Abnormal fluctuation early warning method and system, computing device and storage medium
By applying a dynamic threshold calculation method based on machine learning in the telecom industry business audit, the problem that traditional detection methods cannot adapt to the dynamic market environment is solved, and more accurate and timely abnormal fluctuation warning is achieved, reducing the risk of business losses.
Patent Information
- Application Number
- CN202510030409.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-08
- Publication Date
- 2025-05-30
AI Technical Summary
In traditional telecommunications industry business audits, detection methods that rely on fixed thresholds and rules of thumb cannot adapt to the dynamically changing market environment, resulting in unsatisfactory early warning results and prone to false alarms and missed reports.
Using a machine learning-based method, the prediction model is trained, dynamically calculates and adjusts the warning threshold, and accurately identify and timely warning of abnormal fluctuations is achieved.
It improves the accuracy and timeliness of early warnings, reduces false alarms and missed reports, can identify and prevent potential risks in advance, supports managers to make scientific decisions, and reduce business losses.
Smart Images

Figure CN120069161A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of electronic digital data processing, and specifically relates to an abnormal fluctuation early warning method, system, computing device, and storage medium. Background Art
[0002] In the business audit of the telecommunications industry, it is necessary to monitor and give early warnings to various business data, such as revenue assurance detection and early warning. Traditional detection methods rely on fixed thresholds and empirical rules. Although this method is simple, it has many limitations. Especially in the face of a rapidly changing market environment and complex business scenarios, the early warning effect is not ideal.
[0003] Fixed thresholds are usually based on historical experience and simple statistical methods, and cannot adapt to the dynamically changing market environment. Due to the lack of real-time analysis capabilities, in the face of emergencies or rapid changes, it is often unable to respond in a timely manner, resulting in delayed early warnings. The fixed threshold method is prone to false alarms and missed alarms, and cannot accurately identify real abnormal fluctuations. Therefore, it is necessary to design an abnormal fluctuation early warning method through dynamic thresholds. Summary of the Invention
[0004] In view of the above technical problems existing in the prior art, the present invention provides an abnormal fluctuation early warning method, system, computing device, and storage medium, which obtain dynamic thresholds based on machine learning methods and perform abnormal fluctuation early warning through dynamic thresholds, improving accuracy and timeliness.
[0005] The first aspect of the present invention provides an abnormal fluctuation early warning method, including the following steps: collecting detection values; obtaining predicted values through a prediction model based on machine learning; obtaining an early warning threshold according to the predicted values and detection values; detecting abnormal fluctuations through the early warning threshold and detection values, and generating an early warning.
[0006] Preferably, the training method of the prediction model includes:
[0007] Collecting historical data and performing data preprocessing;
[0008] Training the data set based on machine learning methods to obtain a prediction model; the machine learning methods are selected from: regression analysis, decision tree, random forest, long short-term memory network, and gated recurrent unit.
[0009] Preferably, the calculation method of the early warning threshold includes:
[0010] Obtaining the error and error sequence according to the predicted values and detection values;
[0011] Calculating the early warning threshold according to the mean and standard deviation of the error sequence.
[0012] Preferably, the calculation formula of the early warning threshold is:
[0013] T = μ(e) + kσ(e)
[0014] Wherein, T represents the warning threshold, μ(e) represents the mean of the error sequence e, σ(e) represents the standard deviation of the error sequence e, and k is a constant that can be set according to experience.
[0015] Preferably, the specific calculation method includes:
[0016] Eliminate the error peak of the error sequence by the method of exponentially weighted moving average to obtain a smoothed sequence;
[0017] Calculate the warning threshold according to the mean and standard deviation of the smoothed sequence:
[0018] T = μ(es) + kσ(es)
[0019] Wherein, T represents the warning threshold, μ(es) represents the mean of the smoothed sequence es, and σ(es) represents the standard deviation of the smoothed sequence es.
[0020] Preferably, the method for detecting abnormal fluctuations includes:
[0021] Judge whether the difference between the detected value and the predicted value exceeds the warning threshold;
[0022] If so, the detected value has abnormal fluctuations and an abnormal fluctuation warning is generated.
[0023] The second aspect of the present invention provides a system for implementing the abnormal fluctuation warning method, including an acquisition module, a prediction module, a dynamic threshold module and an abnormal detection module,
[0024] The acquisition module is used to acquire historical data and detected values;
[0025] The prediction module is used to obtain a predicted value according to the prediction model and the detected value;
[0026] The dynamic threshold module is used to obtain a warning threshold according to the predicted value and the detected value;
[0027] The abnormal detection module is used to detect abnormal fluctuations according to the warning threshold and the detected value and generate a warning.
