Abnormality detection method, device and equipment

By obtaining user detection preference information, dynamically adjusting the detection threshold, and combining the output of the abnormal detection model, the problem that the fixed detection threshold in the prior art cannot meet the needs of different users is solved, and more efficient and accurate abnormal detection is achieved.

CN120066825APending Publication Date: 2025-05-30HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311626584.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In the existing anomaly detection methods, fixed detection thresholds cannot meet the differences in the definition and sensitivity of abnormalities in different industries and users to computing equipment, resulting in the inability to obtain abnormal detection results that meet user needs.

Method used

By obtaining the detection preference information provided by the user, the adaptive detection threshold is determined, and the abnormality score output by the abnormality detection model is compared with the adaptive detection threshold to obtain the abnormality detection result.

Benefits of technology

It realizes dynamic adjustment of detection thresholds based on user accuracy and recall requirements, improves the accuracy and user experience of abnormal detection, and can better meet the needs of different users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120066825A_ABST
    Figure CN120066825A_ABST
Patent Text Reader

Abstract

An anomaly detection method, device and equipment, in the application, a detection device obtains detection preference information provided by a user, and the detection preference information indicates the user's demand for anomaly detection precision and recall rate. The detection device determines a detection threshold using the detection preference information. The detection device deploys an anomaly detection model, the anomaly detection model is a machine learning model used for outputting an anomaly score according to the input operation data of the computing equipment, and the anomaly score represents the probability that the computing equipment is abnormal. And the detection device obtains an anomaly detection result by using the detection threshold value and the anomaly score output by the anomaly detection model, and transmits the anomaly detection result to the user. The detection threshold value is set according to the detection preference information provided by the user, the specific value of the detection threshold value better meets the requirements of the user, and the detection preference information describes the requirements of the user for the precision and the recall rate, so that the detection threshold value is ensured to meet the requirements of the user from the two dimensions of the precision and the recall rate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to an anomaly detection method, apparatus, and device. Background Art

[0002] Anomaly detection is a routine detection required for the daily operation and maintenance of computing devices. Through anomaly detection, it is possible to determine in advance whether a computing device will malfunction, so that the operation and maintenance personnel can take countermeasures in advance and perform timely repairs on the computing device.

[0003] A common anomaly detection method is as follows: analyze the operation data of a computing device by invoking an anomaly detection algorithm to output an anomaly score, and then compare the anomaly score with a fixed detection threshold to obtain a final anomaly detection result.

[0004] In this method, the detection threshold is usually fixed. However, since different industries and users have different definitions and sensitivities to anomalies in computing devices, using a fixed detection threshold and the comparison of anomaly scores cannot obtain an anomaly detection result that meets the user's requirements. Summary of the Invention

[0005] An anomaly detection method, apparatus, and device provided in an embodiment of this application are used to meet the user's requirements for anomaly detection.

[0006] In a first aspect, an embodiment of this application further provides an anomaly detection method. This anomaly detection method can be executed by a detection device, and the method includes:

[0007] The detection device can obtain detection preference information provided by a user. The detection preference information indicates the user's requirements for the accuracy and recall rate of anomaly detection. The detection device determines a detection threshold using the detection preference information.

[0008] An anomaly detection model is deployed in the detection device. The anomaly detection model is a machine learning model used to output an anomaly score based on the operation data of a computing device input to the anomaly detection model. The anomaly score represents the probability of the computing device malfunctioning.

[0009] The detection device can obtain an anomaly detection result using the detection threshold and the anomaly score output by the anomaly detection model, and transmit the anomaly detection result to the user.

[0010] Through the above method, the detection threshold used by the detection device during anomaly detection is set according to the detection preference information provided by the user. The specific value of the detection threshold better meets the user's requirements. Moreover, since the detection preference information describes the user's requirements for accuracy and recall rate, it is ensured that the detection threshold meets the user's requirements from both the accuracy and recall rate dimensions, thereby improving the user experience.

[0011] In a possible implementation, before obtaining the anomaly detection result by using the detection threshold and the anomaly score output by the anomaly detection model, the detection device may also obtain anomaly information provided by the user. The anomaly information indicates the abnormal operation data, and the abnormal operation data is the operation data when the computing device has an anomaly. The detection device determines a training set by using the anomaly information and trains the anomaly detection model based on the training set. The embodiments of the present application do not limit the manner in which the detection device trains the anomaly detection model, which may be a supervised learning, semi-supervised learning, or unsupervised learning manner.

[0012] Through the above method, the training set used by the detection device to train the anomaly detection model is determined according to the anomaly information provided by the user, so that the operation data when the computing device has an anomaly detected by the trained anomaly detection model can better conform to the user's definition of "anomaly" and better meet the user's needs.

[0013] In a possible implementation, there are various forms of expression for the anomaly information provided by the user. The anomaly information may include the abnormal operation data, and the anomaly information may also include the normal operation data, where the normal operation data is the operation data when the computing device does not have an anomaly.

[0014] Through the above method, the form of expression of the anomaly information is relatively flexible, which is convenient for the user to provide the anomaly information according to their own needs and is applicable to different scenarios.

[0015] In a possible implementation, when the anomaly information includes the abnormal operation data, the detection device may provide the user with at least one candidate abnormal operation data. Then, the user can select from the at least one candidate abnormal operation data. The detection device may use the candidate abnormal operation data selected by the user as the abnormal operation data.

[0016] When the anomaly information includes the normal operation data, the detection device may provide the user with at least one candidate normal operation data. Then, the user can select from the at least one candidate normal operation data. The detection device may use the candidate normal operation data selected by the user as the abnormal operation data.

[0017] Through the above method, the detection device can provide the user with some candidate abnormal operation data or candidate normal operation data for selection, which is convenient for the user to define the anomaly information.

[0018] In a possible implementation, there are many ways to detect preference information indicating the user's requirements for the precision and recall rate of anomaly detection. For example, the detection preference information includes the weights set by the user for precision and recall rate. When the detection device determines the detection threshold using the detection preference information, it can use the Fβ score transformed from the F1 score, as well as the weights of precision and recall rate, to determine the detection threshold that can maximize the Fβ score, where β is determined based on the weights of precision and recall rate.

[0019] Through the above method, the user can simply and clearly indicate their requirements for precision and recall rate by setting weights for precision and recall rate. The detection device can efficiently determine the detection threshold using the Fβ score, as well as the weights of precision and recall rate.

[0020] In a possible implementation, before the detection device obtains the anomaly detection result using the detection threshold and the anomaly score output by the anomaly detection model, it can first obtain the operation data of the computing device to be detected. The detection device can be deployed on the computing device to collect the operation data of the computing device on the computing device. The detection device can also obtain the operation data of the computing device transmitted by the user.

[0021] Through the above method, the detection device can obtain the operation data of the computing device to be detected in different ways, which is applicable to different scenarios.

