A large-scale cloud node anomaly identification method for computing power network, electronic equipment and storage medium

By extracting and analyzing key intent elements from cloud node time-series data using a multi-level Transformer structure, the problem of insufficient accuracy of traditional methods in large-scale cloud computing environments is solved, achieving more accurate and robust abnormal node identification.

CN120162719BActive Publication Date: 2025-12-05HARBIN INST OF TECH +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510242142.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-12-05
Estimated Expiration
2045-03-03

AI Technical Summary

Technical Problem

Traditional rule-based and statistical analysis-based anomaly detection methods struggle to adapt to dynamic changes and complex behavioral patterns in large-scale cloud computing environments, resulting in insufficient accuracy.

Method used

A multi-level Transformer structure is used to extract and analyze key intent elements from cloud node time-series data. By jointly learning the internal features of intent elements and context sequence features, an anomaly classification model is constructed to identify abnormal nodes.

Benefits of technology

It achieves more accurate identification of abnormal nodes, improves the accuracy and robustness of detection, and can fully characterize the abnormal patterns of cloud node data in multiple dimensions, adapting to complex cloud computing environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120162719B_ABST
    Figure CN120162719B_ABST
Patent Text Reader

Abstract

A large-scale cloud node anomaly identification method for computing power network, an electronic device and a storage medium belong to the technical field of cloud computing data processing. In order to solve the problem that the existing node abnormal behavior analysis method usually faces the problem of insufficient accuracy caused by the mode deviation of intention elements, the present application comprises collecting large-scale cloud node time series data for computing power network; the extraction of key intention elements is carried out to obtain the key intention element set for identification, the intention element identification sequence is obtained, and then it is converted into a vector representation to obtain the representation vector of the intention element identification sequence; a multi-level Transformer structure is constructed to construct an abnormal classification model, the representation vector of the intention element identification sequence is classified, the internal features and context sequence features of the representation vector of the intention element identification sequence are jointly learned, and the final classification task is completed to judge whether the large-scale cloud node time series data for computing power network is abnormal. The present application has high robustness.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of cloud computing data processing technology, specifically relating to a method, electronic device and storage medium for large-scale cloud node anomaly identification for computing power networks. Background Technology

[0002] Traditional rule-based and statistical analysis-based anomaly detection methods mainly rely on manually defined rules or statistical methods to detect abnormal behavior of cloud nodes, including the following methods:

[0003] Rule-driven anomaly detection: This method monitors the normal behavior of cloud nodes using predefined rules and thresholds (such as CPU load and memory usage). When a node's behavior exceeds a set threshold, it is considered an anomaly. While simple to implement, this approach lacks flexibility and struggles to adapt to dynamic changes in complex environments.

[0004] Statistical analysis and clustering methods: Traditional methods use statistical analysis (such as mean and standard deviation) to describe normal behavior and detect anomalies based on these statistical characteristics. This approach uses clustering techniques to identify normal patterns in the data, thereby distinguishing abnormal behavior. However, the effectiveness of these methods is often affected by data noise and variation, and they cannot fully capture complex behavioral patterns.

[0005] Anomaly detection based on time series: Traditional time series analysis methods (such as ARIMA and moving averages) are used to monitor the time dependencies of cloud node behavior, helping to identify sudden anomalies in the short term. However, time series models may not be able to adequately adapt to the dynamic changes in data when facing the ever-changing and complex cloud computing environment.

[0006] Threshold-based anomaly detection: Many rule-based anomaly detection methods set thresholds to monitor abnormal behavior. This method is simple and intuitive, but it is easily affected by improperly set thresholds or fluctuations in cloud node load, leading to false positives or false negatives.

[0007] Traditional rule-based and statistical analysis methods are effective in simple scenarios, but they are not good enough when dealing with dynamic changes and complex behavioral patterns, especially in large-scale cloud computing environments, where they cannot cope with the complexity of node behavior and high-dimensional data. Summary of the Invention

[0008] To address the problem of insufficient accuracy caused by intent element pattern offset in existing node abnormal behavior analysis methods, this invention proposes a large-scale cloud node anomaly identification method, electronic device, and storage medium for computing power networks.

