A method and device for mining abnormal patterns in spatio-temporal sequences

By determining the adaptive neighbor values ​​of space-time coordinated abnormal events in the space-time sequence exception mode mining method and clustering space-time coordinated abnormal events, the problem of ignoring the coordination situation of space-time abnormal events in the existing technology is solved, and efficient abnormal mode mining of space-time sequence data is realized.

CN116028690BActive Publication Date: 2025-06-13UNIV OF SCI & TECH BEIJING
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210730876.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-24
Publication Date
2025-06-13
Estimated Expiration
2042-06-24

AI Technical Summary

Technical Problem

The prior art ignores the synergy of space-time anomalies, and rarely cluster analysis is performed on data involving different spatial and temporal ranges, and parameters are usually required to be set manually.

Method used

A spatiotemporal sequence anomaly mode mining method is proposed. By determining the set of abnormal subsequences at all spatial locations, the spatial direct neighbor relationship and the temporal intersection relationship between the abnormal subsequences, and the distance between space-time coordinated abnormal events, the adaptive nearest neighbor value clustering space-time coordinated abnormal events are used to determine the final space-time abnormal mode.

Benefits of technology

The abnormal mode mining of spatiotemporal sequence data is realized, and the spatial and temporal changes of spatiotemporal abnormal events are discovered and mined. There is no need to set parameters manually, which improves the collaborative analysis ability of spatiotemporal abnormal events.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116028690B_ABST
    Figure CN116028690B_ABST
Patent Text Reader

Abstract

The present invention provides a spatio-temporal sequence anomaly pattern mining method and apparatus, which relate to the technical fields of anomaly pattern mining and spatio-temporal collaboration. Determine the set of anomalous subsequences at all spatial positions; determine the spatial direct neighbor relationship and time intersection relationship between the anomalous subsequences, and determine the spatial range and duration of the spatio-temporal collaborative anomaly event; obtain the adaptive neighbor value of the spatio-temporal collaborative anomaly event according to the determined spatial range and duration, cluster the spatio-temporal collaborative anomaly events through the adaptive neighbor value, determine the final spatio-temporal anomaly pattern, and complete the spatio-temporal sequence anomaly pattern mining. Aiming at the problem of anomaly pattern mining for spatio-temporal sequence data, a spatio-temporal sequence anomaly pattern mining algorithm based on spatio-temporal collaborative anomaly events is proposed. The concept of spatial direct neighbors is used to mine spatio-temporal collaborative anomaly patterns, and the density of each event is determined through a spatio-temporal collaborative anomaly event metric, so as to realize the anomaly pattern mining of spatio-temporal sequence data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of abnormal pattern mining and spatio-temporal collaboration, and particularly to a method and device for mining abnormal patterns of spatio-temporal sequences. Background Art

[0002] Mining spatio-temporal abnormal events is to better understand certain abnormal phenomena by analyzing events with abnormal states in space and time, such as natural disaster events, environmental pollution events, health and safety events, etc. According to the different manifestations of abnormal events, the abnormal events of spatio-temporal sequences are divided into two situations: (1) The first situation is "things that occur at specific times and locations", which describes the abnormal event points, including three aspects of the abnormal event: time, location, and abnormality, and is applied in multiple fields. However, this situation ignores the process factors of abnormal events, namely start, end, duration, scope of influence, etc.; (2) The second situation is the continuous abnormality that appears in non-spatio-temporal attributes, and the application scope of this kind of spatio-temporal abnormal event is more extensive.

[0003] The current methods for mining spatio-temporal abnormal events ignore the collaboration situation of spatio-temporal abnormal events, that is, if there is a time intersection (at the same time, before or after) between abnormal events occurring at two adjacent locations, the two should belong to the same abnormal event. There are few existing spatio-temporal clustering algorithms that perform clustering analysis on data involving different spatial ranges and time ranges, and usually require manual parameter setting. Summary of the Invention

[0004] Aiming at the problems in the prior art that the collaboration situation of spatio-temporal abnormal events is ignored, there are few clustering analyses on data involving different spatial ranges and time ranges, and usually manual parameter setting is required, the present invention proposes a method and device for mining abnormal patterns of spatio-temporal sequences.

[0005] To solve the above technical problems, the present invention provides the following technical solutions:

[0006] On the one hand, a method for mining abnormal patterns of spatio-temporal sequences is provided. The method is applied to an electronic device and includes the following steps:

[0007] S1: Determine the set of abnormal subsequences at all spatial positions;

[0008] S2: Determine the spatial direct neighbor relationship and time intersection relationship between abnormal subsequences, and determine spatio-temporal collaborative abnormal events;

[0009] S3: Determine the distances between all spatio-temporal collaborative abnormal events, obtain the adaptive neighbor value of the spatio-temporal collaborative abnormal events, cluster the spatio-temporal collaborative abnormal events through the adaptive neighbor value, determine the final spatio-temporal abnormal pattern, and complete the mining of the abnormal pattern of the spatio-temporal sequence.

[0010] Optionally, step S1 includes determining a set of abnormal subsequences at all spatial positions, including:

[0011] S11: Obtain spatio-temporal data X = {X 1 , X 2 ,..., X i ,..., X n}; where n is the number of spatial positions, and X i represents the time series at the i-th spatial position;

[0012] S12: According to the spatio-temporal data, determine a set of abnormal subsequences at all spatial positions, denoted as

[0013] Optionally, in step S2, determine the spatial direct neighbor relationship and time intersection relationship between abnormal subsequences, and determine spatio-temporal collaborative abnormal events, including:

[0014] S21: Define the spatial direct neighbor relationship between abnormal subsequences;

[0015] S22: Use the abnormal subsequence with the earliest start time in the set S - of all spatial positions as the first element e 1 of the first spatio-temporal collaborative abnormal event E 1,1 , and determine the spatial position L 1,1 where e j is located;

[0016] S23: According to the spatial direct neighbor relationship, determine the spatial direct neighbor L j of L i , and search for whether there is an abnormal subsequence at these spatial positions. If there is, use this abnormal subsequence as e 1,2 and add it to E 1 . Then, judge the spatial direct neighbor of e 1,2 ; until there is no abnormal subsequence intersecting with its time on the direct neighbors of the spatial positions where all elements in E 1 are located;

[0017] S24: Determine the final first spatio-temporal collaborative abnormal event

[0018] Optionally, in step S21, defining the spatial direct neighbor relationship between abnormal subsequences includes:

[0019] S211: Taking the selected target position as the center and the straight line between the target position and its nearest position as one axis of the rectangular coordinate system, construct a rectangular coordinate system;

[0020] S212: Determine L according to the preset angle range i with respect to L j the spatial range area it belongs to;

[0021] S213: Determine the closest points in the spatial area respectively as the spatial direct neighbors of the target spatial position L j of L.

