Method for optimizing model parameters, and method and device for detecting anomaly in time series data
By constructing source domain graph neural networks and target domain graph neural networks and optimizing model parameters using attribute similarity matrices, the model adaptability problem of multivariate temporal anomaly detection systems in cross-domain deployment is solved, and the detection performance of the target domain is improved.
Patent Information
- Application Number
- CN202210784623.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-05
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2042-07-05
AI Technical Summary
Existing multivariate temporal anomaly detection systems cannot directly apply models trained in the source domain to the target domain when upgrading the system or deploying across platforms, which requires retraining the model in the target domain, increasing costs and difficulty.
By constructing a source domain graph neural network, using the source domain embedding vector to generate an attribute similarity matrix, updating the target domain embedding vector, constructing a target domain graph neural network, and optimizing the model parameters on the target domain sample data, the detection performance is improved.
This approach improves the performance of anomaly detection in the target domain, leverages the superior data characteristics of the source domain, reduces the need for retraining the model, and enhances detection efficiency and accuracy.
Smart Images

Figure CN115130661B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of artificial intelligence, and in particular to a method for optimizing model parameters, and a method and device for detecting anomalies in time series data. Background Art
[0002] Multivariate time series (MTS) analysis refers to the study of multivariate time series. Many problems involve observing not just a single process but multiple processes simultaneously. In multivariate time series data, outliers are typically rare. To accurately label anomalies, manual insertion of anomalies into the system is often necessary, resulting in high labeling costs. Therefore, unsupervised multivariate time series anomaly detection is a highly practical and research-oriented problem.
[0003] Graph deviation networks (GDNs) have been proposed for anomaly detection in multivariate time series. GDNs introduce the concept of graphs, constructing a graph structure based on multivariate time series data, with each attribute as a node. Connections are generated by calculating the similarity of the embedding vectors between attributes. They construct prediction tasks for future values and use the error between the predicted value and the true value as an anomaly score to identify anomalies.
[0004] The inventors have discovered that existing solutions present at least the following issues: Multivariate time series anomaly detection systems often face system upgrades or cross-platform deployments, which necessitates migration from the source domain to the target domain. However, the upgrade process for multivariate time series systems typically increases the number of attributes, making it impossible to directly apply models trained in the source domain to the target domain. Instead, the model must be retrained on the target domain. Currently, no effective solutions have been proposed to address these issues. Summary of the Invention
[0005] The present invention provides a method for optimizing model parameters and a method and apparatus for detecting anomalies in time series data. This application can improve the performance of anomaly detection in target domain data by collaborating with source domain attributes. Furthermore, by updating the source domain detection network, detection performance in the target domain can be further improved.
[0006] In view of this, the present application provides a method for optimizing model parameters, including:
[0007] Obtain source domain sample data and target domain sample data, wherein the source domain sample data includes time series data of Ns source domain attributes, and the target domain sample data includes time series data of Nt target domain attributes, where both Ns and Nt are integers greater than 1;
[0008] Construct a source domain graph neural network based on the Ns source domain embedding vectors corresponding to the Ns source domain attributes, where the source domain embedding vectors have a one-to-one correspondence with the source domain attributes;
[0009] Based on the source domain sample data, the Ns source domain embedding vectors and the model parameters of the source domain detection network are updated, where the source domain detection network includes a source domain graph neural network;
[0010] Generate an attribute similarity matrix based on the source domain sample data and the target domain sample data, where the attribute similarity matrix is used to describe the similarity between each source domain attribute and each target domain attribute;
[0011] Generate Nt target domain embedding vectors based on the attribute similarity matrix and the updated Ns source domain embedding vectors, where the target domain embedding vectors have a one-to-one correspondence with the target domain attributes;
[0012] According to the Nt target domain embedding vectors, a target domain graph neural network is constructed, where the model parameters of the target domain graph neural network adopt the updated model parameters of the source domain graph neural network;
[0013] According to the target domain sample data, the Nt target domain embedding vectors and the model parameters of the target domain detection network are updated, where the target domain detection network includes a target domain graph neural network.
[0014] Another aspect of the present application provides a method for optimizing model parameters, comprising:
[0015] Acquire the data to be detected, where the data to be detected includes time series data of Nt target domain attributes, and the time series data of each target domain attribute includes data at T moments, where Nt and T are both integers greater than 1;
[0016] Based on the data to be detected, obtain Nt predicted data values corresponding to the target time through the target domain detection network, where the target domain detection network is trained using the above method;
[0017] Get Nt actual data values corresponding to the target time;
[0018] Based on Nt actual data values and Nt predicted data values, calculate the anomaly score corresponding to the target time;
[0019] If the anomaly score corresponding to the target moment is greater than or equal to the anomaly score threshold, the target moment is determined to be a data anomaly moment.
[0020] Another aspect of the present application provides a parameter optimization device, comprising:
[0021] An acquisition module is used to acquire source domain sample data and target domain sample data, wherein the source domain sample data includes time series data of Ns source domain attributes, and the target domain sample data includes time series data of Nt target domain attributes, where Ns and Nt are both integers greater than 1;
[0022] A construction module is used to construct a source domain graph neural network based on Ns source domain embedding vectors corresponding to the Ns source domain attributes, wherein the source domain embedding vectors have a one-to-one correspondence with the source domain attributes;
[0023] A training module is used to update Ns source domain embedding vectors and model parameters of the source domain detection network based on the source domain sample data, wherein the source domain detection network includes a source domain graph neural network;
[0024] A generation module is used to generate an attribute similarity matrix based on the source domain sample data and the target domain sample data, wherein the attribute similarity matrix is used to describe the similarity between each source domain attribute and each target domain attribute;
[0025] The generation module is further configured to generate Nt target domain embedding vectors based on the attribute similarity matrix and the updated Ns source domain embedding vectors, wherein the target domain embedding vectors have a one-to-one correspondence with the target domain attributes;
[0026] The construction module is further used to construct a target domain graph neural network based on the Nt target domain embedding vectors, wherein the model parameters of the target domain graph neural network adopt the updated model parameters of the source domain graph neural network;
[0027] The training module is also used to update the Nt target domain embedding vectors and the model parameters of the target domain detection network based on the target domain sample data, wherein the target domain detection network includes a target domain graph neural network.
[0028] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0029] The construction module is specifically used to calculate (Ns-1) vector similarities for each source domain attribute based on the source domain embedding vector corresponding to the source domain attribute and the source domain embedding vectors corresponding to the remaining source domain attributes, where the remaining source domain attributes are the (Ns-1) source domain attributes remaining in the Ns source domain attributes except the source domain attribute;
[0030] For each source domain attribute, determine the largest Ks vector similarities from (Ns-1) vector similarities, where Ks is an integer greater than or equal to 1 and less than (Ns-1);
[0031] For each source domain attribute, determine Ks source domain attributes that have a connection relationship with the source domain attribute based on the largest Ks vector similarities, wherein the vector similarities in the Ks vector similarities have a one-to-one correspondence with the source domain attributes in the Ks source domain attributes;
[0032] According to each source domain attribute and Ks source domain attributes that have a connection relationship with each source domain attribute, a source domain graph structure is constructed, wherein the source domain graph structure includes source domain nodes and source domain edges. The source domain nodes are used to represent source domain attributes, and the source domain edges are used to represent the connection relationship between different source domain attributes;
[0033] According to the source domain graph structure and Ns source domain embedding vectors, a source domain graph neural network is constructed.
[0034] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0035] The construction module is specifically used to calculate (Nt-1) vector similarities for each target domain attribute based on the target domain embedding vector corresponding to the target domain attribute and the target domain embedding vectors corresponding to the remaining target domain attributes, where the remaining target domain attributes are the (Nt-1) target domain attributes remaining in the Nt target domain attributes except the target domain attribute;
[0036] For each target domain attribute, determine the largest Kt vector similarities from the (Nt-1) vector similarities, where Kt is an integer greater than or equal to 1 and less than (Nt-1);
[0037] For each target domain attribute, determine Kt target domain attributes that have a connection relationship with the target domain attribute based on the largest Kt vector similarities, wherein the vector similarities in the Kt vector similarities have a one-to-one correspondence with the target domain attributes in the Kt target domain attributes;
[0038] According to each target domain attribute and Kt target domain attributes that have a connection relationship with each target domain attribute, a target domain graph structure is constructed, wherein the target domain graph structure includes target domain nodes and target domain edges. The target domain nodes are used to represent the target domain attributes, and the target domain edges are used to represent the connection relationship between different target domain attributes.
[0039] According to the target domain graph structure and Nt target domain embedding vectors, a target domain graph neural network is constructed.
[0040] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0041] The training module is specifically used to obtain Ns source domain aggregated feature vectors corresponding to the first moment through the source domain graph neural network based on the source domain sample data, wherein the source domain aggregated feature vectors have a one-to-one correspondence with the source domain attributes. The source domain graph neural network belongs to the source domain detection network;
[0042] Based on the Ns source domain aggregated feature vectors and the Ns source domain embedding vectors, obtaining Ns source domain prediction data values corresponding to the first moment through a first fully connected layer included in the source domain detection network, where the source domain prediction data values have a one-to-one correspondence with the source domain attributes;
[0043] Constructing a first loss function based on Ns source domain predicted data values and Ns source domain actual data values corresponding to the first moment, wherein the Ns source domain actual data values are derived from the source domain sample data;
[0044] Based on the first loss function, update the Ns source domain embedding vectors;
[0045] Based on the first loss function, the model parameters of the source domain graph neural network and the model parameters of the first fully connected layer are updated.
[0046] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0047] A training module is specifically configured to obtain Ns source domain time series data from source domain sample data, wherein the source domain time series data has a one-to-one correspondence with the source domain attributes, and each source domain time series data includes time series data from a second moment to a third moment, where the second moment is a moment before the first moment, and the third moment is a moment immediately preceding the first moment;
[0048] For each source domain attribute, determine Ks source domain attributes that have a connection relationship with the source domain attribute based on the source domain graph structure corresponding to the source domain graph neural network. The source domain graph neural network belongs to the source domain detection network. The source domain graph structure includes source domain nodes and source domain edges. The source domain nodes are used to represent source domain attributes, and the source domain edges are used to represent the connection relationship between source domain attributes.
[0049] For each source domain attribute, the source domain aggregated feature vector at the first moment is obtained based on the model parameters of the source domain graph neural network, the source domain time series data corresponding to the source domain attribute, and the source domain time series data corresponding to each of the Ks source domain attributes.
[0050] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0051] A training module is specifically configured to obtain Ns source domain time series data from source domain sample data, wherein the source domain time series data has a one-to-one correspondence with the source domain attributes, and each source domain time series data includes time series data from a second moment to a third moment, where the second moment is a moment before the first moment, and the third moment is a moment immediately preceding the first moment;
[0052] For each source domain attribute, determine Ks source domain attributes that have a connection relationship with the source domain attribute based on the source domain graph structure corresponding to the source domain graph neural network. The source domain graph neural network belongs to the source domain detection network. The source domain graph structure includes source domain nodes and source domain edges. The source domain nodes are used to represent source domain attributes, and the source domain edges are used to represent the connection relationship between source domain attributes.
[0053] For each source domain attribute, obtain the aggregated attention weight between the source domain attribute and each of the Ks source domain attributes;
[0054] For each source domain attribute, the source domain aggregated feature vector at the first moment is obtained based on the model parameters of the source domain graph neural network, the source domain time series data corresponding to the source domain attribute, the aggregated attention weight corresponding to the source domain attribute, the source domain time series data corresponding to each of the Ks source domain attributes, and the aggregated attention weight corresponding to each of the Ks source domain attributes.
[0055] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0056] The training module is specifically used to obtain the time series splicing vector corresponding to the source domain attribute based on the model parameters of the source domain graph neural network, the source domain time series data corresponding to the source domain attribute, and the source domain embedding vector;
[0057] Obtain a time series concatenation vector corresponding to each of the Ks source domain attributes according to the model parameters of the source domain graph neural network, the source domain time series data corresponding to each of the Ks source domain attributes, and the source domain embedding vector;
[0058] According to the time series splicing vector corresponding to the source domain attribute, the source domain intermediate vector corresponding to the source domain attribute is obtained;
[0059] According to the time series concatenation vector corresponding to each source domain attribute in the Ks source domain attributes, obtain the source domain intermediate vector corresponding to each source domain attribute in the Ks source domain attributes;
[0060] According to the source domain intermediate vector corresponding to the source domain attribute and the source domain intermediate vector corresponding to each of the Ks source domain attributes, the aggregated attention weight between the source domain attribute and each of the Ks source domain attributes is obtained.
[0061] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0062] A training module is specifically configured to obtain Nt target domain aggregated feature vectors corresponding to the fourth moment through a target domain graph neural network based on target domain sample data, wherein the target domain aggregated feature vectors have a one-to-one correspondence with the target domain attributes, and the target domain graph neural network belongs to the target domain detection network;
[0063] Based on the Nt target domain aggregated feature vectors and the Nt target domain embedding vectors, obtaining Nt target domain prediction data values corresponding to the fourth moment through the second fully connected layer included in the target domain detection network, where the target domain prediction data values have a one-to-one correspondence with the target domain attributes;
[0064] Constructing a second loss function based on the Nt target domain predicted data values and the Nt target domain actual data values corresponding to the fourth moment, wherein the Nt target domain actual data values are derived from the target domain sample data;
[0065] Based on the second loss function, the Nt target domain embedding vectors are updated;
[0066] Based on the second loss function, the model parameters of the target domain graph neural network and the model parameters of the second fully connected layer are updated.
[0067] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0068] A training module is specifically configured to obtain Nt target domain time series data from the target domain sample data, wherein the target domain time series data has a one-to-one correspondence with the target domain attributes, and each target domain time series data includes time series data from a fifth moment to a sixth moment, where the fifth moment is a moment before the first moment, and the sixth moment is a moment immediately preceding the first moment;
[0069] For each target domain attribute, Kt target domain attributes having a connection relationship with the target domain attribute are determined according to the target domain graph structure corresponding to the target domain graph neural network, wherein the target domain graph neural network belongs to the target domain detection network, and the target domain graph structure includes target domain nodes and target domain edges. The target domain nodes are used to represent the target domain attributes, and the target domain edges are used to represent the connection relationship between the target domain attributes;
[0070] For each target domain attribute, the target domain aggregated feature vector at the fourth moment is obtained based on the model parameters of the target domain graph neural network, the target domain time series data corresponding to the target domain attribute, and the target domain time series data corresponding to each of the Kt target domain attributes.
[0071] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0072] A training module is specifically configured to obtain Nt target domain time series data from the target domain sample data, wherein the target domain time series data has a one-to-one correspondence with the target domain attributes, and each target domain time series data includes time series data from a fifth moment to a sixth moment, where the fifth moment is a moment occurring before the fourth moment, and the sixth moment is a moment immediately preceding the fourth moment;
[0073] For each target domain attribute, Kt target domain attributes having a connection relationship with the target domain attribute are determined according to the target domain graph structure corresponding to the target domain graph neural network, wherein the target domain graph neural network belongs to the target domain detection network, and the target domain graph structure includes target domain nodes and target domain edges. The target domain nodes are used to represent the target domain attributes, and the target domain edges are used to represent the connection relationship between the target domain attributes;
[0074] For each target domain attribute, obtain the aggregated attention weight between the target domain attribute and each of the Kt target domain attributes;
[0075] For each target domain attribute, the target domain aggregate feature vector at the fourth moment is obtained based on the model parameters of the target domain graph neural network, the target domain time series data corresponding to the target domain attribute, the aggregated attention weight corresponding to the target domain attribute, the target domain time series data corresponding to each of the Kt target domain attributes, and the aggregated attention weight corresponding to each of the Kt target domain attributes.
[0076] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0077] The training module is specifically used to obtain the time series splicing vector corresponding to the target domain attribute based on the model parameters of the target domain graph neural network, the target domain time series data corresponding to the target domain attribute, and the target domain embedding vector;
[0078] Obtain a time series concatenation vector corresponding to each of the Kt target domain attributes according to the model parameters of the target domain graph neural network, the target domain time series data corresponding to each of the Kt target domain attributes, and the target domain embedding vector;
[0079] According to the time series concatenation vector corresponding to the target domain attribute, the target domain intermediate vector corresponding to the target domain attribute is obtained;
[0080] According to the time series concatenation vector corresponding to each of the Kt target domain attributes, a target domain intermediate vector corresponding to each of the Kt target domain attributes is obtained;
[0081] According to the target domain intermediate vector corresponding to the target domain attribute and the target domain intermediate vector corresponding to each of the Kt target domain attributes, the aggregated attention weight between the target domain attribute and each of the Kt target domain attributes is obtained.
