Abnormal root cause positioning method and system, electronic equipment and storage medium

By stating and classifying the original behavioral data structured characteristics, combining adaptive anomaly detection and benchmark value prediction methods, the problem of insufficient generalization ability and adaptability of traditional algorithms under data complexity and business differences is solved, and higher anomaly detection and root cause positioning accuracy and adaptability are achieved.

CN120067596APending Publication Date: 2025-05-30CTRIP TRAVEL NETWORK TECH SHANGHAI0
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510228774.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Traditional anomaly detection and root-based positioning algorithms have limited generalization capabilities and poor adaptability in industrial practice, and the accuracy needs to be improved in actual business scenarios.

Method used

By obtaining the original behavior data, statistics are performed according to the data structured characteristics, continuous timing statistics are obtained, and classified. According to the data type, select the matching abnormal threshold calculation method, abnormal detection method and reference value prediction method to identify the abnormal points and determine their root cause.

Benefits of technology

Improve the accuracy and adaptability of abnormal detection and root cause positioning, and can more accurately and quickly identify abnormalities that occur in the target system, and accurately locate the root causes of the abnormality, thereby providing more powerful data support for the technical team.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120067596A_ABST
    Figure CN120067596A_ABST
Patent Text Reader

Abstract

The invention provides an abnormal root cause positioning method and system, electronic equipment and a storage medium. The abnormal root cause positioning method comprises the following steps: performing statistics on original behavior data according to data structured features to obtain continuous time sequence statistical data; classifying the time sequence statistical data; selecting an abnormal threshold calculation method, an abnormal detection method and a reference value prediction method which are matched according to the type of the time sequence statistical data; obtaining an abnormal threshold value of the time sequence statistical data by using an abnormal threshold value calculation method, and carrying out anomaly detection on data points in the time sequence statistical data based on the abnormal threshold value by using an anomaly detection method; performing reference value prediction by using a reference value prediction method; forming a cross dimension combination set; and constructing a contribution degree function, obtaining the contribution degree of each subset in the cross dimension combination set to the total index mutation, and determining the abnormal root cause according to the contribution degree of each subset. The abnormal root cause positioning method can effectively improve the accuracy and adaptability of abnormal detection and root cause positioning.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] Currently, anomaly detection and root cause localization algorithms have been widely applied in industrial practices, covering multiple fields such as IT operation and maintenance, financial risk control, and manufacturing monitoring. These algorithms can monitor a large amount of data in real time, timely detect potential problems in the system, avoid major failures or losses, and can also help the technical team quickly troubleshoot and fix problems by analyzing the causes of anomalies.

[0003] However, traditional anomaly detection and root cause localization algorithms still have some problems in industrial practices. For example, the limited generalization ability and poor adaptability of the model are caused by data complexity and business differences, and the accuracy of the algorithms also needs to be improved in actual business scenarios.

[0004] It should be noted that the information disclosed in the above background art section is only used to strengthen the understanding of the background of this application, and thus may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0005] Based on this, the embodiments of this application provide an anomaly root cause localization method, system, electronic device, and storage medium, which can effectively improve the accuracy and adaptability of anomaly detection and root cause localization, accurately locate the root cause leading to anomalies, and thus provide more powerful data support for the technical team.

[0006] According to some embodiments, on the one hand, this application provides an anomaly root cause localization method, including:

[0007] Obtain original behavior data, and perform statistics on the original behavior data according to data structured features to obtain continuous time series statistical data;

[0008] Classify the time series statistical data, and the time series statistical data is at least divided into a first type, a second type, and a third type;

[0009] According to the type of the time series statistical data, respectively select a matching anomaly threshold calculation method, anomaly detection method, and benchmark value prediction method;

[0010] Use the anomaly threshold calculation method to obtain the anomaly threshold of the time series statistical data, and use the anomaly detection method to perform anomaly detection on the data points in the time series statistical data based on the anomaly threshold;

[0011] For the anomaly points obtained by anomaly detection, use the benchmark value prediction method to predict the benchmark value to obtain index prediction data;

[0012] Identify the influencing elements of each dimension from the index prediction data to form a cross-dimension combination set; construct a contribution function, obtain the contribution of each subset in the cross-dimension combination set to the total index mutation, and determine the root cause of the anomaly based on the contribution of each subset.

[0013] In some embodiments, the data structured features include at least one of a time period, a holiday identifier, and a drill-down dimension.

[0014] In some embodiments, the classifying the time-series statistical data includes:

[0015] Perform a stationarity test on the time-series statistical data. If the time-series statistical data is measured to be stationary, the time-series statistical data is classified into the first type;

[0016] If the time-series statistical data is measured to be non-stationary, perform a periodicity test on the time-series statistical data. If the time-series statistical data is measured to have periodicity, the time-series statistical data is classified into the second type; otherwise, the time-series statistical data is classified into the third type.

[0017] In some embodiments, the obtaining the anomaly threshold of the time-series statistical data by using the anomaly threshold calculation method includes:

[0018] For the time-series statistical data of the second type, at least remove the periodic component, seasonal component, and predetermined time interval component from the corresponding original behavior data, and calculate the anomaly threshold;

[0019] For the time-series statistical data of the third type, directly calculate and determine whether the time-series statistical data is skewed, and select a matching anomaly threshold calculation method according to the determination result to calculate the anomaly threshold;

[0020] For the time-series statistical data of the first type, at least remove the predetermined time interval component from the corresponding original behavior data, and calculate the anomaly threshold.

[0021] In some embodiments, the performing anomaly detection on the data points in the time-series statistical data based on the anomaly threshold by using the anomaly detection method includes:

[0022] For the time-series statistical data of the first type, use a global detection algorithm for anomaly detection;

[0023] For the time-series statistical data of the second type, decompose the time-series statistical data to obtain a residual component, and use the global detection algorithm to perform anomaly detection according to the residual component;

[0024] For the time series statistical data of the third type, a local detection algorithm is used for anomaly detection.