[0009] To achieve the above objectives, the present invention provides the following technical solution:

[0010] A method for identifying anomalies in large-scale cloud nodes for computing power networks includes the following steps:

[0011] S1. Collect large-scale cloud node time-series data for computing power networks;

[0012] S2. Extract key intent elements from the large-scale cloud node time-series data for computing power networks obtained in step S1 to obtain a set of key intent elements;

[0013] S3. Identify the set of key intent elements obtained in step S2 to obtain the intent element identification sequence, and then convert it into a vector representation to obtain the representation vector of the intent element identification sequence;

[0014] S4. Construct a multi-level Transformer structure to build an anomaly classification model. Perform anomaly classification on the representation vector of the intent element recognition sequence obtained in step S3. Jointly learn the internal features and context sequence features of the representation vector of the intent element recognition sequence to complete the final classification task and determine whether there are anomalies in the time series data of large-scale cloud nodes for computing power networks.

[0015] Furthermore, the specific implementation method of step S2 includes the following steps:

[0016] S2.1. The time-series data of large-scale cloud nodes for computing power networks collected in step S1 includes an intent element sequence S of length n. i (l) is the i-th intention element subsequence of length l in the intention element sequence S, S j (l) is the j-th intention element subsequence of length l in the intention element sequence S, generating an intention element candidate set C(T) of length l:

[0017]

[0018] S2.2. Use a binary classification method to identify normal intent elements and abnormal intent elements. Set the label of abnormal intent elements to 0 and the label of normal intent elements to 1. For normal intent elements, select the first k intent element sequence segments as key intent elements.

[0019] S2.3. For the key intent elements obtained in step S2.2, perform a key intent element quality assessment and calculate the S of length l. i (l) and S j The Euclidean distance d(S) between (l) i (l),S j (l)), the expression is:

[0020]

[0021] Then set the intention element subsequence S of length l. i (l) The distance between the intention element sequence S and S is S i The minimum distance between (l) and all normalized subsequences is expressed as:

[0022]

[0023] Set the intention element subsequence S of length l. i (l) All distances between the intention element sequence S and the distance list D(S) constitute the distance list D(S) i (l),S), the expression is:

[0024] D(S i (l),S)={d(S i (l),S j (l))|S j (l)∈S};

[0025] S2.4. Based on the method in step S2.3, evaluate all intention element subsequences, sort the intention element subsequences according to the quality evaluation, and delete self-similar intention elements. Then, merge the sorted top k key intention elements with the key intention elements set in step S2.2, obtain the top k key intention elements again, and discard all self-similar intention elements to obtain the key intention element set.

[0026] Furthermore, in step S2.4, a learning-based time series model is used to measure the quality of key intent elements.

[0027] Furthermore, the specific implementation method of step S3 includes the following steps:

[0028] S3.1. Use the subsequence matching method to identify the key intent element set obtained in step S2, given the intent element identification set S c , will S c Each intent element in the process is matched with the set of key intent elements obtained in step S2, and the elements selected by S are filtered out. c The intent elements are fully contained and preserved in their order in the original sequence, ultimately forming the intent element identification sequence S′;

[0029] S3.2. Convert the intent element recognition sequence S′ obtained in step S3.1 into a vector representation using the word2vec model. Train the word2vec model using the skip-gram method based on the intent element recognition set, and set S′={s1′,s2′,...,s n If '}, then the representation vector vec(S') of the intent element identification sequence is:

[0030]

[0031] Among them, word2vec(s i ) represents the intention element s i The embedding vector of ', s i ′ represents the i-th intention element identification subsequence.

[0032] Furthermore, the specific implementation method of step S4 includes the following steps:

[0033] S4.1. Construct a multi-level Transformer structure to build an anomaly classification model, including an intent element internal feature learning module, an intent element relationship feature learning module, and a classification layer;

[0034] The multi-level Transformer structure constructs an anomaly classification model. The input features are intention elements with a size of 100×768. First, the input features are processed by the internal feature learning module of the intention elements to extract the internal features of the intention elements. Then, the extracted internal features of the intention elements are concatenated with the input features to form concatenated features with a dimension of 100×1536.

[0035] S4.2. Input the concatenated features obtained in step S4.1 into the intention element relationship feature learning module. Model the global dependency relationship between intention elements through multi-head attention mechanism and feedforward network, and output a high-level feature representation sequence with a dimension of 100×1536.

