Time series anomaly detection method, computer device and storage medium

CN117033975BActive Publication Date: 2026-09-29PURPLE MOUNTAIN LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311004050.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-10
Publication Date
2026-09-29
Estimated Expiration
2043-08-10

AI Technical Summary

Technical Problem

但是由于多维时间序列的长期与短期模式相互纠缠,因此对多维时间序列直接提取时间相关特征十分困难

Benefits of technology

[0051]上述时间序列异常检测方法、装置、计算机设备和存储介质,提取待检测时间序列的目标趋势性特征和目标季节性特征,然后再进行重构得到目标时间序列,后续继续待检测时间序列和所述目标时间序列进行异常检测,这样可以准确提取时间序列特征,相比传统的Transformer的深度异常检测方法可以直接提取到时间相关的目标趋势性特征和目标季节性特征,从而更加准确。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117033975B_ABST
    Figure CN117033975B_ABST
Patent Text Reader

Abstract

The application relates to a time series anomaly detection method and device, computer equipment and a storage medium. The method comprises the following steps: obtaining a time series to be detected; extracting a target trend feature and a target seasonal feature of the time series to be detected; reconstructing a time series based on the target trend feature and the target seasonal feature to obtain a target time series; and performing anomaly detection based on the time series to be detected and the target time series. The method can accurately extract time series features.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of artificial intelligence technology, and in particular to a method for detecting time series anomalies, a computer device, and a storage medium. Background Technology

[0002] Anomaly detection refers to identifying data that differs from normal data or significantly deviates from expected behavior, and it is a key task in monitoring the various states (indicators) of systems or services. In the field of operations and maintenance, the monitoring data of these systems or services are generally multi-dimensional time series, and anomalies often lack sufficient labels. Therefore, how to perform unsupervised anomaly detection on multi-dimensional time series is a very important task.

[0003] In recent years, the explosive growth of available raw data has made anomaly detection in multidimensional time series increasingly challenging. Unsupervised multidimensional time series anomaly detection solutions have been extensively studied in recent years. In early stages, researchers used parametric statistical forecasting methods to detect time series anomalies. The Autoregressive Differential Integrated Moving Average (ARIMA) model transforms non-stationary processes into stationary ones through differentiation, learning seasonal and trend characteristics in the time series. Other researchers have used classic machine learning techniques such as K-Means clustering, Support Vector Machines (SVM), or regression models to model time series distributions for anomaly detection. However, hand-designed low-level features often fail to represent high-dimensional data effectively, resulting in poor anomaly detection performance. With the rapid development and significant progress of deep neural networks, using advanced deep learning techniques to learn highly complex multidimensional time series has become an important research direction for anomaly detection.

[0004] For example, Transformer-based deep anomaly detection methods utilize self-attention mechanisms to model the long-term and short-term trends of time series. However, due to the entanglement of long-term and short-term patterns in multidimensional time series, directly extracting time-related features from multidimensional time series is extremely difficult. Summary of the Invention

[0005] Therefore, it is necessary to provide a time series anomaly detection method, apparatus, computer equipment, and storage medium that can accurately extract time series features and perform anomaly detection to address the above-mentioned technical problems.

[0006] In a first aspect, this application provides a method for detecting anomalies in time series data, the method comprising:

[0007] Obtain the time series to be detected;

[0008] Extract the target trend features and target seasonal features of the time series to be detected;

[0009] Based on the target trend characteristics and the target seasonal characteristics, the time series is reconstructed to obtain the target time series;

[0010] Anomaly detection is performed based on the time series to be detected and the target time series.

[0011] In one embodiment, extracting the target trend features and target seasonal features of the time series to be detected includes:

[0012] The time series to be detected is encoded using a self-attention mechanism that includes Fourier transform and inverse Fourier transform to obtain encoded seasonal features and encoded trend features.

[0013] Based on the encoded seasonality features and the encoded trend features, the target trend features and target seasonality features are obtained by decoding through a self-attention mechanism that includes Fourier transform and inverse Fourier transform.

[0014] In one embodiment, encoding the time series to be detected to obtain encoded seasonal features and encoded trend features includes:

[0015] The first seasonal feature is obtained by decomposing the time series to be detected;

[0016] The first seasonal feature is processed using Fourier transform and inverse Fourier transform to obtain the input for the encoding attention mechanism;

[0017] The output of the encoding attention mechanism is obtained based on the input of the encoding attention mechanism;

[0018] The output of the encoding attention mechanism is decomposed to obtain the second seasonal feature and the encoding trend feature;

[0019] The second seasonal feature is output-mapped to obtain the encoded seasonal feature.

[0020] In one embodiment, the step of decoding based on the encoded seasonality feature and the encoded trend feature to obtain the target trend feature and the target seasonality feature includes:

[0021] The third seasonal feature is obtained by decomposing the encoded seasonal feature;

[0022] The third seasonal feature is processed using Fourier transform and inverse Fourier transform to obtain the input for the decoding attention mechanism;

[0023] The output of the decoding attention mechanism is obtained based on the input of the decoding attention mechanism;

[0024] Based on the output of the decoding attention mechanism, the decoded seasonal features are obtained; based on the output of the decoding attention mechanism and the encoded trend features, the target trend features are obtained.

[0025] In one embodiment, obtaining decoded seasonal features based on the output of the decoding attention mechanism, and obtaining target trend features based on the output of the decoding attention mechanism and the encoded trend features, includes:

[0026] The output of the decoding attention mechanism is decomposed to obtain a fourth seasonal feature and a first trend feature;

[0027] The fifth seasonal feature is obtained by mapping the output of the fourth seasonal feature.

[0028] The fifth seasonal characteristic is decomposed to obtain the target seasonal characteristic and the second trend characteristic;

[0029] The target trend feature is obtained based on the encoded trend feature, the first trend feature, and the second trend feature.

