosine distance, or Mahalanobis distance to characterize the degree of discrepancy between the original fused feature vector and the decoded output. To ensure environmental adaptability of the error determination mechanism, the system incorporates dynamic threshold judgment logic. This dynamically adjusts the threshold based on historical data statistics or real-time distribution estimation. Only when the reconstruction error of the current sample significantly exceeds this threshold is it considered a potential anomaly, triggering the subsequent signal response process.

[0085] The anomaly warning signal is not simply a classification label; it serves as a trigger signal that drives system components such as causal analysis, policy intervention, and risk warnings. It is both immediate and traceable. The signal generation logic relies not only on the reconstruction of the current input but also incorporates the error fluctuation trend within the time window to reduce the risk of false alarms. The results are then transmitted to the logging system and the response strategy execution module.

[0086] The implementation path can be constructed using a sparse autoencoder with a three-layer encoding structure. The fused feature vector is input and compressed into an implicit representation. The original input is then reconstructed through decoding using a symmetrical structure. The encoder layer uses ReLU or LeakyReLU activation functions, while the decoder layer uses Sigmoid to ensure the output is within a controllable range. The model can be trained using a mean squared error loss function with weight decay to ensure robust reconstruction capabilities.

[0087] Dynamic threshold generation can use a sliding window statistical mechanism, collecting historical reconstruction error samples in the last N time windows, calculating their mean and standard deviation, and constructing threshold boundaries based on the three-sigma principle or other anomaly detection distribution models. Alternatively, an exponentially weighted moving average mechanism can be introduced to dynamically adjust sensitivity based on time-varying trends to accommodate data drift.

[0088] In a multi-threaded environment, the generation of early warning signals requires synchronous locking of the current window statistical values ​​to avoid misjudgment due to inconsistent threshold updates. After the signal is output, it can be bound to the timestamp, sample identifier and error value and pushed to the downstream counterfactual reasoning module or manual review system.

[0089] Example: In the healthcare sector, a fused feature vector generated by integrating patient text records, monitoring device time series data, and medical knowledge graph relationships is input into an autoencoder model. If the model finds that the current condition characteristics cannot effectively reconstruct normal range indicators (for example, the combination of vital signs is broken), the error exceeds the dynamic threshold, triggering a warning signal, indicating the possibility of postoperative complications or potential critical conditions.

[0090] In the fintech sector, account transaction behavior sequences, text interaction logs, and account relationship graphs are integrated into a fused feature vector and fed into an autoencoder to determine whether the behavior pattern falls outside the normal range of the historical learning model. If abnormal fund flow patterns or sudden changes in the interactive language structure lead to increased reconstruction error, the system can identify potential fraud based on dynamic thresholds and immediately generate an early warning signal for further analysis or account freezing by the risk control system.

[0091] This embodiment utilizes an autoencoder reconstruction mechanism and dynamic threshold judgment logic based on historical statistics to achieve weakly supervised anomaly detection without label information, capable of identifying potentially high-risk inputs outside of training samples. This structure effectively improves the system's recognition coverage of unknown anomaly patterns, reduces the maintenance cost of manual rule-based systems, and enhances responsiveness to environmental changes through dynamic adaptive mechanisms, ultimately forming a highly robust, low-latency, and scalable closed-loop early warning capability.

[0092] S60, in response to the abnormal warning signal, constructing a causal graph model and determining the causal effect value of the key feature through counterfactual reasoning;

[0093] In this embodiment, once an abnormal warning signal is triggered, the system must begin tracing and reasoning about the cause of the event. To do this, a structured relationship graph with causal expression capabilities is constructed to depict the influence paths and conditional dependencies between features. A causal graph model is a directed graph structure in which nodes represent variables and edges represent causal influence relationships between variables. This graph structure supports discriminative mechanisms based on intervention modeling, such as counterfactual reasoning.

[0094] Causal graph models can be constructed by combining and inferring the structural information contained in the fused feature vector, the statistical dependencies between features, and the causal paths recorded in the external business knowledge graph. The directionality of edges between variables is determined by causal assumptions or structural equation models, and edge weights can represent the strength of influence, propagation probability, or sensitivity to covariates. The constructed causal graph must have a minimal closure structure to ensure identifiability and interpretability.

[0095] Counterfactual reasoning involves hypothetical analysis of events that have not occurred under current known conditions. The typical process involves performing a "value substitution" operation on the target feature, assuming different states, simulating changes in system behavior, and comparing their impact on the final output. In practice, all input variables except the target feature are first frozen. The target feature's value is then adjusted within a causal graph structure, and the affected variables are updated along the causal path. Finally, the change in the output is calculated. This change is the causal effect value of the feature, reflecting its contribution to the anomalous behavior in the current input context.

[0096] Causal effect values ​​can be expressed as continuous values, representing the degree of change in the expected outcome, or as categorical effect probabilities, used to rank the relative importance of different features. The feature selection module uses these values ​​to identify key variables, which can be further used for grouped interventions, feature masking, or model structure modification.

[0097] Causal Bayesian networks can be used as a modeling approach, automatically generating a causal graph structure based on historical data using a structural learning algorithm (such as the PC algorithm or NOTEARS). Alternatively, some edge connections can be manually set by embedding expert knowledge based on business rules, and their parameters can be fitted using data. During model training, maximum likelihood estimation or variational inference techniques can be used to learn causal edge weights.

[0098] During counterfactual reasoning, an intervention sample can be constructed based on a structural equation model. The original observed value of the target characteristic is replaced with the hypothesized value. This is then propagated back layer by layer through the dependency paths in the graph to the target output node, where the output change is calculated. For example, for a transaction risk score, the "transaction location" can be changed from "domestic" to "overseas." The incremental change in the risk score can be observed and recorded as the causal effect.

[0099] To improve system response efficiency, a partial counterfactual graph cache structure can be pre-built to perform incremental reasoning on high-frequency variable combinations. A causal attention mechanism can also be introduced to selectively weight paths in the graph, retaining only critical path nodes for counterfactual simulation to reduce computational complexity.

[0100] Example: In the healthcare business, when an abnormality in patient monitoring data triggers an alert, the system constructs a causal graph containing nodes such as body temperature, respiratory rate, medication time, and disease diagnosis. Assuming that "failure to take medication on time" is a causal intervention variable, the system calculates its incremental value for the abnormal status score through counterfactual reasoning, and then confirms that this variable is the key factor triggering the alert, assisting doctors in optimizing the treatment path.

[0101] In the financial technology business field, when a cross-border transfer transaction is identified as abnormal, the system establishes a causal graph including variables such as transaction frequency, device IP address, and historical interaction cycle, and uses "device IP change" as the target intervention variable. Through counterfactual reasoning, it determines its impact on the risk score and ultimately identifies the device switching frequency as the main driving factor, thereby prompting the risk control system to adjust the weights of related factors or trigger the account freezing mechanism.

[0102] This embodiment introduces causal graph modeling and counterfactual reasoning after an anomaly is triggered. This allows the system to not only identify the key factors that trigger the anomalous behavior but also quantify the causal contribution of each variable to the final outcome, achieving a leap in capabilities from predictive judgment to explanatory diagnosis. This mechanism improves the model's traceability and understandability, facilitating subsequent risk correction, strategy optimization, and manual intervention in the decision-making process. It also establishes a lightweight causal tracing mechanism without compromising the main model's reasoning structure.

[0103] S70, calibrating the preliminary anomaly score using the causal effect value to generate a final anomaly score and an anomaly intervention instruction;

[0104] In this example, the preliminary anomaly score is a numerical result generated after a preliminary assessment of the fused feature vector. It quantifies the degree of anomaly in a data sample, but it does not fully account for differences in the causal contributions of features and can easily mislead due to information redundancy or superficial correlations. To improve the accuracy of anomaly assessment, it is necessary to calibrate the preliminary anomaly score by introducing a causal effect value.

[0105] The causal effect value reflects the strength of each key variable's influence on the final anomaly decision and is a quantitative metric generated based on counterfactual reasoning. The basic logic of the calibration operation is to adjust the original anomaly score based on the causal effect value of each feature, thereby suppressing misleading features with low causal contributions but high correlations, while amplifying the weighted influence of highly causal driving variables. Calibration can be achieved through weight redistribution. For example, the initial anomaly score is treated as the weighted sum of the contributions of multiple features, and the causal effect value is used to proportionally adjust the feature contribution components, thereby generating a final anomaly score that better reflects the actual source of the anomaly.