[0036] S4.3. The classification layer integrates the high-level feature representation sequence obtained in step S4.2 into a fixed-length vector of 1536 through global average pooling, and generates classification results through a multi-layer perceptron layer and a softmax layer to complete the classification task of the intent element sequence.

[0037] Furthermore, the intent element internal feature learning module in step S4.1 includes a multi-head attention layer, an Add&Norm layer, and a feedforward network layer. The specific network results are as follows:

[0038] A multi-head attention layer is used to capture global dependencies between intent elements, with an output size of 100×768.

[0039] The Add&Norm layer is used to perform residual connections and normalization on the multi-head attention results, with an output size of 100×768.

[0040] Feedforward network layer, two fully connected network layers, improves the ability to represent nonlinear features, output size 100×768;

[0041] The second Add&Norm layer performs residual connection and normalization on the feedforward network results, with an output size of 100×768.

[0042] Module stacking: Repeat the above structure twice, and the final output size is 100×768.

[0043] Furthermore, the intent element relationship feature learning module in step S4.2 includes a multi-head attention layer, an Add&Norm layer, and a feedforward network layer. The specific network results are as follows:

[0044] A multi-head attention layer is used to capture global dependencies between intent elements, with an output size of 100×1536.

[0045] The Add&Norm layer is used to perform residual connections and normalization on the multi-head attention results, with an output size of 100×1536.

[0046] Feedforward network layer, two fully connected network layers, improves the ability to represent nonlinear features, output size 100×1536;

[0047] The second Add&Norm layer performs residual connection and normalization on the feedforward network results, with an output size of 100×1536.

[0048] Module stacking: Repeat the above structure twice, and the final output size is 100×1536.

[0049] Furthermore, the classification layer in step S4.3 includes a pooling layer, an MLP layer, and a Softmax layer:

[0050] Pooling layer: Global average pooling integrates sequence features into a fixed-length representation with an output size of 1536;

[0051] MLP layer: The fully connected layer maps features to the classification space, and the output size is 2 times the number of classes;

[0052] Softmax layer: Calculates the classification probability distribution, output size 2.

[0053] An electronic device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of the method for identifying anomalies in large-scale cloud nodes for computing power networks.

[0054] A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the aforementioned method for identifying large-scale cloud node anomalies in computing power networks.

[0055] The beneficial effects of this invention are:

[0056] The innovation of this invention, a method for identifying large-scale cloud node anomalies in computing power networks, lies in the extraction and analysis of key intent elements from cloud node data. By deeply mining the contextual features of the key intent element sequences of cloud nodes, more accurate anomaly node identification is achieved. Specifically, this method first extracts key intent elements from the time-series data of cloud nodes, identifies highly correlated feature information, and further captures the potential dependencies between different intent elements through cross-node contextual relationship modeling.

[0057] This invention discloses a method for large-scale cloud node anomaly identification in computing power networks. By introducing a multi-level Transformer structure, it jointly learns and models the internal features and context sequence features of intent elements, ensuring a comprehensive representation of abnormal patterns in cloud node data across multiple dimensions. Specifically, the model employs a self-attention mechanism, which enhances the robustness and generalization ability of the feature extraction process, thereby effectively improving detection accuracy.

[0058] This invention discloses a method for identifying anomalies in large-scale cloud nodes for computing power networks. This method effectively integrates global information and local features among cloud nodes, comprehensively improving the anomaly detection performance of large-scale computing power networks. Therefore, it achieves more accurate anomaly node identification across various dimensions and possesses stronger anti-interference and adaptability capabilities.

[0059] This invention presents a method for identifying anomalies in large-scale cloud nodes for computing power networks. Test results were compared with several publicly available and general methods proposed in recent years, with identification accuracy used as the experimental evaluation metric. The results show that this model achieves excellent performance in the task of detecting anomalies in large-scale cloud nodes for computing power networks. The best experimental results show that the anomaly node identification accuracy reaches 90%, surpassing the detection performance of other current general methods and improving the robustness of the detection. Attached Figure Description

[0060] Figure 1 This is a flowchart of a method for identifying anomalies in large-scale cloud nodes for computing power networks, as described in this invention.

[0061] Figure 2 This is a structural block diagram of a large-scale cloud node anomaly identification method for computing power networks according to the present invention.