[0022] In a possible implementation, the anomaly detection result can indicate the magnitude relationship between the anomaly score output by the anomaly detection model and the detection threshold. The embodiments of the present application do not limit the specific indication method of the anomaly detection result. For example, the anomaly detection result includes the anomaly score output by the anomaly detection model and the detection threshold. Another example is that the anomaly detection result is the comparison result between the anomaly score output by the anomaly detection model and the detection threshold.

[0023] Through the above method, the indication method of the anomaly detection result is relatively flexible, effectively expanding the application scope of the anomaly detection method.

[0024] In a possible implementation, the anomaly detection result includes the maximum value reached by the Fβ score. The maximum value reached by the Fβ score can reflect the accuracy of the detection device in performing anomaly detection. By providing the maximum value reached by the Fβ score, it is convenient for the user to determine the accuracy of the anomaly detection result.

[0025] In a possible implementation, the Fβ score satisfies:

[0026]

[0027] where Precision is precision, Recall is recall rate, and β = w1 / w 2 where w 1 is the weight for precision, w 2 is the weight for recall, and F β is the Fβ score.

[0028] Through the above method, the Fβ score is related to precision, recall, detection threshold, the weight for precision, and the weight for recall, ensuring that the inspection threshold that meets the weights for precision and recall can be determined.

[0029] In a second aspect, an embodiment of the present application further provides a detection device. The detection device has the function of implementing the behaviors in the method example of the first aspect above. The beneficial effects can be referred to the description of the first aspect and will not be elaborated here. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In a possible design, the structure of the device includes a transmission module and a processing module. These modules can execute the corresponding functions in the method example of the first aspect above. For specific details, refer to the detailed description in the method example and will not be elaborated here.

[0030] In a third aspect, the present application further provides a computing device. The computing device includes a processor and a memory, and may further include a communication interface. The processor executes the program instructions in the memory to execute the method provided in the first aspect or any possible implementation manner of the first aspect. The memory is coupled to the processor and stores the necessary computer program instructions and data during the abnormal detection process. The communication interface is used to communicate with other devices, such as obtaining abnormal information, detection preference information, and operation data of the computing device to be detected.

[0031] In a fourth aspect, the present application provides a computing device system. The computing device system includes at least one computing device. Each computing device includes a memory and a processor. The processor of at least one computing device is used to access the code in the memory to execute the method provided in the first aspect or any possible implementation manner of the first aspect.

[0032] In a fifth aspect, the present application provides a computer-readable storage medium. When the computer-readable storage medium is executed by a computing device, the computing device executes the method provided in the first aspect or any possible implementation manner of the first aspect. The storage medium stores computer program instructions. The storage medium includes, but is not limited to, volatile memory, such as random access memory, and non-volatile memory, such as flash memory, hard disk drive (HDD), and solid state drive (SSD).

[0033] Sixth aspect, the present application provides a computing device program product, which includes computer program instructions. When executed by a computing device, the computing device executes the method provided in the foregoing first aspect or any possible implementation manner of the first aspect. This computer program product can be a software installation package. In the case where it is necessary to use the method provided in the foregoing first aspect or any possible implementation manner of the first aspect, this computer program product can be downloaded and executed on the computing device.

[0034] Seventh aspect, the present application further provides a computer chip, which is connected to a memory. The chip is used to read and execute computer program instructions stored in the memory, and execute the method described in the foregoing first aspect and each possible implementation manner of the first aspect. Description of the Drawings

[0035] Figure 1 It is a schematic structural diagram of an anomaly detection system provided by the present application;

[0036] Figure 2 It is a flowchart of an anomaly detection method provided by the present application;

[0037] Figures 3A to 3D It is a schematic diagram of a configuration interface for anomaly information provided by the present application;

[0038] Figures 4A to 4B It is a schematic diagram of a configuration interface for detection preference information provided by the present application;

[0039] Figure 5 It is a schematic diagram of a display interface for anomaly detection results provided by the present application;

[0040] Figure 6 It is a schematic structural diagram of a parameter tuning device provided by the present application;

[0041] Figures 7 to 8 It is a schematic structural diagram of a computing device provided by an embodiment of the present application. Detailed Embodiments

[0042] Before introducing an anomaly detection method, device, and equipment provided by an embodiment of the present application, some concepts related to the embodiment of the present application will be described.

[0043] (1), Operating data, abnormal operating data, and normal operating data of a computing device.

[0044] Both anomaly detection and the training of the anomaly detection model are based on the operation data of the computing device. The operation data of the computing device can characterize the state of the computing device during operation. The operation data of the computing device can be obtained during the operation of the computing device. The embodiments of the present application do not limit the specific content of the operation data of the computing device. For example, the operation data of the computing device includes some or all of the following: the occupancy rate of the processor, the bandwidth of the computing device, the free storage space in the computing device, the temperature of the computing device, and the continuous operation duration of the computing device.

[0045] In the embodiments of the present application, the operation data of the computing device can include two categories. One category is the operation data when the computing device has an anomaly (or is about to have an anomaly). For the convenience of description, this type of operation data is called anomaly operation data. The other category is the operation data when the computing device has no anomaly. For the convenience of description, this type of operation data is called normal operation data. The anomaly operation data or the normal operation data is the data required by the detection device for training the anomaly detection model. That is, the training set of the anomaly detection model includes the anomaly operation data or the normal operation data. Among them, "about to" means that there is a certain time interval from the moment when the computing device has an anomaly, and this time interval is relatively small.

[0046] Assume that the training set includes anomaly operation data. The anomaly operation data can be used as a sample set. The anomaly operation data includes one or more samples, and each sample can be the operation data when the computing device has an anomaly (or is about to have an anomaly) once.

[0047] Assume that the training set includes normal operation data. The normal operation data can be used as a sample set. The normal operation data includes one or more samples, and each sample can be the operation data when the computing device is operating normally at a certain time or at a certain moment.

[0048] (2) Anomaly detection model.

[0049] The anomaly detection model is a type of machine learning model for performing anomaly detection. The anomaly detection model can analyze the operation data of the computing device to determine whether the computing device has an anomaly or determine the probability that the computing device has an anomaly. The embodiments of the present application do not limit the specific form of the data output by the anomaly detection model. For example, the data output by the anomaly detection model is a probability value, and this probability value is the probability that the computing device has an anomaly. For another example, the data output by the anomaly detection model is an anomaly score, and this anomaly score is used to indicate the probability that the computing device has an anomaly. For another example, the data output by the anomaly detection model is a judgment result indicating whether the computing device has an anomaly or has no anomaly. In the embodiments of the present application, the case where the data output by the anomaly detection model is an anomaly score is taken as an example for description. In fact, the anomaly detection model that outputs other types of data is also applicable to the embodiments of the present application.