[0106] After the final anomaly score is generated, the system must form an anomaly intervention instruction based on the set response strategy. The type, intensity, and scope of the intervention instruction can be determined based on the anomaly level, the identity information of the object involved, and historical behavior patterns. An anomaly intervention instruction is a structured data item that typically includes a combination of an operation identifier (such as freeze, demotion, or alarm), an object identifier (such as an account, transaction, or user device), an execution time limit (immediate, delayed), and a policy path (trigger module, control module).

[0107] The instruction can be sent to the execution module to automatically implement control measures, or it can be reviewed and confirmed by a manual terminal as a human-machine collaborative input. Its format needs to meet the grammatical rules of the instruction parsing module to ensure that it can be correctly parsed by the execution module and has backtracking capabilities.

[0108] Score calibration can be performed using linear mapping, such as weighted fusion of the initial anomaly score and the causal effect value of key features, or by constructing a calibration function to perform a nonlinear transformation on the initial score. This calibration function can use kernel methods, interpolation algorithms, or gradient descent to optimize model parameters to adapt to the variable distribution in different scenarios.

[0109] When generating abnormality intervention instructions, the final anomaly score can be mapped to specific action instructions through decision trees, rule engines, or neural control networks. For example, if the anomaly score exceeds 0.85, a trading freeze will be generated, while if the score is between 0.7 and 0.85, a risk control alert will be generated, along with contextual information requiring further confirmation.

[0110] In different deployment environments, the command output can be encapsulated in JSON format and transmitted to the control system through the RESTful interface, or pushed to the flow control channel through a message queue system such as Kafka or RabbitMQ to ensure the real-time and reliability of command execution.

[0111] Example: In the healthcare business field, after the system generates a preliminary anomaly score for abnormal vital sign monitoring events, it combines the causal effect value to identify the primary driver of the abnormal results, namely "drug change time". Based on the higher causal calibration score, the system generates a clinical intervention instruction, recommending that the doctor be notified immediately to adjust the medication regimen, and records the instruction as part of the medical record event for subsequent review.

[0112] In the financial technology business field, an account transaction was identified as suspected fraud and generated a preliminary anomaly score. Through counterfactual reasoning, the system found that the "frequency of switching the MAC address of the login device" was the main cause. After calibration, the final anomaly score was higher than the threshold of 0.92. It then automatically issued an account freezing instruction and notified manual review to ensure that the risk control response was completed within millisecond delays.

[0113] This embodiment introduces causal effect values ​​into the anomaly assessment system and uses them to calibrate preliminary anomaly scores. This significantly reduces the probability of misjudgments due to feature redundancy or spurious correlations, improving the accuracy and robustness of risk assessments. Furthermore, structured intervention instructions are generated based on the calibration results, making the entire risk control process quantifiable, executable, and traceable. This helps the system efficiently respond to complex anomalies and supports personalized decision-making interventions.

[0114] S80: Execute the abnormal intervention instruction and record the instruction execution result.

[0115] In this embodiment, the abnormal intervention instruction is a structured control command generated by the system based on the final anomaly score, and its purpose is to perform targeted intervention operations on data objects with abnormal risks. The process of executing abnormal intervention instructions includes three consecutive stages: instruction parsing, scheduling execution, and state synchronization. The instruction parsing stage usually relies on predefined command syntax standards to translate structured commands into a set of control instructions that can be recognized by the execution engine. The scheduling execution stage is based on the execution policy configuration and calls up the corresponding control service or module to complete the actual implementation of the instruction content, such as freezing accounts, intercepting tasks, triggering alarms, adjusting system parameters, etc. The state synchronization stage is used to write the execution results into the recording system to ensure that subsequent links can track the complete context of the intervention behavior.

[0116] Instruction execution results refer to the actual execution feedback of the intervention behavior. They can include metadata such as execution status (success, failure, partial completion), response time, exception description, processing object identification, and control path. This result data is structured and is typically written as a record entry to the control log system or security audit platform, serving as the basic data source for subsequent causal tracing and performance analysis.

[0117] To ensure atomicity and consistency in command execution, transaction mechanisms and rollback strategies can be introduced to prevent system state disruption caused by partial operation failures. Furthermore, to safeguard execution efficiency and data integrity in high-concurrency scenarios, resource management must be implemented through the use of asynchronous execution queues, priority scheduling strategies, and distributed locking mechanisms.

[0118] In actual deployment, the command execution module can be encapsulated as an independent service node based on a microservices architecture, receiving input intervention commands and performing semantic parsing. Parsed commands can then invoke various execution services, such as database control services, permission management services, or resource isolation services. For freezing operations, a freeze API can be sent directly to the account management system; for device disabling operations, blacklist updates can be pushed to the gateway layer; and for warning notification commands, an information push service can be invoked to send risk alerts to users.

[0119] To record command execution results, you can use a structured data format like JSON to encapsulate all execution metadata, transmit it to the log service via a messaging middleware, or write it synchronously to an audit database. Execution records must include fields such as the unique command identifier, target object, execution status code, response content summary, and timestamp to support subsequent status queries, fault backtracking, and causal chain reconstruction.

[0120] Execution results can also be pushed as real-time events to the state analysis module for dynamic construction of execution behavior graphs, enabling subsequent policy optimization. Furthermore, execution records can be written to the distributed link tracing platform, where they can be associated with contextual links using Trace IDs.

[0121] Example: In the fintech business field, when the transaction monitoring system identifies high-risk operations and generates intervention instructions to freeze accounts, the instructions are parsed by the execution module and submitted to the account control service. The system performs the freeze operation on the target account, and information such as the success status and execution time is recorded in the risk log system, providing a data foundation for subsequent risk control audits.

[0122] In the healthcare business field, after the system identifies device anomalies and generates a disable instruction, the execution module calls the device management platform interface to physically isolate the designated device channel, and at the same time encapsulates the execution status, channel ID, and response time and writes them into the medical control log for process verification and subsequent analysis by the hospital security center.

[0123] This embodiment establishes a complete closed-loop mechanism from detection to control by structuredly executing intervention instructions and recording the results of each execution. This improves the system's response speed to abnormal risks and execution stability, while also enhancing the traceability and explainability of risk control actions. Standardized recording of execution results provides accurate and reliable behavioral data support for subsequent causal analysis, system evaluation, and strategy optimization, effectively enhancing the autonomous evolutionary capabilities of intelligent control systems.

[0124] The present invention relates to the field of artificial intelligence technology and can be applied to business scenarios such as financial technology and medical health. It discloses an intelligent anomaly identification and intervention processing method, device, equipment and medium, including: obtaining multi-source data and updating a dynamic knowledge graph based on the multi-source data; obtaining entity association information based on the updated dynamic knowledge graph, and extracting text feature vectors, time series feature vectors and graph embedding feature vectors; fusing the above feature vectors into a fused feature vector through a gated fusion network to generate a preliminary anomaly score; inputting the fused feature vector into an autoencoder, calculating the reconstruction error, and generating an anomaly warning signal when it exceeds a dynamic threshold; constructing a causal graph model, determining the causal effect value of key features through counterfactual reasoning; calibrating the preliminary anomaly score based on the causal effect value, generating a final anomaly score and an anomaly intervention instruction; executing the anomaly intervention instruction and recording the instruction execution results. The present invention enhances the feature expression ability of anomaly identification by fusing three types of features: text, time series and graph embedding; improves the warning accuracy by using a dynamic threshold recognition mechanism for reconstruction error; introduces a causal graph model and a counterfactual reasoning mechanism to improve the interpretability and accuracy of anomaly decision-making.

[0125] In one embodiment, the above step S10 includes:

[0126] S101, collecting event core attribute data, behavior trajectory data and external related data;

[0127] S102, performing standardization processing on the numerical data in the event core attribute data to generate standardized event attribute data;

[0128] S103, performing one-hot encoding processing on the categorical data in the behavior trajectory data to generate one-hot encoded behavior trajectory data;

[0129] S104, parsing entities and their relationships in the external related data;

[0130] S105, constructing a dynamic knowledge graph based on the standardized event attribute data, the encoded behavior trajectory data, and the entities and their relationships;

[0131] S106, obtaining external abnormal information through the application program interface;

[0132] S107: Update the abnormal entity labels in the dynamic knowledge graph based on the external abnormal information.

