Abnormality analysis method and device based on artificial intelligence, computer equipment and medium

By preprocessing and abnormal analysis of the operating data of the target business system, the problem of low dependence on data quality of existing tools is solved, and higher abnormal analysis accuracy and system stability are achieved.

CN120234733APending Publication Date: 2025-07-01PING AN TECH (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510323205.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

Existing anomaly analysis tools have a high dependence on data quality, resulting in low accuracy of system anomaly analysis and inability to effectively overcome the impact of data quality.

Method used

By obtaining the operating data of the target business system, pre-processing, call the exception analysis model for exception analysis, and perform exception interpretation analysis, and finally output processing, including building historical behavior sample data, training and optimization models, identifying exception data and generating interpretation results.

Benefits of technology

Improves the accuracy and comprehensibility of abnormal analysis, helps quickly locate and resolve abnormal problems, and improves the stability and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120234733A_ABST
    Figure CN120234733A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of artificial intelligence, and relates to an anomaly analysis method based on artificial intelligence, which is applied to the field of financial science and technology, and comprises the following steps: obtaining operation data of a target business system; preprocessing the operation data based on a preset processing strategy to obtain corresponding target operation data; calling a preset anomaly analysis model; performing exception analysis on the target operation data based on the exception analysis model to obtain corresponding exception data; performing exception interpretation analysis on the exception data to obtain a corresponding exception interpretation result; and carrying out output processing on the abnormal data and the abnormal explanation result. The invention further provides an anomaly analysis device based on artificial intelligence, computer equipment and a storage medium. In addition, the invention also relates to a block chain technology, and the abnormal data can be stored in a block chain. Based on the use of the exception analysis model, the accuracy and understandability of exception analysis of the target service system are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical fields of artificial intelligence development and fintech, and particularly to an anomaly analysis method, device, computer device, and storage medium based on artificial intelligence. Background Art

[0002] In the financial field, the stable operation of system software is crucial to ensure business continuity and customer trust. With the increasing complexity of financial operations and the continuous growth of transaction volumes, the anomaly analysis of system software and the location of its root causes have become a crucial part of the operation and maintenance work. Quickly and accurately locating and resolving system anomalies is of great significance for restoring system functions, reducing business interruption time, and maintaining system stability and reliability.

[0003] To address this challenge, various anomaly analysis tools, such as KSyAK, have been developed in the industry. These tools are designed to assist operation and maintenance personnel in analyzing system anomalies through intelligent means. These tools can usually use advanced algorithms and models to analyze system logs, monitoring data, etc., to identify anomaly patterns, predict potential problems, and attempt to locate the root causes of anomalies. However, although these anomaly analysis tools have improved the efficiency and accuracy of operation and maintenance work to a certain extent, they still have some significant defects. In particular, some anomaly analysis tools highly rely on high-quality and comprehensive data input. This means that if the input data is incomplete, inaccurate, or contains noise, then the analysis results of these tools may be severely affected, resulting in reduced accuracy and even misleading conclusions.

[0004] Therefore, in existing anomaly analysis tools, how to overcome the dependence on data quality and improve the accuracy of system anomaly analysis is an urgent problem to be solved in the current operation and maintenance work in the financial field. Summary of the Invention

[0005] The purpose of the embodiments of the present application is to propose an anomaly analysis method, device, computer device, and storage medium based on artificial intelligence to solve the technical problem that existing anomaly analysis tools cannot overcome the dependence on data quality, resulting in low accuracy of system anomaly analysis.

[0006] To solve the above technical problem, the embodiments of the present application provide an anomaly analysis method based on artificial intelligence, adopting the following technical solutions:

[0007] Obtain the operation data of the target business system;

[0008] Preprocess the operation data based on a preset processing strategy to obtain corresponding target operation data;

[0009] Invoke a preset anomaly analysis model;

[0010] Perform anomaly analysis on the target operation data based on the anomaly analysis model to obtain corresponding anomaly data;

[0011] Perform anomaly interpretation analysis on the anomaly data to obtain corresponding anomaly interpretation results;

[0012] Perform output processing on the anomaly data and the anomaly interpretation results.

[0013] Furthermore, before the step of calling the preset anomaly analysis model, it further includes:

[0014] Obtain pre-constructed historical behavior sample data; wherein, the historical behavior sample data includes normal behavior data and abnormal behavior data;

[0015] Divide the historical behavior sample data into a training data set and a test data set;

[0016] Call a preset interpretable model;

[0017] Train the interpretable model based on the training data set to obtain a corresponding first model;

[0018] Perform model optimization on the first model based on the test data set to obtain a second model that meets the preset performance requirements;

[0019] Use the second model as the anomaly analysis model.

[0020] Furthermore, the step of performing model optimization on the first model based on the test data set to obtain a second model that meets the preset performance requirements specifically includes:

[0021] Evaluate the performance of the first model on the test data set based on a preset performance evaluation strategy to obtain corresponding first evaluation index data;

[0022] Judge whether the first evaluation index data is greater than a preset index threshold;

[0023] If not, perform optimization processing on the first model based on a preset optimization strategy to obtain an optimized third model;

[0024] Evaluate the performance of the third model on the test data set to obtain corresponding second evaluation index data;

[0025] Judge whether the second evaluation index data is greater than the index threshold;

[0026] If so, use the third model as the second model.

[0027] Further, the step of preprocessing the operation data based on a preset processing strategy to obtain corresponding target operation data specifically includes:

[0028] Clean the operation data to obtain corresponding first operation data;

[0029] Perform data conversion processing on the first operation data to obtain corresponding second operation data;

[0030] Perform normalization processing on the second operation data to obtain corresponding third operation data;

[0031] Use the third operation data as the target operation data.

[0032] Further, the step of performing anomaly interpretation analysis on the anomaly data to obtain corresponding anomaly interpretation results specifically includes:

[0033] Extract the decision path by which the anomaly data is defined as an anomaly type based on the anomaly analysis model;

[0034] Generate corresponding interpretation data based on the decision path;

[0035] Use the interpretation data as the anomaly interpretation result.

