Multi-scale time sequence abnormal segment detection method and system based on knowledge perception
By constructing a time series knowledge graph and using a multi-scale Transformer model, combining the relationship graph attention network and gated recursive unit, the problem of knowledge information and multi-scale modes in the multi-variable time series are solved, and more efficient and flexible anomaly detection is achieved.
Patent Information
- Application Number
- CN202510230094.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-05-30
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing multivariate time series anomaly detection methods fail to effectively utilize the knowledge and complex multi-scale time patterns in the time series, resulting in insufficient detection accuracy and adaptability.
A multi-scale time series anomaly segment detection method based on knowledge perception is proposed. By acquiring and preprocessing the multi-variable time series, decomposing it into trend components and seasonal components, building a time series knowledge graph, using a relational graph attention network and gated recursive unit to capture the time dynamic characteristics of the trend components, and using a multi-scale Transformer to capture the multi-scale mode of seasonal components, generating anomaly scores for detection.
It significantly improves the accuracy and adaptability of abnormal detection, reduces the probability of false alarms and missed alarms, can effectively process complex and periodic data, and has wide application value.
Smart Images

Figure CN120067949A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data mining, and more specifically, to a method and system for detecting abnormal segments of multi-scale time series based on knowledge perception. Background Art
[0002] The detection of abnormal segments in multivariate time series has important research value in the field of data mining and has wide applications in fields such as industrial monitoring, financial analysis, intelligent manufacturing, and network security. Most of the existing anomaly detection methods rely on the self-learning ability of data, but often ignore the rich knowledge information and complex time patterns related to multivariate time series. The knowledge information in multivariate time series (such as production and sales information of different products) can provide a more comprehensive reference for anomaly detection. However, most current methods fail to effectively utilize this knowledge information, thereby reducing the accuracy of detection.
[0003] In addition, multivariate time series usually exhibit complex time patterns, including different periodic patterns such as daily, weekly, monthly, etc. and aperiodic patterns. Traditional methods often only focus on single-scale or fixed-period patterns and cannot effectively adapt to the diversity of time patterns. This makes it difficult to distinguish normal periodic fluctuations from real anomalies, especially when facing complex time series data. Therefore, how to develop an anomaly detection method that can combine the knowledge information of time series and multi-scale time patterns has become a technical problem to be solved in this field. Summary of the Invention
[0004] In order to solve the above technical problems, the present invention proposes a method and system for detecting abnormal segments of multi-scale time series based on knowledge perception. For the problem of detecting abnormal segments in multivariate time series data, the knowledge information and multi-scale periodic patterns in multivariate time series data are combined to improve the detection accuracy and adaptability of abnormal segments.
[0005] The present invention provides a method for detecting abnormal segments of multi-scale time series based on knowledge perception, including the following steps:
[0006] Obtain the multivariate time series of an enterprise and perform preprocessing, divide the multivariate time series into multiple time periods and generate binary labels to identify whether each time period is abnormal, and generate training data and test data for parameter training;
[0007] Decompose the multivariate time series into a trend component and a seasonal component, construct a time series knowledge graph, and based on the time series knowledge graph, use a relational graph attention network and a gated recurrent unit to construct the time dynamic characteristics of the trend component and obtain the predicted value of the trend component;
[0008] Decompose the seasonal component of a multivariate time series into univariate series and segment them into patches. Use a multi-scale Transformer to capture various patterns of the seasonal component, extract the pattern features of the seasonal component, and obtain the predicted values of the seasonal component;
[0009] Calculate the predicted values of the trend component and the deviation between the predicted and actual observed values of the seasonal component to generate an anomaly score. If the anomaly score exceeds a preset threshold, mark the corresponding time period as an anomaly.
[0010] In this solution, obtain the multivariate time series of an enterprise and perform preprocessing, specifically:
[0011] Obtain the multivariate time series of the enterprise as the input data X for multivariate time series segment detection t ={x 1 ,…,x t}, where t represents the length of the multivariate time series. Divide the input multivariate time series to generate several detection time series segments Z t+1 ={x t+1 ,…,x t+τ}, where τ represents the size of the time period;
[0012] Perform anomaly detection on the multivariate time series based on historical time step data. Predict the expected values in future time steps through historical data, compare the actual observed values in the multivariate time series with the expected values, and obtain the anomaly score of the time period Z t+1 Generate a binary label for each time period according to the anomaly score where indicates that this time period is an abnormal segment;
[0013] Select normal segments as training data according to the binary label, and use abnormal segments containing anomalies as test data.
