Equipment monitoring index screening method and system based on time sequence modeling

Through the equipment monitoring index screening method based on timing modeling, the NCDE model and time-varying correlation coefficient are used to filter out key indicators related to server status, solving the problem of difficulty in screening key indicators in the existing technology, and achieving efficient and low-overhead equipment monitoring and fault warning.

CN120011775AActive Publication Date: 2025-05-16HUNAN UNIV OF SCI & TECH

Patent Information

Application Number
CN202510457782.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-05-16
Estimated Expiration
2045-04-14

AI Technical Summary

Technical Problem

It is difficult for the prior art to screen out key indicators closely related to the server status from massive monitoring data, resulting in the possibility of missing critical abnormal signals in dynamic environments. In addition, traditional monitoring solutions have high requirements for real-time acquisition and storage of all indicators, resulting in high overhead.

Method used

The equipment monitoring index screening method based on timing modeling is used to map candidate monitoring indexes to hidden space through the NCDE model, capture their prediction residuals and hidden state evolution characteristics, and combine auxiliary parameters such as service response delay and business alarm information to calculate the time-varying correlation coefficient and importance score of the indicators, and finally filter out the target monitoring index.

Benefits of technology

It significantly improves the accuracy and adaptability of key indicator screening, reduces data acquisition and storage overhead, improves the early warning ability of potential failures, and realizes efficient and low-overhead equipment monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120011775A_ABST
    Figure CN120011775A_ABST
Patent Text Reader

Abstract

The invention discloses an equipment monitoring index screening method and system based on time sequence modeling, and relates to the field of server state analysis, and the method comprises the steps: obtaining equipment monitoring time sequence data; based on the candidate monitoring indexes and the auxiliary parameters, main input and extended input of the NCDE model are defined respectively, and prediction residual errors and hidden state evolution characteristics of the candidate monitoring indexes are captured through continuous time modeling; calculating a correlation coefficient between a prediction residual error of the candidate monitoring index and a system operation state in a continuous time window, and calculating a corresponding time-varying correlation coefficient; and fusing the prediction residual error, the time-varying correlation coefficient and the hidden state evolution characteristic of each candidate monitoring index to obtain a corresponding index comprehensive characteristic, evaluating an importance score corresponding to the index comprehensive characteristic, and screening a target monitoring index for equipment monitoring. Therefore, the accuracy and timeliness of the key indexes screened from the mass monitoring parameters of the server system are improved, and the data acquisition and storage overhead is effectively reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of server status analysis, and in particular to a method and system for screening equipment monitoring indicators based on time series modeling. Background Art

[0002] With the vigorous development of cloud computing, edge computing and the Internet of Things, the number of servers and various devices in modern data centers and distributed systems has exploded. There are many types of device monitoring indicators in modern data centers and cloud platforms, involving multiple dimensions such as CPU, memory, disk I / O, and network traffic.

[0003] Most existing feature selection algorithms (such as principal component analysis, correlation coefficient method, information gain, etc.) mainly rely on statistical analysis of static data, assuming that the data distribution and the correlation between indicators are basically stable throughout the monitoring cycle. However, in a dynamic environment, the operating status of the server is affected by multiple factors such as business load and network conditions, and the correlation between its indicators will change significantly. Static algorithms are difficult to adjust adaptively, resulting in the possibility of missing key abnormal signals in a specific time period.

[0004] In addition, traditional monitoring solutions often require real-time collection and storage of all indicators, which not only places a huge burden on the network and storage systems, but also in actual fault warning and status analysis, redundant data may mask key change signals.

[0005] Therefore, how to screen out key indicators closely related to server status from massive monitoring data and achieve low-overhead and efficient monitoring has become a difficult problem that needs to be solved urgently in the industry. Summary of the invention

[0006] The present application provides a device monitoring indicator screening method, system, storage medium, computer program product and electronic device based on time series modeling, which are used to at least solve the problem that current related technologies are difficult to screen out core key indicators closely related to server status from massive monitoring data.

[0007] In the first aspect, an embodiment of the present application provides a method for screening equipment monitoring indicators based on time series modeling, including: obtaining equipment monitoring time series data, wherein the equipment monitoring time series data covers multiple categories of candidate monitoring indicators and multiple categories of auxiliary parameters, wherein the auxiliary parameters include any one of the following: service response delay, business alarm information, and network delay; based on each category of the candidate monitoring indicators and each category of the auxiliary parameters, respectively define the main input and extended input of the NCDE model, so that the NCDE model uses the continuous time differential equation form to map the continuously changing candidate monitoring indicators to the latent space, and captures the prediction residuals and latent state of each category of the candidate monitoring indicators through continuous time modeling. state evolution characteristics; calculating the correlation coefficient between the prediction residual of each type of candidate monitoring indicator and the system operation state in a continuous time window, and performing weighted summation on the correlation coefficients of each time window to obtain the corresponding time-varying correlation coefficients of each type of candidate monitoring indicator; the system operation state is determined according to the service response delay and the request error rate in the corresponding time window; fusing the prediction residual, time-varying correlation coefficient and latent state evolution characteristics of each candidate monitoring indicator to obtain the corresponding comprehensive indicator characteristics, and evaluating the importance score corresponding to the comprehensive indicator characteristics; screening the target monitoring indicator for equipment monitoring from each candidate monitoring indicator according to the importance score.

[0008] In the second aspect, the embodiment of the present application provides an equipment monitoring indicator screening system based on time series modeling, including: a data acquisition unit, used to acquire equipment monitoring time series data, the equipment monitoring time series data covers multiple categories of candidate monitoring indicators and multiple categories of auxiliary parameters, the auxiliary parameters include any one of the following: service response delay, business alarm information and network delay; an NCDE analysis unit, used to define the main input and extended input of the NCDE model based on each category of the candidate monitoring indicators and each category of the auxiliary parameters, so that the NCDE model uses the continuous time differential equation form to map the continuously changing candidate monitoring indicators to the latent space, and captures the prediction residuals and latent state evolution characteristics of each category of the candidate monitoring indicators through continuous time modeling; A time-varying correlation analysis unit is used to calculate the correlation coefficient between the prediction residual of each type of candidate monitoring indicator and the system operation status within a continuous time window, and to perform weighted summation of the correlation coefficients of each time window to obtain the corresponding time-varying correlation coefficients of each type of candidate monitoring indicator; the system operation status is determined based on the service response delay and request error rate within the corresponding time window; an importance evaluation unit is used to fuse the prediction residual, time-varying correlation coefficient and latent state evolution characteristics of each candidate monitoring indicator to obtain the corresponding comprehensive indicator feature, and evaluate the importance score corresponding to the comprehensive indicator feature; a target indicator screening unit is used to screen the target monitoring indicator for equipment monitoring from each of the candidate monitoring indicators according to the importance score.