[0030] In one embodiment, the anomaly detection based on the time series to be detected and the target time series includes:

[0031] Obtain the difference between the time series to be detected and the target time series at corresponding times;

[0032] Anomaly detection is performed on the time series to be detected based on the difference.

[0033] In one embodiment, after obtaining the time series to be detected, the method further includes:

[0034] Obtain the statistical values ​​of the time series to be detected;

[0035] The time series to be detected is standardized based on the mathematical statistical values.

[0036] In one embodiment, after obtaining the time series to be detected, the method further includes:

[0037] The time series to be detected is segmented into a window to obtain a time series window;

[0038] The extraction of the target trend features and target seasonal features of the time series to be detected includes:

[0039] Extract the target trend features and target seasonality features for each of the time series windows;

[0040] The process of reconstructing the time series based on the target trend characteristics and the target seasonal characteristics to obtain the target time series includes:

[0041] Each time series window is reconstructed based on its target trend characteristics and target seasonality characteristics.

[0042] Based on the reconstructed time series window, the target time series is obtained.

[0043] Secondly, this application also provides a time series anomaly detection device, the device comprising:

[0044] The time series acquisition module is used to acquire the time series to be detected;

[0045] The feature extraction module is used to extract the target trend features and target seasonal features of the time series to be detected;

[0046] The reconstruction module is used to reconstruct the time series based on the target trend characteristics and the target seasonal characteristics to obtain the target time series.

[0047] The detection module is used to perform anomaly detection based on the time series to be detected and the target time series.

[0048] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method in any of the above embodiments.

[0049] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the methods in any of the above embodiments.

[0050] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the methods in any of the above embodiments.

[0051] The aforementioned time series anomaly detection method, apparatus, computer equipment, and storage medium extract the target trend features and target seasonal features of the time series to be detected, and then reconstruct the target time series. Subsequently, anomaly detection is performed on the time series to be detected and the target time series. This can accurately extract time series features. Compared with the traditional Transformer deep anomaly detection method, it can directly extract time-related target trend features and target seasonal features, thus being more accurate. Attached Figure Description

[0052] Figure 1This is a flowchart illustrating a time series anomaly detection method in one embodiment;

[0053] Figure 2 This is a flowchart illustrating the encoding steps in one embodiment;

[0054] Figure 3 This is a schematic diagram of the structure of an artificial intelligence network model in one embodiment;

[0055] Figure 4 This is a schematic diagram of the structure of an encoding self-attention subunit or a decoding self-attention subunit in one embodiment;

[0056] Figure 5 This is a flowchart illustrating the decoding steps in one embodiment;

[0057] Figure 6 This is a structural block diagram of a time series anomaly detection device in one embodiment;

[0058] Figure 7 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0059] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0060] In one embodiment, such as Figure 1 As shown, a time series anomaly detection method is provided. This embodiment illustrates the method's application to a terminal, but it is understood that the method can also be applied to a server, or to a system including both a terminal and a server, and is implemented through interaction between the terminal and the server. The terminal can be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, etc. Portable wearable devices can include smartwatches, smart bracelets, head-mounted devices, etc. The server can be a standalone server or a server cluster consisting of multiple servers. In this embodiment, the method includes the following steps:

[0061] S102: Obtain the time series to be detected.

[0062] Specifically, the time series to be detected is the time series for which anomaly detection is required. This time series to be detected can be a multidimensional time series, for example, a multidimensional time series X∈R. w×m , where R is a vector representation of the time series to be detected, w represents the length of the multidimensional time series, and m represents the dimension of the multidimensional time series.

[0063] In some optional embodiments, after obtaining the time series to be detected, the method further includes: preprocessing the time series to be detected. The preprocessing includes: obtaining statistical values ​​of the data from the time series to be detected; and standardizing the time series to be detected based on the mathematical statistical values.

[0064] Specifically, the process of preprocessing the time series to be detected is the process of standardizing the time series to be detected, so as to obtain standardized data.

[0065] Specifically, for the original time series X to be detected, the mean u and variance σ of the time series are calculated. The time series is then processed using the Z-score normalization method. The formula for Z-score normalization is shown below:

[0066]

[0067] Where x represents each point in the original time series to be detected before processing, u represents the mean of the time series to be detected, σ represents the variance of the time series to be detected, and x′ represents each point in the time series to be detected after standardization.

[0068] In some optional embodiments, after obtaining the time series to be detected, the method further includes: performing window segmentation on the time series to be detected to obtain a time series window.

[0069] Window segmentation refers to dividing the standardized time series to be detected into windows to obtain time series windows. Subsequently, each time series window can be processed in parallel, thereby improving processing efficiency.

[0070] Specifically, the window length is set to p, and the time series to be detected is divided into k consecutive windows. A time series window ending at time t can be represented as: w t =[x t-p+1 ,…,x t The window sequence ending at time t is: W t =[w t-(k-1)×p ,w t-(k-2)×p ,…,w t ].

[0071] S104: Extract the target trend features and target seasonal features of the time series to be detected.

[0072] Trend characteristics refer to the monotonicity of the time series to be detected within a certain period of time. Generally, the slope is fixed, meaning that the data shows an upward or downward trend within a certain period of time. Target trend characteristics refer to the trend characteristics of the time series to be detected obtained after model processing. Optionally, this includes the trend characteristics of the time series corresponding to each time series window.

[0073] Seasonal characteristics refer to the changes in a time series under test over a fixed period of time, much like the four seasons of a year. Target seasonal characteristics refer to the seasonal features of the time series under test obtained after model processing, and optionally include the seasonal features of the time series corresponding to each time series window.