[0014] In this solution, decompose the multivariate time series into a trend component and a seasonal component, specifically:
[0015] Use a moving average pooling operation to smooth the multivariate time series to obtain the trend component. The calculation formula is:
[0016]
[0017] where, represents the trend component, AvgPool represents performing a moving average pooling operation on the multivariate time series X t Padding(X t ) represents padding the multivariate time series;
[0018] The seasonal component is obtained by removing the trend component from the multivariate time series, and the calculation formula for the seasonal component is:
[0019]
[0020] where represents the seasonal component.
[0021] In this solution, a time series knowledge graph is constructed. Based on the time series knowledge graph, a relational graph attention network and a gated recurrent unit are used to construct the temporal dynamic characteristics of the trend component, and the predicted value of the trend component is obtained. Specifically:
[0022] Entity and relationship extraction are performed on the multivariate time series through knowledge extraction to obtain a set of entities and a set of relationships between entities. The set of entities includes time series entities and other knowledge entities. The extracted entities and relationships are represented in the form of triples, and a sequence-oriented time series knowledge graph is constructed according to the triples;
[0023] Channel independence processing is performed on the trend component of the multivariate time series, which is decomposed into several univariate time series. For time series entities, the trend components of each time series at different time steps are characterized, and the attribute features of non-time series entities are extracted based on the relevant triples to obtain a set of node feature vectors;
[0024] Based on the time series knowledge graph, a relational graph attention network is introduced. The set of node feature vectors is used as the input of the relational graph attention network to capture the high-order correlation relationships between different trend components and generate a feature matrix;
[0025] The feature matrix is imported into the gated recurrent unit. The gated recurrent unit is used to further capture the temporal dependence of the trend component. The temporal dynamic characteristics of the trend component are constructed by gradually updating the hidden state matrix, and the predicted value of the trend component is calculated through a fully connected layer for the obtained hidden state matrix.
[0026] In this solution, the seasonal component of the multivariate time series is decomposed into univariate sequences and segmented into patches. A multi-scale Transformer is used to capture each pattern of the seasonal component, extract the pattern features of the seasonal component, and obtain the predicted value of the seasonal component. Specifically:
[0027] Channel independence operation is performed on the seasonal component of the multivariate time series, which is decomposed into multiple univariate time series. Each univariate time series is segmented into overlapping or non-overlapping patches and input into the multi-scale Transformer encoder;
[0028] Map the patches to the feature space of the multi-scale Transformer encoder, add positional encoding to each patch, and capture the pattern features of different seasonal components through the multi-head self-attention mechanism, where each attention head has a different observation range to identify the multi-scale features in the seasonal components;
[0029] Calculate the predicted value of the seasonal component from the pattern features through a flattening layer and a linear transformation layer.
[0030] In this solution, calculate the deviation between the predicted values of the trend component and the seasonal component and the actual observed values to generate an anomaly score, specifically:
[0031] For each time period of the multivariate time series, generate the corresponding predicted value of the trend component and the predicted value of the seasonal component, compare the predicted values of the trend component and the seasonal component with the observed values respectively to obtain the anomaly score of the trend component and the anomaly score of the seasonal component;
[0032] Sum the anomaly score of the trend component and the anomaly score of the seasonal component to obtain the total anomaly score. If the total anomaly score exceeds the preset threshold, mark the corresponding time period as an anomaly.
[0033] In this solution, during the model training process, define the total loss function by combining the mean square error losses of the trend component and the seasonal component, specifically;
[0034] Use the training data and test data for model training. During the model training process, define the mean square error loss functions of the trend component module and the seasonal component, combine the two mean square error loss functions, and define the total loss function;
[0035] Guide the model training by minimizing the total loss function, iteratively update the model parameters, and use the test data to test the detection results in each iteration. If the detection performance meets the preset standard, retain the model parameters and output the multi-scale time series anomaly segment detection framework.
