Behavior event chain acquisition method and related equipment
By layering, normalizing and sorting and segmenting the mobile user behavior data, the device behavior event chain is generated, which solves the complexity of massive behavior data processing and realizes efficient data extraction and model analysis.
Patent Information
- Application Number
- CN202510344764.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-06-27
AI Technical Summary
How to extract effective features from massive and redundant mobile user behavior data to achieve efficient modeling and analysis, especially when the data structure is complex and the format is not unified.
By hierarchically and normalized the device behavior data, multi-level behavior events and normalized behavior events are obtained, and then the normalized behavior events are sorted and divided to generate a chain of equipment behavior events. Specific steps include standardizing and normalizing class-level behavioral events, using ngram model to capture the timing relationship of events, and dividing session segments according to time intervals.
It effectively solves the redundancy, messy and complex problems of device behavior data, improves data processing efficiency, provides high-quality input data, improves the accuracy and generalization capabilities of the model, and reduces the consumption of computing resources.
Smart Images

Figure CN120216879A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer and communication technologies. Specifically, it relates to a method for obtaining a behavior event chain and related devices. Background Art
[0002] With the sharp increase in the amount of mobile user behavior data, how to extract effective features from the massive, redundant behavior data and achieve efficient modeling and analysis has become a current technical problem. Mobile behavior data usually has colloquial language, complex structures, and long sequences, and the data formats are not unified. The event chains stored in JSON format often contain multi-dimensional information, increasing the difficulty of data cleaning and processing. In addition, there is redundancy in user behavior, and there is a time-dependent relationship between events in the behavior sequence. How to capture these complex behavior patterns and extract useful features is the key to improving the performance of the model. Summary of the Invention
[0003] Embodiments of this application provide a method for obtaining a behavior event chain and related devices, which can thus at least to a certain extent overcome the problems of redundancy, clutter, and complexity of device behavior data in the prior art and effectively solve these problems.
[0004] Other features and advantages of this application will become apparent through the following detailed description, or will be partially learned through the practice of this application.
[0005] According to one aspect of the embodiments of this application, a method for obtaining a behavior event chain is provided, including: performing dotting and layering on device behavior data to obtain multi-level behavior events, where the multi-level behavior events include type-level behavior events, category-level behavior events, and sub-category-level behavior events; normalizing the category-level behavior events to obtain normalized behavior events; and performing sorting and segmentation processing on the normalized behavior events to obtain a device behavior event chain.
[0006] In some embodiments of this application, normalizing the category-level behavior events to obtain normalized behavior events specifically includes: performing standardized preprocessing on the category-level behavior events to obtain standardized behavior events; and performing normalization processing on the standardized behavior events to obtain normalized behavior events.
[0007] In some embodiments of this application, performing normalization processing on the standardized behavior events to obtain normalized behavior events specifically includes: identifying behavior events of the same type in the standardized behavior events, where the behavior events of the same type are behavior events representing the same operation behavior; performing normalization processing on the behavior events of the same type to obtain normalized events of the same type; and using an ngram model to process the normalized events of the same type to obtain normalized behavior events.
[0008] In some embodiments of the present application, processing the same-class normalized events using an ngram model to obtain normalized behavior events specifically includes: inputting the same-class normalized events into the ngram model to obtain ngram features; performing normalization processing on the ngram features to obtain normalized features; generating a feature representation based on the normalized features to obtain normalized events.
[0009] In some embodiments of the present application, performing sorting and segmentation processing on the normalized behavior events to obtain a device behavior event chain specifically includes: sorting all the behavior events corresponding to each device in time sequence according to device granularity to obtain a device behavior time sequence; segmenting the device behavior time sequence in units of sessions to obtain the corresponding device behavior event chain.
[0010] In some embodiments of the present application, segmenting the device behavior time sequence in units of sessions to obtain the corresponding device behavior event chain specifically includes: determining the time interval between adjacent behavior events in the device behavior time sequence; determining the session segments included in the device behavior time sequence according to the time intervals between adjacent behavior events in the device behavior time sequence; cutting the session segments included in the device behavior time sequence to obtain the corresponding device behavior event chain.
[0011] In some embodiments of the present application, determining the session segments included in the device behavior time sequence according to the time intervals between adjacent behavior events in the device behavior time sequence specifically includes: obtaining the length and quantity of each device behavior time sequence to determine a predetermined cutting event interval; if the time interval between adjacent behavior events in the device behavior time sequence exceeds the predetermined cutting event interval, then the adjacent behavior events belong to different session segments respectively; if the time interval between adjacent behavior events in the device behavior time sequence does not exceed the predetermined cutting event interval, then the adjacent behavior events jointly belong to the same session segment.
[0012] According to one aspect of the embodiments of the present application, there is provided a device for obtaining a behavior event chain, where the device for obtaining a behavior event chain includes: a data layering module, configured to perform dotting and layering on device behavior data to obtain multi-level behavior events, and the multi-level behavior events include type-level behavior events, category-level behavior events, and sub-category-level behavior events; an event normalization module, configured to normalize the category-level behavior events to obtain normalized behavior events; a sorting and segmentation module, configured to perform sorting and segmentation processing on the normalized behavior events to obtain a device behavior event chain.
