Abnormality monitoring method and electronic equipment

By obtaining multiple monitoring data of communication services, extracting data characteristics and assigning dynamic weights to each data in combination with environmental status parameters, the problem of limited accuracy of abnormal monitoring in real-time communication alarm systems is solved, and efficient abnormal detection in dynamic environments is achieved.

CN120281629APending Publication Date: 2025-07-08GUANGZHOU OVERSEAS KANGBAZI NETWORK TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510549413.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The existing real-time communication alarm system cannot adapt to dynamic environment changes, resulting in limited accuracy of abnormal monitoring, and false alarms or missed reports may occur, affecting the operation and maintenance efficiency and user experience of communication services.

Method used

By obtaining multiple monitoring data of communication services, extracting data characteristics, determining abnormal indicators, and assigning dynamic weights to each data in combination with environmental status parameters, calculating abnormal scores, and using preset dynamic thresholds for abnormal detection.

Benefits of technology

Improve the accuracy of abnormal monitoring, reduce false alarms and missed reports, and ensure that the system can identify abnormal situations in a timely and accurate manner in a dynamic environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281629A_ABST
    Figure CN120281629A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an abnormity monitoring method and electronic equipment, and the method comprises the steps: obtaining various types of monitoring data of communication service, and extracting the data features of each type of monitoring data; determining an abnormal index of each type of monitoring data based on the data features; determining the weight of each type of monitoring data according to the environment state parameter of each type of monitoring data; determining an abnormal score of the communication service according to the weight and the abnormal index; and determining an anomaly detection result of the communication service according to the anomaly score and a preset dynamic threshold. The method can adapt to the dynamic change of the environment, and improves the accuracy of abnormal monitoring of the communication service.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of real-time communication technology, involves anomaly monitoring technology, and particularly relates to an anomaly monitoring method and an electronic device. Background Art

[0002] Real-time communication (RTC) alarm systems usually make anomaly judgments based on multiple monitoring metrics. Among them, traditional systems rely on fixed processes and preset weights for processing these metrics. However, in the on-site environment of real-time communication, such as network conditions and device performance, often change, which will affect the importance and sensitivity of the metrics. Since the fixed processing process and weights cannot adapt to these dynamic changes, the accuracy of anomaly monitoring is limited, and false alarms or missed alarms of anomalies may occur, affecting the operation and maintenance efficiency of communication services and the user experience. Summary of the Invention

[0003] Embodiments of this application provide an anomaly monitoring method and an electronic device, which can solve the problem that existing anomaly monitoring technologies are difficult to adapt to dynamic environmental changes, resulting in low accuracy of anomaly monitoring.

[0004] In a first aspect of the embodiments of this application, an anomaly monitoring method is provided, including: obtaining multiple monitoring data of a communication service, and extracting data features of each monitoring data; based on the data features, determining anomaly metrics of each monitoring data; according to the environmental state parameters of each monitoring data, determining weights of each monitoring data; according to the weights and the anomaly metrics, determining an anomaly score of the communication service; according to the anomaly score and a preset dynamic threshold, determining an anomaly detection result of the communication service.

[0005] According to the embodiments of this application, the obtaining multiple monitoring data of a communication service and extracting data features of each monitoring data includes: based on a sliding window algorithm, determining the median and the absolute median difference of each monitoring data; according to the median and the absolute median difference, determining a normalized deviation factor of each monitoring data; according to the normalized deviation factor, determining the data features.

[0006] According to the embodiments of this application, the determining anomaly metrics of each monitoring data based on the data features includes: determining the anomaly metrics according to the data features, a preset smoothing factor, and an anomaly threshold.

[0007] According to the embodiments of this application, the determining weights of each monitoring data according to the environmental state parameters of each monitoring data includes: based on the environmental state parameters, determining a noise parameter of each monitoring data; according to the noise parameter and a preset adjustment parameter, determining the weights.

[0008] According to an embodiment of the present application, the method further includes: obtaining historical monitoring data of the communication service, and determining the preset adjustment parameter according to the historical monitoring data.

[0009] According to an embodiment of the present application, determining the anomaly score of the communication service according to the weight and the anomaly index includes: determining the anomaly score according to the weighted fusion result of the weight and the anomaly index.

[0010] According to an embodiment of the present application, the method further includes: determining the preset dynamic threshold according to the median and the absolute median difference of the anomaly scores within a preset time length.

[0011] According to an embodiment of the present application, determining the anomaly detection result of the communication service according to the anomaly score and the preset dynamic threshold includes: if the anomaly score is greater than the preset dynamic threshold, determining that the anomaly detection result is that there is an anomaly; or, if the anomaly score is less than or equal to the preset dynamic threshold, determining that the anomaly detection result is that there is no anomaly.

[0012] According to an embodiment of the present application, the multiple monitoring data includes the stuttering rate, the first-play delay, the loading failure rate, the packet loss rate, and the video frame rate when playing multimedia data.