[0074] The process of extracting the target trend features and target seasonal features of the time series to be detected includes extracting the target trend features and target seasonal features for each time series window. This windowing of the time series to be detected allows for parallel processing of the time series in each window, improving efficiency.

[0075] The extraction of target trend and seasonal features from the time series to be detected can be achieved using a pre-trained artificial intelligence model. This AI model can be a deep learning model, which is embedded in the extraction process to achieve deep joint optimization. Compared to traditional recurrent neural networks, this approach offers advantages such as simpler structure, faster speed, and parallelizable computation. The performance of the anomaly detection model is evaluated based on metrics such as P (Precision) and R (Recall). If the model meets the requirements, it is used in practical processing.

[0076] This deep learning model improves upon the original Transformer architecture, transforming it into a deep decomposition architecture, primarily comprising an Auto-Attention module, a Decompose module, and a Feed Forward Network (FFN). The improved Transformer method not only extracts periodic signal features from time series more effectively but also learns long-term trend changes within the time series, thereby enhancing anomaly detection performance in multidimensional time series.

[0077] S106: Based on the target trend characteristics and target seasonal characteristics, reconstruct the time series to obtain the target time series.

[0078] Specifically, based on the target trend characteristics and target seasonality characteristics, the time series is reconstructed to obtain the target time series, that is, the target trend characteristics and target seasonality characteristics corresponding to each time point are added together to obtain the target time series. The reconstruction of the time series based on the target trend characteristics and target seasonality characteristics includes: reconstructing each time series window based on the target trend characteristics and target seasonality characteristics of each time series window; and obtaining the target time series based on the reconstructed time series windows. The reconstruction of each time series window can be performed by processing each time series window in parallel, and by adding the target trend characteristics and target seasonality characteristics corresponding to each time point in each time series window in parallel to obtain the target time series.

[0079] Specifically, the reconstruction formula is as follows:

[0080]

[0081] in, To reconstruct the target time series, Targeting seasonal characteristics, For the target trend feature, l represents the number of layers in the encoder and decoder.

[0082] S108: Anomaly detection is performed based on the time series to be detected and the target time series.

[0083] Anomaly detection is based on the time series to be detected and the target time series. For example, the time series to be detected and the target time series are compared to obtain the difference between the two, and anomaly detection is performed based on the difference between the two.

[0084] In one optional embodiment, anomaly detection is performed based on the time series to be detected and the target time series, including: obtaining the difference between the corresponding times of the time series to be detected and the target time series; and performing anomaly detection on the time series to be detected based on the difference.

[0085] Specifically, define the scoring function s t Abnormal behavior is identified by summing the reconstruction errors over time t, and the calculation formula is as follows:

[0086]

[0087] in The reconstructed value corresponding to time t, i.e., the value of t in the target time series, x t`i` is the input value at time `t`, i.e., the value at time `t` in the original time series to be detected. `i` is a variable whose value ranges from 1 to `m`, where `i` is an integer and `m` is the dimension of the time series. A threshold can be set here; when the score exceeds the threshold, the data point at the corresponding time in the time series to be detected is judged as abnormal; otherwise, it is considered a normal value.

[0088] The above-mentioned time series anomaly detection method extracts the target trend features and target seasonal features of the time series to be detected, and then reconstructs them to obtain the target time series. Subsequently, anomaly detection is performed on the time series to be detected and the target time series. This method can accurately extract time series features and perform anomaly detection. Compared with traditional recurrent neural networks, it has advantages such as simpler structure, faster speed, and parallelizable computation.

[0089] In one embodiment, extracting the target trend features and target seasonal features of the time series to be detected includes: encoding the time series to be detected using a self-attention mechanism including Fourier transform and inverse Fourier transform to obtain encoded seasonal features and encoded trend features; and decoding the encoded seasonal features and encoded trend features using a self-attention mechanism including Fourier transform and inverse Fourier transform to obtain the target trend features and target seasonal features.

[0090] Specifically, in this embodiment, the time series to be detected is first encoded to obtain encoded seasonal features and encoded trend features, and then the encoded seasonal features and encoded trend features are decoded to obtain target trend features and target seasonal features.

[0091] The encoding and decoding processes both incorporate a self-attention mechanism, which uses Fast Fourier Transform (FFT) and Inverse Fourier Transform to extract periodic information features from multidimensional time series. Compared with methods based on Variational Autoencoder (VAE), this mechanism can more effectively model long-term trends in time series.

[0092] In one optional embodiment, the encoding and decoding processes are implemented by improving the original Transformer structure and transforming it into a deep decomposition architecture, mainly including an Auto-Attention module, a Decompose module, and a Feed Forward Network (FFN) module. The Auto-Attention module is further improved by using Fast Fourier Transform (FFT) and Inverse Fourier Transform. The improved Transformer structure can not only extract periodic signal features from the time series more effectively, but also learn the long-term trend changes in the time series, thereby improving the anomaly detection effect of multidimensional time series.

[0093] In one embodiment, combined Figure 2 As shown, Figure 2 This is a flowchart of the encoding steps in one embodiment, combined with Figure 3 , Figure 3 This is a schematic diagram of the structure of an artificial intelligence network model in one embodiment. Encoding the time series to be detected to obtain encoded seasonal features and encoded trend features is achieved by the encoding module of the artificial intelligence network model. The encoding module includes at least one encoding unit, which includes an encoding self-attention subunit, an encoding decomposition subunit, and an encoding feedforward network subunit.

[0094] Specifically, assuming the encoding module includes N encoding units, the input of the l-th encoder layer is... The output is The input to the first coding layer is the time series to be detected, and the input to subsequent coding layers is the output of the previous coding layer, that is, the encoded seasonal features output by the previous coding layer. The l-th encoder layer, i.e., the l-th coding unit, can be defined as:

[0095]

[0096] The calculation formula is as follows:

[0097]

[0098]

[0099]

[0100] Where Auto_attention(·) represents the automatic attention function, Decomp(·) represents the temporal decomposition function, and FFN(·) represents the feedforward network function.