[0013] In some embodiments of the present application, the event normalization module specifically includes: a normalization sub-module, configured to perform normalization preprocessing on the category-level behavior events to obtain normalized behavior events; a normalization sub-module, configured to perform normalization processing on the normalized behavior events to obtain normalized behavior events.
[0014] In some embodiments of the present application, the normalization sub-module specifically includes: a same-class recognition unit, configured to recognize same-class behavior events in the normalized behavior events, where the same-class behavior events are behavior events representing the same operation behavior; a same-class normalization unit, configured to perform normalization processing on the same-class behavior events to obtain same-class normalized events; an ngram model unit, configured to process the same-class normalized events using an ngram model to obtain normalized behavior events.
[0015] In some embodiments of the present application, the ngram model unit specifically includes: a feature extraction sub-unit, configured to input the same-class normalized events into an ngram model to obtain ngram features; a feature normalization sub-unit, configured to perform normalization processing on the ngram features to obtain normalized features; an event normalization sub-unit, configured to generate a feature representation according to the normalized features to obtain normalized events.
[0016] In some embodiments of the present application, the sorting and segmentation module specifically includes: an event sorting sub-module, configured to sort all the behavior events corresponding to each device in time sequence according to device granularity to obtain device behavior time sequences; a time sequence segmentation sub-module, configured to segment the device behavior time sequences in units of sessions to obtain corresponding device behavior event chains.
[0017] In some embodiments of the present application, the time sequence segmentation sub-module specifically includes: a time determination unit, configured to determine the time interval between adjacent behavior events in the device behavior time sequences; a session determination unit, configured to determine the session segments included in the device behavior time sequences according to the time intervals between adjacent behavior events in the device behavior time sequences; a segment cutting unit, configured to cut the session segments included in the device behavior time sequences to obtain corresponding device behavior event chains.
[0018] In some embodiments of the present application, the session determination unit specifically includes: a length and quantity sub-unit, configured to obtain the length and quantity of each device behavior time sequence and determine a predetermined cutting event interval; a different session sub-unit, configured to determine that if the time interval between adjacent behavior events in the device behavior time sequence exceeds the predetermined cutting event interval, then the adjacent behavior events belong to different session segments respectively; a same session sub-unit, configured to determine that if the time interval between adjacent behavior events in the device behavior time sequence does not exceed the predetermined cutting event interval, then the adjacent behavior events belong to the same session segment together.
[0019] According to one aspect of the embodiments of the present application, there is provided a computer-readable medium having a computer program stored thereon, and when the computer program is executed by a processor, it implements the method for obtaining a behavior event chain as described in the above embodiments.
[0020] According to one aspect of the embodiments of the present application, there is provided an electronic device, including: one or more processors; a storage device for storing one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors implement the method for obtaining a behavior event chain as described in the above embodiments.
[0021] A computer program product includes one or more computer programs, characterized in that when the one or more computer programs are executed by one or more processors, they implement the steps of the method for obtaining a behavior event chain as described in the above embodiments.
[0022] In the technical solutions provided by some embodiments of the present application, effective behavior event chains are extracted from the original behavior data of the device through hierarchical normalization and segmentation, effectively solving the technical problems of redundancy, clutter, and complexity of device behavior data, while improving data processing efficiency, and ultimately providing high-quality input for subsequent analysis and modeling. Specifically, through layering and normalization, behavior events are effectively summarized and standardized, eliminating redundant information and inconsistencies in the data, reducing the complexity of the data, and ensuring the efficiency during the model training process. At the same time, through sorting and segmentation processing, the temporal relationship of behavior events is retained, enabling the device behavior data to be correctly understood and analyzed, and segmenting long sequence data can also avoid the consumption of computing resources caused by overly long sequences.
[0023] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application. Obviously, the drawings in the following description are only some embodiments of the present application, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts. In the drawings:
[0025] Figure 1 A schematic diagram of an exemplary system architecture to which the technical solutions of the embodiments of the present application can be applied is shown.
[0026] Figure 2 A flowchart showing a method for obtaining a behavior event chain provided by an embodiment of the present application is shown.
[0027] Figure 3 shows a specific implementation flowchart of step S200 in the method for obtaining a behavior event chain according to Figure 2 the corresponding embodiment.
[0028] Figure 4 shows a specific implementation flowchart of step S200 in the method for obtaining a behavior event chain according to Figure 3 the corresponding embodiment.
[0029] Figure 5 shows a specific implementation flowchart of step S300 in the method for obtaining a behavior event chain according to Figure 2 the corresponding embodiment.
[0030] Figure 6 shows a specific implementation flowchart of step S320 in the method for obtaining a behavior event chain according to Figure 5 the corresponding embodiment.
[0031] Figure 7 shows a schematic structural diagram of a device for obtaining a behavior event chain provided by an embodiment of the present application.
[0032] Figure 8 shows a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0033] Now, example embodiments will be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art.
[0034] In addition, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of this application. However, those skilled in the art will realize that the technical solutions of this application can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. can be used. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of this application.
[0035] The block diagrams shown in the drawings are only functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0036] The flowcharts shown in the accompanying drawings are merely illustrative and not necessarily include all the content and operations / steps, nor are they necessarily executed in the described order. For example, some operations / steps can be decomposed, while some operations / steps can be combined or partially combined. Therefore, the actual execution order may change according to the actual situation.
