Abnormality detection method and device for time series data

By using the abnormality detection model of the multi-view angle slice alignment module, multi-scale state perception module and consistent characterization reconstruction module in timing data abnormal detection, the problems of deep information loss and low detection accuracy in the prior art are solved, and comprehensive and deep perception of timing data are achieved, and detection accuracy is improved.

CN120145266AActive Publication Date: 2025-06-13HUNAN TECHN COLLEGE OF RAILWAY HIGH SPEED
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510295503.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-06-13
Estimated Expiration
2045-03-13

AI Technical Summary

Technical Problem

The prior art has deep information loss in time series data abnormality detection, resulting in low accuracy of detection results, unable to learn normal models of sequences from a global perspective, and linear structures lead to inability to parallel calculations.

Method used

The anomaly detection model of the multi-view slicing alignment module, a multi-scale state perception module and a consistent characterization reconstruction module are adopted to slice, feature fusion, multi-scale state perception and overall consistency evaluation of the time series data to be detected to achieve comprehensive and deep perception of the time series data.

Benefits of technology

Through multi-view feature fusion and multi-scale state perception, the accuracy of timing data abnormal detection is improved, deep information loss is avoided, and comprehensive and deep perception of timing data is achieved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145266A_ABST
    Figure CN120145266A_ABST
Patent Text Reader

Abstract

The invention provides an anomaly detection method and device for time series data, which are used for carrying out anomaly detection on to-be-detected time series data based on a trained anomaly detection model, and the anomaly detection model comprises a multi-view slice alignment module, a multi-scale state sensing module and a consistent representation reconstruction module. The method comprises the following steps: slicing to-be-detected time sequence data by using different slicing parameters to obtain a plurality of groups of first view angle slice sets, and performing matrix recombination on the plurality of groups of first view angle slice sets to obtain a plurality of groups of second view angle slice sets; performing feature fusion on the first view angle slice set and the second view angle slice set based on a multi-view angle slice alignment module to obtain multi-view angle features; performing multi-scale state sensing on the multi-view features based on a multi-scale state sensing module to obtain state space sensing features; and performing overall consistency evaluation on the state space perception features based on a consistency representation reconstruction module to obtain a detection result. According to the invention, the accuracy of time series data anomaly detection is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular, to an abnormal detection method and device for time series data. Background Art

[0002] Time series anomaly detection is widely used in different fields, including medical device detection, economic fraud detection, industrial control system detection, and so on. With the continuous development of the Internet of Things and the rapid development of various sensors, the operating system generates large-scale high-dimensional multivariate time series data all the time. However, inevitably, large-scale systems will also generate anomalies, and sudden problems often bring huge irreversible losses. Therefore, it is very important to quickly and accurately process massive information and detect anomalies to ensure system security and avoid economic losses.

[0003] In time series data, the recurrent neural network (RNN) or long short-term memory network (LSTM) structure is often used for anomaly prediction. However, it has the problem of long-term forgetting and is difficult to learn the normal model of the sequence from a global perspective. Moreover, this kind of linear structure makes it impossible to perform parallel computing, greatly reducing the speed of model training. In other words, both the LSTM and Transformer processing modes can only extract features from partial scales, which will inevitably cause the loss of deep information, and then lead to the problem of low accuracy of the anomaly detection results of time series data.

[0004] Therefore, there is an urgent need to provide an abnormal detection method and device for time series data to avoid the loss of deep information, comprehensively combine features of multiple scales, and improve the accuracy of abnormal detection of time series data. Summary of the Invention

[0005] In view of this, it is necessary to provide an abnormal detection method and device for time series data to solve the technical problem in the prior art that features can only be extracted from partial scales, resulting in the loss of deep information and then leading to low accuracy of the abnormal detection results of time series data.