[0022] Optionally, in step S3, determine the distances between all spatio-temporal collaborative anomaly events to obtain the adaptive neighbor value of the spatio-temporal collaborative anomaly events, and cluster the spatio-temporal collaborative anomaly events through the adaptive neighbor value to determine the final spatio-temporal anomaly pattern, completing the mining of the spatio-temporal sequence anomaly pattern, including:

[0023] S31: Denote the set of spatio-temporal collaborative anomaly events as: STE = {E 1 , E 2 ,..., E q , …, E w}, where the number of spatio-temporal collaborative anomaly events is w, b q is the number of spatial positions involved in the q-th spatio-temporal collaborative anomaly event, e q,j is a certain anomaly subsequence in the set of all spatial position anomaly subsequences, where a q,j represents the number of data points contained in the subsequence e q,j ;

[0024] S32: For any two collaborative anomaly events in the set of spatio-temporal collaborative anomaly events STE calculate the distance D q between E z and E dtw (E q , E z ) using the superimposed DTW metric method according to the following formula (1):

[0025]

[0026] where, E z [1:b z -1] is the set of remaining anomaly subsequences after removing the last anomaly subsequence from E z , that is E q [1:b q -1] is the set of remaining anomaly subsequences after removing the last anomaly subsequence from E q , that is represents the anomaly subsequence and the anomaly subsequence The DTW distance between;

[0027] S33: Determine the adaptive k-nearest neighbor values K = {K 1 , K 2 , …, K q , …, K w} of all collaborative anomaly events based on the adaptive k-nearest neighbor search method, and use them as the density of each collaborative anomaly event;

[0028] S34: Iteratively obtain the cluster centers according to the obtained density and the distance of spatio-temporal collaborative anomaly events, and determine the number c of cluster centers when the iteration stops according to the silhouette coefficient in Definition 5;

[0029] S35: Output the set of cluster centers, and determine the set of anomaly patterns P = {p 1 , p 2 , …, p j ,..., p c}, and complete the mining of spatio-temporal sequence anomaly patterns.

[0030] Optionally, in step S34, iteratively obtaining the cluster centers according to the obtained density and the distance of spatio-temporal collaborative anomaly events includes:

[0031] Take the collaborative anomaly event with the largest adaptive k value as the first cluster center p 1 , and find the collaborative anomaly event with the largest density among the v collaborative anomaly events farthest from p 1 as the second cluster center p 2 ;

[0032] where is the value obtained by rounding up the ratio of the number w of collaborative anomaly events to 10 and adding 1;

[0033] Determine the cluster to which each collaborative anomaly event belongs when the number of clusters is 2 according to the distances between the remaining collaborative anomaly events and the two cluster centers; Calculate the current silhouette coefficient sil 2 using the silhouette coefficient as the clustering validity index, and obtain all cluster centers.

[0034] Optionally, in step S35, determining the set of anomaly patterns P = {p 1 , p 2 , …, p j , …, p c} includes:

[0035] When the number of clusters is i, among the distances from the existing cluster centers {p 1 , p 2 ,..., p i-1Find the collaborative anomaly event with the highest density among the v collaborative anomaly events with the largest sum of distances as the i-th clustering center p i , and assign each remaining collaborative anomaly event to the category where the nearest clustering center is located; calculate the silhouette coefficient sil at this time i , if sil i < sil i-1 , at this time c = i - 1, then output the clustering center set P = {p 1 , p 2 ,..., p c}, to determine the clustering center and divide the collaborative anomaly events; otherwise i = i + 1, and continue to find the next clustering center p i ; determine the spatio-temporal anomaly pattern set P = {p 1 , p 2 ,..., p i ,..., p c}.

[0036] On the one hand, a spatio-temporal sequence anomaly pattern mining device is provided. The device is applied to an electronic device and includes:

[0037] A set determination module for determining the set of abnormal subsequences at all spatial positions;

[0038] A relationship determination module for determining the spatial direct neighbor relationship and time intersection relationship between abnormal subsequences, and determining spatio-temporal collaborative anomaly events;

[0039] A spatio-temporal sequence anomaly pattern mining module for determining the distances between all spatio-temporal collaborative anomaly events, obtaining the adaptive neighbor value of the spatio-temporal collaborative anomaly events, clustering the spatio-temporal collaborative anomaly events through the adaptive neighbor value, determining the final spatio-temporal anomaly pattern, and completing the spatio-temporal sequence anomaly pattern mining.

[0040] Optionally, the set determination module is used to obtain spatio-temporal data X = {X 1 , X 2 ,..., X i ,..., X n}; where n is the number of spatial positions, and X i represents the time series at the i-th spatial position;

[0041] According to the spatio-temporal data, determine the set of abnormal subsequences at all spatial positions, denoted as

[0042] Optionally, the relationship determination module is used to define the spatial direct neighbor relationship between abnormal subsequences;

[0043] The set S of abnormal subsequences at all spatial positions -The abnormal subsequence with the earliest start time in the middle is used as the first spatio-temporal collaborative abnormal event E 1 The first element e 1,1 of, determine e 1,1 The spatial location L j where it is located;

[0044] Determine the direct spatial neighbors of L j The direct spatial neighbors L i of, and look for abnormal subsequences at these spatial positions. If any exist, use this abnormal subsequence as e 1,2 Add it to E 1 in, and then judge the direct spatial neighbors of e 1,2 ; until there are no abnormal subsequences intersecting with its time on the direct neighbors of the spatial positions of all elements in E 1 ;

[0045] Determine the final first spatio-temporal collaborative abnormal event

[0046] On the one hand, an electronic device is provided. The electronic device includes a processor and a memory. At least one instruction is stored in the memory, and the at least one instruction is loaded and executed by the processor to implement the above-mentioned spatio-temporal sequence anomaly pattern mining method.

[0047] On the one hand, a computer-readable storage medium is provided. At least one instruction is stored in the storage medium, and the at least one instruction is loaded and executed by a processor to implement the above-mentioned spatio-temporal sequence anomaly pattern mining method.

[0048] The above technical solutions of the embodiments of the present invention have at least the following beneficial effects:

[0049] In the above solution, the present invention proposes an Anomaly Pattern Recognition of Spatio Timeseries Based on Spatio Temporal Collaborate Anomaly Events (AP-COAE) algorithm for the problem of abnormal pattern mining of spatio-temporal sequence data. It uses the concept of direct spatial neighbors to mine spatio-temporal collaborative abnormal patterns, and determines the density of each event through a spatio-temporal collaborative abnormal event metric to achieve abnormal pattern mining of spatio-temporal sequence data. Different from previous spatio-temporal anomaly mining algorithms, it discovers and mines the spatio-temporal change process of spatio-temporal anomaly events. Description of the Drawings

[0050] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0051] Figure 1 is a flowchart of a spatio-temporal sequence anomaly pattern mining method provided by an embodiment of the present invention;

[0052] Figure 2 is a spatial direct neighborhood graph of spatial data with coordinate information in a spatio-temporal sequence anomaly pattern mining method provided by an embodiment of the present invention;

[0053] Figure 3 is a monitoring graph of the same anomaly event at different spatial position points in a spatio-temporal sequence anomaly pattern mining method provided by an embodiment of the present invention;

[0054] Figure 4 is a flowchart of the AP-COAE algorithm in a spatio-temporal sequence anomaly pattern mining method provided by an embodiment of the present invention;

[0055] Figure 5 is a distribution map of the buoy positions of the Yellow Sea Station and the East China Sea Station in a spatio-temporal sequence anomaly pattern mining method provided by an embodiment of the present invention;

[0056] Figure 6 is the mining process of the first spatio-temporal collaborative anomaly event in a spatio-temporal sequence anomaly pattern mining method provided by an embodiment of the present invention;

