Multivariate time series anomaly detection method and system based on disentangled network

By using a method based on disentangled networks, the global, local and temporal dependencies of multivariate time series are obtained, which solves the problems of hidden connections between sensors and ignored long-term dependencies, and achieves more efficient anomaly detection.

CN115344621BActive Publication Date: 2025-09-05HUBEI UNIV OF TECH +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210797654.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-06
Publication Date
2025-09-05
Estimated Expiration
2042-07-06

AI Technical Summary

Technical Problem

Existing multivariate time series anomaly detection methods ignore the possible hidden connections and long-term temporal dependencies between sensors, resulting in low detection accuracy and high false alarm rate, and difficulty in distinguishing normal patterns from abnormal patterns.

Method used

A method based on disentanglement network is adopted to obtain the global dependency between sensors by disentangling the global network. The local dynamic dependency and temporal dependency of sensors are captured by combining the local attention network and the temporal network. These relationships are fused to improve the detection accuracy.

Benefits of technology

The ability of multivariate time series anomaly detection has been significantly improved, which can better identify abnormal fluctuations and reduce false alarm rates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115344621B_ABST
    Figure CN115344621B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of anomaly detection technology, and in particular to a multivariate time series anomaly detection method and system based on a disentangled network. The method comprises: obtaining initial multivariate time series data and normalizing the multivariate time series data to obtain preprocessed multivariate time series data; obtaining global dependencies, local dynamic dependencies, and temporal dependencies of the preprocessed multivariate time series data to further obtain fusion relationships; obtaining predicted multivariate time series data based on the fusion relationships; and determining whether anomalies exist based on the predicted multivariate time series data and the preprocessed multivariate time series data. The present invention can effectively detect abnormal fluctuations in multivariate time series, significantly improving the anomaly detection capability for multivariate time series.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of anomaly detection technology, and in particular to a multivariate time series anomaly detection method and system based on a disentangled network. Background Art

[0002] With the advent of the Internet of Things (IoT), more and more sensors are being deployed in our daily lives. These sensors generate time series data. For example, data collected by various sensors measuring water level, flow rate, and water quality in a water treatment plant, as well as a set of monitoring indicators from application servers, are all standard time series data. In practical applications, it is crucial to be able to efficiently and accurately identify outliers using this time series data. This helps continuously monitor sensor systems and generate timely alerts for potential incidents.

[0003] Multivariate time series are composed of multiple univariate time series from the same entity, each representing the measurement of a sensor in the system. Traditionally, domain experts establish thresholds based on the characteristics of univariate indicators to detect anomalies. However, with the rapid increase in system scale and data complexity, this labor-intensive and non-scalable approach has become unsustainable. To overcome the limitations of traditional methods, numerous anomaly detection algorithms have been proposed in recent years, performing anomaly detection on a single variable. However, in complex real-world systems, changes in one indicator often cause fluctuations in other indicators, which interact with each other. As a result, a single indicator cannot fully represent the overall state of the system, resulting in poor performance of these univariate detection algorithms in multivariate time series anomaly detection tasks.

[0004] With the rapid development of deep learning, deep learning-based techniques have improved multivariate time series anomaly detection.

[0005] Graph neural networks have achieved success in modeling graph data. Many real-world problems can be abstracted as graph-structured, non-Euclidean data. Multivariate time series can also be represented on a graph, with each sensor considered a node in the graph, interconnected by hidden dependencies. Graph neural networks are better able to learn dependency patterns between sensors.

[0006] Existing anomaly detection work based on multivariate time series has the following problems:

[0007] 1) Typically, multivariate time series lack a clear graph structure, and the correlations between sensors change dynamically over time. The reasons for this change are highly complex. Existing technologies attempt to model the dynamic transformation patterns of sensor correlations over time by creating learnable embeddings for each univariate node in a multivariate time series. Although the performance of these models has improved, they are far from satisfactory because the dependencies between sensors remain fixed after training. They only consider local sensor correlations within the graph structure, ignoring the potential hidden connections between isolated sensors. Furthermore, they uniformly learn and train normal and abnormal patterns in time series data, failing to distinguish them effectively.