[0006] On the one hand, to solve the above technical problems, the present invention provides an abnormal detection method for time series data, which is used to perform abnormal detection on the time series data to be detected based on a trained abnormal detection model. The abnormal detection model includes a multi-perspective slice alignment module, a multi-scale state perception module, and a consistent representation reconstruction module. The method includes:

[0007] Slice the time series data to be detected with different slice parameters to obtain multiple groups of first-perspective slice sets, and respectively perform matrix recombination on the multiple groups of first-perspective slice sets to obtain multiple groups of second-perspective slice sets;

[0008] Based on the multi - perspective slice alignment module, perform feature fusion on the first - perspective slice set and the second - perspective slice set to obtain multi - perspective features;

[0009] Based on the multi - scale state perception module, perform multi - scale state perception on the multi - perspective features to obtain state - space perception features;

[0010] Based on the consistent representation reconstruction module, perform overall consistency evaluation on the state - space perception features to obtain the detection result.

[0011] In a possible implementation, the slice parameters include the number of slices and the unit slice length.

[0012] In a possible implementation, the multi - perspective slice alignment module includes an intra - slice embedding unit, an inter - slice embedding unit, and an information alignment unit; then the performing feature fusion on the first - perspective slice set and the second - perspective slice set based on the multi - perspective slice alignment module to obtain multi - perspective features includes:

[0013] Based on the intra - slice embedding unit, perform feature embedding on the multiple groups of first - perspective slice sets to obtain multiple groups of intra - slice features;

[0014] Based on the inter - slice embedding unit, perform feature embedding on the multiple groups of second - perspective slice sets to obtain multiple groups of inter - slice features;

[0015] Based on the information alignment unit, perform feature fusion on the multiple groups of intra - slice features and the multiple groups of inter - slice features to obtain the multi - perspective features.

[0016] In a possible implementation, the multi - perspective features are:

[0017]

[0018] where Z p is the multi - perspective feature; q is the number of groups of the first - perspective slice set and the second - perspective slice set; is the intra - slice feature corresponding to the i - th group of the first - perspective slice set ; is the inter - slice feature corresponding to the i - th group of the second - perspective slice set ; ⊕ is the matrix concatenation operator; E inter () is the intra - slice embedding operation; P i () is the intra - slice linear projection operation; E cross () is the inter - slice embedding operation; P c () is the inter - slice linear projection operation.

[0019] In a possible implementation, the multi-scale state perception module includes a global attention unit, a state space perception unit, and a mutual attention unit; then, performing multi-scale state perception on the multi-view features based on the multi-scale state perception module to obtain state space perception features includes:

[0020] Performing global attention learning on the multi-view features based on the global attention unit to obtain attention features;

[0021] Determining latent variables of the attention features at different time steps based on the state space perception unit, and determining output features at different time steps based on the latent variables and the attention features;

[0022] Performing mutual attention learning on the multi-view features and the output features based on the mutual attention unit to obtain the state space perception features.

[0023] In a possible implementation, the multi-scale state perception module further includes a local feature extraction unit disposed between the global attention unit and the state space perception unit; the local feature extraction unit is used to extract local information of the attention features to obtain local features.

[0024] In a possible implementation, the state space perception features are:

[0025]

[0026] where V is the spatial state perception feature; V i is the output of the i-th attention head in the mutual attention learning unit; M is the number of attention heads in the mutual attention learning unit; d k is the dimension size of each attention head; is the output feature at the i-th time step; N i 、 are all learnable parameter matrices; is the local feature at the t-th time step; is the latent variable at the t-th time step; I is the identity matrix; is the latent variable at the (t - 1)-th time step.

[0027] In a possible implementation, the consistent representation reconstruction module includes an encoder and a decoder; then, performing an overall consistency evaluation on the state space perception features based on the consistent representation reconstruction module to obtain a detection result includes:

[0028] Using the encoder to determine the fitting distribution of the state space perception features;

[0029] Based on the decoder being used to determine the estimated fitting distribution of the state - space perception features, an overall consistency evaluation is performed on the fitting distribution and the estimated fitting distribution to determine the detection result.