[0050] Among them, when the data output by the anomaly detection model is a judgment result indicating whether an anomaly has occurred or not occurred in the computing device, the anomaly detection model can be divided into two sub-models. One sub-model is used to determine the probability value (or anomaly score), and the other sub-model is to compare the probability value (or anomaly score) with the detection threshold. If the detection device adopts such an anomaly detection model, it can first train the sub-model for determining the data as a probability value or a probability value, and then after the detection device determines the detection threshold by using the detection preference information set by the user, configure the detection threshold to the other sub-model of the anomaly detection model (that is, the sub-model that makes a judgment by using the probability value (or anomaly score) and the detection threshold).

[0051] The embodiments of the present application do not limit the specific type of the anomaly detection model. The anomaly detection model is a variational quantized variational autoencoder (VQVAE) model, an isolation forest, a neural network (such as an autoencoder (AE), a long short term memory network (LSTM)), etc.

[0052] (3), Precision, recall rate.

[0053] Precision and recall rate are two parameters for measuring the accuracy of anomaly detection. In the embodiments of the present application, precision and recall rate are used to measure the accuracy of the detection device in performing anomaly detection. Specifically inside the detection device, the precision and recall rate can be understood as measuring the accuracy of the trained anomaly detection model (and the detection threshold) in the detection device.

[0054] Precision, also known as the precision rate, indicates the proportion of correctly predicted samples among all samples predicted to have an anomaly. Among them, a correctly predicted sample is the operation data when an anomaly actually occurs (or is about to occur) in the computing device, and the prediction result obtained by using the correctly predicted sample for anomaly prediction indicates that the computing device will have an anomaly (or is about to have an anomaly). Precision characterizes the probability that the detection device (or anomaly detection model) predicts that an anomaly will occur as a correctly predicted sample. The larger the precision, the greater the probability that the operation data predicted by the detection device (or anomaly detection model) to have an anomaly is real and the computing device is operating abnormally.

[0055] Recall rate, also known as the completeness rate, indicates the proportion of correctly predicted samples among all correct samples. Correct samples are the operation data when an anomaly actually occurs (or is about to occur) in the computing device. The recall rate characterizes the ability of the detection device (or anomaly detection model) to predict all samples with anomalies. The larger the recall rate, the stronger the ability of the detection device (or anomaly detection model) to predict all operation data with anomalies.

[0056] (4) Detection threshold.

[0057] In anomaly detection, the detection threshold is an important parameter, which affects the judgment result of whether the operation data of the computing device is abnormal operation data. That is to say, the detection threshold is the main basis for determining whether the computing device has an anomaly (or is about to have an anomaly).

[0058] The detection threshold can be understood as the critical value for determining whether the computing device has an anomaly (or is about to have an anomaly). Here, it is assumed that the data output by the anomaly detection model is an anomaly score. The larger the anomaly score, the greater the probability that the computing device has an anomaly. Then, when the anomaly score is greater than or equal to the detection threshold, it indicates that the computing device has an anomaly (or is about to have an anomaly). When the anomaly score is less than the detection threshold, it indicates that the computing device will not have an anomaly. Among them, the situation where the anomaly score is equal to the detection threshold is a special case. In some scenarios, when the anomaly score is equal to the detection threshold, it indicates that the predicted computing device will have an anomaly. In other scenarios, when the anomaly score is equal to the detection threshold, it indicates that the predicted computing device will not have an anomaly. This application only takes the case where the anomaly score is equal to the detection threshold and indicates that the predicted computing device will have an anomaly as an example for illustration.

[0059] The specific value of the detection threshold is related to the specific form of the data output by the anomaly detection model. For example, if the data output by the anomaly detection model is an anomaly score, then the detection threshold is also a score. The detection threshold is the minimum score when the computing device has an anomaly (applicable to the case where the larger the anomaly score, the greater the probability that the computing device has an anomaly); the detection threshold is the maximum score when the computing device has an anomaly (applicable to the case where the larger the anomaly score, the smaller the probability that the computing device has an anomaly).

[0060] It can be seen that the specific value of the detection threshold will affect the accuracy of determining whether the computing device has an anomaly (or is about to have an anomaly). In the embodiments of this application, the detection threshold is not fixed, but is defined according to the user's own needs. The method of defining the detection threshold according to the user's own needs will be introduced below and will not be elaborated here.

[0061] Such as Figure 1As shown in the figure, it is a schematic architecture diagram of an anomaly detection system provided by an embodiment of the present application. The anomaly detection system includes a collection device 200 and a detection device 100.

[0062] The collection device 200 has a data collection function. The collection device 200 is deployed on the user side or on the side of the computing device to be detected. The collection device 200 can obtain the anomaly information and detection preference information provided by the user from the user. Among them, the anomaly information indicates the abnormal operation data, and the detection preference information indicates the user's requirements for the accuracy and / or recall rate of anomaly detection. The collection device 200 can also obtain the operation data of the computing device from the user or from the side of the computing device to be detected.

[0063] There is a connection between the collection device 200 and the detection device 100, and the collected data (such as anomaly information, detection preference information, and operation data of the computing device to be detected) can be transmitted to the detection device 100 so that the detection device 100 can complete the training of the anomaly detection model, the determination of the detection threshold, and the anomaly detection of the computing device to be detected.

[0064] The collection device 200 also has a transmission function. Since the collection device 200 is closer to the user, the collection device 200 can also transmit the anomaly detection result to the user.

[0065] In the embodiment of the present application, the specific form of the collection device 200 is not limited. The collection device 200 can be a hardware device. For example, the collection device 200 can be an offloading card, a computing device, a chip, a processor, etc. The collection device 200 can also be a software module, such as a client for anomaly detection deployed on the user side, a virtual machine, a container, etc.

[0066] The detection device 100 can perform anomaly detection on the computing device. The detection device 100 can provide a personalized anomaly detection function for the user and can perform anomaly detection on the computing device based on the user's own needs. "Personalization" is reflected in the following two aspects:

[0067] First, the training of the anomaly detection model.

[0068] The anomaly detection model is the main module in the detection device 100 to implement anomaly detection. The training set used in the training of the anomaly detection model can be determined according to the anomaly information provided by the user.

[0069] Through the anomaly information, the user can define the abnormal operation data. The user-defined abnormal operation data is the operation data that the user expects to be detected in the anomaly detection or the operation data that has similar (or the same) characteristics as the operation data that the user expects to be detected in the anomaly detection. The user-defined abnormal operation data reflects the user's requirements for anomaly detection to a certain extent.

[0070] Moreover, the abnormal operation data detected by the anomaly detection model trained using the user-defined abnormal operation data is also more in line with the user's needs.

[0071] The embodiments of the present application do not limit the manner in which the detection device 100 provides the user with abnormal operation data defined by the abnormal information. For example, the user can directly use the abnormal operation data as the abnormal information; or, the user can use the normal operation data as the abnormal information. In this case, the user-defined abnormal operation data is the operation data different from the normal operation data.