[0057] Figure 7 is a schematic diagram of the distribution of spatio-temporal collaborative anomaly events (typhoons) in a spatio-temporal sequence anomaly pattern mining method provided by an embodiment of the present invention;

[0058] Figure 8 is a schematic diagram of the clustering result and anomaly pattern of the first type of spatio-temporal collaborative anomaly event - strong wind in a spatio-temporal sequence anomaly pattern mining method provided by an embodiment of the present invention;

[0059] Figure 9 is a schematic diagram of the clustering result and anomaly pattern of the second type of spatio-temporal collaborative anomaly event - gale in a spatio-temporal sequence anomaly pattern mining method provided by an embodiment of the present invention;

[0060] Figure 10 is a schematic diagram of the clustering result and anomaly pattern of the third type of spatio-temporal collaborative anomaly event - storm in a spatio-temporal sequence anomaly pattern mining method provided by an embodiment of the present invention;

[0061] Figure 11It is a schematic diagram of the clustering results and abnormal patterns of the fourth type of spatio-temporal collaborative abnormal event - hurricane in the spatio-temporal sequence abnormal pattern mining method provided by the embodiment of the present invention;

[0062] Figure 12 It is a clustering result diagram of the AP-COAE algorithm in the spatio-temporal sequence abnormal pattern mining method provided by the embodiment of the present invention;

[0063] Figure 13 It is a block diagram of the spatio-temporal sequence abnormal pattern mining device provided by the embodiment of the present invention;

[0064] Figure 14 It is a schematic structural diagram of an electronic device provided by the embodiment of the present invention. Detailed implementation manners

[0065] To make the technical problems, technical solutions and advantages to be solved by the present invention clearer, the following will be described in detail with reference to the accompanying drawings and specific embodiments.

[0066] The embodiment of the present invention provides a spatio-temporal sequence abnormal pattern mining method, which can be implemented by an electronic device, and the electronic device can be a terminal or a server. As Figure 1 shown in the flowchart of the spatio-temporal sequence abnormal pattern mining method, the processing flow of the method can include the following steps:

[0067] The embodiment of the present invention provides a spatio-temporal sequence abnormal pattern mining method, which can be implemented by an electronic device, and the electronic device can be a terminal or a server. As Figure 1 shown in the flowchart of the spatio-temporal sequence abnormal pattern mining method, the processing flow of the method can include the following steps:

[0068] S101: Obtain spatio-temporal data X = {X 1 , X 2 ,..., X i ,..., X n}; where n is the number of spatial positions, and X i represents the time series at the i-th spatial position;

[0069] S102: Determine the set of abnormal subsequences at all spatial positions according to the spatio-temporal data, denoted as

[0070] S103: Define the spatial direct neighbor relationship between abnormal subsequences;

[0071] In a feasible implementation manner, define the spatial direct neighbor relationship between abnormal subsequences. Taking the selected target position as the center and the straight line where the target position and its nearest position are located as one axis of the rectangular coordinate system, construct a rectangular coordinate system; according to the preset angle range, determine Li Relative to L j The spatial range area to which it belongs; determine the nearest points in the spatial area respectively as the target spatial position L j The direct spatial neighbor of

[0072] L i The direct spatial neighbor of L is i The spatial position most likely to be affected when an abnormal event occurs at. According to the different forms of spatial position representation, determine L i The method of determining the direct spatial neighbor is different. The present invention only defines the direct spatial neighbor of the spatial position containing coordinate information. As shown in Table 1 for L i Relative to L j The angle range determination table of

[0073] Table 1 L i Relative to L j The angle range determination table of

[0074]

[0075]

[0076] To determine the direct spatial neighbor of the spatial position L j First, with the target position as the center and the straight line where the target position and its nearest position are located as one axis of the rectangular coordinate system, construct a rectangular coordinate system, and use Table 1 to determine L i Relative to L j The spatial range area to which it belongs, determine the nearest points in 8 spatial areas respectively as the target spatial position L j The direct spatial neighbor of Figure 2 As shown in 1 When looking for the direct spatial neighbor of the target position L 1 Take L i Relative to L 1 The spatial area where it is located, and find the positions closest to L 1 respectively in 8 angle ranges. In the figure, L 2 , L 3 , L 4 , L 5 , L 6 , L 7 , L 8 , L 9 Are the direct spatial neighbors of L 1

[0077] S104: The set S of abnormal subsequences of all spatial positions - ​The abnormal subsequence with the earliest start time among them is used as the first spatio-temporal collaborative abnormal event E 1 as the first element e 1,1 of, and determine e 1,1 's spatial location L j ;

[0078] S105: Determine L j 's spatial direct neighbor L i , and search for whether there is an abnormal subsequence at these spatial positions. If there is, use this abnormal subsequence as e 1,2 and add it to E 1 . Then, judge e 1,2 's spatial direct neighbor; until there is no abnormal subsequence intersecting with its time on the direct neighbors of the spatial positions where all elements in E 1 are located;

[0079] S106: Determine the final first spatio-temporal collaborative abnormal event E 1 ={e 1,1 , e 1,2 ,..., e 1,b1}.

[0080] S107: Denote the spatio-temporal collaborative abnormal event set as: STE = {E 1 , E 2 ,..., E q ,..., E w}, where the number of spatio-temporal collaborative abnormal events is w, b q is the number of spatial positions involved in the qth spatio-temporal collaborative abnormal event, e q,j is an abnormal subsequence in the set of all spatial position abnormal subsequences, where a q,j represents the number of data points contained in the subsequence e q,j .

[0081] In a feasible implementation, the spatio-temporal collaborative abnormal event: appears as abnormal subsequences at adjacent times occurring on time series of different spaces. The spatio-temporal collaborative abnormal event set is denoted as: STE = {E 1 , E 2 ,..., E q ,..., E w}, where the number of spatio-temporal collaborative abnormal events is w, and among them b q is the number of spatial positions involved in the qth spatio-temporal collaborative abnormal event, e q,j is an abnormal subsequence in the set of all spatial position abnormal subsequences, where aq,j Denote the subsequence e q,j The number of data points it contains. Therefore, the spatio-temporal collaborative anomaly event is a two-dimensional array with different numbers of elements in each row.

[0082] S108: For any two collaborative anomaly events in the spatio-temporal collaborative anomaly event set STE Calculate E using the superimposed DTW metric method according to the following formula (1) q and E z The distance D between them dtw (E q , E z ):

[0083]

[0084] where E z [1:b z -1]) is the set of remaining anomaly subsequences after removing the last anomaly subsequence from E z , that is E q [1:b q -1]) is the set of remaining anomaly subsequences after removing the last anomaly subsequence from E q , that is Denote the anomaly subsequence and the anomaly subsequence The DTW distance between them.