[0028] Preferably, the system further includes a training module, a visualization module and a reporting module,
[0029] The training module is used to train the historical data based on machine learning methods to obtain a prediction model; and is used for the self-learning and updating of the prediction model;
[0030] The visualization module is used to visually display abnormal fluctuations and warning information;
[0031] The reporting module is used to generate an abnormal fluctuation detection report.
[0032] A third aspect of the present invention provides a computing device, including a memory and a processor, where the memory stores executable code,
[0033] When the executable code is executed by the processor, the above-mentioned abnormal fluctuation early warning method is executed.
[0034] A fourth aspect of the present invention provides a storage medium that stores executable code. When the executable code is executed by a computing device, the computing device executes the above-mentioned abnormal fluctuation early warning method.
[0035] Compared with the prior art, the beneficial effects of the present invention are as follows: By using machine learning methods and big data analysis, the early warning threshold is dynamically calculated and adjusted, abnormal fluctuations are accurately identified and timely warned, reducing false alarms and missed alarms; Through the early warning of abnormal fluctuations in income, potential risks can be identified and prevented in advance, supporting managers to make scientific decisions and reducing business losses. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 is a flowchart of the abnormal fluctuation early warning method based on machine learning of the present invention;
[0037] Figure 2 is a system logic block diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0038] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0039] The present invention will be further described in detail below with reference to the accompanying drawings:
[0040] Overview: The main objective of the revenue assurance system is to ensure the stability of the enterprise's revenue, reduce revenue losses and fluctuations. The revenue assurance system audits the enterprise's revenue, timely discovers abnormal fluctuations in revenue, and gives timely warnings. Outlier detection and processing are an indispensable part of the revenue auditing process. Thresholds are of great significance in anomaly detection. When the detected value exceeds the threshold, it is determined as an anomaly.
[0041] Machine learning is a multi-disciplinary cross-discipline that involves multiple disciplines such as probability theory, statistics, approximation theory, convex analysis, and algorithm complexity theory. The main research object is artificial intelligence, especially how to improve the performance of specific algorithms in empirical learning.
[0042] In the present invention, it should be understood that terms such as "including" or "having" are intended to indicate the presence of features, numbers, steps, actions, components, parts, or combinations thereof disclosed in this specification, and do not exclude the possibility of the presence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.
[0043] In addition, it should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in combination with embodiments.
[0044] The present invention provides an anomaly fluctuation warning method based on machine learning, as Figure 1 shown, which includes the following steps:
[0045] Step 101: Collect historical data and perform data preprocessing to obtain a data set.
[0046] Relevant data can be collected from a variety of data sources (such as user behavior data, call records, network usage conditions, etc.) to ensure the comprehensiveness and diversity of the data. Preprocessing steps such as cleaning, denoising, and standardizing the collected historical data are performed to ensure data quality and consistency.
[0047] Step 102: Based on a machine learning method, train the data set to obtain a prediction model.
[0048] A suitable machine learning algorithm can be selected for modeling, such as regression analysis, decision tree, random forest, neural network, etc. More specifically, deep learning models such as LSTM and GRU can be applied to process complex time series data and improve prediction performance.
[0049] The long short-term memory network LSTM is a special recurrent neural network (RNN) used to process and predict time series data or data with sequential properties. The gated recurrent unit GRU is a variant of the recurrent neural network (Recurrent Neural Network, RNN) designed to process sequential data.
[0050] Step 103: Obtain a predicted value through the prediction model.
[0051] Step 104: Collect a detection value.
[0052] Step 105: Obtain a warning threshold according to the predicted value and the detection value.
[0053] Step 106: Detect an anomaly fluctuation through the warning threshold and the detection value, and generate a warning; after generating the warning information, send the warning information to the management personnel.
[0054] Using machine learning methods and big data analysis, dynamically calculate and adjust the warning threshold, accurately identify and timely warn of abnormal fluctuations, reduce false alarms and missed alarms; through the warning of abnormal fluctuations in revenue, potential risks can be identified and prevented in advance, support managers to make scientific decisions, and reduce business losses.
[0055] By continuously monitoring detection values such as enterprise revenue, visitor traffic, transaction volume, etc., continuously collect and analyze the latest real-time data, and detect abnormal fluctuations in real time through the warning threshold. When abnormal fluctuations occur, generate warning information in a timely manner and notify relevant managers. According to the real-time detection value, dynamically adjust the expected threshold to avoid the limitations of the fixed threshold method.
[0056] In a specific embodiment, display abnormal fluctuations and warning information in a visual manner to help managers intuitively understand data changes and risk situations. A detailed abnormal fluctuation detection report can also be generated regularly, providing comprehensive revenue fluctuation analysis and prediction results to provide data support for management decisions.
