Early warning method, device and computer device for terminal equipment
By obtaining and analyzing the real-time performance indicators of the monitoring system, and using a trained early warning model to generate alarm information, it solves the problem that unified centralized monitoring and management cannot be achieved in the existing technology, and improves the accuracy and reliability of terminal equipment fault warning.
Patent Information
- Application Number
- CN202510378445.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-03-28
AI Technical Summary
The existing technology cannot achieve unified centralized monitoring and management, resulting in poor early warning of terminal equipment failures and lack of in-depth mining and correlation analysis of the overall system.
By obtaining real-time performance indicators of the monitoring system, inputting a fully trained early warning model for intelligent analysis, and generating alarm information. The method includes data acquisition, standardized processing, model training and dynamic alarm threshold comparison to achieve in-depth analysis and early warning of the operating status of the terminal equipment.
It realizes data integration of multiple devices, cross-language and cross-platforms, improves the accuracy and reliability of terminal equipment fault warning, and solves the shortcomings of fault warning in traditional monitoring methods.
Smart Images

Figure CN119892601B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data processing, and particularly to a warning method, device, and computer device for a terminal device. Background Art
[0002] In modern monitoring and security systems, the management and maintenance of terminal devices such as cameras are crucial for ensuring security. However, with the increase in the number of terminal devices and their applications in complex environments, traditional monitoring methods face the problem of frequent device failures. For example, cameras are easily affected by environmental factors (such as temperature, humidity, dust, etc.), resulting in failures. Traditional monitoring methods often rely on manual regular inspections and cannot detect potential problems in a timely manner, leading to repairs only after failures occur, affecting the continuity and reliability of security monitoring.
[0003] Currently, there are some warning schemes for cameras to monitor and predict the operating status of cameras. However, data from different devices and environments are often generated based on different programming languages or different technical standards. Existing technologies can only independently process and analyze data from different devices and services, and cannot achieve unified centralized monitoring and management, resulting in the lack of in-depth mining and correlation analysis of the overall system in the prediction results, affecting the warning effect of terminal device failures. Summary of the Invention
[0004] In this embodiment, a warning method, device, and computer device for a terminal device are provided to solve the problem in related technologies that unified centralized monitoring and management cannot be achieved.
[0005] In a first aspect, in this embodiment, a warning method for a terminal device is provided. The method includes:
[0006] Obtain real-time performance indicators of a monitoring system; the real-time performance indicators are obtained by a data acquisition component by acquiring operation data of the monitoring system and performing standardized processing on the operation data; wherein, the monitoring system includes a terminal device and a server and network nodes connected to the terminal device;
[0007] Input the real-time performance indicators into a trained warning model, and perform intelligent analysis on the operating status of the terminal device to obtain an index prediction value for a subsequent time step;
[0008] Generate a warning message based on the comparison result between the index prediction value and a dynamically obtained warning threshold.
[0009] In some of these embodiments, the data acquisition component is deployed on the terminal device, the server, and the network nodes.
[0010] In some of these embodiments, before inputting the real-time performance metrics into the trained early warning model, it further includes:
[0011] Obtain the standardized historical performance metrics of the monitoring system;
[0012] Based on the data characteristics of the historical performance metrics, adjust the architecture of the time series prediction model to obtain an initial early warning model;
[0013] Train the initial early warning model based on the historical performance data to obtain the trained early warning model.
[0014] In some of these embodiments, obtaining the standardized historical performance metrics of the monitoring system further includes:
[0015] Based on the data acquisition component deployed on the monitoring system, collect standardized raw metric data and store the raw metric data in a database;
[0016] In response to a model training instruction, extract the corresponding raw metric data from the database and perform preprocessing to obtain the standardized historical performance metrics.
[0017] In some of these embodiments, based on the data characteristics of the historical performance metrics, adjusting the architecture of the time series prediction model to obtain an initial early warning model includes:
[0018] When the historical performance data is three-dimensional time series data, the architecture of the time series prediction model includes a single-layer long short-term memory network and a dropout layer to obtain an initial first early warning model;
[0019] When the historical performance data is six-dimensional data, the architecture of the time series prediction model includes a two-layer long short-term memory network layer and a time attention mechanism layer to obtain an initial second early warning model;
[0020] When the historical performance data is twelve-dimensional data, the architecture of the time series prediction model includes a two-layer long short-term memory network layer and a feature fusion layer to obtain an initial third early warning model.
