Edge node abnormality positioning method, device, equipment and computer program product

By using the network performance data of edge nodes and neighbor nodes to locate edge nodes based on the trained anomaly, the problem of abnormal positioning difficulty caused by the diversity of edge node deployment is solved, and efficient and accurate prediction of edge node abnormality is achieved.

CN115437858BActive Publication Date: 2025-06-06CHINA MOBILE GROUP ZHEJIANG +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110629207.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-06-04
Publication Date
2025-06-06
Estimated Expiration
2041-06-04

AI Technical Summary

Technical Problem

Due to the diverse deployment of edge nodes, the difficulty of abnormal positioning of edge nodes has increased, and the existing technology is difficult to effectively solve this problem.

Method used

By obtaining the network performance data of the current edge node and neighbor node, and performing abnormal positioning prediction based on the trained abnormal prediction model, the abnormal positioning prediction results are obtained. This model includes a central node-level graph attention layer, an edge node abnormal locator and several neighbor node-level graph attention layers. Through a multi-level graph attention mechanism, the relationship between nodes is learned to improve positioning accuracy.

Benefits of technology

The processing performance of abnormal positioning of edge nodes is improved, and the abnormal prediction with high accuracy and efficiency is achieved, simplifying the process of abnormal positioning of edge nodes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115437858B_ABST
    Figure CN115437858B_ABST
Patent Text Reader

Abstract

The present application discloses an edge node abnormal location method, device, equipment and computer program product, the edge node abnormal location method comprising: obtaining network performance data of the current edge node and neighboring nodes, wherein the neighboring nodes are nodes associated with the current edge node; based on the trained abnormal prediction model and the network performance data, performing abnormal location prediction on the current edge node to obtain an abnormal location prediction result. The present application automatically performs abnormal location prediction on the current edge node based on the built and trained abnormal prediction model, and because the abnormal prediction model is obtained through iterative training, the abnormal prediction model has high accuracy and fast processing efficiency in abnormal location prediction, thereby improving the processing performance of edge node abnormal location.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a method, device, equipment and computer program product for locating anomalies in an edge node. Background Art

[0002] With the rapid development of communication technology, users have higher and higher requirements for communication speed. In order to reduce the bandwidth and delay loss caused by network transmission and multi-level forwarding, edge nodes are usually built on the edge of the network close to users. Since edge nodes can be deployed differently according to customer needs, the deployment of edge nodes is very diverse, which increases the difficulty of locating edge node anomalies. Summary of the invention

[0003] The main purpose of the present application is to provide a method, device, equipment and computer program product for locating anomalies in edge nodes, aiming to improve the processing performance of locating anomalies in edge nodes.

[0004] To achieve the above object, the present application provides a method for locating an edge node anomaly, and the method for locating an edge node anomaly comprises the following steps:

[0005] Obtain network performance data of a current edge node and neighboring nodes, wherein the neighboring nodes are nodes that are associated with the current edge node;

[0006] Based on the trained anomaly prediction model and the network performance data, anomaly location prediction is performed on the current edge node to obtain an anomaly location prediction result.

[0007] Optionally, the anomaly prediction model includes a central node level graph attention layer, an edge node anomaly locator and several neighbor node level graph attention layers, and the step of performing anomaly location prediction on the current edge node based on the trained anomaly prediction model and the network performance data to obtain an anomaly location prediction result includes:

[0008] Based on the several neighbor node level graph attention layers, the network performance data of the current edge node is respectively aggregated with the network performance data of each of the neighbor nodes at the neighbor node level to obtain the features of each edge node;

[0009] Based on the central node level graph attention layer, performing central node level attention aggregation on the features of each edge node to obtain edge node aggregate features;

[0010] Based on the edge node anomaly locator and the edge node aggregation feature, anomaly location prediction is performed on the current edge node to obtain an anomaly location prediction result.

[0011] Optionally, the step of performing neighbor node level attention aggregation on the network performance data of the current edge node and the network performance data of each of the neighbor nodes based on the plurality of neighbor node level graph attention layers to obtain the features of each edge node includes:

[0012] Standardizing the network performance data of the current edge node and the network performance data of each of the neighboring nodes to obtain a performance vector of the current edge node and a performance vector of each of the neighboring nodes;

[0013] Based on the several neighbor node level graph attention layers, the performance vector of the current edge node is respectively aggregated with the performance vectors of each neighbor node by neighbor node level attention to obtain the features of each edge node.

[0014] Optionally, the neighbor nodes include multiple neighbor nodes, including MEP nodes, UPF nodes, DC-GW nodes and terminal nodes, the several neighbor node-level graph attention layers include a first neighbor node-level graph attention layer, a second neighbor node-level graph attention layer, a third neighbor node-level graph attention layer and a fourth neighbor node-level graph attention layer, and the step of performing neighbor node-level attention aggregation on the network performance data of the current edge node and the network performance data of each of the neighbor nodes based on the several neighbor node-level graph attention layers to obtain the characteristics of each edge node includes:

[0015] Based on the first neighbor node level graph attention layer, performing neighbor node level attention aggregation on the network performance data of the current edge node and the network performance data of the MEP node to obtain a first edge node feature;

[0016] Based on the second neighbor node level graph attention layer, the network performance data of the current edge node and the network performance data of the UPF node are aggregated at the neighbor node level to obtain a second edge node feature;

[0017] Based on the third neighbor node level graph attention layer, the network performance data of the current edge node and the network performance data of the DC-GW node are aggregated at the neighbor node level to obtain a third edge node feature;

[0018] Based on the fourth neighbor node level graph attention layer, the network performance data of the current edge node and the network performance data of the terminal node are aggregated at the neighbor node level to obtain a fourth edge node feature.

[0019] Optionally, before the step of performing abnormal location prediction on the current edge node based on the trained abnormality prediction model and the network performance data to obtain the abnormal location prediction result, the step further includes:

[0020] Acquire edge node training data and neighbor node training data, and annotate the edge node training data and the neighbor node training data with labels for abnormal location results to obtain abnormal location result data;

[0021] Acquire a model to be trained, and select training sample data from the edge node training data, the neighbor node training data, and the anomaly positioning result data;

[0022] Based on the training sample data, the model to be trained is iteratively trained to obtain an abnormality prediction model.

[0023] Optionally, the model to be trained is a heterogeneous graph attention network model to be trained, and the step of obtaining the model to be trained, before the step of selecting training sample data from the edge node training data, the neighbor node training data and the anomaly positioning result data, further includes:

[0024] Determine an edge node and each neighbor node of the edge node based on the edge node training data and the neighbor node training data;

[0025] Taking the edge node as the central node, the heterogeneous graph attention network model to be trained is constructed by the edge node and each neighbor node.

[0026] Optionally, the heterogeneous graph attention network model to be trained includes a central node level graph attention layer, an edge node anomaly locator and several neighbor node level graph attention layers, and the step of iteratively training the model to be trained based on the training sample data to obtain the anomaly prediction model includes:

[0027] Based on the plurality of neighbor node level graph attention layers, performing neighbor node level attention aggregation on the edge node training data in the training sample data and each of the neighbor node training data in the training sample data, respectively, to obtain each edge node feature;

[0028] Based on the central node level graph attention layer, performing central node level attention aggregation on the features of each edge node to obtain edge node aggregate features;

[0029] Based on the edge node anomaly locator and the edge node aggregation features, anomaly location prediction is performed on the edge node to obtain an anomaly location prediction result;

[0030] Based on the anomaly location prediction result and the anomaly location result data in the training sample data, the heterogeneous graph attention network model to be trained is iteratively trained to obtain an anomaly prediction model.