[0101] The specific calculation process is as follows:

[0102] Specifically, the encoding steps, namely encoding the time series to be detected to obtain encoded seasonal features and encoded trend features, include:

[0103] S202: Decompose the time series to be detected to obtain the first seasonal feature.

[0104] The input of the l-th encoder layer The input is fed into the automatic attention function and superimposed with the original time series to be detected. Obtain the output of the corresponding encoding attention mechanism

[0105]

[0106] Where Auto_attention(·) represents the automatic attention function, which is defined as follows:

[0107] For any input X, Auto_attention(·) can be formalized as:

[0108] X s ,X t =Decomp(X)

[0109] K = Q = Γ(X) s )

[0110] D s =Γ -1 (Topk(Concat(K,Q)))

[0111] M s =Attention(D s D s D s )

[0112] Auto_attention(X s )=LN(M s (7)

[0113] Where Decomp(·) represents the time series decomposition function, which decomposes the time series to be detected into the first seasonal feature and the corresponding trend feature. For any input X, the time series decomposition process can be formalized as follows:

[0114] X t =MA(X)

[0115] X s =XX t (8)

[0116] Where Xs X t Let X represent the first seasonal characteristic and the corresponding trend characteristic, respectively, and MA(·) represent the moving average function. First seasonal characteristic X s The periodicity characteristic representing the original complex multidimensional time series, and the corresponding trend characteristic X. t This reflects the long-term trend of the sequence. In the following text, X will be used... s ,X t =Decomp(X) to replace formula (8).

[0117] S204: The first seasonal feature is processed based on Fourier transform and inverse Fourier transform to obtain the input for the encoding attention mechanism.

[0118] Specifically, K and Q represent the inputs to the attention mechanism, and here we choose the first seasonal feature X. s The result of the Fast Fourier Transform (FFT) Γ(X) s ) serves as the input to the attention mechanism. Since this embodiment employs a self-attention mechanism, K = Q = Γ(X) s For the first seasonal feature X) s The Fast Fourier Transform (FFT) is defined as follows:

[0119]

[0120] Concat(·) is a concatenation operation. Concat(K,Q) means concatenating K and Q.

[0121] The Topk() function is used to sort data and select the top k values. Where c is a hyperparameter.

[0122] Γ -1 () indicates performing an inverse Fourier transform on the data. The result H obtained from the FFT... m The inverse Fourier transform is defined as follows:

[0123]

[0124] Here D s The result is the inverse Fourier transform. Here, the self-attention mechanism uses the fast Fourier transform and the inverse Fourier transform to expand the time series in the time domain and frequency domain, which can extract the periodic features of the time series.

[0125] S206: The input of the encoding attention mechanism yields the output of the encoding attention mechanism.

[0126] Attention() represents the self-attention function, whose input is the inverse Fourier transform result D.s The calculation formula is as follows:

[0127]

[0128] Where d(k) represents D s The vector dimension. LN(·) represents the layer normalization function, which takes the output M of the attention module as the vector dimension. s The input is fed into the layer normalization function, and finally the output of the automatic attention module, Auto_attention(X), is obtained. s ).

[0129] Optionally, the first seasonal feature is obtained by decomposing the time series to be detected using an encoded self-attention subunit; the first seasonal feature is then processed using Fourier transform and inverse Fourier transform to obtain the input of the encoded attention mechanism; and the output of the encoded attention mechanism is obtained based on the input of the encoded attention mechanism. The specific structure of the self-attention subunit can be found in [reference needed]. Figure 4 As shown.

[0130] S208: Decompose the output of the encoding attention mechanism to obtain the second seasonal feature and the encoding trend feature.

[0131] Specifically, the output of the automatic attention function of the l-th encoder layer The second seasonal feature and the encoded trend feature are obtained by performing time-series decomposition.

[0132]

[0133] in, This is the second seasonal characteristic. This is for encoding trend characteristics.

[0134] Optionally, the output of the encoding attention mechanism can be decomposed by encoding decomposition subunits to obtain the second seasonal feature and the encoding trend feature.

[0135] S210: Output mapping of the second seasonal feature yields the encoded seasonal feature.

[0136] Specifically, the second seasonal characteristic The input is fed into the feedforward network subunit (FFN) to obtain the output. The final output is obtained by superimposing a second seasonal feature.

[0137]

[0138] here, This is the output of the l-th encoder layer, which encodes seasonal features, i.e., the embedded features at each time step within the input window.

[0139] Optionally, the second seasonal feature is output-mapped through a coding feedforward network subunit, and the second seasonal feature is superimposed to obtain the coded seasonal feature.

[0140] In the above embodiments, a self-attention mechanism is introduced in the encoding process. This self-attention mechanism uses Fast Fourier Transform (FFT) and Inverse Fourier Transform to extract periodic information features in multidimensional time series. Compared with the method based on Variational Autoencoder (VAE), it can more effectively model the long-term trend in time series.

[0141] In one embodiment, combined Figure 5 As shown, Figure 5 The flowchart shows the decoding steps in one embodiment. The decoding is implemented by the decoding module of an artificial intelligence network model based on the target seasonality and target trend characteristics. The decoding module includes at least one decoding unit, which includes a decoding self-attention subunit, a first decoding decomposition subunit, a decoding feedforward network subunit, a second decoding decomposition subunit, and a connection subunit.

