A Work Order Abnormal Information Detection Method Based on LOF Algorithm

By considering the processing time and priority of work orders in the LOF algorithm, filtering relevant data points and adjusting the reachable distance, the misjudgment problem in work order abnormal detection is solved, and more accurate abnormal detection is achieved.

CN120067844BActive Publication Date: 2025-07-29青岛他坦科技服务有限公司 +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510559011.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-07-29
Estimated Expiration
2045-04-30

AI Technical Summary

Technical Problem

In the work ticket abnormal detection, the existing LOF algorithm has not been considered due to the uneven distribution of data points density and the difference in priority, resulting in misjudgment of abnormal points, affecting the detection accuracy.

Method used

By obtaining the processing time and priority data of the work order, filtering relevant data points, adjusting the reachable distance and local reachable density according to the priority, and calculating the LOF value to identify abnormal work orders.

Benefits of technology

It improves the accuracy of work order abnormal detection, can focus more on work orders of similar importance, refine judgments, and reduce misjudgment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120067844B_ABST
    Figure CN120067844B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of electronic digital data processing, and discloses a method for detecting abnormal information of work orders based on the LOF algorithm, as follows: Obtain a number of work orders including processing duration and priority; Use the processing duration as basic data to obtain a set of data points for all work orders; Screen the data points within the k-distance neighborhood range of the data point set to obtain relevant data points; Screen the relevant data points according to the priority to obtain key data points; Screen the data points within the k-distance neighborhood range of the key data points to obtain target data points, and determine the reachable distance of each key data point in combination with the distances among the key data points and the current data point; Determine the priority level importance coefficient of the key data points according to the priority, and update and adjust the reachable distance of each key data point. Obtain the local reachable density of the current data point according to the updated reachable distance; Calculate the LOF value of the current data point in this way, and thus determine the abnormal work orders.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of electronic digital data processing, and particularly relates to a method for detecting work order exception information based on the LOF algorithm. Background Art

[0002] A work order is a written or electronic carrier of work instructions, which details information such as the work tasks to be completed, relevant requirements, performers, time limits, etc., in order to arrange, track, and manage the work process to ensure that all tasks can be completed accurately and in a timely manner.

[0003] The LOF algorithm is a density-based unsupervised anomaly detection method that identifies anomaly points by calculating the local density deviation between data points and their neighbors, and is widely used in the field of anomaly detection. When using the LOF algorithm for work order anomaly detection, due to the possible uneven density distribution of data points, a fixed k value is difficult to adapt to work orders with different priorities; moreover, the calculation of the reachable distance in the algorithm is also based on a fixed neighborhood, without considering the priority differences between data points, which may lead to misjudgment of data points, such as misjudging anomaly points in high-density areas as normal points, or misjudging normal points in low-density areas as anomaly points; and the importance and potential impacts of different work orders are different, resulting in errors in the judgment of anomaly work orders and affecting the accuracy of work order anomaly information detection. Therefore, it is necessary to adjust the relevant parameters in the algorithm according to the priorities of different data points. Summary of the Invention

[0004] The present invention provides a method for detecting work order anomaly information based on the LOF algorithm to overcome the deficiencies and defects of the above prior art.

[0005] To solve the above technical problems, the technical solution adopted by the present invention is:

[0006] A method for detecting work order anomaly information based on the LOF algorithm, the method includes the following steps:

[0007] Obtain a number of work orders, and the data of each work order includes processing duration and priority;

[0008] Take the processing duration in each work order as the basic data to obtain a set of data points for all work orders;

[0009] Screen the data points within the k-distance neighborhood range of the data point set to obtain relevant data points;

[0010] Screen the relevant data points according to the priority to obtain key data points;

[0011] Screen the data points within the k-distance neighborhood of the key data point k to obtain the target data points, and determine the reachable distance of each key data point by combining the distances among the key data point, the current data point, and the target data points;

[0012] Determine the importance coefficient of the priority level of the key data point according to the priority of the key data point, and update and adjust the reachable distance of each key data point according to the importance coefficient of the priority level;

[0013] Obtain the local reachable density of the current data point according to the updated reachable distances of all key data points;

[0014] Calculate the LOF value of the current data point according to the local reachable density of the current data point, and determine the abnormal work orders based on this;

[0015] Preferably, screen the data points within the k-distance neighborhood of the data point set to obtain the relevant data points, including:

[0016] Confirm the initial k-nearest neighbor distance of each data point in the data point set;

[0017] Take the range with each data point as the center and the k-nearest neighbor distance as the radius as the k-distance neighborhood of each data point;

[0018] Screen according to the k-distance neighborhood of each data point and determine all data points included in the k-distance neighborhood;

[0019] Record all data points included in the k-distance neighborhood as relevant data points.