[0008] 2) In existing methods, long-term temporal dependencies are often ignored. Existing techniques use long-short-term memory (LSTM) networks to identify temporal dependencies in multivariate time series, achieving some success. However, LSTM networks cannot fully encode long sequences into intermediate vectors. Long-term dependencies are often discarded in the encoder, and temporal correlations that do not match their structure are also discarded. Furthermore, the sequential nature of these models results in time-consuming computations and limited scalability for long sequences. Summary of the Invention

[0009] In view of this, the present invention provides a multivariate time series anomaly detection method and system based on a disentangled network, which solves the problems of low detection accuracy and high false alarm rate caused by the existing anomaly detection methods ignoring the very likely hidden connections and long-term time dependencies between sensors separated from each other in the graph structure, and failing to distinguish between normal and abnormal patterns in the time series.

[0010] To achieve the above object, the present invention provides the following solutions:

[0011] A multivariate time series anomaly detection method based on disentangled networks, comprising:

[0012] Acquiring initial multivariate time series data, and performing normalization processing on the multivariate time series data to obtain preprocessed multivariate time series data;

[0013] Obtaining a global dependency relationship of the preprocessed multivariate time series data based on a disentangled global network;

[0014] Obtaining local dynamic dependencies of the preprocessed multivariate time series data based on a local attention network;

[0015] Obtaining a fusion dependency relationship based on the global dependency relationship and the local dynamic dependency relationship;

[0016] Obtaining a time dependency relationship of the preprocessed multivariate time series data based on a time network;

[0017] Obtaining a fusion relationship based on the fusion dependency, time dependency, and order relationship of the preprocessed multivariate time series data;

[0018] Based on the fusion relationship, predicted multivariate time series data is obtained; and based on the predicted multivariate time series data and the preprocessed multivariate time series data, whether it is abnormal is determined.

[0019] Preferably, the initial multivariate time series data is composed of multiple initial univariate time series data of the same entity, each of the initial univariate time series data corresponds to a monitoring value of a sensor; the preprocessed multivariate time series data includes multiple preprocessed univariate time series data.

[0020] Preferably, obtaining the global dependency of the preprocessed multivariate time series data based on the disentangled global network comprises:

[0021] The similarity between each sensor is obtained based on the embedding vector of each sensor;

[0022] The disentangled adjacency matrix is ​​obtained based on the similarity between each sensor;

[0023] The global dependency is obtained based on the disentangled adjacency matrix and the preprocessed multivariate time series data.

[0024] Preferably, the obtaining of the local dynamic dependency of the preprocessed multivariate time series data based on the local attention network includes:

[0025] Embed the position information of each sensor to obtain the initial sensor position embedding matrix;

[0026] Flattening the initial sensor position embedding matrix along the spatial axis to obtain a sensor position embedding matrix;

[0027] Obtaining an embedding feature matrix based on the sensor position embedding matrix and the preprocessed multivariate time series data;

[0028] Projecting the embedded feature matrix into three high-dimensional subspaces to obtain three embedded feature components;

[0029] Obtaining an initial local dynamic dependency relationship based on the three embedded feature components;

[0030] Based on the initial local dynamic dependency relationship, a feedforward neural network is used to obtain the local dynamic dependency relationship.

[0031] Preferably, obtaining the time dependency of the preprocessed multivariate time series data based on a time network includes:

[0032] Embed the time position information of each sensor to obtain the initial sensor time position embedding matrix;

[0033] Flattening the initial sensor time position embedding matrix along the spatial axis to obtain a sensor time position embedding matrix;

[0034] Obtaining a time embedding feature matrix based on the sensor time position embedding matrix and the preprocessed multivariate time series data;

[0035] Projecting the time embedding feature matrix into three high-dimensional subspaces to obtain three time embedding feature components;

[0036] Based on the three embedded feature components, an initial local dynamic dependency relationship is obtained by using a scaled dot product function;

[0037] Based on the initial local dynamic dependency, a feedforward neural network is used to obtain the time dependency.

