Data anomaly detection processing method and device

By performing abnormal detection and multimodal knowledge extraction on the business data of Internet platform merchants, and combining with large language models for abnormal analysis, the problem of detection and analysis of abnormal business data faced by merchants is solved, and rapid and in-depth exception handling is achieved.

CN120123935APending Publication Date: 2025-06-10ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510194200.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

On Internet platforms, merchants face abnormal situations of sudden changes in business data, and lack of effective detection and analysis methods, which may lead to user churn and trust crisis.

Method used

A data exception detection and processing method is adopted to obtain the data to be detected for abnormal detection, extract multimodal knowledge, perform text conversion, build exception analysis text, and input it into a large language model for data exception analysis, obtain processing results and analysis process information.

Benefits of technology

It realizes rapid detection and in-depth analysis of abnormal business data situations, helping merchants identify problems in a timely manner and reducing user churn and trust crises.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120123935A_ABST
    Figure CN120123935A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data exception detection processing method and device.The data exception detection processing method comprises the steps that in the data exception detection processing process, to-be-detected data triggering exception detection is obtained, exception detection is conducted on the to-be-detected data, and exception parameters are obtained, then performing multi-modal knowledge extraction according to the to-be-detected data and the abnormal parameters, performing text conversion on a knowledge extraction result to obtain a knowledge text, and further constructing an abnormal analysis text based on the knowledge text and an abnormal analysis prompt template corresponding to the to-be-detected data; and finally, inputting the exception analysis text into the large language model to perform data exception analysis to obtain an exception analysis processing result and analysis process information, thereby performing more comprehensive exception detection on the to-be-detected data through the large language model on the basis of knowledge extraction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to the field of data processing technology, and in particular to a method and device for data anomaly detection and processing. Background Art

[0002] With the continuous development and promotion of the Internet, there are more and more platforms that provide various online services based on the Internet. Merchants provide corresponding services to users by entering the platforms. In this process, business data is the focus of attention of merchants and platforms. The most common concern is the reasons for abnormal situations such as sudden rise, fall, and fluctuation of business data. In this case, if merchants lack correct guidance, it may lead to user loss and even cause merchants to lose trust in the platform. Summary of the invention

[0003] One or more embodiments of the present specification provide a data anomaly detection and processing method, including: obtaining data to be detected that triggers anomaly detection, and performing anomaly detection on the data to be detected to obtain anomaly parameters. Performing multimodal knowledge extraction based on the data to be detected and the anomaly parameters, and performing text conversion on the knowledge extraction results to obtain knowledge text. Constructing an anomaly analysis text based on the knowledge text and the anomaly analysis prompt template corresponding to the data to be detected. Inputting the anomaly analysis text into a large language model to perform data anomaly analysis, and obtaining an anomaly analysis processing result and analysis process information.

[0004] One or more embodiments of the present specification provide a data anomaly detection and processing device, including: an anomaly detection module, configured to obtain the data to be detected that triggers anomaly detection, and perform anomaly detection on the data to be detected to obtain anomaly parameters. A knowledge extraction module, configured to perform multimodal knowledge extraction based on the data to be detected and the anomaly parameters, and perform text conversion on the knowledge extraction results to obtain knowledge text. A text construction module, configured to construct an anomaly analysis text based on the knowledge text and the anomaly analysis prompt template corresponding to the data to be detected. An anomaly analysis module, configured to input the anomaly analysis text into a large language model to perform data anomaly analysis, and obtain an anomaly analysis processing result and analysis process information.

[0005] One or more embodiments of this specification provide a data anomaly detection and processing device, including: a processor; and a memory configured to store computer-executable instructions, which when executed cause the processor to: obtain the data to be detected that triggers anomaly detection, and perform anomaly detection on the data to be detected to obtain anomaly parameters. Perform multimodal knowledge extraction based on the data to be detected and the anomaly parameters, and perform text conversion on the knowledge extraction result to obtain a knowledge text. Construct an anomaly parsing text based on the knowledge text and the anomaly parsing prompt template corresponding to the data to be detected. Input the anomaly parsing text into a large language model for data anomaly parsing to obtain an anomaly parsing processing result and parsing process information.

[0006] One or more embodiments of this specification provide a computer-readable storage medium for storing computer-executable instructions, which when executed implement the following process: obtain the data to be detected that triggers anomaly detection, and perform anomaly detection on the data to be detected to obtain anomaly parameters. Perform multimodal knowledge extraction based on the data to be detected and the anomaly parameters, and perform text conversion on the knowledge extraction result to obtain a knowledge text. Construct an anomaly parsing text based on the knowledge text and the anomaly parsing prompt template corresponding to the data to be detected. Input the anomaly parsing text into a large language model for data anomaly parsing to obtain an anomaly parsing processing result and parsing process information. Description of the Drawings

[0007] In order to more clearly illustrate the technical solutions in one or more embodiments of this specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings; Figure 1 It is a schematic diagram of the implementation environment of a data anomaly detection and processing method provided by one or more embodiments of this specification; Figure 2 It is a processing flow chart of a data anomaly detection and processing method provided by one or more embodiments of this specification; Figure 3 It is a schematic diagram of a data display control provided by one or more embodiments of this specification; Figure 4 It is a schematic diagram of a dialogue interface provided by one or more embodiments of this specification; Figure 5 It is a processing flow chart of a data anomaly detection and processing method applied to the merchant data anomaly detection and processing scenario provided by one or more embodiments of this specification; Figure 6 A processing flow chart of a data anomaly detection and processing method applied to the operation data anomaly detection and processing scenario provided for one or more embodiments of this specification; Figure 7 A schematic diagram of an embodiment of a data anomaly detection and processing device provided for one or more embodiments of this specification; Figure 8 A schematic structural diagram of a data anomaly detection and processing device provided for one or more embodiments of this specification. Detailed implementation manners

[0008] In order to enable those skilled in the art to better understand the technical solutions in one or more embodiments of this specification, the technical solutions in one or more embodiments of this specification will be clearly and completely described below in conjunction with the accompanying drawings in one or more embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this document.

[0009] The data anomaly detection and processing method provided by one or more embodiments of this specification is applicable to the implementation environment of a data anomaly detection system. Referring to Figure 1 , this implementation environment at least includes: Anomaly detection module 101, knowledge extraction module 102, anomaly analysis module 103, large language model 104. In addition, it may also include a database 105; Among them, the anomaly detection module 101 is used to obtain the data to be detected and perform anomaly detection on the data to be detected; The knowledge extraction module 102 is used to extract knowledge from multiple modalities for the data to be detected; The anomaly analysis module 103 is used to convert the knowledge extracted by the knowledge extraction module 102 into text, construct a prompt text according to the converted text and a pre-set prompt template, that is, construct a prompt text for inputting into the large language model 104, and input the prompt text into the large language model 104; the large language model 104 performs data anomaly analysis according to the input prompt text, specifically, combines the extracted knowledge to perform data anomaly analysis on the data to be detected, and outputs an anomaly analysis processing result and parsing process information.

[0010] In this implementation environment, during the process of data anomaly detection and processing, first, the anomaly detection module 101 obtains the data to be detected that triggers the anomaly detection, and performs anomaly detection on the data to be detected to obtain anomaly parameters. The knowledge extraction module 102 extracts knowledge from multiple modalities based on the data to be detected and the anomaly parameters to obtain a knowledge extraction result, and submits the knowledge extraction result to the anomaly analysis module 103. The anomaly analysis module 103 first performs text conversion on the knowledge extraction result to obtain a knowledge text, then constructs an anomaly analysis text based on the knowledge text and the anomaly analysis prompt template corresponding to the data to be detected, inputs the anomaly analysis text into the large language model 104 for data anomaly analysis, and obtains the anomaly analysis processing result and the analysis process information output by the large language model 104, so as to perform a more comprehensive anomaly detection on the data to be detected through the large language model on the basis of knowledge extraction.

[0011] It should be noted that considering that the merchant data involved in this specification may, to a certain extent, belong to the privacy of the merchant, therefore, if you want to collect the merchant's data, you can obtain the merchant's authorization before collecting the data to make the operation of collecting data comply with relevant data management regulations. For example, you can perform data authorization before the merchant conducts data anomaly detection and processing, or you can also perform data authorization during the first process of the merchant's data anomaly detection and processing; the specific method of data authorization can be to send a merchant data authorization reminder to the merchant, and the merchant can obtain data collection authorization after confirming the reminder through an instruction. Or, the method of data authorization can also be to obtain data collection authorization by signing a data authorization agreement.

[0012] One or more embodiments of a data anomaly detection and processing method provided in this specification are as follows: Refer to Figure 2 In this embodiment, the provided data anomaly detection and processing method specifically includes steps S202 to S208.

[0013] Step S202, obtain the data to be detected that triggers the anomaly detection, and perform anomaly detection on the data to be detected to obtain anomaly parameters.

[0014] In this embodiment, during the process of data anomaly detection and processing, the anomaly detection of data is initiated by triggering the anomaly detection. The entity triggering the anomaly detection can be a merchant or an operation platform, specifically an operation personnel of the operation platform. The data triggering the anomaly detection can be the merchant's data or the operation data of the operation platform. Based on this, during the process of data anomaly detection, first obtain the data to be detected that triggers the anomaly detection. The data to be detected refers to the data that needs to be subjected to anomaly detection, specifically, it can be to obtain the data to be detected triggered by the merchant or the data to be detected triggered by the operation personnel.

[0015] In the specific execution process, when merchants or operators trigger anomaly detection, different triggering methods may exist according to different data access scenarios or interaction scenarios. For example, in the scenario of data access through a data display control, merchants or operators can trigger anomaly detection by triggering the merchant data or operation data in the data display control. In this case, the data to be detected includes the triggering data (selected data) and the metric data of the triggering data. Among them, the triggering data refers to the merchant data or operation data displayed in the data display control. Specifically, it is the merchant data triggered by the merchant in the merchant data displayed by the data display control, or the operation data triggered by the operator in the operation data displayed by the data display control. The metric data of the triggering data refers to the data related to the triggering data stored in the database, such as the detailed data of the triggering data obtained from the database, or the metric data of the triggering data, etc. Specifically, the metric data can be the metric name, time period, product information, and / or industry category information, and can also be other data, such as product inventory information, etc.

[0016] In the specific execution process, during the anomaly detection and processing of data, in order to improve the accuracy and reliability of anomaly detection, the target data and the metric data of the target data can be obtained as the data to be detected to provide accurate and comprehensive data for anomaly detection. In an optional implementation provided in this embodiment, obtaining the data to be detected for triggering anomaly detection includes: Obtain the target merchant data selected by the merchant from the merchant data displayed in the data display control, and use the target merchant data and the metric data of the target merchant data read as the data to be detected. Or, Obtain the target operation data selected by the operator from the operation data displayed in the data display control, and use the target operation data and the metric data of the target operation data read as the data to be detected.