[0020] Preferably, screen the relevant data points according to the priority to obtain the key data points, including:

[0021] According to the actual situation of the business to which the work order belongs, determine a priority difference range with reference to the priority of the current data point;

[0022] Traverse all relevant data points of the current data point and calculate the priority difference between each relevant data point and the current data point;

[0023] Screen out the relevant data points within the priority difference range and record them as key data points.

[0024] Preferably, screen the data points within the k-distance neighborhood of the key data point to obtain the target data points, including:

[0025] For each key data point, take the range with each key data point as the center and the determined k-nearest neighbor distance as the radius as the k-distance neighborhood of each key data point;

[0026] Filter according to the k-distance neighborhood of each data point, determine all data points included in the k-distance neighborhood, and denote them as target data points.

[0027] Furthermore, determine the reachable distance of each key data point in combination with the distances among the key data points, the current data point, including

[0028] Calculate the distance between each key data point and each target data point;

[0029] Take the average value of the distances between each key data point and all its target data points as the new k-nearest distance of this key data point;

[0030] Compare the new k-nearest distance of each key data point with the distance between each key data point and the current data, and take the larger value of the two as the reachable distance of each key data point to the current data point; thus obtain the reachable distance of each key data point.

[0031] Preferably, determine the importance coefficient of the priority level of the key data point according to the priority of the key data point, including:

[0032] Judge whether the priorities of each key data point and other key data points are the same; when the priority levels of two key data points are the same, assign the similarity coefficient of the priority level of each key data point as the first priority level similarity coefficient; when the priority levels of two key data points are different, then assign the similarity coefficient of the priority level of each key data point as the second priority level similarity coefficient; the first priority level similarity coefficient is greater than the second priority level similarity coefficient;

[0033] According to the similarity coefficient of the priority level between each key data point and other key data points, calculate the average value of the similarity coefficients of the priority level between each key data point and all key data points, and take it as the importance coefficient of the priority level of each key data point.

[0034] Furthermore, update and adjust the reachable distance of each key data point according to the importance coefficient of the priority level, including:

[0035] Determine the priority formation reason sequence according to the reason for the priority of the work order corresponding to each key data point;

[0036] Determine the importance coefficient of the priority formation reason of each key data point according to the priority formation reason sequence of each key data point;

[0037] Calculate the importance coefficient of each key data point according to the importance coefficient of the priority formation reason and the importance coefficient of the priority level of each key data point;

[0038] Update and adjust the reachable distance of each key data point according to the importance coefficient of the key data point to obtain the updated reachable distance.

[0039] Furthermore, determining the importance coefficient of the priority level of the key data point according to the priority of the key data point further includes:

[0040] For another key data point with the same priority level as each key data point, determine the number of formation reasons included in the intersection and union of the formation reason sequences of the two priorities, and adjust the importance coefficient of the priority level of each key data point accordingly.

[0041] Preferably, determining the importance coefficient of the formation reason of the priority of each key data point according to the formation reason sequence of the priority of each key data point further includes:

[0042] Classify the formation reasons of the priorities of all key data points according to the reasons to obtain the importance sequence of the formation reasons of each key data point, and count the number of all reasons and the number of important reasons in the importance sequence of the formation reasons of each key data point;

[0043] Sort the importance sequences of the formation reasons of all work orders in chronological order according to the creation time of each work order;

[0044] Centered on a certain work order, judge the reasons and their quantities that exist simultaneously in all the importance sequences of the formation reasons within a preset number of time points before and after it, sort the quantities of the reasons that exist simultaneously from large to small, and record the top two reasons with the largest quantities as high-frequency reasons, and determine the quantity of the high-frequency reasons;

[0045] Determine the number of all reasons in the formation reason sequence of each key data point;

[0046] Calculate the importance coefficient of the formation reason of the priority of each key data point according to the number of all reasons in the importance sequence of the formation reason, the number of important reasons in the importance sequence of the formation reason, the number of high-frequency reasons, and the number of all reasons in the formation reason sequence.

[0047] Preferably, calculate the LOF value of the current data point according to the local reachable density of the current data point, and determine the abnormal work order based on this, including

[0048] Calculate the LOF value of the current data point according to the local reachable density of the current data point;

[0049] Compare the LOF value of the current data point with a preset first threshold. If the LOF value of the current data point is greater than the preset first threshold, then the current data point is regarded as an abnormal data point, and the corresponding work order is an abnormal work order; otherwise, the current data point is a normal data point.

