Abnormal monitoring method, device, electronic device and storage medium for time series data
By generating target feature combinations and performing abnormal monitoring, the problem of poor flexibility and accuracy of existing timing data abnormal monitoring methods is solved, and the low-cost and high-scalability abnormal monitoring effect is achieved.
Patent Information
- Application Number
- CN202011606882.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-30
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2040-12-30
AI Technical Summary
The flexibility and accuracy of the abnormality monitoring methods for existing time-series data are poor, costly and low scalability, and automatic machine learning methods require difficult access to label data.
By acquiring multiple feature information of timing data, a target feature combination is generated, and abnormal results are monitored according to the target feature combination, without setting a fixed threshold and obtaining tag data.
It realizes the flexibility and accuracy of timing data exception monitoring, reduces costs, and improves the scalability of the system.
Smart Images

Figure CN113723734B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology, and in particular to a method, device, electronic device and storage medium for abnormal monitoring of time series data. Background Art
[0002] At present, anomaly monitoring of time series data is widely used in production and life. For example, pedestrian flow monitoring in business districts can prevent accidents caused by excessive pedestrian flow and abnormal status monitoring of information systems.
[0003] In related technologies, abnormal monitoring of time series data is often based on rules given by domain experts. For example, according to expert experience and daily monitoring values, the normal range of various technical indicators is specified, and data within the normal range is judged as normal, and data outside the normal range is judged as abnormal. However, this method lacks flexibility and accuracy, is costly, and has low scalability.
[0004] In related technologies, anomaly monitoring of time series data can also be performed through automatic machine learning methods. However, this method requires label information to establish an evaluation metric for the quality of the model in order to provide feedback to adjust the model and parameters, etc. However, it is difficult to obtain label data in actual situations. Summary of the invention
[0005] The first aspect of the present application proposes a method for anomaly monitoring time series data, which uses a target feature combination to monitor abnormal results without setting a fixed threshold and obtaining label data, with low cost and high scalability.
[0006] A second embodiment of the present application provides a device for monitoring abnormalities in time series data.
[0007] A third aspect of the present application provides an electronic device.
[0008] The fourth aspect of the present application provides a computer-readable storage medium.
[0009] The first embodiment of the present application provides a method for monitoring abnormality of time series data, including:
[0010] Obtain multiple feature information of time series data;
[0011] Generating a target feature combination according to the plurality of feature information; and
[0012] Abnormal result monitoring is performed based on the target feature combination.
[0013] According to the abnormality monitoring method of time series data in the embodiment of the present application, multiple feature information of the time series data is first obtained, and a target feature combination is generated according to the multiple feature information, and then abnormal result monitoring is performed according to the target feature combination. Therefore, the abnormal result monitoring is performed using the target feature combination, without setting a fixed threshold and obtaining label data, with low cost and high scalability.
[0014] In addition, the abnormality monitoring method for time series data according to the above embodiment of the present application may also have the following additional technical features:
[0015] In one embodiment of the present application, the step of acquiring multiple feature information of time series data includes:
[0016] Acquire multiple features of the time series data including proximity deviation features, period deviation features, trend deviation features, and residual features.
[0017] In one embodiment of the present application, generating a target feature combination according to the plurality of feature information includes:
[0018] generating a plurality of feature combinations according to the plurality of feature information;
[0019] The target feature combination is selected from among the plurality of feature combinations.
[0020] In one embodiment of the present application, the selecting the target feature combination from the multiple feature combinations includes:
[0021] Calculating the correlation coefficient between the multiple features in each feature combination;
[0022] The target feature combination is selected from the plurality of feature combinations according to the correlation coefficient.
[0023] In one embodiment of the present application, the above-mentioned abnormality monitoring method for time series data further includes:
[0024] The minimum variance among the multiple features in each of the feature combinations is calculated, wherein the target feature combination is selected from the multiple feature combinations according to the correlation coefficient and the minimum variance.
[0025] In one embodiment of the present application, the abnormal result monitoring according to the target feature combination includes:
[0026] Inputting the target feature combination into a plurality of anomaly monitoring models to generate anomaly points and normal points identified by each of the anomaly monitoring models;
[0027] selecting a target abnormality monitoring model suitable for the time series from the plurality of abnormality monitoring models according to the abnormal points and the normal points output by each of the abnormality monitoring models;
[0028] Abnormal result monitoring is performed according to the target feature combination and the target abnormality monitoring model.