[0021] In some of these embodiments, after obtaining the trained early warning model, it further includes:
[0022] Obtain the updated historical performance metrics within a preset period;
[0023] Based on the incremental learning method, fine-tune the trained early warning model to obtain the updated trained early warning model.
[0024] In some of these embodiments, the method further includes:
[0025] Obtain the link tracing information collected by the data collection component; perform fault location based on the metric prediction value and the link tracing information.
[0026] In a second aspect, in this embodiment, an early warning device for a terminal device is provided. The device includes:
[0027] A metric acquisition module, configured to acquire real-time performance metrics of a monitoring system; the real-time performance metrics are obtained by a data collection component by acquiring the operation data of the monitoring system and performing standardization processing on the operation data; wherein, the monitoring system includes a terminal device and a server and network nodes connected to the terminal device;
[0028] A model prediction module, configured to input the real-time performance metrics into a trained and complete early warning model, perform intelligent analysis on the operation state of the terminal device, and obtain metric prediction values for subsequent time steps;
[0029] An alarm generation module, configured to generate alarm information based on the comparison result between the metric prediction value and the obtained dynamic alarm threshold.
[0030] In a third aspect, the present application further provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the early warning method for the terminal device described in the first aspect.
[0031] In a fourth aspect, the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the early warning method for the terminal device described in the first aspect.
[0032] Compared with the related art, the early warning method for the terminal device provided in this embodiment obtains real-time performance metrics of a monitoring system; the real-time performance metrics are obtained by a data collection component by acquiring the operation data of the monitoring system and performing standardization processing on the operation data; wherein, the monitoring system includes a terminal device and a server and network nodes connected to the terminal device; input the real-time performance metrics into a trained and complete early warning model, perform intelligent analysis on the operation state of the terminal device, and obtain metric prediction values for subsequent time steps; generate alarm information based on the metric prediction values, which solves the problem that device early warning cannot be performed based on unified centralized monitoring and management, realizes data integration of multiple devices, across languages, and across platforms, thereby deeply analyzing the operation state of the terminal device and improving the accuracy of early warning.
[0033] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more concise and understandable. Description of the Drawings
[0034] The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0035] Figure 1 is a hardware structure block diagram of the terminal for the early warning method of the terminal device in the embodiment of the present application;
[0036] Figure 2 is a schematic flowchart of the early warning method of the terminal device in the embodiment of the present application;
[0037] Figure 3 is a schematic diagram of the data flow process in the embodiment of the present application;
[0038] Figure 4 is a schematic flowchart of the early warning method of the terminal device in the preferred embodiment of the present application;
[0039] Figure 5 is a schematic flowchart of the model training in the preferred embodiment of the present application;
[0040] Figure 6 is a block diagram of the structure of the early warning device of the terminal device in the embodiment of the present application.
[0041] Reference numerals: 102, processor; 104, memory; 106, transmission device; 108, input / output device; 10, index acquisition module; 20, model prediction module; 30, alarm generation module. Detailed Embodiments
[0042] To more clearly understand the purpose, technical solution and advantages of the present application, the present application will be described and illustrated below with reference to the drawings and embodiments.
[0043] Unless otherwise defined, technical terms or scientific terms involved in this application shall have the ordinary meanings understood by those of ordinary skill in the technical field to which this application pertains. In this application, words such as "a", "an", "one kind", "the", "these", etc. do not indicate a limitation in quantity, and they can be singular or plural. The terms "including", "comprising", "having" and any variants thereof involved in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product or device including a series of steps or modules (units) is not limited to the listed steps or modules (units), but may include unlisted steps or modules (units), or may include other steps or modules (units) inherent in these processes, methods, products or devices. The terms "connected", "coupled", etc. involved in this application do not limit to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The "plurality" involved in this application means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, "A and / or B" may represent: A exists alone, A and B exist simultaneously, and B exists alone. Usually, the character " / " indicates that the objects associated before and after are in an "or" relationship. The terms "first", "second", "third", etc. involved in this application only distinguish similar objects and do not represent a specific sorting of the objects.
[0044] The method embodiments provided in this embodiment may be executed on a terminal, a computer, or a similar computing device. For example, when running on a terminal, Figure 1 is a block diagram of the hardware structure of the terminal for the early warning method of the terminal device in this embodiment. As Figure 1 shown, the terminal may include one or more ( Figure 1 only one is shown in the figure) processors 102 and a memory 104 for storing data. Among them, the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA. The above terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not impose limitations on the structure of the above terminal. For example, the terminal may further include more or fewer components than those shown in Figure 1 the figure, or have a different configuration from that shown in Figure 1 the figure.
