A spatiotemporal perception framework for multivariate time series anomaly detection

CN122333045BActive Publication Date: 2026-09-29SOUTHWEST PETROLEUM UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610715501.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-05-22
Publication Date
2026-09-29
Estimated Expiration
2046-05-22

AI Technical Summary

Technical Problem

尽管取得了一些进展,但这些方法在重建时通常采用简单化的方式,平等对待所有变量,忽略了变量间的空间关系和时间特性,导致两个关键局限:一是弱相关变量引入噪声,降低重建质量并导致过拟合;二是重建误差的计算未考虑空间信息量或时间稳定性,导致噪声误差信号掩盖真实异常

Benefits of technology

1.本发明通过变量社区分析驱动的分组重建(VCAGR),显式地利用了变量间的空间相关性,将强相关变量分组并进行独立重建,有效减少了弱相关变量引入的噪声和干扰,提升了重建质量和模型泛化能力。通过时空平稳性模块驱动的误差增强(SSMEE),引入了空间重要性权重和时间稳定性度量,对重建误差进行增强和平滑处理,突出了真实异常信号,抑制了噪声波动,提升了异常检测的鲁棒性和准确性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122333045B_ABST
    Figure CN122333045B_ABST
Patent Text Reader

Abstract

The application discloses a kind of space-time perception framework for multivariate time series anomaly detection, belong to abnormal detection technical field, comprising: variable community analysis driven grouping remodeling module, for variable spatial relationship modeling and variable grouping to multivariate time series, and each variable group is respectively reconstructed;Error enhancement module driven by space-time stationarity module, for spatial importance weighting and time stationarity smoothing to reconstruction error, and generate enhanced anomaly score.The application explicitly utilizes the spatial correlation between variables by variable community analysis driven grouping reconstruction, groups strongly correlated variables and independently reconstructs, effectively reduces the noise and interference introduced by weakly correlated variables, and improves the reconstruction quality and model generalization ability.Two modules that capture space-time relationship features work together, significantly improve the accuracy and robustness of anomaly detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of anomaly detection technology, and in particular to a spatiotemporal perception framework for anomaly detection in multivariate time series. Background Technology

[0002] With the widespread adoption of Internet of Things (IoT) technology and the exponential growth in data collection across industrial systems, healthcare, and financial monitoring, multivariate time series anomaly detection has become a key research area. Time series anomaly detection aims to identify anomalous behaviors such as financial fraud, medical abnormalities, or equipment malfunctions. Multivariate time series data, containing multiple variables collected over time, are widely used in predictive maintenance of industrial equipment, detection of financial transaction fraud, and patient monitoring in healthcare. Anomalies are defined as deviations from expected patterns, often indicating critical events such as equipment failure, cyberattacks, or health crises, thus requiring timely and accurate detection to mitigate risks and losses.

[0003] Existing anomaly detection methods include statistical methods, classical machine learning methods, and deep learning methods. Statistical methods (such as moving averages, exponential smoothing, and ARIMA models) perform well on simple, low-dimensional time series, but poorly on high-dimensional or non-linear data. Classical machine learning methods (such as k-means clustering, density-based methods, and classification techniques like decision trees and support vector machines) struggle to capture complex patterns in high-dimensional settings due to the curse of dimensionality. The high dimensionality, complex inter-variable correlations, and temporal dynamics of modern datasets pose significant challenges to these traditional methods, making them difficult to scale and maintain robustness in real-world scenarios.

[0004] Reconstruction-based anomaly detection methods have gained attention for their ability to model complex data without the need for labeling anomalies (due to scarce or costly samples). These methods train models on normal data to reconstruct expected patterns and label deviations with large reconstruction errors as anomalies. Early methods relied on simple autoencoders, followed by more advanced models such as LSTM-based variational autoencoders (LSTM-VAE), generative adversarial networks (GANs) like FGANomaly, and Transformer-based models like VTT. Despite some progress, these methods often employ a simplistic approach during reconstruction, treating all variables equally and ignoring spatial relationships and temporal characteristics. This leads to two key limitations: first, weakly correlated variables introduce noise, reducing reconstruction quality and causing overfitting; second, the calculation of reconstruction errors does not consider spatial information or temporal stability, causing noisy error signals to mask true anomalies.