[0025] In some embodiments, determining the anomaly root cause according to the contribution degree of each subset includes:

[0026] Selecting the subset with the largest contribution degree as the anomaly root cause.

[0027] In some embodiments, the anomaly root cause localization method further includes:

[0028] Providing simulated anomaly data, and using the simulated anomaly data as the original behavior data to determine the anomaly root cause;

[0029] Evaluating the anomaly root cause localization result by using a preset evaluation index.

[0030] In some embodiments, the step of determining the anomaly root cause is repeatedly executed until a preset number of experiments is reached.

[0031] According to some embodiments, on the other hand, the present application further provides an anomaly root cause localization system for implementing the anomaly root cause localization method provided in the foregoing embodiments. The system includes:

[0032] A data preprocessing module, configured to obtain original behavior data, and perform statistics on the original behavior data according to data structural features to obtain continuous time series statistical data;

[0033] A time series data classification module, configured to classify the time series statistical data, and the time series statistical data is at least divided into a first type, a second type, and a third type;

[0034] A matching module, configured to respectively select a matching anomaly threshold calculation method, an anomaly detection method, and a reference value prediction method according to the type of the time series statistical data;

[0035] An anomaly threshold calculation and anomaly detection module, configured to obtain the anomaly threshold of the time series statistical data by using the anomaly threshold calculation method, and perform anomaly detection on the data points in the time series statistical data based on the anomaly threshold by using the anomaly detection method;

[0036] An index prediction module, configured to perform reference value prediction on the anomaly points obtained by anomaly detection by using the reference value prediction method to obtain index prediction data;

[0037] A root cause localization module, configured to identify the influencing elements of each dimension from the index prediction data to form a cross-dimension combination set; construct a contribution degree function, obtain the contribution degree of each subset in the cross-dimension combination set to the total index mutation, and determine the anomaly root cause according to the contribution degree of each subset.

[0038] According to some embodiments, on another aspect, the present application further provides an electronic device, including:

[0039] a processor;

[0040] a memory storing executable instructions of the processor;

[0041] wherein, the processor is configured to execute the steps of the abnormal root cause location method provided in the foregoing embodiments by executing the executable instructions.

[0042] According to some embodiments, on yet another aspect, the present application provides a computer-readable storage medium for storing a program, and when the program is executed by a processor, the steps of the abnormal root cause location method provided in the foregoing embodiments are implemented.

[0043] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application.

[0044] The embodiments of the present application may / at least have the following advantages:

[0045] In the embodiments of the present application, by statistically analyzing the original behavior data according to the data structuring characteristics, continuous time-series statistical data is obtained, which helps to solve the problems of the complexity and diversity of the original behavior data, and provides a more effective and accurate data basis for subsequent anomaly detection and root cause location. By classifying the time-series statistical data, selecting appropriate abnormal threshold calculation methods and anomaly detection methods to identify anomaly points, and selecting appropriate benchmark value prediction methods to obtain index prediction data, it can better adapt to different types of time-series statistical data, and improve the generalization ability and adaptability of the embodiments of the present application. By identifying the influencing elements of each dimension from the index prediction data to form a cross-dimensional combination set, the influence of the element combinations under different dimensions on the total index can be comprehensively considered, so as to more accurately locate the root cause of the anomaly. And by constructing a contribution function to obtain the contribution of each subset in the cross-dimensional combination set to the mutation of the total index, the element set with the greatest influence on the change of the total index can be quickly screened out, so as to quickly determine the root cause of the anomaly according to the contribution of each subset.

[0046] Therefore, the embodiments of the present application can effectively improve the accuracy and adaptability of anomaly detection and root cause location, more accurately and quickly identify the anomalies occurring in the target system, and accurately locate the root cause of the anomalies, thereby providing more powerful data support for the technical team, helping the technical team to more quickly and accurately troubleshoot problems, reduce the impact of faults and repair time, and support the decision-making of system optimization and business continuity.

[0047] Other advantages, objects, and features of the present application will be set forth in part in the description which follows, and in part will be obvious to those skilled in the art upon examination of the following or may be learned from the practice of the present application. The objectives and other advantages of the present application may be realized and attained by the means of the instrumentalities and combinations particularly pointed out hereinafter. Brief Description of the Drawings

[0048] Other features, objects, and advantages of the present application will become more apparent from the following detailed description of non-limiting embodiments read in conjunction with the accompanying drawings.

[0049] Figure 1 Schematic flowchart of the abnormal root cause location method provided in some embodiments of the present application;

[0050] Figure 2 Schematic flowchart of the abnormal root cause location method provided in some other embodiments of the present application;

[0051] Figure 3 Schematic flowchart of the abnormal root cause location method provided in some further embodiments of the present application;

[0052] Figure 4 Schematic diagram of the principle of root cause location;

[0053] Figure 5 Schematic flowchart of the root cause location in the abnormal root cause location method provided in some embodiments of the present application;

[0054] Figure 6 Schematic flowchart of the effect evaluation in the abnormal root cause location method provided in some embodiments of the present application;

[0055] Figure 7 Schematic flowchart of the effect evaluation in the abnormal root cause location method provided in some other embodiments of the present application;

[0056] Figure 8 Schematic flowchart of the monitoring and backtesting mechanism in the abnormal root cause location method provided in some embodiments of the present application;

[0057] Figure 9 Schematic diagram of the structure of the abnormal root cause location system provided in some embodiments of the present application;

[0058] Figure 10 Schematic diagram of the structure of the electronic device provided in some embodiments of the present application;

[0059] Figure 11 Schematic diagram of the structure of the computer-readable storage medium provided in some embodiments of the present application. Detailed Description of the Embodiments

[0060] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art. The features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments.

