Event attribution convergence method and device, equipment and medium

By acquiring historical convergence datasets and using pre-trained language models to generate attribution parameter tables, the correlation between events is dynamically updated, solving the problems of accurate attribution and adaptive convergence of event data in existing technologies, and achieving efficient event correlation identification and processing.

CN120930103APending Publication Date: 2025-11-11PING AN TECH (SHENZHEN) CO LTD
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202511185249.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-22
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing technologies lack the ability to accurately attribute and adaptively converge dynamic, multi-source, and highly correlated event data, resulting in the inability to effectively identify and merge correlated events, increasing the workload of maintenance or medical personnel and affecting processing efficiency and accuracy.

Method used

By acquiring historical convergence datasets, using pre-trained language models to analyze and generate attribution parameter tables, dynamically updating the correlation between events, and selecting hierarchical convergence or model-assisted convergence operations based on the existence and correlation of event data, accurate event attribution and adaptive convergence are achieved.

Benefits of technology

It improves the accuracy of event correlation identification and the adaptive capability of convergence processing, reduces redundant alarms, and improves event processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120930103A_ABST
    Figure CN120930103A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of artificial intelligence, can be applied to business scenes such as machine room monitoring, financial science and technology and medical health, and discloses an event attribution convergence method, device and equipment and a medium. Analyzing and generating an attribution parameter table containing attribution parameters and probability values by utilizing a pre-training language model, analyzing concurrency and association convergence conditions of event data pairs to generate association degrees among events, dynamically updating the attribution parameter table according to the association degrees, receiving to-be-processed event data, judging whether the to-be-processed event data exist in the attribution parameter table or not, and if yes, executing the next step; and if yes, executing hierarchical convergence judgment and executing convergence or release, and if not, executing model-assisted convergence and executing convergence or release. According to the method, automatic extraction and dynamic updating of the attribution parameters are achieved by combining the historical convergence data and the pre-training language model, the convergence mode is selected according to the matching condition, the event association recognition accuracy and convergence processing adaptivity are improved, and the processing efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of artificial intelligence technology, and in particular to an event attribution convergence method, apparatus, device, and storage medium. Background Technology

[0002] In practice, the concentrated outbreaks and recurring triggers of alarm events in data center monitoring have long been a challenge. Existing technologies typically rely on pre-defined scenario-based convergence algorithms, using manually defined rules to merge similar or related alarms. However, due to the highly dynamic and complex nature of the data center operating environment, alarm triggering scenarios are diverse and unpredictable, making it difficult for pre-defined rules to cover all situations. This results in some highly correlated alarms failing to converge during concentrated outbreaks, generating a large number of duplicate and scattered alarm messages, increasing the processing burden on operations and maintenance personnel. Furthermore, manually defined rules have poor adaptability to new alarm patterns, easily leading to false convergence or missed convergence, thus reducing the efficiency and accuracy of alarm processing.

[0003] In the healthcare sector, equipment monitoring and patient management systems face similar challenges. For instance, during monitoring, medical devices may trigger multiple related alarms within a short period due to changes in the same patient's condition, such as abnormal blood pressure, abnormal heart rate, and insufficient blood oxygenation. Existing alarm convergence strategies based on preset scenarios struggle to identify the potential causal relationships between these alarms in a timely manner. This can easily lead to the same condition being reported multiple times and repeatedly, increasing the workload of medical staff and potentially obscuring key alarms due to information redundancy, thus affecting the timeliness and accuracy of clinical treatment.

[0004] In the fintech sector, risk monitoring and transaction alert systems also suffer from issues of concentrated and duplicated alerts. For example, a certain type of market volatility event may trigger risk alerts for multiple transactions, or anomalies in the same funds may trigger related alerts for multiple accounts. Existing alert merging methods that rely on fixed rules often lack the ability to perform dynamic correlation analysis across accounts and transaction types. This results in highly correlated risk events being presented in a scattered manner, wasting the efforts of risk management personnel and easily overlooking the overall risk picture, thus affecting the timeliness and accuracy of risk response. Summary of the Invention

[0005] The main objective of this invention is to provide an event attribution convergence method, apparatus, device, and storage medium, aiming to solve the technical problem that the prior art lacks the ability to accurately attribute and adaptively converge dynamic, multi-source, and highly correlated event data, resulting in the inability to effectively identify and merge correlated events.

[0006] To achieve the above objectives, the present invention provides an event attribution convergence method, comprising:

[0007] Retrieve the historical converged dataset containing converged event data pairs;

[0008] The historical convergence dataset is analyzed using a pre-trained language model to extract and generate an attribution parameter table containing multiple attribution parameters and the probability values ​​corresponding to the attribution parameters.

[0009] Analyze the concurrency and convergence of event data in the event data pairs to generate the correlation degree between events;

[0010] The attribution parameter table is dynamically updated based on the correlation between the events.

[0011] When event data to be processed is received, it is determined whether the event data to be processed exists in the attribution parameter table;

[0012] If the event data to be processed exists in the attribution parameter table, then a hierarchical convergence judgment operation is performed, and a convergence or release operation is performed based on the result of the hierarchical convergence judgment operation.

[0013] If the event data to be processed does not exist in the attribution parameter table, then a model-assisted convergence operation is performed, and a convergence or release operation is performed based on the result of the model-assisted convergence operation.

[0014] Furthermore, to achieve the above objectives, the present invention provides an event attribution convergence apparatus, comprising:

[0015] The historical data acquisition module is used to acquire historical converged datasets containing converged event data pairs;

[0016] The attribution parameter table generation module is used to analyze the historical convergence dataset using a pre-trained language model, extract and generate an attribution parameter table containing multiple attribution parameters and probability values ​​corresponding to the attribution parameters.

[0017] The event correlation calculation module is used to analyze the concurrency and correlation convergence of the event data in the event data pair, and generate the correlation between events.

[0018] The attribution parameter table update module is used to dynamically update the attribution parameter table based on the correlation between the events.

[0019] The event existence determination module is used to determine whether the event data to be processed exists in the attribution parameter table when the event data to be processed is received.

[0020] The hierarchical convergence processing module is used to perform a hierarchical convergence judgment operation if the event data to be processed exists in the attribution parameter table, and to perform a convergence or release operation based on the result of the hierarchical convergence judgment operation.

[0021] The model-assisted convergence module is used to perform a model-assisted convergence operation if the event data to be processed does not exist in the attribution parameter table, and to perform a convergence or release operation based on the result of the model-assisted convergence operation.

[0022] Furthermore, to achieve the above objectives, the present invention also provides a computer device, the computer device including a memory, a processor, and an event attribution convergence program stored in the memory and executable on the processor, wherein when the event attribution convergence program is executed by the processor, it implements the steps of the event attribution convergence method as described above.

[0023] Furthermore, to achieve the above objectives, the present invention also provides a computer-readable storage medium storing an event attribution convergence program, wherein the event attribution convergence program, when executed by a processor, implements the steps of the event attribution convergence method as described above.

[0024] Beneficial Effects: This invention relates to the field of artificial intelligence technology and can be applied to business scenarios such as data center monitoring, fintech, and healthcare. It discloses an event attribution convergence method, apparatus, device, and medium, comprising: acquiring a historical convergence dataset containing converged event data pairs; analyzing the historical convergence dataset using a pre-trained language model to generate an attribution parameter table containing multiple attribution parameters and their corresponding probability values; analyzing the concurrency and correlation convergence of event data pairs to generate inter-event correlation; dynamically updating the attribution parameter table based on the inter-event correlation; receiving event data to be processed and determining whether it exists in the attribution parameter table; if it exists, performing a hierarchical convergence judgment operation and performing convergence or release operation based on the judgment result; if it does not exist, performing a model-assisted convergence operation and performing convergence or release operation based on the operation result. This invention achieves automatic extraction and dynamic updating of attribution parameters by combining historical convergence data with a pre-trained language model, and selects hierarchical convergence or model-assisted convergence paths according to different matching situations of the event data to be processed, effectively improving the accuracy of event correlation identification and the adaptive capability of convergence processing, thereby reducing redundant alarms and improving event processing efficiency. Attached Figure Description

[0025] The present invention will be further described below with reference to the accompanying drawings and embodiments. In the accompanying drawings:

[0026] Figure 1 This is a schematic diagram of an application environment for the event attribution convergence method in one embodiment of the present invention;

[0027] Figure 2 This is a flowchart illustrating an embodiment of the event attribution convergence method of the present invention;

[0028] Figure 3 This is a schematic diagram of the functional modules of a preferred embodiment of the event attribution convergence device of the present invention;

[0029] Figure 4 This is a schematic diagram of the structure of a computer device according to an embodiment of the present invention;

[0030] Figure 5 This is another structural schematic diagram of a computer device according to one embodiment of the present invention. Detailed Implementation

[0031] It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the invention.

[0032] The event attribution convergence method provided in this embodiment of the invention can be applied to, for example, Figure 1 In this application environment, the user terminal communicates with the server via a network. The server can obtain a historical convergence dataset containing converged event data pairs from the user terminal, analyze the historical convergence dataset using a pre-trained language model, generate an attribution parameter table containing multiple attribution parameters and their corresponding probability values, analyze the concurrency and correlation convergence of event data pairs to generate the correlation between events, dynamically update the attribution parameter table based on the correlation between events, receive event data to be processed and determine whether it exists in the attribution parameter table, if it exists, perform a hierarchical convergence judgment operation and perform convergence or release operation based on the judgment result, if it does not exist, perform a model-assisted convergence operation and perform convergence or release operation based on the operation result. This invention achieves automatic extraction and dynamic updating of attribution parameters by combining historical convergence data with a pre-trained language model, and selects hierarchical convergence or model-assisted convergence paths according to different matching situations of the event data to be processed, effectively improving the accuracy of event correlation identification and the adaptive capability of convergence processing, thereby reducing redundant alarms and improving event processing efficiency. The user terminal can be, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices. The server can be implemented using a standalone server or a server cluster consisting of multiple servers. The invention will be described in detail below through specific embodiments.

[0033] Please see Figure 2 , Figure 2 This is a flowchart illustrating an embodiment of the event attribution convergence method provided by the present invention. It should be noted that although the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than that shown here.

[0034] like Figure 2 As shown, the event attribution convergence method proposed in this invention includes the following steps:

[0035] S10, Obtain the historical converged dataset containing converged event data pairs;

[0036] In this embodiment, the process of acquiring a historical convergence dataset containing converged event data pairs is to accumulate a batch of validated convergence results before processing new events, for subsequent analysis and parameter modeling. The historical convergence dataset must meet both timeliness and accuracy requirements, and its data source is typically a distributed alarm database or other event logging system with persistent storage capabilities. During data acquisition, a secure connection to the distributed alarm database can be established via an API interface, using an encrypted channel to ensure that the data is not tampered with or leaked during transmission. The original historical alarm records in the database must completely include the event occurrence time, event type, event identifier, and convergence marker information. By scanning these original records, all event data pairs marked as converged are identified; these data pairs are valid samples for subsequent analysis.

[0037] After identifying event data pairs, it is necessary to extract key features reflecting the relationships between events. Commonly used dimensions include time difference of occurrence, physical location distance, and device topology relationships. Obtaining the time difference typically relies on high-precision timestamps, accurate to the millisecond level, to analyze relationships between short-duration, burst-type events. The calculation of physical location distance can be based on device installation coordinates, room numbers, or GIS location information, using spatial geometric algorithms or path calculations to determine the relative distance to the event's location. Determining device topology relationships usually relies on a pre-established device connection map. Each node in the map represents a device, and edges represent physical connections or logical dependencies between devices. By traversing the map, the topological location relationships of the devices involved in the event can be determined, such as whether they are in the same subsystem or adjacent network nodes.

[0038] To facilitate subsequent data analysis, these features are uniformly integrated into a three-dimensional feature data matrix containing time, spatial, and topological dimensions. When constructing the matrix, each row represents an event data pair, each column represents a feature dimension, and the elements in the matrix are feature values. To evaluate the reliability of these data pairs, a data confidence score calculation mechanism is introduced. The calculation can combine the accuracy of the feature values, the reliability of the data source, and consistency with other data pairs to achieve a comprehensive score. To ensure data quality, event data pairs with confidence scores below a preset quality threshold are filtered out to avoid noise affecting subsequent analysis. The filtered data is then sorted by timestamp to ensure the consistency of the temporal order of event data pairs in the dataset, facilitating subsequent time-based pattern analysis and model training.

[0039] In a data center monitoring environment, historical alarm records can be retrieved in batches by directly calling the alarm data interface of the monitoring system, and data filtering and feature extraction can be performed in the local cache to reduce the pressure on the production database. In a cloud computing environment, a distributed computing framework can be used to process historical data in parallel on multiple nodes, significantly shortening the data extraction and filtering time. For calculating location distances, the three-dimensional Euclidean distance formula can be used when three-dimensional coordinates exist, while a weighted path distance can be defined to reflect the relative positional relationship between different floors when only floor and room information is available. The method of constructing device topology relationships can be adapted to different network types. For example, in a power monitoring system, connection data from the SCADA system can be used to generate a topology map, and in a communication equipment room, link information from the network management system can be used to generate a topology structure. The quality threshold can be dynamically adjusted based on historical statistical data. Different thresholds can be used in different scenarios. For example, the threshold can be increased in environments with high false alarm rates to ensure data quality, while the threshold can be decreased in environments with low event frequency to retain more samples.

[0040] Example: In the healthcare business field, multiple medical records in the medical institution's information system that have been confirmed to be from the same patient and have the same cause can be used as historical converged data pairs. The differences in medical time, the distance between wards, and the topological relationships of medical equipment usage can be extracted to construct a three-dimensional feature data matrix for analyzing the association patterns of medical record events.

[0041] In the fintech business, multiple transaction records that have been confirmed to belong to the same fraudulent behavior can be used as historical converged data pairs. The transaction time difference, geographical distance of the transaction terminal, and account association can be extracted to form a feature matrix for analyzing the correlation of transaction risks.

[0042] In the field of data center monitoring, multiple alarms confirmed to be caused by the same equipment failure can be used as historical convergence data pairs. The alarm time difference, equipment location distance and network connection topology can be extracted to form a high-quality dataset for optimizing alarm convergence logic.