[0029] In one embodiment of the present application, the selecting a target abnormality monitoring model suitable for the time series from the multiple abnormality monitoring models according to the abnormal points and the normal points output by each of the abnormality monitoring models includes:
[0030] Obtaining the distance between the abnormal point and the normal point;
[0031] A target abnormality monitoring model suitable for the time series is selected from the plurality of abnormality monitoring models according to the distance between the abnormal point and the normal point.
[0032] In one embodiment of the present application, there are multiple abnormal points, and the method further includes:
[0033] An average distance between the plurality of abnormal points and the normal point is obtained, wherein a target abnormality monitoring model suitable for the time series is selected from the plurality of abnormality monitoring models according to the distance between the abnormal point and the normal point and the average distance.
[0034] The second aspect of the present application provides a device for monitoring abnormality of time series data, including:
[0035] An acquisition module is used to obtain multiple feature information of time series data;
[0036] A generating module, configured to generate a target feature combination according to the plurality of feature information; and
[0037] A monitoring module is used to monitor abnormal results according to the target feature combination.
[0038] The abnormality monitoring device for time series data of the embodiment of the present application obtains multiple feature information of the time series data through the acquisition module, generates a target feature combination according to the multiple feature information through the generation module, and performs abnormal result monitoring according to the target feature combination through the monitoring module. Therefore, the abnormal result monitoring is performed using the target feature combination, without setting a fixed threshold and obtaining label data, with low cost and high scalability.
[0039] In addition, the abnormality monitoring device for time series data according to the above embodiment of the present application may also have the following additional technical features:
[0040] In one embodiment of the present application, the acquisition module is specifically used to:
[0041] Acquire multiple features of the time series data including proximity deviation features, period deviation features, trend deviation features, and residual features.
[0042] In one embodiment of the present application, the generating module includes:
[0043] A first generating unit, configured to generate a plurality of feature combinations according to the plurality of feature information;
[0044] The first selection unit is used to select the target feature combination from the multiple feature combinations.
[0045] In one embodiment of the present application, the first selection unit is specifically configured to:
[0046] Calculating the correlation coefficient between the multiple features in each feature combination;
[0047] The target feature combination is selected from the plurality of feature combinations according to the correlation coefficient.
[0048] In one embodiment of the present application, the first selection unit is further configured to:
[0049] The minimum variance among the multiple features in each of the feature combinations is calculated, wherein the target feature combination is selected from the multiple feature combinations according to the correlation coefficient and the minimum variance.
[0050] In one embodiment of the present application, the monitoring module includes:
[0051] A second generating unit, configured to input the target feature combination into a plurality of anomaly monitoring models to generate anomaly points and normal points identified by each of the anomaly monitoring models;
[0052] A second selection unit, configured to select a target abnormality monitoring model suitable for the time series from the plurality of abnormality monitoring models according to the abnormal points and the normal points output by each of the abnormality monitoring models;
[0053] A monitoring unit is used to monitor abnormal results according to the target feature combination and the target abnormality monitoring model.
[0054] In one embodiment of the present application, the second selection unit is specifically configured to:
[0055] Obtaining the distance between the abnormal point and the normal point;
[0056] A target abnormality monitoring model suitable for the time series is selected from the plurality of abnormality monitoring models according to the distance between the abnormal point and the normal point.
[0057] In one embodiment of the present application, there are multiple abnormal points, and the second selection unit is further used to:
[0058] An average distance between the plurality of abnormal points and the normal point is obtained, wherein a target abnormality monitoring model suitable for the time series is selected from the plurality of abnormality monitoring models according to the distance between the abnormal point and the normal point and the average distance.
[0059] The third aspect embodiment of the present application proposes an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the method for monitoring abnormalities of time series data as described in the first aspect embodiment above is implemented.
[0060] The electronic device of the embodiment of the present application executes a computer program stored in a memory through a processor, and uses a target feature combination to monitor abnormal results. There is no need to set a fixed threshold and obtain label data, and the cost is low and the scalability is high.
[0061] The fourth aspect of the present application provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the method for monitoring abnormalities in time series data as described in the first aspect of the present application is implemented.
