Abnormity detection method, device and equipment for multi-dimensional time series and medium
By combining the variational autoencoder and the interpolation diffusion model, the problem of multi-dimensional time series anomaly detection is solved, which achieves higher detection accuracy and scope of application, and enhances detection robustness.
Patent Information
- Application Number
- CN202510296913.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-05-30
AI Technical Summary
The existing multidimensional time series anomaly detection methods perform suboptimal in high-dimensional data, making it difficult to deal with a wide range of anomaly types in different fields, and due to the large number of abnormal samples and normal samples, unsupervised learning increases the difficulty.
Anomaly detection is performed using a combination of variational autoencoder and interpolation diffusion model. The specific steps include: reconstructing through a variational autoencoder, masking and interpolation using the interpolation diffusion model, combining the fusion results with the preset fusion mechanism, and training the neural network using the reconstruction error, and finally setting an abnormality detection threshold based on the training results for detection.
It improves the accuracy and scope of application of multidimensional time series anomaly detection, enhances the robustness of the detection process, and can more accurately model the time and interrelated dependencies in multidimensional data.
Smart Images

Figure CN120067951A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and particularly relates to an anomaly detection method, device, equipment and medium for multi-dimensional time series. Background Art
[0002] Anomaly detection is a key area in machine learning, and its goal is to identify those outliers that are significantly different from the normal patterns in the dataset. This technology plays an important role in many industries such as financial monitoring, industrial maintenance and medical diagnosis, such as identifying fraudulent transactions, predicting equipment failures and monitoring patient health conditions.
[0003] Existing methods perform anomaly detection by using common techniques such as distance-based and distribution-based. However, with the increase in the number of dimensions, leading to the curse of dimensionality, these techniques usually exhibit suboptimal performance. Moreover, some advanced anomaly detection methods perform well in specific scenarios, but they are often designed for a certain type of anomaly and are difficult to handle a wide range of anomaly types in different fields. In addition, due to the extremely large difference in the number between anomaly samples and normal samples, and the high cost of manually annotating anomaly data, most anomaly detection algorithms adopt unsupervised learning methods, which also increases a certain degree of difficulty.
[0004] As can be seen from the above, how to improve the accuracy and applicable range of multi-dimensional time series anomaly detection and enhance the robustness of the detection process is an issue to be solved in this field. Summary of the Invention
[0005] In view of this, the purpose of the present invention is to provide an anomaly detection method, device, equipment and medium for multi-dimensional time series, which can improve the accuracy and applicable range of multi-dimensional time series anomaly detection and enhance the robustness of the detection process. The specific solutions are as follows:
[0006] In a first aspect, the present application discloses an anomaly detection method for multi-dimensional time series, including:
[0007] Obtain a multi-dimensional time series, input the multi-dimensional time series into a variational autoencoder of an artificial neural network for reconstruction to output a reconstruction result;
[0008] Input the multi-dimensional time series into an imputation diffusion model for masked imputation to output an imputation result;
[0009] Use a preset fusion mechanism to fuse the reconstruction result and the imputation result, and use the difference between the fusion result and the multi-dimensional time series as a reconstruction error, and use the reconstruction error to train the artificial neural network to obtain a first training result; the preset fusion mechanism is a fusion mechanism that can be learned and optimized;
[0010] Train the variational autoencoder based on the first training result, and run the multi-dimensional time series to obtain a second training result;
[0011] Set an anomaly detection threshold based on the second training result, and use the trained variational autoencoder and the anomaly detection threshold to perform anomaly detection on the multi-dimensional time series to obtain an anomaly detection result.
[0012] Optionally, the step of inputting the multi-dimensional time series into the variational autoencoder of the artificial neural network for reconstruction to output a reconstruction result includes:
[0013] Construct an unsupervised artificial neural network based on the variational autoencoder and the decoder;
[0014] Input the multi-dimensional time series into the variational autoencoder in the artificial neural network, use the variational autoencoder to map the multi-dimensional time series to obtain latent variables, and use the decoder to map the latent variables to the input space to obtain a reconstruction result.
[0015] Optionally, before inputting the multi-dimensional time series into the imputation diffusion model for masked imputation, it further includes:
[0016] Construct a deep learning network for denoising and imputing time series based on the integration of the U-Net neural network model, the Transformer time transformer and spatial transformer, and the diffusion model; the deep learning network is the ImputationNet network;
[0017] Train the imputation diffusion model using the ImputationNet network.
[0018] Optionally, the step of inputting the multi-dimensional time series into the imputation diffusion model for masked imputation includes:
[0019] Input the multi-dimensional time series into the imputation diffusion model, use the raster masking strategy to mask the data in the multi-dimensional time series at equal intervals along the time dimension, introduce noise into the multi-dimensional time series, then gradually remove the noise, and calculate the masking value;
[0020] Use the masking value to generate missing values, calculate the imputation error, and use the imputation error as an anomaly detection signal to complete the masked imputation.