[0050] Compared with the prior art, the beneficial effects of the present invention are:

[0051] The present invention screens the data points within the k-distance neighborhood range of the data point set to obtain relevant data points; screens the relevant data points according to the priority to obtain key data points; screens the data points within the k-distance neighborhood range of the key data points to obtain target data points, and determines the reachable distance of each key data point by combining the distances among the key data points and the current data point; determines the importance coefficient of the priority level of the key data points according to the priority of the key data points, and updates and adjusts the reachable distance of each key data point according to the importance coefficient of the priority level. According to the updated reachable distances of all key data points, the local reachable density of the current data point is obtained; according to the local reachable density of the current data point, the LOF value of the current data point is calculated, and the abnormal work order is determined thereby.

[0052] The present invention screens the data points included within the k-neighborhood range according to the priority among different data points, which helps to focus more on the work orders similar to the current work order in terms of importance. At the same time, the reachable distance of each key data point is updated and adjusted according to the importance coefficient of the priority level, further refining the judgment of the work order similarity, which helps to more accurately identify the work orders with similar potential problems, thereby improving the accuracy of anomaly detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 is a flowchart of the steps of the work order anomaly information detection method based on the LOF algorithm according to the present invention;

[0054] Figure 2 is an example drawing of a work order provided by the present invention;

[0055] Figure 3 is an example of the data point set of all work orders of the present invention;

[0056] Figure 4 is an example of obtaining key data points of the present invention;

[0057] Figure 5 is a schematic block diagram of a computer device provided by the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0058] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention. The present invention will be described in detail below in conjunction with the drawings and specific embodiments.

[0059] It should be understood that when used in this specification, the terms "comprises" and "comprising" indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0060] It should also be understood that the terms used in this specification of the present invention are merely for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in this specification of the present invention, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to include the plural forms.

[0061] It should be further understood that the term " / and" as used in this specification of the present invention refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0062] As Figure 1 shown, a method for detecting work order exception information based on the LOF algorithm, the method includes the following steps:

[0063] Obtain a number of work orders, and the data of each work order includes processing duration and priority;

[0064] Take the processing duration in each work order as the basic data to obtain a set of data points for all work orders;

[0065] Screen the data points within the k-distance neighborhood range of the data point set to obtain relevant data points;

[0066] Screen the relevant data points according to the priority to obtain key data points;

[0067] Screen the data points within the k-distance neighborhood range of the key data points to obtain target data points, and determine the reachable distance of each key data point in combination with the distances among the key data point, the current data point;

[0068] Determine the priority level importance coefficient of the key data points according to the priority of the key data points, and update and adjust the reachable distance of each key data point according to the priority level importance coefficient;

[0069] The local reachability density of the current data point is obtained based on the reachable distance updated according to all key data points.

[0070] Based on the local reachability density of the current data point, the LOF value of the current data point is calculated, and the abnormal work orders are determined based on this.

[0071] According to the present invention, the data points included within the k-neighborhood range are screened according to the priority levels between different data points, which helps to focus more on the work orders that are similar to the current work order in terms of importance. At the same time, the reachable distance of each key data point is updated and adjusted according to the importance coefficient of the priority level, further refining the judgment of work order similarity, which helps to more accurately identify the work orders with similar potential problems, thereby improving the accuracy of anomaly detection.

[0072] In a specific embodiment, a number of work orders are obtained, and the data of each work order includes the processing duration and the priority.

[0073] Specifically, the work orders are collected from the enterprise's internal management systems, such as the customer support system, the operation and maintenance management system, or the project management system; the detailed information of the work orders is recorded in these systems, and the data of each work order includes the processing duration and the priority, and also includes the creation time, the processing status, the completion time, the problem description, the processing information, the current status, etc.

[0074] Most enterprises have their own work order management systems, and the work order-related data can be directly exported from the system; for example, by writing scripts or using the API interfaces provided by the system, the work order data is extracted to the local area or stored in the data warehouse regularly (such as daily or weekly), or the log analysis tool is used to parse and extract the log files to obtain the required work order data; the work orders listed in this embodiment are as Figure 2 shown.

[0075] The collected work order information needs to include but is not limited to the following key information:

[0076] Work order number: The unique identifier of each work order, which is used to track and manage the work order.

[0077] Creation time: Record the specific moment when the work order is created.

[0078] Completion time: The time when the work order is processed and completed. The processing duration of the work order can be calculated by combining the creation time.

[0079] Priority: Usually divided into different levels such as high, medium, and low, which reflects the importance and urgency of the work order and helps to distinguish the normal and abnormal situations of work orders with different priorities in the detection.

[0080] Problem description: A detailed description of the problem involved in the work order.

[0081] Processing information: including the personnel information for processing the work order, the solutions adopted for the problems in the work order, etc.;

[0082] Current status: such as to be processed, in processing, completed, closed, etc. The change of the status can reflect whether the work order processing process is normal.

