Abnormality detection method and device, electronic equipment, storage medium and program product

By extracting and matching features of unlabeled data, combined with abnormal score detection, the existing abnormal detection methods have solved the problems of poor adaptability to dynamic data and high computing resources, and efficient abnormal detection performance has been achieved.

CN119961851AActive Publication Date: 2025-05-09HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510450757.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-05-09
Estimated Expiration
2045-04-11

AI Technical Summary

Technical Problem

Existing anomaly detection methods rely on a large number of labeled samples, consume large computing resources, poor adaptability to dynamically changing data, and catastrophic forgetting problems.

Method used

An abnormality detection method is proposed, by performing local feature extraction on unlabeled data, using a pre-constructed feature matching model to perform feature matching, calculate anomaly scores, and detecting based on the abnormal scores to identify abnormal areas.

Benefits of technology

This method can improve the detection performance of dynamic data and unknown anomalies, is suitable for practical application scenarios, reduces the demand for computing resources, and avoids catastrophic forgetting.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119961851A_ABST
    Figure CN119961851A_ABST
Patent Text Reader

Abstract

The invention provides an anomaly detection method and device, electronic equipment, a storage medium and a program product, and the method comprises the steps: determining unlabeled data of a to-be-detected task, carrying out the local feature extraction of the unlabeled data, and obtaining at least one unlabeled data feature; performing feature matching on the at least one unlabeled data feature through a pre-constructed feature matching model to obtain at least one neighbor feature fragment corresponding to the at least one unlabeled data feature; performing distance calculation on the at least one unlabeled data feature and the at least one neighbor feature fragment to obtain at least one abnormal score corresponding to the at least one unlabeled data feature; and performing detection based on the at least one abnormal score to obtain an abnormal region. According to the invention, the detection performance of dynamic data and unknown anomalies can be improved, and the method is closer to practical application.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of quality detection, and in particular to an abnormality detection method, device, electronic device, storage medium and program product. Background Art

[0002] This section is intended to provide a background or context to the embodiments of the disclosure that are recited in the claims. No description herein is admitted to be prior art by inclusion in this section.

[0003] Anomaly detection aims to identify data points or behaviors that significantly deviate from normal patterns. It builds a model of normal data and detects data that is significantly different from the model. It is widely used in industrial quality inspection, network security, medical imaging and other fields to detect abnormal situations such as defects, intrusions or diseases.

[0004] However, in the related technologies, there are problems such as anomaly detection methods relying on a large number of labeled samples, consuming large amounts of computing resources, having poor adaptability to dynamically changing data, and catastrophic forgetting. Summary of the invention

[0005] In view of this, the purpose of the present disclosure is to propose an anomaly detection method, device, electronic device, storage medium and program product, which at least to a certain extent solve one of the technical problems in the related art.

[0006] Based on the above purpose, the first aspect of the exemplary embodiment of the present disclosure provides an anomaly detection method, which is applied to a server, and the method includes: Determine unlabeled data of the task to be detected, perform local feature extraction on the unlabeled data, and obtain at least one unlabeled data feature; Performing feature matching on the at least one unlabeled data feature through a pre-built feature matching model to obtain at least one neighbor feature fragment corresponding to the at least one unlabeled data feature; Performing distance calculation on the at least one unlabeled data feature and the at least one neighboring feature segment to obtain at least one anomaly score corresponding to the at least one unlabeled data feature; Detection is performed based on the at least one anomaly score to obtain an abnormal region.

[0007] Based on the same inventive concept, the second aspect of the exemplary embodiment of the present disclosure provides an abnormality detection device, including: A data feature determination module is configured to determine unlabeled data of a task to be detected, perform local feature extraction on the unlabeled data, and obtain at least one unlabeled data feature; A feature segment determination module is configured to perform feature matching on the at least one unlabeled data feature through a pre-built feature matching model to obtain at least one neighbor feature segment corresponding to the at least one unlabeled data feature; an anomaly score determination module, configured to perform distance calculation on the at least one unlabeled data feature and the at least one neighboring feature segment to obtain at least one anomaly score corresponding to the at least one unlabeled data feature; The abnormal region determination module is configured to perform detection based on the at least one abnormality score to obtain an abnormal region.

[0008] Based on the same inventive concept, a third aspect of the exemplary embodiment of the present disclosure provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method described in the first aspect is implemented.

[0009] Based on the same inventive concept, a fourth aspect of the exemplary embodiments of the present disclosure provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the method described in the first aspect.

[0010] Based on the same inventive concept, a fifth aspect of the exemplary embodiments of the present disclosure provides a computer program product, including computer program instructions. When the computer program instructions are executed on a computer, the computer executes the method described in the first aspect.

[0011] From the above, it can be seen that the embodiments of the present disclosure provide anomaly detection methods, devices, electronic devices, storage media and program products, the method comprising: determining the unlabeled data of the task to be detected, performing local feature extraction on the unlabeled data, and obtaining at least one unlabeled data feature; performing feature matching on the at least one unlabeled data feature through a pre-constructed feature matching model, and obtaining at least one neighbor feature fragment corresponding to the at least one unlabeled data feature; performing distance calculation on the at least one unlabeled data feature and the at least one neighbor feature fragment, and obtaining at least one anomaly score corresponding to the at least one unlabeled data feature; performing detection based on the at least one anomaly score, and obtaining an abnormal area. The present disclosure can improve the detection performance of dynamic data and unknown anomalies, and is closer to practical applications. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the technical solutions in the present disclosure or related technologies, the drawings required for use in the embodiments or related technical descriptions are briefly introduced below. Obviously, the drawings described below are only embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0013] Figure 1 A schematic diagram of an application scenario of the anomaly detection method provided by an exemplary embodiment of the present disclosure; Figure 2 A flowchart of an abnormality detection method provided by an exemplary embodiment of the present disclosure; Figure 3 A schematic diagram of a process framework of an abnormality detection method provided by an exemplary embodiment of the present disclosure; Figure 4 A schematic diagram of a feature enhancement process of an anomaly detection method provided by an exemplary embodiment of the present disclosure; Figure 5 A schematic diagram of a structure of an abnormality detection device provided by an exemplary embodiment of the present disclosure; Figure 6 A schematic diagram of the hardware structure of an electronic device provided for an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION

[0014] It is understandable that before using the technical solutions disclosed in the embodiments of this application, the type, scope of use, usage scenarios, etc. of the personal information involved in this application should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.