[0061] In addition, the accompanying drawings are only schematic illustrations of the present application and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0062] Traditional anomaly detection and root cause localization algorithms still have some problems in industrial practice. For example, the data complexity and business differences lead to limited model generalization ability, poor adaptability, and the accuracy of the algorithms also needs to be improved in actual business scenarios.

[0063] Based on this, the present application hopes to provide a solution that can solve the above technical problems, can effectively improve the accuracy and adaptability of anomaly detection and root cause localization, accurately locate the root cause of anomalies, and thus provide more powerful data support for the technical team. Its detailed content will be elaborated in the subsequent embodiments.

[0064] According to some embodiments, on the one hand, the present application provides an anomaly root cause localization method. Please refer to Figure 1 , the anomaly root cause localization method may specifically include S100 to S600:

[0065] S100: Obtain the original behavior data, and perform statistics on the original behavior data according to the data structuring characteristics to obtain continuous time series statistical data.

[0066] S200: Classify the time series statistical data, and the time series statistical data is at least divided into a first type, a second type, and a third type.

[0067] S300: According to the type of the time series statistical data, respectively select a matching anomaly threshold calculation method, an anomaly detection method, and a reference value prediction method.

[0068] S400: Use the anomaly threshold calculation method to obtain the anomaly threshold of the time series statistical data, and use the anomaly detection method to perform anomaly detection on the data points in the time series statistical data based on the anomaly threshold.

[0069] S500: For the abnormal points obtained from anomaly detection, use the baseline value prediction method to predict the baseline value in order to obtain index prediction data.

[0070] S600: Identify the influencing elements of each dimension from the index prediction data to form a cross-dimension combination set; construct a contribution function to obtain the contribution of each subset in the cross-dimension combination set to the mutation of the total index, and determine the root cause of the anomaly according to the contribution of each subset.

[0071] This method for locating the root cause of anomalies obtains continuous time-series statistical data by statistically analyzing the original behavior data according to its data structuring characteristics, which helps to solve the problems of the complexity and diversity of the original behavior data and provides a more effective and accurate data basis for subsequent anomaly detection and root cause location. By classifying the time-series statistical data, selecting appropriate methods for calculating anomaly thresholds and anomaly detection methods to identify abnormal points, and selecting appropriate baseline value prediction methods to obtain index prediction data, it can better adapt to different types of time-series statistical data and improve the generalization ability and adaptability of this method for locating the root cause of anomalies. By identifying the influencing elements of each dimension from the index prediction data to form a cross-dimension combination set, it can comprehensively consider the impact of element combinations under different dimensions on the total index, thereby more accurately locating the root cause of the anomaly. And by constructing a contribution function to obtain the contribution of each subset in the cross-dimension combination set to the mutation of the total index, it can quickly screen out the set of elements that have the greatest impact on the change of the total index, so as to quickly determine the root cause of the anomaly according to the contribution of each subset.

[0072] Therefore, this method for locating the root cause of anomalies can effectively improve the accuracy and adaptability of anomaly detection and root cause location, more accurately and quickly identify the anomalies occurring in the target system, and precisely locate the root cause of the anomaly, thereby providing stronger data support for the technical team, helping the technical team to more quickly and accurately troubleshoot problems, reduce the impact and repair time of faults, and support decisions on system optimization and business continuity.

[0073] To more clearly illustrate the above method for locating the root cause of anomalies, the following will be combined with Figure 2 and Figure 3 to understand some embodiments of this application.

[0074] Considering that the original behavior data usually has complexity and diversity, lacks a unified standard and format, and involves different data sources and data structures, it is necessary to preprocess the original behavior data. Step S100 can also be called the data preprocessing step. In step S100, the original behavior data is statistically analyzed according to its data structuring characteristics, so that the original behavior data can be organized and statistically analyzed according to its data structuring characteristics, thereby obtaining continuous time-series statistical data.

[0075] In some embodiments, the data structuring features may include at least one of a time period, a holiday identifier, and a drill-down dimension.

[0076] It can be understood that the data structuring features have a certain degree of flexibility in actual application scenarios. For example, the time period and the drill-down dimension are necessary features, while the holiday identifier is not. In actual application scenarios, users can choose whether to include the holiday identifier according to specific needs to achieve the best effect of abnormal root cause location.

[0077] Exemplarily, step S100 may perform statistics on the metrics of the original behavior data (such as log data) according to the time period, the holiday identifier, and the drill-down dimension, so as to obtain continuous time-series statistical data. The time-series statistical data can also be referred to as metric time-series data.

[0078] Among them, the metric refers to the core metrics that the actual business cares about, such as traffic, order volume, conversion rate, and / or ROI (return on investment), etc.

[0079] In the above embodiments, the time period represents the time-periodic division of the original behavior data, such as continuous cycles of hours, days, weeks, and / or months, etc. The holiday identifier indicates whether a single time period is a holiday. Performing statistics according to the holiday identifier can identify and process some special time points in the original behavior data, and these special time points may have a significant impact on business metrics, such as traffic peaks and / or troughs during holidays, etc. The drill-down dimension is a categorical variable for further refined analysis, such as sales channels and / or business types, etc. Performing statistics on the metrics according to the drill-down dimension can enable the original behavior data to be analyzed at different classification levels, helping to identify the data change rules under different dimensions.

[0080] Through the above step S100, the original behavior data can be transformed into structured time-series statistical data, providing a more effective data basis for subsequent anomaly detection and root cause location.

[0081] Considering different business forms, the degree of volatility of the time-series statistical data is different, and a single method cannot be used for detection. Step S200 can also be referred to as the time-series data classification step. In step S200, the time-series statistical data is classified.

[0082] In some embodiments, first perform a stationarity test on the time-series statistical data. If the measured time-series statistical data is stationary, the time-series statistical data is classified into the first type. In this embodiment, the first type can also be referred to as the stationary type.

