Analysis device, analysis method, and computer-readable storage medium
By combining unsupervised and supervised learning methods in the analysis device, the performance of the prediction model is detected and adjusted, and the problem of degradation of analysis reliability caused by the reduction of prediction model accuracy is solved, thereby achieving higher analysis reliability and result accuracy.
Patent Information
- Application Number
- CN202411808393.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-11
- Filing Date
- 2024-12-10
- Publication Date
- 2025-06-13
AI Technical Summary
In the prior art, the reduction in the accuracy of the prediction model leads to a decrease in the reliability of the analysis, especially the accuracy of the SHAP method depends on the accuracy of the prediction model.
An analysis device including detection, supervised learning, evaluation and re-learning departments is adopted to input object system data through a first prediction model that performs unsupervised learning on the pre-data to detect abnormal data, and a second prediction model with supervised learning is performed based on the abnormal data and the pre-data. The reliability of the key analysis is improved by inputting the same data into the first and second prediction models to evaluate the performance of the first prediction model, and unsupervised learning of the first prediction model is performed again based on the evaluation results.
Improve the reliability of data analysis, and ensure the accuracy and trustworthiness of analysis results by detecting and adjusting the performance of prediction models.
Smart Images

Figure CN120146240A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an analysis device, an analysis method, and a computer-readable storage medium. Background Art
[0002] There is the following prior art, that is, root cause analysis of data is performed using a prediction model.
[0003] Non-Patent Document 1: Iori Oki, Takahisa Nishigaki, Takashi Onoda, "Factor Estimation Using SHAP for Outlier Detection Models of Merchant Ship-Borne Equipment", National Research Presentation Meeting of the Institute of Management Information, November 12, 2022 (Iori Oki, Takahisa Nishigaki, Takashi Onoda, "Factor Estimation for Outlier Detection Models of Merchant Ship-Borne Equipment Using SHAP", National Research Presentation Meeting of the Institute of Management Information, November 12, 2022) Summary of the Invention
[0004] However, the following problem exists in the above prior art, that is, when the accuracy of the prediction model decreases, the reliability of the root cause analysis decreases.
[0005] For example, SHAP is ultimately a method for calculating how much the feature quantity contributes based on the abnormal data output from the prediction model, and the accuracy of the Shapley value depends on the accuracy of the prediction model.
[0006] An object of one aspect is to provide an analysis device, an analysis method, and an analysis program capable of improving the reliability of root cause analysis of data.
[0007] The analysis device according to one aspect includes: a detection unit that detects abnormal data by inputting data acquired from an object system into a first prediction model that has performed unsupervised learning on pre-data acquired during normal operation of the object system; a supervised learning unit that performs supervised learning on a second prediction model based on the abnormal data and the pre-data; an evaluation unit that evaluates the first prediction model by inputting the same data as the data input to the first prediction model into the second prediction model; and a re-learning unit that performs unsupervised learning on the first prediction model again based on the evaluation result of the evaluation unit.
[0008] The analysis method according to one aspect is executed by a computer to perform the following processing:
[0009] Data obtained from the object system is input to a first prediction model that has undergone unsupervised learning on pre - data obtained during normal operation of the object system to detect abnormal data. Based on the abnormal data and the pre - data, supervised learning for a second prediction model is performed. By inputting the same data as that input to the first prediction model into the second prediction model, the first prediction model is evaluated. Based on the evaluation result, unsupervised learning for the first prediction model is performed again.
[0010] A computer - readable storage medium according to one aspect causes a computer to perform the following processing: Data obtained from the object system is input to a first prediction model that has undergone unsupervised learning on pre - data obtained during normal operation of the object system to detect abnormal data. Based on the abnormal data and the pre - data, supervised learning for a second prediction model is performed. By inputting the same data as that input to the first prediction model into the second prediction model, the first prediction model is evaluated. Based on the evaluation result, unsupervised learning for the first prediction model is performed again.
[0011] Effects of the Invention
[0012] According to one embodiment, the reliability of cause analysis of data can be improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 It is a diagram (1) for explaining the cause analysis (SHAP).
[0014] Figure 2 It is a diagram (2) for explaining the cause analysis (SHAP).
[0015] Figure 3 It is a diagram (3) for explaining the cause analysis (SHAP).
[0016] Figure 4 It is a diagram for explaining the processing of the analysis device according to Embodiment 1.
[0017] Figure 5 It is a diagram showing an example of the data structure of the learning data set according to Embodiment 1.
[0018] Figure 6 It is a diagram showing an example of the determination result of the process data obtained in real time.
[0019] Figure 7 It is a diagram for explaining the evaluation of the first prediction model.
[0020] Figure 8 It is a functional block diagram showing the functional structure of the analysis device according to Embodiment 1.
[0021] Figure 9 It is a flowchart showing the processing flow of the analysis device of Embodiment 1.
[0022] Figure 10 It is a diagram for explaining the processing of the analysis device related to Embodiment 2.
[0023] Figure 11 It is a functional block diagram showing the functional structure of the analysis device related to Embodiment 2.
[0024] Figure 12 It is a flowchart showing the processing flow of the analysis device of Embodiment 2.
[0025] Figure 13 It is a diagram for explaining the processing of the analysis device related to Embodiment 3.
[0026] Figure 14 It is a functional block diagram showing the functional structure of the analysis device related to Embodiment 3.
[0027] Figure 15 It is a flowchart showing the processing flow of the analysis device of Embodiment 3.
[0028] Figure 16 It is a diagram for explaining the processing of the analysis device related to Embodiment 4.
[0029] Figure 17 It is a diagram for explaining an example of the determination strategy of the analysis device of Embodiment 4.
[0030] Figure 18 It is a diagram showing an example of the determination result of the process data obtained in real time and the workshop KPI.
[0031] Figure 19 It is a functional block diagram showing the functional structure of the analysis device related to Embodiment 4.
[0032] Figure 20 It is a flowchart showing the processing flow of the analysis device of Embodiment 4.
[0033] Figure 21 It is a diagram for explaining an example of the hardware structure.
[0034] Figure 22 It is a diagram for explaining the prior art. Specific Embodiments
[0035] Next, embodiments of the analysis device, analysis method, and computer-readable storage medium disclosed in the present application will be described in detail with reference to the accompanying drawings. In addition, the present invention is not limited by this embodiment. Further, the same reference numerals are assigned to the same elements, and repeated descriptions are appropriately omitted, and the respective embodiments can be combined as appropriate without contradiction.
[0036] First, after describing the prior art, embodiments of the present application will be described. In the following description, the device that executes the prior art is denoted as the "prior device". Figure 22 This is a diagram for explaining the prior art. First, in the prior art, a learning data set 10 is prepared in advance. A plurality of process data collected during a period when no abnormality occurs in the system to be monitored is registered in the learning data set 10. For example, for the process data, a feature amount is set for each of a plurality of items. For example, when the system to be monitored is a workshop, the process data includes pressure, temperature, flow rate, operating state, etc.
[0037] The prior device performs unsupervised learning on the prediction model 15 based on the learning data set 10. The prediction model 15 is OneClass SVM (Support Vector Machine) or the like.
[0038] After the unsupervised learning of the prediction model 15 is completed, the prior device performs the following processing. The prior device inputs the process data 5 received in real time from the system 50 to be monitored into the prediction model 15, thereby performing abnormality determination. In the following description, the process data 5 determined to be abnormal is denoted as "abnormal data". A case where the prior device repeatedly performs abnormality determination every time the process data 5 is received and detects abnormal data at a plurality of x points will be described.
[0039] The prior device performs root cause analysis on the abnormal data at a plurality of x points. For example, the prior device performs SHAP (Shapley Additive exPlanations) as the root cause analysis, and calculates the Shapley value for each feature amount of the abnormal data. The Shapley value is a value indicating how much the feature amount of the abnormal data contributes to the prediction value obtained by inputting the data into the prediction model 15. For example, when the Shapley value of the feature amount for pressure among the plurality of feature amounts included in the abnormal data is greater than the Shapley values of other feature amounts, it can be said that the root cause of the abnormality is pressure.
[0040] (Embodiment 1)
[0041] (Root cause analysis)
[0042] Before describing Embodiment 1, an example of cause analysis (SHAP) will be described. Figure 1 This is a diagram (1) for explaining cause analysis (SHAP). In Figure 1 the example shown, data 11 that forms one record and a prediction model M1 are used for the explanation. A set of features and feature quantities is set for data 11.
[0043] For example, for data 11, Age, SEX, BP (Blood Pressure), and BMI (Body Mass Index) are set as features. The feature quantity of the feature "Age" is "60". The feature quantity of the feature "Sex" is "F (Female)". The feature quantity of the feature "BP" is "180". The feature quantity of the feature "BMI" is "40". In addition, the feature quantity of the feature "Sex" can be represented by 1 (Female) or 0 (male).
[0044] The prediction model M1 is a model that has completed unsupervised learning and outputs a prediction value when data is input. When the prediction value is greater than or equal to the threshold, the input data is determined to be normal data. On the other hand, when the prediction value is less than the threshold, the input data is determined to be abnormal data. Base rate is one of the parameters of the prediction model M1, and the larger the Base rate, the easier it is to detect abnormal data. For example, the Base rate is set to "0.1".
[0045] In Figure 1 the example shown, when data 11 is input to the prediction model M1, the prediction value is "0.4". For example, if the pre-set threshold is set to "0.5", then data 11 is determined to be abnormal data.
[0046] If cause analysis based on SHAP is performed using data 11 and the prediction model M1, Shapley values corresponding to each feature are calculated respectively. For example, data 11 with the feature quantities of each feature changed is input to the prediction model 11, and the process of calculating the prediction value is repeatedly executed, and the change in the value of the feature quantity with respect to the change in the prediction value is calculated as the Shapley value. In Figure 1 the example shown, the Shapley value for the feature "Age" is "+0.4". The Shapley value for the feature "Sex" is "-0.3". The Shapley value for the feature "BP" is "+0.1". The Shapley value for the feature "BMI" is "+0.1".
[0047] According to Figure 1From the calculation results of the Shapley values shown, it can be seen that the feature "Age" has the greatest impact on the predicted value of the prediction model M1, and the second greatest impact is the feature "Sex".