[0009] According to a third aspect, an electronic device is provided, comprising: at least one processor, and a memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the steps of the equipment monitoring indicator screening method based on time series modeling of any embodiment of the present application.

[0010] In a fourth aspect, an embodiment of the present application provides a storage medium on which a computer program is stored, characterized in that when the program is executed by a processor, the steps of the device monitoring indicator screening method based on time series modeling of any embodiment of the present application are implemented.

[0011] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps of the device monitoring indicator screening method based on time series modeling of any embodiment of the present application.

[0012] The device monitoring indicator screening method and system based on time series modeling provided by the present application can produce at least the following technical effects: (1) By introducing a time series modeling method based on the NCDE (Neural Controlled Differential Equations) model, the dynamic changes of equipment monitoring indicators are modeled using continuous-time differential equations, fully capturing the hidden state evolution characteristics and prediction residual characteristics of indicators over time, and further combining system state parameters to evaluate the importance of indicators, thereby significantly improving the accuracy and adaptability of key indicator screening. In addition, by introducing auxiliary parameters such as service response delay, business alarm information, and network delay as extended inputs in the NCDE model, the model can more accurately characterize the correlation between the server system status and monitoring indicators, effectively improving the accuracy of key indicator screening, thereby improving the early warning capability of potential failures.

[0013] (2) By analyzing the correlation between the prediction residual and the system operation status, the changes in the correlation of indicators can be discovered in a timely manner, enhancing the ability to capture key signals in a dynamic environment. In addition, when calculating the time-varying correlation coefficient, the weighted summation method is used to integrate the data of multiple time windows, which can effectively balance the short-term fluctuations and long-term trends in the time series data without increasing a large amount of computing overhead, further improving the stability of indicator screening.

[0014] (3) By integrating the prediction residuals, time-varying correlation coefficients, and latent state evolution characteristics of candidate monitoring indicators, a more comprehensive indicator feature is constructed. On this basis, the importance score of each indicator is evaluated. The influence of various candidate indicators on the system state is comprehensively evaluated by fusing multiple feature information. This enables indicator screening to not only identify indicators that have a strong correlation with the system state, but also capture those hidden indicators that have a potential indicative effect on abnormal changes in the system in a complex environment, further improving the comprehensiveness and stability of the screening results.

[0015] Through this technical solution, not only the accuracy and timeliness of key indicators selected from the massive monitoring parameters of the server system are improved, but also the data collection and storage overhead are effectively reduced, providing an efficient and low-overhead solution for equipment monitoring in data centers, cloud platforms and edge computing environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0017] Figure 1 A flowchart showing an example of a method for screening equipment monitoring indicators based on time series modeling according to an embodiment of the present application is shown; Figure 2 An operation flow chart of an example of screening target monitoring indicators according to importance scores according to an embodiment of the present application is shown; Figure 3 A structural block diagram of an example of a device monitoring indicator screening system based on time series modeling according to an embodiment of the present application is shown; Figure 4 It is a schematic structural diagram of an embodiment of an electronic device of the present application. DETAILED DESCRIPTION

[0018] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0019] In the technical solution of this application, the collection, storage, use, processing, transmission, provision and disclosure of user personal information involved shall comply with the relevant laws and regulations and shall not violate public order and good morals.

[0020] Figure 1 A flowchart of an example of a method for screening equipment monitoring indicators based on time series modeling according to an embodiment of the present application is shown.

[0021] Regarding the execution subject of the method of the embodiment of the present application, it can be any controller or processor with computing or processing capabilities. Specifically, it can be implemented by a server system management platform or a cloud platform management system, which effectively makes up for the shortcomings of traditional static feature selection methods in dynamic environments through the deep combination of time series modeling and NCDE models, realizes accurate screening and real-time dynamic adjustment of key monitoring indicators, and provides low-cost, high-efficiency, and highly adaptive technical support for equipment monitoring in modern data centers and cloud platforms.

[0022] In some examples, it may be integrated and configured in an electronic device or terminal by means of software, hardware, or a combination of software and hardware, and the type of the terminal or electronic device may be diverse, such as a mobile phone, a tablet computer, or a desktop computer, etc.

[0023] like Figure 1 As shown, in step S110, equipment monitoring time series data is obtained, and the equipment monitoring time series data covers multiple types of candidate monitoring indicators and multiple types of auxiliary parameters.

[0024] It should be noted that the types of candidate monitoring indicators can be diverse, and can be computing resource indicators (such as CPU utilization, CPU load, memory utilization, etc.), storage resource indicators (such as disk utilization, number of I / Os per second, I / O waiting queue length, etc.), network resource indicators (such as network traffic, network bandwidth utilization, etc.), etc. It can be that all service monitoring indicators are selected as the basis for analysis, or the scope of automatic screening of core indicators can be narrowed in advance according to service business needs.

[0025] In addition, the auxiliary parameters include any one of the following: service response delay, business alarm information and network delay. It should be pointed out that the auxiliary parameters may also partially overlap with some indicators in the candidate monitoring indicators, and the purpose of selecting auxiliary parameters is to use the parameters in the auxiliary indicators to highlight the business environment change information corresponding to the key abnormalities of the system equipment.

[0026] In some implementations, timestamp-based log data, performance monitoring tools (such as Prometheus, Zabbix) or system API interfaces can be used to obtain indicator data to ensure the continuity and integrity of time series data. In addition, preliminary aggregation (such as average values ​​or maximum values ​​per second or minute) can be performed at the collection level according to business needs, which not only reduces storage overhead but also provides smooth input data for subsequent time series modeling.

[0027] In step S120, the main input and extended input of the NCDE model are defined based on various candidate monitoring indicators and various auxiliary parameters, so that the NCDE model maps the continuously changing candidate monitoring indicators to the latent space using the continuous-time differential equation form, and captures the prediction residuals and latent state evolution characteristics of various candidate monitoring indicators through continuous-time modeling.

[0028] In some embodiments, for each candidate monitoring indicator (such as CPU utilization, memory usage, disk I / O, network traffic, etc.), a continuous time signal is constructed through data preprocessing (normalization, denoising, timing alignment, etc.), and used as the main input of the NCDE model. It should be noted that since the actual sampling is discrete data, a continuous function can be constructed using interpolation or piecewise linear methods to ensure the continuity of the model input. In addition, auxiliary parameters can also be preprocessed to construct a continuous control signal.

[0029] Here, the NCDE model is used to model the candidate monitoring indicators in continuous time, extract the prediction residual and hidden state evolution characteristics, and fuse auxiliary parameters to enhance the model expression ability. Specifically, the auxiliary parameters are fused with the time series data of the candidate indicators, for example, the information of the auxiliary parameters is embedded in the hidden state update by splicing, so that the model can perceive the impact of changes in the business environment on the dynamics of the candidate indicators.

[0030] The NCDE model uses the form of continuous-time differential equations to map the preprocessed candidate monitoring indicators (main input) into the latent space. At the same time, through the modulation of auxiliary parameters (extended input), it captures the prediction residuals and latent state evolution characteristics of the indicators, effectively handles the irregular sampling problem, and can also provide rich and accurate time series dynamics.