[0083] Exemplarily, statistical methods such as ADF (Augmented Dickey-Fuller), pp (Phillips-Perron), dfgls (Dickey-Fuller Generalized Least Squares), and / or kpss (Kwiatkowski-Phillips-Schmidt-Shin) can be used to detect the stationarity of time series statistical data respectively, but it is not limited thereto.

[0084] When using the ADF, pp, or dfgls statistical method to detect the stationarity of time series statistical data, if the p-value of the statistical index is less than the significance level (e.g., 0.05), it indicates that the time series statistical data is stationary. When using the kpss statistical method to detect the stationarity of time series statistical data, if the p-value of the statistical index is greater than the significance level (e.g., 0.05), it indicates that the time series statistical data is stationary.

[0085] If the stationarity of time series statistical data is detected and the time series statistical data is measured to be non-stationary, then the time series statistical data is continuously subjected to periodic detection.

[0086] Exemplarily, the Fourier transform method can be used to transform time-domain data into frequency-domain data, that is, to expand the time series statistical data into a linear combination of trigonometric functions. The coefficient of each expansion term is the Fourier coefficient. The larger the Fourier coefficient, the more likely the period of the sine wave corresponding to the expansion term is the period of the time series statistical data. The top k periods with the largest amplitudes can be taken as candidate periods. If the maximum value of the amplitude is more than 2 times the average value of other amplitudes, then the period corresponding to the maximum amplitude is considered the maximum period of the time series statistical data, indicating that the time series statistical data has periodicity.

[0087] If the periodicity of time series statistical data is detected and the time series statistical data is measured to have periodicity, then the time series statistical data is classified into the second type. In this embodiment, the second type can also be called the periodic type.

[0088] If the periodicity of time series statistical data is detected and the time series statistical data is measured to have no periodicity, then the time series statistical data is classified into the third type. In this embodiment, the third type can also be called the irregular fluctuation type.

[0089] Steps S300 and S400 jointly execute the abnormal threshold calculation step and the abnormal detection step. For the specific implementation of steps S300 and S400, some embodiments will be described below.

[0090] It can be understood that when performing anomaly detection, since an unsupervised learning method is adopted, an anomaly threshold needs to be set for the anomaly scores output by the unsupervised algorithm to determine whether a data point is anomalous.

[0091] In some embodiments, for the second type of time series statistical data, at least the periodic component, seasonal component, and predetermined time interval component are removed from the corresponding original behavior data, and the anomaly threshold is calculated; for the third type of time series statistical data, it is directly determined whether the time series statistical data is skewed, and according to the determination result, a matching anomaly threshold calculation method is selected to calculate the anomaly threshold; for the first type of time series statistical data, at least the predetermined time interval component is removed from the corresponding original behavior data, and the anomaly threshold is calculated.

[0092] Exemplarily, for the second type of time series statistical data, the STL (Seasonal-Trend decomposition using Loess) method can be used to decompose the time series statistical data into some main components and residual components. At least the periodic component, seasonal component, and predetermined time interval component are removed from the original behavior data, and the residual component is retained. By performing STL time series decomposition on the second type of time series statistical data, periodic fluctuations and trend changes can be removed to facilitate further analysis of the time series statistical data.

[0093] Among them, the predetermined time interval can be, for example, a holiday.

[0094] After at least removing the periodic component, seasonal component, and predetermined time interval component from the original behavior data, the anomaly threshold can be calculated using, for example, the Z-score + elbow method.

[0095] The Z-score + elbow method refers to the combination of the Z-score and the elbow method. Among them, the Z-score is used to measure the degree of deviation of a data point from its mean value, so as to identify outliers that deviate too far from the average value. The calculation formula of the Z-score is as follows:

[0096]

[0097] In the above formula, X represents the original behavior data, represents the average value of the original behavior data, and S represents the standard deviation.

[0098] Exemplarily, when calculating the anomaly threshold for the third type of time series statistical data, if it is determined that the time series statistical data has obvious skewness, for example, the skewness is greater than or equal to 1, the IQR method (interquartile range method) can be used to calculate the anomaly threshold; if it is determined that the time series statistical data is relatively close to the normal distribution or only slightly skewed, for example, the skewness is less than 1, the Z-score + elbow method can be used to calculate the anomaly threshold.

[0099] The IQR method refers to the difference between the third quartile (Q3) and the first quartile (Q1) of a data set, which is used to measure the dispersion of the data set, thereby helping to identify outliers in the original behavioral data.

[0100] The calculation formula of IQR is as follows:

[0101] IQR = Q3 - Q1

[0102] When calculating the anomaly threshold using the IQR method, a box plot can be generated as a visual output. Through the box plot, the central tendency, dispersion degree, and positions of anomaly points of the data can be clearly displayed, etc., providing more intuitive visual support for data analysis and anomaly detection.

[0103] Exemplarily, for the first type of time series statistical data, after at least removing the predetermined time interval component from the original behavioral data, the Z-score + elbow method can be used to calculate the anomaly threshold.

[0104] In some embodiments, for the first type of time series statistical data, a global detection algorithm is used for anomaly detection; for the second type of time series statistical data, the residual component is obtained by decomposing the time series statistical data, and a global detection algorithm is used for anomaly detection based on the residual component; for the third type of time series statistical data, a local detection algorithm is used for anomaly detection.

[0105] Exemplarily, for the second type of time series statistical data, the STL method can be used to decompose the time series statistical data to obtain the residual component, and a global detection algorithm is used for anomaly detection of the residual component.

[0106] As an example, the voting method can be used to judge anomaly points. Two or more anomaly detection algorithms are used together to judge anomalies. When the number of times a data point is judged to be an anomaly is greater than the preset number threshold, then this data point is considered an anomaly point. For example, four anomaly detection algorithms can be used together to judge anomalies. When the number of times a data point is judged to be an anomaly is greater than two, then this data point is considered an anomaly point.

[0107] Using the voting method to judge anomaly points can combine multiple anomaly detection algorithms for comprehensive judgment, thereby improving the accuracy and reliability of anomaly detection and providing more reliable data support for subsequent root cause location.