[0043] This embodiment acquires and constructs a high-quality historical convergence dataset, providing reliable training samples and reference data for subsequent event attribution and convergence analysis. This approach improves the accuracy of parameter modeling, enhances the ability to identify correlations between events in dynamic, multi-source event environments, thereby increasing the accuracy of convergence judgment and reducing false positives and false negatives.

[0044] S20, Analyze the historical convergence dataset using a pre-trained language model, extract and generate an attribution parameter table containing multiple attribution parameters and probability values ​​corresponding to the attribution parameters;

[0045] In this embodiment, before analyzing the historical convergence dataset using a pre-trained language model, the input data needs to be transformed into a unified representation that the model can process. The historical convergence dataset contains pairs of converged event data recorded from different sources. These data may come from heterogeneous data sources such as distributed alarm systems, device operation logs, and external monitoring platforms, and these data sources may differ in field formats, naming rules, and encoding methods. To enable the pre-trained language model to accurately process and understand this data, data preprocessing and format normalization are required. This involves converting basic fields such as event time information, physical location information, device identifier, and alarm type into a unified structure, and cleaning up invalid or redundant fields.

[0046] After data standardization, structured data is transformed into embedded features that the model can understand through event semantic templates. For example, information such as "Event A occurs on device X, is located at position Y, and is triggered in association with event B within Z seconds" is transformed into vector representations. These embedded vectors can preserve the multi-dimensional semantic relationships between events, including temporal, spatial, and topological aspects.

[0047] The generated event vectors are used to construct an event topology graph. Nodes in the graph represent event data, edges represent the relationships between events, and association weights are added using similarity metrics, such as cosine similarity, Mahalanobis distance, or dynamic time warping. These association weights reflect the proximity of different events in the semantic space and provide a numerical basis for subsequent pattern mining.

[0048] The event topology graph is fed into a graph neural network for processing. Through multi-layer neighborhood aggregation and feature propagation, it identifies high-frequency event association patterns that repeatedly appear in historical data. These patterns can reveal potential causal or co-occurrence relationships in event triggering, thereby extracting multi-dimensional attribution parameters, including parameters related to the same triggering cause, device type, and scope of influence. The frequency of these parameters in historical data is then statistically analyzed to calculate their corresponding probability values, ultimately generating an attribution parameter table. This provides a quantifiable and updatable knowledge base for subsequent event attribution and convergence judgment.

[0049] In different implementation scenarios, pre-trained language models can adopt different types of deep learning architectures, such as encoder models based on the Transformer structure and hybrid models combining sequence modeling and graph networks. For environments with large amounts of data and multiple input sources, historical convergence datasets can be sharded using distributed computing frameworks, enabling data preprocessing, embedding vector generation, topology construction, and graph neural network inference to run in parallel, thereby improving processing speed.

[0050] During the model's input phase, event-attribute-oriented feature encoding methods can be used to quantize time fields at the second, minute, or hour level, convert spatial information into latitude and longitude codes or device topology paths, and map device types and alarm types into sparse one-hot codes or dense embedding vectors. For textual descriptive fields, word vectors or contextual embeddings can be used to preserve the event feature information implicit in natural language.

[0051] During the model inference phase, the number of layers and aggregation methods of the graph neural network can be adjusted according to different business needs. For example, shallower neighborhood aggregation can be chosen when more attention needs to be paid to the correlation of local events, while deeper multi-hop aggregation structures can be chosen when long-chain causal patterns need to be identified. The probability value can be calculated based on the proportion of parameters in high-frequency patterns, the stability of pattern occurrence, and the weighted result of association weights. For business scenarios with more noise, a confidence weighting mechanism can be introduced to attenuate the contribution value of unstable patterns.

[0052] After generating the attribution parameter table, it can be interfaced with the decision engine for event attribution convergence, and a periodic or triggered update strategy can be designed. For example, when a certain number of new convergence results are obtained or when the probability value of a key parameter is detected to change beyond a threshold, an update can be automatically triggered to maintain the synchronization of the attribution parameter table with environmental changes.

[0053] Example Explanation: In the healthcare business, historical medical record event pairs can be used as input datasets. Each event pair may include symptom records of different patients within a similar time period and their associated examination results. Through model analysis, high-frequency symptom-examination association patterns can be identified, such as the high correlation probability of a specific symptom with a specific examination result, thereby generating an attribution parameter table to provide a reference for subsequent automated diagnosis and treatment suggestions or related case analysis.

[0054] In the fintech business, historical abnormal transaction event pairs can be used as input datasets. Each event pair may include abnormal user account login records and associated abnormal transaction records. Through model analysis, stable and high-frequency correlations between certain specific transaction patterns and specific login behaviors can be discovered. For example, the high correlation probability between cross-regional logins within a short period of time and large-amount cash withdrawals can be transformed into attribution parameters, providing support for the risk control system to quickly make convergence or release judgments when new events occur.

[0055] In the field of data center monitoring, historical alarm event pairs can be used as input datasets. Each event pair includes records of abnormal equipment status occurring within a similar time period and associated environmental monitoring alarms, such as alarms about excessively high air conditioning return air temperature and alarms about excessively high temperature from temperature and humidity sensors in the same area. Through model analysis, stable correlation patterns between these environmental and equipment statuses can be identified. Attribution probability values ​​are assigned based on the frequency and stability of these patterns, thereby forming an attribution parameter table that can guide alarm convergence decisions, reducing the operational burden caused by repetitive alarms and improving the accuracy of alarm processing.

[0056] This embodiment transforms historical convergence datasets into a unified structured representation and inputs it into a pre-trained language model for analysis. This allows for the automatic identification of stable and business-significant attribution parameters from multi-source, heterogeneous alarm histories, and the establishment of a probability quantification mechanism for these parameters. This approach not only reduces the limitations of manual rule definition but also continuously optimizes parameters and probability values ​​as data accumulates, making the attribution parameter table more closely reflect the dynamic changes in the real business environment.

[0057] S30, Analyze the concurrency and correlation convergence of the event data in the event data pair, and generate the correlation degree between events;

[0058] In this embodiment, an event data pair refers to two event units that have been recorded in pairs in a historical dataset, and these event units have temporal, spatial, or logical relationships. For example, in a network system, alarm records on two different servers may appear successively within a short period of time; in a medical system, two different examination results may occur sequentially during a single diagnosis and treatment. Each event data in an event data pair needs to have basic descriptive information such as a timestamp, event type, and event source, and may also include device number, geographical location, or business classification information for subsequent concurrency and convergence analysis.

[0059] Concurrency refers to the phenomenon where two data events occur simultaneously or nearly simultaneously within a defined dynamic time interval. The dynamic time interval can be dynamically adjusted based on the average interval of historical events, business processing latency, or device data sampling period. Concurrency statistics are achieved through timestamp comparison to determine whether the time difference between two data events falls within the dynamic time interval and to record the number of times such concurrency occurs. To ensure the accuracy of the statistical results, it is also necessary to remove abnormal records, duplicate collection records, or records with incorrect timestamps.

[0060] Convergence correlation refers to the historical record of two event data sets being processed together in actual business operations. For example, in an alarm convergence process, alarms from two different sources are merged into a single processing unit. Identifying convergence correlations can be achieved by tagging historical convergence records. Specifically, this involves searching the dataset for event pairs that share the same convergence batch number, convergence identifier, or processing unit number, and counting the frequency of these occurrences. These counts reflect the degree of convergence between the event data pairs in historical processing.

[0061] Inter-event correlation is a quantitative indicator calculated based on concurrency and correlation convergence, reflecting the degree of connection between two event data points in a real-world operating environment. The calculation first obtains the concurrency impact factor and the convergence correlation factor separately. Then, weights are determined based on business importance, event type sensitivity, or data stability, and the two factors are weighted and fused to form a normalized correlation value. The correlation value can be set between 0 and 1, with a higher value indicating a stronger correlation between the two events. This indicator is not only used for subsequent attribution analysis but also for dynamically adjusting convergence strategies to improve the accuracy and stability of the processing.

[0062] In healthcare operations, event data pairs can be established using patient visit records and examination records. Dynamic time intervals can be set based on disease progression patterns or the issuance time of examination reports. Concurrency statistics are used to identify multiple symptom combinations that occur simultaneously within the same treatment cycle, while convergence correlations are obtained through merging diagnostic records in the medical record management system.

[0063] In fintech business, event data pairs can be established by account login events and transaction events. The dynamic time interval can be adjusted according to user transaction activity and risk strategies. The number of concurrent transactions reflects high-frequency transactions or cross-regional login behavior in a short period of time. Convergence correlation can be obtained from the event merging logs of the anti-fraud system.

[0064] In data center monitoring, event data pairs can be established through environmental monitoring alarms and equipment status alarms. Dynamic time intervals can be set based on equipment acquisition frequency and alarm trigger delay. Concurrency counts reflect the frequency of simultaneous occurrences of temperature and humidity anomalies and air conditioning equipment malfunctions within the same data center. Convergence correlations can be extracted from historical convergence batch records in the alarm management system. The weights of concurrency and convergence can be adjusted in different scenarios to adapt to varying business requirements for real-time performance and accuracy.

[0065] This embodiment generates the correlation degree between events by quantitatively analyzing the concurrency and convergence of event data pairs. This can prioritize the identification of strongly correlated event combinations in subsequent event attribution and convergence processing, reducing the risk of duplicate processing and omissions, thereby improving the efficiency and accuracy of the overall processing.

[0066] S40, dynamically update the attribution parameter table based on the correlation between the events;

[0067] In this embodiment, the correlation between events is a quantitative indicator calculated based on the concurrency and correlation convergence of historical event data. It reflects the strength of mutual influence between different event data in the business operation environment. The process of dynamically updating the attribution parameter table involves using this quantitative indicator to adjust the probability values ​​of the parameters in the attribution parameter table and their interrelationships, so that it can reflect the latest trend of event relationship changes. The attribution parameter table records multiple attribution parameters and their corresponding probability values. These attribution parameters can include multi-dimensional information such as triggering cause, device type, business module, and scope of impact. Each attribution parameter may also have different correlations with other parameters.

[0068] During the dynamic update process, a correlation change matrix needs to be constructed first. This matrix compares the currently calculated correlation between events with the correlation between events in the historical records to obtain the change in correlation strength for each pair of events. This change can be a positive increase, a negative decrease, or remain unchanged. The dimensions of the change matrix match the number of event types, and the value of each cell represents the change in correlation strength for a specific event pair.

[0069] Each attribution parameter in the attribution parameter table needs to undergo correlation analysis with the change matrix. The correlation score can be determined by statistically analyzing the magnitude and direction of changes in the event pairs involved in the parameter within the change matrix, reflecting the degree to which the parameter is affected by changes in the correlation between events in the current business environment. Parameters with correlation scores exceeding a preset correlation threshold are selected as key influencing parameters, which play an important role in attribution and convergence strategies during the current business cycle.

[0070] For each key influencing parameter, a dynamically updated weight value needs to be determined based on the magnitude of change in the change matrix. The weight value calculation can consider the absolute magnitude of the change, the duration of the change trend, and the importance level of the event. A higher weight value indicates that the parameter should be given a larger adjustment range in this update. Using dynamically updated weight values, the probability values ​​corresponding to the parameter in the attribution parameter table can be weighted and adjusted to generate updated probability values.

[0071] After updating the probability values, it is necessary to reanalyze the relationships between attribution parameters in order to reconstruct the correlation network between parameters. This step ensures that the parameter table is up-to-date not only in terms of the probability values ​​of individual parameters, but also in terms of the relationship structure between parameters, reflecting the latest state of the business operating environment. The updated attribution parameter table needs to be version-marked and stored in the business database to support subsequent attribution judgments and convergence decisions.

[0072] In healthcare, the latest inter-event correlation analysis can be used to analyze the relationship between patient symptoms and test results. For example, when the correlation between abnormal blood sugar and abnormal heart rate increases in recent medical records, the system will increase the probability values ​​of related symptom parameters in the attribution parameter table and readjust the relationships between parameters related to cardiovascular disease, so that the next diagnosis is more in line with the current disease trend.

[0073] In fintech operations, risk parameters in the attribution parameter table can be dynamically adjusted based on changes in the correlation between transaction and login events. For example, if the correlation between cross-regional logins and abnormal transactions increases significantly within a short period, the system will increase the probability value of the relevant risk attribution parameters and reconstruct their correlation with other risk factors, so that such event combinations can be prioritized in anti-fraud strategies.

[0074] In data center monitoring, the system can dynamically adjust attribution parameters related to environmental monitoring based on changes in the correlation between temperature and humidity sensor anomalies and high-temperature alarms from equipment. If the correlation increases, the system will increase the importance weight of this type of alarm in the attribution parameter table and strengthen the correlation with cooling system fault parameters, making the next round of alarm convergence more efficient.

[0075] This embodiment dynamically updates the attribution parameter table by utilizing the correlation between events, ensuring that parameter values ​​and relationships always reflect the latest business operation status. This guarantees the accuracy and adaptability of subsequent attribution and convergence judgments, thereby reducing the probability of erroneous convergence and missed convergence, and improving the real-time performance and effectiveness of event processing.

[0076] S50, when receiving event data to be processed, determine whether the event data to be processed exists in the attribution parameter table;

[0077] In this embodiment, the event data to be processed refers to new event records received in real time during the current system operation that have not yet completed attribution analysis and convergence processing. This type of data may originate from different event collection terminals such as data center monitoring systems, business application logs, device sensors, and network traffic monitoring platforms. To ensure that subsequent attribution judgments can be executed accurately, the system needs to match the event data to be processed with the attribution parameter table to determine whether the event already has a corresponding attribution parameter record and probability value information in the attribution parameter table.

[0078] An attribution parameter table is a structured collection of event attribution reference data. Its content is generated based on historical convergence data analysis and includes multiple attribution parameters and their corresponding probability values, as well as the relationships between these parameters. Each attribution parameter can be stored in the table as a key-value pair, a vectorized feature, or a graph database node, and is uniquely identified by an identifier corresponding to the actual event type.

[0079] The judgment process requires first transforming the event data to be processed into a feature form that can be directly compared with the attribution parameter table. This feature form can include metadata such as the event's trigger cause code, device category identifier, occurrence location code, and event level, or it can include event feature vectors generated through a semantic vectorization model. For structured event information, matching can be performed directly according to fields; for unstructured information such as event description text, it can first be vectorized, and then the similarity with the feature vectors already stored in the attribution parameter table can be calculated.