[0015] For example, in response to receiving an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested to be performed will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, application, server, or storage medium that performs the operation of the technical solution of the present application according to the prompt message.

[0016] As an optional but non-limiting implementation, in response to receiving an active request from the user, the prompt information may be sent to the user in the form of a pop-up window, in which the prompt information may be presented in text form. In addition, the pop-up window may also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0017] It is understandable that the above notification and the process of obtaining user authorization are merely illustrative and do not constitute a limitation on the implementation method of the present application. Other methods that meet the relevant laws and regulations may also be applied to the implementation method of the present application.

[0018] It is understandable that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and relevant provisions.

[0019] In order to make the purpose, technical solutions and advantages of the present disclosure more clear, the principles and spirit of the present disclosure will be described with reference to several exemplary embodiments. It should be understood that these embodiments are provided only to enable those skilled in the art to better understand and implement the present disclosure, and are not intended to limit the scope of the present disclosure in any way. On the contrary, these embodiments are provided to make the present disclosure more thorough and complete, and to fully convey the scope of the present disclosure to those skilled in the art.

[0020] It should be understood herein that any number of elements in the drawings is for illustration rather than limitation, and any naming is only for distinction rather than having any limiting meaning.

[0021] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present disclosure should be understood by people with ordinary skills in the field to which the present disclosure belongs. The "first", "second" and similar words used in the embodiments of the present disclosure do not represent any order, quantity or importance, but are only used to distinguish different components. "Including" or "comprising" and similar words mean that the elements or objects appearing in front of the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connecting" or "connected" and similar words are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly. The article "one" or "a" before an element does not exclude the existence of multiple such elements.

[0022] The principle and spirit of the present disclosure are explained in detail below with reference to several representative embodiments of the present disclosure.

[0023] As described in the background technology, in the related art, there are problems such as anomaly detection methods relying on a large number of labeled samples, high consumption of computing resources, poor adaptability to dynamically changing data, and catastrophic forgetting. Specifically, the purpose of anomaly detection (AD) is to identify data points that are significantly deviated from the majority of data. Due to its wide application in different fields, it has attracted widespread attention from academia and industry: such as industrial inspection, medical imaging, scientific discovery and other fields.

[0024] In early studies, researchers regarded anomaly detection as a single classification task, and the proposed solution also required a large number of normal samples for model training. Such methods are usually called full-shot methods. Recently, the text-image contrast pre-training model CLIP (Contrastive Language-Image Pre-training) developed by the OpenAI team has demonstrated excellent zero-shot migration capabilities on a variety of computer vision tasks, which has opened up a new field for anomaly detection, namely the zero-shot anomaly detection method. Compared with traditional methods, zero-shot anomaly detection has higher flexibility and adaptability, and is particularly suitable for processing new categories and dynamically changing data scenarios.

[0025] Although the above progress has largely solved the problem of sample annotation difficulties, other major challenges still hinder the deployment of these methods. First, CLIP is not very adaptable to domain-specific data (such as medical images or industrial inspection data) and may require fine-tuning, which, as well as the subsequent inference process, consumes a lot of computing resources, which is a major challenge for deployment on edge devices with insufficient computing resources. Second, in complex and dynamic real-world environments, the categories of input data may change over time. In this case, anomaly detection algorithms must successfully run on both old and new categories at the same time. When category changes occur repeatedly, it is usually desirable to train the model on a series of tasks, where each task represents a change in the data. For example, in the factory quality inspection process, different industrial products continue to appear and defects need to be identified. However, neural networks are prone to an effect known as catastrophic forgetting: when learning a new task, artificial neural networks often forget the old tasks, and catastrophic forgetting greatly hinders the deployment of anomaly detection models in real-world scenarios.

[0026] In real-world environments, the categories of input data change over time. For example, in the field of cybersecurity, new types of cyberattacks may continue to emerge. In such dynamic scenarios, anomaly detection algorithms need to adapt to both known categories and newly introduced categories. However, when learning new tasks, neural networks often adjust weights to adapt to new data, which may cause previously learned knowledge to be overwritten or forgotten, a phenomenon known as catastrophic forgetting. For example, an image recognition system may forget previously learned categories when adding new categories. This catastrophic forgetting seriously affects the deployment and application of anomaly detection models in dynamic real-world scenarios.

[0027] In order to solve the above problems, the present disclosure provides an abnormality detection method, device, electronic device, storage medium and program product solution, the method comprising: Determine the unlabeled data of the task to be detected, perform local feature extraction on the unlabeled data, and obtain at least one unlabeled data feature; perform feature matching on the at least one unlabeled data feature through a pre-constructed feature matching model to obtain at least one neighbor feature fragment corresponding to the at least one unlabeled data feature; perform distance calculation on the at least one unlabeled data feature and the at least one neighbor feature fragment to obtain at least one anomaly score corresponding to the at least one unlabeled data feature; perform detection based on the at least one anomaly score to obtain an abnormal area. Traditional anomaly detection methods are mostly based on static training data, but in real applications, data usually changes dynamically. This dynamism may cause the model to degrade in performance due to catastrophic forgetting. Therefore, the present disclosure proposes a quasi-incremental anomaly detection method that is closer to actual application scenarios, but there is currently little related research.