[0030] In a possible implementation manner, the total loss function during the training of the anomaly detection model is:

[0031]

[0032] L re =-E q(z│x) [log(p(x|z))]+D KL [q(z|x)||p(x|z)]

[0033]

[0034] Wherein, is the total loss function; L a is the similarity loss function; L re is the reconstruction loss function; E q(z│x) [log(p(x|z))] is the maximum likelihood estimation of q(z│x) for log(p(x|z)); p(x|z) is the fitting distribution; q(z│x) is the estimated fitting distribution; D KL [q(z|x)||p(z)] is the KL divergence between q(z│x) and p(x|z); Z in is the in - slice feature; Z cr is the inter - slice feature; || || 2 is the Euclidean norm.

[0035] On the other hand, the present invention also provides an anomaly detection device for time - series data, which is used to perform anomaly detection on the to - be - detected time - series data based on the trained anomaly detection model. The anomaly detection model includes a multi - perspective slice alignment module, a multi - scale state perception module, and a consistent representation reconstruction module; the device includes:

[0036] A slicing unit, configured to slice the to - be - detected time - series data with different slicing parameters to obtain multiple groups of first - perspective slice sets, and respectively perform matrix recombination on the multiple groups of first - perspective slice sets to obtain multiple groups of second - perspective slice sets;

[0037] A multi - perspective feature determination unit, configured to perform feature fusion on the first - perspective slice sets and the second - perspective slice sets based on the multi - perspective slice alignment module to obtain multi - perspective features;

[0038] A state - space perception feature determination unit, configured to perform multi - scale state perception on the multi - perspective features based on the multi - scale state perception module to obtain state - space perception features;

[0039] Anomaly detection unit, configured to perform an overall consistency evaluation on the state space perception features based on the consistent representation reconstruction module to obtain a detection result.

[0040] The beneficial effects of the present invention are as follows: The anomaly detection method for time series data provided by the present invention, after slicing the time series data to be detected with different slicing parameters to obtain multiple groups of first perspective slice sets, performs matrix recombination on the multiple groups of first perspective slice sets to obtain multiple groups of second perspective slice sets, so that the finally obtained overall slice set includes both different dimensions of a slice within a batch and the same dimension of different slices between batches as data from different perspectives to embed data, realizing a comprehensive perception of the time series data to be detected, improving the comprehensiveness of the multi-perspective features after feature fusion, and improving the detection accuracy of time series data anomaly detection based on multi-perspective features.

[0041] Furthermore, the present invention sets a multi-scale state perception module to perform multi-scale state perception on multi-perspective features, which can consider the time series state while comprehensively perceiving multi-dimensional time series data, further realizing a deep perception of time series data, and further improving the accuracy of the detection result. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for description in the embodiments. Obviously, the following described drawings are only some embodiments of the present invention. For those skilled in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0043] Figure 1 It is a schematic structural diagram of an embodiment of the anomaly detection model provided by the present invention;

[0044] Figure 2 It is a schematic flowchart of an embodiment of the anomaly detection method for time series data provided by the present invention;

[0045] Figure 3 It is a schematic flowchart of an embodiment of step S202 of the present invention;

[0046] Figure 4 It is a schematic flowchart of an embodiment of step S203 of the present invention;

[0047] Figure 5 It is a schematic structural diagram of an embodiment of the anomaly detection device for time series data provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0048] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0049] It should be understood that the schematic drawings are not drawn to scale. The flowcharts used in the present invention illustrate the operations implemented according to some embodiments of the present invention. It should be understood that the operations in the flowchart may not be implemented in sequence, and steps without logical context relationships may be reversed or implemented simultaneously. In addition, those skilled in the art can add one or more other operations to the flowchart or remove one or more operations from the flowchart under the guidance of the content of the present invention. Some of the block diagrams shown in the drawings are functional entities, which do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor systems and / or microcontroller systems.

