Anomaly Detection Method Based on Energy and Mirror Generative Adversarial Network

By combining mirror generation adversarial networks and energy ideas in the field of exception detection, and generating and adding key exception points, the problem of data set imbalance is solved, the exception detector's ability to identify unknown exceptions is improved, and the category balance of the data set is achieved.

CN114139686BActive Publication Date: 2025-06-27NANJING UNIV OF AERONAUTICS & ASTRONAUTICS
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111479582.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-06
Publication Date
2025-06-27
Estimated Expiration
2041-12-06

AI Technical Summary

Technical Problem

When existing anomaly detection methods face the situation of data set imbalance, it is difficult to effectively identify and classify exception points, especially in unknown exceptions.

Method used

Anomaly detection method based on mirror generation adversarial network (GAN) and energy ideas is adopted to achieve the purpose of category balance by generating key anomaly points and adding them to the original data set, thereby improving the recognition ability of the anomaly detector.

Benefits of technology

By generating key exception points located outside the normal point, the exception detector can learn complete positive exception boundary information, improve the ability to identify unknown exceptions, and achieve category balance of the data set.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114139686B_ABST
    Figure CN114139686B_ABST
Patent Text Reader

Abstract

The present invention discloses an anomaly detection method based on energy and mirror generative adversarial network. The proposed method includes three parts. The first part is to use a clustering algorithm to divide the original data into multiple clusters, and then perform subsequent processing on each cluster separately to eliminate the influence of the gaps between clusters. The second part is to construct a mirror generative adversarial network with a neural network and introduce the idea of energy. Use normal data for iterative training to generate key anomaly points located at the edge and add them to the original data set to achieve the purpose of class balance. The third part is to construct an anomaly detector. Use the generated anomaly points and the normal points in the data set for iterative training. The key edge positions where the anomaly points are located can enable the anomaly detector to learn the boundary information between positive and negative anomalies, so as to have good detection ability for unknown anomalies. The present invention realizes the generation of key anomaly points with higher efficiency, and while solving the problem of class imbalance, it also improves the detection ability of the anomaly detector for unknown anomalies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of machine learning and anomaly detection, and particularly to an anomaly detection method based on a mirror generative adversarial network combined with an energy idea. Background Art

[0002] Anomaly detection is a very active research topic in the field of artificial intelligence, and its purpose is to identify abnormal instances that do not belong to the normal data distribution, that is, observations with significantly different characteristics from most other data. These observations are so unique that they raise suspicions that they are generated by illegal behavior or undetected errors. In a dataset, positive example samples are relatively easy to obtain, and the "patterns" of positive example samples tend to be fixed or not very variable. On the contrary, anomalies are few in number, relatively variable in area, and even unknown. At this time, anomaly detection faces the situation of sample imbalance.

[0003] Generally speaking, according to the availability of data labels, existing anomaly detection methods can be divided into three categories: unsupervised, semi-supervised, and supervised anomaly detection. Unsupervised algorithms are one of the most widely studied algorithms because they do not require additional labels or prior information. They include methods based on statistics, clustering, regression, and neighbors. These methods explicitly or implicitly assume that outliers are not as concentrated as normal data. Therefore, discrete anomalies can be effectively detected. However, in many cases, the same mechanism may generate multiple anomalies (such as DoS attacks). They become more and more concentrated, so that unsupervised outlier detection wrongly detects these groups of anomalies as normal data. In addition, the selection of models and parameters is a rather large challenge for unsupervised methods without the help of prior knowledge. While supervised algorithms can usually obtain a higher detection rate and better parameters because the labels are complete and corrected during the training process. However, in the vast majority of cases, the cost of obtaining complete labels is huge and unaffordable. Since fully supervised methods have too high requirements for the dataset, their implementation has great limitations. And semi-supervised algorithms are in between. Only normal data is needed to obtain a robust model, and the acquisition of normal data is relatively easier and occupies the vast majority of the dataset. Based on this, the present invention regards anomaly detection as a semi-supervised problem.

