Large-model-based time series anomaly detection method, device and equipment and medium
By constructing a time series anomaly detection method based on large models, using variational autoencoder, recurrent neural network and convolutional neural network, the problem of low accuracy of multi-dimensional time series anomaly detection is solved, efficient anomaly detection is achieved, and detection uncertainty and manual labeling costs are reduced.
Patent Information
- Application Number
- CN202510445125.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2045-04-10
AI Technical Summary
The prior art has the problem of low accuracy in the detection of abnormalities of multi-dimensional time series, especially when high-dimensional data processing, data sparsity intensifies and detection performance declines due to dimensional disasters. At the same time, the proportion of abnormal samples is very small and the cost of manual labeling is high, resulting in the lack of labeling information guidance for unsupervised learning, which increases the difficulty of detection and uncertainty of results.
A time series anomaly detection method based on large models is used to construct anomaly detection large model using variational autoencoder, recurrent neural network and convolutional neural network. The model performs feature extraction and fusion through convolutional layer, cyclic layer and self-attention cyclic layer, and combines a linear learning layer and a decoder to perform anomaly detection.
It improves the accuracy of abnormal detection of multi-dimensional time series, can effectively process high-dimensional data, reduces detection uncertainty, and reduces the cost of manual labeling.
Smart Images

Figure CN119961849A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a time series anomaly detection method, device, equipment and medium based on a large model. Background Art
[0002] Anomaly detection is a key area in machine learning today, where the goal is to identify abnormal points that are significantly different from the regular patterns in a dataset.
[0003] However, the current mainstream anomaly detection technology for multidimensional time series has obvious shortcomings. Traditional methods based on distance or distribution can handle low-dimensional data. When faced with high-dimensional data, the dimensionality disaster leads to increased data sparsity and a significant decline in detection performance. Advanced solutions developed for specific scenarios, although they work well in limited environments, are difficult to adapt to various cross-domain anomaly types due to their strong specificity. At the same time, abnormal samples account for a very small proportion of the data set, which is far different from the number of normal samples, and manual labeling of abnormal data requires a lot of manpower and professional knowledge, which is extremely costly. This means that most anomaly detection algorithms can only use unsupervised learning. However, unsupervised learning lacks guidance from annotation information, which greatly increases the difficulty of anomaly detection and the uncertainty of the results.
[0004] Therefore, how to improve the accuracy of anomaly detection in multidimensional time series is a technical problem that needs to be solved urgently. Summary of the invention
[0005] In view of this, the purpose of the present invention is to provide a time series anomaly detection method, device, equipment and medium based on a large model, which can improve the accuracy of anomaly detection of multidimensional time series. The specific scheme is as follows:
[0006] In a first aspect, the present application provides a time series anomaly detection method based on a large model, wherein the large model is an anomaly detection large model constructed based on a variational autoencoder, a recurrent neural network, and a convolutional neural network; wherein the method comprises:
[0007] Determine the convolution layer output result based on the model convolution layer of the anomaly detection large model and the initial multi-dimensional time series data, and determine the single recurrent layer output result and the time step prediction matrix based on the convolution layer output result and the long short-term memory network of the model recurrent layer of the anomaly detection large model; wherein the model convolution layer includes a filter and the convolution neural network;
[0008] Determine the self-attention loop layer output result by using the convolution layer output result, the time step prediction matrix, the dimension of the single loop layer output result and the model self-attention loop layer of the anomaly detection large model, and determine the fusion output result based on the single loop layer output result, the self-attention loop layer output result and the first preset result fusion mechanism; the model self-attention loop layer includes a self-attention mechanism and the long short-term memory network;
[0009] Determine a linear output result based on the model linear learning layer of the anomaly detection large model and the initial multidimensional time series data, and determine a target output result using the linear output result, the fusion output result and a second preset result fusion mechanism;
[0010] Based on the target output result and the decoder of the variational autoencoder, target multidimensional time series data is determined, and anomaly detection is performed using the target multidimensional time series data, the initial multidimensional time series data, and a preset anomaly detection threshold to determine anomalies in the initial multidimensional time series data.
[0011] Optionally, determining the convolution layer output result based on the model convolution layer of the anomaly detection large model and the initial multi-dimensional time series data includes:
[0012] Determining the height of the filter in the convolutional layer of the model based on the number of data features in the initial multidimensional time series data to complete the filter height configuration operation;
[0013] Determining the width of the filter in the model convolution layer based on the period of the initial multidimensional time series data to complete the filter width configuration operation;
[0014] Configuring the parameters of the filter based on the filter height configuration operation and the filter width configuration operation, and obtaining a configured filter;
[0015] The initial multi-dimensional time series data is input into the model convolution layer of the anomaly detection large model, and the convolution layer output result is generated using the ReLU activation function and the configured post-filter.
[0016] Optionally, the determining of a single recurrent layer output result and a time step prediction matrix based on the convolutional layer output result and the long short-term memory network of the model recurrent layer of the large anomaly detection model includes:
[0017] Input the output result of the convolution layer into the long short-term memory network of the model recurrent layer of the large anomaly detection model, and process the output result of the convolution layer using the forget gate, input gate and output gate in the long short-term memory network to obtain a processing result;
[0018] A hidden state and a time step prediction matrix are obtained from the processing result, and the hidden state is determined as a single recurrent layer output result.
[0019] Optionally, the determining the self-attention recurrent layer output result by using the convolutional layer output result, the time step prediction matrix, the dimension of the single recurrent layer output result, and the model self-attention recurrent layer of the anomaly detection large model includes:
[0020] Input the convolution layer output result and the time step prediction matrix into the model self-attention recurrent layer, and determine the current time series data based on the convolution layer output result, the time step prediction matrix and the long short-term memory network in the model self-attention recurrent layer;
[0021] Determine a Query vector, a Key vector, and a Value vector based on the current time series data and the self-attention mechanism in the self-attention loop layer of the model;
[0022] Performing a dot product on the Query vector and the Key vector to obtain a dot product result, and determining a weight score using the dot product result and a normalized exponential function;
[0023] A weighted Value vector is determined based on the weight score and the Value vector, and the weighted Value vector is used to determine the output result of the self-attention mechanism, so as to determine the self-attention recurrent layer output result based on the dimension of the self-attention mechanism output result and the single recurrent layer output result.