[0050] Referring to "embodiments" herein means that specific features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of the present invention. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0051] The present invention provides an anomaly detection method and device for time series data, which will be described separately below.

[0052] Before elaborating on the specific embodiments, it should be noted first that: the anomaly detection method for time series data in the embodiments of the present invention is based on an anomaly detection model for detection. Figure 1 FIG. is a schematic structural diagram of an embodiment of the anomaly detection model provided by the present invention. As Figure 1 shown, the anomaly detection model includes a multi-view slice alignment module, a multi-scale state perception module, and a consistent representation reconstruction module. Then, as Figure 2 shown, the anomaly detection method for time series data includes:

[0053] S201. Slice the time series data to be detected with different slice parameters to obtain multiple groups of first-view slice sets, and respectively perform matrix recombination on the multiple groups of first-view slice sets to obtain multiple groups of second-view slice sets;

[0054] S202. Feature fusion is performed on the first - perspective slice set and the second - perspective slice set based on the multi - perspective slice alignment module to obtain multi - perspective features;

[0055] S203. Multi - scale state perception is performed on the multi - perspective features based on the multi - scale state perception module to obtain state - space perception features;

[0056] S204. Overall consistency evaluation is performed on the state - space perception features based on the consistent representation reconstruction module to obtain the detection result.

[0057] It should be understood that the time - series data to be detected is also collected from the original time - series data through a data collection window.

[0058] Among them, the first perspective refers to different time spans in the time - series data to be detected, and the second perspective can be the data - type dimension in the time - series data to be detected. That is, the time - series data to be detected is reorganized from two completely different dimensions to achieve multi - perspective perception.

[0059] Compared with the prior art, in the anomaly detection method for time - series data provided by the embodiments of the present invention, after slicing the time - series data to be detected with different slicing parameters to obtain multiple groups of first - perspective slice sets, matrix reorganization is performed on the multiple groups of first - perspective slice sets to obtain multiple groups of second - perspective slice sets, so that the finally obtained overall slice set includes both different dimensions of a slice within a batch and the same dimension of different slices between batches as different - perspective data for data embedding, realizing a comprehensive perception of the time - series data to be detected, improving the comprehensiveness of the multi - perspective features after feature fusion, and thus improving the detection accuracy of time - series data anomaly detection based on multi - perspective features.

[0060] Furthermore, in the embodiments of the present invention, a multi - scale state perception module is set to perform multi - scale state perception on the multi - perspective features, which can consider the time - series state while comprehensively perceiving multi - dimensional time - series data, further realizing a deep - level perception of the time - series data, and thus further improving the accuracy of the detection result.

[0061] In some embodiments of the present invention, the slicing parameters include the number of slices and the unit slice length, and the slicing parameters satisfy: τ = e×sub, where τ is the size of the collection window, sub is the number of slices; e is the unit slice length.

[0062] Multiple groups of first - perspective slice sets can be obtained based on different slicing parameters q is the total number of slicing parameters.

[0063] In the specific embodiments of the present invention, as Figure 1 shown, the multi - perspective slice alignment module includes a within - slice embedding unit, a between - slice embedding unit, and an information alignment unit; then as Figure 3 shown, step S202 includes:

[0064] S301. Embed the features of multiple groups of first - perspective slice sets based on the in - slice embedding units to obtain multiple groups of in - slice features;

[0065] S302. Embed the features of multiple groups of second - perspective slice sets based on the inter - slice embedding units to obtain multiple groups of inter - slice features;

[0066] S303. Fuse the multiple groups of in - slice features and multiple groups of inter - slice features based on the information alignment unit to obtain multi - perspective features.

