An abnormal user behavior detection method based on the analysis of spatio-temporal behavior characteristic data
Through the dimensionality reduction method based on manifold learning and Riemann geometric analysis, combined with optimal transmission theory and multi-scale distribution analysis, the problems of nonlinear distribution, high-dimensional characteristics, multimodal correlation and dynamic change complexity in spatiotemporal behavior feature data are solved, and efficient and accurate abnormal user behavior detection is achieved.
Patent Information
- Application Number
- CN202510272751.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-03-10
AI Technical Summary
When the prior art processes complex, multimodal, and dynamic spatiotemporal behavior feature data, it is difficult to capture nonlinear correlations between features, multimodal data correlation analysis and dynamic fusion, and the distribution difference measurement method is simple, making it difficult to adapt to the requirements of complex data distribution.
The multimodal feature matrix is dimensionally reduced by using a manifold learning method to construct a low-dimensional manifold space to maintain the local geometric relationship of the original data; the local dynamic change mode of user behavior is portrayed through Riemann geometric analysis; the optimal transmission theory is used to calculate the degree of deviation between the normal user behavior distribution and the current user behavior distribution, and anomaly judgment is made based on multi-scale distribution analysis and dynamic threshold adjustment mechanism.
It significantly improves the accuracy and efficiency of abnormal detection, can more accurately capture the nonlinear characteristics and dynamic changing patterns of user behavior, enhances the ability to describe complex behavior patterns, and improves the robustness and accuracy of detection.
Smart Images

Figure CN119807974B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of big data analysis, and particularly to an abnormal user behavior detection method based on spatio-temporal behavior feature data parsing. Background Art
[0002] With the rapid development of big data and artificial intelligence technologies, abnormal user behavior detection has become a core research direction in fields such as network security, intelligent transportation, and financial risk control. In the prior art, methods based on statistical analysis, machine learning, or rule models are usually adopted to achieve abnormal behavior detection. For example, traditional principal component analysis technology can reduce the dimension of data to a certain extent and extract main features, and methods based on clustering and classification algorithms are also widely applied to the detection task of behavioral anomalies. In addition, for the modeling of dynamic behavior data, some technologies use time series analysis methods to depict the change trend of behavior and have achieved preliminary application effects. These methods have shown good performance in specific scenarios and laid a foundation for abnormal detection.
[0003] However, with the increase in the complexity and diversity of user behavior data, the prior art gradually exposes limitations when facing spatio-temporal behavior feature data. Specifically, user behavior data usually presents high-dimensional non-linear distribution characteristics, and it is difficult for traditional methods to capture the non-linear associations between features; the correlation analysis and dynamic fusion of multi-modal data are still a technical difficulty, and conventional technologies often fail to fully explore the information interaction between modalities; in addition, dynamic behavior modeling is mostly limited to the analysis of short-term data and has insufficient ability to describe long-term evolution trends; in terms of the measurement of distribution differences, the prior art mostly uses simple distance calculation methods and is difficult to meet the requirements of complex data distributions. Therefore, how to improve the detection accuracy and efficiency when dealing with complex, multi-modal, and dynamic spatio-temporal behavior feature data has become an urgent problem to be solved. Summary of the Invention
[0004] Aiming at the deficiencies of the prior art, the present invention provides an abnormal user behavior detection method based on spatio-temporal behavior feature data parsing, which solves the problem of difficult detection of abnormal user behavior caused by non-linear distribution, high-dimensional characteristics, multi-modal association, and dynamic change complexity in spatio-temporal behavior feature data.
[0005] To achieve the above objectives, the present invention is realized through the following technical solutions: An abnormal user behavior detection method based on spatio-temporal behavior feature data parsing, comprising the following steps:
[0006] S1. Data collection: Obtain the spatio-temporal behavior feature data of users;
[0007] S2. Data preprocessing: Preprocess the spatio-temporal behavior feature data, extract spatio-temporal behavior features, and form a multi-modal feature matrix;
[0008] S3. Feature Dimensionality Reduction: Based on the manifold learning method, reduce the dimensionality of the multi-modal feature matrix to construct a low-dimensional manifold space and maintain the local geometric relationship of the original data;
[0009] S4. Dynamic Modeling: In the low-dimensional manifold space, characterize the local dynamic change pattern of user behavior through Riemannian geometry analysis;
[0010] S5. Distribution Analysis: Based on the optimal transport theory, calculate the deviation degree between the normal user behavior distribution and the current user behavior distribution;
[0011] S6. Anomaly Judgment: Compare the deviation degree with a preset threshold to determine whether it is an abnormal user behavior.
[0012] Preferably, in the S1 step, the spatio-temporal behavior feature numbers include:
[0013] Time features: time points when behaviors occur, time intervals, periodic rules;
[0014] Space features: geographical locations where users are located, movement trajectories, position stay times;
[0015] Behavior features: types of accessed resources by users, device usage conditions.
[0016] Preferably, the S2 step further includes the following steps:
[0017] S21. Complement missing values in the spatio-temporal behavior feature data;
[0018] S22. Eliminate outliers in time and space features;
[0019] S23. Normalize the numerical range of behavior features to ensure that the features are within the same scale.
[0020] Preferably, in the S3 step, the manifold learning dimensionality reduction includes the following steps:
[0021] S31. Calculate the similarity of sample points in the spatio-temporal behavior feature data, construct a neighborhood structure, and represent the local relationship between samples;
[0022] S32. Construct a feature matrix related to the neighborhood structure to characterize the geometric properties between samples;
[0023] S33. Based on the constructed feature matrix, perform dimensionality reduction on the data to obtain a low-dimensional embedding representation that maintains the geometric relationship.
[0024] Preferably, in the step S3, the dimensionality reduction process introduces a manifold regularization constraint to maintain the geometric relationship of sample points within the neighborhood, where the constraint conditions include constructing a similarity matrix of local sample points and minimizing the relative error after the projection of sample points.
[0025] Preferably, in the step S4, the local dynamic change patterns include:
[0026] S41. Construct a local metric on the low-dimensional manifold space to characterize the change characteristics of user behavior in the local area;
[0027] S42. Calculate the degree of change of user behavior data in the low-dimensional manifold space to describe the dynamic evolution of behavior;
[0028] S43. Based on the abnormality judgment index of the degree of change, mark the potential abnormal points in user behavior.