[0031] In step S130, the correlation coefficients between the prediction residuals of various candidate monitoring indicators and the system operating status are calculated in continuous time windows, and the correlation coefficients of various time windows are weighted and summed to obtain the corresponding time-varying correlation coefficients of various candidate monitoring indicators.

[0032] In some implementations, continuous time series data is divided into multiple overlapping or non-overlapping time windows according to business characteristics and monitoring requirements to ensure that the data in each window is sufficiently representative. Furthermore, in each time window, the trained NCDE model is used to predict the candidate monitoring indicators, and the residual between the actual value and the predicted value is calculated. Indicators with larger prediction residuals may have a more obvious fluctuation effect on the device status.

[0033] On the other hand, the system operation status is determined based on the service response delay and request error rate within the corresponding time window. The system operation status is determined based on the service response delay and request error rate within the time window, for example, through linear weighted fusion, so that the obtained comprehensive indicator system operation status not only measures the system's response speed to the request, but also considers the stability of the response correctness.

[0034] In each time window, the correlation coefficient between the prediction residual of the candidate monitoring indicator and the system operation status is calculated. The correlation coefficient can be measured in the form of Pearson correlation coefficient, Spearman rank correlation coefficient, etc., to capture the dynamic relationship between the candidate monitoring indicator and the system operation status in the corresponding time window. Then, the weighted summation method is used to summarize the correlation coefficients of each time window to obtain the time-varying correlation coefficient of each candidate indicator. In addition, the window weighting strategy can also be diversified, such as flexible adjustment based on the length of the time window, adaptive weights, or exponential smoothing weighting methods based on sliding windows, so as to smooth the accidental fluctuations that may exist in a single time window and improve the robustness of the time-varying correlation coefficient of the overall evaluation.

[0035] In step S140, the prediction residuals, time-varying correlation coefficients and latent state evolution characteristics of each candidate monitoring indicator are fused to obtain the corresponding comprehensive indicator characteristics, and the importance score corresponding to the comprehensive indicator characteristics is evaluated.

[0036] Here, feature fusion can be achieved by simple vector concatenation, weighted averaging, or nonlinear mapping and feature weighting based on multi-layer perceptrons, so that each feature can be reasonably reflected in the comprehensive features. In terms of importance scores, nonlinear models (such as lightweight neural networks or regression models) can be used to output the final importance scores. Through supervised learning of historical data or self-supervision mechanisms, model parameters are continuously optimized so that the model can capture the nonlinear relationship between features.

[0037] For example, in order to capture more complex nonlinear relationships between features, a lightweight neural network (such as a one- or two-layer fully connected network) can be used to train candidate monitoring indicators. The comprehensive feature vector of To model: , Formula (1) In the formula, represents the scoring network, The parameters of the scoring network are trained through supervised learning or self-supervised methods. Represents the importance score of the corresponding output, which can automatically learn the interactions and nonlinear relationships between features, thereby improving the scoring accuracy.

[0038] In step S150, target monitoring indicators for equipment monitoring are screened from various candidate monitoring indicators according to the importance scores.

[0039] Here, a variety of screening strategies can be set according to business needs, such as a fixed threshold method, a sorting method or an adaptive screening method. In the fixed threshold method, only indicators with importance scores higher than a set threshold are selected; in the sorting method, a preset number of indicators with top scores are selected; in the adaptive screening method, the number of indicators is dynamically adjusted according to the distribution characteristics of the importance scores, and all of them fall within the scope of implementation of the embodiments of the present application.

[0040] Through the screening method based on importance score, key indicators that have a significant impact on the equipment status can be accurately screened out, and the screened target monitoring indicators can be integrated into the actual monitoring platform, avoiding the ineffective monitoring of secondary or redundant indicators, greatly reducing the occupation of network, storage and computing resources, and improving the overall operation efficiency of the system. In addition, based on the high accuracy and real-time performance of the screened target monitoring indicators, the system can quickly detect abnormal conditions and provide effective data support for fault warning and performance optimization.

[0041] Figure 2 An operational flowchart of an example of screening target monitoring indicators according to importance scores according to an embodiment of the present application is shown.

[0042] like Figure 2 As shown, in step S210, each candidate monitoring indicator is screened according to a preset importance threshold to obtain at least one corresponding potential monitoring indicator.

[0043] Here, the importance threshold can be a preset fixed threshold or a dynamic threshold. For example, by setting a fixed value (such as 0.5 or 0.7) as the screening criterion, indicators with scores higher than the threshold are screened out. The threshold can also be adaptively set according to the distribution characteristics of the importance score (such as the mean, standard deviation or quantile) to ensure that the number of screened indicators is within a specific range.

[0044] In addition, through screening based on importance scores, redundant indicators that have little impact on the equipment status can be effectively eliminated, thereby reducing the size of the indicator set and the computational complexity of subsequent clustering analysis, ensuring that the potential monitoring indicators screened out have high relevance and representativeness, further improving the efficiency of the monitoring system and data processing performance.

[0045] In step S220, each potential monitoring indicator and the corresponding comprehensive indicator features are input into the dynamic DBSCAN model to determine at least one corresponding cluster, calculate the cluster feature vector center corresponding to each cluster, and select the potential monitoring indicator closest to the cluster feature vector center as the cluster representative monitoring indicator of the corresponding cluster.

[0046] Here, DBSCAN (Density-Based Spatial Clustering of Applications with Noise) can effectively identify clusters of different densities and exclude noise data, but the traditional DBSCAN has relatively fixed parameter settings. The dynamic DBSCAN model can adaptively adjust parameters (such as neighborhood radius and minimum number of samples) to improve the adaptability to data distribution and ensure accurate clustering under different data feature conditions.

[0047] Through the dynamic DBSCAN model, the potential monitoring indicators are divided into several clusters according to the similarity between the comprehensive characteristics of the indicators, and the cluster feature vector center of each cluster is calculated (that is, the average value of each feature vector in the cluster). In each cluster, the potential monitoring indicator closest to the cluster center is selected as the cluster representative monitoring indicator of the cluster. In this way, by selecting the indicator closest to the cluster center as the cluster representative monitoring indicator, it can be ensured that the indicator has a strong central feature and represents the overall characteristics of the cluster to the greatest extent, reducing the retention of repetitive and redundant indicators and improving the accuracy of indicator screening.

[0048] In step S230, a target monitoring indicator is determined according to the cluster representative monitoring indicators corresponding to each cluster.

[0049] In some embodiments, the cluster representative monitoring indicators selected from each cluster cluster can be directly used as the target monitoring indicators. Compared with direct screening based on importance scores, the optimization screening method provided in this embodiment selects cluster representative monitoring indicators as the final target monitoring indicators, ensuring that the screened indicators not only have high importance, but also have representativeness and stability in feature distribution, which can further reduce the redundancy between indicators, reduce data redundancy and storage overhead caused by repeated features, and ensure the independence and effectiveness of each monitoring indicator in describing the system status.

