Network detection method and device, electronic equipment and storage medium

By acquiring real-time time-series data and inputting it into a user number prediction model, the predicted number of online users and confidence intervals are generated. This solves the problems of inaccurate alarm judgment and difficulty in fault location in traditional network management systems, realizes multi-dimensional network detection and rapid fault location, and ensures network stability.

CN116805927BActive Publication Date: 2026-05-19CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM CORP LTD
Filing Date
2023-07-04
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Traditional network management systems suffer from inaccurate alarm judgment, poor timeliness, and difficulty in locating non-disruptive faults. In particular, the differences in indicators between holidays and weekends and weekdays, as well as rest and non-rest times, lead to inaccurate judgments and make it impossible to detect non-disruptive faults in the large network in a timely manner.

Method used

By acquiring real-time time-series data of each detection zone level in the target area, inputting it into the user number prediction model, obtaining the predicted number of online users and confidence intervals, generating network detection results based on this data, including whether the network is normal or abnormal, and using the user number prediction model for multi-dimensional detection to quickly locate the affected area.

Benefits of technology

It enables multi-dimensional network detection, increases the detection area, quickly locates abnormal network areas, handles them in a timely manner, ensures network stability, and detects potential risks in advance, discovering faults and locating the affected area 15-30 minutes earlier than professional network administrators and business departments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116805927B_ABST
    Figure CN116805927B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a network detection method and device, electronic equipment and storage medium, applied to the technical field of network communication, the method comprises: obtaining real-time time series data corresponding to each detection area level in a target area; inputting the real-time time series data into a user number prediction model to obtain online user prediction numbers corresponding to each detection area level and a confidence interval; performing network fault processing according to the online user prediction numbers corresponding to each detection area level and the confidence interval to generate a network detection result for the target area, wherein the network detection result comprises that the network of the target area is normal, or at least one detection area level in the target area has network anomaly.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network communication technology, and in particular to a network detection method, a network detection device, an electronic device, and a computer-readable storage medium. Background Technology

[0002] Traditional network management systems for alarm monitoring currently have the following drawbacks: 1) Fixed alarm judgment thresholds: There are significant differences in indicators between weekends and weekdays, and between holidays and rest periods within a day. Fixed thresholds cannot be used to make accurate judgments, leading to inaccurate alarm judgments; 2) Poor timeliness: It is impossible to detect non-interruption faults in the large network in a timely manner. The network management system does not generate alarms, but users' services have already been affected; 3) Difficulty for professional network management personnel to locate non-interruption faults: For non-interruption faults, professional network management personnel generally do not generate alarms, making it impossible to quickly locate the fault and determine the scope of impact. Summary of the Invention

[0003] The present invention provides a network detection method, apparatus, electronic device, and computer-readable storage medium to solve or partially solve the problems of inaccurate alarm judgment, poor timeliness, and difficulty in fault location during network management.

[0004] This invention discloses a network detection method, comprising:

[0005] Acquire real-time time-series data corresponding to each detection zone level in the target area;

[0006] The real-time time series data is input into the user number prediction model to obtain the online user prediction number and confidence interval corresponding to each detection area level;

[0007] Network fault handling is performed based on the predicted number of online users and the confidence interval corresponding to each of the detection area levels, and network detection results for the target area are generated. The network detection results include whether the network in the target area is normal or whether there is a network anomaly at least one of the detection area levels in the target area.

[0008] Optionally, the predicted number of online users includes provincial-level predicted number of online users and city-level predicted number of online users, and the confidence interval includes a first confidence interval corresponding to the provincial-level predicted number of online users and a second confidence interval corresponding to the city-level predicted number of online users. The step of performing network fault processing based on the predicted number of online users corresponding to each detection area level and the confidence interval to generate network detection results for the target area includes:

[0009] If the predicted number of online users in the provincial region falls within the first confidence interval, then a normal network result for the target region is generated.

[0010] If the predicted number of online users at the provincial level is less than the upper limit of the first confidence interval, a provincial-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users at the municipal level and the second confidence interval, municipal-level network fault handling is performed to generate a network detection result for the target area. The provincial-level sudden drop alarm result is the result of a sudden drop in the number of online users at the provincial level in the target area, which leads to network anomalies.

[0011] Optionally, the predicted number of online users further includes the predicted number of online users at the county level, and the confidence interval further includes a third confidence interval corresponding to the predicted number of online users at the county level. The step of performing city-level network fault handling based on the predicted number of online users at the city level and the second confidence interval to generate network detection results for the target area includes:

[0012] If the predicted number of online users at the city level falls within the second confidence interval, a network normal result for the target area is generated, and the provincial-level sudden drop alarm result is canceled.

[0013] If the predicted number of online users at the city level is less than the lower limit of the second confidence interval, a city-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users at the county level and the third confidence interval, county-level network fault handling is performed, and a network detection result for the target area is generated. The city-level sudden drop alarm result is the result of a sudden drop in the number of online users at the city level in the target area, which leads to network anomalies.

[0014] Optionally, the predicted number of online users further includes the predicted number of operational online users, and the confidence interval further includes a fourth confidence interval corresponding to the predicted number of operational online users. The step of performing county-level network fault handling based on the predicted number of county-level online users and the third confidence interval to generate network detection results for the target area includes:

[0015] If the predicted number of online users at the county level falls within the third confidence interval, a network normal result for the target area is generated, and the city-level sudden drop alarm result is canceled.

[0016] If the predicted number of online users at the county level is less than the lower limit of the third confidence interval, a county-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users and the fourth confidence interval, network fault handling for the service is performed, and a network detection result for the target area is generated. The county-level sudden drop alarm result is the result of a sudden drop in the number of online users at the county level in the target area, which leads to network anomalies.

[0017] Optionally, the predicted number of online users further includes the predicted number of online users for devices, and the confidence interval further includes a fifth confidence interval corresponding to the predicted number of online users for devices. The step of performing network fault handling for the service based on the predicted number of online users and the fourth confidence interval, and generating network detection results for the target area, includes:

[0018] If the predicted number of online users falls within the fourth confidence interval, a network normal result for the target area is generated, and the county-level sudden drop alarm result is canceled.

[0019] If the predicted number of online users in the business service sector is less than the lower limit of the fourth confidence interval, a business service-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users and the fifth confidence interval, network fault handling for the business service sector is performed, and a network detection result for the target area is generated. The business service sudden drop alarm result is the result of a sudden drop in the number of online users in the target area at the business service hall level, which leads to network anomalies.

[0020] Optionally, the step of performing network fault handling for the target area based on the predicted number of online users of the device and the fifth confidence interval, and generating network detection results for the target area, includes:

[0021] If the predicted number of online users of the device falls within the fifth confidence interval, a network normal result for the target area is generated, and the service drop alarm result is cancelled.

[0022] Network devices located in the target area whose predicted number of online users is less than the lower limit of the fifth confidence interval are identified as abnormal devices. A device drop alarm result is generated for the abnormal devices. The device drop alarm result is the result of a sudden drop in the number of online users in the target area at the device level, which leads to network abnormality.

[0023] Optionally, the step of performing network fault processing based on the predicted number of online users and confidence intervals corresponding to each detection area level to generate network detection results for the target area further includes:

[0024] If the predicted number of online users in the province is greater than the upper limit of the first confidence interval, a provincial surge alarm result is generated for the target area. The provincial surge alarm result is the result of a sudden increase in the number of online users in the target area at the provincial level, which leads to network anomalies.

[0025] If the predicted number of online users at the city level is greater than the upper limit of the second confidence interval, a city-level surge alarm result is generated for the target area. The city-level surge alarm result is the result of a sudden increase in the number of online users at the city level in the target area, which leads to network anomalies.

[0026] If the predicted number of online users at the county level is greater than the upper limit of the third confidence interval, a county-level surge alarm result is generated for the target area. The county-level surge alarm result is the result of a sudden increase in the number of online users at the county level in the target area, which leads to network anomalies.

[0027] If the predicted number of online users in the business service sector is greater than the upper limit of the fourth confidence interval, a sudden increase alarm result for the business service sector in the target area is generated. The sudden increase alarm result is the result of a sudden increase in the number of online users in the target area at the business service hall level, which leads to network anomalies.

[0028] If the predicted number of online users of the device is greater than the upper limit of the fifth confidence interval, a device surge alarm result is generated for the target area. The device surge alarm result is the result of a sudden increase in the number of online users at the device level in the target area, which leads to network anomalies.