[0062] The computer-readable storage medium of the embodiment of the present application stores a computer program and is executed by a processor, and uses a target feature combination to monitor abnormal results. There is no need to set a fixed threshold and obtain label data, and the cost is low and the scalability is high.
[0063] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:
[0065] Figure 1 A flowchart of a method for monitoring abnormality of time series data according to an embodiment of the present application;
[0066] Figure 2 is a flow chart of a method for monitoring abnormality of time series data according to another embodiment of the present application;
[0067] Figure 3 is a block diagram of a device for monitoring abnormality of time series data according to an embodiment of the present application; and
[0068] Figure 4It is a schematic diagram of the structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0069] Embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.
[0070] The following describes the abnormality monitoring method, device, electronic device and storage medium for time series data in embodiments of the present application with reference to the accompanying drawings.
[0071] The method for monitoring abnormalities of time series data provided in the embodiment of the present application can be executed by an electronic device, and the electronic device can be a PC (Personal Computer), a tablet computer or a server, etc., without any limitation here.
[0072] In an embodiment of the present application, a processing component, a storage component, and a drive component may be provided in the electronic device. Optionally, the drive component and the processing component may be integrated, the storage component may store an operating system, an application program, or other program modules, and the processing component implements the abnormality monitoring method of time series data provided in the embodiment of the present application by executing the application program stored in the storage component.
[0073] Figure 1 The figure is a flow chart of a method for monitoring abnormality of time series data according to an embodiment of the present application.
[0074] The method for monitoring anomalies of time series data of the embodiment of the present application can also be executed by the device for monitoring anomalies of time series data provided by the embodiment of the present application. The device can be configured in an electronic device to obtain multiple feature information of time series data, generate a target feature combination based on the multiple feature information, and monitor abnormal results based on the target feature combination, thereby eliminating the need to set fixed thresholds and obtain label data, and having low cost and high scalability.
[0075] As a possible situation, the method for monitoring anomalies of time series data in the embodiment of the present application may also be executed on the server side. The server may be a cloud server, and the method for monitoring anomalies of time series data may be executed on the cloud.
[0076] like Figure 1 As shown, the abnormality monitoring method of time series data may include:
[0077] Step 101, obtaining multiple feature information of time series data, wherein the multiple feature information may include multiple features of the adjacent deviation feature, the period deviation feature, the trend deviation feature and the residual feature of the time series data.
[0078] It should be noted that the time series data described in this embodiment may be sales record data of a shopping platform, for example, sales record data within a period of time (for example, one day, one week, one month, etc.) of a shopping platform, or page browsing record data of a shopping platform, or traffic record data of a business district, without any limitation here. Among them, a shopping platform may include a shopping website, a shopping APP (Application, mobile software) and a shopping system, etc.
[0079] Step 102: Generate a target feature combination based on multiple feature information.
[0080] In an embodiment of the present application, the electronic device may generate a target feature combination according to multiple feature information based on a feature combination generation model or a preset algorithm.
[0081] It should be noted that the feature combination generation model described in this embodiment can be trained in advance and pre-stored in the storage space of the electronic device for easy retrieval and use. The storage space is not limited to a physical storage space, such as a hard disk. The storage space can also be a storage space of a network hard disk connected to the electronic device (cloud storage space). The preset algorithm described in this embodiment can be calibrated according to actual conditions.
[0082] Step 103, monitor abnormal results according to the target feature combination.
[0083] Specifically, the electronic device can obtain time series data from the shopping platform, and parse and calculate the time series data to generate multiple feature information of the time series data, and then generate a target feature combination according to a preset algorithm and multiple feature information, and finally monitor abnormal results according to the target feature combination.
[0084] It should be noted that, under normal circumstances, relatively recent and periodic changes in time series data that are relatively large are likely to be abnormal. Through the abnormality monitoring method of time series data in the embodiment of the present application, the relatively recent and periodic changes in time series data can be monitored in real time.
[0085] In the embodiment of the present application, multiple feature information of time series data is first obtained, and a target feature combination is generated according to the multiple feature information, and then abnormal result monitoring is performed according to the target feature combination. Therefore, the abnormal result monitoring is performed using the target feature combination, without setting a fixed threshold and obtaining label data, with low cost and high scalability.
[0086] To clearly illustrate the previous embodiment, in one embodiment of the present application, obtaining multiple feature information of time series data may include obtaining multiple features of proximity deviation features, periodic deviation features, trend deviation features, and residual features of the time series data.
