Complex event prediction method based on nested mode
By constructing a probability suffix automata (PSA) model and using flattening rules and symbolic automata to process nested patterns, the problem of difficulty in predicting complex events in the existing technology is solved, and efficient processing and prediction of nested patterns is achieved.
Patent Information
- Application Number
- CN202510044791.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-10
- Publication Date
- 2025-05-09
AI Technical Summary
It is difficult for the existing technology to effectively predict complex event, especially when dealing with nested patterns. The existing research mainly focuses on the SEQ pattern and cannot be directly applied to complex event prediction.
A complex event prediction method based on nested mode is adopted, and a probability suffix automata (PSA) model is constructed, and the flattening rules and symbolic automata are used to realize the processing of operators such as SEQ, OR, and AND, supporting the maximum nesting mode and flattening.
It realizes efficient processing and prediction of nested patterns, can support pattern prediction of complex events, and improves prediction accuracy and efficiency.
Smart Images

Figure CN119962741A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of complex event prediction, and in particular relates to a complex event prediction method based on nested patterns. Background Art
[0002] Complex event prediction (CEF) is a new and promising research direction. With the rapid development of Internet technology and the sharp increase in the amount of streaming data, large-scale event systems have become indispensable in many fields. It aggregates simple derived events (SDEs) occurring within the system and transforms them into more insightful complex events (CEs) for further analysis. The goal of complex event recognition (CER) is to detect and identify event patterns that have already occurred in real time in event streams, while CEF focuses on the prediction of event patterns. Specifically, CEF aims to predict when a specific complex event pattern will occur, and even provide early warning before the event occurs. For some event patterns that may have serious consequences, CEF can issue early warnings before they actually occur, so that the system can take timely intervention measures to avoid unnecessary losses and risks.
[0003] Mei’s research designed a tree-based model to handle complex event detection [1], which implemented some basic operators but did not optimize nested expressions. Liu’s work defined a series of flattening rules for handling nested patterns [2], which can be used for nesting of operators at any level, and used decomposition and shared merging techniques to improve the efficiency of multi-pattern detection, but it has stricter restrictions on the patterns of complex events, so it cannot be directly applied to CEF. Alevizos’ work used symbolic automata and Markov chains for CEF, but mainly focused on SEQ (sequential) patterns and did not implement nested patterns [3,4].
[0004] Existing research on nested patterns mainly focuses on complex event recognition, while for complex event prediction, existing research still mainly focuses on SEQ patterns.
[0005] References:
[0006] [1] Mei, Y., & Madden, S. (2009, June). Zstream: a cost-based query processor for adaptively detecting composite events. In Proceedings of the 2009ACMSIGMOD International Conference on Management of data (pp.193-206).
[0007] [2]Liu,M.,Rundensteiner,E.,Dougherty,D.,Gupta,C.,Wang,S.,Ari,I.,&Mehta,A.(2011,April).High-performance nested CEP query processing over eventstreams.In 2011IEEE 27th International Conference on Data Engineering(pp.123-134).IEEE.
[0008] [3]Alevizos,E.,Artikis,A.,&Paliouras,G.(2021).Symbolic RegisterAutomata for Complex Event Recognition and Forecasting.arXiv preprint arXiv:2110.04032.
[0009] [4]Alevizos,E.,Artikis,A.,&Paliouras,G.(2022).Complex eventforecasting with prediction suffix trees.The VLDB Journal,31(1),157-180. Summary of the invention
[0010] The purpose of the present invention is to provide a complex event prediction method based on nested patterns in order to be able to perform complex event prediction of nested patterns. The method designs a flattening rule for nested patterns and implements operators such as SEQ (sequence), OR (disjunction), and AND (conjunction) using symbolic automata. The present invention also defines nested patterns suitable for prediction. The present invention uses a predicted suffix tree (PST) and a probabilistic suffix automaton (PSA) as the probability model of the present invention, and constructs a PSA model to perform CEF.
