A data detection method, device, equipment and storage medium
Through the graph neural network perspective transformation and adaptive data enhancement within and between signals, combined with the Transformer network, the problem of abnormal identification in multi-dimensional timing data detection is solved, and higher detection accuracy and model adaptability are achieved.
Patent Information
- Application Number
- CN202310970472.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-02
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2043-08-02
AI Technical Summary
When existing data detection methods process multi-dimensional time series data, it is difficult to effectively identify abnormal data. Especially in the presence of noise and complex environments, traditional machine learning methods are highly sensitive, while recurrent neural network-based methods are slow to train and are sensitive to noise, which affects the detection effect.
The graph neural network perspective transformation within the signal and between the signals is adopted, and the initial signal internal graph neural network, the graph neural network between the signals is iteratively trained through the target model, the feature representation ability is improved, and the transformation network is used for reconstruction, combined with the adaptive data enhancement method, the model parameters are optimized.
It improves the accuracy of data detection, can process multi-dimensional time-series data more comprehensively, improves the ability to identify abnormal data, reduces noise interference, and improves the generalization ability and adaptability of the model.
Smart Images

Figure CN117009902B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the technical field of data processing, and in particular, to a data detection method, apparatus, device, and storage medium. Background Art
[0002] Data detection is a process of identifying abnormal events or behaviors from normal time series. Existing data detection methods include: data detection methods based on traditional machine learning and methods based on recurrent neural networks and sequence reconstruction.
[0003] Among them, methods based on traditional machine learning (statistical models, multivariate normal distribution models, independent forests, etc.) can detect obvious abnormal data to a certain extent. However, traditional machine learning is sensitive to data noise and only independently models each time series data, making it difficult to solve the anomalies caused by the mutual correlation in multi-dimensional time series data. The time series data in actual scenarios has characteristics such as large noise, large fluctuations, and being greatly affected by the environment, and traditional machine learning methods are difficult to meet the requirements of complex scenarios.
[0004] The method based on recurrent neural networks and sequence reconstruction uses an LSTM in the recurrent neural network for feature encoding and decoding, and at the same time, uses a variational autoencoder (VAE) as the architecture for feature encoding and decoding. The main reasoning process is: 1) data preprocessing, 2) inputting the image into the trained encoder network (Encoder) for feature extraction and encoding, 3) inputting the encoded features into the decoder (Decoder) for decoding to reconstruct the signal at a certain moment, 4) determining whether it is an abnormal point by means of threshold judgment. Due to the serial computing characteristics of the recurrent neural network, the model training and inference speeds are slow, and the above method does not consider the noise problem existing in the training data, which will interfere with the reconstruction error and thus affect the detection effect. Summary of the Invention
[0005] The embodiments of the present invention provide a data detection method, apparatus, device, and storage medium to achieve improving the accuracy of data detection.
[0006] According to one aspect of the present invention, there is provided a data detection method, including:
[0007] Obtaining the cloud network status data to be detected within a target time period;
[0008] Performing a perspective transformation on the cloud network status data to be detected to obtain a graph neural network view from the perspective of the graph neural network of the internal view of the signal and a graph neural network view from the perspective of the graph neural network between signals;
[0009] Input the graph neural network view from the perspective of the internal graph neural network of the signal and the graph neural network view from the perspective of the graph neural network between signals into the target model to obtain target data, where the target model is obtained by iteratively training a first model with a target sample set, and the first model includes: an initial internal graph neural network of the signal, an initial graph neural network between signals, an initial feature fusion network, and an initial reconstruction network;
[0010] Determine the data detection result of the to-be-detected cloud network status data according to the error between the target data and the to-be-detected cloud network status data.
[0011] According to another aspect of the present invention, there is provided a data detection device, which includes:
[0012] A to-be-detected cloud network status data acquisition module, configured to acquire the to-be-detected cloud network status data within a target time period;
[0013] A perspective transformation module, configured to perform perspective transformation on the to-be-detected cloud network status data to obtain a graph neural network view from the perspective of the internal graph neural network of the signal and a graph neural network view from the perspective of the graph neural network between signals;
[0014] A reconstruction module, configured to input the graph neural network view from the perspective of the internal graph neural network of the signal and the graph neural network view from the perspective of the graph neural network between signals into the target model to obtain target data, where the target model is obtained by iteratively training a first model with a target sample set, and the first model includes: an initial internal graph neural network of the signal, an initial graph neural network between signals, an initial feature fusion network, and an initial reconstruction network;
[0015] A data detection module, configured to determine the data detection result of the to-be-detected cloud network status data according to the error between the target data and the to-be-detected cloud network status data.
[0016] According to another aspect of the present invention, there is provided an electronic device, which includes:
[0017] At least one processor; and
[0018] A memory communicatively connected to the at least one processor; wherein,
[0019] The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the data detection method according to any embodiment of the present invention.