[0082] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0083] A generation module is specifically configured to calculate the similarity between the source domain attribute and the target domain attribute based on the time series data corresponding to each source domain attribute in the source domain sample data and the time series data corresponding to each target domain attribute in the target domain sample data;
[0084] A generation module is specifically used to perform a transposition process on the attribute similarity matrix to obtain a transposed attribute similarity matrix;
[0085] Multiply the transposed attribute similarity matrix with the updated Ns source domain embedding vectors to obtain Nt target domain embedding vectors.
[0086] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0087] A generation module is specifically configured to generate a first sliding window based on the time series data corresponding to the target domain attribute if the time series data corresponding to the source domain attribute is greater than or equal to the time series data corresponding to the target domain attribute, wherein the first sliding window is Tt, and Tt is an integer greater than 1;
[0088] Based on the first sliding window, slide the time series data corresponding to the source domain attribute with a first preset step size to obtain P first sub-time series data, where P is an integer greater than or equal to 1;
[0089] Calculate the similarity between the time series data corresponding to the target domain attribute and each first sub-time series data to obtain P sequence similarities;
[0090] Average the similarities of P sequences to obtain the similarity between the source domain attributes and the target domain attributes;
[0091] or,
[0092] A generation module is specifically configured to generate a second sliding window based on the time series data corresponding to the source domain attribute if the time series data corresponding to the target domain attribute is greater than or equal to the time series data corresponding to the source domain attribute, wherein the second sliding window is Ts, and Ts is an integer greater than 1;
[0093] Based on the second sliding window, slide the time series data corresponding to the target domain attribute with a second preset step size to obtain Q second sub-time series data, where Q is an integer greater than or equal to 1;
[0094] Calculate the similarity between the time series data corresponding to the source domain attribute and each second sub-time series data to obtain Q sequence similarities;
[0095] The similarities of the Q sequences are averaged to obtain the similarity between the source domain attributes and the target domain attributes.
[0096] Another aspect of the present application provides an anomaly detection device, comprising:
[0097] An acquisition module is used to acquire data to be detected, wherein the data to be detected includes time series data of Nt target domain attributes, and the time series data of each target domain attribute includes data at T moments, where Nt and T are both integers greater than 1;
[0098] The acquisition module is further configured to obtain Nt predicted data values corresponding to the target time through the target domain detection network based on the data to be detected, wherein the target domain detection network is trained using the above method;
[0099] The acquisition module is also used to obtain Nt actual data values corresponding to the target time;
[0100] A determination module is used to calculate the anomaly score corresponding to the target time based on Nt actual data values and Nt predicted data values;
[0101] The determination module is further configured to determine that the target moment is a data anomaly moment if the anomaly score corresponding to the target moment is greater than or equal to the anomaly score threshold.
[0102] In one possible design, in another implementation of another aspect of the embodiment of the present application,
[0103] The determination module is specifically used to calculate the mean and variance corresponding to each target domain attribute;
[0104] For each target domain attribute, calculate the absolute value of the difference between the predicted data value corresponding to the target domain attribute and the actual data value to obtain the first data value corresponding to the target domain attribute;
[0105] For each target domain attribute, the difference between the first data value corresponding to the target domain attribute and the mean value corresponding to the target domain attribute is calculated to obtain a second data value corresponding to the target domain attribute;
[0106] For each target domain attribute, taking the quotient of the second data value corresponding to the target domain attribute and the variance corresponding to the target domain attribute to obtain a third data value corresponding to the target domain attribute;
[0107] The maximum value is selected from the third data values corresponding to each target domain attribute as the anomaly score corresponding to the target moment.
[0108] On the other hand, the present application provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor implements the above-mentioned methods when executing the computer program.
[0109] Another aspect of the present application provides a computer-readable storage medium having a computer program stored thereon, which implements the above-mentioned methods when the computer program is executed by a processor.
[0110] Another aspect of the present application provides a computer program product, including a computer program, which implements the above-mentioned methods when executed by a processor.
[0111] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:
[0112] In an embodiment of the present application, a method for optimizing model parameters is provided. First, source domain sample data and target domain sample data are obtained. Based on this, a source domain graph neural network is constructed according to Ns source domain embedding vectors corresponding to Ns source domain attributes. In addition, an attribute similarity matrix can be generated based on the source domain sample data and the target domain sample data. Based on this, Nt target domain embedding vectors are generated based on the attribute similarity matrix and the updated Ns source domain embedding vectors. Thus, a target domain graph neural network can be constructed based on the Nt target domain embedding vectors. Finally, the Nt target domain embedding vectors and the model parameters of the target domain detection network are updated based on the target domain sample data. In this way, the intra-domain attribute connection is constructed based on the graph neural network, and the connection between cross-domain attributes is constructed based on the attribute similarity matrix. Thus, the source domain attributes are coordinated to achieve the improvement of the target domain data anomaly detection performance. In addition, the source domain usually contains some data characteristics that are excellent for target domain anomaly detection. Therefore, updating based on the source domain detection network can further improve the detection performance for the target domain. BRIEF DESCRIPTION OF THE DRAWINGS
[0113] Figure 1 This is a schematic diagram of the architecture of an anomaly detection system in an embodiment of the present application;
[0114] Figure 2 This is a schematic diagram of a scenario in which multivariate time series anomaly detection is implemented based on gaming services in an embodiment of the present application;
[0115] Figure 3 This is a schematic diagram of a scenario in which multivariate time series anomaly detection is implemented based on vehicle-side services in an embodiment of the present application;
[0116] Figure 4 This is a schematic diagram of a scenario in which multivariate time series anomaly detection is implemented based on network services in an embodiment of the present application;
[0117] Figure 5 This is a schematic diagram of a scenario for implementing multivariate time series anomaly detection based on meteorological services in an embodiment of the present application;
[0118] Figure 6 A flow chart of the model parameter optimization method in the embodiment of the present application;
[0119] Figure 7 A system framework diagram of the model parameter optimization method in the embodiment of the present application;
[0120] Figure 8 This is a schematic diagram of implementing self-supervised prediction based on a source domain graph neural network in an embodiment of the present application;
[0121] Figure 9 This is a schematic diagram of implementing self-supervised prediction based on a target domain graph neural network in an embodiment of the present application;
[0122] Figure 10 A flowchart of a method for detecting anomalies in time series data according to an embodiment of the present application;
[0123] Figure 11 This is a system framework diagram of the time series data anomaly detection method in an embodiment of the present application;
[0124] Figure 12 A schematic diagram of a parameter optimization device in an embodiment of the present application;
[0125] Figure 13 This is a schematic diagram of an abnormality detection device in an embodiment of the present application;
[0126] Figure 14 This is a structural diagram of a computer device in an embodiment of the present application. DETAILED DESCRIPTION
[0127] The present invention provides a method for optimizing model parameters and a method and apparatus for detecting anomalies in time series data. This application can improve the performance of anomaly detection in target domain data by collaborating with source domain attributes. Furthermore, by updating the source domain detection network, detection performance in the target domain can be further improved.
[0128] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the numbers used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can, for example, be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "corresponding to" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0129] Time series data, also known as time series data, is a collection of data recorded in chronological order for the same business. Specifically, in time series data, data values correspond one-to-one with time. Time series data can be used to describe the changing trends of a business over time. Currently, time series data has been applied in a variety of fields, such as gaming, industrial production, agricultural production, meteorology, and economics.
[0130] Time series data also plays a crucial role in machine learning. Using time series data for machine learning can predict data changes at a certain point in the future. Machine learning (ML) is a multidisciplinary discipline that encompasses probability theory, statistics, approximation theory, convex analysis, and algorithmic complexity theory. It specifically studies how computers simulate or implement human learning behaviors to acquire new knowledge or skills and reorganize existing knowledge structures to continuously improve their performance. ML is the core of artificial intelligence (AI) and the fundamental way to make computers intelligent. Its applications span all areas of AI. ML and deep learning typically include techniques such as artificial neural networks, belief networks, reinforcement learning, transfer learning, and inductive learning.
[0131] It is understandable that real-world systems usually work in a continuous manner and generate corresponding multivariate time series data. Therefore, automatically detecting outliers from long-term monitoring data can ensure the safety of the system and avoid large-scale property losses. In multivariate time series data, outliers are usually rare, and anomaly labels are difficult to obtain due to the high cost of annotation. Therefore, unsupervised multivariate time series anomaly detection is a problem of great practical and research significance. Multivariate time series anomaly detection systems often face system upgrades or cross-platform deployments, which also creates the need to migrate from the source domain to the target domain. However, the upgrade process of a multivariate time series system usually increases the number of attributes, which makes it difficult to directly use the model trained in the source domain for the target domain. In addition, the source domain usually contains some data features that are excellent for anomaly detection in the target domain. Retraining the model from scratch cannot cooperate with the source domain data to improve the detection performance of the target domain.
[0132] Based on this, this application proposes an adaptive unsupervised multivariate time series anomaly detection method, which constructs intra-domain attribute connections through graph neural networks, constructs cross-domain attribute connections through sliding matching similarity, and collaborates with source domain attributes to improve the anomaly detection performance of target domain data. The method provided in this application can be applied to Figure 1 The anomaly detection system shown in the figure includes a server and a terminal device, and the client is deployed on the terminal device, wherein the client can be run on the terminal device in the form of a browser, or in the form of an independent application (APP), etc. The specific presentation form of the client is not limited here. The server involved in this application can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms. The terminal device can be a mobile phone, a computer, an intelligent voice interaction device, a smart home appliance, a car terminal, an aircraft, etc. The terminal device and the server can be directly or indirectly connected via wired or wireless communication, and this application does not limit this. The number of servers and terminal devices is also not limited. The solution provided in this application can be completed independently by the terminal device, independently by the server, or in cooperation with the terminal device and the server, and this application does not specifically limit this. The embodiments of the present application can be applied to various scenarios, including but not limited to cloud technology, AI, smart transportation, assisted driving, etc.
[0133] It is understandable that real systems usually work in a continuous manner and generate corresponding multivariate time series data. In the above system, automatically detecting abnormal values from long-term time series data can ensure the safety of the system and avoid a large amount of property losses. Figure 1 And several application scenarios, the multivariate time series anomaly detection method provided by this application is introduced.
[0134] Scenario 1: Game business anomaly detection;
[0135] For example, see Figure 2 , Figure 2 This is a schematic diagram of a scenario for implementing multivariate timing anomaly detection based on gaming services in an embodiment of the present application. As shown in the figure, taking a multiplayer online battle arena (MOBA) game as an example, the terminal device can collect data on each frame of the player to record the timing data corresponding to the moving speed and moving distance. In one case, the target domain detection network local to the terminal device is called to detect these timing data. In another case, the terminal device can push these timing data to the server, and the server calls the target domain detection network to detect these timing data. If the game is detected to be abnormal, a corresponding prompt message will be displayed.
[0136] Scenario 2: Autonomous driving anomaly detection;
[0137] For example, see Figure 3 , Figure 3 This is a schematic diagram of a scenario for implementing multivariate time series anomaly detection based on vehicle-side services in an embodiment of the present application. As shown in the figure, the vehicle's speed sequence data, acceleration sequence data, and direction sequence data are recorded by the vehicle system. In one case, the target domain detection network local to the vehicle system is called to detect these time series data. In another case, the vehicle system can push these time series data to the server, and the server will call the target domain detection network to detect these time series data. If a driving anomaly is detected, the driver will be notified in a timely manner.
[0138] Scenario 3: Network anomaly detection;
[0139] For example, see Figure 4 , Figure 4 This is a schematic diagram of a scenario for implementing multi-dimensional time series anomaly detection based on network services in an embodiment of the present application. As shown in the figure, the server can obtain the connection duration sequence, transmission byte data sequence, and connection type data sequence of each terminal device in the local area network over a period of time. The server then calls the target domain detection network to detect this time series data. If a network connection anomaly is detected, the user can be prompted accordingly.
[0140] Scenario 4: Weather anomaly detection;
[0141] For example, see Figure 5 , Figure 5 This is a schematic diagram of a scenario for implementing multivariate time series anomaly detection based on meteorological services in an embodiment of the present application. As shown in the figure, a temperature data sequence over a period of time is collected by a thermometer, a humidity data sequence over a period of time is collected by a hygrometer, and a pressure data sequence over a period of time is collected by a barometer. In one case, the target domain detection network local to the terminal device is called to detect these time series data. In another case, the target domain detection network local to the server is called to detect these time series data. If a meteorological anomaly is detected, a corresponding broadcast will be generated in a timely manner.
[0142] Since this application involves some terms related to professional fields, they will be explained below for ease of understanding.
[0143] (1) Multivariate time series (MTS): refers to time series data that contains multiple attribute features at each moment.
[0144] (2) Unsupervised anomaly detection (AD): Given a set of unlabeled data, the data characteristics are analyzed and sample points that deviate from the overall data distribution are selected from the data.
[0145] (3) Within a domain: For two different multivariate time series systems A and B, if multivariate time series system A contains attributes a1, a2, and a3, and multivariate time series system B contains attributes b1, b2, and b3, then attributes a1, a2, and a3 belong to one domain, and attributes b1, b2, and b3 belong to another domain.
[0146] (4) Cross-domain: For two different multivariate time series systems A and B, if multivariate time series system A contains attributes a1, a2, and a3, and multivariate time series system B contains attributes b1, b2, and b3, then attributes a1 and b1 belong to a cross-domain relationship.
[0147] (5) Source domain and target domain: For two different multivariate time series systems A and B, the dataset of multivariate time series system A is used to help improve the anomaly detection performance on multivariate time series system B. Since the purpose is to improve the performance of multivariate time series system B, multivariate time series system B is the target domain, and multivariate time series system A provides an additional data source for the target domain. Therefore, multivariate time series system A is the source domain.
[0148] Combined with the above introduction, the optimization method of the model parameters in this application will be introduced below. Please refer to Figure 6 In the embodiment of the present application, the method for optimizing model parameters may be executed by a computer device, which may be a terminal device or a server. The embodiment of the present application includes:
[0149] 210. Obtain source domain sample data and target domain sample data, wherein the source domain sample data includes time series data of Ns source domain attributes, and the target domain sample data includes time series data of Nt target domain attributes, where both Ns and Nt are integers greater than 1;
[0150] In one or more embodiments, source domain sample data and target domain sample data are obtained. For ease of understanding, please refer to Figure 7 , Figure 7 This is a system framework diagram of the model parameter optimization method in an embodiment of the present application. As shown in the figure, the source domain sample data includes time series data of Ns source domain attributes, and the target domain sample data includes time series data of Nt target domain attributes. Both Ns and Nt are integers greater than 1, and Ns and Nt do not necessarily have the same value.
[0151] 220. Construct a source domain graph neural network based on the Ns source domain embedding vectors corresponding to the Ns source domain attributes, where the source domain embedding vectors have a one-to-one correspondence with the source domain attributes;
[0152] In one or more embodiments, in multivariate time series data, attributes may be interrelated in complex ways. Therefore, this application utilizes trainable multidimensional embedding vectors to represent each attribute and thereby capture the interrelationships between them. For multivariate time series data containing N attributes, an embedding vector is associated with each attribute to characterize its characteristics.
[0153] Specifically, the following will be combined again Figure 7 For multivariate time series data containing Ns source domain attributes, a source domain embedding vector associated with each source domain attribute is expressed as:
[0154]
[0155] Among them, v i Represents the source domain embedding vector corresponding to the i-th source domain attribute.
[0156] The source domain embedding vector is randomly initialized and iteratively updated as the model trains. The source domain embedding vector captures the characteristics of the source domain attributes, providing a foundation for subsequent graph structure learning. Based on this, the similarity between source domain embedding vectors is used to measure the similarity between source domain attributes. This similarity is then used as the basis for aggregating the values of each neighbor in the source domain graph neural network.
[0157] 230. Update the Ns source domain embedding vectors and the model parameters of the source domain detection network according to the source domain sample data, wherein the source domain detection network includes a source domain graph neural network;
[0158] In one or more embodiments, for ease of understanding, please refer again to Figure 7 , multivariate time series data with a duration of L (for example, from time 0 to time L) (i.e., Ns source domain time series data) can be obtained from the source domain sample data, and multivariate time series data at the (L+1)th time (i.e., Ns source domain actual data values) can be obtained.