[0083] In this embodiment, taking the processing duration of each work order as basic data, a data point set of all the collected work orders is obtained. As Figure 3 shown in the example, the processing durations of each work order are not completely the same. Horizontally represents the processing durations of different work orders, and vertically represents that there are multiple work orders with the same processing duration at this processing duration.

[0084] In a specific embodiment, the data points within the k-distance neighborhood range of the data point set are screened to obtain relevant data points, including:

[0085] Confirm the initial k-nearest neighbor distance of each data point in the data point set; In this embodiment, taking point 1 in the data point set as an example, the initial k-nearest neighbor distance of point 1 is determined to be 5.

[0086] Taking the range with each data point as the center and the k-nearest neighbor distance as the radius as the k-distance neighborhood of each data point; Taking point 1 as the center and the k-nearest neighbor distance as the radius, the range is the k-distance neighborhood of point 1. The k-nearest neighbor distance is used to determine the neighborhood range of each data point, and the k-distance neighborhood range can reflect the local density situation around the data point. A suitable k value can accurately reflect the local environmental characteristics where the data point is located.

[0087] Screen and determine all the data points included in the k-distance neighborhood according to the k-distance neighborhood of each data point; In this embodiment, according to the k-distance neighborhood of point 1, all the data points included in the k-distance neighborhood can be determined. When the k-nearest neighbor distance is 5, data points 2 - 11 are all within the k-distance neighborhood of point 1, and the data points included in the k-distance neighborhood are recorded as relevant data points.

[0088] Record all the data points included in the k-distance neighborhood as relevant data points.

[0089] When determining relevant data points through the above steps, all data points are treated equally, ignoring the importance differences between different data points. The importance, processing urgency, and potential impacts of different work order data are different. In work order anomaly detection, high-priority work orders may be more easily affected by abnormal situations, or rather, the anomaly of high-priority work orders is more worthy of attention. Therefore, according to the priorities of all the relevant data points determined by the above steps, the relevant data points are screened to exclude the interference of irrelevant or low-correlation information.

[0090] In a specific embodiment, relevant data points are screened according to priorities to obtain key data points, including:

[0091] According to the actual situation of the business to which the work order belongs, with reference to the priority of the current data point, a priority difference range is determined. For example, it is set that the priority difference range is that the difference does not exceed one level, the difference between "low" and "high" is two levels, and the differences between "low" and "medium", and "medium" and "high" are one level.

[0092] Traverse all relevant data points of the current data point, and calculate the priority difference between each relevant data point and the current data point;

[0093] Screen out the relevant data points within the priority difference range, and record them as key data points.

[0094] For example, represent the three priorities of "low", "medium", and "high" as A, B, and C respectively. When taking the 1st data point as the center, if its priority is A, then after screening its relevant data points, the obtained key data points are the 2nd, 3rd, 4th, 6th, 9th, 10th, and 11th data points. The priority differences between these data points and the priority of the 1st data point are within the set difference range, while the priority differences between other data points and the 1st data point are relatively large, so they are excluded, as Figure 4 shown in the example.

[0095] Through the above steps, in order to exclude the interference of irrelevant or low-correlation data points, the relevant data points included in the k-neighborhood range of the current data point are screened, which is equivalent to optimizing the k-distance. And the drawbacks of the reachable distances of each key data point are also related to the k-neighborhood distance, so it is also necessary to adjust the k-neighborhood distance of each key data point, specifically as follows:

[0096] Screen the data points within the k-distance neighborhood range of the key data points to obtain target data points, including:

[0097] For each key data point, according to the determined k-neighborhood distance, the range centered on each key data point with the k-neighborhood distance as the radius is used as the k-distance neighborhood of each key data point;

[0098] Screen according to the k-distance neighborhood of each data point and determine all the data points included in the k-distance neighborhood, and record them as target data points.

[0099] In this embodiment, after determining the target data points, the reachable distance of each key data point is determined in combination with the distances among the key data points and the current data point, including:

[0100] Calculate the distance between each key data point and each target data point;

[0101] The average value of the distances between each of the key data points and all of its target data points is used as the new k-nearest neighbor distance of the key data point.

[0102] Compare the new k-nearest neighbor distance of each of the key data points with the distance between each of the key data points and the current data point, and take the larger value of the two as the reachable distance from each of the key data points to the current data point; thus, the reachable distance of each key data point is obtained and denoted as d2.

[0103] In this embodiment, among the work order data, work orders with different priorities have different business importance and different degrees of impact on the business. High-priority work orders usually involve key business processes, major customer requirements, etc. Once an anomaly occurs, it may cause relatively serious consequences. The reasons for generating work orders with the same priority may also vary, and the importance of different generation reasons is also different; for example, work orders under different business modules may have the same priority due to the same problem.