[0024] Optionally, determining the fusion output result based on the single recurrent layer output result, the self-attention recurrent layer output result and a first preset result fusion mechanism includes:
[0025] Splicing the single recurrent layer output result and the self-attention recurrent layer output result, and determining a first weight coefficient based on the obtained splicing result, a tanh activation function, and a preset bias term;
[0026] Performing a scaling operation on the first weight coefficient to obtain a second weight coefficient;
[0027] A fusion output result is determined based on the second weight coefficient, the single loop layer output result, and the self-attention loop layer output result.
[0028] Optionally, the determining of a linear output result based on a model linear learning layer of the anomaly detection large model and the initial multidimensional time series data includes:
[0029] Inputting the initial multidimensional time series data into the model linear learning layer;
[0030] The initial multidimensional time series data is processed using the autoregressive model in the linear learning layer of the model to obtain a processed linear output result.
[0031] Optionally, performing anomaly detection using the target multidimensional time series data, the initial multidimensional time series data, and a preset anomaly detection threshold to determine anomalies in the initial multidimensional time series data includes:
[0032] Determine a sample set containing only normal multidimensional time series data as a validation set, and determine a first anomaly score based on the validation set;
[0033] performing statistical analysis on the first anomaly score to determine a corresponding mean and standard deviation;
[0034] Determine a preset abnormality detection threshold based on the sum of the average value and a preset multiple of the standard deviation;
[0035] A second anomaly score is determined based on the target multidimensional time series data and the initial multidimensional time series data, so as to determine an abnormality of the initial multidimensional time series data by using the second anomaly score and the preset anomaly detection threshold.
[0036] In a second aspect, the present application provides a time series anomaly detection device based on a large model, wherein the large model is an anomaly detection large model constructed based on a variational autoencoder, a recurrent neural network, and a convolutional neural network; wherein the device comprises:
[0037] A recurrent layer output module, used to determine the convolution layer output result based on the model convolution layer of the anomaly detection large model and the initial multi-dimensional time series data, and to determine the single recurrent layer output result and the time step prediction matrix based on the convolution layer output result and the long short-term memory network of the model recurrent layer of the anomaly detection large model; wherein the model convolution layer includes a filter and the convolution neural network;
[0038] A first output result fusion module, used to determine the self-attention loop layer output result by using the convolution layer output result, the time step prediction matrix, the dimension of the single loop layer output result and the model self-attention loop layer of the anomaly detection large model, and determine the fusion output result based on the single loop layer output result, the self-attention loop layer output result and a first preset result fusion mechanism; the model self-attention loop layer includes a self-attention mechanism and the long short-term memory network;
[0039] A second output result fusion module is used to determine a linear output result based on the model linear learning layer of the anomaly detection large model and the initial multidimensional time series data, and determine a target output result using the linear output result, the fused output result and a second preset result fusion mechanism;
[0040] An anomaly detection module is used to determine the target multidimensional time series data based on the target output result and the decoder of the variational autoencoder, and perform anomaly detection using the target multidimensional time series data, the initial multidimensional time series data and a preset anomaly detection threshold to determine the abnormal situation in the initial multidimensional time series data.
[0041] In a third aspect, the present application provides an electronic device, including:
[0042] Memory, used to store computer programs;
[0043] A processor is used to execute the computer program to implement the aforementioned large model-based time series anomaly detection method.
[0044] In a fourth aspect, the present application provides a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the aforementioned large model-based time series anomaly detection method is implemented.
[0045] In the present application, the output result of the convolution layer is determined based on the model convolution layer of the large anomaly detection model and the initial multidimensional time series data, and the single loop layer output result and the time step prediction matrix are determined based on the convolution layer output result and the long short-term memory network of the model loop layer of the large anomaly detection model; wherein the model convolution layer includes a filter and the convolution neural network; the self-attention loop layer output result is determined using the convolution layer output result, the time step prediction matrix, the dimension of the single loop layer output result and the model self-attention loop layer of the large anomaly detection model, and the single loop layer output result, the self-attention loop layer output result and the first preset are used. The result fusion mechanism determines the fusion output result; the model self-attention loop layer includes the self-attention mechanism and the long short-term memory network; the linear output result is determined based on the model linear learning layer of the anomaly detection large model and the initial multidimensional time series data, and the target output result is determined using the linear output result, the fusion output result and the second preset result fusion mechanism; the target multidimensional time series data is determined based on the target output result and the decoder of the variational autoencoder, and the target multidimensional time series data, the initial multidimensional time series data and the preset anomaly detection threshold are used for anomaly detection to determine the abnormal situation in the initial multidimensional time series data. As can be seen from the above, in this application, the initial multidimensional time series data is first input into the model convolution layer of the anomaly detection large model, and after the convolution layer processing, the convolution layer output result is obtained. Then, the convolution layer output result is input into the long short-term memory network of the model loop layer of the anomaly detection large model, and after the calculation of the long short-term memory network, the single loop layer output result and the time step prediction matrix are determined. Then, with the help of the convolution layer output result, the time step prediction matrix and the dimension information of the single loop layer output result, it is input into the model self-attention loop layer of the anomaly detection large model. After the processing of the self-attention loop layer, the output result of the self-attention loop layer is obtained. Subsequently, according to the first preset result fusion mechanism, the single loop layer output result and the self-attention loop layer output result are fused to determine the fusion output result. After that, the initial multidimensional time series data is input into the model linear learning layer of the anomaly detection large model, and the linear output result is determined after the layer is processed. Then, according to the second preset result fusion mechanism, the linear output result and the fusion output result are fused to obtain the target output result. Finally, the target output result is input into the decoder of the variational autoencoder, and the decoder outputs the target multidimensional time series data. The target multidimensional time series data is compared with the initial multidimensional time series data, and combined with the preset anomaly detection threshold, anomaly detection is carried out to determine whether there is anomaly in the initial multidimensional time series data. In this way, the present application can improve the accuracy of anomaly detection of multidimensional time series. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0047] Figure 1 A flow chart of a time series anomaly detection method based on a large model disclosed in this application;
[0048] Figure 2 A flow chart of a specific time series anomaly detection method based on a large model disclosed in this application;
[0049] Figure 3 An operation process of a self-attention mechanism with a length of 2 for a multidimensional time series disclosed in this application;
[0050] Figure 4 This is a schematic diagram of the structure of a time series anomaly detection device based on a large model disclosed in this application;
[0051] Figure 5 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION
[0052] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0053] At present, the mainstream anomaly detection technology for multidimensional time series has obvious shortcomings. Traditional methods based on distance or distribution can handle low-dimensional data. When facing high-dimensional data, the data sparsity is aggravated due to the dimensional disaster, and the detection performance drops significantly. Although the advanced solutions developed for specific scenarios are excellent in limited environments, they are difficult to adapt to various cross-domain anomaly types due to their strong specificity. At the same time, abnormal samples account for a very small proportion of the data set, which is far from the number of normal samples, and manual labeling of abnormal data requires a lot of manpower and professional knowledge, and the cost is extremely high. This makes most anomaly detection algorithms can only use unsupervised learning. However, unsupervised learning lacks guidance from annotation information, which greatly increases the difficulty of anomaly detection and the uncertainty of results. To this end, the present application provides a time series anomaly detection method, device, equipment and medium based on a large model, which can improve the accuracy of anomaly detection of multidimensional time series.