[0004] Generative Adversarial Networks (GANs) are a type of adversarial representation learning model that has achieved advanced performance in many application scenarios. In the related work of combining GANs and anomaly detection, for unsupervised outlier detection and semi-supervised outlier detection that only use normal examples, GAN-based reconstruction models and generative models have been studied. GAN-based reconstruction models usually learn the generation mechanism of normal data by training a conventional GAN or a combination of GAN and autoencoder, and then based on the reconstruction loss or discriminator loss. GAN-based generative models usually use GANs to generate informative latent outliers or uncommon normal samples so that subsequent detectors can describe the correct boundaries. For supervised outlier detection, GANs are often used to synthesize minority class examples to balance the relative proportions between the two classes.

[0005] The purpose of the present invention is to address the common problem of dataset imbalance in the field of anomaly detection. By combining the ideas of mirror generative adversarial networks and energy, key outliers are generated to supplement the dataset to achieve class balance. The key positions where the generated outliers are located can also be the boundary information between positive and negative anomalies learned by the anomaly detector, thus enabling good detection ability for unknown anomalies. Summary of the Invention

[0006] Since most data exists in the form of multiple clusters, the within-cluster is the normal space, while the vast inter-cluster and out-of-cluster spaces are the positions where outliers may appear. Therefore, the present invention first preprocesses the data and then clusters it, and each cluster is processed separately. The single-generator single-discriminator structure of the generative adversarial network is improved by adding a new mirror discriminator, and combined with the idea of energy, to generate key outliers located outside the normal points and add them to the original dataset to achieve class balance. The key edge positions where the added outliers are located can enable the anomaly detector to learn the complete boundary information between positive and negative anomalies and improve its recognition ability for unknown anomalies.

[0007] The present invention is realized through the following technical solutions: An anomaly detection method based on energy and mirror generative adversarial network, specifically including the following steps:

[0008] Step 1: Preprocess the normal data, standardize it to eliminate the influence of dimension on the results. Divide the dataset into training samples and test samples, which are used for training and testing the model respectively, and cluster the training samples using a clustering algorithm to eliminate the influence of inter-cluster gaps on the generation of edge outliers;

[0009] Step 2: Construct a mirror generative adversarial network using a neural network, introduce the idea of energy, and use the single-cluster training data obtained in Step 1 to iteratively train the model to obtain optimal parameters, and add the edge outliers after the training is completed to the original dataset;

[0010] Step 3: Use a neural network to separately build an outlier detector, and use the edge outliers and normal points obtained from the training of all clusters in Step 2 to iteratively train it, and use the test set to test it.

[0011] Furthermore, the preprocessing of the data in Step 1 includes the following steps:

[0012] Step 11: Standardize all the data in the dataset to eliminate the influence of the dimension on the results.

[0013] Step 12: Divide the dataset, and divide all the abnormal data into the test set. For the normal data, 80% of the data is split out as the training set, and the remaining 20% of the data is merged with the abnormal data to form the test set, denoted as X train , X test .

[0014] Step 13: Use the clustering algorithm to cluster the training data X train into clusters, where m is the number of data clusters. Take each cluster of data to separately execute the subsequent Step 2 and Step 3 to eliminate the influence of the inter-cluster gap on the generation of outliers.

[0015] Furthermore, the step of training the mirror generation network in Step 2 and combining the energy idea includes the following steps:

[0016] Step 21: Construct a mirror generative adversarial network. Different from the traditional single-generator single-discriminator structure, we add a mirror discriminator, and denote its components as G (generator), D (discriminator), D mirror (mirror discriminator), where D and D mirror have the same structure but opposite target outputs.

[0017] Step 22: Introduce the idea of energy, change D and D mirror into the encoder-decoder structure, and obtain the reconstructed data y i of the original data x i through encoding and decoding calculations. x i and y i are of the same dimension, and the mean square error of x i and y i is used as the energy value and directly used for the adversarial training with the generator G.

[0018] Step 23: Take a cluster of data from the preprocessed training set, denoted as where n is the number of training samples in this cluster.

[0019] Step 24: Randomly sample k-dimensional uniform noise z as the input to the generator G, and output the initial generated samples, denoted as X g ={x g1 , x g2 ,..., x gn}, where n is the number of generated samples.