[0037] Figure 1 A schematic diagram of an exemplary system architecture to which the technical solution of the embodiment of the present application can be applied is shown.
[0038] As Figure 1 shown, the system architecture may include terminal devices (such as Figure 1 one or more of the smart phone 101, tablet computer 102, and portable computer 103 shown in
[0039] Of course, it can also be a desktop computer, etc.), network 104, and server 105. Network 104 is used to provide a medium for the communication link between the terminal device and server 105. Network 104 may include various connection types, such as wired communication links, wireless communication links, and so on. Figure 1 It should be understood that
[0040] the numbers of terminal devices, networks, and servers in
[0041] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. For example, server 105 can be a server cluster composed of multiple servers, etc.
[0042] The implementation details of the technical solution of the embodiment of the present application are elaborated in detail below:
[0043] Figure 2 The flowchart of a method for obtaining a behavior event chain according to an embodiment of the present application is shown. The method for obtaining a behavior event chain can be executed by a server, and the server can be the Figure 1 server shown in Figure 2 As shown, the method for obtaining a behavior event chain at least includes:
[0044] S100, dot and layer the device behavior data to obtain multi-level behavior events, where the multi-level behavior events include type-level behavior events, category-level behavior events, and sub-category-level behavior events.
[0045] S200, normalize the category-level behavior events to obtain normalized behavior events.
[0046] S300, perform sorting and splitting processing on the normalized behavior events to obtain a device behavior event chain.
[0047] In the embodiment of the present application, an effective behavior event chain is extracted from the original behavior data of the device through layering normalization and splitting, effectively solving the technical problems of redundancy, clutter, and complexity of device behavior data. At the same time, the data processing efficiency is improved, and finally high-quality input is provided for subsequent analysis and modeling. Specifically, through layering and normalization, behavior events are effectively summarized and standardized, eliminating redundant information and inconsistencies in the data, reducing the complexity of the data, and ensuring the efficiency during model training. At the same time, through sorting and splitting processing, the temporal relationship of behavior events is retained, enabling the device behavior data to be correctly understood and analyzed, and splitting long sequence data can also avoid the consumption of computing resources caused by overly long sequences.
[0048] Adopting a hierarchical behavior event processing method, the device behavior data is refined from multiple levels and dimensions, and finally the patterns of user behavior are effectively extracted, providing high-quality input data for subsequent modeling and analysis. This embodiment not only improves the accuracy and generalization ability of the model, but also reduces the consumption of computing resources, making model training more efficient.
[0049] In S100, the original behavior data of the device is dot and layered, and the data is divided into multiple levels (such as type level, category level, sub-category level, etc.). The events at each level represent different abstraction levels of device behavior. By layering the behavior events, different levels of behavior can be clearly identified, and meaningful features can be gradually extracted.
[0050] The above hierarchical processing method effectively decomposes complex behavioral data into multiple sub - problems that are easy to analyze. The stratified data can not only help reduce the complexity of the data, but also provide structured input for subsequent feature engineering and model training. For example, the type - level behavioral events can represent large - scale behavioral patterns, and the category - level behavioral events are further refined. Finally, more detailed information is provided through the sub - stratified behavioral events.
[0051] In S200, through normalization operations (such as unifying the behavioral events of all categories to the same scale or standard), the differences between different categories can be eliminated. After normalization, the behavioral events of each category have similar scales or distributions, avoiding disproportionate impacts of certain categories on model training. Normalization helps improve the consistency of data processing, making subsequent analysis and model training smoother and more efficient. The normalized behavioral events eliminate the scale differences between categories, ensuring that the behavioral events of each category contribute more evenly to the model, thus enhancing the learning ability and prediction performance of the model.
[0052] Specifically, in some embodiments, the specific implementation of step S200 can refer to Figure 3 . Figure 3 It is based on Figure 2 The detailed description of step S200 in the behavioral event chain acquisition method shown in the corresponding embodiment. In the behavioral event chain acquisition method, step S200 may include the following steps:
[0053] S210, perform standard pre - processing on the category - level behavioral events to obtain standardized behavioral events.
[0054] S220, perform normalization processing on the standardized behavioral events to obtain normalized behavioral events.
[0055] In this embodiment, through data standardization and normalization, it is ensured that behavioral events of different categories can be processed on the same scale, eliminating the dimension difference, thereby improving the accuracy and efficiency of subsequent analysis and modeling.
[0056] Among them, standardization and normalization ensure that different - category behavioral events in device behavioral data are processed on the same scale, eliminating the dimension difference and numerical range difference, making the data more consistent and standardized, avoiding the problem of weight imbalance between different - category events, and also helping to optimize the calculation process, reducing the convergence time in the model training process, and enhancing the efficiency and stability of model training. After standardization, the data has the same mean and standard deviation, which is convenient for analysis through distance or similarity metrics. The normalization process further ensures that the behavioral events are within a unified numerical range, making the contributions of different - category events to model training more balanced and reducing the risk of over - fitting of the model to certain features.
[0057] In S210, for each category of behavior events, after standardization, all behavior events will be mapped to the same scale, making their distributions have the same mean and standard deviation, eliminating the possible differences in units and dimensions in the original data.