[0067] Specifically, perform feature embedding on , and w i is the slice data in the i - th first - perspective slice set. Then use the CNN network as the in - slice embedding network E inter , and then project all the embedding representations into a unified space through the in - slice linear projection P i to obtain a more detailed in - slice feature representation

[0068]

[0069] Perform feature embedding on , where u i is the combined information of all sub - slices in the i - th dimension. Similarly, use the CNN network for inter - slice embedding E cross , and then through the inter - slice linear projection P c to obtain a relatively macroscopic inter - slice representation

[0070]

[0071] Finally, fuse the inter - slice and in - slice features under different slicing methods to obtain multi - perspective features:

[0072]

[0073] In the formula, Z p is the multi - perspective feature; q is the number of groups of the first - perspective slice set and the second - perspective slice set; ⊕ is the matrix splicing operator.

[0074] In order to learn stronger representations, in some embodiments of the present invention, as Figure 1 shown, the multi - scale state perception module includes a global attention unit, a state space perception unit, and a mutual attention unit; then as Figure 4 shown, step S103 includes:

[0075] S401. Perform global attention learning on the multi - perspective features based on the global attention unit to obtain attention features;

[0076] S402. Determine the latent variables of the attention features at different time steps based on the state space perception unit, and determine the output features at different time steps based on the latent variables and the attention features;

[0077] S403. Perform mutual attention learning on the multi-view features and the output features based on the mutual attention unit to obtain the state space perception features.

[0078] In the embodiment of the present invention, by setting a global attention unit to perform global attention learning on multi-view features, the mutual relationships of different scales of time series data can be obtained. By setting a state space perception unit, features that retain the time state relationship can be improved from the coherent time domain, and then the deep features of the state space perception features can be extracted to further improve the accuracy of the anomaly detection result.

[0079] In order to better sense the sudden occurrence of anomalies, in some embodiments of the present invention, as Figure 1 shown, the multi-scale state perception module further includes a local feature extraction unit arranged between the global attention unit and the state space perception unit; the local feature extraction unit is used to extract the local information of the attention features to obtain local features.

[0080] In the embodiment of the present invention, by setting a local feature extraction unit to obtain local information, the local relationship between the features after obtaining the global attention can be improved, so as to increase the perception of abnormal mutations and improve the robustness of anomaly detection.

[0081] Generally speaking, the global attention unit first obtains Q, K, and V in each attention head, calculates the global self-attention to obtain comprehensive correlation. Then use the local feature extraction unit to extract the local feature relationship. After normalization using the activation function, the features that retain the time state relationship are improved from the coherent time domain through the state space machine. Then, the weights of different scale information in the original structure are adjusted through the mutual attention mechanism.

[0082] Specifically: The global attention unit obtains the preliminary overall correlation. Using the multi-view feature Z p obtained in the previous step, Q, K, and V matrices are obtained in each attention head respectively. Here, the output S i of each attention head is as follows:

[0083]

[0084] where d k is the dimension size of each attention head, and f(·) is the linear projection.

[0085] The local feature extraction unit uses the CNN convolution module c(·) to further obtain local information relationships:

[0086] C i = c(s(Z p ))

[0087] where C i is the local feature.

[0088] In time series data, it is usually necessary to consider the characteristics of time series state transitions. The local relationship C i obtained in the previous step. The number of batches in a batch can be regarded as D time steps. C of a batch i can also be expressed as To further improve the perception of specific time series data, a state space perception unit is used to establish a latent variable space to store time states. The latent variable at the t-th time step can be expressed as:

[0089]

[0090] where are all learnable parameter matrices; is the local feature at the t-th time step; is the latent variable at the t-th time step; I is the identity matrix; is the latent variable at the (t - 1)-th time step.

[0091] At this time, the output representation o at time step t t can be characterized as:

[0092]

[0093] where is the state space perception feature; N i are all learnable parameter matrices; is the local feature at the t-th time step; is the latent variable at the t-th time step.