[0050] In the following, the relevant details of some example algorithms that may be involved or applied in the embodiments of the present application will be expanded. It should be understood that the description of these algorithms is only to facilitate the public to more conveniently understand the spirit of the present application, and is not intended to limit the scope of implementation of the present application. Other non-restrictive suitable algorithms may also be used.

[0051] Regarding the modeling details of the prediction residual of the candidate monitoring indicator in step S120, in some embodiments, the discrete sampled data is interpolated and converted into a continuous signal and normalized. Then, the candidate monitoring indicator is used as the main input, and the auxiliary parameter is used as the extended input. The continuous time differential equation modeling is used through the NCDE model to capture the time series dynamic characteristics. Finally, the predicted value is obtained through the decoder, and the predicted value is compared with the true value to calculate the prediction residual.

[0052] More specifically, it is assumed that the candidate monitoring indicators and auxiliary parameter discrete sampling data are expressed as and , Indicates Sampling time points, Represents the total number of sampling time points, and Respectively expressed in The sampled candidate monitoring indicator data values ​​and auxiliary parameter data values ​​are used to construct a continuous time series signal through interpolation method and normalize it to obtain the continuous time series signal of the corresponding candidate monitoring indicator and continuous timing signals of auxiliary parameters , to meet the input conditions of the NCDE model.

[0053] Here, in order to meet the NCDE requirement for "continuous time input", the original discrete data needs to be interpolated. For example, linear interpolation, spline interpolation or more advanced interpolation methods (such as local weighted regression) can be used to smoothly connect adjacent sampling points. In addition, if there is missing data or sampling anomalies, certain outlier detection and preprocessing are required before interpolation, such as using forward filling or mean filling strategies to ensure data continuity.

[0054] The continuous time series signal of the candidate monitoring indicators is transformed into Mapped to the hidden state space and using the continuous time series signal of the auxiliary parameters Modulate the model.

[0055] , Formula (2) In the formula, Indicates that in continuous time The hidden state of Indicates the initial time, represents the initial hidden state; is the integral variable, which means from arrive Any time point in between; represents the control function, parameterized by a neural network with parameters , this function is used to calculate the time The hidden state and extended input Dynamically calculate the rate of change of hidden states; Indicates the main input signal The increment in a small time interval, Represents the driving effect of candidate monitoring indicators on the evolution of hidden states.

[0056] It should be noted that in traditional discrete time series models such as RNN / LSTM, the state is updated at discrete time steps. However, in NCDE, the hidden state can be integrated and evolved at every moment in the time series, which has the natural advantage of handling irregular sampling and complex time-varying associations.

[0057] The control function is parameterized using an attention mechanism.

[0058] Specifically, in the control function, you can first and Mapped to the same latent space, and then get the attention weight through the attention network .like Contains multiple auxiliary sub-channels (such as alarm frequency, network RTT, business KPI), which can be spliced ​​and then reduced in dimension by a multi-layer perceptron (MLP) and then combined with Input them into the attention network for fusion.

[0059] , Formula (3) , Formula (4) In the formula, Represents a multi-layer perceptron in an attention network for nonlinear feature mapping; represents the vector concatenation operation, Indicates time The attention weight vector, , and They represent the hidden state weight matrix, auxiliary input weight matrix and attention bias term respectively.

[0060] here, Determined at the time At this point, the attention paid to the hidden state and auxiliary input is increased. If a dimension in the auxiliary input is particularly sensitive to the current state of the device, the attention will automatically increase its weight, and the importance of different auxiliary parameters will be dynamically scheduled through the attention mechanism. Splice to The data are then input into a multi-layer perceptron, which uses nonlinear mapping to calculate the incremental update of the hidden state. This way, when the device status is close to the critical value or business alarms occur frequently, the update process will be more intense, which will help capture subtle signs before failure.

[0061] It should be noted that although it is continuous time in theory, in practice the fourth-order Runge-Kutta (RK4) method is used to iteratively solve the problem at discrete sampling points. The value of .

[0062] Based on the decoder processing corresponding sampling time The hidden state , to infer at the next sampling time point The predicted value of candidate monitoring indicators .

[0063] , Formula (5) In the formula, represents the decoder function, represents the learnable parameters of the decoder.

[0064] Here, the decoder is defined as The hidden state is transformed to the moment Specifically, the decoder can use a simple MLP or a more complex network structure (such as convolution, Transformer decoder) to improve the capture of nonlinear relationships.

[0065] The predicted values ​​of the candidate monitoring indicators at each sampling time point are compared with the true observed values ​​to calculate the corresponding prediction residuals.

[0066] , Formula (6) In the formula, Indicates the sampling time The corresponding prediction residual is Indicates that at the sampling time The actual value of the candidate monitoring indicator collected at the location.

[0067] By analyzing the time series changes of residuals, sudden fluctuations and abnormal trends can be discovered in a timely manner. When the absolute value is continuously large, it means that the model has a clear lack of understanding of the device behavior in this interval, which often corresponds to potential failures or sudden interference. In addition, the prediction residuals of different types of indicators can be combined or normed to obtain the overall anomaly measure.

[0068] Through the embodiments of the present application, the continuous time property and attention mechanism of NCDE are used to enable the model to better cope with irregular sampling, load mutations and multiple business interferences. In addition, the prediction residual can clearly identify key indicators that are sensitive to faults, reduce the monitoring frequency of redundant indicators with little value, and save storage and computing overhead.

[0069] In some examples of the embodiments of the present application, the hidden state evolution characteristics include the hidden state mean, the hidden state variance, the hidden state instantaneous change rate and the hidden state cumulative change.

[0070] In the NCDE model, the hidden state will continue to evolve over time. In order to measure the overall level of the hidden state in a time interval, it is necessary to integrate and average it to obtain the hidden state mean, which reflects the basic operating level of the system in this time period.

[0071] , Formula (7) In the formula, Indicates the time interval The hidden state mean in Indicates from arrive At any point in time between Indicates from arrive Any time point between The hidden state of is a small time increment of the integral variable, representing the integral of a continuously changing process in time.

[0072] The value of is that it can quickly assess the "average level" of the system's hidden state over a period of time, which can be used to detect significant deviations from historical benchmarks.

[0073] Hidden state variance Reflects the system state relative to its mean value within the time interval The greater the variance, the more obvious the fluctuation of the system's operating status, and the more likely there is a potential abnormality or fault sign.

[0074] , Formula (8) In the formula, Indicates the time interval The hidden state variance within .

[0075] The value of is that it is complementary to the mean. It only reveals the "central level" of the system as a whole, while the variance It measures the dispersion around the center, and The abnormal increase of often indicates that the system state is unstable.

