A method, apparatus, device, and storage medium for detecting outliers in a time series

Through the combined method of STL decomposition and Boxplot-sigma, outliers are detected directly from the time series, solving the inefficiency problem of relying on manual annotation and prediction algorithms in the prior art, and achieving simple and easy time series outlier detection.

CN114218009BActive Publication Date: 2025-07-25SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111666924.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-30
Publication Date
2025-07-25
Estimated Expiration
2041-12-30

AI Technical Summary

Technical Problem

When facing complex industrial-grade scenarios, the time series anomaly detection method relies on manual annotation and prediction algorithms, resulting in ineffective detection.

Method used

The time series is decomposed into trend components, periodic components and balance terms, and Boxplot and sigma are used to detect outliers on the balance terms to determine that the outliers in the balance terms are the target value.

Benefits of technology

Without manual labeling of historical data and prediction algorithms, the time series outliers detection process is simplified and the detection efficiency and accuracy are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114218009B_ABST
    Figure CN114218009B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, device, equipment and storage medium for detecting outliers in a time series. The method includes: obtaining the time series that needs to detect outliers currently as the sequence to be detected, and decomposing the sequence to be detected into a trend component, a periodic component and a remainder by using the STL decomposition algorithm; detecting outliers in the remainder by using the combination of Boxplot and sigma to obtain the outliers in the remainder, and determining the outliers in the remainder as target values; determining the values in the sequence to be detected corresponding to the target values as the outliers in the sequence to be detected, so as to realize the detection of outliers in the time series. It can be seen that this application does not need to use a classification algorithm or a prediction algorithm, and more importantly, does not need to manually label historical data, thus making the detection of outliers in the time series simple and easy to implement.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of anomaly detection, and more specifically, to a method, apparatus, device and storage medium for detecting outliers in time series. Background Art

[0002] Anomaly detection is one of the most commonly studied directions in current time series data analysis. It is defined as the process of identifying abnormal events or behaviors from normal time series. The problem of anomaly detection in time series is usually formulated as finding abnormal data points relative to certain standards or regular signals. There are usually multiple types of anomaly points. From a business perspective, usually only the most important ones are focused on, such as unexpected peaks, unexpected troughs, and trend mutations. Generally speaking, many anomalies can be judged manually; however, when the business combination is complex and the time series scale becomes larger, relying on traditional manual and simple absolute value algorithms such as year-on-year and month-on-month becomes inadequate. Therefore, it is particularly important to systematically understand time series anomaly detection methods when facing various industrial scenarios.

[0003] Basically, anomaly detection algorithms are divided into two categories. The first category uses classification algorithms to label each time point as abnormal / non-abnormal, and then classifies each time point through the classification algorithm. The disadvantage is that it requires manual annotation of the abnormality / non-abnormality of historical data and has an obvious dependence on human judgment. The second category uses prediction algorithms to predict the signal of a certain point, and then tests the difference between the actual value of this point and the predicted value, and then observes whether the difference is sufficient to regard it as an anomaly. The disadvantage is that it depends on the accuracy of the budget algorithm. Summary of the Invention

[0004] The purpose of the present invention is to provide a method, apparatus, device and storage medium for detecting outliers in time series, which does not require the use of classification algorithms or prediction algorithms, and does not require manual annotation of historical data, so that the detection of outliers in time series can be simply and easily implemented.

[0005] To achieve the above purpose, the present invention provides the following technical solutions:

[0006] A method for detecting outliers in time series, comprising:

[0007] Obtain the time series to be detected for outlier detection as the sequence to be detected, and use the STL decomposition algorithm to decompose the sequence to be detected into a trend component, a periodic component, and a remainder;

[0008] Use Boxplot and sigma combination to detect outliers in the remainder to obtain the outliers in the remainder, and determine the outliers in the remainder as the target values;

[0009] Determine that the value corresponding to the target value in the sequence to be detected is an outlier in the sequence to be detected, so as to realize the detection of outliers in the time series.

[0010] Preferably, use Boxplot and sigma in combination to detect outliers in the remainder to obtain the outliers in the remainder, including:

[0011] Use Boxplot to process the remainder to obtain the corresponding maximum observed value and minimum observed value, and use sigma to process the remainder to obtain the corresponding sigma value;

[0012] Based on the maximum observed value, the minimum observed value and the sigma value, obtain the corresponding data range, and determine that the values in the remainder that are not within the data range are the outliers in the remainder.