[0017] Taking merchant data as an example, the merchant data displayed in the data display control is the product sales volume data of the merchant. After the merchant selects the product sales volume at a certain time point from the product sales volume data, the product information, metric name (daily product sales volume), time information corresponding to the daily product sales volume, and industry category information of the product sales volume are obtained from the database as metric data, and the metric data and the product sales volume selected at a certain time point are jointly used as the data to be detected.

[0018] For example, Figure 3In the data display control of the merchant shown, the daily sales volume change trend of a certain product over a period of time is displayed; by the merchant triggering the anomaly point 301-1, the sales volume of the product at the time point corresponding to this anomaly point (20xx-xx-14) is used as the target merchant data, and then product information, indicator name (daily sales volume of the product), time information corresponding to the daily sales volume of the product (20xx-xx-14), and industry category information are obtained from the database as indicator data, and the sales volume of the product corresponding to the time point (20xx-xx-14) and the indicator data are jointly used as the data to be detected.

[0019] In addition, the merchant or the operator can also trigger anomaly detection by triggering a certain data label in the data display control. In this case, the data to be detected includes the data label and the indicator data of the data label. Among them, the data label refers to the label of the data displayed in the data display control. The data label can specifically include the timestamp of the data, and can also include specific values. In addition, the data label can also include other information of the data; correspondingly, the indicator data of the data label refers to the data related to the data label stored in the database, such as the detailed data of the data label obtained from the database, or the indicator data of the data label.

[0020] For another example, in the scenario of dialogue interaction through the dialogue interface, the merchant or the operator can trigger anomaly detection by entering dialogue content in the dialogue interface. In this case, the data to be detected includes the data label and the indicator data of the data label in the dialogue content; Among them, the data label refers to the data label included in the dialogue content entered in the dialogue interface; the indicator data of the data label refers to the data related to the data label stored in the database, such as the detailed data of the data label obtained from the database, or the indicator data of the data label, etc.; specifically, the indicator data can be the indicator name, time period, product information and / or industry category information, and can also be other data, such as product inventory information, etc.

[0021] In the specific execution process, in another optional implementation manner provided by this embodiment, obtaining the data to be detected for triggering anomaly detection includes: Extracting the data label in the dialogue content entered by the merchant in the dialogue interface, and reading the merchant data corresponding to the data label from the database as the data to be detected; Or, Extracting the data label in the dialogue content entered by the operator in the dialogue interface, and reading the operation data corresponding to the data label from the database as the data to be detected.

[0022] Taking the dialogue interaction scenario as an example, a merchant inputs a dialogue in the dialogue interface to analyze the sales volume of goods at a certain time. After extracting the data tags in the input dialogue content, the merchant reads the merchant data corresponding to the data tags from the database. For example, the merchant reads the product information of the product sales volume, the index name (daily product sales volume), the time information corresponding to the daily product sales volume, and the industry category information from the database as the index data of the data tags, and takes the data tags and the index data of the data tags together as the data to be detected.

[0023] For example, Figure 4 In the shown dialogue interface, the merchant inputs the dialogue: Please analyze the sales volume data of xx product on 20xx-10-01; based on this dialogue content, the time information label and the product information label in the dialogue content can be extracted as data tags. After extracting the data tags, the product information of the product sales volume, the daily product sales volume, the time information corresponding to the daily product sales volume, and the industry category information are read from the database as the index data of the data tags, and the data tags and the index data of the data tags are taken together as the data to be detected.

[0024] In specific implementation, based on the obtained data to be detected, anomaly detection is performed on the data to be detected to obtain anomaly parameters. Here, the purpose of performing anomaly detection on the data to be detected can be to detect whether there is an anomaly in the data to be detected, that is, to detect whether there is an anomaly in the data to be detected, or it can also be to perform preliminary anomaly detection on the data to be detected to provide the detection parameters obtained from the preliminary detection here to the subsequent anomaly analysis process.

[0025] Specifically, in the process of performing anomaly detection on the data to be detected, in order to improve the accuracy and comprehensiveness of anomaly detection, multiple anomaly detection methods can be used to perform anomaly detection on the data to be detected, and the detection results of multiple anomaly detection methods are summarized to form a more accurate and comprehensive detection result, that is, the anomaly parameters are determined according to the detection results of multiple anomaly detection methods; optionally, the anomaly parameters include the anomaly type and the anomaly level; Among them, the anomaly type refers to the characterization type of data anomaly. For example, the anomaly type can be the anomaly increase type or the anomaly decrease type that characterizes the abnormal increase or decrease of data, and the anomaly type can also be the type of other abnormal forms of data, such as the anomaly oscillation type or the anomaly fluctuation type that characterizes the abnormal oscillation or abnormal fluctuation of data; The anomaly level refers to the degree of data anomaly situation. By classifying the data anomaly situation into multiple anomaly levels, different anomaly levels can represent different degrees of data anomaly situation. For example, the anomaly level can be divided into three anomaly levels. The first anomaly level represents the situation of serious data anomaly, the second anomaly level represents the situation of relatively serious anomaly in the data, and the third anomaly level represents the situation of slight anomaly in the data.

[0026] In a specific implementation process, in an optional implementation manner provided in this embodiment, performing anomaly detection on the data to be detected to obtain anomaly parameters includes: Invoking multiple data detection interfaces to perform anomaly detection on the data to be detected, and obtaining the anomaly detection results returned by each data detection interface; Determining the anomaly type and anomaly level of the data to be detected according to the returned anomaly detection results.

[0027] For example, the following three data detection interfaces are respectively invoked to perform anomaly detection on the data to be detected: a data detection interface for anomaly detection based on mathematical statistics, a data detection interface for anomaly detection based on an anomaly detection algorithm, and a data detection interface for anomaly detection based on time series data prediction. After invoking the above three data detection interfaces for data anomaly detection, the anomaly type and anomaly level returned by each of the three data detection interfaces are obtained, and the anomaly type and anomaly level of the data to be detected are determined according to the anomaly type and anomaly level returned by each of the three data detection interfaces.

[0028] Step S204, performing multi-modal knowledge extraction according to the data to be detected and the anomaly parameters, and performing text conversion on the knowledge extraction result to obtain knowledge text.

[0029] In this embodiment, in the scenario of performing anomaly detection processing on the data to be detected, the abnormal situation existing in the data to be detected is specifically analyzed by parsing the data to be detected. At the same time, in order to improve the accuracy and comprehensiveness of anomaly analysis of the data to be detected, data related to the data to be detected can be further extracted on the basis of the data to be detected as knowledge data for subsequent anomaly analysis of the data to be detected. Data related to the data to be detected and knowledge data related to the anomaly of the data to be detected can also be further extracted on the basis of the data to be detected and the anomaly parameters, so as to be able to perform more accurate and comprehensive anomaly analysis on the data to be detected in combination with the knowledge data.

[0030] The multi-modal knowledge extraction can be a process of extracting knowledge data of the data to be detected from multiple modalities, or a process of extracting multiple, various or multiple types of knowledge data from a single modality; among them, the modality refers to the data extraction modality for extracting knowledge data. The data extraction modality can be an index statistics modality for data extraction based on index statistics according to an index statistics algorithm. The data extraction modality can be an index graph modality for data extraction according to an index relationship graph. Or, the data extraction modality can also be an index knowledge modality for data extraction based on knowledge and experience. Or, the data extraction modality can also be an abnormal index modality for data extraction based on calling an abnormal attribution interface for abnormal attribution processing. In addition, it can also be other modalities, such as an additional data extraction modality for extracting abnormal attribution examples matching the data to be detected and / or application scenario data of the data to be detected.

[0031] Among them, knowledge data refers to data that can be used in the subsequent abnormal analysis process of the data to be detected. Specifically, knowledge data includes data related to the data to be detected and / or data related to the abnormality of the data to be detected. For example, knowledge data can include data related to the data to be detected and / or data related to the abnormality of the data to be detected extracted from the index statistics modality. Knowledge data can be data related to the data to be detected and / or data related to the abnormality of the data to be detected extracted from the index graph modality. Or, knowledge data can also be data related to the data to be detected and / or data related to the abnormality of the data to be detected extracted from the index knowledge modality. Or, knowledge data can also be data related to the data to be detected and / or data related to the abnormality of the data to be detected extracted from the abnormal index modality. In addition, knowledge data can also be data extracted from other modalities, such as data related to the data to be detected and / or data related to the abnormality of the data to be detected extracted from the attachment data extraction modality.

[0032] In specific implementation, during the process of multi-modal knowledge extraction according to the data to be detected and abnormal parameters, index data can be obtained by extracting data according to the knowledge extraction strategy. And, on the basis of obtaining the index data, the index data, the data to be detected, and the abnormal parameters can be subjected to parsing processing, so as to parse the data to be detected during the multi-modal knowledge extraction process. On this basis, the parsing processing result and the index data are provided to the subsequent abnormal analysis process of the data to be detected, which can improve the depth of abnormal detection of the data to be detected.

[0033] Specifically, in an optional implementation manner provided in this embodiment, multi-modal knowledge extraction according to the data to be detected and abnormal parameters includes: Determine a knowledge extraction strategy according to the data to be detected and abnormal parameters, and extract index data from the database according to the knowledge extraction strategy; Perform parsing processing on the index data, the data to be detected, and the abnormal parameters, and use the parsing processing result and the index data as the knowledge extraction result.

[0034] Among them, the knowledge extraction strategy refers to the strategy for extracting knowledge data of the data to be detected. The knowledge extraction strategy can correspond to the above modalities one by one, that is: each modality is set with its corresponding knowledge extraction strategy. Specifically, the knowledge extraction strategy can be a strategy for extracting knowledge data based on the index statistical algorithm for index statistics, the knowledge extraction strategy can be a strategy for extracting knowledge data according to the index relationship graph, or the knowledge extraction strategy can also be a strategy for extracting knowledge data based on knowledge index data, or the knowledge extraction strategy can also be a strategy for extracting knowledge data based on abnormal index data; in addition, the knowledge extraction strategy can also be other strategies, such as a strategy for extracting knowledge data based on the abnormal attribution example of knowledge data matching and / or the application scenario data of knowledge data.

[0035] It should be noted that the number of knowledge extraction strategies can be one or more. In the case where the number of knowledge extraction strategies is multiple, the above implementation process of multi-modal knowledge extraction according to the data to be detected and abnormal parameters can be replaced by: determining multiple knowledge extraction strategies according to the data to be detected and abnormal parameters, extracting index data from the database according to each knowledge extraction strategy, performing parsing processing on each index data, the data to be detected and abnormal parameters, and taking the parsing processing result and each index data as the knowledge extraction result.

[0036] Furthermore, in the scenario of performing abnormal detection processing on the data to be detected, in order to further improve the accuracy and comprehensiveness of the subsequent abnormal parsing process of the data to be detected, here, in the process of performing parsing processing on the index data, the data to be detected and abnormal parameters, it is also possible to start from one or more of the three processing dimensions of abnormal detection of index data, statistical processing of index data, and abnormal contribution of index data, and perform parsing processing on the index data, the data to be detected and abnormal parameters to obtain the parsing processing result.