[0057] The prediction model can self-learn and update: by collecting new data and trends, update and optimize the prediction model to improve the adaptability and accuracy of the predicted value.
[0058] According to the actual warning effect and user feedback, adjust and improve the coefficients in the dynamic threshold calculation method to improve the reliability and practicality of abnormal fluctuation detection.
[0059] In step 105, the calculation method of the warning threshold is as follows:
[0060] Step 501: Obtain the error and error sequence according to the predicted value and the detected value.
[0061] Within a time point, the difference between the predicted value and the detected value is used as the error, and the errors at multiple time points form the error sequence e.
[0062] Step 502: Calculate the warning threshold according to the mean and standard deviation of the error sequence. The calculation formula is as follows:
[0063] T = μ(e) + kσ(e)
[0064] Where, T represents the warning threshold, μ(e) represents the mean of the error sequence e, σ(e) represents the standard deviation of the error sequence e, and k is a constant that can be set according to experience.
[0065] It is also possible to eliminate the error peak of the error sequence through the exponentially weighted moving average EWMA method to obtain the smoothed sequence es, make the error sequence smoother, and reduce the situation of false alarms. The calculation method of the warning threshold is:
[0066] T = μ(es) + kσ(es)
[0067] Among them, T represents the warning threshold, μ(es) represents the mean of the smoothed sequence es, and σ(es) represents the standard deviation of the smoothed sequence es.
[0068] In step 106, the method for detecting abnormal fluctuations includes:
[0069] Step 601: Determine whether the difference between the detected value and the predicted value exceeds the warning threshold.
[0070] If so, step 602: The detected value has abnormal fluctuations, and an abnormal fluctuation warning is generated.
[0071] If not, step 603: Continuously collect the detected value.
[0072] The present invention also provides a system for implementing the above abnormal fluctuation warning method, as Figure 2 shown, including a collection module 1, a prediction module 2, a dynamic threshold module 3, and an abnormal detection module 4.
[0073] The collection module 1 is used to collect historical data and detected values;
[0074] The prediction module 2 is used to obtain a predicted value according to the prediction model and the detected value;
[0075] The dynamic threshold module 3 is used to obtain the warning threshold according to the predicted value and the detected value;
[0076] The abnormal detection module 4 is used to detect abnormal fluctuations according to the warning threshold and the detected value, and generate a warning.
[0077] The system further includes a training module 5, a visualization module 6, and a report module 7.
[0078] The training module 5 is used to train the historical data based on a machine learning method to obtain a prediction model; and is used for self-learning and updating of the prediction model.
[0079] The visualization module 6 is used to visually display abnormal fluctuations and warning information;
[0080] The report module 7 is used to generate an abnormal fluctuation detection report.
[0081] The present invention realizes accurate and timely warning of abnormal fluctuations in the revenue of the telecommunications industry by dynamically adjusting the warning threshold and based on a variety of machine learning methods and self-learning mechanisms. It has the following effects: significantly improved warning accuracy: by dynamically adjusting the threshold and integrating multiple machine learning algorithms, the system can more accurately identify and warn of abnormal revenue fluctuations. Enhanced warning timeliness: through real-time monitoring and data analysis, the system can quickly respond to market changes, issue warnings in a timely manner, and help managers take measures promptly. Improved risk management ability: by identifying and warning of potential risks in advance, enterprises can take preventive measures earlier, reduce business losses, and optimize operation strategies. Enhanced system flexibility and adaptability: the system can continuously optimize the prediction model by continuously learning and adapting to new data, consider multiple factors for comprehensive analysis, improve the adaptability and flexibility of the system, automate data analysis, and improve operation efficiency.
[0082] The present invention also provides a computing device for implementing the above abnormal fluctuation warning method, including a memory and a processor. The processor can be a multi-core processor or can include multiple processors. In some embodiments, the processor can include a general-purpose main processor and one or more special co-processors, such as a graphics processing unit (GPU), a digital signal processor (DSP), and so on. In some embodiments, the processor can be implemented using custom circuits, such as an application specific integrated circuit (ASIC) or a field programmable gate array (FPGA).