[0045] The memory 104 can be used to store computer programs, such as software programs and modules of application software, such as the computer program corresponding to the warning method of the terminal device in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the terminal through a network. Examples of the above network include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network, and combinations thereof.
[0046] The transmission device 106 is used to receive or send data via a network. The above network includes a wireless network provided by a communication provider of the terminal. In one instance, the transmission device 106 includes a network adapter (abbreviated as NIC), which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0047] In this embodiment, a warning method for a terminal device is provided. Figure 2 is a flowchart of the warning method for the terminal device in this embodiment, as Figure 2 shown, and the process includes the following steps:
[0048] Step S210, obtain the real-time performance metrics of the monitoring system; the real-time performance metrics are obtained by the data acquisition component by acquiring the operation data of the monitoring system and performing normalization processing on the operation data; wherein, the monitoring system includes a terminal device and a server and network nodes connected to the terminal device.
[0049] Specifically, in the monitoring system, the terminal device includes a camera and various sensors. Real-time collect the performance data of the monitoring system, such as frame rate, latency, packet loss rate, etc.; link tracing information can also be collected to record the flow of requests between different components to analyze problems such as latency and packet loss and accurately locate faults.
[0050] Step S220, input the real-time performance metrics into a trained warning model, perform intelligent analysis on the operating state of the terminal device, and obtain the predicted metric values for subsequent time steps.
[0051] Specifically, the predicted values of the metrics at subsequent time steps include the metric values at the next time step or the multi-step prediction results. Taking a camera as an example, in one specific embodiment, a warning model is used to predict the video encoding time consumption. The input metrics are time series features, including: historical single-frame encoding time consumption sequence, GPU / CPU utilization fluctuation, video resolution and bitrate change records (such as 4K → 1080P), encoding queue length (number of frames to be processed), hardware acceleration module status (such as whether GPU encoding is enabled), environmental temperature and device power consumption; the output metrics are single-frame delay prediction, including: I-frame encoding time consumption at the next time step (such as 5 seconds later) (unit: ms); P-frame encoding time consumption at the next time step (unit: ms); queue backlog prediction: threshold of the number of frames to be processed within the next 30 seconds (such as increasing from 200 frames to 350 frames). Example of the prediction result data structure, in json format:
[0052] {
[0053] "timestamp": 1762225733000,
[0054] "prediction": {
[0055] "IFrameDelay": 158.3, / / Unit: ms
[0056] "PFrameDelay": 51.8, / / Unit: ms
[0057] "queueBacklog": 328 / / Number of frames backlogged in the next 30 seconds
[0058] },
[0059] "action": "reduceResolution" / / Trigger optimization action (such as reducing resolution)
[0060] }
[0061] In another specific embodiment, a warning model is used to predict video packet loss. The input metrics are network performance features: historical packet loss rate sequence, network jitter intensity (unit: ms), number of TCP retransmissions and round-trip delay RTT, bandwidth utilization, transmission path stability (such as switching frequency of distributed nodes CDN (Content Delivery Network)), key frame (I-frame) sending interval and size; the output metrics include: 1. Packet loss rate prediction: packet loss percentage at the next time step (such as 5 seconds later) (such as 3.5% → 5.2%); 2. Key frame integrity prediction: complete arrival rate of the next key frame (such as decreasing from 98% to 92%), number of I-frame losses (predicted value within the next 10 seconds).
[0062] Example of prediction result data structure, in JSON format:
[0063] {
[0064] "timestamp": 1762225733000,
[0065] "prediction": {
[0066] "packetLossRate": 5.2, / / Unit: %
[0067] "IFrameIntegrity": 0.92, / / Integrity rate of key frames (0 - 1)
[0068] "lostIFrames": 1 / / Number of lost I-frames in the next 10 seconds
[0069] },
[0070] "action": "enableFEC" / / Trigger the error correction mechanism
[0071] }
[0072] In step S230, based on the comparison result between the metric prediction value and the obtained dynamic alarm threshold, generate an alarm message.
[0073] Specifically, the dynamic threshold will be adjusted dynamically according to dimensions such as environment, device status, business load, and historical patterns, so as to reduce false alarms and missed alarms. For example, dynamic adjustment based on factors such as time period, environment, and device health status.