[0028] In view of the limitations of convolutional neural networks (CNNs) in understanding global information, this paper introduces a self-attention mechanism to enhance features. By capturing long-distance dependencies, strengthening the correlation between features, and improving the perception of multi-scale abnormal patterns, this method can effectively improve the detection effect of unknown anomalies.

[0029] In addition, the present disclosure also adopts a weight-based abnormal feature selection method. The abnormal features in the feature space are regarded as "pollution". By analyzing the density changes of the feature distribution, low-density areas that are different from normal samples are identified and marked as abnormal features for exclusion. In this way, the model can focus more on learning the features of normal samples, thereby improving the overall performance.

[0030] After introducing the basic principles of the present disclosure, various non-limiting embodiments of the present disclosure are described in detail below.

[0031] refer to Figure 1 , which is a schematic diagram of an application scenario of the anomaly detection method provided by an exemplary embodiment of the present disclosure.

[0032] This application scenario includes a terminal device 101 and a server 102. The terminal device 101 and the server 102 may be connected via a wired or wireless communication network to achieve data interaction.

[0033] The terminal device 101 may be an electronic device with data transmission and multimedia input / output functions close to the user side, including but not limited to a desktop computer, a mobile phone, a mobile computer, a tablet computer, a media player, a smart wearable device, a personal digital assistant (PDA) or other electronic devices capable of realizing the above functions. The electronic device may include a processor and a display screen with a touch input function, the display screen is used to present a graphical user interface, the graphical user interface can display an application interface, and the processor is used to process application data, generate a graphical user interface, and control the display of the graphical user interface on the display screen.

[0034] Server 102 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), as well as big data and artificial intelligence platforms.

[0035] In some exemplary embodiments, the anomaly detection method may be executed on the terminal device 101 or the server 102 .

[0036] When the anomaly detection method is run on the server 102 , the server 102 is used to provide anomaly detection services to the user of the terminal device 101 .

[0037] The terminal device 101 determines the unlabeled data of the task to be detected and transmits the unlabeled data to the server 102; The server 102 receives the unlabeled data transmitted by the terminal device 101, and the server 102 extracts local features from the unlabeled data to obtain at least one unlabeled data feature; The server 102 performs feature matching on the at least one unlabeled data feature through a pre-built feature matching model to obtain at least one neighbor feature segment corresponding to the at least one unlabeled data feature; The server 102 performs distance calculation on the at least one unlabeled data feature and the at least one neighboring feature segment to obtain at least one anomaly score corresponding to the at least one unlabeled data feature; The server 102 performs detection based on the at least one anomaly score, and after obtaining the abnormal area, the server 102 transmits relevant information of the abnormal area to the terminal device 101 .

[0038] It should be noted that the above application scenarios are only shown to facilitate understanding of the spirit and principle of the present disclosure, and the embodiments of the present disclosure are not limited in this respect. On the contrary, the embodiments of the present disclosure can be applied to any applicable scenario.

[0039] refer to Figure 2 , an anomaly detection method, the method comprising the following steps: Step S210: determine unlabeled data for the task to be detected, perform feature extraction on the unlabeled data, and obtain at least one unlabeled data feature.

[0040] In specific implementation, the unlabeled data of the task to be detected refers to: In the anomaly detection task, there is no data that is pre-labeled as abnormal.

[0041] In a specific implementation, local feature extraction is performed on the unlabeled data to obtain at least one unlabeled data feature: In this exemplary embodiment, features can be extracted through the encoder of a generative adversarial network (GAN), features can be extracted using a model pre-trained on a large-scale data set (such as ResNet, VGG, BERT, etc.), features can be extracted through a contrastive learning framework (such as SimCLR, MoCo), feature extraction can be performed through a convolutional neural network, or other technical means can be used to perform local feature extraction on unlabeled data to obtain at least one unlabeled data feature, so as to subsequently match it with the features stored in a pre-built feature matching model.

[0042] Specifically, refer to Figure 3 , the figure includes a training process section (i.e., a feature matching model training section) and a testing process section; among them, class 1, class 2, class 3…class k in the testing process section represent several different input image examples, including images of industrial parts such as screws and gears, which are unlabeled. Local features are extracted from these unlabeled data to obtain at least one unlabeled data feature; these features are usually used to capture detailed information in the image, such as local patterns such as texture, edge, and shape, which are crucial for identifying abnormal areas in the image.

[0043] Step S220: performing feature matching on the at least one unlabeled data feature using a pre-built feature matching model to obtain at least one neighbor feature segment corresponding to the at least one unlabeled data feature.

[0044] In this exemplary embodiment, the feature matching model is constructed by the following method: Constructing an unlabeled data sample set for training, and performing feature extraction on a plurality of unlabeled data sample data in the unlabeled data sample set based on a convolutional neural network to obtain an initial feature set of the unlabeled sample data for training; Perform anomaly extraction based on the initial feature set of the unlabeled sample data for training to obtain a pure feature set of the unlabeled sample data for training; Performing feature sampling on the pure feature set of the unlabeled sample data for training to obtain a core feature set; A global feature memory library is constructed, and the core feature set is stored in the global feature memory library to obtain the feature matching model.