[0013] Preferably, obtaining the corresponding data range based on the maximum observed value, the minimum observed value and the sigma value includes:

[0014] Obtain the data range according to the following formula:

[0015] low = 3σ * ratio + min * (1 - ratio),

[0016] hight = 3σ * ratio + max * (1 - ratio);

[0017] Where σ is the sigma value, min is the minimum observed value, max is the maximum observed value, ratio is the weight coefficient, low is the minimum value in the data range, and hight is the maximum value in the data range.

[0018] Preferably, before using Boxplot and sigma in combination to detect outliers in the remainder to obtain the outliers in the remainder, it further includes:

[0019] If the number of outliers detected when detecting outliers in a preset number of time series before the current moment is greater than the number threshold, then use 4sigma as the sigma used for detecting outliers in the time series after the current moment, otherwise use 3sigma as the sigma used for detecting outliers in the time series after the current moment.

[0020] Preferably, after determining that the value corresponding to the target value in the sequence to be detected is an outlier in the sequence to be detected, it further includes:

[0021] Remove the outliers from the sequence to be detected, and use the missing value filling method to obtain the normal values corresponding to the removed outliers, and add the obtained normal values to the sequence to be detected.

[0022] Preferably, using the missing value filling method to obtain the normal values corresponding to the removed outliers includes:

[0023] Obtain the average value of the other values in the sequence to be detected except the outliers, and use it as the normal value corresponding to the removed outliers.

[0024] Preferably, after adding the obtained normal values to the sequence to be detected, it further includes:

[0025] Predict the pedestrian flow data in a specified area at any time after the current time based on the sequence to be detected, and output the any time and the predicted pedestrian flow data at that any time; wherein, the time series is the pedestrian flow data at different times in the specified area.

[0026] A time series outlier detection device includes:

[0027] A decomposition module for: obtaining the time series to be detected for outlier detection currently as the sequence to be detected, and decomposing the sequence to be detected into a trend component, a periodic component, and a remainder using the STL decomposition algorithm;

[0028] A detection module for: using Boxplot and sigma in combination to detect outliers in the remainder to obtain the outliers in the remainder, and determining the outliers in the remainder as target values;

[0029] A determination module for: determining the values in the sequence to be detected corresponding to the target values as the outliers in the sequence to be detected, so as to implement the outlier detection of the time series.

[0030] A time series outlier detection device includes:

[0031] A memory for storing a computer program;

[0032] A processor for implementing the steps of the time series outlier detection method as described in any one of the above when executing the computer program.

[0033] A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the time series outlier detection method as described in any one of the above are implemented.

[0034] The present invention provides a method, apparatus, device, and storage medium for detecting outliers in a time series. The method includes: obtaining the time series for which outlier detection needs to be implemented currently as the sequence to be detected, and decomposing the sequence to be detected into a trend component, a periodic component, and a remainder using the STL decomposition algorithm; performing outlier detection on the remainder using the combination of Boxplot and sigma to obtain the outliers in the remainder, and determining the outliers in the remainder as target values; determining the values in the sequence to be detected corresponding to the target values as the outliers in the sequence to be detected, so as to implement the outlier detection of the time series. This application uses the STL decomposition algorithm to decompose the time series to be detected into a trend component, a periodic component, and a remainder, and then uses the combination criterion of Boxplot and sigma to perform outlier detection on the remainder. The values of the time series corresponding to the detected outliers in the remainder are the outliers, so as to implement the detection of outliers in the time series. It can be seen that this application does not need to use classification algorithms or prediction algorithms, and does not need to perform manual annotation on historical data, thus making the outlier detection of time series simple and easy to implement. Description of the Drawings

[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.