[0133] In this embodiment, the operations of collecting event core attribute data, behavioral trajectory data, and external related data cover three types of heterogeneous information: structured data, time series data, and graph data. Event core attribute data mainly include metadata fields directly related to risk identification events, which usually come from business systems or operation logs, such as account status, transaction amount, geographical location information, etc., and most of its data types are numerical. Behavioral trajectory data refers to recorded information that reflects the continuous behavior of an object. The sources may include click streams, access sequences, operation sequences, etc. Its fields are mostly categorical, reflecting the behavioral status of the event subject within a specific time period. External related data refers to information obtained from external platforms, third-party systems, or other data sources that contains logical associations between entities, reflecting the direct or indirect interactions between the target object and other individuals, such as friend relationships in social networks, transaction paths in supply chain systems, or business dependencies within organizational structures.

[0134] Normalizing the numerical data in event core attribute data is intended to improve feature balance and convergence efficiency in subsequent knowledge graph construction. Common normalization methods include Z-Score transformation, Min-Max normalization, or quantile mapping, which can be dynamically selected based on the statistical characteristics of the field distribution. Normalization ensures that numerical fields of different dimensions have similar scales, which facilitates weight consistency during embedding generation.

[0135] One-hot encoding of categorical data in behavioral trajectory data aims to convert discrete class fields into sparse, high-dimensional vectors, providing a vector foundation for subsequent feature fusion and entity modeling. This process typically uses a fixed encoding dictionary or a dynamically constructed category set for field mapping, ensuring that the same type of behavior maintains semantic consistency across different samples.

[0136] Parsing entities and their relationships in external linked data aims to extract structured entity node and edge information from natural language text, table records, or graph structures. This process can be combined with entity recognition and relationship extraction models for joint modeling to improve extraction accuracy. Entity information includes participating objects, time annotations, and role descriptions. Relationship information typically includes multiple types of graph edges, such as dependencies, transfers, collaborations, and upstream and downstream relationships.

[0137] The process of constructing a dynamic knowledge graph based on standardized event attribute data, encoded behavioral trajectory data, and entity relationship information uses graph modeling to generate a directed graph structure consisting of multiple types of nodes and edges. Nodes can include entities such as event objects, timestamps, actions, and external accounts, while edges are used to characterize causal relationships, behavioral sequences, or structural dependencies. The graph construction supports incremental updates and entity merging mechanisms to adapt to the dynamic changes of new data in real-time scenarios.

[0138] Retrieving external anomaly information through an application programming interface (API) provides the ability to dynamically inject external knowledge sources. API calls can be made through HTTP pull, event push, and database subscription. Input data can come from regulatory systems, risk control alliance platforms, or other anomaly event sharing networks. This data structure typically includes key fields such as anomaly type, impact scope, time window, and anomaly object identifier.

[0139] Updating the labels of abnormal entities in the graph based on external anomaly information is done by matching anomaly identifiers obtained through the interface with entity nodes in the graph and marking the corresponding nodes as abnormal. The matching mechanism can be based on a fusion of entity IDs, feature vector similarity, or graph structure adjacency. The label update operation supports the coexistence of multiple labels and anomaly level annotation, making the graph dynamic and risk-sensitive in its representation capabilities.

[0140] This embodiment uniformly extracts, encodes, and graphs data from diverse sources and types, building a dynamic knowledge graph system with high relevance, strong representation, and real-time update capabilities. This provides a foundation for accurate entity semantic modeling in complex environments. Furthermore, by accessing external anomaly information and mapping it to abnormal entity labels, the knowledge graph is rapidly adaptable to sudden risk events, providing more accurate and context-aware structured input for subsequent risk detection and causal analysis, ultimately enabling the proactive identification of hidden risk patterns and cross-domain coordinated control.

[0141] In one embodiment, the above step S20 includes:

[0142] S201, obtaining a target entity associated with the current event to be analyzed from the dynamic knowledge graph;

[0143] S202, obtaining original text data associated with the target entity, and processing the original text data using a pre-trained language model to generate a text feature vector;

[0144] S203, acquiring time series data associated with the target entity, and processing the time series data using a recurrent neural network to generate a time series feature vector;

[0145] S204: Based on the target entity and its neighboring nodes, a graph neural network is used to generate a graph embedding feature vector.

[0146] In this embodiment, after the dynamic knowledge graph is constructed, obtaining the target entity associated with the current event to be analyzed is a key operation for contextual retrieval of nodes in the graph. The target entity is typically determined based on the contextual information of the event to be analyzed, such as the account, device, user, or IP address involved. These identifiers are matched to entity nodes through the graph indexing mechanism, focusing on potential risk targets.

[0147] After identifying the target entity, its associated raw text data is obtained in order to extract linguistic semantic representations from unstructured information. Sources of raw text data include user registration information, device descriptions, operation log instructions, business field notes, etc., and the text content is irregular and heterogeneous. To extract its semantic features, it can be encoded using a language model trained based on deep learning. For example, the bidirectional Transformer structure has advantages in modeling contextual dependencies, sparse representation, and semantic alignment. The resulting text feature vector retains the entity's representational capabilities at the semantic level, providing a semantic channel for subsequent multimodal fusion.

[0148] Meanwhile, the time series data associated with a target entity generally refers to the entity's continuous behavior over time, including sequences such as operation records, capital flows, and access trajectories. Time series data exhibits sequential correlation and dynamic fluctuations, necessitating processing using a structure that captures temporal dependencies. Recurrent neural networks are an effective model architecture for modeling time series, suited for capturing long-term dependencies and cyclical patterns. By dynamically encoding time series data, we can obtain time series feature vectors that reflect the changing trends of entity behavior.

[0149] Furthermore, the target entity does not exist in isolation within the graph, but is connected to other entities through edge structures. To model this structural adjacency, graph convolution or message passing operations are required between entity nodes and their neighboring nodes. Graph neural networks are a type of neural architecture specifically designed to process graph-structured data, leveraging inter-node connections to propagate contextual information. By processing information about the target entity and its neighboring entities through graph neural networks, we can obtain a graph embedding feature vector that exhibits both local consistency and global embedding capabilities.

[0150] The extraction process of these three vectors is complementary: the text feature vector encodes semantic information, the time series feature vector describes dynamic behavior, and the graph embedding feature vector preserves the structural constraints between entities. This multi-channel representation mechanism provides a high-dimensional and rich input foundation for subsequent risk modeling and anomaly identification.

[0151] This embodiment extracts target entities from a dynamic knowledge graph and generates multi-channel vectors combining semantic, behavioral, and structural information. This allows for comprehensive modeling of entities across different dimensions. This not only enhances the model's ability to represent complex risk behaviors but also increases its sensitivity to the transmission relationships between upstream and downstream entities. This processing approach bridges the gap between structured and unstructured data, enabling a more comprehensive presentation of multi-layered information about potentially abnormal objects, contributing to greater accuracy and targetedness in subsequent causal reasoning and decision-making.

[0152] In one embodiment, the above step S50 includes:

[0153] S501, inputting the fused feature vector into the encoder layer of a pre-trained autoencoder to generate a latent space representation;

[0154] S502, inputting the latent space representation into a decoder layer of an autoencoder to generate a reconstructed feature vector;

[0155] S503, determining the Euclidean distance between the fused feature vector and the reconstructed feature vector, and using the Euclidean distance as a current reconstruction error;

[0156] S504, obtaining historical reconstruction error records of a first preset number of events stored in the storage system;

[0157] S505, determining a statistical mean and a statistical standard deviation based on the historical reconstruction error records;

[0158] S506, determining a product of a preset multiple and a statistical standard deviation, and adding the statistical mean to the product to obtain a dynamic threshold;

[0159] S507, comparing the current reconstruction error with the dynamic threshold;

[0160] S508: When the current reconstruction error exceeds the dynamic threshold, an abnormal warning signal is generated.

[0161] In this embodiment, the fused feature vector is fed into the encoder layer to perform dimensionality compression on the multimodal representation. This fused feature vector is typically a joint representation generated by integrating text, temporal, and graph features through a gating mechanism, resulting in high dimensional density. The encoder portion of the autoencoder projects the original features into a latent space through multiple layers of nonlinear transformations. This compressed latent space representation retains the key features of the input information while removing some redundancy or noise.

[0162] Feeding the latent space representation into the decoder layer is the process of reconstructing this compressed representation. The decoder structure is typically symmetrical with the encoder, and its goal is to restore the input vector as closely as possible. The reconstructed feature vector generated by the decoder should ideally be as close as possible to the original fused feature vector. Any significant difference can be considered a deviation from the original pattern space.