[0054] See also Figure 1 and Figure 2 As shown, an embodiment of the present invention discloses a time series anomaly detection method based on a large model, wherein the large model is an anomaly detection large model constructed based on a variational autoencoder, a recurrent neural network, and a convolutional neural network, wherein the method comprises:
[0055] Step S11, determining the convolution layer output result based on the model convolution layer of the anomaly detection large model and the initial multidimensional time series data, and determining the single recurrent layer output result and the time step prediction matrix based on the convolution layer output result and the long short-term memory network of the model recurrent layer of the anomaly detection large model; wherein the model convolution layer includes a filter and the convolution neural network.
[0056] First of all, it should be noted that multidimensional time series have different connotations and forms of expression in different specific application scenarios. The following is an explanation based on financial monitoring, industrial maintenance, and medical diagnosis scenarios.
[0057] Specifically, in the financial monitoring scenario, multidimensional time series contain a variety of information. For example, in the stock market, the price trend, trading volume, price-earnings ratio, price-to-book ratio and other data of each stock constitute multiple dimensions. The data of these dimensions change over time, forming a certain time series. The data between different stocks are interrelated, such as the price fluctuations of stocks in the industry may be similar or correlated. By analyzing these multidimensional time series and using the anomaly detection large model of this application, it is possible to timely detect abnormal fluctuations in stock prices, abnormal changes in trading volume, etc., thereby helping investors and regulators make accurate decisions and prevent financial risks.
[0058] In industrial maintenance scenarios, multidimensional time series mainly come from data monitored by various sensors. Taking large engines as an example, sensors will collect data in multiple dimensions such as engine temperature, pressure, speed, vibration frequency, etc. in real time. These data change dynamically over time, reflecting the operating status of the engine. The parameters between different components of the engine affect each other, such as changes in temperature may affect pressure and vibration. Using the anomaly detection model of this application to perform anomaly detection on these multidimensional time series, potential engine failures such as component wear, abnormal vibration, etc. can be discovered in advance, thereby achieving preventive maintenance and reducing equipment downtime and maintenance costs.
[0059] In the medical diagnosis scenario, multidimensional time series contain various physiological indicator data of patients. For example, the changes in indicators such as electrocardiogram, blood pressure, heart rate, body temperature, blood sugar, etc. over time. There are intrinsic connections between different physiological indicators. For example, changes in heart rate may be related to blood pressure and body temperature. By analyzing these multidimensional time series, doctors can have a more comprehensive understanding of the patient's health status. The abnormal detection model of this application can detect abnormal changes in the patient's physiological indicators in a timely manner, which is helpful for the diagnosis and treatment of early diseases and improves the accuracy and timeliness of medical diagnosis.
[0060] In this embodiment, in order to effectively extract features from the initial multi-dimensional time series data, it is necessary to reasonably configure the model convolution layer of the large anomaly detection model.
[0061] First, the height of the filter in the model convolution layer is determined based on the number of data features in the initial multidimensional time series data to complete the filter height configuration operation. Among them, the number of features in the initial multidimensional time series data reflects the complexity and dimensional information of the data, and the height of the filter plays a key role in the convolution operation, which determines the processing range in the data feature dimension. Through the analysis of the number of data features and reasonable algorithm calculation, the appropriate filter height can be determined, so that the convolution layer can effectively capture key features when processing the initial multidimensional time series data, while avoiding excessive redundant information.
[0062] Next, the width of the filter in the model convolution layer is determined based on the period of the initial multidimensional time series data to complete the filter width configuration operation. Specifically, the periodicity of multidimensional time series data is one of its important characteristics, and different multidimensional time series may have different period lengths. The width of the filter determines the processing range in the time dimension. For time series data with obvious periods, reasonably setting the width of the filter can better capture the temporal changes of the data.
[0063] Based on the above filter height configuration operation and filter width configuration operation, the filter parameters are configured to obtain the configured filter. The configured filter parameters include the height, width and other related parameters of the filter. The reasonable setting of these parameters can improve the performance of the model convolution layer to a certain extent, so as to better extract the features in the initial multidimensional time series data by using the model convolution layer.