[0031] In addition, to achieve the above-mentioned purpose, the present application also provides an edge node abnormality locating device, the edge node abnormality locating device comprising:

[0032] An acquisition module, used to acquire network performance data of a current edge node and a neighboring node, wherein the neighboring node is a node associated with the current edge node;

[0033] The prediction module is used to perform abnormal location prediction on the current edge node based on the trained abnormality prediction model and the network performance data to obtain an abnormal location prediction result.

[0034] In addition, to achieve the above-mentioned purpose, the present application also provides an edge node abnormality locating device, which includes: a memory, a processor, and an edge node abnormality locating program stored in the memory and executable on the processor, and when the edge node abnormality locating program is executed by the processor, the steps of the edge node abnormality locating method as described above are implemented.

[0035] In addition, to achieve the above-mentioned purpose, the present application also provides a computer-readable storage medium, on which an edge node anomaly locating program is stored, and when the edge node anomaly locating program is executed by a processor, the steps of the edge node anomaly locating method as described above are implemented.

[0036] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, the steps of the edge node abnormality locating method as described above are implemented.

[0037] The present application provides an edge node abnormal location method, device, equipment and computer program product, which obtains the network performance data of the current edge node and the neighboring node, wherein the neighboring node is a node associated with the current edge node; based on the trained abnormal prediction model and network performance data, the current edge node is predicted to be abnormally located, and the abnormal location prediction result is obtained. Through the above method, based on the built and trained abnormal prediction model, the abnormal location prediction of the current edge node is automatically performed, and because the abnormal prediction model is obtained through iterative training, the abnormal location prediction of the abnormal prediction model is highly accurate and efficient, thereby improving the processing performance of the abnormal location of the edge node. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 A schematic diagram of the terminal structure of the hardware operating environment involved in the embodiment of the present application;

[0039] Figure 2 This is a flow chart of the first embodiment of the edge node abnormality location method of the present application;

[0040] Figure 3 This is a flow chart of the second embodiment of the edge node abnormality location method of the present application;

[0041] Figure 4 A schematic diagram of the node relationship involved in the embodiment of the present application;

[0042] Figure 5 This is a schematic diagram of the model structure involved in the embodiment of the present application;

[0043] Figure 6 This is a functional module diagram of the first embodiment of the edge node abnormality locating device of the present application.

[0044] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0045] It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0046] The main solution of the embodiment of the present invention is: obtaining the network performance data of the current edge node and the neighboring node, wherein the neighboring node is a node associated with the current edge node; based on the trained abnormal prediction model and the network performance data, performing abnormal location prediction on the current edge node to obtain an abnormal location prediction result. Through the above method, based on the built and trained abnormal prediction model, the abnormal location prediction of the current edge node is automatically performed, and because the abnormal prediction model is obtained through iterative training, the abnormal location prediction of the abnormal prediction model is highly accurate and efficient, thereby improving the processing performance of abnormal location of edge nodes.

[0047] Technical terms involved in the embodiments of this application:

[0048] MEC (Mobile Edge Computing) is an architecture based on the evolution of 5G. In the 5G era, everything is connected, and massive IoT devices extend upward. The cloud computing model will have bottlenecks in data processing and cost and energy consumption. At the same time, the ultimate user experience also requires the cloud content to extend to users. For this reason, the rapid development of MEC will be inevitable in the evolution of technology. MEC provides flexible network access capabilities and edge computing services at the edge of the mobile network, reduces network transmission and service delivery latency, improves data security, and gives new development momentum to vertical industries. It is a technology that deeply integrates mobile access networks with Internet services, and sinks computing and processing capabilities to the edge closest to the business. On the one hand, MEC can improve user experience, save bandwidth resources, reduce congestion and burden on core networks and transmission networks, ease network bandwidth pressure, and achieve low latency. On the other hand, by sinking computing power to mobile edge nodes and providing third-party application integration, it provides unlimited possibilities for service innovation at the mobile edge entrance, and can quickly respond to user requests and improve service quality.

[0049] Edge nodes refer to business platforms built on the edge of the network close to users, providing storage, computing, network and other resources, and sinking some key business applications to the edge of the access network to reduce the bandwidth and latency losses caused by network transmission and multi-level forwarding. This type of node is characterized by the multi-dimensional performance KPI of the overall edge node at the current moment (including overall load, request latency, request success rate, etc.).

[0050] MEP (MEC platform) is the middleware capability of MEC application integration deployment and network openness, which can host MEC services such as 5G network capabilities and business capabilities. The characteristics of MEC nodes are the UPF multi-dimensional performance KPIs (including network element load, response delay, success rate, etc.) at the current moment.

[0051] UPF (user plane function) is a 5G user plane network element. The high-speed and reliable data transmission provided by 5G networks to users must be implemented through UPF at the core network level. The characteristics of UPF nodes are the current UPF multi-dimensional performance KPIs (including network element load, response delay, success rate, etc.).

[0052] DC-GW (DC-gateway), each pair of MEC will be equipped with a pair of DC-GW as the export, and the relevant network equipment is built at the prefecture-level and connected to the DC-GW through transmission. DC-GW accesses the CMNET (China Mobile Net) CE at the prefecture-level through transmission, and goes to the public network or the anchor point UPF in other provinces and cities. The characteristics of this type of node are the multi-dimensional performance KPIs of DC-GW at the current moment (including traffic load, forwarding delay, forwarding rate, etc.).

[0053] The embodiments of the present application take into account that in existing related solutions, in order to reduce the bandwidth and delay loss caused by network transmission and multi-stage forwarding, edge nodes are usually built on the edge side of the network close to the user. However, since edge nodes can be deployed differently according to customer needs, the deployment of edge nodes is very diverse, which increases the difficulty of locating abnormal edge nodes.

[0054] Therefore, the embodiment of the present application proposes a solution to automatically predict the abnormal location of the current edge node based on the built and trained abnormal prediction model, and because the abnormal prediction model is obtained through iterative training, the abnormal location prediction of the abnormal prediction model has high accuracy and fast processing efficiency, thereby improving the processing performance of abnormal location of edge nodes.

[0055] Reference Figure 1 , Figure 1 This is a schematic diagram of the terminal structure of the hardware operating environment involved in the embodiment of the present application.

[0056] The terminal in the embodiment of the present application is an edge node anomaly locating device, which can be a terminal device with processing function such as a PC (personal computer), a microcomputer, a laptop computer, a server, etc.

[0057] like Figure 1 As shown, the terminal may include: a processor 1001, such as a CPU (Central Processing Unit), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and the optional user interface 1003 may also include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed RAM memory, or a stable memory (non-volatile memory), such as a disk memory. The memory 1005 may also be a storage device independent of the aforementioned processor 1001.

[0058] Those skilled in the art will understand that Figure 1 The terminal structure shown in the figure does not constitute a limitation on the terminal, and may include more or less components than shown in the figure, or combine certain components, or arrange the components differently.

[0059] like Figure 1As shown, the memory 1005 as a computer storage medium may include an operating system, a network communication module, a user interface module, and an edge node abnormality locating program.

