Object-oriented event log anomaly detection method and system

By using neural network models of graph convolution, long and short-term memory networks and bidirectional gated recurrent units in object-oriented event logs, the problem of difficult extraction of implicit relationships and timing correlation information between events is solved, and a more comprehensive abnormality detection of event logs is achieved.

CN120234752AActive Publication Date: 2025-07-01HANGZHOU DIANZI UNIV +1

Patent Information

Application Number
CN202510729554.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-07-01
Estimated Expiration
2045-06-03

AI Technical Summary

Technical Problem

In object-oriented event logs, it is difficult to obtain implicit relationships and timing association information between events, resulting in the existing exception detection model ignoring key timing characteristics when capturing topological associations between objects.

Method used

The neural network model based on graph convolution, long-term short-term memory network and bidirectional gating recurrent unit is adopted. The attribute dependence relationship between objects is extracted through the graph convolution module, the long-term short-term memory network module extracts long-term timing information, and the bidirectional gating recurrent unit module extracts the event dependence relationship before and after, and finally generates log reconstruction features through the full connection layer to determine event exceptions.

Benefits of technology

Taking into account both the graph structure and time characteristics, it can identify abnormal patterns in different situations, provide a more comprehensive abnormal detection scheme, and accurately predict abnormal events in the event log.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120234752A_ABST
    Figure CN120234752A_ABST
Patent Text Reader

Abstract

The invention discloses an object-oriented event log anomaly detection method and system. According to the method, an object-oriented event log anomaly detection model based on a graph convolution self-encoding module, a long-short-term memory network and a bidirectional gating loop unit is designed, and the graph convolution self-encoding module extracts a dependency relationship of object attributes between events in an event log with an object as a center; the long-short-term memory network extracts long-term time sequence information in the object-oriented event log, the bidirectional gating circulation unit extracts the dependency relationship of the front and back events in the object-oriented event log, and finally the outputs of the three modules are fused to obtain an event exception score. According to the method, event-level anomaly detection can be carried out on the object-oriented event log, and the accuracy is high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of event log anomaly detection, and particularly to an object-oriented event log anomaly detection method based on graph convolution, long short-term memory network, and bidirectional gated recurrent unit. Background Art

[0002] In the era of rapid development of information technology, enterprises widely use process-aware information systems (PAIS) to handle enterprise processes. In business process management, due to the complexity of application scenarios, there are often anomalies, such as operator transactions or program failures. Business process anomalies are behaviors that conflict with normal process data and violate process execution constraints. Business process anomalies can cause economic losses to enterprises or organizations due to the uncertainty of their results. Anomaly detection technology is to detect situations that violate process constraints in event logs, so as to handle abnormal event logs accordingly. Object-oriented event logs refer to event logs with multiple case identifiers, and we call these case identifiers objects. Therefore, events in such logs can reference any number of objects. In contrast to object-oriented event logs is the "flat" event log, that is, the log commonly processed by process-aware information systems, where events are represented by a single case identifier.

[0003] Currently, the main challenges faced in anomaly detection for object-oriented event logs are as follows:

[0004] The first challenge is how to obtain the implicit relationships between events in object-oriented event logs. In a standard event log (SEL), a trace can be extracted based on whether there are the same cases, and all events in this trace form a process instance. However, in object-oriented event logs, there is no such concept as a case. Instead, there are object types and object instances, which makes the boundaries of process instances become blurred. The association between events is no longer bound by explicit case IDs, but is implicit in the interaction network and attribute dependencies of object instances. Mining the implicit relationships between different events is crucial for improving the anomaly detection ability of the model.

[0005] The second challenge is how to extract temporal association information from object-oriented event logs. During the anomaly detection process, timestamp errors (such as reversed event order, time window conflicts) are one of the typical anomaly types (for example, the order shipping event is earlier than the payment event). However, the multi-object correlation of object-oriented event logs makes it particularly difficult to extract temporal associations. Currently existing anomaly detection models based on graph structures or feature engineering can capture the topological associations between objects, but generally ignore the extraction and utilization of key temporal features. Summary of the Invention

[0006] The object of the present invention is to overcome the deficiencies of the above-mentioned prior art and provide an object-oriented event log anomaly detection method and system.

[0007] The specific technical solution adopted by the present invention is as follows:

[0008] In a first aspect, the present invention provides an object-oriented event log anomaly detection method, which includes:

[0009] S1. Obtain the object-oriented event log to be detected, perform data cleaning and attribute field standardization processing on the event log, and obtain a target event log in which each row represents only one event and each column represents only one independent attribute;

[0010] S2. Extract all objects from the target event log, organize all events associated with each object into an initial event sequence according to the chronological order of the event timestamps, and then merge all initial event sequences with common events into subgraphs with the common events as connection nodes, so as to convert the target event log into a series of process instances in the form of subgraphs;

[0011] S3. Input the target event log and all the converted process instances into an event log anomaly detection model, and perform predictions respectively by three prediction branches of a graph convolution module, a long short-term memory network module, and a bidirectional gated recurrent unit module; wherein the graph convolution module takes the subgraph set of all process instances as input, and obtains the first log feature through graph convolution autoencoding and graph convolution decoding; the long short-term memory network module takes the initial log feature encoded from the target event log as input, fuses the output features of all time steps through an attention mechanism, and then splices them with the output feature of the last time step to obtain the second log feature; the bidirectional gated recurrent unit module takes the initial log feature encoded from the target event log as input, and splices the output features of all forward time steps and backward time steps to obtain the third log feature; finally, the log features output by the three prediction branches are spliced and passed through a fully connected layer to obtain a log reconstruction feature, and the feature error of each event in the log reconstruction feature and the initial log feature is used as the anomaly score of the event, so as to determine whether the event is abnormal.