[0074] In this embodiment, obtain the real-time performance metrics of the monitoring system; the real-time performance metrics are obtained by the data acquisition component by acquiring the operation data of the monitoring system and performing standardized processing on the operation data; wherein, the monitoring system includes terminal devices and servers and network nodes connected to the terminal devices; input the real-time performance metrics into a well-trained early warning model to perform intelligent analysis on the operation status of the terminal devices, and obtain the metric prediction values for subsequent time steps; generate alarm messages based on the metric prediction values, solve the problem of lack of in-depth mining and correlation analysis for the early warning of terminal devices, realize data integration of multiple devices, across languages, and across platforms, so as to perform in-depth analysis on the operation status of terminal devices and improve the accuracy of early warning.
[0075] In some of these embodiments, the data acquisition component is deployed on terminal devices, servers, and network nodes.
[0076] Specifically, the data acquisition component is responsible for real-time acquisition of performance data, such as frame rate, latency, packet loss rate, etc.; it can also collect link tracing information, which is used to record the flow of requests between different components to analyze problems such as latency and packet loss and accurately locate faults.
[0077] In some of these embodiments, the data acquisition component includes an OpenTelemetry software development kit and an OpenTelemetry agent to receive, process, and export standardized data.
[0078] Specifically, OpenTelemetry is an open-source observability framework designed to provide standardized tools for collecting, processing, and exporting metrics, logs, and tracing data in distributed systems, offering a cross-platform and cross-language solution. Among them, the Agent formats the data into standardized metrics, logs, and link tracing data.
[0079] In this embodiment, compared with traditional Simple Network Management Protocol (SNMP), Syslog, proprietary software development kits (SDKs), or custom log collection solutions, OpenTelemetry has the advantages of unified standards, low-invasive distributed tracing, dynamic sampling, and rich ecosystem.
[0080] In some of these embodiments, see Figure 3 , before inputting the real-time performance metrics into the trained early warning model, it further includes:
[0081] Step S240, obtaining the standardized historical performance metrics of the monitoring system.
[0082] Specifically, the data acquisition component collects data from different devices and environments to ensure data consistency and interoperability.
[0083] Step S250, adjusting the architecture of the time series prediction model based on the data characteristics of the historical performance metrics to obtain an initial early warning model.
[0084] Specifically, the time series prediction model can adopt the ARIMA model (AutoRegressive Integrated Moving Average), the Transformer model, or the long short-term memory network (LSTM, Long Short-Term Memory) to capture the temporal characteristics of the data and provide more accurate prediction results. In one implementation, the time series prediction model includes an input layer, multiple LSTM layers, and an output layer. Further, the number of LSTM layers and the number of units in each layer can be adjusted to adapt to the data characteristics.
[0085] Step S260: Train the initial warning model based on the historical performance data to obtain a well-trained warning model.
[0086] Specifically, the mean squared error (MSE) is used as the loss function, and the Adam optimizer is selected for model training. During the training process, the batch size and the number of training epochs are set, and the change in loss during the training process is monitored. The model performance is evaluated on the validation set, and the validation loss is monitored in real time to prevent overfitting. After training is completed, the model performance is evaluated on the test set, and metrics such as the root mean squared error (RMSE) and the coefficient of determination (R²) are calculated. According to the model evaluation results, the hyperparameters (such as the learning rate, batch size, number of LSTM layers, etc.) are adjusted, and the model is retrained.
[0087] In some of these embodiments, after obtaining the well-trained warning model, it further includes:
[0088] Step S270: Obtain the updated historical performance metrics within a preset period.
[0089] Step S280: Fine-tune the well-trained warning model based on the incremental learning method to obtain the updated well-trained warning model.
[0090] In this embodiment, a regular update mechanism is set, and the model is retrained periodically according to the arrival of new data to adapt to the change of data. When new data arrives, the incremental learning method can be used to fine-tune the existing model instead of training from scratch, improving the model update efficiency.
[0091] In this embodiment, by training on historical data, the time series prediction model can identify normal and abnormal states, thereby realizing real-time monitoring and fault prediction of the terminal device.
[0092] In some of these embodiments, obtaining the standardized historical performance metrics of the monitoring system further includes:
[0093] Step S241: Based on the data acquisition component deployed on the monitoring system, collect standardized original metric data and store the original metric data in the database.