[0060] exist Figure 1 In the terminal shown, the processor 1001 can be used to call the edge node abnormality locating program stored in the memory 1005 and execute various embodiments of the following edge node abnormality locating method.

[0061] Based on the above hardware structure, various embodiments of the edge node abnormality positioning method of the present application are proposed.

[0062] The present application provides a method for locating anomalies in an edge node.

[0063] Reference Figure 2 , Figure 2 This is a flow chart of the first embodiment of the edge node abnormality location method of the present application.

[0064] In this embodiment, the edge node abnormality location method includes:

[0065] Step S10, obtaining network performance data of the current edge node and neighboring nodes, wherein the neighboring nodes are nodes associated with the current edge node;

[0066] In this embodiment, the edge node abnormality positioning method can be applied to an edge node abnormality positioning device, which can be an edge computing management platform, which can be a 5G (5th Generation Mobile Communication Technology) edge computing management platform, which can be managed by an operator; it can also be applied to an edge node abnormality positioning system composed of the edge computing management platform and other related devices, and the edge node abnormality positioning system is subordinate to the above Figure 1 Edge node abnormality positioning device.

[0067] In this embodiment, network performance data of the current edge node and neighboring nodes are obtained, where the neighboring nodes are nodes associated with the current edge node. The current edge node is the edge node performing edge computing at the current moment, that is, the edge node that needs to be abnormally located.

[0068] It should be noted that different nodes include different network performance data. For example, edge nodes include overall load, request delay, request success rate, etc.; MEP nodes include network element load, response delay, success rate, etc.; UPF nodes include network element load, response delay, success rate, etc.; DC-GW nodes include traffic load, forwarding delay, forwarding rate, etc.; terminal (such as mobile phones, base stations) nodes include uplink rate, downlink rate, etc.

[0069] In one embodiment, the neighbor node includes multiple neighbor nodes, and the multiple neighbor nodes include a MEP node, a UPF node, a DC-GW node, and a terminal node. The above step S10 includes:

[0070] Obtain the network performance data of the current edge node, MEP node network performance data, UPF node network performance data, DC-GW node network performance data, and terminal node network performance data. For example, the edge computing management platform collects multi-dimensional performance KPI (Key Performance Indicator) data of each relevant component of edge computing at the current moment, and the multi-dimensional performance KPI data is the network performance data.

[0071] In another embodiment, the terminal node is a base station node, and the above step S10 includes:

[0072] Obtain the network performance data of the current edge node, MEP node, UPF node, DC-GW node, and base station node.

[0073] In addition, it should be noted that the relationship between the current edge node and the MEP node is that the MEP node belongs to a certain edge node; the relationship between the current edge node and the UPF node is that the UPF node is sunk to a certain edge node; the relationship between the current edge node and the DC-GW node is that the edge node and the DC-GW node are connected; the relationship between the edge node and the base station node is that the base station is connected to a certain edge node. In other words, the edge node forms an association relationship with each neighboring node, and the edge node serves as a central node. For ease of understanding, you can refer to Figure 4 , Figure 4 A schematic diagram of the node relationship involved in the embodiment of the present application.

[0074] Step S20, based on the trained anomaly prediction model and the network performance data, anomaly location prediction is performed on the current edge node to obtain an anomaly location prediction result.

[0075] In this embodiment, based on the trained anomaly prediction model and network performance data, an anomaly location prediction is performed on the current edge node to obtain an anomaly location prediction result. Specifically, based on each feature extractor in the trained anomaly prediction model, the performance feature information of the network performance data of the current edge node and each neighboring node is extracted, and then based on each performance feature information and the classifier in the anomaly prediction model, a binary classification prediction is performed on the performance feature information to obtain a binary classification prediction result, and based on the binary classification prediction result, the anomaly location prediction result of the current edge node is obtained.

[0076] The specific execution process of the classifier is to obtain a classification probability vector, and then determine the anomaly location prediction result (binary classification prediction result) corresponding to the largest classification probability value in the classification probability vector. The anomaly location prediction result includes the presence of anomalies and the absence of anomalies. For example, an anomaly location prediction result of 1 represents that the current edge node has an anomaly, and an anomaly location prediction result of 0 represents that the current edge node does not have an anomaly.

[0077] In another embodiment, the anomaly prediction model is a heterogeneous graph attention network model, which includes a number of neighbor node level graph attention layers, a center node level graph attention layer and a classifier, and the above step S20 includes:

[0078] Based on the several neighbor node level graph attention layers, the network performance data of the current edge node is respectively aggregated with the network performance data of each of the neighbor nodes by neighbor node level attention to obtain the features of each edge node; based on the center node level graph attention layer, the features of each edge node are aggregated by center node level attention to obtain the edge node aggregate features; based on the classifier and the edge node aggregate features, the current edge node is predicted for abnormal location to obtain the abnormal location prediction result. The specific execution process can refer to the second embodiment described below, which will not be repeated here.

[0079] Furthermore, in one embodiment, the network performance data of the current edge node and the neighboring node are preprocessed, and then each network performance data after data preprocessing is input into the abnormal prediction model to improve the processing performance of the abnormal prediction model. In another embodiment, the abnormal prediction model includes several standardization layers, through which the network performance data of the current edge node and the neighboring node are preprocessed, and then each network performance data after data preprocessing is input into the corresponding neighbor node level graph attention layer to improve the processing performance of the abnormal prediction model. Among them, the data preprocessing may include standardization processing or normalization processing.

[0080] The embodiment of the present application provides an edge node abnormal location method, which obtains the network performance data of the current edge node and the neighboring nodes, wherein the neighboring nodes are nodes that have an associated relationship with the current edge node; based on the trained abnormal prediction model and the network performance data, the current edge node is predicted to have abnormal location, and an abnormal location prediction result is obtained. Through the above method, based on the built and trained abnormal prediction model, the current edge node is automatically predicted to have abnormal location, and because the abnormal prediction model is obtained through iterative training, the abnormal prediction model has a high accuracy rate and fast processing efficiency in abnormal location prediction, thereby improving the processing performance of edge node abnormal location.

[0081] Furthermore, based on the above first embodiment, a second embodiment of the edge node abnormality locating method of the present application is proposed.

[0082] Reference Figure 3 , Figure 3 This is a flow chart of the second embodiment of the edge node abnormality location method of the present application.

[0083] In this embodiment, the anomaly prediction model includes a central node level graph attention layer, an edge node anomaly locator, and several neighbor node level graph attention layers. The above step S20 includes:

[0084] Step S21, based on the plurality of neighbor node level graph attention layers, the network performance data of the current edge node is respectively aggregated with the network performance data of each of the neighbor nodes at the neighbor node level to obtain the features of each edge node;

[0085] In this embodiment, based on several neighbor node-level graph attention layers, the network performance data of the current edge node is aggregated with the network performance data of each neighbor node at the neighbor node level to obtain the features of each edge node. Specifically, with the current edge node as the central node, the network performance data of the current edge node is aggregated with the network performance data of the adjacent neighbor nodes at the neighbor node level, that is, the node-level attention mechanism is used to learn the different importance of the neighbor nodes of the current edge node for judging whether the current edge node is abnormal and the abnormal location, so as to assign different weights to the relationship between nodes according to the difference in importance, thereby obtaining the features of each edge node. Among them, the features of each edge node integrate the information of each neighbor node.