[0012] As a preference of the first aspect, the event log anomaly detection model needs to be pre-trained using an event log data set with labels, and the event log data set used for training is obtained by injecting abnormal events into a normal target event log, and the types of injected abnormal events include attribute exchange, timestamp error, and random activities.

[0013] Preferably, as the first aspect, the graph convolution module is formed by cascading a graph convolution autoencoder module and a graph convolution decoder module. The graph convolution autoencoder module uses two layers of graph convolution layers to perform graph convolution encoding on the node feature matrix of the complete graph composed of the subgraph set to obtain the global feature of the graph structure. The graph convolution decoder module uses a single layer of graph convolution layer to decode the global feature of the graph structure and obtain the first log feature with the same dimension as the initial log feature.

[0014] Preferably, as the first aspect, in the long short-term memory network module, the output features of all time steps need to be concatenated and then passed through a fully connected layer with a tanh activation function to calculate the attention weight of each time step. Then, the attention weight is normalized by the Softmax function, and the output features of all time steps are weighted and fused according to the normalized weight. The obtained fused feature is reduced in dimension by a fully connected layer and then concatenated with the output feature of the last time step to obtain the second log feature with the same dimension as the initial log feature.

[0015] Preferably, as the first aspect, the feature error, which is the abnormal score of each event, adopts the mean square error between the feature vector corresponding to the event in the log reconstruction feature and the feature vector corresponding to the event in the initial log feature.

[0016] Preferably, as the first aspect, when judging whether an event is abnormal based on the abnormal score, the threshold method is used for judgment.

[0017] In the second aspect, the present invention provides an object-oriented event log anomaly detection system, which includes:

[0018] A log preprocessing module, configured to obtain the object-oriented event log to be detected, and perform data cleaning and attribute field standardization processing on the event log to obtain a target event log in which each row represents only one event and each column represents only one independent attribute;

[0019] A process instance conversion module, configured to extract all objects from the target event log, organize all events associated with each object into an initial event sequence according to the event timestamp sequence, and then merge all initial event sequences with common events into subgraphs with the common events as connection nodes, so as to convert the target event log into a series of process instances in the form of subgraphs;

[0020] The log anomaly detection module is used to input the target event log and all the converted process instance input event log anomaly detection models, and the three prediction branches of the graph convolution module, the long short-term memory network module, and the bidirectional gated recurrent unit module respectively perform predictions. Among them, the graph convolution module takes the subgraph set of all process instances as input, and obtains the first log feature through graph convolution autoencoding and graph convolution decoding. The long short-term memory network module takes the initial log feature encoded from the target event log as input, fuses the output features of all time steps through the attention mechanism, and then concatenates them with the output feature of the last time step to obtain the second log feature. The bidirectional gated recurrent unit module takes the initial log feature encoded from the target event log as input, and concatenates the output features of all forward time steps and backward time steps to obtain the third log feature. Finally, the log features output by the three prediction branches are concatenated and passed through a fully connected layer to obtain the log reconstruction feature. The feature error of each event in the log reconstruction feature and the initial log feature is used as the anomaly score of the event, and then it is determined whether the event is abnormal.

[0021] In a third aspect, the present invention provides a computer program product, including a computer program / instructions, which when executed by a processor, can implement the object-oriented event log anomaly detection method described in any one of the above first aspects.

[0022] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the object-oriented event log anomaly detection method described in any one of the above first aspects is implemented.

[0023] In a fifth aspect, the present invention provides a computer electronic device, which includes a memory and a processor;

[0024] The memory is used to store a computer program;

[0025] The processor is used to implement the object-oriented event log anomaly detection method described in any one of the above first aspects when executing the computer program.

[0026] Compared with the prior art, the present invention has the following beneficial effects:

[0027] The present invention provides an object-oriented event log anomaly detection method. The designed neural network model can extract the dependency relationship of object attributes between events in the object-centered event log based on the object-centered event log, extract the long-term temporal information in the object-oriented event log using a long short-term memory network, and extract the dependency relationship between the front and back events in the object-oriented event log using a bidirectional gated recurrent unit. Finally, the outputs of the three modules are fused to obtain an event anomaly score. In practical applications, the present invention can automatically set a threshold using the quartile method to accurately predict which events in the event log are abnormal. Considering both the graph structure and time characteristics, the present invention can identify abnormal patterns in different scenarios and provide a more comprehensive anomaly detection solution for the object-centered event log. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 is a flowchart of the steps of the object-oriented event log anomaly detection method;

[0029] Figure 2 is a schematic diagram of converting an initial event sequence into a series of process instance subgraphs;

[0030] Figure 3 is a schematic diagram of the model structure of the event log anomaly detection model;

[0031] Figure 4 is a schematic diagram of the module composition of the object-oriented event log anomaly detection system;

[0032] Figure 5 is a schematic diagram of the structure of a computer electronic device. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0033] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following detailed description of the specific embodiments of the present invention will be given with reference to the accompanying drawings. Many specific details are set forth in the following description to fully understand the present invention. However, the present invention can be implemented in many different ways other than those described herein. Those skilled in the art can make similar improvements without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below. The technical features in the various embodiments of the present invention can be combined accordingly without conflict.