[0021] Optionally, the step of training the artificial neural network using the reconstruction error includes:
[0022] Construct a generative adversarial network; the generative adversarial network includes a generator network and a discriminator network;
[0023] With the minimization of the objective of the generator network and the maximization of the objective of the discriminator network as constraints, the artificial neural network is trained using the reconstruction error.
[0024] Optionally, setting the anomaly detection threshold based on the second training result, and using the trained variational autoencoder and the anomaly detection threshold to perform anomaly detection on the multi-dimensional time series to obtain an anomaly detection result, including:
[0025] Setting the anomaly detection threshold based on the proportion of abnormal data in the second training result;
[0026] Using the adversarially trained variational autoencoder to perform anomaly detection on the multi-dimensional time series to calculate the anomaly detection score;
[0027] Selecting the target anomaly detection scores greater than the anomaly detection threshold from the anomaly detection scores to obtain the anomaly detection result.
[0028] In a second aspect, the present application discloses an anomaly detection device for multi-dimensional time series, including:
[0029] A reconstruction module, configured to obtain a multi-dimensional time series, input the multi-dimensional time series into a variational autoencoder of an artificial neural network for reconstruction, and output a reconstruction result;
[0030] A masking imputation module, configured to input the multi-dimensional time series into an imputation diffusion model for masking imputation, and output an imputation result;
[0031] A reconstruction error training module, configured to fuse the reconstruction result and the imputation result using a preset fusion mechanism, use the difference between the fusion result and the multi-dimensional time series as the reconstruction error, and train the artificial neural network using the reconstruction error to obtain a first training result; the preset fusion mechanism is a fusion mechanism capable of learning optimization;
[0032] An encoder training module, configured to train the variational autoencoder based on the first training result, and run the multi-dimensional time series to obtain a second training result;
[0033] An anomaly detection module, configured to set an anomaly detection threshold based on the second training result, and use the trained variational autoencoder and the anomaly detection threshold to perform anomaly detection on the multi-dimensional time series to obtain an anomaly detection result.
[0034] Optionally, the reconstruction module includes:
[0035] A neural network construction module, configured to construct an unsupervised artificial neural network based on a variational autoencoder and a decoder;
[0036] A mapping module, configured to input the multi-dimensional time series into a variational autoencoder in the artificial neural network, map the multi-dimensional time series by using the variational autoencoder to obtain latent variables, and map the latent variables to the input space by using the decoder to obtain a reconstruction result.
[0037] In a third aspect, the present application discloses an electronic device, including:
[0038] A memory, configured to store a computer program;
[0039] A processor, configured to execute the computer program to implement the foregoing anomaly detection method for multi-dimensional time series.
[0040] In a fourth aspect, the present application discloses a computer storage medium, configured to store a computer program; wherein, when the computer program is executed by a processor, the steps of the foregoing disclosed anomaly detection method for multi-dimensional time series are implemented.
[0041] It can be seen that the present application provides an anomaly detection method for multi-dimensional time series, including obtaining a multi-dimensional time series, inputting the multi-dimensional time series into a variational autoencoder of an artificial neural network for reconstruction to output a reconstruction result; inputting the multi-dimensional time series into an imputation diffusion model for masked imputation to output an imputation result; using a preset fusion mechanism to fuse the reconstruction result and the imputation result, and taking the difference between the fusion result and the multi-dimensional time series as a reconstruction error, and using the reconstruction error to train the artificial neural network to obtain a first training result; the preset fusion mechanism is a fusion mechanism capable of learning optimization; training the variational autoencoder based on the first training result, and running the multi-dimensional time series to obtain a second training result; setting an anomaly detection threshold based on the second training result, and using the trained variational autoencoder and the anomaly detection threshold to perform anomaly detection on the multi-dimensional time series to obtain an anomaly detection result. The present application introduces a variational autoencoder and combines it with the structure or method of an imputation diffusion model to process multi-dimensional time series, improving the accuracy and generalization ability of anomaly detection. Time series imputation uses adjacent values in the time series as additional conditional information, enabling more accurate modeling of the time and interrelated dependencies existing in multi-dimensional data. Taking the difference between the fusion result and the multi-dimensional time series as a reconstruction error, training the artificial neural network with the reconstruction error to obtain a first training result, then training the variational autoencoder, running the multi-dimensional time series to obtain a second training result, setting an anomaly detection threshold based on the second training result, and using the adversarial-trained variational autoencoder and the anomaly detection threshold to perform anomaly detection on the multi-dimensional time series to obtain an anomaly detection result, improving the accuracy and scope of application of multi-dimensional time series anomaly detection and enhancing the robustness of the detection process. Description of the Drawings