[0020] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for causing a processor to implement the data detection method according to any embodiment of the present invention when executed.
[0021] In an embodiment of the present invention, by obtaining the cloud network status data to be detected within a target time period; performing perspective transformation on the cloud network status data to be detected to obtain a graph neural network view from the perspective of the graph neural network inside the signal and a graph neural network view from the perspective of the graph neural network between signals; inputting the graph neural network view from the perspective of the graph neural network inside the signal and the graph neural network view from the perspective of the graph neural network between signals into a target model to obtain target data, where the target model is obtained by iteratively training a first model with a target sample set, and the first model includes: an initial graph neural network inside the signal, an initial graph neural network between signals, an initial feature fusion network, and an initial reconstruction network; determining a data detection result of the cloud network status data to be detected according to the error between the target data and the cloud network status data to be detected, which can improve the accuracy of data detection.
[0022] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of the present invention, and thus should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0024] Figure 1 is a flowchart of a data detection method in an embodiment of the present invention;
[0025] Figure 2 is a flowchart of another data detection method in an embodiment of the present invention;
[0026] Figure 3 is a schematic diagram of a training network structure in an embodiment of the present invention;
[0027] Figure 4 is a diagram of an adaptive data augmentation method in an embodiment of the present invention;
[0028] Figure 5 is a schematic diagram of the structure of a target model in an embodiment of the present invention;
[0029] Figure 6It is a schematic structural diagram of a data detection device in an embodiment of the present invention;
[0030] Figure 7 It is a schematic structural diagram of an electronic device in an embodiment of the present invention. Detailed implementation manners
[0031] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0032] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0033] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0034] Embodiment 1
[0035] Figure 1 It is a flowchart of a data detection method provided by an embodiment of the present invention. This embodiment is applicable to the situation of data detection. This method can be executed by the data detection device in the embodiment of the present invention. The device can be implemented in a software and / or hardware manner, such as Figure 1 As shown, the method specifically includes the following steps:
[0036] S110, obtain the cloud network status data to be detected within the target time period.
[0037] Among them, the cloud network status data is the data obtained that can represent the usage and running status of cloud network resources at a certain moment. For example, the cloud network status data includes at least one of the following indicators: uplink network traffic, downlink network traffic, CPU rate, memory occupancy rate, packet loss rate, and network latency. Combining the above data according to time forms multi-dimensional time series data. By analyzing this multi-dimensional time series data, abnormal data can be found, and then the status of the system at the current moment can be judged.
[0038] Among them, the target time period can be a pre-set time period. For example, the target time period can be the time window size w.
[0039] For example, it can be to obtain the cloud network status data X to be detected within the target time. The specification of X is n*w, where n is the number of signals and w is the time window size.
[0040] S120. Perform perspective transformation on the cloud network status data to be detected to obtain a graph neural network view from the perspective of the graph neural network within the signal and a graph neural network view from the perspective of the graph neural network between signals.
[0041] Among them, perspective transformation means transforming the input data into vertex feature data corresponding to the graph neural network. Specifically, the graph neural network view from the perspective of the graph neural network within the signal means taking the data at each time point in a period of time series data as a node of the graph neural network, and all the signal data at this time point as the features of this node. Therefore, a graph neural network view from the perspective of the graph neural network within the signal with w nodes is formed; the graph neural network view from the perspective of the graph neural network between signals means taking each signal in this period of time series data as a node, and the data of this signal within this period of time as the node features. Therefore, a graph neural network view from the perspective of the graph neural network between signals with n nodes is formed.
[0042] Specifically, the method for performing perspective transformation on the cloud network status data to be detected to obtain the graph neural network view from the perspective of the graph neural network inside the signal and the graph neural network view from the perspective of the graph neural network between signals can be as follows: Normalize the cloud network status data to be detected to obtain the normalized cloud network status data to be detected, and then perform perspective transformation on the normalized cloud network status data to obtain the graph neural network view from the perspective of the graph neural network inside the signal and the graph neural network view from the perspective of the graph neural network between signals. Another way to perform perspective transformation on the cloud network status data to be detected to obtain the graph neural network view from the perspective of the graph neural network inside the signal and the graph neural network view from the perspective of the graph neural network between signals is as follows: Determine the time node and the features of the time node based on the cloud network status data to be detected, and generate the graph neural network view from the perspective of the graph neural network inside the signal according to the time node and the features of the time node; Determine the signal node and the features of the signal node based on the cloud network status data to be detected, and generate the graph neural network view from the perspective of the graph neural network between signals according to the signal node and the features of the signal node.
[0043] S130, Input the graph neural network view from the perspective of the graph neural network inside the signal and the graph neural network view from the perspective of the graph neural network between signals into the target model to obtain the target data.
[0044] Among them, the target model is obtained by iteratively training the first model with a target sample set. The first model includes: an initial graph neural network inside the signal, an initial graph neural network between signals, an initial feature fusion network, and an initial reconstruction network.