[0020] Step 25: Use the generated samples X g obtained in Steps 23 and 24 and a cluster of training samples as the input to D. Through the encoding and decoding operations, it is hoped that D outputs a lower energy for the samples in and a higher energy for the samples in X g . The objective function of D is shown in Equation 2-1:

[0021] L D =D(x)+[m - D(G(z))] + Equation 2-1

[0022] Step 26: D mirror has the same structure as D, but its training objective function is the opposite. Use the generated samples X g obtained in Step 23 and in Step 24 as the input to D mirror . Through the encoding and decoding operations, it is hoped that D mirror outputs a lower energy for the samples in X g and a higher energy for the samples in . The objective function of D mirror is shown in Equation 2-2:

[0023]

[0024] Step 27: Resample the k-dimensional uniform noise z * as the input to the generator G. Use the output generated samples as the input to the trained D and D mirror respectively, and obtain the energy values of each generated sample for the two.

[0025] Step 28: To avoid the mode collapse problem, for the generated points calculate their mean Maximize the distance of each point from its mean to encourage the generated points to be scattered, as shown in Equation 2-3:

[0026]

[0027] Add Formula 2-3 to the objective function of generator G, and train generator G according to the energy values of each generated sample. The objective function of generator G is shown in Formula 2-4: mirror For the energy values of each generated sample, train generator G. The objective function of generator G is shown in Formula 2-4:

[0028] L G = ||D(G(z * )) - D mirror (G(z * ))||2 + λloss d Formula 2-4

[0029] Step 29: Go to Step 24, continue to train G, D, D mirror , until the model converges.

[0030] Step 210: After the model converges, resample the k-dimensional uniform noise z′ as the input of generator G, generate the outlier points located at the edge positions, add them to the dataset, switch to the next cluster of data, and go to Step 23 until all data clusters in the training set are processed.

[0031] Furthermore, the training of the anomaly detector in Step 3 includes the following steps:

[0032] Step 31: Use a neural network to construct an anomaly detector AD. The dimension of the input layer is the same as that of the samples, and the dimension of the output layer is 1, that is, the anomaly score in the interval 0-1. Iteratively train the anomaly detector with the augmented training set in Step 2 until convergence.

[0033] Step 32: Use the data in the test set as the input of the anomaly detector, output the corresponding scores, and according to the threshold threshold, determine whether it is normal or abnormal, as shown in Formula 3-1:

[0034]

[0035] The present invention creatively improves the generative adversarial network and combines the idea of energy, and applies it to anomaly detection, obtaining the following beneficial effects:

[0036] (1) To solve the problem of class imbalance in the dataset, train the adversarial generative network to generate outlier points and supplement them to the original dataset, so that the ratio of positive and abnormal samples in the dataset reaches 1:1, improving the effectiveness of the anomaly detector.

[0037] (2) Modify the structure of the adversarial generative network by adding a mirror discriminator with the same structure as the original discriminator but opposite objectives, forming an adversarial form of a single generator and double discriminators, so that the generated points are located at key positions on the edge. Combining the idea of energy, change the structure of the discriminator into an encoding-decoding form to further simplify the objective functions of each component and improve the training stability of the model. The edge positions where the abnormal points are generated enable the anomaly detector to learn the correct positive-abnormal boundary information, thus having good recognition ability for unknown anomalies. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 is a flowchart of an anomaly detection method based on energy and mirror generative adversarial network

[0039] Figure 2 is a structure diagram of a mirror generative adversarial network combined with energy DETAILED DESCRIPTION OF THE EMBODIMENTS

[0040] The embodiments of the present invention will be described in detail below: These embodiments are implemented on the premise of the technical solution of the present invention, and detailed implementation manners and specific operation processes are given. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several deformations and improvements can still be made, and these all belong to the protection scope of the present invention.

[0041] Combined with Figure 1 - Figure 2 as shown, the example of the present invention is an anomaly detection method based on energy and mirror adversarial generative network, including the following steps:

[0042] This embodiment is divided into a training stage and a testing stage. In the training stage, the data is clustered, and each cluster is processed separately to avoid the influence of the inter-cluster gap on the generated points. Each cluster of data is used as the input of the mirror generative adversarial network to train and obtain the weight parameters of the entire network. Combining the idea of energy, through the adversarial training of two discriminators and the generator, the set of generated abnormal points is located at key positions outside the normal points and added to the original dataset to achieve class balance. After all data clusters are processed, the training set with balanced positive and negative sample numbers is used as the input of the anomaly detector. Due to the key positions where the abnormal points are generated, it can learn the complete positive-abnormal boundary information and improve the recognition ability for unknown anomalies. In the testing stage, the data in the test set is used as the input of the anomaly detector, and the positive-abnormal judgments corresponding to each data are output and compared with the labels in the test set to obtain the performance indicators of the anomaly detector.