[0080] Similarity calculation can employ methods such as cosine similarity, Euclidean distance, and Mahalanobis distance, with the threshold determined by business requirements and historical statistical results. When the similarity between a feature of the event data to be processed and a record in the attribution parameter table exceeds a set threshold, it is determined that the event has a matching record in the attribution parameter table. Matching judgment can be not only a direct equality comparison in a single dimension, but also a weighted comprehensive matching of multi-dimensional features. For example, a higher weight can be set for device type equality, while a lower weight can be set for event description semantic similarity, to adapt to different business requirements regarding matching accuracy.

[0081] To improve processing efficiency, a multi-level index structure can be adopted. The first level uses a hash index to quickly locate the range of potentially matching attribution parameter records, and the second level performs fine-grained calculation of vector similarity, thereby reducing computational overhead while ensuring accuracy. During the matching process, time window restrictions can also be incorporated, such as matching only frequently occurring events within a certain time range, to reduce unnecessary association judgments.

[0082] The output of this judgment process is a Boolean result, indicating whether the event data to be processed exists in the attribution parameter table. This result directly determines the subsequent processing path of the system. If it exists, the system proceeds to the hierarchical convergence judgment based on the parameter table; if it does not exist, the system proceeds to the model-assisted convergence processing flow.

[0083] In healthcare operations, pending event data can be defined as newly collected medical records or examination results, such as monitoring records of patients experiencing abnormal heart rates. The system compares the characteristics of the abnormal heart rate event with parameters related to previous cardiovascular diseases in the attribution parameter table. If the similarity exceeds a set threshold, the event is considered to exist in the attribution parameter table.

[0084] In fintech operations, pending event data may be the behavioral log of a high-risk transaction, including features such as transaction location, time, transaction amount, and device fingerprint. The system compares these features with risk behavior patterns recorded in the attribution parameter table. If a match is found, it proceeds to rule-based risk convergence judgment; otherwise, it proceeds to model-based abnormal behavior analysis.

[0085] In the data center monitoring business, the event data to be processed may be a newly triggered high temperature alarm. The system will extract information such as the data center number, equipment number, and temperature value of the alarm, and match it with the existing environmental anomaly parameter records in the attribution parameter table. If the match is successful, it will enter the existing alarm convergence process; otherwise, it will enter the model-assisted judgment path.

[0086] This embodiment can quickly divert event processing paths by determining whether the event data to be processed exists in the attribution parameter table. This ensures that events covered by existing rules directly enter the rule-driven convergence process, reducing unnecessary computational overhead. At the same time, it ensures that new or rare events can enter the model analysis process, so as to dynamically expand the coverage of the attribution parameter table, thereby improving processing efficiency and convergence accuracy.

[0087] S60, if the event data to be processed exists in the attribution parameter table, then perform a hierarchical convergence judgment operation, and perform a convergence or release operation according to the result of the hierarchical convergence judgment operation.

[0088] In this embodiment, after the event data to be processed is determined to exist in the attribution parameter table, it needs to enter a hierarchical convergence judgment process based on existing attribution information. This process first needs to load a set of parameters related to the event data to be processed from the attribution parameter table. These parameter sets may include trigger cause parameters, device type-related parameters, impact range-related parameters, and corresponding probability values. These parameters not only define the potential correlation between the event and other events, but also contain statistical information on the event attribution pattern, providing input for subsequent multi-level judgments.

[0089] After loading the parameter set, the system initializes the convergence decision engine. The convergence decision engine is a processing module used to perform multi-dimensional feature analysis and convergence judgment, and can be implemented based on rules, statistical calculations, or machine learning models. The engine calculates the correlation score between the event data to be processed and multiple live event data based on the numerical weights in the parameter set and the actual characteristics of the event data. Live event data refers to event records that are still active in the current system and have not yet been closed or archived. These events may continue to trigger related alarms in the short term, and are therefore candidate objects for convergence judgment.

[0090] The relevance score can be calculated based on a weighted combination of multiple dimensions, such as the proximity of event trigger times, spatial distance of physical locations, adjacency of device topology, and similarity of semantic descriptions. The system selects the object with the highest relevance score from multiple live event data sets as the preferred relevance event.

[0091] In the first-level judgment, if the correlation score of the preferred correlation event exceeds the preset correlation threshold, it is considered that the event data to be processed has sufficient correlation with the event, and a decision result instructing convergence to the preferred correlation event can be directly generated and the convergence operation is performed. If the correlation score does not reach the threshold, the second-level judgment is initiated.

[0092] The second level of judgment occurs within the convergence decision engine. It uses a set of parameters to analyze the attribution parameter matching degree between the event data to be processed and multiple existing event data. The matching degree measures the consistency of events in attribution patterns, such as the probability of the same triggering cause, consistent device type, and overlapping impact range. The system selects the event with the highest matching degree as the primary event for parameter matching. If the matching degree of this event exceeds a preset matching degree threshold, a decision result indicating convergence towards that event is generated, and the convergence operation is executed. If the requirements are still not met, a release decision result is generated.

[0093] The convergence operation updates the status of the event data to be processed to be associated with the target event, and may merge its alarm information, impact scope, handling responsibility, and other attributes to ensure that the alarm management system no longer pushes multiple alarms with similar content. The release operation marks the event data to be processed as an independent event and pushes an alarm, allowing it to enter the regular processing flow. All convergence or release decisions and execution records are written to the decision log for subsequent analysis and model optimization.

[0094] In healthcare operations, pending event data might include a newly arrived abnormal blood glucose test result. If the attribution parameter table already contains parameter records highly correlated with an abnormal insulin dosage event occurring on the same day as the patient, the convergence decision engine will converge this test result with the existing medication use abnormal event into the same clinical treatment event.

[0095] In fintech operations, pending event data might include a suspected fraudulent credit card transaction. If the attribution parameter table already contains a transaction with the same card number, similar time, but from a different country, and the correlation score exceeds a threshold, the system will merge the new transaction with the existing event into the same fraudulent behavior chain and initiate a unified freezing process.

[0096] In data center monitoring, pending event data may originate from fan failure alarms in a particular rack. If the attribution parameter table already contains alarm events highly correlated with power supply anomalies in the same rack and the correlation score meets the standard, then the fan failure event and the power supply anomaly event will be merged into the same fault handling order to reduce duplicate dispatching.

[0097] This embodiment performs hierarchical convergence judgment when the event already exists in the attribution parameter table, which can minimize the alarm push of duplicate events while ensuring accuracy. The two-level judgment mechanism can first quickly identify significantly related events, and then further identify potentially related events through attribution parameter matching, thereby reducing missed convergence and false convergence, and improving the accuracy and processing efficiency of event merging.

[0098] S70, if the event data to be processed does not exist in the attribution parameter table, then perform model-assisted convergence operation, and perform convergence or release operation according to the result of model-assisted convergence operation.

[0099] In this embodiment, when no corresponding record is found in the attribution parameter table for the event data to be processed, the system enters the model-assisted convergence processing stage. This stage first requires feature extraction from both the event data to be processed and the data of surviving events. Here, a pre-trained language model is introduced as the feature extraction engine. The pre-trained language model can convert multi-dimensional features such as event descriptions, alarm content, and device information into numerical event feature vectors through vectorization, enabling different types of events to be compared and analyzed in a unified feature space. The data of surviving events is also converted into feature vectors at this stage for feature matching and similarity analysis with the event data to be processed.

[0100] After feature extraction, the system constructs a multi-dimensional clustering feature space based on the generated event feature vectors. The dimensions of this space can include temporal features, spatial location features, device attribute features, and event semantic features. The construction process can utilize dimensionality reduction algorithms to optimize feature distribution, or index structures to improve similarity retrieval speed.

[0101] In the multidimensional clustering feature space, the system performs density clustering analysis, automatically classifying events into different cluster groups by identifying dense regions of feature vector distribution. The clustering results not only characterize the feature proximity between events but also reveal potential correlation patterns, such as similar types of alarms triggered by similar device models in similar environments.

[0102] Subsequently, the system calculates a cluster confidence score for each cluster group, measuring the characteristic consistency and distribution density of events within that group. The confidence score can be calculated using indicators such as the average similarity within groups and the variance of features within groups. If the cluster confidence score exceeds a preset confidence threshold, it indicates that the similarity between the event data to be processed and that group is highly reliable, and the system will generate convergence suggestion information based on this result.

[0103] The convergence suggestion will trigger a confirmation request to the user. This request may include a summary of the main events within the cluster group, the distribution of event types, and association probabilities, allowing the user to quickly determine whether they agree to convergence. Upon receiving the user's response, if the user confirms, the system will associate the event data to be processed with the target cluster group and generate the convergence result. The convergence result includes convergence association data (indicating the correspondence between the events to be processed and the target group) and cluster analysis data (recording the clustering process and feature distribution). This result is then updated in the attribution parameter table's data pool for subsequent attribution analysis and parameter updates.

[0104] If the user responds with disagreement on convergence, the system will mark the pending event data as an independent event and push an alarm. Alternatively, if the clustering confidence score does not exceed the threshold, the system will directly generate a release instruction, skipping the user confirmation step, and push the event to the regular alarm processing flow to avoid erroneous merging caused by low-reliability convergence.

[0105] In healthcare operations, pending event data might be a report of a rare adverse drug reaction. Since the attribution parameter table does not contain attribution information related to this drug, the system uses a pre-trained language model to analyze the feature vectors of this event and other recently surviving drug reaction events, clustering it into a high-confidence rare adverse reaction group. After confirmation by a doctor, it is then converged into the case records of this group.

[0106] In fintech operations, pending event data may represent a novel cross-border transfer, the pattern of which is not covered by existing attribution parameter tables. Through feature extraction and cluster analysis, the system identified that this transaction had a high cluster confidence level with several recent suspicious transactions. After confirmation by risk control personnel, these transactions converged into the same suspicious fund flow event, facilitating centralized investigation and handling.

[0107] In data center monitoring, pending event data might be an alarm for an abnormal heat dissipation of a brand-new server model. Since there are no convergence parameters for this model in the attribution parameter table, the system uses feature vector analysis to find that it is clustered with recent power current fluctuation alarms of the same model, and the confidence level exceeds the set threshold. After confirmation by the operations and maintenance personnel, it is converged into a unified hardware stability fault group to avoid duplicate dispatching and information redundancy.

[0108] This embodiment introduces model-assisted convergence processing when the attribution parameter table lacks target event parameters. The system can discover potential event correlation patterns even without predefined attribution rules. Utilizing feature extraction, cluster analysis, and confidence assessment, it can accurately aggregate novel, unknown, or rare events without relying on fixed rules, reducing the risk of false convergence. It also supports a manual verification mechanism to improve decision reliability, while maintaining continuous updates to the data pool to enhance subsequent analytical capabilities.

[0109] This invention relates to the field of artificial intelligence technology and can be applied to business scenarios such as data center monitoring, fintech, and healthcare. It discloses an event attribution convergence method, apparatus, device, and medium, comprising: acquiring a historical convergence dataset containing converged event data pairs; analyzing the historical convergence dataset using a pre-trained language model to generate an attribution parameter table containing multiple attribution parameters and their corresponding probability values; analyzing the concurrency and correlation convergence of event data pairs to generate inter-event correlation; dynamically updating the attribution parameter table based on the inter-event correlation; receiving event data to be processed and determining whether it exists in the attribution parameter table; if it exists, performing a hierarchical convergence judgment operation and performing convergence or release operation based on the judgment result; if it does not exist, performing a model-assisted convergence operation and performing convergence or release operation based on the operation result. This invention achieves automatic extraction and dynamic updating of attribution parameters by combining historical convergence data with a pre-trained language model, and selects hierarchical convergence or model-assisted convergence paths according to different matching situations of the event data to be processed, effectively improving the accuracy of event correlation identification and the adaptive capability of convergence processing, thereby reducing redundant alarms and improving event processing efficiency.

[0110] In one embodiment, step S10 above includes:

[0111] S101 connects to the distributed alarm database via API interface to obtain the original historical alarm record set;

[0112] S102, Scan the original historical alarm record set to identify all event data pairs with convergence markers;

[0113] S103, for each event data pair, extract spatiotemporal correlation features including the time difference of occurrence, physical location distance, and device topology relationship;

[0114] S104, Based on the spatiotemporal correlation features, construct a three-dimensional feature data matrix containing time dimension, spatial dimension and topological dimension;

[0115] S105, determine the data confidence score for each event data pair;

[0116] S106, Filter event data pairs whose data confidence scores are lower than the preset quality threshold according to the preset quality threshold;

[0117] S107. Sort the filtered and retained event data pairs by timestamp to form a historical convergence dataset.

[0118] In this embodiment, the API interface connection to the distributed alarm database adopts a combined strategy of authentication, rate limiting, breakpoint resumption, and consistency integration. Authentication can use tokens or keys for access control, and after connection, shard nodes are located through service discovery or gateway routing. To avoid resource consumption caused by full fetching, incremental fetching is based on the coordinated advancement of time cursors and pagination parameters, supporting idempotent repeated requests and exponential backoff retries. Consistency integration bridges the latency differences of distributed replicas through read verification and version number comparison. The original historical alarm record set is based on events as the smallest unit, and it is recommended that the fields include event identifier, timestamp, device identifier, geographical or data center location information, device type, business domain, severity level, convergence flag, group identifier, topology port and link information, and text description. The timestamp is uniformly set to UTC or a unified data center time base, and deduplication, null value cleanup, and field normalization are performed after fetching.

[0119] Event data pairs with convergence tags are generated through a two-stage filtering process. The first stage filters by convergence tags or group identifiers to construct a candidate set. The second stage pairs events within the same group identifier according to chronological order, or performs a bidirectional mapping between new and old events and their corresponding core convergence events to generate stable event data pair objects. If convergence results in many-to-one or one-to-many relationships, it is split into several binary pairs according to business rules, and the pairing source is recorded to prevent subsequent statistical confusion. Pairing integrity is verified through cross-validation of the existence of fields at both ends, time sequence consistency, device attribution consistency, and convergence logs. Abnormal pairs are marked and moved to a pending review list.