[0045] It should be noted that the initial intra-signal graph neural network and the initial inter-signal graph neural network are two parallel graph neural networks. Through the iteration of multiple graph neural network layers, they can learn the correlation features between each node of the graph, thereby realizing the feature representation of the data.
[0046] Among them, the target data is the reconstruction result, that is, the reconstructed data. The target model includes: a target graph neural network inside the signal, a target graph neural network between signals, a target feature fusion network, and a target reconstruction network.
[0047] Among them, the feature fusion network is a network that fuses the intra-signal features (the output of the graph neural network inside the signal) and the inter-signal features (the output of the graph neural network between signals), and obtains the fused features by means of channel connection and linear layer calculation.
[0048] Among them, the reconstruction network is a network that reconstructs the fused features. For example, the initial reconstruction network adopts a Transformer network structure.
[0049] Specifically, the method of iteratively training the first model with a target sample set to obtain a target model can be as follows: Obtain initial cloud network state data samples, perform data augmentation on the initial cloud network state data samples to obtain target cloud network state data samples, perform perspective transformation on the initial cloud network state data samples and the target cloud network state data samples respectively, input the perspective-transformed initial cloud network state data samples and target cloud network state data samples into the corresponding initial signal internal graph neural network or initial signal between-graph neural network, determine the cross-view contrast loss, cross-network contrast loss, and reconstruction error loss according to the outputs of the initial signal internal graph neural network and the initial signal between-graph neural network, train the parameters of the first model according to the cross-view contrast loss, cross-network contrast loss, and reconstruction error loss, return to perform the operation of performing data augmentation on the initial cloud network state data samples to obtain target cloud network state data samples, until the cross-view contrast loss, cross-network contrast loss, and reconstruction error loss meet the preset conditions, and obtain the target model. Among them, the preset conditions can be: perform weighted summation on the cross-view contrast loss, cross-network contrast loss, and reconstruction error loss to obtain a total loss. If the total loss is less than the set threshold, end the optimization. It should be noted that the termination condition of the optimization can also be: obtain the total number of optimizations. If the total number of optimizations is greater than the optimization number threshold, terminate the optimization.
[0050] S140. Determine the data detection result of the to-be-detected cloud network state data according to the error between the target data and the to-be-detected cloud network state data.
[0051] Among them, the error between the target data and the to-be-detected cloud network state data can be calculated by MSE (Mean Square Error).
[0052] Among them, the error threshold can be a preset threshold.
[0053] Specifically, the method of determining the data detection result of the to-be-detected cloud network state data according to the error between the target data and the to-be-detected cloud network state data can be: if the error between the target data and the to-be-detected cloud network state data is greater than the error threshold, determine that the to-be-detected cloud network state data is abnormal data; if the error between the target data and the to-be-detected cloud network state data is less than or equal to the error threshold, determine that the to-be-detected cloud network state data is normal data.
[0054] In a specific example, the cloud network state data detection method includes the following process:
[0055] 1) Collect the to-be-detected cloud network state data. Among them, the to-be-detected cloud network state data is the normalized time series data X(n*w), where n is the number of signals and w is the time window size, as the input.
[0056] 2) Perform a perspective transformation on X and generate graph neural network views of two perspectives (the perspective of the graph neural network inside the signal and the perspective of the graph neural network between signals);
[0057] 3) Input the view data of the two generated perspectives into the target graph neural network inside the signal and the target graph neural network between signals respectively for feature extraction, and extract the features inside the signal and the features between signals;
[0058] 4) Input the features inside the signal and the features between signals into the target feature fusion network for feature fusion to obtain the fused features;
[0059] 4) Input the fused features into the target reconstruction network to obtain the reconstruction result, which is the target data;
[0060] 5) Calculate the error between the target data and X. When the error is greater than the error threshold, then X is abnormal data; otherwise, X is normal data.
[0061] The embodiment of the present invention uses two parallel graph neural networks inside the signal and between the signals to respectively learn the correlation features inside the signal and the dependency relationship between the signals, and can represent the multi-dimensional time series data more comprehensively, improve the representation ability, and further improve the accuracy of data detection.
[0062] Optionally, the target model includes: a target graph neural network inside the signal, a target graph neural network between the signals, a target feature fusion network, and a target reconstruction network;
[0063] Input the graph neural network views of the graph neural network perspective inside the signal and the graph neural network perspective between the signals into the target model to obtain the target data, including:
[0064] Input the graph neural network view of the graph neural network perspective inside the signal into the target graph neural network inside the signal for feature extraction to obtain the features inside the signal;
[0065] Input the graph neural network view of the graph neural network perspective between the signals into the target graph neural network between the signals for feature extraction to obtain the features between the signals;
[0066] Input the features inside the signal and the features between the signals into the target feature fusion network to obtain the fused features;
[0067] Input the fused features into the target reconstruction network to obtain the target data.