[0029] Optionally, the user number prediction model is generated in the following manner:

[0030] Acquire training sample data, which includes first historical time series data within a first time period and at least one second historical time series data within a second time period;

[0031] The first historical time series data is input into the user number prediction model for model training to obtain prediction data corresponding to the first historical time series data. The prediction data includes the first online user number corresponding to the first time period.

[0032] Obtain the second number of online users corresponding to the second historical time series data;

[0033] The variance of the first number of online users and the second number of online users is calculated to obtain the corresponding variance. The parameters of the user number prediction model are adjusted based on the variance until the variance is less than or equal to a preset threshold. The training of the user number prediction model is then completed, and the trained user number prediction model is obtained.

[0034] Optionally, the user count prediction model includes a time-series encoder, a time-series decoder, and an autocorrelation function. The step of inputting the first historical time-series data into the user count prediction model for model training to obtain predicted data corresponding to the first historical time-series data includes:

[0035] The first historical time series data is input into the user number prediction model, and the first historical time series data is encoded by the time series encoder to output the past period item information corresponding to the first historical time series data.

[0036] The past periodic term information is processed according to the autocorrelation function to obtain global periodic term information;

[0037] The global periodicity information is input into the time-series decoder for decoding to obtain the prediction data corresponding to the first historical time-series data.

[0038] Optionally, the time encoder includes several time coding layers, and the user number prediction model further includes a decomposition function and a feedforward network. The step of processing the past periodic term information based on the autocorrelation function to obtain global periodic term information includes:

[0039] For the Lth temporal coding layer, the past periodic term information is processed by the autocorrelation function to obtain the weighted sum of similar periodic subsequences;

[0040] The sum between the weighted sum of the past periodic term information and the similar periodic subsequence is processed by the decomposition function to obtain the encoded one-stage periodic term information;

[0041] The feedforward network is used to process the sum between the past periodic item information and the encoded first-stage periodic item information to obtain the encoded second-stage periodic item information.

[0042] The encoded two-stage periodic term information is passed as global periodic term information to the timing decoder or the (L+1)th timing coding layer.

[0043] Optionally, the time-series decoder includes several time-series decoding layers, the global periodicity information includes seasonality information and trend information, and the step of inputting the global periodicity information into the time-series decoder for decoding to obtain the predicted data corresponding to the first historical time-series data includes:

[0044] For the Nth time-series decoding layer, the seasonal information is added by the autocorrelation function, and the sum is decomposed by the decomposition function to obtain the decoding stage periodic term information corresponding to the seasonal information;

[0045] The autocorrelation function is used to process the decoded one-stage periodic term information and the past periodic term information to obtain a weighted sum of global historical information;

[0046] The sum between the global historical weighted sum and the seasonal information is decomposed using the decomposition function to obtain the decoded two-stage periodic term information;

[0047] The sum of the seasonal information and the decoded second-stage periodic term information is processed by the feedforward network to obtain the decoded third-stage periodic term information;

[0048] The trend information is decomposed three times using the decomposition function, and the results of the three decompositions are weighted and aggregated to obtain trend-weighted information.

[0049] The three-stage periodic item information and the trend weighting information are passed to the N+1th time series decoding layer, and the predicted data corresponding to the first historical time series data is output through the last time series decoding layer.

[0050] This invention also discloses a network detection device, comprising:

[0051] The time-series data acquisition module is used to acquire real-time time-series data corresponding to each detection area level in the target area;

[0052] The prediction module is used to input the real-time time series data into the user number prediction model to obtain the predicted number of online users and the confidence interval corresponding to each detection area level.

[0053] The detection module is used to perform network fault handling based on the predicted number of online users and the confidence interval corresponding to each detection area level, and generate network detection results for the target area. The network detection results include whether the network in the target area is normal, or whether there is at least one network anomaly at the detection area level in the target area.

[0054] Optionally, the predicted number of online users includes the predicted number of provincial-level online users and the predicted number of municipal-level online users, and the confidence interval includes a first confidence interval corresponding to the predicted number of provincial-level online users and a second confidence interval corresponding to the predicted number of municipal-level online users. The detection module is specifically used for:

[0055] If the predicted number of online users in the provincial region falls within the first confidence interval, then a normal network result for the target region is generated.

[0056] If the predicted number of online users at the provincial level is less than the upper limit of the first confidence interval, a provincial-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users at the municipal level and the second confidence interval, municipal-level network fault handling is performed to generate a network detection result for the target area. The provincial-level sudden drop alarm result is the result of a sudden drop in the number of online users at the provincial level in the target area, which leads to network anomalies.

[0057] Optionally, the predicted number of online users further includes the predicted number of county-level online users, and the confidence interval further includes a third confidence interval corresponding to the predicted number of county-level online users. The detection module is specifically used for:

[0058] If the predicted number of online users at the city level falls within the second confidence interval, a network normal result for the target area is generated, and the provincial-level sudden drop alarm result is canceled.

[0059] If the predicted number of online users at the city level is less than the lower limit of the second confidence interval, a city-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users at the county level and the third confidence interval, county-level network fault handling is performed, and a network detection result for the target area is generated. The city-level sudden drop alarm result is the result of a sudden drop in the number of online users at the city level in the target area, which leads to network anomalies.

[0060] Optionally, the predicted number of online users further includes the predicted number of online service users, and the confidence interval further includes a fourth confidence interval corresponding to the predicted number of online service users. The detection module is specifically used for:

[0061] If the predicted number of online users at the county level falls within the third confidence interval, a network normal result for the target area is generated, and the city-level sudden drop alarm result is canceled.

[0062] If the predicted number of online users at the county level is less than the lower limit of the third confidence interval, a county-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users and the fourth confidence interval, network fault handling for the service is performed, and a network detection result for the target area is generated. The county-level sudden drop alarm result is the result of a sudden drop in the number of online users at the county level in the target area, which leads to network anomalies.

[0063] Optionally, the predicted number of online users further includes the predicted number of online users for devices, and the confidence interval further includes a fifth confidence interval corresponding to the predicted number of online users for devices. The detection module is specifically used for:

[0064] If the predicted number of online users falls within the fourth confidence interval, a network normal result for the target area is generated, and the county-level sudden drop alarm result is canceled.

[0065] If the predicted number of online users in the business service sector is less than the lower limit of the fourth confidence interval, a business service-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users and the fifth confidence interval, network fault handling for the business service sector is performed, and a network detection result for the target area is generated. The business service sudden drop alarm result is the result of a sudden drop in the number of online users in the target area at the business service hall level, which leads to network anomalies.

[0066] Optionally, the detection module is specifically used for:

[0067] If the predicted number of online users of the device falls within the fifth confidence interval, a network normal result for the target area is generated, and the service drop alarm result is cancelled.

[0068] Network devices located in the target area whose predicted number of online users is less than the lower limit of the fifth confidence interval are identified as abnormal devices. A device drop alarm result is generated for the abnormal devices. The device drop alarm result is the result of a sudden drop in the number of online users in the target area at the device level, which leads to network abnormality.

[0069] Optionally, the detection module is further configured to:

[0070] If the predicted number of online users in the province is greater than the upper limit of the first confidence interval, a provincial surge alarm result is generated for the target area. The provincial surge alarm result is the result of a sudden increase in the number of online users in the target area at the provincial level, which leads to network anomalies.

[0071] If the predicted number of online users at the city level is greater than the upper limit of the second confidence interval, a city-level surge alarm result is generated for the target area. The city-level surge alarm result is the result of a sudden increase in the number of online users at the city level in the target area, which leads to network anomalies.

[0072] If the predicted number of online users at the county level is greater than the upper limit of the third confidence interval, a county-level surge alarm result is generated for the target area. The county-level surge alarm result is the result of a sudden increase in the number of online users at the county level in the target area, which leads to network anomalies.

[0073] If the predicted number of online users in the business service sector is greater than the upper limit of the fourth confidence interval, a sudden increase alarm result for the business service sector in the target area is generated. The sudden increase alarm result is the result of a sudden increase in the number of online users in the target area at the business service hall level, which leads to network anomalies.

[0074] If the predicted number of online users of the device is greater than the upper limit of the fifth confidence interval, a device surge alarm result is generated for the target area. The device surge alarm result is the result of a sudden increase in the number of online users at the device level in the target area, which leads to network anomalies.