[0142] Assume the model has M decoder layers, and the input of the l-th decoder layer is... The output is The input to the first decoding layer is the output of the last encoding layer, and the input to subsequent decoding layers is the output of the previous decoding layer, i.e., the target seasonal feature output by the previous decoding layer. The l-th encoder layer can be defined as:

[0143]

[0144] The calculation formula is as follows:

[0145]

[0146]

[0147]

[0148]

[0149]

[0150] in This represents the output of the l-th decoder layer. Let W1 and W2 represent the seasonality and trend characteristics after the i-th time series decomposition at level l, respectively. W1 and W2 represent the weight parameters of the first and second trend characteristics.

[0151] Specifically, this decoding step, which involves decoding based on the encoded seasonal and trend characteristics to obtain the target trend and seasonal characteristics, includes:

[0152] S502: The third seasonal feature is obtained by decomposing the encoded seasonal features.

[0153] S504: The third seasonal feature is processed based on Fourier transform and inverse Fourier transform to obtain the input for the decoding attention mechanism.

[0154] S506: The input of the decoding attention mechanism is used to obtain the output of the decoding attention mechanism.

[0155] Specifically, the input of the l-th decoder layer The input is fed into the automatic attention module, where it is superimposed on the output of the previous layer to obtain the corresponding output. The calculation process is as follows:

[0156]

[0157] Here, Auto_attention(·) represents the automatic attention function, the detailed definition of which can be found in the automatic attention function of the encoding unit, and will not be repeated here.

[0158] Specifically, the third seasonal feature is obtained by decomposing the encoded seasonal feature through the decoding self-attention subunit; the third seasonal feature is processed based on Fourier transform and inverse Fourier transform to obtain the input of the decoding attention mechanism; and the output of the decoding attention mechanism is obtained based on the input of the decoding attention mechanism.

[0159] After obtaining the output of the decoding attention mechanism, the terminal obtains the decoded seasonal features based on the output of the decoding attention mechanism, and obtains the target trend features based on the output of the decoding attention mechanism and the encoded trend features. Specifically:

[0160] S508: The output of the decoding attention mechanism is decomposed to obtain the fourth seasonal feature and the first trend feature.

[0161] The output of the automatic attention function of the l-th decoder layer Perform time-series decomposition operations.

[0162]

[0163] Here, Decomp(·) represents the time series decomposition function, which can be found in the previous section for details. This is the fourth seasonal feature obtained from the first time series decomposition. This represents the first trend feature after the first time series decomposition.

[0164] Specifically, the output of the decoding attention mechanism is decomposed by the first decoding decomposition subunit to obtain the fourth seasonal feature and the first trend feature;

[0165] S510: The output mapping of the fourth seasonal feature is used to obtain the fifth seasonal feature.

[0166] The fourth seasonal characteristic obtained from the first time series decomposition The input is fed into a feedforward network (FFN) to obtain the fifth seasonal feature.

[0167]

[0168] Specifically, the fifth seasonal feature is obtained by decoding the output mapping of the fourth seasonal feature through the feedforward network subunit.

[0169] S512: Decompose the fifth seasonal feature to obtain the decoded seasonal feature and the second trend feature.

[0170] Specifically, the fifth seasonal characteristic of the above-mentioned feedforward network output. Perform a second time series decomposition.

[0171]

[0172] in, This represents the seasonal characteristics obtained after the second time series decomposition. This represents the trend characteristics after the second time series decomposition.

[0173] here, This is the output of the l-th decoder layer, which is the reconstruction result of the embedded features at each time step in the window.

[0174] Specifically, the fifth seasonal feature is decomposed into the second seasonal feature and the second trend feature by the second decoding decomposition subunit.

[0175] S514: Decoding trend features are obtained based on encoding trend features, first trend features, and second trend features.

[0176] Specifically, the encoding trend features in the encoder layer Trend features in decoder layer and Summing them up, we get:

[0177]

[0178] in, Let W1 and W2 represent the seasonality and trend features after the i-th time series decomposition of the l-th layer, respectively. W1 and W2 represent the weight parameters of the first and second trend features of the decoder.

[0179] Specifically, decoding trend features are obtained by connecting subunits based on encoding trend features, first trend features, and second trend features.

[0180] In the above embodiments, a self-attention mechanism is introduced in the decoding process. This self-attention mechanism uses Fast Fourier Transform (FFT) and Inverse Fourier Transform to extract periodic information features in multidimensional time series. Compared with the method based on Variational Autoencoder (VAE), it can more effectively model the long-term trend in time series.

[0181] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0182] Based on the same inventive concept, this application also provides a time series anomaly detection device for implementing the time series anomaly detection method described above. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more time series anomaly detection device embodiments provided below can be found in the limitations of the time series anomaly detection method described above, and will not be repeated here.

[0183] In one embodiment, such as Figure 6 As shown, a time series anomaly detection device is provided, comprising: a time series acquisition module 601, a feature extraction module 602, a reconstruction module 603, and a detection module 604, wherein:

[0184] The time series acquisition module 601 is used to acquire the time series to be detected.

[0185] Feature extraction module 602 is used to extract the target trend features and target seasonal features of the time series to be detected;

[0186] Reconstruction module 603 is used to reconstruct the time series based on the target trend characteristics and the target seasonal characteristics to obtain the target time series;

[0187] The detection module 604 is used for anomaly detection based on the time series to be detected and the target time series.

[0188] In one embodiment, the feature extraction module 602 includes:

[0189] The encoding module is used to encode the time series to be detected using a self-attention mechanism that includes Fourier transform and inverse Fourier transform, so as to obtain encoded seasonal features and encoded trend features.

[0190] The decoding module is used to decode the target trend features and target seasonal features based on the encoded seasonal features and encoded trend features through a self-attention mechanism including Fourier transform and inverse Fourier transform.