[0072] It should be noted that in the embodiments of the present application, the training of the anomaly detection model is completed by the detection device 100 as an example. In fact, the training of the anomaly detection model can also be completed by other devices, and after the training is completed, the anomaly detection model is deployed on the detection device 100.

[0073] II. Determination of the detection threshold.

[0074] The detection threshold is an important parameter for determining whether a computing device is abnormal. In the embodiments of the present application, the user is allowed to define the detection threshold.

[0075] In the embodiments of the present application, the manner in which the user defines the detection threshold is not simply allowing the user to configure the specific value of the detection threshold. Instead, the user is allowed to provide the degree of emphasis on the precision and / or recall rate of anomaly detection (that is, allowing the user to provide detection preference information), and the detection device 100 can determine the value of the detection threshold by understanding the degree of emphasis on the precision and recall rate of anomaly detection by the user.

[0076] It can be seen that the specific value of the detection threshold is determined through comprehensive evaluation from two dimensions: precision and recall rate. Therefore, the finally obtained detection threshold can meet the user's requirements for the precision and recall rate of anomaly detection.

[0077] After the detection device 100 completes the training of the anomaly detection model and the determination of the detection threshold, it can perform anomaly detection on the computing device to be detected and obtain an anomaly detection result, which indicates the magnitude relationship between the anomaly score of the operation data of the computing device and the detection threshold. After obtaining the anomaly detection result, the detection device 100 transmits the anomaly detection result to the user through the acquisition device 200.

[0078] The embodiments of the present application do not limit the specific form of the detection device 100. The detection device 100 may be a hardware device. For example, the detection device 100 may be a computing device, a computing device cluster, or a chip, a processor, etc. in a computing device. The detection device 100 may also be a software device. The detection device 100 may be an anomaly detection software, a container, or a virtual machine, etc. deployed on one or more computing devices.

[0079] It should be noted that the embodiments of the present application do not limit the specific type of the computing device for which the detection device 100 performs anomaly detection. The computing device may be a user equipment (UE), a wireless terminal device, a mobile terminal device, a wearable mobile device. The computing device may also be a server, a desktop computer, an offload card, etc. Any device with data processing capabilities can be used as the detection object of the detection device 100. In some scenarios, anomaly detection may also be performed on components in a computing device or modules in a computing system. The anomaly detection method is the same as the type of anomaly detection method provided in the embodiments of the present application, except that the object for anomaly detection, that is, the object to be detected, is different. Therefore, the anomaly detection method provided in the embodiments of the present application is also applicable to the detection of modules or components other than computing devices.

[0080] In Figure 1 only the case where the detection device 100 interacts with the user through the acquisition device 200 is taken as an example for illustration. In actual applications, the detection device 100 may also be directly deployed on the user side, such as deployed on the computing device to be detected, directly interacting with the user, obtaining the anomaly information and detection preference information provided by the user, as well as the operation data of the computing device to be detected.

[0081] Next, in combination with Figure 2 an anomaly detection method provided by the embodiments of the present application will be described. The anomaly detection method includes two parts. One part is the preparation stage. In this preparation stage, the detection device 100 completes the training of the anomaly detection model and sets the detection threshold according to the detection preference information provided by the user. Specifically, reference may be made to step 201 to step 205. The other part is the testing stage. In the detection stage, the detection device 100 obtains the operation data of the computing device to be detected, calls the anomaly detection model and the anomaly threshold to obtain the anomaly detection result, and presents the anomaly detection result to the user. Specifically, reference may be made to step 206 to step 208.

[0082] Step 201: The detection device 100 obtains the anomaly information provided by the user. The anomaly information indicates the anomaly operation data, and the anomaly operation data is the operation data when the computing device has an anomaly.

[0083] The embodiments of the present application do not limit the specific presentation form of the exception information. The following lists two possible presentation forms:

[0084] Form 1: The exception information includes exception operation data.

[0085] The exception information can directly include the operation data when the computing device has an exception. Since the abnormal operation data of the device is provided for the user, it is the type of abnormal operation data that the user expects to be detected during subsequent exception detection. In other words, the abnormal operation data included in the exception information carries the characteristics of the abnormal operation data that the user expects to be detected during subsequent exception detection.

[0086] There are many ways for the user to provide the exception information of this form to the detection device 100. The embodiments of the present application do not limit the way for the user to provide the exception information of this form to the detection device 100. For example, the user can send the exception information to the detection device 100 through the acquisition device 200 deployed on the user side. Another example is that the user can directly interact with the detection device 100. The user can operate the detection device 100 and transmit the exception information to the detection device 100.

[0087] In other words, the detection device 100 allows the user to determine the abnormal operation data according to their own needs. Thus, the exception information is formed. In the embodiments of the present application, the detection device 100 can provide the user with a variety of different ways to determine the abnormal operation data. Here, two ways to determine the abnormal operation data provided for the user are listed:

[0088] Way 1: The user provides the abnormal operation data collected or saved by themselves as the exception information to the detection device 100.

[0089] In this way, the user can directly provide the abnormal operation data device to the detection device 100. For example, the user can use the operation data of their own computing device when an exception occurs as the abnormal operation data and provide it to the detection device 100.

[0090] The embodiments of the present application do not limit the way for the user to provide the abnormal operation data as the exception information to the detection device 100. For example, the user can send the abnormal operation data to the detection device 100 through the computing device deployed on the user side.

[0091] Another example is that the detection device 100 provides a configuration interface for the abnormal operation data to the user. Through this configuration interface, the user can transmit the abnormal operation data to the detection device 100 through this configuration interface. The embodiments of the present application do not limit the specific form of the configuration interface. For example, the configuration interface can be presented as a visual configuration interface for the user.

[0092] Such asFigure 3A This is a configuration interface for abnormal operation data provided to users in an embodiment of the present application. In this configuration interface, the user can choose to browse files, select the file containing the abnormal operation data for uploading, and in this configuration interface, by clicking the "Upload" option, the abnormal operation data is transmitted to the detection device 100.

[0093] Method 2: The detection device 100 provides the user with multiple candidate abnormal operation data, and the user selects the abnormal operation data from them.

[0094] In some scenarios, it is not convenient for the user to provide abnormal operation data by themselves. For example, the abnormal operation data from the user's computing device has confidentiality requirements, or the user does not save enough abnormal operation data. To facilitate the user to customize the abnormal operation data, the detection device 100 can provide the user with multiple candidate abnormal operation data. The user can view the multiple candidate abnormal operation data and select one or more of them as the abnormal operation data.

[0095] Such as Figure 3B This is a selection interface for candidate abnormal operation data provided to users in an embodiment of the present application. In this selection interface, the user can view the multiple candidate abnormal operation data provided by the detection device 100 and check some or all of them as the abnormal operation data.