[0159] Specifically, Ns source domain time series data of duration L are used as input to the source domain detection network, which then outputs Ns source domain predicted data values at the (L+1)th moment. Based on this, the Ns source domain embedding vectors are updated according to the loss between the Ns source domain predicted data values and the Ns source domain actual data values, and the model parameters of the source domain detection network are also updated.
[0160] 240. Generate an attribute similarity matrix based on the source domain sample data and the target domain sample data, wherein the attribute similarity matrix is used to describe the similarity between each source domain attribute and each target domain attribute;
[0161] In one or more embodiments, the source domain sample data and the target domain sample data are combined to calculate the similarity between each source domain attribute and each target domain attribute, thereby obtaining an Ns×Nt similarity matrix.
[0162] It should be noted that the similarity can be calculated using a sliding window method, where the sliding window similarity calculation method is simple, has low complexity, and is suitable for longer time series data. Alternatively, the similarity can be calculated using dynamic time warping (DTW), where DTW is suitable for shorter time series data.
[0163] 250. Generate Nt target domain embedding vectors based on the attribute similarity matrix and the updated Ns source domain embedding vectors, where the target domain embedding vectors have a one-to-one correspondence with the target domain attributes;
[0164] In one or more embodiments, after obtaining the attribute similarity matrix, Nt target domain embedding vectors can be calculated by multiplying the attribute similarity matrix with the Ns source domain embedding vectors updated in step 230. The Ns source domain embedding vectors constitute a source domain embedding matrix, and the Nt target domain embedding vectors constitute a target domain embedding matrix. Based on this, the target domain embedding matrix can be calculated as follows:
[0165] Vt =V s ×M T Formula (2)
[0166] Among them, V t V represents the target domain embedding matrix. s represents the source domain embedding matrix, i.e., it includes Ns source domain embedding vectors. M represents the attribute similarity matrix, and (·) T Indicates transpose.
[0167] 260. Construct a target domain graph neural network based on the Nt target domain embedding vectors, wherein the model parameters of the target domain graph neural network adopt the updated model parameters of the source domain graph neural network;
[0168] In one or more embodiments, the target domain embedding vector is also iteratively updated as the model is trained. The target domain embedding vector contains the characteristics of the target domain attributes and can provide a basis for subsequent graph structure learning. Based on this, the similarity between target domain embedding vectors can be used to measure the similarity between target domain attributes. The similarity between target domain attributes can be used as the basis for aggregating the values of each neighbor in the target domain graph neural network.
[0169] Specifically, the model parameters of the target domain GNN adopt the updated model parameters of the source domain GNN, that is, they inherit the neural network aggregation parameters W of the source domain GNN. This enables cross-domain data information interaction, allowing the target domain GNN to inherit the attribute associations learned by the source domain GNN and fine-tune it on target domain sample data to continuously improve the model's anomaly detection capabilities.
[0170] 270. Update Nt target domain embedding vectors and model parameters of a target domain detection network based on the target domain sample data, wherein the target domain detection network includes a target domain graph neural network.
[0171] In one or more embodiments, for ease of understanding, please refer again to Figure 7 , multivariate time series data with a duration of L (for example, from time 0 to time L) (i.e., Nt target domain time series data) can be obtained from the target domain sample data, and multivariate time series data at the (L+1)th time (i.e., Nt target domain actual data values) can be obtained.
[0172] Specifically, Nt target domain time series data of duration L are used as input to the target domain detection network, which then outputs Nt target domain predicted data values at the (L+1)th moment. Based on this, the Nt target domain embedding vectors are updated according to the loss between the Nt target domain predicted data values and the Nt target domain actual data values, and the model parameters of the target domain detection network are also updated.
[0173] In the source domain, the input is the source domain sample data. After attribute embedding and graph structure learning, a graph neural network with attributes as nodes is constructed, and the source domain detection network is trained through the future moment attribute prediction self-supervision task. Finally, the prediction error is used as the anomaly classification to identify the anomaly point. In the target domain, the input is the source domain sample data, the target domain sample data, Ns source domain embedding vectors, and the model parameters of the source domain graph neural network. Thus, the association between the source domain attributes and the target domain attributes is obtained according to the similarity calculation method, and the target domain embedding vector is initialized and the graph structure is learned in combination with the Ns source domain embedding vectors. At the same time, this application uses the model parameters of the source domain graph neural network to initialize the target domain graph neural network, and performs self-supervised prediction tasks on the target domain sample data to further train the model. Finally, the multivariate time series data anomaly detection of the target domain is also performed through the prediction error.
[0174] In an embodiment of the present application, a method for optimizing model parameters is provided. Through the above-mentioned method, intra-domain attribute connections are constructed based on a graph neural network, and connections between cross-domain attributes are constructed based on an attribute similarity matrix. Thus, the source domain attributes are coordinated to improve the performance of anomaly detection in the target domain data. In addition, the source domain usually contains some data features that are excellent for anomaly detection in the target domain. Therefore, updating the source domain detection network based on the source domain detection network can further improve the detection performance for the target domain.
[0175] Optionally, in the above Figure 6 On the basis of the corresponding embodiments, in another optional embodiment provided by the embodiments of the present application, constructing a source domain graph neural network according to Ns source domain embedding vectors corresponding to Ns source domain attributes may specifically include:
[0176] For each source domain attribute, according to the source domain embedding vector corresponding to the source domain attribute and the source domain embedding vectors corresponding to the remaining source domain attributes, (Ns-1) vector similarities are calculated, where the remaining source domain attributes are the remaining (Ns-1) source domain attributes in the Ns source domain attributes except the source domain attribute.
[0177] For each source domain attribute, determine the largest Ks vector similarities from (Ns-1) vector similarities, where Ks is an integer greater than or equal to 1 and less than (Ns-1);
[0178] For each source domain attribute, determine Ks source domain attributes that have a connection relationship with the source domain attribute based on the largest Ks vector similarities, wherein the vector similarities in the Ks vector similarities have a one-to-one correspondence with the source domain attributes in the Ks source domain attributes;
[0179] According to each source domain attribute and Ks source domain attributes that have a connection relationship with each source domain attribute, a source domain graph structure is constructed, wherein the source domain graph structure includes source domain nodes and source domain edges. The source domain nodes are used to represent source domain attributes, and the source domain edges are used to represent the connection relationship between different source domain attributes;
[0180] According to the source domain graph structure and Ns source domain embedding vectors, a source domain graph neural network is constructed.
[0181] In one or more embodiments, a method for constructing a source domain graph neural network is described. As can be seen from the aforementioned embodiments, this application requires the use of a graph neural network to extract time series data features. However, in real-world applications, the relationships between source domain attributes and the connectivity between nodes in the graph are typically not given. Therefore, it is necessary to calculate the similarity of source domain attributes to obtain the association between nodes in order to construct the source domain graph neural network.
[0182] Specifically, for the i-th source domain attribute, it may be associated with all source domain attributes except itself. The remaining source domain attributes of the i-th source domain attribute can be represented as an association candidate set, that is, Therefore, the vector similarity between the source domain embedding vector of the i-th source domain attribute and each source domain embedding vector in the associated candidate set can be calculated as follows, and the top Ks source domain attributes with the largest vector similarity are selected to build the connection:
[0183]
[0184] if Then A ij =1; formula (4)
[0185] Where, e represents the similarity matrix. ij represents the vector similarity between the source domain embedding vector of the i-th source domain attribute and the source domain embedding vector of the j-th source domain attribute. A represents the attribute connectivity matrix. ij Indicates that there is a connection relationship between the i-th source domain attribute and the j-th source domain attribute, that is, a source domain edge is established between the two. TopKs represents the operation of selecting Ks source domain attributes with the largest vector similarity from the associated candidate set. Ks represents a pre-set parameter. i v represents the source domain embedding vector corresponding to the i-th source domain attribute. j represents the source domain embedding vector corresponding to the j-th source domain attribute. (·) T Indicates transpose.
[0186] At this point, a source domain graph neural network can be constructed based on each source domain attribute and the Ks source domain attributes that have a connection relationship with each source domain attribute. The source domain graph structure includes source domain nodes and source domain edges. A source domain node represents a source domain attribute, and source domain edges are used to represent the connection relationship between different source domain attributes.
[0187] Secondly, in an embodiment of the present application, a method for constructing a source domain graph neural network is provided. By utilizing the similarity between source domain embedding vectors, source domain attributes with greater similarity can be connected, making the connection relationship between nodes in the source domain graph neural network more accurate.
[0188] Optionally, in the above Figure 6 On the basis of the corresponding embodiments, in another optional embodiment provided by the embodiments of the present application, constructing a target domain graph neural network based on Nt target domain embedding vectors may specifically include:
[0189] For each target domain attribute, according to the target domain embedding vector corresponding to the target domain attribute and the target domain embedding vectors corresponding to the remaining target domain attributes, (Nt-1) vector similarities are calculated, where the remaining target domain attributes are the remaining (Nt-1) target domain attributes in the Nt target domain attributes except the target domain attribute;
[0190] For each target domain attribute, determine the largest Kt vector similarities from the (Nt-1) vector similarities, where Kt is an integer greater than or equal to 1 and less than (Nt-1);
[0191] For each target domain attribute, determine Kt target domain attributes that have a connection relationship with the target domain attribute based on the largest Kt vector similarities, wherein the vector similarities in the Kt vector similarities have a one-to-one correspondence with the target domain attributes in the Kt target domain attributes;
[0192] According to each target domain attribute and Kt target domain attributes that have a connection relationship with each target domain attribute, a target domain graph structure is constructed, wherein the target domain graph structure includes target domain nodes and target domain edges. The target domain nodes are used to represent the target domain attributes, and the target domain edges are used to represent the connection relationship between different target domain attributes.
[0193] According to the target domain graph structure and Nt target domain embedding vectors, a target domain graph neural network is constructed.
[0194] In one or more embodiments, a method for constructing a target domain graph neural network is described. As can be seen from the aforementioned embodiments, this application requires the use of a graph neural network to extract time series data features. However, in real-world applications, the relationships between target domain attributes and the connectivity between nodes in the graph are typically not given. Therefore, it is necessary to calculate the similarity of target domain attributes to obtain the association between nodes in order to construct the target domain graph neural network.
[0195] Specifically, for the i-th target domain attribute, it may be associated with all target domain attributes except itself. The remaining target domain attributes of the i-th target domain attribute can be represented as an association candidate set, that is, Therefore, the vector similarity between the target domain embedding vector of the i-th target domain attribute and each target domain embedding vector in the associated candidate set can be calculated in the following way, and the first Kt target domain attributes with the largest vector similarity are selected to build the connection:
[0196]
[0197] if Then A ij =1; formula (6)
[0198] Where, e represents the similarity matrix. ij represents the vector similarity between the target domain embedding vector of the i-th target domain attribute and the target domain embedding vector of the j-th target domain attribute. A represents the attribute connectivity matrix. ij Indicates that there is a connection relationship between the i-th target domain attribute and the j-th target domain attribute, that is, a target domain edge is established between the two. TopKt represents the operation of selecting Kt target domain attributes with the largest vector similarity from the associated candidate set. Ks represents a pre-set parameter. i v represents the target domain embedding vector corresponding to the i-th target domain attribute. j represents the target domain embedding vector corresponding to the j-th target domain attribute. (·) T Indicates transpose.
[0199] At this point, a target domain graph neural network can be constructed based on each target domain attribute and the Kt target domain attributes that have a connection relationship with each target domain attribute. The target domain graph structure includes target domain nodes and target domain edges. A target domain node represents a target domain attribute, and target domain edges are used to represent the connection relationship between different target domain attributes.
[0200] Secondly, in an embodiment of the present application, a method for constructing a target domain graph neural network is provided. By utilizing the similarity between target domain embedding vectors, target domain attributes with greater similarity can be connected, making the connection relationship between nodes in the target domain graph neural network more accurate.
[0201] Optionally, in the above Figure 6 On the basis of the corresponding embodiments, in another optional embodiment provided by the embodiments of the present application, updating the Ns source domain embedding vectors and the model parameters of the source domain detection network according to the source domain sample data may specifically include:
[0202] Based on the source domain sample data, the source domain graph neural network is used to obtain Ns source domain aggregated feature vectors corresponding to the first moment, where the source domain aggregated feature vectors have a one-to-one correspondence with the source domain attributes. The source domain graph neural network belongs to the source domain detection network;
[0203] Based on the Ns source domain aggregated feature vectors and the Ns source domain embedding vectors, obtaining Ns source domain prediction data values corresponding to the first moment through a first fully connected layer included in the source domain detection network, where the source domain prediction data values have a one-to-one correspondence with the source domain attributes;
[0204] Constructing a first loss function based on Ns source domain predicted data values and Ns source domain actual data values corresponding to the first moment, wherein the Ns source domain actual data values are derived from the source domain sample data;
[0205] Based on the first loss function, update the Ns source domain embedding vectors;
[0206] Based on the first loss function, the model parameters of the source domain graph neural network and the model parameters of the first fully connected layer are updated.
[0207] In one or more embodiments, a method for training a neural network based on a self-supervised prediction task is described. As can be seen from the aforementioned embodiments, the source domain detection network includes a source domain graph neural network and a first fully connected (FC) layer. The source domain detection network obtains Ns source domain aggregated feature vectors at a first moment. Then, the Ns source domain aggregated feature vectors are used as input to the first FC layer, and the first FC layer outputs Ns source domain prediction data values.
[0208] Specifically, assume that the Ns source domain attributes include "temperature attribute", "humidity attribute" and "air pressure attribute". The time series data corresponding to these attributes collected over a period of time is used as the input of the source domain detection network, and the source domain detection network outputs Ns source domain prediction data values at the next moment. For example, the Ns source domain prediction data values include the temperature value "25", the humidity value "0.75", and the air pressure value "1200". The Ns source domain prediction data values at the tth moment (i.e., the first moment) can be predicted as follows:
[0209]
[0210] in, Represents the Ns source domain prediction data values at the tth moment (i.e., the first moment). Represents Ns source domain aggregated feature vectors. {v1,v2,...,v Ns} represents Ns source domain embedding vectors. ⊙ represents vector inner product. f θs Represents the trainable network parameters of the first FC layer.
[0211] Based on this, according to the Ns source domain predicted data values and Ns source domain actual data values corresponding to the t-th moment (i.e., the first moment), a first loss function is constructed. Taking the first loss function as the mean square error (MSE) as an example, the first loss function is expressed as:
[0212]
[0213] Among them, L MSE Represents the first loss function. Represents the Ns source domain predicted data values at time t. Represents the Ns actual data values of the source domain at the tth time. The "2" above represents the square, and the "2" below represents the l2 norm of the matrix. s Represents the total source domain sample dataset. |D s | represents the number of source domain sample data.
[0214] Therefore, with the goal of minimizing the first loss function, the Ns source domain embedding vectors are updated, and the model parameters of the source domain graph neural network and the model parameters of the first FC layer are updated.
[0215] It should be noted that the first loss function can adopt the MSE loss function, or the mean absolute error (MAE) loss function, or the root mean square error (RMSE) loss function, or other types of loss functions, which are not limited here.
[0216] Secondly, in an embodiment of the present application, a method for training a neural network based on a self-supervised prediction task is provided. Through the above method, the model parameters of the source domain graph neural network and the model parameters of the first FC layer are trained according to the error between the actual data value of the source domain and the predicted data value of the source domain. On the one hand, it can optimize the performance of the source domain detection network in the prediction task. On the other hand, the use of the source domain graph neural network can better extract the relationship between each source domain attribute in the multivariate data, providing rich information for accurate anomaly detection.
[0217] Optionally, in the above Figure 6 On the basis of the corresponding embodiments, in another optional embodiment provided by the embodiments of the present application, based on the source domain sample data, obtaining Ns source domain aggregated feature vectors corresponding to the first moment through the source domain graph neural network may specifically include:
[0218] Obtain Ns source domain time series data from the source domain sample data, where the source domain time series data has a one-to-one correspondence with the source domain attributes, and each source domain time series data includes time series data from the second moment to the third moment, where the second moment is a moment before the first moment, and the third moment is the previous moment adjacent to the first moment;
[0219] For each source domain attribute, determine Ks source domain attributes that have a connection relationship with the source domain attribute based on the source domain graph structure corresponding to the source domain graph neural network. The source domain graph neural network belongs to the source domain detection network. The source domain graph structure includes source domain nodes and source domain edges. The source domain nodes are used to represent source domain attributes, and the source domain edges are used to represent the connection relationship between source domain attributes.