[0036] The second aspect of the present invention provides a knowledge-aware multi-scale time series anomaly segment detection system, which includes: an enterprise data acquisition module, a time series decomposition module, a knowledge-aware trend component module, a multi-scale seasonal component module, an anomaly segment prediction module, and a prediction result output module;
[0037] The enterprise data acquisition module is responsible for collecting and preprocessing enterprise multivariate time series data;
[0038] The time series decomposition module is responsible for decomposing the collected multivariate time series into a trend component and a seasonal component;
[0039] The knowledge-aware trend component module is responsible for regarding the trend component of each time series entity as its attribute feature, constructing a triple set containing the relationship between the time series entity and the knowledge entity to form a time series knowledge graph, using a relational graph attention network to capture the trend relationship between time series with similar knowledge information, adopting a gated recurrent unit to capture the temporal dependence within the time series, and generating the predicted value of the trend component through a fully connected layer;
[0040] The multi-scale seasonal component module is responsible for decomposing the seasonal component of the multivariate time series into univariate series and transforming them into fragmented patches for input into the multi-scale Transformer. Through trainable linear projection and positional encoding, the patches are mapped into the feature space of the multi-scale Transformer to capture different seasonal pattern features, and the predicted value of the seasonal component is generated through a linear layer;
[0041] The anomaly segment prediction module is responsible for calculating the deviation between the predicted trend and seasonal components and the actual observed values to generate an anomaly score. If it exceeds the threshold, it is marked as an anomaly, and the threshold is optimized through grid search to improve the detection accuracy, recall rate, and F1 score;
[0042] The prediction result output module is responsible for outputting the anomaly segments in the enterprise's multivariate time series data.
[0043] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0044] The present invention constructs a knowledge graph of time series through a knowledge-aware trend module, which can effectively integrate rich knowledge information in multivariate time series, such as associated information on product production, sales, etc. This module not only captures the trend relationship between different time series but also can identify the behavioral characteristics of each time series in different situations. Therefore, knowledge-aware trend modeling provides a more contextually understanding perspective for anomaly detection, significantly improving the accuracy of anomaly detection and reducing the probability of false positives and false negatives.
[0045] The present invention decomposes the time series into different seasonal components through a multi-scale seasonal component module and uses a multi-scale transformation model to capture various periodic patterns, such as daily, weekly, monthly, etc. This module performs segment-level modeling on the input seasonal components, enabling the system to adapt to pattern changes at different frequencies and different time scales, enhancing the adaptability of the detection system when dealing with complex, periodic data. This multi-scale modeling not only improves the robustness of anomaly detection but also makes the model more easily applicable to a variety of actual scenarios, having broad application value. Brief Description of the Drawings
[0046] To more clearly illustrate the technical solutions in the embodiments or exemplary examples of the present invention, the following will briefly introduce the drawings required for use in the description of the embodiments or exemplary examples. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to these drawings shown.
[0047] Figure 1 shows a flowchart of a knowledge-aware multi-scale time series anomaly segment detection method;
[0048] Figure 2 shows an execution flowchart of a model framework for enterprise multi-dimensional time series anomaly segment detection;
[0049] Figure 3 shows a block diagram of a knowledge-aware multi-scale time series anomaly segment detection system. Specific embodiments
[0050] In order to better understand the above-mentioned objects, features and advantages of the present invention, the following further describes the present invention in detail in conjunction with the drawings and specific embodiments. It should be noted that, without conflict, the embodiments of the present application and the features in the embodiments can be combined with each other.
[0051] Many specific details are set forth in the following description in order to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Therefore, the protection scope of the present invention is not limited by the specific embodiments disclosed below.
[0052] Figure 1 shows a flowchart of a knowledge-aware multi-scale time series anomaly segment detection method.
[0053] Such as Figure 1 shown, in the first embodiment of the present invention, a knowledge-aware multi-scale time series anomaly segment detection method is provided, including:
[0054] S102, obtaining the multi-variable time series of the enterprise and performing preprocessing, dividing the multi-variable time series into multiple time periods and generating binary labels to identify whether each time period is abnormal, and generating training data and test data for parameter training;
[0055] S104, decomposing the multi-variable time series into a trend component and a seasonal component, constructing a time series knowledge graph, and based on the time series knowledge graph, using a relational graph attention network and a gated recurrent unit to construct the time dynamic characteristics of the trend component, and obtaining the predicted value of the trend component;
[0056] S106. Decompose the seasonal component of the multivariate time series into univariate series and segment them into patches. Use the multi-scale Transformer to capture various patterns of the seasonal component, extract the pattern features of the seasonal component, and obtain the predicted values of the seasonal component.
[0057] S108. Calculate the predicted values of the trend component and the deviation between the predicted and actual observed values of the seasonal component to generate an anomaly score. If the anomaly score exceeds a preset threshold, mark the corresponding time period as an anomaly.