[0036] Further, the step of performing output processing on the anomaly data and the anomaly interpretation result specifically includes:

[0037] Call a preset anomaly report template;

[0038] Fill the anomaly data and the anomaly interpretation result into the anomaly report template to obtain a corresponding anomaly report;

[0039] Perform conversion processing on the anomaly report based on a preset conversion tool to obtain a corresponding anomaly report document;

[0040] Perform output processing on the target anomaly report.

[0041] Further, after the step of performing anomaly interpretation analysis on the anomaly data to obtain corresponding anomaly interpretation results, it further includes:

[0042] Obtain the feature data of the anomaly data;

[0043] Obtain the system architecture of the target business system;

[0044] Based on the feature data and the system architecture, identify the target components related to the anomaly data;

[0045] Based on the abnormal interpretation result, perform fault location processing on the target component to obtain the corresponding fault point location result;

[0046] Generate corresponding repair process suggestions based on the fault point location result;

[0047] Send the repair process suggestions to relevant personnel.

[0048] To solve the above technical problems, an embodiment of the present application further provides an abnormal analysis device based on artificial intelligence, which adopts the following technical solutions:

[0049] The first acquisition module is used to acquire the operation data of the target business system;

[0050] The preprocessing module is used to preprocess the operation data based on a preset processing strategy to obtain the corresponding target operation data;

[0051] The first calling module is used to call a preset abnormal analysis model;

[0052] The first analysis module is used to perform abnormal analysis on the target operation data based on the abnormal analysis model to obtain the corresponding abnormal data;

[0053] The second analysis module is used to perform abnormal interpretation analysis on the abnormal data to obtain the corresponding abnormal interpretation result;

[0054] The output module is used to perform output processing on the abnormal data and the abnormal interpretation result.

[0055] To solve the above technical problems, an embodiment of the present application further provides a computer device, which adopts the following technical solutions:

[0056] Acquire the operation data of the target business system;

[0057] Preprocess the operation data based on a preset processing strategy to obtain the corresponding target operation data;

[0058] Call a preset abnormal analysis model;

[0059] Perform abnormal analysis on the target operation data based on the abnormal analysis model to obtain the corresponding abnormal data;

[0060] Perform abnormal interpretation analysis on the abnormal data to obtain the corresponding abnormal interpretation result;

[0061] Perform output processing on the abnormal data and the abnormal interpretation result.

[0062] To solve the above technical problems, an embodiment of the present application further provides a computer-readable storage medium, which adopts the following technical solutions:

[0063] Obtain the operation data of the target business system;

[0064] Preprocess the operation data based on a preset processing strategy to obtain corresponding target operation data;

[0065] Invoke a preset anomaly analysis model;

[0066] Perform anomaly analysis on the target operation data based on the anomaly analysis model to obtain corresponding anomaly data;

[0067] Perform anomaly interpretation analysis on the anomaly data to obtain corresponding anomaly interpretation results;

[0068] Perform output processing on the anomaly data and the anomaly interpretation results.

[0069] Compared with the prior art, the embodiments of the present application mainly have the following beneficial effects:

[0070] The present application first obtains the operation data of the target business system; then preprocesses the operation data based on a preset processing strategy to obtain corresponding target operation data; then invokes a preset anomaly analysis model; and performs anomaly analysis on the target operation data based on the anomaly analysis model to obtain corresponding anomaly data; subsequently, performs anomaly interpretation analysis on the anomaly data to obtain corresponding anomaly interpretation results; and finally, performs output processing on the anomaly data and the anomaly interpretation results. By preprocessing the obtained operation data of the target business system based on the use of the processing strategy to obtain target operation data, the present application effectively ensures the accuracy of the data input of the anomaly analysis model. Furthermore, by using the anomaly analysis model to perform anomaly analysis on the target operation data to obtain anomaly data and performing anomaly interpretation analysis on the anomaly data to obtain anomaly interpretation results, the accuracy and comprehensibility of the anomaly analysis of the target business system are effectively improved. It is beneficial for subsequent output processing of the anomaly data and the anomaly interpretation results, which can help relevant personnel understand the causes and backgrounds of the anomalies occurring in the target business system, as well as the impact degree of the anomalies on the target business system, and can assist relevant personnel in quickly locating and solving the anomaly problems existing in the target business system, thereby improving the stability and security of the target business system. BRIEF DESCRIPTION OF THE DRAWINGS

[0071] To more clearly illustrate the solutions in the present application, the following will briefly introduce the drawings required for the description of the embodiments of the present application. Obviously, the drawings described below are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0072] Figure 1 is an exemplary system architecture diagram to which the present application can be applied;

[0073] Figure 2 Flowchart of an embodiment of the anomaly analysis method based on artificial intelligence according to the present application;

[0074] Figure 3 is a schematic structural diagram of an embodiment of the anomaly analysis device based on artificial intelligence according to the present application;

[0075] Figure 4 is a schematic structural diagram of an embodiment of the computer device according to the present application. Detailed implementation manners

[0076] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs; the terms used in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the specification and claims of this application and the above drawings are intended to cover non-exclusive inclusion. The terms "first", "second", etc. in the specification and claims of this application or the above drawings are used to distinguish different objects and not to describe a specific order.

[0077] Reference to "embodiment" herein means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of this application. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0078] To enable those skilled in the technical field to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.

[0079] As Figure 1 shown, the system architecture 100 may include a terminal device 101, a network 102, and a server 103. The terminal device 101 may be a laptop computer 1011, a tablet computer 1012, or a mobile phone 1013. The network 102 is a medium for providing a communication link between the terminal device 101 and the server 103. The network 102 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0080] Users can use the terminal device 101 to interact with the server 103 via the network 102 to receive or send messages, etc. Various communication client applications can be installed on the terminal device 101, such as a web browser application, a shopping application, a search application, an instant messaging tool, an email client, a social platform software, etc.

[0081] The terminal device 101 can be various electronic devices with a display screen and supporting web browsing. In addition to the laptop computer 1011, the tablet computer 1012 or the mobile phone 1013, the terminal device 101 can also be an e-book reader, an MP3 player (Moving Picture Experts Group Audio Layer III), an MP4 (Moving Picture Experts Group Audio Layer IV) player, a laptop portable computer, a desktop computer, and so on.