[0075] Optionally, the user number prediction model is generated through the following modules:

[0076] The sample data acquisition module is used to acquire training sample data, which includes first historical time series data within a first time period and at least one second historical time series data within a second time period.

[0077] The model prediction module is used to input the first historical time series data into the user number prediction model for model training, and obtain prediction data corresponding to the first historical time series data. The prediction data includes the first number of online users corresponding to the first time period.

[0078] The information acquisition module is used to acquire the number of online users corresponding to the second historical time series data;

[0079] The model adjustment module is used to perform variance calculation on the first number of online users and the second number of online users to obtain the corresponding variance, and adjust the parameters of the user number prediction model based on the variance until the variance is less than or equal to a preset threshold, thereby ending the training of the user number prediction model and obtaining a trained user number prediction model.

[0080] Optionally, the user number prediction model includes a time-series encoder, a time-series decoder, and an autocorrelation function, and the model prediction module is specifically used for:

[0081] The first historical time series data is input into the user number prediction model, and the first historical time series data is encoded by the time series encoder to output the past period item information corresponding to the first historical time series data.

[0082] The past periodic term information is processed according to the autocorrelation function to obtain global periodic term information;

[0083] The global periodicity information is input into the time-series decoder for decoding to obtain the prediction data corresponding to the first historical time-series data.

[0084] Optionally, the time encoder includes several time coding layers, the user number prediction model further includes a decomposition function and a feedforward network, and the model prediction module is specifically used for:

[0085] For the Lth temporal coding layer, the past periodic term information is processed by the autocorrelation function to obtain the weighted sum of similar periodic subsequences;

[0086] The sum between the weighted sum of the past periodic term information and the similar periodic subsequence is processed by the decomposition function to obtain the encoded one-stage periodic term information;

[0087] The feedforward network is used to process the sum between the past periodic item information and the encoded first-stage periodic item information to obtain the encoded second-stage periodic item information.

[0088] The encoded two-stage periodic term information is passed as global periodic term information to the timing decoder or the (L+1)th timing coding layer.

[0089] Optionally, the time-series decoder includes several time-series decoding layers, the global periodic term information includes seasonality information and trend information, and the model prediction module is specifically used for:

[0090] For the Nth time-series decoding layer, the seasonal information is added by the autocorrelation function, and the sum is decomposed by the decomposition function to obtain the decoding stage periodic term information corresponding to the seasonal information;

[0091] The autocorrelation function is used to process the decoded one-stage periodic term information and the past periodic term information to obtain a weighted sum of global historical information;

[0092] The sum between the global historical weighted sum and the seasonal information is decomposed using the decomposition function to obtain the decoded two-stage periodic term information;

[0093] The sum of the seasonal information and the decoded second-stage periodic term information is processed by the feedforward network to obtain the decoded third-stage periodic term information;

[0094] The trend information is decomposed three times using the decomposition function, and the results of the three decompositions are weighted and aggregated to obtain trend-weighted information.

[0095] The three-stage periodic item information and the trend weighting information are passed to the N+1th time series decoding layer, and the predicted data corresponding to the first historical time series data is output through the last time series decoding layer.

[0096] This invention also discloses an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;

[0097] The memory is used to store computer programs;

[0098] When the processor executes a program stored in the memory, it implements the method described in the embodiments of the present invention.

[0099] This invention also discloses a computer-readable storage medium storing instructions that, when executed by one or more processors, cause the processors to perform the methods described in this invention.

[0100] The embodiments of the present invention have the following advantages:

[0101] In this embodiment of the invention, real-time time-series data corresponding to each detection area level in the target area is acquired. This real-time time-series data is then input into a user number prediction model to obtain the predicted number of online users corresponding to each detection area level, as well as the confidence interval corresponding to each detection area level. Network fault handling is then performed based on the predicted number of online users and the confidence interval corresponding to each detection area level, generating network detection results for the target area. These results include whether the network in the target area is normal, or whether there is at least one network anomaly at a detection area level in the target area. By predicting the network in the corresponding region based on the real-time time-series data of each detection area level, multi-dimensional network detection is achieved, increasing the detection area. Furthermore, based on the detection results, affected areas can be quickly located so that areas with network anomalies can be handled promptly, ensuring network stability. Attached Figure Description

[0102] Figure 1 This is a flowchart of the steps of a network detection method provided in an embodiment of the present invention;

[0103] Figure 2 This is a structural block diagram of a network detection device provided in an embodiment of the present invention;

[0104] Figure 3 This is a block diagram of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0105] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0106] As an example, in large-scale network fault early warning and monitoring, 1) there is an urgent need to address the shortcomings in time-series prediction regarding the periodic and trend inconsistencies between non-weekends, weekends, and holidays, and between working and non-working hours within a day, without requiring manual intervention to set fixed alarm thresholds, thus gaining control over operations and maintenance and discovering potential risks in advance of the monitoring system; 2) there is a need to quickly locate the affected area (province / city / county branch / operation service) and promptly assess the affected area (number of services, number of devices, etc.); 3) prediction and early warning tasks should be processed in parallel to achieve real-time online early warning of large-scale network faults. For non-interruption faults, faults should be detected 15-30 minutes earlier than by professional network management and business departments, and the affected area should be located 25 minutes earlier.

[0107] In this invention, real-time time-series data corresponding to each detection area level in the target area is acquired. This data is then input into a user count prediction model to obtain the predicted number of online users corresponding to each detection area level, as well as the confidence interval for each detection area level. Network fault handling is then performed based on the predicted number of online users and the confidence interval for each detection area level, generating network detection results for the target area. These results include whether the network in the target area is normal, or whether at least one detection area level in the target area is abnormal. By predicting the network in the corresponding region using real-time time-series data for each detection area level, multi-dimensional network detection is achieved, increasing the detection area. Furthermore, based on the detection results, affected areas can be quickly located for timely handling of abnormal network areas, ensuring network stability.

[0108] Specifically, refer to Figure 1 The diagram illustrates a flowchart of a network detection method provided in an embodiment of the present invention, which may specifically include the following steps:

[0109] Step 101: Obtain real-time time series data corresponding to each detection area level in the target area;

[0110] The detection area level can include provincial, municipal, county, operational, and equipment levels. Provincial level refers to a province as the detection area level, municipal level refers to a prefecture-level city as the detection area level, county level refers to a county-level city as the detection area level, operational level refers to the area covered by the business server as the detection area level, and equipment level refers to the area covered by a single network device as the detection area level. As the detection area level decreases, the detection accuracy increases.

[0111] For real-time time-series data, it can collect online records of business operations in real time for the data center, including online users of different services in different detection areas. Specifically, the data center can obtain online records of business operations through a Kafka streaming cluster, and set a time window to perform sliding window statistics on online users of multiple service types to obtain real-time time-series data. This real-time time-series data can be used to characterize the usage of services by users in the corresponding area.

[0112] Step 102: Input the real-time time series data into the user number prediction model to obtain the predicted number of online users corresponding to each detection area level, and obtain the confidence interval corresponding to the detection area level;

[0113] The user count prediction model can be used to predict the number of online users in a corresponding detection area. Real-time time series data corresponding to each detection area level can be input into the user count prediction model to obtain the predicted number of online users corresponding to each detection area level. At the same time, the confidence interval corresponding to each detection area level can be obtained. The confidence interval can be used to determine whether the number of online users in the detection area is in an abnormal state, and the network detection result corresponding to the detection area can be generated based on the judgment result.

[0114] In practical implementation, if provincial-level real-time time-series data is input into the user number prediction model, the predicted number of online users at the provincial level can be obtained; if municipal-level real-time time-series data is input into the model, the predicted number of online users at the municipal level can be obtained; if county-level data is input, the predicted number of online users at the county level can be obtained; if operational service data is input, the predicted number of online users for operational services can be obtained; and if device-level real-time time-series data is input, the predicted number of online users for a single network device can be obtained. Correspondingly, different detection levels correspond to different confidence intervals, which this invention does not limit.

[0115] In this embodiment of the invention, the user number prediction model can be generated in the following manner:

[0116] Acquire training sample data, which includes first historical time-series data within a first time period and at least one second historical time-series data within a second time period. Then, input the first historical time-series data into the user count prediction model for model training to obtain prediction data corresponding to the first historical time-series data. The prediction data includes the first number of online users corresponding to the first time period. Next, obtain the second number of online users corresponding to the second historical time-series data. Then, perform variance calculation on the first number of online users and the second number of online users to obtain the corresponding variance. Adjust the parameters of the user count prediction model based on the variance until the variance is less than or equal to a preset threshold, and end the training of the user count prediction model to obtain the trained user count prediction model.