[0045] In a specific implementation, constructing an unlabeled data sample set for training, performing feature extraction on a plurality of unlabeled data sample data of the unlabeled data sample set based on a convolutional neural network, and obtaining an initial feature set of unlabeled sample data for training means: refer to Figure 3 , class 1, class 2, class 3…class k represent several different input image examples, including images of industrial parts such as screws and gears. These images are unlabeled and will be used for anomaly detection as a training set of unlabeled data samples for model training. A pre-trained convolutional neural network (such as WideResNet-50) is used as an encoder to extract the features Layer 2 and Layer 3 of the image, and extract patch-level features from Layer 2 and Layer 3. These features will be further processed to enhance their expressiveness.

[0046] As a specific example, in a zero-shot incremental anomaly detection task, a total of Γ different tasks need to be performed, each task contains data of multiple categories, and the categories between tasks are not exactly the same: In this task, the dataset is split into unlabeled subset streams, where the training set can be represented as ,in Represents the cth class in the dataset The training set and test set can be expressed as ,in Represents the cth class in the dataset For all c, After the sth incremental session, the model is tested on the categories it has seen: Each incremental session has C classes involved in anomaly detection, and the samples of each class are unlabeled samples. These unlabeled samples are subjected to feature extraction to obtain the initial feature set of unlabeled sample data for training.

[0047] In specific implementation, anomaly extraction is performed based on the initial feature set of the unlabeled sample data for training to obtain a pure feature set of the unlabeled sample data for training: refer to Figure 3 After enhancing the patch-level features from Layer 2 and Layer 3, abnormal features are identified, and then the identified abnormal features are removed to obtain a pure feature set of unlabeled sample data for training.

[0048] In specific implementation, feature sampling is performed on the pure feature set of the unlabeled sample data for training to obtain the core feature set: refer to Figure 3 , sample the features after removing abnormal features (i.e., the pure feature set of unlabeled sample data for training) and select the core feature set (CoreSet); by minimizing the maximum and minimum distances and other optimization methods, select a subset covering the core features of the samples, thereby removing redundant features, reducing feature dimensions, and improving matching efficiency.

[0049] As a specific embodiment, after removing the contamination features, feature sampling is performed on the feature space, and the patch weights are discarded in the detection stage. During the sampling process, the feature subset The core features of the sample should be covered as much as possible: . , and After feature sampling, a CoreSet of a single category is obtained. However, under the paradigm of incremental learning, a CoreSet of a single category cannot meet the needs of dynamic increase in data categories. Therefore, a global Memory Bank is set for all sessions of incremental learning. , which aims to include the CoreSet of all categories seen in incremental class learning. Assume that in incremental class learning, C categories have been seen and need to be detected for anomalies. The core feature set of the cth category is , then: .

[0050] In a specific implementation, a global feature memory is constructed, and the core feature set is stored in the global feature memory to obtain the feature matching model: refer to Figure 3, build a global feature repository to store core feature sets of different categories; specifically, in each session, add the core feature set of the new category to the Memory Bank (i.e., the global feature memory library), the feature sets stored in the MemoryBank are classified by category, and the feature set of each category is called CoreSet, and then the feature matching model is obtained.

[0051] In the above exemplary embodiment, a method of constructing a feature matching model is introduced. The following specifically introduces a method of obtaining an initial feature set of unlabeled sample data for training: In this exemplary embodiment, the initial feature set of unlabeled sample data for training includes: a mid-level feature set of unlabeled sample data for training and a high-level feature set of unlabeled sample data for training; The method of extracting features from a plurality of unlabeled data samples in the unlabeled data sample set based on a convolutional neural network to obtain an initial feature set of unlabeled sample data for training includes: Based on the convolutional neural network, feature extraction is performed on several unlabeled data sample data of the unlabeled data sample set to obtain the middle-level feature set of the training unlabeled sample data and the high-level feature set of the training unlabeled sample data.

[0052] In a specific implementation, a method of extracting features from a plurality of unlabeled data samples of the unlabeled data sample set based on a convolutional neural network to obtain a mid-level feature set of the unlabeled sample data for training and a high-level feature set of the unlabeled sample data for training is as follows: Following the above exemplary embodiment, an unlabeled sample set is given , in the setting of incremental learning, a convolutional neural network (CNN) is used to extract samples Assume that the feature map extracted by the lth convolutional layer of the pre-trained model E can be expressed as: . Eigenvector Representing images Patch-level feature representation at position.

[0053] The self-attention mechanism is combined with the traditional convolutional neural network (CNN) model to enhance the model's global perception ability and sensitivity to subtle features. ;in, Represents the convolutional neural network Layers (e.g. It can be expressed as Layer 2, which is the hierarchical feature set in the unlabeled sample data for training or It can be represented as a feature map extracted from Layer 3 (i.e., a high-level feature set of unlabeled sample data for training); represents a real number set, which means that the elements of the feature map are all real numbers; Indicates The width of the layer feature map (width); Indicates The height of the layer feature map (height); Indicates The number of channels of the layer feature map. The number of channels corresponds to the number of different features that the feature map can capture; Indicates that from A specific location extracted from the feature map of the layer The feature vector of , this position can be any point on the feature map, such as a pixel or a local area; represents a one-dimensional vector whose length is , that is, The number of channels of the layer.

[0054] In the above exemplary embodiment, a method of obtaining an initial feature set of unlabeled sample data for training is specifically introduced. Below, a method of obtaining a pure feature set of unlabeled sample data for training is specifically introduced: In this example embodiment, anomaly extraction is performed based on the initial feature set of the unlabeled sample data for training to obtain a clean feature set of the unlabeled sample data for training, including: Performing average pooling on the mid-level unlabeled sample data feature set for training to obtain the unlabeled sample data denoising feature set for training; Performing feature enhancement on the training high-level unlabeled sample data feature set to obtain the training unlabeled sample data enhanced feature set; Anomalies are extracted from the denoising feature set of the unlabeled training sample data and the enhanced feature set of the unlabeled training sample data to obtain a pure feature set of the unlabeled training sample data.