[0082] The server 103 can be a server providing various services, such as a background server that provides support for the pages displayed on the terminal device 101.

[0083] It should be noted that the abnormal analysis method based on artificial intelligence provided by the embodiments of the present application is generally executed by the server / terminal device. Correspondingly, the abnormal analysis device based on artificial intelligence is generally set in the server / terminal device.

[0084] It should be understood that Figure 1 the numbers of the terminal devices, networks, and servers in

[0085] Continuing to refer to Figure 2 , a flowchart of an embodiment of the abnormal analysis method based on artificial intelligence according to the present application is shown. According to different requirements, the order of the steps in this flowchart can be changed, and some steps can be omitted. The abnormal analysis method based on artificial intelligence provided by the embodiments of the present application can be applied to any scenario that requires abnormal analysis. Then, the abnormal analysis method based on artificial intelligence can be applied to the products in these scenarios. For example, the abnormal analysis of the financial system in the financial insurance field. The described abnormal analysis method based on artificial intelligence includes the following steps:

[0086] Step S201, obtain the operation data of the target business system.

[0087] In this embodiment, the electronic device on which the abnormal analysis method based on artificial intelligence runs (such as Figure 1The server / terminal device shown can obtain the operation data of the target business system through a wired connection method or a wireless connection method. It should be noted that the above wireless connection methods may include, but are not limited to, 3G / 4G / 5G connections, WiFi connections, Bluetooth connections, WiMAX connections, Zigbee connections, UWB (ultra wideband) connections, and other currently known or future-developed wireless connection methods. The execution entity of this application can specifically be an anomaly analysis system, or simply referred to as the system. In the business scenarios of finance and insurance, the above business systems may include insurance systems, banking systems, claims settlement systems, and so on. The above operation data is data that can comprehensively reflect the operation status of the target business system. It can be obtained by collecting data including, but not limited to, log data, performance metrics, user behavior data, etc. from the components and applications of the target business system, and performing data integration to obtain the above operation data.

[0088] Step S202, preprocess the operation data based on a preset processing strategy to obtain corresponding target operation data.

[0089] In this embodiment, the specific implementation process of preprocessing the operation data based on a preset processing strategy to obtain corresponding target operation data will be further described in detail in the subsequent specific embodiments of this application, and will not be elaborated here too much.

[0090] Step S203, call a preset anomaly analysis model.

[0091] In this embodiment, the model construction process of the above anomaly analysis model will be further described in detail in the subsequent specific embodiments of this application, and will not be elaborated here too much.

[0092] Step S204, perform anomaly analysis on the target operation data based on the anomaly analysis model to obtain corresponding anomaly data.

[0093] In this embodiment, by inputting the above target operation data into the anomaly analysis model, the anomaly analysis model will identify the data that deviates from the normal behavior according to the learned characteristics of normal behavior and abnormal behavior, mark these data as abnormal, and then output the corresponding anomaly detection results, that is, the above anomaly data marked as abnormal.

[0094] Step S205, perform anomaly interpretation analysis on the anomaly data to obtain corresponding anomaly interpretation results.

[0095] In this embodiment, the specific implementation process of performing anomaly interpretation analysis on the anomaly data to obtain corresponding anomaly interpretation results will be further described in detail in the subsequent specific embodiments of this application, and will not be elaborated here too much.

[0096] Step S206, perform output processing on the abnormal data and the abnormal explanation result.

[0097] In this embodiment, for the specific implementation process of performing output processing on the abnormal data and the abnormal explanation result, this application will further describe the details in subsequent specific embodiments and will not elaborate too much here.

[0098] This application first obtains the operation data of the target business system; then preprocesses the operation data based on a preset processing strategy to obtain corresponding target operation data; then calls a preset abnormal analysis model; and performs abnormal analysis on the target operation data based on the abnormal analysis model to obtain corresponding abnormal data; subsequently, performs abnormal explanation analysis on the abnormal data to obtain a corresponding abnormal explanation result; and finally performs output processing on the abnormal data and the abnormal explanation result. By preprocessing the obtained operation data of the target business system based on the use of the processing strategy to obtain the target operation data, this application effectively ensures the accuracy of the data input of the abnormal analysis model. Furthermore, by using the abnormal analysis model to perform abnormal analysis on the target operation data to obtain abnormal data and performing abnormal explanation analysis on the abnormal data to obtain the abnormal explanation result, it effectively improves the accuracy and comprehensibility of the abnormal analysis of the target business system. It is beneficial for subsequent output processing of the abnormal data and the abnormal explanation result, which can help relevant personnel understand the cause and background of the abnormality occurrence in the target business system, as well as the impact degree of the abnormality on the target business system, and can assist relevant personnel in quickly locating and solving the abnormal problems existing in the target business system, thereby improving the stability and security of the target business system.

[0099] In some optional implementation manners, before step S203, the above electronic device may further perform the following steps:

[0100] Obtain pre-constructed historical behavior sample data; wherein, the historical behavior sample data includes normal behavior data and abnormal behavior data.

[0101] In this embodiment, the normal behavior data and abnormal behavior data of a related system (a business system of the same type as the target business system) within a historical time period can be collected and integrated to construct the corresponding historical behavior sample data. Among them, there is no specific limitation on the selection of the time of the above historical time period. For example, the past year can be adopted. In addition, the historical behavior sample data can be further preprocessed, including data cleaning, data conversion, and data normalization, to improve the data quality and integrity.

[0102] Divide the historical behavior sample data into a training data set and a test data set.

[0103] In this embodiment, the above historical behavior sample data can be divided into a training data set and a test data set according to a preset division ratio. Among them, the value selection of the division ratio is not specifically limited and can be set according to actual usage requirements. For example, it can be set to 8:2.

[0104] Call a preset interpretable model.

[0105] In this embodiment, the above interpretable model can specifically adopt a decision tree model, or a random forest model can also be adopted.

[0106] Train the interpretable model based on the training data set to obtain a corresponding first model.

[0107] In this embodiment, by inputting the training data set into the interpretable model. And set the model parameters of the interpretable model, such as the depth of the decision tree, etc. Then, through training, the interpretable model can learn the characteristics of normal behavior and abnormal behavior, and obtain a corresponding first model.

