Methods, devices, equipment, media, and programs for detecting periodic fluctuations in data

By acquiring the cluster-time window mapping relationship data, historical data is divided into clusters with different periodic characteristics, which solves the problem of inaccurate detection of multi-period and cross-period data fluctuations in existing technologies and achieves higher detection accuracy.

CN116737784BActive Publication Date: 2025-10-31CHINA MOBILE GRP HEILONGJIANG CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210210610.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-04
Publication Date
2025-10-31
Estimated Expiration
2042-03-04

AI Technical Summary

Technical Problem

Existing technologies can only determine data fluctuations through a single set of period determination rules, which cannot accurately detect data fluctuations across multiple periods or across periods, resulting in inaccurate data fluctuation detection for business and systems.

Method used

By acquiring cluster-time window mapping data, historical data is divided into clusters with different periodic characteristics based on the cluster-time window mapping data, the target cluster of real-time data is determined, and data fluctuation detection is performed based on the historical data of the target cluster.

Benefits of technology

It improves the accuracy of detecting fluctuations in business and system data across multiple cycles and time windows. By mapping the clusters to time windows, historical data with different cycle characteristics are divided into several clusters, and historical data of target clusters with similar cycle characteristics are used for detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116737784B_ABST
    Figure CN116737784B_ABST
Patent Text Reader

Abstract

This invention relates to the field of artificial intelligence technology, and more particularly to a method, apparatus, device, medium, and program product for detecting data periodic fluctuations. The data periodic fluctuation detection method includes: acquiring real-time data and cluster-time window mapping relationship data; wherein the cluster-time window mapping relationship data characterizes the types of clusters corresponding to historical data in different time windows; and the historical data of different clusters have different periodic characteristics; determining the target cluster corresponding to the real-time time window of the real-time data based on the cluster-time window mapping relationship data; and performing data fluctuation detection on the real-time data based on the historical data of the target cluster. This invention aims to address the shortcomings of existing solutions in terms of inaccurate data fluctuation detection for business and systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of artificial intelligence technology, and in particular to a method, apparatus, device, medium, and program product for detecting periodic fluctuations in data. Background Technology

[0002] The constantly evolving data generated in the business and technology sectors is a key metric we want to focus on. Through this dynamic data, we aim to accurately uncover hidden information about the real-time changes in a company's business development, operations, and system performance. The accuracy of this hidden information often depends on the judgment of the underlying data's change cycle.

[0003] Existing technologies can usually only determine changes in data using a single set of periodic determination rules. However, in reality, data often exhibits fluctuations across multiple periods and across different periods. Therefore, existing solutions are inaccurate in detecting data fluctuations in business and systems. Summary of the Invention

[0004] This invention provides a method for detecting data periodic fluctuations, which solves the problem that existing technologies can only determine changing data through a single set of period determination rules. However, in reality, data often exhibits multi-period and cross-period fluctuations, so existing solutions are inaccurate in detecting data fluctuations in business and systems.

[0005] In a first aspect, embodiments of this application provide a method for detecting data periodic fluctuations, including:

[0006] Acquire real-time data and cluster-time window mapping relationship data; wherein, the cluster-time window mapping relationship data represents the types of clusters corresponding to historical data in different time windows; and the historical data of different clusters have different periodic characteristics;

[0007] Based on the cluster-time window mapping data, determine the target cluster corresponding to the real-time time window of the real-time data;

[0008] Data fluctuation detection is performed on the real-time data based on the historical data of the target cluster.

[0009] In one embodiment, prior to the step of determining the real-time data and the cluster-time window mapping relationship data, the method further includes:

[0010] The historical data is clustered based on a preset time window to obtain cluster-time window mapping data.

[0011] In one embodiment, the step of clustering the historical data based on a preset time window to obtain cluster-time window mapping data includes:

[0012] The historical data is segmented based on the preset time window;

[0013] Cluster the split historical data;

[0014] The historical data with similar periodic characteristics are clustered together to form clusters. The type of cluster corresponding to the historical data of each time window is determined, and the mapping relationship data between the clusters and the time windows is obtained.