[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0043] Figure 1 Flowchart of an anomaly detection method for multi-dimensional time series disclosed in the present application;
[0044] Figure 2 Anomaly detection architecture and flowchart disclosed in the present application;
[0045] Figure 3 Flowchart of a grating masking strategy disclosed in the present application;
[0046] Figure 4 The system architecture diagram of an ImputationNet network disclosed in this application;
[0047] Figure 5 The detailed structure diagram of a residual block disclosed in this application;
[0048] Figure 6 The structural schematic diagram of an anomaly detection device for multi-dimensional time series disclosed in this application;
[0049] Figure 7 The structural diagram of an electronic device provided by this application. Specific embodiments
[0050] Next, in combination with the accompanying drawings in the embodiments of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0051] Anomaly detection is a key area in machine learning, whose goal is to identify those outliers that are significantly different from the normal patterns in the dataset. This technology plays an important role in many industries such as financial monitoring, industrial maintenance, and medical diagnosis, such as identifying fraudulent transactions, predicting equipment failures, and monitoring patient health conditions. Existing methods perform anomaly detection by using common techniques such as distance-based and distribution-based. However, with the increase in the number of dimensions, leading to the curse of dimensionality, these techniques usually exhibit suboptimal performance. Moreover, some advanced anomaly detection methods perform well in specific scenarios, but they are often designed specifically for a certain type of anomaly and are difficult to handle a wide range of anomaly types in different fields. In addition, due to the extremely large difference in the number between anomaly samples and normal samples, and the high cost of manually annotating anomaly data, most anomaly detection algorithms adopt unsupervised learning methods, which also increases a certain degree of difficulty. As can be seen from the above, how to improve the accuracy and scope of application of multi-dimensional time series anomaly detection and enhance the robustness of the detection process is an issue to be solved in this field.
[0052] See Figure 1 As shown, the embodiments of the present invention disclose an anomaly detection method for multi-dimensional time series, which may specifically include:
[0053] Step S11: Obtain a multi-dimensional time series, input the multi-dimensional time series into the variational autoencoder of an artificial neural network for reconstruction, and output a reconstruction result.
[0054] In this embodiment, an unsupervised artificial neural network is constructed based on a variational autoencoder and a decoder; the multi-dimensional time series is input into the variational autoencoder in the artificial neural network, and the variational autoencoder is used to map the multi-dimensional time series to obtain latent variables, and the decoder is used to map the latent variables to the input space to obtain a reconstruction result.
[0055] Specifically, the variational autoencoder in this application is an unsupervised artificial neural network that combines an encoder E and a decoder D. The encoder part obtains the input multi-dimensional time series X and maps it into a set of latent variables Z, while the decoder maps the latent variables Z back to the input space as the reconstruction result.
[0056] Step S12: Input the multi-dimensional time series into an imputation diffusion model for masked imputation to output an imputation result.
[0057] In this embodiment, a deep learning network for denoising and imputing time series is constructed by integrating a U-Net neural network model, a Transformer time transformer and a spatial transformer, and a diffusion model; the deep learning network is an ImputationNet network; the imputation diffusion model is trained using the ImputationNet network, the multi-dimensional time series is input into the imputation diffusion model, and the data in the multi-dimensional time series is masked at equal intervals along the time dimension using a raster masking strategy, and noise is introduced into the multi-dimensional time series, and then the noise is gradually removed, and the masked value is calculated; the masked value is used to generate missing values, the imputation error is calculated, and the imputation error is used as an anomaly detection signal to complete the masked imputation.
[0058] Specifically, the imputation diffusion model gradually introduces noise into the input multi-dimensional time series X, and then gradually removes the noise from the samples to learn to generate new samples to discover features that are difficult for the autoencoder to find.
[0059] The imputation diffusion model uses the prediction error generated by the imputation of intentionally masked values in the time series to infer anomaly labels. The masking matrix used in the masking process can be expressed as , where m = 1 indicates observed , while 0 indicates masking. The masking matrix M has the same dimension as the time series X, specifically . The application of the masking matrix M to the original time series X produces a new masked time series, denoted as , , where, represents the Hadamard product. Let denote the masked value, where , denotes the observed value, where , the goal of the interpolation process is to estimate the missing values in
[0060] The interpolation process is carried out in a self-supervised learning manner. Missing values to be interpolated can be generated by introducing masked values into the multi-dimensional time series, and the interpolation error is used as a signal for anomaly detection. This application designs an ImputationNet network specifically applied to the interpolation and subsequent anomaly detection tasks to train the interpolation diffusion model.
[0061] By using noise, even when the anomaly points are not masked, the true values can be avoided from being explicitly shown. The data with added noise can still provide indirect information about the unmasked data. By gradually eliminating the noise from the observed values, the unmasked data can be recovered. In this way, the gap between normal values and anomaly values can be increased when estimating the error, improving the anomaly detection performance.