[0064] Furthermore, the initial multi-dimensional time series data is input into the model convolution layer of the anomaly detection model, and the convolution layer output is generated using the ReLU (Rectified Linear Unit) activation function and the configured post-filter. It should be noted that in the convolution operation, the kth (i.e., the number of filters in the model convolution layer of the anomaly detection model) filter scans the input matrix X (i.e., the initial multi-dimensional time series data, the multi-dimensional time series is represented in the form of a matrix). According to the rules of the convolution operation, the output result of the kth filter is as follows:
[0065] ;
[0066] In the formula, represents the convolution operation, is the weight matrix of the filter, is the bias vector. The RELU function is specifically RELU (x) = max (0, x), which can perform nonlinear transformation on the convolution result, so that the convolution layer can learn more complex feature representations. After the convolution layer is processed, the time series will reduce the sequence length and the number of variables, and increase the number of channels. In addition, the output of the convolution layer The size is , where ch is the number of channels of the output matrix, t is the length of the initial multidimensional time series input, and n is the dimension of the initial multidimensional time series input. is the width of the filter and m is the height of the filter.
[0067] After obtaining the output of the convolution layer, it is input into the long short-term memory network of the model recurrent layer of the large anomaly detection model, and the output of the convolution layer is processed using the forget gate, input gate, and output gate in the long short-term memory network to obtain the processing result. Among them, the long short-term memory network is a special recurrent neural network, and its core lies in its ability to effectively capture the time dependency in multidimensional time series data. Specifically, the calculation formula in the long short-term memory network is as follows:
[0068]
[0069] Among the above five formulas, is the calculation formula of the forget gate, where represents the sigmoid (s-shaped) activation function, represents the input at time t, express To the weight matrix of the forget gate, h t-1 represents the hidden state of the long short-term memory network at time t-1, express To the weight matrix of the forget gate, Represents the bias vector of the forget gate;
[0070] is the calculation formula of the input gate. Specifically, express to the weight matrix of the input gate, express to the weight matrix of the input gate, represents the bias vector of the input gate;
[0071] is the calculation formula of the unit state at time t, where represents the Hadamard product (multiplying the elements in corresponding positions of two matrices), represents the cell state at time t-1, represents the tanh activation function, express to the weight matrix of the candidate cell state, express to the weight matrix of the candidate cell state, A bias vector representing the candidate cell state;
[0072] is the calculation formula of the output gate, where express The weight matrix to the output gate, express The weight matrix to the output gate, represents the bias vector of the output gate;
[0073] The calculation formula representing the hidden state.
[0074] Through the above calculation formula, the output results of the convolution layer can be processed to obtain the hidden state and time step prediction matrix from the processing results, and the hidden state is determined as the output result of a single loop layer. When processing the data of each time step, the long short-term memory network will retain the information of the previous time step, thereby realizing dynamic modeling of sequence data. By analyzing and extracting the processing results, the hidden state of each time step can be obtained. , ,……, , , these hidden states contain the feature representation of the time series data at different time steps. At the same time, according to the calculation process of the long short-term memory network, the time step prediction matrix can also be obtained, which reflects the prediction information of the long short-term memory network on the future value of the time series. Using the hidden state as the output result of a single recurrent layer provides an important feature representation for subsequent model processing.
[0075] Step S12, using the convolutional layer output result, the time step prediction matrix, the dimension of the single loop layer output result and the model self-attention loop layer of the anomaly detection large model to determine the self-attention loop layer output result, and based on the single loop layer output result, the self-attention loop layer output result and the first preset result fusion mechanism to determine the fusion output result; the model self-attention loop layer includes a self-attention mechanism and the long short-term memory network.
[0076] In this embodiment, the output of the convolution layer and the time step prediction matrix are input into the model self-attention loop layer of the large anomaly detection model. The output of the convolution layer has undergone feature extraction of the initial multidimensional time series data, and it retains the local correlation and feature information in the data. The time step prediction matrix reflects the prediction information of the long short-term memory network on the future value of the time series. These two are input into the long short-term memory network in the model self-attention loop layer, and the long short-term memory network will process these inputs according to its own forget gate, input gate and output gate mechanism to obtain the current time series data.
[0077] Furthermore, based on the current time series data obtained, the self-attention mechanism in the self-attention loop layer of the model begins to play a role. The core of the self-attention mechanism is to achieve weighted processing of input data by calculating the relationship between the input Query vector (i.e., query vector), Key vector (i.e., key vector) and Value vector (i.e., value vector). Specifically, through a specific linear transformation, the current time series data is mapped to the Query vector, Key vector and Value vector. The dimensions of these vectors are usually set according to the output dimensions of the convolutional layer to ensure that the correlation between the data can be effectively captured in subsequent calculations.
[0078] See also Figure 3 As shown in the figure, specifically, the Query vector and the Key vector are dot-producted to obtain the dot-product result. The dot-product operation can measure the similarity between the Query vector and the Key vector. The higher the similarity, the larger the dot-product result. In order to solve the gradient vanishing problem that may occur when the SoftMax function (i.e., the normalized exponential function) processes large dot-product values, the dot-product result is divided by a scaling factor, which is usually the square root of the dimensions of the Query and Key vectors. Then, the scaled dot-product result is processed using the SoftMax function to obtain a weight score. Among them, the weight score indicates the importance of each Value vector in the final output. The higher the score, the greater the proportion of the corresponding Value vector in the output.
[0079] Next, based on the obtained weight scores and Value vectors, the weighted Value vector is calculated. The specific method is to multiply each Value vector by the corresponding weight score, and then add all the weighted Value vectors to obtain the output result of the self-attention mechanism. Finally, according to the dimension of the output result of the single loop layer, the dimension of the output result of the self-attention mechanism is adjusted to match the dimension of the output result of the single loop layer, thereby obtaining the output result of the self-attention loop layer. And, the generation of the output result of the self-attention mechanism is as follows:
[0080] ;
[0081] In the formula, Q is the Query vector, K is the Key vector, and V is the Value vector. Represents the dimensions of the Query vector and the Key vector, and T represents the transpose of the matrix.
[0082] Furthermore, in this embodiment, the output result of the single loop layer and the output result of the self-attention loop layer are spliced to obtain a spliced result. Based on this spliced result, a nonlinear transformation is performed using the tanh activation function, and a preset bias term is added to obtain a first weight coefficient. The function of the tanh activation function is to map the input value to the range of -1 to 1, so that the output has certain nonlinear characteristics and can better fit complex data relationships.