[0076] In the NCDE model, the input data meets the continuous time series requirements, so that each moment can be regarded as a differentiable state function, so the instantaneous rate of change can be naturally defined. Through the instantaneous rate of change of the hidden state, it is possible to capture whether the system has signs of sudden changes such as acceleration or deceleration in a short period of time, further improving the sensitivity to abnormalities.

[0077] , Formula (9) In the formula, Indicates at time The instantaneous rate of change of the hidden state, and Respectively indicate at time and The hidden state vector of is the preset time interval used for discretized derivative computations.

[0078] It is a very small time interval, which can be set according to the sampling resolution or integration step. When the system state suddenly changes, the instantaneous rate of change often has a peak value, which can reflect the signs of fault more promptly than just looking at the mean or variance.

[0079] Integrate the rate of change of the hidden state within the time interval to form a measure of the "total change amplitude" of the system state, which is similar to the "total distance" traveled by the curve in the latent space, and is used to define the cumulative change of the hidden state.

[0080] , Formula (10) In the formula, Indicates the time interval The cumulative change of hidden state in represents the Euclidean norm.

[0081] Focus on the dramatic changes at a certain moment, The focus is on whether the latent state has experienced a large migration or fluctuation during the entire time period. The two complement each other and jointly complete the abnormal identification of "chronic degradation" or "sudden failure".

[0082] Through the embodiments of the present application, four types of evolutionary features of the latent state are extracted, namely, the instantaneous rate of change, the cumulative change, the variance and the mean. Sudden events are detected by the instantaneous rate of change, slow evolution is identified by the cumulative change, the overall fluctuation is revealed by the variance, and the drift of the overall level is reflected by the mean. This can comprehensively cover different types of anomalies (suddenness, gradualness, etc.) in the system, and achieve multi-angle characterization and anomaly capture of the system or device status.

[0083] Regarding the details of the calculation of the time-varying correlation coefficient of the candidate monitoring indicator in step S130, in some embodiments, it can be designed through an exponentially weighted time-varying correlation coefficient to adapt to the dynamic changes of the system operation status in real time.

[0084] More specifically, the service response delay and request error rate at each sampling moment are weighted and fused to determine the corresponding system operation status.

[0085] , Formula (11) In the formula, Indicates the sampling time The system operating status, Indicates that the system is Service response delay, Indicates the sampling time The request error rate, is the balance weight parameter.

[0086] Here, the overall operating status of the system is abstracted into a comprehensive indicator of service response delay and request error rate. Through linear weighted fusion, not only the response speed of the system to the request is measured, but also the stability of the response correctness is considered. Therefore, through the composite state representation, system operation anomalies can be captured more sensitively, especially when the response is slow or the system is abnormal.

[0087] Assume Time windows Inside Sampling time, record candidate monitoring indicators Get the discrete prediction residual sequence within the time window , and record the system operation status sequence within the time window ;in, Indicates candidate monitoring indicators In the time window The first The prediction residual at sampling time, Indicates that in the time window The first The system operating status at a sampling moment.

[0088] In the time window, the Pearson correlation coefficient between the prediction residual sequence and the system state sequence is calculated for each candidate indicator. .

[0089] , Formula (12) In the formula, Represents candidate indicators In the time window The Pearson correlation coefficient within reflects the linear relationship between the prediction residual and the system state; Is a candidate indicator In the time window The mean of the internal prediction residuals, Represents a time window The mean of the internal system state.

[0090] Here, the correlation between the prediction residual of the candidate indicator and the system operation state sequence is calculated to determine whether the fluctuation of the prediction residual is closely related to the change of the overall state of the system. In this way, it is possible to identify which monitoring indicators’ prediction errors more directly reflect the system’s operation fluctuations or abnormal states.

[0091] The exponential decay weight mechanism is adopted to perform weighted averaging of the Pearson correlation coefficients of each time window to obtain the time-varying correlation coefficients of the candidate monitoring indicators.

[0092] , Formula (13) In the formula, Represents a time window The weight of The window end time and the current time decays with the increase of distance; is a positive parameter that controls the decay rate.

[0093] In formula (13), as time goes by, the closer time window should have a greater impact on the current prediction, and the farther away the data is, the less impact it has. The exponential decay mechanism reflects the principle of timeliness, enhances the sensitivity of the model to real-time data, can quickly respond to real-time changes in system status, and is more suitable for actual dynamic monitoring environments.

[0094] , Formula (14) In the formula, Represents candidate indicators The time-varying correlation coefficient of is the total number of time windows.

[0095] In formula (14), the correlation coefficients of multiple windows are weighted in an exponential weighted manner to obtain the time-varying correlation coefficients of the candidate indicators, which dynamically reflects the system sensitivity change trend of the monitoring indicators, effectively captures short-term and long-term trend changes, reduces the uncertainty caused by single window fluctuations, and makes anomaly detection more robust and reliable.

[0096] Through the embodiment of the present application, the prediction residual sequence and the system state sequence are directly synchronized and correlated, and the key sensitive indicators are clearly located, which effectively avoids the misselection of irrelevant indicators that may exist in traditional methods, and improves monitoring efficiency and early warning accuracy. In addition, in the final calculation of the time-varying correlation coefficient, the correlation coefficients of multiple windows are weighted and fused to weaken occasional fluctuations or abnormal data interference, thereby improving the stability and robustness of the abnormal state judgment of the system.

[0097] For example, in the monitoring process using the time-varying correlation coefficient, each candidate monitoring indicator maintains a continuous dynamic correlation analysis with the system operation status in different time windows. Once the prediction residual of a certain indicator shows a significant positive / negative correlation increase between the recent window and the system status, the time-varying correlation coefficient will be quickly reflected. For example, once the system status deteriorates or shows signs of failure, the prediction residual of the key indicator will maintain a high correlation with the state change, which will greatly increase the time-varying correlation coefficient of the indicator and trigger an early alarm.

[0098] Regarding the implementation details of step S220, in some embodiments, the DBSCAN algorithm parameters are determined dynamically by adaptive and , can effectively adapt to the changes in indicator feature distribution caused by different business loads and changes in the monitoring environment, thereby realizing adaptive clustering and improving the indicator clustering effect and stability.

[0099] More specifically, assume that the set of all potential monitoring indicators Expressed as , It represents the total number of potential monitoring indicators screened by the importance threshold, and forms the indicator feature matrix by integrating the comprehensive characteristics of each potential monitoring indicator .

[0100] Here, potential monitoring indicators are first preliminarily screened out through a preset importance threshold, and then a comprehensive feature matrix is ​​constructed for each potential indicator to accurately characterize the dynamic characteristics of each indicator.

[0101] In order to adapt to the characteristics of monitoring indicators that change with time and environment, a dynamic method is used to calculate the neighborhood radius and the minimum number of neighborhood samples.