[0220] For each source domain attribute, the source domain aggregated feature vector at the first moment is obtained based on the model parameters of the source domain graph neural network, the source domain time series data corresponding to the source domain attribute, and the source domain time series data corresponding to each of the Ks source domain attributes.
[0221] In one or more embodiments, a method for obtaining source domain prediction data values based on a graph neural network (GNN) is introduced. It can be seen from the aforementioned embodiments that the source domain sample data includes Ns source domain time series data within a period of time, wherein each source domain time series data is the time series data corresponding to a source domain attribute. Based on this, Ns source domain time series data of continuous duration can be extracted from the source domain sample data to predict Ns source domain prediction data values at the next moment. Since the present application is suitable for unsupervised anomaly detection, that is, the anomaly labels of the time series data cannot be obtained for training the model, therefore, Ns source domain actual data values and Ns source domain prediction data values at future moments can be used to train the model.
[0222] Specifically, for easier understanding, see Figure 8 , Figure 8 This is a schematic diagram of implementing self-supervised prediction based on the source domain graph neural network in an embodiment of the present application. As shown in the figure, for each time t, the multivariate time series sequence of length L can be expressed as That is, x t =[x t-L ,x t-L+1 ,...,x t-1 ]. The t-th moment to be predicted is taken as the "first moment", the (tL)-th moment is taken as the "second moment", and the (t-1)-th moment is taken as the "third moment". Based on this, the source domain aggregated feature vector of the i-th source domain attribute at the first moment can be calculated as follows:
[0223]
[0224] in, Represents the source domain aggregated feature vector of the i-th source domain attribute at the first moment. Represents the source domain time series data corresponding to the i-th source domain attribute. N(i)={j|A ij =1} represents the Ks source domain attributes that have a connection relationship with the i-th source domain attribute. W represents the neural network aggregation parameter, that is, the model parameter of the source domain graph neural network. ReLU(·) represents the linear rectification function.
[0225] Again, in the embodiment of the present application, a method for obtaining source domain prediction data values based on GNN is provided. Through the above method, the source domain nodes can be directly aggregated by averaging, that is, for Ks neighbor nodes, the weight of each neighbor node is 1 / Ks. Therefore, as a specific implementation method, the feasibility and operability of the solution are ensured.
[0226] Optionally, in the above Figure 6On the basis of the corresponding embodiments, in another optional embodiment provided by the embodiments of the present application, based on the source domain sample data, obtaining Ns source domain aggregated feature vectors corresponding to the first moment through the source domain graph neural network may specifically include:
[0227] Obtain Ns source domain time series data from the source domain sample data, where the source domain time series data has a one-to-one correspondence with the source domain attributes, and each source domain time series data includes time series data from the second moment to the third moment, where the second moment is a moment before the first moment, and the third moment is the previous moment adjacent to the first moment;
[0228] For each source domain attribute, determine Ks source domain attributes that have a connection relationship with the source domain attribute based on the source domain graph structure corresponding to the source domain graph neural network. The source domain graph neural network belongs to the source domain detection network. The source domain graph structure includes source domain nodes and source domain edges. The source domain nodes are used to represent source domain attributes, and the source domain edges are used to represent the connection relationship between source domain attributes.
[0229] For each source domain attribute, obtain the aggregated attention weight between the source domain attribute and each of the Ks source domain attributes;
[0230] For each source domain attribute, the source domain aggregated feature vector at the first moment is obtained based on the model parameters of the source domain graph neural network, the source domain time series data corresponding to the source domain attribute, the aggregated attention weight corresponding to the source domain attribute, the source domain time series data corresponding to each of the Ks source domain attributes, and the aggregated attention weight corresponding to each of the Ks source domain attributes.
[0231] In one or more embodiments, a method for obtaining source domain prediction data values based on an attention-based GNN is described. As can be seen from the aforementioned embodiments, the source domain sample data includes Ns source domain time series data within a period of time, where each source domain time series data is the time series data corresponding to a source domain attribute. Based on this, Ns consecutive source domain time series data can be extracted from the source domain sample data to predict Ns source domain prediction data values at the next moment.
[0232] For details, please refer again to Figure 8 Based on this, the source domain aggregate feature vector of the i-th source domain attribute at the first moment can be calculated as follows:
[0233]
[0234] in, Represents the source domain aggregated feature vector of the i-th source domain attribute at the first moment. Represents the source domain time series data corresponding to the i-th source domain attribute. N(i)={j|A ij =1} represents the Ks source domain attributes that have a connection relationship with the i-th source domain attribute. W represents the neural network aggregation parameter, that is, the model parameter of the source domain graph neural network. i,j represents the aggregated attention weight between the i-th source domain attribute and the j-th source domain attribute. ReLU(·) represents the function.
[0235] Again, in the embodiment of this application, a method for obtaining source domain prediction data values based on attention GNN is provided. Through the above method, a dynamically changing weight can be assigned to neighbor nodes, thereby better extracting the relationship between source domain attributes. Therefore, as another specific implementation method, the feasibility and operability of the solution are guaranteed.
[0236] Optionally, in the above Figure 6 On the basis of the corresponding embodiments, in another optional embodiment provided by the embodiments of the present application, obtaining the aggregated attention weight between the source domain attribute and each of the Ks source domain attributes may specifically include:
[0237] Obtain the time series concatenation vector corresponding to the source domain attribute based on the model parameters of the source domain graph neural network, the source domain time series data corresponding to the source domain attribute, and the source domain embedding vector;
[0238] Obtain a time series concatenation vector corresponding to each of the Ks source domain attributes according to the model parameters of the source domain graph neural network, the source domain time series data corresponding to each of the Ks source domain attributes, and the source domain embedding vector;
[0239] According to the time series splicing vector corresponding to the source domain attribute, the source domain intermediate vector corresponding to the source domain attribute is obtained;
[0240] According to the time series concatenation vector corresponding to each source domain attribute in the Ks source domain attributes, obtain the source domain intermediate vector corresponding to each source domain attribute in the Ks source domain attributes;
[0241] According to the source domain intermediate vector corresponding to the source domain attribute and the source domain intermediate vector corresponding to each of the Ks source domain attributes, the aggregated attention weight between the source domain attribute and each of the Ks source domain attributes is obtained.
[0242] In one or more embodiments, a method for calculating aggregated attention weights is provided. As can be seen from the aforementioned embodiments, taking the i-th source domain attribute as an example, Ks source domain attributes connected to it can be obtained based on the source domain graph structure. Based on this, the aggregated attention weight between the i-th source domain attribute and the j-th source domain attribute at the first moment can be calculated as follows:
[0243]
[0244] in, Represents the time series concatenation vector corresponding to the i-th source domain attribute. Represents the source domain time series data corresponding to the i-th source domain attribute. i represents the source domain embedding vector of the i-th source domain attribute. W represents the neural network aggregation parameters, that is, the model parameters of the source domain graph neural network. Represents the concatenation of matrices. π(i,j) represents the source domain intermediate vector between the i-th source domain attribute and the j-th source domain attribute. represents the time series concatenation vector corresponding to the j-th source domain attribute. a(·) represents a trainable parameter. LeakyReLU(·) represents a function. N(i)={j|A ij =1} represents Ks source domain attributes that have a connection relationship with the i-th source domain attribute.
[0245] Furthermore, in an embodiment of the present application, a method for calculating the aggregated attention weight is provided. Through the above method, the aggregated attention weight between source domain attributes can be calculated in combination with relevant formulas, thereby ensuring the feasibility of the solution.
[0246] Optionally, in the above Figure 6 On the basis of the corresponding embodiments, in another optional embodiment provided by the embodiments of the present application, updating the Nt target domain embedding vectors and the model parameters of the target domain detection network according to the target domain sample data may specifically include:
[0247] Based on the target domain sample data, the target domain graph neural network is used to obtain Nt target domain aggregated feature vectors corresponding to the fourth moment, where the target domain aggregated feature vectors have a one-to-one correspondence with the target domain attributes. The target domain graph neural network belongs to the target domain detection network.
[0248] Based on the Nt target domain aggregated feature vectors and the Nt target domain embedding vectors, obtaining Nt target domain prediction data values corresponding to the fourth moment through the second fully connected layer included in the target domain detection network, where the target domain prediction data values have a one-to-one correspondence with the target domain attributes;
[0249] Constructing a second loss function based on the Nt target domain predicted data values and the Nt target domain actual data values corresponding to the fourth moment, wherein the Nt target domain actual data values are derived from the target domain sample data;
[0250] Based on the second loss function, the Nt target domain embedding vectors are updated;
[0251] Based on the second loss function, the model parameters of the target domain graph neural network and the model parameters of the second fully connected layer are updated.
[0252] In one or more embodiments, a method for training a neural network based on a self-supervised prediction task is described. As can be seen from the aforementioned embodiments, the target domain detection network includes a target domain graph neural network and a second FC layer. The target domain detection network obtains Nt target domain aggregated feature vectors at a fourth time point. These Nt target domain aggregated feature vectors are then used as inputs to the second FC layer, which then outputs Nt target domain prediction data values.
[0253] Specifically, assume that the Nt target domain attributes include "temperature attribute" and "humidity attribute." The time series data corresponding to these attributes collected over a period of time is used as the input of the target domain detection network, which then outputs Nt target domain predicted data values for the next moment. For example, the Nt target domain predicted data values include a temperature value of "30" and a humidity value of "0.87." The Nt target domain predicted data values at moment t (i.e., the fourth moment) can be predicted as follows:
[0254]
[0255] in, Represents Nt target domain prediction data values at the tth moment (i.e., the fourth moment). Represents Nt target domain aggregate feature vectors. {v1,v2,...,v Nt} represents Nt target domain embedding vectors. ⊙ represents vector inner product. f θt Represents the trainable network parameters of the second FC layer.
[0256] Based on this, according to the Nt target domain predicted data values and Nt target domain actual data values corresponding to the t-th moment (i.e., the fourth moment), a second loss function is constructed. Taking the second loss function as MSE as an example, the second loss function is expressed as:
[0257]
[0258] Among them, L MSE Represents the first loss function. Represents the Nt target domain predicted data values at time t. Represents the actual data values of Nt target domains at time t. The "2" above represents the square, and the "2" below represents the l2 norm of the matrix. t Denotes the total target domain sample dataset. |D t | represents the number of sample data in the target domain.
[0259] Therefore, with the goal of minimizing the first loss function, the Nt target domain embedding vectors are updated, and the model parameters of the target domain graph neural network and the model parameters of the second FC layer are updated.
[0260] It should be noted that the second loss function can adopt the MSE loss function, or the MAE loss function, or the RMSE loss function, or other types of loss functions, which are not limited here.
[0261] Secondly, in an embodiment of the present application, a method for training a neural network based on a self-supervised prediction task is provided. Through the above method, the model parameters of the target domain graph neural network and the model parameters of the second FC layer are trained according to the error between the actual data value of the target domain and the predicted data value of the target domain. On the one hand, it can optimize the performance of the target domain detection network in the prediction task. On the other hand, the use of the target domain graph neural network can better extract the relationship between each target domain attribute in the multivariate data, providing rich information for accurate anomaly detection.
[0262] Optionally, in the above Figure 6 On the basis of the corresponding embodiments, in another optional embodiment provided by the embodiments of the present application, based on the target domain sample data, obtaining Nt target domain aggregated feature vectors corresponding to the fourth moment through the target domain graph neural network may specifically include:
[0263] Obtain Nt target domain time series data from the target domain sample data, where the target domain time series data has a one-to-one correspondence with the target domain attributes, and each target domain time series data includes time series data from the fifth moment to the sixth moment, where the fifth moment is a moment before the first moment, and the sixth moment is the previous moment adjacent to the first moment;
[0264] For each target domain attribute, Kt target domain attributes having a connection relationship with the target domain attribute are determined according to the target domain graph structure corresponding to the target domain graph neural network, wherein the target domain graph neural network belongs to the target domain detection network, and the target domain graph structure includes target domain nodes and target domain edges. The target domain nodes are used to represent the target domain attributes, and the target domain edges are used to represent the connection relationship between the target domain attributes;
[0265] For each target domain attribute, the target domain aggregated feature vector at the fourth moment is obtained based on the model parameters of the target domain graph neural network, the target domain time series data corresponding to the target domain attribute, and the target domain time series data corresponding to each of the Kt target domain attributes.
[0266] In one or more embodiments, a method for obtaining target domain prediction data values based on GNN is introduced. It can be seen from the aforementioned embodiments that the target domain sample data includes Nt target domain time series data within a period of time, wherein each target domain time series data is the time series data corresponding to a target domain attribute. Based on this, Nt target domain time series data of continuous duration can be extracted from the target domain sample data to predict Nt target domain prediction data values at the next moment. Since the present application is suitable for unsupervised anomaly detection, that is, the anomaly labels of the time series data cannot be obtained for training the model, therefore, Nt target domain actual data values and Nt target domain prediction data values at future moments can be used to train the model.
[0267] Specifically, for easier understanding, see Figure 9 , Figure 9 This is a schematic diagram of implementing self-supervised prediction based on the target domain graph neural network in an embodiment of the present application. As shown in the figure, for each time t, the multivariate time series sequence of length L can be expressed as That is, x t =[x t-L ,x t-L+1 ,...,x t-1 ], where the t-th moment to be predicted is taken as the "first moment", the (tL)-th moment is taken as the "fifth moment", and the (t-1)-th moment is taken as the "sixth moment". Based on this, the target domain aggregate feature vector of the i-th target domain attribute at the first moment can be calculated as follows:
[0268]
[0269] in, represents the target domain aggregated feature vector of the i-th target domain attribute at the first moment. Represents the target domain time series data corresponding to the i-th target domain attribute. Indicates the target domain time series data corresponding to the j-th target domain attribute. ij =1} represents Kt target domain attributes that have a connection relationship with the i-th target domain attribute. W represents the neural network aggregation parameter, that is, the model parameter of the target domain graph neural network. ReLU(·) represents the linear rectification function.
[0270] Again, in the embodiment of the present application, a method for obtaining target domain prediction data values based on GNN is provided. Through the above method, the target domain nodes can be directly aggregated by averaging, that is, for Kt neighbor nodes, the weight of each neighbor node is 1 / Kt. Therefore, as a specific implementation method, the feasibility and operability of the solution are guaranteed.
[0271] Optionally, in the above Figure 6On the basis of the corresponding embodiments, in another optional embodiment provided by the embodiments of the present application, based on the target domain sample data, obtaining Nt target domain aggregated feature vectors corresponding to the fourth moment through the target domain graph neural network may specifically include:
[0272] Obtain Nt target domain time series data from the target domain sample data, where the target domain time series data has a one-to-one correspondence with the target domain attributes, and each target domain time series data includes time series data from the fifth moment to the sixth moment, where the fifth moment is a moment before the fourth moment, and the sixth moment is the previous moment adjacent to the fourth moment;
[0273] For each target domain attribute, Kt target domain attributes having a connection relationship with the target domain attribute are determined according to the target domain graph structure corresponding to the target domain graph neural network, wherein the target domain graph neural network belongs to the target domain detection network, and the target domain graph structure includes target domain nodes and target domain edges. The target domain nodes are used to represent the target domain attributes, and the target domain edges are used to represent the connection relationship between the target domain attributes;
[0274] For each target domain attribute, obtain the aggregated attention weight between the target domain attribute and each of the Kt target domain attributes;
[0275] For each target domain attribute, the target domain aggregate feature vector at the fourth moment is obtained based on the model parameters of the target domain graph neural network, the target domain time series data corresponding to the target domain attribute, the aggregated attention weight corresponding to the target domain attribute, the target domain time series data corresponding to each of the Kt target domain attributes, and the aggregated attention weight corresponding to each of the Kt target domain attributes.
[0276] In one or more embodiments, a method for obtaining target domain prediction data values based on an attention-based GNN is described. As can be seen from the aforementioned embodiments, the target domain sample data includes Nt target domain time series data within a period of time, where each target domain time series data is the time series data corresponding to a target domain attribute. Based on this, Nt target domain time series data of consecutive duration can be extracted from the target domain sample data to predict Nt target domain prediction data values at the next moment.