[0055] In a specific implementation, average pooling is performed on the feature set of the mid-level unlabeled sample data for training to obtain the denoising feature set of the unlabeled sample data for training; feature enhancement is performed on the feature set of the high-level unlabeled sample data for training to obtain the enhanced feature set of the unlabeled sample data for training: For Layer 2 feature enhancement (i.e., the mid-level unlabeled sample data feature set for training): Figure 3 , extract the original features of Layer 2 features and perform average pooling, add the pooled features of Layer 2 features to the enhanced features of the original features, and calculate the average similarity between the original features and the enhanced features of Layer 2 features s , if the similaritys Less than the preset threshold S If 0, the enhanced features of Layer 2 features are output; otherwise, the original features of Layer 2 features are output. For details, refer to Figure 4 , the original features extracted by Layer 2 , expressed as , the feature map is divided into multiple local areas (patches), and the feature of each patch is represented as , the original features Copy once for subsequent processing, and Perform average pooling to reduce the impact of noise; compare the pooled features with the original features Add together to get the enhanced features ; Calculate the original feature patch level features and enhanced features and enhanced features The average similarity between s ,if s < S 0, then the enhanced features are output ; Otherwise, output the original feature patch level feature .

[0056] As a specific example, given the patch-level feature set Different feature enhancement strategies can be used for the features of different convolutional layers. Given the patch-level features of Layer2 , the features can be averaged and pooled to reduce the impact of noise and retain important feature information: The features after pooling are , calculate feature similarity: .

[0057] For Layer 3 feature enhancement (i.e., high-level unlabeled sample data feature set for training): Figure 3 , after extracting the original features from Layer 3 features, the features are copied three times as query, key, and value respectively, and then the query, key, and value are enhanced through the self-attention mechanism to measure the similarity between the original features and the enhanced features of Layer 3 features s , if the similarity s Less than the preset threshold S If 0, the enhanced features are output; otherwise, the original features of Layer 3 are output. For details, refer to Figure 4 , input the original features extracted from Layer 3 , expressed as , the feature map is divided into multiple local areas (patches), and the feature of each patch is represented as , then Copy it three times as query, key and value respectively; perform max pooling on the value to highlight important features; flatten the query, key and pooled value for matrix operations; calculate the dot product of the query and key to get the attention score matrix; perform softmax normalization on the attention score to get the attention weight matrix, then multiply the attention weight matrix by the pooled value to get the weighted feature; then reshape the weighted feature back to the shape of the original feature; and combine the reshaped feature with the original feature Add together to get the enhanced features ; Calculate the original feature patch level features And the enhanced features The average similarity between s ,if s < S 0, then the enhanced features are output ; Otherwise, output the original feature patch level feature .

[0058] As a specific embodiment, a self-attention mechanism is introduced for the patch-level features of layer3 (i.e., the high-level unlabeled sample data feature set for training) to enhance the features. The eigenvectors in , copy the feature vector three times as the query, key, and value in the Transformer: .in is the eigenvector The depth of Indicates the maximum pooling of feature vectors to emphasize nearby features. is obtained by computing the relationship between pixels, which takes into account the connection between remote features. Specifically, the product of the query and the key is used as the weight, and the product of these weights with the softmax value and the feature value is calculated. Resize to the same size as the original feature map and calculate the similarity between the two: .

[0059] In a specific implementation, the method of performing anomaly extraction on the denoising feature set of the unlabeled training sample data and the enhanced feature set of the unlabeled training sample data to obtain the pure feature set of the unlabeled training sample data is as follows: refer to Figure 3, the output features of Layer 2 (i.e., the denoising feature set of unlabeled sample data for training) and the output features of Layer 3 (i.e., the enhanced feature set of unlabeled sample data for training) are concatenated to obtain the final feature representation; the local outlier factor (LOF) algorithm is used to identify abnormal features; wherein, by calculating the local reachable density of each feature point, the abnormal features in the low-density area are identified, the identified abnormal features are removed, and the normal features (i.e., the pure feature set of unlabeled sample data for training) are retained.

[0060] As a specific implementation example, in the process of extracting features from unlabeled samples, the abnormal features of abnormal samples are also extracted. The abnormal features in the feature space are regarded as a kind of pollution (relative to normal features), and the abnormal features in the feature space need to be identified and removed. The LOF (local outlier detection) algorithm is used to identify abnormal features. LOF normalizes clusters of different densities by calculating the relative density of each cluster, and also uses the local k-nearest neighbor distance as a metric to alleviate the overwhelming impact of large clusters. Given a feature patch-level feature , its k-distance can be expressed as , given the parameter k, the feature To other features The rechabilitydistance is: , express k-distance (i.e. To its k nearest neighbor distance), It is the L2-norm representation and The direct distance between The distance is less than or equal to The data point is called its k-nearest-neighbor (i.e., K-nearest neighbors (KNN)), denoted by , The local rechability density (LRD) is recorded as: . yes The set of k nearest neighbors of When there are no repeated neighbors, it is usually equal to the number of clusters k. As the local reachability density of patch-level features increases, the influence of large clusters is greatly reduced. In order to normalize the local density to relative density, the image-level relative density is given definition: .

[0061] Step S230: performing distance calculation on the at least one unlabeled data feature and the at least one neighboring feature segment to obtain at least one anomaly score corresponding to the at least one unlabeled data feature.

[0062] In this exemplary embodiment, performing distance calculation on the at least one unlabeled data feature and the at least one neighboring feature segment to obtain at least one anomaly score corresponding to the at least one unlabeled data feature includes: Calculating an average distance between the at least one unlabeled data feature and the at least one neighboring feature segment to obtain an average Euclidean distance; The average Euclidean distance is estimated to obtain the at least one anomaly score corresponding to the at least one unlabeled data feature.