[0038] The present invention also provides a multivariate time series anomaly detection system based on a disentangled network, comprising:

[0039] A data processing module is used to obtain initial multivariate time series data and perform normalization processing on the multivariate time series data to obtain preprocessed multivariate time series data;

[0040] A global module, configured to obtain a global dependency relationship of the preprocessed multivariate time series data based on a disentangled global network;

[0041] A local module, configured to obtain local dynamic dependencies of the preprocessed multivariate time series data based on a local attention network;

[0042] A first fusion module, configured to obtain a fused dependency relationship based on the global dependency relationship and the local dynamic dependency relationship;

[0043] A time module, configured to obtain a time dependency of the preprocessed multivariate time series data based on a time network;

[0044] A second fusion module is configured to obtain a fusion relationship based on the fusion dependency, time dependency and sequence relationship of the preprocessed multivariate time series data;

[0045] The prediction judgment module is used to obtain predicted multivariate time series data based on the fusion relationship; and determine whether it is abnormal based on the predicted multivariate time series data and the preprocessed multivariate time series data.

[0046] Preferably, the initial multivariate time series data is composed of multiple initial univariate time series data of the same entity, each of the initial univariate time series data corresponds to a monitoring value of a sensor; the preprocessed multivariate time series data includes multiple preprocessed univariate time series data.

[0047] Preferably, the global module includes:

[0048] A similarity unit is used to obtain the similarity between each sensor based on the embedding vector of each sensor;

[0049] A matrix unit, used to obtain a disentangled adjacency matrix based on the similarity between each sensor;

[0050] A global unit is used to obtain the global dependency based on the disentangled adjacency matrix and the preprocessed multivariate time series data.

[0051] Preferably, the local module includes:

[0052] A first embedding unit is used to embed the position information of each sensor to obtain an initial sensor position embedding matrix;

[0053] a first tiling unit, configured to tile the initial sensor position embedding matrix along a spatial axis to obtain a sensor position embedding matrix;

[0054] a first feature matrix unit, configured to obtain an embedding feature matrix based on the sensor position embedding matrix and the preprocessed multivariate time series data;

[0055] A first projection unit is used to project the embedded feature matrix into three high-dimensional subspaces to obtain three embedded feature components;

[0056] A first initialization unit, configured to obtain an initial local dynamic dependency relationship based on the three embedded feature components;

[0057] The local unit is used to obtain the local dynamic dependency relationship based on the initial local dynamic dependency relationship using a feedforward neural network.

[0058] Preferably, the time module includes:

[0059] The second embedding unit is used to embed the time position information of each sensor to obtain an initial sensor time position embedding matrix;

[0060] a second tiling unit, configured to tile the initial sensor time position embedding matrix along a spatial axis to obtain a sensor time position embedding matrix;

[0061] a second feature matrix unit, configured to obtain a time embedding feature matrix based on the sensor time position embedding matrix and the preprocessed multivariate time series data;

[0062] a second projection unit, configured to project the time embedding feature matrix into three high-dimensional subspaces to obtain three time embedding feature components;

[0063] A second initialization unit is configured to obtain an initial local dynamic dependency relationship based on the three embedded feature components using a scaled dot product function;

[0064] The time unit is used to obtain the time dependency relationship based on the initial local dynamic dependency relationship by using a feedforward neural network.

[0065] According to the specific embodiments provided by the present invention, the present invention discloses the following technical effects:

[0066] The present invention relates to the field of anomaly detection technology, and in particular to a multivariate time series anomaly detection method and system based on a disentangled network. The method comprises: obtaining initial multivariate time series data and normalizing the multivariate time series data to obtain preprocessed multivariate time series data; obtaining global dependencies, local dynamic dependencies, and temporal dependencies of the preprocessed multivariate time series data to further obtain fusion relationships; obtaining predicted multivariate time series data based on the fusion relationships; and determining whether anomalies exist based on the predicted multivariate time series data and the preprocessed multivariate time series data. The present invention can effectively detect abnormal fluctuations in multivariate time series, significantly improving the anomaly detection capability for multivariate time series. BRIEF DESCRIPTION OF THE DRAWINGS

[0067] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0068] Figure 1 This is a flow chart of the multivariate time series anomaly detection method based on the disentangled network of the present invention;

[0069] Figure 2 This is a schematic diagram of preprocessing multivariate time series data in the present invention;

[0070] Figure 3 This is a structural diagram of the multivariate time series anomaly detection system based on the disentangled network of the present invention.