[0104] When calculating the local reachability density of the current data point using the reachable distance, only the spatial distance between data points is considered, while the relevance of the priorities between data points is ignored, and work orders with different priorities may be distributed in different density regions.

[0105] Therefore, in this embodiment, by combining the similarity of priorities between data points, different weights are assigned to the reachable distances of different data points, so that when the LOF algorithm is used to detect work order anomalies, it can pay more attention to the potential associations between data points, adapt to the different density distributions of work orders with different priorities, and improve the accuracy of anomaly detection.

[0106] In a specific embodiment, determining the priority level importance coefficient of the key data point according to the priority of the key data point includes:

[0107] Judge whether the priorities of each key data point and other key data points are the same; when the priority levels of two key data points are the same, assign the priority level similarity coefficient of each key data point as the first priority level similarity coefficient, such as 1; when the priority levels of two key data points are different, then assign the priority level similarity coefficient of each key data point as the second priority level similarity coefficient, such as 0.5; the first priority level similarity coefficient is greater than the second priority level similarity coefficient;

[0108] According to the priority level similarity coefficient between each key data point and other key data points, calculate the mean value of the priority level similarity coefficients between each key data point and all key data points, and use it as the priority level importance coefficient of each key data point.

[0109] In this embodiment, the priority level importance coefficient of the $i$-th key data point is calculated The calculation formula is as follows:

[0110] ;

[0111] In the formula, represents the priority level similarity coefficient between the $i$-th key data point and the $q$-th key data point; represents the mean value of the priority level similarity coefficients between the $i$-th key data point and all key data points, where the larger the value of, the more similar the $i$-th key data point is to other key data points in terms of level, and a higher importance should be assigned to it; $z$ represents the number of all key data.

[0112] In a specific embodiment, the reachable distance of each key data point is updated and adjusted according to the priority level importance coefficient, including:

[0113] Determine the priority formation reason sequence according to the reason for the priority of the work order corresponding to each key data point.

[0114] Since work orders with different priorities have different formation reasons; for example, high-priority work orders may be due to network failures, system failures, permission management vulnerabilities, data leaks, time-limited service requests, special time requirements, key customer needs, etc.; medium-priority work orders may be due to performance degradation, local blockage of business processes, partial function failures, etc.; low-priority work orders may be due to interface display problems, minor error reports, etc.

[0115] For two data points with the same priority level, the reasons for their priorities are not necessarily the same, and there may not be only one reason for the priority of each work order.

[0116] Therefore, according to the reason for the priority of the work order corresponding to each data point, determine its formation reason sequence, and the formation reason sequences of data points with the same priority are not exactly the same.

[0117] For example, the priority of data point 1 is A, high priority, and its formation reason sequence may be {network failure, system failure, data leak, key customer need}.

[0118] The priority of data point 2 is also high priority, and its formation reason sequence may be {special time requirement, local blockage of business process}.

[0119] In this embodiment, it also includes:

[0120] For another key data point with the same priority level as each of the key data points, determine the number of formation reasons included in the intersection and union of the priority formation reason sequences of the two, denoted as m1 and m2 respectively; and adjust the importance coefficient of the priority level of each of the key data points accordingly.

[0121] Among them, The larger the value of, the more similar the formation reasons of the two are. Based on this, adjust the importance coefficient of the priority level of the i-th key data point.

[0122] The adjusted importance coefficient of the priority level can be expressed as:

[0123] ;

[0124] Among them, represents the number of key data points with the same priority level as the i-th key data point; and respectively represent the number of intersections and unions of the reasons in the formation reason sequences of the i-th key data point and the t-th key data point. The more data points with the same priority as the i-th data point, and the larger the intersection-union ratio of each, the more similar they are, which indicates that the importance coefficient of this data point is larger, that is, the larger the value of.

[0125] According to the priority formation reason sequence of each key data point, determine the importance coefficient of the priority formation reason of each key data point. In this embodiment, there may be more than one priority formation reason for each key data point, and the importance of different formation reasons will also vary; data points with the same priority may include formation reasons with different importance. Based on this, determine the importance coefficient of the priority formation reason of each key data point.

[0126] Calculate the importance coefficient of each key data point based on the importance coefficient of the priority formation reason and the importance coefficient of the priority level of each key data point;

[0127] Update and adjust the reachable distance of each key data point according to the importance coefficient of each key data point to obtain the updated reachable distance.