[0058] Among them, the standardization described in this step may refer to converting the data into a distribution with a mean of 0 and a standard deviation of 1, which can be specifically achieved through the following formula:
[0059]
[0060] In the above formula, E std is the standardized value, E org is the original value, μ is the mean of the behavior events, and σ is the standard deviation.
[0061] In this step, after standardization, behavior events of different categories will have a unified scale, avoiding the unbalanced influence of different category events on subsequent analysis. For example, events with a large numerical range (such as amount, browsing duration) will not dominate the model training process. The standardized data is more suitable for many machine learning models, especially those relying on distance metrics (such as K-means, support vector machines, etc.), because they are very sensitive to the scale of the data. Standardization balances the contribution of each behavior event in the analysis. For models that require iterative optimization (such as neural networks), standardized data can accelerate the convergence speed of model training because the standardized data usually has a more uniform distribution, making the model optimization process smoother.
[0062] In S220, normalization ensures that the data of all category behavior events are compressed into a unified range, thus avoiding some behavior events with a large numerical range from overly dominating the analysis and modeling process, and ensuring that the contribution of each event is more balanced. On the one hand, the normalized data can better handle the sparsity problem (that is, some behavior events occur less frequently) during analysis, avoiding the negative impact of sparse data on analysis and modeling. For example, some rare events can be avoided from being ignored to a certain extent after normalization; on the other hand, it can help many models (especially those based on gradient descent, such as neural networks, logistic regression, etc.) better fit the data, improving the stability and performance of the model. Normalization makes the data more consistent and helps the algorithm avoid problems caused by some eigenvalue being too large or too small during the training process.
[0063] In some embodiments, normalization refers to converting the data into a unified range according to certain rules, such as the interval [0, 1] or [-1, 1]. Normalization can be specifically achieved using the following formula:
[0064]
[0065] Among them, E mms is the normalized value, and E std is the value before normalization, that is, the value after standardization. is the minimum value among each E std value, is the maximum value among each E std value.
[0066] The above-mentioned normalized data will no longer be affected by the value range of the original data. Especially for data with extreme values or uneven distributions, normalization can better balance the contributions of various behavior events to the model.
[0067] Specifically, in some other embodiments, the specific implementation manner of step S220 can refer to Figure 4 . Figure 4 is the detailed description of step S220 in the method for obtaining a behavior event chain shown in the corresponding embodiment according to Figure 3 . In the method for obtaining a behavior event chain, step S220 may include the following steps:
[0068] S222, identifying the same type of behavior events in the standardized behavior events, where the same type of behavior events are behavior events representing the same operation behavior.
[0069] S224, performing normalization processing on the same type of behavior events to obtain normalized events of the same type.
[0070] S226, using an ngram model to process the normalized events of the same type to obtain normalized behavior events.
[0071] In this embodiment, the accurate identification of the behavior event categories ensures the consistency of the processing of each type of event; the normalization processing of the same type of behavior events eliminates the numerical range differences and balances the contributions of different types of behavior events; the use of the ngram model to capture the temporal dependence relationship of events enhances the model's understanding of user behavior and improves the prediction accuracy and generalization ability. This embodiment solves the possible deviation problem between different types of behavior events in the standardized data and further improves the analysis and modeling capabilities of the method for obtaining a behavior event chain.
[0072] In S222, based on the standardized behavior events, the events are first classified, and it is identified which behavior events belong to the same class, that is, they represent the same operation behavior and the same behavior event. Specifically, the labels of the behavior events can be classified, and different behavior event categories can be distinguished according to multiple dimensions such as the type of the event (such as click, purchase, browse), the time window when the event occurs, the device to which the event belongs, or the user behavior characteristics.
[0073] This step avoids the situation of event category confusion by accurately identifying similar behavior events, ensures that each category of events in the subsequent analysis can be correctly processed, lays a foundation for the subsequent normalization process, and ensures that each category of events has the same scale and semantic meaning during processing, thereby improving the analysis accuracy.
[0074] In S224, through a normalization method (such as scaling the data to the range of [0, 1] or [-1, 1]), the values of each category of behavior events are compressed into a standard range to eliminate the differences between the numerical ranges of different events. For example, if the numerical range of a certain category of behavior events is very large (such as the purchase amount ranging from a few yuan to several thousand yuan), while the numerical range of another category of behavior events is small (such as the number of clicks), then through normalization, the data ranges of these events are scaled to a unified scale to avoid some events having an excessive impact on the subsequent analysis. Among them, normalization usually scales according to the minimum and maximum values of the events to ensure that the behavior events of each category are within the same numerical range. Each category of events is normalized independently to ensure the consistency of the processing of different categories of events.
[0075] Normalization ensures the consistency of similar behavior events in terms of the numerical scale, eliminates the possible dimensional differences that originally existed, and thus improves the accuracy of the subsequent analysis and the model. After normalization, the influence of each event is balanced, the weights of different categories of events are more balanced, and the dominant role of some events with larger numerical values in model training is reduced.
