Disaster event prediction method, system and device based on artificial intelligence and medium
By combining natural language processing, machine learning, clustering analysis and sequence rule mining technologies, identifying the patterns and risks of catastrophic events in multi-service environments, the problem of insufficient pattern recognition and data modeling capabilities in the existing technology is solved, and catastrophic event prediction with high accuracy and real-time can be achieved.
Patent Information
- Application Number
- CN202510101340.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-16
AI Technical Summary
In the prediction of catastrophic event, the existing technology has problems such as insufficient pattern recognition and time series dependence, lack of modeling capabilities of high-dimensional multi-feature data, and difficulty in combining sequence rules with machine learning models.
Combining natural language processing, machine learning, clustering analysis and sequence rule mining technologies, identify event patterns, risk scores, and root causes from historical and real-time data for catastrophic events in multi-service environments.
By dynamically identifying event patterns and risk scores, the accuracy and real-timeness of catastrophic event prediction are improved, and the problem of insufficient pattern recognition and data modeling capabilities in the prior art is solved.
Smart Images

Figure CN120013246A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of disaster event prediction, and in particular to a disaster event prediction method, system, device and medium based on artificial intelligence. Background Art
[0002] Information Technology Service Management (ITSM) plays a key role in ensuring the continuous availability of information technology (IT) services. Its operation relies on the ticket mechanism to automatically report customer issues and incidents to the operation and maintenance team. These tickets are triggered in two main situations: one is abnormal interruptions in the IT ecosystem, such as downtime, errors, performance issues, etc.; the other is planned needs, such as requesting access rights, resetting passwords, updating data, configuring services, etc. Abnormal interruptions may lead to a series of failures, and in ITSM-related operations, passive response mechanisms often take countermeasures only after high-severity incidents occur, which can cause system downtime and increase costs.
[0003] Traditionally, existing systems use a variety of mechanisms to predict system failures or provide timely warnings of failures to operation and maintenance personnel, or to determine the root cause of failures in application systems. These mechanisms include log filtering-based technologies, OPTICS (Ordering Points to Identify Clustering Structure, density-based clustering algorithm) and LSTM (Long Short-Term Memory Network)-based technologies, as well as formatted text related to IT system console logs, similarity scoring technologies, interpretive technologies based on LIME (Local Interpretable Model-Independent Explanations), and analytical methods such as cluster time analysis. However, these existing technologies have many shortcomings.
[0004] First, the existing technologies do not include a mechanism to identify catastrophic events and their probability of occurrence based on the individual patterns of each service. In addition, these technologies do not consider the event sequence to identify the root causes of catastrophic events. Event prediction systems in the existing technologies usually use independent event models, ignoring the temporal order and correlation of events. This method mainly focuses on the analysis of single event characteristics and the state at the time, lacks dynamic tracking of event sequences, and cannot fully identify the interrelationships and cumulative impacts between consecutive events. In some traditional event analysis models (such as rule-based systems), event processing is often "static", that is, each event is processed independently, ignoring the temporal relationship. This approach cannot fully capture the potential chain of catastrophic events, nor can it determine the root cause through the sequential relationship of historical events.
[0005] Specifically, the OPTICS algorithm is mainly used for density-based clustering. Although it can effectively discover clusters of different densities, it does not naturally consider time series data. In event prediction, the order and time interval of events are crucial to the prediction of catastrophic events, but OPTICS cannot effectively handle event sequences with time dependencies, so it is difficult to capture the temporal relationship between events. Although the LSTM network is a powerful tool for processing time series data, it also has certain limitations. In catastrophic event prediction, LSTM can often only predict future events based on the long-term dependencies of historical data, while ignoring local patterns and sudden changes in event sequences. In addition, LSTM may face overfitting problems when processing large-scale data, especially when the data is sparse or the event interval is long, LSTM may not be able to effectively capture potential catastrophic event sequences.