[0068] Among them, the target reconstruction network adopts a Transformer network structure.
[0069] Specifically, the method of inputting the internal signal features and the inter-signal features into the target feature fusion network to obtain the fusion features can be: inputting the internal signal features and the inter-signal features into the target feature fusion network, and obtaining the fusion features by means of channel connection and linear layer calculation.
[0070] Optionally, performing a perspective transformation on the to-be-detected time-series data to obtain a graph neural network view from the perspective of the internal signal graph neural network and a graph neural network view from the perspective of the inter-signal graph neural network, including:
[0071] Determining the time nodes, the features of the time nodes, the signal nodes, and the features of the signal nodes according to the to-be-detected cloud network status data;
[0072] Generating a graph neural network view from the perspective of the internal signal graph neural network according to the time nodes and the features of the time nodes;
[0073] Generating a graph neural network view from the perspective of the inter-signal graph neural network according to the signal nodes and the features of the signal nodes.
[0074] It should be noted that the to-be-detected cloud network status data is time-series data.
[0075] Among them, the time node is a node of the internal signal graph neural network, the graph neural network view from the perspective of the internal signal graph neural network is composed of multiple time nodes and the features of the time nodes, and the signal node is a node of the inter-signal graph neural network. The graph neural network view from the perspective of the inter-signal graph neural network is composed of multiple signal nodes and the features of the signal nodes.
[0076] Optionally, determining the time nodes, the features of the time nodes, the signal nodes, and the features of the signal nodes according to the to-be-detected cloud network status data, including:
[0077] Regarding each time point in the to-be-detected cloud network status data as a time node of the graph neural network, and regarding the signal corresponding to the time point as the feature of the time node;
[0078] Regarding each signal in the to-be-detected cloud network status data as a signal node of the graph neural network, and regarding the data of the signal within the target time period as the feature of the signal node.
[0079] Among them, the signal corresponding to the time point is all the signals collected at the time point. For example, if the time point is 8 o'clock, the feature of the time node is all the signals collected at 8 o'clock.
[0080] Among them, the data of the signal within the target time is the change data of the signal within the target time. For example, if the target time period is: [t1, t2, t3, t4, t5], then the data of signal A within the target time period includes: the signal A collected at t1, the signal A collected at t2, the signal A collected at t3, the signal A collected at t4, and the signal A collected at t5.
[0081] Optionally, iteratively training the first model with the target sample set includes:
[0082] Obtain a target sample set, where the target sample set includes: initial cloud network state data samples;
[0083] Perform data augmentation on the initial cloud network state data samples to obtain target cloud network state data samples;
[0084] Perform perspective transformation on the initial cloud network state data samples to obtain a graph neural network view from the perspective of the first signal internal graph neural network and a graph neural network view from the perspective of the first signal between graph neural networks;
[0085] Perform perspective transformation on the target cloud network state data samples to obtain a graph neural network view from the perspective of the second signal internal graph neural network and a graph neural network view from the perspective of the second signal between graph neural networks;
[0086] Input the graph neural network view from the perspective of the first signal internal graph neural network into the initial signal internal graph neural network to obtain first signal internal features;
[0087] Input the graph neural network view from the perspective of the second signal internal graph neural network into the initial signal internal graph neural network to obtain second signal internal features;
[0088] Input the graph neural network view from the perspective of the first signal between graph neural networks into the initial signal between graph neural networks to obtain first signal between features;
[0089] Input the graph neural network view from the perspective of the second signal between graph neural networks into the initial signal between graph neural networks to obtain second signal between features;
[0090] Determine the cross-view contrast loss according to the first signal internal features, the second signal internal features, the first signal between features, and the second signal between features;
[0091] Determine the cross-network contrast loss according to the first signal internal features and the first signal between features;
[0092] Input the first signal internal features and the first signal between features into the initial feature fusion network for feature fusion to obtain initial fusion features;
[0093] Input the initial fusion feature into the initial reconstruction network to obtain the first data;
[0094] Determine the reconstruction error loss according to the first data and the initial cloud network state data sample;
[0095] Train the parameters of the first model according to the cross-view contrast loss, the cross-network contrast loss, and the reconstruction error loss;
[0096] Return to perform the operation of data augmentation on the initial cloud network state data sample to obtain the target cloud network state data sample until the target model is obtained.
[0097] Wherein, the initial cloud network state data sample is a positive sample.
[0098] Specifically, the method of performing data augmentation on the initial cloud network state data sample to obtain the target cloud network state data sample can be: input the initial cloud network state data sample into the adaptive data augmentation network to obtain the target cloud network state data sample.
[0099] Specifically, the method of determining the cross-view contrast loss according to the first signal internal feature, the second signal internal feature, the first signal between feature, and the second signal between feature can be: determine the cross-view loss of the signal internal graph neural network according to the first signal internal feature and the second signal internal feature; determine the cross-view loss of the signal between graph neural networks according to the first signal between feature and the second signal between feature; determine the cross-view contrast loss according to the cross-view loss of the signal internal graph neural network and the cross-view loss of the signal between graph neural networks.