[0048] Figure 2 It is a diagram (2) for explaining the cause analysis (SHAP). In Figure 2 the example shown, data 12 including multiple records and the prediction model M1 are used for explanation. The explanation of the prediction model M1 is the same as that Figure 1 presented in
[0049] For each record included in data 12, a group of features and feature quantities is set. The explanation of the features is the same as that Figure 1 presented in
[0050] For data 12a, the average value of the feature quantity of the feature "Age" is set to "60", the average value of the feature quantity of the feature "Sex" is set to "F", the average value of the feature quantity of the feature "BP" is set to "180", and the average value of the feature quantity of the feature "BMI" is set to "40".
[0051] In Figure 1 the example shown, when data 12a is input into the prediction model M1, the predicted value is "0.4". For example, if the pre-set threshold is set to "0.5", then data 12a is determined to be abnormal data.
[0052] If the SHAP-based cause analysis is performed using data 12a and the prediction model M1, the Shapley values corresponding to each feature are calculated respectively. In Figure 2 the example shown, the Shapley value for the feature "Age" is "+0.4". The Shapley value for the feature "Sex" is "-0.3". The Shapley value for the feature "BP" is "+0.1". The Shapley value for the feature "BMI" is "+0.1".
[0053] According to Figure 2 the calculation results of the Shapley values shown, it can be seen that the feature "Age" has the greatest impact on the predicted value of the prediction model M1, and the second greatest impact is the feature "Sex".
[0054] Figure 3 It is a diagram (3) for explaining the cause analysis (SHAP). In Figure 3In the example shown, a description is given using multiple data 13a, 13b, 13c and a prediction model M1. The description of the prediction model M1 is the same as that in Figure 1 the description of the prediction model M1 carried out in
[0055] A set of features and feature quantities is set for the data 13a, 13b, 13c. The description of the features is the same as that in Figure 1 the description carried out in. For the data 13a, the feature quantity of the feature "Age" is "60". The feature quantity of the feature "Sex" is "F". The feature quantity of the feature "BP" is "180". The feature quantity of the feature "BMI" is "40".
[0056] For the data 13b, the feature quantity of the feature "Age" is "50". The feature quantity of the feature "Sex" is "F". The feature quantity of the feature "BP" is "170". The feature quantity of the feature "BMI" is "36".
[0057] For the data 13c, the feature quantity of the feature "Age" is "62". The feature quantity of the feature "Sex" is "M (Male)". The feature quantity of the feature "BP" is "170". The feature quantity of the feature "BMI" is "30".
[0058] In Figure 3 the example shown, when the data 13a is input into the prediction model M1, the predicted value is "0.4". When the data 13b is input into the prediction model M1, the predicted value is "0.3". When the data 13c is input into the prediction model M1, the predicted value is "0.1". For example, if a preset threshold is set to "0.5", the data 13a, 13b, 13c are determined to be abnormal data.
[0059] If a SHAP-based cause analysis is performed using the data 13a and the prediction model M1, Shapley values corresponding to each feature are calculated respectively. In Figure 3 the example shown, the Shapley value for the feature "Age" is "+0.4". The Shapley value for the feature "Sex" is "-0.3". The Shapley value for the feature "BP" is "+0.1". The Shapley value for the feature "BMI" is "+0.1".
[0060] If a SHAP-based cause analysis is performed using the data 13b and the prediction model M1, Shapley values corresponding to each feature are calculated respectively. In Figure 3In the example shown, the Shapley value for the feature "Age" is "+0.5". The Shapley value for the feature "Sex" is "-0.2". The Shapley value for the feature "BP" is "+0.2". The Shapley value for the feature "BMI" is "+0.1".
[0061] If a SHAP-based root cause analysis is performed using the data 13c and the prediction model M1, the Shapley values corresponding to each feature are calculated respectively. In Figure 3 the example shown, the Shapley value for the feature "Age" is "+0.6". The Shapley value for the feature "Sex" is "-0.3". The Shapley value for the feature "BP" is "-0.1". The Shapley value for the feature "BMI" is "+0.1".
[0062] The average values of the Shapley values for each feature are as follows. The average value of the Shapley value for the feature "Age" is "+0.5". The average value of the Shapley value for the feature "Sex" is "-0.28". The average value of the Shapley value for the feature "BP" is "+0.1". The average value of the Shapley value for the feature "BMI" is "+0.1".
[0063] According to Figure 3 the calculation results of the Shapley values (average values) shown, the feature that has the greatest impact on the predicted value of the prediction model M1 is the feature "Age", and the feature with the second greatest impact is the feature "Sex".
[0064] The above has illustrated an example of root cause analysis (SHAP). In Figures 1 to 3 the example shown, Age, SEX, BP, and BMI are used as features for illustration, but even for the feature quantities of other features, root cause analysis can be performed in the same way. For example, the feature quantities of other features are feature quantities such as pressure, temperature, flow rate, and operating status set for the process data of the workshop.
[0065] (Description of the processing of the analysis device 100)
[0066] Next, an example of the processing of the analysis device 100 according to Embodiment 1 will be described. Figure 4 is a diagram for explaining the processing of the analysis device 100 according to Embodiment 1. For example, the analysis device 100 is connected to the system 50 to be monitored.
[0067] The system 50 is a system for managing a workshop, and outputs process data 5 related to a plurality of field instruments included in the workshop to the analysis device 100 at regular intervals. The analysis device 100 performs unsupervised learning, root cause analysis, supervised learning, evaluation of the first prediction model, and re-execution of unsupervised learning, which will be described below, based on the process data 5.
[0068] (Unsupervised learning in Embodiment 1)
[0069] The unsupervised learning performed by the analysis device 100 will be described. In Embodiment 1, a first learning data set 141 is prepared in advance. A plurality of process data collected during a period when no abnormality occurs in the system 50 are registered in the first learning data set 141. The first learning data set 141 is used when performing unsupervised learning of the first prediction model 142. The first prediction model 142 is One Class SVM or the like.
[0070] Figure 5 It is a diagram showing an example of the data structure of the learning data set related to Embodiment 1. As Figure 5 shown, the first learning data set 141 has an item number, a timestamp, a first feature, a second feature, a third feature, a fourth feature, and an evaluation result. The item number is a number for identifying the process data included in the first learning data set 141. The timestamp is the time when the corresponding process data is measured. The first feature quantity, the second feature quantity, the third feature quantity, and the fourth feature quantity are feature quantities of respective features of the workshop.
[0071] The evaluation result indicates the evaluation result when the corresponding process data is input to the first prediction model 142 after unsupervised learning is completed. When the predicted value is greater than or equal to the threshold when the process data is input to the first prediction model 142, the evaluation result is "normal". When the predicted value is less than the threshold when the process data is input to the first prediction model 142, the evaluation result is "abnormal". In Embodiment 1, the evaluation result may not be included in the first learning data set 141.
[0072] In addition, in the information shown in the first learning data set 141, a group of the first feature quantity, the second feature quantity, the third feature quantity, and the fourth feature quantity included in one record is used as one learning data.
[0073] The analysis device 100 performs unsupervised learning of the first prediction model 142 based on the first learning data set 141. Since a plurality of process data (learning data) collected during a period when no abnormality occurs in the system 50 are registered in the first learning data set 141, the analysis device 100 learns the distribution of the feature quantities of the process data in the normal state by performing unsupervised learning.
[0074] (Root cause analysis in Embodiment 1)
[0075] After the unsupervised learning of the first prediction model 142 is completed, the analysis device 100 performs root cause analysis using the first prediction model 142. For example, the analysis device 100 determines whether the input process data is normal data or abnormal data by inputting the process data obtained from the system 50 in real time into the first prediction model 142.
[0076] When the predicted value when inputting the process data into the first prediction model 142 is greater than or equal to a preset threshold, the analysis device 100 determines the process data as normal data. On the other hand, when the predicted value when inputting the process data into the first prediction model 142 is less than the preset threshold, the analysis device 100 determines the process data as abnormal data. The analysis device 100 repeatedly performs the above processing until abnormal data at multiple x points is detected.
[0077] Figure 6 It is a diagram showing an example of the determination result of the process data obtained in real time. As Figure 6 shown, the evaluation result table T1 includes item number, timestamp, first feature, second feature, third feature, fourth feature, and evaluation result. The descriptions of the item number, timestamp, first to fourth feature quantities, and evaluation result are the same as those Figure 5 described in. In the Figure 6 example shown, the process data corresponding to item numbers 0 to 5, 11, and 12 is determined as normal data. The process data corresponding to item numbers 6 to 10 is determined as abnormal data.
[0078] The analysis device 100 performs root cause analysis on the abnormal data at multiple x points. The root cause analysis performed by the analysis device 100 is the same as the Figures 1 to 3 root cause analysis described in. The analysis device 100 outputs the result of the root cause analysis.
[0079] The analysis device 100 uses the abnormal data at multiple x points in the supervised learning described below.
[0080] (Supervised learning of Embodiment 1)
[0081] The analysis device 100 uses the first learning data set 141 used in the unsupervised learning of the first prediction model 142 as the "normal data" for the supervised learning of the second prediction model 143. The analysis device 100 sets the abnormal data at multiple x points detected during the above root cause analysis as the "abnormal data" for the supervised learning of the second prediction model 143.
[0082] For example, the analysis device 100 prepares a second learning dataset for supervised learning by performing the following processes. In Figure 4 the illustration of the second learning dataset is omitted. The analysis device 100 labels the process data included in the first learning dataset 141 with the label "1 (normal)". The analysis device 100 labels the abnormal data at multiple x points with the label "0 (abnormal)".
[0083] The analysis device 100 registers the labeled process data in the second learning dataset. The analysis device 100 performs supervised learning on the second prediction model 143 based on the error propagation method or the like using the second learning dataset. The second prediction model 143 is an NN (Neural Network) or the like.
[0084] For example, the analysis device 100 inputs input data (for example, a group of the first feature quantity, the second feature quantity, the third feature quantity, and the fourth feature quantity) into the second prediction model 143, and updates the parameters of the second prediction model 143 in such a manner that the value output from the second prediction model 143 approaches the value of the label.
[0085] When the process data is input into the second prediction model 143 for which supervised learning has been completed, if the predicted value of the second prediction model 143 is greater than or equal to the threshold value, the input process data is "normal data". On the other hand, when the process data is input into the second prediction model 143 for which supervised learning has been completed, if the predicted value of the second prediction model 143 is less than the threshold value, the input process data is "abnormal data".