[0086] Among them, the calculation of the graph attention of neighbor node-level attention aggregation is divided into two steps: calculating the attention coefficient and weighted summation. It can be understood that the graph attention model is implemented by stacking graph attention layers, and the input of each graph attention layer is the feature set of the node.

[0087] Among them, the number of convolution kernels of the neighbor node level graph attention layer can be 256, and its activation function can be set to "relu".

[0088] Furthermore, the above step S21 includes:

[0089] Step A211, normalizing the network performance data of the current edge node and the network performance data of each of the neighboring nodes to obtain a performance vector of the current edge node and a performance vector of each of the neighboring nodes;

[0090] In this embodiment, the network performance data of the current edge node and the network performance data of each neighboring node are standardized to obtain the performance vector of the current edge node and the performance vector of each neighboring node. Specifically, the abnormal prediction model includes several standardization layers, through which the network performance data of the current edge node and the network performance data of each neighboring node are standardized to obtain the performance vector of the current edge node and the performance vector of each neighboring node.

[0091] In one embodiment, the formula for the normalization process can be:

[0092] (X-mean) / std

[0093] Among them, X represents an attribute in the network performance data, mean represents the mean of all attributes in the network performance data, and std represents the variance of all attributes in the network performance data. In the specific calculation, each attribute (dimension) is calculated separately, and the data is subtracted from its mean by attribute (by column) and divided by its variance.

[0094] It can be understood that the standardized network performance data can improve the convergence speed of the anomaly prediction model, which makes it easier to train the model. At the same time, compared with the original data, the standardized network performance data improves the accuracy of the anomaly prediction model, thereby improving the accuracy of edge node anomaly prediction.

[0095] Step A212, based on the several neighbor node level graph attention layers, the performance vector of the current edge node is respectively aggregated with the performance vectors of each neighbor node by neighbor node level attention to obtain the features of each edge node.

[0096] In this embodiment, based on several neighbor node-level graph attention layers, the performance vector of the current edge node is aggregated with the performance vectors of each neighbor node at the neighbor node level to obtain the features of each edge node. Specifically, with the current edge node as the central node, the performance vector of the current edge node is aggregated with the performance vectors of the adjacent neighbor nodes at the neighbor node level, that is, the node-level attention mechanism is used to learn the different importance of the neighbor nodes of the current edge node for judging whether the current edge node is abnormal and the abnormal location, so as to assign different weights to the relationship between nodes according to the difference in importance, so as to obtain the features of each edge node. Among them, each edge node feature integrates the information of each neighbor node.

[0097] In some embodiments, the neighbor node includes multiple neighbor nodes, the multiple neighbor nodes include MEP nodes, UPF nodes, DC-GW nodes and terminal nodes, the several neighbor node level graph attention layers include a first neighbor node level graph attention layer, a second neighbor node level graph attention layer, a third neighbor node level graph attention layer and a fourth neighbor node level graph attention layer, and the above step S21 includes:

[0098] Step A213, based on the first neighbor node level graph attention layer, performing neighbor node level attention aggregation on the network performance data of the current edge node and the network performance data of the MEP node to obtain a first edge node feature;

[0099] In this embodiment, based on the first neighbor node level graph attention layer, the network performance data of the current edge node and the network performance data of the MEP node are aggregated at the neighbor node level to obtain the first edge node feature. Specifically, the weight of the first type of neighbor node MEP node of the current edge node to its importance is learned.

[0100] In one embodiment, the timing features of the current edge node and the timing features of the MEP node are input to the first neighbor node level graph attention layer, and then the first neighbor node level graph attention layer outputs the first edge node features after integrating the neighbor node MEP node feature information.

[0101] Furthermore, the time series features of the current edge node and the time series features of the neighbor node MEP node are input, and then they are converted into vectors through the normalization layer and input into the first neighbor node level graph attention layer. Finally, the first neighbor node level graph attention layer outputs the first edge node features after integrating the neighbor node MEP node feature information.

[0102] Step A214, based on the second neighbor node level graph attention layer, the network performance data of the current edge node and the network performance data of the UPF node are aggregated at the neighbor node level to obtain a second edge node feature;

[0103] In this embodiment, based on the second neighbor node level graph attention layer, the network performance data of the current edge node and the network performance data of the UPF node are aggregated at the neighbor node level to obtain the second edge node feature. Specifically, the weight of the importance of the second type of neighbor node UPF node of the current edge node to it is learned.

[0104] In one embodiment, the timing features of the current edge node and the timing features of the UPF node are input to the second neighbor node level graph attention layer, and then the second neighbor node level graph attention layer outputs the second edge node features after integrating the neighbor node UPF node feature information.

[0105] Furthermore, the time series features of the current edge node and the time series features of the neighbor node UPF node are input, and then converted into vectors through the normalization layer and input into the second neighbor node level graph attention layer. Finally, the second neighbor node level graph attention layer outputs the second edge node features after integrating the feature information of the neighbor node UPF node.

[0106] Step A215, based on the third neighbor node level graph attention layer, the network performance data of the current edge node and the network performance data of the DC-GW node are aggregated at the neighbor node level to obtain a third edge node feature;

[0107] In this embodiment, based on the third neighbor node level graph attention layer, the network performance data of the current edge node and the network performance data of the DC-GW node are aggregated at the neighbor node level to obtain the third edge node feature. Specifically, the weight of the importance of the third type of neighbor node DC-GW node of the current edge node to it is learned.

[0108] In one embodiment, the timing features of the current edge node and the timing features of the DC-GW node are input to the third neighbor node level graph attention layer, and then the third neighbor node level graph attention layer outputs the third edge node features after integrating the neighbor node DC-GW node feature information.

[0109] Furthermore, the timing features of the current edge node and the timing features of the neighboring node DC-GW node are input, and then converted into vectors through the normalization layer and input into the third neighbor node level graph attention layer. Finally, the third neighbor node level graph attention layer outputs the third edge node features after integrating the feature information of the neighboring node DC-GW node.

[0110] Step A216, based on the fourth neighbor node level graph attention layer, the network performance data of the current edge node and the network performance data of the terminal node are aggregated at the neighbor node level to obtain the fourth edge node feature.

[0111] In this embodiment, based on the fourth neighbor node level graph attention layer, the network performance data of the current edge node and the network performance data of the terminal node are aggregated at the neighbor node level to obtain the fourth edge node feature. Specifically, the weight of the fourth type of neighbor node terminal node of the current edge node on its importance is learned.

[0112] In one embodiment, the timing features of the current edge node and the timing features of the terminal node are input to the fourth neighbor node level graph attention layer, and then the fourth neighbor node level graph attention layer outputs the fourth edge node features after integrating the neighbor node terminal node feature information.

[0113] Furthermore, the time series features of the current edge node and the time series features of the neighbor node terminal node are input, and then converted into vectors through the normalization layer and input into the fourth neighbor node level graph attention layer. Finally, the fourth neighbor node level graph attention layer outputs the fourth edge node features after integrating the feature information of the neighbor node terminal node.

[0114] In some embodiments, the terminal node is a base station node, and the above step A216 includes: based on the fourth neighbor node level graph attention layer, the network performance data of the current edge node is aggregated with the network performance data of the base station node at the neighbor node level to obtain the fourth edge node feature.