[0011] To achieve the above object, the technical solution of the present invention is: a complex event prediction method based on nested patterns, comprising:
[0012] Constructing PSA Model M R ,The core of constructing the PSA model is the process of flattening the nested patterns and encoding the symbolic automaton;
[0013] Complex event prediction, PSA model constructed by the Institute of Computing RThe probability distribution of R The probability distribution of the prediction is used to calculate the probability of issuing a positive prediction or a negative prediction when issuing a prediction.
[0014] In one embodiment of the present invention, the nested pattern flattening process uses the complex event nesting language NEEL, including the flattening rule FLATTENING RULE and the distribution rule DISTRIBUTIVE RULE, which can support nesting with AND operator, OR operator, non-negation operator and sequential SEQ operator at any level, wherein:
[0015] The flattening rules are shown in the following table:
[0016]
[0017] The distribution rule DISTRIBUTIVE RULE is shown in the following table:
[0018]
[0019] Where E i Represents the event type, e i represents an event instance, n represents the length of the event in the group; the SEQ(A a,B b) operator represents that the SEQ operator sequentially accepts two types of events, A and B. Usually, for the sake of simplicity, when describing a pattern, it can be directly written as SEQ(A,B). Based on the flattening rule FLATTENING RULE and the distribution rule DISTRIBUTIVE RULE, if the nested parts of a pattern have the same operator, the flattening rule can be used to eliminate the nested parts. For example, a pattern = OR(OR(A,B),C), the flattening rule can be applied to simplify OR(A,B,C). If the nested parts of a pattern are SEQ or AND and OR nested, the distribution rule can be used to eliminate the nested parts. For example, a pattern = SEQ(OR(A,B),B), the distribution rule can be used to simplify the pattern to SEQ(A,B)OR SEQ(B,B).
[0020] In one embodiment of the present invention, for the field of traffic control, the process of encoding symbol automaton is specifically implemented as follows:
[0021] Suppose a certain pattern pattern = SEQ(AND(A, B), SEQ(B)), and apply the flattening rule FLATTENING RULE to obtain pattern = SEQ(AND(A, B), B), where pattern is directly encoded as a symbolic automaton, where event A represents smooth traffic, event B represents traffic congestion, SEQ is a sequence operator, SEQ(AND(A, B), SEQ(B)) means executing AND(A, B) and SEQ(B) in sequence, and AND is an AND operator, indicating that it is desired to receive consecutive A and B events, but they are not required to occur strictly in a specific order. The pattern pattern is intended to predict the beginning of road congestion, so as to facilitate drivers to make corresponding road planning decisions, thereby alleviating congestion and reducing the risk of accidents on the corresponding roads;
[0022] The method of implementing the pattern using symbolic automata is to uniformly convert the AND operator into a predetermined symbol with the predicate {A,B}. The use of the AND operator requires the maintenance of a sub-pattern table to record the order in which the events are received. When the characters in the AND operator are received and the characters are not repeated, the state of the symbolic automaton will be updated.
[0023] In one embodiment of the present invention, a PSA model M is constructed. R The specific implementation is as follows:
[0024] S1, input modeling data to build a prediction suffix tree PST;
[0025] S2. Based on the predicted suffix tree PST, a probabilistic suffix automaton PSA is constructed, where the nodes of PSA are leaf nodes in PST, and the edges between nodes represent the predicate and probability of transferring from one node to another;
[0026] S3, embed the probabilistic suffix automaton PSA into the pattern pattern implemented by symbolic automaton, and construct the PSA model M in an incremental way R The nodes are then added to each node using the structure of the probabilistic suffix automaton PSA, and the outgoing edges and their corresponding probabilities are obtained to obtain the PSA model M. R ,Each node has two attributes, which represent the current state of the symbolic automaton and the currently recorded event. The edge between nodes records the predicates that the edge needs to receive and their corresponding probabilities;
[0027] S4, based on the obtained PSA model M R, calculate the probability distribution Distribution of each node, by traversing each node, calculate all possible paths and probabilities from each node to its final node, and their collection constitutes the final probability distribution Distribution of each node.