[0013] A second aspect of the embodiments of the present application provides an anomaly monitoring device, including: an acquisition module, configured to acquire multiple monitoring data of a communication service and extract data features of each monitoring data; a determination module, configured to determine an anomaly index of each monitoring data based on the data features; determine a weight of each monitoring data according to the environmental state parameter of each monitoring data; determine an anomaly score of the communication service according to the weight and the anomaly index; and determine an anomaly detection result of the communication service according to the anomaly score and a preset dynamic threshold.

[0014] A third aspect of the embodiments of the present application provides an electronic device, including: a memory and a processor, where the processor executes computer-readable instructions stored in the memory to implement the anomaly monitoring method described above.

[0015] The anomaly monitoring method provided by the embodiments of the present application can adapt to dynamic changes in the environment and improve the accuracy of anomaly monitoring of communication services by acquiring multiple monitoring data of a communication service, extracting their data features, determining the anomaly index of each data, assigning dynamic weights to each data in combination with environmental state parameters, determining the anomaly score of the communication service according to the weights and anomaly indexes, and comparing with a preset dynamic threshold. Description of the Drawings

[0016] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0017] Figure 1 It is a schematic diagram of the application environment of an anomaly monitoring method provided by an embodiment of the present application.

[0018] Figure 2 It is a schematic flowchart of the anomaly monitoring method provided by an embodiment of the present application.

[0019] Figure 3 It is a schematic flowchart of the method for extracting data characteristics of each type of monitoring data provided by an embodiment of the present application.

[0020] Figure 4 It is a principle block diagram of an anomaly monitoring device provided by an embodiment of the present application. Detailed implementation manners

[0021] In order to make the purpose, technical solutions, and advantages of the present application clearer, the present application will be described in detail below in conjunction with the accompanying drawings and specific embodiments.

[0022] It should be noted that in the present application, "at least one" means one or more, and "a plurality" means two or more than two. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The terms "first", "second", "third", "fourth", etc. (if any) in the specification, claims, and drawings of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence.

[0023] In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or having more advantages than other embodiments or design solutions. Exactly, using words such as "exemplary" or "for example" is intended to present related concepts in a specific manner. Without conflict, the following embodiments and the features in the embodiments can be combined with each other.

[0024] With the rapid development of Internet of Things, big data, and real-time communication technologies, the demand for real-time alerts in industrial, security, and surveillance systems is increasing day by day. As a key means to achieve efficient real-time monitoring and alerting, multi-modal data fusion technology integrates data from different sensors and uses feature extraction and fusion algorithms to comprehensively describe the state of devices or communication environments, thereby realizing the detection and alerting of abnormal situations. However, the current multi-modal data fusion technology still faces a series of problems and limitations in practical applications.

[0025] Traditional real-time alert systems usually use fixed thresholds and preset weights for data fusion and anomaly judgment. However, in the actual application environment, the data of monitoring indicators such as frame drop rate, video first frame output time, loading failure rate, packet loss rate, and video frame rate are significantly affected by environmental factors, and their signal-to-noise ratio and numerical fluctuations have significant dynamics. The fixed weight strategy cannot be automatically adjusted to adapt to these changes, resulting in some modal data being underestimated or overestimated in certain environments, thus reducing the accuracy and real-time performance of alert judgment.

[0026] Secondly, the problem of noise interference in multi-modal data fusion is serious. In practical applications, the data of various monitoring indicators not only contain target signals but may also be accompanied by a large amount of environmental noise and occasional interference. Traditional fusion methods often cannot effectively distinguish noise from real anomaly information, resulting in the system being prone to false alarms or missed alarms. Especially in high-noise environments, the abnormal fluctuations of some indicators may be caused only by noise rather than actual faults, which directly affects the stable operation of the system and the reliability of alerts.

[0027] In addition, existing multi-modal alert systems usually lack an adaptive optimization mechanism based on environmental feedback. In existing multi-modal alert systems, the weight allocation of various monitoring indicators usually relies on historical statistics or expert experience, and fails to fully utilize the real-time environmental state as a feedback basis. Since the performance of different sensors varies significantly under different environmental conditions, the system urgently needs a mechanism that can dynamically adjust the weights of each modality according to real-time data distribution, signal-to-noise ratio, and environmental interference. However, the current systems generally lack this adaptive optimization mechanism, resulting in insufficient robustness and adaptability of the overall data fusion results.

[0028] In addition, the accuracy and timeliness of anomaly detection and alarm decision response in existing multimodal alarm systems need to be improved. For example, due to the lack of a dynamic adjustment mechanism for different environmental states, existing systems are often limited by overly simple statistical thresholds when judging anomalies. This results in the system either issuing alarms for short-term non-anomalous fluctuations (e.g., false alarms) or ignoring real anomalies (e.g., missed alarms). This limitation is particularly prominent in real-time communication alarm systems. Since the on-site environment of real-time communication (such as network conditions, device performance, etc.) often changes, the fixed processing flow and weights of traditional systems cannot adapt to these dynamic changes, thus limiting the accuracy of anomaly monitoring and affecting the operation and maintenance efficiency of communication services and the user experience.