[0085] In a feasible implementation, the spatio-temporal collaborative anomaly event distance: For any two collaborative anomaly events in the spatio-temporal collaborative anomaly event set STE The present invention proposes a superimposed DTW metric method to calculate the distance D between E q and E z : dtw (E q , E z ):

[0086]

[0087] where E z [1:b z -1]) is the set of remaining anomaly subsequences after removing the last anomaly subsequence from E z , that is E q [1:b q -1]) is the set of remaining anomaly subsequences after removing the last anomaly subsequence from E q , that is Indicates an abnormal subsequence With the abnormal subsequence The DTW distance between them is calculated as follows

[0088]

[0089] Indicates a point And the point The Euclidean distance between them is calculated as follows

[0090]

[0091] Definition 5 Silhouette coefficient: When the number of clusters is q, the calculation formula of the silhouette coefficient is

[0092]

[0093] Among them, w is the number of all collaborative abnormal events, C i Represents the i-th cluster, x is the collaborative abnormal event belonging to the class C i Of sam(x, C i ) is called the within-cluster dissimilarity of the collaborative abnormal event x, which is the average distance from the collaborative abnormal event x to other collaborative abnormal events in the same class. Dif(x, C j ) is called the between-cluster dissimilarity of the collaborative abnormal event x, which is the smallest one among the average distances from the collaborative abnormal event x to all collaborative abnormal events in all other clusters. Its definition is as follows

[0094]

[0095]

[0096] Among them Is the number of collaborative abnormal events included in the class C i The number of collaborative abnormal events included in the class C Is the number of collaborative abnormal events included in the class C j The number of collaborative abnormal events included in D dtw (x, y) represents the DTW distance between the collaborative abnormal events x and y. The larger the silhouette coefficient value, the better the clustering effect

[0097] S109: Determine the adaptive k-nearest neighbor values K = {K 1 , K 2 ,..., K q ,..., K w} of all collaborative abnormal events based on the adaptive k-nearest neighbor search method, and use them as the density of each collaborative abnormal event

[0098] In a feasible implementation manner, first, the set S of abnormal subsequences at all spatial positions- The abnormal subsequence with the earliest start time among them is used as the first spatio-temporal collaborative abnormal event E 1 The first element e 1,1 of E 1,1 Determine the spatial location L j where e is located, and then determine L according to Definition 2 j The spatial direct neighbors L i of L. Search for whether there are abnormal subsequences at these spatial positions, and the occurrence time of which is within the occurrence time range of the abnormal subsequence e 1,1 . If there is, use this abnormal subsequence as e 1,2 and add it to E 1 . Then judge the spatial direct neighbors of e 1,2 . Search for e 1,2 among the spatial direct neighbors of e 1,3 until there are no abnormal subsequences with intersecting time on the direct neighbors of the spatial positions of all elements in E 1 . At this time, determine the final first spatio-temporal collaborative abnormal event Finally, for the remaining abnormal subsequences other than E 1 , perform the above steps in the same way until all abnormal subsequences belong to a certain spatio-temporal collaborative abnormal event

[0099] Thus, connect the abnormal subsequence sets at all spatial positions into a spatio-temporal collaborative abnormal event set STE = {E 1 , E 2 ,..., E q ,..., E w}. And the spatio-temporal collaborative abnormal event composed of multiple abnormal subsequences contains multiple abnormal subsequences with different time spans, and the number of elements contained in each spatio-temporal collaborative abnormal event is different, which characterizes the duration of the spatio-temporal collaborative abnormal event and the affected spatial range

[0100] In a feasible implementation, since "similar" data often has "correlated" behavior manifestations. "Similar" refers to being similar in time or space, and "correlated" means that the observed data is no longer independent and has a certain correlation. However, "correlated" does not necessarily mean similar, and this situation can be divided into positive correlation and negative correlation. But it can be determined that the occurrence of spatio-temporal abnormal events has an impact on similar spatial positions and times. Therefore, spatio-temporal abnormal events have collaboration

[0101] Spatio-temporal collaborative abnormal events are an important manifestation of spatio-temporal abnormal phenomena and play a very important role in understanding abnormal phenomena in various fields. For example Figure 3As shown, if a typhoon event occurs at location point 1, then the collaborative abnormal event (such as a significant increase in wind speed) should be detected at the nearby location points 2, 3, 4, and 5.

[0102] Geospatial locations are fixed and do not change over time. However, over time, abnormal events such as droughts or diseases will span these fixed spatial locations and spread across multiple spatial regions. Therefore, if the spatial location of one abnormal subsequence is a direct neighbor of the spatial location of another abnormal subsequence, and there is an intersection in their time ranges, then these two abnormal subsequences are very likely to belong to the same spatio-temporal collaborative abnormal event.

[0103] To determine the duration of abnormal events and the affected spatial scope in a spatio-temporal sequence, the present invention proposes a method for mining spatio-temporal collaborative abnormal events based on spatial diffusion and time intersection. The spatio-temporal collaborative abnormal events are mined using the two conditions of spatial direct neighbor and time intersection, based on the fact that a spatio-temporal collaborative abnormal event occurs in adjacent spatial regions and the occurrence times should be related.

[0104] In a feasible implementation, the collaborative abnormal event with the largest adaptive k value is used as the first clustering center p 1 , among the v collaborative abnormal events that are farthest from p 1 , the collaborative abnormal event with the largest density is found as the second clustering center p 2 ;

[0105] where is the value obtained by taking the integer part of the ratio of the number w of collaborative abnormal events to 10 and adding 1;

[0106] According to the distances between the remaining collaborative abnormal events and the two clustering centers, determine the clusters to which each collaborative abnormal event belongs when the number of clusters is 2; calculate the current silhouette coefficient sil using the silhouette coefficient as the clustering validity index 2 , and obtain all clustering centers.

[0107] S110: Iteratively obtain the clustering centers based on the obtained density and the distance of spatio-temporal collaborative abnormal events, and determine the number c of clustering centers when the iteration stops according to the silhouette coefficient in Definition 5;

[0108] S111: Output the set of clustering centers, determine the set of abnormal patterns P = {p 1 , p 2 ,..., p j ,..., p c}, and complete the mining of spatio-temporal sequence abnormal patterns.

[0109] In a feasible implementation, in view of the diversity of spatio-temporal collaborative abnormal events, to distinguish different types of collaborative abnormal events, the present invention clusters the obtained set of collaborative abnormal events STE = {E 1 , E 2 ,..., E q ,..., E w}, defines each clustering center as an abnormal pattern, and identifies different abnormal patterns. This algorithm can ensure the effectiveness of the clustering result when the number of clusters is unknown.

[0110] The clustering algorithm of the present invention finds the clustering centers according to two conditions: (1) the density of the clustering center is higher than the density of its neighboring collaborative abnormal events; (2) the distance between any two cluster centers is relatively far. The specific clustering steps are as follows:

[0111] First, calculate the distances between all spatio-temporal collaborative abnormal events according to Formula 1, and determine the adaptive k-nearest neighbor values K = {K 1 , K 2 ,..., K q ,..., K w} of all collaborative abnormal events based on the adaptive k-nearest neighbor search method, and use them as the densities of each collaborative abnormal event. Then, take the collaborative abnormal event with the largest adaptive k value as the first clustering center p 1 , and find the collaborative abnormal event with the largest density among the v collaborative abnormal events that are farthest from p 1 as the second clustering center p 2 , where is the value obtained by rounding up the ratio of the number w of collaborative abnormal events to 10 and adding 1. Determine the clusters to which each collaborative abnormal event belongs when the number of clusters is 2 according to the distances between the remaining collaborative abnormal events and the two clustering centers. Finally, use the Silhouette Coefficient as the clustering effectiveness index to calculate the current silhouette coefficient sil 2 . The set of clustering centers that maximizes the effectiveness index is all the clustering centers obtained by the algorithm.