[0028] In one embodiment of the present invention, in complex event prediction, based on the final probability distribution Distribution of each node, when publishing a prediction, the probability that the length of all possible paths of the corresponding prediction node is less than or equal to k is calculated. If the sum of the probabilities is greater than a preset value, a positive prediction is published, otherwise a negative prediction is published.
[0029] In one embodiment of the present invention, active prediction refers to the constructed PSA model M R The final state can be reached within the next k steps.
[0030] In one embodiment of the present invention, active prediction refers to the constructed PSA model M R The final state cannot be reached within the next k steps.
[0031] In one embodiment of the present invention, the method can be applied to the field of itinerary management, and by analyzing historical weather to predict the occurrence of severe weather, huge economic losses can be avoided.
[0032] In one embodiment of the present invention, the method can be applied to the field of financial fraud prevention. By analyzing historical financial transaction data and fraud methods, combined with behavioral analysis and pattern recognition, potential financial fraud risks can be predicted, helping to identify and prevent fraudulent activities and reduce economic losses to investors and financial institutions.
[0033] The present invention also provides a computer-readable storage medium, on which computer program instructions that can be executed by a processor are stored. When the processor executes the computer program instructions, the method steps described above can be implemented.
[0034] Compared with the prior art, the present invention has the following beneficial effects:
[0035] 1. The present invention is based on NEEL and can accurately express the pattern input by the user;
[0036] 2. The present invention can support the maximum nested mode and can flatten the nested mode.
[0037] 3. The present invention implements structured operations such as AND and OR. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 Model a flow chart for the present invention.
[0039] Figure 2 This is a prediction flow chart of the present invention.
[0040] Figure 3 NEEL is a complex event nesting language.
[0041] Figure 4 The symbolic automaton structure is pattern = SEQ(AND(A,B),B), and the predicate is {A,B}.
[0042] Figure 5 The process of constructing the PSA model.
[0043] Figure 6 PSA model M constructed for the present invention example R .
[0044] Figure 7 This is a comparison chart of the number of nodes of the AND operator before and after optimization as the event changes.
[0045] Figure 8 This is a graph of PSA experimental results. DETAILED DESCRIPTION
[0046] The technical solution of the present invention is described in detail below in conjunction with the accompanying drawings.
[0047] The present invention provides a complex event prediction method based on nested patterns, comprising:
[0048] Constructing PSA Model M R ,The core of constructing the PSA model is the process of flattening the nested patterns and encoding the symbolic automaton;
[0049] Complex event prediction, PSA model constructed by the Institute of Computing R The probability distribution of R The probability distribution of the prediction is used to calculate the probability of issuing a positive prediction or a negative prediction when issuing a prediction.
[0050] The following is the specific implementation process of the present invention.
[0051] The present invention provides a complex event prediction method based on nested patterns, the purpose of which is to be able to perform complex event prediction of nested patterns. The method is mainly divided into two parts, the first part is to build a PSA model part, and the second part is to perform the prediction part.
[0052] The process of building a PSA model is as follows: Figure 1 The core of model building is the process of flattening nested patterns and encoding symbolic automata. The flowchart for executing prediction is shown in Figure 2As shown, it is necessary to calculate its probability distribution Distribution, and use Distribution to calculate the probability when publishing a prediction to publish a positive prediction or a negative prediction.
[0053] 1. Nested expression rewriting rules
[0054] The present invention uses NEEL, which can support nesting AND, OR, negation and SEQ operators at any level. There are mainly FLATTENING RULE and DISTRIBUTIVE RULE, as shown in Table 1 and Table 2.