[0036] Figure 1 It is a flowchart of a method for detecting outliers in a time series provided by an embodiment of the present invention;

[0037] Figure 2 It is a schematic diagram of the STL inner loop process in a method for detecting outliers in a time series provided by an embodiment of the present invention;

[0038] Figure 3 It is a Boxplot box plot in a method for detecting outliers in a time series provided by an embodiment of the present invention;

[0039] Figure 4 It is a schematic diagram when the Boxplot box plot in a method for detecting outliers in a time series provided by an embodiment of the present invention is applied to outlier detection;

[0040] Figure 5 It is an STL time series decomposition diagram in a method for detecting outliers in a time series provided by an embodiment of the present invention;

[0041] Figure 6Schematic diagram for outlier detection of the remainder using the criterion of combining Boxplot and 3sigma in a time series outlier detection method provided by an embodiment of the present invention;

[0042] Figure 7 Schematic diagram showing that the value of the time series corresponding to the outlier of an item in a time series outlier detection method provided by an embodiment of the present invention is the outlier;

[0043] Figure 8 Schematic structural diagram of a time series outlier detection device provided by an embodiment of the present invention. Detailed implementation manners

[0044] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0045] Please refer to Figure 1 , which shows a flowchart of a time series outlier detection method provided by an embodiment of the present invention. Specifically, it may include:

[0046] S11: Obtain the time series to be currently detected for outlier detection as the sequence to be detected, and use the STL decomposition algorithm to decompose the sequence to be detected into a trend component, a periodic component, and a remainder.

[0047] Among them, a time series (or dynamic series) refers to a series formed by arranging the values of the same statistical indicator in the order of their occurrence time; the main purpose of time series analysis is to predict the future based on existing historical data; according to different observation times, the time in the time series can be years, quarters, months, or any other time form; in particular, most of the data in economic data is given in the form of time series.

[0048] S12: Use the combination of Boxplot and sigma to detect outliers in the remainder to obtain the outliers in the remainder, and determine the outliers in the remainder as the target values.

[0049] S13: Determine the values in the sequence to be detected corresponding to the target values as the outliers in the sequence to be detected, so as to achieve outlier detection of the time series.

[0050] For any time series that needs to implement outlier detection, in the embodiments of the present application, it can be referred to as the sequence to be detected; the STL (Seasonal-Trend decomposition procedure based on Loess) decomposition algorithm is used to first decompose the sequence to be detected into a trend component, a periodic component, and a remainder, and then the remainder is detected for outliers using the combination of Boxplot and sigma. Thus, after detecting the outliers in the remainder, it is possible to determine that the value in the sequence to be detected corresponding to the outliers in the remainder is the outlier in the sequence to be detected, thereby realizing outlier detection in the time series. Among them, the STL decomposition algorithm is a common algorithm in time series decomposition. Based on LOESS (locally weighted regression, a non-parametric learning algorithm), the data at a certain moment is decomposed into a trend component (trend component), a periodic component (seasonal component), and a remainder (remainder component); Boxplot is a box plot, also known as a box-and-whisker plot, a box diagram, or a box-line plot, which is a statistical chart used to display the dispersion of a set of data and gets its name because of its shape like a box; sigma is used to quickly calculate the normal distribution data with known mean and standard deviation.

[0051] The present application uses the STL decomposition algorithm to decompose the time series to be detected into a trend component, a periodic component, and a remainder, and then uses the combination criterion of Boxplot and sigma to detect outliers in the remainder. The value of the time series corresponding to the detected outliers in the remainder is the outlier, so as to realize the detection of outliers in the time series. It can be seen that the present application does not need to use a classification algorithm or a prediction algorithm, and does not need to manually label historical data, so that the detection of time series outliers can be easily implemented.

[0052] It should be noted that the STL decomposition algorithm is an algorithm in time series decomposition. Based on LOESS, the data at a certain moment is decomposed into a trend component (trend component), a periodic component (seasonal component), and a remainder (remainder component), which is expressed by the following formula:

[0053] Y v =T v +S v +R v v = 1, 2, 3,..., N

[0054] Among them, Y v , T v , S v , R vrespectively represent data, trend component, periodic component, and remainder.

[0055] STL consists of two loop mechanisms, with an inner loop nested within an outer loop; the inner loop mainly performs trend fitting and calculation of the periodic component.