[0120] The extraction of spatiotemporal correlation features is calculated item by item for each event data pair. The occurrence time difference is based on the difference between the timestamps of the two ends, and offset calibration is performed after considering the acquisition and transmission delays. If necessary, the upper limit of NTP synchronization error is used as a confidence band. Physical location distance is measured according to asset management and data center coordinate systems. For indoor scenarios, Manhattan distance or Euclidean distance can be calculated using rack row and column coordinates and floor mapping. For cross-regional scenarios, geodesic distance of geographic coordinates is used. Equipment topology is constructed based on a multi-domain equipment graph including network and power. Undirected or directed edges represent connected or causal links. Measurement indicators may include shortest hop count, shortest path reliability, whether they are in the same subnet or the same power distribution branch, and the existence of a common upstream node. The three features are unified and standardized. The time difference can be logarithmically scaled or piecewise normalized. The distance introduces a data center scale factor. The topology can be discretized into multi-dimensional indicators and then normalized to form a vector representation with a consistent scale.

[0121] The three-dimensional feature data matrix structurally combines temporal, spatial, and topological dimensions. Rows correspond to event data pairs, and columns are organized by dimension. Temporal partitions may include time difference, sorting position, and jitter metrics; spatial partitions may include physical distance, co-domain indicators, and environmental interval codes; and topological partitions may include shortest hop count, path redundancy, and common-cause node indicators. To accommodate high dimensionality and sparsity, dense columns are stored in columnar format, while sparse topological metrics use sparse encoding while maintaining column alignment. Missing items are imputed using the co-domain median, KNN imputation, or EM imputation, with imputation actions recorded as source tags for subsequent quality assessment. The matrix version and field dictionary are maintained synchronously to ensure reproducibility of subsequent analyses.

[0122] Data confidence scores are calculated for each event data pair using weighted multiple metrics. Integrity metrics measure key field coverage and imputation ratio; consistency metrics measure field consistency and time-series consistency across multiple data sources for the same event; source reliability metrics score based on acquisition channels and device self-check status; time accuracy metrics assess time synchronization drift and transmission delay distribution; and topology reliability metrics are calculated based on device graph up-to-dateness and link health. Scores in the range of zero to one can be generated using a normalized linear weighted model or a learned weighted model. Anomaly detection introduces quantile thresholds or robust Z-scores to penalize extreme values. Scores for each sub-item and the total score are recorded for easy tuning of quality thresholds.

[0123] The quality threshold can be determined statically or adaptively. Static setting is suitable for scenarios with stable data quality, while adaptive generation can use quantile thresholds or Bayesian optimal cutoff points based on the score distribution within a sliding time window. Different thresholds can be set for different business domains and different device types to match their respective data noise levels. The filtering process retains audit records for all excluded objects, including event data pair identifiers, sub-scores, exclusion reasons, and threshold versions, supporting traceability and review.

[0124] The timestamp-based sorting process constructs a sorting key using representative timestamps of event data pairs. This key can be an earlier timestamp, a later timestamp, or the average of both, ensuring consistency with the downstream analysis's assumptions about causality. A stable algorithm is used to maintain the original relative order within the same key, unifying the sorting across time zones to a single time base. After sorting, a historical converged dataset is generated, containing a list of event data pairs, a three-dimensional feature data matrix, data confidence scores, and a metadata index. When persisting the dataset, version numbers, generation times, data source lists, field dictionary checksums, and quality threshold snapshots are written. Both read-only and incremental append views are provided, and secondary index retrieval based on event identifiers and time ranges is supported.

[0125] This embodiment utilizes API connections for distributed environments, pairwise construction driven by convergence tags, feature generation covering the temporal, spatial, and topological domains, interpretable data confidence assessment and threshold filtering, and stable time-ordered and versioned output to obtain a well-structured and noise-controlled historical convergence dataset. This dataset reduces bias caused by missing and inconsistent data, improves the reliability of parameter estimation and probability calculation in subsequent model analysis, shortens feature preparation and cleaning cycles, enhances portability across data centers and business domains, and provides complete metadata support for future experiment reproduction and quality traceability.

[0126] In one embodiment, step S20 above includes:

[0127] S201, The historical convergence dataset is processed using a pre-trained language model to generate a set of semantic feature vectors;

[0128] S202, Based on the set of semantic feature vectors, create an event topology graph, where nodes in the event topology graph represent event data and edges represent the relationships between events;

[0129] S203, analyze the event topology graph using a graph neural network to identify high-frequency event association patterns;

[0130] S204, extract multidimensional attribution parameters from the high-frequency event association pattern, including parameters for the same triggering cause, parameters related to the device type, and parameters related to the scope of influence.

[0131] S205, Calculate the frequency of occurrence of each multidimensional attribution parameter in the historical convergence dataset and determine the corresponding probability value;

[0132] S206, integrate the multidimensional attribution parameters and their corresponding probability values ​​into an attribution parameter table.

[0133] In this embodiment, when the pre-trained language model processes the historical converged dataset, it first performs unified cleaning and standardization. Timestamps are converted to a unified time zone, templated noise and duplicate tags are removed from text fields, and device identifiers and geographic locations are mapped to integrated asset codes. Then, the process proceeds to word segmentation and sub-word encoding, employing the same vocabulary and regularization standards as the pre-trained language model to ensure consistent comparability of the vector space. When jointly modeling structured and text fields, numerical values, enumerations, and topological labels are encoded as discrete or continuous embeddings, which are then concatenated or gated with the text embeddings to output a set of semantic feature vectors. To reduce scale differences among heterogeneous fields, layer normalization and projection layers are introduced to ensure robust representation of each event data point within the same dimensional space. To prevent bias introduced by long tails and distribution drift in historical samples, time decay weights and hard sample mining strategies can be introduced to improve the representativeness of recent patterns.

[0134] When creating an event topology graph based on a set of semantic feature vectors, each event data point is treated as a node, and edge generation follows a reproducibility criterion. Temporal concurrency relationships, historical convergence relationships, shared device or link relationships, and common upstream point relationships can all be converted into edges. Edge weights can be derived by combining concurrency strength, convergence co-occurrence frequency, and topological distance to obtain a weighted directed or undirected graph. To suppress occasional co-occurrence noise, a minimum support threshold and time window constraints are set, retaining only edges that reach the support threshold within the specified time window. For ease of subsequent learning, weights are normalized or logarithmically scaled. Large-scale graphs are constructed by time slices or business domain partitions, and cross-domain dependencies are recorded through cross-partition indexes.

[0135] Graph neural networks are used to identify high-frequency event association patterns on event topology graphs. In the adjacency aggregation stage, operators such as GCN, GAT, or GraphSAGE can be employed, with edge weights participating in message passing and attention calculations. Residuals and skip connections are superimposed to alleviate oversmoothing. For time-sensitive scenarios, a time-series graph module is introduced, encoding timestamps as relative time embeddings or periodic embeddings, and using a time decay kernel during aggregation. Full-graph-level representations are obtained through global or community-level readouts, combined with contrastive learning or self-supervised tasks (such as edge prediction and subgraph prediction) to improve the discriminative power in unlabeled scenarios. To capture stable co-occurrence patterns structurally, frequent subgraph pattern mining and motif recognition are introduced, corroborating the graph neural network embeddings to screen out high-support, high-confidence high-frequency event association patterns. To address issues of sample imbalance and hotspot bias, reweighting or hierarchical sampling is employed to prevent the learning process from overfitting to a very small number of high-frequency nodes.

[0136] When extracting multidimensional attribution parameters from high-frequency event association patterns, pattern interpretation is mapped to three named dimensions: trigger cause same parameters, device type related parameters, and impact range related parameters. Trigger cause same parameters are obtained through similar semantic clustering and causal clue extraction; the same root cause text description or the same fault tree branch is grouped into the same value. Device type related parameters are determined by the device type label of nodes and the stability of co-occurrence of the same type within the pattern. Impact range related parameters are quantified based on derived measures such as topological propagation range, number of affected nodes, and cross-domain diffusion intensity. The extraction process not only produces values ​​but also the criteria for value determination and pattern tracing numbers for subsequent verification and governance. To avoid misleading results from occasional co-occurrence, parameter values ​​are evaluated in conjunction with time window length, edge weight threshold, and community stability; only when stability reaches the threshold is the value solidified as a valid entry.

[0137] The probability values ​​are determined based on the statistical characteristics of the historical convergent dataset. The frequency of each multidimensional attribution parameter is statistically analyzed, and robust probabilities are obtained through smoothing and calibration. Smoothing can utilize Dirichlet or Beta priors to mitigate low-sample volatility; calibration can use ordinal regression or log-odds calibration to ensure the frequency estimate aligns with the actual hit rate. For differences across data centers or business domains, hierarchical statistics and inter-layer shared priors are employed to find a robust balance between global and local factors. To control time drift, rolling probabilities are output using a sliding time window, and the window width and timestamp are recorded for downstream temporal matching. The joint probability of multidimensional parameters is estimated using a decomposable model with conditional independence assumptions or a sparse factor graph, avoiding the curse of dimensionality caused by the full Cartesian product.

[0138] The integration of attribution parameter tables follows the principles of structure and manageability. Each row records a multi-dimensional attribution parameter entry, including parameter name, parameter dimension value, probability value, confidence interval, support count, time window, applicable device type range, applicable impact range threshold, data source and traceability number, generation model version, validity period, and expiration conditions. When multiple versions of the same parameter coexist, they are distinguished by version and time window. Older versions are archived for playback and traceability only. To support online updates and offline playback, two access semantics are provided: append write and snapshot read. Consistency between upstream and downstream is ensured through checksums and dictionary versions. To ensure security and compliance, sensitive fields are anonymized. Log records include generation time, input dataset version, graph neural network configuration, and random seed to ensure reproducibility. Quality control incorporates hold-out set validation and cross-domain validation. Entries with probability value deviations exceeding the threshold are automatically downgraded or marked for review.

[0139] This embodiment uses a set of semantic feature vectors to uniformly represent text and structured attributes. An event topology graph captures structural relationships across time and devices. Graph neural networks and high-frequency event association pattern recognition provide structured extraction of stable co-occurrence patterns. Multidimensional attribution parameters map patterns to three interpretable dimensions: parameters related to the same triggering cause, parameters related to device type, and parameters related to the scope of influence. Combined with smoothing and calibration, robust probability values ​​are obtained and stored in an attribution parameter table. The resulting data-driven attribution knowledge is interpretable, versionable, and traceable, reducing the impact of noise and long tails on parameter estimation, improving the accuracy and consistency of matching and decision-making in subsequent convergence judgments, shortening the deployment and review cycle, and maintaining stable performance in cross-domain migration scenarios.

[0140] In one embodiment, step S30 above includes:

[0141] S301, Define a dynamic time window for each event data pair, and monitor the occurrence of event data within the dynamic time window;

[0142] S302, within the dynamic time window, count the number of concurrent occurrences of two event data;

[0143] S303, within the dynamic time window, count the number of convergence correlations where two event data are simultaneously converged;

[0144] S304, Based on the number of concurrent occurrences and the total number of events, determine the concurrency impact factor value;

[0145] S305, Based on the convergence correlation count and the total convergence count of the event data, determine the convergence correlation factor value;

[0146] S306, The concurrent impact factor value and the convergence correlation factor value are weighted and fused to generate the correlation degree between events.

[0147] In this embodiment, when defining a dynamic time window for each event data pair, it is necessary to clarify the start and end conditions of the time window and the dynamic adjustment strategy for its length. The time window can be automatically determined based on the occurrence density of historical event data, business processing latency, and device monitoring frequency, and can be implemented based on sliding windows, jumping windows, or adaptive windows. Sliding windows can continuously capture the co-occurrence of events in overlapping time periods, making them suitable for high-frequency alarm environments; jumping windows are suitable for periodic monitoring tasks; adaptive windows can automatically widen or shrink the window length based on the time interval distribution between events to more accurately capture time-series dependencies. The definition of the window is not limited to absolute time; logical triggering conditions can also be introduced, such as the occurrence of a specific type of event triggering the window to open, to enhance the response capability to sudden events.

[0148] When monitoring the occurrence of event data within a dynamic time window, an event stream monitoring mechanism needs to be established to align each record in the event data stream with its timestamp and label its type. An event index structure, such as an ordered hash table based on timestamps or a time-binding structure, can be used to quickly locate event sets within any time period. For events that cross devices or regions, unique event identifiers need to be generated during the monitoring phase to prevent duplicate counting or omissions. The monitoring process can be integrated with a real-time stream processing platform to achieve near real-time analysis and updates of event data within the window.

[0149] When counting the concurrent occurrences of two events within a dynamic time window, the system should perform a matching scan on each pair of event data to determine whether their occurrence times fall within the same window and meet the concurrency definition conditions. Concurrency conditions may include a time difference less than a preset threshold, the order of the two events not affecting the concurrency judgment, and a certain correlation between the two events in physical location or business logic. During the statistical process, bitmap or sparse matrix structures can be used to efficiently record concurrency relationships, which can significantly reduce storage and computational overhead, especially in large-scale event datasets.

[0150] When counting the number of convergence associations where two event data points converge simultaneously within a dynamic time window, historical convergence result records are needed to determine the convergence relationship of the event pair. The system should extract the convergence batch or convergence target identifier corresponding to the event ID from the convergence record table and determine whether the two events occur within the same convergence batch. Further analysis can consider the order and conditions of convergence, such as whether it was caused by the same triggering reason or whether it involved the same combination of attribution parameters, thereby improving the accuracy of determining the number of convergence associations.

[0151] When determining the concurrency impact factor value based on the number of concurrent occurrences and the total number of events, a proportional calculation method can be used. This involves dividing the number of concurrent occurrences of each event pair by the maximum possible number of concurrent opportunities, resulting in a normalized value between 0 and 1. To reduce the impact of occasional concurrency, weighted smoothing or a weighted moving average can be introduced to give greater influence to recent concurrency patterns on the factor value. The concurrency impact factor value reflects the stability of the co-occurrence of two events over time and is of great significance for identifying event pairs with strong temporal correlations.

[0152] When determining the convergence correlation factor value based on the number of convergence correlations and the total number of convergences in the event data, the calculation method is similar. The number of convergence correlations is compared with the maximum possible convergence opportunity to obtain the standardized degree of convergence correlation. To distinguish between strong and weak correlations, convergence condition strength weights can be introduced during the calculation process, such as the matching degree of attribution parameters involved in convergence and the delay time of convergence, to enhance the discriminative power of the convergence correlation factor value.