[0277] For details, please refer again to Figure 9 Based on this, the target domain aggregate feature vector of the i-th target domain attribute at the fourth moment can be calculated as follows:
[0278]
[0279] in, represents the target domain aggregate feature vector of the i-th target domain attribute at the fourth moment. Represents the target domain time series data corresponding to the i-th target domain attribute. Indicates the target domain time series data corresponding to the j-th target domain attribute. ij =1} represents the Kt target domain attributes that have a connection relationship with the i-th target domain attribute. W represents the neural network aggregation parameter, that is, the model parameter of the target domain graph neural network. i,j represents the aggregated attention weight between the i-th target domain attribute and the j-th target domain attribute. ReLU(·) represents the function.
[0280] Again, in the embodiments of this application, a method for obtaining target domain prediction data values based on attention GNN is provided. Through the above method, a dynamically changing weight can be assigned to neighbor nodes, thereby better extracting the relationship between target domain attributes. Thus, as another specific implementation method, the feasibility and operability of the solution are ensured.
[0281] Optionally, in the above Figure 6 On the basis of the corresponding embodiments, in another optional embodiment provided by the embodiments of the present application, obtaining the aggregated attention weight between the target domain attribute and each of the Kt target domain attributes may specifically include:
[0282] According to the model parameters of the target domain graph neural network, the target domain time series data corresponding to the target domain attributes, and the target domain embedding vector, the time series splicing vector corresponding to the target domain attributes is obtained;
[0283] Obtain a time series concatenation vector corresponding to each of the Kt target domain attributes according to the model parameters of the target domain graph neural network, the target domain time series data corresponding to each of the Kt target domain attributes, and the target domain embedding vector;
[0284] According to the time series concatenation vector corresponding to the target domain attribute, the target domain intermediate vector corresponding to the target domain attribute is obtained;
[0285] According to the time series concatenation vector corresponding to each of the Kt target domain attributes, a target domain intermediate vector corresponding to each of the Kt target domain attributes is obtained;
[0286] According to the target domain intermediate vector corresponding to the target domain attribute and the target domain intermediate vector corresponding to each of the Kt target domain attributes, the aggregated attention weight between the target domain attribute and each of the Kt target domain attributes is obtained.
[0287] In one or more embodiments, a method for calculating aggregated attention weights is provided. As can be seen from the aforementioned embodiments, taking the i-th target domain attribute as an example, Kt target domain attributes having a connection relationship with it can be obtained based on the target domain graph structure. Based on this, the aggregated attention weight between the i-th target domain attribute and the j-th target domain attribute at the fourth moment can be calculated as follows:
[0288]
[0289] in, Represents the temporal concatenation vector corresponding to the i-th target domain attribute. Represents the target domain time series data corresponding to the i-th target domain attribute. i represents the target domain embedding vector of the i-th target domain attribute. W represents the neural network aggregation parameters, that is, the model parameters of the target domain graph neural network. Represents the concatenation of matrices. π(i,j) represents the target domain intermediate vector between the i-th target domain attribute and the j-th target domain attribute. represents the temporal concatenation vector corresponding to the jth target domain attribute. a(·) represents a trainable parameter. LeakyReLU(·) represents a function. N(i)={j|A ij =1} represents Kt target domain attributes that have a connection relationship with the i-th target domain attribute.
[0290] Furthermore, in an embodiment of the present application, a method for calculating the aggregated attention weight is provided. Through the above method, the aggregated attention weight between the target domain attributes can be calculated in combination with relevant formulas, thereby ensuring the feasibility of the solution.
[0291] Optionally, in the above Figure 6 On the basis of the corresponding embodiments, in another optional embodiment provided by the embodiment of the present application, generating an attribute similarity matrix based on source domain sample data and target domain sample data may specifically include:
[0292] For the time series data corresponding to each source domain attribute in the source domain sample data, and the time series data corresponding to each target domain attribute in the target domain sample data, the similarity between the source domain attribute and the target domain attribute is calculated based on the time series data corresponding to the source domain attribute and the time series data corresponding to the target domain attribute;
[0293] Generate Nt target domain embedding vectors based on the attribute similarity matrix and the updated Ns source domain embedding vectors, which may include:
[0294] Performing transposition processing on the attribute similarity matrix to obtain a transposed attribute similarity matrix;
[0295] Multiply the transposed attribute similarity matrix with the updated Ns source domain embedding vectors to obtain Nt target domain embedding vectors.
[0296] In one or more embodiments, a method for generating an attribute similarity matrix is introduced. As can be seen from the aforementioned embodiments, by combining source domain sample data and target domain sample data, the similarity between each source domain attribute and each target domain attribute can be calculated, thereby obtaining an Ns×Nt similarity matrix.
[0297] Specifically, the target domain embedding matrix can be calculated as follows:
[0298] V t =V s ×M T Formula (21)
[0299] Among them, V t represents the target domain embedding matrix, i.e., includes Nt target domain embedding vectors, and V t The target domain embedding vector in is represented as i∈{1,2,...,Nt}. V s represents the source domain embedding matrix, i.e., includes the updated Ns source domain embedding vectors, and, V s The source domain embedding vector in is represented as i∈{1,2,...,Ns}. M represents the attribute similarity matrix, and (·) T Indicates transpose.
[0300] Secondly, in the embodiment of the present application, a method for generating an attribute similarity matrix is provided. Through the above method, considering that the time series data may be long, the sliding window similarity calculation method is simpler, less complex, and more efficient.
[0301] Optionally, in the above Figure 6 On the basis of the corresponding embodiments, in another optional embodiment provided by the embodiments of the present application, the similarity between the source domain attribute and the target domain attribute is calculated based on the time series data corresponding to the source domain attribute and the time series data corresponding to the target domain attribute, which may specifically include:
[0302] If the time series data corresponding to the source domain attribute is greater than or equal to the time series data corresponding to the target domain attribute, a first sliding window is generated according to the time series data corresponding to the target domain attribute, where the first sliding window is Tt, and Tt is an integer greater than 1;
[0303] Based on the first sliding window, slide the time series data corresponding to the source domain attribute with a first preset step size to obtain P first sub-time series data, where P is an integer greater than or equal to 1;
[0304] Calculate the similarity between the time series data corresponding to the target domain attribute and each first sub-time series data to obtain P sequence similarities;
[0305] Average the similarities of P sequences to obtain the similarity between the source domain attributes and the target domain attributes;
[0306] or,
[0307] Based on the time series data corresponding to the source domain attributes and the time series data corresponding to the target domain attributes, the similarity between the source domain attributes and the target domain attributes is calculated. Specifically, the similarity may include:
[0308] If the time series data corresponding to the target domain attribute is greater than or equal to the time series data corresponding to the source domain attribute, a second sliding window is generated according to the time series data corresponding to the source domain attribute, where the second sliding window is Ts, and Ts is an integer greater than 1;
[0309] Based on the second sliding window, slide the time series data corresponding to the target domain attribute with a second preset step size to obtain Q second sub-time series data, where Q is an integer greater than or equal to 1;
[0310] Calculate the similarity between the time series data corresponding to the source domain attribute and each second sub-time series data to obtain Q sequence similarities;
[0311] The similarities of the Q sequences are averaged to obtain the similarity between the source domain attributes and the target domain attributes.
[0312] In one or more embodiments, a method for calculating the similarity between attributes using a sliding window similarity function is provided. As can be seen from the aforementioned embodiments, by calculating the similarity between cross-domain attributes (i.e., the similarity between source domain attributes and target domain attributes), cross-domain attribute association information can be obtained, and the model is initialized by combining the Ns source domain embedding vectors obtained from source domain training and the Nt target domain embedding vectors with the model parameters. This allows the target domain to inherit the anomaly detection capability of the source domain model without having to train the model from scratch. Based on this, the following will introduce a method for calculating the similarity between source domain attributes and target domain attributes in combination with two scenarios.
[0313] Case 1: The time series data corresponding to the source domain attribute is greater than or equal to the time series data corresponding to the target domain attribute;
[0314] Specifically, assuming that the source domain sample data is The target domain sample data is Moreover, Ts≥Tt. Based on this, the shorter Tt duration can be used as the first sliding window.
[0315] Take the calculation of the similarity between the i-th source domain attribute and the j-th target domain attribute as an example. First, based on the size of the first sliding window, the time series data corresponding to the i-th source domain attribute can be slid with a first preset step size, thereby obtaining P first sub-time series data. Then, the similarity between the time series data corresponding to the j-th target domain attribute and each first sub-time series data is calculated respectively to obtain P sequence similarities. Finally, the P sequence similarities are averaged to obtain the similarity between the i-th source domain attribute and the j-th target domain attribute. The specific calculation method is:
[0316] M i,j =SlidingSim(X s,i ,X t,j ); Formula (22)
[0317] Among them, M i,j represents the similarity between the i-th source domain attribute and the j-th target domain attribute. s,i represents the time series data corresponding to the i-th source domain attribute, and, X t,j represents the time series data corresponding to the j-th target domain attribute, and, SlidingSim(·) represents the sliding window similarity function, which can be used to calculate the similarity between time series of different lengths.
[0318] Furthermore, the sliding window similarity function is calculated as follows:
[0319] SlidingSim(X s,i ,X t,j )=mean{cos(X s,i [k:k+T t ],X t,j )|k∈[0:stride:T s -T t ]}; Formula (23)
[0320] Where SlidingSim(·) represents the sliding window similarity function. s,i Represents the time series data corresponding to the i-th source domain attribute. t,j Represents the time series data corresponding to the j-th target domain attribute. s Indicates the duration of the source domain sample data. trepresents the duration of the target domain sample data. mean(·) represents the average of the elements in the set. cos(·) represents the cosine similarity. stride is a manually set step size of the sliding window. k represents a variable.
[0321] Case 2: The time series data corresponding to the target domain attribute is greater than or equal to the time series data corresponding to the source domain attribute;
[0322] Specifically, assuming that the source domain sample data is The target domain sample data is Moreover, Ts≤Tt. Based on this, the shorter duration Ts can be used as the second sliding window.
[0323] Take the calculation of the similarity between the i-th source domain attribute and the j-th target domain attribute as an example. First, based on the size of the second sliding window, the second preset step size can be used to slide on the time series data corresponding to the j-th target domain attribute, thereby obtaining Q second sub-time series data. Then, the similarity between the time series data corresponding to the i-th source domain attribute and each second sub-time series data is calculated respectively, obtaining Q sequence similarities. Finally, the Q sequence similarities are averaged to obtain the similarity between the i-th source domain attribute and the j-th target domain attribute.
[0324] It should be noted that due to the different calculation methods of Case 2 and Case 1, they will not be described here. It is understood that the above formula uses cosine similarity for calculation. In practical applications, other types of similarity algorithms can also be used. This is only an illustration and should not be understood as a limitation of this application.
[0325] As can be seen, in short, sliding window similarity is to slide the shorter sequence on the longer sequence with a specified step size, and calculate the similarity of each step (for example, cosine similarity), and finally take the average of all step similarities as the similarity of the two sequences. This method can calculate the similarity of time series of different lengths, and the time consumption of the algorithm can be controlled according to the sliding step size.
[0326] Again, in the embodiment of the present application, a method for calculating the similarity between attributes using a sliding window similarity function is provided. Through the above method, the similarity between attributes can be calculated in combination with relevant formulas, thereby ensuring the feasibility of the solution.
[0327] Combined with the above introduction, the following will introduce the anomaly detection method of time series data in this application. Figure 10 In the embodiment of the present application, the method for detecting anomalies in time series data may be executed by a computer device, which may be a terminal device or a server. The embodiment of the present application includes:
[0328] 310. Acquire data to be detected, wherein the data to be detected includes time series data of Nt target domain attributes, and the time series data of each target domain attribute includes data at T moments, where Nt and T are both integers greater than 1;
[0329] In one or more embodiments, the data to be detected is obtained. For ease of understanding, please refer to Figure 11 , Figure 11 This is a system framework diagram of the time series data anomaly detection method in an embodiment of the present application. As shown in the figure, the data to be detected includes time series data of Nt target domain attributes, and the time series data of each target domain attribute includes data collected at T consecutive moments.
[0330] 320. Based on the data to be detected, obtain Nt predicted data values corresponding to the target time through a target domain detection network, wherein the target domain detection network is trained using any of the methods in the above embodiments;
[0331] In one or more embodiments, the data to be detected is used as input to the target domain detection network, which then outputs Nt predicted data values corresponding to the next moment (i.e., the target moment). It should be noted that the target domain detection network has been introduced in the aforementioned embodiments and will not be further described here.
[0332] 330. Obtain Nt actual data values corresponding to the target time;
[0333] In one or more embodiments, when entering the next moment (ie, the target moment), Nt actual data values may be obtained, ie, N actual data values corresponding to each target domain attribute at the target moment.
[0334] 340. Calculate the anomaly score corresponding to the target time based on the Nt actual data values and the Nt predicted data values;
[0335] In one or more embodiments, the anomaly score for the target moment may be further calculated based on the differences between the Nt actual data values and the Nt predicted data values.
[0336] 350. If the anomaly score corresponding to the target moment is greater than or equal to the anomaly score threshold, the target moment is determined to be a data anomaly moment.
[0337] In one or more embodiments, if the anomaly score corresponding to the target moment is greater than or equal to the anomaly score threshold, the target moment is determined to be a data anomaly moment, i.e., an anomaly may have occurred at the target moment. Conversely, if the anomaly score corresponding to the target moment is less than the anomaly score threshold, the target moment is determined to be a data normal moment, i.e., no anomaly has occurred at the target moment.
[0338] Specifically, for ease of introduction, the following explanation will be combined with sensor scenarios. After the sensors are deployed, sensor data is continuously transmitted to the data storage end. That is, a model can be built using multivariate time series sensor data, and anomaly scores are assigned to the data at each moment. Data points with anomaly scores above the anomaly score threshold are identified as outliers, allowing subsequent operation and maintenance personnel to analyze and process the anomalies. When the sensor system is upgraded (the number or model of sensors changes), the historical model can still be used (i.e., the target domain detection network of the old system is used as the source domain detection network of the new system). Based on the historical model (i.e., the source domain detection network), combined with inter-domain connections and new data, training can be performed to achieve anomaly detection in the new system.
[0339] In an embodiment of the present application, a method for detecting anomalies in time series data is provided. This approach reduces the time complexity of the anomaly detection phase and can be flexibly applied to various multivariate time series systems to achieve real-time anomaly detection. Furthermore, historical data can be effectively utilized to mitigate cold start issues caused by system upgrades.
[0340] Optionally, in the above Figure 10 On the basis of the corresponding embodiments, in another optional embodiment provided by the embodiment of the present application, the anomaly score corresponding to the target time is calculated based on Nt actual data values and Nt predicted data values, which may specifically include:
[0341] For each target domain attribute, calculate the mean and variance corresponding to the target domain attribute;
[0342] For each target domain attribute, calculate the absolute value of the difference between the predicted data value corresponding to the target domain attribute and the actual data value to obtain the first data value corresponding to the target domain attribute;
[0343] For each target domain attribute, the difference between the first data value corresponding to the target domain attribute and the mean value corresponding to the target domain attribute is calculated to obtain a second data value corresponding to the target domain attribute;
[0344] For each target domain attribute, taking the quotient of the second data value corresponding to the target domain attribute and the variance corresponding to the target domain attribute to obtain a third data value corresponding to the target domain attribute;
[0345] The maximum value is selected from the third data values corresponding to each target domain attribute as the anomaly score corresponding to the target moment.
[0346] In one or more embodiments, a method for calculating anomaly scores is introduced. As can be seen from the aforementioned embodiments, the source domain and the target domain are respectively trained to obtain a detection network based on a graph neural network to predict attributes at future moments. For given test data, the present application can identify anomalies in time series data based on the prediction error. Since the present application is aimed at multivariate time series data, for ease of explanation, one target domain attribute among Nt target domain attributes will be used as an example for introduction below. Other target domain attributes are also calculated in a similar manner and are not listed here one by one.