[0056] The meanings of the parameters are as follows: are the trend component and periodic component at the end of the (k - 1)-th pass in the inner loop. Initially, n (i) is the number of inner loop iterations; n (o) is the number of outer loop iterations; n (p) is the number of samples in one period; n (s) is the seasonal smoothing parameter of LOESS in Step 2; as n (s) increases, each periodic subsequence becomes smoother; usually, n (s) is set to an odd number and is expected to be at least 7; n (l) is the low-pass filtering smoothing parameter of LOESS in Step 3; n (l) is usually considered to be greater than or equal to the smallest odd number of n (p) ; this setting helps prevent the trend and seasonal terms from having the same changes in the data; n (t) is the trend smoothing parameter of LOESS in Step 6; as n (t) increases, the trend term T v extracts less variation from Y v and also becomes smoother; usually, n (t) is set to an odd number; d is the highest power of the locally weighted regression function LOESS; if the underlying pattern of the data has a slow bend, then d = 1 is reasonable; however, if there are a large number of bends, such as many peaks and valleys, then d = 2 is a better choice; q is the number of q data points adjacent to the calculated data point; the sample points at the same position in each period form a subsequence, and it is easy to know that there are n (p ) such subsequences, which are called cycle-subseries.

[0057] As Figure 2 shown, the inner loop can be mainly divided into the following 6 steps:

[0058] Step 1: Detrending, subtracting the trend component of the previous round's result,

[0059] Step 2: Cycle-subseries smoothing, using LOESS (q = n n(s), d) Smooth each subsequence and extend it by one period forward and backward; the smoothed results form a temporary periodic component, denoted as

[0060] Step 3: Low-Pass Filtering of the Smoothed Periodic Subsequences. For the result sequence of the previous step perform moving averages of lengths n (p) , n (p) , and 3 in sequence, and then perform LOESS (q = n n(l) , d) smoothing to obtain the result sequence which is equivalent to extracting the low-pass of the periodic subsequence;

[0061] Step 4: Detrending of the Smoothed Cycle-subseries, the purpose of which is to prevent the low-pass from affecting the periodic component;

[0062] Step 5: Deseasonalizing, subtract the periodic component,

[0063] Step 6: Trend Smoothing. For the sequence after removing the period, perform LOESS (q = n n(t) , d) regression to obtain the trend component

[0064] Steps 2, 3, and 4 in the inner loop are seasonal smoothing, and Step 6 is trend smoothing.

[0065] The outer loop is mainly used to adjust the robust weights. If there are outliers in the data sequence, the remainder will be relatively large; assume the estimated values of the trend component T v and the periodic component S v after the first execution of the inner loop, then the remainder is equal to:

[0066] R v = Y v - T v - S v

[0067] Define a robust weight for each data point Y v The robust weight reflects the extremity of R v ; outliers in the data will have a very large |R v |, and in this case, the weight should be reduced or set to 0.

[0068] Definition:

[0069] h = 6 * median(|R v |)

[0070] For the data point at position v, its robustness weight is

[0071] ρ v = B(|R v | / h)

[0072] where the B function is a quadratic function:

[0073]

[0074] Then, in the inner loop of each iteration, when performing LOESS regression in Step 2 and Step 6, the neighborhood weight needs to be multiplied by the robustness weight ρ v , to reduce the influence of outliers on the regression.

[0075] The specific process of STL can be as follows:

[0076] Outer loop:

[0077] Calculate the robustness weight;

[0078] Inner loop:

[0079] Step 1 Detrend;

[0080] Step 2 Smooth the periodic subsequence;

[0081] Step 3 Low-pass filter the periodic subsequence;

[0082] Step 4 Remove the trend of the smoothed periodic subsequence;

[0083] Step 5 Remove the period;

[0084] Step 6 Smooth the trend;

[0085] To make the algorithm have sufficient robustness, an inner loop and an outer loop are designed; in particular, when n (i) is large enough, the trend component and the period component have converged at the end of the inner loop; if there are no obvious outliers in the time series data, n (o) can be set to 0.

[0086] A time series outlier detection method provided by an embodiment of the present invention uses Boxplot and sigma in combination to detect outliers in the remainder, and may include:

[0087] The remainder is processed using Boxplot to obtain the corresponding maximum and minimum observed values, and the remainder is processed using sigma to obtain the corresponding sigma value;

[0088] Based on the maximum observed value, minimum observed value, and sigma value, the corresponding data range is obtained, and the values in the remainder that are not within the data range are determined as the outliers in the remainder.

[0089] A time series outlier detection method provided by an embodiment of the present invention, based on the maximum observed value, minimum observed value, and sigma value to obtain the corresponding data range, may include:

[0090] The data range is obtained according to the following formula:

[0091] low = 3σ * ratio + min * (1 - ratio),

[0092] hight = 3σ * ratio + max * (1 - ratio);

[0093] Where σ is the sigma value, min is the minimum observed value, max is the maximum observed value, ratio is the weight coefficient, low is the minimum value in the data range, and hight is the maximum value in the data range.