[0096] Form 2: The abnormal information includes normal operation data. The normal operation data is the operation data when the computing device does not have an abnormality.

[0097] In this method, the user does not directly provide the abnormal operation data device to the detection device 100, but provides the normal operation data to the detection device 100. Then, the operation data different from the normal operation data provided by the user is the abnormal operation data.

[0098] Method 1: The user provides the normal operation data collected or saved by themselves as the abnormal information to the detection device 100.

[0099] In this method, the user can directly provide the normal operation data device to the detection device 100. For example, the user can provide the operation data when their computing device does not have an abnormality as the normal operation data to the detection device 100.

[0100] In the embodiment of the present application, the method for the user to provide the normal operation data as the abnormal information to the detection device 100 is not limited. For example, the user can send the normal operation data to the detection device 100 through the acquisition device 200 deployed on the user side.

[0101] For another example, the detection device 100 provides a configuration interface for the normal operation data to the user. Through this configuration interface, the user can transmit the normal operation data to the detection device 100 through this configuration interface. The embodiments of the present application do not limit the specific form of this configuration interface. For example, this configuration interface can be presented as a visual configuration interface for the user.

[0102] Such as Figure 3C , a configuration interface for the normal operation data provided to the user by the embodiments of the present application is provided. In this configuration interface, the user can select to browse files, select the files containing the normal operation data for uploading, and in this configuration interface, by clicking the "Upload" option, the normal operation data is transmitted to the detection device 100.

[0103] Method 2: The detection device 100 provides the user with a variety of candidate normal operation data, and the user selects the device normal operation data according to their own needs.

[0104] In some scenarios, it is not convenient for the user to provide the normal operation data by themselves. For example, the normal operation data from the user's computing device has confidentiality requirements. Another example is that the user does not save enough normal operation data. To facilitate the user to customize the normal operation data, the detection device 100 can provide the user with a variety of candidate normal operation data. The user can view the variety of candidate normal operation data and select one or more of them as the normal operation data.

[0105] Such as Figure 3D , a selection interface for the candidate normal operation data provided to the user by the embodiments of the present application is provided. In this selection interface, the user can view the variety of candidate normal operation data provided by the detection device 100 to the user and check some or all of them as the normal operation data.

[0106] Step 202: The detection device 100 trains the anomaly detection model according to the anomaly information provided by the user. The anomaly detection module is used to analyze the operation data of the computing device and output an anomaly score. This anomaly score represents the probability that the input operation data is abnormal operation data, or this anomaly score represents the probability that the computing device has an anomaly (or is about to have an anomaly).

[0107] When the detection device 100 trains the anomaly detection model according to the anomaly information provided by the user, it can determine the training set of the anomaly detection model according to the anomaly information provided by the user, input the samples included in the training set into the anomaly detection model to be trained, and complete the training of the anomaly detection model.

[0108] The embodiments of the present application do not limit the training method of the anomaly detection model. For example, the detection device 100 can train the anomaly detection model by using supervised learning. In supervised learning, the anomaly detection model is trained with labeled samples, and the weights of the anomaly detection model are adjusted during the training process so that the output result of the anomaly detection model gradually coincides with or approaches the label carried by the sample. For another example, the detection device 100 can train the anomaly detection model by using unsupervised learning. In unsupervised learning, the samples are not labeled, but the anomaly detection model itself needs to learn the latent "knowledge" of the samples from the samples in the training set.

[0109] Regardless of whether the data types included in the anomaly information are the same or different, the specific type of the anomaly detection model can be the same or different. For example, when the anomaly information includes normal operation data, the anomaly detection model can be a VQVAE model, and the detection device 100 can train the VQVAE model by using unsupervised learning. For another example, when the anomaly information includes abnormal operation data, the anomaly detection model can be an isolation forest model, and the detection device 100 can train the isolation forest model by using unsupervised learning. For another example, when the anomaly information includes abnormal operation data or normal operation data, the anomaly detection model can be a neural network model, and the detection device 100 can train the neural network model by using unsupervised learning or supervised learning.

[0110] Step 203: The detection device 100 obtains detection preference information provided by the user, and the detection preference information describes the user's requirements for the accuracy and / or recall rate of anomaly detection.

[0111] Different users have different requirements for anomaly detection. Some users expect to detect all possible anomalies of the computing device without omission, which is convenient for users to know in advance the possible abnormal situations and take timely countermeasures to repair the computing device. That is, the user focuses on a higher recall rate for anomaly detection. Some users tend to have the anomalies predicted by each anomaly detection be anomalies that will definitely occur, which can ensure that the countermeasures taken by the user to deal with the possible anomalies are effective and avoid the situation where the computing device has no anomaly but the user still takes countermeasures. That is, the user focuses on a higher accuracy for anomaly detection. Some users expect anomaly detection to have both a certain accuracy and a recall rate.

[0112] In order to meet the different requirements of users for the accuracy and recall rate of anomaly detection, the detection device 100 allows the user to configure the detection preference information by himself / herself, and through the detection preference information, the user can put forward the requirements for the accuracy and / or recall rate of anomaly detection.

[0113] The embodiments of the present application do not limit the way for the user to provide the detection preference information. For example, the user can transmit the detection preference information to the detection device 100 through the acquisition device 200 deployed on the user side. Another example is that the detection device 100 can provide an interface for the user to configure the detection preference information, and through this interface, the user can transmit the detection preference information to the detection device 100. The embodiments of the present application do not limit the specific form of this interface. For example, this interface can be presented as a visual configuration interface for the user.

[0114] There are many forms of expression of this detection preference information. For example, this detection preference information records the values of precision and / or recall rate. Another example is that this detection preference information records the value range of precision and / or recall rate. Another example is that this detection preference information records the weights of precision and / or recall rate, where the greater the weight, the greater the degree of emphasis.

[0115] Such as Figure 4A , a configuration interface for the detection preference information provided to the user by the embodiments of the present application is shown. In this configuration interface, the user can directly configure the weights of precision and recall rate.

[0116] It should be noted that the embodiments of the present application do not limit the value range of the weights of precision and recall rate, and their value ranges can be configured according to the actual scenario.

[0117] In practical applications, the user can provide abnormal information and detection preference information to the detection device 100 at the same time, that is, the detection device 100 can execute step 201 and step 203 simultaneously.

[0118] Such as Figure 4B , a configuration interface for the information provided to the user by the embodiments of the present application is shown. In this configuration interface, for the abnormal information, the user can choose to browse the file, select the file containing the abnormal operation data for uploading, or the user can also select some or all of the crop abnormal operation data from multiple candidate abnormal operation data. For the detection preference information, the user can configure the weights of precision and recall rate.

[0119] Step 204: The detection device 100 determines a detection threshold according to the detection preference information, and the detection threshold is the minimum value of the abnormal score indicating the occurrence of an abnormality.