[0076] In S226, the ngram model is a method commonly used in natural language processing. By capturing the sequential relationship between events, it constructs the context of the events. The ngram model processes consecutive n events as a whole, so as to be able to identify the mutual relationship between events, such as sequences of consecutive click, browse and other events. This step combines the same-category normalized events according to a window of a certain length to generate ngram feature vectors, enhancing the temporal information of the behavior events. Among them, the ngram model extracts n consecutive events in the behavior event chain through a sliding window (for example, the combination of click events and browse events), and takes these consecutive events as input features, providing more context information for the subsequent modeling and analysis.
[0077] In this step, the ngram model can effectively capture the temporal relationship between behavioral events. The model can identify the order and pattern of event occurrences, thereby improving the prediction ability of user behavior. On the one hand, the ngram model can generate new features by combining events, enriching the representation form of data and enabling the model to more comprehensively understand the relationship between events. On the other hand, by capturing the context information of events, the ngram model can improve the model's ability to identify complex behavioral patterns, thereby enhancing the generalization ability of the model.
[0078] Specifically, in some embodiments, the specific implementation manner of step S226 can refer to the following embodiments. This embodiment is based on Figure 4 the detailed description of step S226 in the behavioral event chain acquisition method shown in the corresponding embodiment. In the behavioral event chain acquisition method, step S226 may include the following steps:
[0079] Input the homogeneous normalized events into the ngram model to obtain ngram features.
[0080] Perform normalization processing on the ngram features to obtain normalized features.
[0081] Generate a feature representation according to the normalized features to obtain normalized events.
[0082] In this embodiment, the temporal relationship between behavioral events is effectively captured by extracting the context information of consecutive events. Then, normalization processing is performed on the ngram features to balance the contributions of different features and avoid the bias of features with higher frequencies. Finally, through further processing, a concise and effective feature representation is generated to obtain the final normalized events, providing high-quality data input for subsequent analysis and modeling.
[0083] Specifically, first, by inputting homogeneous normalized events into the ngram model and leveraging the sliding window feature of the ngram, the relationships and context information among multiple consecutive events are captured. The ngram model generates ngram features by extracting the context information of events (i.e., combinations of n consecutive events), thereby providing more temporal information for each behavior event chain. Then, by normalizing the ngram features, the scale of each feature is ensured to be consistent. For example, for ngram features that occur at different frequencies, by performing logarithmic transformation or standardization on the frequency, the feature values will not be imbalanced due to overly high or low frequencies. Based on the normalized ngram features, through certain feature mapping or transformation methods, they are converted into a more concise and efficient feature representation. This process may include operations such as feature dimensionality reduction (e.g., PCA or t-SNE), feature selection, or encoding. After ngram feature extraction, normalization processing, and feature representation generation, the finally obtained normalized behavior events contain refined features extracted from the original data, and these features have been standardized and temporalized, and can be directly used for subsequent analysis or model training.
[0084] In S300, the normalized behavior events are sorted to ensure that each event is arranged in chronological order, retaining the temporal relationship between events. This is a key step in solving temporal data problems. According to the time interval or behavior pattern, the long sequence of behavior data is segmented into multiple subsequences (such as Session segmentation). This segmentation helps to effectively model long-term behavior sequences, avoiding the impact of overly long sequences on model performance, and at the same time can capture short-term behavior patterns. The sorting and segmentation processing can effectively retain the time order relationship, thereby improving the model's ability to capture the dependency relationship between behavior events. At the same time, the segmented data can improve the model training efficiency and avoid the computational burden brought by overly long sequences. The finally obtained device behavior event chain can accurately reflect the evolution process of user behavior. This structured event chain is not only convenient for subsequent analysis (such as behavior pattern analysis, user portrait construction, etc.), but can also be directly used for the training of machine learning models (such as sequence prediction models, classification models, etc.).
[0085] Specifically, in some embodiments, the specific implementation manner of step S300 can refer to Figure 5 . Figure 5 It is based on Figure 2 the detailed description of step S300 in the behavior event chain acquisition method shown in the corresponding embodiment. In the behavior event chain acquisition method, step S300 may include the following steps:
[0086] S310, according to the device granularity, sort all the behavior events corresponding to each device in chronological order to obtain the device behavior time series.
[0087] S320. Segment the device behavior time series in terms of sessions to obtain the corresponding device behavior event chains.
[0088] In this embodiment, by sorting according to device granularity and segmenting based on session units, the time sequence of device behavior events can be ensured to be retained. Moreover, through session segmentation, the analysis better conforms to the actual usage scenario, solving the problem of how to extract valuable information from a large number of complex device behaviors, improving the analyzability and operability of event chains, and ultimately achieving a clearer and more accurate understanding and analysis of device behavior.
[0089] In S310, first, for each device, obtain all its corresponding behavior events. Then, sort these events in chronological order to form the behavior time series of each device, solving the problem of disordered event time sequences.
[0090] In S320, segment the sorted device behavior time series by sessions. A session generally refers to a series of related operations or events that a device performs within a certain time period. Through this segmentation, a series of behavior events can be divided into independent event chains according to functions or interaction scenarios, making event analysis more logical and targeted, and enabling better exploration of device behavior patterns.
[0091] Specifically, in some embodiments, the specific implementation of step S320 can refer to Figure 6 . Figure 6 It is based on Figure 5 the detailed description of step S320 in the behavior event chain acquisition method shown in the corresponding embodiment. In the behavior event chain acquisition method, step S320 may include the following steps:
[0092] S322. Determine the time intervals between adjacent behavior events in the device behavior time series.