[0062] This method adopts a raster masking strategy when masking the multi-dimensional time series. This strategy masks the data at equal intervals along the time dimension. The original time series is divided into multiple windows, and the masked and unmasked windows appear in an interleaved manner. The raster strategy applies two different masking strategies indexed by to the same time series, thus generating two interpolation instances. These two masked sequences are complementary, ensuring that the masked values in the masking index p = 0 are not masked in the masking index p = 1, and vice versa. This ensures that all data points are estimated by the interpolation diffusion model, enabling the generation of a prediction error signal for anomaly detection. The raster strategy provides additional information, which helps to model the time series more effectively and can better understand the potential patterns and correlations by combining partially reconstructed data. Moreover, the raster strategy allows for a partial glimpse of the future values of the time series within the masked window, providing in-depth understanding of the potential future trajectory of the time series data and improving the timeliness of anomaly detection.
[0063] The ImputationNet network contains four different groups of input data: (1) the input time series , (2) the masking embedding M encoding the masking group of the current data, (3) the dimension information L of the time embedding, (4) the dimension information K of the feature embedding. Each of these data groups is processed separately by convolutional or multiple linear layers to ensure consistent dimensions. Then, the input time series and the masking embedding are combined into a single tensor, and the corresponding time embedding and feature embedding are combined and further processed by the time transformer and spatial transformer layers designed based on the Transformer.
[0064] The time transformer plays a crucial role in capturing temporal correlations within a time series. It allows for dynamic weighting of feature values at different time steps and takes into account the masked state of features. The attention mechanism employed in the time transformer provides the necessary flexibility for this. Additionally, a spatial transformer is used to capture the interdependencies between different variables at each time step, and the spatial transformer allows for adaptive weighting and promotes interactions between variables.
[0065] Step S13: Use a preset fusion mechanism to fuse the reconstruction result and the imputation result, and take the difference between the fusion result and the multi-dimensional time series as the reconstruction error, and use the reconstruction error to train the artificial neural network to obtain a first training result; the preset fusion mechanism is a fusion mechanism capable of learning optimization.
[0066] In this embodiment, use a preset fusion mechanism to fuse the reconstruction result and the imputation result, and take the difference between the fusion result and the multi-dimensional time series as the reconstruction error, construct a generative adversarial network, with the goal minimization of the generator network and the goal maximization of the discriminator network as constraints, and use the reconstruction error to train the artificial neural network; the generative adversarial network includes a generator network and a discriminator network.
[0067] This application fuses the reconstruction result and the imputation result through a preset fusion mechanism, takes the difference between the fusion result and the multi-dimensional time series as the reconstruction error, and the goal of training the artificial neural network is to minimize this error to the greatest extent.
[0068] GAN (Generative Adversarial Networks) is an unsupervised artificial neural network based on a two-player minimax adversarial game between two networks trained simultaneously. GAN includes a generator network G designed to generate real data, while a second network acts as a discriminator D that attempts to distinguish real data from the data generated by G. The training goal of G is to maximize the probability that D makes a mistake, while the training goal of D is to minimize its classification error. That is, with the goal minimization of the generator network and the goal maximization of the discriminator network as constraints, and use the reconstruction error to train the artificial neural network.
[0069] This application uses a preset fusion mechanism to fuse the reconstruction result and the imputation result. Instead of simply summing the two parts of the result, this method designs a learnable fusion mechanism to combine the sum of the output results of these two layers as the final result:
[0070] ;
[0071] ;
[0072] ;
[0073] Among them, W and b are parameters of the linear structure. is the result of the interpolation diffusion model. is the result of reconstructing the input data X through the encoder and decoder 1. Similarly, when training decoder 2, replace in the above formula with , and the final result is .
[0074] Step S14: Train the variational autoencoder based on the first training result, and run the multi-dimensional time series to obtain the second training result.
[0075] In the adversarial training stage, the goal is to train to distinguish between real data and data from , and train to deceive . The data from is compressed into Z by the encoder again, and then reconstructed by . Using the adversarial training configuration, 's goal is to minimize the difference between X and the output of . 's goal is to maximize this difference. Train whether it successfully deceives , and will distinguish the data reconstructed by from the real data. The training goal of this stage is , where minimizes the difference between X and the reconstructed output of , while maximizes the difference between X and the reconstructed output of reconstructing X through . Summarize the specific training situation. 's loss function is:
[0076] ;
[0077] 's loss function is:
[0078] ;
[0079] Among them, n represents the training epoch.
[0080] Step S15: Set an anomaly detection threshold based on the second training result, and use the trained variational autoencoder and the anomaly detection threshold to perform anomaly detection on the multi-dimensional time series to obtain an anomaly detection result.