[0100] Specifically, the method of determining the reconstruction error loss according to the first data and the initial cloud network state data sample can be: calculate the reconstruction error loss using MSE based on the first data and the initial cloud network state data sample.
[0101] Optionally, determining the cross-view contrast loss according to the first signal internal feature, the second signal internal feature, the first signal between feature, and the second signal between feature includes:
[0102] Determine the cross-view loss of the signal internal graph neural network according to the first signal internal feature and the second signal internal feature;
[0103] Determine the cross-view loss of the signal between graph neural networks according to the first signal between feature and the second signal between feature;
[0104] Determine the cross-view contrast loss according to the cross-view loss of the signal internal graph neural network and the cross-view loss of the signal between graph neural networks.
[0105] Specifically, the method for determining the cross-view contrast loss based on the cross-view loss of the graph neural network within the signal and the cross-view loss of the graph neural network between the signals can be: performing a weighted sum on the cross-view loss of the graph neural network within the signal and the cross-view loss of the graph neural network between the signals to obtain the cross-view contrast loss.
[0106] In a specific example, the model training process includes:
[0107] 1) Obtain historical cloud network status data y, where the historical cloud network status data y is normal data, the historical cloud network status data y is time-series data, the specification of the historical cloud network status data y is n*w, n is the number of signals, w is the time window size, normalize the historical cloud network status data y to obtain the normalized historical network status data Y, and use the normalized historical cloud network status data Y as the input;
[0108] 2) Input the normalized historical cloud network status data Y into the adaptive data augmentation network to generate Y';
[0109] 3) Perform perspective transformation on Y and Y' respectively to generate views of the graph neural network for two perspectives (i.e., each perspective of the graph neural network has two views);
[0110] 4) Input the two generated views of the graph neural network within the signal into the initial graph neural network within the signal to obtain two internal signal features U 1 1 and U 2 1; Similarly, input the two generated views of the graph neural network between the signals into the initial graph neural network between the signals to obtain two between-signal features U2 1 and U 2 2; where U 1 1 and U 1 2 are generated from Y, and U 2 1 and U 2 2 are generated from Y';
[0111] 5) Calculate the cross-view contrast loss (including the cross-view loss of the graph neural network within the signal calculated from U 1 1 and U 2 1, and the cross-view loss of the graph neural network between the signals calculated from U 1 2 and U 2 2) and the cross-network contrast loss (generated from U 1 1 and U 1 2);
[0112] 6) Input the internal signal features and the between-signal features into the initial feature fusion network for feature fusion to obtain the fused features;
[0113] 7) The fused features are input into the initial reconstruction network to obtain the reconstruction result, which is the first data;
[0114] 8) Calculate the reconstruction error loss between the first data and the normalized historical cloud network state data Y;
[0115] 9) Perform weighted summation on the cross-view contrast loss, cross-network contrast loss, and reconstruction error loss, calculate the total loss, and perform optimization training based on the total loss;
[0116] 10) Obtain the trained model, which is the target model.
[0117] Among them, the adaptive data augmentation network is a network used for adaptive data augmentation after training to obtain the parameters required for data augmentation. Among them, the loss function adopted for contrastive learning is the standard InfoNCE loss; the reconstruction error loss function is the standard mean squared error loss function Mean Squared Loss. It should be noted that here, the graph-level calculation method is adopted for calculating the contrastive learning loss, that is, the features of the entire graph are regarded as a whole to judge positive and negative samples for calculation. Compared with the existing node-level graph contrast loss calculation method, the graph-level can better retain the internal correlation characteristics of the data.
[0118] In another specific example, as Figure 2 shown, the main steps of the training process include:
[0119] Read the training data, where the training data includes: the normalized historical cloud network state data Y.
[0120] Initialize the weights of each layer of each network included in the first model. The first model includes: the initial signal internal graph neural network, the initial signal between graph neural network, the initial feature fusion network, and the initial reconstruction network.
[0121] Perform adaptive data augmentation on the normalized historical cloud network state data Y to obtain Y'.
[0122] Perform perspective transformation on Y and Y' respectively to generate multi-perspectives and multi-views of the graph neural network (two perspectives, two views for each perspective).
[0123] Calculate the internal signal features and the between-signal features.
[0124] Calculate the cross-view contrast learning loss, including the internal signal graph neural network contrast loss and the between-signal graph neural network contrast loss.
[0125] Calculate the cross-graph contrast learning loss.
[0126] Calculate the reconstruction error loss.
[0127] Single optimization operation. A single optimization operation is to update the model parameter weights through backpropagation. Methods that can be used for weight update include but are not limited to SGD, RMSProp, Adam, Nesterov Accelerated Gradient, or their combinations.