[0034] As Figure 1 shown, in a preferred embodiment of the present invention, the above object-oriented event log anomaly detection method specifically includes steps S1 to S3. The following is a detailed description of the specific implementation methods of each step.

[0035] S1. Obtain the object-oriented event log to be detected, perform data cleaning and standardization processing on the event log to obtain a target event log where each row represents only one event and each column represents only one independent attribute.

[0036] It should be noted that the object-oriented event log in the present invention, namely the Object-Centric Event Log (OCEL), is a standard for storing object-centric event logs, which is mainly used to capture the detailed interaction patterns between different process entities. The OCEL log is an event log with multiple case identifiers, which can be called objects. Any number of objects can be referenced in the events in this type of log. The attributes of each event in the OCEL log include two categories: object type attributes and non-object type attributes.

[0037] The originally obtained OCEL log needs to be preprocessed to form a standardized log. In the embodiments of the present invention, the specific process of preprocessing the OCEL log is as follows: Add a unique event id attribute to each event row, and at the same time clean the log to discard some duplicate and unnecessary attributes; for the splittable attributes of each event (that is, a field containing multiple independent attributes in one attribute field), split them according to the attribute strings of each cell according to special identifiers, so that each column represents only one independent attribute, which is convenient for one-hot encoding. The object attributes of each event in the original attributes remain unchanged. In addition, normalization processing needs to be performed on numerical attributes. In the finally obtained target event log, each row represents only one event, and each column represents only one independent attribute.

[0038] S2. Extract all objects from the target event log obtained in S1. All events associated with each object are organized into an initial event sequence according to the chronological order of the event timestamps, and then all initial event sequences with common events are merged into subgraphs with the common events as connection nodes, so as to convert the target event log into a series of process instances in the form of subgraphs.

[0039] Due to the characteristics of the OCEL log, it is impossible to obtain the association between events by displaying the case ID. Therefore, the present invention needs to convert the object-centric log into one or more process instances. By extracting process instances, discrete multi-object events can be converted into subgraphs with topological structures, forming a graph structure containing object attribute dependencies and event associations. Such a structured representation can provide an effective input form for the graph neural network, enabling the model to capture the associations between events simultaneously.

[0040] In the embodiments of the present invention, a fragment of the OCEL log with abnormal events is shown in Table 1, where the abnormal attributes are indicated by bold and underlined.

[0041] Table 1 OCEL Fragment with Exceptions

[0042]

[0043] For the OCEL log shown in Table 1, all objects can be extracted from it, that is, all resources, customers, and pizzas in the three attribute fields of resources, customers, and pizza numbers are extracted. Each object is associated with a time at different timestamps in the log. Therefore, all events associated with each object are organized into an initial event sequence in the order of the event timestamps. As Figure 2 shown, using to represent an event set mapping function that maps objects to event sets, a series of different initial event sequences can be extracted from the log in Table 1. Add these initial event sequences to the processing queue, and use the breadth-first search mechanism to process the event sequences in the queue, scan for common events in the event sequences (i.e., events that appear in multiple initial event sequences), and merge all initial event sequences with common events into subgraphs with the common events as connection nodes, thereby converting the target event log into a series of process instances in the form of subgraphs. For example, Figure 2 the process instance in is synthesized from a series of event sequence queues, and its generation process is shown as follows:

[0044]

[0045] where events and serve as 's connection events. Because appears in multiple event sequences. Similarly can also serve as a connection event. Therefore, the event sequences of the three pizza objects will be automatically merged to form a process instance containing 8 events. Similarly, in the example shown in Figure 2 , the extracted process instance is not just , and according to the connection event , it can form . Some process instances contain only one event, such as , . These process instances that contain only one event are usually related to exceptions.

[0046] Thus, the present invention can convert the OCEL log into a set of process instances , respectively represent the process instances in the set of process instances, and the specific value of depends on the actual log situation.

[0047] S3. Input the target event log and all the converted process instances into an event log anomaly detection model to determine whether the events in the target event log are abnormal.

[0048] As Figure 3 shown, the specific model structure of the event log anomaly detection model is presented. This model is predicted by three prediction branches: a graph convolutional module, a long short-term memory network module, and a bidirectional gated recurrent unit module. Among them, the graph convolutional module takes the subgraph set of all process instances as input and obtains the first log feature through graph convolutional autoencoding and graph convolutional decoding. The long short-term memory network module takes the initial log feature encoded from the target event log as input. After fusing the output features of all time steps through an attention mechanism, it is concatenated with the output feature of the last time step to obtain the second log feature. The bidirectional gated recurrent unit module takes the initial log feature encoded from the target event log as input and concatenates the output features of all forward time steps and backward time steps to obtain the third log feature. Finally, the log features output by the three prediction branches are concatenated and passed through a fully connected layer to obtain a log reconstruction feature. The feature error of each event in the log reconstruction feature and the initial log feature is used as the anomaly score of the event, thereby determining whether the event is abnormal.