[0120] After the detection device 100 obtains the detection preference information, it obtains the basis for setting the detection threshold. The embodiments of the present application do not limit the way for the detection device 100 to execute step 204. The following are several ways for the detection device 100 to determine the detection threshold.

[0121] Method 1: The detection device 100 stores the correspondence between the detection preference information and the detection threshold.

[0122] That is to say, the detection device 100 has pre-saved the corresponding relationships between various different detection preference information and detection thresholds.

[0123] Taking the case where the detection preference information records the values of precision and / or recall rate as an example, the corresponding relationships of the detection device 100 include some or all of the first corresponding relationship, the second corresponding relationship, and the third corresponding relationship.

[0124] Among them, the first corresponding relationship is the corresponding relationship between precision and the detection threshold, and this first corresponding relationship is applicable to the case where the detection preference information only records the value of precision. The second corresponding relationship is the corresponding relationship between recall rate and the detection threshold, and this second corresponding relationship is applicable to the case where the detection preference information records the value of recall rate. The third corresponding relationship is the corresponding relationship between precision, recall rate, and the detection threshold. This third corresponding relationship is applicable to the case where the detection preference information records the values of precision and recall rate.

[0125] After the detection device 100 obtains the detection preference information provided by the user, it can query the saved corresponding relationships, and determine the detection threshold corresponding to the detection preference information according to the values of precision and / or recall rate recorded in the detection preference information.

[0126] Method 2: The detection device 100 uses the F1 score and the detection preference information to determine the detection threshold.

[0127] The F1 score is the harmonic mean of precision and recall rate, and the F1 score is used to comprehensively consider the performance of precision and recall rate. The higher the F1 score, the better the precision and recall rate.

[0128] Here, taking the case where the anomaly detection model outputs an anomaly score, and the larger the anomaly score, the greater the probability of an anomaly occurring as an example, two specific examples of using the F1 score and the detection threshold information to determine the detection threshold are introduced.

[0129] Example 1: The detection preference information records the value range of precision and / or recall rate.

[0130] The F1 score is as follows:

[0131]

[0132] Among them, Precision is the precision of anomaly detection, and Recall is the recall rate of anomaly detection.

[0133] Applied to the anomaly detection model, this precision Precision indicates the proportion of correctly predicted samples among all samples predicted to have an anomaly, and Precision satisfies:

[0134] Precision = T1 / T2

[0135] Among them, T2 is the number of all samples predicted to have anomalies, that is, the anomaly score output after inputting this sample into the anomaly detection model is greater than or equal to the detection threshold. T1 is the number of correctly predicted samples. A correctly predicted sample is the operation data when the computing device actually has an anomaly (or is about to have an anomaly), and the prediction result obtained using this correctly predicted sample indicates that the computing device will have an anomaly (or is about to have an anomaly). That is to say, a correctly predicted sample is a sample whose anomaly score output after inputting this sample into the anomaly detection model is greater than the detection threshold, and this sample is the operation data when the computing device actually has an anomaly (or is about to have an anomaly).

[0136] This recall rate Recall indicates the proportion of correctly predicted samples that will have anomalies among all correct samples. The recall rate Recall satisfies:

[0137] Recall = T1 / T3

[0138] Among them, T3 is the number of correct samples. A correct sample is the operation data when the computing device actually has an anomaly (or is about to have an anomaly). The content indicated by T1 can be seen in the foregoing description and will not be elaborated here.

[0139] After the anomaly detection model is trained, after each sample included in the training set is input into this anomaly detection model, the anomaly score of each sample can be obtained. The anomaly scores of each sample will no longer change. Therefore, the values of precision and recall are related to the detection threshold.

[0140] The detection device 100 can continuously adjust the specific value of the detection threshold to change the values of precision and recall, and ensure that the values of precision and recall meet the detection preference information (records the value range of precision and / or recall), and find the maximum value of the F1 score when the values of precision and recall meet the detection preference information (records the value range of precision and / or recall). When the F1 score reaches the maximum value, the specific value of the detection threshold is the final required detection threshold. The detection device 100 can call the gradient descent algorithm (gradient descent) during the process of adjusting the specific value of the detection threshold to find the maximum value of the F1 score. The gradient descent algorithm is an optimization algorithm, usually also called the steepest descent method. To find the maximum value of the F1 score, the specific value of the detection threshold is adjusted in the direction of the gradient (or an approximate gradient) corresponding to the current point on this F1 score with a specified step size.

[0141] The maximum value that the F1 score can reach can characterize the accuracy of the anomaly detection of the detection device 100. The maximum value that the F1 score can reach can be used as a parameter to measure the detection threshold and the anomaly detection model. For the convenience of description, the maximum value that the F1 score can reach is called the confidence index of anomaly detection. The higher the confidence index, the higher the accuracy of the anomaly detection of the detection device 100.

[0142] Example 2. The detection preference information records the weights of precision and / or recall, where the weight of precision is w 1 , and the weight of recall is w 2 .

[0143] The F1 score is transformed, and the transformed F1 score is F β The score is as follows:

[0144]

[0145] where Precision is the precision of anomaly detection, Recall is the recall of anomaly detection, and β = w 1 / w 2 . The descriptions of Precision and Recall can be referred to the foregoing descriptions, which will not be elaborated here. It can be seen that the F1 score is the Fβ score when β is equal to 1.

[0146] The detection device 100 can continuously adjust the specific value of the detection threshold by using the gradient descent algorithm to change the values of precision and recall, and find the maximum value of the Fβ score. When the Fβ score reaches the maximum value, the specific value of the detection threshold is the final required detection threshold.

[0147] The detection device 100 can call the gradient descent algorithm during the process of adjusting the specific value of the detection threshold to find the maximum value of the Fβ score.

[0148] Similarly, the maximum value that the Fβ score can reach can characterize the accuracy of the anomaly detection of the detection device 100. The maximum value that the Fβ score can reach can be used as a parameter to measure the detection threshold and the anomaly detection model. For the convenience of description, the maximum value that the Fβ score can reach is called the confidence index of anomaly detection.

[0149] So far, the preparation stage is over. In this preparation stage, the detection device 100 has completed the training of the anomaly detection model and determined the detection threshold. After that, the detection device 100 can detect the computing device to be detected. For details, please refer to the following steps.

[0150] Step 205: The detection device 100 obtains the operation data of the computing device to be detected.

[0151] The embodiments of the present application do not limit the manner in which the detection device 100 executes step 205. The following lists two execution manners:

[0152] Execution manner one: The computing device to be detected is deployed with a collection device 200. The collection device 200 collects the operation data of the computing device and sends the collected operation data to the detection device 100.

[0153] The collection device 200 can actively collect the operation data of the computing device. Before collecting the operation data of the computing device, the collection device 200 can first obtain the data collection permission from the user, and when the user grants the data collection permission, then collect the operation data of the computing device.