[0029] Preferably, in the step S4, the dynamic modeling combines the time-sliding window technology to segment the user behavior data to capture the short-term and long-term characteristics of behavior changes over time, and analyze the abnormal characteristic points by calculating the geometric deviation measure of behavior changes.
[0030] Preferably, the step S5 further includes the following steps:
[0031] S51. Model the normal user behavior data to form the distribution pattern of normal behavior;
[0032] S52. Model the current user behavior data to form the distribution pattern of the current behavior;
[0033] S53. Measure the deviation degree between the normal behavior distribution and the current behavior distribution to obtain the distribution difference result.
[0034] Preferably, in the step S5, the distribution analysis is based on the joint distribution of multi-modal features. By weighted adjustment of the importance weights of different modal features, the contribution of different modalities to the calculation of distribution deviation is optimized, thereby improving the accuracy of distribution differences.
[0035] Preferably, the step S6 further includes the following steps:
[0036] S61. Conduct a comparative analysis of the normal behavior distribution and the current behavior distribution on different time scales to obtain the distribution deviation degree on each time scale;
[0037] S62. Conduct a comparative analysis of the normal behavior distribution and the current behavior distribution on different spatial scales to obtain the distribution deviation degree on each spatial scale;
[0038] S63. Synthesize the deviation degrees on multi-scales of time and space to determine whether it is abnormal behavior.
[0039] The present invention provides an abnormal user behavior detection method based on the analysis of spatio-temporal behavior feature data, which has the following beneficial effects:
[0040] 1. The present invention realizes the non-linear dimensionality reduction of high-dimensional spatio-temporal behavior feature data through manifold learning technology, and uses manifold regularization constraints to ensure that the local geometric structure of the data is retained during the dimensionality reduction process. Compared with traditional methods, it effectively reduces the computational complexity while significantly improving the accuracy of feature expression, providing high-quality input for subsequent analysis.
[0041] 2. The present invention constructs a dynamic evolution model of user behavior by combining the multi-scale characteristics of time and space. The sliding window technology is used to capture short-term dynamic changes, and the dynamic characteristics of the user's trajectory are extracted through multi-level spatial analysis. At the same time, the Riemannian geometric curvature analysis is adopted to enhance the description ability of complex behavior patterns.
[0042] 3. The present invention introduces the optimal transport theory, uses the Wasserstein distance to accurately measure the deviation degree between the normal behavior and the current behavior distribution, and combines the multi-scale distribution analysis and the dynamic threshold adjustment mechanism to effectively adapt to the long-term changes of user behavior, significantly improving the robustness and accuracy of anomaly detection. Brief Description of the Drawings
[0043] Figure 1 is the flow chart of the method steps of the present invention;
[0044] Figure 2 is the flow chart of the manifold learning dimensionality reduction steps of the present invention;
[0045] Figure 3 is the schematic diagram of the local dynamic change pattern of the present invention;
[0046] Figure 4 is the expanded flow chart of step S5 of the present invention;
[0047] Figure 5 is the expanded flow chart of step S6 of the present invention;
[0048] Figure 6 is the expanded flow of step S2 of the present invention. Detailed Embodiments
[0049] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0050] Please refer to the appendix Figure 1 , the embodiment of the present invention provides an abnormal user behavior detection method based on spatio-temporal behavior feature data analysis, including the following steps:
[0051] S1. Data collection: Obtain the spatio-temporal behavior feature data of the user;
[0052] S2. Data preprocessing: Preprocess the spatio-temporal behavior feature data, extract spatio-temporal behavior features, and form a multi-modal feature matrix;
[0053] S3. Feature dimensionality reduction: Based on the manifold learning method, reduce the dimensionality of the multi-modal feature matrix, construct a low-dimensional manifold space, and maintain the local geometric relationship of the original data;
[0054] S4. Dynamic modeling: In the low-dimensional manifold space, characterize the local dynamic change pattern of the user behavior through Riemannian geometry analysis;
[0055] S5. Distribution analysis: Based on the optimal transport theory, calculate the deviation degree between the normal user behavior distribution and the current user behavior distribution;
[0056] S6. Abnormality judgment: Compare the deviation degree with a preset threshold to judge whether it is an abnormal user behavior.
[0057] Specifically, the present invention provides an abnormal user behavior detection method based on spatio-temporal behavior feature data analysis. This method realizes the accurate detection of abnormal user behavior by obtaining the spatio-temporal behavior feature data of the user and combining manifold learning, Riemannian geometry analysis and optimal transport theory. Specifically, it includes the following steps:
[0058] First, obtain the spatio-temporal behavior feature data of the user. The data consists of time features, space features, and user behavior features. The time features include the time point of behavior occurrence, time interval, and periodic law. The space features include the geographical location of the user, movement trajectory, and position stay time. The user behavior features include the type of accessed resources and device usage, etc. The data is collected in real time through the user device or system log and then enters the data preprocessing module. The preprocessing process includes missing value filling, outlier removal, and feature normalization to ensure the integrity and consistency of the features. Feature normalization can adopt the Min-Max normalization method to map the feature values to a unified numerical range, laying a foundation for subsequent analysis.
[0059] After completing data preprocessing, the feature dimensionality reduction step is entered. The present invention uses a manifold learning method to reduce the dimensionality of the multi-modal feature matrix and constructs a low-dimensional manifold space to preserve the local geometric relationship of the data. Specifically, a neighborhood relationship matrix is constructed by calculating the similarity between sample points, and a Laplacian matrix is generated based on this matrix to describe the local connectivity of sample points on the manifold. During the dimensionality reduction process, a manifold regularization constraint is introduced to ensure that the geometric relationship of sample points within the neighborhood remains unchanged, thereby removing redundant and noisy features in the high-dimensional data and generating a low-dimensional feature representation.
[0060] The reduced low-dimensional manifold space is used for dynamic modeling to analyze the changing patterns of user behavior over time and space. In this step, a Riemannian metric is constructed to define the local distance on the manifold, which is used to characterize the changing characteristics of user behavior. At the same time, by calculating the geometric change measure (such as Gaussian curvature) of user behavior embedded on the manifold, the local deviation of user behavior is described. The sliding time window technique is used to segment user behavior to capture the short-term dynamic change characteristics of behavior, and a time series analysis model is used to predict the evolution trend of behavior. In the spatial dimension, the details of dynamic modeling are further enriched by analyzing the changing characteristics of user trajectories (such as moving speed, staying time).