[0006] There are technical challenges in combining OPTICS and LSTM with sequence rules for catastrophic event prediction. OPTICS mainly identifies patterns through density clustering of data, but does not consider the dependencies of time series, so it cannot effectively capture the temporal relationship between events. Although LSTM is good at processing time series data, it does not adequately model high-dimensional, multi-feature data and multiple dependencies between complex events, which may lead to inaccurate prediction results. In addition, the difference in expression between sequence rules and machine learning models makes the combination of the two complex and difficult to achieve, especially when dealing with noisy and high-dimensional data, which may lead to overfitting or insufficient generalization, affecting the accuracy of predictions. Summary of the invention
[0007] Based on the problems raised by the above background technology, the purpose of the present invention is to provide a disaster event prediction method, system, device and medium based on artificial intelligence. By combining natural language processing, machine learning, cluster analysis and sequence rule mining technology, event patterns, risk scores and root causes are identified from historical and real-time data for catastrophic events in a multi-service environment, solving the problems of insufficient pattern recognition and time series dependence, lack of high-dimensional multi-feature data modeling capabilities and difficulty in combining sequence rules with machine learning models in the prior art.
[0008] The present invention is achieved through the following technical solutions:
[0009] The first aspect of the present invention provides a disaster event prediction method based on artificial intelligence, comprising the following steps:
[0010] Receive ticket information from multiple service systems;
[0011] Performing severity analysis on the ticket information, and dividing the ticket information into a predefined event window set and a predefined non-event window set according to the severity analysis result;
[0012] Using a clustering model to cluster the predefined event window set and the predefined non-event window set to obtain cluster data;
[0013] Performing sequence pattern mining on the cluster data to obtain event sequence patterns;
[0014] Acquire a pattern rule library, match the event sequence pattern with the pattern rule library and calculate the score to obtain a service event risk score.
[0015] In the above technical solution, the processor of the event prediction system receives multiple ticket data from multiple sources (such as service platform, operation and maintenance platform, etc.). Each ticket contains a set of information, including the severity of the ticket, service type, ticket description, operator information and creation time. The processor first arranges these ticket data in chronological order for subsequent analysis.
[0016] The processor identifies predefined "event windows" and "non-event windows" for each service's ticket data. The event window indicates the set of tickets before the catastrophic event occurs, and the non-event window indicates the set of tickets that are not involved in the catastrophic event. The definition of these windows is based on the arrival time interval of the tickets and other historical data.
[0017] Using natural language processing (NLP) technology, the processor extracts keywords from the ticket description, removes terms that are not related to the event, and extracts a set of relevant words. In this way, the processor is able to generate a set of words that represent the important information of the ticket for each ticket data.
[0018] The processor compares the word set of the ticket with the predefined clustering model and identifies the cluster data of each group of tickets. By calculating the similarity between the word set and the cluster center, the processor can classify each ticket into the most appropriate cluster. Then, the processor uses mining technology to identify sequence rules in each cluster data, which reflect the pattern of occurrence of high-severity events.
[0019] Based on historical ticket data, sequence rules, and clustering data, the processor generates a risk score for each service. The risk score is based on multiple factors, such as the severity of the ticket, historical interval time, patterns in the event window, etc. Based on the generated risk score, the processor can predict potential catastrophic events and take preventive measures in advance.
[0020] By combining natural language processing, machine learning, cluster analysis and sequence rule mining technology, event patterns, risk scores and root causes of catastrophic events in multi-service environments are identified from historical and real-time data, solving the problems of insufficient pattern recognition and time series dependence in existing technologies, lack of high-dimensional and multi-feature data modeling capabilities, and difficulty in combining sequence rules with machine learning models.
[0021] In an optional embodiment, performing severity analysis on the ticket information includes:
[0022] Performing text preprocessing on the ticket information, and performing word segmentation operation on the ticket information after the text preprocessing to obtain multiple word units;
[0023] Merging the multiple word units through word form restoration technology to obtain a unified word;
[0024] The TF-IDF algorithm is used to calculate the importance of the unified words and generate a vectorized vocabulary.
[0025] In an optional embodiment, the ticket information is divided into a predefined event window set and a predefined non-event window set according to the severity analysis result, including:
[0026] Parsing the creation time field of the ticket information;
[0027] Based on the creation time field, the ticket information is divided into time windows using a sliding window algorithm to obtain a ticket information time window;
[0028] The vectorized vocabulary in the ticket information time window is analyzed, and the ticket information time window is divided into a predefined event window set and a predefined non-event window set according to the analysis result.