[0347] Specifically, given the multivariate nature of data, the ranges of the target domain attributes may vary significantly, and anomalies typically only occur in some of the target domain attributes. Therefore, it is necessary to normalize the prediction error and select the maximum attribute prediction error as the anomaly score. Specifically, first, based on the time series data corresponding to each target domain attribute, the mean and variance corresponding to each target domain attribute can be calculated. Then, the anomaly score corresponding to the target moment is calculated using the following method:
[0348]
[0349] Where Anomaly Score represents the anomaly score corresponding to the target time. t represents the target time. max(·) represents the maximum value. μ represents Nt means, i.e., the means corresponding to each target domain attribute. σ represents Nt variances, i.e., the variances corresponding to each target domain attribute. Represents Nt predicted data values at the target time, that is, including the predicted data value corresponding to each target domain attribute. t Represents Nt predicted data values at the target time, that is, including the actual data value corresponding to each target domain attribute.
[0350] Based on this, for a target domain attribute, the predicted data value and actual data value corresponding to the target domain attribute are substituted into The first data value corresponding to the target domain attribute can be calculated. Based on this, the first data value corresponding to the target domain attribute and the mean value corresponding to the target domain attribute are substituted into The second data value corresponding to the target domain attribute can be calculated. Finally, the second data value corresponding to the target domain attribute and the variance corresponding to the target domain attribute are substituted into The third data value corresponding to the target domain attribute can be calculated.
[0351] It should be noted that in practical applications, in addition to directly selecting the maximum target domain attribute prediction error as the anomaly score, if the multivariate time series system has many attribute anomalies, the average prediction error or the top K average prediction errors can also be used to design the anomaly score calculation formula.
[0352] Secondly, in the embodiment of the present application, a method for calculating anomaly scores is provided. Through the above method, the anomaly scores can be calculated in combination with relevant formulas to ensure the feasibility of the solution.
[0353] The parameter optimization device in this application is described in detail below. Figure 12 , Figure 12 This is a schematic diagram of an embodiment of a parameter optimization device in an embodiment of the present application. The parameter optimization device 40 includes:
[0354] An acquisition module 410 is configured to acquire source domain sample data and target domain sample data, wherein the source domain sample data includes time series data of Ns source domain attributes, and the target domain sample data includes time series data of Nt target domain attributes, where both Ns and Nt are integers greater than 1.
[0355] A construction module 420 is configured to construct a source domain graph neural network based on the Ns source domain embedding vectors corresponding to the Ns source domain attributes, wherein the source domain embedding vectors have a one-to-one correspondence with the source domain attributes;
[0356] A training module 430 is configured to update Ns source domain embedding vectors and model parameters of a source domain detection network based on the source domain sample data, wherein the source domain detection network includes a source domain graph neural network;
[0357] A generating module 440 is configured to generate an attribute similarity matrix based on the source domain sample data and the target domain sample data, wherein the attribute similarity matrix is used to describe the similarity between each source domain attribute and each target domain attribute;
[0358] The generating module 440 is further configured to generate Nt target domain embedding vectors based on the attribute similarity matrix and the updated Ns source domain embedding vectors, wherein the target domain embedding vectors have a one-to-one correspondence with the target domain attributes;
[0359] The construction module 420 is further configured to construct a target domain graph neural network based on the Nt target domain embedding vectors, wherein the model parameters of the target domain graph neural network adopt the updated model parameters of the source domain graph neural network;
[0360] The training module 430 is further configured to update the Nt target domain embedding vectors and the model parameters of the target domain detection network according to the target domain sample data, wherein the target domain detection network includes a target domain graph neural network.
[0361] Optionally, in the above Figure 12 On the basis of the corresponding embodiment, in another embodiment of the parameter optimization device 40 provided in the embodiment of the present application,
[0362] The construction module 420 is specifically configured to calculate, for each source domain attribute, (Ns-1) vector similarities based on the source domain embedding vector corresponding to the source domain attribute and the source domain embedding vectors corresponding to the remaining source domain attributes, where the remaining source domain attributes are the (Ns-1) source domain attributes remaining in the Ns source domain attributes except the source domain attribute.
[0363] For each source domain attribute, determine the largest Ks vector similarities from (Ns-1) vector similarities, where Ks is an integer greater than or equal to 1 and less than (Ns-1);
[0364] For each source domain attribute, determine Ks source domain attributes that have a connection relationship with the source domain attribute based on the largest Ks vector similarities, wherein the vector similarities in the Ks vector similarities have a one-to-one correspondence with the source domain attributes in the Ks source domain attributes;
[0365] According to each source domain attribute and Ks source domain attributes that have a connection relationship with each source domain attribute, a source domain graph structure is constructed, wherein the source domain graph structure includes source domain nodes and source domain edges. The source domain nodes are used to represent source domain attributes, and the source domain edges are used to represent the connection relationship between different source domain attributes;
[0366] According to the source domain graph structure and Ns source domain embedding vectors, a source domain graph neural network is constructed.
[0367] Optionally, in the above Figure 12 On the basis of the corresponding embodiment, in another embodiment of the parameter optimization device 40 provided in the embodiment of the present application,
[0368] The construction module 420 is specifically configured to calculate (Nt-1) vector similarities for each target domain attribute based on the target domain embedding vector corresponding to the target domain attribute and the target domain embedding vectors corresponding to the remaining target domain attributes, where the remaining target domain attributes are the remaining (Nt-1) target domain attributes in the Nt target domain attributes except the target domain attribute.
[0369] For each target domain attribute, determine the largest Kt vector similarities from the (Nt-1) vector similarities, where Kt is an integer greater than or equal to 1 and less than (Nt-1);
[0370] For each target domain attribute, determine Kt target domain attributes that have a connection relationship with the target domain attribute based on the largest Kt vector similarities, wherein the vector similarities in the Kt vector similarities have a one-to-one correspondence with the target domain attributes in the Kt target domain attributes;
[0371] According to each target domain attribute and Kt target domain attributes that have a connection relationship with each target domain attribute, a target domain graph structure is constructed, wherein the target domain graph structure includes target domain nodes and target domain edges. The target domain nodes are used to represent the target domain attributes, and the target domain edges are used to represent the connection relationship between different target domain attributes.
[0372] According to the target domain graph structure and Nt target domain embedding vectors, a target domain graph neural network is constructed.
[0373] Optionally, in the above Figure 12 On the basis of the corresponding embodiment, in another embodiment of the parameter optimization device 40 provided in the embodiment of the present application,
[0374] A training module 430 is specifically configured to obtain Ns source domain aggregated feature vectors corresponding to a first moment based on the source domain sample data through a source domain graph neural network, wherein the source domain aggregated feature vectors have a one-to-one correspondence with source domain attributes, and the source domain graph neural network is a source domain detection network;
[0375] Based on the Ns source domain aggregated feature vectors and the Ns source domain embedding vectors, obtaining Ns source domain prediction data values corresponding to the first moment through a first fully connected layer included in the source domain detection network, where the source domain prediction data values have a one-to-one correspondence with the source domain attributes;
[0376] Constructing a first loss function based on Ns source domain predicted data values and Ns source domain actual data values corresponding to the first moment, wherein the Ns source domain actual data values are derived from the source domain sample data;
[0377] Based on the first loss function, update the Ns source domain embedding vectors;
[0378] Based on the first loss function, the model parameters of the source domain graph neural network and the model parameters of the first fully connected layer are updated.
[0379] Optionally, in the above Figure 12 On the basis of the corresponding embodiment, in another embodiment of the parameter optimization device 40 provided in the embodiment of the present application,
[0380] The training module 430 is specifically configured to obtain Ns source domain time series data from the source domain sample data, wherein the source domain time series data has a one-to-one correspondence with the source domain attributes, and each source domain time series data includes time series data from a second moment to a third moment, where the second moment is a moment before the first moment, and the third moment is a moment immediately preceding the first moment;
[0381] For each source domain attribute, determine Ks source domain attributes that have a connection relationship with the source domain attribute based on the source domain graph structure corresponding to the source domain graph neural network. The source domain graph neural network belongs to the source domain detection network. The source domain graph structure includes source domain nodes and source domain edges. The source domain nodes are used to represent source domain attributes, and the source domain edges are used to represent the connection relationship between source domain attributes.
[0382] For each source domain attribute, the source domain aggregated feature vector at the first moment is obtained based on the model parameters of the source domain graph neural network, the source domain time series data corresponding to the source domain attribute, and the source domain time series data corresponding to each of the Ks source domain attributes.
[0383] Optionally, in the above Figure 12 On the basis of the corresponding embodiment, in another embodiment of the parameter optimization device 40 provided in the embodiment of the present application,
[0384] The training module 430 is specifically configured to obtain Ns source domain time series data from the source domain sample data, wherein the source domain time series data has a one-to-one correspondence with the source domain attributes, and each source domain time series data includes time series data from a second moment to a third moment, where the second moment is a moment before the first moment, and the third moment is a moment immediately preceding the first moment;
[0385] For each source domain attribute, determine Ks source domain attributes that have a connection relationship with the source domain attribute based on the source domain graph structure corresponding to the source domain graph neural network. The source domain graph neural network belongs to the source domain detection network. The source domain graph structure includes source domain nodes and source domain edges. The source domain nodes are used to represent source domain attributes, and the source domain edges are used to represent the connection relationship between source domain attributes.
[0386] For each source domain attribute, obtain the aggregated attention weight between the source domain attribute and each of the Ks source domain attributes;
[0387] For each source domain attribute, the source domain aggregated feature vector at the first moment is obtained based on the model parameters of the source domain graph neural network, the source domain time series data corresponding to the source domain attribute, the aggregated attention weight corresponding to the source domain attribute, the source domain time series data corresponding to each of the Ks source domain attributes, and the aggregated attention weight corresponding to each of the Ks source domain attributes.
[0388] Optionally, in the above Figure 12 On the basis of the corresponding embodiment, in another embodiment of the parameter optimization device 40 provided in the embodiment of the present application,
[0389] The training module 430 is specifically configured to obtain a time series concatenation vector corresponding to a source domain attribute based on model parameters of the source domain graph neural network, source domain time series data corresponding to the source domain attribute, and a source domain embedding vector;
[0390] Obtain a time series concatenation vector corresponding to each of the Ks source domain attributes according to the model parameters of the source domain graph neural network, the source domain time series data corresponding to each of the Ks source domain attributes, and the source domain embedding vector;
[0391] According to the time series splicing vector corresponding to the source domain attribute, the source domain intermediate vector corresponding to the source domain attribute is obtained;
[0392] According to the time series concatenation vector corresponding to each source domain attribute in the Ks source domain attributes, obtain the source domain intermediate vector corresponding to each source domain attribute in the Ks source domain attributes;
[0393] According to the source domain intermediate vector corresponding to the source domain attribute and the source domain intermediate vector corresponding to each of the Ks source domain attributes, the aggregated attention weight between the source domain attribute and each of the Ks source domain attributes is obtained.
[0394] Optionally, in the above Figure 12 On the basis of the corresponding embodiment, in another embodiment of the parameter optimization device 40 provided in the embodiment of the present application,
[0395] A training module 430 is specifically configured to obtain Nt target domain aggregated feature vectors corresponding to the fourth moment through a target domain graph neural network based on the target domain sample data, wherein the target domain aggregated feature vectors have a one-to-one correspondence with the target domain attributes, and the target domain graph neural network belongs to the target domain detection network;
[0396] Based on the Nt target domain aggregated feature vectors and the Nt target domain embedding vectors, obtaining Nt target domain prediction data values corresponding to the fourth moment through the second fully connected layer included in the target domain detection network, where the target domain prediction data values have a one-to-one correspondence with the target domain attributes;
[0397] Constructing a second loss function based on the Nt target domain predicted data values and the Nt target domain actual data values corresponding to the fourth moment, wherein the Nt target domain actual data values are derived from the target domain sample data;
[0398] Based on the second loss function, the Nt target domain embedding vectors are updated;
[0399] Based on the second loss function, the model parameters of the target domain graph neural network and the model parameters of the second fully connected layer are updated.
[0400] Optionally, in the above Figure 12 On the basis of the corresponding embodiment, in another embodiment of the parameter optimization device 40 provided in the embodiment of the present application,
[0401] The training module 430 is specifically configured to obtain Nt target domain time series data from the target domain sample data, wherein the target domain time series data has a one-to-one correspondence with the target domain attributes, and each target domain time series data includes time series data from a fifth moment to a sixth moment, where the fifth moment is a moment before the first moment, and the sixth moment is a moment immediately preceding the first moment;
[0402] For each target domain attribute, Kt target domain attributes having a connection relationship with the target domain attribute are determined according to the target domain graph structure corresponding to the target domain graph neural network, wherein the target domain graph neural network belongs to the target domain detection network, and the target domain graph structure includes target domain nodes and target domain edges. The target domain nodes are used to represent the target domain attributes, and the target domain edges are used to represent the connection relationship between the target domain attributes;
[0403] For each target domain attribute, the target domain aggregated feature vector at the fourth moment is obtained based on the model parameters of the target domain graph neural network, the target domain time series data corresponding to the target domain attribute, and the target domain time series data corresponding to each of the Kt target domain attributes.
[0404] Optionally, in the above Figure 12 On the basis of the corresponding embodiment, in another embodiment of the parameter optimization device 40 provided in the embodiment of the present application,
[0405] The training module 430 is specifically configured to obtain Nt target domain time series data from the target domain sample data, wherein the target domain time series data has a one-to-one correspondence with the target domain attributes, and each target domain time series data includes time series data from a fifth moment to a sixth moment, where the fifth moment is a moment before the fourth moment, and the sixth moment is a moment immediately preceding the fourth moment;
[0406] For each target domain attribute, Kt target domain attributes having a connection relationship with the target domain attribute are determined according to the target domain graph structure corresponding to the target domain graph neural network, wherein the target domain graph neural network belongs to the target domain detection network, and the target domain graph structure includes target domain nodes and target domain edges. The target domain nodes are used to represent the target domain attributes, and the target domain edges are used to represent the connection relationship between the target domain attributes;
[0407] For each target domain attribute, obtain the aggregated attention weight between the target domain attribute and each of the Kt target domain attributes;
[0408] For each target domain attribute, the target domain aggregate feature vector at the fourth moment is obtained based on the model parameters of the target domain graph neural network, the target domain time series data corresponding to the target domain attribute, the aggregated attention weight corresponding to the target domain attribute, the target domain time series data corresponding to each of the Kt target domain attributes, and the aggregated attention weight corresponding to each of the Kt target domain attributes.
[0409] Optionally, in the above Figure 12 On the basis of the corresponding embodiment, in another embodiment of the parameter optimization device 40 provided in the embodiment of the present application,
[0410] The training module 430 is specifically configured to obtain a time series concatenation vector corresponding to the target domain attribute based on the model parameters of the target domain graph neural network, the target domain time series data corresponding to the target domain attribute, and the target domain embedding vector;
[0411] Obtain a time series concatenation vector corresponding to each of the Kt target domain attributes according to the model parameters of the target domain graph neural network, the target domain time series data corresponding to each of the Kt target domain attributes, and the target domain embedding vector;
[0412] According to the time series concatenation vector corresponding to the target domain attribute, the target domain intermediate vector corresponding to the target domain attribute is obtained;
[0413] According to the time series concatenation vector corresponding to each of the Kt target domain attributes, a target domain intermediate vector corresponding to each of the Kt target domain attributes is obtained;
[0414] According to the target domain intermediate vector corresponding to the target domain attribute and the target domain intermediate vector corresponding to each of the Kt target domain attributes, the aggregated attention weight between the target domain attribute and each of the Kt target domain attributes is obtained.
[0415] Optionally, in the above Figure 12 On the basis of the corresponding embodiment, in another embodiment of the parameter optimization device 40 provided in the embodiment of the present application,
[0416] The generation module 440 is specifically configured to calculate the similarity between the source domain attribute and the target domain attribute based on the time series data corresponding to each source domain attribute in the source domain sample data and the time series data corresponding to each target domain attribute in the target domain sample data.
[0417] The generating module 440 is specifically used to perform a transposition process on the attribute similarity matrix to obtain a transposed attribute similarity matrix;
[0418] Multiply the transposed attribute similarity matrix with the updated Ns source domain embedding vectors to obtain Nt target domain embedding vectors.