[0083] In addition, the first weight coefficient needs to be scaled to map it from the interval of -1 to 1 to the interval of 0 to 1, thereby obtaining the second weight coefficient. The purpose of this scaling operation is to enable the second weight coefficient to be used as a weight factor for combining the output results of the single recurrent layer and the output results of the self-attention recurrent layer.
[0084] Finally, the fusion output result is determined based on the second weight coefficient, the output result of the single loop layer, and the output result of the self-attention loop layer. Specifically, the output result of the single loop layer is multiplied by the second weight coefficient, and the output result of the self-attention loop layer is multiplied by the difference between 1 and the second weight coefficient, and then the two are added together to obtain the final fusion output result. This fusion mechanism can dynamically adjust the proportion of the single loop layer output result and the self-attention loop layer output result in the final output according to different data sets and specific circumstances, thereby improving the anomaly detection performance of the model. In addition, the determination process of the above fusion output result is expressed as follows:
[0085]
[0086] In the above three formulas, represents the first weight coefficient, represents the second weight coefficient, Represents the output result of a single cycle layer, Represents the output result of the self-attention loop layer, represents the preset bias term, Express and The concatenated matrix is subjected to linear transformation operation. Represents the fusion output result.
[0087] Step S13, determining a linear output result based on the model linear learning layer of the anomaly detection large model and the initial multidimensional time series data, and determining a target output result using the linear output result, the fusion output result and a second preset result fusion mechanism.
[0088] In this embodiment, the initial multidimensional time series data is input into the model linear learning layer of the anomaly detection large model, and the autoregressive model in this layer begins to process the initial multidimensional time series data. The autoregressive model is a common time series analysis model that can predict future values based on past observations. In the anomaly detection large model of this embodiment, the autoregressive model can capture the linear change trend in the initial multidimensional time series. Among them, the formula for processing the initial multidimensional time series data using the autoregressive model is as follows:
[0089] ;
[0090] In the formula, Represents the linear prediction result of the AR model (Autoregressive model). Represents the trainable weight matrix in the AR model.
[0091] Specifically, the expression of the autoregressive model is the linear output result obtained by the autoregressive model through matrix multiplication and addition operations. This linear output result reflects the relatively stable and linear change pattern in the time series.
[0092] After obtaining the linear output result and the fused output result in step S12, it is necessary to fuse them using the second preset result fusion mechanism to obtain the target output result. The purpose of the fusion is to comprehensively utilize the linear features captured by the linear learning layer and the complex nonlinear features captured after the fusion of the previous loop layer and the self-attention loop layer, thereby improving the overall modeling ability of the model for multidimensional time series.
[0093] In addition, the second preset result fusion mechanism also adopts a learnable method. Similar to the fusion mechanism of the previous recurrent layer and the self-attention recurrent layer, the linear output result and the fusion output result are concatenated to obtain a concatenated matrix containing more information.
[0094] Step S14: determine the target multidimensional time series data based on the target output result and the decoder of the variational autoencoder, and perform anomaly detection using the target multidimensional time series data, the initial multidimensional time series data and a preset anomaly detection threshold to determine the abnormal situation in the initial multidimensional time series data.
[0095] In this embodiment, the target output result is a feature representation obtained after processing in the previous multiple steps, and the task of the decoder of the variational autoencoder is to reconstruct this feature representation into target multidimensional time series data. The decoder is a neural network that maps the target output result to the same dimensional space as the initial multidimensional time series data through a series of linear transformations and nonlinear activation functions. In other words, the decoder can reconstruct this target output result into the original input data. By continuously adjusting the parameters of the decoder, the reconstruction error is minimized, so that the decoder can learn how to generate time series data similar to the original data from the feature representation of the latent space. That is, the decoder uses the trained parameters to convert the target output result into target multidimensional time series data. This target multidimensional time series data is a reconstruction of the initial multidimensional time series data by the anomaly detection large model, which reflects the multidimensional time series pattern under normal circumstances considered by the anomaly detection large model.
[0096] In order to perform anomaly detection, a preset anomaly detection threshold needs to be determined. First, a sample set containing only normal multidimensional time series data is determined as a validation set. This validation set needs to represent the distribution of normal data in actual applications as much as possible.
[0097] Furthermore, based on the validation set, a first anomaly score is calculated. The first anomaly score is usually obtained by calculating the reconstruction error of each sample in the validation set. The reconstruction error can be defined as the difference between the sample in the validation set and the sample reconstructed by the decoder. These first anomaly scores are statistically analyzed to calculate the corresponding mean and standard deviation.
[0098] In addition, according to statistical principles, under normal circumstances, the first anomaly scores of most data should be concentrated near the average value. Therefore, the preset anomaly detection threshold (using ), where the preset multiple can be 3. Therefore, when a certain anomaly score exceeds this threshold, it can be considered that the data point may be abnormal.
[0099] Finally, based on the target multidimensional time series data and the initial multidimensional time series data, the second anomaly score (expressed as score) is calculated. The calculated second anomaly score is compared with the preset anomaly detection threshold. If the second anomaly score is greater than the preset anomaly detection threshold, that is, , then the corresponding part of the initial multidimensional time series data is judged to be abnormal (using If the second anomaly score is less than or equal to the preset anomaly detection threshold, that is, , it is judged as normal (using In this way, anomaly detection can be performed on each time step or data segment in the initial multidimensional time series data, thereby determining the anomalies in the entire time series data.
[0100] As can be seen from the above, in this application, the initial multidimensional time series data is first input into the model convolution layer of the anomaly detection large model, and after the convolution layer processing, the convolution layer output result is obtained. Then, the convolution layer output result is input into the long short-term memory network of the model loop layer of the anomaly detection large model, and after the calculation of the long short-term memory network, the single loop layer output result and the time step prediction matrix are determined. Then, with the help of the convolution layer output result, the time step prediction matrix and the dimension information of the single loop layer output result, it is input into the model self-attention loop layer of the anomaly detection large model. After the processing of the self-attention loop layer, the self-attention loop layer output result is obtained. Subsequently, according to the first preset result fusion mechanism, the single loop layer output result and the self-attention loop layer output result are fused to determine the fusion output result. After that, the initial multidimensional time series data is input into the model linear learning layer of the anomaly detection large model, and the linear output result is determined after the layer processing. Then, according to the second preset result fusion mechanism, the linear output result and the fusion output result are fused to obtain the target output result. Finally, the target output result is input into the decoder of the variational autoencoder, and the decoder outputs the target multidimensional time series data. The target multidimensional time series data is compared with the initial multidimensional time series data, and anomaly detection is carried out in combination with a preset anomaly detection threshold to determine whether there are anomalies in the initial multidimensional time series data. In this way, the present application can improve the accuracy of anomaly detection of multidimensional time series.