[0071] Explanation of symbols: 1-data processing module, 2-global module, 3-local module, 4-first fusion module, 5-time module, 6-second fusion module, 7-prediction and judgment module. DETAILED DESCRIPTION

[0072] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0073] The purpose of the present invention is to provide a multivariate time series anomaly detection method and system based on a disentangled network, so as to solve the problems of low detection accuracy and high false alarm rate caused by the existing anomaly detection methods, which ignore the hidden connections and long-term time dependencies that are very likely to exist between sensors separated from each other in the graph structure, and cannot distinguish between normal and abnormal patterns in the time series.

[0074] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.

[0075] Figure 1 This is a flow chart of the multivariate time series anomaly detection method based on the disentangled network of the present invention. Figure 1 As shown, the present invention provides a multivariate time series anomaly detection method based on a disentangled network, comprising:

[0076] Step S1: obtaining initial multivariate time series data, and performing normalization processing on the multivariate time series data to obtain preprocessed multivariate time series data.

[0077] The initial multivariate time series data is composed of multiple initial univariate time series data of the same entity, each of which corresponds to a monitoring value of a sensor; the preprocessed multivariate time series data includes multiple preprocessed univariate time series data. Figure 2 As shown, Figure 2In the figure, a set of preprocessed univariate time series data consisting of monitoring values ​​of 15 sensors is shown, where the time series length is 20,000. In the figure, Sensor represents the sensor, and Sensor1 represents the preprocessed univariate time series data corresponding to the first sensor. The others are similar and will not be explained one by one.

[0078] The normalization process is a minimum-maximum normalization process. Considering that the magnitudes of different sensors may be inconsistent and the differences between the values ​​may be large, normalization is performed to improve the robustness of the detection. The normalization calculation formula is as follows:

[0079]

[0080] Where: x i is the i-th initial univariate time series data, is x i After normalization, min(x i ) is the minimum value in the i-th initial univariate time series data, max(x i ) is the maximum value in the i-th initial univariate time series data.

[0081] Step S2, obtaining the global dependency of the preprocessed multivariate time series data based on the disentangled global network. Specifically, step S2 includes:

[0082] In step S21, the similarity between each sensor is obtained based on the embedding vector of each sensor. The calculation formula is as follows:

[0083]

[0084] Where: e j,i represents the similarity between the i-th sensor and the j-th sensor, m is the number of sensors, V i represents the embedding vector of the i-th sensor, V i V i The transposed matrix, V j represents the embedding vector of the j-th sensor.

[0085] Step S22: obtaining a disentangled adjacency matrix based on the similarity between each sensor.

[0086] Since there is no clear prior information about the graph structure in the preprocessed multivariate time series data, the disentangled adjacency matrix is ​​defined according to the similarity scale k

[0087]

[0088] Where: Π[k] represents the similarity scale set, which is an increasing set with a value range of 0-1; when the similarity between sensors e i,j A dependency relationship is formed between Π[k] and ∏[k+1], and sensors can be connected to different sensors by adjusting similar scales.

[0089] Step S23: obtaining the global dependency relationship based on the unwrapped adjacency matrix and the preprocessed multivariate time series data.

[0090] In the existing graph convolutional network method, the k-order polynomial of the adjacency matrix is ​​used to aggregate the multi-scale structural information. The layer-by-layer update rule is as follows:

[0091]

[0092] In the above formula Replaced by the unwrapped adjacency matrix The layer-by-layer update rule of the disentangled global network is obtained, and then the global dependency relationship is obtained. The calculation formula is as follows:

[0093]

[0094] Where: K represents the number of scales to be aggregated, yes The standardized form of Added self-loops to the adjacency matrix, for The degree matrix of represents the input data, i.e., the preprocessed multivariate time series data, W represents the layer-wise learnable weight matrix, l is the layer index, and σ(·) is the activation function.

[0095] Step S3: obtaining local dynamic dependencies of the preprocessed multivariate time series data based on a local attention network.

[0096] Furthermore, step S3 includes:

[0097] Step S31: embed the position information of each sensor to obtain an initial sensor position embedding matrix.

[0098] Step S32: tiling the initial sensor position embedding matrix along the spatial axis to obtain a sensor position embedding matrix.