[0102] Regarding the dynamic calculation method of the neighborhood radius, specifically, it adopts a weighted calculation method of the mean and standard deviation of the nearest neighbor distance between indicators, which can adaptively adjust the parameters and avoid the poor clustering effect caused by fixed parameters in the traditional DBSCAN algorithm.

[0103] Regarding the dynamic calculation method of the minimum number of neighborhood samples, specifically, the method of taking the logarithm of the total number of potential monitoring indicators and multiplying it by the adjustment coefficient can be dynamically adjusted as the number of indicators changes, ensuring the stability of the clustering effect under different data scales and complexities.

[0104] , Formula (15) , Formula (16) , Formula (17) , Formula (18) In the formula, Indicates Potential monitoring indicators, and Respectively indicate indicators and indicators The corresponding comprehensive characteristics of the indicators, Indicates distance indicator Recent A set of indicators, represents the Euclidean distance between feature vectors, Indicators to The average distance of the nearest neighbor indicators, Indicators to The standard deviation of the distances between the nearest neighbor indices, represents the number of nearest neighbor indices, represents the floor function; It is the neighborhood radius in the DBSCAN algorithm, which represents the neighborhood range of an index point in the feature space; The adjustment coefficient that indicates the tightness of the neighborhood radius, with a value range of [1.0, 2.0]; It is the minimum number of neighborhood samples in the DBSCAN algorithm, which is used to determine the minimum number of indicators in the neighborhood required for a point to become a core point; Represents the adjustment coefficient used to control the speed at which the minimum number of neighborhood samples changes with the total number of indicators. The value range is [1.5,3.0].

[0105] In the above formulas (15)-(18), in order to solve the problem that the traditional DBSCAN clustering parameters are fixed and difficult to adapt to dynamic changes, a solution is proposed to dynamically adjust the DBSCAN clustering parameters (neighborhood radius and minimum sample number) based on the statistical characteristics (mean and standard deviation) of the nearest neighbor distance between indicators. In this way, it is ensured that the clustering algorithm can reflect the real dynamic distribution state of the monitoring indicator feature space in real time.

[0106] The DBSCAN clustering process is performed on the indicator feature matrix using the dynamically calculated neighborhood radius and the minimum number of neighborhood samples. Specifically, for each potential monitoring indicator, , calculate the number of feature points in its neighborhood, if it exceeds , it is marked as a core point, and the cluster is expanded from the core point through the neighborhood expansion method until it can no longer be expanded, thereby obtaining the corresponding cluster set , represents the total number of clusters, Indicates Clusters.

[0107] For each cluster, the cluster feature vector center is calculated according to the mean of the comprehensive characteristics of all indicators in the cluster. The cluster feature center is represented by the mean of the feature vector of all indicators in the cluster, which can accurately reflect the common characteristics within the cluster.

[0108] , Formula (19) In the formula, Indicates Clusters, express The number of indicators in express The eigenvector center of express Each monitoring indicator within The comprehensive characteristics of the indicators.

[0109] For each cluster, the indicator with the smallest distance to the center of the cluster feature vector is selected as the cluster representative monitoring indicator.

[0110] Specifically, the Euclidean distance is used to select the indicator closest to the cluster center as the representative indicator. This method can effectively eliminate the interference of outliers and marginal indicators and ensure the typicality and accuracy of the representative indicator.

[0111] , formula (20) In the formula, Indicated in The selected clusters represent monitoring indicators. express The comprehensive characteristics of the indicators and The Euclidean distance between the centers of the cluster eigenvectors.

[0112] In an embodiment of the present application, after completing the dynamic DBSCAN clustering, the characteristic vector centers of all indicators in each cluster are further accurately calculated, and then the indicators closest to the cluster center are selected as the cluster representative monitoring indicators to ensure the representativeness and accuracy of the selected representative indicators within the cluster.

[0113] Through the embodiments of the present application, clustering parameters are adaptively adjusted according to dynamic environmental changes to ensure that the clustering results are more in line with the actual equipment operating environment and the real distribution state of the feature space, effectively improving the adaptability and sensitivity to environmental changes. Through dynamic DBSCAN clustering parameter calculation and clustering process, the characteristic change trend of potential monitoring indicators evolving over time can be captured in real time, thereby adjusting the key monitoring indicator set in real time and improving the response speed of the monitoring system to abnormal events or failures.

[0114] In addition, the precise selection of cluster representative indicators is adopted. The representative indicators are selected by cluster feature centers to ensure the representativeness and accuracy of indicator selection, and effectively avoid the problem of inaccurate selection of key indicators caused by redundant or atypical indicators. Through the precise selection of representative indicators, the monitoring overhead of redundant indicators is greatly reduced, the data storage and processing costs are reduced, and the allocation efficiency of monitoring resources is optimized.

[0115] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity of description, they are all expressed as a series of actions combined, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application. In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.

[0116] Figure 3 A structural block diagram of an example of an equipment monitoring indicator screening system based on time series modeling according to an embodiment of the present application is shown.

[0117] like Figure 3 As shown, the equipment monitoring indicator screening system 300 based on time series modeling includes a data acquisition unit 310, an NCDE analysis unit 320, a time-varying correlation analysis unit 330, an importance evaluation unit 340 and a target indicator screening unit 350.

[0118] The data acquisition unit 310 is used to acquire device monitoring time series data, which covers multiple types of candidate monitoring indicators and multiple types of auxiliary parameters. The auxiliary parameters include any one of the following: service response delay, business alarm information and network delay.

[0119] The NCDE analysis unit 320 is used to define the main input and extended input of the NCDE model based on each type of candidate monitoring indicators and each type of auxiliary parameters, so that the NCDE model uses the continuous-time differential equation form to map the continuously changing candidate monitoring indicators to the latent space, and captures the prediction residuals and latent state evolution characteristics of each type of candidate monitoring indicators through continuous-time modeling.

[0120] The time-varying correlation analysis unit 330 is used to calculate the correlation coefficient between the prediction residual of each type of candidate monitoring indicator and the system operation status within a continuous time window, and to obtain the corresponding time-varying correlation coefficient of each type of candidate monitoring indicator by weighted summing the correlation coefficients of each time window; the system operation status is determined based on the service response delay and request error rate within the corresponding time window.

[0121] The importance evaluation unit 340 is used to fuse the prediction residuals, time-varying correlation coefficients and latent state evolution characteristics of each candidate monitoring indicator to obtain the corresponding indicator comprehensive characteristics, and evaluate the importance score corresponding to the indicator comprehensive characteristics.

[0122] The target indicator screening unit 350 is used to screen the target monitoring indicator for equipment monitoring from each of the candidate monitoring indicators according to the importance score.

[0123] In some embodiments, an embodiment of the present application provides a non-volatile computer-readable storage medium, in which one or more programs including execution instructions are stored, and the execution instructions can be read and executed by an electronic device (including but not limited to a computer, a server, or a network device, etc.) to execute the steps of any of the above-mentioned equipment monitoring indicator screening methods based on time series modeling in the present application.