[0108] When using global detection algorithms for anomaly detection, algorithms such as KNN (K-Nearest Neighbors), IForest (Isolation Forest), PCA (Principal Component Analysis), and / or CBLOF (Clustering-Based Local Outlier Factor) etc. can be used, but are not limited thereto. When using local detection algorithms for anomaly detection, algorithms such as LOF (Local Outlier Factor), KNN, COF (Connectivity-Based Outlier Factor), and / or CBLOF etc. can be used, but are not limited thereto.

[0109] It should be noted that the detection range of the KNN algorithm depends on the selection of the K value. When the K value is large, KNN considers a wider neighborhood range, which can cover the global distribution characteristics of the data, thus achieving global detection; when the K value is small, KNN mainly focuses on the local neighborhood of the samples, and can more sensitively capture local anomalies to achieve local detection. The CBLOF algorithm combines clustering and local outlier factors. In the clustering stage, CBLOF considers the global distribution of the data and divides the data into different subsets through clustering; when calculating the local outlier factor, CBLOF performs local detection within each cluster and can identify local outlier points within the cluster.

[0110] In the present application, root cause localization refers to comparing the values in the current time interval with the predicted values in the reference time interval, and attributing the difference to the joint influence of one or more dimensions, so as to find the cause of the anomaly. In this process, predicting the reference value for the anomaly point is an important prerequisite for root cause localization.

[0111] Step S500 can also be referred to as the anomaly point data detection step. In step S500, for the anomaly points obtained by anomaly detection, the reference value prediction method is used to predict the reference value to obtain the index prediction data. It should be noted that the aforementioned reference value prediction method should be selected according to the type of time series statistical data in step S300.

[0112] Exemplarily, for the first type of time series statistical data, the reference value of the anomaly point can be estimated by using the weighted moving average value of historical data through EWMA (Exponential Weighted Moving Average) to perform reference value prediction.

[0113] The calculation formula of EWMA is as follows:

[0114] vt = βv t-1 +(1 - β)θ t

[0115] In the above formula, θ t represents the actual value at time t, β represents the rate of weighted decline, and the smaller the value of β, the faster the decline. v t is the value of EWMA at time t.

[0116] Exemplarily, for the time series statistical data of the second type and the third type, the Prophet algorithm can be used for benchmark value prediction. The Prophet algorithm is a time series prediction algorithm based on machine learning, which can automatically fit the trends, seasonal variations, holiday effects, etc. in the time series statistical data, so as to achieve accurate benchmark value prediction.

[0117] The calculation formula of the Prophet algorithm is as follows:

[0118] Y(t) = g(t) + s(t) + h(t) + ε(t)

[0119] In the above formula, Y(t) represents the predicted benchmark value, g(t) represents the overall trend term, s(t) represents the periodic term, h(t) represents the holiday term, and ε(t) represents the residual term. The benchmark value prediction is completed by adding g(t), s(t), h(t) and ε(t).

[0120] In the above steps, by selecting a matching benchmark value prediction method for different types of time series statistical data, the accuracy, adaptability and flexibility of the benchmark value prediction can be effectively improved, so as to provide more reliable data support for subsequent root cause location.

[0121] Please combine Figure 4 to understand that the idea of root cause location is to compare the values in the current time interval with the values in the benchmark time interval / predicted values, attribute the difference to the influence of a certain dimension or some dimensions together, find the cause of the anomaly, and predicting the benchmark value for the anomaly point is the premise of root cause location.

[0122] In actual business, core business indicators are usually a multi-dimensional additive indicator set. Such as Figure 5As shown, when an anomaly is detected in the overall metric at a certain data point, it is necessary to identify the cross-dimensions of which fine-grained metrics have caused the anomaly in the overall metric and construct an index dimension decomposition system. For example, in the overall order volume metric of an OTA platform (online travel platform), multiple dimensions such as sales channels and business types are involved. Each dimension contains a series of elements. For example, sales channels can include APP, web pages, distribution channels, etc., and business types can include air tickets, hotels, train tickets, etc. When the overall metric is abnormal, the cause of the anomaly may be a combination of elements under different dimensions, such as {sales channel = APP, business type = hotel}.

[0123] Step S600 can also be referred to as the root cause location step. Please continue to refer to Figure 5 , in step S600, identify the influencing elements (Contributer) of each dimension from the index prediction data to form a set of cross-dimension combinations. Thus, in the set of element combinations under different dimensions, a contribution function can be constructed to quantify the degree of influence of each subset in the cross-dimension combination set on the change of the overall metric value, obtain the contribution of each subset in the cross-dimension combination set to the mutation of the overall metric, and determine the root cause of the anomaly according to the contribution of each subset. In this way, the root cause of the anomaly can be located comprehensively, accurately, and efficiently, providing strong data support for the technical team.

[0124] Exemplarily, in the process of obtaining the contribution of each subset in the cross-dimension combination set to the mutation of the overall metric, Squeeze can be used for screening. By setting thresholds or rules, exclude element combinations with small or irrelevant contributions, thereby narrowing the scope of the root cause set and improving the efficiency and accuracy of root cause location.

[0125] When determining the root cause of the anomaly, Adtributor can be used to attribute the mutation of the overall metric to specific dimension combinations or influencing elements, and determine the root cause of the anomaly through the analysis of the index prediction data.

[0126] When analyzing the index prediction data, by identifying the Hotspot, the most significant or abnormal part of the data can be found, so as to quickly locate the possible location of the root cause of the anomaly and further narrow the scope of the root cause set.

[0127] In some embodiments, the subset with the largest contribution can be selected as the root cause.

[0128] As an example, the voting method can be used to determine the root cause. Identify the root cause through two or more root cause location algorithms, and use the dimension combination with the highest hit count as the final root cause location result. For example, four root cause location algorithms can be used, and the dimension combination with the highest hit count is used as the final root cause location result.