[0108] Optimize the first model based on the test data set to obtain a second model that meets the preset performance requirements.

[0109] In this embodiment, the specific implementation process of optimizing the first model based on the test data set to obtain a second model that meets the preset performance requirements will be further described in detail in the subsequent specific embodiments of this application, and will not be elaborated here too much.

[0110] Use the second model as the anomaly analysis model.

[0111] In this embodiment, the anomaly analysis model can also be continuously learned and optimized to improve the accuracy of anomaly detection, reduce false alarms and missed detections, improve detection reliability, and reduce unnecessary investigation and repair work. And, for the diverse needs of the system, through transfer learning and adaptive models, the anomaly analysis model can adapt to the needs of different systems and applications, provide customized solutions, improve the versatility and adaptability of the anomaly analysis model, and reduce the complexity and time consumption of customized configuration.

[0112] This application obtains pre-constructed historical behavior sample data; wherein, the historical behavior sample data includes normal behavior data and abnormal behavior data; then divides the historical behavior sample data into a training data set and a test data set; then calls a preset interpretable model; subsequently trains the interpretable model based on the training data set to obtain a corresponding first model; further optimizes the first model based on the test data set to obtain a second model that meets the preset performance requirements; finally, uses the second model as the anomaly analysis model. This application obtains pre-constructed historical behavior sample data, divides the historical behavior sample data into a training data set and a test data set, then trains an interpretable model based on the training data set to obtain a corresponding first model, and optimizes the first model based on the use of the test data set, so as to efficiently and accurately construct an anomaly analysis model that meets the performance requirements, improve the construction efficiency of the anomaly analysis model, and ensure the model effect of the obtained anomaly analysis model.

[0113] In some alternative implementation manners of this embodiment, the optimizing the first model based on the test data set to obtain a second model that meets the preset performance requirements includes the following steps:

[0114] Evaluate the performance of the first model on the test data set based on a preset performance evaluation strategy to obtain corresponding first evaluation index data.

[0115] In this embodiment, the above performance evaluation strategy may specifically adopt evaluation methods such as cross-validation and confusion matrix. The performance of the first model on the test data set can be evaluated by using this performance evaluation strategy, and corresponding first evaluation index data can be obtained. Among them, the first evaluation index data may specifically include one or more of accuracy rate, recall rate, F1 score, etc.

[0116] Judge whether the first evaluation index data is greater than a preset index threshold.

[0117] In this embodiment, the first evaluation index data and the preset index threshold can be numerically compared to determine whether the first evaluation index data is greater than the index threshold. Among them, the numerical selection of the above index threshold is not specifically limited and can be set according to the actual evaluation service requirements.

[0118] If not, optimize the first model based on a preset optimization strategy to obtain an optimized third model.

[0119] In this embodiment, the above optimization strategy may specifically include adjusting parameters, improving the network architecture, etc. If it is detected that the first evaluation index data is less than the above index threshold, the first model is optimized based on the optimization strategy to improve the performance of the first model on the test data set, and the optimized third model is obtained.

[0120] Evaluate the performance of the third model on the test data set to obtain the corresponding second evaluation index data.

[0121] In this embodiment, similarly, the performance of the third model on the test data set can be evaluated according to the above performance evaluation strategy, so as to obtain the corresponding second evaluation index data.

[0122] Judge whether the second evaluation index data is greater than the index threshold.

[0123] In this embodiment, the second evaluation index data and the above index threshold can be numerically compared to determine whether the second evaluation index data is greater than the index threshold.

[0124] If so, use the third model as the second model.

[0125] In this embodiment, if it is detected that the second evaluation index data is greater than the above index threshold, it is determined that the performance of the third model on the test data set meets the performance requirements, and then the third model is used as the above second model.

[0126] In this application, the performance of the first model on the test data set is evaluated based on a preset performance evaluation strategy to obtain the corresponding first evaluation index data; then it is judged whether the first evaluation index data is greater than the preset index threshold; if not, the first model is optimized based on a preset optimization strategy to obtain the optimized third model; then the performance of the third model on the test data set is evaluated to obtain the corresponding second evaluation index data; subsequently, it is judged whether the second evaluation index data is greater than the index threshold; if so, the third model is used as the second model. In this application, the performance of the first model on the test data set is evaluated based on the use of the performance evaluation strategy to obtain the corresponding first evaluation index data, and when it is detected that the first evaluation index data is less than the preset index threshold, the first model is automatically and intelligently optimized based on the use of the optimization strategy to obtain the optimized third model, and then the performance of the third model on the test data set is evaluated to obtain the second evaluation index data, and when it is detected that the second evaluation index data is greater than the index threshold, the obtained third model is used as the second model that meets the preset performance requirements, effectively ensuring the model effect of the obtained second model.

[0127] In some alternative implementation manners, step S202 includes the following steps:

[0128] Clean the operation data to obtain corresponding first operation data.

[0129] In this embodiment, the above cleaning process includes denoising and missing value filling. Specifically, the denoising process includes: automatically identifying the noise in the operation data by using machine learning algorithms. The noise data may include invalid values, duplicate values, or outliers, etc. Then, according to the identification result, the noise in the data is removed. For invalid values, they can be directly deleted or replaced with default values; for duplicate values, a deduplication algorithm can be used for deletion; for outliers, they can be deleted or corrected according to the actual situation. The above missing value filling process includes: for the missing values in the data, appropriate filling strategies are used for filling. Filling strategies including using statistics such as mean, median, and mode can be adopted for filling, or interpolation can be used for estimation, and it is ensured that the data after filling can maintain the integrity and consistency of the data.

[0130] Perform data conversion processing on the first operation data to obtain corresponding second operation data.

[0131] In this embodiment, the above data conversion processing includes: converting the data into a format suitable for analysis. Specifically, it may include data type conversion (such as converting a string-type date to a date type), data format adjustment (such as unifying different formats of data into the same format), etc., so as to ensure that the data after conversion can be conveniently analyzed and processed subsequently.

[0132] Perform normalization processing on the second operation data to obtain corresponding third operation data.