[0153] When weighted fusion of concurrent influence factor values ​​and convergence correlation factor values ​​to generate inter-event correlation, linear weighting, nonlinear combination, or machine learning regression models can be used to fuse the two factor values. The weights can be determined from fitting results of historical data or set as fixed proportions based on domain experience. Nonlinear combination can utilize methods such as logistic regression or gradient boosting trees to better reflect complex correlation patterns. The final generated inter-event correlation is a quantitative indicator that can be used in subsequent processes such as updating dynamic attribution parameter tables and event convergence decisions. It can also be output hierarchically as needed, such as global correlation, regional correlation, and equipment type correlation, to support multi-granularity analysis.

[0154] This embodiment, through a dynamic time window definition and monitoring mechanism, can adapt to event flows of different frequencies and patterns, ensuring the timeliness and accuracy of capturing concurrency and convergence relationships. By separately statistically analyzing the number of concurrency events and the number of convergence correlations, the correlation between events in terms of time dimension and convergence behavior can be quantified simultaneously, avoiding misjudgments caused by a single indicator. The fusion of concurrency impact factor values ​​and convergence correlation factor values ​​generates the correlation degree between events, which not only integrates information from both temporal co-occurrence and convergence history, but also allows for flexible adjustment of its contribution ratio to the final result through weighting or model learning. This makes the correlation degree between events adjustable and highly adaptable in different application scenarios, thus providing a robust quantitative basis for subsequent event attribution and convergence decisions.

[0155] In one embodiment, step S40 above includes:

[0156] S401, construct a correlation change matrix based on the correlation between current events and the correlation between historical events;

[0157] S402, determine the correlation score of each attribution parameter in the attribution parameter table with the correlation change matrix;

[0158] S403, Select the attribution parameter whose correlation score exceeds the preset correlation threshold as the key influence parameter;

[0159] S404, Based on the magnitude of change in the correlation degree change matrix, determine the dynamically updated weight value for each key influence parameter;

[0160] S405, Based on the dynamically updated weight value, adjust the probability value corresponding to the key influencing parameter to generate the updated probability value;

[0161] S406, Based on the updated probability values ​​and the correlation change matrix, reconstruct the correlation relationships between parameters in the attribution parameter table;

[0162] S407, the updated attribution parameter table is version-marked and stored.

[0163] In this embodiment, when constructing the correlation change matrix based on the correlation between current events and the correlation between historical events, the sampling period, indicator dimension, and index space of the two types of correlation are first unified to ensure that the measurements of the same pair of events at different time periods can be aligned item by item. The correlation between current events comes from the fusion results of the most recent batch of concurrent and convergent statistics, while the correlation between historical events can be obtained using robust statistics such as exponential weighted average or segmented median within a sliding time window. After aligning the two by event pairs as rows and correlation dimension as columns, the difference, ratio, or logarithmic difference is calculated by element to form a matrix representation with the increment as the core, while retaining the timestamp and data source identifier for easy traceability and rollback. To suppress abnormal fluctuations, bidirectional truncation and robust standardization can be applied to the matrix elements, and mask information for missing or low-confidence entries can be recorded to avoid subsequent calculations being affected by contaminated data.

[0164] When determining the relevance score of each attribution parameter in the attribution parameter table relative to the correlation change matrix, a mapping relationship between parameters and event pairs is first established. Common mapping methods include the set of events affected by a parameter or the set of event pairs that co-occurred with the parameter in past convergence. Based on this mapping, the corresponding submatrix is ​​extracted from the correlation change matrix and its relevance is quantified with the parameter's historical performance vector. The relevance score can use Pearson correlation for sensitive detection of linear relationships, mutual information to capture nonlinear dependencies, or a robust metric based on rank correlation for stable evaluation in the presence of outliers. To avoid single statistical bias, it is recommended to normalize multiple metrics before weighted summation and introduce sample size weights to give higher support scores greater credibility. Finally, a relevance score in the range of zero to one is output for each parameter, along with the score confidence interval and support count.

[0165] When selecting attribution parameters whose relevance scores exceed a preset relevance threshold as key influencing parameters, it is necessary to clarify the principles for setting the threshold and the adaptive adjustment mechanism. The threshold can be derived from the percentile division of the score distribution over a historical period, or the optimal compromise point can be selected based on the receiver operating characteristic (ROC) curve of the validation set. To address seasonality and sudden disturbances in business operations, the threshold can be updated over time with upper and lower limits to prevent excessive drift. When the number of parameters is large, sparsity constraints can be applied, retaining only a top percentage of entries to improve subsequent update efficiency, and recording suppressed marginal parameters for later auditing.

[0166] When determining the dynamic update weight value for each key influencing parameter based on the change magnitude in the correlation change matrix, the matrix elements associated with the parameter are first weighted and aggregated. The aggregation weight can be set according to the historical confidence of the event pair, data integrity, and recent freshness. The change magnitude can adopt different configurations such as absolute difference, relative rate of change, or logarithmic change intensity, and then a comparable scale is obtained based on distribution adaptive standardization. To suppress over-updating caused by a single drastic fluctuation, asymmetric response curves with different sensitivities for uplink and downlink can be introduced. The uplink side emphasizes rapid correction, while the downlink side emphasizes smooth decay. The obtained dynamic update weight value and correlation score together determine the update step size and direction of the parameter, and trigger weight reduction or freezing when the safety boundary is exceeded.

[0167] When adjusting the probability values ​​of key influencing parameters based on dynamically updated weights and generating updated probability values, an interpretable and numerically stable update mechanism should be prioritized. Bayesian incremental updates can be used to synthesize historical priors with new evidence strength to obtain new posterior probabilities. Alternatively, exponential smoothing can be employed, weighting the original probability against the suggested probability derived from the change magnitude. To prevent probability overflows or unreasonable gradients, a maximum single-cycle change magnitude, global monotonicity constraints, and a minimum support threshold should be set. Updated probability values ​​are simultaneously written to a shadow region with a version number, and are then promoted to the online version after consistency verification. If logical dependencies exist between parameters, such as hierarchical relationships between parameters with the same triggering cause and parameters related to device type, consistency correction can be performed after probability adjustment to ensure that the joint distribution is normalized and meets business rules.

[0168] When reconstructing the relationships between parameters in the attribution parameter table based on updated probability values ​​and the correlation change matrix, it is necessary to switch to graph structure update mode. First, parameters are used as nodes, and co-occurrence strength or conditional dependency strength is used as edge weights. These edge weights are then adjusted based on the latest correlation change signal. For parameter pairs frequently triggered by highly correlated events, their edge weights are increased, and they are labeled as proximate or distant causes. Connections with edge weights below a threshold are soft-deleted, and hard-deleted after stabilizing at low weights over multiple periods to reduce noise. Graph regularization and ternary consistency constraints can be introduced to prevent structural contradictions after the update, such as the same parameter being strongly dependent on and strongly mutually exclusive with another parameter. After the update, a new version of the parameter dependency graph is output and stored in a structure consistent with the table, ensuring that the downstream decision engine can simultaneously read both probability and structural information.

[0169] When versioning and storing the updated attribution parameter table, metadata records containing version number, timestamp, data source, calculation configuration, and verification fingerprint need to be established. The version number uses a non-retrograde monotonic sequence and supports canary releases, allowing for full-scale switching after small-scale verification. The storage layer implements multiple replicas and atomic writes to avoid partial writes caused by concurrent updates. For auditing purposes, difference snapshots need to be retained, including vectors of parameter probability changes, edge lists of structural changes, and cause summaries. Rollback strategies and trigger conditions also need to be defined. For example, if an abnormal convergence rate or increased alarm miss rate occurs after deployment, the system can automatically switch back to the previous stable version and freeze new change sources, awaiting manual review.

[0170] This embodiment utilizes an incremental update and filtering mechanism driven by changes in correlation to effectively map the latest inter-event relationships to attribution parameters and their interdependencies, avoiding excessive fixation of parameters by long-term historical data. The hierarchical design of correlation score filtering and dynamic weight updates allows parameters truly strongly correlated with changes in correlation to receive larger update steps, while weak correlations or noise sources are suppressed, reducing the probability of erroneous updates. Robust updates of probability values ​​and synchronous reconstruction of structural relationships ensure that the parameter table aligns with the current environment at both the numerical and structural levels. This provides a more stable prior and a clearer dependency graph for subsequent convergence judgments, improving convergence accuracy and timeliness. Furthermore, it achieves controllable evolution and traceable operation and maintenance under the protection of versioning and rollback mechanisms.

[0171] In one embodiment, step S60 above includes:

[0172] S601, if the event data to be processed exists in the attribution parameter table, then load the parameter set related to the event data to be processed from the attribution parameter table, and initialize the convergence decision engine based on the parameter set;

[0173] S602, using the convergence decision engine and the parameter set, determine the correlation score between the event data to be processed and multiple live event data;

[0174] S603: Select the live event data with the highest correlation score as the preferred live event data for correlation.

[0175] S604, if the correlation score of the preferred live event data meets the preset correlation requirement, then generate a hierarchical convergence judgment operation result indicating convergence to the preferred live event data.

[0176] S605, if the correlation score does not meet the preset correlation requirement, then the convergence decision engine uses the parameter set to analyze the attribution parameter matching degree between the event data to be processed and multiple live event data;

[0177] S606, Select the live event data with the highest attribution parameter matching degree as the preferred live event data for parameter matching;

[0178] S607, if the attribution parameter matching degree of the preferred live event data meets the preset matching degree requirement, then generate a hierarchical convergence judgment operation result indicating convergence to the preferred live event data; otherwise, generate a hierarchical convergence judgment operation result indicating release.

[0179] S608, if the result of the hierarchical convergence judgment operation indicates convergence towards the target already alive event data, then the event data to be processed is associated with the target already alive event data;

[0180] S609, if the result of the hierarchical convergence judgment operation indicates that the process should proceed, then the pending event data is marked as an independent event and an alarm is pushed.

[0181] S610, record the results of the hierarchical convergence judgment operation and the execution operation in the decision log.

[0182] In this embodiment, the definition of event data to be processed is directed towards single or grouped alarm records entering the system in real time, including fields such as timestamp, device identifier, geographic identifier, measurement point name, original threshold trigger information, context text, and associated ticket number. The data access side completes field standardization and unique key generation to ensure cross-indexing with historical assets, work orders, and monitoring domain models. The attribution parameter table is a structured prior set, recording the attribution parameter name, parameter type, parameter value range, probability value, time validity period, data source, and version number, while maintaining the parameter dependency graph and historical change trajectory. The parameter set represents the minimum usable set selected from the attribution parameter table by key and tailored according to the scenario. It is typically filtered based on device type, alarm category, data center topology, or service domain to reduce interference from irrelevant dimensions in subsequent calculations. The convergence decision engine initializes the parameter set, parameter dependency graph, and necessary feature transformers in memory, configures the correlation and matching degree calculation plugins, threshold gating, conflict processor, and log collection probe, and binds model weights and version metadata to ensure the traceability of different release batches.

[0183] The live event data consists of a set of alarms that are currently active but not yet closed in a loop. These alarms typically originate from the event bus or alarm buffer and are tagged with states such as active, pending confirmation, or being processed. The system establishes an inverted index and a time window index for the live event set, with keys including device, region, service, and topological adjacency, facilitating rapid retrieval of potentially related objects. The correlation score quantifies the correlation strength between the event to be processed and each live event. The calculation path can simultaneously access multiple signal sources: concurrent statistical components, convergence history components, spatiotemporal proximity components, topological similarity components, and textual semantic components. Concurrency and convergence components are derived from statistical priors of historical convergence datasets; spatiotemporal components are compressed to the zero-to-one range using a kernel function based on time difference and spatial distance; topological components are based on structural features of the device graph, such as shortest paths, shared upstreams, and common domain boundaries; and textual components calculate similarity by vectorizing event titles and descriptions. After normalization, multiple components are fused using an additive or multiplicative strategy, combined with confidence weights to generate a single score. To avoid occasional spikes affecting the judgment, a sliding window averaging and robust truncation are introduced.

[0184] The correlation evaluation prioritizes existing event data, sorting all scores to obtain the highest-scoring object, and outputting a list of top candidates for easy rollback strategies. Preset correlation requirements are stored in the configuration library as interval thresholds. Differential thresholds can be set according to environment and alarm category, and an adaptive update mechanism can be introduced to dynamically fine-tune the results using the score distribution of recently correctly converged samples. If the threshold is passed, the hierarchical convergence evaluation results generate a convergence indicator along with the target identifier, score, decision path, and parameter snapshot; if it fails, further review at the parameter level follows.

[0185] Attribution parameter matching measures the consistency of the event to be processed relative to each existing live event across the attribution parameter dimensions. Trigger cause consistency parameters, device type relevance parameters, and impact range relevance parameters in the parameter set are mapped to specific feature comparison logic: trigger cause consistency is achieved through normalized cause encoding or semantic matching; device type relevance is achieved through a similarity mapping table and compatibility matrix; impact range relevance is achieved through topology broadcast radius, rack, or data center domain matching. Each parameter is given a consistency degree and weight ranging from zero to one. The overall matching degree is a weighted summary value, and an explanatory vector is output to record the dimension with the greatest contribution. Parameter matching prioritizes existing live event data determined by the highest matching degree. The preset matching degree requirement also uses threshold gating and allows short-circuit logic with the relevance threshold: a convergence indication is generated as long as the requirement is met at any level; if neither level is met, a release indication is returned.

[0186] The determination of target live event data follows conflict resolution rules. When the relevance and matching scores point to different objects and both exceed thresholds, a weighted vote or the product of the two scores is used for decision-making; if they are still tied, time proximity, alarm importance level, or business domain priority are introduced as deciding factors. The convergence execution phase links the events to be processed to the aggregation link of the target live event data, updates the summary information and statistical fields of the aggregation header object, and triggers state machine transitions and notification processes. The release path writes the events to be processed into the activity set and labels them independently, while recording the reasons for non-convergence for future learning.