[0087] In the embodiments of the present application, the proximity deviation value, the period deviation value, the trend deviation value, and the residual value of the time series data can be calculated respectively through the following formulas (1), (2), (3), and (4):
[0088] L = X t - X t-1 (1)
[0089]
[0090]
[0091]
[0092] Wherein, L can be the proximity deviation value, Z can be the period deviation value, Q can be the trend deviation value, C can be the residual value, X t can be the time series data at the current moment (i.e., the time series value, for example, the sales volume of the shopping platform at the current moment), X t-1 can be the time series data at the previous moment, period can be the period deviation interval (for example, week), trend can be the trend deviation interval (for example, 1 month, 2 months, 15 days, etc.), can be the historical mean of the time series data, and σ can be the variance of the time series data.
[0093] Specifically, after the electronic device obtains the time series data, it can calculate the proximity deviation value, the period deviation value, the trend deviation value, and the residual value of the time series data respectively according to the above formulas (1), (2), (3), and (4), and then can generate the proximity deviation feature, the period deviation feature, the trend deviation feature, and the residual feature of the time series data respectively according to the proximity deviation value, the period deviation value, the trend deviation value, the residual value of the time series data, and the preset feature generation algorithm. Among them, the preset feature generation algorithm can be calibrated according to the actual situation.
[0094] It should be noted that the larger the residual value described in this embodiment, the greater the degree of deviation of the current moment from the mean value, that is, the more likely it is to be abnormal. Among them, the classical statistical-based abnormal monitoring method for time series data believes that a deviation from the mean value greater than 3 times the variance is abnormal. That is to say, the residual value is a very important feature for judging time series anomalies.
[0095] In addition, there can be different types of anomalies, such as oversize anomalies, undersize anomalies, etc. Among them, for oversize anomalies, the calculation method of the proximity deviation value can be: max(X t - X t-1 , 0), and the calculation of other deviation index (such as the period deviation value, the trend deviation value, and the residual value) is the same. Similarly, for undersize anomalies, the calculation method of the proximity deviation value can be: min(Xt -X t-1 ,0).
[0096] Further, in one embodiment of the present application, generating a target feature combination according to a plurality of feature information may include generating a plurality of feature combinations according to the plurality of feature information, and selecting a target feature combination from the plurality of feature combinations.
[0097] Specifically, after acquiring multiple feature information of time series data, the electronic device may combine and reduce the dimensions of the proximity deviation features, period deviation features, trend deviation features, and residual features of the time series data in the multiple feature information, and finally reorganize them according to the effect of feature evaluation to obtain multiple feature combinations. Then, the electronic device may select the optimal (i.e., the one with the best evaluation effect) feature combination from the multiple feature combinations as the target feature combination according to the effect of feature evaluation.
[0098] It should be noted that the dimension reduction described in this embodiment is equivalent to merging related features and performing denoising processing on the features.
[0099] To clearly explain the previous embodiment, in one embodiment of the present application, selecting a target feature combination from a plurality of feature combinations may include: calculating a correlation coefficient between a plurality of features in each feature combination, and selecting the target feature combination from the plurality of feature combinations based on the correlation coefficient.
[0100] It should be noted that the larger the correlation coefficient between features, the more single the feature is and the worse the feature quality is. The correlation can usually be measured by the Pearson correlation coefficient, where the Pearson correlation coefficient is equivalent to the cosine similarity.
[0101] In the embodiment of the present application, the correlation coefficient between multiple features in each feature combination can be calculated by the following formula (5):
[0102]
[0103] in, can be the correlation coefficient, n can be the total time in the time series data, i can be the current time, x 1 and x 2 can be two features respectively (i.e., two features in the above feature combination), and can be the mean of the two features respectively, which is equivalent to x 1 and x 2 The data after averaging.
[0104] Specifically, after the electronic device generates multiple feature combinations based on multiple feature information, it can calculate the correlation coefficients between multiple features in each feature combination respectively through the above formula (5), and can compare the correlation coefficients between multiple features in each feature combination to determine the smallest correlation coefficient between multiple features, and the target feature combination corresponding to the correlation coefficient, that is, select the feature combination with the smallest correlation coefficient from each feature combination as the target feature combination.