[0062] Figure 3 A structural block diagram for constructing an anomaly classification model using the multi-level Transformer structure described in this invention;

[0063] Figure 4 The pseudocode is for extracting key intent elements of this invention. Detailed Implementation

[0064] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only for explaining the invention and are not intended to limit the invention; that is, the described specific embodiments are merely a part of the embodiments of the invention, and not all of them. The components of the specific embodiments of the invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations, and the invention may also have other embodiments.

[0065] Therefore, the following detailed description of specific embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected specific embodiments of the invention. All other specific embodiments obtained by those skilled in the art based on these specific embodiments without inventive effort are within the scope of protection of this invention.

[0066] To further understand the invention's content, features, and effects, the following specific embodiments are provided, along with accompanying drawings. Figure 1 -Appendix Figure 4 Detailed explanation is as follows:

[0067] Example 1:

[0068] A method for identifying anomalies in large-scale cloud nodes for computing power networks includes the following steps:

[0069] S1. Collect large-scale cloud node time-series data for computing power networks;

[0070] S2. Extract key intent elements from the large-scale cloud node time-series data for computing power networks obtained in step S1 to obtain a set of key intent elements;

[0071] Furthermore, the specific implementation method of step S2 includes the following steps:

[0072] S2.1. The time-series data of large-scale cloud nodes for computing power networks collected in step S1 includes an intent element sequence S of length n. i (l) is the i-th intention element subsequence of length l in the intention element sequence S, S j (l) is the j-th intention element subsequence of length l in the intention element sequence S, generating an intention element candidate set C(T) of length l:

[0073]

[0074] S2.2. Use a binary classification method to identify normal intent elements and abnormal intent elements. Set the label of abnormal intent elements to 0 and the label of normal intent elements to 1. For normal intent elements, select the first k intent element sequence segments as key intent elements.

[0075] S2.3. For the key intent elements obtained in step S2.2, perform a key intent element quality assessment and calculate the S of length l. i (l) and S j The Euclidean distance d(S) between (l) i (l),S j (l)), the expression is:

[0076]

[0077] Then set the intention element subsequence S of length l. i (l) The distance between the intention element sequence S and S is S i The minimum distance between (l) and all normalized subsequences is expressed as:

[0078]

[0079] Set the intention element subsequence S of length l. i (l) All distances between the intention element sequence S and the distance list D(S) constitute the distance list D(S) i (l),S), the expression is:

[0080] D(S i (l),S)={d(S i (l),S j (l))|S j (l)∈S};

[0081] S2.4. Based on the method in step S2.3, evaluate all intention element subsequences, sort the intention element subsequences according to the quality evaluation, and delete self-similar intention elements. Then, merge the sorted first k key intention elements with the key intention elements set in step S2.2, obtain the first k key intention elements again, and discard all self-similar intention elements to obtain the key intention element set.

[0082] Furthermore, in step S2.4, a learning-based time series model is used to measure the quality of key intent elements;

[0083] A learning-based time series model was employed to measure the quality of key intent elements. First, a learning model was trained. Then, each intent element candidate was fed into the model, and its quality was evaluated based on the difference between the model's output and the actual label. Instead of searching for possible intent elements from all intent element sequences, the model was iteratively optimized by minimizing a classification loss function.

[0084] Given classifier weights, biases, and feature vector x, a linear prediction model The expression is:

[0085]

[0086] Where x is the distance between the i-th intention element sequence and the j-th model feature, w is the weight of the first learned feature, and b is the weight of the second learned feature;

[0087] The linear prediction model is used to jointly optimize the feature set and classifier weights, as expressed in the following expression:

[0088]

[0089] in, It is the loss function, and θ is the weight of the third learned feature;

[0090] Taking the class label y into account, we obtain the loss function that takes the class label into account. The expression is:

[0091]

[0092] And expressed using the sigmoid function:

[0093]

[0094] Then, features and classifier weights are learned by minimizing the classification objective and reducing generalization error without affecting the model's interpretability. Each intent feature candidate is fed into the model, and the quality of these candidates is evaluated based on the difference between the model output and the actual label.

[0095]

[0096] in, To evaluate the candidate S of the intent element i The quality, if A value close to 0 indicates that the quality of the intention element is relatively high.