[0081] In this embodiment, the anomaly detection threshold is set based on the proportion of abnormal data in the second training result; the variational autoencoder after adversarial training is used to perform anomaly detection on the multi-dimensional time series to calculate an anomaly detection score; the target anomaly detection scores greater than the anomaly detection threshold are screened out from the anomaly detection scores to obtain an anomaly detection result.
[0082] This application sets an anomaly detection threshold to adapt to different scenarios and finally outputs an anomaly detection result. In the anomaly detection stage, the anomaly score is defined as:
[0083] ;
[0084] where , which is used to parameterize the trade-off between the false positive rate and the true positive rate. It can reduce the number of both true positives and false positives, which is a high detection sensitivity scenario. On the contrary will increase the number of both true positives and false positives, which is a low detection sensitivity scenario. This parameterization scheme is of great significance in practical applications because it allows using only a single trained model to obtain a set of anomaly detection results with different sensitivities during the inference process by adjusting the parameters, and then sorting the anomaly scores in the training set from small to large, and setting the threshold with reference to the proportion of abnormal data in the reference dataset. However, it may be difficult to consider the false positive rate and the true positive rate in practical applications. This method also considers another method of setting the sensitivity, setting both and to 0.5, and then not completely setting the threshold with reference to the proportion of abnormal data in the dataset, but multiplying a coefficient greater than 1 or less than 1 according to the sensitivity required by the application scenario.
[0085] Taking specific experimental data as an example, during the training process of the method proposed in this application, the structural parameters of the variational autoencoder training are set such that both the encoder and the decoder have three layers. The first layer of the encoder is the dimension size of the dataset, and the next two layers are set to be half of the previous layer. The decoder is the opposite. In the imputation diffusion model, the dimension of the time encoding information is 128, the spatial encoding information is 16, the embedding_dim of the Embedding layer is uniformly set to 128, and the channels of the convolutional layer are uniformly set to 64. The Batch Size is set to 32, and the Adam (Adam optimization algorithm) algorithm is selected to optimize the parameters of the model, and the learning rate is set to 0.0001. The anomaly score threshold is set according to the proportion of abnormal data in the dataset. In the experiment, 80% of the training set in the dataset is divided into the training set, and the remaining 20% is the validation set, and there is a dedicated test set in the dataset. The training will terminate when any of the following conditions is met: reaching the preset maximum number of iterations of 200 times; or during 20 consecutive iterations, the loss value of the validation set fails to decrease.
[0086] The comparison methods are as follows: OmniAn is an anomaly detection method that combines gated recurrent units and variational autoencoders to learn a robust representation of time series; InterFusion is an anomaly detection method that models normal patterns within multi-dimensional time series data through a hierarchical variational autoencoder with two random latent variables; ImDiffusion is an anomaly detection method that utilizes the unique inference process of the diffusion model for step-by-step denoising output; TranAD is an anomaly detection model based on a deep Transformer network; LSTM-AD is an anomaly detection method for time series by stacking long short-term memory networks; GNNAD is an anomaly detection method that combines graph neural networks and multi-variable time series data; AnTran is an anomaly detection method based on Transformer. The relevant comparison results are shown in Table 1:
[0087] Table 1
[0088]
[0089] This application is divided into three stages in the anomaly detection task. The architecture and the corresponding process are as Figure 2 shown. First, the imputation diffusion model gradually introduces noise and then gradually removes the noise from the samples to learn to generate new samples. Second, a variational autoencoder within a two-stage adversarial training framework is used. Then, a learnable fusion mechanism is used to combine several output results. Finally, the reconstruction error between the two parts of the output of the variational autoencoder and the original sample is used as the final anomaly score, and a sensitivity parameter is set to determine the anomaly score threshold, and the final anomaly detection result is judged according to the threshold.
[0090] The raster strategy masks data at equal intervals along the time dimension as Figure 3 shown. The original time series is divided into multiple windows, and masked and unmasked windows appear in an interleaved manner. The raster strategy generates two complementary imputation instances, ensuring that all data points are estimated by the imputation diffusion model, enabling the generation of a prediction error signal for anomaly detection. After imputation is performed separately on each masked sequence, the imputation results are combined by simple concatenation.
[0091] Using the hierarchical structure of the Transformer to capture the temporal correlations and data similarities between variables works well. For this purpose, this application introduces ImputationNet, a specialized architecture designed specifically for multi-dimensional time series imputation. The architecture of ImputationNet is as Figure 4 shown, which includes a series of stacked residual blocks, each of which contains dedicated components for separately processing the feature dimension and the time dimension. The detailed structure of the residual block is as Figure 5 shown.