[0154] The collection device 200 can also collect the operation data of the computing device under the instruction of the user. When the user determines that abnormal detection needs to be performed on the computing device, the user can send an instruction to the collection device 200 to notify the collection device 200 to collect the operation data of the computing device.

[0155] Execution manner two: The detection device 100 is deployed on the computing device to be detected, and the detection device 100 directly obtains the operation data from the computing device.

[0156] The manner in which the detection device 100 directly collects the computing device is similar to the manner in which the collection device 200 in execution manner one collects the operation data of the computing device. The difference is that the device performing this data collection operation is different. For specific details, reference can be made to the foregoing description and will not be elaborated here.

[0157] Step 206: The detection device 100 inputs the operation data of the computing device into the anomaly detection model and obtains the anomaly score output by the anomaly detection model.

[0158] The detection device 100 uses the collected operation data of the computing device as the input of the anomaly detection model. The anomaly detection model extracts features from the operation data of the computing device, analyzes the features of the operation data of the computing device, and outputs the anomaly score of the operation data of the computing device.

[0159] Step 207: The detection device 100 transmits the anomaly detection result to the user, and the anomaly detection result indicates the magnitude relationship between the anomaly score and the detection threshold.

[0160] There are many specific presentation manners for the anomaly detection result, and the embodiments of the present application do not limit the specific presentation manner.

[0161] For example, the anomaly detection result can be presented as the anomaly score being greater than the detection threshold, the anomaly score being equal to the detection threshold, or the anomaly score being less than the detection threshold. That is to say, the anomaly detection result records the comparison result between the anomaly score and the detection threshold.

[0162] For another example, the anomaly detection result can be presented as the computing device may have an anomaly (when the anomaly score is greater than or equal to the detection threshold), or the computing device is working properly. That is to say, the anomaly detection result records whether the computing device has an anomaly.

[0163] For another example, the anomaly detection result can include the anomaly score and the detection threshold. Optionally, it can also include a confidence index. That is to say, the user can directly obtain the anomaly score and the detection threshold (optionally, can also view the confidence index).

[0164] The embodiments of the present application do not limit the transmission method of the anomaly detection result transmitted by the detection device 100 to the user. For example, the detection device 100 can transmit the anomaly detection result to the user in the form of text messages, emails, voicemails, application notification messages. For another example, the detection device 100 can display the anomaly detection result to the user through a visual result display interface.

[0165] As Figure 5 shown, it is a result display interface provided by the embodiments of the present application. In this result display interface, the detection device 100 can display the anomaly score to the user, as well as the specific values of the detection threshold. The detection device 100 can also display to the user the part of the running data of the computing device where the anomaly score is greater than the detection threshold, and the confidence index.

[0166] In Figure 5 it exemplarily shows a kind of running data that may exist in the computing device, where the abscissa is time and the ordinate is the occupancy rate of the processor of the computing device. The detection device 100 can mark the points where anomalies may occur in this running data.

[0167] In addition, in this result display interface, configuration options for detection preference information can also be provided. The user can view the detection threshold, confidence index, and the part of the running data of the computing device where the anomaly score is greater than the detection threshold corresponding to different detection preference information by changing the detection preference information.

[0168] Based on the same inventive concept as the method embodiments, the embodiments of the present application also provide a detection device, which is used to execute the method executed by the detection device 100 in the above method embodiments. As Figure 6 shown, the detection device 600 includes a transmission module 601 and a processing module 602. Specifically, in the detection device 600, connections are established between each module through a communication path.

[0169] A transmission module 601, configured to obtain detection preference information provided by a user, where the detection preference information indicates the user's requirements for the precision and recall rate of anomaly detection.

[0170] A processing module 602, configured to determine a detection threshold by using the detection preference information; obtain an anomaly detection result by using the detection threshold and the anomaly scores output by an anomaly detection model, where the anomaly detection model is a machine learning model configured to output anomaly scores according to the operation data of a computing device input to the anomaly detection model, and the anomaly scores characterize the probability of the computing device having an anomaly.

[0171] The transmission module 601 is further configured to transmit the anomaly detection result to the user.

[0172] As a possible implementation manner, the transmission module 601 may obtain anomaly information provided by the user, where the anomaly information indicates anomaly operation data, and the anomaly operation data is the operation data of the computing device when an anomaly occurs. The processing module 602 trains the anomaly detection model by using the anomaly information.

[0173] As a possible implementation manner, the anomaly information includes anomaly operation data or normal operation data, and the normal operation data is the operation data of the computing device when no anomaly occurs.

[0174] As a possible implementation manner, the anomaly information includes anomaly operation data, the transmission module 601 provides the user with at least one candidate anomaly operation data; and the user selects a candidate anomaly operation data from the at least one candidate anomaly operation data as the anomaly operation data.

[0175] As a possible implementation manner, the detection preference information includes the weights set by the user for the precision and recall rate, and the processing module 602 determines a detection threshold that can maximize the Fβ score by using the Fβ score after deformation of the F1 score, the weight of the precision, and the weight of the recall rate.

[0176] As a possible implementation manner, the transmission module 601 may collect the operation data of the computing device on the computing device; the transmission module 601 may also obtain the operation data of the computing device transmitted by the user.

[0177] As a possible implementation manner, the anomaly detection result includes the anomaly scores output by the anomaly detection model and the detection threshold.

[0178] As a possible implementation manner, the anomaly detection result includes the maximum value reached by the Fβ score.

[0179] As a possible implementation manner, the Fβ score satisfies:

[0180]

[0181] Among them, Precision is the precision, Recall is the recall rate, and β = w 1 / w 2 , where w 1 is the weight of the precision, w 2 is the weight of the recall rate, and F β is the Fβ score.

[0182] The division of modules in the embodiments of the present application is illustrative. It is only a logical function division. In actual implementation, there may be other division methods. In addition, in each embodiment of the present application, each functional module can be integrated in a processor, or can exist physically alone, or two or more modules can be integrated into one module. The above integrated module can be implemented in the form of hardware or in the form of a software function module.

[0183] If the integrated module is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions to enable a terminal device (which can be a personal computer, a mobile phone, or a network device, etc.) or a processor to execute all or part of the steps of the method in each embodiment of the present application. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program codes.

[0184] The present application also provides a computing device 700 as shown in Figure 7 . The computing device 700 includes a bus 701, a processor 702, a communication interface 703, and a memory 704. The processor 702, the memory 704, and the communication interface 703 communicate with each other through the bus 701.

[0185] Among them, the processor 702 can be a central processing unit (CPU), or it can also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0186] The memory 704 can use dynamic random access memory (DRAM). In addition to DRAM, the memory 704 can also be other random access memories, such as static random access memory (SRAM), etc. Additionally, the memory 702 can also be a read-only memory (ROM). For example, the read-only memory can be a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), etc. The memory 704 can also be a flash memory medium (FLASH), a hard disk drive (HDD), or a solid state disk (SSD), etc.