[0061] Next, distribution analysis is performed. The present invention measures the distribution deviation degree between the distribution model of normal user behavior and the distribution model of current user behavior based on the optimal transport theory by establishing these two distribution models. Specifically, the Wasserstein distance is used to calculate the difference between the normal behavior distribution and the current behavior distribution, and this distance reflects the overall deviation of the current behavior relative to the normal behavior. For multi-modal features, the present invention further introduces a modal weight adjustment mechanism to improve the accuracy of distribution analysis by weighted optimization of the contribution of different modal features to the distribution deviation. In addition, for the multi-scale analysis of the distribution, multi-level modeling in the time and space dimensions is adopted to calculate the distribution deviation degree at each time and space scale respectively, and these deviation degrees are synthesized to obtain the overall distribution difference result.
[0062] After obtaining the distribution difference result, the anomaly judgment step is entered. The present invention compares the distribution deviation degree with a preset threshold, and when the deviation degree exceeds the threshold, the current behavior is determined to be an abnormal behavior. The threshold can be dynamically adjusted according to the actual application scenario, for example, through statistical analysis based on historical data or setting an adaptive mechanism to adapt to the long-term changes of user behavior patterns. In addition, the present invention combines the multi-scale analysis results and improves the robustness and accuracy of anomaly detection by weighted fusion of the deviation degrees in the time and space dimensions.
[0063] In summary, the present invention realizes the efficient and accurate identification of complex user behaviors by combining dimensionality reduction, dynamic modeling, distribution analysis, and anomaly detection of spatio-temporal feature data. The technology of the present invention is fully disclosed, enabling those skilled in the art to reproduce the technology based on the above content, and is applicable to multiple fields such as network security, traffic management, and financial risk control.
[0064] In step S1, the spatio-temporal behavior feature numbers include:
[0065] Time features: the time point when the behavior occurs, time interval, and periodic pattern;
[0066] Space features: the geographical location where the user is located, movement trajectory, and position stay time;
[0067] Behavior features: the type of resources accessed by the user and device usage.
[0068] Specifically, the present invention relates to an abnormal user behavior detection method based on the analysis of spatio-temporal behavior feature data. Among them, data collection is the basic link of the entire technical process. The quality of data collection directly determines the accuracy and reliability of subsequent analysis. In order to comprehensively reflect user behavior characteristics, the present invention collects multi-modal feature data of time, space, and user behavior, and constructs a comprehensive feature data set by combining different data sources and collection strategies. The collected data not only covers the time and geographical information of user behavior, but also includes the device information and context behavior patterns accessed by the user. Through the fusion of multi-modal data, a more accurate basis can be provided for subsequent feature parsing and behavior analysis.
[0069] It should be noted that the data collection in this step needs to meet the requirements of timeliness and the integrity of high-dimensional features. Therefore, a distributed data collection framework is adopted to support large-scale data processing. At the same time, in view of the inconsistency of data sources, the present invention designs a unified data format specification to ensure that the data collected from different data sources can be seamlessly integrated.
[0070] In this embodiment, the spatio-temporal behavior feature data of the user is mainly collected through user devices, log systems, and external data sources. Specifically, the time features include the time point when the behavior occurs, time interval, and periodic pattern; the space features include the geographical location of the user, movement trajectory, and stay area; the behavior features include the type of resources accessed by the user, device information, and operation mode.
[0071] As an implementation method, the collection of time feature data is realized by recording the timestamps of user operations, generating a series of time series data. For example, the login time, request time, and logout time of the user accessing the system can be used as basic time feature data. By calculating the time interval between adjacent operations, the time interval feature of user behavior can be further extracted to analyze the periodic characteristics in the behavior pattern.
[0072] In some embodiments, the spatial feature data is collected through location-based services (such as GPS) or network location technologies. For example, the GPS data of the user's mobile device can record longitude and latitude information, and at the same time, the approximate location of the user can be resolved by combining the network IP address. Specifically, the system generates the user's movement trajectory by continuously collecting the user's geographical location, and calculates the speed and residence time of the position change. These features help to describe the behavior distribution pattern of the user in the spatial dimension.
[0073] It should be noted that there may be noise data in the process of spatial feature collection, such as GPS positioning errors or discontinuous trajectory points. The present invention filters out abnormal points by setting a position deviation threshold and uses interpolation to complement missing trajectory points to ensure the accuracy and continuity of the collected data.
[0074] As an option, the data collection of user behavior features is based on access logs and device information. Exemplarily, the behavior features may include the types of resources accessed by the user (such as web pages, files or applications), and the types of devices operated (such as mobile phones, tablets or computers). In addition, the frequency of user device switching can also be recorded to analyze the cross-device behavior pattern of the user. For example, when the user frequently switches different devices to access the system, the consistency and abnormality of their behavior can be further analyzed.
[0075] In a possible implementation manner, the present invention performs unified formatting processing on multi-modal data. Specifically, the time features are stored in the timestamp format, the spatial features are stored in the longitude and latitude coordinates and time stamps, and the behavior features are stored in the structured data of the user session record. Through this normalization processing, the complexity of data preprocessing can be effectively reduced, providing clear data input for subsequent steps.
[0076] In order to ensure the timeliness of spatio-temporal feature data, the present invention adopts a distributed data collection architecture. As an example, the system can realize the real-time transmission of data streams through message queue technologies such as Apache-Kafka, and archive historical data in combination with a distributed storage system (such as HDFS). Through this architecture design, the large-scale concurrent data collection requirements can be supported.
[0077] In some possible implementation manners, the present invention designs a fault tolerance mechanism for data collection. It should be noted that the user device may cause incomplete data collection due to network interruption or device abnormality. The present invention can automatically complete the supplementary collection operation of missing data after the data source is restored by introducing a retry mechanism and a caching strategy.
[0078] In the specific implementation process, the present invention also supports the integrity verification of the collected data. For example, by calculating whether the sampling interval of the time series data meets the preset standard, it is possible to quickly detect whether there is data loss or duplication during the collection process.