[0092] To address the problems existing in existing anomaly detection algorithms, the present invention introduces a variational autoencoder and combines it with other structures or methods specifically for processing time series to improve the accuracy and generalization ability of anomaly detection. After training, the variational autoencoder can output reconstructed data with the characteristics of the input data. Some restrictions are imposed on the model during the encoding process, forcing the generated latent vectors to generally follow a certain distribution. Time series imputation utilizes adjacent values in the time series as additional conditional information, enabling more accurate modeling of the temporal and interrelated dependencies existing in multi-dimensional data. Moreover, the reference information from adjacent values helps reduce the uncertainty in prediction, thereby enhancing the robustness of the detection process. This application proposes using a variational autoencoder and a structural method specifically for processing time series to improve the accuracy and scope of application of anomaly detection.
[0093] In this embodiment, a multi-dimensional time series is obtained, and the multi-dimensional time series is input into the variational autoencoder of the artificial neural network for reconstruction to output a reconstruction result; the multi-dimensional time series is input into the imputation diffusion model for masked imputation to output an imputation result; a preset fusion mechanism is used to fuse the reconstruction result and the imputation result, and the difference between the fusion result and the multi-dimensional time series is used as a reconstruction error, and the artificial neural network is trained using the reconstruction error to obtain a first training result; the preset fusion mechanism is a fusion mechanism that can be optimized by learning; the variational autoencoder is trained based on the first training result, and the multi-dimensional time series is run to obtain a second training result; an anomaly detection threshold is set based on the second training result, and the multi-dimensional time series is detected for anomalies using the trained variational autoencoder and the anomaly detection threshold to obtain an anomaly detection result. In this application, a variational autoencoder is introduced and combined with the structure or method of the imputation diffusion model for processing multi-dimensional time series to improve the accuracy and generalization ability of anomaly detection. Time series imputation uses adjacent values in the time series as additional conditional information, so as to be able to more accurately model the time and interrelated dependencies existing in multi-dimensional data. The difference between the fusion result and the multi-dimensional time series is used as a reconstruction error, and the artificial neural network is trained using the reconstruction error to obtain a first training result. Then, the variational autoencoder is trained, and the multi-dimensional time series is run to obtain a second training result. An anomaly detection threshold is set based on the second training result, and the multi-dimensional time series is detected for anomalies using the adversarial-trained variational autoencoder and the anomaly detection threshold to obtain an anomaly detection result, improving the accuracy and scope of application of multi-dimensional time series anomaly detection and enhancing the robustness of the detection process.
[0094] See Figure 6 As shown, an embodiment of the present invention discloses an anomaly detection device for multi-dimensional time series, which may specifically include:
[0095] A reconstruction module 11, configured to obtain a multi-dimensional time series, input the multi-dimensional time series into a variational autoencoder of an artificial neural network for reconstruction, and output a reconstruction result;
[0096] A masked imputation module 12, configured to input the multi-dimensional time series into an imputation diffusion model for masked imputation, and output an imputation result;
[0097] A reconstruction error training module 13, configured to fuse the reconstruction result and the imputation result using a preset fusion mechanism, use the difference between the fusion result and the multi-dimensional time series as a reconstruction error, and train the artificial neural network using the reconstruction error to obtain a first training result; the preset fusion mechanism is a fusion mechanism that can be optimized by learning;
[0098] An encoder training module 14, configured to train the variational autoencoder based on the first training result and run the multi-dimensional time series to obtain a second training result;
[0099] An anomaly detection module 15, configured to set an anomaly detection threshold based on the second training result and perform anomaly detection on the multi-dimensional time series by using the trained variational autoencoder and the anomaly detection threshold to obtain an anomaly detection result.
[0100] In this embodiment, a multi-dimensional time series is obtained, and the multi-dimensional time series is input into a variational autoencoder of an artificial neural network for reconstruction to output a reconstruction result; the multi-dimensional time series is input into an imputation diffusion model for masked imputation to output an imputation result; the reconstruction result and the imputation result are fused by using a preset fusion mechanism, and the difference between the fusion result and the multi-dimensional time series is used as a reconstruction error, and the artificial neural network is trained by using the reconstruction error to obtain a first training result; the preset fusion mechanism is a fusion mechanism capable of learning and optimization; the variational autoencoder is trained based on the first training result, and the multi-dimensional time series is run to obtain a second training result; an anomaly detection threshold is set based on the second training result, and the multi-dimensional time series is subjected to anomaly detection by using the trained variational autoencoder and the anomaly detection threshold to obtain an anomaly detection result. This application introduces a variational autoencoder and combines it with the structure or method of an imputation diffusion model for processing multi-dimensional time series, improving the accuracy and generalization ability of anomaly detection. Time series imputation uses adjacent values in the time series as additional conditional information, enabling more accurate modeling of the time and interdependent dependencies existing in multi-dimensional data. The difference between the fusion result and the multi-dimensional time series is used as a reconstruction error, and the artificial neural network is trained by using the reconstruction error to obtain a first training result, then the variational autoencoder is trained, and the multi-dimensional time series is run to obtain a second training result. An anomaly detection threshold is set based on the second training result, and the multi-dimensional time series is subjected to anomaly detection by using the adversarially trained variational autoencoder and the anomaly detection threshold to obtain an anomaly detection result, improving the accuracy and scope of application of multi-dimensional time series anomaly detection and enhancing the robustness of the detection process.