[0112] Determine the set of abnormal patterns P = {p 1 , p 2 ,..., p j ,..., p c}, including: when the number of clusters is i, find the collaborative abnormal event with the largest density among the v collaborative abnormal events with the largest sum of distances from the existing clustering centers {p 1 , p 2 ,..., p i-1} as the i-th clustering center p i, assign each remaining collaborative anomaly event to the category where the nearest cluster center is located; calculate the silhouette coefficient sil at this time i , if sil i < sil i-1 , at this time c = i - 1, then output the set of cluster centers P = {p 1 , p 2 ,..., p c}, to determine the cluster centers and divide the collaborative anomaly events; otherwise i = i + 1, continue to find the next cluster center p i ; determine the set of spatio-temporal anomaly patterns P = {p 1 , p 2 ,..., p i ,..., p c}.

[0113] In a feasible implementation manner, based on the above content, the present invention proposes a spatio-temporal sequence anomaly pattern mining algorithm based on spatio-temporal collaborative anomaly events, which uses the anomaly subsequences at each spatial position, and uses two conditions, spatial diffusion and time intersection, to mine spatio-temporal collaborative anomaly events and cluster them to mine spatio-temporal anomaly patterns. The algorithm process does not require manual parameter setting. The algorithm mainly includes two parts: spatio-temporal collaborative anomaly event mining and spatio-temporal collaborative anomaly event clustering. The overall process of the algorithm is as Figure 4 shown.

[0114] The detailed implementation process of the spatio-temporal sequence anomaly pattern mining AP-COAE based on spatio-temporal collaborative anomaly events is as follows:[[]]

[0115] Input: The set of anomaly subsequences at all spatial positions

[0116] Output: The set of anomaly patterns P = {p 1 , p 2 ,..., p j ,..., p c}

[0117] The present invention identifies the set STE = {E 1 , E 2 ,..., E q ,..., E w} from all sets of anomaly subsequences, and obtains the final set of anomaly patterns P = {p 1 , p 2 ,..., p j ,..., p c} by clustering the spatio-temporal collaborative anomaly events. c is the number of final anomaly patterns and also the optimal number of clusters.

[0118] To more clearly demonstrate the mining process of spatio-temporal collaborative abnormal events and the accuracy of spatio-temporal abnormal pattern mining, the present invention verifies and evaluates the effectiveness of the AP-COAE algorithm from an experimental perspective. First, the experimental data and experimental environment are introduced. Then, the evaluation metrics for clustering algorithms are presented. Finally, the process of mining spatio-temporal collaborative abnormal events and the clustering results of spatio-temporal collaborative abnormal events are shown, and experimental comparisons and analyses are carried out using the evaluation metrics and comparative algorithms.

[0119] The experimental data is as follows:

[0120] Typhoons are disastrous weather generated by tropical cyclones formed over tropical ocean surfaces. The present invention selects the typhoon dataset in the Yellow Sea and East China Sea regions from 2010 to 2018 to illustrate the determination process of spatio-temporal collaborative abnormal events and mine the spatio-temporal abnormal patterns of typhoon events.

[0121] The latitude range of the observation sea areas of the Yellow Sea Station and the East China Sea Station is from 29°45′ north latitude to 38°46′ north latitude, and the longitude range is from 119°36′ east longitude to 124°00′ east longitude. The specific position distributions of 14 buoys with wind speed data when typhoons pass by are as Figure 5 shown.

[0122] The experimental environment is: Intel(R) Core(TM), i5-4200H CPU@2.80GHz processor, 8GB of memory, Win 10 64-bit operating system, and programming is done using the Python language.

[0123] From the buoy position distribution map, it can be seen that the buoys capturing abnormal wind speeds belong to two stations. The buoy numbers belonging to the Yellow Sea Station are: 01, 07, 09, 17, 18, 19; the buoy numbers belonging to the East China Sea Station are: 06, 10, 11, 12, 13, 14, 15, 20. The specific situations of each buoy are shown in Table 2, including information such as the station to which the buoy belongs, the number, the start time, and the number of abnormal subsequences on the buoy.

[0124] Table 2 Situations of buoys for obtaining wind speed data at the Yellow Sea Station and the East China Sea Station

[0125]

[0126] The present invention uses two metrics with upper bounds of 1, namely the Adjusted Rand Index (ARI) and the Normalized Mutual Information (NMI), to measure the clustering results of spatio-temporal abnormal events. The larger the values of these two measurement criteria, the higher the accuracy of the clustering algorithm and the better the clustering results of the algorithm.

[0127] The adjusted Rand index ARI is defined as follows:

[0128]

[0129] where: z a represents the number of abnormal event pairs that are in the same class in the algorithm clustering result and also in the same class in the true clustering of the dataset, z b represents the number of abnormal event pairs that are in the same class in the algorithm clustering result but not in the same class in the true clustering of the dataset, z c represents the number of abnormal event pairs that are not in the same class in the algorithm clustering result but are in the same class in the true clustering of the dataset, z d represents the number of abnormal event pairs that are not in the same class in the algorithm clustering result and also not in the same class in the true clustering of the dataset.

[0130] The normalized mutual information NMI is defined as follows:

[0131]

[0132] where, c A represents the number of clustering categories in the algorithm clustering result, c B represents the number of essential clustering categories in the dataset, w ab represents the number of abnormal events belonging to class a but classified into class b, w a represents the number of abnormal events in class a, w b represents the number of abnormal events in the true label class b.

[0133] The main purpose of the AP-COAE algorithm to identify collaborative spatio-temporal abnormal events is to automatically detect the spatial range and time span of collaborative spatio-temporal abnormal events from the set of abnormal subsequences at each spatial position. First, according to Definition 2, the spatial direct neighbors of all buoys are determined, and the results are shown in Table 3.

[0134] Table 3 Buoys involved in typhoon events at Huanghai Station and Donghai Station from 2010 to 2018

[0135]

[0136] From the typhoon dataset, it can be obtained that the earliest abnormal subsequence among all abnormal subsequences at the buoys occurred at buoy No. 11 at 16:00 on August 8, 2010, as Figure 6As shown in a), in the figure, we mark the date 2010-08-08 16:00 as scale 1, and the scale increases by 1 every 2 hours. Therefore, when the scale is 34, the corresponding date is 2010-08-11 10:00. The direct spatial neighbors of buoy No. 11 are 06, 07, 12, 14, and 15. Check whether the occurrence times of the abnormal subsequences at these buoys are between 16:00 on August 8, 2010 and 10:00 on August 11, 2010. There are abnormal subsequences that meet the requirements at the two buoys numbered 06 and 12. The abnormal subsequence at 06 occurred at 19:00 on August 8, 2010, so its starting scale value is 2.5. The abnormal subsequence at buoy No. 12 occurred at 21:00 on August 8, 2010, and its starting scale value is 3.5. As Figure 6 shown in b) and c). Attribute these two abnormal subsequences to the spatio-temporal collaborative abnormal event E 1 , delete these two abnormal subsequences from the original set of abnormal subsequences, and continue to find the direct spatial neighbors 07, 11, 12, 15, and 20 of buoy No. 06. Search for abnormal subsequences at the starting time of the current abnormal event from the remaining set of abnormal subsequences. There are no abnormal subsequences that meet the conditions. Similarly, there are no abnormal subsequences that meet the conditions at buoy No. 12. At this time, the abnormal event E 1 mining is completed, and its time series representation is as Figure 6 shown in d).