[0128] Reach the termination condition. Determine whether to terminate the training of this branch. The termination condition can be setting a total number of optimization times, or the total loss is less than a certain preset value.
[0129] Save the network weights. Save the corresponding network weights updated after training.
[0130] End. End the model training process. The training is an end-to-end unsupervised training method, and different stages and branches of the model are trained synchronously, updated synchronously, and ended simultaneously.
[0131] In another specific example, as Figure 3 shown, Figure 3 is the overall architecture of the training network provided by the embodiments of the present invention. The main purpose of the training network is to train two types of tasks: contrast learning tasks and reconstruction tasks. For the contrast learning task, two views are generated for the graph neural network between signals and the graph neural network inside the signal respectively through data augmentation, and are optimized respectively through the cross-view contrast loss function, and then further optimized through the cross-graph contrast loss; for the reconstruction task, the input data is reconstructed through the fusion network and the reconstruction network, and then a reconstruction loss is constructed for optimization. In addition, the adaptive parameter learning of the adaptive data augmentation method is also optimized during the network training process. Through the training network, a complete set of model parameters is obtained.
[0132] Optionally, data augmentation is performed on the initial cloud network state data sample to obtain the target cloud network state data sample, including:
[0133] Obtain the importance probability of each signal in the initial cloud network state data sample and / or the importance probability of the data corresponding to each time point;
[0134] Mask the signal with the smallest importance probability and / or the data corresponding to the time point with the smallest importance probability in the initial cloud network state data sample to obtain the target cloud network state data sample.
[0135] It should be noted that the adaptive data augmentation method can be used to augment the initial cloud network state data samples. The adaptive data augmentation method adaptively selects specific data for masking in a learning manner, that is, setting the values of these data to 0. Then, in contrastive learning, it forces the features extracted from the original data to reach a consensus with the features extracted from the augmented data, that is, the features are consistent, aiming to ensure the forced learning of key invariant features. If some data is directly randomly masked during data augmentation, it may lead to the loss of key features and cause learning failure. Therefore, in the embodiments of the present invention, a learning method is adopted. By setting learnable parameters, the importance probability of each feature is learned, and then through sampling, the part of the data with the lowest importance is selected for masking to achieve the adaptive augmentation of the data. Among them, the sampling method can be the standard Gumbel sampling method, which is differentiable and can be trained by backpropagation of gradients. As Figure 4 shown Figure 4 is the adaptive data augmentation in the signal dimension (i.e., between signals: inter-signal). In addition, an augmentation method for the time dimension (i.e., within signals: intra-signal) is also required. The augmentation in the time dimension is similar to Figure 4 and will not be elaborated here. It should be noted that the difference between the augmentation in the time dimension and the augmentation in the signal dimension is: learning and sampling {z1, z2, z3,..., z w}. During training, either one of the augmentation methods in the two dimensions can be randomly selected for augmentation, or they can be superimposed (i.e., augmented in the time dimension and also in the signal dimension).
[0136] In a specific example, as Figure 5 shown Figure 5 is the overall architecture of the target model provided by the embodiments of the present invention. The main purpose of the target model is to detect abnormal data. The target model no longer uses data augmentation in the training network and generates additional views for comparison. It only directly generates a perspective of the network between signals and the network within signals through the input data, and then calculates the features through the graph neural network. Then, the reconstruction result is generated through the fusion network and the reconstruction network, and the reconstruction error is calculated. Finally, it is determined whether the data is abnormal based on the reconstruction error.
[0137] By adopting the adaptive data augmentation method, constructing multiple views, and performing cross-view and cross-network contrastive learning, the embodiments of the present invention can make up for the negative impact caused by the lack of training data, and at the same time reduce the risk of damaging the internal features of the data that may be caused by traditional data augmentation methods, and improve the generalization ability and adaptability of the model.
[0138] The technical solution of this embodiment is to obtain the cloud network status data to be detected within a target time period; perform perspective transformation on the cloud network status data to be detected to obtain a graph neural network view from the perspective of the graph neural network inside the signal and a graph neural network view from the perspective of the graph neural network between signals; input the graph neural network view from the perspective of the graph neural network inside the signal and the graph neural network view from the perspective of the graph neural network between signals into a target model to obtain target data, where the target model is obtained by iteratively training a first model with a target sample set, and the first model includes: an initial graph neural network inside the signal, an initial graph neural network between signals, an initial feature fusion network, and an initial reconstruction network; determine the data detection result of the cloud network status data to be detected according to the error between the target data and the cloud network status data to be detected, which can improve the accuracy of data detection.
[0139] Embodiment 2
[0140] Figure 6 FIG. is a schematic structural diagram of a data detection device provided by an embodiment of the present invention. This embodiment is applicable to the situation of data detection. The device can be implemented in software and / or hardware, and the device can be integrated in any device providing data detection functions, such as Figure 6 As shown, the data detection device specifically includes: a cloud network status data to be detected acquisition module 210, a perspective transformation module 220, a reconstruction module 230, and a data detection module 240.