[0086] (Evaluation of the First Prediction Model in Embodiment 1)
[0087] The analysis device 100 evaluates the first prediction model 142 using the second prediction model 143 for which supervised learning has been completed. For example, the analysis device 100 inputs the process data acquired from the system 50 in real time into the first prediction model 142 and the second prediction model 143, and obtains prediction results from the first prediction model 142 and the second prediction model 143. When the prediction results of the first prediction model 142 and the second prediction model 143 are the same, the analysis device 100 evaluates that the performance of the first prediction model 142 has not deteriorated. On the other hand, when the prediction results of the first prediction model 142 and the second prediction model 143 are different, the analysis device 100 evaluates that the performance of the first prediction model 142 has deteriorated.
[0088] Figure 7 is a diagram for explaining the evaluation of the first prediction model. In Figure 7In the example shown, for the sake of description, the feature quantity space F1 is represented by two axes. The vertical axis is set as the axis corresponding to the first feature quantity, and the horizontal axis is set as the axis corresponding to the second feature quantity. In the feature quantity space F1, the region F1a to the left of the line segment l1 is the region where the second prediction model 143 determines normal data. The region F1b to the right of the line segment l1 is the region where the second prediction model 143 determines abnormal data.
[0089] The circular symbols and triangular symbols drawn in the feature quantity space F1 correspond to the process data. In addition, the process data of the circular symbols are the process data determined as normal data by the first prediction model 142. The process data of the triangular symbols are the process data determined as abnormal data by the first prediction model 142.
[0090] In Figure 7 In the example shown, the process data of the triangular symbols are included in the region F1a, and the process data of the circular symbols are included in the region F1b. Therefore, for multiple process data, the prediction results of the first prediction model 142 and the second prediction model 143 are different, and the analysis device 100 evaluates that the performance of the first prediction model 142 has deteriorated.
[0091] In addition, the analysis device 100 can perform the following processing to evaluate the first prediction model 142. The analysis device 100 inputs the process data obtained from the system 50 in real time into the first prediction model 142 and obtains the data determined as abnormal data by the first prediction model 142. The analysis device 100 repeatedly executes the above processing to obtain abnormal data at multiple x points.
[0092] The analysis device 100 inputs the abnormal data at multiple x points into the second prediction model 143 respectively and obtains the prediction results of the second prediction model 143. When less than a specified ratio of the abnormal data among the abnormal data at multiple x points is determined as normal data by the second prediction model 143, the analysis device 100 evaluates that the performance of the first prediction model 142 has not deteriorated. On the other hand, when greater than or equal to the specified ratio of the abnormal data among the abnormal data at multiple x points is determined as normal data by the second prediction model 143, the analysis device 100 evaluates that the performance of the first prediction model 142 has deteriorated.
[0093] When the performance of the first prediction model 142 deteriorates, the analysis device 100 can perform a cause analysis using the second prediction model 143.
[0094] (Re - execution of unsupervised learning in Embodiment 1)
[0095] In the case where the performance of the first prediction model 142 is evaluated to have deteriorated, the analysis device 100 performs the following processing. The analysis device 100 deletes the old process data registered in the first learning data set 141. The analysis device 100 inputs the process data output from the system 50 into the second prediction model 143 to determine whether the system 50 has an abnormality. The analysis device 100 newly registers the process data during the period when the system 50 has no abnormality into the first learning data set 141.
[0096] The analysis device 100 uses the first learning data set 141 newly registered with the process data and performs unsupervised learning on the first prediction model 142 again.
[0097] The above has described the unsupervised learning, cause analysis, supervised learning, evaluation of the first prediction model, and re-execution of unsupervised learning performed by the analysis device 100.
[0098] As described above, the analysis device 100 according to Embodiment 1 uses the plurality of abnormal data detected by the first prediction model 142 that has performed unsupervised learning and the first learning data set 141 obtained when the system 50 is operating normally to perform supervised learning of the second prediction model 143. The analysis device 100 inputs the same data as the data input to the first prediction model 142 into the second prediction model 143, and evaluates whether the performance of the first prediction model 142 has deteriorated based on the prediction result of the first prediction model 142 and the prediction result of the second prediction model 143. In the case where the performance of the first prediction model 142 has deteriorated, the analysis device 100 performs unsupervised learning of the first prediction model 142 again.
[0099] Thereby, it is possible to detect a deterioration in the performance of the first prediction model 142 used in the case of performing cause analysis of data, and to perform re-learning of the first prediction model 142 at an appropriate timing, so that the reliability of cause analysis can be improved.
[0100] (Functional Structure of the Analysis Device 100 According to Embodiment 1)
[0101] Next, an Figure 4 exemplary structure of the analysis device 100 will be described. Figure 8 is a functional block diagram showing the functional structure of the analysis device according to Embodiment 1. As Figure 8 shown, the analysis device 100 includes a communication unit 110, an input unit 120, a display unit 130, a storage unit 140, and a control unit 150. In addition, the functional units included in the analysis device 100 are not limited to the illustrated functional units, and other functional units may also be provided.
[0102] The communication unit 110 is for communicating with Figure 4The processing unit that controls the communication between the system 50 to be monitored and other devices shown is implemented by a communication interface or the like. For example, the communication unit 110 receives process data from the system 50.
[0103] The input unit 120 is a processing unit for inputting various information to the control unit 150 of the analysis device 100, and is implemented by a keyboard, a mouse, a touch panel, or the like.
[0104] The display unit 130 is a processing unit for displaying the information output from the control unit 150, and is implemented by a display or the like. For example, the display unit 130 displays the result of cause analysis.
[0105] The storage unit 140 stores the first learning data set 141, the first prediction model 142, the second prediction model 143, and the second learning data set 144. The storage unit 140 is implemented by a memory, a hard disk, or the like.
[0106] The first learning data set 141 has process data collected during the period when no abnormality occurred in the system 50. Other descriptions of the first learning data set 141 are the same as those Figure 5 described in etc. regarding the first learning data set 141.
[0107] The first prediction model 142 is One Class SVM or the like. The first prediction model 142 performs unsupervised learning based on the first learning data set 141 through the unsupervised learning unit 152 described later.
[0108] The second prediction model 143 is NN or the like. The second prediction model 143 performs supervised learning based on the second learning data set 144 through the supervised learning unit 155 described later.
[0109] The second learning data set 144 has a plurality of labeled process data. For example, it has information indicating that the label "1 (normal)" is attached to the process data included in the first learning data set 141, and information indicating that the label "0 (abnormal)" is attached to the abnormal data at multiple x points.
[0110] The control unit 150 is a processing unit that controls the entire analysis device 100, and is implemented by a processor or the like, for example. The control unit 150 includes an acquisition unit 151, an unsupervised learning unit 152, a detection unit 153, a cause analysis unit 154, a supervised learning unit 155, an evaluation unit 156, and a relearning unit 157.
[0111] The acquisition unit 151 is a processing unit that acquires process data from the system 50 in real time. The acquisition unit 151 outputs the acquired process data to the detection unit 153 and the evaluation unit 156.
[0112] While the acquisition unit 151 does not detect abnormal data using the detection unit 153 described below, the process data acquired from the system 50 is registered in the first learning data set 141.
[0113] The acquisition unit 151 annotates the process data set for the first learning data set 141 with the label "1 (normal)" and registers it in the second learning data set 144.
[0114] The unsupervised learning unit 152 performs unsupervised learning on the first prediction model 142 based on the first learning data set 141. Since a plurality of process data (learning data) collected during the period when no abnormality occurred in the system 50 are registered in the first learning data set 141, the first prediction model 142 learns the distribution of the feature amounts of the process data in the normal state.
[0115] For example, if process data is input to the first prediction model 142 after unsupervised learning is completed, a prediction value corresponding to the distance between the feature amount of the input process data and the feature amount of the distribution of the process data in the normal state is output. The closer the distance between the feature amount of the input process data and the feature amount of the distribution of the process data in the normal state, the larger the prediction value.
[0116] Other processing of the unsupervised learning unit 152 is the same as the above description regarding (unsupervised learning).
[0117] The detection unit 153 inputs the process data to the first prediction model 142 after unsupervised learning is completed, and determines whether the input process data is normal data or abnormal data based on the prediction value. When the prediction value is greater than or equal to a preset threshold (for example, 0.5), the detection unit 153 determines that the input process data is normal data. On the other hand, when the prediction value is less than the preset threshold, the detection unit 153 determines that the input process data is abnormal data.
[0118] The detection unit 153 repeatedly performs the above processing and detects abnormal data at multiple x points. The detection unit 153 outputs the abnormal data at multiple x points to the root cause analysis unit 154. In addition, the detection unit 153 annotates the abnormal data (process data) at multiple x points with the label "0 (abnormal)" and registers it in the second learning data set 144.
[0119] The detection unit 153 notifies the acquisition unit 151 of the period during which no abnormal data is detected (the period during which no abnormality occurred in the system 50).
[0120] The root cause analysis unit 154 performs root cause analysis using the abnormal data at multiple x points and the first prediction model 142 after unsupervised learning is completed. The root cause analysis performed by the root cause analysis unit 154 is the same as the root cause analysis described in Figures 1 to 3 The root cause analysis unit 154 outputs the result of the root cause analysis to the display unit 130 and the like.
[0121] The supervised learning unit 155 performs supervised learning on the second prediction model 143 based on the second learning data set 144 and based on the error backpropagation method or the like. Other descriptions of the supervised learning unit 155 are the same as the above descriptions of (the supervised learning of Embodiment 1).
[0122] The evaluation unit 156 evaluates the first prediction model 142 by using the second prediction model 143 for which supervised learning has been completed. For example, the evaluation unit 156 inputs the process data obtained from the system 50 in real time into the first prediction model 142 and the second prediction model 143, and obtains prediction results from the first prediction model 142 and the second prediction model 143.
[0123] When the prediction results of the first prediction model 142 and the second prediction model 143 are the same, the evaluation unit 156 evaluates that the performance of the first prediction model 142 has not deteriorated. On the other hand, when the prediction results of the first prediction model 142 and the second prediction model 143 are different, the evaluation unit 156 evaluates that the performance of the first prediction model 142 has deteriorated.
[0124] When it is evaluated that the performance of the first prediction model 142 has deteriorated, the evaluation unit 156 outputs a relearning request to the relearning unit 157. Other descriptions of the evaluation unit 156 are the same as the above descriptions of (the evaluation of the first prediction model of Embodiment 1).
[0125] When receiving the relearning request from the evaluation unit 156, the relearning unit 157 sets that the performance of the first prediction model 142 has deteriorated and performs relearning of the first prediction model 142. For example, the relearning unit 157 performs the following processing.