[0029] Therefore, there are still many problems and limitations in the current multimodal data fusion technology in real-time alarm systems, resulting in limited accuracy of anomaly monitoring, possible false alarms or missed alarms of anomalies, and affecting the operation and maintenance efficiency of communication services and the user experience.

[0030] To solve the above problems, the anomaly monitoring method provided in the embodiments of the present application, by obtaining various monitoring data of communication services and extracting their data features, determines the anomaly indicators for each type of data, and at the same time assigns dynamic weights to each type of data in combination with environmental state parameters, determines the anomaly score of the communication service according to the weights and anomaly indicators, and compares it with a preset dynamic threshold, can adapt to dynamic environmental changes and improve the accuracy of anomaly monitoring of communication services.

[0031] Please refer to Figure 1 , which is a schematic diagram of the application environment of an anomaly monitoring method provided in an embodiment of the present application. As Figure 1 shown, the anomaly monitoring method provided in the embodiments of the present application can be applied to an electronic device 10, and the electronic device 10 can be a mobile phone, a tablet computer, a smart wearable device, an augmented reality (AR) / virtual reality (VR) device, a laptop computer, a netbook, an energy storage device, a power distribution device, and other electronic devices. The embodiments of the present application do not impose any restrictions on the specific type of the electronic device.

[0032] As Figure 1 shown, the electronic device 10 may include a communication module 101, a memory 102, a processor 103, an input / output (I / O) interface 104, and a bus 105. The processor 103 is respectively coupled to the communication module 101, the memory 102, and the I / O interface 104 through the bus 105.

[0033] The communication module 101 may include a wired communication module and / or a wireless communication module. The wired communication module may provide one or more of the solutions for wired communication such as universal serial bus (USB), Controller Area Network (CAN), etc. The wireless communication module may provide one or more of the solutions for wireless communication such as wireless fidelity (Wi-Fi), blue tooth (BT), mobile communication network, frequency modulation (FM), near field communication (NFC), infrared (IR), etc.

[0034] The memory 102 may include one or more random access memories (RAM) and one or more non-volatile memories (NVM). The random access memory can be directly read and written by the processor 103 and can be used to store the operating system or executable programs of other running programs (such as machine instructions), and can also be used to store user and application data, etc. The random access memory may include static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), etc.

[0035] The non-volatile memory can also store executable programs and store user and application data, etc., and can be pre-loaded into the random access memory for direct reading and writing by the processor 103. The non-volatile memory may include disk storage devices, flash memory.

[0036] The memory 102 is used to store one or more computer programs. The one or more computer programs are configured to be executed by the processor 103. The one or more computer programs include a plurality of instructions. When the plurality of instructions are executed by the processor 103, an exception monitoring method executable on the electronic device 10 can be implemented.

[0037] In other embodiments, the electronic device 10 further includes an external memory interface for connecting to an external memory to expand the storage capacity of the electronic device 10.

[0038] The processor 103 may include one or more processing units. For example, the processor 103 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated in one or more processors.

[0039] The processor 103 provides computing and control capabilities. For example, the processor 103 is used to execute the computer program stored in the memory 102 to implement the above-mentioned anomaly monitoring method.

[0040] The I / O interface 104 is used to provide channels for user input or output. For example, the I / O interface 104 can be used to connect various input and output devices, such as a mouse, a keyboard, a touch device, a display screen, etc., so that the user can input information or visualize information. In addition, the I / O interface 104 can also be used to connect various sensor devices, such as a radar sensor, an image sensor, etc., so as to obtain data such as required radar point cloud data and image data.

[0041] The bus 105 is at least used to provide a communication channel for mutual communication between the communication module 101, the memory 102, the processor 103, and the I / O interface 104 in the electronic device 10.

[0042] It can be understood that the structure schematically shown in the embodiments of the present application does not constitute a specific limitation on the electronic device 10. In other embodiments of the present application, the electronic device 10 may include more or fewer components than shown in the figure, or combine certain components, or split certain components, or have different component arrangements. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.

[0043] The following will take the computer program product that implements the anomaly monitoring method of the embodiments of the present application running on an electronic device (such as Figure 1 the electronic device 10 shown) as an example for description. Please refer to Figure 2As shown, it is a schematic flowchart of the anomaly monitoring method provided by an embodiment of the present application. In one embodiment of the present application, the following steps are included: Step S201: Obtain various monitoring data of the communication service and extract the data characteristics of each type of monitoring data.