[0063] In a specific implementation, the average distance between the at least one unlabeled data feature and the at least one neighboring feature fragment is calculated to obtain an average Euclidean distance; the average Euclidean distance is estimated to obtain the at least one anomaly score corresponding to the at least one unlabeled data feature: refer to Figure 3 During the test, for each sample to be tested (i.e., unlabeled data features), the K-nearest neighbor (KNN) algorithm is used to search for the nearest neighbor features in the Memory Bank; specifically, N nearest neighbor features are searched from the Memory Bank to build a local feature library; the anomaly score is calculated based on the similarity between the nearest neighbor features and the features of the sample to be tested.

[0064] As a specific example, under the class incremental learning paradigm, the test data of the cth category in the sth session is , and its corresponding feature set to be detected is For each sample to be tested Using the K nearest neighbor method for anomaly detection, this application searches for the corresponding N nearest neighbors in the Memory Bank to build a local feature library, and takes the average distance of the N nearest neighbors to determine the anomaly of the feature patch of the test sample. The neighbor feature block of : ,in is the function for calculating distance (i.e., Euclidean distance calculation function).

[0065] Estimate the anomaly score using the average Euclidean distance: ;in For samples to be tested The raw anomaly score of and Proportional to distance The larger the anomaly score, Higher: ; Represented as a global parameter that controls the influence of the exponential function; Represents the raw anomaly score The exponential function is used to amplify value, especially when When is large, the exponential function increases its value dramatically.

[0066] Step S240: Perform detection based on the at least one anomaly score to obtain an abnormal area.

[0067] In this exemplary embodiment, performing detection based on the at least one anomaly score to obtain an abnormal area includes: Determine whether the at least one anomaly score is within a preset indicator value range, and in response to the at least one anomaly score being greater than the preset indicator value range, take the at least one unlabeled data feature region corresponding to the at least one anomaly score greater than the preset indicator value range as the anomaly region.

[0068] In a specific implementation, the abnormal region is obtained by performing detection based on the at least one abnormality score: refer to Figure 3 ,According to the anomaly score, it determines whether the sample to be detected is abnormal, and locates the abnormal area, and finally outputs the anomaly detection result, including anomaly determination and location of abnormal area.

[0069] As a specific embodiment, the anomaly score of each unlabeled data feature region is first calculated, which reflects the degree of deviation of the feature region from the normal data distribution. Then, these anomaly scores are compared with the preset index value range to determine whether each feature region is abnormal. If at least one anomaly score exceeds the preset index value range, it indicates that the corresponding feature region is significantly different from the normal sample and is therefore marked as an abnormal region. This process allows the system to automatically identify and locate anomalies in the data without manual intervention, thereby improving the automation and efficiency of anomaly detection.

[0070] It should be noted that the method of the embodiment of the present disclosure can be performed by a single device, such as a computer or a server. The method of the present embodiment can also be applied in a distributed scenario and completed by multiple devices cooperating with each other. In the case of such a distributed scenario, one of the multiple devices can only perform one or more steps in the method of the embodiment of the present disclosure, and the multiple devices will interact with each other to complete the described method.

[0071] It should be noted that the above describes some embodiments of the present disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the above embodiments and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0072] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present disclosure also provides an abnormality detection device.

[0073] refer to Figure 5 , the abnormality detection device comprises: The data feature determination module 510 is configured to determine the unlabeled data of the task to be detected, perform local feature extraction on the unlabeled data, and obtain at least one unlabeled data feature; The feature segment determination module 520 is configured to perform feature matching on the at least one unlabeled data feature through a pre-built feature matching model to obtain at least one neighbor feature segment corresponding to the at least one unlabeled data feature; The anomaly score determination module 530 is configured to perform distance calculation on the at least one unlabeled data feature and the at least one neighboring feature segment to obtain at least one anomaly score corresponding to the at least one unlabeled data feature; The abnormal region determination module 540 is configured to perform detection based on the at least one abnormality score to obtain an abnormal region.

[0074] In this exemplary embodiment, the data feature determination module 510 is specifically configured as follows: Unlabeled data of a task to be detected is determined, and local features are extracted from the unlabeled data to obtain at least one unlabeled data feature.

[0075] In this exemplary embodiment, the feature segment determination module 520 is specifically configured as follows: The at least one unlabeled data feature is feature matched by a pre-constructed feature matching model to obtain at least one neighbor feature fragment corresponding to the at least one unlabeled data feature; wherein the feature matching model is constructed by the following method: constructing a training unlabeled data sample set, extracting features of several unlabeled data samples of the unlabeled data sample set based on a convolutional neural network, and obtaining a mid-level feature set of the training unlabeled sample data and a high-level feature set of the training unlabeled sample data; performing average pooling on the training mid-level unlabeled sample data feature set to obtain a denoised feature set of the training unlabeled sample data; performing feature enhancement on the training high-level unlabeled sample data feature set to obtain an enhanced feature set of the training unlabeled sample data; performing anomaly extraction on the denoised feature set of the training unlabeled sample data and the enhanced feature set of the training unlabeled sample data to obtain a pure feature set of the training unlabeled sample data; performing feature sampling on the pure feature set of the training unlabeled sample data to obtain a core feature set; constructing a global feature memory library, storing the core feature set in the global feature memory library, and obtaining the feature matching model.

[0076] In this exemplary embodiment, the anomaly score determination module 530 is specifically configured to: An average distance is calculated between the at least one unlabeled data feature and the at least one neighboring feature segment to obtain an average Euclidean distance; and the average Euclidean distance is estimated to obtain the at least one anomaly score corresponding to the at least one unlabeled data feature.