[0094] Since using sigma in outlier detection is easily affected by individual outliers, resulting in poor detection effects, therefore, in order to improve the accuracy of time series outlier detection, the embodiments of the present application can combine Boxplot with 3 - sigma to determine the final data range; and, the embodiments of the present application combine sigma with Boxplot, and rationally allocate the importance of the two through the weight coefficient ratio, which can effectively detect outliers in the time series. Among them, the specific value of ratio can be set according to actual needs, and in the embodiments of the present application, it can be preferably set to 0.3.

[0095] Before using Boxplot and sigma in combination to detect outliers in the remainder for a time series outlier detection method provided by an embodiment of the present invention, it may further include:

[0096] If the number of outliers detected when detecting outliers in a preset number of time series before the current moment is greater than the number threshold, then 4sigma is used as the sigma for detecting outliers in the time series after the current moment, otherwise 3sigma is used as the sigma for detecting outliers in the time series after the current moment.

[0097] Among them, the preset number of time series and the preset quantity threshold can both be determined according to actual needs. If the number of outliers in the preset number of time series detected closest to the current moment before the current moment is relatively large (greater than the quantity threshold), it indicates that the standard for time series outlier detection may be too strict. Therefore, 4sigma is used as the sigma for outlier detection in the time series after the current moment. Otherwise, 3sigma is used as the sigma for outlier detection in the time series after the current moment, thereby increasing the flexibility and accuracy of time series detection.

[0098] In addition, in the embodiments of the present application, 3sigma is preferably used as the sigma for outlier detection in the time series after the current moment. The 3sigma criterion is also known as the 68-95-99.7 principle, which is used to quickly estimate the normal distribution data with known mean and standard deviation. In statistics, the empirical rule is the percentage within one standard deviation, two standard deviations, and three standard deviations from the mean in a normal distribution. The more accurate numbers are 68.27%, 95.45%, and 99.73%. The 3-sigma criterion is often used in outlier detection, and values greater than 3-sigma are considered outliers.

[0099] A Boxplot consists of five numerical points, namely the minimum value (i.e., the minimum observed value, min), the lower quartile (Q1), the median, the upper quartile (Q3), and the maximum value (i.e., the maximum observed value, max); the mean can also be added to the box plot. As Figure 3 shown, the lower quartile, median, and upper quartile form a "box with compartments", and an extension line is established between the upper quartile and the maximum value, and this extension line becomes the "whisker". Since there are always various "dirty data" in real-world data, which are also called "outliers", in order not to cause the deviation of the overall characteristics due to these few outlier data, these outliers need to be exported separately, and the two ends of the whisker in the box plot are modified to the minimum observed value and the maximum observed value. Among them, the maximum (minimum) observed value is set to be 1.5 IQRs (interquartile range) away from the quartile value, that is, IQR = Q3 - Q1, which is also the difference between the upper quartile and the lower quartile, that is, the length of the box; the minimum observed value is min = Q1 - 1.5 * IQR. If there are outliers smaller than the minimum observed value, the lower limit of the whisker is the minimum observed value, and the outliers are exported separately as points. If there is no number smaller than the minimum observed value, the lower limit of the whisker is the minimum value; the maximum observed value is max = Q3 + 1.5 * IQR. If there are outliers larger than the maximum observed value, the upper limit of the whisker is the maximum observed value, and the outliers are exported separately as points. If there is no number larger than the maximum observed value, the upper limit of the whisker is the maximum value.

[0100] As Figure 4 shown, through the box plot, when analyzing data, the box plot can effectively help identify the characteristics of the data: visually identify outliers in the dataset (check for outliers); judge the data dispersion degree and bias of the dataset (observe the length of the box, the shape of the upper and lower compartments, and the length of the whiskers).

[0101] A time series outlier detection method provided by an embodiment of the present invention, after determining that the value corresponding to the target value in the to-be-detected sequence is an outlier in the to-be-detected sequence, may further include:

[0102] Removing the outlier from the to-be-detected sequence, obtaining the normal value corresponding to the removed outlier by using a missing value filling method, and adding the obtained normal value to the to-be-detected sequence.