[0129] In some application scenarios, the dimension combination may generate a very large search space. Due to the excessive search space, computational efficiency issues may arise when performing root cause localization. Based on this, in some embodiments, heuristic search methods and / or pruning strategies are adopted to improve computational efficiency, ensuring that the root cause localization task can be completed at a faster speed while being accurate by intelligently reducing the search scope or optimizing the search process.

[0130] According to some of the above embodiments, the abnormal root cause localization method provided by this application can construct an automated detection tool through steps such as automatic classification, anomaly detection, and root cause localization, and accurately locate the root cause of the problem by mining potential anomalies from historical data (such as system log data).

[0131] In actual business scenarios, there are few abnormal samples, making it difficult to evaluate through real data. Based on this, please combine Figure 6 and Figure 7 Understand that in some embodiments, the abnormal root cause localization method may further include the following steps S710 - S720 for evaluating the effectiveness of the abnormal root cause localization model (hereinafter simply referred to as the "model").

[0132] In step S710, simulated abnormal data is provided to determine the root cause of the anomaly using the simulated abnormal data as the original behavior data. By using the simulated abnormal data, a comprehensive and systematic evaluation of the model can be carried out under the premise of controlling variables.

[0133] Exemplarily, for the combination of the finest-grained elements of each dimension, abnormal values can be randomly injected to change the amplitude of the original behavior data at a certain time point, and the change amplitude is k times the original data. If the anomaly of the simulated data increases, the value of k can be taken as 2 - 5; if the anomaly of the simulated data decreases, the value of k can be taken as 0.2 - 0.5. In this way, abnormal situations can be effectively simulated, providing a data basis for model evaluation.

[0134] It should be noted that in step S710, the root cause of the anomaly can be determined by executing the aforementioned steps S200 - S600, and the specific process can be understood with reference to the foregoing embodiments and will not be elaborated here.

[0135] In step S720, the preset evaluation metrics are used to evaluate the abnormal root cause localization results. By using the preset evaluation metrics, the performance of the model is quantified from multiple dimensions.

[0136] Exemplarily, if the value of the calculated preset evaluation metric is greater than or equal to the preset evaluation threshold (such as 0.8), it can be considered that the current model has good performance. The preset evaluation metrics may include but are not limited to precision, recall, root cause hit rate, and so on.

[0137] By adding the step of model effect evaluation, the above embodiments help to improve the root cause location effect of the model. When the system encounters an anomaly, it can assist the technical team in troubleshooting problems more quickly and accurately, further reducing the impact of faults and the repair time.

[0138] In some embodiments, in step S710, the step of determining the root cause of the anomaly can be repeatedly executed, that is, the foregoing steps S200 to S600 are repeatedly executed to determine the root cause of the anomaly until a preset number of experiments is reached.

[0139] By repeatedly executing the step of determining the root cause of the anomaly multiple times, more data points can be provided, thereby effectively reducing the evaluation error caused by data randomness or accidental factors (such as random noise), making the evaluation results more stable and reliable, and being able to more accurately reflect the true performance of the model.

[0140] Exemplarily, the preset number of experiments can be set before executing steps S710 to S720.

[0141] In addition, the anomaly injection rate can also be set before executing steps S710 to S720. The anomaly injection rate refers to the proportion of anomaly data injected into the simulated data. By adjusting the anomaly injection rate, the performance of the model under different anomaly situations can be simulated, so as to more accurately evaluate the adaptability and accuracy of the model under different anomaly scenarios.

[0142] In some embodiments, for misjudged samples, the details of the experimental results will be output, such as generating a detailed experimental result report, which may include the specific situation of the wrong judgment and relevant data information, but is not limited thereto.

[0143] By deeply analyzing the misjudged samples, the performance shortcoming of the model in specific aspects can be accurately found, providing a clear direction for model optimization and process improvement, which is beneficial to further improving the accuracy and reliability of the model, achieving the closed-loop optimization of the system, and gradually approaching and even reaching the expected goal through continuous iterative evolution.

[0144] In some embodiments, a monitoring and backtesting mechanism can be set up after the model is put into production to ensure that the inference effect of the model remains stable and reliable.

[0145] For example Figure 8As shown, the present application can use the effect evaluation module to execute the monitoring and backtesting mechanism, and perform backtesting periodically (e.g., every month) by means of anomaly injection, that is, injecting simulated anomaly data into the normal data at a preset anomaly injection rate, using this data as the original behavior data, and processing it according to the aforementioned anomaly root cause localization method to evaluate the current model's detection and root cause localization effects for anomalies. By comparing the backtesting results before and after the model goes online, it is judged whether the effect of the current model has significantly decreased compared to before going online, for example, the indicator drops by more than 10%. If it is found that the model effect has significantly decreased, it indicates that the model may have performance degradation or other problems. At this time, an alarm needs to be issued in a timely manner to remind the technical team to optimize the model to ensure that the model can continuously and stably provide accurate anomaly root cause localization results to meet the actual business needs. Through this regular monitoring and backtesting mechanism, problems that may occur during the operation of the model can be discovered and solved in a timely manner, ensuring that the inference effect of the model is always in a good state, providing strong data support for the technical team, and helping them better optimize the system and make business decisions.

[0146] Based on the same inventive concept, on the other hand, the present application also provides an anomaly root cause localization system for implementing the above-mentioned anomaly root cause localization method.

[0147] Please refer to Figure 9 , the anomaly root cause localization system may specifically include a data preprocessing module 10, a time series data classification module 20, a matching module 30, an anomaly threshold calculation and anomaly detection module 40, an index prediction module 50, and a root cause localization module 60.

[0148] The data preprocessing module 10 is configured to obtain the original behavior data and perform statistics on the original behavior data according to the data structuring characteristics to obtain continuous time series statistical data.