[0037] In an optional implementation manner provided in this embodiment, performing parsing processing on the index data, the data to be detected and abnormal parameters includes: Performing abnormal detection on the index data to obtain the index abnormal parameters of the index data, performing index statistical processing on the data to be detected and the index data to obtain index statistical data, and / or calculating the contribution degree of each index data to the abnormal parameters; Correspondingly, the parsing processing result includes index abnormal parameters, index statistical data and / or contribution degree.

[0038] Specifically, the process of performing parsing processing on the index data, the data to be detected and abnormal parameters can be replaced according to the actual processing needs by: performing parsing processing on the index data and the data to be detected to obtain the parsing processing result; or it can also be replaced by: performing parsing processing on the index data and abnormal parameters to obtain the parsing processing result; Here, the index data and the data to be detected are parsed and processed to obtain a parsing and processing result, including: performing anomaly detection on the index data to obtain the index anomaly parameters of the index data, and / or performing index statistical processing on the data to be detected and the index data to obtain index statistical data; parsing and processing the index data and the anomaly parameters to obtain a parsing and processing result, including: performing anomaly detection on the index data to obtain the index anomaly parameters of the index data, and / or calculating the contribution degree of each index data to the anomaly parameters.

[0039] In addition, the process of parsing and processing the index data, the data to be detected, and the anomaly parameters can also be replaced according to the actual processing needs with: parsing and processing the index data, the target data included in the data to be detected, and / or the anomaly types and / or anomaly levels included in the index data and the anomaly parameters to obtain a parsing and processing result; or, it can also be replaced with: parsing and processing the index data, the target data included in the data to be detected, and / or the index data to obtain a parsing and processing result; or, it can also be replaced with: parsing and processing the anomaly types and / or anomaly levels included in the index data and the anomaly parameters to obtain a parsing and processing result.

[0040] As described above, the data extraction modes for multi-modal knowledge extraction can be the index statistical mode, the index graph mode, the index knowledge mode, the abnormal index mode, and / or the additional data extraction mode; based on this, specifically in the process of multi-modal knowledge extraction, multi-modal knowledge extraction can be carried out starting from at least one of the five data extraction modes, and the multi-modal knowledge extraction processes of each data extraction mode are specifically described below.

[0041] (1) Index statistical mode In the specific execution process, in order to improve the accuracy of multi-modal knowledge extraction and enhance the adaptability of multi-modal knowledge extraction, multi-modal knowledge extraction can be carried out on the data to be detected and the anomaly parameters on the basis of performing index statistics according to the index statistical algorithm. In an optional implementation manner provided in this embodiment, multi-modal knowledge extraction according to the data to be detected and the anomaly parameters includes: Reading the first index data corresponding to the algorithm index from the database according to the algorithm index included in the index statistical algorithm of the data to be detected; Parsing the first index data, the data to be detected, and the anomaly parameters, and taking the parsing and processing result, the index statistical algorithm, and the first index data as the knowledge extraction result.

[0042] The first indicator data refers to the data related to algorithm indicators read from the database, that is, the first indicator data can be algorithm indicator data. For example, it can be the detailed data of algorithm indicators obtained from the database, or the indicator data of algorithm indicators. Here, the first indicator data can be replaced with: algorithm indicator data; an algorithm indicator refers to an indicator that constitutes an indicator statistical algorithm.

[0043] For example, in the process of analyzing the commodity sales amount of commodity A at a certain time point, commodity information of the commodity sales amount, the daily sales amount of the commodity, the time information corresponding to the daily sales amount of the commodity, and the industry category information are obtained from the database as indicator data, and the indicator data and the commodity sales amount at this time point are jointly used as the data to be detected, and the abnormal decline type and abnormal level of the abnormal decline in the commodity sales amount are used as abnormal parameters; for the data to be detected and abnormal parameters here, first obtain the indicator statistical algorithm related to the sales amount: daily sales amount = unit price * sales quantity, and determine that the algorithm indicators included in this indicator statistical algorithm are the unit price and the sales quantity. Further, read the indicator data corresponding to the unit price and the indicator data corresponding to the sales quantity, and then parse each indicator data, the data to be detected, and the abnormal parameters here, and use the parsing result, the indicator statistical algorithm, and the indicator data as the knowledge extraction result.

[0044] Furthermore, in the process of parsing and processing the first indicator data, the data to be detected, and the abnormal parameters, it is also possible to start from one or more of the three processing dimensions of abnormal detection of the first indicator data, statistical processing of the first indicator data, and abnormal contribution of the first indicator data, and perform parsing and processing on the first indicator data, the data to be detected, and the abnormal parameters to obtain a parsing result; in an optional implementation manner provided in this embodiment, parsing the first indicator data, the data to be detected, and the abnormal parameters includes: Performing abnormal detection on the first indicator data to obtain the indicator abnormal parameters of the first indicator data, performing statistical calculation of the indicator statistical algorithm based on the data to be detected and the first indicator data to obtain indicator statistical data, and / or calculating the contribution degree of each first indicator data to the abnormal parameters.

[0045] Correspondingly, the parsing result includes indicator abnormal parameters, indicator statistical data, and / or contribution degree.

[0046] The indicator abnormal parameter refers to the abnormal value of the indicator data. For example, the indicator abnormal parameter can be the abnormal value of the first indicator data identified during the abnormal detection of the first indicator data; the contribution degree refers to the influence degree of any one or more indicator data on the abnormal parameters. For example, the contribution degree can be the influence degree of each first indicator data on the abnormal parameters.

[0047] In the specific execution process, when performing anomaly detection on the first indicator data to obtain the indicator anomaly parameters of the first indicator data, a data detection interface can be called to perform anomaly detection on the first indicator data, and the anomaly detection results returned by each data detection interface are used as the indicator anomaly parameters. For example, a data detection interface based on mathematical statistics for anomaly detection can be called to perform anomaly detection on the first indicator data, obtaining the anomaly type and anomaly level of the first indicator data returned by the data detection interface, and determining the indicator anomaly parameters of the first indicator data based on the anomaly type and anomaly level returned by the data detection interface; In the process of performing statistical calculation of the indicator statistical algorithm based on the data to be detected and the first indicator data to obtain the indicator statistical data, the statistical calculation of the data to be detected and the first indicator data can be performed according to the determined indicator statistical algorithm, and the corresponding indicator statistical data can be obtained based on the statistical calculation results; In the process of calculating the contribution degree of each first indicator data to the anomaly parameter, the contribution degree can be calculated based on the contribution degree calculation model. For example, the input of the contribution degree calculation model can be the first indicator data, the data to be detected, the anomaly parameter, the indicator anomaly parameter, and / or the indicator statistical data, and the output can be the contribution degree of each first indicator data to the anomaly parameter. In addition, it can also be other data, such as a sorted list for sorting the contribution degree.

[0048] For example, in the process of analyzing the commodity sales amount of commodity A at a certain time point, for the above-mentioned obtained indicator data, data to be detected, and anomaly parameter, in the process of parsing the indicator data, data to be detected, and anomaly parameter, a data detection interface can be called to perform anomaly detection on the indicator data corresponding to the unit price and the indicator data corresponding to the sales quantity, and the anomaly detection results returned by each data detection interface are used as the indicator anomaly parameters. The average unit price, average sales quantity, sales amount mean, and sales amount variance of commodity A within a certain period before and after this time point can also be calculated, and the obtained calculation results are used as the indicator statistical data. The indicator data, anomaly parameter, and / or indicator anomaly parameter can also be input into the contribution degree calculation model for contribution degree calculation, and the contribution degree of each indicator data to the anomaly parameter is output. Based on this, an analysis processing result including the indicator anomaly parameter, indicator statistical data, and contribution degree is obtained.

[0049] It should be noted that the process of parsing and processing the first indicator data, data to be detected, and anomaly parameter can be replaced according to the actual processing needs: parsing and processing the first indicator data and the data to be detected to obtain the parsing and processing result; or, it can also be replaced by: parsing and processing the first indicator data and the anomaly parameter to obtain the parsing and processing result; Here, the first indicator data and the data to be detected are parsed and processed to obtain a parsing and processing result, including: performing anomaly detection on the first indicator data to obtain the indicator anomaly parameter of the first indicator data, and / or performing indicator statistical processing on the data to be detected and the first indicator data to obtain indicator statistical data; parsing and processing the first indicator data and the anomaly parameter to obtain a parsing and processing result, including: performing anomaly detection on the first indicator data to obtain the indicator anomaly parameter of the first indicator data, and / or calculating the contribution degree of each first indicator data to the anomaly parameter.

[0050] In addition, the process of parsing and processing the first indicator data, the data to be detected, and the anomaly parameter can also be replaced according to the actual processing needs with: parsing and processing the first indicator data, the target data and / or indicator data included in the data to be detected, and the anomaly type and / or anomaly level included in the anomaly parameter to obtain a parsing and processing result; or, it can also be replaced with: parsing and processing the first indicator data and the target data and / or indicator data included in the data to be detected to obtain a parsing and processing result; or, it can also be replaced with: parsing and processing the first indicator data and the anomaly type and / or anomaly level included in the anomaly parameter to obtain a parsing and processing result.

[0051] (2) Indicator atlas modality In the specific execution process, in order to improve the depth of multi-modal knowledge extraction and identify potential factors affecting the knowledge extraction result, multi-modal knowledge extraction can be performed on the data to be detected and the anomaly parameter by applying a knowledge relationship atlas. In an optional implementation manner provided in this embodiment, multi-modal knowledge extraction based on the data to be detected and the anomaly parameter includes: Determining the atlas indicators associated with the data indicators included in the data to be detected in the indicator relationship atlas, and reading the second indicator data corresponding to the atlas indicators from the database; Parsing the second indicator data, the data to be detected, and the anomaly parameter, and taking the parsing and processing result, the atlas indicator, and the second indicator data as the knowledge extraction result.

[0052] The second indicator data refers to the data related to the atlas indicator read from the database, that is, the second indicator data can be atlas indicator data, such as the detailed data of the atlas indicator obtained from the database, or the indicator data of the atlas indicator. Here, the second indicator data can be replaced with: atlas indicator data; among them, the atlas indicator data refers to the data corresponding to the atlas indicator associated with the data to be detected in the indicator relationship atlas; the indicator relationship atlas refers to an atlas used to represent the direct and / or indirect relationships between different data indicators.

[0053] Further, in the process of parsing and processing the second indicator data, the data to be detected, and the abnormal parameters, the parsing and processing of the second indicator data, the data to be detected, and the abnormal parameters can also be started from one or two processing dimensions of the abnormal detection of the second indicator data and the abnormal contribution of the second indicator data to obtain the parsing and processing result; in an optional implementation manner provided in this embodiment, the parsing of the second indicator data, the data to be detected, and the abnormal parameters includes: Performing abnormal detection on the second indicator data to obtain the indicator abnormal parameters of the second indicator data, and / or calculating the contribution degree of each second indicator data to the abnormal parameters.