[0029] In an optional embodiment, clustering the predefined event window set and the predefined non-event window set using a clustering model comprises the following steps:
[0030] a. Initialize cluster centers;
[0031] b. Calculating the cosine similarity of the predefined event window set and the predefined non-event window set;
[0032] c. classifying the predefined event window set and the predefined non-event window set into the cluster center according to the cosine similarity;
[0033] d. Update the classified cluster centers and repeat steps b to d until the updated cluster centers tend to be stable.
[0034] In an optional embodiment, performing sequence pattern mining on the cluster data includes:
[0035] Acquire historical event data, use natural language processing and machine learning techniques to perform rule mining on the historical event data, and generate sequence rules;
[0036] Based on the sequence rule, a PrefixSpan algorithm is used to mine the sequence pattern of cluster labels in each window in the cluster data to obtain a frequent event sequence.
[0037] A second aspect of the present invention provides a disaster event prediction system based on artificial intelligence, comprising:
[0038] The receiving module is used to receive ticket information from multiple service systems;
[0039] A window module, configured to perform severity analysis on the ticket information, and divide the ticket information into a predefined event window set and a predefined non-event window set according to the severity analysis result;
[0040] A clustering module, used for clustering the predefined event window set and the predefined non-event window set using a clustering model to obtain cluster data;
[0041] A sequence module, used for performing sequence pattern mining on the cluster data to obtain an event sequence pattern;
[0042] The matching module is used to obtain a pattern rule library, match the event sequence pattern with the pattern rule library and calculate the score to obtain a service event risk score.
[0043] In an optional embodiment, the window module includes:
[0044] A text processing unit, used to perform text preprocessing on the ticket information, and perform word segmentation operation on the ticket information after text preprocessing to obtain multiple word units;
[0045] A word processing unit, used for merging the multiple word units through word form restoration technology to obtain a unified word;
[0046] The vectorization unit is used to calculate the importance of the unified words by using the TF-IDF algorithm to generate a vectorized vocabulary.
[0047] In an optional embodiment, the window module further includes:
[0048] A parsing unit, used for parsing the creation time field of the ticket information;
[0049] A window division unit, configured to divide the ticket information into time windows by using a sliding window algorithm based on the creation time field to obtain a ticket information time window;
[0050] The set division unit is used to analyze the vectorized vocabulary in the ticket information time window, and divide the ticket information time window into a predefined event window set and a predefined non-event window set according to the analysis result.
[0051] A third aspect of the present invention provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements a disaster event prediction method based on artificial intelligence when executing the computer program.
[0052] A fourth aspect of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a disaster event prediction method based on artificial intelligence.
[0053] Compared with the prior art, the present invention has the following advantages and beneficial effects:
[0054] By combining natural language processing, machine learning, cluster analysis and sequence rule mining technology, event patterns, risk scores and root causes of catastrophic events in multi-service environments are identified from historical and real-time data, solving the problems of insufficient pattern recognition and time series dependence in existing technologies, lack of high-dimensional and multi-feature data modeling capabilities, and difficulty in combining sequence rules with machine learning models. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] In order to more clearly illustrate the technical solutions of the exemplary embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, other relevant drawings can be obtained based on these drawings without creative work. In the drawings:
[0056] Figure 1 A schematic diagram of a process flow of a disaster event prediction method based on artificial intelligence provided in Example 1 of the present invention;
[0057] Figure 2 A schematic diagram of the process of sequential pattern mining provided in Example 1 of the present invention;
[0058] Figure 3A schematic diagram of the structure of a disaster event prediction system based on artificial intelligence provided in Example 2 of the present invention;
[0059] Figure 4 A first prediction result diagram provided by Embodiment 2 of the present invention;
[0060] Figure 5 A second prediction result diagram provided by Embodiment 2 of the present invention;
[0061] Figure 6 A schematic diagram of the structure of an electronic device provided in Example 3 of the present invention. DETAILED DESCRIPTION
[0062] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with embodiments and drawings. The exemplary embodiments of the present invention and their description are only used to explain the present invention and are not intended to limit the present invention.