[0079] It can be understood that the collection of spatio-temporal behavior feature data is the starting point and foundation of the anomaly detection process. Ensuring the accuracy, timeliness, and integrity of data collection can significantly improve the analysis efficiency and detection effect of subsequent steps. The data collection scheme of the present invention has wide applicability in the fields of network security, traffic analysis, user behavior modeling, etc., providing a reliable data basis for anomaly behavior detection.
[0080] Please refer to the appendix Figure 6 , and step S2 further includes the following steps:
[0081] S21. Completing the missing values in the spatio-temporal behavior feature data;
[0082] S22. Removing the outliers in the time and space features;
[0083] S23. Normalizing the numerical range of the behavior features to ensure that the features are within the same scale.
[0084] Specifically, in the present invention, data preprocessing is an important step for normalizing, structuring, and cleaning the collected spatio-temporal behavior feature data. Its purpose is to provide high-quality input data for subsequent feature parsing, dynamic modeling, and anomaly detection. Through data preprocessing, the integrity and consistency of the data can be effectively improved, while reducing the interference of feature noise on the detection results. The main tasks of data preprocessing include missing value completion, outlier removal, feature normalization, and data format conversion, and different processing methods are adopted for different attributes of time, space, and behavior features. It should be noted that this step combines context information when processing data to ensure that the processed data can not only retain the original characteristics of the spatio-temporal features but also meet the input requirements of subsequent algorithms.
[0085] In this embodiment, the preprocessing of the time feature includes the normalization of the timestamp data and the calculation of the time interval. Specifically, the timestamp format data is usually recorded in milliseconds or seconds. To ensure the consistency of processing, this embodiment uniformly converts the timestamp to the ISO-8601 standard format, such as "YYYY-MM-DD, HH:MM:SS". This standardized format facilitates subsequent time interval calculation and periodic analysis.
[0086] As an option, the present invention generates time interval feature data of user behavior by calculating the difference between consecutive timestamps. For example, the time interval between user login and operation can be used to analyze the regularity or suddenness of user behavior. In addition, time series data can be segmented into fixed-length segments through the time window method to form short-term dynamic features of behavior.
[0087] In the preprocessing of spatial features, this embodiment performs denoising and completion operations on geographical location data. It should be noted that GPS data may have outliers due to signal interference or device problems, such as suddenly jumping longitude and latitude coordinates or discontinuous trajectory points. Specifically, the present invention uses the threshold filtering method to eliminate coordinate points exceeding the preset error range. For example, when the distance between adjacent points exceeds a reasonable range (such as 500 meters), this point will be marked as an outlier and processed.
[0088] As a possible implementation, for the missing points in the trajectory data, the present invention completes them by the linear interpolation method. For example, when the time interval or position span between two points in the user trajectory is too long, the system inserts virtual position points according to the time difference and distance difference between the front and rear two position points, thereby generating continuous trajectory data.
[0089] In the preprocessing of behavior features, the present invention normalizes and structures multi-modal features. Exemplarily, the types of resources accessed by the user are stored in a discretized form, such as "web page", "file" or "application", and are converted into numerical features through the One-Hot encoding method for subsequent analysis. In addition, the user's device type (such as "mobile phone", "tablet" or "computer") is also encoded in a similar way to enhance the computability of the features.
[0090] To improve the comparability between different features, the present invention normalizes numerical features. Specifically, the normalization operation maps the feature values to the range [0,1], and the normalization formula is as follows:
[0091]
[0092] where x' is the normalized feature value, x is the original feature value, x min and x max are the minimum and maximum values of the feature values respectively. In this way, the influence of too large a difference in the range of feature values on the subsequent model can be avoided.
[0093] As an extension, in the normalization of time features and spatial features, the present invention further considers the periodicity of the features. For example, for the periodic processing of time features, it can be represented by mapping time to a two-dimensional circular coordinate system as:
[0094]
[0095] Among them, is the sine mapping value of the time feature, t is the current time point, is the cosine mapping value of the time feature, and T is the period length. This representation can retain the periodicity of the time feature and avoid the boundary problem in simple numerical normalization.
[0096] It should be noted that in some embodiments, the data preprocessing further includes the conversion of the original data format. As an implementation manner, the present invention stores the processed data in JSON or Parquet format, which can be compatible with distributed storage systems (such as HDFS) and supports the efficient transmission of large-scale data.
[0097] It can be understood that data preprocessing, as a key step in subsequent analysis, aims to improve the availability and consistency of data while ensuring data integrity. The preprocessing process of the present invention provides high-quality input data for subsequent manifold learning dimensionality reduction and dynamic modeling through differential methods for different feature types. Through the above description, those skilled in the art can reproduce the preprocessing steps of the present invention based on the disclosed content and apply them to complex spatio-temporal behavior analysis scenarios.
[0098] Please refer to the appendix Figure 2 , in step S3, the manifold learning dimensionality reduction includes the following steps:
[0099] S31. Calculate the similarity of sample points in the spatio-temporal behavior feature data, construct a neighborhood structure, and represent the local relationship between samples;
[0100] S32. Construct a feature matrix related to the neighborhood structure for characterizing the geometric properties between samples;
[0101] S33. Based on the constructed feature matrix, perform dimensionality reduction processing on the data to obtain a low-dimensional embedding representation that maintains the geometric relationship.
[0102] In step S3, the dimensionality reduction processing introduces a manifold regularization constraint to maintain the geometric relationship of sample points within the neighborhood, where the constraint conditions include constructing a similarity matrix of local sample points and minimizing the relative error after the projection of sample points.
[0103] Specifically, the feature dimensionality reduction step of the present invention aims to map high-dimensional spatio-temporal behavior feature data to a low-dimensional space through non-linear dimensionality reduction techniques while preserving the local geometric relationships of the data. Since user behavior features have a complex high-dimensional distribution, directly processing high-dimensional data may lead to excessively high computational complexity and introduce redundant or noisy features. Through manifold learning methods, high-dimensional data can be embedded into a low-dimensional manifold space, while retaining the core characteristics of user behavior when reducing the data dimension. This step provides an efficient and accurate low-dimensional data representation for subsequent dynamic modeling and anomaly detection.