[0117] The first and second time periods can be consecutive. For example, the historical time series data corresponding to the first and second time periods can be three weeks of historical time series data. In this case, the first time period can be the historical time series data of the first week, and the second time period can be the time series data of the following two weeks. It is understood that other methods can also be used for division. By dividing the data into two different time periods, the first historical time series data of the first time period can be used as the model input for prediction, and the second historical time series data of the second time period can be used as the validation data to test the prediction results. Based on the test results, the model can be back-optimized to achieve model training.

[0118] Optionally, historical time-series data can be divided according to different business types, and then statistically analyzed in multiple dimensions according to the detection area level to obtain historical time-series data corresponding to each business under different detection area levels. For example, businesses may include broadband, IPTV (Internet Protocol Television), and mobile Internet, so historical time-series data of broadband in the corresponding province, city, county, operator, and equipment can be obtained. The same applies to IPTV and mobile Internet, which will not be elaborated here.

[0119] In one example, after acquiring three weeks of historical data (historical time-series data of broadband, IPTV, mobile services, etc., statistically analyzed across multiple levels such as province / city / county / operation / equipment), the first week's time-series data can be input into a user count prediction model to infer the predicted online user count y′ for the second and third weeks. This predicted time-series online user count y′ for the second and third weeks is then compared with the actual online user count y′ for the second and third weeks to calculate the MSE (Mean Squared Error) Loss. MSE =(yy′) 2 The iterative model minimizes this loss, that is, it makes the predicted value close to the true value. At this time, the autograd function of the PyTorch framework realizes the automatic differentiation of MSE Loss (backpropagation process). Adjust the values ​​of each parameter in the model and iterate continuously until the model converges. In the most ideal case... That is, the predicted value is equal to the actual value y′=y.

[0120] In some optional embodiments, the user count prediction model includes a time encoder, a time decoder, and an autocorrelation function. During model training, first historical time series data can be input into the user count prediction model. The time encoder encodes the first historical time series data and outputs past periodic information corresponding to the first historical time series data. The past periodic information is then processed according to the autocorrelation function to obtain global periodic information. Finally, the global periodic information is input into the time decoder for decoding to obtain the prediction data corresponding to the first historical time series data.

[0121] In the specific implementation, the time encoder includes several time coding layers, and the user number prediction model also includes a decomposition function and a feedforward network. In the encoding process, for the Lth time coding layer, the past periodic term information can be calculated first by using the autocorrelation function to obtain the weighted sum of similar periodic subsequences. Then, the sum between the past periodic term information and the weighted sum of similar periodic subsequences can be processed by the decomposition function to obtain the first-stage coding periodic term information. Then, the sum between the past periodic term information and the first-stage coding periodic term information can be processed by the feedforward network to obtain the second-stage coding periodic term information. Finally, the second-stage coding periodic term information is passed as the global periodic term information to the time decoder or the (L+1)th time coding layer. Furthermore, the time-series decoder includes several time-series decoding layers. The global periodic item information includes seasonal information and trend information. During the decoding process, for the Nth time-series decoding layer, the seasonal information can be added using an autocorrelation function, and the sum can be decomposed using a decomposition function to obtain the first-stage periodic item information corresponding to the seasonal information. The first-stage periodic item information and the past periodic item information can be processed using an autocorrelation function to obtain the weighted sum of global historical information. Then, the sum between the global historical weighted sum and the seasonal information can be decomposed using a decomposition function to obtain the second-stage periodic item information. Then, the sum between the seasonal information and the second-stage periodic item information can be processed using a feedforward network to obtain the third-stage periodic item information. The trend information can be decomposed three times using a decomposition function, and the results of the three decompositions can be weighted and aggregated to obtain the trend-weighted information. At the same time, the third-stage periodic item information and the trend-weighted information are passed to the N+1th time-series decoding layer, and the predicted data corresponding to the first historical time-series data is output through the last time-series decoding layer.

[0122] In one example, a user count prediction model can be modeled as follows:

[0123] 1) Introduce an autocorrelation mechanism based on sequence periodicity, by calculating the original sequence x t and lagged sequence x t-τ Autocorrelation coefficient Find periodically similar subsequences, and then shift the time to aggregate similar subsequences to deepen the hierarchical interaction between the intrinsic patterns of the sequences;

[0124] 2) Based on the concept of moving averages, smooth out the periodic fluctuations of time series, highlight the long-term trend, and thus separate the periodic term from the trend term: x t =AvgPool(Padding(x)), x s =xx t Padding is used to ensure the sequence length remains constant, and AvgPool is a moving average. x represents the latent variable to be decomposed.t ,x s These represent the trend term and the cycle term, respectively. Let x be the formula above. s ,x t =SeriesDecomp(x).

[0125] 3) Constructing a time encoder: The focus is on modeling periodic terms. The output is information about past periodic terms, which will be used as mutual information to help the time decoder adjust the prediction results.

[0126] Suppose we have N time-series coding layers, and the Lth time-series coding layer... The internal details are as follows:

[0127]

[0128]

[0129] The periodic term data output from the Lth temporal coding layer is processed by the Autocorrelation function to obtain the weighted sum of similar periodic subsequences. After being added to itself, it is processed by the SeriesDecomp decomposition function to obtain the first-stage periodic term information. After being processed by the FeedForward network and added to itself, the second-stage periodic term information is obtained. This is then passed as the global periodic term information representation to the temporal decoder and the L+1 layer temporal encoder.

[0130] The FeedForward network is defined as FeedForward(x) = max(0, xW1+b1)W2+b2, where W1 and W2 are the weights of the neural network layer, and b1 and b2 are the biases of the neural network layer, both of which are learnable parameters of the model.

[0131] 4) Constructing a time series decoder: For past periodic terms, a stacked autocorrelation mechanism is used to perform dependency mining based on the periodicity of the sequence, and subsequences with similar processes are aggregated to predict periodic terms; for past trend terms, a cumulative approach is used to gradually extract trend information from the predicted latent variables to predict trend terms. Assume we have N time series decoding layers, and the Lth time series decoding layer... The internal details are as follows:

[0132]

[0133]

[0134]

[0135]

[0136] Seasonal information part: The periodic term data output by the L-th time series decoding layer is added to itself through the AutoCorrelation autocorrelation function, and then decomposed by the SeriesDecomp decomposition function to obtain the first-stage periodic term information. The past periodic information output by the time series encoder is weighted and summed through the AutoCorrelation autocorrelation function to obtain the global historical information, added to itself, and then decomposed by the SeriesDecomp decomposition function to obtain the second-stage periodic term information. Then, it is added to itself through the FeedForward feed-forward network, and finally, the SeriesDecomp decomposition function decomposes and extracts the third-stage periodic term information, which is passed to the (L + 1)-th time series decoder (L + 1 < N) or obtains the final periodic term prediction value (the N-th time series decoder).

[0137] Trend information part: The periodic term data output by the L-th time series decoding layer is weighted and aggregated by the trend information obtained through the three-time series decomposition function SeriesDecomp, and then passed to the (L + 1)-th time series decoder (L + 1 < N) or obtains the final trend term prediction value (the N-th time series decoder).

[0138] Through the above process, an autocorrelation mechanism based on sequence periodicity is introduced to deepen the hierarchical interaction between the internal patterns of the sequence and find subsequences with similar periodicities. It can adapt to the differences between cycles such as holidays, weekends, and working schedules. The algorithm model predicts more accurately, fits the actual situation better, and improves the robustness of the early warning task. Moreover, through the encoder-decoder structure time series prediction algorithm, long sequence prediction is achieved, that is, the length of the sequence to be predicted is much larger than the input length. Compared with the short time series prediction algorithm, the number of model predictions is greatly reduced, and resource consumption is reduced.

[0139] It should be noted that for the time series encoder and the time series decoder, they can include the same number of layers or different numbers of layers. That is, for the value of "N" in the time series encoder and the value of "N" in the time series decoder, they can be the same or different. The present invention does not limit this.

[0140] Step 103, perform network fault handling according to the predicted number of online users corresponding to each of the detection area levels and the confidence interval, and generate a network detection result for the target area. The network detection result includes that the network of the target area is normal, or there is at least one network abnormality in the detection area level in the target area.