[0149] The time series data classification module 20 is configured to classify the time series statistical data, and the time series statistical data is at least divided into a first type, a second type, and a third type.

[0150] The matching module 30 is configured to respectively select a matching anomaly threshold calculation method, an anomaly detection method, and a reference value prediction method according to the type of the time series statistical data.

[0151] The anomaly threshold calculation and anomaly detection module 40 is configured to obtain the anomaly threshold of the time series statistical data by using the anomaly threshold calculation method, and perform anomaly detection on the data points in the time series statistical data based on the anomaly threshold by using the anomaly detection method.

[0152] The metric prediction module 50 is configured to perform baseline value prediction on the anomaly points obtained from anomaly detection by using the baseline value prediction method to obtain metric prediction data.

[0153] The root cause location module 60 is configured to identify the influencing elements of each dimension from the metric prediction data to form a cross-dimension combination set; construct a contribution function to obtain the contribution of each subset in the cross-dimension combination set to the total metric mutation, and determine the anomaly root cause according to the contribution of each subset.

[0154] This anomaly root cause location system obtains continuous time-series statistical data by statistically analyzing the original behavior data according to the data structure characteristics, which helps to solve the problems of complexity and diversity of the original behavior data and provides a more effective and accurate data basis for subsequent anomaly detection and root cause location. By classifying the time-series statistical data, selecting appropriate anomaly threshold calculation methods and anomaly detection methods to identify anomaly points, and selecting appropriate baseline value prediction methods to obtain metric prediction data, it can better adapt to different types of time-series statistical data and improve the generalization ability and adaptability of this anomaly root cause location system. By identifying the influencing elements of each dimension from the metric prediction data to form a cross-dimension combination set, it can comprehensively consider the influence of element combinations under different dimensions on the total metric, so as to more accurately locate the root cause of the anomaly. And by constructing a contribution function to obtain the contribution of each subset in the cross-dimension combination set to the total metric mutation, it can quickly screen out the element set with the greatest influence on the total metric change, so as to quickly determine the anomaly root cause according to the contribution of each subset.

[0155] Therefore, this anomaly root cause location system can effectively improve the accuracy and adaptability of anomaly detection and root cause location, more accurately and quickly identify the anomalies occurring in the target system, and accurately locate the root cause of the anomalies, thus providing more powerful data support for the technical team, helping the technical team to more quickly and accurately troubleshoot problems, reduce the impact and repair time of faults, and support the decision-making of system optimization and business continuity.

[0156] It should be noted that each module in the above anomaly root cause location system can be implemented in whole or in part by software, hardware and their combinations. The above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0157] Moreover, the anomaly root cause location system of this application also includes other existing functional modules that support the operation of the anomaly root cause location system. Figure 9 The displayed anomaly root cause location system is only an example and should not bring any restrictions to the functions and usage scopes of the embodiments of this application.

[0158] According to some embodiments, on another aspect, the present application further provides an electronic device, including a processor; a memory storing executable instructions of the processor; wherein, the processor is configured to execute the steps of the abnormal root cause location method described in the foregoing embodiments by executing the executable instructions.

[0159] Those skilled in the art can understand that various aspects of the present application can be implemented as a system, a method, or a program product. Therefore, various aspects of the present application can be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to as "circuit", "module", or "platform" here.

[0160] The following refers to Figure 10 to describe the electronic device 600 according to this embodiment of the present application. Figure 10 The illustrated electronic device 600 is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present application.

[0161] As Figure 10 shown, the electronic device 600 is presented in the form of a general-purpose computing device. The components of the electronic device 600 may include but are not limited to: at least one processing unit 610, at least one storage unit 620, a bus 630 connecting different system components (including the storage unit 620 and the processing unit 610), a display unit 640, etc.

[0162] Among them, the storage unit stores program codes, and the program codes can be executed by the processing unit 610, so that the processing unit 610 executes the steps according to various exemplary embodiments of the present application described in the above abnormal root cause location method part of this specification. For example, the processing unit 610 can execute the steps as Figure 1 shown in

[0163] The storage unit 620 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 6201 and / or a cache storage unit 6202, and may further include a read-only storage unit (ROM) 6203.

[0164] The storage unit 620 may further include a program / utilities 6204 having a set (at least one) of program modules 6205. Such program modules 6205 include but are not limited to: an operating system, one or more application programs, other program modules, and program data. The implementation of a network environment may be included in each or some combination of these examples.

[0165] The bus 630 can represent one or more of several types of bus structures, including a memory unit bus or a memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of the various bus structures.

[0166] The electronic device 600 can also communicate with one or more external devices 700 (such as a keyboard, a pointing device, a Bluetooth device, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 600, and / or communicate with any device that enables the electronic device 600 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 650. Moreover, the electronic device 600 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 660. The network adapter 660 can communicate with other modules of the electronic device 600 through the bus 630. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 600, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0167] In the said electronic device, when the program in the memory is executed by the processor, the steps of the abnormal root cause location method described in the foregoing embodiments are implemented. Therefore, the said electronic device can also obtain the technical effects of the foregoing abnormal root cause location method.

[0168] According to some embodiments, on the other hand, the present application provides a computer-readable storage medium for storing a program, and when the program is executed by a processor, the steps of the abnormal root cause location method described in the foregoing embodiments are implemented. In some possible implementation manners, various aspects of the present application can also be implemented in the form of a program product, which includes program code, and when the program product is executed on a terminal device, the program code is used to cause the terminal device to execute the steps according to various exemplary embodiments of the present application described in the above abnormal root cause location method part of this specification.

[0169] Reference Figure 11 As shown, a program product 800 for implementing the above method according to an embodiment of the present application is described. It can adopt a portable compact disc read-only memory (CD-ROM) and include program code, and can be executed on a terminal device, such as a personal computer. However, the program product of the present application is not limited thereto. In this document, the readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device.