[0015] In one embodiment, the step of detecting data fluctuations in the real-time data based on historical data of the target cluster includes:

[0016] Determine the target dynamic early warning baseline based on the historical data of the target cluster;

[0017] Data fluctuation detection is performed on the real-time data based on the target dynamic early warning baseline.

[0018] In one embodiment, determining the target dynamic early warning baseline based on historical data of the target cluster includes:

[0019] The historical data of the target cluster are concatenated in chronological order to form a subsequence;

[0020] The target dynamic early warning baseline is obtained by fitting the subsequence.

[0021] In one embodiment, the step of detecting data fluctuations in the real-time data based on the target dynamic early warning baseline includes:

[0022] When the value of the real-time data exceeds the set fluctuation range of the target dynamic early warning baseline, it is determined that the real-time data is fluctuating.

[0023] Secondly, embodiments of this application also provide a data periodicity fluctuation detection device, comprising:

[0024] The data acquisition module is used to acquire real-time data and cluster-time window mapping relationship data; wherein, the cluster-time window mapping relationship data represents the types of clusters corresponding to historical data in different time windows; and the historical data of different clusters have different periodic characteristics;

[0025] The target cluster determination module is used to determine the target cluster corresponding to the real-time time window of the real-time data based on the cluster-time window mapping relationship data.

[0026] The data fluctuation detection module is used to detect data fluctuations in the real-time data based on the historical data of the target cluster.

[0027] Thirdly, embodiments of this application also provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the data periodicity fluctuation detection method as described above.

[0028] Fourthly, embodiments of this application also provide a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the data periodic fluctuation detection method as described above.

[0029] Fifthly, embodiments of this application also provide a computer program product, including a computer program that, when executed by a processor, implements the data periodicity fluctuation detection method as described above.

[0030] This invention provides a method, apparatus, device, medium, and program product for detecting periodic fluctuations in data. It acquires cluster-time window mapping data. Since this mapping data characterizes the types of clusters corresponding to historical data in different time windows, and different clusters have different periodic characteristics, the historical data across the entire time period can be converted into several clusters with different periodic characteristics. Using this mapping data, the target cluster corresponding to the real-time time window of the real-time data is determined; thus, historical data with similar periodic characteristics to the real-time time window are found, and data fluctuation detection is performed on the real-time data based on the historical data of the target cluster. Compared to existing solutions that can only determine changing data using a single set of periodicity rules, this invention divides historical data with different periodic characteristics into several clusters using the cluster-time window mapping data, and determines the target cluster in the cluster-time window mapping data to which the real-time data belongs. This allows the use of historical data from the target cluster with similar periodic characteristics to the real-time data for data fluctuation detection, thereby improving the accuracy of data fluctuation detection for multi-period and cross-period business and system data. Attached Figure Description

[0031] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0032] Figure 1 This is one of the flowcharts of the data periodicity fluctuation detection method provided by the present invention;

[0033] Figure 2This is the second flowchart of the data periodicity fluctuation detection method provided by the present invention;

[0034] Figure 3 This indicates the time-series data trend of load indicators in each instance of the present invention;

[0035] Figure 4 This represents the clustering result of the historical load index data of the load index instance 1 in this embodiment of the invention;

[0036] Figure 5 This represents the data characteristics within the cluster of historical load index data for an instance of load index 1 in this embodiment of the invention.

[0037] Figure 6 This indicates the abnormal load metric detection result for the APP application instance with load metric 1;

[0038] Figure 7 This indicates the abnormal load metric detection results for the APP application instance with load metric 2;

[0039] Figure 8 This indicates the abnormal load metric detection results for the APP application instance with load metric 3.

[0040] Figure 9 This indicates the abnormal load metric detection result for the APP application instance with load metric 4.

[0041] Figure 10 This indicates the abnormal load metric detection result for the APP application instance with load metric 5;

[0042] Figure 11 This is a schematic diagram of the data periodicity fluctuation detection device provided by the present invention;

[0043] Figure 12 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0044] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0045] Existing technologies can typically only determine dynamically changing data in business and technology fields using a single set of periodic determination rules. However, in reality, data often exhibits multi-period and cross-period fluctuations. Therefore, existing technological solutions are inaccurate in detecting data fluctuations in business and systems.