[0141] In this embodiment of the invention, after obtaining the predicted number of online users corresponding to each detection area level through the user number prediction model, the predicted number of online users can be compared with the confidence interval to realize network fault handling in the corresponding detection area. Based on the detection results of each detection area, the network detection results of the target area are obtained. The network detection results include whether the network in the target area is normal or whether there is a network anomaly at least one detection area level in the target area. By predicting the network of the corresponding area based on the real-time time series data of each detection area level, multi-dimensional network detection is realized, the detection area is increased, and based on the detection results, the affected area can be quickly located so as to handle the network anomaly area in a timely manner and ensure the stability of the network.

[0142] For example, the predicted number of online users at the provincial level can be compared with the first confidence interval corresponding to the provincial level to determine whether there is a network fault in the target area within the provincial detection area. The detection process is the same for city, county, operational, and equipment levels, and will not be elaborated here.

[0143] In the specific implementation, the predicted number of online users includes the predicted number of online users at the provincial level and the predicted number of online users at the municipal level. The confidence interval includes the first confidence interval corresponding to the predicted number of online users at the provincial level and the second confidence interval corresponding to the predicted number of online users at the municipal level. If the predicted number of online users at the provincial level falls within the first confidence interval, a network normal result is generated for the target area. If the predicted number of online users at the provincial level is less than the upper limit of the first confidence interval, a provincial sudden drop alarm result is generated for the target area. Based on the predicted number of online users at the municipal level and the second confidence interval, municipal-level network fault handling is performed to generate a network detection result for the target area. The provincial sudden drop alarm result is the result of a sudden drop in the number of online users at the provincial level in the target area, which leads to network anomalies.

[0144] For city-level network testing, the predicted number of online users also includes the predicted number of online users at the county level. The confidence interval also includes a third confidence interval corresponding to the predicted number of online users at the county level. If the predicted number of online users at the city level falls within the second confidence interval, a normal network result is generated for the target area, and the provincial-level sudden drop alarm result is canceled. If the predicted number of online users at the city level is less than the lower limit of the second confidence interval, a city-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users at the county level and the third confidence interval, county-level network fault handling is performed, and a network testing result for the target area is generated. The city-level sudden drop alarm result is the result of a sudden drop in the number of online users at the city level in the target area, leading to network anomalies.

[0145] For county-level network testing, the predicted number of online users also includes the predicted number of online users for operational services. The confidence interval also includes a fourth confidence interval corresponding to the predicted number of online users for operational services. If the predicted number of online users at the county level falls within the third confidence interval, a normal network result is generated for the target area, and the city-level sudden drop alarm result is canceled. If the predicted number of online users at the county level is less than the lower limit of the third confidence interval, a county-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users for operational services and the fourth confidence interval, network fault handling for operational services is performed, and a network testing result for the target area is generated. The county-level sudden drop alarm result is the result of a sudden drop in the number of online users at the county level in the target area, leading to network anomalies.

[0146] For network testing of the business service sector, the predicted number of online users also includes the predicted number of online users for devices. The confidence interval also includes the fifth confidence interval corresponding to the predicted number of online users for devices. If the predicted number of online users for the business service sector falls within the fourth confidence interval, a normal network result is generated for the target area, and the county-level sudden drop alarm result is canceled. If the predicted number of online users for the business service sector is less than the lower limit of the fourth confidence interval, a business service-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users for devices and the fifth confidence interval, network fault handling for the business service sector is performed, and a network testing result for the target area is generated. The sudden drop alarm result for the business service sector is the result of a sudden drop in the number of online users at the business service hall level in the target area, which leads to network anomalies.

[0147] For network testing of devices, if the predicted number of online users of a device falls within the fifth confidence interval, a normal network result is generated for the target area, and the service drop alarm result is canceled. Network devices located in the target area whose predicted number of online users is less than the lower limit of the fifth confidence interval are considered abnormal devices, and a device drop alarm result is generated for the abnormal devices. The device drop alarm result is the result of a sudden drop in the number of online users at the device level in the target area, which leads to network abnormality.

[0148] Furthermore, if the predicted number of online users at the provincial level exceeds the upper limit of the first confidence interval, a provincial surge alarm result is generated for the target area. This alarm result indicates that a sudden increase in the number of online users at the provincial level in the target area has led to network anomalies. If the predicted number of online users at the municipal level exceeds the upper limit of the second confidence interval, a municipal surge alarm result is generated for the target area. This alarm result indicates that a sudden increase in the number of online users at the municipal level in the target area has led to network anomalies. If the predicted number of online users at the county level exceeds the upper limit of the third confidence interval, a county surge alarm result is generated for the target area. As a result, a county-level surge alarm indicates a network anomaly caused by a sudden increase in the number of online users at the county level in the target area; if the predicted number of online service users exceeds the upper limit of the fourth confidence interval, a service surge alarm is generated for the target area, indicating a network anomaly caused by a sudden increase in the number of online users at the business service hall level in the target area; if the predicted number of online device users exceeds the upper limit of the fifth confidence interval, a device surge alarm is generated for the target area, indicating a network anomaly caused by a sudden increase in the number of online users at the device level in the target area.

[0149] In one example, based on services such as broadband, IPTV, and mobile internet, and targeting multiple dimensions such as province / city / county branches / operation services / equipment, the model uses the actual number of online users at the current moment to predict the upper and lower confidence intervals of the current moment for comparison. If the number exceeds the upper confidence interval, an alarm is triggered for a sharp increase in the number of online users; if it falls below the lower confidence interval, an alarm is triggered for a sharp decrease in the number of online users.

[0150] In practical implementation, for fault scenarios, the focus is on a sudden drop in the number of online users. Based on multi-dimensional linkage between provinces / municipalities and business operations, the early warning results are combined with judgment strategies to alert on large-scale faults in different scenarios. By associating user business resource tree information, the affected area (province / city / county branch / service provider) can be quickly located, and even the faulty network equipment can be identified, allowing for timely assessment of the affected scope (number of services, number of devices, etc.). The specific process may include:

[0151] 1. If the number of online users for a single business in the provincial dimension drops sharply, then query the number of online users for a single business in the city dimension to see if there is a sharp drop. If there is a sharp drop in the city dimension, proceed to the next step. If not, then the provincial dimension is considered to be a normal fluctuation, and the provincial dimension alarm is canceled.

[0152] 2. If the number of online users for a single business in the city-level alarm order drops sharply, then query the county-level single business online user count for a sharp drop. If a county-level drop exists, proceed to the next step; otherwise, determine that the city-level fluctuation is normal and cancel the city-level alarm.

[0153] 3. If the number of online users for a single business in the county-level alarm dimension drops sharply, then query the situation regarding the sharp drop in the number of online users for a single business in the operations and service dimension. If a sharp drop in operations and service exists, proceed to the next step; if not, then the county-level alarm is determined to be a normal fluctuation and is cancelled.

[0154] 4. If the number of online users for a single service drops sharply in the service dimension alarm, query the device (OLT, base station, etc.) dimension for the sharp drop in the number of online users for a single service. If the device drops sharply, then the network device with the alarm is faulty. If not, then the service dimension is determined to be a normal fluctuation, and the service dimension alarm is canceled.

[0155] By combining the multi-dimensional linkage of the above process, the early warning results are combined with the judgment strategy to quickly alert the affected area (province / city / county branch / service center), and even the network equipment with alarm failure. The information is associated with user service resource tree information to timely assess the affected area (number of services, number of devices, etc.).

[0156] It should be noted that the embodiments of the present invention include, but are not limited to, the examples described above. It is understood that those skilled in the art can make further settings according to actual needs under the guidance of the ideas in the embodiments of the present invention, and the present invention does not limit such settings.

[0157] In this embodiment of the invention, real-time time-series data corresponding to each detection area level in the target area is acquired. This real-time time-series data is then input into a user number prediction model to obtain the predicted number of online users corresponding to each detection area level, as well as the confidence interval corresponding to each detection area level. Network fault handling is then performed based on the predicted number of online users and the confidence interval corresponding to each detection area level, generating network detection results for the target area. These results include whether the network in the target area is normal, or whether there is at least one network anomaly at a detection area level in the target area. By predicting the network in the corresponding region based on the real-time time-series data of each detection area level, multi-dimensional network detection is achieved, increasing the detection area. Furthermore, based on the detection results, affected areas can be quickly located so that areas with network anomalies can be handled promptly, ensuring network stability.

[0158] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.