[0419] Optionally, in the above Figure 12 On the basis of the corresponding embodiment, in another embodiment of the parameter optimization device 40 provided in the embodiment of the present application,
[0420] The generating module 440 is specifically configured to generate a first sliding window based on the time series data corresponding to the target domain attribute if the time series data corresponding to the source domain attribute is greater than or equal to the time series data corresponding to the target domain attribute, wherein the first sliding window is Tt, where Tt is an integer greater than 1;
[0421] Based on the first sliding window, slide the time series data corresponding to the source domain attribute with a first preset step size to obtain P first sub-time series data, where P is an integer greater than or equal to 1;
[0422] Calculate the similarity between the time series data corresponding to the target domain attribute and each first sub-time series data to obtain P sequence similarities;
[0423] Average the similarities of P sequences to obtain the similarity between the source domain attributes and the target domain attributes;
[0424] or,
[0425] The generating module 440 is specifically configured to generate a second sliding window based on the time series data corresponding to the source domain attribute if the time series data corresponding to the target domain attribute is greater than or equal to the time series data corresponding to the source domain attribute, wherein the second sliding window is Ts, and Ts is an integer greater than 1;
[0426] Based on the second sliding window, slide the time series data corresponding to the target domain attribute with a second preset step size to obtain Q second sub-time series data, where Q is an integer greater than or equal to 1;
[0427] Calculate the similarity between the time series data corresponding to the source domain attribute and each second sub-time series data to obtain Q sequence similarities;
[0428] The similarities of the Q sequences are averaged to obtain the similarity between the source domain attributes and the target domain attributes.
[0429] The following is a detailed description of the abnormality detection device in this application. Figure 13 , Figure 13 This is a schematic diagram of an embodiment of an abnormality detection device in an embodiment of the present application. The abnormality detection device 50 includes:
[0430] An acquisition module 510 is configured to acquire data to be detected, wherein the data to be detected includes time series data of Nt target domain attributes, each time series data of the target domain attribute includes data at T moments, and both Nt and T are integers greater than 1;
[0431] The acquisition module 510 is further configured to acquire Nt predicted data values corresponding to the target time through the target domain detection network based on the data to be detected, wherein the target domain detection network is trained using the above method;
[0432] The acquisition module 510 is further configured to acquire Nt actual data values corresponding to the target time;
[0433] A determination module 520 is configured to calculate an anomaly score corresponding to a target time based on Nt actual data values and Nt predicted data values;
[0434] The determination module 520 is further configured to determine that the target moment is a data anomaly moment if the anomaly score corresponding to the target moment is greater than or equal to the anomaly score threshold.
[0435] Optionally, in the above Figure 13 On the basis of the corresponding embodiment, in another embodiment of the abnormality detection device 50 provided in the embodiment of the present application,
[0436] The determination module 520 is specifically configured to calculate the mean and variance corresponding to each target domain attribute;
[0437] For each target domain attribute, calculate the absolute value of the difference between the predicted data value corresponding to the target domain attribute and the actual data value to obtain the first data value corresponding to the target domain attribute;
[0438] For each target domain attribute, the difference between the first data value corresponding to the target domain attribute and the mean value corresponding to the target domain attribute is calculated to obtain a second data value corresponding to the target domain attribute;
[0439] For each target domain attribute, taking the quotient of the second data value corresponding to the target domain attribute and the variance corresponding to the target domain attribute to obtain a third data value corresponding to the target domain attribute;
[0440] The maximum value is selected from the third data values corresponding to each target domain attribute as the anomaly score corresponding to the target moment.
[0441] Figure 14: This is a schematic diagram of the structure of a computer device provided in an embodiment of the present application. The computer device 600 may have relatively large differences due to different configurations or performances, and may include one or more central processing units (CPU) 622 (for example, one or more processors) and memory 632, and one or more storage media 630 (for example, one or more mass storage devices) for storing application programs 642 or data 644. Among them, the memory 632 and the storage medium 630 can be temporary storage or permanent storage. The program stored in the storage medium 630 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations in the computer device. Furthermore, the central processing unit 622 can be configured to communicate with the storage medium 630 to execute a series of instruction operations in the storage medium 630 on the computer device 600.
[0442] The computer device 600 may also include one or more power supplies 626, one or more wired or wireless network interfaces 650, one or more input and output interfaces 658, and / or one or more operating systems 641, such as Windows Server 2008. TM , Mac OS X TM , Unix TM , Linux TM , FreeBSD TM etc.
[0443] The steps performed by the computer device in the above embodiment can be based on the Figure 14 The computer device structure shown.
[0444] A computer device is also provided in an embodiment of the present application, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the steps of the methods described in the above embodiments are implemented.
[0445] A computer-readable storage medium is also provided in an embodiment of the present application, on which a computer program is stored. When the computer program is executed by a processor, the steps of the methods described in the above embodiments are implemented.
[0446] A computer program product is also provided in an embodiment of the present application, including a computer program. When the computer program is executed by a processor, the steps of the methods described in the above embodiments are implemented.
[0447] It is understandable that in the specific implementation of this application, time series data, etc. are involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.
[0448] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0449] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0450] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0451] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0452] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a server or terminal device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store computer programs, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0453] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for optimizing model parameters, characterized in that: include: Obtaining source domain sample data and target domain sample data, wherein the source domain sample data includes time series data of Ns source domain attributes, and the target domain sample data includes time series data of Nt target domain attributes, where both Ns and Nt are integers greater than 1, and the time series data includes any one of game data, driving data, network data, and meteorological data; the game data includes movement speed data and movement distance data corresponding to each frame of a player; the driving data includes speed data, acceleration data, and direction data; the network data includes connection duration data, transmission byte data, and connection type data; and the meteorological data includes temperature data, humidity data, and air pressure data; Constructing a source domain graph neural network according to the Ns source domain embedding vectors corresponding to the Ns source domain attributes, wherein the source domain embedding vectors have a one-to-one correspondence with the source domain attributes; According to the source domain sample data, the Ns source domain embedding vectors and model parameters of the source domain detection network are updated, wherein the source domain detection network includes the source domain graph neural network; Generate an attribute similarity matrix based on the source domain sample data and the target domain sample data, wherein the attribute similarity matrix is used to describe the similarity between each source domain attribute and each target domain attribute; Generate Nt target domain embedding vectors according to the attribute similarity matrix and the updated Ns source domain embedding vectors, wherein the target domain embedding vectors have a one-to-one correspondence with the target domain attributes; Constructing a target domain graph neural network based on the Nt target domain embedding vectors, wherein the model parameters of the target domain graph neural network adopt the updated model parameters of the source domain graph neural network; According to the target domain sample data, the Nt target domain embedding vectors and model parameters of the target domain detection network are updated, wherein the target domain detection network includes the target domain graph neural network.
2. The optimization method according to claim 1, characterized in that The constructing a source domain graph neural network according to the Ns source domain embedding vectors corresponding to the Ns source domain attributes includes: For each source domain attribute, (Ns-1) vector similarities are calculated based on the source domain embedding vector corresponding to the source domain attribute and the source domain embedding vectors corresponding to the remaining source domain attributes, where the remaining source domain attributes are the remaining (Ns-1) source domain attributes in the Ns source domain attributes except the source domain attribute; For each source domain attribute, determine the largest Ks vector similarities from the (Ns-1) vector similarities, where Ks is an integer greater than or equal to 1 and less than (Ns-1); For each source domain attribute, determining, based on the largest Ks vector similarities, Ks source domain attributes that have a connection relationship with the source domain attribute, wherein a vector similarity in the Ks vector similarities has a one-to-one correspondence with a source domain attribute in the Ks source domain attributes; Constructing a source domain graph structure according to each source domain attribute and Ks source domain attributes that are respectively connected to each source domain attribute, wherein the source domain graph structure includes source domain nodes and source domain edges, the source domain nodes are used to represent source domain attributes, and the source domain edges are used to represent that different source domain attributes have a connection relationship; The source domain graph neural network is constructed according to the source domain graph structure and the Ns source domain embedding vectors.
3. The optimization method according to claim 1, characterized in that The step of constructing a target domain graph neural network based on the Nt target domain embedding vectors includes: For each target domain attribute, (Nt-1) vector similarities are calculated based on the target domain embedding vector corresponding to the target domain attribute and the target domain embedding vectors corresponding to the remaining target domain attributes, where the remaining target domain attributes are the remaining (Nt-1) target domain attributes in the Nt target domain attributes except the target domain attribute; For each target domain attribute, determine the largest Kt vector similarities from the (Nt-1) vector similarities, where Kt is an integer greater than or equal to 1 and less than (Nt-1); For each target domain attribute, determining Kt target domain attributes having a connection relationship with the target domain attribute according to the largest Kt vector similarities, wherein a vector similarity in the Kt vector similarities has a one-to-one correspondence with a target domain attribute in the Kt target domain attributes; Constructing a target domain graph structure according to each target domain attribute and Kt target domain attributes that are respectively connected to each target domain attribute, wherein the target domain graph structure includes target domain nodes and target domain edges, the target domain nodes are used to represent target domain attributes, and the target domain edges are used to represent that different target domain attributes have a connection relationship; The target domain graph neural network is constructed according to the target domain graph structure and the Nt target domain embedding vectors.
4. The optimization method according to claim 1, characterized in that The updating of the Ns source domain embedding vectors and the model parameters of the source domain detection network according to the source domain sample data includes: Based on the source domain sample data, obtaining Ns source domain aggregated feature vectors corresponding to the first moment through the source domain graph neural network, wherein the source domain aggregated feature vectors have a one-to-one correspondence with the source domain attributes, and the source domain graph neural network belongs to the source domain detection network; Based on the Ns source domain aggregated feature vectors and the Ns source domain embedding vectors, obtaining, through a first fully connected layer included in the source domain detection network, Ns source domain prediction data values corresponding to the first moment, wherein the source domain prediction data values have a one-to-one correspondence with the source domain attributes; Constructing a first loss function according to the Ns source domain predicted data values and the Ns source domain actual data values corresponding to the first moment, wherein the Ns source domain actual data values are derived from the source domain sample data; Based on the first loss function, updating the Ns source domain embedding vectors; Based on the first loss function, the model parameters of the source domain graph neural network and the model parameters of the first fully connected layer are updated.
5. The optimization method according to claim 4, characterized in that: The obtaining, based on the source domain sample data, Ns source domain aggregated feature vectors corresponding to the first moment through the source domain graph neural network includes: Obtain Ns source domain time series data from the source domain sample data, wherein the source domain time series data has a one-to-one correspondence with the source domain attributes, and each source domain time series data includes time series data from a second moment to a third moment, where the second moment is a moment occurring before the first moment, and the third moment is a moment immediately preceding the first moment; For each source domain attribute, determine Ks source domain attributes having a connection relationship with the source domain attribute according to the source domain graph structure corresponding to the source domain graph neural network, wherein the source domain graph neural network belongs to the source domain detection network, and the source domain graph structure includes source domain nodes and source domain edges, the source domain nodes are used to represent source domain attributes, and the source domain edges are used to represent that there is a connection relationship between source domain attributes; For each source domain attribute, the source domain aggregated feature vector at the first moment is obtained based on the model parameters of the source domain graph neural network, the source domain time series data corresponding to the source domain attribute, and the source domain time series data corresponding to each of the Ks source domain attributes.
6. The optimization method according to claim 4, characterized in that: The obtaining, based on the source domain sample data, Ns source domain aggregated feature vectors corresponding to the first moment through the source domain graph neural network includes: Obtain Ns source domain time series data from the source domain sample data, wherein the source domain time series data has a one-to-one correspondence with the source domain attributes, and each source domain time series data includes time series data from a second moment to a third moment, where the second moment is a moment occurring before the first moment, and the third moment is a moment immediately preceding the first moment; For each source domain attribute, determining Ks source domain attributes having a connection relationship with the source domain attribute according to the source domain graph structure corresponding to the source domain graph neural network, wherein the source domain graph neural network belongs to the source domain detection network, and the source domain graph structure includes source domain nodes and source domain edges, the source domain nodes are used to represent source domain attributes, and the source domain edges are used to represent that there is a connection relationship between source domain attributes; For each source domain attribute, obtaining an aggregated attention weight between the source domain attribute and each of the Ks source domain attributes; For each source domain attribute, the source domain aggregated feature vector at the first moment is obtained based on the model parameters of the source domain graph neural network, the source domain time series data corresponding to the source domain attribute, the aggregated attention weight corresponding to the source domain attribute, the source domain time series data corresponding to each of the Ks source domain attributes, and the aggregated attention weight corresponding to each of the Ks source domain attributes.
7. The optimization method according to claim 6, characterized in that: The obtaining of the aggregated attention weight between the source domain attribute and each of the Ks source domain attributes includes: Obtaining a time series splicing vector corresponding to the source domain attribute according to the model parameters of the source domain graph neural network, the source domain time series data corresponding to the source domain attribute, and the source domain embedding vector; Obtain a time series splicing vector corresponding to each of the Ks source domain attributes according to the model parameters of the source domain graph neural network, the source domain time series data corresponding to each of the Ks source domain attributes, and the source domain embedding vector; Obtaining a source domain intermediate vector corresponding to the source domain attribute according to the time series splicing vector corresponding to the source domain attribute; Obtaining a source domain intermediate vector corresponding to each of the Ks source domain attributes according to the time series splicing vector corresponding to each of the Ks source domain attributes; According to the source domain intermediate vector corresponding to the source domain attribute and the source domain intermediate vector corresponding to each of the Ks source domain attributes, the aggregated attention weight corresponding to the source domain attribute and the aggregated attention weight corresponding to each of the Ks source domain attributes are obtained.
8. The optimization method according to claim 1, characterized in that: The updating of the Nt target domain embedding vectors and the model parameters of the target domain detection network according to the target domain sample data includes: Based on the target domain sample data, obtaining Nt target domain aggregated feature vectors corresponding to the fourth moment through the target domain graph neural network, wherein the target domain aggregated feature vectors have a one-to-one correspondence with the target domain attributes, and the target domain graph neural network belongs to the target domain detection network; Based on the Nt target domain aggregated feature vectors and the Nt target domain embedding vectors, obtaining, through a second fully connected layer included in the target domain detection network, Nt target domain prediction data values corresponding to the fourth moment, wherein the target domain prediction data values have a one-to-one correspondence with the target domain attributes; Constructing a second loss function based on the Nt target domain predicted data values and the Nt target domain actual data values corresponding to the fourth moment, wherein the Nt target domain actual data values are derived from the target domain sample data; Based on the second loss function, updating the Nt target domain embedding vectors; Based on the second loss function, the model parameters of the target domain graph neural network and the model parameters of the second fully connected layer are updated.
9. The optimization method according to claim 8, characterized in that: The obtaining, based on the target domain sample data, Nt target domain aggregated feature vectors corresponding to the fourth moment through the target domain graph neural network includes: Obtain Nt target domain time series data from the target domain sample data, wherein the target domain time series data has a one-to-one correspondence with the target domain attribute, and each target domain time series data includes time series data from a fifth moment to a sixth moment, where the fifth moment is a moment occurring before a first moment, and the sixth moment is a moment immediately preceding the first moment; For each target domain attribute, determining Kt target domain attributes having a connection relationship with the target domain attribute according to a target domain graph structure corresponding to the target domain graph neural network, wherein the target domain graph neural network belongs to the target domain detection network, the target domain graph structure includes target domain nodes and target domain edges, the target domain nodes are used to represent target domain attributes, and the target domain edges are used to represent that there is a connection relationship between target domain attributes; For each target domain attribute, the target domain aggregated feature vector at the fourth moment is obtained based on the model parameters of the target domain graph neural network, the target domain time series data corresponding to the target domain attribute, and the target domain time series data corresponding to each target domain attribute in the Kt target domain attributes.
10. The optimization method according to claim 8, characterized in that: The obtaining, based on the target domain sample data, Nt target domain aggregated feature vectors corresponding to the fourth moment through the target domain graph neural network includes: Obtain Nt target domain time series data from the target domain sample data, wherein the target domain time series data has a one-to-one correspondence with the target domain attribute, and each target domain time series data includes time series data from a fifth moment to a sixth moment, where the fifth moment is a moment before the fourth moment, and the sixth moment is a moment immediately preceding the fourth moment; For each target domain attribute, determining Kt target domain attributes having a connection relationship with the target domain attribute according to a target domain graph structure corresponding to the target domain graph neural network, wherein the target domain graph neural network belongs to the target domain detection network, the target domain graph structure includes target domain nodes and target domain edges, the target domain nodes are used to represent target domain attributes, and the target domain edges are used to represent that there is a connection relationship between target domain attributes; For each target domain attribute, obtaining an aggregated attention weight between the target domain attribute and each of the Kt target domain attributes; For each target domain attribute, the target domain aggregate feature vector at the fourth moment is obtained based on the model parameters of the target domain graph neural network, the target domain time series data corresponding to the target domain attribute, the aggregated attention weight corresponding to the target domain attribute, the target domain time series data corresponding to each of the Kt target domain attributes, and the aggregated attention weight corresponding to each of the Kt target domain attributes.