[0126] The relearning unit 157 deletes the old process data registered in the first learning data set 141 at the timing of receiving the relearning request. After deleting the old process data registered in the first learning data set 141, the relearning unit 157 waits until the process data during the period when the system 50 has not generated an abnormality is re-registered in the first learning data set 141 by using the above acquisition unit 151.
[0127] After the relearning unit 157 re-registers the process data during the period when the system 50 has not generated an abnormality in the first learning data set 141 by using the acquisition unit 151, the relearning unit 157 performs unsupervised learning on the first prediction model 142 based on the first learning data set 141. The unsupervised learning performed by the relearning unit 157 is the same as the unsupervised learning performed by the above unsupervised learning unit 152.
[0128] In addition, in Figure 8In the above, the unsupervised learning unit 152 and the relearning unit 157 are described using different modules, but the unsupervised learning unit 152 may also have the functions of the relearning unit 157.
[0129] (Processing Flow of the Analysis Device 100 in Embodiment 1)
[0130] Next, an example of the processing flow of the analysis device 100 in Embodiment 1 will be described. Figure 9 is a flowchart showing the processing flow of the analysis device 100 in Embodiment 1. As Figure 9 shown, the unsupervised learning unit 152 of the analysis device 100 performs unsupervised learning for the first prediction model 142 based on the first learning data set 141 (step S101).
[0131] The acquisition unit 151 of the analysis device 100 acquires process data from the system 50 in real time (step S102). The detection unit 153 of the analysis device 100 inputs the process data into the first prediction model 142 and determines whether the process data is abnormal data (step S103).
[0132] The cause analysis unit 154 of the analysis device 100 performs cause analysis when abnormal data is detected (step S104). When the analysis device 100 does not detect abnormal data at multiple x points (No in step S105), it proceeds to step S102. On the other hand, when the analysis device 100 detects abnormal data at multiple x points (Yes in step S105), it proceeds to step S106.
[0133] The analysis device 100 generates the second learning data set 144 (step S106). The supervised learning unit 155 of the analysis device 100 performs supervised learning for the second prediction model 143 based on the second learning data set 144 (step S107).
[0134] The evaluation unit 156 of the analysis device 100 evaluates the first prediction model 142 based on the prediction result when the process data is input into the first prediction model 142 and the prediction result when the process data is input into the second prediction model 143 (step S108).
[0135] When the accuracy of the first prediction model does not decrease (No in step S109), the analysis device 100 proceeds to step S102. On the other hand, when the accuracy of the first prediction model decreases (Yes in step S109), the analysis device 100 proceeds to step S110.
[0136] The analysis device 100 updates the first learning data set 141 (step S110). The relearning unit 157 of the analysis device 100 relearns (unsupervised learning) the first prediction model 142 based on the first learning data set 141 (step S111), and proceeds to step S102.
[0137] (Effect of Embodiment 1)
[0138] Next, the effect of the analysis device 100 according to Embodiment 1 will be described. As described above, the analysis device 100 performs supervised learning of the second prediction model 143 using a plurality of abnormal data detected by the first prediction model 142 that has performed unsupervised learning and the first learning data set 141 acquired when the system 50 is operating normally. The analysis device 100 inputs the same data as the data input to the first prediction model 142 to the second prediction model 143, and evaluates whether the performance of the first prediction model 142 has deteriorated based on the prediction result of the first prediction model 142 and the prediction result of the second prediction model 143. When the performance of the first prediction model 142 deteriorates, the analysis device 100 performs unsupervised learning of the first prediction model 142 again.
[0139] Thereby, it is possible to detect a deterioration in the performance of the first prediction model 142 used in performing root cause analysis of data, and to perform relearning of the first prediction model 142 at an appropriate timing, so that the reliability of root cause analysis can be improved.
[0140] (Embodiment 2)
[0141] (Description of the processing of the analysis device 200)
[0142] Next, an example of the processing of the analysis device 200 according to Embodiment 2 will be described. Figure 10 is a diagram for explaining the processing of the analysis device according to Embodiment 2. For example, the analysis device 200 is connected to the system 50 to be monitored. The description of the system 50 is the same as that of Figure 4 the system 50.
[0143] The analysis device 200 performs the following-described unsupervised learning, root cause analysis, supervised learning, evaluation of the first prediction model, and re-execution of unsupervised learning based on the process data 5.
[0144] (Unsupervised learning of Embodiment 2)
[0145] The analysis device 200 performs unsupervised learning of the first prediction model 142 based on the first learning data set 141. The unsupervised learning performed by the analysis device 200 is the same as the unsupervised learning performed by the analysis device 100 in Embodiment 1. In addition, the descriptions of the first learning data set 141 and the first prediction model 142 are the same as those given in Embodiment 1.
[0146] (Cause analysis in Embodiment 2)
[0147] After the unsupervised learning of the first prediction model 142 is completed, the analysis device 200 performs cause analysis using the first prediction model 142. The cause analysis performed by the analysis device 200 is the same as the cause analysis performed by the analysis device 100 in Embodiment 1.
[0148] (Supervised learning in Embodiment 2)
[0149] The analysis device 200 uses the process data with an evaluation result of "normal" among the process data included in the first learning data set 141 used in the unsupervised learning of the first prediction model 142 as the "normal data" for the supervised learning of the second prediction model 242. For example, regarding Figure 5 the process data shown, the analysis device 200 uses the process data with item numbers 0 to 3, 5, and 6 as the "normal data" for the supervised learning of the second prediction model 242. In addition, the analysis device 200 sets the abnormal data at multiple x points detected during the above-mentioned cause analysis as the "abnormal data" for the supervised learning of the second prediction model 242.
[0150] For example, the analysis device 200 prepares a second learning data set for performing supervised learning by executing the following processing. The illustration of the second learning data set is omitted in Figure 10 . The analysis device 200 labels the normal data in the first learning data set 141 with the label "1 (normal)". The analysis device 200 labels the abnormal data at multiple x points with the label "0 (abnormal)".
[0151] The analysis device 200 registers the labeled process data in the second learning data set. The analysis device 200 uses the second learning data set and performs supervised learning for the second prediction model 243 based on the error propagation method or the like. The second prediction model 243 is an NN or the like.
[0152] For example, the analysis device 200 inputs input data (for example, a set of the first feature quantity, the second feature quantity, the third feature quantity, and the fourth feature quantity) into the second prediction model 243, and updates the parameters of the second prediction model 243 in such a way that the value output from the second prediction model 243 approaches the value of the label.
[0153] (Evaluation of the First Prediction Model in Embodiment 2)
[0154] The analysis device 200 evaluates the first prediction model 142 by using the second prediction model 243 that has completed supervised learning. For example, the analysis device 200 inputs the process data acquired from the system 50 in real time into the first prediction model 142 and the second prediction model 243, and obtains prediction results from the first prediction model 142 and the second prediction model 243. When the prediction results of the first prediction model 142 and the second prediction model 243 are the same, the analysis device 200 evaluates that the performance of the first prediction model 142 has not deteriorated. On the other hand, when the prediction results of the first prediction model 142 and the second prediction model 243 are different, the analysis device 200 evaluates that the performance of the first prediction model 142 has deteriorated.
[0155] In addition, the analysis device 200 can evaluate the first prediction model 142 by performing the following processing. The analysis device 200 inputs the process data acquired from the system 50 in real time into the first prediction model 142, and acquires the data determined as abnormal data by the first prediction model 142. The analysis device 200 repeatedly executes the above processing and acquires abnormal data at multiple x points.
[0156] The analysis device 200 inputs the abnormal data at multiple x points into the second prediction model 243 respectively, and obtains the prediction results of the second prediction model 243. When the second prediction model 243 determines that the abnormal data is normal data for less than a specified ratio of the abnormal data at multiple x points, the analysis device 200 evaluates that the performance of the first prediction model 142 has not deteriorated. On the other hand, when the second prediction model 243 determines that the abnormal data is normal data for greater than or equal to the specified ratio of the abnormal data at multiple x points, the analysis device 200 evaluates that the performance of the first prediction model 142 has deteriorated.
[0157] The analysis device 200 can perform cause analysis by using the second prediction model 243 when the performance of the first prediction model 142 deteriorates.
[0158] (Re - execution of Unsupervised Learning in Embodiment 2)
[0159] When the analysis device 200 evaluates that the performance of the first prediction model 142 has deteriorated, it performs the following processing. The analysis device 200 deletes the old process data registered in the first learning data set 141. The analysis device 200 inputs the process data output from the system 50 into the second prediction model 243 to determine whether the system 50 has an abnormality. The analysis device 200 newly registers the process data during the period when the system 50 has no abnormality in the first learning data set 141.
[0160] The analysis device 200 uses the first learning data set 141 newly registered with process data and performs unsupervised learning on the first prediction model 142 again.
[0161] The above has described the unsupervised learning, cause analysis, supervised learning, evaluation of the first prediction model, and re - execution of unsupervised learning performed by the analysis device 200.
[0162] Regarding the analysis device 100 according to the above - mentioned Embodiment 1, instead of based on the evaluation result, a plurality of process data collected during the period when the system 50 did not generate an abnormality were used as normal data for supervised learning of the second prediction model 143. In contrast, regarding the analysis device 200 according to Embodiment 2, a plurality of process data collected during the period when the system 50 did not generate an abnormality and process data with an evaluation result of "normal" were used as normal data to perform supervised learning of the second prediction model 243.
[0163] Thus, supervised learning is performed using normal data from which abnormal data has been removed from the learning data (process data). Therefore, compared with the second prediction model 143 of Embodiment 1, the prediction accuracy of the second prediction model 243 can be improved.
[0164] (Functional structure of the analysis device 200 of Embodiment 2)
[0165] Next, an explanation will be given of Figure 10 the structural example of the analysis device 200 shown. Figure 11 It is a functional block diagram showing the functional structure of the analysis device according to Embodiment 2. As Figure 11 shown, the analysis device 200 has a communication unit 110, an input unit 120, a display unit 130, a storage unit 240, and a control unit 250. In addition, the functional units of the analysis device 200 are not limited to the illustrated functional units and may also have other functional units.
[0166] The explanations of the communication unit 110, the input unit 120, and the display unit 130 are the same as the explanations of the communication unit 110, the input unit 120, and the display unit 130 described in Figure 8 the same.
[0167] The storage unit 240 stores the first learning data set 141, the first prediction model 142, the second prediction model 243, and the second learning data set 244. The storage unit 240 is implemented by a memory, a hard disk, etc.