[0101] The technical solution of the embodiment of the present application is described in detail below in conjunction with an industrial maintenance scenario.
[0102] Specifically, during the operation of large engines, sensors distributed in various key parts of the engine play a key role. These sensors collect data in real time in multiple dimensions such as engine temperature, pressure, speed, and vibration frequency. Taking the temperature sensor as an example, it will continuously monitor the temperature changes in different parts of the engine, including cylinder temperature, coolant temperature, etc.; the pressure sensor will measure important parameters such as fuel pressure and oil pressure; the speed sensor is used to obtain engine speed information; and the vibration frequency sensor can capture the vibration of the engine during operation. The data collected by these sensors will be continuously updated over time, forming a multi-dimensional time series of the engine's operating status.
[0103] The collected multi-dimensional time series data is input into the anomaly detection model of this application. First, the convolution layer of the model processes these initial multi-dimensional time series data. The filters and convolutional neural networks in the convolution layer are like a "data sieve" that extract local features and patterns in the data. For example, it may identify a fixed relationship pattern between engine temperature, pressure, and speed under normal operating conditions.
[0104] The output obtained after the convolutional layer processing is input into the long short-term memory network of the model's recurrent layer. The long short-term memory network has a strong time series analysis capability. It can remember the information of the engine's operating status at different time points, thereby determining the output of a single recurrent layer and the time step prediction matrix. By analyzing these results, we can understand the development trend of the engine's operating status.
[0105] Next, the output of the convolutional layer, the time step prediction matrix, and the model self-attention loop layer are used to determine the output of the self-attention loop layer. The self-attention mechanism allows the model to focus on the important relationships between different dimensions in the data, such as the relationship between temperature changes and pressure and vibration frequency. Then, according to the first preset result fusion mechanism, the output of the single loop layer and the output of the self-attention loop layer are fused to obtain more comprehensive and accurate information.
[0106] The model's linear learning layer determines the linear output result based on the initial multi-dimensional time series data, and then combines the previous fusion output result to obtain the target output result through the second preset result fusion mechanism. This target output result integrates information from multiple analyses and processing, and can more accurately reflect the operating status of the engine.
[0107] Finally, the target multidimensional time series data is determined based on the target output result and the decoder. This target multidimensional time series data is compared with the initial multidimensional time series data, and combined with the preset anomaly detection threshold, it can be determined whether the engine has an abnormality.
[0108] When the anomaly detection model detects an anomaly in the multi-dimensional time series data of the engine, it means that the engine may have potential faults, such as component wear, abnormal vibration, etc. Enterprises can arrange preventive maintenance in a timely manner based on the detection results, such as replacing worn parts in advance and debugging the engine. This can avoid further deterioration of the fault, reduce equipment downtime, thereby reducing maintenance costs and improving the production efficiency and economic benefits of the enterprise.
[0109] Accordingly, see Figure 4 As shown, the embodiment of the present application provides a time series anomaly detection device based on a large model, wherein the large model is an anomaly detection large model constructed based on a variational autoencoder, a recurrent neural network, and a convolutional neural network; wherein the device includes:
[0110] A circulation layer output module 11, used to determine the convolution layer output result based on the model convolution layer of the anomaly detection large model and the initial multi-dimensional time series data, and to determine the single circulation layer output result and the time step prediction matrix based on the convolution layer output result and the long short-term memory network of the model circulation layer of the anomaly detection large model; wherein the model convolution layer includes a filter and the convolution neural network;
[0111] The first output result fusion module 12 is used to determine the self-attention loop layer output result by using the convolution layer output result, the time step prediction matrix, the dimension of the single loop layer output result and the model self-attention loop layer of the anomaly detection large model, and determine the fusion output result based on the single loop layer output result, the self-attention loop layer output result and the first preset result fusion mechanism; the model self-attention loop layer includes a self-attention mechanism and the long short-term memory network;
[0112] A second output result fusion module 13 is used to determine a linear output result based on the model linear learning layer of the anomaly detection large model and the initial multidimensional time series data, and determine a target output result using the linear output result, the fused output result and a second preset result fusion mechanism;
[0113] The anomaly detection module 14 is used to determine the target multidimensional time series data based on the target output result and the decoder of the variational autoencoder, and perform anomaly detection using the target multidimensional time series data, the initial multidimensional time series data and a preset anomaly detection threshold to determine the abnormal situation in the initial multidimensional time series data.
[0114] As can be seen from the above, in this application, the initial multidimensional time series data is first input into the model convolution layer of the anomaly detection large model, and after the convolution layer processing, the convolution layer output result is obtained. Then, the convolution layer output result is input into the long short-term memory network of the model loop layer of the anomaly detection large model, and after the calculation of the long short-term memory network, the single loop layer output result and the time step prediction matrix are determined. Then, with the help of the convolution layer output result, the time step prediction matrix and the dimension information of the single loop layer output result, it is input into the model self-attention loop layer of the anomaly detection large model. After the processing of the self-attention loop layer, the self-attention loop layer output result is obtained. Subsequently, according to the first preset result fusion mechanism, the single loop layer output result and the self-attention loop layer output result are fused to determine the fusion output result. After that, the initial multidimensional time series data is input into the model linear learning layer of the anomaly detection large model, and the linear output result is determined after the layer processing. Then, according to the second preset result fusion mechanism, the linear output result and the fusion output result are fused to obtain the target output result. Finally, the target output result is input into the decoder of the variational autoencoder, and the decoder outputs the target multidimensional time series data. The target multidimensional time series data is compared with the initial multidimensional time series data, and anomaly detection is carried out in combination with a preset anomaly detection threshold to determine whether there are anomalies in the initial multidimensional time series data. In this way, the present application can improve the accuracy of anomaly detection of multidimensional time series.