[0055] Table 1
[0056]
[0057] Table 2
[0058]
[0059] Where E i Represents the event type, e i represents an event instance, and n represents the length of the event in the group; the SEQ(A a,B b) operator represents that the SEQ operator sequentially accepts two types of events, A and B. Usually, for simplicity, when describing a pattern, it can be directly written as SEQ(A,B). If the nested part of a pattern uses the same operator, the nesting can be eliminated by the flattening rules in Table 1. For example, pattern = OR(OR(A,B),C), the flattening rule can be applied to simplify OR(A,B,C). In addition, if the nested part of the pattern is a combination of SEQ or AND and OR, the allocation rule in Table 2 can be used to eliminate the nested part. For example, the pattern pattern = SEQ(OR(A,B),B), the allocation rule can be used to simplify the pattern to SEQ(A,B)OR SEQ(B,B). Flattening the pattern can not only reduce the difficulty of pattern coding, but also reduce the complexity of the coding automaton. For example, the example pattern = OR(OR(A,B),C), the flattening rule is applied to simplify it to OR(A,B,C). If the pattern is not simplified, it is necessary to encode the inner sub-pattern OR(A,B) first and then encode the outer sub-pattern. After simplification, it is only necessary to directly encode OR(A,B,C).
[0060] 2. Coded Symbolic Automata
[0061] The present invention uses traffic control to explain the method of encoding symbolic automata of the present invention. Taking the pattern pattern = SEQ(AND(A, B), B) as an example, this pattern no longer needs to be rewritten and can be directly encoded as a symbolic automaton. Among them, event A represents smooth traffic and event B represents traffic congestion. This pattern is designed to predict the beginning of congestion on the road, so that drivers can make appropriate road planning decisions, thereby alleviating congestion and reducing the risk of accidents on these key sections.
[0062] Figure 4 In order to realize this pattern method using symbolic automata, the present invention converts the AND operator into a symbol ("#1" is used in this example). The use of the AND operator requires the maintenance of a sub-pattern table, which records the order of received events. When the characters in the AND operator (and no repetition) are received, the state of the automaton will be updated.
[0063] 3. Build a probability model
[0064] Next, we will introduce the construction of PSA model M R The present invention uses the historical traffic flow of a road intersection as modeling data to construct a Figure 6 In the PST in (left), taking leaf node AA as an example, it means that after two consecutive events A occur, the probability of event A continuing to occur is 0.1. Figure 6 (Right) is its corresponding PSA. The nodes of PSA are leaf nodes in PST, and the edges between nodes represent the predicate and probability of transferring from one node to another.
[0065] Next, the PSA needs to be embedded into the pattern, and the present invention implements this step incrementally. Figure 6 is to use Figure 5 PSA Embedded in Figure 4 The result of the symbolic automaton in the example is shown in Figure 1, where the gray nodes and edges are meaningless, i.e., nodes that cannot be reached by the path. Each node has two attributes, representing the current state of the automaton and the currently recorded event. The edge between nodes records the predicates it needs to receive and their corresponding probabilities. The present invention constructs M by incrementally R The nodes of the graph are added to each node using the PSA structure and their corresponding probabilities. Taking the (0, AA) node as an example, (0, AA)->(1, AA) represents M R After receiving event A, it changes from state 0 to state 1, corresponding to Figure 4 The automaton in is 0->1. The edge (0, AA)->(1, AA) corresponds to the edge in PSA where the AA node receives the A event and changes to state AA.
[0066] In getting M R After that, the present invention can use it to calculate the Distribution of each node, and by traversing each node, calculate all the paths and probabilities of the final node (3, B). Assume that the present invention calculates the Distribution for the state (2, B), and by executing the traversal algorithm on the state (2, B), the shortest path is path1 = (2, B) -> (3, B) with a length of 1. The present invention is simplified as the predicate set on its edges, that is, path1 = {B}, with a probability of 0.5. Then, by continuing the traversal, path2 = {A, B} is obtained, with a probability of 0.325. Finally, all possible paths are obtained, and their sets constitute the final Distribution.