[0168] The first learning data set 141 has process data collected during the period when the system 50 did not generate an abnormality. Other explanations of the first learning data set 141 are the same as the explanations of the first learning data set 141 described in Figure 5 the same.
[0169] The first prediction model 142 is an One Class SVM or the like. The first prediction model 142 is based on the first learning data set 141 and performs unsupervised learning using the unsupervised learning unit 252 described later.
[0170] The second prediction model 243 is an NN or the like. The second prediction model 243 is based on the second learning data set 244 and performs supervised learning using the supervised learning unit 255 described later.
[0171] The second learning data set 244 has a plurality of labeled process data. For example, it has information indicating that the normal data included in the first learning data set 141 is labeled with "1 (normal)", and information indicating that the abnormal data at multiple x points is labeled with "0 (abnormal)".
[0172] The control unit 250 is a processing unit that controls the entire analysis device 200 and is implemented by, for example, a processor or the like. The control unit 250 includes an acquisition unit 251, an unsupervised learning unit 252, a detection unit 253, a cause analysis unit 254, a supervised learning unit 255, an evaluation unit 256, and a re-learning unit 257.
[0173] The acquisition unit 251 is a processing unit that acquires process data from the system 50 in real time. The acquisition unit 251 outputs the acquired process data to the detection unit 253 and the evaluation unit 256.
[0174] The acquisition unit 251 uses the detection unit 353 described later to register the process data acquired from the system 50 during the period when no abnormal data is detected in the first learning data set 141.
[0175] The acquisition unit 251 labels the normal data (process data with an evaluation result of "normal") set in the first learning data set 141 with "1 (normal)" and registers it in the second learning data set 244.
[0176] The unsupervised learning unit 252 performs unsupervised learning on the first prediction model 142 based on the first learning data set 141. Other descriptions of the unsupervised learning unit 252 are the same as those of the unsupervised learning unit 152 in the first embodiment.
[0177] The detection unit 253 inputs the process data into the first prediction model 142 after unsupervised learning and determines whether the input process data is normal data or abnormal data based on the predicted value. When the predicted value is greater than or equal to a preset threshold (for example, 0.5), the detection unit 253 determines the input process data as normal data. On the other hand, when the predicted value is less than the preset threshold, the detection unit 253 determines the input process data as abnormal data. The detection unit 253 sets the determination result (evaluation result) in the first learning data set 141.
[0178] The detection unit 253 repeatedly executes the above process and detects abnormal data at multiple x points. The detection unit 253 outputs the abnormal data at multiple x points to the root cause analysis unit 254. In addition, the detection unit 253 labels the abnormal data (process data) at multiple x points with the label "0 (abnormal)" and registers it in the second learning data set 244.
[0179] The detection unit 253 notifies the acquisition unit 251 of the period during which no abnormal data is detected (the period during which the system 50 does not generate an abnormality).
[0180] The root cause analysis unit 254 performs root cause analysis using the abnormal data at multiple x points and the first prediction model 142 that has completed unsupervised learning. The root cause analysis performed by the root cause analysis unit 254 is the same as that of the root cause analysis unit 154 in Embodiment 1. The root cause analysis unit 254 outputs the result of the root cause analysis to the display unit 130 and the like.
[0181] The supervised learning unit 255 performs supervised learning on the second prediction model 243 based on the second learning data set 244 and based on the error backpropagation method or the like. Other descriptions of the supervised learning unit 255 are the same as the above descriptions regarding (supervised learning in Embodiment 2).
[0182] The evaluation unit 256 evaluates the first prediction model 142 using the second prediction model 243 that has completed supervised learning. For example, the evaluation unit 256 inputs the process data acquired from the system 50 in real time into the first prediction model 142 and the second prediction model 243, and obtains prediction results from the first prediction model 142 and the second prediction model 243.
[0183] When the prediction results of the first prediction model 142 and the second prediction model 243 are the same, the evaluation unit 256 evaluates that the performance of the first prediction model 142 has not deteriorated. On the other hand, when the prediction results of the first prediction model 142 and the second prediction model 243 are different, the evaluation unit 256 evaluates that the performance of the first prediction model 142 has deteriorated.
[0184] When it is evaluated that the performance of the first prediction model 142 has deteriorated, the evaluation unit 256 outputs a relearning request to the relearning unit 257. Other descriptions of the evaluation unit 256 are the same as the above descriptions regarding (evaluation of the first prediction model in Embodiment 2).
[0185] When the relearning request is received from the evaluation unit 256, the relearning unit 257 assumes that the performance of the first prediction model 142 has deteriorated and performs relearning of the first prediction model 142. Other descriptions of the relearning unit 257 are the same as the descriptions of the relearning unit 157 in Embodiment 1.
[0186] (Processing flow of the analysis device 200 in Embodiment 2)
[0187] Next, an example of the processing flow of the analysis device 200 according to Embodiment 2 will be described. Figure 12 is a flowchart showing the processing flow of the analysis device 200 according to Embodiment 2. As Figure 12 shown, the unsupervised learning unit 252 of the analysis device 200 performs unsupervised learning on the first prediction model 142 based on the first learning data set 141 (step S201).
[0188] The acquisition unit 251 of the analysis device 200 acquires process data from the system 50 in real time (step S202). The detection unit 253 of the analysis device 200 inputs the process data into the first prediction model 142 and determines whether the process data is abnormal data (step S203).
[0189] When the analysis device 200 detects abnormal data, the cause analysis unit 254 performs cause analysis (step S204). When the analysis device 200 does not detect abnormal data at multiple x points (No in step S205), it proceeds to step S202. On the other hand, when the analysis device 200 detects abnormal data at multiple x points (Yes in step S205), it proceeds to step S206.
[0190] The analysis device 200 generates a second learning data set 244 based on the normal data included in the first learning data set 141 and the detected abnormal data (step S206). The supervised learning unit 255 of the analysis device 200 performs supervised learning on the second prediction model 243 based on the second learning data set 244 (step S207).
[0191] The evaluation unit 256 of the analysis device 200 evaluates the first prediction model 142 based on the prediction result when the process data is input into the first prediction model 142 and the prediction result when the process data is input into the second prediction model 243 (step S208).
[0192] When the accuracy of the first prediction model does not decrease (No in step S209), the analysis device 200 proceeds to step S202. On the other hand, when the accuracy of the first prediction model decreases (Yes in step S209), the analysis device 200 proceeds to step S210.
[0193] The analysis device 200 updates the first learning data set 141 (step S210). The relearning unit 257 of the analysis device 200 performs relearning (unsupervised learning) on the first prediction model 142 based on the first learning data set 141 (step S211) and proceeds to step S202.
[0194] (Effect of Embodiment 2)
[0195] Next, the effects of the analysis device 200 according to Embodiment 2 will be described. Regarding the analysis device 100 of the above-described Embodiment 1, instead of using the evaluation results, a plurality of process data collected during the period when the system 50 did not generate an abnormality were set as normal data, and supervised learning of the second prediction model 143 was performed. In contrast, the analysis device 200 of Embodiment 2 sets, as normal data, a plurality of process data collected during the period when the system 50 did not generate an abnormality and for which the evaluation result is "normal", and performs supervised learning of the second prediction model 243.
[0196] Accordingly, supervised learning is performed using normal data obtained by removing abnormal data from the learning data (process data). Therefore, compared with the second prediction model 143 of Embodiment 1, the prediction accuracy of the second prediction model 243 can be improved. In addition, by improving the prediction accuracy of the second prediction model 243, it is possible to more appropriately detect a decrease in the performance of the first prediction model 142.
[0197] (Embodiment 3)
[0198] (Description of the processing of the analysis device 300)
[0199] Next, an example of the processing of the analysis device 300 according to Embodiment 3 will be described. Figure 13 FIG. is a diagram for explaining the processing of the analysis device according to Embodiment 3. For example, the analysis device 300 is connected to the system 50 to be monitored. The description of the system 50 is the same as Figure 4 the description of the system 50 in
[0200] The analysis device 300 performs the unsupervised learning, root cause analysis, supervised learning, evaluation of the first prediction model, and re-execution of the unsupervised learning, which will be described below, based on the process data 5.
[0201] (Unsupervised learning of Embodiment 3)
[0202] The analysis device 300 performs unsupervised learning of the first prediction model 142 based on the first learning data set 141. The unsupervised learning performed by the analysis device 300 is the same as the unsupervised learning performed by the analysis device 100 of Embodiment 1. In addition, the description of the first learning data set 141 and the first prediction model 142 is the same as the description given in Embodiment 1.
[0203] (Root cause analysis of Embodiment 3)
[0204] After the unsupervised learning of the first prediction model 142 is completed, the analysis device 300 performs cause analysis using the first prediction model 142. The cause analysis performed by the analysis device 300 is the same as the cause analysis performed by the analysis device 100 in the first embodiment.
[0205] (Supervised learning of Embodiment 3)
[0206] The analysis device 300 uses the continuous y points immediately before the abnormal data of the plurality of x points detected during the above-mentioned cause analysis as the "normal data" for the supervised learning of the second prediction model 342. For example, the process data corresponding to item numbers 0 to 5 of the evaluation result table T1 of Figure 6 is used as the normal data. In addition, the analysis device 300 sets the abnormal data of the plurality of x points detected during the above-mentioned cause analysis as the "abnormal data" for the supervised learning of the second prediction model 342.
[0207] The analysis device 300 prepares a second learning dataset for performing supervised learning by executing the following processing. In Figure 13 the illustration of the second learning dataset is omitted. The analysis device 300 labels the normal data in the first learning dataset 141 with the label "1 (normal)". The analysis device 300 labels the abnormal data of the plurality of x points with the label "0 (abnormal)".
[0208] The analysis device 300 registers the labeled process data in the second learning dataset. The analysis device 300 uses the second learning dataset and performs supervised learning for the second prediction model 343 based on the error propagation method or the like. The second prediction model 343 is an NN or the like.
[0209] For example, the analysis device 300 inputs input data (for example, a group of the first feature quantity, the second feature quantity, the third feature quantity, and the fourth feature quantity) into the second prediction model 343, and updates the parameters of the second prediction model 343 so that the value output from the second prediction model 343 approaches the value of the label.