[0097] S3. Identify the set of key intent elements obtained in step S2 to obtain the intent element identification sequence, and then convert it into a vector representation to obtain the representation vector of the intent element identification sequence;

[0098] Furthermore, the specific implementation method of step S3 includes the following steps:

[0099] S3.1. Use the subsequence matching method to identify the key intent element set obtained in step S2, given the intent element identification set S c , will S c Each intent element in the process is matched with the set of key intent elements obtained in step S2, and the elements selected by S are filtered out. c The intent elements are fully contained and preserved in their order in the original sequence, ultimately forming the intent element identification sequence S′;

[0100] S3.2. Convert the intent element recognition sequence S′ obtained in step S3.1 into a vector representation using the word2vec model. Train the word2vec model using the skip-gram method based on the intent element recognition set, and set S′={s1′,s2′,...,s n If '}, then the representation vector vec(S') of the intent element identification sequence is:

[0101]

[0102] Among them, word2vec(s i ) represents the intention element s i The embedding vector of ', s i ′ represents the i-th intention element identification subsequence.

[0103] S4. Construct a multi-level Transformer structure to build an anomaly classification model. Perform anomaly classification on the representation vector of the intent element recognition sequence obtained in step S3. Jointly learn the internal features and context sequence features of the representation vector of the intent element recognition sequence to complete the final classification task and determine whether there are anomalies in the time series data of large-scale cloud nodes for computing power networks.

[0104] Furthermore, the specific implementation method of step S4 includes the following steps:

[0105] S4.1. Construct a multi-level Transformer structure to build an anomaly classification model, including an intent element internal feature learning module, an intent element relationship feature learning module, and a classification layer;

[0106] The multi-level Transformer structure constructs an anomaly classification model. The input features are intention elements with a size of 100×768. First, the input features are processed by the internal feature learning module of the intention elements to extract the internal features of the intention elements. Then, the extracted internal features of the intention elements are concatenated with the input features to form concatenated features with a dimension of 100×1536.

[0107] S4.2. Input the concatenated features obtained in step S4.1 into the intention element relationship feature learning module. Model the global dependency relationship between intention elements through multi-head attention mechanism and feedforward network, and output a high-level feature representation sequence with a dimension of 100×1536.

[0108] S4.3. The classification layer integrates the high-level feature representation sequence obtained in step S4.2 into a fixed-length vector of 1536 through global average pooling, and generates classification results through a multi-layer perceptron layer and a softmax layer to complete the classification task of the intent element sequence.

[0109] Furthermore, the intent element internal feature learning module in step S4.1 includes a multi-head attention layer, an Add&Norm layer, and a feedforward network layer. The specific network results are as follows:

[0110] A multi-head attention layer is used to capture global dependencies between intent elements, with an output size of 100×768.

[0111] The Add&Norm layer is used to perform residual connections and normalization on the multi-head attention results, with an output size of 100×768.

[0112] Feedforward network layer, two fully connected network layers, improves the ability to represent nonlinear features, output size 100×768;

[0113] The second Add&Norm layer performs residual connection and normalization on the feedforward network results, with an output size of 100×768.

[0114] Module stacking: Repeat the above structure twice, and the final output size is 100×768.

[0115] Furthermore, the intent element relationship feature learning module in step S4.2 includes a multi-head attention layer, an Add&Norm layer, and a feedforward network layer. The specific network results are as follows:

[0116] A multi-head attention layer is used to capture global dependencies between intent elements, with an output size of 100×1536.

[0117] The Add&Norm layer is used to perform residual connections and normalization on the multi-head attention results, with an output size of 100×1536.

[0118] Feedforward network layer, two fully connected network layers, improves the ability to represent nonlinear features, output size 100×1536;

[0119] The second Add&Norm layer performs residual connection and normalization on the feedforward network results, with an output size of 100×1536.

[0120] Module stacking: Repeat the above structure twice, and the final output size is 100×1536.

[0121] Furthermore, the classification layer in step S4.3 includes a pooling layer, an MLP layer, and a Softmax layer:

[0122] Pooling layer: Global average pooling integrates sequence features into a fixed-length representation with an output size of 1536;

[0123] MLP layer: The fully connected layer maps features to the classification space, and the output size is 2 times the number of classes;

[0124] Softmax layer: Calculates the classification probability distribution, output size 2.