[0054] Correspondingly, the parsing and processing result includes the indicator abnormal parameters and / or the contribution degree.

[0055] For example, in the process of analyzing the commodity sales volume of commodity A at a certain time point, the commodity information, the daily commodity sales volume, and the time information corresponding to the daily commodity sales volume of the commodity sales volume are obtained from the database as the indicator data, and the indicator data and the commodity sales volume at this time point are jointly used as the data to be detected, and the abnormal decline type and abnormal level of the abnormal decline of the commodity sales volume are used as the abnormal parameters; for the data to be detected and the abnormal parameters here, based on the indicator relationship graph, the graph indicators associated with the data indicators are determined to include: the supply volume of supplier a, the supply volume of raw material supplier b, and the purchase volume of the customer. Further, the indicator data corresponding to each of the three graph indicators here is read. Based on this, the data detection interface can be called to perform abnormal detection on each indicator data here and use the abnormal detection results returned by each data detection interface as the indicator abnormal parameters. The contribution degree calculation model can also be input with each indicator data and the abnormal parameters to calculate the contribution degree, and the contribution degree of each indicator data to the abnormal parameters is output, so as to obtain the corresponding parsing and processing result, and use the obtained parsing and processing result, the graph indicator, and the indicator data as the knowledge extraction result; In addition, for the data to be detected and the abnormal parameters here, based on the indicator relationship graph, the graph indicators associated with the data indicators can also be determined to include the sales volume of commodity B that has a competitive relationship with commodity A. Further, the indicator data corresponding to the sales volume of commodity B is read, and the obtained indicator data is subjected to abnormal detection to obtain the indicator abnormal parameters and calculate the contribution degree of the indicator data to the abnormal parameters, so as to obtain the corresponding parsing and processing result, and use the obtained parsing and processing result, the graph indicator, and the indicator data as the knowledge extraction result.

[0056] It should be noted that the process of parsing and processing the second indicator data, the data to be detected, and the abnormal parameters can be replaced according to the actual processing needs: parsing and processing the second indicator data and the data to be detected to obtain a parsing and processing result; correspondingly, parsing and processing the second indicator data and the data to be detected to obtain a parsing and processing result, including: performing abnormal detection on the second indicator data to obtain the indicator abnormal parameters of the second indicator data.

[0057] (3)Indicator knowledge modality During the specific execution process, in order to improve the reliability of the knowledge extraction result of multi-modal knowledge extraction and enhance the adaptability of multi-modal knowledge extraction by adjusting the processing direction of multi-modal knowledge extraction based on the specific application scenario, multi-modal knowledge extraction can be performed on the data to be detected and the abnormal parameters based on the indicator knowledge. In an optional implementation manner provided in this embodiment, multi-modal knowledge extraction based on the data to be detected and the abnormal parameters includes: Matching the data to be detected with the knowledge records in the knowledge base to obtain the target knowledge record matched by the data to be detected; Reading the third indicator data corresponding to the knowledge indicator from the database according to the knowledge indicator included in the target knowledge record; Parsing the third indicator data, the data to be detected, and the abnormal parameters, and taking the parsing and processing result, the target knowledge record, and the third indicator data as the knowledge extraction result.

[0058] The third indicator data refers to the data related to the knowledge indicator read from the database, that is, the third indicator data can be knowledge indicator data, such as the detailed data of the knowledge indicator obtained from the database, or the indicator data of the knowledge indicator. Here, the third indicator data can be replaced by: knowledge indicator data; where the knowledge indicator refers to the indicator related to the application scenario of the data to be detected determined in the knowledge record; the knowledge record refers to the record related to the application scenario data of the data to be detected and / or the attribution example.

[0059] Furthermore, during the process of parsing and processing the third indicator data, the data to be detected, and the abnormal parameters, it is also possible to start from one or more of the three processing dimensions of abnormal detection of the third indicator data, statistical processing of the third indicator data, and abnormal contribution of the third indicator data, and perform parsing and processing on the third indicator data, the data to be detected, and the abnormal parameters to obtain a parsing and processing result; In an optional implementation manner provided in this embodiment, parsing the third indicator data, the data to be detected, and the abnormal parameters includes: Performing abnormal detection on the third indicator data to obtain the indicator abnormal parameters of the third indicator data, performing statistical calculation of the indicator statistical algorithm according to the data to be detected and the third indicator data to obtain indicator statistical data, and / or calculating the contribution degree of each third indicator data to the abnormal parameters.

[0060] Correspondingly, the analysis and processing results include abnormal parameter of the index, index statistical data, and / or contribution degree.

[0061] For example, in the process of analyzing the sales amount of product A at a certain point in time, product information of the sales amount, daily sales amount of the product, and time information corresponding to the daily sales amount of the product are obtained from the database as index data, and the index data and the sales amount of the product at this point in time are jointly used as the data to be detected, and the abnormal decline type and abnormal level of the abnormal decline of the sales amount of the product are used as abnormal parameters; the matching of knowledge records in the database is performed on the data to be detected here to obtain the matching target knowledge record: when the sales amount of the product shows an abnormal decline, attention should be paid to the supply volume of the supply chain related to this product and the sales volume of the same type of products in competition with this product; further read the index data corresponding to the knowledge index included in the target knowledge record: the supply volume of the supplier of product A and the sales volume of competing products. Based on this, each index data, data to be detected, and abnormal parameters are analyzed to obtain the corresponding analysis and processing results, and the obtained analysis and processing results, target knowledge record, and index data are used as knowledge extraction results.

[0062] It should be noted that the process of analyzing and processing the third index data, data to be detected, and abnormal parameters can be replaced according to the actual processing needs: analyzing and processing the third index data and data to be detected to obtain the analysis and processing results; or, it can also be replaced by: analyzing and processing the third index data and abnormal parameters to obtain the analysis and processing results; Here, analyzing and processing the third index data and data to be detected to obtain the analysis and processing results includes: performing abnormal detection on the third index data to obtain the abnormal parameter of the index of the third index data, and / or performing index statistical processing on the data to be detected and the third index data to obtain index statistical data; analyzing and processing the third index data and abnormal parameters to obtain the analysis and processing results includes: performing abnormal detection on the third index data to obtain the abnormal parameter of the index of the third index data, and / or calculating the contribution degree of each third index data to the abnormal parameter.

[0063] (4) Abnormal index modality In the specific implementation process, in order to improve the efficiency of multi-modal knowledge extraction, data indicators that have a greater impact on the knowledge extraction results can be determined and the determined data indicators can be further analyzed. Multi-modal knowledge extraction can be performed on the data to be detected and abnormal parameters based on the characteristics of the indicators. In an optional implementation manner provided in this embodiment, multi-modal knowledge extraction based on the data to be detected and abnormal parameters includes: Invoking the abnormal attribution interface to perform abnormal attribution processing on the data to be detected and abnormal parameters to obtain the abnormal attribution result; Extract the fourth indicator data corresponding to the anomaly indicator from the database based on the anomaly indicator included in the anomaly attribution result; Parse the fourth indicator data, the data to be detected, and the anomaly parameter, and use the parsing result, the anomaly attribution result, and the fourth indicator data as the knowledge extraction result.

[0064] The fourth indicator data refers to the data related to the anomaly indicator read from the database, that is, the fourth indicator data can be the anomaly indicator data. For example, the detailed data of the anomaly indicator obtained from the database, or the indicator data of the anomaly indicator. Here, the fourth indicator data can be replaced by: the anomaly indicator data; among them, the anomaly indicator refers to the indicator used in the anomaly attribution result to describe the degree to which the data to be detected deviates from the preset range.

[0065] Furthermore, during the process of parsing the fourth indicator data, the data to be detected, and the anomaly parameter, it is also possible to start from one or more of the three processing dimensions of anomaly detection of the fourth indicator data, statistical processing of the fourth indicator data, and anomaly contribution of the fourth indicator data, and perform parsing processing on the fourth indicator data, the data to be detected, and the anomaly parameter to obtain the parsing result; in an optional implementation manner provided in this embodiment, parsing the fourth indicator data, the data to be detected, and the anomaly parameter includes: Perform anomaly detection on the fourth indicator data to obtain the indicator anomaly parameter of the fourth indicator data, perform statistical calculation of the indicator statistical algorithm based on the data to be detected and the fourth indicator data to obtain the indicator statistical data, and / or calculate the contribution degree of each fourth indicator data to the anomaly parameter.

[0066] Correspondingly, the parsing result includes the indicator anomaly parameter, the indicator statistical data, and / or the contribution degree.

[0067] For example, in the process of analyzing the commodity sales amount of commodity A at a certain time point, obtain the commodity information of the commodity sales amount, the daily commodity sales amount, and the time information corresponding to the daily commodity sales amount from the database as the indicator data, and use the indicator data and the commodity sales amount at this time point as the data to be detected, and use the anomaly decline type and anomaly level of the abnormal decline of the commodity sales amount as the anomaly parameter; the anomaly attribution result obtained by performing anomaly attribution processing on the data to be detected and the anomaly parameter is: the reduction in the supply volume of the supplier of commodity A and the decrease in the purchase volume of customers for commodity A are the main factors. Further, obtain the indicator data corresponding to the anomaly indicator included in the anomaly attribution result: the supply volume data of the supplier of commodity A and the purchase volume data of customers for commodity A within a certain period of time before and after this time point. Based on this, parse each indicator data, the data to be detected, and the anomaly parameter to obtain the corresponding parsing result, and use the obtained parsing result, the anomaly attribution result, and the indicator data as the knowledge extraction result.

[0068] It should be noted that the process of parsing and processing the fourth index data, the data to be detected, and the abnormal parameters can be replaced according to the actual processing needs as follows: parsing and processing the fourth index data and the data to be detected to obtain a parsing and processing result; or, it can also be replaced by: parsing and processing the fourth index data and the abnormal parameters to obtain a parsing and processing result; Here, parsing and processing the fourth index data and the data to be detected to obtain a parsing and processing result includes: performing anomaly detection on the fourth index data to obtain the index anomaly parameters of the fourth index data, and / or performing index statistical processing on the data to be detected and the fourth index data to obtain index statistical data; parsing and processing the fourth index data and the abnormal parameters to obtain a parsing and processing result includes: performing anomaly detection on the fourth index data to obtain the index anomaly parameters of the fourth index data, and / or calculating the contribution degree of each fourth index data to the abnormal parameters.

[0069] (5)Additional data extraction mode In the specific execution process, in order to improve the comprehensiveness of multi-modal knowledge extraction, so that the knowledge extraction result can consider the uniqueness of a specific application scenario and make the knowledge extraction result more in line with the actual situation, multi-modal knowledge extraction can be performed on the data to be detected and the abnormal parameters based on additional data. In an optional implementation manner provided in this embodiment, multi-modal knowledge extraction based on the data to be detected and the abnormal parameters further includes: Obtaining an anomaly attribution example matching the data to be detected, and / or reading the application scenario data of the data to be detected.