[0063] Example 1
[0064] Figure 1 A schematic diagram of a process flow of a disaster event prediction method based on artificial intelligence provided in Example 1 of the present invention, such as Figure 1 As shown, the disaster event prediction method based on artificial intelligence includes the following steps:
[0065] Receive ticket information from multiple service systems;
[0066] Performing severity analysis on the ticket information, and dividing the ticket information into a predefined event window set and a predefined non-event window set according to the severity analysis result;
[0067] Using a clustering model to cluster the predefined event window set and the predefined non-event window set to obtain cluster data;
[0068] Performing sequence pattern mining on the cluster data to obtain event sequence patterns;
[0069] Acquire a pattern rule library, match the event sequence pattern with the pattern rule library and calculate the score to obtain a service event risk score.
[0070] It should be noted that this method receives ticket information of one or more services related to the service from one or more sources, wherein these ticket information carries information related to the service, including work order ID, service type, creation time, severity level, work order description and assigned personnel information, etc.
[0071] The predefined event window refers to the time period of the set of ticket information that occurred before the high-severity tickets appeared, while the predefined non-event window refers to the time period of the set of ticket information that occurred before the low-severity tickets appeared. Therefore, in this method, the acquired ticket information is first analyzed for severity, and the ticket information is divided into high-severity ticket information and low-severity ticket information, and then the ticket information is divided into a set of predefined event windows and a set of predefined non-event windows based on the results of the severity analysis.
[0072] After completing the division of ticket information, cluster the ticket information in the predefined event window set and the predefined non-event window set, and determine cluster data by associating information associated with the predefined clusters with word sets associated with the ticket set using a ticket clustering model based on one or more clustering techniques to generate cluster data of the ticket set. Specifically, the word set associated with tickets of high severity events is clustered into a first cluster, and the words associated with tickets of low severity events are clustered into a second cluster.
[0073] After determining the cluster data of the ticket set, one or more sequence rules can be identified therefrom to determine the event set that leads to a high severity event or a low severity event. For example, consider a pattern such as AABCDA preceding a high severity event, where A, B, C, D is a set of information containing the ticket set that leads to a high severity event. In this case, the sequence rule can be in the form of AABCDA. Here, in order to identify the presence of one or more sequence rules in the cluster data, the event prediction system can use a mining model to identify the occurrence of one or more predefined patterns corresponding to the predefined sequence rules by associating the predefined sequence rules with the information of the predefined clusters.
[0074] A risk score and a root cause of a set of tickets are generated for each of the one or more services based on the one or more sequence rules, the one or more historical ticket parameters, and the creation time of the one or more tickets to predict a catastrophic event.
[0075] The system matches the real-time work order sequence with the patterns in the rule base and calculates the risk score of each service. For example, if the support of a rule is 0.8 and the confidence is 0.9, its risk score is 0.72. In addition, the system also performs reverse analysis on the matched rules to extract the possible root causes of high-risk events and provide clear decision support for the operation and maintenance team.
[0076] In an alternative embodiment, performing severity analysis on the tickets information includes:
[0077] Performing text preprocessing on the tickets information, and performing word segmentation on the tickets information after text preprocessing to obtain multiple word units;
[0078] Merging the multiple word units through lemmatization technology to obtain unified words;
[0079] Using the TF-IDF algorithm to calculate the importance of the unified words and generating a vectorized word list.
[0080] It should be noted that in this embodiment, natural language processing (NLP) technology is used to perform text processing on the tickets information to identify the vocabulary in the tickets information. Among them, NLP technology includes but is not limited to text preprocessing technology, lemmatization, tokenization, and vectorization.
[0081] First, perform text preprocessing on the tickets information. Among them, in the text preprocessing stage, meaningless stop words (such as "de", "shi") are removed first, and at the same time, HTML tags, special symbols, and redundant information are cleaned. Then perform word segmentation operations (such as Jieba segmentation) on the work order description field, split the text into multiple word units, and merge different forms of the same root word (such as "crash" and "crashed") into a unified form through lemmatization technology.
[0082] Subsequently, the system uses the TF-IDF algorithm to calculate the importance of each word and generates a vectorized word list, which will be used as the input for subsequent clustering analysis.
[0083] Furthermore, this embodiment uses text preprocessing technology to identify and delete irrelevant terms in the ticket descriptions of each ticket in the Ticket set.
[0084] In this embodiment, the irrelevant terms can be selected based on terms generated by testing and validating one or more Tickets, or can be manually provided by domain experts.