[0077] In this exemplary embodiment, the abnormal area determination module 540 is specifically configured as follows: Determine whether the at least one anomaly score is within a preset indicator value range, and in response to the at least one anomaly score being greater than the preset indicator value range, take the at least one unlabeled data feature region corresponding to the at least one anomaly score greater than the preset indicator value range as the anomaly region.

[0078] For the convenience of description, the above device is described by dividing it into various modules according to its functions. Of course, when implementing the present disclosure, the functions of each module can be implemented in the same or multiple software and / or hardware.

[0079] The device of the above embodiment is used to implement the corresponding abnormality detection method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be repeated here.

[0080] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments and methods, the present disclosure also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the anomaly detection method described in any of the above embodiments is implemented.

[0081] Figure 6 A more specific schematic diagram of the hardware structure of an electronic device provided in this embodiment is shown, and the device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are connected to each other through the bus 1050 in the device.

[0082] The processor 1010 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0083] The memory 1020 may be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 may store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program codes are stored in the memory 1020 and are called and executed by the processor 1010.

[0084] The input / output interface 1030 is used to connect the input / output module to realize information input and output. The input / output module can be configured in the device as a component (not shown in the figure), or it can be externally connected to the device to provide corresponding functions. The input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.

[0085] The communication interface 1040 is used to connect a communication module (not shown) to realize communication interaction between the device and other devices. The communication module can realize communication through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0086] The bus 1050 includes a path that transmits information between the various components of the device (eg, the processor 1010 , the memory 1020 , the input / output interface 1030 , and the communication interface 1040 ).

[0087] It should be noted that, although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040 and the bus 1050, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, it can be understood by those skilled in the art that the above device may also only include the components necessary for implementing the embodiments of the present specification, and does not necessarily include all the components shown in the figure.

[0088] The electronic device of the above embodiment is used to implement the corresponding abnormality detection method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be repeated here.

[0089] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present disclosure also provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute the anomaly detection method described in any of the above embodiments.

[0090] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.

[0091] The above-mentioned non-transitory computer-readable storage medium can be any available medium or data storage device that can be accessed by a computer, including but not limited to magnetic storage (such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc.), optical storage (such as CD, DVD, BD, HVD, etc.), and semiconductor storage (such as ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state drive (SSD)), etc.

[0092] The computer instructions stored in the storage medium of the above embodiment are used to enable the computer to execute the anomaly detection method described in any embodiment in the above exemplary method part, and have the beneficial effects of the corresponding method embodiment, which will not be repeated here.

[0093] Based on the same inventive concept, corresponding to the anomaly detection method described in any of the above embodiments, the present disclosure also provides a computer program product, which includes computer program instructions. In some embodiments, the computer program instructions can be executed by one or more processors of a computer so that the computer and / or the processor executes the anomaly detection method. Corresponding to the execution subject corresponding to each step in each embodiment of the anomaly detection method, the processor that executes the corresponding step may belong to the corresponding execution subject.

[0094] The computer program product of the above embodiment is used to enable the computer and / or the processor to execute the anomaly detection method described in any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0095] Those skilled in the art will appreciate that the embodiments of the present disclosure may be implemented as a system, method, or computer program product. Therefore, the present disclosure may be specifically implemented in the following forms, namely: complete hardware, complete software (including firmware, resident software, microcode, etc.), or a combination of hardware and software, generally referred to herein as a "circuit", "module", or "system". In addition, in some embodiments, the present disclosure may also be implemented in the form of a computer program product in one or more computer-readable media, which contains computer-readable program code.

[0096] Any combination of one or more computer-readable media may be used. A computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination thereof. More specific examples (non-exhaustive examples) of computer-readable storage media may include, for example: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium may be any tangible medium containing or storing a program that may be used by or in combination with an instruction execution system, device, or device.

[0097] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, which carry computer-readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0098] The program code embodied on the computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0099] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0100] It should be understood that each box in the flowchart and / or block diagram and the combination of boxes in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer or other programmable data processing device to produce a machine, and these computer program instructions are executed by a computer or other programmable data processing device to produce a device that implements the functions / operations specified in the boxes in the flowchart and / or block diagram.

[0101] These computer program instructions may also be stored in a computer-readable medium that enables a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable medium produce a product that includes an instruction device that implements the functions / operations specified in the blocks in the flowchart and / or block diagram.

[0102] Computer program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device so that a series of operational steps are performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby enabling the instructions executed on the computer or other programmable device to provide a process for implementing the functions / operations specified in the blocks in the flowchart and / or block diagram.

[0103] In addition, although the operations of the disclosed method are described in a particular order in the accompanying drawings, this does not require or imply that the operations must be performed in this particular order, or that all the operations shown must be performed to achieve the desired results. On the contrary, the steps depicted in the flow chart can be performed in a different order. Additionally or alternatively, some steps can be omitted, multiple steps can be combined into one step, and / or one step can be decomposed into multiple steps.

[0104] The flowchart and block diagram in the accompanying drawings illustrate the possible architecture, functions and operations of the system, method and computer program product according to various embodiments of the present application. Wherein, each box in the flowchart or block diagram can represent a module, a program segment, or a part of the code, and the above-mentioned module, program segment, or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0105] It should be noted that, although several modules or units of the equipment for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of two or more modules or units described above can be embodied in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into being embodied by multiple modules or units.

[0106] A person skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present application (including the claims) is limited to these examples. In line with the concept of the present application, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present application as described above, which are not provided in detail for the sake of simplicity.