[0128] In this embodiment, according to the priority formation reason sequence of each key data point, determining the importance coefficient of the priority formation reason of each key data point further includes:

[0129] Classify the priority formation reasons of all key data points according to the reasons, obtain the formation reason importance sequence of each key data point, and count the number of all reasons and the number of important reasons in the formation reason importance sequence of each key data point.

[0130] In this embodiment, since there are multiple reasons for the formation of all key data points, they can be divided into several major categories; for example: network failures and system failures can be classified as reasons for the interruption of key business processes; permission management vulnerabilities and data leakage can be classified as reasons for major security types; time-limited service requests and special time requirements are urgent customer needs; key customer needs are important customer needs; performance degradation, partial blockage of business processes, and partial functional failures are generally affected business functions; interface display problems and minor errors are minor faults.

[0131] Different types of reasons have different importance. The importance of reasons such as interruption of critical business processes, major safety reasons, urgent customer needs, and important customers are usually higher; the importance of reasons such as the impact on general business functions is medium; and the importance of minor faults is lower.

[0132] The priority formation reasons of all key data points are classified according to the reasons, and the importance sequence of the formation reasons of each key data point is obtained, which is expressed as the cause type, for example:

[0133] The importance sequence of the causes of data point 1 can be expressed as {important cause, important cause, important cause, important cause}; the importance sequence of the causes of data point 2 can be expressed as {important cause, medium-important cause}.

[0134] Count the number of all causes in the importance sequence of the causes of formation of each key data point, as well as the number of important causes; thereby determine the number of times causes of different importance appear in the importance sequence of the causes of formation of each key data point; among them, the more times important causes appear and the greater their proportion, the greater the importance coefficient of the causes of formation of the data point.

[0135] The importance of different reasons is also affected by their frequency of occurrence. Some medium-importance or low-importance reasons may appear continuously within a certain period of time, or a large number of work orders caused by medium-importance or low-importance reasons may appear at the same time. At this time, the importance of these reasons is also relatively large.

[0136] According to the creation time of each work order, sort the importance sequence of the reasons for the formation of all work orders in chronological order;

[0137] Focusing on a work order, determine the number of concurrent causes in the cause importance sequence within a preset number of time points before and after it, sort the concurrent causes from largest to smallest, and record the top two causes with the largest number as high-frequency causes. Determine the number of high-frequency causes.

[0138] In this embodiment, the preset quantity is 5. Taking the i-th work order, that is, the i-th sequence of the importance of formation reasons as the center, judge the number of all sequences of the importance of formation reasons included within the first 5 and the last 5 time points, and the reasons and their quantities that coexist in the sequence of the importance of formation reasons of the i-th one. Sort the quantities of the coexisting reasons from largest to smallest, and record the top two reasons with the largest quantities as the high-frequency reasons.

[0139] For example, for the key data points 2, 3, 4, 6, 9, 10, 11 after screening, when taking the 9th key data point as the center, all data points are included within its first 5 and last 5 time points, that is, the sequences of the importance of formation reasons are included. Among these sequences, the coexisting reasons include performance degradation, interface display problems, partial function failures, data leakage, and customer importance. However, interface display problems appear in 10 of these sequences, and the reason of performance degradation appears in 8 sequences of the importance of formation reasons. Therefore, the two reasons of performance degradation and interface display problems are recorded as the high-frequency reasons.

[0140] Determine the quantity of all reasons in the sequence of formation reasons for each key data point;

[0141] According to the quantity of all reasons in the sequence of the importance of formation reasons, the quantity of important reasons in the sequence of the importance of formation reasons, the quantity of high-frequency reasons, and the quantity of all reasons in the sequence of formation reasons, calculate the importance coefficient of the priority formation reasons for each key data point.

[0142] The importance coefficient of the priority formation reasons calculated for each key data point in this embodiment can be expressed as:

[0143] ;

[0144] Among them, represents the importance coefficient of the priority formation reasons for the i-th key data point; represents the length of the sequence of the importance of formation reasons for the i-th key data point, that is, the quantity of all reasons included; represents the quantity of important reasons in the sequence of the importance of formation reasons; represents the quantity of all reasons in the sequence of formation reasons for the i-th key data point; represents the quantity of high-frequency reasons in the sequence of the importance of formation reasons; the larger the proportion of important reasons and high-frequency reasons, the larger the importance coefficient of its formation reasons.

[0145] In this embodiment, the importance coefficient of the cause and the importance coefficient of the priority level are formed according to the priority of each key data point, and the importance coefficient of each key data point is calculated. Specifically, the importance of each key data point is jointly determined by its priority and the cause of formation. Therefore, the importance coefficient of the i-th key data point can be expressed as: .