11. The optimization method according to claim 10, characterized in that: The obtaining of the aggregated attention weight between the target domain attribute and each of the Kt target domain attributes includes: Obtaining a time series splicing vector corresponding to the target domain attribute according to the model parameters of the target domain graph neural network, the target domain time series data corresponding to the target domain attribute, and the target domain embedding vector; Obtain a time series concatenation vector corresponding to each of the Kt target domain attributes according to the model parameters of the target domain graph neural network, the target domain time series data corresponding to each of the Kt target domain attributes, and the target domain embedding vector; Obtaining a target domain intermediate vector corresponding to the target domain attribute according to the time series splicing vector corresponding to the target domain attribute; Obtaining a target domain intermediate vector corresponding to each of the Kt target domain attributes according to the time series splicing vector corresponding to each of the Kt target domain attributes; According to the target domain intermediate vector corresponding to the target domain attribute and the target domain intermediate vector corresponding to each of the Kt target domain attributes, the aggregated attention weight corresponding to the target domain attribute and the aggregated attention weight corresponding to each of the Kt target domain attributes are obtained.
12. The optimization method according to any one of claims 1 to 11, characterized in that: Generating an attribute similarity matrix according to the source domain sample data and the target domain sample data includes: For the time series data corresponding to each source domain attribute in the source domain sample data, and the time series data corresponding to each target domain attribute in the target domain sample data, calculate the similarity between the source domain attribute and the target domain attribute based on the time series data corresponding to the source domain attribute and the time series data corresponding to the target domain attribute; Generating Nt target domain embedding vectors according to the attribute similarity matrix and the updated Ns source domain embedding vectors includes: Transposing the attribute similarity matrix to obtain a transposed attribute similarity matrix; The transposed attribute similarity matrix is multiplied by the updated Ns source domain embedding vectors to obtain the Nt target domain embedding vectors.
13. The optimization method according to claim 12, characterized in that: The calculating, based on the time series data corresponding to the source domain attribute and the time series data corresponding to the target domain attribute, the similarity between the source domain attribute and the target domain attribute includes: If the time series data corresponding to the source domain attribute is greater than or equal to the time series data corresponding to the target domain attribute, a first sliding window is generated according to the time series data corresponding to the target domain attribute, wherein the first sliding window is Tt, and Tt is an integer greater than 1; Based on the first sliding window, sliding with a first preset step size in the time series data corresponding to the source domain attribute to obtain P first sub-time series data, where P is an integer greater than or equal to 1; Calculate the similarity between the time series data corresponding to the target domain attribute and each first sub-time series data to obtain P sequence similarities; Averaging the P sequence similarities to obtain the similarity between the source domain attribute and the target domain attribute; or, The calculating, based on the time series data corresponding to the source domain attribute and the time series data corresponding to the target domain attribute, the similarity between the source domain attribute and the target domain attribute includes: If the time series data corresponding to the target domain attribute is greater than or equal to the time series data corresponding to the source domain attribute, a second sliding window is generated according to the time series data corresponding to the source domain attribute, wherein the second sliding window is Ts, and Ts is an integer greater than 1; Based on the second sliding window, sliding with a second preset step size in the time series data corresponding to the target domain attribute to obtain Q second sub-time series data, where Q is an integer greater than or equal to 1; Calculate the similarity between the time series data corresponding to the source domain attribute and each second sub-time series data to obtain Q sequence similarities; The Q sequence similarities are averaged to obtain the similarity between the source domain attribute and the target domain attribute.
14. A method for detecting anomalies in time series data, characterized in that: include: Acquire data to be detected, wherein the data to be detected includes time series data of Nt target domain attributes, each time series data of the target domain attribute includes data at T moments, and both Nt and T are integers greater than 1; Based on the data to be detected, obtaining Nt predicted data values corresponding to the target time through a target domain detection network, wherein the target domain detection network is trained using any one of the methods of claims 1 to 13 above; Obtain Nt actual data values corresponding to the target time; Calculate the anomaly score corresponding to the target time according to the Nt actual data values and the Nt predicted data values; If the anomaly score corresponding to the target moment is greater than or equal to the anomaly score threshold, the target moment is determined to be a data anomaly moment.
15. The abnormality detection method according to claim 14, characterized in that: The calculating, based on the Nt actual data values and the Nt predicted data values, an anomaly score corresponding to the target moment includes: For each target domain attribute, calculating the mean and variance corresponding to the target domain attribute; For each target domain attribute, calculating the absolute value of the difference between the predicted data value corresponding to the target domain attribute and the actual data value, to obtain a first data value corresponding to the target domain attribute; For each target domain attribute, subtract the first data value corresponding to the target domain attribute from the mean value corresponding to the target domain attribute to obtain a second data value corresponding to the target domain attribute; For each target domain attribute, calculating a quotient of a second data value corresponding to the target domain attribute and a variance corresponding to the target domain attribute to obtain a third data value corresponding to the target domain attribute; A maximum value is selected from the third data values corresponding to each target domain attribute as the abnormality score corresponding to the target moment.
16. A parameter optimization device, characterized in that: include: an acquisition module, configured to acquire source domain sample data and target domain sample data, wherein the source domain sample data includes time series data of Ns source domain attributes, and the target domain sample data includes time series data of Nt target domain attributes, where both Ns and Nt are integers greater than 1, and the time series data includes any one of game data, driving data, network data, and meteorological data; the game data includes movement speed data and movement distance data corresponding to each frame of a player's screen; the driving data includes speed data, acceleration data, and direction data; the network data includes connection duration data, transmission byte data, and connection type data; and the meteorological data includes temperature data, humidity data, and air pressure data; A construction module, configured to construct a source domain graph neural network based on the Ns source domain embedding vectors corresponding to the Ns source domain attributes, wherein the source domain embedding vectors have a one-to-one correspondence with the source domain attributes; A training module, configured to update the Ns source domain embedding vectors and model parameters of a source domain detection network based on the source domain sample data, wherein the source domain detection network includes the source domain graph neural network; A generating module, configured to generate an attribute similarity matrix based on the source domain sample data and the target domain sample data, wherein the attribute similarity matrix is used to describe the similarity between each source domain attribute and each target domain attribute; The generating module is further configured to generate Nt target domain embedding vectors based on the attribute similarity matrix and the updated Ns source domain embedding vectors, wherein the target domain embedding vectors have a one-to-one correspondence with the target domain attributes; The construction module is further configured to construct a target domain graph neural network based on the Nt target domain embedding vectors, wherein the model parameters of the target domain graph neural network adopt the updated model parameters of the source domain graph neural network; The training module is further used to update the Nt target domain embedding vectors and the model parameters of the target domain detection network according to the target domain sample data, wherein the target domain detection network includes the target domain graph neural network.
17. The device according to claim 16, characterized in that The building blocks are specifically used for: For each source domain attribute, (Ns-1) vector similarities are calculated based on the source domain embedding vector corresponding to the source domain attribute and the source domain embedding vectors corresponding to the remaining source domain attributes, where the remaining source domain attributes are the remaining (Ns-1) source domain attributes in the Ns source domain attributes except the source domain attribute; For each source domain attribute, determine the largest Ks vector similarities from the (Ns-1) vector similarities, where Ks is an integer greater than or equal to 1 and less than (Ns-1); For each source domain attribute, determining, based on the largest Ks vector similarities, Ks source domain attributes that have a connection relationship with the source domain attribute, wherein a vector similarity in the Ks vector similarities has a one-to-one correspondence with a source domain attribute in the Ks source domain attributes; Constructing a source domain graph structure according to each source domain attribute and Ks source domain attributes that are respectively connected to each source domain attribute, wherein the source domain graph structure includes source domain nodes and source domain edges, the source domain nodes are used to represent source domain attributes, and the source domain edges are used to represent that different source domain attributes have a connection relationship; The source domain graph neural network is constructed according to the source domain graph structure and the Ns source domain embedding vectors.
18. The device according to claim 16, characterized in that The building blocks are specifically used for: For each target domain attribute, (Nt-1) vector similarities are calculated based on the target domain embedding vector corresponding to the target domain attribute and the target domain embedding vectors corresponding to the remaining target domain attributes, where the remaining target domain attributes are the remaining (Nt-1) target domain attributes in the Nt target domain attributes except the target domain attribute; For each target domain attribute, determine the largest Kt vector similarities from the (Nt-1) vector similarities, where Kt is an integer greater than or equal to 1 and less than (Nt-1); For each target domain attribute, determining Kt target domain attributes having a connection relationship with the target domain attribute according to the largest Kt vector similarities, wherein a vector similarity in the Kt vector similarities has a one-to-one correspondence with a target domain attribute in the Kt target domain attributes; Constructing a target domain graph structure according to each target domain attribute and Kt target domain attributes that are respectively connected to each target domain attribute, wherein the target domain graph structure includes target domain nodes and target domain edges, the target domain nodes are used to represent target domain attributes, and the target domain edges are used to represent that different target domain attributes have a connection relationship; The target domain graph neural network is constructed according to the target domain graph structure and the Nt target domain embedding vectors.
19. The device according to claim 16, characterized in that The training module is specifically used to: Based on the source domain sample data, obtaining Ns source domain aggregated feature vectors corresponding to the first moment through the source domain graph neural network, wherein the source domain aggregated feature vectors have a one-to-one correspondence with the source domain attributes, and the source domain graph neural network belongs to the source domain detection network; Based on the Ns source domain aggregated feature vectors and the Ns source domain embedding vectors, obtaining, through a first fully connected layer included in the source domain detection network, Ns source domain prediction data values corresponding to the first moment, wherein the source domain prediction data values have a one-to-one correspondence with the source domain attributes; Constructing a first loss function according to the Ns source domain predicted data values and the Ns source domain actual data values corresponding to the first moment, wherein the Ns source domain actual data values are derived from the source domain sample data; Based on the first loss function, updating the Ns source domain embedding vectors; Based on the first loss function, the model parameters of the source domain graph neural network and the model parameters of the first fully connected layer are updated.
20. The device according to claim 19, characterized in that The training module is specifically used to: Obtain Ns source domain time series data from the source domain sample data, wherein the source domain time series data has a one-to-one correspondence with the source domain attributes, and each source domain time series data includes time series data from a second moment to a third moment, where the second moment is a moment occurring before the first moment, and the third moment is a moment immediately preceding the first moment; For each source domain attribute, determine Ks source domain attributes having a connection relationship with the source domain attribute according to the source domain graph structure corresponding to the source domain graph neural network, wherein the source domain graph neural network belongs to the source domain detection network, and the source domain graph structure includes source domain nodes and source domain edges, the source domain nodes are used to represent source domain attributes, and the source domain edges are used to represent that there is a connection relationship between source domain attributes; For each source domain attribute, the source domain aggregated feature vector at the first moment is obtained based on the model parameters of the source domain graph neural network, the source domain time series data corresponding to the source domain attribute, and the source domain time series data corresponding to each of the Ks source domain attributes.
21. The device according to claim 19, characterized in that The training module is specifically used to: Obtain Ns source domain time series data from the source domain sample data, wherein the source domain time series data has a one-to-one correspondence with the source domain attributes, and each source domain time series data includes time series data from a second moment to a third moment, where the second moment is a moment occurring before the first moment, and the third moment is a moment immediately preceding the first moment; For each source domain attribute, determining Ks source domain attributes having a connection relationship with the source domain attribute according to the source domain graph structure corresponding to the source domain graph neural network, wherein the source domain graph neural network belongs to the source domain detection network, and the source domain graph structure includes source domain nodes and source domain edges, the source domain nodes are used to represent source domain attributes, and the source domain edges are used to represent that there is a connection relationship between source domain attributes; For each source domain attribute, obtaining an aggregated attention weight between the source domain attribute and each of the Ks source domain attributes; For each source domain attribute, the source domain aggregated feature vector at the first moment is obtained based on the model parameters of the source domain graph neural network, the source domain time series data corresponding to the source domain attribute, the aggregated attention weight corresponding to the source domain attribute, the source domain time series data corresponding to each of the Ks source domain attributes, and the aggregated attention weight corresponding to each of the Ks source domain attributes.
22. The device according to claim 21, characterized in that The training module is specifically used to: Obtaining a time series splicing vector corresponding to the source domain attribute according to the model parameters of the source domain graph neural network, the source domain time series data corresponding to the source domain attribute, and the source domain embedding vector; Obtain a time series splicing vector corresponding to each of the Ks source domain attributes according to the model parameters of the source domain graph neural network, the source domain time series data corresponding to each of the Ks source domain attributes, and the source domain embedding vector; Obtaining a source domain intermediate vector corresponding to the source domain attribute according to the time series splicing vector corresponding to the source domain attribute; Obtaining a source domain intermediate vector corresponding to each of the Ks source domain attributes according to the time series splicing vector corresponding to each of the Ks source domain attributes; According to the source domain intermediate vector corresponding to the source domain attribute and the source domain intermediate vector corresponding to each of the Ks source domain attributes, the aggregated attention weight corresponding to the source domain attribute and the aggregated attention weight corresponding to each of the Ks source domain attributes are obtained.
23. The device according to any one of claims 16 to 22, characterized in that The generation module is specifically used to: For the time series data corresponding to each source domain attribute in the source domain sample data, and the time series data corresponding to each target domain attribute in the target domain sample data, calculate the similarity between the source domain attribute and the target domain attribute based on the time series data corresponding to the source domain attribute and the time series data corresponding to the target domain attribute; The generation module is specifically used to: Transposing the attribute similarity matrix to obtain a transposed attribute similarity matrix; The transposed attribute similarity matrix is multiplied by the updated Ns source domain embedding vectors to obtain the Nt target domain embedding vectors.
24. The device according to claim 23, characterized in that The generation module is specifically used to: If the time series data corresponding to the source domain attribute is greater than or equal to the time series data corresponding to the target domain attribute, a first sliding window is generated according to the time series data corresponding to the target domain attribute, wherein the first sliding window is Tt, and Tt is an integer greater than 1; Based on the first sliding window, sliding with a first preset step size in the time series data corresponding to the source domain attribute to obtain P first sub-time series data, where P is an integer greater than or equal to 1; Calculate the similarity between the time series data corresponding to the target domain attribute and each first sub-time series data to obtain P sequence similarities; Averaging the P sequence similarities to obtain the similarity between the source domain attribute and the target domain attribute; or, The generation module is specifically used to: If the time series data corresponding to the target domain attribute is greater than or equal to the time series data corresponding to the source domain attribute, a second sliding window is generated according to the time series data corresponding to the source domain attribute, wherein the second sliding window is Ts, and Ts is an integer greater than 1; Based on the second sliding window, sliding with a second preset step size in the time series data corresponding to the target domain attribute to obtain Q second sub-time series data, where Q is an integer greater than or equal to 1; Calculate the similarity between the time series data corresponding to the source domain attribute and each second sub-time series data to obtain Q sequence similarities; The Q sequence similarities are averaged to obtain the similarity between the source domain attribute and the target domain attribute.
25. An abnormality detection device, characterized in that: include: An acquisition module is configured to acquire data to be detected, wherein the data to be detected includes time series data of Nt target domain attributes, each time series data of the target domain attribute includes data at T moments, and both Nt and T are integers greater than 1; The acquisition module is further configured to acquire, based on the data to be detected, Nt predicted data values corresponding to the target time through a target domain detection network, wherein the target domain detection network is trained using any one of the methods of claims 1 to 13 above; The acquisition module is further configured to acquire Nt actual data values corresponding to the target time; a determination module, configured to calculate an anomaly score corresponding to the target moment based on the Nt actual data values and the Nt predicted data values; The determination module is further configured to determine that the target moment is a data anomaly moment if the anomaly score corresponding to the target moment is greater than or equal to an anomaly score threshold.
26. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the processor implements the steps of the optimization method according to any one of claims 1 to 13, or implements the steps of the abnormality detection method according to any one of claims 14 to 15.
27. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the optimization method according to any one of claims 1 to 13 are implemented, or the steps of the abnormality detection method according to any one of claims 14 to 15 are implemented.
28. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the optimization method according to any one of claims 1 to 13 are implemented, or the steps of the abnormality detection method according to any one of claims 14 to 15 are implemented.