[0044] In one embodiment of the present application, the communication service may include, but is not limited to, multimedia application services. For example, a service that provides online playback of multimedia data for users, and the multimedia data includes, but is not limited to, audio - video data composed of audio and video, etc.

[0045] In one embodiment of the present application, in order to comprehensively evaluate and optimize the quality of the communication service, various monitoring data of multiple users using the communication service (or multimedia application) in the same environment can be collected in real - time. For example, multiple users can be in different regions, use different devices (such as mobile phones, computers, etc.), and access the same communication service at different times. The electronic device can automatically collect and record the monitoring data of the communication service obtained from each user.

[0046] In one example, the various monitoring data includes, but is not limited to: the freezing rate, the first - play delay, the loading failure rate, the packet loss rate, the video frame rate, etc. when the multimedia data is being played. Among them, each type of monitoring data may include a corresponding data sequence. For example, each type of monitoring data may include multiple monitoring data obtained at multiple time points.

[0047] In one example, the freezing rate represents the ratio of the total pause time during a single playback of multimedia data to the total playback time. The freezing rate is inversely proportional to the smoothness of multimedia data playback, that is, the higher the freezing rate, the lower the playback smoothness. The freezing rate can be used to indicate the stability of the communication service and the data transmission efficiency, and is one of the important indicators for evaluating the user experience.

[0048] In one example, the first - play delay represents the time required from when the user initiates a play request to when the multimedia content starts to be presented to the user. The first - play delay directly affects the user's initial experience, and a shorter delay can significantly improve user satisfaction. The loading failure rate represents the proportion of failed loads when attempting to load multimedia content due to various reasons (such as network problems, slow server response, etc.). The loading failure rate can reflect the reliability and stability of the communication service.

[0049] In one example, during the data transmission process, due to reasons such as network congestion and signal attenuation, some data packets fail to reach the receiving end successfully. The proportion of these lost data packets in the total data packets is the packet loss rate. A high packet loss rate will cause the playback quality of multimedia data to decline, such as discontinuous pictures and distorted sounds.

[0050] In one example, the video frame rate represents the number of frames displayed per second and is an important parameter for measuring the smoothness of multimedia data playback. A high frame rate means smoother images and stronger expressiveness in dynamic scenes.

[0051] In one embodiment of the present application, after obtaining the monitoring data of multiple communication services, in order to ensure the accuracy and effectiveness of subsequent data analysis, these monitoring data can be preprocessed. For example, the preprocessing can include, but is not limited to, denoising, normalization, filtering, missing value processing, data alignment, and other operations.

[0052] In one example, a preset statistical method (such as median filtering, mean filtering) or a preset machine learning algorithm (such as isolation forest) can be used to implement denoising processing, so as to remove random errors or outliers that may be caused by equipment failures, network fluctuations, or improper user operations in the monitoring data.

[0053] In one example, a preset normalization method can be used to implement normalization processing. For example, the normalization method can include, but is not limited to, the minimum-maximum normalization method, the zero-mean normalization method, etc., so as to convert the monitoring data with different dimensions to the same scale, facilitating subsequent data comparison and analysis.

[0054] In one example, a preset filter can be used to implement filtering processing. For example, the filter can include, but is not limited to, a low-pass filter, a high-pass filter, or a band-pass filter, so as to smooth the monitoring data and remove the data noise therein.

[0055] In one example, a preset missing value processing method can be used to implement missing value processing. For example, the missing value processing method includes, but is not limited to: interpolation methods (such as linear interpolation, spline interpolation), mean or median filling methods, prediction filling based on machine learning models, and other methods. Missing value processing can fill in the missing values in the monitoring data and prevent analysis biases caused by incomplete data.

[0056] In one example, the monitoring data can be sorted and aligned according to the timestamps or event identifiers of the monitoring data, so as to ensure that the monitoring data from different sources or different time points can be correctly corresponded, facilitating subsequent time series analysis or cross-source data fusion.

[0057] Based on the above embodiments, by preprocessing the monitoring data of communication services, such as denoising, normalization, filtering, missing value processing, and data alignment, etc., random errors in the monitoring data can be eliminated, the scale of the monitoring data can be unified, data fluctuations can be smoothed, data gaps can be filled, and the timeliness and consistency of the monitoring data can be ensured, which can improve the accuracy of subsequent data analysis.

[0058] In one embodiment of the present application, when extracting data features of each monitoring data, the median (e.g., local median) and absolute median difference (e.g., median absolute deviation) of each monitoring data can be calculated by a sliding window method, and the data can be normalized to obtain a normalized deviation factor, and the normalized deviation factor can be used as a data feature. In this way, a normalized deviation factor that can represent the main characteristics and trends of the data can be extracted from the original monitoring data as a data feature. Data points with a large normalized deviation factor may indicate anomalies or the occurrence of abnormal situations. In one example, the method for extracting data features of each monitoring data can refer to Figure 3 Flowchart shown.