[0094] Specifically, use databases such as Prometheus or Elasticsearch to store the collected data, including historical performance metrics and link tracing information, for subsequent analysis and query.
[0095] Step S242: In response to the model training instruction, extract the corresponding original metric data from the database and perform preprocessing to obtain standardized historical performance metrics.
[0096] Specifically, perform denoising, filling missing values, and feature extraction on the original data to ensure the accuracy and reliability of the data input into the model. Further, data normalization and standardization processing can be carried out to improve the training effect of the model.
[0097] In some of the embodiments, based on the data characteristics of the historical performance metrics, adjust the architecture of the time series prediction model to obtain an initial early warning model, including:
[0098] In the case where the historical performance data is three-dimensional time series data, the architecture of the time series prediction model includes a single-layer long short-term memory network and a dropout layer, to obtain an initial first early warning model.
[0099] Specifically, in the scenario of device fault early warning, the input features include 3D time series data such as CPU temperature, memory occupancy rate, and video encoding time consumption; the model structure includes a single-layer LSTM (32 units) + dropout layer Dropout(0.3). The single-layer LSTM captures the short-term dependence relationship of device performance decline, and Dropout suppresses noise interference. The optimization goal can be set to predict the device health index in the next 5 minutes, and through MSE loss optimization, the prediction error of the device health index is achieved to be <5%.
[0100] In the case where the historical performance data is six-dimensional data, the architecture of the time series prediction model includes a two-layer long short-term memory network layer and a time attention mechanism layer, to obtain an initial second early warning model.
[0101] Specifically, in the scenario of network attack detection, the input features include 6-dimensional data such as bandwidth volatility, TCP retransmission times, and the number of abnormal connections; the model structure includes: bidirectional LSTM (64 units × 2 layers) + temporal attention mechanism. Among them, when detecting a sudden increase in network bandwidth, the data of the previous and next 10 seconds are analyzed simultaneously to determine whether it is a persistent attack. The optimization goal is set to identify DDoS (Distributed Denial of Service) attack patterns, and the weighted FocalLoss loss function is used (parameters α = 0.8 and γ = 2 are set).
[0102] In the case where the historical performance data is 12-dimensional data, the architecture of the time series prediction model includes a two-layer long short-term memory network layer and a feature fusion layer, obtaining an initial third warning model.
[0103] Specifically, in the scenario of video analysis linkage, the input features include 12-dimensional data such as behavior recognition confidence, object movement trajectory, and environmental light intensity; video stream features are added: packet loss rate, number of lost I-frames, and key frame transmission delay. For example, when the packet loss rate > 5% and 3 consecutive I-frames are lost, a video quality warning is triggered. The model structure includes LSTM(128) + CNN feature fusion layer. CNN extracts the spatial features of the video stream (such as the key frame image quality), and LSTM fuses the temporal transmission state; dynamic thresholds (such as the packet loss rate > 5% for 10 seconds) are used to jointly optimize MSE + Focal Loss.
[0104] In this embodiment, the number of LSTM layers and the number of units in each layer are adjusted to adapt to the data characteristics, make full use of the model performance, save computing resources, and improve prediction stability.
[0105] In some of these embodiments, the method further includes: obtaining the link tracing information collected by the data acquisition component; performing fault location based on the metric prediction value and the link tracing information.
[0106] Specifically, when a service occurs once, the link tracing information is used to identify the serial identification from the terminal device -> Service A -> Service B -> Service C. The metric (performance) data output by each service and unit node, or the service identification is relatively independent, and the link data can string these things together.
[0107] In some of these embodiments, the method further includes: triggering a preset processing action based on the alarm information with a priority higher than the preset level, such as restarting the camera or reconnecting to the network, to reduce the operation and maintenance pressure.
[0108] In some of these embodiments, the method further includes: formulating corresponding processing strategies based on the predicted metric values to provide decision-making support for the operation and maintenance personnel. The alarm information and processing strategies can be sent to the operation and maintenance personnel through various means such as emails and text messages.
[0109] In some of these embodiments, the method further includes: sending the real-time performance metrics, link tracing information, and predicted metric values to a control interface for display, so that the operation and maintenance personnel can intuitively monitor the system status through a visualization interface.