[0099] Step S33: obtaining an embedding feature matrix based on the sensor position embedding matrix and the preprocessed multivariate time series data.

[0100] Step S34: Project the embedded feature matrix into three high-dimensional subspaces to obtain three embedded feature components. The three embedded feature components are the feature query subspace component, the feature key subspace component, and the eigenvalue subspace component. Specifically, the formula is as follows:

[0101]

[0102] Where: Q F represents the feature query subspace component, K F represents the characteristic bond subspace component, V F represents the eigenvalue subspace component, X F X′ F The state of any timestamp, X′ F is the embedding feature matrix, is the weight matrix of the feature query subspace, is the weight matrix of the feature bond subspace, is the weight matrix of the eigenvalue subspace.

[0103] Step S35: obtaining an initial local dynamic dependency relationship based on the three embedded feature components.

[0104] By learning different inter-sensor dependency patterns through multi-head attention, different local time-varying dependencies can be captured from different high-dimensional latent subspaces. Using dot product self-attention to learn the local dependency M between multiple sensors F , and further with V F Aggregate to obtain the learned node feature Z F , Z F This is the initial local dynamic dependency.

[0105]

[0106] Z F =M F V F

[0107] Where: is the scaling factor of the dot product self-attention. In order to stabilize the gradient, the result of each dot product is divided by

[0108] Step S36: Based on the initial local dynamic dependency relationship, a feedforward neural network is used to obtain the local dynamic dependency relationship.

[0109] In order to further improve the prediction ability, the node feature Z′ after adding the residual connection F =Z F +X FThe input is fed into a shared two-layer feed-forward neural network to explore the interactions between node features.

[0110]

[0111] in, and W1 F is the weight matrix of the two-layer feedforward neural network. F and Z′ F pass The local dynamic dependency is obtained by combining features and using a gate mechanism to fuse features.

[0112] Step S4: obtaining a fusion dependency based on the global dependency and the local dynamic dependency.

[0113] The output global dependency X of the disentangled global network G and the local dynamic dependencies of the output of the local attention network Multiply by the weight matrix W G and W F , converted by the sigmoid activation function as the fusion gate g.

[0114]

[0115]

[0116] Fusion gate g weighted X G and Get the output Y of a single timestamp F , connect the outputs of w timestamps to obtain the fused dependency Y′ F .

[0117] Step S5: obtaining the time dependency of the preprocessed multivariate time series data based on the time network.

[0118] Specifically, step S5 includes:

[0119] Step S51: embed the time position information of each sensor to obtain an initial sensor time position embedding matrix.

[0120] Step S52: Flatten the initial sensor time position embedding matrix along the spatial axis to obtain a sensor time position embedding matrix.

[0121] Step S53: obtaining a time embedding feature matrix based on the sensor time position embedding matrix and the preprocessed multivariate time series data.

[0122] Step S54: Project the time embedding feature matrix into three high-dimensional subspaces to obtain three time embedding feature components.

[0123] Three high-dimensional subspaces are defined to capture dynamic temporal correlations, namely, temporal query subspace, temporal key subspace, and temporal value subspace.

[0124]

[0125] Among them, Q T represents the temporal query subspace component, K T represents the time-key subspace component, V T represents the time value subspace component, X T X′ T The state of any timestamp, X′ T is the time embedding feature matrix, is the weight matrix of the time query subspace, is the weight matrix of the time-key subspace, is the weight matrix of the time-valued subspace.

[0126] Step S55 : Based on the three embedded feature components, a scaling dot product function is used to obtain an initial local dynamic dependency relationship.

[0127] Introduce a scaled dot product function to learn temporal dependencies within historical time:

[0128]

[0129] Further V T With M T Aggregate to get the time feature Z T =M T V T , Z T This is the initial local dynamic dependency.

[0130] Step S56: Based on the initial local dynamic dependency, a feedforward neural network is used to obtain the time dependency.

[0131] To explore Z T The potential interactions inside are fed into a two-layer neural network to learn the hidden temporal dependencies. Here, the residual connection Z′ is introduced T =Z T +X T Conduct stability training.

[0132]

[0133] The output of each sensor is Y T =Z′T +U T , the time dependency Y′ is obtained by connecting the outputs of m sensors T .