[0005] In summary, the shortcomings and deficiencies of existing technologies are mainly reflected in the following aspects: ignoring the spatial correlation between variables leads to interference from weakly correlated variables in the reconstruction process; lack of spatiotemporal smoothing processing of error signals makes the detection results unstable and susceptible to noise; poor interpretability of the model makes it difficult to trace the source of anomalies; and insufficient generalization ability and robustness in high-dimensional complex data scenarios. Summary of the Invention

[0006] The purpose of this invention is to overcome the problems existing in the prior art and provide a spatiotemporal awareness framework for anomaly detection in multivariate time series. The core innovation of this framework lies in explicitly modeling and utilizing the inherent spatial correlation and temporal dependence characteristics in multivariate time series. By having two modules that capture spatiotemporal relationship features work together, the accuracy and robustness of anomaly detection are significantly improved.

[0007] The objective of this invention is achieved through the following technical solution: A spatiotemporal awareness framework for multivariate time series anomaly detection is provided, including: The variable community analysis-driven grouping and reconstruction module is used to model the spatial relationships of variables and group variables in multivariate time series, and to reconstruct each variable group separately; the variable spatial relationship modeling specifically includes: The interdependencies between variables are modeled as a weighted undirected graph. The mutual information between all pairs of variables is calculated, and the correlation matrix of the variables is constructed. ,in, and Represent two variables, Representing variables and The joint probability density function, Representing variables The marginal probability density function, Representing variables The marginal probability density function; The variable grouping specifically includes: The community detection algorithm is used to partition the weighted undirected graph, dividing all variables into multiple groups of variables with tight internal connections but sparse inter-group connections. The community detection algorithm is the Louvain community detection algorithm. When partitioning the weighted undirected graph, the maximum modularity is calculated: in, This indicates maximizing modularity. It is a set of variable groups. It is a group of variables The sum of the internal edge weights, It is with the variable group The sum of the weights of all connected edges. It is the total weight of all edges in a weighted undirected graph; An error enhancement module driven by a spatiotemporal stationarity module is used to perform spatial importance weighting and temporal stationarity smoothing on the reconstruction error, and generate an enhanced anomaly score; the spatial importance weighting specifically includes: Calculate the within-group reconstruction error and assess the importance of each variable group; when assessing the importance of each variable group, consider the group size, the stability of the variables within the group, the average reconstruction error of the group, and the correlation of the variables within the group. in, Indicate the importance of the variable group, Indicates the number of variables within a group. This represents the average variance of the variable within the group. This represents the average reconstruction error of the group, used to evaluate the reconstruction quality. The lower the error, the more accurately the model models the normal patterns. This indicates the correlation between variables within a group, and d represents the total number of variables.

[0008] In some embodiments, the reconstruction of each variable group includes: An independent reconstruction model is instantiated for each group of variables. The reconstruction model includes a generator and a discriminator. The generator is used to reconstruct the group of variables. The reconstruction results of all variable groups are concatenated according to the variable dimensions to obtain the final full-variable reconstruction output.

[0009] In some embodiments, the time-stationarity smoothing specifically includes: A time sliding window is introduced to analyze the stability of the error sequence for each variable group. For each time point and variable group, the stationarity and significance of the reconstruction error are calculated within the window.

[0010] In some embodiments, the stationarity is calculated by the following formula: ,in, It is the average error within the window. A higher value indicates a more stable error sequence, which is more conducive to identifying true anomalies. Indicates the size of the time smoothing window. This indicates that the k-th variable group is in the k-th position. The stationarity value at each time point Indicates the first The time points within the right half of the time smoothing window at each time point. Indicates the first The time points within the left half of the time smoothing window at each time point. This represents the original reconstruction error of the k-th variable group at the j-th time point. Indicates the k-th variable group in the th order. The original reconstruction error at each time point.

[0011] In some embodiments, the significance value is the maximum error within the window, calculated by the following formula: .

[0012] In some embodiments, the generation of the anomaly score includes: The original reconstruction error of each variable group at each time point is multiplied by its corresponding spatial importance weight and time stationarity measure, and the sum is obtained to obtain the comprehensive anomaly score.