[0125] Specifically, assuming an intent element consists of several subsequences, each intent element is input into a Transformer encoder block, and the output of the last layer of the encoder is used as the embedding representation of that intent element. After processing through multiple layers of self-attention mechanisms, this embedding contains rich semantic information and can better reflect the overall features of the intent element. For the l-th layer of the Transformer encoder block, its output is represented as H. l In the second stage, contextual features between intent element sequences are further learned. This module fuses the embedded representations of intent elements with sequence features and inputs the joint embeddings into another Transformer encoder block to model the associations and dependencies between intent elements. This joint feature learning effectively captures the temporal and semantic information between different intent elements, improving the overall anomaly detection performance. Finally, the output of the Transformer encoder block is passed to a pooling layer to integrate global information, and the final classification task is completed through a multilayer perceptron (MLP) and a softmax classification layer to determine whether the current input intent element sequence contains anomalies.

[0126] Example 2:

[0127] An electronic device includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the steps of the large-scale cloud node anomaly identification method for computing power networks described in Embodiment 1.

[0128] The computer device of the present invention may include a processor and a memory, such as a microcontroller containing a central processing unit. Furthermore, the processor executes the computer program stored in the memory to implement the steps of the above-described method for large-scale cloud node anomaly identification in computing power networks.

[0129] The processor referred to can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.

[0130] The memory may primarily include a program storage area and a data storage area. The program storage area may store the operating system and at least one application program required for a function (such as sound playback, image playback, etc.); the data storage area may store data created based on the use of the mobile phone (such as audio data, phonebook, etc.). Furthermore, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disks, RAM, plug-in hard disks, smart media cards (SMC), secure digital cards (SD cards), flash cards, at least one disk storage device, flash memory device, or other volatile solid-state storage devices.

[0131] Example 3:

[0132] A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the large-scale cloud node anomaly identification method for computing power networks described in Embodiment 1.

[0133] The computer-readable storage medium of the present invention can be any form of storage medium that can be read by the processor of a computer device, including but not limited to non-volatile memory, volatile memory, ferroelectric memory, etc. The computer-readable storage medium stores a computer program. When the processor of the computer device reads and executes the computer program stored in the memory, the steps of the above-mentioned method for identifying anomalies in large-scale cloud nodes for computing power networks can be implemented.

[0134] The computer program includes computer program code, which may be in the form of source code, object code, executable file, or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.

[0135] It should be noted that relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0136] Although this application has been described above with reference to specific embodiments, various modifications can be made and components can be replaced with equivalents without departing from the scope of this application. In particular, as long as there is no structural conflict, the features in the specific embodiments disclosed in this application can be combined with each other in any way. The lack of an exhaustive description of these combinations in this specification is merely for the sake of brevity and resource conservation. Therefore, this application is not limited to the specific embodiments disclosed herein, but includes all technical solutions falling within the scope of the claims.

Claims

1. A large-scale cloud node anomaly identification method for a computing power network, characterized in that, Comprising the following steps: S1. Collecting large-scale cloud node time series data for computing power network; S2. Extracting key intent elements from the large-scale cloud node time series data for computing power network obtained in step S1 to obtain a set of key intent elements; The specific implementation method of step S2 comprises the following steps: S2.

1. Set the large-scale cloud node timing data of the computing power-oriented network collected in step S1 to include an intention element sequence with a length of n , is the i-th intention element sub-sequence with a length of l in the intention element sequence , is the j-th intention element sub-sequence with a length of l in the intention element sequence , and generate an intention element candidate set with a length of l : ; S2.

2. Use a binary classification method to identify normal intent elements and abnormal intent elements, set the label of abnormal intent elements to 0 and the label of normal intent elements to 1, for normal intent elements, select the first k intent element sequence fragments as key intent elements; S2.

3. Perform key intent element quality evaluation on the key intent elements obtained in step S2.2, and calculate the Euclidean distance between the length of and and , expressed as: ​ ; Then set the distance between the intent element sub-sequence with the length of and the intent element sequence is and the minimum distance of all normalized sub-sequences, the expression is: ; The set length is all distances between the intent element subsequences and the intent element sequence constitute a distance list , expressed as: ; S2.