[0094] Cross-attention: Here, the Q and K matrices of the attention projection are obtained by matrix cross-multiplication after activation using the output of the state space model and the batch projection output Z at the beginning of this module p . The V matrix directly uses the activated Z p . Therefore, one attention head of the cross-attention module can be expressed as:

[0095]

[0096] Finally, the state space perception feature is:

[0097]

[0098] Where M is the number of attention heads in the mutual attention learning unit.

[0099] In some embodiments of the present invention, as Figure 1 shown, the consistent representation reconstruction module includes an encoder and a decoder; then step S104 includes:

[0100] Based on the encoder to determine the fitting distribution of the state space perception features;

[0101] Based on the decoder to determine the estimated fitting distribution of the state space perception features, conduct an overall consistency evaluation on the fitting distribution and the estimated fitting distribution, and determine the detection result.

[0102] In the consistent representation reconstruction module in the embodiments of the present invention, first, the distribution of the latent variables learned by the encoder is obtained, and then its distribution is sampled to ensure that the model tries to fit the regular structure in the time series, but does not overfit the abnormal samples. Finally, the decoder is used to predict the estimate of the input features. This can ensure the existence of a certain variance, and use the reconstructed estimate to learn the overall distribution, so as to amplify the difference from the latent abnormal samples and achieve accurate anomaly detection.

[0103] Where the encoder structure is expressed as:

[0104] E v (V) = proj(s(V))

[0105] This is equivalent to fitting the distribution q(z│x), where z|x ∼ N(a,b); a and b are the mean and variance of the distribution respectively.

[0106] The decoder is used to fit the estimated distribution P(x│z), which can be expressed as: D v (V) = s(proj(V)).

[0107] Because the training adopts unsupervised learning, a reconstruction method is used here to find the subtle differences between normal samples and abnormal samples. That is: in the specific embodiments of the present invention, the total loss function of the anomaly detection model during training is:

[0108]

[0109] L re = -E q(z│x) [log(p(x|z))] + D KL [q(z|x)||p(x|z)]

[0110]

[0111] In the formula, is the total loss function; L a is the similarity loss function; L re is the reconstruction loss function; E q(z│x) [log(p(x|z))] is the maximum likelihood estimate of q(z│x) for log(p(x|z)); p(x|z) is the fitting distribution; q(z│x) is the estimated fitting distribution; D KL [q(z|x)||p(z)] is the KL divergence between q(z│x) and p(x|z); Z in is the in-slice feature; Z cr is the inter-slice feature; || || 2 is the Euclidean norm.

[0112] In the embodiment of the present invention, the reconstruction loss function can maximize the fitting ability of the decoder under any given encoder to obtain stronger representation ability, and the KL divergence is used to regularize the encoder and decoder for structuring the latent space. Meanwhile, the similarity loss function is used to align features from different perspectives, which can further improve the accuracy of the loss value during training, so as to improve the model detection performance of the anomaly detection model determined by the above loss function.

[0113] In summary, the anomaly detection method for time series data proposed in the embodiment of the present invention uses a multi-perspective slice alignment structure in the information embedding stage, divides the data in different batch sizes, and each group contains different dimensions of a slice within a batch and the same dimension of different slices between batches as different perspectives to embed the data. At the same time, the input data is made three-dimensional by aligning different embeddings, which can comprehensively perceive the regional correlation of the data. Then, the multi-scale state space perception module is used to consider the time series state while comprehensively perceiving multi-dimensional time series data. The latent state space is used to extract deep features from multiple scales of global correlation, local correlation, and time series state transferability, amplifying the features related to the time series pattern in the data. Finally, consistent representation reconstruction is used to fit the normal sequence features, ensuring the excellent fitting ability of the model.