[0070] Correspondingly, the knowledge extraction result includes the anomaly attribution example, and / or the application scenario data.

[0071] Among them, the anomaly attribution example refers to the analysis data for the data anomaly situation and the data anomaly situation. Specifically, the anomaly attribution example can be the anomaly situation and the analysis data similar to the current data to be detected.

[0072] For example, in the process of analyzing the overdue rate of a certain credit installment platform at a certain time point, platform information, product details, overdue days corresponding to the overdue rate, and time information corresponding to the overdue rate are obtained from the database as index data, and the index data and the overdue rate at this time point are jointly used as the data to be detected. For the obtained data to be detected, on the one hand, an anomaly attribution example for the data anomaly situation and the data anomaly situation matching the data to be detected is obtained, and on the other hand, the data generated or used in the specific application scenario for the data to be detected is obtained. Based on this, the obtained anomaly attribution example and the data of the application scenario are used as the knowledge extraction result.

[0073] It should be noted that for the implementation method of multi-modal knowledge extraction based on the data to be detected and abnormal parameters, one or all of them can be selected for implementation according to actual needs in the specific implementation process. For example, multi-modal knowledge extraction based on the data to be detected and abnormal parameters includes: obtaining abnormal attribution examples matching the data to be detected; or, multi-modal knowledge extraction based on the data to be detected and abnormal parameters includes: reading the application scenario data of the data to be detected; or, multi-modal knowledge extraction based on the data to be detected and abnormal parameters includes: obtaining abnormal attribution examples matching the data to be detected, and reading the application scenario data of the data to be detected.

[0074] It should be pointed out that the multi-modal knowledge extraction process of the additional data extraction mode can be combined with any one of the implementation methods of the above four data extraction modes, namely the index statistics mode, the index graph mode, the index experience mode, and the index feature mode, to form a new multi-modal knowledge extraction process. For example, the index statistics mode and the additional data extraction mode can be combined, and the index graph mode and the additional data extraction mode can also be combined. This embodiment does not make any limitations here.

[0075] In addition, the multi-modal knowledge extraction processes under the above five data extraction modes can be combined in any way according to actual needs. For example, any two, any three, or any four of them can be combined, or all five can be combined; or, in the actual application scenario, the implementation methods of combining any two, any three, or any four can also be adaptively adjusted, or the implementation method of combining all five can also be adaptively adjusted; For example, multi-modal knowledge extraction based on the data to be detected and abnormal parameters includes: reading the first index data corresponding to the algorithm index from the database according to the algorithm index included in the index statistical algorithm of the data to be detected; determining the graph index associated with the data index included in the data to be detected in the index relationship graph, and reading the second index data corresponding to the graph index from the database; parsing the first index data, the second index data, the data to be detected, and the abnormal parameters, and taking the parsing result, the graph index, the first index data, and the second index data as the knowledge extraction result.

[0076] Another example, multi-modal knowledge extraction based on the data to be detected and abnormal parameters includes: determining the graph index associated with the data index included in the data to be detected in the index relationship graph, and reading the second index data corresponding to the graph index from the database; parsing the second index data, the data to be detected, and the abnormal parameters; reading the application scenario data of the data to be detected; taking the parsing result, the graph index, the second index data, and the application scenario data as the knowledge extraction result.

[0077] For another example, multi-modal knowledge extraction is performed based on the data to be detected and abnormal parameters, including: matching the data to be detected with the knowledge records in the knowledge base to obtain the target knowledge records matched by the data to be detected; reading the third index data corresponding to the knowledge index from the database according to the knowledge index included in the target knowledge records; calling the abnormal attribution interface to perform abnormal attribution processing on the data to be detected and the abnormal parameters to obtain an abnormal attribution result; extracting the fourth index data corresponding to the abnormal index from the database based on the abnormal index included in the abnormal attribution result; parsing the third index data, the fourth index data, the data to be detected, and the abnormal parameters, and using the parsing result, the target knowledge record, the abnormal attribution result, the third index data, and the fourth index data as the knowledge extraction result.

[0078] In specific implementation, the knowledge extraction result obtained by performing multi-modal knowledge extraction based on the data to be detected and the abnormal parameters is specifically the knowledge data related to the data to be detected and / or the knowledge data related to the data anomaly parsing of the data to be detected obtained in one or more modalities. Subsequently, a large language model is used to perform data anomaly parsing on the data to be detected. Since the large language model is a natural language model, in order to enable the large language model to more fully understand the input content of the large language model, here, the knowledge extraction result is text-converted to obtain knowledge text, thereby converting the knowledge extraction result into a natural language text that the subsequent large language model can understand, that is: the knowledge text refers to the text composed of natural language after natural language conversion of the knowledge extraction result.

[0079] For example, in the scenario of performing multi-modal knowledge extraction on the combination of the index graph modality and the additional data extraction modality and obtaining the corresponding knowledge extraction result, before inputting the obtained knowledge extraction result into the large language model, for the obtained knowledge extraction result of the multi-modal knowledge extraction, the knowledge extraction result is naturally language-converted through a text conversion mechanism to convert the knowledge extraction result into a text that the large language model can perform semantic recognition on, that is, converting the knowledge extraction result into a natural language text described by natural language.

[0080] Step S206, construct an anomaly parsing text based on the knowledge text and the anomaly parsing prompt template corresponding to the data to be detected.

[0081] In this embodiment, in the scenario of performing anomaly detection processing on the data to be detected, the subsequent data anomaly parsing of the data to be detected is performed by a large language model. Here, based on performing multi-modal knowledge extraction according to the data to be detected and the abnormal parameters and text-converting the knowledge extraction result to obtain knowledge text, starting from the obtained knowledge text and the anomaly parsing prompt template of the large language model, the input text of the large language model is constructed, that is, the anomaly parsing text input into the large language model for subsequent data anomaly parsing processing.

[0082] In specific implementation, during the process of multi-modal knowledge extraction based on the data to be detected and abnormal parameters, knowledge data of the data to be detected is extracted from one or more modalities. There may be multiple pieces of multi-modal knowledge obtained by extraction, and correspondingly, there may also be multiple pieces of knowledge text obtained by text conversion of the knowledge extraction results. Moreover, the multi-modal knowledge extracted from multiple modalities may be repetitive. Therefore, in order to improve data processing efficiency, after text conversion of the knowledge extraction results to obtain knowledge text, the knowledge text can be further filtered to obtain target knowledge text, and the abnormal analysis text can be constructed based on the filtered target knowledge text during the construction process.

[0083] In addition, in the subsequent case of using a large language model to perform data anomaly detection on the data to be detected, in order to improve the accuracy of the data anomaly detection performed by the large language model on the data to be detected, the knowledge text can also be converted. Specifically, the knowledge text is converted into conditions, such as converting the knowledge text into conditions for data detection using the attribution analysis method, so that the large language model can use the attribution analysis method to perform more in-depth and accurate data anomaly analysis on the data to be detected.

[0084] In a specific execution process, in an optional implementation manner provided in this embodiment, constructing an abnormal analysis text based on the knowledge text and the abnormal analysis prompt template corresponding to the data to be detected includes: Filtering the knowledge text to obtain target knowledge text; Performing conditional conversion on the target knowledge text according to a preset conversion protocol to obtain a conversion text, and writing the conversion text into the abnormal analysis prompt template to obtain the abnormal analysis text.

[0085] Among them, the target knowledge text refers to the knowledge text obtained by filtering the knowledge text; the conversion text refers to the text generated by performing conditional conversion on the knowledge text according to a preset conversion protocol. For example, the knowledge text can be standardized to obtain the conversion text; the abnormal analysis prompt template refers to the text template for constructing the input text of the large language model. Correspondingly, the abnormal analysis text refers to the text obtained by writing the conversion text into the abnormal analysis prompt template.

[0086] For example, during the process of filtering the knowledge text to obtain target knowledge text, the knowledge text can be sorted based on deterministic knowledge data to obtain the target knowledge text; during the process of performing conditional conversion on the target knowledge text, the target knowledge text can be standardized according to the preset conversion protocol. For example, the key information in the target knowledge text can be converted into standard conditional statements according to the preset conversion protocol; finally, the conversion text is written into the abnormal analysis prompt template to obtain the corresponding abnormal analysis text.

[0087] To enable merchants or operators conducting data anomaly detection to more clearly understand the anomaly situation of the data to be detected, it can also be required that the large language model can perform data anomaly analysis in a chain-of-thought manner and output the analysis process information of performing data anomaly analysis in a chain-of-thought manner. On this basis, through the analysis process information of performing data anomaly analysis in a chain-of-thought manner, merchants or operators can more clearly and comprehensively learn the reasons and situations of data anomalies, thus helping merchants or operators make operation decisions.

[0088] In this embodiment, the anomaly analysis prompt template refers to the text template for constructing the input text of the large language model. To enable the large language model to perform data anomaly analysis in a chain-of-thought manner and output the corresponding process information, a task prompt for performing data anomaly analysis in a chain-of-thought manner can be set in the anomaly analysis prompt template, and a task prompt for outputting the analysis process information of performing data anomaly analysis in a chain-of-thought manner can be further set.

[0089] Optionally, the anomaly analysis prompt template includes a task prompt for performing data anomaly analysis in a chain-of-thought manner and a task prompt for outputting the analysis process information of performing data anomaly analysis in a chain-of-thought manner; correspondingly, the anomaly analysis text includes a task prompt for performing data anomaly analysis in a chain-of-thought manner.

[0090] In addition, to enable merchants or operators conducting data anomaly detection to more quickly and comprehensively master the anomaly situation of the data to be detected, it can also be required that the large language model can perform data anomaly analysis in a zero-shot learning manner and output the analysis process information of performing data anomaly analysis in a zero-shot learning manner. On this basis, through the analysis process information of performing data anomaly analysis in a zero-shot learning manner, merchants or operators can more quickly and flexibly respond to various sudden data anomaly reasons and situations, thus helping merchants or operators make operation decisions.

[0091] Optionally, the anomaly analysis prompt template includes a zero-shot learning prompt for performing data anomaly analysis in a zero-shot learning manner; correspondingly, the anomaly analysis text includes a zero-shot learning prompt for performing data anomaly analysis in a zero-shot learning manner.

[0092] Step S208, input the anomaly analysis text into the large language model for data anomaly analysis to obtain an anomaly analysis processing result and analysis process information.

[0093] In the scenario of performing anomaly detection on the data to be detected, an anomaly parsing text is constructed based on the knowledge text and the anomaly parsing prompt template corresponding to the data to be detected. Here, on the basis of performing conditional conversion on the target knowledge text to obtain a converted text and writing the converted text into the anomaly parsing prompt template to obtain the anomaly parsing text, the anomaly parsing text is input into a large language model for data anomaly parsing, and a data anomaly parsing result is obtained.