[0049] In an embodiment of the present invention, the graph convolutional module is composed of a graph convolutional autoencoding module and a graph convolutional decoding module connected in series. The graph convolutional autoencoding module uses layers of graph convolutional (GCN) layers to perform graph convolutional encoding on the node feature matrix of the complete graph formed by the subgraph set, obtaining the global feature of the graph structure. The graph convolutional decoding module uses layers of graph convolutional (GCN) layers to decode the global feature of the graph structure and obtain the first log feature with the same dimension as the initial log feature.

[0050] It should be noted that the input of the above graph convolutional module is the subgraph set composed of all subgraphs, that is, the subgraphs of the process instances are formed into a complete graph for input. The graph adjacency matrix corresponding to this complete graph is denoted as , and the node feature matrix is denoted as , where E is the total number of events, and W is the total dimension of the encoded features of all attributes of each event. The element in the i-th row and j-th column of the graph adjacency matrix is represented as , representing the edge connection situation between any node and node . Its expression is:

[0051]

[0052] Meanwhile, the node feature matrix It is composed of the node features of each event node, and the node features of each event node are obtained by combining the encoded features of all attributes of the corresponding event. Different attributes need to use different encodings. For example, after the normalization processing of numerical attributes, the normalized values can be directly used as features, and one-hot encoding can be used for categorical attributes. The specific encoding method belongs to the conventional technology of feature engineering and will not be elaborated here.

[0053] In the graph convolutional autoencoder module, according to the obtained graph adjacency matrix and the node feature matrix perform a total of layers of GCN calculations through the graph convolutional network, and output the final graph convolutional encoding result . The graph convolutional process of the th layer in the graph convolutional network is expressed as follows:

[0054]

[0055] where is the degree matrix of the graph adjacency matrix , is the trainable parameter matrix, is the output of the th graph convolutional layer, where uses the aforementioned node feature matrix , represents the ReLU activation function.

[0056] In the embodiments of the present invention, 2 to 4 layers of GCN are used to learn the latent representation of the input graph, that is , preferably 3.

[0057] The operation of the graph convolutional decoding stage is similar to the above graph convolutional encoding stage, except that the input of the graph convolutional decoding stage is the output of the graph convolutional encoding stage. Graph convolutional decoding is to map the embedded representation of the nodes back to the original input space. A total of layers of graph convolutional layer calculations are performed in the graph convolutional decoding module, and the output result of the final graph convolutional module is output. In the embodiments of the present invention, 1 to 4 layers of GCN are used to reconstruct the output in the decoding stage, that is , preferably 1. The output result is the aforementioned first log feature with the same dimension as the initial log feature, .

[0058] In the event log anomaly detection model, the graph convolution module can effectively capture the spatial correlation information between implicit relationships, but it ignores the temporal dependencies of the overall event log. For example, two events have no spatial correlation in the implicit relationship, but in the overall event log, there is temporal correlation information between the two. If only relying on the graph structure (or the association between nodes) to identify anomalies, some temporal dynamic features may be lost. Therefore, the present invention introduces a temporal enhancement module composed of a long short-term memory network (LSTM) module and a bidirectional gated recurrent unit (BiGRU) module to help the model mine important temporal information and thus accurately reconstruct the event log.

[0059] In the long short-term memory network module of the present invention, the long short-term memory network is used to implement. The LSTM network itself belongs to the prior art. This network can retain context information in a long sequence, overcome the problem of gradient disappearance or explosion that traditional RNNs are prone to, and can be used to extract long-term temporal information in object-oriented event logs. The neuron formula in the long short-term memory network is as follows:

[0060]

[0061]

[0062]

[0063]

[0064]

[0065]

[0066] where the weight parameter offset value represent the learning parameters and bias terms in each threshold respectively, represents the sigmoid function. Inside the neuron, the cell state is updated jointly by the forget gate and the output gate where the forget gate is used to control the information that needs to be forgotten, while the output gate controls and the information that will be added. In addition, the output gate integrates and as well as the updated three signals to output the hidden state at the current time step. Finally, the cell state at the current time step and the hidden state will be output to the next neuron for information transmission.

[0067] In the long short-term memory network module of the present invention, its input is the initial log feature obtained by encoding the above-mentioned target event log , and this initial log feature is composed of all attributes encoded at each time in the target event log, and it is actually equivalent to the aforementioned node feature matrix . The LSTM network is calculated by time steps, and the hidden layer features representing context information will be output at each time step. In the present invention, the output features of all time steps can be concatenated to obtain the complete output feature :

[0068]

[0069] In the formula: respectively represent the output features of different time steps, represents the output feature of the last time step T.

[0070] Next, the above output feature calculates the attention weight of each time step through a fully connected layer with a tanh activation function, and then normalizes the attention weight through the Softmax function and uses it to weight and fuse the output features of all time steps to obtain a fused feature representing temporal context information:

[0071]

[0072] In the formula: is the output feature of the i-th time step corresponding normalized attention weight.