[0058] It should be noted that a multivariate time series of an enterprise is obtained, such as an enterprise sales data series. The enterprise sales data series includes multiple explanatory variables, such as advertising investment, promotional activities, seasonality, etc., and a response variable, such as sales. The obtained multivariate time series of the enterprise is used as the input data X for anomaly detection of multivariate time series segments t ={x 1 ,…,x t}}, where t represents the length of the multivariate time series. The input multivariate time series is divided to generate several detection time series segments Z t+1 ={x t+1 ,…,x t+τ}}, where τ represents the size of the time period. Anomaly detection of the multivariate time series is performed based on historical time step data, and the expected value in future time steps is predicted through historical data Compare the actual observed value in the multivariate time series with the expected value to obtain the anomaly score of the time period Z t+1 Generate a binary label for each time period according to the anomaly score where indicates that this time period is an abnormal segment. Considering the high data imbalance between normal segments and abnormal segments, select normal segments as training data according to the binary labels, and use the abnormal segments containing anomalies as test data. Use the training data and test data to train a model framework for detecting abnormal segments of multi-dimensional time series, which mainly includes six modules: data preprocessing module, time series decomposition module, knowledge-aware trend module, multi-scale seasonal component module, abnormal segment detection module, and joint optimization module. The execution flow block diagram of the model framework for detecting abnormal segments of enterprise multi-dimensional time series is as Figure 2 shown.
[0059] It should be noted that time series with similar knowledge information should exhibit similar trends during the corresponding time periods. At the same time, the diversity of time patterns is mainly reflected in the seasonal components of the time series. The time series decomposition module decomposes the multivariate time series into trend components and seasonal components to capture these potential patterns. The moving average pooling operation is used to smooth the multivariate time series to obtain the trend component, and the calculation formula is:
[0060]
[0061] where represents the trend component, AvgPool represents the moving average pooling operation on the multivariate time series X t and Padding(X t ) represents padding the multivariate time series;
[0062] In the multivariate time series, the seasonal component is obtained by removing the trend component, and the calculation formula for the seasonal component is:
[0063]
[0064] where represents the seasonal component.
[0065] By decomposing the multivariate time series into trend variables and seasonal variables, the trend components and seasonal components in the time series are clearly extracted, laying a data foundation for subsequent model construction and anomaly detection, helping to understand the internal structure of the time series, and also improving the detection ability for abnormal segments.
[0066] It should be noted that the trend component mainly focuses on modeling the relationships between multiple time series. The knowledge-aware trend module involves how to effectively utilize the extensive knowledge information related to the multivariate time series in order to model the complex relationships between different time series. Entity and relationship extraction are performed in the multivariate time series through knowledge extraction. For example, taking the chickens of a poultry company as an example, the knowledge graph contains the time series entity "chickens", as well as relevant knowledge entities that are not time series, such as sales regions, sales companies, grades of chickens, etc. Obtain the set of entities and the set of relationships between entities. The set of entities contains time series entities and other knowledge entities. The extracted entities and relationships are represented in the form of triples, and an entity-oriented time series knowledge graph is constructed according to the triples. Define the time series knowledge graph as e h ,e t ∈ε,r∈Ω}, where: represents the set of entities, is the time series entity, For other knowledge entities; Ω represents the set of relationships between entities; the triple (e h , r, e t ) represents the observation that there is a relationship r from the head entity e h to the tail entity e t .
[0067] The trend component of the multivariate time series R m×t represents the real number space of size m×t, where m represents the number of features of the multivariate time series and t represents the time stamp. Channel independence processing is performed and decomposed into m univariate time series For time series entities, the trend components of the i-th time series at different time steps t are characterized, and the attribute features of non-time series entities are extracted based on relevant triples for modeling to obtain a set of node feature vectors, where the trend components are modeled as their attribute features, denoted as
[0068] For the non-time series entity h, the set of its single-hop triples is denoted as:
[0069]
[0070] where {e 1 , e 2 …, e j} is the set of head entities of the tail entity h. Select from the set of triples whose head entities are time series triples as Therefore, the attribute features of the h-th non-time series entity are:
[0071]
[0072] where l is the number of triples in
[0073] The set of node feature vectors obtained in the time series knowledge graph is denoted as:
[0074]
[0075] where represents the number of all entities in the time series knowledge graph
[0076] When modeling the trend components, focus on the relationships between time series with similar knowledge information. To this end, a relational graph attention network is used to effectively capture the connections between these trend components. The input of the relational graph attention network is the set of node feature vectors representing the multivariate time series, that is The output is a new set of node feature vectors, denoted as where d represents the entity dimension, and the node feature vectors capture time series information with similar knowledge information. For entity i in the time series knowledge graph, the triple (e h , r, i) is converted to (i, r -1 , e h ), such that entity i always serves as the head entity of adjacent triples. This means that aggregating the neighbor entity information of entity i only requires aggregating from the tail entity to the head entity.