[0093] S324. Determine the session segments included in the device behavior time series according to the time intervals between adjacent behavior events in the device behavior time series.
[0094] S326. Cut the session segments included in the device behavior time series to obtain the corresponding device behavior event chains.
[0095] In this embodiment, the device behavior time series is segmented by sessions, making the device behavior event chains clearer and more orderly. Through the segmentation of this embodiment, the problems of chaos and time sequence of device behavior events are solved, which helps to more accurately analyze the operation mode of the device, improves the operability and effectiveness of data, and ultimately contributes to the accuracy of intelligent monitoring and behavior prediction.
[0096] In S322, by calculating the time intervals between adjacent behavioral events in the device behavior time series, it provides a basis for subsequent session partitioning. The length of the time intervals obtained in this step can reflect the correlation and closeness between events, thereby helping to identify which behaviors belong to the same session and which belong to different sessions, thus solving the ambiguity of time series event partitioning.
[0097] In S324, based on the time interval information, the algorithm will identify which behavioral events belong to the same session and which belong to different sessions. Events with shorter time intervals are considered as a coherent session segment, while those with longer time intervals are regarded as the separation between sessions.
[0098] The technical effect of this step is that the system can dynamically partition sessions based on a time threshold, accurately reflecting the continuous behavior patterns of the device, and avoiding over-cutting or merging.
[0099] Specifically, in some embodiments, the specific implementation of step S324 can refer to the following embodiments. This embodiment is based on Figure 5 the detailed description of step S324 in the behavioral event chain acquisition method shown in the corresponding embodiment. In the behavioral event chain acquisition method, step S324 may include the following steps:
[0100] Obtain the length and quantity of each of the device behavior time series, and determine a predetermined cutting event interval.
[0101] If the time interval between adjacent behavioral events in the device behavior time series exceeds the predetermined cutting event interval, then the adjacent behavioral events respectively belong to different session segments.
[0102] If the time interval between adjacent behavioral events in the device behavior time series does not exceed the predetermined cutting event interval, then the adjacent behavioral events jointly belong to the same session segment.
[0103] In this embodiment, by judging whether adjacent behavioral events belong to the same session according to their time intervals, session segments can be accurately partitioned, thus eliminating the problems of unclear session partitioning, over-merging or over-segmentation in traditional methods. The time series data of device behaviors is extremely large and complex. Correctly partitioning session segments can make subsequent analysis more efficient and accurate. Through dynamic cutting and analysis, the system can better identify the operation patterns of the device, thereby improving the operability and analysis effect of the data.
[0104] Specifically, the system first counts the overall data length of the time series of each device behavior and the number of behavior events. Based on this data, a predetermined cut event interval is determined to judge whether two behavior events belong to the same session. If the time interval between two adjacent behavior events in the device behavior time series exceeds the predetermined cut event interval, the system will regard these two behavior events as belonging to different session segments. This is because if the event interval is long, the system infers that there may not be sufficient correlation or continuity between these two events and they should be regarded as different sessions or behavior patterns. If the time interval between two adjacent behavior events does not exceed the predetermined cut event interval, the system considers them to belong to the same session segment. This indicates that there is a strong temporal correlation between these two events and they may occur in the same operation process or device state transition, so they should be classified into the same session segment.
[0105] The predetermined cut event interval can be determined through a length - quantity mapping table, obtained according to the mapping relationship formula between the length and quantity of the device behavior time series and the predetermined cut event interval, or obtained by inputting into the corresponding neural network model. This application does not make a limitation here.
[0106] In the above - mentioned embodiment, by setting a reasonable time - interval threshold, the system can effectively distinguish event segments belonging to the same session and different sessions, making the time - series data of device behavior clearer and more structured. By dynamically adjusting the time interval of cut events, the system can adapt to the behavior patterns of different devices, improving applicability and flexibility, and solving the problem that the behavior patterns and time - series characteristics of different devices may vary greatly. And accurately dividing the device behavior time series into multiple session segments with strong internal connections also helps subsequent analyses such as behavior prediction and fault diagnosis, enhancing the system's understanding of the device state and operation rules.
[0107] In S326, after the session segment division is completed, these segments are further cut into independent event chains. Each event chain represents the continuous behavior of the device within a period of time and can clearly reflect the operation process or state transition of the device within a certain time period. It achieves the effect of extracting analyzable units from the continuous large - data stream of device behavior, facilitating subsequent behavior analysis and pattern recognition.
[0108] The following introduces the device embodiments of this application, which can be used to execute the behavior event chain acquisition method in the above - mentioned embodiments of this application. For the details not disclosed in the device embodiments of this application, please refer to the embodiments of the behavior event chain acquisition method above.
[0109] Figure 7 The block diagram of a behavior event chain acquisition device according to an embodiment of this application is shown.
[0110] Refer toFigure 7 As shown in Figure 7 , the behavior event chain acquisition device 130 according to an embodiment of the present application includes: a data stratification module 710, an event normalization module 720, and a sorting and segmentation module 730.