[0013] In some embodiments, the error enhancement module driven by the spatiotemporal stability module is further used to set an anomaly threshold and determine the anomaly situation at each time point based on the anomaly score and the magnitude of the anomaly threshold.

[0014] It should be further noted that the technical features corresponding to the above-mentioned options and embodiments can be combined or substituted with each other to form new technical solutions without conflict.

[0015] Compared with the prior art, the beneficial effects of the present invention are: 1. This invention utilizes Variable Community Analysis-Driven Group Reconstruction (VCAGR) to explicitly leverage the spatial correlation between variables, grouping strongly correlated variables and reconstructing them independently. This effectively reduces noise and interference introduced by weakly correlated variables, improving reconstruction quality and model generalization ability. Furthermore, the invention employs Spatiotemporal Stationarity Module-Driven Error Enhancement (SSMEE), introducing spatial importance weights and temporal stability measures to enhance and smooth reconstruction errors. This highlights genuine anomalous signals, suppresses noise fluctuations, and improves the robustness and accuracy of anomaly detection.

[0016] 2. The framework of this invention has good interpretability. The variable grouping results reflect the inherent semantics and statistical relationships in the data, which helps to trace the source of anomalies and understand system behavior, and provides convenience for fault diagnosis and decision support in practical applications.

[0017] 3. The framework of this invention can be trained without labeling anomalous data, making it suitable for real-world scenarios where anomalous samples are scarce or expensive to obtain, and thus possessing high practicality and adaptability.

[0018] In summary, this invention not only improves the performance of multivariate time series anomaly detection, but also enhances the interpretability and practicality of the model, providing effective technical support for anomaly detection tasks in fields such as industrial monitoring, healthcare, and financial security. Attached Figure Description

[0019] Figure 1 This is a flowchart of a multivariate time series anomaly detection method according to the present invention; Figure 2 This is a schematic diagram of variable spatial relationship modeling and community discovery (VCAGR-1) of the present invention; Figure 3 This is a schematic diagram of the group model training and reconstruction (VCAGR-2) of the present invention; Figure 4 This is a schematic diagram of the Spatiotemporal Error Enhancement (SSMEE) of the present invention. Detailed Implementation

[0020] The technical solution of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0021] It should be noted that the defects in the solutions in the prior art are all the results of the inventors' practice and careful research. Therefore, the discovery process of the above problems and the solutions proposed by the embodiments of this application in the following text should be the inventors' contributions to this application in the process of invention and creation, and should not be understood as technical content known to those skilled in the art.

[0022] In view of the technical problems pointed out in the background art, the present invention provides the following embodiments: In one exemplary embodiment, a spatiotemporal awareness framework (STPF) for multivariate time series anomaly detection is provided, comprising: The variable community analysis-driven grouping and reconstruction module is used to model the spatial relationships of variables and group variables in multivariate time series, and to reconstruct each variable group separately. The error enhancement module, driven by the spatiotemporal stationarity module, is used to perform spatial importance weighting and temporal stationarity smoothing on the reconstruction error and generate an enhanced anomaly score.

[0023] The specific implementation principles of the two modules are as follows: 1. Variable Community Analysis-Driven Group Reconstruction (VCAGR) Module This module aims to address the problem of traditional methods that treat all variables as a whole during reconstruction, thus ignoring the inherent spatial relationships between variables. Its core idea is "group first, then reconstruct," and the specific steps are as follows: Spatial Relationship Modeling and Variable Grouping: First, this invention does not treat all sensors or variables equally, but instead models their interdependencies as a network (such as a weighted undirected graph). This network uses each variable as a node, with edge weights between nodes measured by mutual information, thus capturing both linear and non-linear dependencies between variables. Subsequently, a community detection algorithm (Louvain's algorithm) is used to partition this network, automatically dividing all variables into several communities or variable groups with tight internal connections but relatively sparse inter-group connections. Variables within each group are strongly correlated; for example, in server monitoring data, CPU utilization and network traffic may be grouped into one group, while disk I / O metrics may be grouped into another.