[0059] In one example, if Figure 3 As shown, the method for extracting data features of each monitoring data includes the following process.

[0060] S301, based on a sliding window algorithm, determining the median and the absolute median difference of each monitoring data.

[0061] In an embodiment of the present application, for the data sequence corresponding to each monitoring data collected by each user, the median (e.g., local median) and the absolute median difference (e.g., median absolute deviation) thereof may be calculated using a sliding window method, and the formula used may be exemplarily expressed as follows: , , in, ,express The i-th monitoring data among the monitoring data, It represents the value corresponding to time point t in the data sequence corresponding to the i-th monitoring data, and T represents the size of the sliding window. Indicates the calculation time point The local median of the values ​​at time point t, Represents the calculated local median.

[0062] Indicates the calculation of each data point in the sliding window and the local median The absolute deviation , and find the median of these deviations to get the median absolute deviation .

[0063] S302: Determine a normalized deviation factor for each type of monitoring data according to the median and the absolute median difference.

[0064] In an embodiment of the present application, the formula used to determine the normalized deviation factor can be exemplarily expressed as: , in, Represents the value corresponding to time point t in the data sequence corresponding to the i-th monitoring data, represents the median, represents the absolute median difference, Indicates a preset positive number, which is used to prevent the denominator from being 0. It can be set according to actual needs. Represents the normalized deviation factor, which is used to indicate the degree of deviation of the value at time point t of each monitoring data relative to the local median, and has been normalized to a scale related to the absolute deviation of the median. The larger the normalized deviation factor, the greater the deviation of the value at time point t from the local median.

[0065] S303: Determine the data feature according to the normalized deviation factor.

[0066] In one embodiment of the present application, a normalized deviation factor may be used as a data feature, which may indicate the distribution of the monitoring data and the degree of deviation of each data point of the monitoring data relative to the whole, thereby providing a basis for subsequent abnormality monitoring.

[0067] Based on the above embodiment, the local median and absolute median difference are first calculated for each monitoring data using a sliding window algorithm. Subsequently, a normalized deviation factor is further derived based on these statistics, which quantifies the degree of deviation of each data point relative to the local median and has been normalized to a scale related to the absolute deviation of the median. Ultimately, establishing the normalized deviation factor as a data feature can not only reveal the distribution characteristics of the monitoring data, but also intuitively display the deviation level of the data point relative to the overall data, laying the foundation for subsequent abnormal monitoring work.

[0068] Step S202: determining an abnormality indicator of each monitoring data based on the data characteristics.

[0069] In one embodiment of the present application, the abnormality index can be determined according to the data feature, the preset smoothing factor, and the abnormality threshold. The abnormality index can be used to indicate the degree of abnormality of a data point of the monitoring data. The value range of the abnormality index can be (0, 1). The larger the abnormality index, the higher the degree of abnormality of a data point in the monitoring data.

[0070] In one example, a preset abnormal index function can be used to calculate the abnormal index of each monitoring data. For example, the abnormal index function can include but is not limited to the Sigmoid function, so that the value of the abnormal index can be mapped to the interval (0,1). For example, the formula used to determine the abnormal index can be exemplarily expressed as: , in, Represents a data feature, such as a normalized deviation factor, used to indicate the degree of deviation of the value of the i-th type of monitoring data at time point t. Represents a preset smoothing factor that can be set according to actual needs. Represents a preset anomaly threshold that can be set according to actual needs, such as 1. Represents the anomaly index corresponding to the i-th type of monitoring data at time point t.

[0071] Based on the above embodiments, according to the data features of the monitoring data, combined with the preset smoothing factor and anomaly threshold, the anomaly index of each type of monitoring data at each time point can be determined. For example, this anomaly index is calculated using a preset anomaly index function such as the Sigmoid function, which can quantify the degree of anomaly as a value between 0 and 1, and the larger the value, the higher the degree of anomaly. Among them, the normalized deviation factor, as a data feature, reflects the degree of deviation of the monitoring data from a certain benchmark, while the smoothing factor and anomaly threshold are flexibly set according to actual needs to ensure the accuracy and sensitivity of anomaly detection.

[0072] Step S203, determine the weight of each type of monitoring data according to the environmental state parameters of each type of monitoring data.

[0073] In an embodiment of the present application, the environmental state parameters of the monitoring data may include, but are not limited to, region, device model, time period information, etc. In an example, the region represents the region where the user device is located, which can be determined according to the global positioning system, such as a satellite sensor; the device model represents the model of the user device; the time period information represents the time period corresponding to when the monitoring data is collected. Among them, each environmental state parameter may affect the monitoring data, resulting in noise in the environmental state parameters. For example, noise represents the numerical value with errors in the monitoring data due to the interference or influence of the environmental state parameters.