[0094] In specific implementation, on the basis of performing conditional conversion on the target knowledge text to obtain a converted text and writing the converted text into the anomaly parsing prompt template to obtain the anomaly parsing text, in order to improve the processing efficiency, accuracy, and comprehensiveness of the anomaly parsing text, the obtained anomaly parsing text is input into a large language model for data anomaly parsing, and data anomaly detection is performed on the data to be detected based on the anomaly parsing result of the data anomaly parsing, and an anomaly parsing result and parsing process information are obtained.

[0095] Optionally, the anomaly parsing result includes the determination content of the anomaly determination reason of the data to be detected, the parsing description of the data to be detected, and / or the parsing process information; specifically, the content of the anomaly parsing result can be any one or more of the determination content of the anomaly determination reason of the data to be detected, the parsing description of the data to be detected, and the parsing process information.

[0096] For example, in the scenario of a merchant accessing a data display control, Figure 3 in the data display control of the merchant shown, the display process of the anomaly parsing result 302 can be performed on the data display control accessed by the merchant; in the scenario of dialogue interaction, Figure 4 in the dialogue interface shown, the display process of the anomaly parsing result 401 can be performed on the dialogue interface.

[0097] In the specific execution process, on the basis of performing conditional conversion on the target knowledge text according to the preset conversion protocol to obtain a converted text and writing the converted text into the anomaly parsing prompt template to obtain the anomaly parsing text, after the anomaly parsing text is input into the large language model, during the process of the large language model performing data anomaly parsing, semantic recognition can be performed on the converted text, and semantic recognition can be performed on the processing prompts in the anomaly parsing text to obtain a semantic recognition result, and data anomaly parsing is performed on the data to be detected based on the semantic recognition result in combination with the parsing conditions in the converted text, and an anomaly parsing result and parsing process information are obtained, that is: data anomaly parsing includes: performing semantic recognition on the converted text, performing semantic recognition on the processing prompts in the anomaly parsing text, and performing data anomaly parsing based on the semantic recognition result and the parsing conditions in the converted text.

[0098] In addition, the anomaly parsing prompt template includes a task prompt for data anomaly parsing using the chain of thought method, and a task prompt for outputting the parsing process information of data anomaly parsing using the chain of thought method. When constructing the anomaly parsing text based on the knowledge text and the anomaly parsing prompt template corresponding to the data to be detected, it also includes a task prompt for data anomaly parsing using the chain of thought method and a task prompt for outputting the parsing process information of data anomaly parsing using the chain of thought method. Based on this, after inputting the anomaly parsing text into the large language model, the large language model uses the chain of thought method to perform data anomaly parsing on the data to be detected, obtains the anomaly parsing processing result, and outputs the anomaly parsing processing result and the parsing process information of data anomaly parsing using the chain of thought method according to the task prompt for outputting the parsing process information of data anomaly parsing using the chain of thought method, that is: data anomaly parsing includes: using the chain of thought method to perform data anomaly parsing on the data to be detected, obtaining the anomaly parsing processing result, and outputting the anomaly parsing processing result and the parsing process information according to the task prompt.

[0099] The large language model described in this embodiment refers to a pre-trained natural language model. The large language model can use the foundation model, and can also use the pre-trained model. The specific architecture of the large language model can be a neural network architecture with a large number of parameters, a Transform architecture, or other architectures. In the specific execution process, the large language model can directly use the foundation model or the pre-trained model, or can fine-tune (Supervised Fine-Tuning, SFT) the foundation model or the pre-trained model for the specific task of data anomaly parsing on the basis of the foundation model or the pre-trained model, and thus obtain a large language model that can handle the specific task of data anomaly parsing.

[0100] In practical applications, in order to enable merchants or operators performing data anomaly detection to more clearly understand the anomaly situation of the data to be detected, a task prompt for outputting the reasoning logic of the anomaly determination reason can also be configured in the anomaly parsing prompt template; on this basis, after the large language model performs data anomaly parsing on the data to be detected and obtains the anomaly parsing processing result, according to the task prompt for outputting the reasoning logic of the anomaly determination reason, it outputs the anomaly parsing processing result and the parsing process information including the reasoning logic of the anomaly determination reason, that is: outputting the determination content of the anomaly determination reason of the data to be detected, the parsing description of the data to be detected, and / or the reasoning logic of the anomaly determination reason; In addition, in practical applications, a task prompt for configuring a reference basis for outputting the reason for abnormal determination can also be set in the abnormal parsing prompt template. On this basis, after the large language model performs data abnormal parsing on the data to be detected and obtains the abnormal parsing processing result, according to the task prompt for outputting the reference basis for the reason for abnormal determination, the abnormal parsing processing result and the parsing process information including the reference basis for the reason for abnormal determination are output, that is: the determination content of the reason for abnormal determination of the data to be detected, the parsing description of the data to be detected, and / or the reference basis for the reason for abnormal determination; On this basis, after the large language model performs data abnormal parsing on the data to be detected and obtains the abnormal parsing processing result, it can also output the abnormal parsing processing result and the reasoning logic and / or reference basis including the reason for abnormal determination according to the task prompt for outputting the reasoning logic and / or reference basis for the reason for abnormal determination, that is: output the determination content of the reason for abnormal determination of the data to be detected, the parsing description of the data to be detected, the reasoning logic and / or reference basis for the reason for abnormal determination; It should be noted that the abnormal parsing prompt template includes a task prompt for performing data abnormal parsing in a chain-of-thought manner, a task prompt for outputting the parsing process information of performing data abnormal parsing in a chain-of-thought manner, and a task prompt for configuring the reasoning logic and / or reference basis for outputting the reason for abnormal determination can also be set in the abnormal parsing prompt template. In this case, after the large language model performs data abnormal parsing on the data to be detected and obtains the abnormal parsing processing result, it can also output at least one of the abnormal parsing processing result, the parsing process information of performing data abnormal parsing in a chain-of-thought manner, that is, the reasoning logic and / or reference basis for the reason for abnormal determination of performing data abnormal parsing in a chain-of-thought manner.

[0101] In summary, for the data anomaly detection and processing method provided in this embodiment, first, the data to be detected that triggers anomaly detection is obtained. Based on the obtained data to be detected, anomaly detection is performed on the data to be detected to obtain anomaly parameters. Secondly, in order to improve the accuracy and comprehensiveness of anomaly analysis for the data to be detected, knowledge extraction is performed from multiple modalities according to the data to be detected and the anomaly parameters to obtain a knowledge extraction result, and the knowledge extraction result is converted into a knowledge text through text conversion, so as to convert the knowledge extraction result into a natural language text that can be understood by the subsequent large language model. Then, starting from the obtained knowledge text and the anomaly analysis prompt template of the large language model, an anomaly analysis text is constructed based on the knowledge text and the anomaly analysis prompt template corresponding to the data to be detected. After that, in order to improve the processing efficiency, accuracy, and comprehensiveness of the anomaly analysis text, the obtained anomaly analysis text is input into the large language model for data anomaly analysis, and data anomaly detection is performed on the data to be detected based on the anomaly analysis processing result of the data anomaly analysis, obtaining an anomaly analysis processing result and parsing process information, so as to perform more comprehensive anomaly detection on the data to be detected through the large language model based on knowledge extraction.

[0102] Further, in the process of multi-modal knowledge extraction according to the data to be detected and the anomaly parameters, a knowledge extraction strategy is determined according to the data to be detected and the anomaly parameters, and index data is extracted from the database according to the knowledge extraction strategy. Moreover, based on the obtained index data, the index data, the data to be detected, and the anomaly parameters can be subjected to parsing processing, so as to parse the data to be detected in the process of multi-modal knowledge extraction. On this basis, the parsing processing result and the index data are provided to the subsequent process of anomaly analysis for the data to be detected, which can improve the depth of anomaly detection for the data to be detected.

[0103] Further, after extracting the index data from the database according to the knowledge extraction strategy, the index data, the data to be detected, and the anomaly parameters are subjected to parsing processing. Specifically, anomaly detection is performed on the index data to obtain the index anomaly parameters of the index data, index statistical processing is performed according to the data to be detected and the index data to obtain index statistical data, and / or the contribution degree of each index data to the anomaly parameters is calculated, so as to further improve the comprehensiveness of the parsing processing process provided to the subsequent process of anomaly analysis for the data to be detected, thereby helping to improve the accuracy of the subsequent process of anomaly analysis for the data to be detected.

[0104] The following takes the application of the data anomaly detection and processing method provided in this embodiment in the scenario of merchant data anomaly detection and processing as an example, combined with Figure 5 to further illustrate the data anomaly detection and processing method provided in this embodiment. See Figure 5 The data anomaly detection and processing method applied to the scenario of merchant data anomaly detection and processing specifically includes the following steps.

[0105] Step S502: Extract the data tags in the conversation content input by the merchant in the conversation interface.

[0106] Step S504: Read the merchant data corresponding to the data tags from the database as the data to be detected.

[0107] Step S506: Call multiple data detection interfaces to perform anomaly detection on the data to be detected, and obtain the anomaly detection results returned by each data detection interface.

[0108] Step S508: Determine the anomaly type and anomaly level of the data to be detected according to the returned anomaly detection results.

[0109] Step S510: Determine the graph metrics associated with the data metrics included in the data to be detected in the metric relationship graph, and read the graph metric data corresponding to the graph metrics from the database.

[0110] Step S512: Parse the graph metric data, the data to be detected, and the anomaly parameters to obtain the parsing processing results.

[0111] Step S514: Obtain the anomaly attribution examples matching the data to be detected.

[0112] Step S516: Read the application scenario data of the data to be detected.

[0113] Step S518: Determine the knowledge extraction results based on the parsing processing results, graph metrics, graph metric data, anomaly attribution examples, and application scenario data.

[0114] Step S520: Perform text conversion on the knowledge extraction results to obtain knowledge text.

[0115] Step S522: Construct an anomaly parsing text based on the knowledge text and the anomaly parsing prompt template corresponding to the data to be detected.

[0116] Step S524: Input the anomaly parsing text into a large language model for data anomaly parsing, and obtain the anomaly parsing processing results and parsing process information.

[0117] Step S526: Send the anomaly parsing processing results and parsing process information to the merchant for display processing of the anomaly parsing processing results and parsing process information in the conversation interface.