[0073] Thus, through the above global attention mechanism to fuse different times, the information of key time steps can be highlighted, and the obtained fused feature is concatenated with the output feature of the last time step of the LSTM to obtain the output feature of the module:

[0074]

[0075] This output feature is the second log feature with the same dimension as the above initial log feature, .

[0076] In addition, in the temporal enhancement module, besides the LSTM, a BiGRU module is introduced to extract forward and backward temporal information. LSTM can generally capture the long-term dependencies of data, but for the order of events before and after and the possible bidirectional context information, LSTM or ordinary gated recurrent units still have limitations. Therefore, based on the unidirectional GRU, the BiGRU of the present invention adds a backpropagation branch, enabling each event to simultaneously perceive the context information of its neighboring events before and after, enhancing the ability to capture sequence dependencies. The input of the BiGRU module is also the initial log features obtained by encoding the above-mentioned target event logs. Initial log features After being input into the BiGRU module, information can be gradually learned from both forward and backward time steps simultaneously. For each time step, the forward gated recurrent unit generates a forward hidden state , and the backward gated recurrent unit generates a backward hidden state . These hidden states can form the output features of each time step . By concatenating and combining the output features of each time step , the output features of the BiGRU module can be obtained . This output feature is the third log feature with the same dimension as the above-mentioned initial log features .

[0077] Thus, through the above three branches, their respective log features can be output respectively. By concatenating the first log feature output by the graph convolution module, the second log feature output by the long short-term memory network module, and the third log feature of the bidirectional gated recurrent unit module, and then reducing the dimension through a fully connected layer, a log reconstruction feature with the same dimension as the above-mentioned initial log features is obtained :

[0078] ,

[0079] where represents the activation function, and represent the learnable parameter matrix and bias term in the fully connected layer.

[0080] When the above log reconstruction feature is obtained, since the remaining initial log features have the same dimension, all being , each event in the log reconstruction feature and the initial log features There is a corresponding eigenvector. For each event, calculating the eigenvector error of these two eigenvectors can be used as the anomaly score of the event, and then determine whether the event is abnormal. For any i-th event, if its eigenvectors corresponding to the log reconstruction feature and the initial log feature are respectively and , then the calculation formula of its eigenvector error is:

[0081]

[0082] In the formula: and are respectively the j-th dimension of and .

[0083] Finally, in practical applications, it is possible to judge whether an event is abnormal based on the anomaly score , and the specific judgment method can adopt the threshold method for judgment. This threshold can be optimized according to the actual data situation.

[0084] In the embodiments of the present invention, it is recommended to use the interquartile range method (IQR) to determine the threshold of the anomaly label so as to achieve the purpose of identifying outliers. The interquartile range method is a statistical indicator, which represents the range of the middle 50% of the values in the dataset, that is, the difference between the third quartile and the first quartile , and the calculation process is as follows:

[0085]

[0086]

[0087] In the formula: k is a hyperparameter, which is set according to convention .

[0088] Thus, after setting the threshold , the present invention automatically marks the events in the event log as normal or abnormal according to whether the anomaly score is lower or higher than the threshold.

[0089] During actual detection, if the anomaly score of an event (i.e., its corresponding average reconstruction error) exceeds the above threshold, the event is marked as an anomaly; otherwise, it is determined to be normal. This process is regarded as a binary classification problem, and the threshold is the classification boundary. In actual business scenarios, the event log data volume is large and the distribution pattern may be complex. The IQR method can adaptively adapt to the distribution changes of data at different stages without having to assume in advance that the data is normally or uniformly distributed. For scenarios with large fluctuations (such as data during high-concurrency periods), the threshold will be raised accordingly; for scenarios with small fluctuations, the threshold will be lower, so as to keep the anomaly detection sensitivity within a reasonable range. Additionally, for certain scenarios that clearly require more stringent detection, the value can be appropriately adjusted to improve the detection sensitivity.

[0090] It should be noted that the methods described in S1 - S3 above are actually the processes during the model inference or actual application of the present invention. However, those skilled in the art should know that the above event log anomaly detection model needs to be pre-trained before application and then used for inference in actual business after meeting the corresponding performance requirements.

[0091] In the embodiments of the present invention, it is necessary to pre-train using an event log data set with labels, and the event log data set used for training is obtained by injecting anomaly events into normal target event logs. The types of injected anomaly events include attribute exchange, timestamp error, and random activities. Attribute exchange means replacing the attribute value of one event with that of another event. Given a candidate event , an event with the farthest Euclidean distance from this event can be selected as the exchange event, and then all the attributes on event are used to replace the attributes on event . Timestamp error is based on the timestamp information of all events in the event log. On the basis of the maximum and minimum values, respectively 5%, and then any timestamp outside this range is used to replace the timestamp information of the candidate event. Random activity means that the newly inserted activity type does not come from the original event log but is randomly generated, but other attributes are extracted from the original event log. After injecting different anomaly events into the normal target event log (i.e., the log without anomalies), labels can be set to mark whether the event is an anomaly. Finally, all labeled training samples form a training sample set.