[0133] In this embodiment, the above normalization processing includes: scaling the operation data to a specific range (such as [0, 1] or [-1, 1]), so that data in different dimensions can have the same weight in subsequent analysis to eliminate the dimensional difference between different data dimensions. Among them, normalization methods including Min-Max Normalization and Z-score standardization can be adopted to implement the normalization processing.

[0134] Use the third operation data as the target operation data.

[0135] In this application, the corresponding first operation data is obtained by cleaning the operation data; then the corresponding second operation data is obtained by performing data conversion processing on the first operation data; after that, the corresponding third operation data is obtained by performing normalization processing on the second operation data; subsequently, the third operation data is used as the target operation data. By using the processing strategy, this application performs cleaning processing, data conversion processing, and normalization processing on the operation data, thereby enabling efficient and accurate preprocessing of the operation data, reducing manual intervention, and effectively ensuring the quality and integrity of the generated target operation data. When the subsequent anomaly analysis model is used to perform anomaly analysis on the target operation data, the processing efficiency and accuracy of the anomaly analysis can be effectively improved.

[0136] In some alternative implementation manners of this embodiment, step S205 includes the following steps:

[0137] Extracting the decision path in which the abnormal data is defined as the abnormal type based on the anomaly analysis model.

[0138] In this embodiment, the above anomaly analysis model may specifically adopt a decision tree - type model. By using the above anomaly analysis model, the decision path from the root node to the leaf node of the output abnormal data can be extracted, which represents the logical process of classifying the abnormal data into a specific abnormal type.

[0139] Generating corresponding explanation data based on the decision path.

[0140] In this embodiment, easy - to - understand explanation data can be generated based on the obtained decision path, including the characteristics of the abnormal data (such as abnormal values, abnormal frequencies, etc.), the reasons for the occurrence of the anomaly (such as configuration errors, resource overload, etc.), and the background (such as the occurrence time, the scope of influence, etc.).

[0141] Using the explanation data as the anomaly explanation result.

[0142] In this embodiment, by using the anomaly analysis result, a detailed decision - making process and explanation can be provided, which can help the operation and maintenance personnel understand the abnormal data and improve the efficiency of fault location and repair.

[0143] In this application, the decision path in which the abnormal data is defined as the abnormal type is extracted based on the abnormal analysis model; then the corresponding explanation data is generated based on the decision path; subsequently, the explanation data is used as the abnormal explanation result. By extracting the decision path in which the abnormal data is defined as the corresponding abnormal type based on the abnormal analysis model, this application can then quickly and accurately generate the corresponding abnormal explanation result based on the decision path, improving the accuracy and comprehensibility of the abnormal analysis of the target business system. It is beneficial to output the abnormal explanation result subsequently, which can help relevant personnel understand the cause and background of the abnormality and the impact degree of the abnormality on the target business system, and can assist relevant personnel in quickly locating and solving the abnormal problems existing in the target business system, thereby improving the stability and security of the target business system.

[0144] In some alternative implementation manners of this embodiment, step S206 includes the following steps:

[0145] Call a preset abnormal report template.

[0146] In this embodiment, the above abnormal report template is a report template constructed according to actual business requirements and including an abnormal data area and an explanation result area.

[0147] Fill the abnormal data and the abnormal explanation result into the abnormal report template to obtain the corresponding abnormal report.

[0148] In this embodiment, the corresponding abnormal report can be obtained by filling the above abnormal data into the abnormal data area in the abnormal report template and filling the above abnormal explanation result into the explanation result area in the abnormal report template.

[0149] Perform conversion processing on the abnormal report based on a preset conversion tool to obtain the corresponding abnormal report document.

[0150] In this embodiment, the above conversion tool is a tool with the function of converting a report into an easily readable report document. By using the conversion tool to perform conversion processing on the abnormal report, the corresponding abnormal report document can be obtained, and the abnormal report document can include charts, tables, detailed explanations, etc.

[0151] Perform output processing on the target abnormal report.

[0152] In this embodiment, the target abnormal report can be distributed to relevant operation and maintenance teams or management personnel to complete the output processing of the target abnormal report, so as to facilitate relevant personnel to take actions in a timely manner.

[0153] This application calls a preset exception report template; then fills the exception data and the exception explanation result into the exception report template to obtain a corresponding exception report; then performs a conversion process on the exception report based on a preset conversion tool to obtain a corresponding exception report document; and subsequently performs an output process on the target exception report. By filling the exception data and the exception explanation result into the preset exception report template, this application obtains a corresponding exception report, and then performs a conversion process on the exception report based on the use of the conversion tool to obtain a corresponding exception report document, and performs an output process on the target exception report, improving the intelligence of data output, helping relevant personnel to quickly locate and solve exception problems based on the target exception report, and thus improving the stability and security of the target business system.

[0154] In some alternative implementation manners, after step S206, the above-mentioned electronic device may further perform the following steps:

[0155] Obtain the characteristic data of the exception data.

[0156] In this embodiment, the characteristic data of the above-mentioned exception data includes data such as the exception type, occurrence time, and influence range of the exception data.

[0157] Obtain the system architecture of the target business system.

[0158] In this embodiment, the system architecture of the above-mentioned target business system includes architecture data such as the functions of each component in the target business system, the connection relationships between them, and the data flow.

[0159] Based on the characteristic data and the system architecture, identify the target components related to the exception data.

[0160] In this embodiment, by analyzing the above-mentioned characteristic data and system architecture to analyze the components that the exception may involve, that is, identifying the target components related to the exception data. And the dependency relationship and interaction mode between the exception data and the target components can be further determined.

[0161] Based on the exception explanation result and the target components, perform a fault location process to obtain a corresponding fault point location result.

[0162] In this embodiment, the specific fault point can be located according to the exception explanation result and the target components, and the possible causes of the fault point can be determined, such as configuration errors, software defects, hardware failures, etc., and the fault point and the possible causes of the fault point are integrated to obtain a corresponding fault point location result.

[0163] Generate a corresponding repair process suggestion based on the fault point location result.