[0103] Obtaining the normal value corresponding to the removed outlier by using a missing value filling method may include:

[0104] Obtaining the average value of other values in the to-be-detected sequence except the outlier as the normal value corresponding to the removed outlier.

[0105] For the convenience of subsequent analysis of the time series in an embodiment of the present application, after determining the outlier in the to-be-detected sequence, the outlier can be removed from the to-be-detected sequence. At this time, the position where the outlier was located before being removed becomes a missing value, and then the corresponding value is obtained from the to-be-detected sequence in the way of average value or maximum value or minimum value to implement missing value filling; among them, in the embodiment of the present application, the average value of other values except the outlier in the to-be-detected sequence is preferentially used to implement missing value filling.

[0106] A time series outlier detection method provided by an embodiment of the present invention, after adding the obtained normal value to the to-be-detected sequence, may further include:

[0107] Predicting the pedestrian flow data in any specified area after the current moment based on the to-be-detected sequence, and outputting the arbitrary moment and the predicted pedestrian flow data at the arbitrary moment; wherein, the time series is the pedestrian flow data at different times in the specified area.

[0108] It should be noted that anomaly detection is widely used in many fields of industry, such as quantitative trading, network security detection, autonomous driving vehicles, and daily maintenance of large industrial equipment. In the embodiments of the present application, the time series anomaly detection method is applied to the scenario of pedestrian flow prediction. Then, for a specified area (such as a subway station, an intersection, etc.), monitoring is carried out to obtain the number of people at different times in the specified area as the corresponding pedestrian flow data. After that, after obtaining the pedestrian flow data at different times in the specified area, the time series anomaly detection method is used to detect the outliers in the pedestrian flow data. Then, after performing operations such as removing and filling the corresponding outliers, the pedestrian flow data obtained after the final processing is used to predict the pedestrian flow data (i.e., the number of people) in the specified area at a certain future moment, thereby effectively improving the accuracy of pedestrian flow prediction.

[0109] In the present application, the STL decomposition of the time series can obtain the corresponding results as Figure 5 shown, Figure 5 where the first item is the data item, the second item is the trend component, the third item is the periodic component, and the last item is the remainder; the use of the criterion of combining Boxplot and 3sigma to detect outliers in the remainder can be as Figure 6 shown, Figure 6 where the horizontal lines between 50 and 100 on the vertical axis and between -100 and -50 on the vertical axis are the thresholds of 4sigma, and the horizontal lines at 50 and -50 on the vertical axis are the thresholds of 3sigma; the values of the time series corresponding to the outliers in the remainder are the outliers, as Figure 7 shown.

[0110] An embodiment of the present invention also provides a time series anomaly detection device, as Figure 8 shown, which specifically may include:

[0111] A decomposition module 11, configured to: obtain the time series to be detected for anomaly detection currently as the sequence to be detected, and use the STL decomposition algorithm to decompose the sequence to be detected into a trend component, a periodic component, and a remainder;

[0112] A detection module 12, configured to: use Boxplot and sigma combination to detect outliers in the remainder to obtain the outliers in the remainder, and determine the outliers in the remainder as the target values;

[0113] A determination module 13, configured to: determine the values in the sequence to be detected corresponding to the target values as the outliers in the sequence to be detected, so as to implement the anomaly detection of the time series.

[0114] An embodiment of the present invention also provides a time series anomaly detection device, which may include:

[0115] A memory, configured to store a computer program;

[0116] A processor, which is configured to implement the steps of the time series outlier detection method according to any one of the above when executing a computer program.

[0117] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the time series outlier detection method as described above are implemented.

[0118] It should be noted that for the description of the relevant parts in a time series outlier detection device, equipment and storage medium provided by an embodiment of the present invention, please refer to the detailed description of the corresponding parts in a time series outlier detection method provided by an embodiment of the present invention, which will not be elaborated here. In addition, for the parts in the above technical solution provided by an embodiment of the present invention that are consistent with the implementation principles of the corresponding technical solutions in the prior art, no detailed description is given to avoid excessive elaboration.