[0043] An anomaly detection algorithm based on energy and mirror generative adversarial network in this embodiment specifically includes the following steps:

[0044] Step 1: Preprocess the normal data and standardize it to eliminate the influence of dimension on the results. Divide the dataset into training samples and test samples for model training and testing respectively, and cluster the training samples using a clustering algorithm to eliminate the influence of the gaps between clusters on the generation of edge outliers;

[0045] Step 2: Construct a mirror generative adversarial network using a neural network, introduce the idea of energy, and use the single-cluster training data obtained in Step 1 to iteratively train the model to obtain optimal parameters, and add the edge outliers after training to the original dataset;

[0046] Step 3: Build an anomaly detector using a neural network separately, and use the edge outliers and normal points obtained from training all clusters in Step 2 to iteratively train it and test it using the test set.

[0047] Further, according to Figure 1 in the data processing stage, the preprocessing of the data in Step 1 includes the following steps:

[0048] Step 11: Standardize all the data in the dataset to eliminate the influence of dimension on the results. Standardize the features by subtracting the mean and scaling to the standard deviation for each data according to the column attributes, and its transformation function is Formula 1-1, where μ is the mean of the attribute column and σ is its standard deviation

[0049]

[0050] Step 12: Divide the dataset, and divide all the abnormal data into the test set. For the normal data, 80% of the data is split out as the training set, and the remaining 20% of the data is merged with the abnormal data to form the test set, denoted as X train ,X test .

[0051] Step 13: Use the DBSCAN clustering algorithm to cluster the training data X train where m is the number of data clusters. Take each cluster of data and separately execute the subsequent Steps 2 and 3 to eliminate the influence of the gaps between clusters on the generation of outliers. where m is the number of data clusters. Take each cluster of data and separately execute the subsequent Steps 2 and 3 to eliminate the influence of the gaps between clusters on the generation of outliers.

[0052] Further, according to Figure 1 in the edge outlier generation stage and Figure 2 , the steps of training the mirror generation network and combining the energy idea in Step 2 include the following steps:

[0053] Step 21: Use Pytorch to construct a mirror generative adversarial network. Different from the traditional single-generator single-discriminator structure, we add a mirror discriminator and denote its components as G (generator), D (discriminator), Dmirror (Mirror discriminator), where D and D mirror have the same structure, but opposite target outputs.

[0054] Step 22: Introduce the idea of energy and change D and D mirror into the encoder-decoder structure. After encoding and decoding calculations, the original data x i is reconstructed into data y i . x i and y i have the same dimension. Take the mean square error of x i and y i as the energy value, which is directly used for the adversarial training with the generator G.

[0055] Step 23: Take a cluster of data from the preprocessed training set, denoted as where n is the number of training samples in this cluster.

[0056] Step 24: Randomly sample a k-dimensional uniform noise z as the input of the generator G, and output the initial generated samples, denoted as X g ={x g1 , x g2 ,..., x gn}, where n is the number of generated samples.

[0057] Step 25: Use the generated samples X g and obtained in Steps 23 and 24 as the input of D. Through encoding and decoding operations, it is hoped that D outputs a lower energy for the samples in and a higher energy for the samples in X g . That is, through training, the reconstructed samples y of D with respect to l are obtained, such that the mean square error between and y l is smaller; while for the reconstructed samples y gl ∈X g of x gl , the mean square error between x gl and y gl is larger. The objective function of D is as shown in Equation 2-1:

[0058] L D =D(x)+[m - D(G(z))] + Equation 2-1

[0059] Step 26: D mirror and D have the same structure, but the training objective function is the opposite. Use the generated samples X g obtained in Step 23 and in Step 24 as the input of Dmirror For the input of D, through encoding and decoding operations, it is hoped that mirror for X g the output energy of the samples is relatively low, while for the output energy of the samples is high. That is, the target of D is opposite to that of D mirror and D obtains x mirror such that x gl ∈X g the reconstructed sample y gl satisfies that the mean square error between x gl and y gl is relatively small; while for the reconstructed sample y of l it satisfies that the mean square error between y l is relatively large. The objective function of D mirror is shown in Formula 2-2:

[0060]

[0061] Step 27: Resample the k-dimensional uniform noise z * as the input of the generator G, and use the generated samples as the inputs of the trained D and D mirror respectively to obtain the energy values of each generated sample for the two discriminators.