[0191] In one embodiment, the above-mentioned encoding module is used to decompose the time series to be detected to obtain a first seasonal feature; process the first seasonal feature based on Fourier transform and inverse Fourier transform to obtain the input of the encoding attention mechanism; obtain the output of the encoding attention mechanism based on the input of the encoding attention mechanism; decompose the output of the encoding attention mechanism to obtain a second seasonal feature and an encoding trend feature; and perform output mapping on the second seasonal feature to obtain the encoding seasonal feature.

[0192] In one embodiment, the decoding module is used to decompose the encoded seasonal features to obtain a third seasonal feature; process the third seasonal feature based on Fourier transform and inverse Fourier transform to obtain the input of the decoding attention mechanism; obtain the output of the decoding attention mechanism based on the input of the decoding attention mechanism; obtain the decoded seasonal feature based on the output of the decoding attention mechanism; and obtain the target trend feature based on the output of the decoding attention mechanism and the encoded trend feature.

[0193] In one embodiment, the above-mentioned decoding seasonal features are obtained from the output of the decoding attention mechanism, and the target trend features are obtained from the output of the decoding attention mechanism and the encoded trend features, including: decomposing the output of the decoding attention mechanism to obtain a fourth seasonal feature and a first trend feature; mapping the output of the fourth seasonal feature to obtain a fifth seasonal feature; decomposing the fifth seasonal feature to obtain a decoded seasonal feature and a second trend feature; and obtaining the decoded trend features based on the encoded trend features, the first trend feature, and the second trend feature.

[0194] In one embodiment, the detection module 604 is further configured to obtain the difference between the time series to be detected and the target time series at corresponding times; and to perform anomaly detection on the time series to be detected based on the difference.

[0195] In one embodiment, the above-mentioned time series anomaly detection device further includes a preprocessing module, which is used to preprocess the time series to be detected; the preprocessing includes: obtaining the data statistics of the time series to be detected; and standardizing the time series to be detected based on the mathematical statistics.

[0196] In one embodiment, the time series anomaly detection device further includes a window segmentation module, which is used to segment the time series to be detected into time series windows; thereby, the feature extraction module is also used to extract the target trend features and target seasonal features of each time series window; the reconstruction module is also used to reconstruct each time series window based on the target trend features and target seasonal features of each time series window; and based on the reconstructed time series windows, the target time series is obtained.

[0197] Each module in the aforementioned time series anomaly detection device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of a computer device in software form, so that the processor can call and execute the operations corresponding to each module.

[0198] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 7As shown, the computer device includes a processor, memory, input / output interface, communication interface, display unit, and input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interface. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The input / output interface is used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When executed by the processor, the computer program implements a time-series anomaly detection method. The display unit is used to form a visually visible image and can be a display screen, projection device, or virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.

[0199] Those skilled in the art will understand that Figure 7 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0200] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to perform the following steps: acquiring a time series to be detected; extracting target trend features and target seasonal features from the time series to be detected; reconstructing the time series based on the target trend features and target seasonal features to obtain a target time series; and performing anomaly detection based on the time series to be detected and the target time series.

[0201] In one embodiment, the extraction of target trend features and target seasonal features of a time series to be detected by the processor executing a computer program includes: encoding the time series to be detected to obtain encoded seasonal features and encoded trend features through a self-attention mechanism including Fourier transform and inverse Fourier transform; and decoding the encoded seasonal features and encoded trend features to obtain target trend features and target seasonal features through a self-attention mechanism including Fourier transform and inverse Fourier transform.

[0202] In one embodiment, the encoding of the time series to be detected to obtain encoded seasonal features and encoded trend features implemented by the processor when executing the computer program includes: decomposing the time series to be detected to obtain a first seasonal feature; processing the first seasonal feature based on Fourier transform and inverse Fourier transform to obtain the input of the encoding attention mechanism; obtaining the output of the encoding attention mechanism based on the input of the encoding attention mechanism; decomposing the output of the encoding attention mechanism to obtain a second seasonal feature and encoded trend features; and mapping the output of the second seasonal feature to obtain the encoded seasonal feature.

[0203] In one embodiment, the decoding of target trend features and target seasonal features based on encoded seasonal features and encoded trend features, implemented by the processor when executing a computer program, includes: decomposing the encoded seasonal features to obtain a third seasonal feature; processing the third seasonal feature based on Fourier transform and inverse Fourier transform to obtain the input of the decoding attention mechanism; obtaining the output of the decoding attention mechanism based on the input of the decoding attention mechanism; obtaining the decoded seasonal feature based on the output of the decoding attention mechanism; and obtaining the target trend feature based on the output of the decoding attention mechanism and the encoded trend features.

[0204] In one embodiment, when a processor executes a computer program, the output based on a decoding attention mechanism is used to obtain a decoded seasonal feature, and the output of the decoding attention mechanism and the encoded trend feature are used to obtain a target trend feature, including: decomposing the output of the decoding attention mechanism to obtain a fourth seasonal feature and a first trend feature; mapping the output of the fourth seasonal feature to obtain a fifth seasonal feature; decomposing the fifth seasonal feature to obtain a decoded seasonal feature and a second trend feature; and obtaining a decoded trend feature based on the encoded trend feature, the first trend feature, and the second trend feature.

[0205] In one embodiment, the anomaly detection based on a time series to be detected and a target time series implemented by the processor when executing a computer program includes: obtaining the difference between corresponding moments of the time series to be detected and the target time series; and performing anomaly detection on the time series to be detected based on the difference.

[0206] In one embodiment, after the processor executes the computer program to acquire the time series to be detected, the method further includes: acquiring the data statistics of the time series to be detected; and standardizing the time series to be detected based on the mathematical statistics.