[0137] Table 4 Buoys involved in typhoon events at the Yellow Sea Station and the East China Sea Station from 2010 to 2018

[0138]

[0139]

[0140] Table 5 Duration of typhoon events at the Yellow Sea Station and the East China Sea Station from 2010 to 2018

[0141]

[0142]

[0143] Continuously mine the typhoon data set according to the above steps until all abnormal subsequences belong to a certain spatio-temporal collaborative abnormal event. Finally, 24 spatio-temporal collaborative abnormal events are successfully mined. The actual number of typhoon events that occurred is 27. The specific descriptions of the real typhoon events in the Yellow Sea and East China Sea waters from 2010 to 2018 are shown in Table 4 and Table 5. Table 4 lists the buoys involved in 27 real typhoon events, and Table 5 lists the generation, end dates, and durations of 27 real typhoon events.

[0144] It can be seen from Table 4 and Table 5 that there is a large overlap in the occurrence times of Typhoon "Tembin" (No. 07), Typhoon "Bolaven" (No. 08), Typhoon "Meranti" (No. 19) and Typhoon "Mekkhala" (No. 20), as well as Typhoon "Rumbia" (No. 25) and Typhoon "Soulik" (No. 26). Therefore, the algorithm AP-COAE of the present invention misidentifies two typhoon events in the above three situations as one typhoon event. However, except for these three situations, all other spatio-temporal collaborative anomaly events are accurately identified. The distribution of all spatio-temporal collaborative anomaly events is as Figure 7 shown.

[0145] Next, the AP-COAE algorithm clusters the set of spatio-temporal collaborative anomaly events {E 1 , E 2 ,..., E 27}. First, according to Definition 4, the distance relationship between all collaborative anomaly events is determined, and the adaptive k-value of these collaborative anomaly events is re-determined using the adaptive k-nearest neighbor search method as the density of each collaborative anomaly event; the clustering center and the number of clusters are determined according to the density and silhouette coefficient of each collaborative anomaly event. The final output clustering result is {E 1 , E 3 , E 4 , E 6 , E 10 , E 11 , E 12 , E 13}, {E 2 , E 5 , E 15 , E 16 , E 19 , E 20 , E 21 , E 22}, {E 7 , E 9 , E 14 , E 24 , E 25 , E 26 , E 27}, {E 8 , E 17 , E 18 , E 23}. The set of anomaly patterns is the set of clustering centers {E 1 , E 20 , E 7 , E 17}. Figure 8 , 9, 10, 11 visually represents the clustering results of spatio-temporal collaborative anomaly events.

[0146] Figure 8, 9, 10, and 11 respectively represent four types of spatio-temporal collaborative anomaly events, as well as the cluster centroids - anomaly patterns generated by the spatio-temporal collaborative anomaly event clustering algorithm. From 8a), 9a), 10a), and 11a), it can be seen that spatio-temporal collaborative anomaly events of the same category have similar spatial change processes. By comparing 8b), 9b), 10b), and 11b), it can be found that the attribute values, i.e., wind speeds, of spatio-temporal collaborative anomaly events of different categories vary greatly. This proves the effectiveness and significance of the algorithm of the present invention.

[0147] The reasons for the differences between the algorithm clustering results and the true results are analyzed below. The true clustering results are shown in Table 6. After comparison, it can be seen that the AP-COAE algorithm wrongly classifies the fourth category into the first category. We found that two typhoon events, Typhoon Muifa (T3) and Typhoon Haikui (T6), both occurred in 2013 and before. Combining the buoy situation of obtaining typhoon observation data at the Yellow Sea Station and the East China Sea Station in Table 2, it can be known that there were multiple buoys in the non-enabled state before 2013. Therefore, it can be concluded that the imperfection of early equipment makes the AP-COAE algorithm of the present invention unable to accurately cluster all spatio-temporal collaborative anomaly events.

[0148] Table 6 True Clustering Situation of Typhoon Events

[0149]

[0150] In the part of spatio-temporal collaborative anomaly event clustering, since the objects of other spatio-temporal clustering algorithms are spatio-temporal sequence datasets, while the object of the clustering of the present invention is the abnormal spatio-temporal change process, and the two clustering objects are fundamentally different. Therefore, we selected three time series clustering algorithms, kmlShape, DDC, and KShape, as comparison algorithms, which use the spatio-temporal collaborative anomaly event measurement method defined in Definition 4.3 of the present invention. The AP-COAE clustering algorithm does not need to set any parameters. In order to better show the superiority of our algorithm, for each of the three comparison algorithms, kmlShape, DDC, and KShape, a parameter that makes the evaluation index optimal is selected as the number of clusters. The final clustering results of the algorithm on the typhoon dataset are as Figure 12 shown in a - 12d.

[0151] The ARI and NMI indexes of AP-COAE are 0.858 and 0.891 respectively; the ARI and NMI indexes of kmlShape are 0.536 and 0.634 respectively; the ARI and NMI indexes of DDC are 0.551 and 0.656 respectively; the ARI and NMI indexes of KShape are 0.443 and 0.559 respectively. From this, it can be seen that the AP-COAE algorithm of the present invention has the best clustering performance.

[0152] In the embodiments of the present invention, the present invention addresses the problem of anomaly pattern mining for spatio-temporal sequence data, and proposes an Anomaly Pattern Recognition of SpatioTime series Based on Spatio Temporal Collaborate Anomaly Events (AP-COAE) algorithm. By using the concept of spatial direct neighbors, spatio-temporal collaborative anomaly patterns are mined. Through a spatio-temporal collaborative anomaly event metric, the density of each event is determined to achieve anomaly pattern mining for spatio-temporal sequence data. Different from previous spatio-temporal anomaly mining algorithms, the spatio-temporal change process of spatio-temporal anomaly events is discovered and mined. The present invention uses the typhoon dataset in the Yellow Sea and East China Sea from 2010 to 2018 to verify the effectiveness of the AP-COAE algorithm. AP-COAE mines spatio-temporal anomaly patterns with the characteristics of spatio-temporal anomaly change processes from a novel perspective, which is conducive to more accurately mining the typhoon movement path and improving the accuracy of typhoon early warning.

[0153] Figure 13 The block diagram of a spatio-temporal sequence anomaly pattern mining device shown according to an exemplary embodiment. Refer to Figure 13 The device 300 includes:

[0154] A set determination module 310, configured to determine a set of anomaly subsequences at all spatial positions;

[0155] A relationship determination module 320, configured to determine the spatial direct neighbor relationship and the time intersection relationship between the anomaly subsequences, and determine spatio-temporal collaborative anomaly events;

[0156] A spatio-temporal sequence anomaly pattern mining module 330, configured to determine the distances between all spatio-temporal collaborative anomaly events, obtain an adaptive neighbor value of the spatio-temporal collaborative anomaly events, cluster the spatio-temporal collaborative anomaly events through the adaptive neighbor value, determine the final spatio-temporal anomaly pattern, and complete the mining of the spatio-temporal sequence anomaly pattern.