[0110] The following describes and illustrates this embodiment through preferred embodiments. This preferred embodiment provides an early warning method for a terminal device to monitor and give early warnings to camera devices in a monitoring system. Refer to Figure 4 , the method includes:
[0111] S1. Data collection: Deploy the OpenTelemetry SDK / Agent on camera devices, servers, and network nodes to collect performance data (such as frame rate, latency, packet loss rate, etc.) and link tracing information (recording the flow of requests between different components) in real time.
[0112] S2. Data storage: Use databases such as Prometheus or Elasticsearch to store the collected data, including historical performance metrics and link tracing information, for subsequent analysis and query.
[0113] S3. Data preprocessing: Denoise, fill in missing values, and extract features from the original performance data and link tracing information to ensure the accuracy and reliability of the data input into the AI model. This module can also perform data normalization and standardization processing to improve the training effect of the model.
[0114] S4. Model training and deployment. Refer to Figure 5 :
[0115] S4.1. Build a time series prediction model: First, define the network architecture and create a time series prediction model that includes an input layer, multiple long short-term memory network layers (LSTM layers), and an output layer. The number of LSTM layers and the number of units in each layer can be adjusted to adapt to the data characteristics. Second, select a loss function and an optimizer, use the mean squared error (MSE) as the loss function, and select the Adam optimizer for model training.
[0116] S4.2. Model training: The training process includes using the training set for model training, setting an appropriate batch size and number of training epochs, and monitoring the change in loss during the training process. The validation process includes evaluating the model performance on the validation set and monitoring the validation loss in real time to prevent overfitting.
[0117] S4.3, Model Evaluation and Optimization: Evaluate the performance of the model on the test set and calculate metrics such as Root Mean Square Error (RMSE) and Coefficient of Determination (R²). According to the model evaluation results, adjust the hyperparameters (such as learning rate, batch size, number of LSTM layers, etc.) and retrain the model.
[0118] S4.4, Model Update: Set up a regular update mechanism to periodically retrain the model according to the arrival of new data to adapt to data changes. When new data arrives, an incremental learning approach can be adopted to fine-tune the existing model instead of training from scratch.
[0119] S4.5, Prediction and Application: Deploy the trained time series prediction model on the server to input new input data into the trained time series prediction model for fault prediction and output the metric values for the next time step or multi-step prediction results.
[0120] S5, Real-time Analysis and Decision-making: The analysis engine deployed on the server processes the data from the data storage module in real time, runs the trained time series prediction model for fault prediction and anomaly detection. According to the analysis results of the time series prediction model, formulate corresponding processing strategies to provide decision support for operation and maintenance personnel.
[0121] S6, Intelligent Alarm and Automatic Response:
[0122] S6.1, Alarm Management System: Set dynamic alarm thresholds according to the results of fault prediction and anomaly detection and generate alarm notifications. The alarm information can be sent to relevant operation and maintenance personnel through various methods such as email and text message.
[0123] S6.2, Automatic Response Mechanism: For high-priority alarms, the system can automatically trigger preset processing actions, such as restarting the camera or reconnecting the network, to reduce the operation and maintenance pressure.
[0124] S7, Visualization and Monitoring:
[0125] S7.1, Monitoring Dashboard: Provide a real-time monitoring interface to display the performance metrics of the camera, link tracing information, and AI prediction results. Operation and maintenance personnel can intuitively monitor the system status through the visualization interface.
[0126] S7.2, Fault Tracing Tool: Analyze the link and root cause of the fault occurrence and generate an anomaly score to help operation and maintenance personnel quickly locate the problem.
[0127] In this preferred embodiment, through OpenTelemetry, data from different devices and environments is effectively collected to ensure data consistency and interoperability. Using the LSTM algorithm for time series analysis, the system can capture the temporal characteristics of the data, thereby providing more accurate fault prediction. The real-time data processing and intelligent anomaly detection functions of this preferred embodiment enable it to quickly identify potential problems and issue alerts in a timely manner through a dynamic alert mechanism. This automated response mechanism not only reduces the need for manual intervention but also significantly shortens the fault response time, thus improving the system's availability and operation and maintenance efficiency. In addition, the powerful data visualization and monitoring capabilities provide an intuitive interface for operation and maintenance personnel, supporting rapid decision-making and fault location.
[0128] It should be noted that the steps shown in the above process or the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0129] In this embodiment, an early warning device for a terminal device is also provided. This device is used to implement the above-mentioned embodiment and preferred implementation manners, and those that have been described will not be repeated here. The following terms such as "module", "unit", "sub-unit", etc. can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0130] Figure 6 is the structural block diagram of the early warning device for the terminal device of this embodiment, as Figure 6 shown, the device includes: an index acquisition module 10, a model prediction module 20, and an alarm generation module 30.