[0074] For example, for the region: the network infrastructure in different regions varies greatly, including network bandwidth, network latency, network stability, etc. These factors directly affect the transmission speed and quality of multimedia data, thus affecting the stuttering rate, first-play latency, and loading failure rate during playback. The geographical location also affects data transmission. For example, remote areas or mountainous areas may have poor signal coverage, resulting in blocked data transmission and thus affecting playback quality.

[0075] For device models: The hardware configuration (such as processor, memory, graphics card, etc.) of the same device model directly affects its ability to process multimedia data. Devices with lower hardware configurations may be more likely to experience problems such as freezing and loading failure when playing high-definition or high-bitrate videos. Different device models may lead to differences in their software compatibility. If the encoding format of the multimedia data is incompatible with the device, it may cause playback failure or reduced playback quality. As the device is used for a longer time, its performance may gradually decline, resulting in affected playback quality.

[0076] As for time period information: in certain time periods (such as peak hours in the evening), the network may be more congested, resulting in a decrease in data transmission speed, which in turn affects the playback quality of multimedia data. Time period information is also related to user behavior. For example, on weekends or holidays, users may be more inclined to watch multimedia content, resulting in increased network traffic, which in turn affects the playback quality.

[0077] In another embodiment of the present application, the environmental state parameters of the monitoring data may include but are not limited to temperature, humidity, etc., and can be obtained according to actual needs. Among them, each environmental state parameter may affect the monitoring data, causing noise to appear in the environmental state parameters. For example, for temperature: high temperature may cause the user device to overheat, thereby reducing its performance and increasing the jam rate. For another example, for humidity: too high humidity may cause a short circuit in the internal circuit of the user device, causing a malfunction and resulting in a high packet loss rate.

[0078] In an embodiment of the present application, the electronic device can receive the environmental state parameters input by the user, and can also obtain the environmental state parameters of the monitoring data from a variety of sensors. The present application does not specifically limit the types of environmental state parameters and the methods for obtaining environmental state parameters.

[0079] In one example, the environmental state parameter corresponding to time point t can be expressed as a vector ,in, It can represent the region corresponding to time point t, It can represent the device model corresponding to the time point t, It can represent the time period information corresponding to the time point t, etc. When determining the weight of each monitoring data according to the environmental state parameter of each monitoring data, the pre-trained mapping function An environmental adaptation coefficient (such as a weight adjustment factor) is calculated for each monitoring data, which can be exemplarily expressed as ,in, Represents the weight corresponding to the monitoring data in the i-th order.

[0080] In an embodiment of the present application, when determining the weight of each type of monitoring data according to the environmental state parameters, the noise parameter of each type of monitoring data may be determined based on the environmental state parameters. The weight is determined according to the noise parameter and a preset adjustment parameter.

[0081] In an embodiment of the present application, when determining the noise parameter of each type of monitoring data, historical environmental state parameters and corresponding historical monitoring data may be collected to determine the noise in the historical monitoring data. Statistical analysis methods (such as regression analysis, variance analysis, etc.) or machine learning algorithms (such as decision trees, neural networks, etc.) are used to determine the relationship model between the noise and the historical environmental state parameters. This relationship model can indicate how the historical environmental state parameters affect the historical monitoring data to generate noise. According to this relationship model, the noise parameter of each type of monitoring data is determined.

[0082] In an example, an example is given to determine the relationship model between the environmental state parameter "region" and the noise of the monitoring data "lag rate". Due to differences in aspects such as network infrastructure, geographical location, and user behavior in different regions, it may have different impacts on the transmission and playback of multimedia content, thereby leading to changes in the lag rate. To determine the impact of the region on the lag rate, multimedia playback lag rate data from different regions can be collected and analyzed. These data can include network infrastructure indicators such as network bandwidth and network latency in each region, as well as the lag rate data collected within the same time period. By analyzing these data, the potential relationship between the region and the lag rate noise can be determined.

[0083] For example, regression analysis can be used to explore the linear or non-linear relationship between the lag rate noise and the network infrastructure indicators of the region (such as network bandwidth, network latency), and variance analysis can be used to evaluate the significant differences in the lag rate noise between different regions. For example, a multiple linear regression model can be established, where the lag rate noise (Y) is used as the dependent variable, and network bandwidth (X1), network latency (X2), and region dummy variable (X3, representing the differences between different regions) are used as independent variables. The model can be expressed as: Y = β0 + β1X1 + β2X2 + β3X3 + u. Where, β0 is the intercept term, β1, β2, and β3 are regression coefficients, and u is the error term. Through regression analysis, the impacts of network bandwidth, network latency, and region on the lag rate noise can be obtained.

[0084] In an embodiment of the present application, when determining the weight according to the noise parameter and the preset adjustment parameter, the formula used can be exemplarily expressed as: , Where, represents the noise parameter corresponding to the i-th type of monitoring data at time point t, represents the adjustment parameter, Represents the weight corresponding to the i-th monitoring data at time point t.