[0159] Reference Figure 2 The diagram shows a structural block diagram of a network detection device provided in an embodiment of the present invention, which may specifically include the following modules:

[0160] The time-series data acquisition module 201 is used to acquire real-time time-series data corresponding to each detection area level in the target area;

[0161] Prediction module 202 is used to input the real-time time series data into the user number prediction model to obtain the online user prediction number and confidence interval corresponding to each detection area level;

[0162] The detection module 203 is used to perform network fault processing based on the predicted number of online users and the confidence interval corresponding to each detection area level, and generate network detection results for the target area. The network detection results include whether the network in the target area is normal or whether there is at least one network anomaly at the detection area level in the target area.

[0163] In some optional embodiments, the predicted number of online users includes the predicted number of provincial-level online users and the predicted number of municipal-level online users, and the confidence interval includes a first confidence interval corresponding to the predicted number of provincial-level online users and a second confidence interval corresponding to the predicted number of municipal-level online users. The detection module 203 is specifically used for:

[0164] If the predicted number of online users in the provincial region falls within the first confidence interval, then a normal network result for the target region is generated.

[0165] If the predicted number of online users at the provincial level is less than the upper limit of the first confidence interval, a provincial-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users at the municipal level and the second confidence interval, municipal-level network fault handling is performed to generate a network detection result for the target area. The provincial-level sudden drop alarm result is the result of a sudden drop in the number of online users at the provincial level in the target area, which leads to network anomalies.

[0166] In some optional embodiments, the predicted number of online users further includes the predicted number of county-level online users, and the confidence interval further includes a third confidence interval corresponding to the predicted number of county-level online users. The detection module 203 is specifically used for:

[0167] If the predicted number of online users at the city level falls within the second confidence interval, a network normal result for the target area is generated, and the provincial-level sudden drop alarm result is canceled.

[0168] If the predicted number of online users at the city level is less than the lower limit of the second confidence interval, a city-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users at the county level and the third confidence interval, county-level network fault handling is performed, and a network detection result for the target area is generated. The city-level sudden drop alarm result is the result of a sudden drop in the number of online users at the city level in the target area, which leads to network anomalies.

[0169] In some optional embodiments, the predicted number of online users further includes the predicted number of online service users, and the confidence interval further includes a fourth confidence interval corresponding to the predicted number of online service users. The detection module 203 is specifically used for:

[0170] If the predicted number of online users at the county level falls within the third confidence interval, a network normal result for the target area is generated, and the city-level sudden drop alarm result is canceled.

[0171] If the predicted number of online users at the county level is less than the lower limit of the third confidence interval, a county-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users and the fourth confidence interval, network fault handling for the service is performed, and a network detection result for the target area is generated. The county-level sudden drop alarm result is the result of a sudden drop in the number of online users at the county level in the target area, which leads to network anomalies.

[0172] In some optional embodiments, the predicted number of online users further includes the predicted number of online users for devices, and the confidence interval further includes a fifth confidence interval corresponding to the predicted number of online users for devices. The detection module 203 is specifically used for:

[0173] If the predicted number of online users falls within the fourth confidence interval, a network normal result for the target area is generated, and the county-level sudden drop alarm result is canceled.

[0174] If the predicted number of online users in the business service sector is less than the lower limit of the fourth confidence interval, a business service-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users and the fifth confidence interval, network fault handling for the business service sector is performed, and a network detection result for the target area is generated. The business service sudden drop alarm result is the result of a sudden drop in the number of online users in the target area at the business service hall level, which leads to network anomalies.

[0175] In some alternative embodiments, the detection module 203 is specifically used for:

[0176] If the predicted number of online users of the device falls within the fifth confidence interval, a network normal result for the target area is generated, and the service drop alarm result is cancelled.

[0177] Network devices located in the target area whose predicted number of online users is less than the lower limit of the fifth confidence interval are identified as abnormal devices. A device drop alarm result is generated for the abnormal devices. The device drop alarm result is the result of a sudden drop in the number of online users in the target area at the device level, which leads to network abnormality.

[0178] In some alternative embodiments, the detection module 203 is further configured to:

[0179] If the predicted number of online users in the province is greater than the upper limit of the first confidence interval, a provincial surge alarm result is generated for the target area. The provincial surge alarm result is the result of a sudden increase in the number of online users in the target area at the provincial level, which leads to network anomalies.

[0180] If the predicted number of online users at the city level is greater than the upper limit of the second confidence interval, a city-level surge alarm result is generated for the target area. The city-level surge alarm result is the result of a sudden increase in the number of online users at the city level in the target area, which leads to network anomalies.

[0181] If the predicted number of online users at the county level is greater than the upper limit of the third confidence interval, a county-level surge alarm result is generated for the target area. The county-level surge alarm result is the result of a sudden increase in the number of online users at the county level in the target area, which leads to network anomalies.

[0182] If the predicted number of online users in the business service sector is greater than the upper limit of the fourth confidence interval, a sudden increase alarm result for the business service sector in the target area is generated. The sudden increase alarm result is the result of a sudden increase in the number of online users in the target area at the business service hall level, which leads to network anomalies.

[0183] If the predicted number of online users of the device is greater than the upper limit of the fifth confidence interval, a device surge alarm result is generated for the target area. The device surge alarm result is the result of a sudden increase in the number of online users at the device level in the target area, which leads to network anomalies.

[0184] In some alternative embodiments, the user number prediction model is generated by the following modules:

[0185] The sample data acquisition module is used to acquire training sample data, which includes first historical time series data within a first time period and at least one second historical time series data within a second time period.

[0186] Model prediction module 202 is used to input the first historical time series data into the user number prediction model for model training, and obtain prediction data corresponding to the first historical time series data. The prediction data includes the first number of online users corresponding to the first time period.

[0187] The information acquisition module is used to acquire the number of online users corresponding to the second historical time series data;

[0188] The model adjustment module is used to perform variance calculation on the first number of online users and the second number of online users to obtain the corresponding variance, and adjust the parameters of the user number prediction model based on the variance until the variance is less than or equal to a preset threshold, thereby ending the training of the user number prediction model and obtaining a trained user number prediction model.

[0189] In some optional embodiments, the user number prediction model includes a time-series encoder, a time-series decoder, and an autocorrelation function, and the model prediction module 202 is specifically used for:

[0190] The first historical time series data is input into the user number prediction model, and the first historical time series data is encoded by the time series encoder to output the past period item information corresponding to the first historical time series data.

[0191] The past periodic term information is processed according to the autocorrelation function to obtain global periodic term information;

[0192] The global periodicity information is input into the time-series decoder for decoding to obtain the prediction data corresponding to the first historical time-series data.

[0193] In some optional embodiments, the timing encoder includes several timing coding layers, the user number prediction model further includes a decomposition function and a feedforward network, and the model prediction module 202 is specifically used for:

[0194] For the Lth temporal coding layer, the past periodic term information is processed by the autocorrelation function to obtain the weighted sum of similar periodic subsequences;

[0195] The sum between the weighted sum of the past periodic term information and the similar periodic subsequence is processed by the decomposition function to obtain the encoded one-stage periodic term information;

[0196] The feedforward network is used to process the sum between the past periodic item information and the encoded first-stage periodic item information to obtain the encoded second-stage periodic item information.

[0197] The encoded two-stage periodic term information is passed as global periodic term information to the timing decoder or the (L+1)th timing coding layer.

[0198] In some optional embodiments, the time-series decoder includes several time-series decoding layers, the global periodicity information includes seasonality information and trend information, and the model prediction module 202 is specifically used for:

[0199] For the Nth time-series decoding layer, the seasonal information is added by the autocorrelation function, and the sum is decomposed by the decomposition function to obtain the decoding stage periodic term information corresponding to the seasonal information;

[0200] The autocorrelation function is used to process the decoded one-stage periodic term information and the past periodic term information to obtain a weighted sum of global historical information.

[0201] The sum between the global historical weighted sum and the seasonal information is decomposed using the decomposition function to obtain the decoded two-stage periodic term information;

[0202] The sum of the seasonal information and the decoded second-stage periodic term information is processed by the feedforward network to obtain the decoded third-stage periodic term information;

[0203] The trend information is decomposed three times using the decomposition function, and the results of the three decompositions are weighted and aggregated to obtain trend-weighted information.

[0204] The three-stage periodic item information and the trend weighting information are passed to the N+1th time series decoding layer, and the predicted data corresponding to the first historical time series data is output through the last time series decoding layer.

[0205] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.