[0163] After reconstruction, the Euclidean distance between the original fused feature vector and the decoded feature vector is calculated. As a measure of the spatial difference between vectors, the Euclidean distance can quantify the reconstruction deviation. This value is the current reconstruction error, and its magnitude reflects whether the current input vector conforms to the normal data distribution.

[0164] To establish a reasonable judgment standard, a first preset amount of historical reconstruction error data is extracted from the system to construct a dynamic baseline. This historical reconstruction error data is derived from the results of recent events marked as normal by the system and represents the model's reconstruction performance under normal conditions. Based on these records, the statistical mean and standard deviation are calculated to form the upper and lower limits for dynamic adjustment.

[0165] Multiplying the standard deviation by an adjustable, preset factor, such as 2 or 3, reflects the system's sensitivity preference for anomaly detection. Adding this product to the mean yields a dynamic threshold, which changes dynamically over time and with system state, providing adaptive environmental capabilities. Comparing the current reconstruction error with this dynamic threshold is a key step in anomaly detection.

[0166] When the current reconstruction error exceeds the dynamic threshold, it indicates that the reconstruction deviation between the current input and the system's known normal samples is significantly large, and the system generates an abnormal warning signal. This signal serves as a trigger for subsequent causal analysis and intervention response, indicating that the input sample does not conform to the historical statistical distribution in the representation space.

[0167] This embodiment uses an autoencoder structure to calculate reconstruction error, enabling measurement of whether input feature representations deviate from a normal distribution without the need for label supervision. It also leverages historical reconstruction records to establish dynamic thresholds, enhancing the adaptability and sensitivity of anomaly detection. This process accurately identifies samples with potentially risky characteristics and, through the measurement of reconstruction deviation, provides proactive risk warnings even when data does not clearly violate rules, thereby improving the overall system's response speed and accuracy in the face of complex anomalies.

[0168] In one embodiment, the above step S60 includes:

[0169] S601, obtaining a preliminary anomaly score of the current event as an abnormal state indicator value;

[0170] S602, screening a second preset number of key feature variables from the fused feature vector based on feature importance ranking;

[0171] S603, constructing a directed acyclic graph structure including the key feature variables, abnormal state indicator values, and causal relationships between features;

[0172] S604, for each key feature variable, performing an intervention operation in the directed acyclic graph, setting the key feature to a specific value, and using a causal forest algorithm to determine the probability of an abnormal state under the intervention state;

[0173] S605, for each key feature variable, performing a benchmark operation in the directed acyclic graph, setting the key feature to a benchmark value, and using a causal forest algorithm to determine the probability of an abnormal state under the benchmark state;

[0174] S606: Taking the difference between the abnormal state probability in the intervention state and the abnormal state probability in the baseline state as the causal effect value of the key characteristic variable.

[0175] In this embodiment, the preliminary anomaly score for the current event represents the raw anomaly indicator calculated by the anomaly scoring model based on the fused feature vector input. At this stage, it is used as the anomaly status indicator input into the causal analysis model and serves as the target variable for the entire causal effect assessment. This anomaly status indicator is not limited to a probability output; it can also be a score range to quantify the risk level.

[0176] Extracting key feature variables from the fused feature vector reduces computational complexity and highlights the primary drivers. This selection is performed based on a feature importance ranking strategy. This strategy can use evaluation results based on Shapley value, information gain, LIME, or other explanatory metrics, sorting them in descending order, and then selecting a second preset number of key variables. This second preset number is an adjustable parameter that balances the complexity of causal mapping with the accuracy of inference.

[0177] The construction of a directed acyclic graph (DAG) structure encompassing the causal relationships between key feature variables and abnormal status indicators provides a topological representation of the relationships between variables, based on causal graph modeling. This graph structure consists of nodes and edges, with nodes representing variables and edges indicating the direction of causal influence between variables. The construction process considers not only the path from key features to abnormal status but also the interaction paths between key features, thus forming a complete causal transmission map.

[0178] In this graph structure, performing an intervention on each key feature variable involves manually setting that variable to a target value and re-evaluating the probability of an abnormal state while preserving the graph structure. The semantics of the intervention operation are equivalent to a counterfactual simulation: imagining whether the probability of an abnormality would change if a certain feature of the current event had a different value. The intervention value can be the maximum, minimum, or mean value of the variable, or a high-risk / low-risk threshold defined by the business.

[0179] The baseline operation is performed to serve as a reference state for the causal effect, typically the actual observed value of the variable or the mean of the training set. The intervention state and the baseline state form a set of comparable observational conditions.

[0180] The causal forest algorithm is used to calculate the probability of abnormal states for both the intervention state and the baseline state. This is a multi-path simulation under the premise of unchanged conditional structure. Causal forest is a nonparametric causal effect estimation method based on a random forest structure. It can estimate the trend of the target variable under different variable conditions in heterogeneous samples. It is particularly suitable for causal relationship modeling in high-dimensional and nonlinear structures.

[0181] The difference between the abnormal state probabilities under the two states yields the causal effect value of the key characteristic variables. This value quantifies each characteristic variable's ability to drive abnormal states and serves as a measure of the variable's actual influence on the current risk event. Causal effect values ​​can be positive or negative; a positive value indicates that the variable increases the probability of abnormality, while a negative value indicates that it suppresses the possibility of abnormality, providing quantitative support for subsequent abnormality intervention strategies.

[0182] This embodiment constructs a causal graph structure containing key characteristic variables and abnormal state indicators, and combines it with counterfactual reasoning strategies to effectively identify the primary causal factors driving current abnormal risk changes, avoiding misjudgments caused by relying solely on correlation indicators. Furthermore, by simulating abnormal probabilities under intervention and baseline conditions and quantifying the difference, it provides accurate and interpretable causal impact assessment results, providing a scientific basis for subsequent abnormal response strategies and significantly improving the transparency and controllability of the risk decision-making process.

[0183] In one embodiment, the above step S70 includes:

[0184] S701, obtaining a preset causal effect weight parameter;

[0185] S702, multiplying the causal effect value of each key feature by the corresponding causal effect weight parameter to generate a weighted causal effect value;

[0186] S703, determining the sum of all weighted causal effect values ​​to generate a causal effect adjustment value;

[0187] S704, adding the causal effect adjustment value to the preliminary anomaly score to generate a final anomaly score;

[0188] S705, comparing the final anomaly score with a preset intervention threshold;

[0189] S706, when the final anomaly score is greater than the intervention threshold, sorting the key features in descending order according to the causal effect value, and selecting the third preset number of key features with the highest order as target intervention features;

[0190] S707 , matching preset intervention measures according to the type of the target intervention feature, and generating an abnormal intervention instruction including the target intervention feature and the corresponding intervention measure.

[0191] In this embodiment, the preset causal effect weight parameter is used to introduce a modulating factor for manually controlling the degree of causal influence in the fusion decision. It is used to modify the contribution of each key feature's causal effect value to the final anomaly score. This weight parameter can be set based on domain experience, historical evaluation performance, or adaptively determined through model training. Different weights can be assigned to each feature to reflect differences in its influence strength and credibility.

[0192] Multiplying the causal effect value of each key feature by the corresponding causal effect weight parameter is a proportional adjustment process that ensures the explanatory power of the variable, making the causal inference output more consistent with actual business risk assessment logic. The output after the weighting operation is defined as the weighted causal effect value.

[0193] The sum of all weighted causal effect values ​​reflects the global impact direction and intensity of the causal factor set in the current risk event on the original anomaly score. This sum is the causal effect adjustment value, which is used to introduce the reasoning results from the causal perspective into the final scoring system.

[0194] By adding the causal effect adjustment value to the preliminary anomaly score, the causal reasoning-based anomaly score calibration operation is completed. The final anomaly score combines the automatically learned anomaly score with the incremental information from the causal modeling analysis, improving the rationality and interpretability of the score.

[0195] Comparing the final anomaly score with the preset intervention threshold determines whether the current event triggers an actual response mechanism. The intervention threshold can be dynamically set based on risk control strategies, business tolerance, and resource allocation to avoid redundant intervention for low-risk events.

[0196] If the final anomaly score exceeds the intervention threshold, the intervention feature screening phase begins. Here, all key feature variables are sorted in descending order based on causal effect value, prioritizing those with the greatest impact on the anomaly. The number of selected features is determined by a third preset number, typically an integer between 1 and 5, to support systematic intervention control.

[0197] Intervention instructions are generated based on the variable type of the target intervention feature, matching the corresponding intervention measures. Target intervention feature types can include identity, behavior, transaction structure, device identification, network behavior, and more. Intervention measures can include temporary freezes, secondary identity authentication, access rights reduction, interface request rate limiting, and rule trigger review. The resulting abnormal intervention instructions should clearly specify the intervention target and corresponding actions, ensuring enforceability and traceability.