[0146] According to the importance coefficient of each key data point, the reachable distance of the key data point is updated and adjusted to obtain the updated reachable distance of the i-th key data point , specifically as follows: , represents the reachable distance of the i-th key data point.

[0147] According to the updated reachable distances of all key data points (data points 2, 3, 4, 6, 9, 10, 11), the local reachability density of the current data point (data point 1) is obtained.

[0148] In a specific embodiment, according to the local reachability density of the current data point, the LOF value of the current data point is calculated, and the abnormal work order is determined accordingly, including:

[0149] According to the local reachability density of the current data point, the LOF value of the current data point is calculated;

[0150] In this embodiment, the LOF value of each data point can be calculated in the same way; the larger the LOF value, the more likely the data point is an abnormal point.

[0151] The LOF value of the current data point is compared with a preset first threshold. If the LOF value of the current data point is greater than the preset first threshold, the current data point is regarded as an abnormal data point, and the corresponding work order is an abnormal work order; otherwise, the current data point is a normal data point.

[0152] In this embodiment, the preset first threshold can be set to 1.5, and the LOF value of each data point is compared with the preset first threshold; when the LOF value of the data point is greater than 1.5, it is regarded as an abnormal data point, and the corresponding work order is an abnormal work order.

[0153] The abnormal work order is further verified to determine the problems and severity thereof, and corresponding processing is performed.

[0154] Please refer to Figure 5 , Figure 5 which is a schematic block diagram of the computer device provided by the embodiment of the present invention. The computer device 500 is a server, and the server can be an independent server or a server cluster composed of multiple servers.

[0155] Refer to Figure 5 , the computer device 500 includes a processor 502, a memory, and a network interface 505 connected through a system bus 501. Among them, the memory may include a non-volatile storage medium 503 and an internal memory 504.

[0156] The non-volatile storage medium 503 can store an operating system 5031 and a computer program 5032. When the computer program 5032 is executed, it can cause the processor 502 to execute a work order anomaly information detection method based on the LOF algorithm.

[0157] The processor 502 is used to provide computing and control capabilities to support the operation of the entire computer device 500.

[0158] The internal memory 504 provides an environment for the operation of the computer program 5032 in the non-volatile storage medium 503. When the computer program 5032 is executed by the processor 502, it can cause the processor 502 to execute a work order anomaly information detection method based on the LOF algorithm.

[0159] The network interface 505 is used for network communication, such as providing the transmission of data information, etc. Those skilled in the art can understand that Figure 5 the structure shown in Figure 5 is only a block diagram of some structures related to the solution of the present invention, and does not constitute a limitation on the computer device 500 to which the solution of the present invention is applied. The specific computer device 500 may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0160] Among them, the processor 502 is used to run the computer program 5032 stored in the memory to implement the work order anomaly information detection method based on the LOF algorithm disclosed in the embodiments of the present invention.

[0161] Those skilled in the art can understand that Figure 5 the embodiments of the computer device shown in Figure 5 do not constitute a limitation on the specific composition of the computer device. In other embodiments, the computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements. For example, in some embodiments, the computer device may only include a memory and a processor. In such an embodiment, the structures and functions of the memory and the processor are the same as those in Figure 5 the embodiment shown in Figure 5 , and will not be elaborated here.

[0162] It should be understood that in the embodiments of the present invention, the processor 502 may be a central processing unit (CPU), and the processor 502 may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0163] In another embodiment of the present invention, a computer-readable storage medium is provided. The computer-readable storage medium may be a non-volatile computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the work order exception information detection method based on the LOF algorithm disclosed in the embodiments of the present invention.