[0067] 4. Release forecast
[0068] The purpose of the prediction of the present invention is to determine whether the automaton can reach the final state of the automaton within the next k steps (that is, whether this pattern will occur). Figure 6 M R For example, since there are three starting states, the present invention needs to observe the data in the stream first and select the initial starting point. If two A events are received consecutively, then (0, AA) is selected as the starting point. R Accept events in the stream. Suppose that after processing a number of events, M R Arriving at state (2, B), at this point, the probability of all paths with lengths less than or equal to k is calculated using the Distribution obtained above for (2, B). If the sum of the probabilities is greater than the preset threshold, M is predicted. R Will reach the final state within the next k steps, otherwise predict M R The final state will not be reached within k steps.
[0069] 5. Experimental results
[0070] Through a large number of experiments, the present invention uses the US meteorological data set and the traffic flow data set to verify the method of the present invention and verify the feasibility of encoding the nested pattern into a symbolic automaton. The experiment shows that the present invention has significantly optimized the storage structure for the implementation of the AND structure, such as Figure 7 As shown in FIG. 1 , when the number of events in the AND operator increases from 1 to 5, the number of nodes required by the unoptimized AND structure increases rapidly, while the present invention keeps the number of nodes required by the AND structure at a lower level. The performance of the PSA model continues to improve as the modeling order m increases, as shown in FIG. Figure 8As shown in the figure, the larger the area enclosed by the curve and the X-axis, the higher the accuracy of the model. When m=6, the area enclosed by the curve and the X-axis is the largest, which means that the model has the strongest predictive ability.
[0071] The present invention can be applied to the following fields:
[0072] 1. Traffic control: Based on historical data, the vehicle data at the intersection can be analyzed and traffic can be controlled when necessary.
[0073] 2. Trip management: Predict bad weather by analyzing historical weather to avoid huge economic losses.
[0074] 3. Financial fraud prevention: By analyzing historical financial transaction data and fraud methods, combined with behavioral analysis and pattern recognition, we can predict potential financial fraud risks, help identify and prevent fraudulent activities, and reduce economic losses to investors and financial institutions.
[0075] The present invention also provides a computer-readable storage medium, on which computer program instructions that can be executed by a processor are stored. When the processor executes the computer program instructions, the method steps described above can be implemented.
[0076] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.
[0077] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0078] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0079] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0080] The above is only a preferred embodiment of the present invention, and does not limit the present invention in other forms. Any technician familiar with the profession may use the above disclosed technical content to change or modify it into an equivalent embodiment with equivalent changes. However, any simple modification, equivalent change and modification made to the above embodiment according to the technical essence of the present invention without departing from the technical solution of the present invention still belongs to the protection scope of the technical solution of the present invention.
Claims
1. A complex event prediction method based on nested patterns, characterized in that: include: Constructing PSA Model M R ,The core of constructing the PSA model is the process of flattening the nested patterns and encoding the symbolic automaton; Complex event prediction, PSA model constructed by the Institute of Computing R The probability distribution of R The probability distribution of the prediction is used to calculate the probability of issuing a positive prediction or a negative prediction when issuing a prediction.
2. The complex event prediction method based on nested patterns according to claim 1, characterized in that: The nested pattern flattening process uses the complex event nesting language NEEL, including the flattening rule FLATTENING RULE and the distribution rule DISTRIBUTIVE RULE, which can support nesting with AND operators, OR operators, non-negation operators and sequential SEQ operators at any level, among which, The flattening rules are shown in the following table: The distribution rule DISTRIBUTIVE RULE is shown in the following table: Where E i Represents the event type, e i represents an event instance, and n represents the length of the event in the group; based on the flattening rule FLATTENING RULE and the distributing rule DISTRIBUTIVE RULE, if the nested part of a pattern has the same operator, the flattening rule FLATTENING RULE can be used to eliminate the nested part; if the nested part of a pattern is a SEQ or AND and OR nested, the distributing rule DISTRIBUTIVE RULE can be used to eliminate the nested part.