[0046] Therefore, embodiments of the present invention propose a method, apparatus, device, medium, and program product for detecting data periodic fluctuations. The main idea of ​​the data periodic fluctuation detection method of the present invention is as follows:

[0047] First, the historical data is divided into segments with a certain time window size. Then, using clustering methods, subsequences with similar periodic distributions are grouped together to form clusters, thereby physically dividing subsequences with different periodic distributions (or different periodic characteristics).

[0048] Secondly, define attributes for different clusters, such as whether it is a billing cycle, a day of the week, a day of the month, a rest day, etc. Then, connect all the data in the subsequence in chronological order into a new subsequence, which will have obvious periodicity.

[0049] Finally, for real-time data, the cluster attributes and the current date are compared to determine the appropriate cluster, and the data is then used to detect data fluctuation anomalies by utilizing the data of the subsequence corresponding to that cluster.

[0050] The following is combined Figures 1-2 The present invention describes a method for detecting periodic fluctuations in data.

[0051] Please refer to Figure 1 A method for detecting periodic fluctuations in data, comprising:

[0052] Step 200: Obtain real-time data and cluster-time window mapping relationship data; wherein, the cluster-time window mapping relationship data represents the types of clusters corresponding to historical data in different time windows; and the historical data of different clusters have different periodic characteristics.

[0053] Real-time data and cluster-to-time window mapping data are acquired through electronic devices. The real-time and historical data can be load data of various applications that change over time. For example, in one embodiment, real-time and historical data can be indicator data carried by the application, such as system access data, application framework performance data, etc. In other embodiments, real-time and historical data can also be billing cycle indicators for financial apps, specifically recording the user's daily spending and income. In still other embodiments, real-time and historical data can also be load data from telecommunications operators, specifically recording the user's daily phone bill usage or smartphone data usage.

[0054] The cluster-time window mapping data is calculated based on historical data and represents the types of clusters corresponding to historical data in different time windows. The historical data of different clusters exhibit different periodic characteristics.

[0055] Understandably, the aforementioned real-time and historical data often exhibit periodic characteristics. For example, when recording a user's daily expenses and income, income fluctuates significantly on fixed monthly payment dates (or billing cycles) compared to ordinary dates. By using clustering methods, app load data with different periodic characteristics are clustered within the historical data, resulting in multiple clusters with varying periodic distributions. Each cluster's historical data possesses distinct periodic characteristics. This divides the historical data across the entire timeframe into multiple subsequences with different periodic characteristics. Based on the time characteristics of the real-time data, historical data with corresponding periodic characteristics is selected for data fluctuation detection.

[0056] For example, in one embodiment, when historical data is the billing cycle indicator of a financial app, the cluster-time window mapping relationship data may include a first type of historical data consisting of income data for the 1st and 15th of each month, and a second type of historical data consisting of income data for other times excluding the 1st and 15th.

[0057] Step 300: Based on the cluster-time window mapping relationship data, determine the target cluster corresponding to the real-time time window of the real-time data;

[0058] The electronic device determines the target cluster corresponding to the real-time time window of the real-time data based on the cluster-time window mapping relationship data. Specifically, based on the real-time time window of the real-time data, the corresponding target time window in the cluster-time window mapping relationship data is searched, and the attributes of the cluster corresponding to the target time window are determined, thereby determining the target cluster.

[0059] For example, when historical data represents the billing cycle metrics of a financial app, the first type of historical data in the cluster-time window mapping relationship consists of the revenue data for the 1st and 15th of each month within a year; the second type of historical data consists of the revenue data for each month within a year excluding the 1st and 15th. When the time window for real-time data is the 5th, the target cluster in the corresponding cluster-time window mapping relationship is the cluster composed of the second type of historical data, i.e., the revenue data for each month within a year excluding the 1st and 15th.