[0104] It should be noted that manifold learning assumes that user behavior feature data is distributed on an implicit low-dimensional manifold and generates a low-dimensional representation that can reflect the global data structure by constructing local similarity relationships between sample points. The present invention introduces manifold regularization constraints during the dimensionality reduction process to ensure that the dimensionality-reduced data can retain the geometric structure of neighboring sample points.
[0105] In this embodiment, first, the similarity of sample points in the spatio-temporal behavior feature data is calculated to construct a neighborhood structure to represent the local relationship between samples. Specifically, the similarity metric is calculated using a Gaussian kernel function, defined as follows:
[0106]
[0107] where N(X i ) represents the neighborhood set of sample x i , σ is the Gaussian kernel bandwidth parameter, is the Euclidean distance between sample points, x i , x j are the feature vectors of the sample points. It should be noted that the neighborhood set can be determined by the k-nearest neighbor algorithm, and the number k of neighborhood sample points is a preset parameter used to control the local range of the neighborhood.
[0108] As an option, the similarity matrix W can be further normalized to eliminate the non-uniformity of the data distribution. Specifically, the similarity values of each sample point can be normalized so that:
[0109]
[0110] where W ij ’ is the normalized similarity weight value, W ij is the original similarity weight value, is the sum of the similarity weight values of all adjacent sample points of sample point x i . This normalization operation can improve the robustness during the dimensionality reduction process.
[0111] After constructing the similarity matrix, the present invention further generates a Laplacian matrix L to describe the local connectivity of sample points on the manifold. Specifically, the Laplacian matrix is defined as: L = D - W, where D is the degree matrix and W is the similarity matrix. The eigenvalues and eigenvectors of the Laplacian matrix can reflect the global distribution characteristics of sample points in the low-dimensional space.
[0112] As an implementation, the present invention obtains the feature representation after dimensionality reduction by minimizing the following objective function:
[0113]
[0114] where, is the value of the dimensionality reduction objective function, F represents the feature matrix after dimensionality reduction, tr is the trace operator of the matrix, is the transpose of the feature matrix F. By performing eigenvalue decomposition on the Laplacian matrix, the eigenvectors corresponding to the smallest d eigenvalues are taken as the low-dimensional embedding result F, where d is the target dimension of the low-dimensional space.
[0115] In some embodiments, the present invention introduces a manifold regularization constraint during the dimensionality reduction process to enhance the ability to preserve the neighborhood geometric relationship. Specifically, the regularization objective function is as follows:
[0116]
[0117] where f represents the mapping function of data points, λ is the regularization strength parameter, is the Hilbert space where the function f is located, is the norm of the function f in the Hilbert space, λ is the regularization strength parameter, W ij is the similarity weight between sample points, x i , x j are the feature vectors of sample points.
[0118] By optimizing this objective function, it is possible to effectively reduce data distortion during the dimensionality reduction process and at the same time enhance the preservation of the local geometric structure.
[0119] It should be noted that the present invention supports the non-linear mapping of high-dimensional features and improves the flexibility of dimensionality reduction by introducing the kernel function method. Exemplarily, the kernel principal component analysis (KPCA) method is used to map the original feature space to a high-dimensional kernel space, and then manifold learning operations are performed in the kernel space. The kernel function can be selected from Gaussian kernel, polynomial kernel or Sigmoid kernel to adapt to different types of feature distributions.
[0120] In a possible implementation, the low-dimensional manifold representation after dimensionality reduction contains the main structural information of user behavior characteristics and significantly reduces the dimensionality of the original data. The dimensionality reduction result can be used as the input for subsequent dynamic modeling and anomaly detection. For example, the trajectory data after dimensionality reduction can be used to analyze the movement patterns of users, while the low-dimensional representation of time feature data can reveal the periodic patterns of behaviors.
[0121] It can be understood that feature dimensionality reduction is an important step in the efficient anomaly detection of the present invention. By reducing the data dimensionality and retaining the core features, it provides a simplified and accurate data representation for subsequent steps. The dimensionality reduction method combines Laplacian eigenmaps and manifold regularization, which not only ensures the geometric relationship of the local neighborhood but also enhances the adaptability to complex behavior characteristics. The disclosure of the above technical details enables those skilled in the art to perform a complete technical reproduction according to the content of the present invention and apply it to the processing scenario of large-scale spatio-temporal behavior data.
[0122] Please refer to the appendix Figure 3 , in step S4, the local dynamic change patterns include:
[0123] S41. Construct a local metric on the low-dimensional manifold space to characterize the change characteristics of user behavior in the local area;
[0124] S42. Calculate the degree of change of user behavior data in the low-dimensional manifold space to describe the dynamic evolution of the behavior;
[0125] S43. Based on the anomaly judgment index of the degree of change, mark the potential anomaly points in user behavior.
[0126] In step S4, the dynamic modeling combines the time sliding window technology to segment the user behavior data to capture the short-term and long-term characteristics of the behavior changing over time, and analyzes the abnormal feature points by calculating the geometric deviation measure of the behavior change.
[0127] Specifically, in the present invention, dynamic modeling is a key step in spatio-temporal behavior modeling of the low-dimensional manifold feature data after dimensionality reduction. By constructing the dynamic change pattern of user behavior, it analyzes the evolution characteristics of the behavior over time and space. This step uses Riemannian geometry theory and sliding window technology to extract dynamic change features from the local geometric relationship of user behavior and depicts the potential trend of abnormal behavior occurrence. Through piecewise modeling of the time dimension and space dimension, the present invention can capture short-term anomalies in user behavior and improve the robustness of modeling by using the global characteristics of the behavior. It should be noted that the result of dynamic modeling not only provides input for subsequent distribution analysis but also can be directly used for the auxiliary determination of anomaly detection.
[0128] In this embodiment, first, a local metric of user behavior is constructed on the low-dimensional manifold space to characterize the change characteristics of behavior data. Specifically, the Riemannian metric g ij is defined as:
[0129]
[0130] where g ij is the metric tensor of the manifold, and ds 2 is the local distance element on the manifold, representing the local distance between two sample points in the low-dimensional manifold space. dx i dx j is the small change in the i-th and j-th dimensions in the feature space, reflecting the local geometric relationship of the sample points in the low-dimensional manifold space. As an implementation, g ij can be derived from the inner product or similarity matrix of the sample points in the original feature space to ensure that the geometric structure in the low-dimensional space is consistent with the original space.