3. The complex event prediction method based on nested patterns according to claim 2, characterized in that: For the field of traffic control, the process of encoding symbolic automata is implemented as follows: Suppose a certain pattern pattern = SEQ(AND(A,B),SEQ(B)), and apply the flattening rule FLATTENING RULE to obtain pattern = SEQ(AND(A,B),B), where pattern is directly encoded as a symbolic automaton, event A represents smooth traffic, event B represents traffic congestion, SEQ(AND(A,B),SEQ(B)) means executing AND(A,B) and SEQ(B) in sequence, indicating that it is desired to receive consecutive events A and B, but they are not required to occur strictly in a specific order. The pattern pattern is intended to predict the beginning of road congestion, so as to facilitate drivers to make corresponding road planning decisions, thereby alleviating congestion and reducing the risk of accidents on the corresponding roads; The method of implementing the pattern using symbolic automata is to uniformly convert the AND operator into a predetermined symbol with the predicate {A,B}. The use of the AND operator requires the maintenance of a sub-pattern table to record the order in which the events are received. When the characters in the AND operator are received and the characters are not repeated, the state of the symbolic automaton will be updated.
4. The complex event prediction method based on nested patterns according to claim 3 is characterized in that: Constructing PSA Model M R The specific implementation is as follows: S1, input modeling data to build a prediction suffix tree PST; S2. Based on the predicted suffix tree PST, a probabilistic suffix automaton PSA is constructed, where the nodes of PSA are leaf nodes in PST, and the edges between nodes represent the predicate and probability of transferring from one node to another; S3, embed the probabilistic suffix automaton PSA into the pattern pattern implemented by symbolic automaton, and construct the PSA model M in an incremental way R The nodes are then added to each node using the structure of the probabilistic suffix automaton PSA, and the outgoing edges and their corresponding probabilities are obtained to obtain the PSA model M. R ,Each node has two attributes, which represent the current state of the symbolic automaton and the currently recorded event. The edge between nodes records the predicates that the edge needs to receive and their corresponding probabilities; S4, based on the obtained PSA model M R , calculate the probability distribution Distribution of each node, by traversing each node, calculate all possible paths and probabilities from each node to its final node, and their collection constitutes the final probability distribution Distribution of each node.
5. The complex event prediction method based on nested patterns according to claim 4, characterized in that: In complex event prediction, based on the final probability distribution of each node, when publishing a prediction, the probability that the length of all possible paths of the corresponding prediction node is less than or equal to k is calculated. If the sum of the probabilities is greater than the preset value, a positive prediction is published, otherwise a negative prediction is published.
6. The complex event prediction method based on nested patterns according to claim 5, characterized in that: Positive prediction refers to the constructed PSA model M R The final state can be reached within the next k steps.
7. The complex event prediction method based on nested patterns according to claim 5, characterized in that: Positive prediction refers to the constructed PSA model M R The final state cannot be reached within the next k steps.
8. The complex event prediction method based on nested patterns according to claim 1, characterized in that: The method can be applied to the field of itinerary management, and can predict the occurrence of severe weather by analyzing historical weather, thereby avoiding huge economic losses.
9. The complex event prediction method based on nested patterns according to claim 1, characterized in that: The method can be applied to the field of financial fraud prevention. By analyzing historical financial transaction data and fraud methods, combined with behavioral analysis and pattern recognition, it can predict potential financial fraud risks, help identify and prevent fraudulent activities, and reduce economic losses to investors and financial institutions.
10. A computer-readable storage medium having stored thereon computer program instructions that can be executed by a processor, and when the processor executes the computer program instructions, the method steps according to any one of claims 1 to 9 can be implemented.