[0085] In one embodiment of the present application, historical monitoring data of the communication service may be obtained, and the preset adjustment parameter may be determined based on the historical monitoring data. For example, a noise parameter corresponding to the historical monitoring data may be obtained, and the adjustment parameter may be set based on the noise parameter, for example, such that the adjustment parameter is proportional to the noise parameter.

[0086] Based on the above embodiment, by comprehensively considering the environmental state parameters of the monitoring data and using the pre-trained mapping function or relationship model, the weight of each monitoring data in the overall evaluation or analysis can be accurately determined. These weights reflect the quality and reliability of the monitoring data and the degree of influence on the overall result. In particular, when the noise in the monitoring data is large, the corresponding weight will be reduced accordingly to reduce the influence of the noise on the final result. Therefore, the interference of noise can be effectively reduced, the accuracy and reliability of the monitoring data can be improved, and more accurate data support can be provided for subsequent decision-making and optimization.

[0087] In addition, by adaptively adjusting the weights of each modal monitoring data, the data fusion effect can be dynamically optimized according to the on-site environment to ensure that subsequent abnormal monitoring will neither cause false alarms due to noise nor miss real abnormal situations due to fixed weight settings, thereby improving the accuracy of real-time alarms.

[0088] Step S204: determining an abnormality score of the communication service according to the weight and the abnormality indicator.

[0089] In an embodiment of the present application, the anomaly score may be determined based on a weighted fusion result of the weight and the anomaly index. For example, the formula used may be exemplarily represented as: , in, represents the abnormal score at time point t, represents the weight corresponding to the i-th monitoring data at time point t, Represents the abnormal index corresponding to the i-th monitoring data at time point t.

[0090] Based on the above embodiment, the weights of various monitoring data and their corresponding abnormal indicators can be comprehensively considered, and the abnormal score of the communication service can be calculated using the weighted fusion method. This method can more comprehensively reflect the overall operating status of the communication service, ensure the accuracy and reliability of the abnormal score, and provide strong data support for subsequent abnormal diagnosis and optimization.

[0091] Step S205: determining an anomaly detection result of the communication service according to the anomaly score and a preset dynamic threshold.

[0092] In one embodiment of the present application, an adaptive method may be used to determine a dynamic alarm threshold, such as a preset dynamic threshold. In one example, the preset dynamic threshold may be determined based on the median and absolute median difference of the abnormality score within a preset time length. For example, the formula used may be exemplarily expressed as: , in, represents the dynamic threshold corresponding to time point t, Indicates the preset time length. Indicates the preset time length before time point t Within, determine the anomaly score of the median. Indicates the preset time length before time point t Within, determine the anomaly score The absolute median difference. It represents the preset threshold adjustment coefficient, which can be set according to actual needs, and this application does not impose any specific restrictions on this.

[0093] Based on the above embodiment, when determining the alarm threshold, the dynamic threshold is calculated based on the statistical characteristics of the abnormal score in the recent historical window. Specifically, a statistical window length is selected. , and calculate within this time frame The median and absolute median difference are then weighted by a threshold adjustment coefficient to obtain a dynamic threshold, which can automatically adjust the threshold based on the statistical characteristics of historical data.

[0094] In one embodiment of the present application, when determining the abnormality detection result of the communication service, if the abnormality score is greater than the preset dynamic threshold, the abnormality detection result is determined to be abnormal; or, if the abnormality score is less than or equal to the preset dynamic threshold, the abnormality detection result is determined to be abnormal. In one example, if the monitoring result is abnormal, an abnormal alarm can be issued. For example, an abnormal alarm sound is issued, an alarm message is displayed on a preset interface, or an alarm message is sent to a corresponding user, etc.

[0095] Based on the above embodiment, when the anomaly score calculated in real time exceeds the dynamic threshold, it is determined that an abnormal situation is detected and an alarm is triggered, thereby more accurately reflecting the real-time status of the communication service and reducing the possibility of false positives and false negatives.

[0096] The anomaly monitoring method provided by the embodiments of the present application can adapt to dynamic environmental changes and improve the accuracy of anomaly monitoring of communication services by obtaining various monitoring data of the communication service, extracting data features therefrom, determining the anomaly indicators for each type of data, and simultaneously assigning dynamic weights to each type of data in combination with environmental status parameters, determining the anomaly score of the communication service based on the weights and anomaly indicators, and comparing it with a preset dynamic threshold. A closed-loop control system for real-time updating and adjusting parameters based on actual operation feedback can also be established to ensure that the system always maintains high accuracy in identifying anomaly states under different environmental and interference conditions.

[0097] Figure 4 It is a structural diagram of an anomaly monitoring device provided by an embodiment of the present application.