[0085] In an alternative embodiment, dividing the tickets information into a predefined event window set and a predefined non-event window set according to the severity analysis result includes:
[0086] Parsing the creation time field of the tickets information;
[0087] Based on the creation time field, using a sliding window algorithm to perform time window division on the tickets information to obtain the tickets information time window;
[0088] The vectorized vocabulary in the ticket information time window is analyzed, and the ticket information time window is divided into a predefined event window set and a predefined non-event window set according to the analysis result.
[0089] It should be noted that the predefined event window indicates the time period of the set of tickets that occurred before the high-severity ticket appeared, while the predefined non-event window indicates the time period of the set of tickets that occurred before the low-severity ticket appeared. Therefore, before dividing the time window, it is necessary to extract the creation time field of the work order in the ticket information and set the time range (for example, 30 minutes to 24 hours before the occurrence of a high-severity event) to define the event window and non-event window.
[0090] This embodiment uses a sliding window algorithm to divide the ticket information into time windows based on the creation of the time field, and moves a fixed time step (such as 10 minutes) each time to cover all possible event time points. For each time window, the work order type (event window or non-event window) in the window is marked and stored as an independent data set. In this embodiment, the work order type in the window is marked by a vectorized vocabulary, thereby determining a set of predefined event windows and a set of predefined non-event windows.
[0091] In an optional embodiment, clustering the predefined event window set and the predefined non-event window set using a clustering model comprises the following steps:
[0092] a. Initialize cluster centers;
[0093] b. Calculating the cosine similarity of the predefined event window set and the predefined non-event window set;
[0094] c. classifying the predefined event window set and the predefined non-event window set into the cluster center according to the cosine similarity;
[0095] d. Update the classified cluster centers and repeat steps b to d until the updated cluster centers tend to be stable.
[0096] It should be noted that the purpose of this step is to use the clustering model to determine the clustering data of the Ticket set of each predefined event window and predefined non-event window. This embodiment adopts k-means clustering, and first initializes the cluster center, wherein the cluster center includes a high severity cluster center and a low severity cluster center. Specifically, the high severity and low severity keyword sets are initialized as two cluster centers respectively.
[0097] By calculating the cosine similarity between each keyword vector and the cluster center, determine which category the keyword belongs to. Recalculate the position of the cluster center based on the classified keyword set until the cluster center no longer changes significantly. Mark the clustering results of high-severity keywords as "high-risk category" and low-severity keywords as "low-risk category". Through the above clustering analysis, the system converts complex keyword sets into structured data, providing support for subsequent rule mining and risk assessment.
[0098] In an optional embodiment, performing sequence pattern mining on the cluster data includes:
[0099] Acquire historical event data, use natural language processing and machine learning techniques to perform rule mining on the historical event data, and generate sequence rules;
[0100] Based on the sequence rule, a PrefixSpan algorithm is used to mine the sequence pattern of cluster labels in each window in the cluster data to obtain a frequent event sequence.
[0101] It should be noted that if Figure 2 As shown, the extraction of sequence rules is one of the core concepts of the present invention. Sequence rules can generate prediction rules in two ways: one is based on manually set rules, and the expert team manually defines rules based on past experience and historical data analysis, such as a specific combination of event types and occurrence frequencies that may indicate the occurrence of catastrophic events. The advantages of manual rules are their high accuracy and business adaptability, but their adaptability is poor and they cannot respond quickly to environmental changes.
[0102] In this embodiment, through data-driven automatic learning, natural language processing (NLP) technology is used to analyze the event description text to extract potential patterns and relationships. For example, by analyzing the timestamp, event interval, and contextual information of the event, NLP can reveal the potential causes and consequences of the event. Combined with machine learning and cluster analysis, the system can automatically discover and adjust rules to make them more adaptable to the actual business environment. By continuously learning and analyzing historical data, the system can gradually establish a set of complete, data-driven prediction rules.
[0103] By using natural language processing and machine learning techniques to perform rule mining on historical event data, sequence rules for sequence pattern mining are generated. Furthermore, this embodiment uses the PrefixSpan algorithm to perform sequence rule mining, and extracts frequently occurring event sequences by performing sequence pattern mining on cluster labels in each window.