[0111] Among them, the data stratification module 710 is used to mark and stratify the device behavior data to obtain multi-level behavior events, and the multi-level behavior events include type-level behavior events, category-level behavior events, and subdivision-level behavior events; the event normalization module 720 is used to normalize the category-level behavior events to obtain normalized behavior events; the sorting and segmentation module 730 is used to perform sorting and segmentation processing on the normalized behavior events to obtain a device behavior event chain.
[0112] In some embodiments of the present application, the event normalization module specifically includes: a standardization sub-module, which is used to perform standardization preprocessing on the category-level behavior events to obtain standardized behavior events; a normalization sub-module, which is used to perform normalization processing on the standardized behavior events to obtain normalized behavior events.
[0113] In some embodiments of the present application, the normalization sub-module specifically includes: a same-class recognition unit, which is used to recognize the same-class behavior events in the standardized behavior events, and the same-class behavior events are behavior events representing the same operation behavior; a same-class normalization unit, which is used to perform normalization processing on the same-class behavior events to obtain same-class normalization events; an ngram model unit, which is used to process the same-class normalization events using the ngram model to obtain normalized behavior events.
[0114] In some embodiments of the present application, the ngram model unit specifically includes: a feature extraction sub-unit, which is used to input the same-class normalization events into the ngram model to obtain ngram features; a feature normalization sub-unit, which is used to perform normalization processing on the ngram features to obtain normalized features; an event normalization sub-unit, which is used to generate a feature representation according to the normalized features to obtain normalized events.
[0115] In some embodiments of the present application, the sorting and segmentation module specifically includes: an event sorting sub-module, which is used to sort all the behavior events corresponding to each device in time sequence according to the device granularity to obtain a device behavior time sequence; a time sequence segmentation sub-module, which is used to segment the device behavior time sequence in units of sessions to obtain a corresponding device behavior event chain.
[0116] In some embodiments of the present application, the timing segmentation sub-module specifically includes: a time determination unit, configured to determine the time intervals between adjacent behavior events in the device behavior timing; a session determination unit, configured to determine the session segments included in the device behavior timing according to the time intervals between adjacent behavior events in the device behavior timing; and a segment cutting unit, configured to cut the session segments included in the device behavior timing to obtain corresponding device behavior event chains.
[0117] In some embodiments of the present application, the session determination unit specifically includes: a length and quantity sub-unit, configured to obtain the length and quantity of each device behavior timing and determine a predetermined cut event interval; a different session sub-unit, configured to determine that if the time interval between adjacent behavior events in the device behavior timing exceeds the predetermined cut event interval, then the adjacent behavior events belong to different session segments respectively; and a same session sub-unit, configured to determine that if the time interval between adjacent behavior events in the device behavior timing does not exceed the predetermined cut event interval, then the adjacent behavior events belong to the same session segment together.
[0118] In the embodiments of the present application, effective behavior event chains are extracted from the original behavior data of the device through hierarchical normalization and segmentation, effectively solving the technical problems of redundancy, disorder, and complexity of device behavior data. At the same time, the data processing efficiency is improved, and finally high-quality input is provided for subsequent analysis and modeling. Specifically, through hierarchical and normalization, behavior events are effectively summarized and standardized, eliminating redundant information and inconsistencies in the data, reducing the complexity of the data, and ensuring the efficiency during the model training process. At the same time, through sorting and segmentation processing, the timing relationship of behavior events is retained, enabling the device behavior data to be correctly understood and analyzed, and segmenting long sequence data can also avoid the consumption of computing resources caused by overly long sequences.
[0119] Adopting a hierarchical behavior event processing method, the device behavior data is refined from multiple levels and dimensions, and finally the patterns of user behavior are effectively extracted, providing high-quality input data for subsequent modeling and analysis. This embodiment not only improves the accuracy and generalization ability of the model, but also reduces the consumption of computing resources, making the model training more efficient.
[0120] Figure 8 The structure diagram of a computer system of an electronic device suitable for implementing the embodiments of the present application is shown.
[0121] It should be noted that Figure 8 The computer system of the electronic device shown is only an example and should not bring any restrictions to the functions and usage scope of the embodiments of the present application.
[0122] Such as Figure 8As shown, the computer system includes a Central Processing Unit (CPU) 1801, which can perform various appropriate actions and processes according to the program stored in the Read-Only Memory (ROM) 1802 or the program loaded from the storage section 1808 into the Random Access Memory (RAM) 1803, such as executing the method described in the above embodiments. In the RAM 1803, various programs and data required for system operation are also stored. The CPU 1801, ROM 1802, and RAM 1803 are connected to each other via a bus 1804. An Input / Output (I / O) interface 1805 is also connected to the bus 1804.
[0123] The following components are connected to the I / O interface 1805: an input section 1806 including a keyboard, a mouse, etc.; an output section 1807 including, for example, a Cathode Ray Tube (CRT), a Liquid Crystal Display (LCD), etc. and a speaker, etc.; a storage section 1808 including a hard disk, etc.; and a communication section 1809 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 1809 performs communication processing via a network such as the Internet. A drive 1810 is also connected to the I / O interface 1805 as needed. A removable medium 1811, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1810 as needed so that a computer program read from it can be installed into the storage section 1808 as needed.