[0170] The program product may employ any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0171] The computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable storage medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0172] The program code for performing the operations of this application may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user computing device, partially on the user device, as a stand-alone software package, partially on the user computing device and partially on a remote computing device, or entirely on the remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., through the Internet using an Internet service provider).

[0173] When the program in the computer storage medium is executed by the processor, the steps of the above-mentioned abnormal root cause location method are implemented. Therefore, the computer storage medium can also achieve the technical effects of the above-mentioned abnormal root cause location method.

[0174] In the description of this specification, the descriptions referring to terms such as "some embodiments", "as an example", "exemplarily", etc. mean that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic descriptions of the above terms do not necessarily refer to the same embodiment or example.

[0175] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features of the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as within the scope described in this specification.

[0176] The above-described embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.

Claims

1. A method for locating an abnormality root cause, characterized in that: include: Acquire original behavior data, and perform statistics on the original behavior data according to data structured features to obtain continuous time series statistical data; Classifying the time series statistical data, wherein the time series statistical data is divided into at least a first type, a second type, and a third type; According to the type of the time series statistical data, a matching anomaly threshold calculation method, an anomaly detection method and a baseline value prediction method are selected respectively; Using the abnormal threshold calculation method to obtain the abnormal threshold of the time series statistical data, and using the abnormality detection method to perform abnormality detection on the data points in the time series statistical data based on the abnormal threshold; For the abnormal points obtained by abnormal detection, the benchmark value prediction method is used to perform benchmark value prediction to obtain indicator prediction data; Identify the influencing elements of each dimension from the indicator prediction data to form a cross-dimensional combination set; construct a contribution function to obtain the contribution of each subset in the cross-dimensional combination set to the total indicator mutation, and determine the root cause of the abnormality based on the contribution of each subset.

2. The abnormality root cause location method according to claim 1, characterized in that: The data structured feature includes at least one of a time period, a holiday identifier, and a drill-down dimension.

3. The abnormality root cause location method according to claim 1, characterized in that: The classifying the time series statistical data includes: Performing a stationarity test on the time series statistical data, if the time series statistical data is detected to be stationary, the time series statistical data is classified as a first type; If the time series statistical data is measured to be non-stationary, a periodicity detection is performed on the time series statistical data. If the time series statistical data is measured to be periodic, the time series statistical data is classified as the second type, otherwise the time series statistical data is classified as the third type.

4. The abnormality root cause location method according to claim 1, characterized in that: The method of obtaining the abnormal threshold of the time series statistical data by using the abnormal threshold calculation method includes: For the time series statistical data of the second type, at least a periodic component, a seasonal component and a predetermined time interval component are removed from the corresponding original behavior data, and the abnormal threshold is calculated; For the third type of the time series statistical data, directly calculate and determine whether the time series statistical data is skewed, and select the matching abnormal threshold calculation method according to the determination result to calculate the abnormal threshold; For the time series statistical data of the first type, at least the predetermined time interval component is removed from the corresponding original behavior data, and an abnormal threshold is calculated.

5. The abnormality root cause location method according to claim 1, characterized in that: The using the anomaly detection method to perform anomaly detection on the data points in the time series statistical data based on the anomaly threshold comprises: For the time series statistical data of the first type, anomaly detection is performed using a global detection algorithm; For the time series statistical data of the second type, decomposing the time series statistical data to obtain residual components, and using the global detection algorithm to perform anomaly detection based on the residual components; For the time series statistical data of the third type, a local detection algorithm is used to perform anomaly detection.

6. The abnormality root cause location method according to claim 1, characterized in that: Determining the root cause of the abnormality according to the contribution of each subset includes: The subset with the largest contribution is selected as the root cause of the anomaly.

7. The abnormality root cause location method according to any one of claims 1 to 6, characterized in that: The abnormal root cause locating method further includes: Providing simulated abnormal data, and using the simulated abnormal data as original behavior data to determine the abnormal root cause; Use preset evaluation indicators to evaluate the abnormal root cause location results.

8. The abnormality root cause location method according to claim 7, characterized in that: The step of determining the root cause of the abnormality is repeated until a preset number of experiments is reached.

9. An abnormality root cause location system, characterized in that: The system for implementing the abnormality root cause location method according to any one of claims 1 to 8 comprises: A data preprocessing module is configured to obtain original behavior data, and perform statistics on the original behavior data according to data structured features to obtain continuous time series statistical data; A time series data classification module, configured to classify the time series statistical data, wherein the time series statistical data is divided into at least a first type, a second type and a third type; A matching module, configured to select a matching anomaly threshold calculation method, anomaly detection method, and reference value prediction method according to the type of the time series statistical data; an abnormality threshold calculation and abnormality detection module, configured to obtain the abnormality threshold of the time series statistical data by using the abnormality threshold calculation method, and perform abnormality detection on the data points in the time series statistical data based on the abnormality threshold by using the abnormality detection method; An indicator prediction module is configured to perform a baseline value prediction on an abnormal point obtained by anomaly detection using the baseline value prediction method to obtain indicator prediction data; The root cause location module is configured to identify the influencing elements of each dimension from the indicator prediction data to form a cross-dimensional combination set; construct a contribution function to obtain the contribution of each subset in the cross-dimensional combination set to the total indicator mutation, and determine the abnormal root cause according to the contribution of each subset.

10. An electronic device, characterized in that: include: processor; a memory storing executable instructions of the processor; The processor is configured to execute the steps of the abnormality root cause locating method according to any one of claims 1 to 8 by executing the executable instructions.

11. A computer-readable storage medium for storing a program, characterized in that: When the program is executed by a processor, the steps of the abnormality root cause locating method described in any one of claims 1 to 8 are implemented.

Citation Information

Cited By

  • Service index anomaly attribution method, device, equipment and medium

    CN121327375A

  • Program error tracing method, electronic equipment, storage medium and program product

    CN121412024A

  • Intelligent operation and maintenance anomaly detection method, system and equipment

    CN121659148A