[0114] To better implement the anomaly detection method for time series data in the embodiment of the present invention, correspondingly, based on the anomaly detection method for time series data, the embodiment of the present invention further provides an anomaly detection device for time series data, as Figure 5 shown, the anomaly detection device 500 for time series data includes:

[0115] A slicing unit 501, configured to slice the time series data to be detected with different slice parameters to obtain multiple groups of first-perspective slice sets, and respectively perform matrix recombination on the multiple groups of first-perspective slice sets to obtain multiple groups of second-perspective slice sets;

[0116] A multi - perspective feature determination unit 502, configured to perform feature fusion on a first - perspective slice set and a second - perspective slice set based on a multi - perspective slice alignment module to obtain multi - perspective features;

[0117] A state - space perception feature determination unit 503, configured to perform multi - scale state perception on the multi - perspective features based on a multi - scale state perception module to obtain state - space perception features;

[0118] An anomaly detection unit 504, configured to perform an overall consistency evaluation on the state - space perception features based on a consistent representation reconstruction module to obtain a detection result.

[0119] The anomaly detection device 500 for time - series data provided in the above - mentioned embodiment can implement the technical solutions described in the anomaly detection method embodiment of the above - mentioned time - series data. The specific implementation principles of the above - mentioned modules or units can be referred to the corresponding content in the anomaly detection method embodiment of the above - mentioned time - series data, which will not be elaborated here.

[0120] Those skilled in the art can understand that all or part of the processes for implementing the methods in the above - mentioned embodiments can be completed by instructing relevant hardware (such as a processor, a controller, etc.) through a computer program. The computer program can be stored in a computer - readable storage medium. Among them, the computer - readable storage medium is a disk, an optical disk, a read - only memory, or a random access memory, etc.

[0121] The above - mentioned anomaly detection method and device for time - series data provided by the present invention have been introduced in detail. Specific examples are used in this article to elaborate on the principles and implementation manners of the present invention. The description of the above - mentioned embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those skilled in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A method for detecting anomalies in time series data, characterized in that: The method is used for performing anomaly detection on time series data to be detected based on a trained anomaly detection model, wherein the anomaly detection model includes a multi-view slice alignment module, a multi-scale state perception module, and a consistent representation reconstruction module; the method includes: Slicing the time series data to be detected with different slicing parameters to obtain multiple groups of first-view slice sets, and performing matrix reorganization on the multiple groups of first-view slice sets respectively to obtain multiple groups of second-view slice sets; Based on the multi-view slice alignment module, feature fusion is performed on the first-view slice set and the second-view slice set to obtain multi-view features; Performing multi-scale state perception on the multi-view features based on the multi-scale state perception module to obtain state space perception features; Based on the consistent representation reconstruction module, an overall consistency evaluation is performed on the state space perception features to obtain a detection result.

2. The method for detecting anomalies in time series data according to claim 1, characterized in that: The slice parameters include the number of slices and the unit slice length.

3. The method for detecting anomalies in time series data according to claim 1, characterized in that: The multi-view slice alignment module includes an intra-slice embedding unit, an inter-slice embedding unit, and an information alignment unit; then the step of performing feature fusion on the first-view slice set and the second-view slice set based on the multi-view slice alignment module to obtain multi-view features includes: Based on the intra-slice embedding unit, feature embedding is performed on the multiple groups of first-view slice sets to obtain multiple groups of intra-slice features; Based on the inter-slice embedding unit, feature embedding is performed on the multiple sets of second-view slice sets to obtain multiple sets of inter-slice features; Based on the information alignment unit, feature fusion is performed on the multiple groups of intra-slice features and the multiple groups of inter-slice features to obtain the multi-view features.

4. The method for detecting anomalies in time series data according to claim 3, characterized in that: The multi-view features are: In the formula, Z p is a multi-view feature; q is the number of groups of the first-view slice set and the second-view slice set; is the i-th group of first-view slices The corresponding intra-slice features; is the i-th set of second-view slices Corresponding inter-slice features; ⊕ is the matrix concatenation operator; E inter () is the embedding operation in the slice; P i () is the linear projection operation within the slice; E cross () is the inter-slice embedding operation; P c () is the linear projection operation between slices.