[0124] In some embodiments, the embodiments of the present application also provide a computer program product, which includes a computer program stored on a non-volatile computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer, the computer executes any step of the above-mentioned equipment monitoring indicator screening method based on time series modeling.

[0125] In some embodiments, an embodiment of the present application also provides an electronic device, comprising: at least one processor, and a memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the steps of the equipment monitoring indicator screening method based on time series modeling.

[0126] Figure 4 is a schematic diagram of the hardware structure of an electronic device for executing a device monitoring index screening method based on time series modeling provided by another embodiment of the present application, such as Figure 4 As shown, the device includes: One or more processors 410 and memory 420, Figure 4 A processor 410 is taken as an example.

[0127] The device for executing the device monitoring indicator screening method based on time series modeling may further include: an input device 430 and an output device 440 .

[0128] The processor 410, the memory 420, the input device 430 and the output device 440 may be connected via a bus or other means. Figure 4 The example of connecting through bus is taken in the following.

[0129] The memory 420, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer executable programs and modules, such as program instructions / modules corresponding to the device monitoring index screening method based on time series modeling in the embodiment of the present application. The processor 410 executes various functional applications and data processing of the server by running the non-volatile software programs, instructions and modules stored in the memory 420, that is, the device monitoring index screening method based on time series modeling in the above method embodiment is implemented.

[0130] The memory 420 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the electronic device, etc. In addition, the memory 420 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some embodiments, the memory 420 may optionally include a memory remotely arranged relative to the processor 410, and these remote memories may be connected to the electronic device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0131] The input device 430 may receive input digital or character information and generate signals related to user settings and function control of the electronic device. The output device 440 may include a display device such as a display screen.

[0132] The one or more modules are stored in the memory 420, and when executed by the one or more processors 410, the equipment monitoring indicator screening method based on time series modeling in any of the above method embodiments is executed.

[0133] The above-mentioned product can execute the method provided in the embodiment of the present application, and has the functional modules and beneficial effects corresponding to the execution method. For technical details not fully described in this embodiment, please refer to the method provided in the embodiment of the present application.

[0134] The electronic devices of the embodiments of the present application exist in various forms, including but not limited to: (1) Mobile communication equipment: This type of equipment is characterized by having mobile communication functions and its main purpose is to provide voice and data communications. This type of terminal includes: smart phones, multimedia phones, functional phones, and low-end phones.

[0135] (2) Ultra-mobile personal computer devices: These devices belong to the category of personal computers, have computing and processing functions, and generally also have mobile Internet access features. These terminals include: PDA, MID and UMPC devices, etc.

[0136] (3) Portable entertainment devices: These devices can display and play multimedia content. They include audio and video players, handheld game consoles, e-books, smart toys, and portable car navigation devices.

[0137] (4) Other onboard electronic devices with data interaction functions, such as on-board devices installed in vehicles.

[0138] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0139] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a general hardware platform, and of course, by hardware. Based on this understanding, the above technical solution, in essence, or the part that contributes to the relevant technology, can be embodied in the form of a software product, which can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiment.

[0140] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A device monitoring indicator screening method based on time series modeling, comprising: Acquire device monitoring time series data, where the device monitoring time series data covers multiple types of candidate monitoring indicators and multiple types of auxiliary parameters, where the auxiliary parameters include any one of the following: service response delay, service alarm information, and network delay; Based on the various candidate monitoring indicators and the various auxiliary parameters, the main input and extended input of the NCDE model are defined respectively, so that the NCDE model maps the continuously changing candidate monitoring indicators to the latent space using the continuous time differential equation form, and captures the prediction residuals and latent state evolution characteristics of the various candidate monitoring indicators through continuous time modeling; Calculating the correlation coefficient between the prediction residual of each type of candidate monitoring indicator and the system operation state in a continuous time window, and performing weighted summation on the correlation coefficients of each time window to obtain the corresponding time-varying correlation coefficient of each type of candidate monitoring indicator; The system operation status is determined based on the service response delay and request error rate within the corresponding time window; The prediction residuals, time-varying correlation coefficients and latent state evolution characteristics of each candidate monitoring indicator are integrated to obtain the corresponding comprehensive characteristics of the indicator, and the importance scores corresponding to the comprehensive characteristics of the indicator are evaluated; The target monitoring indicator for equipment monitoring is screened from each of the candidate monitoring indicators according to the importance score.

2. The method according to claim 1, wherein: Modeling of the prediction residuals of the candidate monitoring indicators includes: Assume that the discrete sampling data of candidate monitoring indicators and auxiliary parameters are expressed as and , Indicates Sampling time points, Represents the total number of sampling time points, and Respectively expressed in The sampled candidate monitoring indicator data values ​​and auxiliary parameter data values ​​are used to construct a continuous time series signal through interpolation method and normalize it to obtain the continuous time series signal of the corresponding candidate monitoring indicator and continuous timing signals of auxiliary parameters , to meet the input conditions of the NCDE model; The continuous time series signal of the candidate monitoring indicators is transformed into Mapped to the hidden state space and using the continuous time series signal of the auxiliary parameters Modulate the model: , In the formula, Indicates that in continuous time The hidden state of Indicates the initial time, represents the initial hidden state; is the integral variable, which means from arrive Any time point in between; represents the control function, parameterized by a neural network with parameters , this function is used to calculate the time The hidden state and extended input Dynamically calculate the rate of change of hidden states; Indicates the main input signal The increment in a small time interval, Indicates the driving effect of candidate monitoring indicators on the evolution of hidden states; The control function is parameterized using the attention mechanism: , , In the formula, Represents a multi-layer perceptron in an attention network for nonlinear feature mapping; represents the vector concatenation operation, Indicates time The attention weight vector, , and Represent the hidden state weight matrix, auxiliary input weight matrix and attention bias term respectively; Based on the decoder processing corresponding sampling time The hidden state , to infer at the next sampling time point The predicted value of candidate monitoring indicators : , In the formula, represents the decoder function, represents the learnable parameters of the decoder; Compare the predicted values ​​of the candidate monitoring indicators at each sampling time point with the actual observed values ​​to calculate the corresponding prediction residuals: , In the formula, Indicates the sampling time The corresponding prediction residual is Indicates that at the sampling time The actual value of the candidate monitoring indicator collected at the location.

3. The method according to claim 2, wherein: The hidden state evolution characteristics include hidden state mean, hidden state variance, hidden state instantaneous change rate and hidden state cumulative change amount; Modeling the hidden state evolution characteristics includes: , In the formula, Indicates the time interval The hidden state mean in Indicates from arrive At any point in time between Indicates from arrive Any time point between The hidden state of is a small time increment of the integral variable, representing the integral of a continuously changing process in time; , In the formula, Indicates the time interval The hidden state variance within , In the formula, Indicates at time The instantaneous rate of change of the hidden state, and Respectively indicate at time and The hidden state vector of is the preset time interval used for discretization derivative calculation; , In the formula, Indicates the time interval The cumulative change of hidden state in represents the Euclidean norm.