[0062] For a specific generated sample initially located at a random position in the abnormal space during training, due to the opposite training objectives of D and D mirror the output energy values of the two discriminators for this sample are different, where the output energy value of D is relatively large, while the output energy of D mirror for it is relatively low. The generation objective of the generator G is to make the two discriminators produce similar energy values for the same generated point, thereby constraining the generation behavior of G so that the position of the generated point does not deviate too much from the normal point region or coincide with the normal point region, resulting in a large difference in the output energy values of D and D mirror . When and only when the generated point of G is located at the edge position outside the normal points, the output energies of D and D mirror are similar.

[0063] Step 28: Add a heuristic term to the objective function of the generator G to avoid the mode collapse problem, and train the generator G according to the energy values of each generated sample of D and D in Step 26 mirror respectively.

[0064] Due to the phenomenon of mode collapse, the edge points we generate may not cover the entire edge region, thus failing to achieve the enclosure of the normal points. Calculate the mean value of the generated points Maximize the distance of each point from its mean, encourage the generated points to be scattered, and avoid the mode collapse problem. This heuristic term is as shown in Equation 2-3:

[0065]

[0066] The generator G receives D and D mirror For the energy of each generated sample, the goal is to make the two produce similar output values. The mean squared error is used to describe the difference in the output energy values of the two, and Equation 2-3 is added to the objective function of the generator G. The objective function of the generator G can be obtained as shown in Equation 2-4:

[0067] L G = ||D(G(z * )) - D mirror (G(z * ))||2 + λloss d Equation 2-4

[0068] Step 29: Go to Step 24 and continue to train G, D, D mirror , until convergence. That is, for the generated points of G, D and D mirror give similar energy values, indicating that the generated points are at the edge position at this time, and due to the loss d constraint in Step 27, the generated points are evenly distributed at the edge position.

[0069] Step 210: After the model converges, resample the k-dimensional uniform noise z′ as the input of the generator G to generate outlier points at the edge position, add them to the dataset, switch to the next data cluster, and go to Step 23 until all data clusters in the training set are processed. At this time, the training set has reached class balance.

[0070] Furthermore, according to Figure 1 in the outlier detection phase, the steps of training the outlier detector in Step 3 include the following steps:

[0071] Step 31: Use a neural network to construct an outlier detector AD. The dimension of the input layer is the same as that of the samples, the dimension of the output layer is 1, and the Sigmoid function is used as the activation function to map the output value to the 0-1 interval as the outlier score of the input sample. After the training set data is augmented in Step 2 to achieve class balance, use this balanced training set to iteratively train the outlier detector until convergence.

[0072] Step 32: Use the data in the test set as the input of the outlier detector, output the corresponding scores, and according to the threshold threshold, determine whether it is normal or abnormal, as shown in Equation 3-1:

[0073]

[0074] Step 33: Compare and analyze the judgment results and output scores of each data in the test set with the labels, calculate the accuracy rate, and draw the receiver operating characteristic curve as the performance index of the anomaly detector.

[0075] Although the above-described illustrative specific embodiments of the present invention have been described to facilitate the understanding of the present invention by those skilled in the art, it should be clear that the present invention is not limited to the scope of the specific embodiments. For those skilled in the art, as long as various changes are within the spirit and scope of the present invention defined and determined by the appended claims, these changes are obvious, and all inventions and creations using the concept of the present invention are within the scope of protection.