5. The method for detecting anomalies in time series data according to claim 1, characterized in that: The multi-scale state perception module includes a global attention unit, a state space perception unit and a mutual attention unit; Then, performing multi-scale state perception on the multi-view features based on the multi-scale state perception module to obtain state space perception features includes: Performing global attention learning on the multi-view features based on the global attention unit to obtain attention features; Determine the latent variables of the attention feature at different time steps based on the state space perception unit, and determine the output features at different time steps based on the latent variables and the attention feature; Based on the mutual attention unit, mutual attention learning is performed on the multi-view features and the output features to obtain the state space perception features.

6. The method for detecting anomalies in time series data according to claim 5, characterized in that: The multi-scale state perception module also includes a local feature extraction unit arranged between the global attention unit and the state space perception unit; the local feature extraction unit is used to extract local information of the attention feature to obtain a local feature.

7. The method for detecting anomalies in time series data according to claim 6, characterized in that: The state space perception features are: Where V is the spatial state perception feature; V i is the output of the i-th attention head in the mutual attention learning unit; M is the number of attention heads in the mutual attention learning unit; d k is the dimension size of each attention head; is the output feature of the i-th time step; N i , All are learnable parameter matrices; is the local feature of the tth time step; is the latent variable at the tth time step; I is the identity matrix; is the latent variable at the t-1th time step.

8. The method for detecting anomalies in time series data according to claim 1, characterized in that: The consistent representation reconstruction module includes an encoder and a decoder; then the overall consistency evaluation of the state space perception feature based on the consistent representation reconstruction module to obtain the detection result includes: Based on the encoder, a fitted distribution is used to determine the state-space perceptual features; Based on the estimated fitting distribution used by the decoder to determine the state-space perceptual feature, an overall consistency evaluation is performed on the fitting distribution and the estimated fitting distribution to determine the detection result.

9. The method for detecting anomalies in time series data according to claim 8, characterized in that: The total loss function of the anomaly detection model during training is: L re =-E q(z│x) [log(p(x|z))]+D KL [q(z|x)||p(x|z)] In the formula, is the total loss function; L a is the similarity loss function; L re is the reconstruction loss function; E q(z│x) [log(p(x|z))] is the maximum likelihood estimate of q(z│x) for log(p(x|z)); p(x|z) is the fitted distribution; q(z│x) is the estimated fitted distribution; D KL [q(z|x)||p(z)] is the KL divergence between q(z│x) and p(x|z); Z in is the feature within the slice; Z cr is the inter-slice feature; ||||2 is the Euclidean norm.

10. A device for detecting anomalies in time series data, characterized in that: Used to perform anomaly detection on time series data to be detected based on a trained anomaly detection model, wherein the anomaly detection model includes a multi-view slice alignment module, a multi-scale state perception module, and a consistent representation reconstruction module; the device includes: a slicing unit, configured to slice the time series data to be detected with different slicing parameters to obtain a plurality of first-view slice sets, and to perform matrix reorganization on the plurality of first-view slice sets respectively to obtain a plurality of second-view slice sets; a multi-view feature determination unit, configured to perform feature fusion on the first-view slice set and the second-view slice set based on the multi-view slice alignment module to obtain a multi-view feature; a state space perception feature determination unit, configured to perform multi-scale state perception on the multi-view feature based on the multi-scale state perception module to obtain a state space perception feature; The anomaly detection unit is used to perform an overall consistency evaluation on the state space perception feature based on the consistent representation reconstruction module to obtain a detection result.

Citation Information

Patent Citations

  • Multi-dimensional time series data anomaly detection method

    CN116361635A

  • Time sequence anomaly detection method based on multi-time multi-feature description network

    CN118965078A

  • Device and system for detecting abnormality

    US20030117279A1