[0092] In addition, when actually training the event log anomaly detection model, the loss function can be set as the mean of the feature errors of all times in the target event log, that is, the overall reconstruction error of the log, which is expressed by the formula:

[0093]

[0094] Thus, based on the above loss function, in each round of iterative training, according to the loss function of the event log anomaly detection model , use the backpropagation algorithm to calculate the gradient of the loss function with respect to the model parameters, and update all learnable parameters of the event log anomaly detection model according to the calculated gradient and the strategy of the optimizer. The model iteratively executes the above training process on the dataset until the maximum number of iterations is reached or the loss function has converged, and then the model training is considered completed.

[0095] It should be noted that the method steps shown in the above S1~S3 can essentially be implemented in the form of a computer program.

[0096] Thus, based on the same inventive concept, as Figure 4 shown, the present invention also provides an object-oriented event log anomaly detection system, which includes:

[0097] A log preprocessing module, configured to obtain an object-oriented event log to be detected, and perform data cleaning and attribute field standardization processing on the event log to obtain a target event log in which each row represents only one event and each column represents only one independent attribute;

[0098] A process instance conversion module, configured to extract all objects from the target event log, organize all events associated with each object into an initial event sequence according to the chronological order of event timestamps, and then merge all initial event sequences with common events into subgraphs with common events as connection nodes, so as to convert the target event log into a series of process instances in the form of subgraphs;

[0099] A log anomaly detection module, configured to input the target event log and all converted process instances into an event log anomaly detection model, and perform predictions respectively by three prediction branches of a graph convolution module, a long short-term memory network module, and a bidirectional gated recurrent unit module; wherein the graph convolution module takes the subgraph set of all process instances as input, and obtains the first log feature through graph convolution autoencoding and graph convolution decoding; the long short-term memory network module takes the initial log feature encoded from the target event log as input, fuses the output features of all time steps through an attention mechanism, and then splices them with the output feature of the last time step to obtain the second log feature; the bidirectional gated recurrent unit module takes the initial log feature encoded from the target event log as input, and splices the output features of all forward time steps and backward time steps to obtain the third log feature; finally, the log features respectively output by the three prediction branches are spliced and then passed through a fully connected layer to obtain a log reconstruction feature, and the feature error of each event in the log reconstruction feature and the initial log feature is used as the anomaly score of the event, so as to determine whether the event is abnormal.

[0100] In addition, based on the same inventive concept, as Figure 5 shown, the present invention also provides a computer electronic device corresponding to an object-oriented event log anomaly detection method provided in the above embodiments, which includes a memory and a processor;

[0101] The memory is used to store a computer program;

[0102] The processor is used to implement the object-oriented event log anomaly detection method as described above when executing the computer program;

[0103] In addition, when the logical instructions in the above-mentioned memory are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention.

[0104] Thus, based on the same inventive concept, the present invention provides a computer-readable storage medium corresponding to an object-oriented event log anomaly detection method. A computer program is stored on the storage medium, and when the computer program is executed by a processor, it can implement the object-oriented event log anomaly detection method as described above.

[0105] Thus, based on the same inventive concept, the present invention provides a computer program product, including a computer program / instructions. When the computer program / instructions are executed by a processor, they can implement the object-oriented event log anomaly detection method as described above.

[0106] Specifically, in the computer-readable storage media of the above three embodiments, the stored computer program is executed by a processor, and the steps of S1~S3 can be executed.

[0107] It can be understood that the above storage medium may include a random access memory (Random Access Memory, RAM), and may also include a non-volatile memory (Non-Volatile Memory, NVM), such as at least one disk memory. At the same time, the storage medium may also be various media such as a USB flash drive, a mobile hard disk, a magnetic disk, or an optical disc that can store program codes.

[0108] It can be understood that the above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0109] In addition, it should be noted that those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working process of the above-described system can refer to the corresponding process in the foregoing method embodiments, and will not be elaborated herein. In the embodiments provided in the present application, the division of steps or modules in the system and method is only a logical function division, and there may be other division methods in actual implementation. For example, multiple modules or steps can be combined or integrated together, and a module or step can also be split.

[0110] To demonstrate the advantages of the object-oriented event log anomaly detection method shown in S1~S3 of the present invention above, it will be applied to a specific example below to demonstrate its technical effects.

[0111] Embodiment

[0112] The steps of this embodiment are as shown in S1~S3 above, and will not be elaborated herein. The following shows some implementation processes and implementation results:

[0113] This embodiment selects event logs from a public order management process. The order management process event logs contain more than 20,000 events from May 20, 2019 to August 25, 2020, recording a series of processes from customer order placement, order confirmation to product processing, packaging and shipping. Each event contains 3 object attributes, 2 numerical attributes and 2 split attributes. Model training and testing are carried out according to the method shown in S1~S2 of the present invention above.

[0114] For the convenience of description, the event log anomaly detection model trained by the method shown in S1~S3 of the present invention above is called Model. In this embodiment, the parameters of Model are selected as follows: the proportion of the number of abnormal events in the total number of events Take 0.1, the number of graph convolutional layers in the graph convolutional encoding stage Take 3, the number of graph convolutional layers in the graph convolutional decoding stage Take 1, the hyperparameter in the quartile method Take 1.5. During the model training process, the AdamW optimizer updates all trainable parameters of the neural network model, and the learning rate Take , the decay weight Take 0.00001.