[0210] (Evaluation of the first prediction model in Embodiment 3)
[0211] The analysis device 300 evaluates the first prediction model 142 by using the second prediction model 343 that has completed supervised learning. For example, the analysis device 300 inputs the process data obtained from the system 50 in real time into the first prediction model 142 and the second prediction model 343, and obtains prediction results from the first prediction model 142 and the second prediction model 343. When the prediction results of the first prediction model 142 and the second prediction model 343 are the same, the analysis device 300 evaluates that the performance of the first prediction model 142 has not deteriorated. On the other hand, when the prediction results of the first prediction model 142 and the second prediction model 343 are different, the analysis device 300 evaluates that the performance of the first prediction model 142 has deteriorated.
[0212] In addition, the analysis device 300 can perform the following processing to evaluate the first prediction model 142. The analysis device 300 inputs the process data obtained from the system 50 in real time into the first prediction model 142, and obtains the data determined by the first prediction model 142 as abnormal data. The analysis device 300 repeatedly executes the above processing and obtains abnormal data at multiple x points.
[0213] The analysis device 300 inputs the abnormal data at multiple x points into the second prediction model 343 respectively, and obtains the prediction results of the second prediction model 343. When the second prediction model 343 determines that the abnormal data is normal data for less than a specified ratio of the abnormal data at multiple x points, the analysis device 300 evaluates that the performance of the first prediction model 142 has not deteriorated. On the other hand, when the second prediction model 343 determines that the abnormal data is normal data for a specified ratio or more of the abnormal data at multiple x points, the analysis device 300 evaluates that the performance of the first prediction model 142 has deteriorated.
[0214] When the performance of the first prediction model 142 deteriorates, the analysis device 200 can perform root cause analysis by using the second prediction model 343.
[0215] (Re - execution of unsupervised learning in Embodiment 3)
[0216] When it is evaluated that the performance of the first prediction model 142 has deteriorated, the analysis device 300 performs the following processing. The analysis device 300 deletes the old process data registered in the first learning data set 141. The analysis device 300 inputs the process data output from the system 50 into the second prediction model 343 to determine whether the system 50 has generated an abnormality. The analysis device 300 newly registers the process data during the period when the system 50 has not generated an abnormality in the first learning data set 141.
[0217] The analysis device 300 uses the first learning data set 141 in which the process data has been newly registered, and performs unsupervised learning on the first prediction model 142 again.
[0218] As described above, the analysis device 300 according to the third embodiment uses the continuous y points immediately before the abnormal data of the plurality of x points detected during the cause analysis as the "normal data" for the supervised learning of the second prediction model 342, and sets the abnormal data of the plurality of x points detected during the above-mentioned cause analysis as the "abnormal data" for the supervised learning of the second prediction model 342. Thereby, the supervised learning of the second prediction model 343 can be performed using the latest process data.
[0219] (Functional Structure of the Analysis Device 300 of the Third Embodiment)
[0220] Next, Figure 13 a structural example of the analysis device 300 shown will be described. Figure 14 is a functional block diagram showing the functional structure of the analysis device according to the third embodiment. As Figure 14 shown, the analysis device 300 includes a communication unit 110, an input unit 120, a display unit 130, a storage unit 340, and a control unit 350. In addition, the functional units included in the analysis device 300 are not limited to the illustrated functional units, and other functional units may also be included.
[0221] The descriptions of the communication unit 110, the input unit 120, and the display unit 130 are the same as Figure 8 the descriptions of the communication unit 110, the input unit 120, and the display unit 130 described in
[0222] The storage unit 340 stores the first learning data set 141, the first prediction model 142, the second prediction model 343, and the second learning data set 344. The storage unit 340 is implemented by a memory, a hard disk, or the like.
[0223] The first learning data set 141 has process data collected during the period when the system 50 has not generated an abnormality. Other descriptions of the first learning data set 141 are the same as Figure 5 the descriptions of the first learning data set 141 described in
[0224] The first prediction model 142 is One Class SVM or the like. The first prediction model 142 performs unsupervised learning based on the first learning data set 141 and using the unsupervised learning unit 352 described later.
[0225] The second prediction model 343 is NN or the like. The second prediction model 343 performs supervised learning based on the second learning data set 344 and using the supervised learning unit 355 described later.
[0226] The second learning dataset 344 includes normal data labeled with the label "1 (normal)" and abnormal data labeled with the label "0 (abnormal)". The normal data is the data of consecutive y points immediately before the abnormal data of multiple x points detected during root cause analysis. The abnormal data is the data of multiple x points detected during root cause analysis.
[0227] The control unit 350 is a processing unit that manages the overall processing of the analysis device 300 and is implemented by, for example, a processor. The control unit 350 includes an acquisition unit 351, an unsupervised learning unit 352, a detection unit 353, a root cause analysis unit 354, a supervised learning unit 355, an evaluation unit 356, and a re-learning unit 357.
[0228] The acquisition unit 351 is a processing unit that acquires process data from the system 50 in real time. The acquisition unit 351 outputs the acquired process data to the detection unit 353 and the evaluation unit 356.
[0229] The acquisition unit 351 registers the process data acquired from the system 50 during the period when abnormal data is not detected in the first learning dataset 141 by using the detection unit 353 described later.
[0230] The unsupervised learning unit 352 performs unsupervised learning on the first prediction model 142 based on the first learning dataset 141. Other descriptions of the unsupervised learning unit 352 are the same as those of the unsupervised learning unit 152 in the first embodiment.
[0231] The detection unit 353 inputs the process data into the first prediction model 142 that has completed unsupervised learning and determines whether the input process data is normal data or abnormal data based on the predicted value. When the predicted value is greater than or equal to a preset threshold (for example, 0.5), the detection unit 353 determines the input process data as normal data. On the other hand, when the predicted value is less than the preset threshold, the detection unit 353 determines the input process data as abnormal data.
[0232] The detection unit 353 repeatedly performs the above processing and detects abnormal data of multiple x points. The detection unit 253 outputs the abnormal data of multiple x points to the root cause analysis unit 254.
[0233] The detection unit 353 labels the data of consecutive y points (normal data) immediately before the abnormal data of multiple x points with the label "1 (normal)" and registers it in the second learning dataset 344. The detection unit 353 labels the abnormal data of multiple x points with the label "0 (abnormal)" and registers it in the second learning dataset 344.
[0234] The detection unit 353 notifies the acquisition unit 351 of the period during which abnormal data is not detected (the period when the system 50 does not generate abnormalities).
[0235] The cause analysis unit 354 performs cause analysis using abnormal data at multiple x points and the first prediction model 142 for which unsupervised learning has been completed. The cause analysis performed by the cause analysis unit 354 is the same as that of the cause analysis unit 154 in the first embodiment. The cause analysis unit 354 outputs the result of the cause analysis to the display unit 130 and the like.
[0236] The supervised learning unit 355 performs supervised learning on the second prediction model 343 based on the second learning data set 344 and based on the error propagation method or the like. Other descriptions of the supervised learning unit 355 are the same as the above descriptions regarding (the supervised learning in the third embodiment).
[0237] The evaluation unit 356 evaluates the first prediction model 142 using the second prediction model 343 for which supervised learning has been completed. For example, the evaluation unit 356 inputs the process data acquired from the system 50 in real time to the first prediction model 142 and the second prediction model 343, and obtains prediction results from the first prediction model 142 and the second prediction model 343.
[0238] When the prediction results of the first prediction model 142 and the second prediction model 343 are the same, the evaluation unit 356 evaluates that the performance of the first prediction model 142 has not decreased. On the other hand, when the prediction results of the first prediction model 142 and the second prediction model 343 are different, the evaluation unit 356 evaluates that the performance of the first prediction model 142 has decreased.
[0239] When the evaluation unit 356 evaluates that the performance of the first prediction model 142 has decreased, the evaluation unit 356 outputs a relearning request to the relearning unit 357. Other descriptions of the evaluation unit 356 are the same as the above descriptions regarding (the evaluation of the first prediction model in the third embodiment).
[0240] When the relearning unit 357 receives a relearning request from the evaluation unit 356, the relearning unit 357 assumes that the performance of the first prediction model 142 has decreased and performs relearning of the first prediction model 142. Other descriptions of the relearning unit 357 are the same as the descriptions of the relearning unit 157 in the first embodiment.
[0241] (Processing flow of the analysis device 300 in the third embodiment)
[0242] Next, an example of the processing flow of the analysis device 300 in the third embodiment will be described. Figure 15 is a flowchart showing the processing flow of the analysis device 300 in the third embodiment. As Figure 15 shown, the unsupervised learning unit 252 of the analysis device 300 performs unsupervised learning on the first prediction model 142 based on the first learning data set 141 (step S301).
[0243] The acquisition unit 251 of the analysis device 300 acquires process data from the system 50 in real time (step S302). The detection unit 353 of the analysis device 300 inputs the process data into the first prediction model 142 and determines whether the process data is abnormal data (step S303).
[0244] In the case where abnormal data is detected, the cause analysis unit 354 of the analysis device 300 performs cause analysis (step S304). When the analysis device 300 does not detect abnormal data at multiple x points (No in step S305), it proceeds to step S302. On the other hand, when the analysis device 300 detects abnormal data at multiple x points (Yes in step S305), it proceeds to step S306.
[0245] The analysis device 300 labels the abnormal data at multiple x points and the normal data at multiple y points, and generates a second learning data set (step S306). The supervised learning unit 355 of the analysis device 300 performs supervised learning of the second prediction model 343 based on the second learning data set 344 (step S307).
[0246] The evaluation unit 356 of the analysis device 300 evaluates the first prediction model 142 based on the prediction result when the process data is input into the first prediction model 142 and the prediction result when the process data is input into the second prediction model 343 (step S308).
[0247] When the accuracy of the first prediction model does not decrease (No in step S309), the analysis device 300 proceeds to step S302. On the other hand, when the accuracy of the first prediction model decreases (Yes in step S309), the analysis device 300 proceeds to step S310.
[0248] The analysis device 300 updates the first learning data set 141 (step S310). The relearning unit 257 of the analysis device 200 performs relearning (unsupervised learning) of the first prediction model 142 based on the first learning data set 141 (step S311), and then proceeds to step S302.
[0249] (Effect of Embodiment 3)
[0250] The analysis device 300 according to Embodiment 3 uses the consecutive y points immediately before the abnormal data at multiple x points detected during cause analysis as the "normal data" for supervised learning of the second prediction model 342, and sets the abnormal data at multiple x points detected during the above-mentioned cause analysis as the "abnormal data" for supervised learning of the second prediction model 342. Thus, it is possible to perform supervised learning of the second prediction model 343 using the latest process data.