[0060] Step 400: Detect data fluctuations in the real-time data based on the historical data of the target cluster.

[0061] The electronic device performs data fluctuation detection on the real-time data based on historical data of the target cluster. By acquiring the target cluster corresponding to the real-time time window of the real-time data, and considering that the historical data of the target cluster and the real-time data of the current time window have similar periodic distributions or characteristics, it is possible to predict and determine whether data fluctuations have occurred in the real-time data using the historical data of the target cluster.

[0062] Specifically, in some embodiments, step 400, the data fluctuation detection of the real-time data based on the historical data of the target cluster, includes:

[0063] Step 410: Determine the target dynamic early warning baseline based on the historical data of the target cluster;

[0064] The electronic device determines a dynamic early warning baseline for the target cluster based on historical data. By using historical data as empirical data, the dynamic early warning baseline can be determined, and based on this baseline, data fluctuations in real-time data can be detected.

[0065] Specifically, in some embodiments, step 410, determining the target dynamic early warning baseline based on the historical data of the target cluster, includes:

[0066] Step 411: Connect the historical data of the target cluster in chronological order to form a subsequence.

[0067] Step 412: Fit the subsequence to obtain the target dynamic early warning baseline.

[0068] By using electronic devices, all historical data in the cluster are connected into a subsequence in the original time order, and a dynamic early warning baseline for the target is obtained by fitting each subsequence.

[0069] Specifically, historical data in the cluster are sequentially connected according to time order to obtain the normal trend prediction of historical data. Then, by combining the fitted residual information and offsetting it by a certain amount, the target dynamic early warning baseline can be obtained.

[0070] For example, when the real-time data time window is number 5, the target cluster of the corresponding cluster-time window mapping data is a cluster composed of the second type of historical data, that is, the revenue data of each month excluding the 1st and 15th of the year. The revenue data of each month excluding the 1st and 15th of the year are concatenated in chronological order, and a target dynamic early warning baseline is obtained based on this data. Based on this target dynamic early warning baseline, it can be determined whether the real-time data at the current moment has experienced data fluctuations.

[0071] Step 420: Detect data fluctuations in the real-time data based on the target dynamic early warning baseline.

[0072] The electronic device performs data fluctuation detection on the real-time data based on the target dynamic early warning baseline. The target dynamic early warning baseline includes the early warning baseline value corresponding to each time window. For example, when the time window of the real-time data is number 5, the target cluster of the corresponding cluster and time window mapping data is a cluster composed of second-type historical data. The target dynamic early warning baseline obtained by fitting based on the cluster composed of second-type historical data includes the early warning baseline value of the monthly income data excluding the 1st and 15th of each month in a year.

[0073] Specifically, step 420, the data fluctuation detection of the real-time data based on the target dynamic early warning baseline, includes:

[0074] Step 421: When the real-time data value exceeds the set fluctuation range of the target dynamic early warning baseline, it is determined that the real-time data has fluctuated.

[0075] Specifically, when the real-time data value exceeds the set fluctuation range of the target dynamic early warning baseline, the electronic device determines that the real-time data has fluctuated. The set fluctuation range can be set according to specific circumstances; for example, it can be set to 20%. When the real-time data value exceeds 20% of the target dynamic early warning baseline value, the electronic device determines that the real-time data within that time window has fluctuated.

[0076] Steps 300 and 400 are represented by the following algorithm:

[0077] Input: Date to be detected (d);

[0078] Output: Whether there is an anomaly at a certain time on the date d to be detected;

[0079] 1. Index the cluster c corresponding to date d in the cluster-time window mapping data;

[0080] 2. Perform anomaly detection on the subsequence formed by c;

[0081] 3. Compare the current instance value with its corresponding warning baseline value for that time. If the value exceeds the set fluctuation range of the warning baseline value, a fluctuation warning will be issued; otherwise, no warning will be issued.