[0115] Step S22, based on the central node level graph attention layer, performing central node level attention aggregation on the features of each edge node to obtain edge node aggregate features;

[0116] In this embodiment, based on the central node-level graph attention layer, central node-level attention aggregation is performed on each edge node feature to obtain edge node aggregate features. Specifically, central node-level attention aggregation is performed on each edge node feature that is fused with the network performance data of neighboring nodes, that is, different attention weights are assigned to each edge node feature to output edge node aggregate features that simultaneously fuse the features of each neighboring node.

[0117] Among them, the calculation of the graph attention of the central node-level attention aggregation is divided into two steps: calculating the attention coefficient and weighted summation. It can be understood that the graph attention model is implemented by stacking graph attention layers, and the input of each graph attention layer is the feature set of the node.

[0118] Among them, the number of convolution kernels of the central node level graph attention layer can be 128, and the activation function can be set to "relu".

[0119] Step S23: Based on the edge node anomaly locator and the edge node aggregation feature, anomaly location prediction is performed on the current edge node to obtain an anomaly location prediction result.

[0120] In this embodiment, based on the edge node anomaly locator and the edge node aggregation feature, an anomaly location prediction is performed on the current edge node to obtain an anomaly location prediction result. Specifically, based on the edge node anomaly locator and the edge node aggregation feature, a binary classification prediction is performed on the edge node aggregation feature to obtain a binary classification prediction result, and based on the binary classification prediction result, an anomaly location prediction result of the current edge node is obtained.

[0121] Wherein, the edge node anomaly locator includes a fully connected layer, and the above step S23 includes: based on the fully connected layer and the edge node aggregation features, performing anomaly location prediction on the current edge node to obtain an anomaly location prediction result. Specifically, based on the fully connected layer and the edge node aggregation features, performing binary classification prediction on the edge node aggregation features to obtain a binary classification prediction result, and based on the binary classification prediction result, obtaining the anomaly location prediction result of the current edge node.

[0122] In one embodiment, the number of neurons in the fully connected (Dense) layer is set to Z, where Z is the Z components of edge computing, the activation function can be set to "sigmoid", and the abnormal location prediction result of 1 represents that there is an abnormality in the edge computing component, and the abnormal location prediction result of 0 represents that there is no abnormality in the edge computing component.

[0123] For ease of understanding, refer to Figure 5 , Figure 5 This is a schematic diagram of the model structure involved in the embodiment of the present application. The network performance data (edge ​​node timing characteristics) of the current edge node are standardized by the standardization layer, and the network performance data (neighboring node MEP timing characteristics, neighboring node UPF timing characteristics, neighboring node DC-GW timing characteristics, neighboring node base station timing characteristics) of the MEP node, UPF node, DC-GW node and base station node are standardized by the standardization layer respectively, and then the standardized edge node timing characteristics and the timing characteristics of each standardized neighbor node are aggregated at the neighbor node level to obtain the edge node characteristics, and then the edge node characteristics are input into the edge node anomaly locator so that the edge node anomaly locator can output the anomaly locating result of the current edge node.

[0124] In this embodiment, the graph attention network can be used to assign different weights according to the difference in the influence of neighbor nodes in the graph network, and construct an edge computing heterogeneous graph network with the current edge node as the center, which is composed of heterogeneous nodes of the current edge node and various neighbor nodes. In addition, the multi-level heterogeneous graph attention network of the abnormal prediction model includes two parts: neighbor node level graph attention and central node level graph attention. With the edge node as the central node, neighbor node level attention aggregation is performed with adjacent neighbor nodes of various types respectively. The node-level attention mechanism is used to learn the different importance of various neighbor nodes of the edge node for judging whether the current edge node is abnormal and the abnormal location, and different weights are assigned to the relationship between nodes according to the difference in importance. Then, the features of each edge node after the current multi-dimensional KPI feature information of each node is respectively fused, and different attention weights are assigned to each edge node feature. Finally, the edge node features that simultaneously fuse the features of various neighbor nodes are input into the edge node abnormal locator composed of the fully connected layer to output the abnormal location prediction result of the edge node, thereby improving the abnormal discovery and processing capabilities of the edge node, and further improving the processing performance of the abnormal location of the edge node.

[0125] Furthermore, based on the above first embodiment, a third embodiment of the edge node abnormality location method of the present application is proposed.

[0126] In this embodiment, before the above step S20, the edge node abnormality location method further includes:

[0127] Step A30, acquiring edge node training data and neighbor node training data, and labeling the edge node training data and the neighbor node training data with labels for anomaly location results to obtain anomaly location result data;

[0128] In this embodiment, edge node training data and neighbor node training data are obtained, and the edge node training data and the neighbor node training data are labeled with labels for abnormal location results to obtain abnormal location result data. The edge node training data is the network performance data of the edge node, and the neighbor node training data is the network performance data of the neighbor node.

[0129] Specifically, each edge node representation value in the edge node training data and each neighbor node representation value in the neighbor node training data are extracted, and then based on each edge node representation value and each neighbor node representation value, the corresponding anomaly location results are matched for the edge node training data and the neighbor node training data, thereby obtaining anomaly location result data.

[0130] In one embodiment, historical network performance data of edge nodes and historical network performance data of neighbor nodes are obtained. In other implementations, edge node training data and neighbor node training data can be set manually or in other ways. The edge node training data includes at least one edge node's network performance data, and the neighbor node training data includes at least one neighbor node's network performance data.

[0131] Furthermore, after the step of acquiring edge node training data and neighbor node training data, the edge node abnormality locating method further includes:

[0132] The network performance data of the edge node training data and the neighbor node training data are preprocessed. Alternatively, the model to be trained includes several standardization layers, and the network performance data of the edge node training data and the neighbor node training data are preprocessed through the several standardization layers. The data preprocessing may include standardization processing or normalization processing.

[0133] In one embodiment, the formula for the normalization process can be:

[0134] (X-mean) / std

[0135] Among them, X represents an attribute in the network performance data, mean represents the mean of all attributes in the network performance data, and std represents the variance of all attributes in the network performance data. In the specific calculation, each attribute (dimension) is calculated separately, and the data is subtracted from its mean by attribute (by column) and divided by its variance.

[0136] It can be understood that the standardized network performance data can improve the convergence speed of the model to be trained, which makes it easier to train the model. At the same time, compared with the original data, the standardized network performance data improves the training accuracy of the model to be trained, thereby further improving the processing performance of edge node abnormal positioning.

[0137] Step A40, obtaining a model to be trained, and selecting training sample data from the edge node training data, the neighbor node training data, and the anomaly positioning result data;

[0138] In this embodiment, a model to be trained is obtained, and training sample data is selected from edge node training data, neighbor node training data, and abnormal location result data. The training sample data includes at least one training sample, and one training sample includes one network performance data of an edge node from the edge node training data, one network performance data of a neighbor node from the neighbor node training data, and one abnormal location result from the abnormal location result data.

[0139] Further, the training sample data is divided into a training set and a test set, for example, 80% of the training sample data is divided into a training set, and 20% of the training sample data is divided into a test set, wherein the training set is used to train the model, and the test set is used to test the model.

[0140] Step A50: iteratively train the model to be trained based on the training sample data to obtain an abnormality prediction model.

[0141] In this embodiment, based on the training sample data, the model to be trained is iteratively trained to obtain an abnormality prediction model. Specifically, a training sample is selected from the training sample data, and the network performance data of the edge node and the network performance data of the neighbor node corresponding to the training sample are input into the model to be trained, and the model prediction is performed to obtain the model output label, and then the difference between the model output label and the abnormality location prediction result corresponding to the training sample is calculated to obtain the model loss, and then based on the model loss, the model to be trained is updated until the number of iterations of the model to be trained reaches the preset number of iterations.