[0131] The index acquisition module 10 is used to acquire the real-time performance indexes of the monitoring system; the real-time performance indexes are obtained by the data acquisition component by acquiring the operation data of the monitoring system and performing standardized processing on the operation data; wherein, the monitoring system includes a terminal device and a server and network nodes connected to the terminal device.
[0132] The model prediction module 20 is used to input the real-time performance indexes into a well-trained early warning model, perform intelligent analysis on the operation state of the terminal device, and obtain the index prediction values for subsequent time steps.
[0133] The alarm generation module 30 is used to generate alarm information based on the comparison result between the index prediction value and the obtained dynamic alarm threshold.
[0134] In some of these embodiments, the data acquisition component is deployed on terminal devices, servers, and network nodes.
[0135] In some of these embodiments, the data acquisition component includes an OpenTelemetry software development kit and an OpenTelemetry agent.
[0136] In some of these embodiments, there is also a model training module, which is used to obtain the standardized historical performance metrics of the monitoring system; adjust the architecture of the time series prediction model based on the data characteristics of the historical performance metrics to obtain an initial warning model; and train the initial warning model based on the historical performance data to obtain a fully trained warning model.
[0137] In some of these embodiments, the model training module is further used to collect standardized raw metric data based on the data acquisition component deployed on the monitoring system and store the raw metric data in a database; in response to a model training instruction, extract the corresponding raw metric data from the database and perform preprocessing to obtain standardized historical performance metrics.
[0138] In some of these embodiments, the model training module is further used to, when the historical performance data is three-dimensional time series data, the architecture of the time series prediction model includes a single-layer long short-term memory network and a dropout layer to obtain an initial first warning model; when the historical performance data is six-dimensional data, the architecture of the time series prediction model includes a two-layer long short-term memory network layer and a time attention mechanism layer to obtain an initial second warning model; when the historical performance data is twelve-dimensional data, the architecture of the time series prediction model includes a two-layer long short-term memory network layer and a feature fusion layer to obtain an initial third warning model.
[0139] In some of these embodiments, there is also a fault location module, which is used to obtain the link tracing information collected by the data acquisition component; and perform fault location based on the metric prediction value and the link tracing information.
[0140] It should be noted that the above-mentioned various modules can be functional modules or program modules, which can be implemented either by software or by hardware. For the modules implemented by hardware, the above-mentioned various modules can be located in the same processor; or the above-mentioned various modules can also be located in different processors in any combination form.
[0141] In this embodiment, there is also provided a computer device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0142] Optionally, the above computer device may further include a transmission device and an input / output device, wherein the transmission device is connected to the above processor, and the input / output device is connected to the above processor.
[0143] It should be noted that for the specific examples in this embodiment, reference may be made to the examples described in the above embodiment and the optional implementation manners, and details will not be repeated in this embodiment.
[0144] In addition, in combination with the warning method for the terminal device provided in the above embodiment, a storage medium may also be provided in this embodiment to implement it. A computer program is stored on the storage medium; when the computer program is executed by a processor, the warning method for any one of the terminal devices in the above embodiment is implemented.
[0145] It should be understood that the specific embodiments described here are only used to explain this application, rather than to limit it. According to the embodiments provided in this application, all other embodiments obtained by those of ordinary skill in the art without creative work belong to the protection scope of this application.
[0146] Obviously, the accompanying drawings are only some examples or embodiments of this application. For those of ordinary skill in the art, this application can also be applied to other similar situations based on these drawings without creative work. Additionally, it can be understood that although the work done during the development process here may be complex and time-consuming, for those of ordinary skill in the art, certain design, manufacturing, or production changes based on the technical content disclosed in this application are only conventional technical means and should not be regarded as insufficient disclosure of this application.
[0147] The term "embodiment" in this application means that the specific features, structures, or characteristics described in combination with the embodiment may be included in at least one embodiment of this application. The phrase appears in various positions in the specification and does not necessarily mean the same embodiment, nor does it mean being independent or alternative to other embodiments and mutually exclusive. Those of ordinary skill in the art can clearly or implicitly understand that the embodiments described in this application can be combined with other embodiments without conflict.
