Abnormality detection method, device and equipment for time series data and storage medium
Through the method of frequency domain decomposition and multimodal attention mechanism combined with the comparative learning network, the detection problem of multi-level and multi-type anomaly recognition is solved, and the accuracy and robustness of abnormal detection of time series data is improved.
Patent Information
- Application Number
- CN202510366261.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-07-11
AI Technical Summary
The existing time series data exception detection methods are difficult to effectively deal with multi-level and multi-type exceptions, and ignore the correlation between different exception types.
The frequency domain decomposition network is used to decompose the time series data, and combine the multimodal attention mechanism and the comparison learning network to calculate the anomaly score to determine the abnormal detection result.
It improves the detection accuracy of multiple types of anomalies, especially suitable for non-stationary time series data, and enhances the robustness and accuracy of the model.
Smart Images

Figure CN120296622A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence technology, and in particular, to an anomaly detection method, device, equipment and storage medium for time series data. Background Art
[0002] With the development of big data technology and the Internet, more and more industries rely on time series data to monitor system status. Most traditional anomaly detection methods rely on the assumption of stationary time series, that is, the data has stable statistical characteristics without changing over time. However, in practice, time series data usually has diversity and non-stationarity, may have different types of anomalies, and these anomalies often intertwine with each other, posing challenges to detection.
[0003] Some existing methods, such as detection methods based on statistical models or deep learning models, usually assume that anomalies are global, or ignore the correlation between different types of anomalies. There is a lack of effective detection methods for multi-level and multi-type anomaly recognition. Summary of the Invention
[0004] The present invention provides an anomaly detection method, device, equipment and storage medium for time series data to solve the problem of lack of effective detection methods for multi-level and multi-type anomaly recognition.
[0005] In the first aspect, an embodiment of the present invention provides an anomaly detection method for time series data, including:
[0006] Obtain the time series data to be detected, and input the time series data to be detected into the target anomaly detection model;
[0007] Perform frequency domain decomposition on the time series data to be detected through the frequency domain decomposition network in the target anomaly detection model to obtain detail components and approximation components;
[0008] Through the feature encoding network in the target anomaly detection model, calculate the first attention score vector and the reconstructed time series feature vector based on the multi-modal attention mechanism and the time series data to be detected, the detail components and the approximation components;
[0009] Through the contrast learning network in the target anomaly detection model, calculate the anomaly score of the time series data to be detected at each time point according to the first attention score vector, the time series feature vector and the reconstructed time series feature vector, and determine the anomaly detection result of the time series data to be detected according to the anomaly score.
[0010] In the second aspect, an embodiment of the present invention provides an anomaly detection device for time series data, including:
[0011] A data input module, configured to obtain time series data to be detected and input the time series data to be detected into a target anomaly detection model;
[0012] A frequency domain decomposition module, configured to perform frequency domain decomposition on the time series data to be detected through a frequency domain decomposition network in the target anomaly detection model to obtain detail components and approximation components;
[0013] A feature encoding module, configured to calculate a first attention score vector and a reconstructed time series feature vector based on a multi-modal attention mechanism, the time series data to be detected, the detail components, and the approximation components through a feature encoding network in the target anomaly detection model;
[0014] A contrastive learning module, configured to calculate an anomaly score of the time series data to be detected at each time point according to the first attention score vector, the time series feature vector, and the reconstructed time series feature vector through a contrastive learning network in the target anomaly detection model, and determine an anomaly detection result of the time series data to be detected according to the anomaly score.
[0015] In a third aspect, an embodiment of the present invention provides an electronic device, where the electronic device includes:
[0016] At least one processor; and
[0017] A memory communicatively connected to the at least one processor; wherein,
[0018] The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the anomaly detection method for time series data according to any embodiment of the present invention.
[0019] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, where the computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the anomaly detection method for time series data according to any embodiment of the present invention when executed by a processor.