[0024] Independent Reconstruction by Groups: After variable grouping, the traditional single reconstruction model is replaced by multiple reconstruction sub-models dedicated to each variable group. Each sub-model is only responsible for learning and reconstructing the data patterns within one variable group. This approach effectively isolates the interference of weakly correlated variables on the reconstruction process, enabling each sub-model to more accurately capture the normal patterns within its corresponding group, greatly improving reconstruction quality and laying a solid foundation for subsequent accurate anomaly detection.

[0025] 2. Spacetime Stationarity Module-Driven Error Augmentation (SSMEE) Module This module aims to address the problems of noisy and unstable raw reconstruction error signals, and the varying contributions of different variable groups to anomaly detection. It enhances and reduces noise in the raw error signal from both spatial and temporal dimensions. Spatial Dimension Enhancement (Importance Weighting): Not all variable groups are equally important in anomaly detection. This module designs an evaluation system that calculates an importance weight for each variable group. The weighting takes into account the following factors: (a) group size (number of variables); (b) stability of variables within the group (variance); (c) the average reconstruction error of the group (reflecting the model's learning degree of the group's normal patterns); and (d) the cohesiveness of variables within the group. Groups with high importance (e.g., large size, stability, good reconstruction results, and strong internal consistency) will receive higher weights in the final anomaly score, thus highlighting signals with greater information content in the spatial dimension.

[0026] Enhanced Time Dimension (Stability Smoothing): Real anomalies are often persistent, while error fluctuations caused by noise are instantaneous. To distinguish between the two, this module introduces a time-sliding window to analyze the stability of the error sequence for each variable group. Within the window, the fluctuation of the error (e.g., variance) is calculated; the smaller the fluctuation, the more reliable and stable the error signal is considered at that time point. Simultaneously, the maximum error value within the window is considered to capture significant anomaly peaks. This time-series smoothing process suppresses instantaneous noise and highlights persistent and significant anomaly patterns.

[0027] Error Fusion and Anomaly Scoring: Finally, the original error of each variable group at each time point is multiplied by its corresponding spatial importance weight and temporal stationarity metric, and the results are summed to obtain a new, enhanced comprehensive anomaly score. This score contains both spatial and temporal insights, making it more robust and reliable than traditional single-error methods, thus achieving more accurate anomaly detection.

[0028] The framework uses the VCAGR module to extract spatial features and isolate noise, and the SSMEE module to reduce noise and enhance error signals. The two work together to effectively solve the shortcomings of the existing technology.

[0029] In another exemplary embodiment, based on the aforementioned spatiotemporal awareness framework (STPF), such as Figure 1 As shown, a method for anomaly detection in multivariate time series data is provided, with the following specific steps: 1. Data preprocessing and sliding window partitioning Multivariate time series are observation series Each observation This represents d variables (such as sensor measurements) recorded at time t, input to the original multivariate time series training set. and test set ,in As a variable dimension, in the test set Each observation in Assign binary labels , where 0 indicates normal and 1 indicates abnormal.

[0030] To capture temporal dependencies, the time series is converted into a sliding window sequence, and the sliding window size is set. With sliding step size The sliding window W samples ws consecutive observations from T, starting from the starting point and incrementing by a step size. Slide the window and successively cut off lengths of... A continuous subsequence. If the end window length is insufficient. These are then discarded to ensure the integrity of the sliding window set. Finally, the training window set is obtained. (N is the number of windows) and the set of test windows , The division and Similar, but with a step size of Each of these windows .

[0031] 2. Variable Spatial Relationship Modeling and Community Detection (VCAGR-1) like Figure 2 As shown, the process of community detection based on the mutual information matrix is ​​intuitively illustrated. The nodes in the diagram represent variables; variables with strong correlations are grouped together for separate training and testing, based on the training set. Calculate the mutual information (MI) between all pairs of variables and construct the variable correlation matrix. : ,in, and Represent two variables, Representing variables and The joint probability density function, Representing variables The marginal probability density function, Representing variables The marginal probability density function; View it as a weighted undirected graph The adjacency matrix, where the vertex set is... correspond One variable, edge weight The Louvain community detection algorithm is used to calculate the maximum modularity. Automatically divide variables into Individual communities (variable groups) : in, It is a community collection. It is a community The sum of the internal edge weights, It is with the community The sum of the weights of all connected edges. It is the total weight of all edges in the graph.