[0077] For relation k, the output in entity i calculated by the relational graph attention layer is denoted as:
[0078]
[0079] where σ is a non-linear activation function, α ij is the attention score contributed by entity j to entity i, j is one of the neighbor entities of node i in relation k, N k is the number of neighbor nodes of node i in relation k, is the parameter for performing node-sharing linear transformation for each node.
[0080] The attention score α ij is calculated by the following formula:
[0081]
[0082] where a T represents transpose, is the concatenation operation, and is the weight vector, and u ij represents the attention coefficient of entity j to entity i;
[0083] The output representation of entity i after aggregating different relations k is as follows:
[0084]
[0085] where β ik is a learnable parameter indicating the importance of relation k to entity i, and N is the number of relations of node i. Finally, the output feature matrix of all entities is constructed as follows:
[0086]
[0087] Import the feature matrix into a gated recurrent unit, use the gated recurrent unit to further capture the time dependence of the trend component, construct the time dynamics of the trend component by gradually updating the hidden state matrix, and calculate the predicted value of the trend component through a fully connected layer. Let represent the hidden state matrix at time step t-1, and given the input at time step t the reset gate at time step t and the candidate state matrix are calculated as follows:
[0088]
[0089] where and are weight matrices, is a bias vector.
[0090] Based on the hidden state matrix H at time step t-1 t-1 and the input at time step t , the update of the gate is calculated as:
[0091]
[0092] where and are weight matrices, is a bias vector.
[0093] Therefore, the hidden state matrix H at time step t t can be calculated as:
[0094]
[0095] Finally, based on the hidden state matrix H t , the prediction result at time step t can be calculated through a fully connected layer as follows:
[0096]
[0097] where is a weight matrix, is a bias vector, and τ is the prediction time length.
[0098] Through the above process, the knowledge dependence learning and time dependence learning of the trend component are effectively utilized, aiming to improve the detection ability of abnormal segments of multivariate time series.
[0099] It should be noted that in the multi-scale seasonal component module, the seasonal component of the multivariate time series Perform channel independence operation, decompose it into m univariate time series, and for each univariate time series Partition it into overlapping or non - overlapping patches and input them into the multi - scale Transformer encoder; set the patch length to τ and the stride to S, then the number of patches is Each patch is represented as: Using patch input can convert the time series into a segment form, thus enhancing the model's memory ability and enabling it to focus more on anomaly detection within the patches. At the same time, such processing reduces the input length from t to approximately t / S, thereby reducing memory usage and computational complexity.
[0100] To handle various patterns that may exist in the seasonal component, use a trainable linear projection Map the patches to the feature space of the multi - scale Transformer encoder and add positional encoding to each patch The patch input after projection and positional encoding Is represented as:
[0101]
[0102] Capture different pattern features of the seasonal component through the multi - head self - attention mechanism, where each attention head has a different observation range to identify multi - scale features in the seasonal component; given an input patch sequence of length M, control the sequence range that each attention head can observe, set as the parameter γ. For each attention head i and position j, the calculation formula is:
[0103]
[0104] Among them, Represents the function of extracting the context at a given position, specifically:
[0105]
[0106] Next, define the calculation methods of query Q, key K, and value V:
[0107]
[0108] Among them, W Q 、W K And W V Are learnable parameter matrices.
[0109] For N' attention heads, the multi - scale Transformer with scales Θ = [γ 1 ,…,γ N′ can be represented as:
[0110]
[0111] where W O is the output parameter matrix. Different from the traditional multi-head self-attention mechanism, the variable Θ controls the observation range of each head, enabling different heads to capture different pattern features of the seasonal component.
[0112] Through a flattening operation with a linear output layer, the predicted value of the seasonal component is obtained
[0113]
[0114] Through this design of the multi-scale Transformer, the seasonal component of the multivariate time series can be effectively processed, and the complex patterns therein can be captured, thus achieving more accurate anomaly detection and prediction.