[0198] This implementation incorporates causal inference results into the anomaly scoring system in the form of weighted adjustments, shifting from data-driven correlation detection to more interpretable causal logic analysis, significantly improving the credibility of anomaly scores. Furthermore, by combining causal influence to screen target intervention features and match intervention strategies, targeted, high-priority anomaly responses can be achieved, effectively avoiding resource waste and false triggers, and ensuring the risk control system's responsiveness and decision-making accuracy in high-frequency risk scenarios.

[0199] In one embodiment, after the above step S70, the method further includes:

[0200] S901, obtain the final status tag of the event through the system feedback interface;

[0201] S902, comparing the instruction execution result with the final state label of the event to identify misjudgment cases;

[0202] S903, adjusting the parameters of the gated fusion network based on the back propagation of the misjudgment case;

[0203] S904, updating the causal effect weight parameter based on the misjudgment case;

[0204] S905, based on the reconstruction error records of the latest first preset number of events stored in the storage system, update the dynamic threshold through sliding window statistics;

[0205] S906, obtaining newly added external exception information through the application program interface;

[0206] S907: Update the entity embedding feature vector in the dynamic knowledge graph based on the newly added external exception information.

[0207] In this embodiment, the system feedback interface is used to obtain the development results of each intervened event in the subsequent cycle. The results can be given by manual annotation (such as doctor's review and confirmation results), automatic evaluation module or external system feedback, and can be in the form of label vector or classification value. The final state label of the event has different semantics in different application scenarios. In the medical and health scenario, it can be "symptom stability" or "indicator deterioration". In the financial scenario, it can be "normal transaction" or "confirmation of transaction violation". The operation of comparing the execution result of the instruction with the final state label of the event essentially constitutes an automatic evaluation behavior. Through the structured comparison strategy, it identifies which intervention operations have produced invalid reactions or erroneous triggers, that is, identifies misjudgment cases. Misjudgment cases include false positives and false negatives. By marking these events and constructing a mapping relationship between them and the pre-input features, fusion expressions, and intervention decisions, a feedback path that can be used for subsequent network optimization is established.

[0208] As a multimodal feature fusion structure, the internal parameters of the gated fusion network must maintain dynamic awareness of changes in feature weights. Using misjudgment cases as training examples, the gating coefficients in the fusion module can be fine-tuned through backpropagation, thereby increasing sensitivity to feature signals that cause misjudgments or weakening their erroneous weights. This process relies on a closed-loop record of historical inputs, fusion, anomaly scoring, intervention execution, and feedback results, providing high-quality task signals for network tuning.

[0209] The causal effect weight parameter controls the degree to which causal inference results influence the final anomaly score. In cases of false positives, it's possible that certain key features under-represent the intervention effect, or that the causal role of certain features is overestimated. By collecting a large amount of false positive data and analyzing the actual response of each feature under different anomaly labels, we can dynamically adjust the causal effect weight for each feature to more closely reflect the true response relationship.

[0210] Dynamic thresholds are generated from historical reconstruction error sequences and updated using a sliding window mechanism to avoid lag effects caused by old data and ensure the system adapts to changing environmental conditions. The size and update frequency of the sliding window can be dynamically adjusted based on event trigger frequency, error rate fluctuations, and device performance resources. The update process involves re-estimating the mean and standard deviation of the error data within the window to derive a new reconstruction error threshold.

[0211] The system periodically pulls new external abnormal information through the API interface. The sources include real-time alarm streams, audit confirmation systems, knowledge management platforms, etc. The data format can be text or structured annotations such as abnormal event summaries, case labels, and diagnostic instructions. New abnormal information serves as an external expert signal and is a reinforcing feedback for the evolution of the knowledge graph. In the knowledge graph, by embedding and correcting the feature vectors of the entity nodes corresponding to new abnormal events, the adaptability of the graph in abnormality prediction can be enhanced, especially the ability to perceive new types of abnormalities. The update operation can be implemented through incremental embedding learning or retraining mechanisms. Specific strategies include using the new event adjacency graph for neighbor propagation, or optimizing the discriminability of entity embedding representations based on contrastive learning.

[0212] Example: In the fintech business field, a commercial bank monitored a large number of transactions with characteristics such as rapid transfers, relay transfers, and cross-domain changes in IP addresses while providing high-frequency trading services to corporate accounts and small and medium-sized personal accounts. To address the potential risk of gang fraud, the bank deployed an intelligent anomaly control process based on a causal enhancement mechanism, completing the entire chain of data processing and decision-making responses in stages.

[0213] First, the system acquires financial data from various sources, including core transaction data (such as transfer amounts, account IDs, and transaction timestamps), user behavior logs (such as login locations, terminal devices, and login frequency), blacklist entity information shared by third-party credit reporting and anti-fraud platforms, and historical alarm data. After being standardized, encoded, and structured, this data is integrated into the data foundation for building a dynamic knowledge graph. The dynamic knowledge graph uses accounts as nodes and constructs transfer relationship edges between accounts. It also incorporates device IDs and IP addresses to construct a user behavior layer. External anomaly information is used to mark high-risk nodes and update label status.

[0214] Subsequently, the system automatically retrieves target entities associated with a suspicious transaction event from the graph, such as a high-frequency outgoing account and its one-hop and two-hop neighboring accounts, and extracts historical transaction texts (such as transaction notes, account opening application texts), time series data (such as five consecutive days of transaction flow), and graph adjacency structures related to these accounts. These are input into the language model, recurrent neural network, and graph neural network respectively to generate text feature vectors, time series feature vectors, and graph embedding feature vectors, which are then integrated into a fused feature vector through a gated fusion network to capture potential abnormal behavior collaborative patterns.

[0215] The fused feature vector is used to generate a preliminary anomaly score, which measures the degree to which the current transaction event deviates from the normal pattern. To further determine its confidence, the fused feature vector is also input into a pre-trained autoencoder. The system records the reconstruction error and compares it with a dynamic threshold generated based on the distribution of reconstruction errors of past normal events. If the reconstruction error of the current event significantly exceeds the dynamic threshold, an anomaly alert is triggered.

[0216] In response to anomaly alerts, the system performs causal modeling. It first uses a preliminary anomaly score as an indicator of abnormal status, and selects several key variables (such as transaction frequency, number of device jumps, distance between accounts, account registration time, etc.) from the fused features to construct a causal graph model. In this graph model, counterfactual reasoning is performed on each key variable: it is set to an intervention value (such as stable device use) and a baseline value (such as high-frequency switching). The causal forest algorithm is used to calculate the probability of abnormal status under the corresponding state, and the causal effect value of each key variable is obtained.

[0217] Next, the system multiplies each causal effect value by a preset weight coefficient to form a weighted causal effect value. The sum of these values ​​yields a causal adjustment value, which is then added to the preliminary anomaly score to form the final anomaly score. When this final score exceeds the platform-defined intervention trigger threshold, the system ranks key feature variables by causal effect value and selects the top-ranked variables as target intervention features. For example, it finds that "frequent device switching" and "new account openings with sudden increases in transaction amounts" have the greatest causal contributions.

[0218] Based on these target intervention characteristics, the system automatically matches intervention measures, such as temporarily freezing the account's withdrawal permissions, requiring facial recognition and secondary identity authentication, or initiating a manual review process. It then generates intervention instructions that include key characteristics and corresponding measures. Finally, the system distributes these instructions to the business middleware system, where the corresponding control module executes account control, provides information feedback, and records review, while also recording the execution status of the instructions, forming a complete intervention closed loop.

[0219] Subsequently, after the abnormal intervention instruction is executed, the system obtains the subsequent status information of the event through the feedback interface linked to the business process. For example, after freezing the account's withdrawal authority, the system waits for the background business data or the anti-fraud manual processing results to confirm whether the transaction is indeed an abnormal behavior. The extracted event final status labels include "confirmed as fraud," "false alarm," "pending," and other identifiers. The system performs a structured comparison between the results of the intervention instruction execution and the event final status labels to identify events that are misjudged, including false positives where normal operations are identified as abnormal.