[0131] After constructing the metric, the present invention further describes the local dynamic characteristics of user behavior by calculating the curvature of user behavior data in the low-dimensional manifold space. It should be noted that the Gaussian curvature K is an important measure for characterizing the local geometric properties of the manifold, and its definition is:
[0132]
[0133] where Hess(f) is the Hessian matrix on the embedded manifold, represents the norm of the gradient. By calculating the Gaussian curvature value of each sample point, it is possible to identify the regions where significant changes occur on the manifold, and these regions usually correspond to potential abnormal points of user behavior.
[0134] As an option, the present invention combines the sliding time window technology to perform time-segmented modeling of user behavior. Specifically, user behavior data is sliced according to a fixed time length (such as 5 minutes, 1 hour, or 1 day), and the curvature and change trend are calculated independently for each time slice. For example, a user's access behavior in a day can be divided into multiple time periods, and by calculating the dynamic characteristics within these time periods respectively, it is possible to identify abnormal behaviors within a specific time period.
[0135] It should be noted that the present invention also considers the multi-scale characteristics of behavior data in time. In some embodiments, the length of the time window can be gradually increased in a recursive manner, for example, extended from the minute level to the hour level and the day level, to capture the long-term evolution patterns in user behavior. This multi-scale time modeling helps to take into account both short-term fluctuations and long-term trends when detecting anomalies.
[0136] In the spatial dimension, in this embodiment, by analyzing the user's movement trajectory, the dynamic characteristics of the trajectory data are extracted. For example, by calculating the speed and acceleration between consecutive position points of the user, the changing pattern of the user's behavior in space can be reflected. Specifically, for the trajectory point sequence {p1, p2..., p n}, its speed v i and acceleration a i are respectively defined as:
[0137]
[0138] where a i is the speed of the i-th segment of the trajectory, ∆t is the time interval between adjacent trajectory points, p i+1 -p i are consecutive position points in the user's trajectory, is the distance between consecutive position points. By analyzing the distribution of speed and acceleration, it can be further identified whether the user has an abnormal movement pattern, such as a sudden large movement or frequent position changes within a short period of time.
[0139] As a possible implementation, the present invention also combines a spatial partitioning strategy in dynamic modeling, and classifies the user behavior into three spatial ranges of local, regional, and global according to the hierarchy of geographical locations. For each spatial range, the geometric change characteristics of the user behavior are calculated independently. For example, the local range can analyze the residence time distribution of the user at a specific location, while the global range can analyze the behavior pattern of the user crossing multiple geographical regions within a short period of time.
[0140] It should be emphasized that the results of dynamic modeling can be directly used for behavior classification and determination. For example, when the Gaussian curvature value of the user behavior within a certain time period is significantly higher than that in other time periods, this time period can be initially marked as a candidate area for abnormal behavior. In addition, the high-acceleration points in the trajectory data can also be used as triggering conditions for potential abnormalities, providing further verification basis for subsequent distribution analysis.
[0141] It can be understood that dynamic modeling is an important part of the present invention for detecting complex user behaviors. By extracting the dynamic change characteristics of user behaviors from the time and space dimensions, it provides rich feature inputs for subsequent distribution analysis and anomaly detection. The dynamic modeling method of the present invention combines manifold geometric analysis and multi-scale time window technology, and has strong adaptability and robustness. The disclosure of the above content enables those skilled in the art to perform a complete technical reproduction based on the present invention.
[0142] Please refer to Appendix Figure 4 , and step S5 further includes the following steps:
[0143] S51. Model the normal user behavior data to form a distribution pattern of normal behaviors;
[0144] S52. Model the current user behavior data to form the distribution pattern of the current behavior;
[0145] S53. Measure the deviation degree between the normal behavior distribution and the current behavior distribution to obtain the distribution difference result.
[0146] In step S5, the distribution analysis is based on the joint distribution of multi-modal features. By weighted adjustment of the importance weights of different modal features, the contribution of different modalities to the distribution deviation calculation is optimized, thereby improving the accuracy of the distribution difference.
[0147] Specifically, the distribution analysis step of the present invention aims to quantify the deviation degree between the normal behavior distribution and the current behavior distribution by establishing a mathematical model, so as to provide a basis for anomaly detection. The distribution analysis introduces the Optimal-Transport-Theory, uses the Wasserstein distance to accurately measure the distribution difference, and combines the characteristics of multi-modal data to further optimize the accuracy and robustness of the distribution modeling. It should be noted that the result of the distribution analysis directly affects the performance of subsequent anomaly judgment. Therefore, the goal of this step is to provide a stable distribution deviation result through strict distribution construction and efficient difference measurement.
[0148] In this embodiment, first, the normal user behavior data is modeled to form a reference distribution P. Specifically, the normal user behavior distribution is obtained by statistical analysis of historical data. Assuming that the data samples {x1, x2…, x N} represent the feature set of normal behaviors, then P can be defined as the joint probability distribution of these samples:
[0149]
[0150] where δ represents the Dirac function, which is used to describe the position distribution of sample points, P(x) is the probability distribution function of sample points, which is used to describe the distribution of sample points in the feature space, N is the total number of sample points, x is any point in the feature space, and x i is the position of the i-th sample point in the feature space. As a possible implementation, the distribution P can be further smoothed by kernel density estimation to obtain a continuous distribution model. The formula for kernel density estimation is:
[0151]
[0152] where is the smoothed distribution function obtained by kernel density estimation, N is the total number of sample points, h is the bandwidth parameter of kernel density estimation, which is used to control the smoothing degree, K is the kernel function, x is any point in the feature space, and x iis the position of the i-th sample point in the feature space.
[0153] In a possible implementation, to improve the efficiency of Wasserstein distance calculation, the present invention introduces the Sinkhorn distance algorithm. By introducing a regularization term, the Sinkhorn distance transforms the optimization problem of the joint distribution into an efficient solution problem of matrix multiplication, and its calculation formula is:
[0154]
[0155] where W λ (P, Q) is the Sinkhorn distance, which is used to describe the regularized Wasserstein distance between distributions P and Q. P and Q are two probability distributions, representing the normal behavior distribution and the current behavior distribution respectively. inf is the operator for taking the minimum value, indicating finding the optimal joint distribution. γ is the joint distribution of P and Q, which is used to describe the matching relationship between the two distributions. is the set of all possible joint distributions, satisfying that the marginal distributions are P and Q respectively. is the square of the Euclidean distance between sample points x and y. is the Cartesian product of the feature space, representing the combination space of all sample point pairs. λ is the regularization strength parameter, which is used to control the sensitivity of the Sinkhorn distance to the regularization term. KL(γ) is the KL divergence of the joint distribution γ, which is used to represent the regularization constraint.