[0083] The memory may include various types of storage units, such as system memory, read-only memory (ROM), and permanent storage devices. Among them, the ROM can store static data or instructions required by the processor or other modules of the computer. The permanent storage device can be a read-write storage device. The permanent storage device can be a non-volatile storage device that does not lose the stored instructions and data even when the computer is powered off. In some embodiments, the permanent storage device uses a mass storage device (such as a magnetic or optical disk, flash memory) as the permanent storage device. In some other embodiments, the permanent storage device can be a removable storage device (such as a floppy disk, optical drive). The system memory can be a read-write storage device or a volatile read-write storage device, such as dynamic random access memory. The system memory can store some or all of the instructions and data required by the processor during operation. In addition, the memory can include any combination of computer-readable storage media, including various types of semiconductor storage chips (DRAM, SRAM, SDRAM, flash memory, programmable read-only memory), and magnetic disks and / or optical disks can also be used. In some embodiments, the memory can include a removable storage device that can be read and / or written, such as a compact disc (CD), read-only digital versatile disc (such as DVD-ROM, dual-layer DVD-ROM), read-only Blu-ray disc, super density disc, flash memory card (such as SD card, min SD card, Micro-SD card, etc.), magnetic floppy disk, etc. The computer-readable storage medium does not include carrier waves and instantaneous electronic signals transmitted wirelessly or wired. An executable code is stored on the memory, and when the executable code is processed by the processor, it can cause the processor to execute the method for constructing the service mesh instance described above.
[0084] The present invention can also be implemented as a readable storage medium (or computer-readable storage medium, or machine-readable storage medium) on which an executable code (or computer program, or computer instruction code) is stored. When the executable code (or computer program, or computer instruction code) is executed by a processor of an electronic device (or computing device, server, etc.), it causes the processor to execute each step of the above method according to the present invention.
[0085] The flowcharts and block diagrams in the accompanying drawings show the possible implementations of the systems and methods according to multiple embodiments of the present invention.
[0086] The present system architecture, functions, and operations. In this regard, each block in a flowchart or block diagram can represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0087] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. The abnormal fluctuation early warning method is characterized by: The following steps are involved: Collect test values; Obtain predicted values through prediction models based on machine learning; Obtaining a warning threshold value according to the predicted value and the detected value; Through warning thresholds and detection values, abnormal fluctuations are detected and warnings are generated.
2. The abnormal fluctuation early warning method according to claim 1, characterized in that: The training methods of the prediction model include: Collect historical data and perform data preprocessing; Based on a machine learning method, the data set is trained to obtain a prediction model; the machine learning method is selected from: regression analysis, decision tree, random forest, long short-term memory network and gated recurrent unit.
3. The abnormal fluctuation early warning method according to claim 1 is characterized in that: The calculation method of the warning threshold includes: According to the predicted value and the detected value, an error and an error sequence are obtained; Calculate the warning threshold based on the mean and standard deviation of the error sequence.
4. The abnormal fluctuation early warning method according to claim 3 is characterized in that: The calculation formula for the warning threshold is: T=μ(e)+kσ(e) Among them, T represents the warning threshold, μ(e) represents the mean of the error sequence e, σ(e) represents the standard deviation of the error sequence e, and k is a constant.
5. The abnormal fluctuation early warning method according to claim 3 is characterized in that: The specific calculation methods include: The error peak of the error sequence is eliminated by the exponentially weighted sliding average method to obtain a smooth sequence; Calculate the warning threshold based on the mean and standard deviation of the smoothed sequence: T=μ(es)+kσ(es) Where T represents the warning threshold, μ(es) represents the mean of the smoothed sequence es, and σ(es) represents the standard deviation of the smoothed sequence es.
6. The abnormal fluctuation early warning method according to claim 1, characterized in that: Methods for detecting abnormal fluctuations include: Determine whether the difference between the detected value and the predicted value exceeds a warning threshold; If so, the detection value has abnormal fluctuations, and an abnormal fluctuation warning is generated.
7. A system for implementing the abnormal fluctuation early warning method according to any one of claims 1 to 6, characterized in that: It includes acquisition module, prediction module, dynamic threshold module and anomaly detection module. The acquisition module is used to collect historical data and test values; The prediction module is used to obtain a prediction value according to the prediction model and the detection value; The dynamic threshold module is used to obtain the warning threshold according to the predicted value and the detected value; The anomaly detection module is used to detect abnormal fluctuations and generate an alarm according to the alarm threshold and the detection value.
8. The system according to claim 7, characterized in that It also includes training modules, visualization modules and reporting modules. The training module is used to train historical data based on machine learning methods to obtain a prediction model; and is used for self-learning and updating of the prediction model; The visualization module is used to visualize abnormal fluctuations and warning information; The reporting module is used to generate an abnormal fluctuation detection report.
9. A computing device, characterized in that comprising a memory and a processor, wherein the memory stores executable code, When the executable code is executed by the processor, the abnormal fluctuation warning method according to any one of claims 1 to 6 is executed.
10. A storage medium, characterized in that: An executable code is stored, and when the executable code is executed by a computing device, the computing device executes the abnormal fluctuation early warning method according to any one of claims 1 to 6.