[0187] The memory 704 stores computer program instructions, and the processor 702 executes the computer program instructions to perform the steps executed by the detection device 100 in the method described above. Figure 2 The memory 704 can also include software modules required for other running processes such as an operating system (such as multiple modules in the detection device 600). The operating system can be LINUX TM , UNIX TM , WINDOWS TM and so on.

[0188] This application also provides a computing device system, and the computing device system includes at least one such as Figure 8The computing device 800 shown. The computing device 800 includes a bus 801, a processor 802, a communication interface 803, and a memory 804. Communication occurs between the processor 802, the memory 804, and the communication interface 803 via the bus 801. Communication occurs between at least one of the computing devices 800 in the computing device system via a communication path.

[0189] Among them, for the specific types of the processor 802 and the memory 804, reference can be made to the relevant descriptions of the processor 702 and the memory 704, which will not be elaborated here. The processor 802 executes the computer program instructions stored in the memory 804 to perform some or all of the steps executed by the detection device 100 in the method described above. Figure 2 The memory may also include software modules such as an operating system required for other running processes. The operating system can be LINUX TM , UNIX TM , WINDOWS TM and so on.

[0190] Communication is established between at least one of the computing devices 800 in the computing device system via a communication network, and any one or any number of modules in the detection device 600 run on each computing device 800.

[0191] The descriptions of the processes corresponding to the above respective figures have different focuses. For parts not detailed in a certain process, reference can be made to the relevant descriptions of other processes.

[0192] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes computer program instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in accordance with the embodiments of the present invention are generated in whole or in part. Figure 2 The processes or functions described.

[0193] The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be accessed by the computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium may be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as an SSD).

[0194] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to include these modifications and variations.

Claims

1. An anomaly detection method, characterized in that, the method includes: Obtaining detection preference information provided by the user, where the detection preference information indicates the user's requirements for the accuracy and recall rate of anomaly detection; Determining a detection threshold using the detection preference information; Obtaining an anomaly detection result using the detection threshold and the anomaly score output by the anomaly detection model, and transmitting the anomaly detection result to the user. The anomaly detection model is a machine learning model used to output the anomaly score according to the input operation data of the computing device, and the anomaly score represents the probability of the computing device having an anomaly.

2. The method according to claim 1, characterized in that, before obtaining the anomaly detection result using the detection threshold and the anomaly score output by the anomaly detection model, it further includes: Obtaining anomaly information provided by the user, where the anomaly information indicates anomaly operation data, and the anomaly operation data is the operation data when the computing device has an anomaly; Training the anomaly detection model using the anomaly information.

3. The method according to claim 2, characterized in that, the anomaly information includes the anomaly operation data or normal operation data, and the normal operation data is the operation data when the computing device does not have an anomaly.

4. The method according to claim 3, characterized in that, the anomaly information includes the anomaly operation data, and the method further includes: Providing the user with at least one candidate anomaly operation data; Selecting the candidate anomaly operation data by the user from the at least one candidate anomaly operation data as the anomaly operation data.

5. The method according to any one of claims 1 to 4, characterized in that, the detection preference information includes the weights set by the user for accuracy and recall rate, and determining the detection threshold using the detection preference information includes: Determining the detection threshold that can maximize the Fβ score using the Fβ score after deformation of the F1 score, the weight of the accuracy, and the weight of the recall rate.

6. The method according to any one of claims 1 to 5, characterized in that, before obtaining the anomaly detection result using the detection threshold and the anomaly score output by the anomaly detection model, it further includes: Collecting the operation data of the computing device on the computing device; or Obtaining the operation data of the computing device transmitted by the user.

7. The method according to any one of claims 1 to 6, characterized in that, the anomaly detection result includes the anomaly score output by the anomaly detection model and the detection threshold.

8. The method according to claim 5, characterized in that, the anomaly detection result includes the maximum value reached by the Fβ score.

9. The method according to claim 5, characterized in that, the Fβ score satisfies: Among them, Precision is the precision, Recall is the recall rate, and β = w 1 / w 2 , w 1 is the weight of the precision, w 2 is the weight of the recall rate, and F β is the Fβ score.

10. A detection device, characterized in that, the device includes: A transmission module for obtaining detection preference information provided by the user, where the detection preference information indicates the user's requirements for the accuracy and recall rate of anomaly detection; A processing module, configured to determine a detection threshold by using the detection preference information; obtain an anomaly detection result by using the detection threshold and an anomaly score output by an anomaly detection model, where the anomaly detection model is a machine learning model configured to output the anomaly score according to input operation data of a computing device, and the anomaly score represents the probability that the computing device has an anomaly; The transmission module is further configured to transmit the anomaly detection result to the user.

11. The apparatus according to claim 10, wherein, The transmission module is further configured to: obtain anomaly information provided by the user, where the anomaly information indicates anomaly operation data, and the anomaly operation data is operation data when the computing device has an anomaly; The processing module is further configured to: train the anomaly detection model by using the anomaly information.

12. The apparatus according to claim 11, wherein, The anomaly information includes the anomaly operation data or normal operation data, and the normal operation data is operation data when the computing device does not have an anomaly.

13. The apparatus according to claim 12, wherein, The anomaly information includes the anomaly operation data, and the transmission module is further configured to: Provide at least one candidate anomaly operation data to the user; Select, by the user, a candidate anomaly operation data from the at least one candidate anomaly operation data as the anomaly operation data.

14. The apparatus according to any one of claims 10 to 13, wherein, The detection preference information includes weights set by the user for precision and recall, and the processing module is configured to: Determine the detection threshold that can maximize the Fβ score by using the Fβ score obtained by transforming the F1 score, the weight of the precision, and the weight of the recall.

15. The apparatus according to any one of claims 10 to 14, wherein, The transmission module is further configured to: Collect operation data of the computing device on the computing device; or Obtain operation data of the computing device transmitted by the user.

16. The apparatus according to any one of claims 10 to 15, wherein, The anomaly detection result includes the anomaly score output by the anomaly detection model and the detection threshold.

17. The apparatus according to claim 14, wherein, The anomaly detection result includes the maximum value reached by the Fβ score.

18. The apparatus according to claim 14, wherein, The Fβ score satisfies: where Precision is the precision, Recall is the recall rate, and β = w 1 / w 2 , w 1 is the weight of the precision, w 2 is the weight of the recall rate, and F β is the Fβ score.

19. A computing device, wherein, The computing device includes a processor and a memory; The memory is configured to store computer program instructions; The processor executes by calling the computer program instructions stored in the memory to execute the method according to any one of claims 1 to 7.

20. A computer-readable storage medium, wherein, When the computer-readable storage medium is executed by a computing device, the computing device executes the method according to any one of claims 1 to 9 above.