[0118] It should be noted that the multi-modal knowledge extraction process corresponding to the above steps S510 to S518 can be replaced by other steps according to actual needs during implementation. For example, it can be replaced by: reading the algorithm index data corresponding to the algorithm index from the database according to the algorithm indexes included in the index statistical algorithm of the data to be detected; parsing the algorithm index data, the data to be detected, and the abnormal parameters, and taking the parsing result, the index statistical algorithm, and the algorithm index data as the knowledge extraction result; or, it can be replaced by: determining the graph indexes associated with the data indexes included in the data to be detected in the index relationship graph, and reading the graph index data corresponding to the graph indexes from the database; parsing the graph index data, the data to be detected, and the abnormal parameters, and taking the parsing result, the graph indexes, and the graph index data as the knowledge extraction result; or, it can also be replaced by: matching the data to be detected with the knowledge records in the knowledge base to obtain the target knowledge records matched by the data to be detected; reading the knowledge index data corresponding to the knowledge indexes from the database according to the knowledge indexes included in the target knowledge records; parsing the knowledge index data, the data to be detected, and the abnormal parameters, and taking the parsing result, the target knowledge records, and the knowledge index data as the knowledge extraction result; or, it can also be replaced by: calling the abnormal attribution interface to perform abnormal attribution processing on the data to be detected and the abnormal parameters to obtain the abnormal attribution result; extracting the abnormal index data corresponding to the abnormal indexes from the database based on the abnormal indexes included in the abnormal attribution result; parsing the abnormal index data, the data to be detected, and the abnormal parameters, and taking the parsing result, the abnormal attribution result, and the abnormal index data as the knowledge extraction result; in addition, it can also be replaced by: obtaining the abnormal attribution examples matched by the data to be detected, and / or, reading the application scenario data of the data to be detected; determining the abnormal attribution examples and / or the application scenario data as the knowledge extraction result.

[0119] In addition, the above five multi-modal knowledge extraction processes can be combined in any way according to actual needs. For example, any two, any three, or any four of them can be combined, and all five can also be combined; or, in the actual application scenario, the implementation methods of combining any two, any three, or any four of them can also be adaptively adjusted, or, the implementation method of combining all five can also be adaptively adjusted.

[0120] It should be noted that any one step or any combination of steps from step S502 to step S526 can be combined with any one step or any combination of steps from the above-mentioned step S202 to step S208 according to the needs of implementation and deployment to form a new implementation method; in addition, according to the actual deployment needs, any one or any combination of technical features can be selected from step S502 to step S526 and combined with any one or more technical features provided by the above-mentioned step S202 to step S208 to form a new implementation method; or, any one or any combination of technical features in step S502 to step S526 can also be replaced by any one or more technical feature combinations provided by the above-mentioned step S202 to step S208 according to the actual deployment needs to form a new implementation method, which will not be elaborated here one by one.

[0121] The following takes the application of a data anomaly detection and processing method provided in this embodiment in the operation data anomaly detection and processing scenario as an example, and combines Figure 6 to further illustrate the data anomaly detection and processing method provided in this embodiment. See Figure 6 The data anomaly detection and processing method applied to the operation data anomaly detection and processing scenario specifically includes the following steps.

[0122] Step S602, obtain the target operation data selected by the operation personnel from the operation data displayed in the data display control.

[0123] Step S604, read the index data of the target operation data, and use the target operation data and the index data as the data to be detected.

[0124] Step S606, call multiple data detection interfaces to perform anomaly detection on the data to be detected, and obtain the anomaly detection results returned by each data detection interface.

[0125] Step S608, determine the anomaly type and anomaly level of the data to be detected according to the returned anomaly detection results.

[0126] Step S610, match the data to be detected with the knowledge records in the knowledge base to obtain the target knowledge records matched by the data to be detected.

[0127] Step S612, read the knowledge index data corresponding to the knowledge index from the database according to the knowledge index included in the target knowledge record.

[0128] Step S614, parse the knowledge index data, the data to be detected and the anomaly parameters, and use the parsing result, the target knowledge record and the knowledge index data as the knowledge extraction result.

[0129] Step S616, perform text conversion on the knowledge extraction result to obtain the knowledge text.

[0130] Step S618: Construct an anomaly parsing text based on the knowledge text and the anomaly parsing prompt template corresponding to the data to be detected.

[0131] Step S620: Input the anomaly parsing text into a large language model for data anomaly parsing to obtain an anomaly parsing processing result and parsing process information.

[0132] Step S622: Perform display processing on the anomaly parsing processing result and parsing process information in the data display control accessed by the operator.

[0133] It should be noted that the multi-modal knowledge extraction process corresponding to the above steps S610 to S614 can be replaced by other steps according to actual needs during implementation. For example, it can be replaced by: Reading the algorithm index data corresponding to the algorithm index from the database according to the algorithm index included in the index statistical algorithm of the data to be detected; Parsing the algorithm index data, the data to be detected, and the anomaly parameters, and taking the parsing processing result, the index statistical algorithm, and the algorithm index data as the knowledge extraction result; Or, it can be replaced by: Determining the graph index associated with the data index included in the data to be detected in the index relationship graph, and reading the graph index data corresponding to the graph index from the database; Parsing the graph index data, the data to be detected, and the anomaly parameters, and taking the parsing processing result, the graph index, and the graph index data as the knowledge extraction result; Or, it can also be replaced by: Invoking an anomaly attribution interface to perform anomaly attribution processing on the data to be detected and the anomaly parameters to obtain an anomaly attribution result; Extracting the anomaly index data corresponding to the anomaly index from the database based on the anomaly index included in the anomaly attribution result; Parsing the anomaly index data, the data to be detected, and the anomaly parameters, and taking the parsing processing result, the anomaly attribution result, and the anomaly index data as the knowledge extraction result; In addition, it can also be replaced by: Obtaining an anomaly attribution example matched by the data to be detected, and / or reading the application scenario data of the data to be detected; Determining the anomaly attribution example and / or the application scenario data as the knowledge extraction result.

[0134] In addition, the above five multi-modal knowledge extraction processes can be combined in any way according to actual needs. For example, any two, any three, or any four of them can be combined, or all five can be combined; Or, in the actual application scenario, the implementation methods of combining any two, any three, or any four can also be adaptively adjusted, or the implementation method of combining all five can also be adaptively adjusted.

[0135] It should be noted that any one or any combination of steps from step S602 to step S622 can be combined with any one or any combination of steps from the above-mentioned step S202 to step S208 according to the needs of implementation and deployment to form a new implementation method; in addition, according to the actual deployment needs, any one or any combination of technical features can be selected from step S602 to step S622 and combined with any one or more technical features provided in the above-mentioned step S202 to step S208 to form a new implementation method; or, any one or any combination of technical features in step S602 to step S622 can also be replaced by any one or more technical feature combinations provided in the above-mentioned step S202 to step S208 according to the actual deployment needs to form a new implementation method, which will not be elaborated here one by one.

[0136] An embodiment of a data anomaly detection and processing device provided in this specification is as follows: In the above embodiment, a data anomaly detection and processing method is provided. Correspondingly, a data anomaly detection and processing device is also provided, which will be described below with reference to the accompanying drawings.

[0137] Refer to Figure 7 , which shows a schematic diagram of an embodiment of a data anomaly detection and processing device provided in this embodiment.

[0138] Since the device embodiment corresponds to the method embodiment, the description is relatively simple. For the relevant parts, please refer to the corresponding description of the method embodiment provided above. The device embodiments described below are merely illustrative.

[0139] This embodiment provides a data anomaly detection and processing device, and the device includes: Anomaly detection module 702, configured to obtain the data to be detected that triggers anomaly detection, and perform anomaly detection on the data to be detected to obtain anomaly parameters; Knowledge extraction module 704, configured to perform multimodal knowledge extraction according to the data to be detected and the anomaly parameters, and perform text conversion on the knowledge extraction result to obtain a knowledge text; Text construction module 706, configured to construct an anomaly analysis text based on the knowledge text and the anomaly analysis prompt template corresponding to the data to be detected; Anomaly analysis module 708, configured to input the anomaly analysis text into a large language model for data anomaly analysis to obtain an anomaly analysis processing result and analysis process information.

[0140] An embodiment of a data anomaly detection and processing device provided in this specification is as follows: Corresponding to the data anomaly detection and processing method described above, based on the same technical concept, one or more embodiments of this specification also provide a data anomaly detection and processing device, which is used to execute the data anomaly detection and processing method provided above. Figure 8 It is a schematic structural diagram of a data anomaly detection and processing device provided by one or more embodiments of this specification.

[0141] A data anomaly detection and processing device provided in this embodiment includes: As Figure 8 shown, the data anomaly detection and processing device may have relatively large differences due to configuration or performance, and may include one or more processors 801 and a memory 802. One or more application programs or data may be stored in the memory 802. Among them, the memory 802 may be short-term storage or persistent storage. The application programs stored in the memory 802 may include one or more modules (not shown in the figure), and each module may include a series of computer-executable instructions in the data anomaly detection and processing device. Further, the processor 801 may be set to communicate with the memory 802 and execute a series of computer-executable instructions in the memory 802 on the data anomaly detection and processing device. The data anomaly detection and processing device may also include one or more power supplies 803, one or more wired or wireless network interfaces 804, one or more input / output interfaces 805, one or more keyboards 806, etc.

[0142] In a specific embodiment, the data anomaly detection and processing device includes a memory and one or more programs, where one or more programs are stored in the memory, and one or more programs may include one or more modules, and each module may include a series of computer-executable instructions in the data anomaly detection and processing device, and is configured to be executed by one or more processors. The one or more programs include the following computer-executable instructions: Obtain the data to be detected that triggers anomaly detection, and perform anomaly detection on the data to be detected to obtain anomaly parameters; Perform multi-modal knowledge extraction based on the data to be detected and the anomaly parameters, and perform text conversion on the knowledge extraction result to obtain a knowledge text; Construct an anomaly analysis text based on the knowledge text and the anomaly analysis prompt template corresponding to the data to be detected; Input the anomaly analysis text into a large language model for data anomaly analysis to obtain an anomaly analysis processing result and analysis process information.

[0143] An embodiment of a computer-readable storage medium provided by this specification is as follows: Corresponding to a data anomaly detection and processing method described above, based on the same technical concept, one or more embodiments of this specification also provide a computer-readable storage medium.

[0144] The computer-readable storage medium provided in this embodiment is used to store computer-executable instructions, and when the computer-executable instructions are executed, the following processes are implemented: Obtain the data to be detected that triggers anomaly detection, and perform anomaly detection on the data to be detected to obtain anomaly parameters; Perform multimodal knowledge extraction based on the data to be detected and the anomaly parameters, and perform text conversion on the knowledge extraction result to obtain knowledge text; Construct an anomaly parsing text based on the knowledge text and the anomaly parsing prompt template corresponding to the data to be detected; Input the anomaly parsing text into a large language model for data anomaly parsing to obtain an anomaly parsing processing result and parsing process information.

[0145] It should be noted that the embodiment of a computer-readable storage medium in this specification and the embodiment of a data anomaly detection and processing method in this specification are based on the same inventive concept. Therefore, the specific implementation of this embodiment can refer to the implementation of the corresponding method described above, and the repeated parts will not be elaborated.

[0146] An embodiment of a computer program product provided in this specification is as follows: Corresponding to a data anomaly detection and processing method described above, based on the same technical concept, one or more embodiments of this specification also provide a computer program product.

[0147] A computer program product includes a computer program / instructions, and when the computer program / instructions are executed by a processor, the following steps are implemented: Obtain the data to be detected that triggers anomaly detection, and perform anomaly detection on the data to be detected to obtain anomaly parameters; Perform multimodal knowledge extraction based on the data to be detected and the anomaly parameters, and perform text conversion on the knowledge extraction result to obtain knowledge text; Construct an anomaly parsing text based on the knowledge text and the anomaly parsing prompt template corresponding to the data to be detected; Input the anomaly parsing text into a large language model for data anomaly parsing to obtain an anomaly parsing processing result and parsing process information.