[0105] Furthermore, in one embodiment of the present application, the method for monitoring anomalies in time series data may also include calculating the minimum variance between multiple features in each feature combination, wherein a target feature combination is selected from the multiple feature combinations based on a correlation coefficient and a minimum variance.
[0106] In the embodiment of the present application, the minimum square error between multiple features in each feature combination can be calculated by the following formula (6):
[0107]
[0108] Among them, G can be the minimum variance between multiple features, x 1 and x 2 can be two features respectively (i.e., two features in the above feature combination), and They can be the means of two features respectively, n can be the total time in the time series data, and i can be the current time.
[0109] Specifically, after the electronic device calculates the correlation coefficient between multiple features in each feature combination, it can also calculate the minimum variance between multiple features in each feature combination according to the above formula (6), and can compare the minimum variances between multiple features in each feature combination to generate a first comparison result. Then the electronic device can also calculate the correlation coefficient between multiple features in each feature combination according to the above formula (5), and can compare the correlation coefficients between multiple features in each feature combination to generate a second comparison result. Finally, the electronic device can select a target feature combination from multiple feature combinations based on the first comparison result and the second comparison result. For example, select the smallest correlation coefficient and minimum variance between multiple features, and the corresponding feature combination is used as the target feature combination. In this way, the selected target feature combination can be more suitable for the current time series data.
[0110] In one embodiment of the present application, Figure 2 As shown, monitoring of abnormal results based on target feature combinations may include:
[0111] Step 201, input the target feature combination into multiple anomaly monitoring models to generate anomalies and normal points identified by each anomaly monitoring model. There may be multiple anomalies and normal points, and the multiple anomaly monitoring models may include: KNN (k-NearestNeighbor, nearest neighbor classification algorithm) model, one-class SVM (One-Class Support VectorMachine, single-class support vector machine) model, Isolation Forest (isolation forest) model, etc.
[0112] It should be noted that the multiple abnormality monitoring models described in this embodiment may be trained in advance and pre-stored in the storage space of the electronic device for easy retrieval and use.
[0113] Furthermore, the training and generation of the above-mentioned multiple abnormality monitoring models can be performed by a related server, which can be a cloud server or a computer host. A communication connection is established between the server and an electronic device that can execute the abnormality monitoring method of time series data provided by the application embodiment, and the communication connection can be at least one of a wireless network connection and a wired network connection. The server can send the trained multiple abnormality monitoring models to the electronic device so that the electronic device can call them when needed, thereby greatly reducing the computing pressure of the electronic device.
[0114] Specifically, after obtaining the target feature combination, the electronic device can input the target feature combination into multiple anomaly monitoring models respectively, so that the target feature combination is processed by multiple anomaly monitoring models respectively, so that each anomaly monitoring model outputs abnormal points and normal points, that is, the abnormal points and normal points identified by each anomaly monitoring model.
[0115] Step 202 : selecting a target anomaly monitoring model suitable for the time series from a plurality of anomaly monitoring models according to the anomaly points and normal points output by each anomaly monitoring model.
[0116] In one embodiment of the present application, selecting a target abnormality monitoring model suitable for the time series from multiple abnormality monitoring models according to the abnormal points and normal points output by each abnormality monitoring model may include obtaining the distance between the abnormal point and the normal point, and selecting a target abnormality monitoring model suitable for the time series from multiple abnormality monitoring models according to the distance between the abnormal point and the normal point. It should be noted that the distance described in this embodiment may be the shortest distance between the abnormal point and the normal point.
[0117] In the embodiment of the present application, the distance between the abnormal point and the normal point can be calculated by the following formula (7):
[0118]
[0119] Among them, V can be the distance between the abnormal point and the normal point, The set of all abnormal points that can be output by the anomaly monitoring model. The set of all normal points output by the anomaly monitoring model, x i Can be an outlier point, x j It can be normal.
[0120] It should be noted that the present application can measure the performance of each anomaly monitoring model by the shortest distance between the anomaly point and the normal point output by each anomaly monitoring model, wherein the shortest distance may refer to the minimum value of the distance between the anomaly point and the normal point. Generally, the longer the minimum distance is, the more obvious the effect of distinguishing the anomaly is, that is, the better the performance of the model is.
[0121] Step 203: monitor abnormal results according to the target feature combination and the target abnormality monitoring model.