[0187] The hierarchical convergence judgment operation results and execution operations are fully written to the decision log. The log content includes input snapshots, parameter set versions, scores of each component, threshold values, decision paths, final decisions, execution times, time consumption, exceptions, and alarms. The log is written using immutable event streams and supports retrieval and compressed archiving, providing a chain of evidence for subsequent auditing, review, and parameter updates. To control latency, the entire judgment process reduces redundant calculations through asynchronous pipelines and cache reuse. External dependencies within the critical path are all configured with timeout and degradation strategies to ensure stable decision-making even during peak load periods.

[0188] This embodiment employs a two-level decision-making mechanism. First, it uses correlation scores for rapid convergence screening based on multi-source signal fusion. Then, it uses attribution parameter matching for structured verification, improving robustness while maintaining real-time performance. A convergence indication is returned when any level meets the threshold, reducing reliance on single statistical or semantic signals. If both levels are insufficient, passage is directly allowed, preventing false convergence from spreading to the aggregation link. Conflict resolution of target objects and full decision log recording ensure that each connection or release is interpretable and traceable, facilitating subsequent optimization of thresholds and weights, thereby improving convergence accuracy, shortening average processing latency, and maintaining the stability and clarity of the aggregation structure in high-concurrency scenarios.

[0189] In one embodiment, step S70 above includes:

[0190] S701, if the event data to be processed does not exist in the attribution parameter table, then the pre-trained language model is used to extract features from the event data to be processed and the live event data to generate an event feature vector;

[0191] S702, Based on the event feature vector, construct a multidimensional clustering feature space;

[0192] S703, Perform density clustering analysis in the multidimensional clustering feature space to generate clustering grouping results;

[0193] S704, determine the cluster confidence score for each cluster group;

[0194] S705, when the clustering confidence score exceeds a preset confidence threshold, convergence suggestion information is generated, and a confirmation request is sent to the user based on the convergence suggestion information;

[0195] S706, receives user response commands;

[0196] S707, if the user response instruction is a confirmation instruction, then the event data to be processed is associated with the target cluster group, a convergence operation result containing convergence association data and cluster analysis data is generated, and the convergence operation result is updated to the data pool of the attribution parameter table.

[0197] S708, if the user response instruction is not a confirmation instruction, then the pending event data is marked as an independent event and an alarm message is pushed;

[0198] S709, when the cluster confidence score does not exceed the preset confidence threshold, a release operation instruction is generated, and the pending event data is marked as an independent event and an alarm message is pushed.

[0199] In this embodiment, a pre-trained language model is used to map the event data to be processed and the existing event data to a unified vector space. Input fields include timestamps, device and measurement point identifiers, geographic locations, topological location information, event titles and descriptions, historical processing tags, and impact range tags. Text fields are first cleaned, segmented, and standardized into sentences; numerical and enumerated fields are normalized and embedded. Event feature vectors are then generated using the same model. To avoid single-domain feature dominance, a multi-head concatenation and layer normalization strategy is used to aggregate semantic sub-vectors, spatiotemporal sub-vectors, and topological sub-vectors into a fixed-length vector. Metadata such as version numbers, token counts, and mask positions are retained during vector generation to ensure subsequent traceability and consistency verification.

[0200] A multidimensional clustering feature space is constructed based on event feature vectors. The vector dimensions remain consistent with the model output, and cosine distance is preferentially used as the distance metric. High-frequency dimensions are whitened when necessary to reduce collinearity. To address time sensitivity and fluctuating data size, time decay weights and hierarchical sampling are introduced: high-time-sensitivity samples are given larger weights, and distant samples are compressed exponentially. When the number of live event data exceeds a threshold, the data is first sharded within the device or data center domain, and then clustering is performed within the shards to avoid excessive latency caused by global computation.

[0201] Density clustering analysis is performed within a multidimensional clustering feature space, and algorithms such as DBSCAN or HDBSCAN can be used. Automatic parameter optimization is achieved in two steps: first, inflection points on the k-distance curve are detected and eps are estimated; then, min_samples is set based on the desired minimum cluster size. If significant spatiotemporal local density phenomena exist, scale factors are introduced for both the temporal and spatial dimensions, and the weights in the distance metric are adjusted accordingly. The clustering results output cluster identifiers, member lists, core point sets, noise point sets, and local reachability statistics, providing basic statistics for subsequent reliability assessment.

[0202] Cluster confidence scores measure whether each cluster possesses a stable structure suitable for convergence. The score is a weighted average of several metrics: silhouette coefficient reflects cohesion and separation; core point percentage reflects density stability; temporal compactness reflects the consistency of occurrence time (normalized by intra-cluster time span and member count); topological consistency reflects the homodomainity of members in the network or device graph (represented by the average shortest path and the proportion of common upstream nodes); and textual consistency reflects semantic similarity (represented by the mean cosine similarity between members). Each metric is mapped to a zero-to-one range and weighted by configurable weights to obtain a single score. The output includes details of each metric and its weighted version. To suppress occasional anomalies, the scores are exponentially smoothed using a sliding window, and a correction term is applied to low-sample clusters.

[0203] When the clustering confidence score exceeds a preset confidence threshold, the system generates convergence suggestion information. The suggestion includes the target cluster group identifier, candidate target sample summary, scoring details, threshold comparison, expected impact (statistical changes in the aggregation head object, potential scope of impact), and risk warnings (such as insufficient samples or indicator discrepancies). This information is pushed to the monitoring console or automated approval component via an interface, forming a user confirmation request. The request includes timeout and rollback policies to ensure continued progress even when unattended.

[0204] User response instructions are primarily of two types: confirmation and rejection. Modification suggestions can also be included, such as adjusting thresholds, restricting device domains, or removing individual members. The system records the differences between the original suggestion and the response and proceeds to the execution branch. Upon receiving confirmation, the pending event data and the target cluster group establish a convergence relationship, generating convergence operation results. These results include convergence relationship data and cluster analysis data. The convergence relationship data records the connection relationship, target aggregation head, before and after statistical snapshots, executor or execution channel, timestamp, and idempotent key. The cluster analysis data records the vector summary, clustering parameters, scoring details, indicator characteristics, candidate list, and removed members. Both parts are written to the attribution parameter table's data pool using a unified schema, triggering an incremental update task for subsequent learning and parameter recalculation.

[0205] When a user responds with a rejection command, the system marks the pending event data as an independent event and pushes an alarm. If the reason includes tags such as "threshold too high" or "topology inconsistency," the relevant metadata is also written to the data pool for reverse calibration of the threshold or weight. Another approach, for cases where the clustering confidence score does not exceed the threshold, directly generates a release command, avoiding extra time spent in the human-machine interaction process. It also records the details of the failed score, sample size, and other context along with the independent event for subsequent clustering parameter tuning. The entire process follows the principles of low latency and traceability: vectorization and nearest neighbor search for real-time links reside in memory or use high-performance vector indexes; time-consuming operations are separated into asynchronous update channels; immutable event logs are generated at all decision points, including input summaries, model and parameter versions, thresholds, scores, conclusions, and execution time, supporting auditing and replay.

[0206] Example Explanation: During the operation of a data center server room, the monitoring system receives and stores real-time alarm information from various devices such as temperature and humidity sensors, air conditioning controllers, power distribution cabinets, battery packs, UPS, fire protection systems, and access control systems. These alarms are entered into the server room alarm management platform in the form of events. Due to the multiple dependencies between devices, environmental disturbances that can trigger cascading alarms, and the fact that the multi-point deployment of the monitoring system itself can lead to duplicate reporting, a large number of similar or related alarm events may be triggered by the same cause within a short period of time. For example, an air conditioning failure in a server room may cause alarms from cold aisle temperature sensors, high return air temperature, and abnormal humidity, and may also be accompanied by overheating alarms from servers inside the racks.

[0207] To effectively handle such scenarios, the system first establishes a connection with the data center's distributed alarm database via an API interface to extract a set of raw alarm records from historical periods. These records include the data center number, rack location, device identifier, alarm type, alarm occurrence time, clearing time, alarm text description, and a marker indicating whether the alarm was manually or systematically converged. After extraction, the system scans the dataset to identify all alarm event pairs marked as converged, such as the combination of "air conditioning return air high temperature alarm" and "cold aisle high temperature alarm." Subsequently, key spatiotemporal correlation features are extracted from each pair of events, including the time difference between the two alarms (millisecond precision), the straight-line distance between the physical locations of the devices (meters), and the hierarchical path differences of the devices in the data center topology (e.g., whether they are in the same rack or the same cooling zone). These features are combined to construct a three-dimensional feature matrix containing temporal, spatial, and topological dimensions for subsequent analysis. To ensure data reliability, the system calculates the confidence score of each event pair based on historical manual verification and data collection logs, filters records below the preset quality threshold, retains only high-confidence event pairs, and sorts them by timestamp to form a historical convergence dataset.

[0208] The system inputs the historical converged dataset into a pre-trained language model that has been optimized for industry performance. The model performs word segmentation, entity extraction, and semantic modeling on fields such as the title and description text of alarm events, normalizes the spatiotemporal features of numerical classes, and encodes multi-source information into a unified set of semantic feature vectors. Based on these vectors, the system constructs a topological relationship graph of data center events. Nodes in the graph represent individual alarm events, and the weights of the edges reflect the semantic similarity between events, the topological adjacency of equipment, and the probability of simultaneous occurrence in history. Subsequently, a graph neural network is used to perform pattern mining on this graph to identify high-frequency alarm combination patterns in data center operation, such as "cooling unit abnormality + high temperature alarm" or "UPS input voltage abnormality + battery pack alarm". Attribution parameters are extracted from these patterns, including parameters with the same triggering cause (such as belonging to the cooling system failure), equipment type correlation parameters (such as the correlation between air conditioners and temperature and humidity sensors), and impact range correlation parameters (such as the situation where multiple racks in the same area are affected). The frequency of each parameter in historical data is counted to generate an attribution parameter table with probability values.

[0209] The system further analyzes the concurrency and convergence correlation of each pair of alarm events in the historical dataset. For each pair of alarm events, a dynamic time window is defined. The length of this window can be automatically adjusted according to the alarm type and the data center's workload; for example, cooling-related alarms may be set to 10 minutes, while power system alarms may be set to 2 minutes. Within this time window, the system counts the number of times the two events occur simultaneously as the concurrency count and the number of times the two events appear in the same convergence operation as the convergence correlation count. A concurrency impact factor is calculated based on the concurrency count and the total number of events, and a convergence correlation factor is calculated based on the convergence correlation count and the total number of convergences. Finally, the two factors are weighted and fused to obtain the correlation degree between the events.

[0210] When a new round of real-time operational data arrives, the system dynamically updates the attribution parameter table using the aforementioned correlations between events. The system calculates the change between the current correlation and historical correlations, constructs a correlation change matrix, and calculates a correlation score for each parameter in the attribution parameter table relative to the change matrix. Parameters exceeding a threshold are selected as key influencing parameters. For these parameters, the system dynamically updates their weight values ​​based on the magnitude of the change, adjusts their probability values ​​in the attribution parameter table, and reconstructs the correlations between parameters based on the updated probability values ​​and the change matrix. Finally, the new parameter table is versioned and stored to ensure the adaptive evolution of the convergence model's random room operation status.

[0211] When the monitoring platform receives a new pending alarm event, the system first determines whether the event already has a matching record in the attribution parameter table. If a matching record exists, the system loads the parameter set related to the event from the attribution parameter table, initializes the convergence decision engine, and calculates the correlation score between the event and all live alarm events (active events that have not yet converged). If the highest correlation score exceeds a set threshold, an instruction is generated to converge the event to the live event with the highest correlation. If the correlation score does not reach the threshold, the system calculates the attribution parameter matching degree, selects the live event with the highest matching degree as a convergence candidate, and if the matching degree also meets the requirements, convergence is performed; otherwise, the event is allowed to proceed and an alarm is triggered separately.

[0212] If no matching record is found in the attribution parameter table for the pending alarm event, the system will invoke the model-assisted convergence process. This process utilizes a pre-trained language model to extract features from both the pending event and all surviving events simultaneously. The resulting vector is input into a multi-dimensional clustering feature space, density clustering analysis is performed to generate clustering results, and a clustering confidence score is calculated for each group. When the confidence score exceeds a threshold, the system generates a convergence suggestion and pushes it to the on-duty engineer for confirmation. After confirmation, the event is associated with other events within the clustering group, and the convergence operation results (including associated data and clustering analysis data) are written into the data pool of the attribution parameter table to provide samples for subsequent model learning. If the engineer refuses convergence, or the clustering confidence score itself is insufficient, the system marks the event as an independent event and issues an alarm directly to avoid the risk of false convergence.

[0213] The overall processing chain performs as follows in the field of data center monitoring: When faced with a series of environmental alarms, such as "Air conditioner compressor failure in data center A", the system can quickly determine the correlation between alarms by using historical convergence patterns and real-time feature analysis, and automatically converge when reliability is sufficient, reducing the intervention of on-duty personnel; for new alarm combination patterns, the system gradually incorporates them into the range of automatic convergence through a combination of model-assisted clustering and manual confirmation, ensuring that while reducing the number of alarms, the accuracy and interpretability of convergence are maintained, thereby improving the efficiency of data center alarm processing and operational stability.

[0214] In the operation of large comprehensive medical institutions, regional medical centers, or smart healthcare platforms, medical monitoring and alarm systems continuously receive and store real-time alarm information from patient monitoring equipment, medical imaging systems, testing equipment, infusion pumps, ventilators, and medical institution information systems (HIS, LIS, PACS). These alarm events may originate from various scenarios, such as physiological indicators exceeding limits (e.g., excessively fast heart rate, decreased blood oxygen), medical equipment malfunctions (e.g., infusion pump blockage, loss of monitor signal), and systemic risks (e.g., medication conflicts, delayed test reports). Due to the highly complex medical environment, there are multiple connections between different departments, different equipment, and different monitoring systems, and some patients are simultaneously managed by multiple sets of monitoring equipment. Therefore, a single clinical change or equipment malfunction often triggers multiple similar or related alarm messages. For example, a blood oxygen decrease alarm for a critically ill patient may simultaneously trigger an abnormal ventilator ventilation parameter alarm and a resuscitation reminder from the nursing station.