[0148] It should be noted that the embodiment of a computer program product in this specification and the embodiment of a data anomaly detection and processing method in this specification are based on the same inventive concept. Therefore, the specific implementation of this embodiment can refer to the implementation of the corresponding method described above, and the repeated parts will not be elaborated.

[0149] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. The key point of each embodiment is to illustrate the differences from other embodiments. For example, the device embodiment, the equipment embodiment, the computer-readable storage medium embodiment, and the computer program product embodiment are all similar to the method embodiment, so the description is relatively simple. To read the relevant content in the device embodiment, the equipment embodiment, the computer-readable storage medium embodiment, and the computer program product embodiment, please refer to the corresponding part of the method embodiment for description.

[0150] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be executed in a different order from that in the embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0151] In the 1930s, it was quite obvious to distinguish whether an improvement in a technology was a hardware improvement (e.g., improvement in circuit structures such as diodes, transistors, switches, etc.) or a software improvement (improvement in method flows). However, with the development of technology, many improvements in method flows today can be regarded as direct improvements in hardware circuit structures. Almost all designers obtain the corresponding hardware circuit structures by programming the improved method flows into the hardware circuits. Therefore, it cannot be said that an improvement in a method flow cannot be implemented with hardware entity modules. For example, a programmable logic device (PLD) (e.g., a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user programming the device. Designers can program themselves to "integrate" a digital system on a piece of PLD without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called a hardware description language (HDL), and there is not only one kind of HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones currently are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that as long as the method flow is slightly logically programmed with the above-mentioned several hardware description languages and programmed into the integrated circuit, it is easy to obtain the hardware circuit that implements the logical method flow.

[0152] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that, in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to make the controller implement the same function in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, and embedded microcontrollers by logically programming the method steps. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or structures within the hardware component.

[0153] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.

[0154] For the convenience of description, when describing the above devices, they are described separately as various units according to their functions. Of course, when implementing the embodiments of this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0155] Those skilled in the art should understand that one or more embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, one or more embodiments of this specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, this specification can take the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.

[0156] This specification is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the specification. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data anomaly detection processing devices to produce a machine, such that the instructions executed by the processors of the computer or other programmable data anomaly detection processing devices produce means for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.

[0157] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data anomaly detection processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.

[0158] These computer program instructions can also be loaded onto a computer or other programmable data anomaly detection processing device, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.

[0159] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0160] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash RAM. The memory is an example of computer-readable media.

[0161] Computer-readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer-readable instructions, data structures, program modules or other data. Examples of computer-readable storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.

[0162] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of further restrictions, the elements defined by the sentence "includes at least one ..." do not exclude the presence of other identical elements in the process, method, commodity or device including the elements.

[0163] One or more embodiments of the present specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of the present specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0164] The above description is only an embodiment of this document and is not intended to limit this document. For those skilled in the art, this document may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this document should be included in the scope of the claims of this document.

Claims

1. A data anomaly detection and processing method, comprising: Acquire the data to be detected that triggers anomaly detection, and perform anomaly detection on the data to be detected to obtain anomaly parameters; Performing multimodal knowledge extraction according to the data to be detected and the abnormal parameters, and performing text conversion on the knowledge extraction result to obtain knowledge text; Constructing an abnormality analysis text based on the knowledge text and the abnormality analysis prompt template corresponding to the data to be detected; The exception analysis text is input into a large language model to perform data exception analysis, and the exception analysis processing result and analysis process information are obtained.

2. According to the data anomaly detection processing method of claim 1, the multimodal knowledge extraction based on the data to be detected and the anomaly parameters comprises: Determine a knowledge extraction strategy according to the data to be detected and the abnormal parameters, and extract indicator data from the database according to the knowledge extraction strategy; The indicator data, the data to be detected and the abnormal parameters are analyzed and processed, and the analysis results and the indicator data are used as the knowledge extraction results.

3. According to the data anomaly detection and processing method of claim 2, the parsing and processing of the indicator data, the data to be detected and the anomaly parameters comprises: Performing anomaly detection on the indicator data to obtain indicator anomaly parameters of the indicator data; Performing indicator statistical processing according to the data to be detected and the indicator data to obtain indicator statistical data; The contribution of each indicator data to the abnormal parameter is calculated; the analysis processing result includes the indicator abnormal parameter, the indicator statistical data and the contribution.

4. According to the data anomaly detection processing method of claim 1, the step of obtaining the data to be detected that triggers anomaly detection comprises: Acquire target merchant data selected by the merchant from the merchant data displayed by the data display control, and use the target merchant data and the read indicator data of the target merchant data as the data to be detected; or, The data tags in the dialogue content input by the merchant in the dialogue interface are extracted, and the merchant data corresponding to the data tags are read from the database as the data to be detected.

5. According to the data anomaly detection processing method of claim 1, the step of obtaining the data to be detected that triggers anomaly detection comprises: Obtain target operation data selected by an operation personnel from the operation data displayed by the data display control, and use the target operation data and the read indicator data of the target operation data as the data to be detected; or, The data tags in the dialogue content input by the operator in the dialogue interface are extracted, and the operation data corresponding to the data tags are read from the database as the data to be detected.

6. According to the data anomaly detection processing method of claim 1, the step of performing anomaly detection on the data to be detected to obtain anomaly parameters comprises: Calling multiple data detection interfaces to perform anomaly detection on the data to be detected, and obtaining each anomaly detection result returned by each data detection interface; The abnormality type and abnormality level of the data to be detected are determined according to the returned abnormality detection results.

7. According to the data anomaly detection processing method of claim 1, the multimodal knowledge extraction based on the data to be detected and the anomaly parameters comprises: According to the algorithm index included in the index statistical algorithm of the data to be detected, first index data corresponding to the algorithm index is read from the database; The first indicator data, the data to be detected and the abnormal parameters are analyzed, and the analysis results, the indicator statistical algorithm and the first indicator data are used as the knowledge extraction results.

8. According to the data anomaly detection and processing method of claim 7, the parsing of the first indicator data, the data to be detected and the anomaly parameter comprises: Performing anomaly detection on the first indicator data to obtain an indicator anomaly parameter of the first indicator data; Perform statistical calculation of the indicator statistical algorithm according to the data to be detected and the first indicator data to obtain indicator statistical data; Calculate the contribution of each first indicator data to the abnormal parameter; the analysis processing result includes the indicator abnormal parameter, the indicator statistical data and the contribution.

9. According to the data anomaly detection processing method of claim 1, the multimodal knowledge extraction based on the data to be detected and the anomaly parameters comprises: Determine in the indicator relationship map the map indicator associated with the data indicator contained in the data to be detected, and read the second indicator data corresponding to the map indicator from the database; The second indicator data, the data to be detected and the abnormal parameters are analyzed, and the analysis results, the graph indicators and the second indicator data are used as the knowledge extraction results.

10. According to the data anomaly detection processing method of claim 1, the multimodal knowledge extraction based on the data to be detected and the anomaly parameters comprises: Matching the data to be detected with the knowledge records in the knowledge base to obtain the target knowledge records that match the data to be detected; Reading third indicator data corresponding to the knowledge indicator from a database according to the knowledge indicator included in the target knowledge record; The third indicator data, the data to be detected and the abnormal parameters are analyzed, and the analysis results, the target knowledge record and the third indicator data are used as the knowledge extraction results.

11. According to the data anomaly detection processing method of claim 1, the multimodal knowledge extraction based on the data to be detected and the anomaly parameters comprises: Calling an abnormal attribution interface to perform abnormal attribution processing on the data to be detected and the abnormal parameters to obtain an abnormal attribution result; Extracting fourth indicator data corresponding to the abnormal indicator from a database based on the abnormal indicator included in the abnormal attribution result; The fourth indicator data, the data to be detected and the abnormal parameters are analyzed, and the analysis results, the abnormal attribution results and the fourth indicator data are used as the knowledge extraction results.

12. The data anomaly detection processing method according to any one of claims 7 to 11, wherein the multimodal knowledge extraction based on the data to be detected and the anomaly parameters further comprises: Obtaining anomaly attribution examples matching the data to be detected; Reading application scenario data of the data to be detected; The knowledge extraction result includes the abnormal attribution example and the application scenario data.

13. According to the data anomaly detection processing method of claim 1, the step of constructing an anomaly analysis text based on the knowledge text and the anomaly analysis prompt template corresponding to the data to be detected comprises: Filtering the knowledge text to obtain a target knowledge text; The target knowledge text is conditionally converted according to a preset conversion protocol to obtain a conversion text, and the conversion text is written into the exception analysis prompt template to obtain the exception analysis text.

14. According to the data anomaly detection and processing method of claim 1, the anomaly analysis prompt template includes a task prompt for performing data anomaly analysis in a thought chain manner, and includes a task prompt for outputting analysis process information for performing data anomaly analysis in a thought chain manner; The anomaly analysis prompt template includes a zero-sample prompt for performing data anomaly analysis using zero-sample learning.

15. According to the data anomaly detection and processing method of claim 1, after the step of inputting the anomaly analysis text into a large language model for data anomaly analysis and obtaining anomaly analysis processing results and analysis process information is executed, the method further comprises: Sending the abnormal analysis processing result and the analysis process information to the merchant or operator, so as to display the abnormal analysis processing result and the analysis process information on the dialogue interface; or, The abnormal analysis processing result and the analysis process information are displayed in the data display control accessed by the merchant or the operator.

16. A data anomaly detection and processing device, comprising: The anomaly detection module is configured to obtain the data to be detected that triggers the anomaly detection, and perform anomaly detection on the data to be detected to obtain anomaly parameters; A knowledge extraction module is configured to perform multimodal knowledge extraction according to the data to be detected and the abnormal parameters, and perform text conversion on the knowledge extraction result to obtain knowledge text; A text construction module is configured to construct an abnormality analysis text based on the knowledge text and the abnormality analysis prompt template corresponding to the data to be detected; The exception analysis module is configured to input the exception analysis text into the large language model to perform data exception analysis, and obtain the exception analysis processing result and analysis process information.

17. A data anomaly detection and processing device, comprising: processor; and a memory configured to store computer executable instructions that, when executed, cause the processor to: Acquire the data to be detected that triggers anomaly detection, and perform anomaly detection on the data to be detected to obtain anomaly parameters; Performing multimodal knowledge extraction according to the data to be detected and the abnormal parameters, and performing text conversion on the knowledge extraction result to obtain knowledge text; Constructing an abnormality analysis text based on the knowledge text and the abnormality analysis prompt template corresponding to the data to be detected; The exception analysis text is input into a large language model to perform data exception analysis, and the exception analysis processing result and analysis process information are obtained.

18. A computer-readable storage medium for storing computer-executable instructions, wherein the computer-executable instructions implement the steps of the method of claim 1 when executed.