[0164] In this embodiment, an intelligent repair process recommendation can be generated based on the obtained fault point location result. Specifically, the fault location result can be matched with the fault types in the preset knowledge base to find the historical fault most similar to the current fault, and its repair steps and required resources can be extracted, and the obtained repair steps and required resources can be integrated to generate the above-mentioned repair process recommendation. Among them, historical fault data is collected in advance, including fault types, occurrence times, repair steps, required resources, etc. Furthermore, based on the historical fault data, a knowledge base including fault types, causes, repair steps, and required resources is established. And the knowledge base is continuously updated and improved to reflect the latest fault repair experience and best practices.

[0165] Send the repair process recommendation to relevant personnel.

[0166] In this embodiment, the above-mentioned relevant personnel include relevant operation and maintenance teams or management personnel.

[0167] This application obtains the characteristic data of the abnormal data; and obtains the system architecture of the target business system; then based on the characteristic data and the system architecture, identifies the target components related to the abnormal data; then based on the abnormal explanation result and the target components, performs fault location processing to obtain the corresponding fault point location result; subsequently, generates the corresponding repair process recommendation based on the fault point location result; and finally sends the repair process recommendation to relevant personnel. After this application performs abnormal explanation analysis on the abnormal data to obtain the corresponding abnormal explanation result, it will also identify the target components related to the abnormal data according to the obtained characteristic data of the abnormal data and the obtained system architecture of the target business system, and perform fault location processing based on the abnormal explanation result and the target components to obtain the corresponding fault point location result, and then automatically generate the corresponding repair process recommendation based on the fault point location result and send it to relevant personnel, which helps relevant personnel quickly locate and solve the abnormal problems of the target business system according to the obtained repair process recommendation, thereby improving the stability and security of the target business system.

[0168] In some alternative implementation manners, the obtained user information has obtained the consent of the user and complies with the provisions of relevant laws and relevant policies.

[0169] In addition, the non-company software tools or components appearing in the embodiments of this application are only for illustrative introduction and do not represent actual use.

[0170] In addition, based on the use of the anomaly analysis model, this application can effectively support the solution of the deficiencies of the anomaly analysis tools in the auxiliary system, improve the efficiency and accuracy of system monitoring and troubleshooting, reduce manual intervention in the anomaly analysis process, improve the analysis efficiency, and reduce the operation and maintenance costs, enabling the organization to achieve higher system stability and reliability at a lower cost. In addition, it can provide intelligent analysis assistance and repair process suggestions, reduce the requirements for professional knowledge and skills, enable more people to use and understand the anomaly analysis tools, and thus improve the overall efficiency of the team.

[0171] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0172] It should be emphasized that to further ensure the privacy and security of the above-mentioned anomaly data, the above-mentioned anomaly data can also be stored in the nodes of a blockchain.

[0173] The blockchain referred to in this application is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithms. Blockchain, in essence, is a decentralized database, a series of data blocks generated by using cryptographic methods. Each data block contains information about a batch of network transactions, used to verify the validity of the information (anti-counterfeiting) and generate the next block. The blockchain can include the blockchain underlying platform, the platform product service layer, and the application service layer, etc.

[0174] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Among them, Artificial Intelligence (AI) is to use a digital computer or a machine controlled by a digital computer to simulate, extend, and expand human intelligence, sense the environment, acquire knowledge, and use the knowledge to obtain the best results of theory, method, technology, and application system.

[0175] The basic technologies of artificial intelligence generally include technologies such as sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technology, operation / interaction systems, and mechatronics. The software technologies of artificial intelligence mainly include several major directions such as computer vision technology, robotics, biometric technology, speech processing technology, natural language processing technology, and machine learning / deep learning.

[0176] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through computer-readable instructions. These computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.

[0177] It should be understood that although the steps in the flowchart of the accompanying drawings are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps does not have a strict order limit, and they can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. Their execution order is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or sub-steps or stages of other steps.

[0178] Further referring to Figure 3 as an implementation of the above Figure 2 shown method, an embodiment of an abnormal analysis device based on artificial intelligence is provided in this application. This device embodiment corresponds to the Figure 2 shown method embodiment, and this device can be specifically applied to various electronic devices.

[0179] As Figure 3 shown, the abnormal analysis device 300 based on artificial intelligence described in this embodiment includes: a first acquisition module 301, a preprocessing module 302, a first call module 303, a first analysis module 304, a second analysis module 305, and an output module 306. Among them:

[0180] The first acquisition module 301 is used to acquire the operation data of the target business system;

[0181] The preprocessing module 302 is used to preprocess the operation data based on a preset processing strategy to obtain corresponding target operation data;

[0182] The first call module 303 is used to call a preset abnormal analysis model;

[0183] The first analysis module 304 is used to perform abnormal analysis on the target operation data based on the abnormal analysis model to obtain corresponding abnormal data;

[0184] The second analysis module 305 is configured to perform abnormal interpretation analysis on the abnormal data to obtain corresponding abnormal interpretation results;

[0185] The output module 306 is configured to perform output processing on the abnormal data and the abnormal interpretation results.

[0186] In this embodiment, the operations respectively performed by the above modules or units correspond one by one to the steps of the artificial intelligence-based abnormal analysis method in the foregoing embodiment, and will not be elaborated herein.

[0187] In some optional implementation manners of this embodiment, the artificial intelligence-based abnormal analysis device 300 further includes:

[0188] The second acquisition module is configured to acquire pre-constructed historical behavior sample data; wherein, the historical behavior sample data includes normal behavior data and abnormal behavior data;

[0189] The division module is configured to divide the historical behavior sample data into a training data set and a test data set;

[0190] The second call module is configured to call a preset interpretable model;

[0191] The training module is configured to train the interpretable model based on the training data set to obtain a corresponding first model;

[0192] The optimization module is configured to perform model optimization on the first model based on the test data set to obtain a second model that meets the preset performance requirements;

[0193] The determination module is configured to use the second model as the abnormal analysis model.

[0194] In this embodiment, the operations respectively performed by the above modules or units correspond one by one to the steps of the artificial intelligence-based abnormal analysis method in the foregoing embodiment, and will not be elaborated herein.