[0082] This invention acquires cluster-time window mapping data. Since this data represents the types of clusters corresponding to historical data in different time windows, and different clusters have different periodic characteristics, the historical data across the entire time period can be transformed into several clusters with different periodic characteristics. Using this mapping data, the target cluster corresponding to the real-time time window of the real-time data is determined; thus, historical data with similar periodic characteristics to the real-time time window are found, and data fluctuation detection is performed on the real-time data based on the historical data of the target cluster. Compared to existing solutions that can only determine changing data using a single set of periodicity rules, this invention divides historical data with different periodic characteristics into several clusters using the cluster-time window mapping data, and determines the target cluster in the cluster-time window mapping data to which the real-time data belongs. This allows the use of historical data from the target cluster with similar periodic characteristics to the real-time data for data fluctuation detection, thereby improving the accuracy of data fluctuation detection for multi-period and cross-period business and system data.

[0083] For other aspects of the invention, please refer to Figure 2 Before step 200, the step of determining the real-time data and the cluster-time window mapping relationship data, the method further includes:

[0084] Step 100: Cluster the historical data based on a preset time window to obtain cluster-time window mapping data.

[0085] The electronic device clusters the historical data based on a preset time window to obtain cluster-time window mapping data. The preset time window refers to the smallest time unit for segmenting the historical data. The preset time window can be considered as pre-set; for example, it can be daily or hourly.

[0086] Specifically, step 100, clustering the historical data based on a preset time window to obtain cluster-time window mapping data, includes:

[0087] Step 110: Segment the historical data based on the preset time window.

[0088] Step 120: Cluster the split historical data.

[0089] Step 130: Aggregate the historical data with similar periodic characteristics into clusters, determine the type of cluster corresponding to the historical data of each time window, and obtain the cluster-time window mapping relationship data.

[0090] Specifically, in some embodiments, taking historical data such as the billing cycle data of a financial app as an example, the user's monetary income data is split into segments with a preset time window of days. These user monetary income data are then clustered using DBSCAN based on density estimation. For each cluster, we can define the mapping relationship between each date and the cluster based on the date attribute, and then we concatenate all subsequences within the cluster into a single subsequence in their original chronological order.

[0091] By using the DBSCAN clustering algorithm, k (i.e., the number of clusters) can be inferred from historical data. Secondly, it can discover clusters of arbitrary shapes and handle most distance metrics, exhibiting better generalization ability.

[0092] It should be noted that before step 100, which involves clustering the historical data based on a preset time window to obtain the cluster-time window mapping relationship data, the following steps are also included:

[0093] Step 010: Smooth the historical data using the moving average method.

[0094] Specifically, before performing clustering, electronic devices first need to preprocess historical data. Historical data is typically monitored at regular time intervals (e.g., every ten minutes or half an hour). However, sometimes the monitoring system fails to receive data, resulting in missing values. Considering that noise and anomalies in historical data may affect clustering results, we use a moving average method to smooth the historical data, thereby removing noise and mitigating the negative impact of anomalies.

[0095] Furthermore, since the app generally operates smoothly, its data trends are relatively stable. Therefore, we chose Euclidean distance as the distance metric between samples.

[0096] Specifically, the process of obtaining the cluster-time window mapping data is as follows:

[0097]

[0098] By applying artificial intelligence techniques, historical data is clustered into multiple clusters, each with different periodic characteristics. This allows for the selection of corresponding historical data within the real-time time window to detect fluctuations in the real-time data, ensuring that different periodic characteristics do not interfere with each other. This approach leverages both historical and real-time data to more accurately identify anomalies. This invention has broad applicability and can be applied to business data and system operation data in enterprise operations.

[0099] The specific implementation process of the present invention will be described below through a typical embodiment:

[0100] 1) Obtain the data source

[0101] The test data for this experiment was obtained using data from five different mobile applications, as shown in Table 1. The data includes the time frame and the load metrics for the five instances [Load Metric 1, Load Metric 2, Load Metric 3, Load Metric 4, Load Metric 5]. The data spans from 00:00:00 on January 1, 2019 to 23:30:00 on December 30, 2020, with a statistical frequency of every 30 minutes. The statistical value is the average load metric for that 30-minute interval.