[0142] It should be noted that the preset number of iterations can be set to 1000 (epochs = 1000), and the gradient descent optimization algorithm selects the adam optimizer to improve the learning speed of traditional gradient descent. It can be understood that through gradient descent, the optimal weight value that minimizes the objective function can be found, and the weight value can be learned autonomously through training. Use the training set to train so that the smaller the objective function, the better, and use the test set to evaluate the verification model after each round of training until the model converges and the weight of the model is derived.

[0143] Among them, the objective function can select the binary logarithmic loss function (binary_crossentropy), which is described as follows:

[0144]

[0145] Furthermore, the model to be trained is a heterogeneous graph attention network model to be trained. Before the above step A40, the edge node abnormality location method also includes:

[0146] Step A60, determining an edge node and each neighbor node of the edge node based on the edge node training data and the neighbor node training data;

[0147] Step A70, taking the edge node as the central node, constructing the heterogeneous graph attention network model to be trained by the edge node and each neighbor node.

[0148] In this embodiment, based on the edge node training data and the neighbor node training data, the edge node and each neighbor node of the edge node are determined, and then, with the edge node as the central node, the edge node and each neighbor node construct a heterogeneous graph attention network model to be trained, so as to provide for subsequent model training based on the heterogeneous graph attention network model to be trained. Specifically, based on the edge node training data and the neighbor node training data, the edge node and each neighbor node of the edge node are determined, and then, with the edge node as the central node, the edge node and each neighbor node construct an edge computing heterogeneous graph network, and finally, a heterogeneous graph attention network model is constructed based on the edge computing heterogeneous graph network.

[0149] Furthermore, the heterogeneous graph attention network model to be trained includes a central node level graph attention layer, an edge node anomaly locator and several neighbor node level graph attention layers, and the above step A50 includes:

[0150] Step A51, based on the plurality of neighbor node level graph attention layers, perform neighbor node level attention aggregation on the edge node training data in the training sample data and each of the neighbor node training data in the training sample data to obtain each edge node feature;

[0151] In this embodiment, based on several neighbor node-level graph attention layers, the edge node training data in the training sample data are respectively aggregated with the neighbor node training data in the training sample data at the neighbor node level to obtain the features of each edge node. Specifically, taking an edge node in the edge node training data as the central node, the network performance data of an edge node in the edge node training data are respectively aggregated with the network performance data of the adjacent neighbor nodes at the neighbor node level, that is, the node-level attention mechanism is used to learn the different importance of the neighbor nodes of the edge node for judging whether the edge node is abnormal and the abnormal location, so as to assign different weights to the relationship between nodes according to the difference in importance, so as to obtain the features of each edge node. Among them, each edge node feature integrates the information of each neighbor node.

[0152] Among them, the calculation of the graph attention of neighbor node-level attention aggregation is divided into two steps: calculating the attention coefficient and weighted summation. It can be understood that the graph attention model is implemented by stacking graph attention layers, and the input of each graph attention layer is the feature set of the node.

[0153] Among them, the number of convolution kernels of the neighbor node level graph attention layer can be 256, and its activation function can be set to "relu".

[0154] In some embodiments, the neighbor node training data includes multiple neighbor node training data including MEP nodes, UPF nodes, DC-GW nodes and terminal nodes, the several neighbor node level graph attention layers include a first neighbor node level graph attention layer, a second neighbor node level graph attention layer, a third neighbor node level graph attention layer and a fourth neighbor node level graph attention layer, and the above step A51 includes:

[0155] Based on the first neighbor node-level graph attention layer, the network performance data of the edge nodes in the edge node training data and the network performance data of the MEP node are aggregated at the neighbor node level attention to obtain a first edge node feature; based on the second neighbor node-level graph attention layer, the network performance data of the edge nodes in the edge node training data and the network performance data of the UPF node are aggregated at the neighbor node level attention to obtain a second edge node feature; based on the third neighbor node-level graph attention layer, the network performance data of the edge nodes in the edge node training data and the network performance data of the DC-GW node are aggregated at the neighbor node level attention to obtain a third edge node feature; based on the fourth neighbor node-level graph attention layer, the network performance data of the edge nodes in the edge node training data and the network performance data of the terminal node are aggregated at the neighbor node level attention to obtain a fourth edge node feature.

[0156] In one embodiment, the terminal node is a base station node, and the step of performing neighbor node level attention aggregation on the network performance data of the edge nodes in the edge node training data and the network performance data of the terminal node based on the fourth neighbor node level graph attention layer to obtain a fourth edge node feature includes: performing neighbor node level attention aggregation on the network performance data of the edge nodes in the edge node training data and the network performance data of the base station node based on the fourth neighbor node level graph attention layer to obtain a fourth edge node feature.

[0157] Step A52, based on the central node level graph attention layer, performing central node level attention aggregation on the edge node features to obtain edge node aggregate features;

[0158] In this embodiment, based on the central node-level graph attention layer, central node-level attention aggregation is performed on each edge node feature to obtain edge node aggregate features. Specifically, central node-level attention aggregation is performed on each edge node feature that is fused with the network performance data of neighboring nodes, that is, different attention weights are assigned to each edge node feature to output edge node aggregate features that simultaneously fuse the features of each neighboring node.

[0159] Among them, the calculation of the graph attention of the central node-level attention aggregation is divided into two steps: calculating the attention coefficient and weighted summation. It can be understood that the graph attention model is implemented by stacking graph attention layers, and the input of each graph attention layer is the feature set of the node.

[0160] Among them, the number of convolution kernels of the central node level graph attention layer can be 128, and the activation function can be set to "relu".

[0161] Step A53, based on the edge node anomaly locator and the edge node aggregation feature, performing anomaly location prediction on the edge node to obtain an anomaly location prediction result;

[0162] In this embodiment, based on the edge node anomaly locator and the edge node aggregation feature, an abnormal location prediction is performed on the edge node to obtain an abnormal location prediction result. Specifically, based on the edge node anomaly locator and the edge node aggregation feature, a binary classification prediction is performed on the edge node aggregation feature to obtain a binary classification prediction result, and based on the binary classification prediction result, an abnormal location prediction result of the current edge node is obtained.

[0163] Wherein, the edge node anomaly locator includes a fully connected layer, and the above step S23 includes: based on the fully connected layer and the edge node aggregation features, performing anomaly location prediction on the current edge node to obtain an anomaly location prediction result. Specifically, based on the fully connected layer and the edge node aggregation features, performing binary classification prediction on the edge node aggregation features to obtain a binary classification prediction result, and based on the binary classification prediction result, obtaining the anomaly location prediction result of the current edge node.

[0164] In one embodiment, the number of neurons in the fully connected (Dense) layer is set to Z, where Z is the Z components of edge computing, the activation function can be set to "sigmoid", and the abnormal location prediction result of 1 represents that there is an abnormality in the edge computing component, and the abnormal location prediction result of 0 represents that there is no abnormality in the edge computing component.

[0165] Step A54, based on the anomaly location prediction result and the anomaly location result data in the training sample data, iteratively train the heterogeneous graph attention network model to be trained to obtain an anomaly prediction model.