[0164] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the present invention, rather than limitations on the implementation manners of the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for detecting abnormal information of work orders based on the LOF algorithm, characterized in that: The method includes the following steps: Obtain a number of work orders, and the data of each work order includes processing duration and priority; Take the processing duration in each work order as basic data to obtain a set of data points for all work orders; Screen the data points within the k-distance neighborhood range of the set of data points to obtain relevant data points; Screen the relevant data points according to the priority to obtain key data points; Screen the data points within the k-distance neighborhood range of the key data points to obtain target data points, and determine the reachable distance of each key data point by combining the distances among the key data points, the current data points; Determine the priority level importance coefficient of each key data point according to the priority of the key data point, and update and adjust the reachable distance of each key data point according to the priority level importance coefficient; Obtain the local reachable density of the current data point according to the updated reachable distances of all key data points; Calculate the LOF value of the current data point according to the local reachable density of the current data point, and determine the abnormal work order based on this; Among them, determining the priority level importance coefficient of the key data point according to the priority of the key data point includes: Judge whether the priorities of each key data point and other key data points are the same; when the priority levels of two key data points are the same, assign the similarity coefficient of the priority level of each key data point as the first priority level similarity coefficient; when the priority levels of two key data points are different, assign the similarity coefficient of the priority level of each key data point as the second priority level similarity coefficient; the first priority level similarity coefficient is greater than the second priority level similarity coefficient; Calculate the mean value of the similarity coefficients of the priority levels of each key data point and all key data points according to the similarity coefficients of the priority levels of each key data point and other key data points, and use it as the priority level importance coefficient of each key data point; Determine the priority formation reason sequence according to the reason for the priority of each work order corresponding to the key data point; For another key data point with the same priority level as each key data point, determine the number of formation reasons included in the intersection and union of the priority formation reason sequences of the two, and adjust the priority level importance coefficient of each key data point accordingly; And updating and adjusting the reachable distance of each key data point according to the priority level importance coefficient includes: Determine the priority formation reason importance coefficient of each key data point according to the priority formation reason sequence of each key data point, including: Classify the reasons for the priorities of all key data points according to the reasons, obtain the importance sequence of formation reasons for each key data point, and count the number of all reasons and the number of important reasons in the importance sequence of formation reasons for each key data point; Sort the importance sequences of formation reasons of all work orders in chronological order according to the creation time of each work order; Centered around a certain work order, judge the reasons that coexist in all the importance sequences of formation reasons within a preset number of time points before and after it, as well as their quantities. Sort the quantities of the coexisting reasons in descending order, and record the top two reasons with the largest quantities as high-frequency reasons, and determine the quantity of high-frequency reasons; determine the quantity of all reasons in the formation reason sequence of each key data point; Calculate the importance coefficient of the formation reasons with priority for each key data point based on the quantity of all reasons in the formation reason importance sequence, the quantity of important reasons in the formation reason importance sequence, the quantity of high-frequency reasons, and the quantity of all reasons in the formation reason sequence; Calculate the importance coefficient of each key data point based on the importance coefficient of the formation reasons with priority for each key data point and the importance coefficient of the priority level; Update and adjust the reachable distance of each key data point according to the importance coefficient of each key data point to obtain the updated reachable distance.

2. The method for detecting work order abnormal information based on the LOF algorithm according to claim 1, wherein: Screen the data points within the k-distance neighborhood range of the data point set to obtain relevant data points, including: Confirm the initial k-nearest distance of each data point in the data point set; Take the range with each data point as the center and the k-nearest distance as the radius as the k-distance neighborhood of each data point; Screen according to the k-distance neighborhood of each data point and determine all the data points included in the k-distance neighborhood; Record all the data points included in the k-distance neighborhood as relevant data points.

3. The work order abnormal information detection method based on the LOF algorithm according to claim 1, characterized in that: Screen the relevant data points according to the priority to obtain key data points, including: According to the actual situation of the business to which the work order belongs, determine a priority difference range with reference to the priority of the current data point; Traverse all the relevant data points of the current data point and calculate the priority difference between each relevant data point and the current data point; Screen out the relevant data points within the priority difference range and record them as key data points.

4. The method for detecting work order abnormal information based on the LOF algorithm according to claim 1, characterized in that: Screen the data points within the k-distance neighborhood range of the key data points to obtain target data points, including: For each key data point, take the range with each key data point as the center and the k-nearest distance as the radius as the k-distance neighborhood of each key data point according to the determined k-nearest distance; Screen according to the k-distance neighborhood of each data point and determine all the data points included in the k-distance neighborhood, and record them as target data points.

5. The method for detecting work order exception information based on the LOF algorithm according to claim 4, characterized in that: And determine the reachable distance of each key data point in combination with the distances among the key data point, the current data point, including: Calculate the distance between each key data point and each target data point; Take the average value of the distances between each key data point and all its target data points as the new k-nearest distance of this key data point; Compare the new k-nearest distance of each key data point with the distance between each key data point and the current data, and take the larger value of the two as the reachable distance of each key data point to the current data point; thus, the reachable distance of each key data point is obtained.

6. The method for detecting work order abnormal information based on the LOF algorithm according to claim 1, characterized in that: Calculate the LOF value of the current data point according to the local reachable density of the current data point, and determine the abnormal work order based on this, including: Calculate the LOF value of the current data point according to the local reachability density of the current data point; Compare the LOF value of the current data point with a preset first threshold. If the LOF value of the current data point is greater than the preset first threshold, then regard the current data point as an abnormal data point, and the corresponding work order is an abnormal work order; otherwise, the current data point is a normal data point.

Citation Information

Patent Citations

  • Feeder adaptive control method of traction power supply wide-area protection measurement and control system

    CN116231603A

  • Targeted short message reaching method based on dynamic position tracking and crowd density analysis

    CN119052736A