[0098] In some embodiments, the anomaly monitoring device 40 may include multiple functional modules composed of computer program segments. The computer programs of each program segment in the anomaly monitoring device 40 can be stored in the memory of the electronic device and executed by at least one processor to perform the functions of anomaly monitoring (see the description in Figure 2 for details).

[0099] In this embodiment, the anomaly monitoring device 40 can be divided into multiple functional modules according to the functions it performs. The functional modules may include: an acquisition module 401 and a determination module 402. The module referred to in the present application means a series of computer program segments that can be executed by at least one processor and can complete fixed functions, and are stored in the memory. In this embodiment, for the implementation manners of the functions of each module in the anomaly monitoring device 40, reference can be made to the limitations on the anomaly monitoring method above, and the description will not be repeated here.

[0100] The acquisition module 401 is used to acquire various monitoring data of the communication service and extract the data features of each type of monitoring data.

[0101] The determination module 402 is used to determine the anomaly indicators for each type of monitoring data based on the data features; determine the weights for each type of monitoring data according to the environmental status parameters of each type of monitoring data; determine the anomaly score of the communication service according to the weights and the anomaly indicators; and determine the anomaly detection result of the communication service according to the anomaly score and a preset dynamic threshold.

[0102] The embodiments of the present application also provide a computer-readable storage medium, on which a computer program is stored. The computer program includes program instructions, and the method implemented when the program instructions are executed can refer to the methods in the above various embodiments of the present application.

[0103] Among them, the computer-readable storage medium can be the internal memory of the electronic device in the above embodiments, such as the hard disk or memory of the electronic device. The computer-readable storage medium can also be an external storage device of the electronic device, such as a plug-in hard disk equipped on the electronic device, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc.

[0104] In some embodiments, the computer-readable storage medium may include a storage program area and a storage data area. Among them, the storage program area can store an operating system, application programs required for at least one function, etc.; the storage data area can store data created according to the use of the electronic device, etc.

[0105] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0106] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0107] In the embodiments provided in this application, it should be understood that the disclosed device / terminal device and method can be implemented in other ways. For example, the device / terminal device embodiments described above are only illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical, mechanical or other form.

[0108] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0109] The above embodiments are only used to illustrate the technical solutions of the present application, rather than limiting it; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. An anomaly monitoring method, characterized in that, The method includes: Obtaining various monitoring data of a communication service and extracting data features of each piece of monitoring data; Based on the data features, determining an anomaly metric for each piece of monitoring data; According to the environmental status parameters of each piece of monitoring data, determining the weight of each piece of monitoring data; According to the weight and the anomaly metric, determining an anomaly score of the communication service; According to the anomaly score and a preset dynamic threshold, determining an anomaly detection result of the communication service.

2. The anomaly monitoring method according to claim 1, wherein The obtaining various monitoring data of a communication service and extracting data features of each piece of monitoring data includes: Based on a sliding window algorithm, determining the median and the absolute median difference of each piece of monitoring data; According to the median and the absolute median difference, determining a normalized deviation factor of each piece of monitoring data; According to the normalized deviation factor, determining the data features.

3. The anomaly monitoring method according to claim 1, wherein The based on the data features, determining an anomaly metric for each piece of monitoring data includes: According to the data features, a preset smoothing factor, and an anomaly threshold, determining the anomaly metric.

4. The anomaly monitoring method according to claim 1, wherein The according to the environmental status parameters of each piece of monitoring data, determining the weight of each piece of monitoring data includes: Based on the environmental status parameters, determining a noise parameter of each piece of monitoring data; According to the noise parameter and a preset adjustment parameter, determining the weight.

5. The anomaly monitoring method according to claim 4, characterized in that, The method further includes: Obtaining historical monitoring data of the communication service and determining the preset adjustment parameter according to the historical monitoring data.

6. The anomaly monitoring method according to claim 1, characterized in that The according to the weight and the anomaly metric, determining an anomaly score of the communication service includes: According to the weighted fusion result of the weight and the anomaly metric, determining the anomaly score.

7. The anomaly monitoring method according to claim 1, wherein The method further includes: According to the median and the absolute median difference of the anomaly score within a preset time length, determining the preset dynamic threshold.

8. The anomaly monitoring method according to claim 1, wherein The according to the anomaly score and a preset dynamic threshold, determining an anomaly detection result of the communication service includes: If the anomaly score is greater than the preset dynamic threshold, determining that the anomaly detection result is that an anomaly exists; or, If the anomaly score is less than or equal to the preset dynamic threshold, determining that the anomaly detection result is that no anomaly exists.

9. The anomaly monitoring method according to claim 1, wherein The various monitoring data includes the stuttering rate, the first play latency, the loading failure rate, the packet loss rate, and the video frame rate during the playback of multimedia data.

10. An electronic device, characterized in that, including: a memory, and a processor, where the processor executes computer-readable instructions stored in the memory to implement the anomaly monitoring method according to any one of claims 1 to 9.