[0157] Optionally, the set determination module 310 is configured to obtain spatio-temporal data X = {X 1 , X 2 ,..., X i ,..., X n}; where n is the number of spatial positions, and X i represents the time series at the i-th spatial position;

[0158] According to the spatio-temporal data, determine a set of anomaly subsequences at all spatial positions, denoted as

[0159] Optionally, the relationship determination module 320 is configured to define a spatial direct neighbor relationship between abnormal subsequences;

[0160] Regarding the set S of abnormal subsequences at all spatial positions - The abnormal subsequence with the earliest start time is used as the first element e of the first spatio-temporal collaborative abnormal event E 1 of 1,1 , determine the spatial position L where e is located 1,1 ; j ;

[0161] Determine the spatial direct neighbor L of L according to the spatial direct neighbor relationship j ; search for whether there is an abnormal subsequence at these spatial positions. If so, use this abnormal subsequence as e i and add it to E 1,2 ; then judge the spatial direct neighbor of e 1 ; until there is no abnormal subsequence whose time intersects with the direct neighbors of the spatial positions of all elements in E 1,2 ; 1 ;

[0162] Determine the final first spatio-temporal collaborative abnormal event

[0163] Optionally, the relationship determination module 320 is further configured to construct a rectangular coordinate system with the selected target position as the center and the straight line between the target position and its nearest position as one axis of the rectangular coordinate system;

[0164] According to the preset angle range, determine the spatial range area to which L i belongs relative to L j ;

[0165] Determine the nearest points in the spatial area respectively as the spatial direct neighbors of the target spatial position L j ;

[0166] Optionally, the spatio-temporal sequence abnormal pattern mining module 330 is configured to record the spatio-temporal collaborative abnormal event set as: STE = {E 1 , E 2 ,..., E q ,..., E w}, where the number of spatio-temporal collaborative abnormal events is w, (1 ≤ q ≤ w), b q is the number of spatial positions involved in the qth spatio-temporal collaborative abnormal event, e q,j is an abnormal subsequence in the set of abnormal subsequences at all spatial positions, where a q,j represents the subsequence e q,jThe number of data points included;

[0167] For any two collaborative anomaly events in the spatio-temporal collaborative anomaly event set STE Calculate E using the superimposed DTW metric method according to the following formula (1) q With E z The distance D between dtw (E q , E z ):

[0168]

[0169] Wherein, E z [1:b z -1]) is the set of remaining anomaly subsequences after removing the last anomaly subsequence from E, that is z E q [1:b q -1]) is the set of remaining anomaly subsequences after removing the last anomaly subsequence from E, that is q

[0170]

[0171]

[0172]

[0173] 1 , K 2 ,..., K q ,..., K w}, and use it as the density of each collaborative anomaly event;

[0171] Iteratively obtain the cluster centers according to the obtained density and the spatio-temporal collaborative anomaly event distance, and determine the number c of cluster centers when the iteration stops according to the silhouette coefficient in Definition 5;

[0172] Output the cluster center set, and determine the anomaly pattern set P = {p 1 , p 2 ,..., p j ,..., p c}, to complete the mining of spatio-temporal sequence anomaly patterns.

[0173] Optionally, the spatio-temporal sequence anomaly pattern mining module 330 is used to use the collaborative anomaly event with the largest adaptive k value as the first cluster center p 1 , and find the collaborative anomaly event with the largest density among the v collaborative anomaly events farthest from p 1 as the second cluster center p 2 ;

[0174] wherein is the value obtained by adding 1 to the integer part of the ratio of the number w of collaborative anomaly events to 10;

[0175] According to the distances between the remaining collaborative anomaly events and the two cluster centers, determine the clusters to which each collaborative anomaly event belongs when the number of clusters is 2; Calculate the current silhouette coefficient sil by using the silhouette coefficient as the clustering validity index 2 , and obtain all cluster centers.

[0176] Optionally, the spatio-temporal sequence anomaly pattern mining module 330 is used to, when the number of clusters is i, among the v collaborative anomaly events with the largest sum of distances from the existing cluster centers {p 1 , p 2 ,..., p i-1}, find the collaborative anomaly event with the highest density as the i-th cluster center p i , and assign each remaining collaborative anomaly event to the category where the nearest cluster center is located; Calculate the silhouette coefficient sil at this time i , if sil i < sil i-1 , and at this time c = i - 1, then output the cluster center set P = {p 1 , p 2 ,..., p c}, to determine the cluster centers and divide the collaborative anomaly events; Otherwise, i = i + 1, and continue to find the next cluster center p i ; Determine the spatio-temporal anomaly pattern set P = {p 1 , p 2 ,..., p i ,..., p c}

[0177] In the embodiments of the present invention, for the problem of anomaly pattern mining of spatio-temporal sequence data, an Anomaly Pattern Recognition of Spatio Timeseries Based on Spatio Temporal Collaborate Anomaly Events (AP-COAE) algorithm is proposed. The spatio-temporal collaborative anomaly pattern is mined by using the concept of spatial direct neighbors, and the density of each event is determined through a spatio-temporal collaborative anomaly event metric, so as to realize the anomaly pattern mining of spatio-temporal sequence data. Different from the previous spatio-temporal anomaly mining algorithms, the spatio-temporal change process of spatio-temporal anomaly events is discovered and mined.

[0178] Figure 14Schematic diagram of the structure of an electronic device 400 provided by an embodiment of the present invention. The electronic device 400 may vary greatly due to different configurations or performances, and may include one or more processors (central processing units, CPUs) 401 and one or more memories 402. Among them, at least one instruction is stored in the memory 402, and the at least one instruction is loaded and executed by the processor 401 to implement the steps of the following spatio-temporal sequence anomaly pattern mining method:

[0179] S1: Determine the set of abnormal subsequences at all spatial positions;

[0180] S2: Determine the spatial direct neighbor relationship and temporal intersection relationship between abnormal subsequences, and determine the spatial range and duration of spatio-temporal collaborative abnormal events;

[0181] S3: Obtain the adaptive neighbor value of spatio-temporal collaborative abnormal events according to the determined spatial range and duration, cluster the spatio-temporal collaborative abnormal events through the adaptive neighbor value, determine the final spatio-temporal abnormal pattern, and complete the mining of spatio-temporal sequence abnormal patterns.

[0182] In an exemplary embodiment, a computer-readable storage medium is also provided, such as a memory including instructions, and the above instructions can be executed by a processor in a terminal to complete the above spatio-temporal sequence anomaly pattern mining method. For example, the computer-readable storage medium may be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.

[0183] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above embodiments can be completed by hardware, or can be completed by a program instructing relevant hardware. The program can be stored in a computer-readable storage medium, and the above-mentioned storage medium can be a read-only memory, a magnetic disk, or an optical disc, etc.