[0206] In addition, this invention also provides an electronic device, including: a processor, a memory, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, it implements the various processes of the above-described network detection method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here.

[0207] This invention also provides a computer-readable storage medium storing a computer program. When executed by a processor, the computer program implements the various processes of the above-described network detection method embodiments and achieves the same technical effects. To avoid repetition, it will not be described again here. The computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0208] Figure 3 A schematic diagram of the hardware structure of an electronic device for implementing various embodiments of the present invention.

[0209] The electronic device 300 includes, but is not limited to, components such as: a radio frequency unit 301, a network module 302, an audio output unit 303, an input unit 304, a sensor 305, a display unit 306, a user input unit 307, an interface unit 308, a memory 309, a processor 310, and a power supply 311. Those skilled in the art will understand that the electronic device structure involved in the embodiments of the present invention does not constitute a limitation on the electronic device. An electronic device may include more or fewer components than illustrated, or combine certain components, or have different component arrangements. In the embodiments of the present invention, the electronic device includes, but is not limited to, mobile phones, tablet computers, laptop computers, PDAs, in-vehicle terminals, wearable devices, and pedometers.

[0210] It should be understood that, in this embodiment of the invention, the radio frequency unit 301 can be used for receiving and transmitting signals during information transmission or calls. Specifically, it receives downlink data from the base station and processes it with the processor 310; additionally, it transmits uplink data to the base station. Typically, the radio frequency unit 301 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, etc. Furthermore, the radio frequency unit 301 can also communicate with networks and other devices through a wireless communication system.

[0211] The electronic device provides users with wireless broadband internet access through the network module 302, such as helping users send and receive emails, browse web pages, and access streaming media.

[0212] The audio output unit 303 can convert audio data received by the radio frequency unit 301 or the network module 302 or stored in the memory 309 into audio signals and output them as sound. Furthermore, the audio output unit 303 can also provide audio output related to specific functions performed by the electronic device 300 (e.g., call signal reception sound, message reception sound, etc.). The audio output unit 303 includes a speaker, a buzzer, and a receiver, etc.

[0213] Input unit 304 is used to receive audio or video signals. Input unit 304 may include a graphics processing unit (GPU) 3041 and a microphone 3042. The GPU 3041 processes image data of still images or videos acquired by an image capture device (such as a camera) in video capture mode or image capture mode. The processed image frames can be displayed on display unit 306. The image frames processed by GPU 3041 can be stored in memory 309 (or other storage media) or transmitted via radio frequency unit 301 or network module 302. Microphone 3042 can receive sound and process such sound into audio data. The processed audio data can be converted into a format that can be transmitted to a mobile communication base station via radio frequency unit 301 in telephone call mode.

[0214] The electronic device 300 also includes at least one sensor 305, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor includes an ambient light sensor and a proximity sensor. The ambient light sensor can adjust the brightness of the display panel 3061 according to the ambient light level, and the proximity sensor can turn off the display panel 3061 and / or backlight when the electronic device 300 is moved to the ear. As a type of motion sensor, an accelerometer sensor can detect the magnitude of acceleration in various directions (generally three axes). When stationary, it can detect the magnitude and direction of gravity and can be used to identify the posture of the electronic device (such as landscape / portrait switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc. The sensor 305 may also include a fingerprint sensor, pressure sensor, iris sensor, molecular sensor, gyroscope, barometer, hygrometer, thermometer, infrared sensor, etc., which will not be described in detail here.

[0215] The display unit 306 is used to display information input by the user or information provided to the user. The display unit 306 may include a display panel 3061, which may be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), or the like.

[0216] User input unit 307 can be used to receive input numerical or character information, and generate key signal inputs related to user settings and function control of electronic devices. Specifically, user input unit 307 includes a touch panel 3071 and other input devices 3072. Touch panel 3071, also known as a touch screen, can collect touch operations performed by the user on or near it (such as operations performed by the user using a finger, stylus, or any suitable object or accessory on or near touch panel 3071). Touch panel 3071 may include two parts: a touch detection device and a touch controller. The touch detection device detects the user's touch position and the signal generated by the touch operation, and transmits the signal to the touch controller; the touch controller receives touch information from the touch detection device, converts it into touch point coordinates, and sends it to the processor 310, which receives and executes commands from the processor 310. In addition, touch panel 3071 can be implemented using various types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to touch panel 3071, user input unit 307 may also include other input devices 3072. Specifically, other input devices 3072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, joysticks, etc., which will not be described in detail here.

[0217] Furthermore, the touch panel 3071 can cover the display panel 3061. When the touch panel 3071 detects a touch operation on or near it, it transmits the information to the processor 310 to determine the type of touch event. Subsequently, the processor 310 provides corresponding visual output on the display panel 3061 according to the type of touch event. It is understood that in one embodiment, the touch panel 3071 and the display panel 3061 are implemented as two independent components to realize the input and output functions of the electronic device. However, in some embodiments, the touch panel 3071 and the display panel 3061 can be integrated to realize the input and output functions of the electronic device. The specific implementation is not limited here.

[0218] Interface unit 308 serves as an interface for connecting external devices to electronic device 300. For example, external devices may include a wired or wireless headphone port, an external power supply (or battery charger) port, a wired or wireless data port, a memory card port, a port for connecting a device with an identification module, an audio input / output (I / O) port, a video I / O port, a headphone port, and so on. Interface unit 308 can be used to receive input from external devices (e.g., data, power, etc.) and transmit the received input to one or more components within electronic device 300, or it can be used to transmit data between electronic device 300 and external devices.

[0219] The memory 309 can be used to store software programs and various data. The memory 309 may primarily include a program storage area and a data storage area. The program storage area may store the operating system, applications required for at least one function (such as sound playback, image playback, etc.), etc.; the data storage area may store data created based on the use of the mobile phone (such as audio data, phonebook, etc.). Furthermore, the memory 309 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0220] The processor 310 is the control center of the electronic device. It connects various parts of the electronic device via various interfaces and lines. By running or executing software programs and / or modules stored in the memory 309, and by calling data stored in the memory 309, it performs various functions and processes data, thereby providing overall monitoring of the electronic device. The processor 310 may include one or more processing units; preferably, the processor 310 may integrate an application processor and a modem processor. The application processor mainly handles the operating system, user interface, and applications, while the modem processor mainly handles wireless communication. It is understood that the modem processor may not be integrated into the processor 310.

[0221] The electronic device 300 may also include a power supply 311 (such as a battery) for supplying power to various components. Preferably, the power supply 311 can be logically connected to the processor 310 through a power management system, thereby enabling functions such as managing charging, discharging, and power consumption through the power management system.

[0222] In addition, the electronic device 300 includes some functional modules not shown, which will not be described in detail here.

[0223] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0224] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0225] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of the present invention without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of the present invention.

[0226] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this invention can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0227] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0228] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0229] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0230] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0231] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0232] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A method for detecting a network, characterized in that, include: Acquire real-time time-series data corresponding to each detection zone level in the target area; The real-time time series data is input into the user number prediction model to obtain the online user prediction number and confidence interval corresponding to each detection area level; Based on the predicted number of online users and the confidence interval corresponding to each of the detection area levels, network fault handling is performed to generate network detection results for the target area. The network detection results include whether the network in the target area is normal or whether there is at least one network anomaly at the detection area level in the target area. The user number prediction model is generated in the following manner: Acquire training sample data, which includes first historical time series data within a first time period and at least one second historical time series data within a second time period; The first historical time series data is input into the user number prediction model for model training to obtain prediction data corresponding to the first historical time series data. The prediction data includes the first online user number corresponding to the first time period. Obtain the second number of online users corresponding to the second historical time series data; The variance of the first number of online users and the second number of online users is calculated to obtain the corresponding variance. The parameters of the user number prediction model are adjusted based on the variance until the variance is less than or equal to a preset threshold. The training of the user number prediction model is then completed, and the trained user number prediction model is obtained.

2. The method according to claim 1, characterized in that, The predicted number of online users includes provincial-level and municipal-level predicted numbers of online users. The confidence interval includes a first confidence interval corresponding to the predicted number of provincial-level online users and a second confidence interval corresponding to the predicted number of municipal-level online users. The step of performing network fault handling based on the predicted number of online users corresponding to each detection area level and the confidence interval, and generating network detection results for the target area, includes: If the predicted number of online users in the provincial region falls within the first confidence interval, then a normal network result for the target region is generated. If the predicted number of online users at the provincial level is less than the upper limit of the first confidence interval, a provincial-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users at the municipal level and the second confidence interval, municipal-level network fault handling is performed to generate a network detection result for the target area. The provincial-level sudden drop alarm result is the result of a sudden drop in the number of online users at the provincial level in the target area, which leads to network anomalies.