[0148] The above-described embodiments only represent several implementation manners of this application, and their descriptions are relatively specific and detailed, but should not be construed as limiting the scope of patent protection. It should be pointed out that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of this application shall be subject to the appended claims.
Claims
1. An early warning method for a terminal device, characterized in that: The method comprises: Acquire real-time performance indicators of the monitoring system; the real-time performance indicators are obtained by the data acquisition component through acquiring the operating data of the monitoring system and standardizing the operating data; wherein the monitoring system includes a terminal device and a server and a network node connected to the terminal device; the data acquisition component is deployed on the terminal device, the server and the network node; The real-time performance indicator is input into a well-trained early warning model, and the operating status of the terminal device is intelligently analyzed to obtain the indicator prediction value of the subsequent time step; the early warning model dynamically adjusts the architecture based on the historical performance data dimension, including at least one of the following: a single-layer long short-term memory network and a discard layer architecture corresponding to three-dimensional time series data, a double-layer long short-term memory network layer and a time attention mechanism layer architecture corresponding to six-dimensional data, and a double-layer long short-term memory network layer and a feature fusion layer architecture corresponding to twelve-dimensional data; Based on the comparison result of the indicator prediction value and the acquired dynamic alarm threshold, alarm information is generated.
2. The early warning method of the terminal device according to claim 1, characterized in that: Before inputting the real-time performance indicators into the well-trained early warning model, it also includes: Obtaining standardized historical performance indicators of the monitoring system; Based on the data characteristics of the historical performance indicators, the architecture of the time series prediction model is adjusted to obtain an initial early warning model; The initial early warning model is trained based on the historical performance data to obtain the fully trained early warning model.
3. The early warning method of the terminal device according to claim 2, characterized in that: Obtaining standardized historical performance indicators of the monitoring system, further comprising: Based on the data collection component deployed on the monitoring system, collect standardized original indicator data, and store the original indicator data in a database; In response to the model training instruction, the corresponding original indicator data is extracted from the database and preprocessed to obtain standardized historical performance indicators.
4. The early warning method of the terminal device according to claim 2, characterized in that: Based on the data characteristics of the historical performance indicators, the architecture of the time series prediction model is adjusted to obtain an initial early warning model, including: In the case where the historical performance data is three-dimensional time series data, the architecture of the time series prediction model includes a single-layer long short-term memory network and a dropout layer to obtain an initial first warning model; When the historical performance data is six-dimensional data, the architecture of the time series prediction model includes a two-layer long short-term memory network layer and a time attention mechanism layer, and an initial second warning model is obtained; When the historical performance data is twelve-dimensional data, the architecture of the time series prediction model includes a two-layer long short-term memory network layer and a feature fusion layer to obtain an initial third warning model.
5. The early warning method of terminal equipment according to claim 2, characterized in that: After obtaining the well-trained early warning model, the following steps are also included: Obtaining the historical performance indicators updated within a preset period; Based on the incremental learning method, the well-trained early warning model is fine-tuned to obtain an updated well-trained early warning model.
6. The early warning method of terminal equipment according to claim 1, characterized in that: The method further comprises: Acquire link tracking information collected by the data collection component; and locate the fault based on the indicator prediction value and the link tracking information.
7. An early warning device for a terminal device, characterized in that: The device comprises: An indicator acquisition module is used to acquire real-time performance indicators of the monitoring system; the real-time performance indicators are obtained by the data acquisition component by acquiring the operating data of the monitoring system and performing standardization processing on the operating data; wherein the monitoring system includes a terminal device and a server and a network node connected to the terminal device; the data acquisition component is deployed on the terminal device, the server and the network node; A model prediction module is used to input the real-time performance indicator into a well-trained early warning model, perform intelligent analysis on the operating status of the terminal device, and obtain the indicator prediction value for the subsequent time step; the early warning model dynamically adjusts the architecture based on the historical performance data dimension, including at least one of the following: a single-layer long short-term memory network and a discard layer architecture corresponding to three-dimensional time series data, a double-layer long short-term memory network layer and a time attention mechanism layer architecture corresponding to six-dimensional data, and a double-layer long short-term memory network layer and a feature fusion layer architecture corresponding to twelve-dimensional data; The alarm generation module is used to generate alarm information based on the comparison result of the indicator prediction value and the obtained dynamic alarm threshold.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Business data prediction method and device, equipment and medium
CN114445143A
Intelligent early warning method, system and equipment for resource quality monitoring and storage medium
CN114726751A