[0134] The current timestamp is connected to any timestamp in the sliding window, which can effectively capture time dependencies. At the same time, by changing the window size without sacrificing too much computational efficiency, it can be easily extended to long sequences to learn long-range dependencies.

[0135] Step S6: obtaining a fusion relationship based on the fusion dependency, time dependency and sequence relationship of the preprocessed multivariate time series data.

[0136] Step S7, obtaining predicted multivariate time series data based on the fusion relationship; and determining whether there is an abnormality based on the predicted multivariate time series data and the preprocessed multivariate time series data.

[0137] Furthermore, the step S7 is specifically as follows:

[0138] The predicted value at time t With the actual value x t The square error between the predicted value and the true value is used as the anomaly score, which indicates the degree of error between the predicted value and the true value. The larger the anomaly score, the greater the possibility of an anomaly at time t. If the anomaly score exceeds the threshold, it is determined that an anomaly occurs at time t. Calculate the anomaly scores of n timestamps and obtain the anomaly score time series {L1, L2, ..., L n}. The anomaly score calculation formula is as follows:

[0139]

[0140] Where, L t represents the anomaly score at time t, x t,i represents the value of the i-th preprocessed univariate time series data at time t, is x t,i The predicted value of .

[0141] Dynamic automatic threshold selection uses the POT theorem in extreme value theory. It does not assume any distribution of abnormal data, but fits the tail distribution through the generalized Pareto (GPD) method. The formula is as follows:

[0142]

[0143] Where τ is the initial threshold, α is the shape parameter of GPD, β is the scale parameter of GPD, L represents the anomaly score time series, and L-τ follows the generalized Pareto distribution with parameters α and β, representing the part that exceeds the initial threshold τ.

[0144] The method of moments is used to estimate the values ​​of parameters α and β. The method of moments uses the mean and variance of the sample to estimate the population, thereby inferring the unknown parameters of the distribution. Depend on Replace, the variance of GPD Depend on Replace. Among them, Y i Indicates the sample point where S>τ, N is Y i The estimated values ​​of α and β are calculated as follows:

[0145]

[0146] Where: is the estimated value of α, is the estimated value of β.

[0147] The final threshold τ final It is calculated by the following formula, where q is the risk factor used to determine abnormality.

[0148]

[0149] Figure 3 This is a diagram showing the structure of the multivariate time series anomaly detection system based on the disentangled network of the present invention. Figure 3 As shown, the present invention provides a multivariate time series anomaly detection system based on a disentangled network, comprising: a data processing module 1, a global module 2, a local module 3, a first fusion module 4, a time module 5, a second fusion module 6 and a prediction and judgment module 7.

[0150] The data processing module 1 is used to obtain initial multivariate time series data and perform normalization processing on the multivariate time series data to obtain preprocessed multivariate time series data.

[0151] The global module 2 is used to obtain the global dependency of the preprocessed multivariate time series data based on the disentangled global network.

[0152] The local module 3 is used to obtain the local dynamic dependency of the preprocessed multivariate time series data based on the local attention network.

[0153] The first fusion module 4 is configured to obtain a fused dependency relationship based on the global dependency relationship and the local dynamic dependency relationship.

[0154] The time module 5 is used to obtain the time dependency of the preprocessed multivariate time series data based on a time network.

[0155] The second fusion module 6 is used to obtain a fusion relationship based on the fusion dependency, time dependency and sequence relationship of the preprocessed multivariate time series data.

[0156] The prediction and judgment module 7 is used to obtain predicted multivariate time series data based on the fusion relationship; and determine whether there is an abnormality based on the predicted multivariate time series data and the pre-processed multivariate time series data.

[0157] Optionally, the initial multivariate time series data is composed of multiple initial univariate time series data of the same entity, each initial univariate time series data corresponds to a monitoring value of a sensor; the preprocessed multivariate time series data includes multiple preprocessed univariate time series data.

[0158] Optionally, the global module 2 includes:

[0159] A similarity unit is used to obtain the similarity between each sensor based on the embedding vector of each sensor;

[0160] A matrix unit, used to obtain a disentangled adjacency matrix based on the similarity between each sensor;

[0161] A global unit is used to obtain the global dependency based on the disentangled adjacency matrix and the preprocessed multivariate time series data.