[0122] Specifically, after obtaining the abnormal points and normal points identified by each abnormal monitoring model, the electronic device can calculate the closest distance between the abnormal points and normal points output by each abnormal monitoring model respectively through the above formula (7), and can compare the closest distances between the abnormal points and normal points output by each abnormal monitoring model to determine the closest distance between the farthest abnormal point and the normal point, and use the abnormal monitoring model corresponding to the closest distance as the target abnormal monitoring model. Then, the electronic device monitors the abnormal results according to the target feature combination and the target abnormal monitoring model.
[0123] In order to improve the accuracy of selecting a target anomaly monitoring model suitable for a time series, in one embodiment of the present application, there may be multiple abnormal points, and the abnormality monitoring method of the time series data may further include obtaining the average distance between the multiple abnormal points and the normal points, wherein the target anomaly monitoring model suitable for the time series is selected from the multiple abnormality monitoring models according to the distance between the abnormal points and the normal points and the average distance. It should be noted that the average distance described in this embodiment may be the average closest distance between the multiple abnormal points and the normal points.
[0124] In the embodiment of the present application, the average distance between multiple abnormal points and normal points can be calculated by the following formula (8):
[0125]
[0126] Where W can be the average distance between multiple abnormal points and normal points, The set of all abnormal points that can be output by the anomaly monitoring model. The set of all normal points that can be output by the anomaly monitoring model, Can be the number of outliers, x iCan be an outlier point, x j It can be normal.
[0127] It should be noted that the present application can also measure the performance of each anomaly monitoring model by the average nearest distance between multiple anomaly points and normal points output by each anomaly monitoring model, wherein the average nearest distance may refer to the average of the nearest distances between multiple anomaly points and normal points. Generally, the longer the average nearest distance, the better the performance of the model.
[0128] Specifically, after obtaining the abnormal points and normal points identified by each abnormal monitoring model, the electronic device can also calculate the average value of the closest distances between multiple abnormal points and normal points output by each abnormal monitoring model through the above formula (8), and can compare the average values of the closest distances between the abnormal points and normal points output by each abnormal monitoring model to generate a third comparison result. Then the electronic device can also calculate the closest distances between the abnormal points and normal points output by each abnormal monitoring model through the above formula (7), and can compare the closest distances between the abnormal points and normal points output by each abnormal monitoring model to generate a fourth comparison result. Finally, the electronic device can select a target abnormal monitoring model suitable for the time series from multiple abnormal monitoring models based on the third comparison result and the fourth comparison result. For example, the closest distance between the farthest abnormal point and the normal point and the average value of the closest distance are selected, and the corresponding abnormal monitoring model is used as the target abnormal monitoring model. In this way, the selected target abnormal monitoring model can be more suitable for the current time series data.
[0129] In summary, according to the abnormality monitoring method of time series data in the embodiment of the present application, multiple feature information of the time series data is first obtained, and a target feature combination is generated according to the multiple feature information, and then abnormal result monitoring is performed according to the target feature combination. Therefore, the abnormal result monitoring is performed using the target feature combination, without setting a fixed threshold and obtaining label data, with low cost and high scalability.
[0130] Figure 3 Schematic diagram of a block diagram of a device for monitoring abnormality of time series data according to an embodiment of the present application;
[0131] The device for monitoring anomalies of time series data in an embodiment of the present application can be configured in an electronic device to obtain multiple feature information of time series data, generate a target feature combination based on the multiple feature information, and monitor abnormal results based on the target feature combination, thereby eliminating the need to set fixed thresholds and obtain label data, and having low cost and high scalability.
[0132] like Figure 3 As shown, the abnormality monitoring device 300 for time series data may include: an acquisition module 310 , a generation module 320 and a monitoring module 330 .
[0133] The acquisition module 310 is used to acquire multiple feature information of time series data.
[0134] The generating module 320 is used to generate a target feature combination according to a plurality of feature information.
[0135] The monitoring module 330 is used to monitor abnormal results according to the target feature combination.
[0136] In one embodiment of the present application, the acquisition module 310 may be specifically used to acquire multiple features of the time series data including the proximity deviation feature, the period deviation feature, the trend deviation feature, and the residual feature.
[0137] In one embodiment of the present application, Figure 3 As shown, the generating module 320 may include: a first generating unit 321 and a first selecting unit 322 .
[0138] The first generating unit 321 is used to generate multiple feature combinations according to multiple feature information.