[0220] For these misjudgment events, the system builds a feedback link to establish a mapping relationship between the input vector, fusion weight, anomaly score and the final result during the model processing. First, these misjudgment samples are used to update the parameters of the gated fusion network, automatically adjusting the weight coefficients of different modal inputs (such as graph embedding, time series, and text features) to optimize the model's ability to express edge feature signals. Secondly, the causal reasoning performance of key variables in the feedback misjudgment events is used to update the causal effect weight parameters, appropriately reducing the causal influence of features with poor explanatory power and insensitive response, thereby enhancing the interpretability and accuracy of the scoring mechanism.

[0221] At the same time, the system also reconstructs the historical sequence of errors based on recent events recorded in the storage system, uses a sliding window method to recalculate the error mean and standard deviation, and dynamically adjusts the anomaly recognition threshold for the next cycle to improve the model's adaptability under changes in abnormal forms. The system synchronously accesses the abnormal case sharing platform, continuously obtains new external abnormal events or risk account information through the application interface, injects them into the dynamic knowledge graph as new labels, annotates relevant entity nodes, and further guides the graph embedding update operation based on the new labels. The graph embedding update process constructs a new feature propagation path based on the new adjacency structure, or uses a fine-tuning mechanism on the basis of the existing embedding to improve the expression ability of new types of abnormal patterns, thereby achieving forward-looking identification of potential gang relationships or abnormal collaborative behaviors.

[0222] Through the above-mentioned closed-loop update, the system not only completes the intervention effect evaluation in the current event processing, but also realizes the adaptive learning of key modules such as fusion layer parameters, causal weights, graph expression and dynamic thresholds, significantly enhancing the system's long-term stable operation capabilities and intelligent evolution capabilities in complex financial business environments.

[0223] In the healthcare sector, a smart ward system has deployed real-time vital sign monitoring and anomaly control processes for critically ill patients to address the risk of sudden deterioration and enhance automated intervention capabilities. Through a multi-source data access module, the system collects in real time the patient's core clinical attributes (including basic vital signs such as heart rate, blood pressure, and blood oxygen concentration), continuous behavioral data (such as turning frequency, nocturnal movement status, and bedside device operation logs), as well as historical diagnosis and treatment data and expert annotation records provided by an external electronic medical record system. After structural standardization and encoding transformation, this heterogeneous data is used to dynamically construct a knowledge graph of patient status that evolves across time and space.

[0224] The constructed dynamic knowledge graph uses patients as the central node, incorporating their past diagnoses, medication records, medical procedures, and vital signs as attributes and edge weights to achieve structured associations of high-dimensional health status entities. The system also interfaces with hospital early warning systems to obtain past hospital infection risk events or disease mutation cases, and labels nodes in the graph with similar characteristics as potentially high-risk entities, enhancing the risk sensitivity of the graph.

[0225] During a nighttime monitoring session, the system detected abnormal respiratory fluctuations in an elderly patient with COPD and hypertension. The system automatically extracted key entities associated with the patient from the knowledge graph, including nearly 48 hours of monitoring sequences, physician assessment records, historical oxygen intensity change curves, and nurse handover notes. Raw text data was fed into a language model to extract potential nursing intervention information, while time series data was fed into a recurrent neural network to learn its changing patterns. The graph adjacency structure, through a graph neural network, captured potential risk paths between diagnostic and treatment events. These three types of features were fused to generate a fused feature vector, representing the patient's overall health status.

[0226] Based on this fused feature, the system generates a preliminary anomaly score and feeds it into the autoencoder module, which reconstructs the image and calculates the reconstruction error. Based on historical error statistics from hundreds of similar patients, the system dynamically calculates the anomaly threshold for the current scenario. If the patient's reconstruction error significantly exceeds the threshold, the system issues an anomaly warning.

[0227] After the early warning is activated, the system further analyzes the potential deterioration mechanism. Based on the abnormal score and fusion feature vector, the system screens several key variables, such as the short-term oxygen saturation decline rate, the abnormal increase in the frequency of body movements in bed at night, the fluctuation range of ventilator parameters, etc., and constructs a causal graph between key variables. Through the counterfactual reasoning mechanism, the system sets the intervention state (such as a stable oxygen inhalation ratio) and the baseline state (such as intermittent oxygen inhalation) of each variable, and calculates the difference between the patient's abnormal risk probability in the two states to obtain the causal effect value.

[0228] The system then weights these results based on predefined causal effect weight parameters to form a causal adjustment value, which calibrates the initial anomaly score to generate a final anomaly score. When this value exceeds the preset intervention threshold, the system automatically identifies the most causally driven variable, such as "violent respiratory fluctuations" and "sudden heart rate changes" that have the greatest impact on the anomaly, triggering intelligent intervention instructions.

[0229] Intervention instructions include placing the patient in high-frequency monitoring mode, adjusting respiratory support equipment parameters, activating the oxygen therapy parameter adaptation module, and sending condition alerts to the attending physician and nursing team. The system simultaneously records the issuance of instructions, execution feedback, and subsequent status tracking results, forming a structured intervention record for subsequent review, evaluation, and regulatory audits.

[0230] After the intervention is completed, the system automatically obtains subsequent updates on the patient's status through the feedback interface integrated with the electronic medical record system, such as the doctor's annotation of the remission of the condition, the description of the effect of the intervention measures in the nursing record, the vital sign recovery curve, etc., to generate the final status label of the event. The system performs a structured comparison of the recorded intervention instruction execution feedback with the above-mentioned final status label to identify whether there are false alarms or intervention deviations. For example, if a certain oxygen therapy parameter adjustment does not bring about the expected improvement in indicators and is ultimately determined to be a non-critical event, it is marked as a misjudgment sample.

[0231] For these cases that are misdiagnosed, the system constructs a feedback sample set and adjusts the model parameters through a backpropagation mechanism. First, based on the modal contribution of the fused features in these samples, the weight configuration of different feature channels in the gated fusion network is re-evaluated, thereby enhancing the model's ability to identify clinically atypical signals. Second, the system uses the performance of key variables in the counterfactual reasoning process to update the causal effect weight coefficient, reducing reliance on misleading causal paths, thereby improving the accuracy and interpretability of the causal decision-making mechanism.

[0232] At the same time, the system, based on a statistical reconstruction error mechanism, aggregates historical reconstruction error data from the most recent batch of patients within a sliding time window, dynamically updating anomaly identification thresholds to accommodate nighttime fluctuations in patient conditions or periodic environmental disturbances, ensuring stable anomaly detection sensitivity. External interfaces also continuously access high-risk case labels from infection warning platforms and newly added medical knowledge bases, such as nosocomial infection transmission pathways and respiratory failure progression indicators, to enhance the representation of abnormal entities in the atlas.

[0233] The graph embedding update mechanism recalculates embedding vectors upon acquiring new anomaly labels, combining adjacency structures with newly added node labels to construct a more fine-grained representation of potential associations. The updated embedding vectors are fed back to downstream recognition processes, improving the ability to model common patterns across individuals and enabling continuous learning of graph reasoning in complex disease scenarios.

[0234] Through the above feedback correction, model reshaping and knowledge graph enhancement, the system builds a closed-loop adaptive optimization path, which not only improves the accuracy of abnormality identification and intervention, but also provides more reliable historical experience and knowledge transfer capabilities for future events, demonstrating strong decision-making intelligence and dynamic evolution capabilities in clinical continuity monitoring tasks.

[0235] This embodiment can achieve accurate identification and structured recording of misjudgment cases and enhance the closed-loop learning ability of the model by constructing a feedback mechanism for execution results and final state labels. Using misjudgment data for reverse parameter adjustment of the gated fusion network helps to improve the accuracy and adaptability of multimodal feature fusion. Updating the causal weight parameters enables the anomaly scoring mechanism to have historical perception capabilities, avoids the deviation caused by static estimation, and improves the target orientation of intervention instructions. The sliding update of the dynamic threshold enhances the adaptability of the model in real-time scenarios, avoiding false alarms or missed alarms due to profile statistics. The incremental update mechanism of embedded features enables the dynamic knowledge graph to have the ability to respond to the evolution of anomaly types, thereby improving the anomaly recognition breadth and depth of the overall system. The entire process constitutes a complete closed-loop feedback optimization chain, which enhances the robustness, sustainability and continuous optimization capabilities of the anomaly identification and intervention system.