[0251] (Embodiment 4)
[0252] In the above-described Embodiments 1 to 3, the determination of whether or not the system 50 has an abnormality is made using the first prediction model 142 or the second prediction model 143 (243, 343), but it is not limited thereto. For example, based on the prediction results of the first prediction model 142 or the second prediction model 143, the shop floor KPI (Key Performance Indicator) is further calculated, and based on the prediction results of the first prediction model 142 or the second prediction model 143 and the value of the shop floor KPI, it is determined whether or not the system 50 has an abnormality and a root cause analysis is performed.
[0253] (Description of the processing of the analysis device 400)
[0254] An example of the processing of the analysis device 400 according to Embodiment 4 will be described. Figure 16 FIG. is a diagram for explaining the processing of the analysis device according to Embodiment 4. For example, the analysis device 400 is connected to the system 50 to be monitored. The description of the system 50 is the same as that of Figure 4 the system 50.
[0255] The analysis device 400 performs supervised learning on the second prediction model 143 based on the pre-prepared normal data 60a and abnormal data 60b. The analysis device 400 can collect the normal data 60a using the methods shown in Embodiments 1 to 3, or can collect it using other methods. The analysis device 400 uses the abnormal data obtained by the first prediction model 142 that has completed unsupervised learning as the abnormal data 60b. The description of the first prediction model 142 is the same as that described in Embodiment 1. In addition, the supervised learning performed by the analysis device 400 on the second prediction model 143 is the same as that described in Embodiment 1.
[0256] The analysis device 400 inputs the process data 5 into the second prediction model 143 that has completed supervised learning, and determines whether the process data 5 is abnormal data.
[0257] In addition, the analysis device 400 inputs the process data 5 into the shop floor KPI calculation model 445 and calculates the value of the shop floor KPI. In addition to the feature quantities described in Embodiment 1, the process data 5 includes feature quantities related to the productivity, quality, and cost of the shop floor, etc.
[0258] The shop floor KPI calculation model 445 is a model that calculates the shop floor KPI for the specified feature quantities included in the process data 5. For example, the shop floor KPI calculation model 445 calculates the shop floor KPI based on Equation (1). For example, the actual performance value is the specified feature quantities (quality of the product, CO2 emission amount, etc.) included in the process data 5, and the target value is a pre-set value.
[0259] Workshop KPI = (Actual performance value ÷ Target value) × 100…(1)
[0260] Figure 17 This is a diagram for explaining an example of the determination strategy of the analysis device according to Embodiment 4. For example, when the determination result when inputting process data into the second prediction model 143 is "abnormal data" and the KPI value when inputting the process data into the workshop KPI calculation model 445 is less than the threshold value, the analysis device 400 performs root cause analysis on the corresponding process data. In addition, when the determination result when inputting process data into the second prediction model 143 is "normal data", but the KPI value when inputting the process data into the workshop KPI calculation model 445 is also less than the threshold value, the analysis device 400 performs root cause analysis on the corresponding process data.
[0261] Figure 18 This is a diagram showing an example of the determination result of the process data obtained in real time and the workshop KPI. As Figure 18 shown, the evaluation result table T2 includes item number, timestamp, first feature, second feature, third feature, fourth feature, evaluation result, and workshop KPI. The descriptions of the item number, timestamp, first to fourth feature quantities, and evaluation result are the same as those described in Figure 5 . In addition, the description of the workshop KPI is also the same as the above description. In addition, the threshold value compared with the workshop KPI is set to "50".
[0262] In Figure 18 the example shown, the analysis device 400 determines the process data corresponding to item numbers 6 to 11 as Figure 17 the process data that becomes the execution object of root cause analysis shown. The analysis device 400 performs root cause analysis on the process data corresponding to item numbers 6 to 11. The root cause analysis performed by the analysis device 400 is the same as the root cause analysis described in Embodiments 1 to 3.
[0263] As described above, the analysis device 400 according to Embodiment 4 determines the process data that becomes the object of root cause analysis based on the prediction result of the second prediction model 143 for the process data and the calculation result of the workshop KPI calculation model 445. Thereby, it is possible to perform root cause analysis on the process data that did not become the object of root cause analysis in Embodiments 1 to 3. For example, regarding the analysis device 400 according to Embodiment 4, when the determination result when inputting process data into the second prediction model 143 is "normal data", but the KPI value when inputting the process data into the workshop KPI calculation model 445 is also less than the threshold value, it is possible to perform root cause analysis on the corresponding process data.
[0264] (Functional Structure of the Analysis Device 400 in Embodiment 4)
[0265] Next, an example of the structure of the analysis device 400 shown in Figure 16 will be described. Figure 19 is a functional block diagram showing the functional structure of the analysis device according to Embodiment 4. As Figure 19 shown, the analysis device 400 includes a communication unit 110, an input unit 120, a display unit 130, a storage unit 440, and a control unit 450. In addition, the functional units included in the analysis device 400 are not limited to the illustrated functional units, and other functional units may also be included.
[0266] The descriptions of the communication unit 110, the input unit 120, and the display unit 130 are the same as those Figure 8 described for the communication unit 110, the input unit 120, and the display unit 130 in
[0267] The storage unit 440 stores the first learning data set 141, the first prediction model 142, the second prediction model 243, the second learning data set 144, and the workshop KPI calculation model 445. The storage unit 440 is implemented by a memory, a hard disk, etc.
[0268] The first learning data set 141 has process data collected during the period when the system 50 did not generate an abnormality. Other descriptions of the first learning data set 141 are the same as those Figure 5 described for the first learning data set 141 in
[0269] The first prediction model 142 is One Class SVM or the like. The first prediction model 142 performs unsupervised learning based on the first learning data set 141 and using the unsupervised learning unit 452 described later.
[0270] The second prediction model 143 is NN or the like. The second prediction model 143 performs supervised learning based on the second learning data set 144 and using the supervised learning unit 455 described later.
[0271] The second learning data set 144 has a plurality of labeled process data. For example, it has information in which the normal data included in the first learning data set 141 is labeled with "1 (normal)", and information in which the abnormal data at multiple x points is labeled with "0 (abnormal)".
[0272] The workshop KPI calculation model 445 is a model for calculating the workshop KPI.
[0273] The control unit 450 is a processing unit that manages the overall analysis device 400 and is implemented by, for example, a processor or the like. The control unit 450 includes an acquisition unit 451, an unsupervised learning unit 452, a detection unit 453, a cause analysis unit 454, a supervised learning unit 455, an evaluation unit 456, and a re-learning unit 457.
[0274] The acquisition unit 451 is a processing unit that acquires process data from the system 50 in real time. The acquisition unit 451 outputs the acquired process data to the detection unit 453 and the evaluation unit 456.
[0275] The acquisition unit 451 registers the process data acquired from the system 50 during the period when abnormal data is not detected by the detection unit 453 described below in the first learning data set 141.
[0276] The acquisition unit 451 labels the normal data (process data with an evaluation result of "normal") set in the first learning data set 141 with the label "1 (normal)" and registers it in the second learning data set 244. In addition, the acquisition unit 451 can acquire normal data using other methods, label the acquired normal data, and register it in the second learning data set 244.
[0277] The unsupervised learning unit 452 performs unsupervised learning on the first prediction model 142 based on the first learning data set 141. Other descriptions of the unsupervised learning unit 452 are the same as those of the unsupervised learning unit 152 in the first embodiment.
[0278] The detection unit 453 inputs the process data into the first prediction model 142 that has completed unsupervised learning and determines whether the input process data is normal data or abnormal data based on the predicted value. When the predicted value is greater than or equal to a pre-set threshold (for example, 0.5), the detection unit 453 determines the input process data as normal data. On the other hand, when the predicted value is less than the pre-set threshold, the detection unit 453 determines the input process data as abnormal data.
[0279] In addition, the detection unit 453 inputs the process data into the workshop KPI calculation model 445 and calculates the value of the workshop KPI. The process of the detection unit 453 calculating the workshop KPI is the same as the above process.
[0280] The detection unit 453 repeatedly performs the above process, extracts the process data that becomes the object of cause analysis as described in Figure 17 and outputs the extracted process data to the cause analysis unit 454. For example, the detection unit 453 outputs the process data corresponding to item numbers 6 to 11 in the process data described in Figure 18 to the cause analysis unit 454.
[0281] The cause analysis unit 454 performs cause analysis by using process data (abnormal data) at multiple x points and the second prediction model 143 that has completed supervised learning. The cause analysis performed by the cause analysis unit 454 is the same as that of the cause analysis unit 154 in Embodiment 1. The cause analysis unit 454 outputs the result of the cause analysis to the display unit 130 and the like. In addition, the cause analysis unit 454 may perform cause analysis by using the first prediction model 142 that has completed unsupervised learning.
[0282] The supervised learning unit 455 performs supervised learning on the second prediction model 143 based on the second learning data set 144 and based on the error propagation method or the like. Other descriptions of the supervised learning unit 455 are the same as the above descriptions regarding (supervised learning in Embodiment 1).
[0283] The evaluation unit 456 evaluates the first prediction model 142 by using the second prediction model 143 that has completed supervised learning. The description of the evaluation unit 456 is the same as the description of the evaluation unit 156 described in Embodiment 1.
[0284] The relearning unit 457 performs relearning of the first prediction model 142 assuming that the performance of the first prediction model 142 has deteriorated when receiving a relearning request from the evaluation unit 456. Other descriptions of the relearning unit 457 are the same as the descriptions of the relearning unit 157 in Embodiment 1.
[0285] (Processing flow of the analysis device 400 in Embodiment 4)
[0286] Next, an example of the processing flow of the analysis device 400 in Embodiment 4 will be described. Figure 20 is a flowchart showing the processing flow of the analysis device 400 in Embodiment 4. In addition, the processing flow for performing unsupervised learning of the first prediction model 142, the processing flow for performing supervised learning of the second prediction model 143, and the processing flow for determining a deterioration in the performance of the first prediction model 142 are the same as the processing flow of the analysis device 100 in Embodiment 1. Therefore, in Figure 20 the description of the processing flow, the processing flow that is closely related to Embodiment 4 and after the supervised learning of the second prediction model 143 is completed will be described.
[0287] As Figure 20 shown, the acquisition unit 451 of the analysis device 400 acquires process data from the system 50 in real time (step S401). The detection unit 453 of the analysis device 400 inputs the process data into the second prediction model 143 and obtains a prediction result (step S402).