[0139] The first selection unit 322 is used to select a target feature combination from multiple feature combinations.
[0140] In one embodiment of the present application, the first selection unit 322 may be specifically configured to calculate a correlation coefficient between multiple features in each feature combination, and select a target feature combination from the multiple feature combinations according to the correlation coefficient.
[0141] In one embodiment of the present application, the first selection unit 322 may also be used to calculate the minimum variance between multiple features in each feature combination, wherein a target feature combination is selected from the multiple feature combinations according to the correlation coefficient and the minimum variance.
[0142] In one embodiment of the present application, Figure 3 As shown, the monitoring module 330 may include: a second generating unit 331 , a second selecting unit 332 and a monitoring unit 333 .
[0143] The second generating unit 331 is used to input the target feature combination into multiple anomaly monitoring models to generate anomaly points and normal points identified by each anomaly monitoring model.
[0144] The second selection unit 332 is used to select a target abnormality monitoring model suitable for the time series from multiple abnormality monitoring models according to the abnormal points and normal points output by each abnormality monitoring model.
[0145] The monitoring unit 333 is used to monitor abnormal results according to the target feature combination and the target abnormality monitoring model.
[0146] In one embodiment of the present application, the second selection unit 332 may be specifically configured to obtain the distance between the abnormal point and the normal point, and select a target abnormality monitoring model suitable for the time series from a plurality of abnormality monitoring models according to the distance between the abnormal point and the normal point.
[0147] In one embodiment of the present application, there may be multiple abnormal points, and the second selection unit 332 may also be used to obtain the average distance between the multiple abnormal points and the normal points, wherein a target abnormality monitoring model suitable for the time series is selected from multiple abnormality monitoring models based on the distance between the abnormal points and the normal points and the average distance.
[0148] It should be noted that for details not disclosed in the device for monitoring abnormality of time series data in an embodiment of the present invention, please refer to the details disclosed in the method for monitoring abnormality of time series data in an embodiment of the present invention, and the details will not be repeated here.
[0149] In summary, the abnormality monitoring device for time series data of the embodiment of the present application obtains multiple feature information of the time series data through the acquisition module, generates a target feature combination according to the multiple feature information through the generation module, and performs abnormal result monitoring according to the target feature combination through the monitoring module. Therefore, the abnormal result monitoring is performed using the target feature combination, without setting a fixed threshold and obtaining label data, with low cost and high scalability.
[0150] In order to implement the above embodiment, Figure 4 As shown, the present invention also proposes an electronic device 400, including a memory 410, a processor 420, and a computer program stored in the memory 410 and executable on the processor 420, and the processor 420 executes the program to implement the abnormality monitoring method of time series data proposed in the aforementioned embodiment of the present application.
[0151] The electronic device of the embodiment of the present application executes a computer program stored in a memory through a processor, and uses a target feature combination to monitor abnormal results. There is no need to set a fixed threshold and obtain label data, and the cost is low and the scalability is high.
[0152] In order to implement the above embodiments, the present invention also proposes a non-temporary computer-readable storage medium on which a computer program is stored. The program is executed by a processor to implement the abnormality monitoring method of time series data proposed in the above embodiments of the present application.
[0153] The computer-readable storage medium of the embodiment of the present application stores a computer program and is executed by a processor, and uses a target feature combination to monitor abnormal results. There is no need to set a fixed threshold and obtain label data, and the cost is low and the scalability is high.
[0154] In the description of this specification, the terms "first" and "second" are used for descriptive purposes only and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In the description of this application, the meaning of "plurality" is at least two, such as two, three, etc., unless otherwise clearly and specifically defined.
[0155] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.
[0156] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations on the present application. Ordinary technicians in this field can change, modify, replace and modify the above embodiments within the scope of the present application.
Claims
1. A method for monitoring anomalies in time series data. It is characterized in that include: Acquire multiple feature information of the time series data, wherein multiple features of the time series data including proximity deviation features, period deviation features, trend deviation features, and residual features are acquired; Generating a target feature combination according to the plurality of feature information; and Inputting the target feature combination into a plurality of anomaly monitoring models to generate anomaly points and normal points identified by each of the anomaly monitoring models; selecting a target abnormality monitoring model suitable for the time series from the plurality of abnormality monitoring models according to the abnormal points and the normal points output by each of the abnormality monitoring models; Perform abnormal result monitoring according to the target feature combination and the target abnormality monitoring model; The selecting a target abnormality monitoring model suitable for the time series from the plurality of abnormality monitoring models according to the abnormal points and the normal points output by each of the abnormality monitoring models comprises: Obtaining the distance between the abnormal point and the normal point; A target abnormality monitoring model suitable for the time series is selected from the plurality of abnormality monitoring models according to the distance between the abnormal point and the normal point.