[0236] In one embodiment, an intelligent abnormality identification and intervention processing device is provided, which corresponds one-to-one with the intelligent abnormality identification and intervention processing method in the above embodiment. Figure 3 , Figure 3 This is a schematic diagram of the functional modules of a preferred embodiment of the intelligent anomaly identification and intervention processing device of the present invention. These include a graph update module 10, a feature extraction module 20, a feature fusion module 30, a preliminary anomaly scoring module 40, an anomaly detection module 50, a causal analysis module 60, an anomaly intervention generation module 70, and an instruction execution module 80. Each functional module is described in detail below:

[0237] A graph updating module 10 is configured to acquire multi-source data and update a dynamic knowledge graph based on the multi-source data;

[0238] A feature extraction module 20 is configured to obtain entity association information based on the updated dynamic knowledge graph, and to extract text feature vectors, time series feature vectors, and graph embedding feature vectors based on the entity association information;

[0239] A feature fusion module 30 is configured to fuse the text feature vector, the time series feature vector, and the graph embedding feature vector into a fused feature vector through a gated fusion network;

[0240] a preliminary anomaly scoring module 40, configured to generate a preliminary anomaly score based on the fused feature vector;

[0241] An anomaly detection module 50 is configured to input the fused feature vector into an autoencoder to determine a reconstruction error, and generate an anomaly warning signal when the reconstruction error exceeds a dynamic threshold;

[0242] A causal analysis module 60 is configured to construct a causal graph model and determine the causal effect value of key features through counterfactual reasoning in response to the abnormal warning signal;

[0243] an abnormality intervention generating module 70, configured to calibrate the preliminary abnormality score using the causal effect value to generate a final abnormality score and abnormality intervention instructions;

[0244] The instruction execution module 80 is used to execute the abnormal intervention instruction and record the instruction execution result.

[0245] In one embodiment, the atlas updating module 10 is specifically configured to:

[0246] Collect event core attribute data, behavior trajectory data, and external related data;

[0247] Standardizing the numerical data in the event core attribute data to generate standardized event attribute data;

[0248] Performing one-hot encoding on the categorical data in the behavior trajectory data to generate one-hot encoded behavior trajectory data;

[0249] Parsing entities and their relationships in the external related data;

[0250] Constructing a dynamic knowledge graph based on the standardized event attribute data, the encoded behavior trajectory data, and the entities and their relationships;

[0251] Obtain external exception information through the application program interface;

[0252] The abnormal entity labels in the dynamic knowledge graph are updated based on the external abnormal information.

[0253] In one embodiment, the feature extraction module 20 is specifically configured to:

[0254] Obtaining a target entity associated with the current event to be analyzed from the dynamic knowledge graph;

[0255] Obtaining original text data associated with the target entity, and processing the original text data using a pre-trained language model to generate a text feature vector;

[0256] Acquire time series data associated with the target entity, and process the time series data using a recurrent neural network to generate a time series feature vector;

[0257] Based on the target entity and its neighboring nodes, a graph neural network is used to generate a graph embedding feature vector.

[0258] In one embodiment, the anomaly detection module 50 is specifically configured to:

[0259] Inputting the fused feature vector into the encoder layer of a pre-trained autoencoder to generate a latent space representation;

[0260] Inputting the latent space representation into a decoder layer of an autoencoder to generate a reconstructed feature vector;

[0261] Determine the Euclidean distance between the fused feature vector and the reconstructed feature vector, and use the Euclidean distance as a current reconstruction error;

[0262] Obtaining historical reconstruction error records of a first preset number of events stored in a storage system;

[0263] determining a statistical mean and a statistical standard deviation based on the historical reconstruction error records;

[0264] Determine the product of a preset multiple and a statistical standard deviation, and add the statistical mean to the product to obtain a dynamic threshold;

[0265] comparing the current reconstruction error with the dynamic threshold;

[0266] When the current reconstruction error exceeds the dynamic threshold, an abnormal warning signal is generated.

[0267] In one embodiment, the cause-effect analysis module 60 is specifically configured to:

[0268] Obtaining a preliminary anomaly score for the current event as an abnormality status indicator;

[0269] Screening a second preset number of key feature variables from the fused feature vector based on feature importance ranking;

[0270] Constructing a directed acyclic graph structure including the key feature variables, abnormal state indicator values ​​and causal relationships between features;

[0271] For each key feature variable, performing an intervention operation in the directed acyclic graph, setting the key feature to a specific value, and using a causal forest algorithm to determine the probability of an abnormal state under the intervention state;

[0272] For each key feature variable, a benchmark operation is performed in the directed acyclic graph, the key feature is set to a benchmark value, and a causal forest algorithm is used to determine the probability of an abnormal state under the benchmark state;

[0273] The difference between the abnormal state probability under the intervention state and the abnormal state probability under the baseline state is used as the causal effect value of the key characteristic variable.

[0274] In one embodiment, the abnormal intervention generation module 70 is specifically configured to:

[0275] Get the preset causal effect weight parameters;

[0276] Multiply the causal effect value of each key feature by the corresponding causal effect weight parameter to generate a weighted causal effect value;

[0277] Determine the sum of all weighted causal effect values ​​to generate a causal effect adjustment value;

[0278] Adding the causal effect adjustment value to the preliminary anomaly score to generate a final anomaly score;

[0279] comparing the final anomaly score to a preset intervention threshold;

[0280] When the final anomaly score is greater than the intervention threshold, the key features are sorted in descending order according to the causal effect value, and the third preset number of key features with the highest order are selected as target intervention features;

[0281] The preset intervention measures are matched according to the type of the target intervention feature, and an abnormal intervention instruction including the target intervention feature and the corresponding intervention measure is generated.

[0282] In one embodiment, the instruction execution module 80 is specifically configured to:

[0283] Get the final status label of the event through the system feedback interface;

[0284] Comparing the instruction execution result with the final state label of the event to identify misjudgment cases;

[0285] Adjusting the parameters of the gated fusion network based on the back propagation of the misjudgment cases;

[0286] updating causal effect weight parameters based on the misjudgment cases;

[0287] Based on the reconstruction error records of the latest first preset number of events stored in the storage system, updating the dynamic threshold through sliding window statistics;

[0288] Get new external exception information through the application program interface;

[0289] The entity embedding feature vector in the dynamic knowledge graph is updated based on the newly added external exception information.

[0290] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 4As shown. The computer device includes a processor, a memory, a network interface and a database connected via a system bus. The processor of the computer device is used to provide determination and control capabilities. The memory of the computer device includes a non-volatile and / or volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external user terminal via a network connection. When the computer program is executed by the processor, it realizes the functions or steps on the service side of an intelligent anomaly identification and intervention processing method.

[0291] In one embodiment, a computer device is provided. The computer device may be a user terminal, and its internal structure diagram may be as follows: Figure 5 As shown. The computer device includes a processor, memory, network interface, display screen and input device connected via a system bus. Among them, the processor of the computer device is used to provide determination and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external server via a network connection. When the computer program is executed by the processor, it realizes the functions or steps on the user side of an intelligent anomaly identification and intervention processing method.

[0292] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the following steps are performed:

[0293] Acquire multi-source data and update the dynamic knowledge graph based on the multi-source data;

[0294] Acquire entity association information based on the updated dynamic knowledge graph, and extract text feature vectors, time series feature vectors, and graph embedding feature vectors based on the entity association information;

[0295] The text feature vector, the time series feature vector and the graph embedding feature vector are fused into a fused feature vector through a gated fusion network;

[0296] generating a preliminary anomaly score based on the fused feature vector;

[0297] Inputting the fused feature vector into an autoencoder to determine a reconstruction error, and generating an abnormal warning signal when the reconstruction error exceeds a dynamic threshold;

[0298] In response to the abnormal warning signal, a causal graph model is constructed and the causal effect value of the key feature is determined through counterfactual reasoning;

[0299] calibrating the preliminary anomaly score using the causal effect value to generate a final anomaly score and an anomaly intervention instruction;

[0300] Execute the abnormal intervention instruction and record the instruction execution result.

[0301] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0302] Acquire multi-source data and update the dynamic knowledge graph based on the multi-source data;

[0303] Acquire entity association information based on the updated dynamic knowledge graph, and extract text feature vectors, time series feature vectors, and graph embedding feature vectors based on the entity association information;

[0304] The text feature vector, the time series feature vector and the graph embedding feature vector are fused into a fused feature vector through a gated fusion network;

[0305] generating a preliminary anomaly score based on the fused feature vector;

[0306] Inputting the fused feature vector into an autoencoder to determine a reconstruction error, and generating an abnormal warning signal when the reconstruction error exceeds a dynamic threshold;

[0307] In response to the abnormal warning signal, a causal graph model is constructed and the causal effect value of the key feature is determined through counterfactual reasoning;

[0308] calibrating the preliminary anomaly score using the causal effect value to generate a final anomaly score and an anomaly intervention instruction;

[0309] Execute the abnormal intervention instruction and record the instruction execution result.