[0104] Specifically, thresholds of support (such as 50%) and confidence (such as 80%) are set, and sequence patterns that meet the conditions are extracted as frequent event sequences, such as "A→B→C". The extracted rules are stored in the rule base for real-time matching.
[0105] When predicting catastrophic events, it is necessary not only to identify potential catastrophic events, but also to risk score them to determine the events to be prioritized. By analyzing the characteristics of each event, based on a predefined risk assessment model and combined with risk patterns in historical data, a risk score is assigned to each event. The score takes into account factors such as the severity of the event, frequency of occurrence, and historical background.
[0106] High-risk events will be prioritized to avoid greater impacts due to delayed processing. In order to optimize resource allocation, the risk score of the event will be dynamically updated based on real-time monitoring data to ensure timely response before a disaster occurs.
[0107] Root cause analysis (RCA) is to identify and avoid further deterioration of catastrophic events in advance by analyzing the potential factors of catastrophic events. Based on event prediction, the root cause of the event is found through multi-dimensional analysis (including device status, application behavior, operating environment, etc.). This analysis not only involves technical factors, but also takes into account changes in the external environment, such as network attacks and surges in system load. Through this process, corresponding repair measures are proposed, including equipment maintenance, performance optimization or emergency response, to ensure that the problem is effectively contained. The response mechanism is combined with automation technology to automatically dispatch resources when high-risk events are detected, start predefined repair procedures, and minimize the impact of catastrophic events on service systems.
[0108] Example 2
[0109] Embodiment 2 of the present invention provides a disaster event prediction system based on artificial intelligence, including:
[0110] The receiving module is used to receive ticket information from multiple service systems;
[0111] A window module, configured to perform severity analysis on the ticket information, and divide the ticket information into a predefined event window set and a predefined non-event window set according to the severity analysis result;
[0112] A clustering module, used for clustering the predefined event window set and the predefined non-event window set using a clustering model to obtain cluster data;
[0113] A sequence module, used for performing sequence pattern mining on the cluster data to obtain an event sequence pattern;
[0114] The matching module is used to obtain a pattern rule library, match the event sequence pattern with the pattern rule library and calculate the score to obtain a service event risk score.
[0115] It should be noted that if Figure 3 As shown in the figure, the system architecture consists of several key components, which together support the system to efficiently and reliably perform disaster event prediction and management tasks. First, the system relies on an efficient computer system, including a central processing unit (CPU), memory, input / output interface (I / O) and network interface, which is mainly responsible for executing machine learning algorithms, prediction models and event management logic. Secondly, the data acquisition and processing module is responsible for collecting data from various input devices (such as sensors, log files, monitoring tools, etc.), and performing cleaning, conversion and normalization to ensure data quality and consistency. These processed data are then stored in the system database to provide support for subsequent analysis and prediction.
[0116] The core disaster event prediction model analyzes historical data through machine learning algorithms and trains models that can identify potential catastrophic events. These algorithms use real-time data such as event logs, system load, and network traffic to predict the risks that may cause catastrophic events. The risk assessment and prioritization system evaluates and sorts risk events according to set rules, giving priority to high-risk events to avoid catastrophic impacts caused by processing delays. The root cause analysis and incident response mechanism is another key module in the system. It can analyze and provide preventive repair measures based on the predicted event type and root cause to minimize the occurrence of events.
[0117] The system's workflow includes several key links: data collection and processing, event pattern recognition and prediction, root cause analysis, and response and repair. First, the system collects various data sources such as system logs, network traffic, hardware status, and application performance through real-time monitoring tools, stores them through the storage system, and combines them with historical data to provide a data basis for event prediction. Then, based on this data, the event pattern recognition and prediction module uses machine learning algorithms to identify recurring patterns in historical events and predict catastrophic events before they occur. By combining and analyzing historical ticket data and real-time monitoring information, the model can provide high accuracy and timeliness in predictions.
[0118] Once a potential high-risk event is detected, the root cause analysis module will identify potential factors that may lead to catastrophic events based on multi-dimensional analysis. This process not only includes technical analysis such as device status and application behavior, but also takes into account various changes in the operating environment. The results of the analysis will help the system provide proactive repair measures to prevent the problem from worsening. Next, the system will generate a response and repair plan based on the results of the risk assessment. Through the automated resource scheduling mechanism, the system can prioritize high-risk events and take necessary repair measures to reduce potential catastrophic effects.