[0102] Visualize the test data of different APP application instances, such as Figure 3 As shown. Based on the understanding of the business, load metric 1, load metric 3, and load metric 4 are application instances related to accounting, while load metric 2 and load metric 5 are application instances related to non-accounting. DB1-DB5 represent the application instances of load metric 1, load metric 3, load metric 4, load metric 2, and load metric 5, respectively.

[0103] Table 1: Overview of data formats for 5 different APP applications used in the test subjects

[0104]

[0105] 2) Cluster historical data and define the mapping between clusters and dates.

[0106] Here, we divide the data in chronological order, using September 30, 2020 as the dividing line. Data before this date is used as historical data for clustering training, while data after this date is used as online test data.

[0107] First, the historical data of a single load indicator in the original data is divided according to the time sequence of each day, that is, the data is divided into the following: Figure 4 The given 24-hour trend subsequences show a total of 638 days, with 48 time points per day. We can construct a training set of 638 samples with 48 features.

[0108] Then, the obtained training dataset is clustered, and the clustering results are as follows:

[0109] Load index 1

[0110] Table 2 shows the clustering results and date mapping relationship of historical load index data for Example 1. The table shows that the clustering model groups the data into two clusters [-1 and 0]. The 1st and 2nd of each month are clustered in the -1 cluster, while most data for other dates (only three dates are listed here) are concentrated in the 0 cluster. Based on this data partitioning, future fitting and prediction will use the time series data from the -1 cluster (concatenated chronologically) for the 1st and 2nd of each month; fitting and prediction for other dates will use the time series data from the 0 cluster (concatenated chronologically).

[0111] Table 2: Clustering results of historical load metric data for Load Metric 1 instance and mapping to date

[0112]

[0113] from Figure 5 As can be seen, the data trends within the two clusters are quite similar, indicating that the dataset has been well partitioned. Here, "payment period" refers to the date of receipt of payment.

[0114] Load index 2

[0115] Table 3 shows the clustering results and date mapping relationship of historical load index data for instance 2. Table 3 shows that the clustering model groups the data into two clusters [-1, 0, and 1]; most of the data for all dates in each month (we only list 3 dates here) is concentrated in the cluster with category 0. Therefore, it can be determined that this database is not an accounting database, and the trends of the data for all dates are relatively similar. For such data, no further partitioning is needed; anomaly detection will be performed on the future based on the original time series.

[0116] Table 3: Clustering results of historical load metric data for Load Metric 2 instance and mapping to date

[0117]

[0118] Load index 3, load index 4, load index 5

[0119] Table 4 shows that there is a less obvious payment period with the date 1, and the other dates are non-payment periods; Table 5 shows that the date 1 is an obvious payment period, and the other dates are non-payment periods; Table 6 shows that there are no payment periods in the time series data.

[0120] Table 4: Clustering results of historical load metric data for instance 3 and mapping to date

[0121]

[0122] Table 5: Clustering results of historical load metric data for instance 4 and mapping to date.

[0123]

[0124]

[0125] Table 6: Clustering results of historical load metric data for instance 5 and mapping to date

[0126]

[0127] 3) Online anomaly detection (data fluctuation detection)

[0128] Based on the historical data of each of the above app application examples, online anomaly detection is performed. First, based on the date corresponding to the time to be detected, it is determined which historical data to use for fitting and predicting the current time, thus obtaining a normal trend prediction for the time series. Then, combined with the residual information from the fitting, a certain offset is applied to obtain the early warning baseline for the load index. Based on this dynamic early warning baseline, it is possible to determine whether the actual load index at the current moment is abnormal.

[0129] The test results for the 5 APP application instances in the test data are as follows: Figures 6-10 .

[0130] pass Figures 6-10 The detection results show that, compared to existing solutions that use a set of periodic determination rules to judge changing data, the changing trend of the target dynamic early warning baseline obtained by this invention has a high degree of similarity to the changing trend of the real-time data's true value. The embodiments of this application can improve the accuracy of data fluctuation detection for multi-period and cross-period business and system data.