[0195] In some optional implementation manners of this embodiment, the optimization module includes:

[0196] The first evaluation sub-module is configured to evaluate the performance of the first model on the test data set based on a preset performance evaluation strategy to obtain corresponding first evaluation index data;

[0197] The first judgment sub-module is configured to judge whether the first evaluation index data is greater than a preset index threshold;

[0198] The optimization sub-module is configured to, if not, perform optimization processing on the first model based on a preset optimization strategy to obtain an optimized third model;

[0199] A second evaluation sub-module, configured to evaluate the performance of the third model on the test data set to obtain corresponding second evaluation index data;

[0200] A second judgment sub-module, configured to judge whether the second evaluation index data is greater than the index threshold;

[0201] A first determination sub-module, configured to, if so, use the third model as the second model.

[0202] In this embodiment, the operations respectively performed by the above modules or units correspond one by one to the steps of the artificial intelligence-based anomaly analysis method in the foregoing embodiment, and will not be elaborated herein.

[0203] In some alternative implementation manners of this embodiment, the preprocessing module 302 includes:

[0204] A first processing sub-module, configured to clean the operation data to obtain corresponding first operation data;

[0205] A second processing sub-module, configured to perform data conversion processing on the first operation data to obtain corresponding second operation data;

[0206] A third processing sub-module, configured to perform normalization processing on the second operation data to obtain corresponding third operation data;

[0207] A second determination sub-module, configured to use the third operation data as the target operation data.

[0208] In this embodiment, the operations respectively performed by the above modules or units correspond one by one to the steps of the artificial intelligence-based anomaly analysis method in the foregoing embodiment, and will not be elaborated herein.

[0209] In some alternative implementation manners of this embodiment, the second analysis module 305 includes:

[0210] An extraction sub-module, configured to extract the decision path in which the abnormal data is defined as an abnormal type based on the anomaly analysis model;

[0211] A generation sub-module, configured to generate corresponding explanation data based on the decision path;

[0212] A third determination sub-module, configured to use the explanation data as the anomaly explanation result.

[0213] In this embodiment, the operations respectively performed by the above modules or units correspond one by one to the steps of the artificial intelligence-based anomaly analysis method in the foregoing embodiment, and will not be elaborated herein.

[0214] In some alternative implementation manners of this embodiment, the output module 306 includes:

[0215] A calling sub-module, which is used to call a preset exception report template;

[0216] A filling sub-module, which is used to fill the exception data and the exception explanation result into the exception report template to obtain a corresponding exception report;

[0217] A conversion sub-module, which is used to perform conversion processing on the exception report based on a preset conversion tool to obtain a corresponding exception report document;

[0218] An output sub-module, which is used to perform output processing on the target exception report.

[0219] In this embodiment, the operations respectively performed by the above modules or units correspond one by one to the steps of the artificial intelligence-based exception analysis method in the foregoing embodiment, and will not be elaborated herein.

[0220] In some optional implementation manners of this embodiment, the artificial intelligence-based exception analysis device further includes:

[0221] A third acquisition module, which is used to acquire the feature data of the exception data;

[0222] A fourth acquisition module, which is used to acquire the system architecture of the target business system;

[0223] An identification module, which is used to identify a target component related to the exception data based on the feature data and the system architecture;

[0224] A positioning module, which is used to perform fault positioning processing based on the exception explanation result and the target component to obtain a corresponding fault point positioning result;

[0225] A generation module, which is used to generate a corresponding repair process suggestion based on the fault point positioning result;

[0226] A sending module, which is used to send the repair process suggestion to relevant personnel.

[0227] In this embodiment, the operations respectively performed by the above modules or units correspond one by one to the steps of the artificial intelligence-based exception analysis method in the foregoing embodiment, and will not be elaborated herein.

[0228] To solve the above technical problems, an embodiment of the present application further provides a computer device. For details, please refer to Figure 4 , Figure 4 which is the basic structural block diagram of the computer device in this embodiment.

[0229] The computer device 4 includes a memory 41, a processor 42, and a network interface 43 that are communicatively connected to each other via a system bus. It should be noted that only the computer device 4 with components 41-43 is shown in the figure, but it should be understood that it is not required to implement all the shown components, and more or fewer components can be alternatively implemented. Among them, those skilled in the art of this technology can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0230] The computer device can be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The computer device can perform human-computer interaction with the user through means such as a keyboard, a mouse, a remote control, a touchpad, or a voice control device.

[0231] The memory 41 includes at least one type of readable storage medium, and the readable storage medium includes flash memory, a hard disk, a multimedia card, a card-type memory (such as an SD or DX memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, an optical disk, etc. In some embodiments, the memory 41 can be an internal storage unit of the computer device 4, such as the hard disk or memory of the computer device 4. In other embodiments, the memory 41 can also be an external storage device of the computer device 4, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device 4. Of course, the memory 41 can also include both the internal storage unit and the external storage device of the computer device 4. In this embodiment, the memory 41 is generally used to store the operating system and various application software installed on the computer device 4, such as computer-readable instructions for an anomaly analysis method based on artificial intelligence. In addition, the memory 41 can also be used to temporarily store various types of data that have been output or will be output.

[0232] In some embodiments, the processor 42 may be a Central Processing Unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips. The processor 42 is generally used to control the overall operation of the computer device 4. In this embodiment, the processor 42 is used to run the computer-readable instructions stored in the memory 41 or process data, such as running the computer-readable instructions of the abnormal analysis method based on artificial intelligence.

[0233] The network interface 43 may include a wireless network interface or a wired network interface, and this network interface 43 is generally used to establish a communication connection between the computer device 4 and other electronic devices.

[0234] Compared with the prior art, the embodiments of the present application mainly have the following beneficial effects:

[0235] In the embodiments of the present application, the obtained operation data of the target business system is preprocessed based on the use of a processing policy to obtain target operation data, effectively ensuring the accuracy of the data input of the abnormal analysis model. Furthermore, based on the use of the abnormal analysis model, abnormal analysis is performed on the target operation data to obtain abnormal data, and abnormal interpretation analysis is performed on the abnormal data to obtain an abnormal interpretation result, effectively improving the accuracy and comprehensibility of the abnormal analysis of the target business system. It is beneficial for subsequent output processing of the abnormal data and the abnormal interpretation result, which can help relevant personnel understand the cause and background of the abnormality occurrence in the target business system, as well as the impact degree of the abnormality on the target business system, and can assist relevant personnel in quickly locating and solving the abnormal problems existing in the target business system, thereby improving the stability and security of the target business system.