3. The method according to claim 2, characterized in that, The predicted number of online users also includes the predicted number of online users at the county level, and the confidence interval also includes a third confidence interval corresponding to the predicted number of online users at the county level. The step of performing city-level network fault handling based on the predicted number of online users at the city level and the second confidence interval, and generating network detection results for the target area, includes: If the predicted number of online users at the city level falls within the second confidence interval, a network normal result for the target area is generated, and the provincial-level sudden drop alarm result is canceled. If the predicted number of online users at the city level is less than the lower limit of the second confidence interval, a city-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users at the county level and the third confidence interval, county-level network fault handling is performed, and a network detection result for the target area is generated. The city-level sudden drop alarm result is the result of a sudden drop in the number of online users at the city level in the target area, which leads to network anomalies.

4. The method according to claim 3, characterized in that, The predicted number of online users also includes the predicted number of online service users, and the confidence interval also includes a fourth confidence interval corresponding to the predicted number of online service users. The step of performing county-level network fault handling based on the predicted number of county-level online users and the third confidence interval, and generating network detection results for the target area, includes: If the predicted number of online users at the county level falls within the third confidence interval, a network normal result for the target area is generated, and the city-level sudden drop alarm result is canceled. If the predicted number of online users at the county level is less than the lower limit of the third confidence interval, a county-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users and the fourth confidence interval, network fault handling for the service is performed, and a network detection result for the target area is generated. The county-level sudden drop alarm result is the result of a sudden drop in the number of online users at the county level in the target area, which leads to network anomalies.

5. The method according to claim 4, characterized in that, The predicted number of online users also includes the predicted number of online users for devices, and the confidence interval also includes a fifth confidence interval corresponding to the predicted number of online users for devices. The step of performing network fault handling for the service based on the predicted number of online users and the fourth confidence interval, and generating network detection results for the target area, includes: If the predicted number of online users falls within the fourth confidence interval, a network normal result for the target area is generated, and the county-level sudden drop alarm result is canceled. If the predicted number of online users in the business service sector is less than the lower limit of the fourth confidence interval, a business service-level sudden drop alarm result is generated for the target area. Based on the predicted number of online users and the fifth confidence interval, network fault handling for the business service sector is performed, and a network detection result for the target area is generated. The business service sudden drop alarm result is the result of a sudden drop in the number of online users in the target area at the business service hall level, which leads to network anomalies.

6. The method according to claim 5, characterized in that, The step of performing network fault handling for the target area based on the predicted number of online users of the device and the fifth confidence interval, and generating network detection results for the target area, includes: If the predicted number of online users of the device falls within the fifth confidence interval, a network normal result for the target area is generated, and the service drop alarm result is cancelled. Network devices located in the target area whose predicted number of online users is less than the lower limit of the fifth confidence interval are identified as abnormal devices. A device drop alarm result is generated for the abnormal devices. The device drop alarm result is the result of a sudden drop in the number of online users in the target area at the device level, which leads to network abnormality.

7. The method according to claim 6, characterized in that, The step of performing network fault handling based on the predicted number of online users and confidence intervals corresponding to each detection area level, and generating network detection results for the target area, further includes: If the predicted number of online users in the province is greater than the upper limit of the first confidence interval, a provincial surge alarm result is generated for the target area. The provincial surge alarm result is the result of a sudden increase in the number of online users in the target area at the provincial level, which leads to network anomalies. If the predicted number of online users at the city level is greater than the upper limit of the second confidence interval, a city-level surge alarm result is generated for the target area. The city-level surge alarm result is the result of a sudden increase in the number of online users at the city level in the target area, which leads to network anomalies. If the predicted number of online users at the county level is greater than the upper limit of the third confidence interval, a county-level surge alarm result is generated for the target area. The county-level surge alarm result is the result of a sudden increase in the number of online users at the county level in the target area, which leads to network anomalies. If the predicted number of online users in the business service sector is greater than the upper limit of the fourth confidence interval, a sudden increase alarm result for the business service sector in the target area is generated. The sudden increase alarm result is the result of a sudden increase in the number of online users in the target area at the business service hall level, which leads to network anomalies. If the predicted number of online users of the device is greater than the upper limit of the fifth confidence interval, a device surge alarm result is generated for the target area. The device surge alarm result is the result of a sudden increase in the number of online users at the device level in the target area, which leads to network anomalies.

8. The method according to claim 1, characterized in that, The user count prediction model includes a time-series encoder, a time-series decoder, and an autocorrelation function. The step of inputting the first historical time-series data into the user count prediction model for model training to obtain prediction data corresponding to the first historical time-series data includes: The first historical time series data is input into the user number prediction model, and the first historical time series data is encoded by the time series encoder to output the past period item information corresponding to the first historical time series data. The past periodic term information is processed according to the autocorrelation function to obtain global periodic term information; The global periodicity information is input into the time-series decoder for decoding to obtain the prediction data corresponding to the first historical time-series data.

9. The method according to claim 8, characterized in that, The time-series encoder includes several time-series coding layers, and the user number prediction model further includes a decomposition function and a feedforward network. The step of processing the past periodic term information based on the autocorrelation function to obtain global periodic term information includes: For the Lth temporal coding layer, the past periodic term information is processed by the autocorrelation function to obtain the weighted sum of similar periodic subsequences; The sum between the weighted sum of the past periodic term information and the similar periodic subsequence is processed by the decomposition function to obtain the encoded one-stage periodic term information; The feedforward network is used to process the sum between the past periodic item information and the encoded first-stage periodic item information to obtain the encoded second-stage periodic item information. The encoded two-stage periodic term information is passed as global periodic term information to the timing decoder or the (L+1)th timing coding layer.

10. The method according to claim 9, characterized in that, The time-series decoder includes several time-series decoding layers. The global periodicity information includes seasonality information and trend information. The step of inputting the global periodicity information into the time-series decoder for decoding to obtain predicted data corresponding to the first historical time-series data includes: For the Nth time-series decoding layer, the seasonal information is added by the autocorrelation function, and the sum is decomposed by the decomposition function to obtain the decoding stage periodic term information corresponding to the seasonal information; The autocorrelation function is used to process the decoded one-stage periodic term information and the past periodic term information to obtain a weighted sum of global historical information. The sum between the global historical weighted sum and the seasonal information is decomposed using the decomposition function to obtain the decoded two-stage periodic term information; The sum of the seasonal information and the decoded second-stage periodic term information is processed by the feedforward network to obtain the decoded third-stage periodic term information; The trend information is decomposed three times using the decomposition function, and the results of the three decompositions are weighted and aggregated to obtain trend-weighted information. The three-stage periodic item information and the trend weighting information are passed to the N+1th time series decoding layer, and the predicted data corresponding to the first historical time series data is output through the last time series decoding layer.

11. A network detection device, characterized in that, include: The time-series data acquisition module is used to acquire real-time time-series data corresponding to each detection area level in the target area; The prediction module is used to input the real-time time series data into the user number prediction model to obtain the predicted number of online users and the confidence interval corresponding to each detection area level. The detection module is used to perform network fault handling based on the predicted number of online users and the confidence interval corresponding to each detection area level, and generate network detection results for the target area. The network detection results include whether the network in the target area is normal, or whether there is at least one network anomaly at the detection area level in the target area. The user number prediction model is generated in the following manner: Acquire training sample data, which includes first historical time series data within a first time period and at least one second historical time series data within a second time period; The first historical time series data is input into the user number prediction model for model training to obtain prediction data corresponding to the first historical time series data. The prediction data includes the first online user number corresponding to the first time period. Obtain the second number of online users corresponding to the second historical time series data; The variance of the first number of online users and the second number of online users is calculated to obtain the corresponding variance. The parameters of the user number prediction model are adjusted based on the variance until the variance is less than or equal to a preset threshold. The training of the user number prediction model is then completed, and the trained user number prediction model is obtained.

12. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; The memory is used to store computer programs; When the processor executes a program stored in the memory, it implements the method as described in any one of claims 1-10.

13. A computer-readable storage medium having instructions stored thereon that, when executed by one or more processors, cause the processors to perform the method as described in any one of claims 1-10.