[0032] 3. Grouped Model Training and Reconstruction (VCAGR-2) For each group k, the normal pattern is learned using the GAN-based model FGANomaly with a filtering mechanism, based on the community partitioning results. The complete window data is divided into variable groups. For the first... Group (Include (1 variable), and its training and testing data are: in, and These represent the number of sliding windows in the training and test sets, respectively. For each variable group... Instantiate a standalone refactoring model (containing a generator) and discriminator ).use Train the model. For example... Figure 3 As shown, the process of training and reconstructing the grouped model is illustrated, with each group of variables trained and reconstructed using a separate model.

[0033] After training, the generator is used to reconstruct the test data: Finally, the reconstruction results of all groups are concatenated according to the variable dimensions to obtain the final full-variable reconstruction output. .

[0034] 4. Spatiotemporal Error Enhancement (SSMEE) (1) Calculate the within-group reconstruction error: for each variable group Calculate its reconstruction error over the entire test time series, where the first... The error at each time point is: in, It is a vector whose dimension is equal to the number of variables in the k-th variable group. Indicates the first The reconstructed value vector of the k-th variable group at time point k. |⋅|2 represents the norm calculation.

[0035] (2) Calculate the spatial importance weights ( The weighting comprehensively assesses the importance of each variable group. It includes: (a) group size (number of variables); (b) stability of variables within the group (variance); (c) mean reconstruction error of the group (reflecting the model's learning of the normal pattern of the group); and (d) cohesiveness of variables within the group.

[0036] in, This indicates the number of variables within the group, reflecting the group's ability to capture comprehensive patterns. It represents the average variance of variables within a group. The lower the variance, the more stable the variable's behavior, thus improving the reliability of anomaly detection. This represents the average reconstruction error of the group, used to evaluate the reconstruction quality. The lower the error, the more accurately the model models the normal patterns. It indicates the correlation between variables within a group and measures the consistency of variables within a group. The higher the correlation, the stronger the group's ability to capture meaningful patterns. The importance weights of the above indicator combinations are indicated by assigning higher weights to groups that are larger, more stable, have better reconstruction results, and stronger cohesion, while reducing the weights of groups with high variance or poor reconstruction quality.

[0037] (3) Calculate the time stationarity measure: Set the size of the time smoothing window For each time point and variable group Calculate its time stationarity and significance value : in, It is the average error within the window. A higher value indicates a more stable error sequence, which is more conducive to identifying true anomalies. Furthermore, adjusting the value captures the maximum error within the window. Highlight persistent anomalies (such as persistent attacks that cause long-term system outages).

[0038] (4) Fusion to obtain enhanced error (anomaly score): Spatial importance and temporal stationarity are incorporated into the error to obtain the final enhanced anomaly score sequence: This approach combines spatial information of variable groups with the stability and significance of error signals. This integration ensures that groups with clear anomalous signals (such as those observed in the SMD dataset) are highlighted, while reducing the weight of noisy groups, achieving more accurate and stable anomaly detection compared to traditional methods that ignore these spatiotemporal features. Figure 4 The diagram illustrates the core operations of the spatiotemporal error enhancement module, namely, calculating the reconstruction error of each variable group and the fusion process using spatiotemporal features. Finally, it shows the enhanced reconstruction error after modulation by spatial weights and time stationarity, demonstrating its effective suppression of instantaneous noise and highlighting of anomalies.

[0039] 5. Anomaly Detection Select an anomaly threshold (Adjustments may be made based on specific data). For each time point in the test set. ,like If so, then the point is determined to be abnormal. ), otherwise it is normal ( ).

[0040] The above detailed embodiments are a description of the present invention. It should not be considered that the specific embodiments of the present invention are limited to these descriptions. For those skilled in the art, several simple deductions and substitutions can be made without departing from the concept of the present invention, and all of these should be considered to fall within the protection scope of the present invention.