[0207] In one embodiment, after the processor acquires the time series to be detected when executing the computer program, the method further includes: segmenting the time series to be detected into windows to obtain time series windows. Extracting target trend features and target seasonality features of the time series to be detected, as implemented by the processor executing the computer program, includes: extracting target trend features and target seasonality features for each time series window; reconstructing the time series based on the target trend features and target seasonality features to obtain the target time series, as implemented by the processor executing the computer program, includes: reconstructing each time series window based on the target trend features and target seasonality features for each time series window; and obtaining the target time series based on the reconstructed time series windows.

[0208] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, performs the following steps: acquiring a time series to be detected; extracting target trend features and target seasonal features from the time series to be detected; reconstructing the time series based on the target trend features and target seasonal features to obtain a target time series; and performing anomaly detection based on the time series to be detected and the target time series.

[0209] In one embodiment, the extraction of target trend features and target seasonal features of a time series to be detected by the computer program when executed by a processor includes: encoding the time series to be detected to obtain encoded seasonal features and encoded trend features through a self-attention mechanism including Fourier transform and inverse Fourier transform; and decoding the encoded seasonal features and encoded trend features to obtain target trend features and target seasonal features through a self-attention mechanism including Fourier transform and inverse Fourier transform.

[0210] In one embodiment, when a computer program is executed by a processor, it encodes a time series to be detected to obtain encoded seasonal features and encoded trend features, including: decomposing the time series to be detected to obtain a first seasonal feature; processing the first seasonal feature based on Fourier transform and inverse Fourier transform to obtain the input of an encoding attention mechanism; obtaining the output of the encoding attention mechanism based on the input of the encoding attention mechanism; decomposing the output of the encoding attention mechanism to obtain a second seasonal feature and encoded trend features; and mapping the second seasonal feature to obtain encoded seasonal features.

[0211] In one embodiment, when a computer program is executed by a processor, it decodes the encoded seasonal features and encoded trend features to obtain target trend features and target seasonal features, including: decomposing the encoded seasonal features to obtain a third seasonal feature; processing the third seasonal feature based on Fourier transform and inverse Fourier transform to obtain the input of the decoding attention mechanism; obtaining the output of the decoding attention mechanism based on the input of the decoding attention mechanism; obtaining the decoded seasonal feature based on the output of the decoding attention mechanism; and obtaining the target trend feature based on the output of the decoding attention mechanism and the encoded trend features.

[0212] In one embodiment, when a computer program is executed by a processor, the output based on a decoding attention mechanism is used to obtain a decoded seasonal feature, and the output of the decoding attention mechanism and the encoded trend feature are used to obtain a target trend feature, including: decomposing the output of the decoding attention mechanism to obtain a fourth seasonal feature and a first trend feature; mapping the output of the fourth seasonal feature to obtain a fifth seasonal feature; decomposing the fifth seasonal feature to obtain a decoded seasonal feature and a second trend feature; and obtaining a decoded trend feature based on the encoded trend feature, the first trend feature, and the second trend feature.

[0213] In one embodiment, the anomaly detection based on a time series to be detected and a target time series implemented when the computer program is executed by a processor includes: obtaining the difference between corresponding moments of the time series to be detected and the target time series; and performing anomaly detection on the time series to be detected based on the difference.

[0214] In one embodiment, after the computer program is executed by the processor to acquire the time series to be detected, it further includes: acquiring the data statistics of the time series to be detected; and standardizing the time series to be detected based on the mathematical statistics.

[0215] In one embodiment, after the computer program, when executed by the processor, acquires the time series to be detected, the method further includes: segmenting the time series to be detected into windows to obtain time series windows. Extracting target trend features and target seasonality features of the time series to be detected, as implemented by the computer program, when executed by the processor, includes: extracting target trend features and target seasonality features for each time series window; reconstructing the time series based on the target trend features and target seasonality features to obtain the target time series, as implemented by the computer program, when executed by the processor, includes: reconstructing each time series window based on the target trend features and target seasonality features for each time series window; and obtaining the target time series based on the reconstructed time series windows.

[0216] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps: acquiring a time series to be detected; extracting target trend features and target seasonal features from the time series to be detected; reconstructing the time series based on the target trend features and target seasonal features to obtain a target time series; and performing anomaly detection based on the time series to be detected and the target time series.

[0217] In one embodiment, the extraction of target trend features and target seasonal features of a time series to be detected by the computer program when executed by a processor includes: encoding the time series to be detected to obtain encoded seasonal features and encoded trend features through a self-attention mechanism including Fourier transform and inverse Fourier transform; and decoding the encoded seasonal features and encoded trend features to obtain target trend features and target seasonal features through a self-attention mechanism including Fourier transform and inverse Fourier transform.

[0218] In one embodiment, when a computer program is executed by a processor, it encodes a time series to be detected to obtain encoded seasonal features and encoded trend features, including: decomposing the time series to be detected to obtain a first seasonal feature; processing the first seasonal feature based on Fourier transform and inverse Fourier transform to obtain the input of an encoding attention mechanism; obtaining the output of the encoding attention mechanism based on the input of the encoding attention mechanism; decomposing the output of the encoding attention mechanism to obtain a second seasonal feature and encoded trend features; and mapping the second seasonal feature to obtain encoded seasonal features.

[0219] In one embodiment, when a computer program is executed by a processor, it decodes the encoded seasonal features and encoded trend features to obtain target trend features and target seasonal features, including: decomposing the encoded seasonal features to obtain a third seasonal feature; processing the third seasonal feature based on Fourier transform and inverse Fourier transform to obtain the input of the decoding attention mechanism; obtaining the output of the decoding attention mechanism based on the input of the decoding attention mechanism; obtaining the decoded seasonal feature based on the output of the decoding attention mechanism; and obtaining the target trend feature based on the output of the decoding attention mechanism and the encoded trend features.