[0141] Among them, the cloud network status data to be detected acquisition module is used to obtain the cloud network status data to be detected within a target time period;
[0142] The perspective transformation module is used to perform perspective transformation on the cloud network status data to be detected to obtain a graph neural network view from the perspective of the graph neural network inside the signal and a graph neural network view from the perspective of the graph neural network between signals;
[0143] The reconstruction module is used to input the graph neural network view from the perspective of the graph neural network inside the signal and the graph neural network view from the perspective of the graph neural network between signals into a target model to obtain target data, where the target model is obtained by iteratively training a first model with a target sample set, and the first model includes: an initial graph neural network inside the signal, an initial graph neural network between signals, an initial feature fusion network, and an initial reconstruction network;
[0144] The data detection module is used to determine the data detection result of the cloud network status data to be detected according to the error between the target data and the cloud network status data to be detected.
[0145] The above product can execute the method provided by any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method.
[0146] In the technical solution of this embodiment, by obtaining the cloud network status data to be detected within a target time period; performing perspective transformation on the cloud network status data to be detected to obtain a graph neural network view from the perspective of the graph neural network of the signal interior and a graph neural network view from the perspective of the graph neural network between signals; inputting the graph neural network view from the perspective of the graph neural network of the signal interior and the graph neural network view from the perspective of the graph neural network between signals into a target model to obtain target data, where the target model is obtained by iteratively training a first model with a target sample set, and the first model includes: an initial signal interior graph neural network, an initial signal between graph neural network, an initial feature fusion network, and an initial reconstruction network; determining a data detection result of the cloud network status data to be detected according to the error between the target data and the cloud network status data to be detected, which can improve the accuracy of data detection.
[0147] Embodiment III
[0148] Figure 7 FIG. shows a schematic structural diagram of an electronic device 10 that can be used to implement an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0149] As Figure 7 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., where the memory stores a computer program executable by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0150] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0151] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the data detection method.
[0152] In some embodiments, the data detection method can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the data detection method described above can be executed. Alternatively, in other embodiments, the processor 11 can be configured to execute the data detection method by any other suitable means (e.g., by means of firmware).
[0153] The various embodiments of the systems and technologies described above in this article can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs, which can be executed and / or interpreted on a programmable system including at least one programmable processor, the programmable processor can be a dedicated or general-purpose programmable processor, can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0154] A computer program for implementing the method of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general purpose computer, a special purpose computer, or other programmable data processing apparatus, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer program may be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0155] In the context of the present invention, a computer-readable storage medium may be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium may be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0156] In order to provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).
[0157] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected with each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0158] A computing system can include a client and a server. The client and the server are generally far from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0159] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0160] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. A data detection method, characterized in that, Including: Obtain the cloud network status data to be detected within the target time period; Perform perspective transformation on the cloud network status data to be detected to obtain a graph neural network view from the perspective of the graph neural network of the internal signals and a graph neural network view from the perspective of the graph neural network between signals; Input the graph neural network view from the perspective of the graph neural network of the internal signals and the graph neural network view from the perspective of the graph neural network between signals into the target model to obtain target data, where the target model is obtained by iteratively training the first model with a target sample set, and the first model includes: an initial graph neural network of internal signals, an initial graph neural network between signals, an initial feature fusion network, and an initial reconstruction network; Determine the data detection result of the cloud network status data to be detected according to the error between the target data and the cloud network status data to be detected; The target model includes: a target graph neural network of internal signals, a target graph neural network between signals, a target feature fusion network, and a target reconstruction network; Inputting the graph neural network view from the perspective of the graph neural network of the internal signals and the graph neural network view from the perspective of the graph neural network between signals into the target model to obtain target data includes: Input the graph neural network view from the perspective of the graph neural network of the internal signals into the target graph neural network of the internal signals for feature extraction to obtain internal signal features; Input the graph neural network view from the perspective of the graph neural network between signals into the target graph neural network between signals for feature extraction to obtain features between signals; Input the internal signal features and the features between signals into the target feature fusion network to obtain fused features; Input the fused features into the target reconstruction network to obtain target data.
2. The method according to claim 1, characterized in that, Performing perspective transformation on the time series data to be detected to obtain a graph neural network view from the perspective of the graph neural network of the internal signals and a graph neural network view from the perspective of the graph neural network between signals includes: Determine time nodes, features of time nodes, signal nodes, and features of signal nodes according to the cloud network status data to be detected; Generate a graph neural network view from the perspective of the graph neural network of the internal signals according to the time nodes and the features of the time nodes; Generate a graph neural network view from the perspective of the graph neural network between signals according to the signal nodes and the features of the signal nodes.