2. The method for monitoring abnormality of time series data according to claim 1, It is characterized in that The generating a target feature combination according to the plurality of feature information comprises: generating a plurality of feature combinations according to the plurality of feature information; The target feature combination is selected from among the plurality of feature combinations.
3. The method for monitoring abnormality of time series data according to claim 2, It is characterized in that The selecting the target feature combination from the plurality of feature combinations comprises: Calculating the correlation coefficient between the multiple features in each feature combination; The target feature combination is selected from the plurality of feature combinations according to the correlation coefficient.
4. The method for monitoring abnormality of time series data according to claim 3, It is characterized in that Also includes: The minimum variance among the multiple features in each of the feature combinations is calculated, wherein the target feature combination is selected from the multiple feature combinations according to the correlation coefficient and the minimum variance.
5. The method for monitoring abnormality of time series data according to claim 1, It is characterized in that There are multiple abnormal points, and the method further includes: An average distance between the plurality of abnormal points and the normal point is obtained, wherein a target abnormality monitoring model suitable for the time series is selected from the plurality of abnormality monitoring models according to the distance between the abnormal point and the normal point and the average distance.
6. An abnormality monitoring device for time series data, It is characterized in that include: An acquisition module is used to obtain multiple feature information of time series data; A generating module, used for generating a target feature combination according to the plurality of feature information; as well as A monitoring module, used for monitoring abnormal results according to the target feature combination; The acquisition module is specifically used for: Acquire multiple features of the time series data including proximity deviation features, period deviation features, trend deviation features, and residual features; The monitoring module comprises: A second generating unit, configured to input the target feature combination into a plurality of anomaly monitoring models to generate anomaly points and normal points identified by each of the anomaly monitoring models; A second selection unit, configured to select a target abnormality monitoring model suitable for the time series from the plurality of abnormality monitoring models according to the abnormal points and the normal points output by each of the abnormality monitoring models; A monitoring unit, configured to monitor abnormal results according to the target feature combination and the target abnormality monitoring model; The second selection unit is specifically used to: Obtaining the distance between the abnormal point and the normal point; A target abnormality monitoring model suitable for the time series is selected from the plurality of abnormality monitoring models according to the distance between the abnormal point and the normal point.
7. The abnormality monitoring device for time series data according to claim 6, It is characterized in that The generating module comprises: A first generating unit, configured to generate a plurality of feature combinations according to the plurality of feature information; The first selection unit is used to select the target feature combination from the multiple feature combinations.
8. The abnormality monitoring device for time series data according to claim 7, It is characterized in that The first selection unit is specifically configured to: Calculating the correlation coefficient between the multiple features in each feature combination; The target feature combination is selected from the plurality of feature combinations according to the correlation coefficient.
9. The abnormality monitoring device for time series data according to claim 8, It is characterized in that The first selection unit is further configured to: The minimum variance among the multiple features in each of the feature combinations is calculated, wherein the target feature combination is selected from the multiple feature combinations according to the correlation coefficient and the minimum variance.
10. The abnormality monitoring device for time series data according to claim 6, It is characterized in that There are multiple abnormal points, and the second selection unit is further used to: An average distance between the plurality of abnormal points and the normal point is obtained, wherein a target abnormality monitoring model suitable for the time series is selected from the plurality of abnormality monitoring models according to the distance between the abnormal point and the normal point and the average distance.
11. An electronic device, It is characterized in that The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the program, the method for monitoring abnormality of time series data as described in any one of claims 1 to 5 is implemented.
12. A computer-readable storage medium having a computer program stored thereon, It is characterized in that When the program is executed by a processor, the method for monitoring abnormality of time series data as described in any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Locomotive and vehicle abnormal axle temperature diagnostic method and system
CN109000940A
Abnormity detection method, device and equipment and computer readable storage medium
CN111860897A
Apparatus and method for analyzing abnormal data using combination of multi-dimensional features
KR1020160070327A