[0131] The data periodicity fluctuation detection device provided by the present invention will be described below. The data periodicity fluctuation detection device described below can be referred to in correspondence with the data periodicity fluctuation detection method described above.

[0132] Please refer to Figure 11 This application also provides a data periodicity fluctuation detection device, including:

[0133] The data acquisition module 201 is used to acquire real-time data and cluster-time window mapping relationship data; wherein, the cluster-time window mapping relationship data represents the types of clusters corresponding to historical data in different time windows; and the historical data of different clusters have different periodic characteristics.

[0134] The target cluster determination module 202 is used to determine the target cluster corresponding to the real-time time window of the real-time data based on the cluster-time window mapping relationship data;

[0135] The data fluctuation detection module 203 is used to detect data fluctuations in the real-time data based on the historical data of the target cluster.

[0136] Based on the above embodiments, as an optional embodiment, the data periodic fluctuation detection device further includes:

[0137] The mapping relationship data acquisition module is used to cluster the historical data based on a preset time window to obtain the cluster-time window mapping relationship data.

[0138] Based on the above embodiments, as an optional embodiment, the mapping relationship data acquisition module specifically includes:

[0139] The splitting module is used to split the historical data based on the preset time window;

[0140] The clustering module is used to cluster the split historical data;

[0141] The final data acquisition module is used to aggregate the historical data with similar periodic characteristics into clusters, determine the type of the cluster corresponding to the historical data of each time window, and obtain the cluster-time window mapping relationship data.

[0142] Based on the above embodiments, as an optional embodiment, the data fluctuation detection module includes:

[0143] The dynamic early warning baseline determination module is used to determine the target dynamic early warning baseline based on the historical data of the target cluster;

[0144] The final detection module is used to detect data fluctuations in the real-time data based on the target dynamic early warning baseline.

[0145] Based on the above embodiments, as an optional embodiment, the dynamic early warning baseline determination module includes:

[0146] The subsequence acquisition module is used to connect the historical data of the target cluster in chronological order to form a subsequence.

[0147] The fitting module is used to fit the subsequence to obtain the target dynamic early warning baseline.

[0148] Based on the above embodiments, as an optional embodiment, the final detection module is specifically used for:

[0149] When the value of the real-time data exceeds the set fluctuation range of the target dynamic early warning baseline, it is determined that the real-time data is fluctuating.

[0150] By acquiring cluster-time window mapping data, which characterizes the types of clusters corresponding to historical data in different time windows and shows that different clusters have different periodic characteristics, the historical data across the entire time period can be transformed into several clusters with different periodic characteristics. Using this mapping data, the target cluster corresponding to the real-time time window of the real-time data is determined; thus, historical data with similar periodic characteristics to the real-time time window are found, and data fluctuation detection is performed on the real-time data based on the historical data of the target cluster. Compared to existing solutions that can only determine changing data using a single set of periodicity rules, this invention divides historical data with different periodic characteristics into several clusters using the cluster-time window mapping data, determines the target cluster in the cluster-time window mapping data to which the real-time data belongs, and uses the historical data of the target cluster with similar periodic characteristics to the real-time data for data fluctuation detection, thereby improving the accuracy of data fluctuation detection for multi-period and cross-period business and system data.

[0151] Figure 12 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 12 As shown, the electronic device may include a processor 1210, a communications interface 1220, a memory 1230, and a communication bus 1240. The processor 1210, communications interface 1220, and memory 1230 communicate with each other via the communication bus 1240. The processor 1210 can call logical instructions in the memory 1230 to execute a data periodic fluctuation detection method. This method includes: acquiring real-time data and cluster-time window mapping relationship data; wherein the cluster-time window mapping relationship data characterizes the types of clusters corresponding to historical data in different time windows; and the historical data of different clusters have different periodic characteristics.

[0152] Based on the cluster-time window mapping data, the target cluster corresponding to the real-time time window of the real-time data is determined; and data fluctuation detection is performed on the real-time data based on the historical data of the target cluster.