[0236] The present application also provides another implementation manner, that is, to provide a computer-readable storage medium storing computer-readable instructions, and the computer-readable instructions can be executed by at least one processor to enable the at least one processor to execute the steps of the abnormal analysis method based on artificial intelligence as described above.

[0237] Compared with the prior art, the embodiments of the present application mainly have the following beneficial effects:

[0238] In the embodiments of the present application, the obtained operation data of the target business system is preprocessed based on the use of a processing strategy to obtain target operation data, effectively ensuring the accuracy of the data input of the anomaly analysis model. Furthermore, based on the use of the anomaly analysis model, the target operation data is analyzed for anomalies to obtain anomaly data, and the anomaly data is analyzed for anomaly interpretation to obtain an anomaly interpretation result, effectively improving the accuracy and comprehensibility of the anomaly analysis of the target business system. It is beneficial for subsequent output processing of the anomaly data and the anomaly interpretation result, which can help relevant personnel understand the cause and background of the anomalies occurring in the target business system, as well as the impact degree of the anomalies on the target business system, and can assist relevant personnel in quickly locating and solving the anomaly problems existing in the target business system, thereby improving the stability and security of the target business system.

[0239] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal device (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in the various embodiments of the present application.

[0240] Obviously, the above-described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The accompanying drawings show the preferred embodiments of the present application, but do not limit the patent scope of the present application. The present application can be implemented in many different forms. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosed content of the present application more thorough and comprehensive. Although the present application has been described in detail with reference to the foregoing embodiments, for those skilled in the art, they can still modify the technical solutions described in the foregoing specific embodiments, or perform equivalent replacements for some of the technical features. Any equivalent structure directly or indirectly using the content of the specification and drawings of the present application in other related technical fields is similarly within the scope of the patent protection of the present application.

Claims

1. An abnormality analysis method based on artificial intelligence, characterized in that: The steps include: Obtain the operating data of the target business system; Preprocessing the operation data based on a preset processing strategy to obtain corresponding target operation data; Call the preset abnormal analysis model; Performing an abnormality analysis on the target operation data based on the abnormality analysis model to obtain corresponding abnormal data; Performing abnormal interpretation analysis on the abnormal data to obtain corresponding abnormal interpretation results; The abnormal data and the abnormal interpretation result are outputted.

2. The artificial intelligence-based abnormality analysis method according to claim 1, characterized in that: Before the step of calling the preset abnormality analysis model, the method further includes: Acquire pre-constructed historical behavior sample data; wherein the historical behavior sample data includes normal behavior data and abnormal behavior data; Dividing the historical behavior sample data into a training data set and a test data set; Call the preset interpretable model; Training the interpretable model based on the training data set to obtain a corresponding first model; Optimizing the first model based on the test data set to obtain a second model that meets preset performance requirements; The second model is used as the abnormality analysis model.

3. The artificial intelligence-based abnormality analysis method according to claim 2, characterized in that: The step of optimizing the first model based on the test data set to obtain a second model that meets the preset performance requirements specifically includes: Evaluate the performance of the first model on the test data set based on a preset performance evaluation strategy to obtain corresponding first evaluation index data; Determine whether the first evaluation index data is greater than a preset index threshold; If not, optimizing the first model based on a preset optimization strategy to obtain an optimized third model; Evaluate the performance of the third model on the test data set to obtain corresponding second evaluation index data; Determine whether the second evaluation index data is greater than the index threshold; If so, use the third model as the second model.

4. The artificial intelligence-based abnormality analysis method according to claim 1, characterized in that: The step of preprocessing the operation data based on a preset processing strategy to obtain corresponding target operation data specifically includes: Cleaning the operation data to obtain corresponding first operation data; Performing data conversion processing on the first operating data to obtain corresponding second operating data; normalizing the second operating data to obtain corresponding third operating data; The third operating data is used as the target operating data.

5. The artificial intelligence-based abnormality analysis method according to claim 1, characterized in that: The step of performing abnormal interpretation analysis on the abnormal data to obtain a corresponding abnormal interpretation result specifically includes: Extracting a decision path where the abnormal data is defined as an abnormal type based on the abnormal analysis model; generating corresponding explanation data based on the decision path; The interpretation data is used as the abnormal interpretation result.

6. The artificial intelligence-based abnormality analysis method according to claim 1, characterized in that: The step of outputting the abnormal data and the abnormal interpretation result specifically includes: Call the preset exception report template; Filling the abnormal data and the abnormal interpretation result into the abnormal report template to obtain a corresponding abnormal report; Convert the exception report based on a preset conversion tool to obtain a corresponding exception report document; The target abnormality report is outputted.

7. The artificial intelligence-based abnormality analysis method according to claim 1, characterized in that: After the step of performing abnormal interpretation analysis on the abnormal data to obtain a corresponding abnormal interpretation result, the method further includes: Acquiring characteristic data of the abnormal data; Acquire the system architecture of the target business system; Based on the feature data and the system architecture, identifying a target component related to the abnormal data; Perform fault location processing based on the abnormal interpretation result and the target component to obtain a corresponding fault point location result; Generate a corresponding repair process suggestion based on the fault point location result; Send the repair process suggestions to relevant personnel.

8. An abnormality analysis device based on artificial intelligence, characterized in that: include: The first acquisition module is used to acquire the operation data of the target business system; A preprocessing module, used to preprocess the operation data based on a preset processing strategy to obtain corresponding target operation data; A first calling module is used to call a preset abnormality analysis model; A first analysis module, configured to perform an abnormality analysis on the target operation data based on the abnormality analysis model to obtain corresponding abnormal data; A second analysis module is used to perform an abnormal interpretation analysis on the abnormal data to obtain a corresponding abnormal interpretation result; The output module is used to output the abnormal data and the abnormal interpretation result.

9. A computer device, characterized in that: It comprises a memory and a processor, wherein the memory stores computer-readable instructions, and when the processor executes the computer-readable instructions, the steps of the artificial intelligence-based anomaly analysis method as described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps of the artificial intelligence-based anomaly analysis method as described in any one of claims 1 to 7 are implemented.