[0115] For each time period Z t+1 , the KMogram model generates two inference results: the predicted value of the trend component, denoted as: the predicted value of the seasonal component, denoted as:
[0116] It should be noted that in the anomaly segment detection module, for each time period of the multivariate time series, the predicted value of the corresponding trend component and the predicted value of the seasonal component are generated, and the predicted values of the trend component and the seasonal component are respectively compared with the observed values. The actual observed value of the trend component is denoted as The actual observed value of the seasonal component is denoted as The anomaly score of the trend component and the anomaly score of the seasonal component are obtained; the anomaly score of the trend component is calculated as:
[0117]
[0118] where represents the L2 norm, which is used to measure the deviation between the predicted value of the trend component and the actual observed value .
[0119] The anomaly score of the seasonal component is calculated as:
[0120]
[0121] where respectively represent the predicted value and the actual observed value of the seasonal component.
[0122] Sum the anomaly scores of the trend component and the anomaly scores of the seasonal component to obtain the total anomaly score If the total anomaly score exceeds a preset threshold, mark the corresponding time period as an anomaly. Grid search is applied to all possible anomaly thresholds to determine the theoretically optimal precision, recall, and F1 score, and then report them
[0123] It should be noted that during the training process of the model framework for multi-scale time series anomaly segment detection, the mean square error loss of the trend component and the seasonal component is combined to define the total loss function. In the model framework for multi-scale time series anomaly segment detection, it consists of the following two key modules: Knowledge-aware trend component module: This module is responsible for predicting the trend values of each timestamp within the time period Z t+1 For each timestamp within the period, it can effectively capture the trend characteristics of the data by making full use of historical knowledge and data patterns. Multi-scale seasonal component module: This module focuses on predicting the seasonal values of each timestamp within the time period Z t+1 By using a multi-scale method to capture seasonal features, it ensures the sensitivity of the model to different seasonal patterns. The joint optimization module defines the mean square error (MSE) loss functions of the two modules, respectively, to evaluate the prediction accuracy of the trend component and the seasonal component
[0124] Loss function of the knowledge-aware trend component module Is defined as:
[0125]
[0126] Where: Is the number of samples, Is the actual trend value, Is the trend value predicted by the model, τ is the predicted time step; this loss function calculates the difference between the trend value predicted by the model and the actual trend value, sums and averages after squaring to reflect the overall prediction error;
[0127] Loss function of the multi-scale seasonal component module Is defined as:
[0128]
[0129] Where: Is the actual seasonal value, Is the seasonal value predicted by the model; this loss function also calculates the seasonal prediction error of the model and evaluates the model performance in the form of mean square error
[0130] To optimize the predictions of both the trend component and the seasonal component simultaneously, the two loss functions are combined and defined as the total loss function
[0131] Use the training data and test data for model training. During the model training process, define the mean squared error loss functions for the trend component module and the seasonal component, combine the two mean squared error loss functions, and define the total loss function. Guide the model training by minimizing the total loss function, iteratively update the model parameters to ensure that the model simultaneously improves the prediction capabilities for the trend component and the seasonal component, thereby achieving higher accuracy and recall rates in the anomaly detection task. Use the test data to test the detection results in each iteration. If the detection performance meets the preset criteria, retain the model parameters and output the multi-scale time series anomaly segment detection framework.
[0132] Figure 3 The block diagram of the knowledge-aware multi-scale time series anomaly segment detection system is shown.
[0133] The second embodiment of the present invention provides a knowledge-aware multi-scale time series anomaly segment detection system 3, which includes: an enterprise data collection module 301, a time series decomposition module 302, a knowledge-aware trend component module 303, a multi-scale seasonal component module 304, an anomaly segment prediction module 305, and a prediction result output module 306;
[0134] The enterprise data collection module 301 is responsible for collecting and preprocessing enterprise multivariate time series data;
[0135] The time series decomposition module 302 is responsible for decomposing the collected multivariate time series into a trend component and a seasonal component;
[0136] The knowledge-aware trend component module 303 is responsible for regarding the trend component of each time series entity as its attribute feature, constructing a triple set containing the relationship between the time series entity and the knowledge entity to form a time series knowledge graph, using a relational graph attention network to capture the trend relationship between time series with similar knowledge information, adopting a gated recurrent unit to capture the temporal dependence within the time series, and generating the predicted value of the trend component through a fully connected layer;
[0137] The multi-scale seasonal component module 304 is responsible for decomposing the seasonal component of the multivariate time series into univariate sequences and transforming them into fragmented patches to be input into the multi-scale Transformer. Through trainable linear projection and positional encoding, map the patches into the feature space of the multi-scale Transformer to capture different seasonal pattern features, and generate the predicted value of the seasonal component through a linear layer;
[0138] The anomaly segment prediction module 305 is responsible for calculating the deviation between the predicted trend and seasonal components and the actual observed values to generate an anomaly score, marking it as an anomaly if it exceeds the threshold, and optimizing the threshold through grid search to improve the detection accuracy, recall rate, and F1 score;
[0139] The prediction result output module 306 is responsible for outputting the abnormal segments in the enterprise multi-variable time series data.