[0115] The experiment in this embodiment compares the method of the present invention with several prediction methods. The prediction methods for comparison are: (1) AE: A neural network using an ordinary autoencoder model, applicable to ordinary event logs; (2) LSTMAE: An autoencoder model based on LSTM, applicable to ordinary event logs; (3) GCNAE: An autoencoder model based on GCN, applicable to object-oriented event logs; (4) WAKE: A neural network that uses a pre-trained autoencoder to extract trajectory feature representations and generates anomaly scores using a multi-layer perceptron-based anomaly score generator, applicable to ordinary event logs; (5) Model: An event log anomaly detection model trained using the method of the present invention.

[0116] Considering that several of the above anomaly detection methods are applicable to ordinary event logs, the order management process event logs in this embodiment are flattened. For the flattened ordinary event logs, anomaly detection methods applicable to ordinary event logs can be used for comparative experiments.

[0117] The experimental results of the method of the present invention and each pair of control methods on the dataset are shown in Table 2.

[0118] Table 2 Performance of all methods on the order management process event logs

[0119]

[0120] As shown in Table 2, as detection methods for object-centered event logs, the method of the present invention generally has better effects than GCNAE. This is because the event logs not only contain instance information composed of individual objects but also time series information of events. When the long short-term memory network module and the bidirectional gated recurrent unit module are added to the present invention, a significant improvement in the F1 score index for anomaly detection can be seen. And the WAKE method performs poorly on this dataset. The WAKE method is based on weak supervision, while the datasets of the present invention are all labeled as abnormal or not after preprocessing, so the adaptation of this method to the dataset is not high, resulting in poor results. It can be seen the effectiveness of the object-oriented event log anomaly detection method proposed by the present invention.

[0121] In addition, this embodiment also conducts ablation studies on a financial institution loan dataset (BPIC2017) and a sales process dataset (OM) to verify the effectiveness of the key structures in the model. The naming of each ablation variant experiment is as follows:

[0122] w / o GCN: The model Model does not include the graph convolution module, that is, only the long short-term memory network module LSTM and the bidirectional gated recurrent unit BiGRU are used to train the preprocessed event log.

[0123] w / o LSTM: The model Model does not include LSTM, that is, only BiGRU is used to train the preprocessed event log and the graph convolution module is used to train the graph-encoded data.

[0124] w / o BiGRU: The model Model does not include BiGRU, that is, only LSTM is used to train the preprocessed event log and the graph convolution module is used to train the graph-encoded data.

[0125] This embodiment conducts experiments on different ablation variants, and the performance on the two datasets is shown in Tables 3 and 4:

[0126] Table 3 Effects of ablation variants on the BPIC2017 dataset

[0127]

[0128] Table 4 Effects of ablation variants on the OM dataset

[0129]

[0130] Comparing different ablation variant experiments, it can be seen that the BiGRU module has the most significant improvement in the abnormal detection accuracy of the model. It enables the output of the model to contain the time pattern information from the original input (i.e., the temporal dependence relationship between front and back events). When the detection model of the present invention does not use BiGRU, the abnormal detection accuracy of the model drops significantly.

[0131] Comparing the model Model of the present invention with w / o LSTM, when only BiGRU is used to train the preprocessed event log and the graph convolution module is used to train the graph-encoded data, the various indicators of abnormal detection will decrease to a certain extent. This shows that the long-term temporal information extracted by the LSTM network has a certain positive impact on abnormal detection, but its importance is less than the temporal dependence relationship between front and back events extracted by BiGRU.

[0132] When comparing the model of the present invention with w / o GCN, that is, when only using LSTM and BiGRU to train the preprocessed event log, the anomaly detection result of w / o GCN also decreases. This phenomenon can be attributed to the lack of implicit relationships in OCEL, resulting in the lack of key structural information in the event log. In addition, the introduction of the graph convolutional layer improves the accuracy of the model output because it allows nodes to capture the overall information of the implicit relationships in the event log from its neighbor nodes.

[0133] The embodiments described above are only a preferred solution of the present invention, but they are not intended to limit the present invention. Those of ordinary skill in the relevant technical fields can still make various changes and modifications without departing from the spirit and scope of the present invention. Therefore, all technical solutions obtained by means of equivalent replacement or equivalent transformation fall within the protection scope of the present invention.