4. The method according to claim 3, wherein: The calculation of the time-varying correlation coefficient of the candidate monitoring indicator includes: The service response delay and request error rate at each sampling time are weighted and integrated to determine the corresponding system operation status: , In the formula, Indicates the sampling time The system operating status, Indicates that the system is Service response delay, Indicates the sampling time The request error rate, is the balance weight parameter; Assume Time windows Inside Sampling time, record candidate monitoring indicators Get the discrete prediction residual sequence within the time window , and record the system operation status sequence within the time window ;in, Indicates candidate monitoring indicators In the time window The first The prediction residual at sampling time, Indicates that in the time window The first The system operation status at each sampling moment; In the time window, the Pearson correlation coefficient between the prediction residual sequence and the system state sequence is calculated for each candidate indicator. : , In the formula, Represents candidate indicators In the time window The Pearson correlation coefficient within reflects the linear relationship between the prediction residual and the system state; Is a candidate indicator In the time window The mean of the internal prediction residuals, Represents a time window The mean of the internal system state; The exponential decay weight mechanism is used to perform weighted averaging of the Pearson correlation coefficients of each time window to obtain the time-varying correlation coefficients of the candidate monitoring indicators: , In the formula, Represents a time window The weight of The window end time and the current time decays with the increase of distance; is a positive parameter that controls the decay rate; , In the formula, Represents candidate indicators The time-varying correlation coefficient of is the total number of time windows.

5. The method according to any one of claims 1 to 4, wherein: The step of selecting a target monitoring indicator for equipment monitoring from each of the candidate monitoring indicators according to the importance score includes: Screening the importance of each of the candidate monitoring indicators according to a preset importance threshold to obtain at least one corresponding potential monitoring indicator; Input each of the potential monitoring indicators and the corresponding comprehensive indicator features into a dynamic DBSCAN model to determine at least one corresponding cluster, calculate the center of the cluster feature vector corresponding to each of the clusters, and select the potential monitoring indicator closest to the center of the cluster feature vector as the cluster representative monitoring indicator of the corresponding cluster; The target monitoring indicator is determined according to the cluster representative monitoring indicators corresponding to each of the clusters.

6. The method according to claim 5, wherein: The step of inputting each of the potential monitoring indicators and the corresponding comprehensive indicator features into a dynamic DBSCAN model to determine at least one corresponding cluster, calculating the cluster feature vector center corresponding to each of the clusters, and selecting the potential monitoring indicator closest to the cluster feature vector center as the cluster representative monitoring indicator of the corresponding cluster, includes: Assume that the set of all potential monitoring indicators Expressed as , It represents the total number of potential monitoring indicators screened by the importance threshold, and forms the indicator feature matrix by integrating the comprehensive characteristics of each potential monitoring indicator ; The neighborhood radius and the minimum number of neighborhood samples are calculated dynamically: , , , , In the formula, Indicates Potential monitoring indicators, and Respectively indicate indicators and indicators The corresponding comprehensive characteristics of the indicators, Indicates distance indicator Recent A set of indicators, represents the Euclidean distance between feature vectors, Indicator to The average distance of the nearest neighbor indicators, Indicator to The standard deviation of the distances between the nearest neighbor indices, represents the number of nearest neighbor indices, represents the floor function; It is the neighborhood radius in the DBSCAN algorithm, which represents the neighborhood range of an index point in the feature space; The adjustment coefficient that indicates the tightness of the neighborhood radius, with a value range of [1.0, 2.0]; It is the minimum number of neighborhood samples in the DBSCAN algorithm, which is used to determine the minimum number of indicators in the neighborhood required for a point to become a core point; Represents the adjustment coefficient used to control the speed at which the minimum number of neighborhood samples changes with the total number of indicators, with a value range of [1.5, 3.0]; Use the dynamically calculated neighborhood radius and the minimum number of neighborhood samples to perform DBSCAN clustering on the indicator feature matrix to obtain the corresponding cluster set , Represents the total number of clusters. Indicates Clusters; For each cluster, the cluster feature vector center is calculated according to the mean of the comprehensive characteristics of all indicators in the cluster: , In the formula, Indicates Clusters, express The number of indicators in express The eigenvector center of express Each monitoring indicator within Comprehensive characteristics of indicators; For each cluster, select the indicator with the smallest distance to the center of the cluster feature vector as the cluster representative monitoring indicator: , In the formula, Indicated in The selected clusters represent monitoring indicators. express The comprehensive characteristics of the indicators and The Euclidean distance between the centers of the cluster eigenvectors.

7. A device monitoring index screening system based on time series modeling, comprising: A data acquisition unit, used to acquire equipment monitoring time series data, wherein the equipment monitoring time series data covers multiple types of candidate monitoring indicators and multiple types of auxiliary parameters, wherein the auxiliary parameters include any one of the following: service response delay, service alarm information and network delay; An NCDE analysis unit, used to define the main input and extended input of the NCDE model based on each type of candidate monitoring indicators and each type of auxiliary parameters, so that the NCDE model maps the continuously changing candidate monitoring indicators to the latent space using the continuous time differential equation form, and captures the prediction residuals and latent state evolution characteristics of each type of candidate monitoring indicators through continuous time modeling; A time-varying correlation analysis unit, used to calculate the correlation coefficient between the prediction residual of each type of candidate monitoring indicator and the system operation state in a continuous time window, and to perform weighted summation on the correlation coefficients of each time window to obtain the corresponding time-varying correlation coefficient of each type of candidate monitoring indicator; The system operation status is determined based on the service response delay and request error rate within the corresponding time window; An importance evaluation unit, used to fuse the prediction residuals, time-varying correlation coefficients and latent state evolution characteristics of each candidate monitoring indicator to obtain the corresponding indicator comprehensive characteristics, and evaluate the importance score corresponding to the indicator comprehensive characteristics; The target indicator screening unit is used to screen the target monitoring indicator for equipment monitoring from each of the candidate monitoring indicators according to the importance score.

Citation Information

Patent Citations

  • Time sequence prediction method and device

    CN116432834A

  • Data processing system for driving measurement calibration

    CN116821729A

  • Method and equipment for complementing network monitoring data

    CN117828283A

  • Running state monitoring method based on deep learning and feature screening

    CN118783632A

  • Power system dominant instability mode identification method based on deep learning

    CN119066561A

Cited By

  • Preparation process of alloy powder for spraying fracturing pump plunger

    CN120306651A

  • Improved principal component regression machine tool thermal error modeling method based on density clustering

    CN120541508A

  • Real-time fault intelligent detection method for electric energy meter

    CN120804753A

  • A real-time fault intelligent detection method for an electric energy meter

    CN120804753B

  • Method and system for automatically selecting monitoring indexes of large-scale computer system

    CN121807655A