[0140] In several embodiments provided in the present application, it should be understood that the disclosed method can be implemented in other ways. The system embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the displayed or discussed components can be through some interfaces, and the indirect coupling or communication connection of devices or modules can be electrical, mechanical, or other forms. In addition, in each embodiment of the present invention, each functional module can be fully integrated in a processing module, or each module can be separately used as a module, or two or more modules can be integrated in a module; the above integrated modules can be implemented in the form of hardware, or in the form of a combination of hardware and software functional modules.
[0141] If the above integrated module of the present invention is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in the various embodiments of the present invention. The foregoing storage medium includes: various media such as removable storage devices, ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0142] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention.
Claims
1. A multi-scale time series abnormal segment detection method based on knowledge perception, characterized in that: The following steps are involved: Obtaining and preprocessing the multivariate time series of the enterprise, dividing the multivariate time series into multiple time periods and generating binary labels to identify whether each time period is abnormal, generating training data and test data for parameter training; Decomposing a multivariate time series into a trend component and a seasonal component, constructing a time series knowledge graph, constructing the temporal dynamic characteristics of the trend component using a relational graph attention network and a gated recursive unit based on the time series knowledge graph, and obtaining a predicted value of the trend component; The seasonal components of the multivariate time series are decomposed into univariate sequences and segmented into patches. The multiscale Transformer is used to capture the various patterns of the seasonal components, extract the pattern features of the seasonal components, and obtain the predicted values of the seasonal components. The deviation between the predicted value of the trend component and the predicted value of the seasonal component and the actual observed value is calculated to generate an anomaly score. If the anomaly score exceeds a preset threshold, the corresponding time period is marked as abnormal.
2. The method for detecting abnormal segments of multi-scale time series based on knowledge perception according to claim 1 is characterized in that: Obtain the multivariate time series of the enterprise and perform preprocessing, specifically: Get the multivariate time series of the enterprise as the input data X for multivariate time series segment detection t ={x1,…,x t }, where t represents the length of the multivariate time series, the input multivariate time series is divided to generate several detection time series segments Z t+1 ={x t+1 ,…,x t+τ }, where τ represents the size of the time period; Based on the data of historical time steps, the anomaly detection of the multivariate time series is performed, the expected value in the future time step is predicted by the historical data, the actual observed value in the multivariate time series is compared with the expected value, and the time period Z is obtained. t+1 Anomaly score, generating a binary label for each time period based on the anomaly score in Indicates that this time period is an abnormal period; Normal segments are selected as training data according to the binary labels, and abnormal segments containing abnormalities are selected as test data.
3. The method for detecting abnormal segments of multi-scale time series based on knowledge perception according to claim 1 is characterized in that: Decompose the multivariate time series into trend and seasonal components as follows: Use the moving average pooling operation to smooth the multivariate time series and obtain the trend component. The calculation formula is: in, represents the trend component, AvgPool represents the multivariate time series X t Perform moving average pooling operation, Padding(X t ) indicates filling of multivariate time series; In the multivariate time series, the seasonal component is obtained by removing the trend component. The calculation formula of the seasonal component is: in, Indicates seasonal component.
4. The method for detecting abnormal segments of multi-scale time series based on knowledge perception according to claim 1 is characterized in that: Construct a time series knowledge graph, and use a relational graph attention network and a gated recursive unit based on the time series knowledge graph to construct the temporal dynamic characteristics of the trend component and obtain the predicted value of the trend component, specifically: Entities and relationships are extracted in a multivariate time series through knowledge extraction to obtain a set of entities and a set of relationships between entities, wherein the entity set includes time series entities and other knowledge entities, the extracted entities and relationships are represented in the form of triples, and a sequence-oriented time series knowledge graph is constructed based on the triples; The trend component of the multivariate time series is processed for channel independence and decomposed into several univariate time series. For the time series entities, the trend components of each time series at different time steps are characterized, and the attribute features of the non-time series entities are extracted based on the relevant triples to obtain the node feature vector set. Based on the time series knowledge graph, a relationship graph attention network is introduced, and the node feature vector set is used as the input of the relationship graph attention network to capture the high-order correlation relationship between different trend components and generate a feature matrix; The feature matrix is imported into a gated recursive unit, and the gated recursive unit is used to further capture the time dependency of the trend component. The time dynamic characteristics of the trend component are constructed by gradually updating the hidden state matrix, and the predicted value of the trend component is calculated by using the acquired hidden state matrix through a fully connected layer.