[0101] In some specific embodiments, the reconstruction module 11 may specifically include:
[0102] A neural network construction module, configured to construct an unsupervised artificial neural network based on a variational autoencoder and a decoder;
[0103] A mapping module, configured to input the multi-dimensional time series into a variational autoencoder in the artificial neural network, and use the variational autoencoder to map the multi-dimensional time series to obtain latent variables, and use the decoder to map the latent variables to the input space to obtain a reconstruction result.
[0104] In some specific embodiments, the masking and imputation module 12 may specifically include:
[0105] A deep learning network construction module, configured to construct a deep learning network for denoising and imputing time series based on an integration of a U-Net neural network model, a Transformer time transformer and a spatial transformer, and a diffusion model; the deep learning network is an ImputationNet network;
[0106] A network training module, configured to train the imputation diffusion model by using the ImputationNet network.
[0107] In some specific embodiments, the masking and imputation module 12 may specifically include:
[0108] A masking module, configured to input the multi-dimensional time series into an imputation diffusion model, use a raster masking strategy to mask the data in the multi-dimensional time series at equal intervals along the time dimension, introduce noise into the multi-dimensional time series, then gradually remove the noise, and calculate a masking value;
[0109] An imputation module, configured to generate missing values by using the masking value, calculate an imputation error, and use the imputation error as an anomaly detection signal to complete masking and imputation.
[0110] In some specific embodiments, the reconstruction error training module 13 may specifically include:
[0111] A generative adversarial network construction module, configured to construct a generative adversarial network; the generative adversarial network includes a generator network and a discriminator network;
[0112] An artificial neural network training module, configured to use the minimization of the objective of the generator network and the maximization of the objective of the discriminator network as constraint conditions, and train the artificial neural network by using the reconstruction error.
[0113] In some specific embodiments, the anomaly detection module 15 may specifically include:
[0114] A threshold setting module, configured to set an anomaly detection threshold based on the proportion of abnormal data in the second training result;
[0115] An anomaly detection module, configured to perform anomaly detection on a multi-dimensional time series by using a variational autoencoder after adversarial training to calculate an anomaly detection score;
[0116] An anomaly detection result determination module, configured to screen out target anomaly detection scores greater than the anomaly detection threshold from the anomaly detection scores to obtain an anomaly detection result.
[0117] Figure 7 The figure is a schematic structural diagram of an electronic device provided by an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the anomaly detection method for multi-dimensional time series executed by the electronic device disclosed in any of the foregoing embodiments.
[0118] In this embodiment, the power supply 23 is used to provide operating voltages for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and specific limitations are not imposed here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and no specific limitations are made here.
[0119] In addition, as a carrier for resource storage, the memory 22 may be a read-only memory, a random access memory, a magnetic disk, or an optical disc, etc. The resources stored thereon include an operating system 221, a computer program 222, and data 223, etc., and the storage method may be temporary storage or permanent storage.
[0120] Among them, the operating system 221 is used to manage and control each hardware device on the electronic device 20 and the computer program 222 to implement the operation and processing of the data 223 in the memory 22 by the processor 21, and it may be Windows, Unix, Linux, etc. In addition to the computer program capable of implementing the anomaly detection method for multi-dimensional time series executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 may further include a computer program capable of performing other specific tasks. In addition to the data transmitted from external devices received by the anomaly detection device for multi-dimensional time series, the data 223 may also include data collected by its own input / output interface 25, etc.
[0121] The steps of the methods or algorithms described in combination with the embodiments disclosed in this article can be implemented directly by hardware, software modules executed by a processor, or a combination of both. The software module can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.
[0122] Furthermore, an embodiment of the present application also discloses a computer-readable storage medium. When a computer program stored in the storage medium is loaded and executed by a processor, it implements the steps of the anomaly detection method for multi-dimensional time series disclosed in any of the foregoing embodiments.
[0123] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.
[0124] The above has introduced in detail a method, device, equipment and storage medium for anomaly detection of multi-dimensional time series provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A method for detecting anomalies in multidimensional time series, characterized in that: include: Acquire a multidimensional time series, input the multidimensional time series into a variational autoencoder of an artificial neural network for reconstruction, and output a reconstruction result; Inputting the multidimensional time series into an interpolation diffusion model for masked interpolation to output an interpolation result; The reconstruction result and the interpolation result are fused by using a preset fusion mechanism, and the difference between the fusion result and the multidimensional time series is used as a reconstruction error, and the artificial neural network is trained by using the reconstruction error to obtain a first training result; The preset fusion mechanism is a fusion mechanism capable of learning optimization; Training the variational autoencoder based on the first training result, and running the multidimensional time series to obtain a second training result; An anomaly detection threshold is set based on the second training result, and anomaly detection is performed on the multidimensional time series using the trained variational autoencoder and the anomaly detection threshold to obtain an anomaly detection result.