[0119] In an optional embodiment, the window module includes:
[0120] A text processing unit, used to perform text preprocessing on the ticket information, and perform word segmentation operation on the ticket information after text preprocessing to obtain multiple word units;
[0121] A word processing unit, used for merging the multiple word units through word form restoration technology to obtain a unified word;
[0122] The vectorization unit is used to calculate the importance of the unified words by using the TF-IDF algorithm to generate a vectorized vocabulary.
[0123] In an optional embodiment, the window module further includes:
[0124] A parsing unit, used for parsing the creation time field of the ticket information;
[0125] A window division unit, configured to divide the ticket information into time windows by using a sliding window algorithm based on the creation time field to obtain a ticket information time window;
[0126] The set division unit is used to analyze the vectorized vocabulary in the ticket information time window, and divide the ticket information time window into a predefined event window set and a predefined non-event window set according to the analysis result.
[0127] This system achieves disaster event prediction results such as Figure 4 , 5As shown, compared with the prior art, the prediction accuracy and real-time performance of the present invention are higher. Traditional catastrophic event prediction systems often rely on static rules or are based on simple statistical analysis models. The accuracy of these models is usually low and they cannot cope with complex changes in the environment and data. Their prediction capabilities are limited and often lag behind, resulting in the inability to provide effective warnings before risk events occur. This system or method introduces advanced machine learning algorithms and combines historical data with real-time data analysis to dynamically learn and adapt to new data patterns and continuously optimize the prediction model. Compared with traditional technologies, the system can more accurately predict potential catastrophic events and has real-time update and self-correction capabilities, significantly improving prediction accuracy and timeliness.
[0128] At the same time, many existing systems rely on manual or static rules to perform problem diagnosis and root cause analysis. This method is not only slow, but may also lead to inaccurate diagnosis due to human error. Especially when facing complex systems, the root cause mining is often incomplete and cannot be comprehensive and in-depth. By introducing multi-dimensional automated analysis and combining factors such as device status, application behavior, and network environment, the system can fundamentally analyze and identify the real cause of the event. The introduction of machine learning algorithms enables the system to not only make rapid diagnoses, but also gradually optimize itself to reduce the interference of human errors.
[0129] Traditional catastrophic event processing systems usually have fixed algorithms and rules, and it is difficult to self-optimize according to new data and environmental changes. Over time, the system may perform poorly due to its inability to adapt to new challenges, affecting the accuracy of predictions and the effectiveness of processing. The system or method uses machine learning technology to achieve continuous self-learning and optimization. As the system processes more event data, the machine learning model will continue to adjust and improve, thereby improving the ability to predict and process events. This mechanism enables the system to always maintain a high level of accuracy and adaptability in the face of a changing environment.
[0130] Example 3
[0131] Figure 6 A schematic diagram of the structure of an electronic device provided in Embodiment 3 of the present invention is shown in FIG. Figure 6 As shown, the electronic device includes a processor, a memory, an input device and an output device; the number of processors in the computer device can be one or more, Figure 6 A processor is taken as an example; the processor, memory, input device and output device in the electronic device can be connected through a bus or other means.
[0132] The memory is a computer-readable storage medium that can be used to store software programs, computer executable programs, and modules. The processor executes various functional applications and data processing of the electronic device by running the software programs, instructions, and modules stored in the memory, that is, implementing the disaster event prediction method based on artificial intelligence in Example 1.
[0133] The memory may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system and an application required for at least one function; the data storage area may store data created according to the use of the terminal, etc. In addition, the memory may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some instances, the memory may further include a memory remotely arranged relative to the processor, and these remote memories may be connected to the electronic device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0134] The input device can be used to receive user input and password, etc. The output device is used to output the network configuration page.
[0135] Example 4
[0136] Embodiment 4 of the present invention further provides a computer-readable storage medium, wherein the computer-executable instructions, when executed by a computer processor, are used to implement the disaster event prediction method based on artificial intelligence as provided in Embodiment 1.