[0156] It should be noted that the present invention also optimizes the multi-scale characteristics of distribution analysis. In some embodiments, distributions P and Q are decomposed into multiple sub-distributions according to time scales and spatial scales. For example, the time scale can be divided into minute, hour, and day levels, and the spatial scale can be divided into local area, city scope, and transnational area. For each sub-distribution, the Wasserstein distance is calculated respectively, and the overall distribution difference is obtained by weighted summation.
[0157] In some implementations, the present invention further introduces a modality weight adjustment mechanism to optimize the contribution of multi-modal features to distribution analysis. Exemplarily, the modality weights can be dynamically adjusted through feature importance analysis based on historical data, so as to improve the accuracy of distribution difference calculation.
[0158] It is understandable that distribution analysis is a core step in the anomaly detection process. By modeling the distributions of normal behaviors and current behaviors and measuring the differences, it provides a quantitative basis for anomaly judgment. In the distribution analysis process of the present invention, Wasserstein distance, multi-scale modeling, and modal weight adjustment techniques are combined, which have high precision and robustness. The above technologies are disclosed in sufficient detail to ensure that those skilled in the art can fully implement the distribution analysis step according to the content of the present invention and apply it to complex spatio-temporal behavior detection scenarios.
[0159] Please refer to the appendix Figure 5 , and step S6 further includes the following steps:
[0160] S61. Compare and analyze the normal behavior distributions and current behavior distributions at different time scales to obtain the distribution deviation degrees at each time scale;
[0161] S62. Compare and analyze the normal behavior distributions and current behavior distributions at different spatial scales to obtain the distribution deviation degrees at each spatial scale;
[0162] S63. Synthesize the deviation degrees of multiple time and space scales to determine whether it is an abnormal behavior.
[0163] Specifically, the anomaly judgment step of the present invention is the final decision-making link based on the distribution analysis results. Its core lies in combining the deviation degree between the normal user behavior distribution and the current user behavior distribution to determine whether the current user behavior is abnormal. By comparing the distribution deviation degree with a preset threshold, it can effectively determine whether the behavior exceeds the normal range, thereby identifying potential abnormal behaviors. It should be noted that the anomaly judgment process not only depends on the quantitative results of the distribution differences, but also combines technologies such as multi-modal features, multi-scale distribution analysis, and dynamic threshold adjustment to ensure the accuracy and robustness of the judgment results.
[0164] In this embodiment, the anomaly judgment is based on the measurement result of the distribution deviation, and mainly uses the distribution difference W(P,Q) calculated by the Wasserstein distance to characterize the difference between the normal distribution P and the current distribution Q. It should be noted that W(P,Q) is the core quantitative index of the behavior distribution deviation degree, and the larger its value, the higher the degree of deviation of the current behavior from the normal behavior.
[0165] As an implementation method, when W(P,Q) exceeds the set threshold ∈, the system will determine that the current behavior is an abnormal behavior. The setting of this threshold ∈ can be based on the statistical analysis of historical data. For example, by calculating the distribution of the normal behavior Wasserstein distance and setting a certain confidence interval, an appropriate threshold can be determined. Specifically, the threshold can be expressed as:
[0166]
[0167] where μ w and σ w are the mean and standard deviation of the Wasserstein distance respectively, k is a parameter for controlling the abnormal range, and ∈ is the threshold for abnormal behavior detection.
[0168] In a possible implementation, the present invention further combines the results of multi-scale distribution analysis to improve the robustness of abnormal judgment by comprehensively considering the distribution differences in the time and space dimensions. Specifically, the distribution deviation results in the time scale and space scale are used for multi-scale abnormal judgment. When the comprehensive deviation degree exceeds the preset threshold ∈, the behavior is determined to be abnormal. The multi-scale abnormal judgment formula is:
[0169]
[0170] where W multi (P,Q) is the multi-scale distribution deviation value, T and L are the numbers of the time scale and space scale, α t , β l are the weight factors of the time and space scales, W(P t , Q t ) is the Wasserstein distance on the time scale, and W(P l , Q l ) is the Wasserstein distance on the space scale.
[0171] As an option, for different modalities of behavior characteristics, the present invention designs a modality weighting mechanism to enable abnormal judgment to assign higher weights to key modalities. For example, in some application scenarios, time characteristics may be more important than space characteristics, and then the influence of time characteristics can be strengthened by increasing the weight α t of the time modality. It should be noted that the modality weights can be determined by analyzing the feature importance of historical data, so as to optimize the accuracy of abnormal judgment.
[0172] In some embodiments, the present invention adopts a dynamic threshold adjustment mechanism to adapt to the long-term changes in the user behavior pattern. Specifically, the dynamic threshold adjustment is based on the statistical distribution of the Wasserstein distance within a time window, and the threshold ∈ is updated periodically. For example, at the end of each time window, the mean and standard deviation of the Wasserstein distance are recalculated, and the threshold range for the next cycle is adjusted accordingly. This dynamic adjustment mechanism can effectively cope with the gradual change of user behavior and reduce the false positive rate.
[0173] It should be noted that the abnormal judgment step of the present invention also supports the hierarchical determination of abnormal behaviors. Exemplarily, when the distribution deviation degree W(P,Q) is within a lower threshold range, it can be marked as "mild abnormal" to prompt the system for further observation; while when the deviation degree exceeds the higher threshold, it is directly marked as "severe abnormal" to trigger the alarm or intervention mechanism of the system.
[0174] In a possible implementation manner, the abnormal judgment result can be verified in combination with the curvature analysis result of dynamic modeling. For example, when both the Gaussian curvature K and the Wasserstein distance W(P,Q) exceed the threshold, the reliability of the abnormal behavior determination can be significantly improved. In addition, the present invention can also combine the speed and acceleration characteristics in the trajectory data to further verify the rationality of the abnormal behavior. For example, if the Wasserstein distance is high but there is no obvious abnormality in the trajectory characteristics, the abnormal marking of this behavior can be postponed.