2. The method for detecting anomalies in multidimensional time series according to claim 1, characterized in that: The step of inputting the multidimensional time series into a variational autoencoder of an artificial neural network for reconstruction to output a reconstruction result includes: Construct unsupervised artificial neural networks based on variational autoencoders and decoders; The multidimensional time series is input into the variational autoencoder in the artificial neural network, and the variational autoencoder is used to map the multidimensional time series to obtain latent variables, and the decoder is used to map the latent variables to the input space to obtain a reconstruction result.
3. The method for detecting anomalies in multidimensional time series according to claim 1, characterized in that: Before inputting the multidimensional time series into the interpolation diffusion model for masked interpolation, the method further includes: Based on the U-Net neural network model, Transformer time transformer and space transformer, and diffusion model integration, a deep learning network for denoising and interpolating time series is constructed; the deep learning network is an ImputationNet network; The interpolation diffusion model is obtained by using the ImputationNet network training.
4. The method for detecting anomalies in a multidimensional time series according to claim 1, characterized in that: The step of inputting the multidimensional time series into an interpolation diffusion model for masked interpolation includes: Inputting the multidimensional time series into an interpolation diffusion model, using a grating masking strategy to mask the data in the multidimensional time series at equal intervals along the time dimension, introducing noise into the multidimensional time series, then gradually removing the noise, and calculating a masking value; The masked value is used to generate a missing value, an interpolation error is calculated, and the interpolation error is used as an abnormality detection signal to complete masked interpolation.
5. The method for detecting anomalies in multidimensional time series according to claim 1, characterized in that: The step of training the artificial neural network using the reconstruction error comprises: Constructing a generative adversarial network; the generative adversarial network includes a generator network and a discriminator network; The objective minimization of the generator network and the objective maximization of the discriminator network are taken as constraints, and the reconstruction error is used to train the artificial neural network.
6. The method for detecting anomalies in a multidimensional time series according to any one of claims 1 to 5, characterized in that: The step of setting an anomaly detection threshold based on the second training result, and performing anomaly detection on the multidimensional time series using the trained variational autoencoder and the anomaly detection threshold to obtain an anomaly detection result includes: Setting an anomaly detection threshold based on the proportion of abnormal data in the second training result; Anomaly detection is performed on multi-dimensional time series using adversarially trained variational autoencoders to calculate anomaly detection scores. A target anomaly detection score greater than the anomaly detection threshold is screened out from the anomaly detection scores to obtain an anomaly detection result.
7. A multidimensional time series anomaly detection device, characterized in that: include: A reconstruction module, used for obtaining a multidimensional time series, inputting the multidimensional time series into a variational autoencoder of an artificial neural network for reconstruction, and outputting a reconstruction result; A masked interpolation module, used for inputting the multidimensional time series into an interpolation diffusion model for masked interpolation to output an interpolation result; A reconstruction error training module, used to fuse the reconstruction result and the interpolation result by using a preset fusion mechanism, and use the difference between the fusion result and the multidimensional time series as a reconstruction error, and use the reconstruction error to train the artificial neural network to obtain a first training result; The preset fusion mechanism is a fusion mechanism capable of learning optimization; An encoder training module, configured to train the variational autoencoder based on the first training result and run the multidimensional time series to obtain a second training result; An anomaly detection module is used to set an anomaly detection threshold based on the second training result, and use the trained variational autoencoder and the anomaly detection threshold to perform anomaly detection on the multidimensional time series to obtain an anomaly detection result.
8. The multidimensional time series anomaly detection device according to claim 7, characterized in that: The reconstruction module comprises: Neural network building blocks for building unsupervised artificial neural networks based on variational autoencoders and decoders; A mapping module is used to input the multidimensional time series into the variational autoencoder in the artificial neural network, and use the variational autoencoder to map the multidimensional time series to obtain latent variables, and use the decoder to map the latent variables to the input space to obtain a reconstruction result.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the multidimensional time series anomaly detection method as described in any one of claims 1 to 6.
10. A computer-readable storage medium, characterized in that: Used to store a computer program; wherein, when the computer program is executed by a processor, the anomaly detection method for a multidimensional time series as described in any one of claims 1 to 6 is implemented.
Citation Information
Cited By
Time sequence anomaly detection method, electronic equipment and medium
CN121256649A
A time series anomaly detection method, electronic device and medium
CN121256649B