[0124] Specifically, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network via the communication section 1809, and / or installed from the removable medium 1811. When the computer program is executed by the Central Processing Unit (CPU) 1801, various functions defined in the system of the present application are executed.
[0125] It should be noted that the computer-readable medium shown in the embodiments of the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. In the present application, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable computer program. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0126] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. Among them, each block in the flowchart or block diagram can represent a module, a program segment, or a part of the code, and the above module, program segment, or part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, as well as the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0127] The units involved in the embodiments described in this application can be implemented in software or in hardware, and the described units can also be provided in a processor. Among them, the names of these units do not, in some cases, constitute a limitation on the unit itself.
[0128] On the other hand, this application also provides a computer-readable medium, which can be included in the electronic device described in the above embodiments; or it can exist separately without being assembled into the electronic device. The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by an electronic device, the electronic device implements the methods described in the above embodiments.
[0129] This specification also provides a computer program product, which stores at least one instruction, and the at least one instruction is loaded and executed by the processor to perform the method as described in the above Figures 1 to 6 illustrated embodiments. For the specific execution process, reference can be made to the specific description of the illustrated embodiments, which will not be elaborated here. Figures 1 to 6
[0130] It should be noted that although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of this application, the features and functions of the two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0131] From the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described here can be implemented in software or in a manner combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (such as a personal computer, a server, a touch terminal, or a network device, etc.) to execute the methods according to the embodiments of this application.
[0132] After considering the specification and practicing the disclosed embodiments here, those skilled in the art will readily think of other implementation schemes of this application. This application aims to cover any variations, uses, or adaptive changes of this application, which follow the general principles of this application and include common general knowledge or conventional technical means in the technical field not disclosed in this application.
[0133] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A method for obtaining a behavior event chain, characterized in that: The behavior event chain acquisition method includes: Marking and stratifying the device behavior data to obtain multi-level behavior events, wherein the multi-level behavior events include type-level behavior events, category-level behavior events, and subdivision-level behavior events; Normalizing the category-level behavior events to obtain normalized behavior events; The normalized behavior events are sorted and segmented to obtain a device behavior event chain.
2. The behavior event chain acquisition method according to claim 1, characterized in that: The category-level behavior events are normalized to obtain normalized behavior events, specifically including: Performing standardized preprocessing on the category-level behavior events to obtain standardized behavior events; The standardized behavior events are normalized to obtain normalized behavior events.
3. The behavior event chain acquisition method according to claim 2, characterized in that: The normalizing the standardized behavior event to obtain the normalized behavior event specifically includes: Identifying the same type of behavior events in the standardized behavior events, wherein the same type of behavior events are behavior events representing the same operation behavior; Normalizing the same type of behavior events to obtain similar normalized events; The similar normalized events are processed using an ngram model to obtain normalized behavior events.
4. The behavior event chain acquisition method according to claim 3, characterized in that: The ngram model is used to process the similar normalized events to obtain normalized behavior events, specifically including: Inputting the same type of normalized events into an ngram model to obtain ngram features; Normalizing the ngram features to obtain normalized features; A feature representation is generated according to the normalized feature to obtain a normalized event.
5. The behavior event chain acquisition method according to claim 1, characterized in that: The step of sorting and segmenting the normalized behavior events to obtain a device behavior event chain specifically includes: According to the device granularity, all behavior events corresponding to each device are sorted by time to obtain the device behavior time sequence; The device behavior sequence is segmented into sessions to obtain a corresponding device behavior event chain.
6. The behavior event chain acquisition method according to claim 5, characterized in that: The device behavior sequence is divided into sessions to obtain a corresponding device behavior event chain, specifically including: Determining the time interval between adjacent behavior events in the device behavior time sequence; Determining the session segments included in the device behavior time sequence according to the time intervals between adjacent behavior events in the device behavior time sequence; The session segments included in the device behavior sequence are cut to obtain corresponding device behavior event chains.
7. The behavior event chain acquisition method according to claim 6, characterized in that: The determining, according to the time intervals between adjacent behavior events in the device behavior time sequence, the session segments included in the device behavior time sequence specifically includes: Obtaining the length and quantity of each of the device behavior time series, and determining a predetermined cutting event interval; If the time interval between adjacent behavior events in the device behavior sequence exceeds the predetermined cutting event interval, the adjacent behavior events belong to different session segments respectively; If the time interval between adjacent behavior events in the device behavior sequence does not exceed the predetermined cutting event interval, the adjacent behavior events belong to the same session segment.
8. A behavior event chain acquisition device, characterized in that: The behavior event chain acquisition device comprises: A data stratification module, used to mark and stratify device behavior data to obtain multi-level behavior events, wherein the multi-level behavior events include type-level behavior events, category-level behavior events, and subdivision-level behavior events; An event normalization module, used for normalizing the category-level behavior events to obtain normalized behavior events; The sorting and segmentation module is used to sort and segment the normalized behavior events to obtain a device behavior event chain.
9. A computer readable medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the behavior event chain acquisition method according to any one of claims 1 to 7 is implemented.
10. An electronic device, characterized in that: include: one or more processors; A storage device for storing one or more programs, which, when executed by the one or more processors, enables the one or more processors to implement the behavior event chain acquisition method as described in any one of claims 1 to 7.