[0288] The detection unit 453 inputs the process data into the workshop KPI calculation model 445 and calculates the value of the workshop KPI (step S403). The detection unit 453 determines whether the process data is the object of root cause analysis based on the prediction result of the second prediction model 143 and the value of the workshop KPI (step S405).
[0289] In the case where the process data is the object of root cause analysis (Yes in step S405), the root cause analysis unit 454 of the analysis device 400 performs root cause analysis (step S406) and enters step S402. On the other hand, in the case where the process data is not the object of root cause analysis (No in step S405), the root cause analysis unit 454 enters step S402.
[0290] (Effect of Embodiment 4)
[0291] The analysis device 400 according to Embodiment 4 determines the process data that becomes the object of root cause analysis based on the prediction result of the second prediction model 143 for the process data and the calculation result of the workshop KPI calculation model 445. Thus, it is possible to perform root cause analysis on the process data that did not become the object of root cause analysis in Embodiments 1 to 3. For example, regarding the analysis device 400 according to Embodiment 4, in the case where the determination result when the process data is input into the second prediction model 143 is "normal data", but the KPI value when the process data is input into the workshop KPI calculation model 445 is also less than the threshold value, it is possible to perform root cause analysis on the corresponding process data.
[0292] [Hardware]
[0293] Next, a hardware structure example of the analysis device 100 (200, 300, 400) will be described. Figure 21 It is a diagram for explaining a hardware structure example. As Figure 21 shown, the analysis device 100 includes a communication device 5a, an HDD (Hard Disk Drive) 5b, a memory 5c, and a processor 5d. In addition, Figure 21 the respective parts shown are connected to each other by a bus or the like.
[0294] The communication device 5a is a network interface card or the like and performs communication with other devices. The HDD 5b stores programs and DBs for executing the functions shown Figure 8 shown.
[0295] The processor 5d reads out from the HDD 5b or the like a program for executing the same processing as each processing unit shown Figure 8 shown and expands it in the memory 5c, thereby enabling the execution Figure 8The process execution actions of each function described in etc. For example, this process performs the same functions as each processing unit of the analysis device 100. Specifically, the processor 5d executes the following process, that is, executes the same processing as the acquisition unit 151, the unsupervised learning unit 152, the detection unit 153, the cause analysis unit 154, the supervised learning unit 155, the evaluation unit 156, the relearning unit 157, etc.
[0296] In this way, the analysis device 100 executes actions as an analysis device that reads and executes a program to execute the analysis method. In addition, the analysis device 100 can also read the above program from a recording medium by using a medium reading device and execute the read program, thereby realizing the same functions as the above embodiments. In addition, the program described in other embodiments is not limited to being executed by the analysis device 100. For example, in the case where a program is executed by other computers or servers, or in the case where they cooperate to execute a program, the present invention can also be applied in the same way.
[0297] This program can be distributed via a network such as the Internet. In addition, this program can be recorded on a recording medium readable by a computer such as a hard disk, a floppy disk (FD), a CD-ROM, a MO (Magneto-Optical disk), a DVD (Digital Versatile Disc), etc., and read and executed by a computer from the recording medium.
[0298] (Other)
[0299] Several examples of combinations of the disclosed technical features are described below.
[0300] (1) An analysis device, comprising:
[0301] A detection unit that detects abnormal data by inputting data acquired from the target system into a first prediction model that has performed unsupervised learning on pre-data acquired during normal operation of the target system;
[0302] A supervised learning unit that performs supervised learning on a second prediction model based on the abnormal data and the pre-data;
[0303] An evaluation unit that evaluates the first prediction model by inputting the same data as the data input to the first prediction model into the second prediction model; and
[0304] A relearning unit that, based on the evaluation result of the evaluation unit, performs unsupervised learning on the first prediction model again.
[0305] (2) The analysis device according to (1), further comprising a cause analysis unit that performs cause analysis based on the abnormal data and the first prediction model.
[0306] (3) The analysis device according to (1) or (2), wherein the detection unit further calculates the value of the shop floor KPI (Key Performance Indicator) based on the data obtained from the target system, and the root cause analysis unit determines the data to be the object of root cause analysis based on the prediction result of the first prediction model or the second prediction model and the value of the shop floor KPI, according to a plurality of data obtained from the target system.
[0307] (4) The analysis device according to any one of (1) to (3), wherein the evaluation unit evaluates the first prediction model based on the first prediction result output from the first prediction model when data is input to the first prediction model, and the second prediction result output from the second prediction model when the same data as the data input to the first prediction model is input to the second prediction model.
[0308] (5) The analysis device according to (4), wherein the evaluation unit evaluates the first prediction model based on the second prediction result output from the second prediction model when the data predicted as abnormal data by the first prediction model is input to the second prediction model.
[0309] (6) The analysis device according to (5), wherein the evaluation unit evaluates that the performance of the first prediction model has declined when the first prediction result and the second prediction result are different, and the relearning unit performs unsupervised learning for the first prediction model again when it is evaluated that the performance of the first prediction model has declined.
[0310] (7) The analysis device according to any one of (1) to (6), wherein the supervised learning unit performs supervised learning for the second prediction model based on the normal data determined to be normal by the first prediction model and the abnormal data among a plurality of prior data obtained during the normal operation of the target system.
[0311] (8) The analysis device according to any one of (1) to (6), wherein the supervised learning unit performs supervised learning for the second prediction model based on the data obtained from the target system immediately before the abnormal data detected by the detection unit and the abnormal data.
[0312] (9) An analysis method, in which a computer performs the following processing:
[0313] By inputting the data obtained from the target system to the first prediction model that has performed unsupervised learning on the prior data obtained during the normal operation of the target system, abnormal data is detected.
[0314] Perform supervised learning for the second prediction model based on the abnormal data and the prior data.
[0315] Evaluate the first prediction model by inputting the same data as the data input to the first prediction model into the second prediction model.
[0316] Based on the evaluation result, perform unsupervised learning for the first prediction model again.
[0317] (10) A computer-readable storage medium, which is a computer-readable recording medium recording an analysis program, and the analysis program causes a computer to execute the following processing:
[0318] Detect abnormal data by inputting the data obtained from the target system into the first prediction model that has performed unsupervised learning on the prior data obtained during the normal operation of the target system.
[0319] Perform supervised learning for the second prediction model based on the abnormal data and the prior data.
[0320] Evaluate the first prediction model by inputting the same data as the data input to the first prediction model into the second prediction model.
[0321] Based on the evaluation result, perform unsupervised learning for the first prediction model again.
[0322] Description of reference numerals
[0323] 100, 200, 300, 400 Analysis device
[0324] 110 Communication unit
[0325] 120 Input unit
[0326] 130 Display unit
[0327] 140 Storage unit
[0328] 141 First learning data set
[0329] 142 First prediction model
[0330] 143 Second prediction model
[0331] 144 Second learning data set
[0332] 150, 250, 350, 450 Control unit
[0333] 151, 251, 351, 451 Acquisition unit
[0334] Unsupervised Learning Departments 152, 252, 352, 452
[0335] Detection Departments 153, 253, 353, 453
[0336] Root Cause Analysis Departments 154, 254, 354, 454
[0337] Supervised Learning Departments 155, 255, 355, 455
[0338] Evaluation Departments 156, 256, 356, 456
[0339] Relearning Departments 157, 257, 357, 457
Claims
1. An analysis device, wherein: The analysis device comprises: a detection unit that detects abnormal data by inputting data acquired from the target system into a first prediction model that has performed unsupervised learning based on prior data acquired during normal operation of the target system, and detecting abnormal data; a supervised learning unit that performs supervised learning on a second prediction model based on the abnormal data and the prior data; an evaluation unit that evaluates the first prediction model by inputting the same data as the data input to the first prediction model into the second prediction model; and A re-learning unit executes unsupervised learning on the first prediction model again based on the evaluation result of the evaluation unit.
2. The analysis device according to claim 1, wherein The analysis device further includes a factor analysis unit that performs factor analysis based on the abnormal data and the first prediction model.
3. The analysis device according to claim 2, wherein: The detection unit further calculates the value of the workshop KPI based on the data obtained from the object system, and the factor analysis unit determines the data that becomes the object of factor analysis based on the prediction results of the first prediction model or the second prediction model and the value of the workshop KPI according to multiple data obtained from the object system. KPI is a key performance indicator.
4. The analysis device according to claim 1, wherein The evaluation unit evaluates the first prediction model based on a first prediction result output from the first prediction model when data is input into the first prediction model, and a second prediction result output from the second prediction model when data identical to the data input into the first prediction model is input into the second prediction model.
5. The analysis device according to claim 4, wherein: The evaluation unit evaluates the first prediction model based on a second prediction result output from the second prediction model when data predicted by the first prediction model as abnormal data is input to the second prediction model.
6. The analysis device according to claim 5, wherein: The evaluation unit evaluates that the performance of the first prediction model has deteriorated when the first prediction result and the second prediction result are different, and the relearning unit performs unsupervised learning on the first prediction model again when the performance of the first prediction model has deteriorated.
7. The analysis device according to any one of claims 1 to 6, wherein: The supervised learning unit performs supervised learning on the second prediction model based on normal data determined to be normal by the first prediction model and the abnormal data among a plurality of prior data acquired when the target system is operating normally.
8. The analysis device according to any one of claims 1 to 6, wherein: The supervised learning unit performs supervised learning on the second prediction model based on data acquired from the target system immediately before the abnormal data detected by the detection unit and the abnormal data.
9. An analytical method, wherein: The analysis method is performed by a computer as follows: The abnormal data is detected by inputting the data acquired from the target system into a first prediction model that performs unsupervised learning based on prior data acquired during normal operation of the target system, Based on the abnormal data and the prior data, supervised learning is performed on the second prediction model. evaluating the first prediction model by inputting the same data as the data input to the first prediction model into the second prediction model, Based on the evaluation result, unsupervised learning of the first prediction model is performed again.
10. A computer-readable storage medium, which is a computer-readable recording medium having an analysis program recorded thereon, wherein: The analysis program causes the computer to execute the following processing: The abnormal data is detected by inputting the data acquired from the target system into a first prediction model that performs unsupervised learning based on prior data acquired during normal operation of the target system, Based on the abnormal data and the prior data, supervised learning is performed on the second prediction model. evaluating the first prediction model by inputting the same data as the data input to the first prediction model into the second prediction model, Based on the evaluation result, unsupervised learning of the first prediction model is performed again.