[0153] Furthermore, the logical instructions in the aforementioned memory 1230 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0154] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the data periodic fluctuation detection method provided by the above methods. The method includes: acquiring real-time data and cluster-time window mapping relationship data; wherein the cluster-time window mapping relationship data characterizes the types of clusters corresponding to historical data of different time windows; and the historical data of different clusters have different periodic characteristics; determining the target cluster corresponding to the real-time time window of the real-time data based on the cluster-time window mapping relationship data; and performing data fluctuation detection on the real-time data based on the historical data of the target cluster.

[0155] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements a data periodic fluctuation detection method provided by the above methods. This method includes: acquiring real-time data and cluster-time window mapping relationship data; wherein the cluster-time window mapping relationship data characterizes the types of clusters corresponding to historical data in different time windows; and the historical data of different clusters have different periodic characteristics; determining the target cluster corresponding to the real-time time window of the real-time data based on the cluster-time window mapping relationship data; and performing data fluctuation detection on the real-time data based on the historical data of the target cluster.

[0156] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0157] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0158] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for detecting periodic fluctuations in data, characterized in that, include: Acquire real-time data and cluster-time window mapping relationship data; wherein, the cluster-time window mapping relationship data represents the types of clusters corresponding to historical data in different time windows; and the historical data of different clusters have different periodic characteristics; Based on the cluster-time window mapping data, determine the target cluster corresponding to the real-time time window of the real-time data; Data fluctuation detection is performed on the real-time data based on the historical data of the target cluster; Before the step of determining the real-time data and the cluster-time window mapping relationship data, the method further includes: The historical data is clustered based on a preset time window to obtain cluster-time window mapping data. The step of clustering the historical data based on a preset time window to obtain cluster-time window mapping data includes: The historical data is segmented based on the preset time window; Cluster the split historical data; The historical data with similar periodic characteristics are clustered together to form clusters. The type of cluster corresponding to the historical data of each time window is determined, and the mapping relationship data between the clusters and the time windows is obtained.

2. The data periodicity fluctuation detection method according to claim 1, characterized in that, The step of detecting data fluctuations in the real-time data based on historical data of the target cluster includes: Determine the target dynamic early warning baseline based on the historical data of the target cluster; Data fluctuation detection is performed on the real-time data based on the target dynamic early warning baseline.

3. The data periodicity fluctuation detection method according to claim 2, characterized in that, The determination of the target dynamic early warning baseline based on the historical data of the target cluster includes: The historical data of the target cluster are concatenated in chronological order to form a subsequence; The target dynamic early warning baseline is obtained by fitting the subsequence.

4. The data periodicity fluctuation detection method according to claim 2, characterized in that, The step of detecting data fluctuations in the real-time data based on the target dynamic early warning baseline includes: When the value of the real-time data exceeds the set fluctuation range of the target dynamic early warning baseline, it is determined that the real-time data is fluctuating.

5. A data periodicity fluctuation detection device, characterized in that, include: The data acquisition module is used to acquire real-time data and cluster-time window mapping relationship data; wherein, the cluster-time window mapping relationship data represents the types of clusters corresponding to historical data in different time windows; and the historical data of different clusters have different periodic characteristics; The target cluster determination module is used to determine the target cluster corresponding to the real-time time window of the real-time data based on the cluster-time window mapping relationship data. The data fluctuation detection module is used to detect data fluctuations in the real-time data based on the historical data of the target cluster. The mapping relationship data acquisition module is used to cluster the historical data based on a preset time window to obtain cluster-time window mapping relationship data. The mapping relationship data acquisition module specifically includes: a splitting module, used to split the historical data based on the preset time window; a clustering module, used to cluster the split historical data; and a final data acquisition module, used to gather the historical data with similar periodic characteristics into clusters, determine the type of the cluster corresponding to the historical data of each time window, and obtain the cluster-time window mapping relationship data.

6. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the data periodic fluctuation detection method as described in any one of claims 1 to 4.

7. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the data periodic fluctuation detection method as described in any one of claims 1 to 4.

8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the data periodic fluctuation detection method as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Time series data anomaly detection method and device, electronic equipment and storage medium

    CN112818066A

  • Electronic file management

    US10762060B1