[0166] In this embodiment, based on the anomaly location prediction results and the anomaly location result data in the training sample data, the heterogeneous graph attention network model to be trained is iteratively trained to obtain an anomaly prediction model. Specifically, a training sample is selected from the training sample data, and the network performance data of the edge nodes and the network performance data of the neighbor nodes corresponding to the training sample are input into the heterogeneous graph attention network model to be trained, and the model prediction is performed to obtain the model output label, and then the difference between the model output label and the anomaly location prediction result corresponding to the training sample is calculated to obtain the model loss, and then based on the model loss, the heterogeneous graph attention network model to be trained is updated until the number of iterations of the heterogeneous graph attention network model to be trained reaches a preset number of iterations.

[0167] In this embodiment, the graph attention network can be used to assign different weights according to the difference in the influence of neighbor nodes in the graph network, and an edge computing heterogeneous graph network is constructed with the edge node as the center, which is composed of heterogeneous nodes of edge nodes and various neighbor nodes. In addition, the multi-level heterogeneous graph attention network of the abnormal prediction model includes two parts: neighbor node level graph attention and central node level graph attention. With the edge node as the central node, neighbor node level attention aggregation is performed with adjacent neighbor nodes of various types respectively. The node-level attention mechanism is used to learn the different importance of various neighbor nodes of the edge node for judging whether the edge node is abnormal and the abnormal location, and different weights are assigned to the relationship between nodes according to the difference in importance. Then, the features of each edge node after the multi-dimensional KPI feature information of each node is fused respectively, and different attention weights are assigned to each edge node feature. Finally, the edge node features that simultaneously fuse the features of various neighbor nodes are input into the edge node abnormal locator composed of the fully connected layer to output the abnormal location prediction result of the edge node, thereby improving the abnormal discovery and processing capabilities of the edge node, and further improving the processing performance of the abnormal location of the edge node.

[0168] The present application also provides a device for locating anomalies in edge nodes.

[0169] Reference Figure 6 , Figure 6 This is a functional module diagram of the first embodiment of the edge node abnormality locating device of the present application.

[0170] In this embodiment, the edge node abnormality locating device includes:

[0171] An acquisition module 10 is used to acquire network performance data of a current edge node and a neighboring node, wherein the neighboring node is a node associated with the current edge node;

[0172] The prediction module 20 is used to perform anomaly location prediction on the current edge node based on the trained anomaly prediction model and the network performance data to obtain an anomaly location prediction result.

[0173] Furthermore, the anomaly prediction model includes a central node level graph attention layer, an edge node anomaly locator and several neighbor node level graph attention layers, and the prediction module 20 includes:

[0174] A neighbor aggregation unit, configured to perform neighbor node-level attention aggregation on the network performance data of the current edge node and the network performance data of each of the neighbor nodes based on the plurality of neighbor node-level graph attention layers, to obtain features of each edge node;

[0175] A central aggregation unit, configured to perform central node-level attention aggregation on each edge node feature based on the central node-level graph attention layer to obtain edge node aggregation features;

[0176] The anomaly prediction unit is used to perform anomaly location prediction on the current edge node based on the edge node anomaly locator and the edge node aggregation feature to obtain an anomaly location prediction result.

[0177] Furthermore, the neighbor aggregation unit includes:

[0178] A standardization processing subunit, used to perform standardization processing on the network performance data of the current edge node and the network performance data of each of the neighboring nodes to obtain a performance vector of the current edge node and a performance vector of each of the neighboring nodes;

[0179] The neighbor aggregation subunit is used to perform neighbor node level attention aggregation on the performance vector of the current edge node and the performance vector of each neighbor node respectively based on the several neighbor node level graph attention layers to obtain the characteristics of each edge node.

[0180] Further, the neighbor node includes a plurality of neighbor nodes, the plurality of neighbor nodes include a MEP node, a UPF node, a DC-GW node and a terminal node, the plurality of neighbor node level graph attention layers include a first neighbor node level graph attention layer, a second neighbor node level graph attention layer, a third neighbor node level graph attention layer and a fourth neighbor node level graph attention layer, and the neighbor aggregation unit further includes:

[0181] A first neighbor aggregation subunit is configured to perform neighbor node level attention aggregation on the network performance data of the current edge node and the network performance data of the MEP node based on the first neighbor node level graph attention layer to obtain a first edge node feature;

[0182] A second neighbor aggregation subunit is used to perform neighbor node level attention aggregation on the network performance data of the current edge node and the network performance data of the UPF node based on the second neighbor node level graph attention layer to obtain a second edge node feature;

[0183] A third neighbor aggregation subunit is used to perform neighbor node level attention aggregation on the network performance data of the current edge node and the network performance data of the DC-GW node based on the third neighbor node level graph attention layer to obtain a third edge node feature;

[0184] The fourth neighbor aggregation subunit is used to perform neighbor node level attention aggregation on the network performance data of the current edge node and the network performance data of the terminal node based on the fourth neighbor node level graph attention layer to obtain a fourth edge node feature.

[0185] Furthermore, the edge node abnormality locating device further includes:

[0186] A label marking module is used to obtain edge node training data and neighbor node training data, and to mark the edge node training data and the neighbor node training data with labels for abnormal location results to obtain abnormal location result data;

[0187] A sample selection module is used to obtain a model to be trained and select training sample data from the edge node training data, the neighbor node training data and the anomaly positioning result data;

[0188] The model training module is used to iteratively train the model to be trained based on the training sample data to obtain an abnormality prediction model.

[0189] Furthermore, the model to be trained is a heterogeneous graph attention network model to be trained, and the edge node abnormality locating device also includes:

[0190] A node determination module, configured to determine an edge node and each neighbor node of the edge node based on the edge node training data and the neighbor node training data;

[0191] A model construction module is used to take the edge node as the central node and construct the heterogeneous graph attention network model to be trained by the edge node and each neighbor node.

[0192] Furthermore, the heterogeneous graph attention network model to be trained includes a central node level graph attention layer, an edge node anomaly locator and several neighbor node level graph attention layers, and the model training module includes:

[0193] The neighbor aggregation unit is further used to perform neighbor node level attention aggregation on the edge node training data in the training sample data and each of the neighbor node training data in the training sample data based on the plurality of neighbor node level graph attention layers to obtain each edge node feature;

[0194] The central aggregation unit is further used to perform central node level attention aggregation on each edge node feature based on the central node level graph attention layer to obtain edge node aggregation features;

[0195] The anomaly prediction unit is further used to perform anomaly location prediction on the edge node based on the edge node anomaly locator and the edge node aggregation feature to obtain an anomaly location prediction result;

[0196] A model training unit is used to iteratively train the heterogeneous graph attention network model to be trained based on the anomaly location prediction result and the anomaly location result data in the training sample data to obtain an anomaly prediction model.

[0197] Among them, the functional implementation of each module in the above-mentioned edge node anomaly locating device corresponds to each step in the above-mentioned edge node anomaly locating method embodiment, and its functions and implementation processes are no longer repeated here one by one.

[0198] The present application also provides a computer-readable storage medium, on which an edge node anomaly locating program is stored. When the edge node anomaly locating program is executed by a processor, the steps of the edge node anomaly locating method described in any of the above embodiments are implemented.

[0199] The specific embodiments of the computer-readable storage medium of the present application are basically the same as the embodiments of the above-mentioned edge node abnormality location method, and will not be described in detail here.