[0310] It should be noted that the above functions or steps that can be implemented by the computer-readable storage medium or computer device can be found in the relevant descriptions of the server side and the user side in the aforementioned method embodiment. To avoid repetition, they will not be described one by one here.

[0311] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0312] Those skilled in the art will clearly understand that for the sake of convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0313] It should be noted that if any software tools or components other than those of the Company appear in the embodiments of this application, they are merely for illustration and do not represent actual use. The above embodiments are intended only to illustrate the technical solutions of the present invention, not to limit them. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or replace some of the technical features therein with equivalents. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the scope of protection of the present invention.

Claims

1. An intelligent anomaly identification and intervention processing method, characterized in that: The following steps are involved: Acquire multi-source data and update the dynamic knowledge graph based on the multi-source data; Acquire entity association information based on the updated dynamic knowledge graph, and extract text feature vectors, time series feature vectors, and graph embedding feature vectors based on the entity association information; The text feature vector, the time series feature vector and the graph embedding feature vector are fused into a fused feature vector through a gated fusion network; generating a preliminary anomaly score based on the fused feature vector; Inputting the fused feature vector into an autoencoder to determine a reconstruction error, and generating an abnormal warning signal when the reconstruction error exceeds a dynamic threshold; In response to the abnormal warning signal, a causal graph model is constructed and the causal effect value of the key feature is determined through counterfactual reasoning; calibrating the preliminary anomaly score using the causal effect value to generate a final anomaly score and an anomaly intervention instruction; Execute the abnormal intervention instruction and record the instruction execution result.

2. The intelligent anomaly identification and intervention processing method according to claim 1, characterized in that: Acquiring multi-source data and updating a dynamic knowledge graph based on the multi-source data includes: Collect event core attribute data, behavior trajectory data, and external related data; Standardizing the numerical data in the event core attribute data to generate standardized event attribute data; Performing one-hot encoding on the categorical data in the behavior trajectory data to generate one-hot encoded behavior trajectory data; Parsing entities and their relationships in the external related data; Constructing a dynamic knowledge graph based on the standardized event attribute data, the encoded behavior trajectory data, and the entities and their relationships; Obtain external exception information through the application program interface; The abnormal entity labels in the dynamic knowledge graph are updated based on the external abnormal information.

3. The intelligent anomaly identification and intervention processing method according to claim 1, characterized in that: Obtaining entity association information based on the updated dynamic knowledge graph, and extracting text feature vectors, time series feature vectors, and graph embedding feature vectors based on the entity association information, including: Obtaining a target entity associated with the current event to be analyzed from the dynamic knowledge graph; Obtaining original text data associated with the target entity, and processing the original text data using a pre-trained language model to generate a text feature vector; Acquire time series data associated with the target entity, and process the time series data using a recurrent neural network to generate a time series feature vector; Based on the target entity and its neighboring nodes, a graph neural network is used to generate a graph embedding feature vector.

4. The intelligent anomaly identification and intervention processing method according to claim 1, characterized in that: Inputting the fused feature vector into an autoencoder to determine a reconstruction error, and generating an abnormal warning signal when the reconstruction error exceeds a dynamic threshold, including: Inputting the fused feature vector into the encoder layer of a pre-trained autoencoder to generate a latent space representation; Inputting the latent space representation into a decoder layer of an autoencoder to generate a reconstructed feature vector; Determine the Euclidean distance between the fused feature vector and the reconstructed feature vector, and use the Euclidean distance as a current reconstruction error; Obtaining historical reconstruction error records of a first preset number of events stored in a storage system; determining a statistical mean and a statistical standard deviation based on the historical reconstruction error records; Determine the product of a preset multiple and a statistical standard deviation, and add the statistical mean to the product to obtain a dynamic threshold; comparing the current reconstruction error with the dynamic threshold; When the current reconstruction error exceeds the dynamic threshold, an abnormal warning signal is generated.

5. The intelligent anomaly identification and intervention processing method according to claim 1, characterized in that: In response to the abnormal warning signal, a causal graph model is constructed and the causal effect value of the key feature is determined through counterfactual reasoning, including: Obtaining a preliminary anomaly score for the current event as an abnormality status indicator; Screening a second preset number of key feature variables from the fused feature vector based on feature importance ranking; Constructing a directed acyclic graph structure including the key feature variables, abnormal state indicator values ​​and causal relationships between features; For each key feature variable, performing an intervention operation in the directed acyclic graph, setting the key feature to a specific value, and using a causal forest algorithm to determine the probability of an abnormal state under the intervention state; For each key feature variable, a benchmark operation is performed in the directed acyclic graph, the key feature is set to a benchmark value, and a causal forest algorithm is used to determine the probability of an abnormal state under the benchmark state; The difference between the abnormal state probability under the intervention state and the abnormal state probability under the baseline state is used as the causal effect value of the key characteristic variable.

6. The intelligent anomaly identification and intervention processing method according to claim 1, characterized in that: The preliminary anomaly score is calibrated using the causal effect value to generate a final anomaly score and an anomaly intervention instruction, including: Get the preset causal effect weight parameters; Multiply the causal effect value of each key feature by the corresponding causal effect weight parameter to generate a weighted causal effect value; Determine the sum of all weighted causal effect values ​​to generate a causal effect adjustment value; Adding the causal effect adjustment value to the preliminary anomaly score to generate a final anomaly score; comparing the final anomaly score to a preset intervention threshold; When the final anomaly score is greater than the intervention threshold, the key features are sorted in descending order according to the causal effect value, and the third preset number of key features with the highest order are selected as target intervention features; The preset intervention measures are matched according to the type of the target intervention feature, and an abnormal intervention instruction including the target intervention feature and the corresponding intervention measure is generated.

7. The intelligent anomaly identification and intervention processing method according to claim 1, characterized in that: After executing the abnormal intervention instruction and recording the instruction execution result, the method further includes: Get the final status label of the event through the system feedback interface; Comparing the instruction execution result with the final state label of the event to identify misjudgment cases; Adjusting the parameters of the gated fusion network based on the back propagation of the misjudgment cases; updating causal effect weight parameters based on the misjudgment cases; Based on the reconstruction error records of the latest first preset number of events stored in the storage system, updating the dynamic threshold through sliding window statistics; Get new external exception information through the application program interface; The entity embedding feature vector in the dynamic knowledge graph is updated based on the newly added external exception information.

8. An intelligent abnormality identification and intervention processing device, characterized in that: The intelligent abnormality identification and intervention processing device includes: A graph updating module, configured to acquire multi-source data and update a dynamic knowledge graph based on the multi-source data; A feature extraction module is used to obtain entity association information based on the updated dynamic knowledge graph, and to extract text feature vectors, time series feature vectors, and graph embedding feature vectors based on the entity association information; A feature fusion module, configured to fuse the text feature vector, the time series feature vector, and the graph embedding feature vector into a fused feature vector through a gated fusion network; a preliminary anomaly scoring module, configured to generate a preliminary anomaly score based on the fused feature vector; An anomaly detection module, configured to input the fused feature vector into an autoencoder to determine a reconstruction error, and generate an anomaly warning signal when the reconstruction error exceeds a dynamic threshold; A causal analysis module, configured to construct a causal graph model in response to the abnormal warning signal and determine the causal effect value of the key feature through counterfactual reasoning; an anomaly intervention generating module, configured to calibrate the preliminary anomaly score using the causal effect value to generate a final anomaly score and an anomaly intervention instruction; An instruction execution module is used to execute the abnormal intervention instruction and record the instruction execution result.

9. A computer device, characterized in that: The computer device includes a memory, a processor, and an intelligent anomaly identification and intervention processing program stored in the memory and capable of running on the processor. When the intelligent anomaly identification and intervention processing program is executed by the processor, the steps of the intelligent anomaly identification and intervention processing method described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium, characterized in that The storage medium stores an intelligent anomaly identification and intervention processing program, which, when executed by the processor, implements the steps of the intelligent anomaly identification and intervention processing method according to any one of claims 1 to 7.

Citation Information

Cited By

  • High-speed danger early warning method and system based on machine vision

    CN120997802A

  • High-speed danger warning method and system based on machine vision

    CN120997802B

  • Multi-source parameter fusion battery system intelligent grading early warning method and device

    CN121008175A

  • Communication chip signal interference prediction and optimization system based on artificial intelligence

    CN121173404A

  • Equipment fault diagnosis system based on large model

    CN121211292A