[0107] In addition, to simplify the description and discussion, and in order not to make the embodiments of the present application difficult to understand, the well-known power / ground connections to the integrated circuit (IC) chip and other components may or may not be shown in the provided drawings. In addition, the device may be shown in the form of a block diagram to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present application are to be implemented (that is, these details should be fully within the scope of understanding of those skilled in the art). Where specific details (e.g., circuits) are set forth to describe exemplary embodiments of the present application, it is obvious to those skilled in the art that the embodiments of the present application can be implemented without these specific details or with changes in these specific details. Therefore, these descriptions should be considered illustrative rather than restrictive.

[0108] Although the present application has been described in conjunction with specific embodiments of the present application, many alternatives, modifications and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may use the discussed embodiments.

[0109] The embodiments of the present application are intended to cover all such substitutions, modifications and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application should be included in the scope of protection of the present application.

[0110] Although the spirit and principle of the present disclosure have been described with reference to several specific embodiments, it should be understood that the present disclosure is not limited to the disclosed specific embodiments, and the division of various aspects does not mean that the features in these aspects cannot be combined to benefit, and such division is only for the convenience of expression. The present disclosure is intended to cover various modifications and equivalent arrangements included in the spirit and scope of the attached claims. The scope of the attached claims conforms to the broadest interpretation, thereby including all such modifications and equivalent structures and functions.

Claims

1. An anomaly detection method, characterized in that: include: Determine unlabeled data of the task to be detected, perform local feature extraction on the unlabeled data, and obtain at least one unlabeled data feature; Performing feature matching on the at least one unlabeled data feature through a pre-built feature matching model to obtain at least one neighbor feature fragment corresponding to the at least one unlabeled data feature; Performing distance calculation on the at least one unlabeled data feature and the at least one neighboring feature segment to obtain at least one anomaly score corresponding to the at least one unlabeled data feature; Detection is performed based on the at least one anomaly score to obtain an abnormal region.

2. The method according to claim 1, characterized in that: The feature matching model is constructed by the following method: Constructing an unlabeled data sample set for training, and performing feature extraction on a plurality of unlabeled data sample data in the unlabeled data sample set based on a convolutional neural network to obtain an initial feature set of the unlabeled sample data for training; Perform anomaly extraction based on the initial feature set of the unlabeled sample data for training to obtain a pure feature set of the unlabeled sample data for training; Performing feature sampling on the pure feature set of the unlabeled sample data for training to obtain a core feature set; A global feature memory library is constructed, and the core feature set is stored in the global feature memory library to obtain the feature matching model.

3. The method according to claim 2, characterized in that The initial feature set of unlabeled sample data for training includes: a mid-level feature set of unlabeled sample data for training and a high-level feature set of unlabeled sample data for training; The method of extracting features from a plurality of unlabeled data samples in the unlabeled data sample set based on a convolutional neural network to obtain an initial feature set of unlabeled sample data for training includes: Based on the convolutional neural network, feature extraction is performed on several unlabeled data sample data of the unlabeled data sample set to obtain the middle-level feature set of the training unlabeled sample data and the high-level feature set of the training unlabeled sample data.

4. The method according to claim 3, characterized in that The extracting anomalies based on the initial feature set of the unlabeled sample data for training to obtain a pure feature set of the unlabeled sample data for training includes: Performing average pooling on the mid-level unlabeled sample data feature set for training to obtain the unlabeled sample data denoising feature set for training; Performing feature enhancement on the training high-level unlabeled sample data feature set to obtain the training unlabeled sample data enhanced feature set; Anomalies are extracted from the denoising feature set of the unlabeled training sample data and the enhanced feature set of the unlabeled training sample data to obtain a pure feature set of the unlabeled training sample data.

5. The method according to claim 1, characterized in that The performing distance calculation on the at least one unlabeled data feature and the at least one neighboring feature segment to obtain at least one anomaly score corresponding to the at least one unlabeled data feature includes: Calculating an average distance between the at least one unlabeled data feature and the at least one neighboring feature segment to obtain an average Euclidean distance; The average Euclidean distance is estimated to obtain the at least one anomaly score corresponding to the at least one unlabeled data feature.

6. The method according to claim 1, characterized in that The detecting based on the at least one anomaly score to obtain an abnormal area includes: Determine whether the at least one anomaly score is within a preset indicator value range, and in response to the at least one anomaly score being greater than the preset indicator value range, take the at least one unlabeled data feature region corresponding to the at least one anomaly score greater than the preset indicator value range as the anomaly region.

7. An abnormality detection device, characterized in that: include: A data feature determination module is configured to determine unlabeled data of a task to be detected, perform local feature extraction on the unlabeled data, and obtain at least one unlabeled data feature; A feature segment determination module is configured to perform feature matching on the at least one unlabeled data feature through a pre-built feature matching model to obtain at least one neighbor feature segment corresponding to the at least one unlabeled data feature; an anomaly score determination module, configured to perform distance calculation on the at least one unlabeled data feature and the at least one neighboring feature segment to obtain at least one anomaly score corresponding to the at least one unlabeled data feature; The abnormal region determination module is configured to perform detection based on the at least one abnormality score to obtain an abnormal region.

8. An electronic device, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method according to any one of claims 1 to 6 is implemented.

9. A non-transitory computer-readable storage medium, characterized in that: The non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to cause a computer to execute the method according to any one of claims 1 to 6.

10. A computer program product, characterized in that The method comprises computer program instructions, which, when executed on a computer, cause the computer to execute the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Display defect detection method based on deep learning, detector and training method

    CN117809137A

  • Flat wire winding welding spot defect detection method independent of defect data

    CN118505631A

  • Computer aided traffic enforcement using dense correspondence estimation with multi-level metric learning and hierarchical matching

    US20190065868A1