[0137] An embodiment of the present invention provides a storage medium containing computer executable instructions, and its computer executable instructions are not limited to the method operations provided in Example 1, and can also execute related operations in the disaster event prediction method based on artificial intelligence provided in any embodiment of the present invention.
[0138] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A disaster event prediction method based on artificial intelligence, characterized in that: The steps include: Receive ticket information from multiple service systems; Performing severity analysis on the ticket information, and dividing the ticket information into a predefined event window set and a predefined non-event window set according to the severity analysis result; Using a clustering model to cluster the predefined event window set and the predefined non-event window set to obtain cluster data; Performing sequence pattern mining on the cluster data to obtain event sequence patterns; Acquire a pattern rule library, match the event sequence pattern with the pattern rule library and calculate the score to obtain a service event risk score.
2. The method for predicting disaster events based on artificial intelligence according to claim 1, characterized in that: Perform severity analysis on the ticket information, including: Performing text preprocessing on the ticket information, and performing word segmentation operation on the ticket information after the text preprocessing to obtain multiple word units; Merging the multiple word units through word form restoration technology to obtain a unified word; The TF-IDF algorithm is used to calculate the importance of the unified words and generate a vectorized vocabulary.
3. The method for predicting disaster events based on artificial intelligence according to claim 2, characterized in that: The ticket information is divided into a predefined event window set and a predefined non-event window set according to the severity analysis result, including: Parsing the creation time field of the ticket information; Based on the creation time field, the ticket information is divided into time windows using a sliding window algorithm to obtain a ticket information time window; The vectorized vocabulary in the ticket information time window is analyzed, and the ticket information time window is divided into a predefined event window set and a predefined non-event window set according to the analysis result.
4. The method for predicting disaster events based on artificial intelligence according to claim 1, characterized in that: Clustering the predefined event window set and the predefined non-event window set using a clustering model comprises the following steps: a. Initialize cluster centers; b. Calculating the cosine similarity of the predefined event window set and the predefined non-event window set; c. classifying the predefined event window set and the predefined non-event window set into the cluster center according to the cosine similarity; d. Update the classified cluster centers and repeat steps b to d until the updated cluster centers tend to be stable.
5. The method for predicting disaster events based on artificial intelligence according to claim 1, characterized in that: Performing sequence pattern mining on the cluster data includes: Acquire historical event data, use natural language processing and machine learning techniques to perform rule mining on the historical event data, and generate sequence rules; Based on the sequence rule, a PrefixSpan algorithm is used to mine the sequence pattern of cluster labels in each window in the cluster data to obtain a frequent event sequence.
6. The disaster event prediction system based on artificial intelligence is characterized by: include: The receiving module is used to receive ticket information from multiple service systems; A window module, configured to perform severity analysis on the ticket information, and divide the ticket information into a predefined event window set and a predefined non-event window set according to the severity analysis result; A clustering module, used for clustering the predefined event window set and the predefined non-event window set using a clustering model to obtain cluster data; A sequence module, used for performing sequence pattern mining on the cluster data to obtain an event sequence pattern; The matching module is used to obtain a pattern rule library, match the event sequence pattern with the pattern rule library and calculate the score to obtain a service event risk score.
7. The artificial intelligence-based disaster event prediction system according to claim 6, characterized in that: The window module comprises: A text processing unit, used to perform text preprocessing on the ticket information, and perform word segmentation operation on the ticket information after text preprocessing to obtain multiple word units; A word processing unit, used for merging the multiple word units through word form restoration technology to obtain a unified word; The vectorization unit is used to calculate the importance of the unified words by using the TF-IDF algorithm to generate a vectorized vocabulary.
8. The disaster event prediction system based on artificial intelligence according to claim 7 is characterized in that: The window module also includes: A parsing unit, used for parsing the creation time field of the ticket information; A window division unit, configured to divide the ticket information into time windows by using a sliding window algorithm based on the creation time field to obtain a ticket information time window; The set division unit is used to analyze the vectorized vocabulary in the ticket information time window, and divide the ticket information time window into a predefined event window set and a predefined non-event window set according to the analysis result.
9. An electronic device, characterized in that: It includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the disaster event prediction method based on artificial intelligence as described in any one of claims 1 to 5 is implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the disaster event prediction method based on artificial intelligence as described in any one of claims 1 to 5 is implemented.