4. Based on the method of step S2.3, evaluate all intent element subsequences, sort the intent element subsequences according to the quality evaluation, and delete self-similar intent elements, then combine the top k key intent elements obtained by sorting with the key intent elements set in step S2.2, and again obtain the top key intent elements and discard all self-similar intent elements to obtain a key intent element set; S3. Identifying the set of key intent elements obtained in step S2 to obtain an intent element identification sequence, and then converting it into a vector representation to obtain a representation vector of the intent element identification sequence; S4. Constructing a multi-level Transformer structure to build an anomaly classification model, performing anomaly classification on the representation vector of the intent element identification sequence obtained in step S3, jointly learning the internal features and context sequence features of the representation vector of the intent element identification sequence, and completing the final classification task to determine whether the large-scale cloud node time series data for computing power network is abnormal.

2. The method according to claim 1, wherein, In step S2.4, a learning-based time series model is used to measure the quality of the key intent elements.

3. The method according to claim 2, wherein, The specific implementation method of step S3 comprises the following steps: S3.

1. Use the subsequence matching method to identify the set of key intent elements obtained in step S2, given the intent element identification set. ,Will Each intent element in the process is matched with the set of key intent elements obtained in step S2, and the elements selected are... The intent elements are fully contained and preserved in their order in the original sequence, ultimately forming an intent element identification sequence. ; S3.

2. The intent element recognition sequence obtained in step S3.1 is converted into a vector representation using a word2vec model. The word2vec model is trained using the skip-gram method according to the intent element recognition set, and the word2vec model is set as follows: The representation vector of the intent element recognition sequence is: ​ ; wherein, represents an embedding vector of an intent element represents an i-th intent element identification sub-sequence.​ 4. The method according to claim 3, wherein, The specific implementation method of step S4 comprises the following steps: S4.

1. Constructing a multi-level Transformer structure to build an anomaly classification model comprises an intent element internal feature learning module, an intent element relationship feature learning module, and a classification layer; The multi-level Transformer structure constructs an anomaly classification model to take the intent element with a size of as an input feature, first processes the input feature through an intent element internal feature learning module to extract internal features of the intent element, and then splices the extracted internal features of the intent element with the input feature to form spliced features with a dimension of . S4.

2. Input the spliced features obtained in step S4.1 into an intent element relationship feature learning module, model the global dependency relationship between the intent elements through a multi-head attention mechanism and a feedforward network, and output a high-level feature representation sequence with a dimension of ​ S4.

3. The classification layer integrates the length of the high-level feature representation sequence obtained in step S4.2 into a fixed length vector 1536 through global average pooling, and generates a classification result through a multi-layer perception layer and a Softmax layer, completing the classification task of the intent element sequence.

5. The method of claim 4, wherein, In step S4.1, the intent element internal feature learning module comprises a multi-head attention layer, an Add & Norm layer, and a feedforward network layer, and the specific network result is as follows: a multi-head attention layer for capturing global dependencies among intent elements, output size ; Add & Norm layer for residual connection and normalization of multi-head attention results, output size ; Feedforward network layers, two fully connected networks, to boost non-linear feature representation capability, output size ; Second Add & Norm layer: residual connection and normalization on the feed-forward network result, output size ; Module stacking: repeat the above structure twice, the final output size is .

6. The method of claim 5, wherein the method is characterized by, In step S4.2, the intent element relationship feature learning module comprises a multi-head attention layer, an Add & Norm layer, and a feedforward network layer, and the specific network result is as follows: a multi-head attention layer for capturing global dependencies among intent elements, output size ; Add & Norm layer for residual connection and normalization of multi-head attention results, output size ; Feedforward network layers, two fully connected networks, to boost non-linear feature representation capability, output size ; Second Add & Norm layer: residual connection and normalization on the feed-forward network result, output size ; Module stacking: repeat the above structure twice, the final output size is .

7. The method according to claim 6, wherein, In step S4.3, the classification layer comprises a pooling layer, an MLP layer, and a Softmax layer: Pooling layer: Global average pooling integrates sequence features into a fixed length representation, with an output size of 1536; MLP layer: The fully connected layer maps the features to the classification space, with an output size of 2 for the number of categories; Softmax layer: Calculate the classification probability distribution, with an output size of 2.

8. An electronic device, comprising: The computer program is executed by the processor to realize the steps of the large-scale cloud node anomaly identification method for computing power network according to any one of claims 1-7.

9. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to realize the steps of the large-scale cloud node anomaly identification method for computing power network according to any one of claims 1-7.

Citation Information

Patent Citations

  • Automated root-cause analysis for distributed systems using tracing-data

    CN113454600A

  • Method and system for detecting abnormal data of smart power grid based on federated learning

    CN117171686A