[0175] It can be understood that the abnormal judgment is the final decision-making link of the present invention, and its core lies in converting the distribution deviation result into a clear abnormal behavior determination. The present invention realizes the efficient and accurate judgment of complex user behaviors by combining the Wasserstein distance, multi-scale analysis, modal weighting, and dynamic threshold adjustment technologies. The disclosure of the above technical content is sufficient to ensure that those skilled in the art can conduct a complete technical reproduction according to the present invention and apply it to various spatio-temporal behavior abnormal detection scenarios.
[0176] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirits of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for detecting abnormal user behavior based on spatiotemporal behavior feature data analysis, characterized in that: The following steps are involved: S1. Data collection: obtaining users’ spatiotemporal behavior feature data; S2, data preprocessing: preprocessing the spatiotemporal behavior feature data, extracting spatiotemporal behavior features, and forming a multimodal feature matrix; The S2 step further comprises the following steps: S21, completing missing values in spatiotemporal behavior feature data; S22, removing outliers in time and space characteristics; S23, normalizing the numerical range of the behavioral features to ensure that the features are within the same scale; The normalization operation maps the eigenvalues to the range [0,1]. The normalization formula is as follows: Among them, x' is the normalized eigenvalue, x is the original eigenvalue, and x min and x max are the minimum and maximum eigenvalues, respectively; For the periodic processing of time features, time is mapped to a two-dimensional circular coordinate system as follows: in, is the sinusoidal mapping value of the time feature, t is the current time point, is the cosine mapping value of the time feature, T is the period length; S3, feature dimensionality reduction: Based on the manifold learning method, the multimodal feature matrix is reduced in dimension, a low-dimensional manifold space is constructed, and the local geometric relationship of the original data is maintained; In the step S3, the dimension reduction process maintains the geometric relationship of the sample points in the neighborhood by introducing manifold regularization constraints, wherein the constraints include constructing a similarity matrix of local sample points and minimizing the relative error after the sample points are projected; The manifold regularization constraint is introduced in the dimensionality reduction process, and the regularization objective function is as follows: Among them, f represents the mapping function of the data point, λ is the regularization strength parameter, is the Hilbert space where the function f is located, is the norm of function f in Hilbert space, λ is the regularization strength parameter, W ij is the similarity weight between sample points, x i , x j is the feature vector of the sample point; S4, dynamic modeling: in the low-dimensional manifold space, the local dynamic change pattern of user behavior is characterized by Riemannian geometry analysis; In the step S4, dynamic modeling is combined with time sliding window technology to segment user behavior data to capture short-term and long-term characteristics of behavior changes over time, and abnormal feature points are analyzed by calculating the geometric deviation measure of behavior changes; By calculating the curvature of user behavior data in the low-dimensional manifold space, the local dynamic characteristics of user behavior are described. Gaussian curvature K is an important measure used to characterize the local geometric properties of the manifold, which is defined as: Where Hess(f) is the Hessian matrix on the embedded manifold, Represents the modulus of the gradient. By calculating the Gaussian curvature value of each sample point, we can identify areas on the manifold where significant changes occur. These areas correspond to potential abnormal points in user behavior. S5. Distribution analysis: Based on the optimal transmission theory, calculate the deviation between the normal user behavior distribution and the current user behavior distribution; S6. Abnormality determination: Compare the degree of deviation with a preset threshold to determine whether it is abnormal user behavior.
2. According to claim 1, the abnormal user behavior detection method based on spatiotemporal behavior feature data analysis is characterized in that: In the step S1, the spatiotemporal behavior feature numbers include: Temporal characteristics: the time point, time interval, and periodicity of the behavior; Spatial features: user’s geographical location, movement trajectory, and time spent at the location; Behavioral characteristics: the user's access resource types and device usage.
3. The abnormal user behavior detection method based on spatiotemporal behavior feature data analysis according to claim 1 is characterized in that: In the step S3, the manifold learning dimensionality reduction includes the following steps: S31, calculate the similarity of sample points in the spatiotemporal behavior feature data, build a neighborhood structure, and represent the local relationship between samples; S32, constructing a feature matrix related to the neighborhood structure to characterize geometric characteristics between samples; S33. Based on the constructed feature matrix, the data is subjected to dimensionality reduction processing to obtain a low-dimensional embedding representation that maintains geometric relationships.
4. The abnormal user behavior detection method based on spatiotemporal behavior feature data analysis according to claim 1 is characterized in that: In the step S4, the local dynamic change mode includes: S41. Construct a local metric on a low-dimensional manifold space to characterize the changing characteristics of user behavior in a local area. S42. Calculate the degree of change of user behavior data in the low-dimensional manifold space to describe the dynamic evolution of the behavior; S43. Based on the abnormality judgment index of the degree of change, mark the potential abnormal points in the user behavior.
5. The abnormal user behavior detection method based on spatiotemporal behavior feature data analysis according to claim 1 is characterized in that: The step S5 further comprises the following steps: S51, modeling normal user behavior data to form a distribution pattern of normal behavior; S52, modeling the current user behavior data to form a distribution pattern of the current behavior; S53. Measure the degree of deviation between the normal behavior distribution and the current behavior distribution to obtain a distribution difference result.
6. The abnormal user behavior detection method based on spatiotemporal behavior feature data analysis according to claim 1 is characterized in that: In the step S5, the distribution analysis is based on the joint distribution of multimodal features. The importance weights of different modal features are adjusted by weighting to optimize the contribution of different modalities to the distribution deviation calculation, thereby improving the accuracy of the distribution difference.
7. The abnormal user behavior detection method based on spatiotemporal behavior feature data analysis according to claim 1 is characterized in that: The step S6 further comprises the following steps: S61, comparing and analyzing the normal behavior distribution on different time scales with the current behavior distribution, and obtaining the distribution deviation degree on each time scale; S62, comparing and analyzing the normal behavior distribution at different spatial scales with the current behavior distribution, and obtaining the distribution deviation degree at each spatial scale; S63. Determine whether it is abnormal behavior by comprehensively considering the degree of deviation at multiple time and space scales.
Citation Information
Patent Citations
Customer portrait key data mining method and system based on space-time big data
CN118797542A