Claims

1. An anomaly detection method based on energy and mirror generative adversarial network, characterized in that: Specifically, it includes the following steps: Step 1: Preprocess the normal data, standardize it to eliminate the influence of dimension on the results; divide the dataset to obtain training samples and test samples, which are used for training and testing the model respectively, and cluster the training samples using a clustering algorithm to eliminate the influence of inter-cluster gaps on the generation of edge outliers; Step 2: Construct a mirror generative adversarial network with a neural network, introduce the idea of energy, and use the single-cluster training data obtained in Step 1 to iteratively train the model to obtain optimal parameters, and add the edge outliers after the training is completed to the original dataset; Step 3: Construct an outlier detector separately with a neural network, use the edge outliers and normal points obtained by training all clusters in Step 2 to iteratively train it, and use the test set to test it; Among them, training the mirror generative network and combining the energy idea in Step 2 includes the following steps: Step 21: Construct an image generation adversarial network. Different from the traditional single generator and single discriminator structure, an image discriminator is added. Denote the generator as G, the discriminator as D, and the image discriminator as D mirror , where D and D mirror have the same structure but opposite target outputs; Step 22: Introduce the idea of energy and change D and D mirror to the encoder-decoder structure, and obtain the reconstructed data y of the original data x through encoding and decoding calculations i The reconstructed data y of i x i and y i are of the same dimension. Use the mean square error of x i and y i as the energy value, which is directly used for the adversarial training with the generator G; Step 23: Take a cluster of data from the preprocessed training set, denoted as where n is the number of training samples in this cluster; Step 24: Randomly sample k-dimensional uniform noise z as the input of the generator G, and output the initial generated sample, denoted as X g ={x g1 , x g2 , …, x gn}, where n is the number of generated samples; Step 25: Use the generated samples X obtained in Steps 23 and 24 g and a cluster of training samples as the input to D. Through the encoding and decoding operations, it is expected that D outputs lower energy for the samples in and higher energy for the samples in X g . The objective function of D is shown in Equation 2-1: L D = D(x) + [m - D(G(z))] + Formula 2-1 Step 26: D mirror has the same structure as D, but the training objective function is the opposite. Take the generated sample X obtained in Step 23 g and in Step 24 as the input of D mirror . Through the encoding and decoding operations, it is hoped that D mirror outputs a lower energy for the samples in X g and a higher energy for the samples in . The objective function of D mirror is shown in Equation 2-2: Step 27: Resample the k-dimensional uniform noise z * As the input of the generator G, the generated samples output are respectively used as the inputs of the trained D and D mirror to obtain the energy values of the two for each generated sample respectively; Step 28: To avoid mode collapse problems, for the generated points calculate their mean Maximize the distance of each point from its mean to encourage the generated points to be spread out, as shown in Equation 2-3: Add formula 2-3 to the objective function of generator G, and according to D and D in step 26 mirror For the energy values of each generated sample, train generator G, and the objective function of generator G is as shown in formula 2-4: L G = ||D(G(z * )) - D mirror (G(z * ))||² + λloss d Equation 2-4 Step 29: Go to Step 24 and continue to train G, D, D mirror , until the model converges; Step 210: After the model converges, resample the k-dimensional uniform noise z′ as the input of the generator G to generate outliers located at the edge positions, add them to the dataset, switch to the next cluster of data, and go to Step 23 until all data clusters in the training set are processed.

2. The anomaly detection method according to claim 1, wherein: The preprocessing of the data in Step 1 includes the following steps: Step 11: Standardize all data in the dataset to eliminate the influence of dimension on the results; Step 12: Divide the dataset. All the abnormal data in it are assigned to the test set. For the normal data, 80% of the data is split out as the training set, and the remaining 20% of the data is merged with the abnormal data to form the test set, denoted as X train , X test ; Step 13: Use a clustering algorithm to cluster the training data X train into m clusters, where m is the number of data clusters. Take each cluster of data and separately execute the subsequent Step 2 and Step 3 to eliminate the influence of the gaps between clusters on the generation of outliers.

3. The anomaly detection method according to claim 1, wherein: The training of the outlier detector in Step 3 includes the following steps: Step 31: Use a neural network to construct an outlier detector AD, with the input layer dimension being the same as the sample and the output layer dimension being 1 to obtain an outlier score in the range of 0-1; Iteratively train the outlier detector with the training set augmented in Step 2 until convergence; Step 32: Use the data in the test set as the input of the anomaly detector, output the corresponding scores, and determine whether it is normal or abnormal according to the threshold threshold, as shown in Equation 3-1:

Citation Information

Patent Citations

  • Audio abnormality detection method based on confrontation network generation

    CN109461458A

  • Internet-of-Things time series data anomaly detection method and system

    CN112148955A