[0184] The above are only the preferred embodiments of the present invention, and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for mining abnormal patterns in spatio-temporal sequences, characterized in that, it includes the following steps: S1: Determine the set of abnormal subsequences at all spatial positions; S2: Determine the spatial direct neighbor relationship and temporal intersection relationship between abnormal subsequences, and determine spatio-temporal collaborative abnormal events; S3: Determine the distances between all spatio-temporal collaborative abnormal events, obtain the adaptive neighbor value of spatio-temporal collaborative abnormal events, cluster the spatio-temporal collaborative abnormal events through the adaptive neighbor value, determine the final spatio-temporal abnormal pattern, and complete the mining of spatio-temporal sequence abnormal patterns; S31: Denote the set of spatio-temporal collaborative anomaly events as: STE = {E 1 , E 2 ,..., E q ,..., E w}, where the number of spatio-temporal collaborative anomaly events is w, b q is the number of spatial positions involved in the q-th spatio-temporal collaborative anomaly event, and e q,j is a certain anomaly subsequence in the set of all spatial position anomaly subsequences, where a q,j represents the number of data points contained in the subsequence e q,j ; S32: For any two collaborative abnormal events in the set STE of spatio-temporal collaborative abnormal events Calculate E using the superimposed DTW metric method according to the following formula (1) q The distance D between E z and E dtw (E q , E z ): Among them, E z [1:b z -1]) is the set of abnormal subsequences remaining after removing the last abnormal subsequence, that is z E E q [1:b q -1]) is the set of abnormal subsequences remaining after removing the last abnormal subsequence, that is q denotes the abnormal subsequence and the abnormal subsequence the DTW distance between them;​ S33: Determine the adaptive k-nearest neighbor values K = {K 1 , K 2 ,..., K q ,..., K w} for all collaborative anomaly events based on the adaptive k-nearest neighbor search method, and use them as the density of each collaborative anomaly event; S34: Iteratively obtain the cluster centers according to the obtained density and the distances of spatio-temporal collaborative abnormal events, and judge the number c of cluster centers when the iteration stops according to the silhouette coefficient in Definition 5; S35: Output the set of cluster centers, determine the set of abnormal patterns \(P = \{p 1 , p 2 , \ldots, p j , \ldots, p c \}, and complete the mining of spatio-temporal sequence abnormal patterns.

2. The method according to claim 1, characterized in that, the step S1 includes determining the set of abnormal subsequences at all spatial positions, including: S11: Obtain spatio-temporal data X = {X 1 , X 2 ,..., X i ,..., X n}; where n is the number of spatial positions, and X i represents the time series at the i-th spatial position; S12: Determine the set of abnormal subsequences at all spatial positions based on the spatio-temporal data, denoted as 3. The method according to claim 2, characterized in that, in the step S2, determining the spatial direct neighbor relationship and temporal intersection relationship between abnormal subsequences, and determining spatio-temporal collaborative abnormal events, includes: S21: Define the spatial direct neighbor relationship between abnormal subsequences; S22: Take the abnormal subsequence with the earliest start time in the set S of abnormal subsequences at all spatial positions - as the first spatio-temporal collaborative abnormal event E 1 and take the first element e 1,1 of E. Determine the spatial position L 1,1 where e is located j ; S23: Determine L according to the spatial direct neighborhood relationship j 's spatial direct neighbor L i , and check whether there is an abnormal subsequence at these spatial positions. If there is, use this abnormal subsequence as e 1,2 Add it to E 1 , and then judge the spatial direct neighbor of e 1,2 ; until there is no abnormal subsequence whose time intersects with it on the direct neighbors of the spatial positions of all elements in E 1 ​ S24: Determine the final first spatio-temporal collaborative anomaly event 4. The method according to claim 3, characterized in that, in the step S21, defining the spatial direct neighbor relationship between abnormal subsequences, includes: S211: Taking the selected target position as the center, and the straight line where the target position and its nearest position are located as one axis of the rectangular coordinate system, construct a rectangular coordinate system; S212: Determine L according to a preset angle range i with respect to L j of the spatial range area to which it belongs; S213: Determine the points with the shortest distances in the spatial region respectively as the target spatial position L j which are the direct spatial neighbors.

5. The method according to claim 4, characterized in that, in the step S34, iteratively obtaining the cluster centers according to the obtained density and the distances of spatio-temporal collaborative abnormal events, includes: Take the collaborative anomaly event with the largest adaptive k value as the first clustering center p 1 , among the v collaborative anomaly events with the farthest distance from p 1 , find the collaborative anomaly event with the highest density as the second clustering center p 2 ; Among them is the value obtained by adding 1 to the integer part of the ratio of the number w of collaborative exception events to 10; Determine the cluster to which each collaborative anomaly event belongs when the number of clusters is 2 based on the distance between the remaining collaborative anomaly events and the two cluster centers; calculate the current silhouette coefficient sil using the silhouette coefficient as the clustering validity index 2 to obtain all cluster centers.

6. The method according to claim 5, characterized in that, In the step S35, it is determined that the abnormal mode set P = {p 1 , p 2 ,..., p j ,…, p c}, includes: When the number of clusters is i, among the v collaborative anomaly events with the largest sum of distances from the existing cluster centers {p 1 , p 2 ,..., p i-1}, find the collaborative anomaly event with the highest density as the i-th cluster center p i . Assign each remaining collaborative anomaly event to the category of the cluster center closest to it; calculate the silhouette coefficient sil i . If sil i < sil i-1 , and at this time c = i - 1, then output the set of cluster centers P = {p 1 , p 2 ,..., p c} to determine the cluster centers and divide the collaborative anomaly events; otherwise i = i + 1 and continue to find the next cluster center p i ; determine the set of spatio-temporal anomaly patterns P = {p 1 , p 2 ,..., p i ,..., p c}.

7. A device for mining abnormal patterns in spatio-temporal sequences, characterized in that, the device is applicable to the method described in any one of claims 1-6, and the device includes: A set determination module for determining the set of abnormal subsequences at all spatial positions; A relationship determination module for determining the spatial direct neighbor relationship and temporal intersection relationship between abnormal subsequences, and determining spatio-temporal collaborative abnormal events; A spatio-temporal sequence abnormal pattern mining module for determining the distances between all spatio-temporal collaborative abnormal events, obtaining the adaptive neighbor value of spatio-temporal collaborative abnormal events, clustering the spatio-temporal collaborative abnormal events through the adaptive neighbor value, determining the final spatio-temporal abnormal pattern, and completing the mining of spatio-temporal sequence abnormal patterns.

8. The device according to claim 7, characterized in that, The set determination module is configured to obtain spatio-temporal data X = {X 1 , X 2 ,..., X i ,..., X n}; where n is the number of spatial positions, and X i represents the time series at the i-th spatial position; Determine the set of abnormal subsequences at all spatial positions based on the spatio-temporal data, denoted as 9. The device according to claim 8, characterized in that, the relationship determination module is used to define the spatial direct neighbor relationship between abnormal subsequences; The set S of abnormal subsequences at all spatial positions - The abnormal subsequence with the earliest start time in it is used as the first spatio-temporal collaborative abnormal event E 1 The first element e 1,1 , determine e 1,1 The spatial position L where it is located j ; Determine L according to the spatial direct neighbor relationship j The spatial direct neighbor L of i , search for whether there is an abnormal subsequence at these spatial positions. If there is, use this abnormal subsequence as e 1,2 Add it to E 1 , and then judge the spatial direct neighbor of e 1,2 ; until there is no abnormal subsequence intersecting with its time on the direct neighbors of the spatial positions of all elements in E 1 ; Determine the final first spatio-temporal collaborative anomaly event

Citation Information

Patent Citations

  • Abnormal analysis method and device and storage medium

    CN113971425A

  • Method and device for detecting abnormal behavior

    WO2020135392A1