[0215] To address this multi-source alarm outbreak, the system first establishes a connection with a distributed medical alarm database via a secure authentication interface, extracting a set of raw alarm records from historical periods. These records include unique patient identifiers, department and ward information, equipment model and serial number, alarm type, occurrence and resolution times, alarm text descriptions, and a marker indicating whether the alarms were previously manually or automatically converged. After extraction, the system scans the records to identify all converged historical alarm event pairs, such as "blood oxygen drop alarm" and "ventilator ventilation pressure abnormality alarm." Subsequently, key spatiotemporal correlation features are extracted for each event pair, including the alarm occurrence time difference (with second-level precision), the physical distance of the medical equipment (e.g., bed, ward), and the medical process topology (e.g., whether they belong to the same treatment plan or the same vital sign monitoring link). These features are constructed into a three-dimensional feature matrix containing time, space, and process topology, and a confidence score is calculated for each event pair (based on the confidence assessment of clinical validation data and equipment logs). Low-confidence data below a preset quality threshold is filtered out, and the remaining high-quality event pairs are sorted by timestamp to form a historical converged dataset.

[0216] The system inputs the historical convergence dataset into a pre-trained language model jointly trained with medical semantics and device alarm data. The model performs semantic modeling on alarm titles, descriptive texts, and related medical indicator data, and numerically vectorizes time, space, and process features to form a unified set of semantic feature vectors. Based on these vectors, the system constructs a medical event topology graph, where nodes represent individual medical alarm events, and edges represent semantic correlation between events, device / patient topological adjacency, and historical co-occurrence probability. A graph neural network is used to perform pattern mining on this graph to identify high-frequency medical alarm combination patterns, such as "infusion pump obstruction + abnormal venous pressure" or "insufficient ventilator ventilation + decreased blood oxygen." Attribution parameters are extracted from these, including parameters related to the same pathological cause (e.g., respiratory failure), device type correlation parameters (e.g., the linkage between monitors and ventilators), and impact range correlation parameters (e.g., multiple patients in the same ward affected by the same type of alarm). The frequency of these parameters in historical data is then statistically analyzed to generate an attribution parameter table with probability values.

[0217] Based on historical event data, the system analyzes the concurrency and convergence of each pair of medical alarm events. A dynamic time window is defined for each pair of events (e.g., 30 seconds for cardiac arrest-related alarms, and 10 minutes for equipment maintenance alarms). The number of times the two events occur simultaneously within the window is counted as the concurrency count, and the number of times they appear in the same convergence process is counted as the convergence correlation count. The concurrency impact factor and convergence correlation factor are calculated and weighted and fused to generate the correlation degree between events.

[0218] When a new real-time medical alarm event arrives, the system dynamically updates the attribution parameter table by utilizing the correlation between current events. It constructs a correlation change matrix by calculating the change between the current and historical correlations, analyzes the correlation score between each attribution parameter and the change matrix, selects highly correlated parameters as key influencing parameters, calculates and updates the weight values ​​based on the magnitude of change, adjusts their probability values ​​in the attribution parameter table, reconstructs the correlation between parameters, and generates and stores the latest attribution parameter table with version tags.

[0219] The system then checks whether a new alarm has a matching record in the attribution parameter table. If it does, the system loads the relevant parameter set to initialize the convergence decision engine, calculates the correlation score between the alarm and all surviving medical alarm events, and if the highest score exceeds the threshold, it directly converges to the surviving event; if it does not exceed the threshold, it calculates the attribution parameter matching degree, selects the highest matching event for convergence, and otherwise allows the alarm to proceed.

[0220] If a new alarm is not in the attribution parameter table, the system initiates a model-assisted convergence process. It uses a pre-trained language model to extract features from both the new alarm and existing alarms, inputs these features into a multi-dimensional clustering feature space, and performs density clustering analysis to generate cluster groups and their confidence scores. When the confidence score is higher than a threshold, a convergence suggestion is generated and pushed to the on-duty doctor or nurse for confirmation. If confirmed, the alarm is converged, and the convergence correlation data and clustering analysis data are written to the attribution parameter table data pool. If rejected or the confidence score is insufficient, the alarm is marked as an independent event and directly alerted.

[0221] In healthcare settings, this processing mechanism can automatically identify and converge multiple alarms caused by the same reason when a patient's vital signs fluctuate or equipment malfunctions frequently. This significantly reduces the alarm burden on medical staff during busy periods, while maintaining the ability to discover and gradually converge new alarm combination patterns, ensuring that clinical safety and accuracy are not reduced while improving alarm processing efficiency.

[0222] In fintech business systems such as banking, securities, insurance, and internet finance, transaction monitoring and risk alert platforms need to receive real-time alerts from multiple sources, including transaction matching systems, payment clearing systems, risk control engines, anti-money laundering (AML) systems, and compliance monitoring platforms. These alerts may involve risks such as transaction fraud, abnormal account logins, abnormally concentrated transfers, suspicious transactions related to AML, and market price fluctuations. Due to the complexity of the financial business chain, the high frequency of transactions, and the intensive cross-system collaboration, different systems may issue multiple related alerts for the same risk event. For example, when a large cross-border transfer is detected, the AML system may trigger a "suspicious large transfer" alert, the transaction monitoring system may trigger a "transaction amount abnormal" alert, and the user behavior analysis system may trigger a "sudden change in account behavior pattern" alert, resulting in an alert explosion and repeated notifications.

[0223] To reduce redundant alarms and improve handling efficiency, the system first connects to a distributed financial alarm database via an encrypted and authenticated API interface to extract a set of raw financial alarm records from historical periods. These records include account identifiers, transaction serial numbers, transaction channels, alarm types, occurrence and resolution times, alarm descriptions, and whether they have been converged. The system scans the records to identify converged alarm event pairs, such as "suspicious large transfers" and "abnormal transaction amounts," which have historically occurred simultaneously and been processed together. For each event pair, the system extracts the time interval (accurate to the second), the geographical location difference between the originating account and the triggering system (e.g., cross-border or cross-regional transaction servers), and the business topology relationship (e.g., system dependencies in the transaction chain). This information is used to construct a three-dimensional feature data matrix containing time, space, and business topology dimensions. The system then calculates the confidence score for each event pair (combining historical handling verification results and monitoring logs), filters out low-confidence event pairs below a preset quality threshold, and sorts the data by time to form a high-quality historical converged dataset.

[0224] The system inputs this dataset into a pre-trained language model jointly trained on financial semantic data and transaction structured data. The model processes alarm text descriptions, transaction metadata, and contextual information to generate a unified set of semantic feature vectors. Based on these vectors, a topological graph of financial alarm events is constructed, where nodes represent individual financial alarm events and edges represent the connections between two alarms in terms of semantic features, transaction account / channel relationships, and historical co-occurrence probabilities. The graph structure is analyzed using a graph neural network to identify high-frequency alarm association patterns, such as "abnormal account login + large cross-regional transfer" or "violent market price fluctuations + abnormal high-frequency automated trading." Attribution parameters are extracted from these patterns, including parameters related to the same risk source (such as risks caused by the same transaction account or the same IP address), parameters related to business type (such as the association between foreign exchange transactions and cross-border payments), and parameters related to the scope of impact (such as involving the same fund clearing channel). Simultaneously, the frequency of each attribution parameter in historical data is statistically analyzed to form an attribution parameter table with probability values, which is used for subsequent real-time alarm analysis and convergence decision-making.

[0225] Based on historical event data, the system further analyzes the concurrency and convergence of event pairs. A dynamic time window is set for each event pair (a few seconds may be set for high-frequency trading risks, and a few minutes may be set for cross-border settlement risks). The number of times the events occur simultaneously within the time window is counted as the concurrency count, and the number of times they are converged in the same handling is counted as the convergence correlation count. The concurrency impact factor and convergence correlation factor are calculated, and the correlation degree between events is generated through weighted fusion.

[0226] When a new financial alert event arrives, the system dynamically updates the attribution parameter table using the correlation between events. By comparing the current correlation with historical correlations, a correlation change matrix is ​​generated, and the correlation score of each attribution parameter with the change matrix is ​​calculated. Key influencing parameters with correlation scores exceeding a threshold are selected, and their dynamic update weights are determined based on the magnitude of change. Their probability values ​​are adjusted, the relationships between parameters are reconstructed, and the updated table with version tags is stored.

[0227] The system determines whether a new alarm already exists in the attribution parameter table. If it does, the corresponding parameter set is loaded, the convergence decision engine is initialized, and the correlation score between the alarm and currently active financial alarm events is calculated. If the highest score exceeds a preset threshold, the new alarm is converged to the active event. If it does not exceed the threshold, the attribution parameter matching degree is calculated. If the event with the highest matching degree exceeds the threshold, convergence is performed; otherwise, the alarm is allowed and output as an independent alarm.

[0228] If a new alarm is not in the attribution parameter table, the system performs model-assisted convergence, using a pre-trained language model to extract feature vectors from the new alarm and existing alarms, constructing a multi-dimensional clustering feature space, and performing density clustering analysis to obtain cluster groups and their confidence scores. When the confidence score is higher than a preset threshold, a convergence suggestion is generated and pushed to risk management personnel or transaction monitoring personnel for confirmation; after confirmation, convergence is achieved, and convergence correlation data and clustering analysis data are written to the attribution parameter table data pool; if rejected or the confidence score is lower than the threshold, the alarm is directly pushed as an independent event.

[0229] In fintech businesses, this processing mechanism can address the issue of redundant risk alarms across systems and multiple dimensions, enabling alarm fusion between different systems and business chains, reducing the pressure of manual intervention caused by duplicate alarms, and possessing the ability to identify and gradually converge new risk patterns, ensuring an efficient balance between transaction security, compliance management, and real-time risk control.

[0230] This embodiment incorporates new events not covered by the attribution parameter table into a structured discrimination path through a combined process of vectorized representation, density clustering, and confidence quantification. When the cluster structure is stable and the score is above a threshold, reliable convergence associations are formed and stored in the data pool with a single user confirmation. When the structure is unstable or the score is insufficient, events are automatically allowed to proceed with a failure context for subsequent threshold and weight calibration. This mechanism reduces the risk of false convergence without relying on fixed rules, shortens the identification and absorption cycle of new alarms, continuously expands the convergent coverage, and maintains interpretable decisions, traceable processes, and low latency, thus maintaining processing efficiency and stability in scenarios with concentrated alarm outbreaks.

[0231] In one embodiment, an event attribution convergence device is provided, which corresponds one-to-one with the event attribution convergence method in the above embodiments. (Refer to...) Figure 3 , Figure 3 This is a schematic diagram of the functional modules of a preferred embodiment of the event attribution convergence device of the present invention. The modules include: historical data acquisition module 10, attribution parameter table generation module 20, event correlation calculation module 30, attribution parameter table update module 40, event existence judgment module 50, hierarchical convergence processing module 60, and model-assisted convergence module 70. Detailed descriptions of each functional module are as follows:

[0232] The historical data acquisition module 10 is used to acquire a historical converged dataset containing converged event data pairs;

[0233] The attribution parameter table generation module 20 is used to analyze the historical convergence dataset using a pre-trained language model, extract and generate an attribution parameter table containing multiple attribution parameters and probability values ​​corresponding to the attribution parameters.

[0234] The event correlation calculation module 30 is used to analyze the concurrency and correlation convergence of the event data in the event data pair and generate the correlation between events.

[0235] Attribution parameter table update module 40 is used to dynamically update the attribution parameter table according to the correlation between the events;

[0236] The event existence determination module 50 is used to determine whether the event data to be processed exists in the attribution parameter table when the event data to be processed is received.

[0237] The hierarchical convergence processing module 60 is used to perform a hierarchical convergence judgment operation if the event data to be processed exists in the attribution parameter table, and to perform a convergence or release operation according to the result of the hierarchical convergence judgment operation.

[0238] The model-assisted convergence module 70 is used to perform a model-assisted convergence operation if the event data to be processed does not exist in the attribution parameter table, and to perform a convergence or release operation based on the result of the model-assisted convergence operation.

[0239] In one embodiment, the historical data acquisition module 10 is specifically used for:

[0240] Connect to the distributed alarm database via API interface to obtain the original historical alarm record set;

[0241] Scan the original historical alarm record set to identify all event data pairs with convergence markers;

[0242] For each event data pair, extract spatiotemporal correlation features including the time difference of occurrence, physical location distance, and device topology relationship;

[0243] Based on the aforementioned spatiotemporal correlation features, a three-dimensional feature data matrix containing time, space, and topological dimensions is constructed.

[0244] Determine the data confidence score for each event data pair;

[0245] Based on a preset quality threshold, filter event data pairs whose data confidence scores are lower than the quality threshold;

[0246] The filtered and retained event data pairs are sorted by timestamp to form a historical convergence dataset.

[0247] In one embodiment, the attribution parameter table generation module 20 is specifically used for:

[0248] The historical convergence dataset is processed using a pre-trained language model to generate a set of semantic feature vectors;

[0249] Based on the set of semantic feature vectors, an event topology graph is created, where nodes represent event data and edges represent the relationships between events.

[0250] The event topology graph is analyzed using a graph neural network to identify high-frequency event association patterns.

[0251] Extract multidimensional attribution parameters from the high-frequency event association patterns, including parameters related to the same triggering cause, parameters related to the device type, and parameters related to the scope of influence.

[0252] Calculate the frequency of occurrence of each multidimensional attribution parameter in the historical convergence dataset and determine the corresponding probability value;

[0253] The multidimensional attribution parameters and their corresponding probability values ​​are integrated into an attribution parameter table.

[0254] In one embodiment, the event correlation calculation module 30 is specifically used for:

[0255] Define a dynamic time window for each event data pair and monitor the occurrence of the event data within the dynamic time window;

[0256] Within the dynamic time window, the number of concurrent occurrences of two event data points is counted.

[0257] Within the dynamic time window, count the number of convergence correlations where two event data are simultaneously converged;

[0258] Based on the number of concurrent occurrences and the total number of events, the concurrency impact factor value is determined;

[0259] The convergence correlation factor value is determined based on the convergence correlation count and the total convergence count of the event data;

[0260] The concurrent impact factor value and the convergence correlation factor value are weighted and fused to generate the correlation degree between events.