Claims

1. A spatiotemporal awareness framework for multivariate time series anomaly detection, used for server monitoring, characterized in that, include: The variable community analysis-driven grouping and reconstruction module is used to model the spatial relationships of variables and group variables in multivariate time series data in server monitoring data, and reconstruct each variable group separately. The variables include CPU utilization, network traffic, and disk I / O metrics; The modeling of the spatial relationships of variables specifically includes: The interdependencies between variables are modeled as a weighted undirected graph. The mutual information between all pairs of variables is calculated, and the correlation matrix of the variables is constructed. ,in, and Represent two variables, Representing variables and The joint probability density function, Representing variables The marginal probability density function, Representing variables The marginal probability density function; The variable grouping specifically includes: The weighted undirected graph is partitioned using a community detection algorithm, dividing all variables in the server monitoring data into multiple variable groups with tight internal connections but sparse inter-group connections; CPU utilization and network traffic are assigned to one variable group, and disk I / O metrics are assigned to another variable group. The community detection algorithm is the Louvain community detection algorithm. When partitioning the weighted undirected graph, the maximum modularity is calculated: ,in, This indicates maximizing modularity. It is a set of variable groups. It is a group of variables The sum of the internal edge weights, It is with the variable group The sum of the weights of all connected edges. It is the total weight of all edges in a weighted undirected graph; The error enhancement module, driven by the spatiotemporal stationarity module, is used to perform spatial importance weighting and temporal stationarity smoothing on the reconstruction error and generate an enhanced anomaly score. The spatial importance weighting specifically includes: Calculate the within-group reconstruction error and assess the importance of each variable group; when assessing the importance of each variable group, consider the group size, the stability of the variables within the group, the average reconstruction error of the group, and the correlation of the variables within the group. ,in, Indicate the importance of the variable group. Indicates the number of variables within a group. This represents the average variance of the variable within the group. This represents the average reconstruction error of the group, used to evaluate the reconstruction quality. The lower the error, the more accurately the model models the normal patterns. This indicates the correlation between variables within a group, where d represents the total number of variables. The error enhancement module driven by the spatiotemporal stability module is also used to set an anomaly threshold and determine the anomaly situation at each time point based on the anomaly score and the magnitude of the anomaly threshold.

2. The spatiotemporal awareness framework for multivariate time series anomaly detection according to claim 1, characterized in that, The reconstruction of each variable group separately includes: An independent reconstruction model is instantiated for each group of variables. The reconstruction model includes a generator and a discriminator. The generator is used to reconstruct the group of variables. The reconstruction results of all variable groups are concatenated according to the variable dimensions to obtain the final full-variable reconstruction output.

3. The spatiotemporal awareness framework for multivariate time series anomaly detection according to claim 1, characterized in that, The time-stationarity smoothing specifically includes: A time sliding window is introduced to analyze the stability of the error sequence for each variable group. For each time point and variable group, the stationarity and significance of the reconstruction error are calculated within the window.

4. The spatiotemporal awareness framework for multivariate time series anomaly detection according to claim 3, characterized in that, The stationarity is calculated by the following formula: ,in, It is the average error within the window. A higher value indicates a more stable error sequence, which is more conducive to identifying true anomalies. Indicates the size of the time smoothing window. This indicates that the k-th variable group is in the k-th position. The stationarity value at each time point Indicates the first The time points within the right half of the time smoothing window at each time point. Indicates the first The time points within the left half of the time smoothing window at each time point. This represents the original reconstruction error of the k-th variable group at the j-th time point. Indicates the k-th variable group in the th order. The original reconstruction error at each time point.

5. A spatiotemporal awareness framework for multivariate time series anomaly detection according to claim 4, characterized in that, The significance value is the maximum error within the window, calculated by the following formula: 。 6. A spatiotemporal awareness framework for multivariate time series anomaly detection according to claim 5, characterized in that, The generation of the anomaly score includes: The original reconstruction error of each variable group at each time point is multiplied by its corresponding spatial importance weight and time stationarity measure, and the sum is obtained to obtain the comprehensive anomaly score.

Citation Information

Patent Citations

  • Noise robust multivariable time sequence anomaly detection method for intelligent manufacturing field

    CN121881197A

  • Analyzing social media data to identify markers of coordinated movements, using stance detection, and using clustering techniques

    WO2023034358A2