[0220] In one embodiment, when a computer program is executed by a processor, the output based on a decoding attention mechanism is used to obtain a decoded seasonal feature, and the output of the decoding attention mechanism and the encoded trend feature are used to obtain a target trend feature, including: decomposing the output of the decoding attention mechanism to obtain a fourth seasonal feature and a first trend feature; mapping the output of the fourth seasonal feature to obtain a fifth seasonal feature; decomposing the fifth seasonal feature to obtain a decoded seasonal feature and a second trend feature; and obtaining a decoded trend feature based on the encoded trend feature, the first trend feature, and the second trend feature.

[0221] In one embodiment, the anomaly detection based on a time series to be detected and a target time series implemented when the computer program is executed by a processor includes: obtaining the difference between corresponding moments of the time series to be detected and the target time series; and performing anomaly detection on the time series to be detected based on the difference.

[0222] In one embodiment, after the computer program is executed by the processor to acquire the time series to be detected, it further includes: acquiring the data statistics of the time series to be detected; and standardizing the time series to be detected based on the mathematical statistics.

[0223] In one embodiment, after the computer program, when executed by the processor, acquires the time series to be detected, the method further includes: segmenting the time series to be detected into windows to obtain time series windows. Extracting target trend features and target seasonality features of the time series to be detected, as implemented by the computer program, when executed by the processor, includes: extracting target trend features and target seasonality features for each time series window; reconstructing the time series based on the target trend features and target seasonality features to obtain the target time series, as implemented by the computer program, when executed by the processor, includes: reconstructing each time series window based on the target trend features and target seasonality features for each time series window; and obtaining the target time series based on the reconstructed time series windows.

[0224] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0225] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0226] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A method for detecting anomalies in time series data, characterized in that, The method includes: Obtain the time series to be detected; Extract the target trend features and target seasonal features of the time series to be detected in the time domain; Based on the target trend characteristics and the target seasonal characteristics, the time series is reconstructed to obtain the target time series; Anomaly detection is performed based on the time series to be detected and the target time series; The extraction of the target trend features and target seasonal features of the time series to be detected includes: The time series to be detected is encoded through multiple encoder layers to obtain encoded seasonal features and encoded trend features. Each encoder layer includes a self-attention mechanism of Fourier transform and inverse Fourier transform. The input of the first encoder layer is the time series to be detected, and the input of the subsequent encoder layers is the output of the previous encoder layer. The input of each encoder layer is fed into the self-attention mechanism and superimposed with the time series to be detected to obtain the output of each encoder layer. Based on the encoded seasonality features and the encoded trend features, the target trend features and target seasonality features are obtained by decoding through a self-attention mechanism including Fourier transform and inverse Fourier transform; Each encoder layer encodes the time series to be detected to obtain encoded seasonal features and encoded trend features, including: The first seasonal feature is obtained by decomposing the input of the encoder layer; The frequency domain signal obtained by performing Fourier transform processing on the first seasonal feature based on Fourier transform is used as each input of the self-attention mechanism, and the inputs of the self-attention mechanism are connected. The data obtained from the connection processing is frequency-filtered to obtain the top k values, and the filtered data is subjected to inverse Fourier transform to obtain the inverse Fourier transform result. The output of the self-attention mechanism is obtained by processing the inverse Fourier transform result through the self-attention mechanism. The output of the self-attention mechanism is decomposed to obtain the second seasonal feature and the encoded trend feature; The second seasonal feature is output-mapped to obtain the encoded seasonal feature.

2. The method according to claim 1, characterized in that, The step of decoding based on the encoded seasonality features and the encoded trend features to obtain the target trend features and target seasonality features includes: The third seasonal feature is obtained by decomposing the encoded seasonal feature; The third seasonal feature is processed using Fourier transform and inverse Fourier transform to obtain the input for the decoding attention mechanism; The output of the decoding attention mechanism is obtained based on the input of the decoding attention mechanism; Based on the output of the decoding attention mechanism, the decoded seasonal features are obtained, and based on the output of the decoding attention mechanism and the encoded trend features, the target trend features are obtained.

3. The method according to claim 2, characterized in that, The process of obtaining decoded seasonal features based on the output of the decoding attention mechanism, and obtaining target trend features based on the output of the decoding attention mechanism and the encoded trend features, includes: The output of the decoding attention mechanism is decomposed to obtain a fourth seasonal feature and a first trend feature; The fifth seasonal feature is obtained by mapping the output of the fourth seasonal feature; The fifth seasonal characteristic is decomposed to obtain the target seasonal characteristic and the second trend characteristic; The target trend feature is obtained based on the encoded trend feature, the first trend feature, and the second trend feature.

4. The method according to any one of claims 1 to 3, characterized in that, The anomaly detection based on the time series to be detected and the target time series includes: Obtain the difference between the time series to be detected and the target time series at corresponding times; Anomaly detection is performed on the time series to be detected based on the difference.

5. The method according to any one of claims 1 to 3, characterized in that, After obtaining the time series to be detected, the process further includes: Obtain the mathematical statistical values ​​of the time series to be detected; The time series to be detected is standardized based on the mathematical statistical values.

6. The method according to any one of claims 1 to 3, characterized in that, After obtaining the time series to be detected, the process further includes: The time series to be detected is divided into windows to obtain a time series window; The extraction of the target trend features and target seasonal features of the time series to be detected includes: Extract the target trend features and target seasonality features for each of the time series windows; The process of reconstructing the time series based on the target trend characteristics and the target seasonal characteristics to obtain the target time series includes: Each time series window is reconstructed based on its target trend characteristics and target seasonality characteristics. Based on the reconstructed time series window, the target time series is obtained.

7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Time series data anomaly detection method and device

    CN116226770A

  • Power prediction method and device based on deep learning, and storage medium

    CN116415744A