[0162] Optionally, the local module 3 includes:

[0163] The first embedding unit is used to embed the position information of each sensor to obtain an initial sensor position embedding matrix.

[0164] The first tiling unit is configured to tile the initial sensor position embedding matrix along a spatial axis to obtain a sensor position embedding matrix.

[0165] The first feature matrix unit is configured to obtain an embedding feature matrix based on the sensor position embedding matrix and the preprocessed multivariate time series data.

[0166] The first projection unit is used to project the embedded feature matrix into three high-dimensional subspaces to obtain three embedded feature components.

[0167] The first initialization unit is used to obtain an initial local dynamic dependency relationship based on the three embedded feature components.

[0168] The local unit is used to obtain the local dynamic dependency relationship based on the initial local dynamic dependency relationship using a feedforward neural network.

[0169] Optionally, the time module 5 includes:

[0170] The second embedding unit is used to embed the time position information of each sensor to obtain an initial sensor time position embedding matrix.

[0171] The second tiling unit is configured to tile the initial sensor time position embedding matrix along the spatial axis to obtain a sensor time position embedding matrix.

[0172] The second feature matrix unit is used to obtain a time embedding feature matrix based on the sensor time position embedding matrix and the preprocessed multivariate time series data.

[0173] The second projection unit is configured to project the time embedding feature matrix into three high-dimensional subspaces to obtain three time embedding feature components.

[0174] The second initialization unit is used to obtain an initial local dynamic dependency relationship based on the three embedded feature components using a scaled dot product function.

[0175] The time unit is used to obtain the time dependency relationship based on the initial local dynamic dependency relationship by using a feedforward neural network.

[0176] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the common and similar parts between the various embodiments. For the systems disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method description.

[0177] This document uses specific examples to illustrate the principles and implementation methods of the present invention. The above examples are only intended to help understand the method and core concept of the present invention. At the same time, those skilled in the art will find that the specific implementation methods and application scopes may vary based on the concept of the present invention. In summary, the contents of this specification should not be construed as limiting the present invention.

Claims

1. A multivariate time series anomaly detection method based on disentangled networks, characterized in that: include: Acquiring initial multivariate time series data, and performing normalization processing on the multivariate time series data to obtain preprocessed multivariate time series data; Obtaining a global dependency relationship of the preprocessed multivariate time series data based on a disentangled global network includes: The similarity between each sensor is obtained based on the embedding vector of each sensor; The disentangled adjacency matrix is ​​obtained based on the similarity between each sensor; Obtaining the global dependency relationship based on the disentangled adjacency matrix and the preprocessed multivariate time series data; Obtaining local dynamic dependencies of the preprocessed multivariate time series data based on a local attention network; Obtaining a fusion dependency relationship based on the global dependency relationship and the local dynamic dependency relationship; Obtaining a time dependency relationship of the preprocessed multivariate time series data based on a time network; Obtaining a fusion relationship based on the fusion dependency, time dependency, and order relationship of the preprocessed multivariate time series data; Based on the fusion relationship, predicted multivariate time series data is obtained; and based on the predicted multivariate time series data and the preprocessed multivariate time series data, whether it is abnormal is determined.

2. The multivariate time series anomaly detection method based on disentangled networks according to claim 1 is characterized in that: The initial multivariate time series data is composed of a plurality of initial univariate time series data of the same entity, and each of the initial univariate time series data corresponds to a monitoring value of a sensor; The preprocessed multivariate time series data includes a plurality of preprocessed univariate time series data.

3. The multivariate time series anomaly detection method based on disentangled networks according to claim 1 is characterized in that: The obtaining of the local dynamic dependency relationship of the preprocessed multivariate time series data based on the local attention network includes: Embed the position information of each sensor to obtain the initial sensor position embedding matrix; Flattening the initial sensor position embedding matrix along the spatial axis to obtain a sensor position embedding matrix; Obtaining an embedding feature matrix based on the sensor position embedding matrix and the preprocessed multivariate time series data; Projecting the embedded feature matrix into three high-dimensional subspaces to obtain three embedded feature components; Obtaining an initial local dynamic dependency relationship based on the three embedded feature components; Based on the initial local dynamic dependency relationship, a feedforward neural network is used to obtain the local dynamic dependency relationship.