[0261] In one embodiment, the attribution parameter table update module 40 is specifically used for:

[0262] Construct a correlation change matrix based on the correlation between current events and the correlation between historical events;

[0263] For each attribution parameter in the attribution parameter table, determine a correlation score with the correlation change matrix;

[0264] Attribution parameters whose correlation scores exceed a preset correlation threshold are selected as key influencing parameters;

[0265] Based on the magnitude of change in the correlation degree change matrix, determine the dynamically updated weight value for each key influence parameter;

[0266] Based on the dynamically updated weight values, the probability values ​​corresponding to the key influencing parameters are adjusted to generate updated probability values.

[0267] Based on the updated probability values ​​and the correlation change matrix, the correlation relationships between parameters in the attribution parameter table are reconstructed.

[0268] The updated attribution parameter table is version-marked and stored.

[0269] In one embodiment, the hierarchical convergence processing module 60 is specifically used for:

[0270] If the event data to be processed exists in the attribution parameter table, then load the parameter set related to the event data to be processed from the attribution parameter table, and initialize the convergence decision engine based on the parameter set;

[0271] The convergent decision engine uses the parameter set to determine the correlation score between the event data to be processed and multiple live event data.

[0272] Select the live event data with the highest correlation score as the preferred live event data for correlation.

[0273] If the correlation score of the preferred live event data meets the preset correlation requirement, a hierarchical convergence judgment operation result indicating convergence to the preferred live event data is generated.

[0274] If the correlation score does not meet the preset correlation requirement, the convergence decision engine will use the parameter set to analyze the attribution parameter matching degree between the event data to be processed and multiple live event data.

[0275] Select the live event data with the highest attribution parameter matching degree as the preferred live event data for parameter matching;

[0276] If the attribution parameter matching degree of the preferred live event data meets the preset matching degree requirement, a hierarchical convergence judgment operation result indicating convergence to the preferred live event data is generated; otherwise, a hierarchical convergence judgment operation result indicating release is generated.

[0277] If the result of the hierarchical convergence judgment operation indicates convergence towards the target already alive event data, then the event data to be processed is associated with the target already alive event data;

[0278] If the result of the hierarchical convergence judgment operation indicates that the process should proceed, then the pending event data will be marked as an independent event and an alarm will be pushed.

[0279] The results of the hierarchical convergence judgment operation and the execution operation are recorded in the decision log.

[0280] In one embodiment, the model-aided convergence module 70 is specifically used for:

[0281] If the event data to be processed does not exist in the attribution parameter table, then the pre-trained language model is used to extract features from the event data to be processed and the live event data to generate an event feature vector.

[0282] Based on the event feature vectors, a multidimensional clustering feature space is constructed;

[0283] Density clustering analysis is performed in the multidimensional clustering feature space to generate clustering grouping results;

[0284] Determine the cluster confidence score for each cluster group;

[0285] When the cluster confidence score exceeds a preset confidence threshold, convergence suggestion information is generated, and a confirmation request is sent to the user based on the convergence suggestion information.

[0286] Receive user response commands;

[0287] If the user response instruction is a confirmation instruction, then the event data to be processed is associated with the target cluster group, a convergence operation result containing convergence association data and cluster analysis data is generated, and the convergence operation result is updated to the data pool of the attribution parameter table.

[0288] If the user response command is not a confirmation command, the pending event data will be marked as an independent event and an alarm message will be pushed.

[0289] When the cluster confidence score does not exceed the preset confidence threshold, a release operation instruction is generated, and the pending event data is marked as an independent event and an alarm message is pushed.

[0290] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 4 As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides determination and control capabilities. The memory includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used for communication with external user terminals via a network connection. When the computer program is executed by the processor, it implements the functions or steps of an event attribution convergence method on the server side.

[0291] In one embodiment, a computer device is provided, which may be a user terminal, and its internal structure diagram may be as follows: Figure 5 As shown, the computer device includes a processor, memory, network interface, display screen, and input devices connected via a system bus. The processor provides determination and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with an external server via a network connection. When executed by the processor, the computer program implements the user-side functions or steps of an event attribution convergence method.

[0292] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to perform the following steps:

[0293] Retrieve the historical converged dataset containing converged event data pairs;

[0294] The historical convergence dataset is analyzed using a pre-trained language model to extract and generate an attribution parameter table containing multiple attribution parameters and the probability values ​​corresponding to the attribution parameters.

[0295] Analyze the concurrency and convergence of event data in the event data pairs to generate the correlation degree between events;

[0296] The attribution parameter table is dynamically updated based on the correlation between the events.

[0297] When event data to be processed is received, it is determined whether the event data to be processed exists in the attribution parameter table;

[0298] If the event data to be processed exists in the attribution parameter table, then a hierarchical convergence judgment operation is performed, and a convergence or release operation is performed based on the result of the hierarchical convergence judgment operation.

[0299] If the event data to be processed does not exist in the attribution parameter table, then a model-assisted convergence operation is performed, and a convergence or release operation is performed based on the result of the model-assisted convergence operation.

[0300] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:

[0301] Retrieve the historical converged dataset containing converged event data pairs;

[0302] The historical convergence dataset is analyzed using a pre-trained language model to extract and generate an attribution parameter table containing multiple attribution parameters and the probability values ​​corresponding to the attribution parameters.

[0303] Analyze the concurrency and convergence of event data in the event data pairs to generate the correlation degree between events;

[0304] The attribution parameter table is dynamically updated based on the correlation between the events.

[0305] When event data to be processed is received, it is determined whether the event data to be processed exists in the attribution parameter table;

[0306] If the event data to be processed exists in the attribution parameter table, then a hierarchical convergence judgment operation is performed, and a convergence or release operation is performed based on the result of the hierarchical convergence judgment operation.

[0307] If the event data to be processed does not exist in the attribution parameter table, then a model-assisted convergence operation is performed, and a convergence or release operation is performed based on the result of the model-assisted convergence operation.

[0308] It should be noted that the functions or steps that can be implemented by the computer-readable storage medium or computer device described above can be referred to the relevant descriptions on the server side and user side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.

[0309] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0310] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0311] It should be noted that if any software tools or components not belonging to this company appear in the embodiments of this application, they are merely illustrative examples and do not represent actual use. The embodiments described above are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. An event attribution convergence method, characterized in that, Includes the following steps: Retrieve the historical converged dataset containing converged event data pairs; The historical convergence dataset is analyzed using a pre-trained language model to extract and generate an attribution parameter table containing multiple attribution parameters and the probability values ​​corresponding to the attribution parameters. Analyze the concurrency and convergence of event data in the event data pairs to generate the correlation degree between events; The attribution parameter table is dynamically updated based on the correlation between the events. When event data to be processed is received, it is determined whether the event data to be processed exists in the attribution parameter table; If the event data to be processed exists in the attribution parameter table, then a hierarchical convergence judgment operation is performed, and a convergence or release operation is performed based on the result of the hierarchical convergence judgment operation. If the event data to be processed does not exist in the attribution parameter table, then a model-assisted convergence operation is performed, and a convergence or release operation is performed based on the result of the model-assisted convergence operation.

2. The event attribution convergence method as described in claim 1, characterized in that, Retrieve the historical converged dataset containing converged event data pairs, including: Connect to the distributed alarm database via API interface to obtain the original historical alarm record set; Scan the original historical alarm record set to identify all event data pairs with convergence markers; For each event data pair, extract spatiotemporal correlation features including the time difference of occurrence, physical location distance, and device topology relationship; Based on the aforementioned spatiotemporal correlation features, a three-dimensional feature data matrix containing time, space, and topological dimensions is constructed. Determine the data confidence score for each event data pair; Based on a preset quality threshold, filter event data pairs whose data confidence scores are lower than the quality threshold; The filtered and retained event data pairs are sorted by timestamp to form a historical convergence dataset.

3. The event attribution convergence method as described in claim 1, characterized in that, The historical convergence dataset is analyzed using a pre-trained language model to extract and generate an attribution parameter table containing multiple attribution parameters and their corresponding probability values, including: The historical convergence dataset is processed using a pre-trained language model to generate a set of semantic feature vectors; Based on the set of semantic feature vectors, an event topology graph is created, where nodes represent event data and edges represent the relationships between events. The event topology graph is analyzed using a graph neural network to identify high-frequency event association patterns. Extract multidimensional attribution parameters from the high-frequency event association patterns, including parameters related to the same triggering cause, parameters related to the device type, and parameters related to the scope of influence. Calculate the frequency of occurrence of each multidimensional attribution parameter in the historical convergence dataset and determine the corresponding probability value; The multidimensional attribution parameters and their corresponding probability values ​​are integrated into an attribution parameter table.

4. The event attribution convergence method as described in claim 1, characterized in that, Analyze the concurrency and convergence of event data in the event data pairs to generate the correlation degree between events, including: Define a dynamic time window for each event data pair and monitor the occurrence of the event data within the dynamic time window; Within the dynamic time window, the number of concurrent occurrences of two event data points is counted. Within the dynamic time window, count the number of convergence correlations where two event data are simultaneously converged; Based on the number of concurrent occurrences and the total number of events, the concurrency impact factor value is determined; The convergence correlation factor value is determined based on the convergence correlation count and the total convergence count of the event data; The concurrent impact factor value and the convergence correlation factor value are weighted and fused to generate the correlation degree between events.

5. The event attribution convergence method as described in claim 1, characterized in that, The attribution parameter table is dynamically updated based on the correlation between the events, including: Construct a correlation change matrix based on the correlation between current events and the correlation between historical events; For each attribution parameter in the attribution parameter table, determine a correlation score with the correlation change matrix; Attribution parameters whose correlation scores exceed a preset correlation threshold are selected as key influencing parameters; Based on the magnitude of change in the correlation degree change matrix, determine the dynamically updated weight value for each key influence parameter; Based on the dynamically updated weight values, the probability values ​​corresponding to the key influencing parameters are adjusted to generate updated probability values. Based on the updated probability values ​​and the correlation change matrix, the correlation relationships between parameters in the attribution parameter table are reconstructed. The updated attribution parameter table is version-marked and stored.

6. The event attribution convergence method as described in claim 1, characterized in that, If the event data to be processed exists in the attribution parameter table, then a hierarchical convergence judgment operation is performed, and a convergence or release operation is performed based on the result of the hierarchical convergence judgment operation, including: If the event data to be processed exists in the attribution parameter table, then load the parameter set related to the event data to be processed from the attribution parameter table, and initialize the convergence decision engine based on the parameter set; The convergent decision engine uses the parameter set to determine the correlation score between the event data to be processed and multiple live event data. Select the live event data with the highest correlation score as the preferred live event data for correlation. If the correlation score of the preferred live event data meets the preset correlation requirement, a hierarchical convergence judgment operation result indicating convergence to the preferred live event data is generated. If the correlation score does not meet the preset correlation requirement, the convergence decision engine will use the parameter set to analyze the attribution parameter matching degree between the event data to be processed and multiple live event data. Select the live event data with the highest attribution parameter matching degree as the preferred live event data for parameter matching; If the attribution parameter matching degree of the preferred live event data meets the preset matching degree requirement, a hierarchical convergence judgment operation result indicating convergence to the preferred live event data is generated; otherwise, a hierarchical convergence judgment operation result indicating release is generated. If the result of the hierarchical convergence judgment operation indicates convergence towards the target already alive event data, then the event data to be processed is associated with the target already alive event data; If the result of the hierarchical convergence judgment operation indicates that the process should proceed, then the pending event data will be marked as an independent event and an alarm will be pushed. The results of the hierarchical convergence judgment operation and the execution operation are recorded in the decision log.

7. The event attribution convergence method as described in claim 1, characterized in that, If the event data to be processed does not exist in the attribution parameter table, then a model-assisted convergence operation is performed, and a convergence or release operation is performed based on the result of the model-assisted convergence operation, including: If the event data to be processed does not exist in the attribution parameter table, then the pre-trained language model is used to extract features from the event data to be processed and the live event data to generate an event feature vector. Based on the event feature vectors, a multidimensional clustering feature space is constructed; Density clustering analysis is performed in the multidimensional clustering feature space to generate clustering grouping results; Determine the cluster confidence score for each cluster group; When the cluster confidence score exceeds a preset confidence threshold, convergence suggestion information is generated, and a confirmation request is sent to the user based on the convergence suggestion information. Receive user response commands; If the user response instruction is a confirmation instruction, then the event data to be processed is associated with the target cluster group, a convergence operation result containing convergence association data and cluster analysis data is generated, and the convergence operation result is updated to the data pool of the attribution parameter table. If the user response command is not a confirmation command, the pending event data will be marked as an independent event and an alarm message will be pushed. When the cluster confidence score does not exceed the preset confidence threshold, a release operation instruction is generated, and the pending event data is marked as an independent event and an alarm message is pushed.

8. An event attribution convergence device, characterized in that, The event attribution convergence device includes: The historical data acquisition module is used to acquire historical converged datasets containing converged event data pairs; The attribution parameter table generation module is used to analyze the historical convergence dataset using a pre-trained language model, extract and generate an attribution parameter table containing multiple attribution parameters and probability values ​​corresponding to the attribution parameters. The event correlation calculation module is used to analyze the concurrency and correlation convergence of the event data in the event data pair, and generate the correlation between events. The attribution parameter table update module is used to dynamically update the attribution parameter table based on the correlation between the events. The event existence determination module is used to determine whether the event data to be processed exists in the attribution parameter table when the event data to be processed is received. The hierarchical convergence processing module is used to perform a hierarchical convergence judgment operation if the event data to be processed exists in the attribution parameter table, and to perform a convergence or release operation based on the result of the hierarchical convergence judgment operation. The model-assisted convergence module is used to perform a model-assisted convergence operation if the event data to be processed does not exist in the attribution parameter table, and to perform a convergence or release operation based on the result of the model-assisted convergence operation.

9. A computer device, characterized in that, The computer device includes a memory, a processor, and an event attribution convergence program stored in the memory and executable on the processor, wherein the event attribution convergence program, when executed by the processor, implements the steps of the event attribution convergence method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The storage medium stores an event attribution convergence program, which, when executed by a processor, implements the steps of the event attribution convergence method as described in any one of claims 1-7.

Citation Information

Cited By

  • Catalyst industry chain-oriented full-life-cycle tracing method and catalyst industry chain-oriented full-life-cycle tracing system

    CN121365918A

  • Operation and maintenance data tracing method of weak current intelligent management system

    CN121502620A

  • Dynamic quantile filtering method for commodity co-occurrence network

    CN122089367A