3. The method according to claim 2, wherein Determining time nodes, features of time nodes, signal nodes, and features of signal nodes according to the cloud network status data to be detected includes: Take each time point in the cloud network status data to be detected as a time node of the graph neural network, and take the signal corresponding to the time point as the feature of the time node; Take each signal in the cloud network status data to be detected as a signal node of the graph neural network, and take the data of the signal within the target time period as the feature of the signal node.
4. The method according to claim 1, wherein Iteratively training the first model with a target sample set includes: Obtain a target sample set, where the target sample set includes: an initial cloud network status data sample; Perform data augmentation on the initial cloud network status data sample to obtain a target cloud network status data sample; Perform perspective transformation on the initial cloud network status data sample to obtain a graph neural network view from the perspective of the first graph neural network of the internal signals and a graph neural network view from the perspective of the first graph neural network between signals; Perform perspective transformation on the target cloud network state data sample to obtain the graph neural network view from the perspective of the second signal internal graph neural network and the graph neural network view from the perspective of the graph neural network between the second signals; Input the graph neural network view from the perspective of the first signal internal graph neural network into the initial signal internal graph neural network to obtain the first signal internal feature; Input the graph neural network view from the perspective of the second signal internal graph neural network into the initial signal internal graph neural network to obtain the second signal internal feature; Input the graph neural network view from the perspective of the first signal between graph neural networks into the initial signal between graph neural networks to obtain the first signal between features; Input the graph neural network view from the perspective of the second signal between graph neural networks into the initial signal between graph neural networks to obtain the second signal between features; Determine the cross-view contrast loss according to the first signal internal feature, the second signal internal feature, the first signal between features, and the second signal between features; Determine the cross-network contrast loss according to the first signal internal feature and the first signal between features; Input the first signal internal feature and the first signal between features into the initial feature fusion network for feature fusion to obtain the initial fusion feature; Input the initial fusion feature into the initial reconstruction network to obtain the first data; Determine the reconstruction error loss according to the first data and the initial cloud network state data sample; Train the parameters of the first model according to the cross-view contrast loss, the cross-network contrast loss, and the reconstruction error loss; Return to perform the operation of data augmentation on the initial cloud network state data sample to obtain the target cloud network state data sample until the target model is obtained.
5. The method according to claim 4, wherein Determining the cross-view contrast loss according to the first signal internal feature, the second signal internal feature, the first signal between features, and the second signal between features includes: Determine the cross-view loss of the signal internal graph neural network according to the first signal internal feature and the second signal internal feature; Determine the cross-view loss of the signal between graph neural networks according to the first signal between features and the second signal between features; Determine the cross-view contrast loss according to the cross-view loss of the signal internal graph neural network and the cross-view loss of the signal between graph neural networks.
6. The method according to claim 4, wherein Performing data augmentation on the initial cloud network state data sample to obtain the target cloud network state data sample includes: Obtain the importance probability of each signal in the initial cloud network state data sample and / or the importance probability of the data corresponding to each time point; Mask the signal with the smallest importance probability and / or the data corresponding to the time point with the smallest importance probability in the initial cloud network state data sample to obtain the target cloud network state data sample.
7. A data detection device, characterized in that, Includes: A module for obtaining the cloud network state data to be detected, which is used to obtain the cloud network state data to be detected within the target time period; A perspective transformation module, which is used to perform perspective transformation on the cloud network state data to be detected to obtain the graph neural network view from the perspective of the signal internal graph neural network and the graph neural network view from the perspective of the graph neural network between signals; A reconstruction module, configured to input the graph neural network view from the perspective of the graph neural network inside the signal and the graph neural network view between the signals from the perspective of the graph neural network into a target model to obtain target data, where the target model is obtained by iteratively training a first model with a target sample set, and the first model includes: an initial graph neural network inside the signal, an initial graph neural network between the signals, an initial feature fusion network, and an initial reconstruction network; A data detection module, configured to determine a data detection result of the to-be-detected cloud network status data according to an error between the target data and the to-be-detected cloud network status data; The target model includes: a target graph neural network inside the signal, a target graph neural network between the signals, a target feature fusion network, and a target reconstruction network; Specifically, the reconstruction module is configured to: Input the graph neural network view from the perspective of the graph neural network inside the signal into the target graph neural network inside the signal for feature extraction to obtain features inside the signal; Input the graph neural network view from the perspective of the graph neural network between the signals into the target graph neural network between the signals for feature extraction to obtain features between the signals; Input the features inside the signal and the features between the signals into the target feature fusion network to obtain fused features; Input the fused features into the target reconstruction network to obtain target data.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the data detection method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and when the computer instructions are executed by a processor, the data detection method according to any one of claims 1-6 is implemented.
Citation Information
Patent Citations
Graph neural network training method, point cloud feature extraction method, equipment and medium
CN115424223A
Graph convolutional neural network clustering method based on multi-view structure
CN115952424A