4. The multivariate time series anomaly detection method based on disentangled networks according to claim 2, characterized in that: The obtaining of the time dependency of the preprocessed multivariate time series data based on the time network includes: Embed the time position information of each sensor to obtain the initial sensor time position embedding matrix; Flattening the initial sensor time position embedding matrix along the spatial axis to obtain a sensor time position embedding matrix; Obtaining a time embedding feature matrix based on the sensor time position embedding matrix and the preprocessed multivariate time series data; Projecting the time embedding feature matrix into three high-dimensional subspaces to obtain three time embedding feature components; Based on the three embedded feature components, an initial local dynamic dependency relationship is obtained by using a scaled dot product function; Based on the initial local dynamic dependency, a feedforward neural network is used to obtain the time dependency.

5. A multivariate time series anomaly detection system based on disentangled networks, characterized in that: include: A data processing module is used to obtain initial multivariate time series data and perform normalization processing on the multivariate time series data to obtain preprocessed multivariate time series data; A global module is used to obtain the global dependency of the preprocessed multivariate time series data based on the disentangled global network, and the global module includes: A similarity unit is used to obtain the similarity between each sensor based on the embedding vector of each sensor; A matrix unit, used to obtain a disentangled adjacency matrix based on the similarity between each sensor; A global unit, configured to obtain the global dependency relationship based on the disentangled adjacency matrix and the preprocessed multivariate time series data; A local module, configured to obtain local dynamic dependencies of the preprocessed multivariate time series data based on a local attention network; A first fusion module, configured to obtain a fused dependency relationship based on the global dependency relationship and the local dynamic dependency relationship; A time module, configured to obtain a time dependency of the preprocessed multivariate time series data based on a time network; a second fusion module, configured to obtain a fusion relationship based on the fusion dependency, time dependency, and sequence relationship of the preprocessed multivariate time series data; The prediction judgment module is used to obtain predicted multivariate time series data based on the fusion relationship; and determine whether it is abnormal based on the predicted multivariate time series data and the preprocessed multivariate time series data.

6. The multivariate time series anomaly detection system based on disentangled networks according to claim 5, characterized in that: The initial multivariate time series data is composed of a plurality of initial univariate time series data of the same entity, and each of the initial univariate time series data corresponds to a monitoring value of a sensor; The preprocessed multivariate time series data includes a plurality of preprocessed univariate time series data.

7. The multivariate time series anomaly detection system based on disentangled networks according to claim 6, characterized in that: The local module includes: A first embedding unit is used to embed the position information of each sensor to obtain an initial sensor position embedding matrix; a first tiling unit, configured to tile the initial sensor position embedding matrix along a spatial axis to obtain a sensor position embedding matrix; a first feature matrix unit, configured to obtain an embedding feature matrix based on the sensor position embedding matrix and the preprocessed multivariate time series data; A first projection unit is used to project the embedded feature matrix into three high-dimensional subspaces to obtain three embedded feature components; A first initialization unit, configured to obtain an initial local dynamic dependency relationship based on the three embedded feature components; The local unit is used to obtain the local dynamic dependency relationship based on the initial local dynamic dependency relationship by adopting a feedforward neural network.

8. The multivariate time series anomaly detection system based on disentangled networks according to claim 6, characterized in that: The time module includes: The second embedding unit is used to embed the time position information of each sensor to obtain an initial sensor time position embedding matrix; a second tiling unit, configured to tile the initial sensor time position embedding matrix along a spatial axis to obtain a sensor time position embedding matrix; a second feature matrix unit, configured to obtain a time embedding feature matrix based on the sensor time position embedding matrix and the preprocessed multivariate time series data; A second projection unit is used to project the time embedding feature matrix into three high-dimensional subspaces to obtain three time embedding feature components; A second initialization unit is configured to obtain an initial local dynamic dependency relationship based on the three embedded feature components using a scaled dot product function; The time unit is used to obtain the time dependency relationship based on the initial local dynamic dependency relationship by using a feedforward neural network.

Citation Information

Patent Citations

  • Abnormal packet detection method and system based on deep packet analysis

    CN113449815A

  • Abnormality detection method, system and equipment for time series data and storage medium

    CN114386521A