Claims

1. An object-oriented event log anomaly detection method, characterized in that, Including: S1. Obtain the object-oriented event log to be detected, perform data cleaning and attribute field standardization processing on the event log, and obtain a target event log in which each row represents only one event and each column represents only one independent attribute; S2. Extract all objects from the target event log. All events associated with each object are organized into an initial event sequence according to the chronological order of event timestamps, and then all initial event sequences with common events are merged into subgraphs with the common events as connection nodes, so as to convert the target event log into a series of process instances in the form of subgraphs; S3. Input the target event log and all converted process instances into the event log anomaly detection model, and perform predictions respectively by three prediction branches of the graph convolution module, the long short-term memory network module and the bidirectional gated recurrent unit module; Among them, the graph convolution module takes the subgraph set of all process instances as input, and obtains the first log feature through graph convolution autoencoding and graph convolution decoding; the long short-term memory network module takes the initial log feature encoded from the target event log as input, fuses the output features of all time steps through the attention mechanism, and then splices them with the output feature of the last time step to obtain the second log feature; the bidirectional gated recurrent unit module takes the initial log feature encoded from the target event log as input, and splices the output features of all forward time steps and backward time steps to obtain the third log feature; finally, the log features output by the three prediction branches are spliced and passed through a fully connected layer to obtain the log reconstruction feature, and the feature error of each event in the log reconstruction feature and the initial log feature is used as the anomaly score of the event, so as to determine whether the event is abnormal.

2. The object-oriented event log anomaly detection method according to claim 1, characterized in that, The event log anomaly detection model needs to be pre-trained using the event log data set with labels, and the event log data set used for training is obtained by injecting abnormal events into the normal target event log. The types of injected abnormal events include attribute exchange, timestamp error and random activities.

3. The object-oriented event log anomaly detection method according to claim 1, characterized in that, The graph convolution module is composed of a graph convolution autoencoding module and a graph convolution decoding module in cascade. The graph convolution autoencoding module uses two layers of graph convolution layers to perform graph convolution encoding on the node feature matrix of the complete graph composed of the subgraph set to obtain the global feature of the graph structure. The graph convolution decoding module uses a single layer of graph convolution layer to decode the global feature of the graph structure to obtain the first log feature with the same dimension as the initial log feature.

4. The object-oriented event log anomaly detection method according to claim 1, wherein In the long short-term memory network module, the output features of all time steps need to be spliced and then passed through a fully connected layer with a tanh activation function to calculate the attention weight of each time step, and then the attention weight is normalized through the Softmax function, and the output features of all time steps are weighted and fused according to the normalized weight. The obtained fusion feature is reduced in dimension through a fully connected layer and then spliced with the output feature of the last time step to obtain the second log feature with the same dimension as the initial log feature.

5. The object-oriented event log anomaly detection method according to claim 1, characterized in that, The feature error, which is the anomaly score for each event, is the mean square error between the feature vector corresponding to the event in the log reconstruction features and the feature vector corresponding to the event in the initial log features.

6. The object-oriented event log anomaly detection method according to claim 1, characterized in that When determining whether an event is abnormal based on the anomaly score, a threshold method is used for judgment.

7. An object-oriented event log anomaly detection system, characterized in that, It includes: A log preprocessing module, which is used to obtain the object-oriented event log to be detected, and perform data cleaning and attribute field standardization processing on the event log to obtain a target event log where each row represents only one event and each column represents only one independent attribute; A process instance conversion module, which is used to extract all objects from the target event log. All events associated with each object are organized into an initial event sequence according to the chronological order of the event timestamps, and then all initial event sequences with common events are merged into subgraphs with the common events as connection nodes, so as to convert the target event log into a series of process instances in the form of subgraphs; A log anomaly detection module, which is used to input the target event log and all converted process instances into an event log anomaly detection model, and perform predictions respectively by three prediction branches: a graph convolution module, a long short-term memory network module, and a bidirectional gated recurrent unit module; Among them, the graph convolution module takes the subgraph set of all process instances as input, and obtains the first log features through graph convolution autoencoding and graph convolution decoding; the long short-term memory network module takes the initial log features encoded from the target event log as input, fuses the output features of all time steps through an attention mechanism, and then concatenates them with the output features of the last time step to obtain the second log features; the bidirectional gated recurrent unit module takes the initial log features encoded from the target event log as input, and concatenates the output features of all forward time steps and backward time steps to obtain the third log features; finally, the log features output by the three prediction branches respectively are concatenated and passed through a fully connected layer to obtain log reconstruction features, and the feature error of each event in the log reconstruction features and the initial log features is used as the anomaly score of the event, so as to determine whether the event is abnormal.

8. A computer program product comprising computer programs / instructions, characterized in that, When the computer program / instructions are executed by a processor, the object-oriented event log anomaly detection method described in any one of claims 1 to 6 can be implemented.

9. A computer-readable storage medium, characterized in that, A computer program is stored on the storage medium, and when the computer program is executed by a processor, the object-oriented event log anomaly detection method described in any one of claims 1 to 6 is implemented.

10. A computer electronic device, characterized in that, It includes a memory and a processor; The memory is used to store a computer program; The processor is used to implement the object-oriented event log anomaly detection method described in any one of claims 1 to 6 when executing the computer program.

Citation Information

Patent Citations

  • Data anomaly detection method and device, storage medium and electronic equipment

    CN117056166A

  • Log anomaly detection method based on spatio-temporal feature fusion

    CN117992496A

  • Method and system for detecting anomaly of multi-dimensional time series data of wind driven generator

    CN118656756A

  • Network security event analysis processing method and system and readable storage medium

    CN118842661A

  • Log anomaly detection method based on hybrid expert network

    CN119127619A

Cited By

  • Low-code process anomaly detection method, device and equipment and readable storage medium

    CN120832262A