[0119] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for detecting outliers in a time series, characterized in that, include: The time series for which outlier detection is currently required is obtained as a sequence to be detected, and the sequence to be detected is decomposed into a trend component, a period component and a remainder by using an STL decomposition algorithm; Use Boxplot and sigma criteria to perform outlier detection on the remainder to obtain outliers in the remainder, and determine the outliers in the remainder as target values; Determine that the value in the sequence to be detected corresponding to the target value is an abnormal value in the sequence to be detected, so as to realize abnormal value detection of the time series; Among them, using Boxplot and sigma criteria to perform outlier detection on the remainder to obtain outliers in the remainder includes: The remainder is processed using Boxplot to obtain the corresponding maximum observation value and minimum observation value, and the remainder is processed to obtain the corresponding sigma value; a corresponding data range is obtained based on the maximum observation value, the minimum observation value and the sigma value, and a value in the remainder that is not within the data range is determined to be an abnormal value in the remainder; After determining that the value in the sequence to be detected corresponding to the target value is an abnormal value in the sequence to be detected, the method further includes: Eliminate the abnormal values in the sequence to be detected, and use the missing value filling method to obtain the normal values corresponding to the eliminated abnormal values, and add the obtained normal values to the sequence to be detected; After adding the obtained normal value to the sequence to be detected, the method further includes: Predicting the flow of people in a specified area at any time after the current time based on the sequence to be detected, and outputting the predicted flow of people at any time; wherein the time series is the flow of people at different times in the specified area; The corresponding data range is obtained based on the maximum observed value, the minimum observed value and the sigma value, including: The data range is obtained according to the following formula: , ; wherein, is the said sigma value, is the said minimum observed value, is the said maximum observed value, is the weight coefficient, is the minimum value in the said data range, is the maximum value in the said data range.

2. The method according to claim 1, characterized in that, Before using Boxplot and sigma criteria to perform outlier detection on the remainder to obtain outliers in the remainder, the method further includes: If the number of detected outliers is greater than the quantity threshold when outlier detection is performed on a preset time series before the current moment, 4sigma is used in the sigma criterion used for outlier detection in the time series after the current moment, otherwise 3sigma is used in the sigma criterion used for outlier detection in the time series after the current moment.

3. The method according to claim 1, characterized in that, The normal value corresponding to the removed abnormal value is obtained by using the missing value filling method, including: The average value of other values in the sequence to be detected except the abnormal value is obtained as the normal value corresponding to the eliminated abnormal value.

4. A time series outlier detection device, characterized in that, include: A decomposition module is used to: obtain the time series for which outlier detection is currently required as a sequence to be detected, and decompose the sequence to be detected into a trend component, a periodic component and a remainder using an STL decomposition algorithm; A detection module is used to: perform outlier detection on the remainder using Boxplot and sigma criteria to obtain outliers in the remainder, and determine the outliers in the remainder as target values; A determination module, configured to: determine that the value corresponding to the target value in the sequence to be detected is an outlier in the sequence to be detected, so as to implement outlier detection of the time series; Wherein, the detection module is specifically configured to: Use Boxplot to process the remainder to obtain corresponding maximum and minimum observed values, process the remainder to obtain a corresponding sigma value; obtain a corresponding data range based on the maximum observed value, the minimum observed value, and the sigma value, and determine that the values in the remainder that are not within the data range are outliers in the remainder; A time series outlier detection device, specifically configured to: Remove the outliers in the sequence to be detected, use a missing value filling method to obtain the normal values corresponding to the removed outliers, and add the obtained normal values to the sequence to be detected; A time series outlier detection device, specifically configured to: Predict the pedestrian flow data within a specified area at any time after the current moment based on the sequence to be detected, and output the any time and the predicted pedestrian flow data at the any time; wherein, the time series is the pedestrian flow data at different times within the specified area; The detection module is specifically configured to: Obtain the data range according to the following formula: , ; wherein, is the sigma value, is the minimum observed value, is the maximum observed value, is the weight coefficient, is the minimum value in the data range, is the maximum value in the data range.

5. A time series outlier detection device, characterized in that, Including: A memory, configured to store a computer program; A processor, configured to implement the steps of the time series outlier detection method according to any one of claims 1 to 3 when executing the computer program.

6. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the time series outlier detection method according to any one of claims 1 to 3 are implemented.

Citation Information

Patent Citations

  • Method for detecting and processing daily maximum load abnormal data of distribution room transformer

    CN111444168A

  • Household photovoltaic anomaly identification method based on intelligent electric meter and geographic information grouping

    CN112434822A