5. The method for detecting abnormal segments of multi-scale time series based on knowledge perception according to claim 1 is characterized in that: The seasonal components of the multivariate time series are decomposed into univariate sequences and split into patches. The multiscale Transformer is used to capture the various patterns of the seasonal components, extract the pattern features of the seasonal components, and obtain the predicted values of the seasonal components. Specifically: Perform channel independence operations on the seasonal components of the multivariate time series and decompose them into multiple univariate time series. Each univariate time series is split into overlapping or non-overlapping patches and input into a multi-scale Transformer encoder. Map the patches to the feature space of a multi-scale Transformer encoder, add position encoding to each patch, and capture the different pattern features of seasonal components through a multi-head self-attention mechanism, where each attention head has a different observation range and identifies multi-scale features in seasonal components; The pattern features are passed through a flattening layer and a linear transformation layer to calculate the predicted value of the seasonal component.
6. The method for detecting abnormal segments of multi-scale time series based on knowledge perception according to claim 1 is characterized in that: Calculate the deviation between the predicted value of the trend component and the predicted value of the seasonal component and the actual observed value to generate anomaly scores, specifically: For each time period of the multivariate time series, the corresponding trend component forecast value and seasonal component forecast value are generated, and the forecast values of the trend component and seasonal component are compared with the observed values to obtain the anomaly score of the trend component and the anomaly score of the seasonal component; The anomaly score of the trend component and the anomaly score of the season component are summed to obtain a total anomaly score. If the total anomaly score exceeds a preset threshold, the corresponding time period is marked as abnormal.
7. The method for detecting abnormal segments of multi-scale time series based on knowledge perception according to claim 2 is characterized in that: During the model training process, the total loss function is defined by combining the mean square error loss of the trend component and the seasonal component, specifically: Use training data and test data to train the model. During the model training process, define the mean square error loss function of the trend component module and the seasonal component, combine the two mean square error loss functions, and define the total loss function; The model training is guided by minimizing the total loss function, and the model parameters are iteratively updated. The detection results are tested using test data in each iteration. If the detection performance meets the preset standards, the model parameters are retained to output the multi-scale time series anomaly segment detection framework.
8. A multi-scale time series abnormal segment detection system based on knowledge perception, characterized in that: Used to implement the knowledge-aware multi-scale time series abnormal segment detection method according to any one of claims 1 to 7, the system comprises: an enterprise data acquisition module, a time series decomposition module, a knowledge-aware trend component module, a multi-scale seasonal component module, an abnormal segment prediction module and a prediction result output module; The enterprise data collection module is responsible for collecting and preprocessing enterprise multivariate time series data; The time series decomposition module is responsible for decomposing the collected multivariate time series into trend components and seasonal components; The knowledge-aware trend component module is responsible for treating the trend component of each time series entity as its attribute feature, constructing a set of triples containing the relationship between the time series entity and the knowledge entity, forming a time series knowledge graph, using the relationship graph attention network to capture the trend relationship between time series with similar knowledge information, using the gated recursive unit to capture the time dependency within the time series, and generating the predicted value of the trend component through the fully connected layer; The multi-scale seasonal component module is responsible for decomposing the seasonal components of the multivariate time series into univariate sequences and converting them into fragmented patches that are input into the multi-scale Transformer. Through trainable linear projection and position encoding, the patches are mapped to the feature space of the multi-scale Transformer to capture different seasonal pattern features, and the predicted values of the seasonal components are generated through the linear layer. The abnormal segment prediction module is responsible for calculating the deviation between the predicted trend and seasonal components and the actual observed values to generate an abnormal score. If the deviation exceeds the threshold, it is marked as abnormal, and the threshold is optimized through grid search to improve the detection accuracy, recall rate and F1 score; The prediction result output module is responsible for outputting abnormal segments in the enterprise multivariate time series data.
Citation Information
Cited By
Industrial control anomaly detection method and system based on dual-path noise adjustment
CN121523311A