[0115] In some specific implementations, the circulation layer output module 11 specifically includes:
[0116] A height configuration unit, used to determine the height of the filter in the model convolution layer based on the number of data features in the initial multi-dimensional time series data, so as to complete the filter height configuration operation;
[0117] A width configuration unit, used to determine the width of the filter in the model convolution layer based on the period of the initial multi-dimensional time series data to complete the filter width configuration operation;
[0118] A filter configuration unit, configured to configure the parameters of the filter based on the filter height configuration operation and the filter width configuration operation, and obtain a configured filter;
[0119] A convolutional layer result generating unit is used to input the initial multi-dimensional time series data into the model convolutional layer of the anomaly detection large model, and generate a convolutional layer output result by using the ReLU activation function and the configured post-filter.
[0120] In some specific implementations, the circulation layer output module 11 specifically includes:
[0121] A convolutional layer result processing unit, used to input the convolutional layer output result into the long short-term memory network of the model recurrent layer of the large anomaly detection model, and process the convolutional layer output result using the forget gate, input gate and output gate in the long short-term memory network to obtain a processing result;
[0122] A single cycle layer result determination unit is used to obtain a hidden state and a time step prediction matrix from the processing result, and determine the hidden state as a single cycle layer output result.
[0123] In some specific implementations, the first output result fusion module 12 specifically includes:
[0124] A data determination unit, configured to input the convolution layer output result and the time step prediction matrix into the model self-attention recurrent layer of the anomaly detection large model, and determine the current time series data based on the convolution layer output result, the time step prediction matrix and the long short-term memory network in the model self-attention recurrent layer;
[0125] A vector determination unit, configured to determine a Query vector, a Key vector, and a Value vector based on the current time series data and the self-attention mechanism in the self-attention loop layer of the model;
[0126] A weight score determination unit, configured to perform a dot product on the Query vector and the Key vector to obtain a dot product result, and determine a weight score using the dot product result and a normalized exponential function;
[0127] A self-attention loop layer result determination unit is used to determine a weighted Value vector based on the weight score and the Value vector, and use the weighted Value vector to determine the output result of the self-attention mechanism, so as to determine the self-attention loop layer output result based on the dimension of the self-attention mechanism output result and the single loop layer output result.
[0128] In some specific implementations, the first output result fusion module 12 specifically includes:
[0129] A first weight coefficient determination unit, used to splice the single recurrent layer output result and the self-attention recurrent layer output result, and determine a first weight coefficient based on the obtained splicing result, a tanh activation function and a preset bias term;
[0130] a second weight coefficient determining unit, configured to perform a scaling operation on the first weight coefficient and obtain a second weight coefficient;
[0131] A result fusion unit is used to determine a fusion output result based on the second weight coefficient, the single loop layer output result and the self-attention loop layer output result.
[0132] In some specific implementations, the second output result fusion module 13 specifically includes:
[0133] A data input unit, used to input the initial multidimensional time series data into the model linear learning layer;
[0134] A data processing unit is used to process the initial multidimensional time series data using the autoregressive model in the linear learning layer of the model to obtain a processed linear output result.
[0135] In some specific implementations, the anomaly detection module 14 specifically includes:
[0136] a score determination unit, configured to determine a sample set containing only normal multidimensional time series data as a validation set, and determine a first anomaly score based on the validation set;
[0137] an information determination unit, configured to perform statistical analysis on the first anomaly score to determine a corresponding mean value and standard deviation;
[0138] a threshold determination unit, configured to determine a preset abnormality detection threshold based on the sum of the average value and a preset multiple of the standard deviation;
[0139] The anomaly detection unit is used to determine a second anomaly score based on the target multidimensional time series data and the initial multidimensional time series data, so as to determine the abnormality of the initial multidimensional time series data by using the second anomaly score and the preset anomaly detection threshold.
[0140] Furthermore, the present application also discloses an electronic device. Figure 5 It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment, and the content in the figure cannot be regarded as any limitation on the scope of use of this application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input and output interface 25 and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the time series anomaly detection method based on a large model disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0141] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0142] In addition, the memory 22 as a carrier for resource storage may be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon may include an operating system 221, a computer program 222, etc., and the storage method may be temporary storage or permanent storage.
[0143] The operating system 221 is used to manage and control the hardware devices and computer program 222 on the electronic device 20, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the time series anomaly detection method based on a large model performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to complete other specific tasks.
[0144] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the aforementioned disclosed method for detecting anomalies in a time series based on a large model is implemented. The specific steps of the method can be referred to the corresponding contents disclosed in the aforementioned embodiment, and will not be repeated here.
[0145] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.
[0146] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0147] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0148] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0149] The technical solution provided by the present application is introduced in detail above. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for general technicians in this field, according to the idea of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A time series anomaly detection method based on a large model, characterized in that: The large model is an anomaly detection large model constructed based on a variational autoencoder, a recurrent neural network, and a convolutional neural network; wherein the method comprises: Determine the convolution layer output result based on the model convolution layer of the anomaly detection large model and the initial multi-dimensional time series data, and determine the single recurrent layer output result and the time step prediction matrix based on the convolution layer output result and the long short-term memory network of the model recurrent layer of the anomaly detection large model; wherein the model convolution layer includes a filter and the convolution neural network; Determine the self-attention loop layer output result by using the convolution layer output result, the time step prediction matrix, the dimension of the single loop layer output result and the model self-attention loop layer of the anomaly detection large model, and determine the fusion output result based on the single loop layer output result, the self-attention loop layer output result and the first preset result fusion mechanism; the model self-attention loop layer includes a self-attention mechanism and the long short-term memory network; Determine a linear output result based on the model linear learning layer of the anomaly detection large model and the initial multidimensional time series data, and determine a target output result using the linear output result, the fusion output result and a second preset result fusion mechanism; Based on the target output result and the decoder of the variational autoencoder, target multidimensional time series data is determined, and anomaly detection is performed using the target multidimensional time series data, the initial multidimensional time series data, and a preset anomaly detection threshold to determine anomalies in the initial multidimensional time series data.