[0200] The present application also provides a computer program product, which includes a computer program. When the computer program product is executed by a processor, the steps of the edge node abnormality locating method as described in any of the above embodiments are implemented.

[0201] The specific embodiments of the computer program product of the present application are basically the same as the embodiments of the above-mentioned edge node abnormality positioning method, and will not be described in detail here.

[0202] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or system. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or system including the element.

[0203] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0204] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes a number of instructions for a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0205] The above are only preferred embodiments of the present application, and are not intended to limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. A method for locating abnormal edge nodes. It is characterized in that The edge node abnormality positioning method comprises the following steps: Obtain network performance data of the current edge node and neighbor nodes, wherein the neighbor node is a node associated with the current edge node, the neighbor node includes multiple neighbor nodes, and the multiple neighbor nodes include MEP nodes, UPF nodes, DC-GW nodes, and terminal nodes; Based on the trained anomaly prediction model and the network performance data, anomaly location prediction is performed on the current edge node to obtain an anomaly location prediction result, wherein the anomaly prediction model includes a central node level graph attention layer, an edge node anomaly locator, and several neighbor node level graph attention layers, wherein the several neighbor node level graph attention layers include a first neighbor node level graph attention layer, a second neighbor node level graph attention layer, a third neighbor node level graph attention layer, and a fourth neighbor node level graph attention layer; The abnormal location prediction of the current edge node is performed based on the trained abnormality prediction model and the network performance data to obtain the abnormal location prediction result, including: Based on the several neighbor node level graph attention layers, the network performance data of the current edge node is respectively aggregated with the network performance data of each of the neighbor nodes at the neighbor node level to obtain the features of each edge node; Based on the central node level graph attention layer, performing central node level attention aggregation on the features of each edge node to obtain edge node aggregate features; Based on the edge node anomaly locator and the edge node aggregation feature, anomaly location prediction is performed on the current edge node to obtain an anomaly location prediction result.

2. The edge node abnormality positioning method according to claim 1, It is characterized in that The step of performing neighbor node level attention aggregation on the network performance data of the current edge node and the network performance data of each of the neighbor nodes based on the plurality of neighbor node level graph attention layers to obtain the features of each edge node comprises: Standardizing the network performance data of the current edge node and the network performance data of each of the neighboring nodes to obtain a performance vector of the current edge node and a performance vector of each of the neighboring nodes; Based on the several neighbor node level graph attention layers, the performance vector of the current edge node is respectively aggregated with the performance vectors of each neighbor node by neighbor node level attention to obtain the features of each edge node.

3. The edge node abnormality positioning method according to claim 2, It is characterized in that The step of performing neighbor node level attention aggregation on the network performance data of the current edge node and the network performance data of each of the neighbor nodes based on the plurality of neighbor node level graph attention layers to obtain the features of each edge node comprises: Based on the first neighbor node level graph attention layer, performing neighbor node level attention aggregation on the network performance data of the current edge node and the network performance data of the MEP node to obtain a first edge node feature; Based on the second neighbor node level graph attention layer, the network performance data of the current edge node and the network performance data of the UPF node are aggregated at the neighbor node level to obtain a second edge node feature; Based on the third neighbor node level graph attention layer, the network performance data of the current edge node and the network performance data of the DC-GW node are aggregated at the neighbor node level to obtain a third edge node feature; Based on the fourth neighbor node level graph attention layer, the network performance data of the current edge node and the network performance data of the terminal node are aggregated at the neighbor node level to obtain a fourth edge node feature.

4. The edge node abnormality positioning method according to claim 1, It is characterized in that Before the step of performing abnormal location prediction on the current edge node based on the trained abnormality prediction model and the network performance data to obtain an abnormal location prediction result, the method further includes: Acquire edge node training data and neighbor node training data, and annotate the edge node training data and the neighbor node training data with labels for anomaly location results to obtain anomaly location result data; Acquire a model to be trained, and select training sample data from the edge node training data, the neighbor node training data, and the anomaly positioning result data; Based on the training sample data, the model to be trained is iteratively trained to obtain an abnormality prediction model.

5. The method for locating an abnormal edge node according to claim 4, It is characterized in that The model to be trained is a heterogeneous graph attention network model to be trained. The step of obtaining the model to be trained, before the step of selecting training sample data from the edge node training data, the neighbor node training data and the anomaly positioning result data, further includes: Determine an edge node and each neighbor node of the edge node based on the edge node training data and the neighbor node training data; Taking the edge node as the central node, the heterogeneous graph attention network model to be trained is constructed by the edge node and each neighbor node.

6. The edge node abnormality positioning method according to claim 5, It is characterized in that The heterogeneous graph attention network model to be trained includes a central node level graph attention layer, an edge node anomaly locator and several neighbor node level graph attention layers. The step of iteratively training the model to be trained based on the training sample data to obtain an anomaly prediction model includes: Based on the plurality of neighbor node level graph attention layers, the edge node training data in the training sample data are respectively subjected to neighbor node level attention aggregation with each of the neighbor node training data in the training sample data to obtain features of each edge node; Based on the central node level graph attention layer, performing central node level attention aggregation on the features of each edge node to obtain edge node aggregate features; Based on the edge node anomaly locator and the edge node aggregation features, anomaly location prediction is performed on the edge node to obtain an anomaly location prediction result; Based on the anomaly location prediction result and the anomaly location result data in the training sample data, the heterogeneous graph attention network model to be trained is iteratively trained to obtain an anomaly prediction model.

7. An edge node abnormality positioning device, It is characterized in that The edge node abnormality locating device comprises: An acquisition module is used to acquire network performance data of a current edge node and a neighboring node, wherein the neighboring node is a node associated with the current edge node, and the neighboring node includes multiple nodes, and the multiple neighboring nodes include a MEP node, a UPF node, a DC-GW node, and a terminal node; A prediction module, used to perform anomaly location prediction on the current edge node based on the trained anomaly prediction model and the network performance data to obtain an anomaly location prediction result, wherein the anomaly prediction model includes a central node level graph attention layer, an edge node anomaly locator, and several neighbor node level graph attention layers, wherein the several neighbor node level graph attention layers include a first neighbor node level graph attention layer, a second neighbor node level graph attention layer, a third neighbor node level graph attention layer, and a fourth neighbor node level graph attention layer; The prediction module includes a neighbor aggregation unit, a center aggregation unit and an abnormal prediction unit. The neighbor aggregation unit is used to perform neighbor node level attention aggregation on the network performance data of the current edge node and the network performance data of each of the neighbor nodes based on the plurality of neighbor node level graph attention layers to obtain features of each edge node; The central aggregation unit is used to perform central node level attention aggregation on each edge node feature based on the central node level graph attention layer to obtain edge node aggregation features; The anomaly prediction unit is used to perform anomaly location prediction on the current edge node based on the edge node anomaly locator and the edge node aggregation feature to obtain an anomaly location prediction result.

8. An edge node abnormality location device, It is characterized in that The edge node anomaly locating device comprises: a memory, a processor, and an edge node anomaly locating program stored in the memory and executable on the processor. When the edge node anomaly locating program is executed by the processor, the steps of the edge node anomaly locating method according to any one of claims 1 to 6 are implemented.

9. A computer program product, It is characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the steps of the edge node abnormality locating method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Prediction method and system based on heterogeneous graph neural network model

    CN111400560A

  • Social network abnormal user detection method and device based on heterogeneous graph neural network

    CN112861967A