2. The time series anomaly detection method based on a large model according to claim 1 is characterized in that: The method of determining the output result of the convolution layer based on the model convolution layer of the anomaly detection large model and the initial multi-dimensional time series data includes: Determining the height of the filter in the convolutional layer of the model based on the number of data features in the initial multidimensional time series data to complete the filter height configuration operation; Determining the width of the filter in the model convolution layer based on the period of the initial multidimensional time series data to complete the filter width configuration operation; Configuring the parameters of the filter based on the filter height configuration operation and the filter width configuration operation, and obtaining a configured filter; The initial multi-dimensional time series data is input into the model convolution layer of the anomaly detection large model, and the convolution layer output result is generated using the ReLU activation function and the configured post-filter.
3. The time series anomaly detection method based on a large model according to claim 1 is characterized in that: The method of determining a single recurrent layer output result and a time step prediction matrix based on the convolutional layer output result and the long short-term memory network of the model recurrent layer of the large anomaly detection model includes: Input the output result of the convolution layer into the long short-term memory network of the model recurrent layer of the large anomaly detection model, and process the output result of the convolution layer using the forget gate, input gate and output gate in the long short-term memory network to obtain a processing result; A hidden state and a time step prediction matrix are obtained from the processing result, and the hidden state is determined as a single recurrent layer output result.
4. The time series anomaly detection method based on a large model according to claim 1 is characterized in that: The method of determining the self-attention recurrent layer output result by using the convolutional layer output result, the time step prediction matrix, the dimension of the single recurrent layer output result, and the model self-attention recurrent layer of the anomaly detection large model includes: Input the convolution layer output result and the time step prediction matrix into the model self-attention recurrent layer, and determine the current time series data based on the convolution layer output result, the time step prediction matrix and the long short-term memory network in the model self-attention recurrent layer; Determine a Query vector, a Key vector, and a Value vector based on the current time series data and the self-attention mechanism in the self-attention loop layer of the model; Performing a dot product on the Query vector and the Key vector to obtain a dot product result, and determining a weight score using the dot product result and a normalized exponential function; A weighted Value vector is determined based on the weight score and the Value vector, and the weighted Value vector is used to determine the output result of the self-attention mechanism, so as to determine the self-attention recurrent layer output result based on the dimension of the self-attention mechanism output result and the single recurrent layer output result.
5. The time series anomaly detection method based on a large model according to claim 1 is characterized in that: The determining of the fusion output result based on the single loop layer output result, the self-attention loop layer output result and the first preset result fusion mechanism includes: Splicing the single recurrent layer output result and the self-attention recurrent layer output result, and determining a first weight coefficient based on the obtained splicing result, a tanh activation function, and a preset bias term; Performing a scaling operation on the first weight coefficient to obtain a second weight coefficient; A fusion output result is determined based on the second weight coefficient, the single loop layer output result, and the self-attention loop layer output result.
6. The time series anomaly detection method based on a large model according to claim 1 is characterized in that: The determining of the linear output result based on the model linear learning layer of the anomaly detection large model and the initial multi-dimensional time series data includes: Inputting the initial multidimensional time series data into the model linear learning layer; The initial multidimensional time series data is processed using the autoregressive model in the linear learning layer of the model to obtain a processed linear output result.
7. The time series anomaly detection method based on a large model according to any one of claims 1 to 6, characterized in that: The performing anomaly detection using the target multidimensional time series data, the initial multidimensional time series data, and a preset anomaly detection threshold to determine anomalies in the initial multidimensional time series data includes: Determine a sample set containing only normal multidimensional time series data as a validation set, and determine a first anomaly score based on the validation set; performing statistical analysis on the first anomaly score to determine a corresponding mean and standard deviation; Determine a preset abnormality detection threshold based on the sum of the average value and a preset multiple of the standard deviation; A second anomaly score is determined based on the target multidimensional time series data and the initial multidimensional time series data, so as to determine an abnormality of the initial multidimensional time series data by using the second anomaly score and the preset anomaly detection threshold.
8. A time series anomaly detection device based on a large model, characterized in that: The large model is an anomaly detection large model constructed based on a variational autoencoder, a recurrent neural network, and a convolutional neural network; wherein the device comprises: A recurrent layer output module, used to determine the convolution layer output result based on the model convolution layer of the anomaly detection large model and the initial multi-dimensional time series data, and to determine the single recurrent layer output result and the time step prediction matrix based on the convolution layer output result and the long short-term memory network of the model recurrent layer of the anomaly detection large model; wherein the model convolution layer includes a filter and the convolution neural network; A first output result fusion module, used to determine the self-attention loop layer output result by using the convolution layer output result, the time step prediction matrix, the dimension of the single loop layer output result and the model self-attention loop layer of the anomaly detection large model, and determine the fusion output result based on the single loop layer output result, the self-attention loop layer output result and a first preset result fusion mechanism; the model self-attention loop layer includes a self-attention mechanism and the long short-term memory network; A second output result fusion module is used to determine a linear output result based on the model linear learning layer of the anomaly detection large model and the initial multidimensional time series data, and determine a target output result using the linear output result, the fused output result and a second preset result fusion mechanism; An anomaly detection module is used to determine the target multidimensional time series data based on the target output result and the decoder of the variational autoencoder, and perform anomaly detection using the target multidimensional time series data, the initial multidimensional time series data and a preset anomaly detection threshold to determine the abnormal situation in the initial multidimensional time series data.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the large model-based time series anomaly detection method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: Used to store computer programs; wherein, when the computer program is executed by a processor, the time series anomaly detection method based on a large model as described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Time series data anomaly detection method combining graph learning and double attention mechanism
CN118779804A
Reconstruction and prediction-based time sequence anomaly detection method
CN119089342A
Abnormal root cause positioning method and device based on attention mechanism and medium
CN119512798A
Early anomaly prediction on multi-variate time series data
US20190391574A1
Unsupervised anomaly detection, diagnosis, and correction in multivariate time series data
US20200064822A1