[0020] In the technical solution of the embodiment of the present invention, by obtaining the time series data to be detected and inputting the time series data to be detected into the target anomaly detection model; performing frequency domain decomposition on the time series data to be detected through the frequency domain decomposition network in the target anomaly detection model to obtain detail components and approximation components; through the feature encoding network in the target anomaly detection model, calculating the first attention score vector and the reconstructed time series feature vector based on the multi-modal attention mechanism, the time series data to be detected, the detail components and the approximation components; through the contrastive learning network in the target anomaly detection model, calculating the anomaly score of the time series data to be detected at each time point according to the first attention score vector, the time series feature vector and the reconstructed time series feature vector, and determining the anomaly detection result of the time series data to be detected according to the anomaly score; by adopting a combination method of frequency domain decomposition, multi-modal attention mechanism and contrastive learning, enhancing the robustness and accuracy of the anomaly detection model from multiple perspectives, solving the problem of lack of effective detection methods for multi-level and multi-type anomaly recognition, and having the beneficial effect of improving the detection accuracy of different types of anomalies, especially being able to handle multiple types of anomalies in non-stationary time series data.
[0021] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0023] Figure 1 It is a flowchart of an anomaly detection method for time series data provided in Embodiment 1 of the present invention;
[0024] Figure 2 It is a flowchart of an anomaly detection method for time series data provided in Embodiment 2 of the present invention;
[0025] Figure 3 It is an architecture diagram of the target anomaly detection model;
[0026] Figure 4 It is a structural schematic diagram of an anomaly detection device for time series data provided in Embodiment 3 of the present invention;
[0027] Figure 5 It is a structural schematic diagram of an electronic device for implementing the anomaly detection method for time series data in the embodiment of the present invention. Detailed implementation manners
[0028] In order to enable those skilled in the art of the present technology to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.
[0029] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order different from those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0030] Embodiment 1
[0031] Figure 1 As shown in the flowchart of an anomaly detection method for time series data provided in Embodiment 1 of the present invention, this embodiment is applicable to the situation of performing anomaly detection on time series data. This method can be executed by an anomaly detection device for time series data. The anomaly detection device for time series data can be implemented in the form of hardware and / or software, and the anomaly detection device for time series data can be configured in an electronic device. As Figure 1 shown, the method includes:
[0032] S110. Obtain the time series data to be detected, and input the time series data to be detected into the target anomaly detection model.
[0033] Among them, the time series data to be detected can be understood as a set of data points arranged in chronological order that needs to be detected. Exemplarily, in the field of the power industry, the time series data to be detected can be power equipment operation data or power service data, etc. The two dimensions of the time series data to be detected include a time dimension and a type dimension.
[0034] The target anomaly detection model can be understood as a well-trained anomaly detection model for detecting whether there are anomalies in the time series data to be detected. The target anomaly detection model can be trained based on the time series sample data in the target domain. Optionally, the target anomaly detection model includes: a frequency domain decomposition network, a feature encoding network, a contrast learning network, and an output network.
[0035] Exemplarily, the method for obtaining the data sequence to be detected can be: obtaining the initial time series data, and preprocessing the initial time series data to obtain the data sequence to be detected. T is the length of the time series data . It can be understood that the data sequence to be detected can contain multiple dimensions. The preprocessing can include data cleaning and normalization processing. The normalization processing can enable the time series data to be compared on a unified scale to ensure the consistency of the data.
[0036] S120. Perform frequency domain decomposition on the time series data to be detected through the frequency domain decomposition network in the target anomaly detection model to obtain the detail component and the approximation component.
[0037] Among them, the frequency domain decomposition network can be understood as a network for performing frequency domain decomposition on the time series data to be detected. The detail component mainly reflects the high-frequency changes and local features of the time series data to be detected at different scales, and the approximation component mainly reflects the long-term trend and low- and medium-frequency features of the time series data to be detected.
[0038] Specifically, through the frequency domain decomposition network in the target anomaly detection model, the input time series data is decomposed in the frequency domain to obtain the detail component reflecting the high-frequency component for detecting mutation anomalies, and the approximation component reflecting the low- and medium-frequency components for describing the long-term trend changes and capturing periodic anomalies or oscillatory anomalies.
[0039] In this embodiment, by decomposing the time series data to be detected in the frequency domain into the detail component and the approximation component, different types of anomalies can be effectively separated to avoid interference between them, thereby improving the anomaly detection accuracy.
[0040] S130. Through the feature encoding network in the target anomaly detection model, calculate the first attention score vector and the reconstructed time series feature vector based on the multi-modal attention mechanism and the time series data to be detected, the detail component, and the approximation component.
[0041] Among them, the feature encoding network is used to encode the input data into feature vectors. Optionally, the feature encoding network may include a feature extraction sub-network and a multi-modal attention sub-network. The first attention score vector can be understood as a vector composed of the attention scores of each data point. Optionally, the first attention score vector may include: a first reconstruction attention score vector, a first anomaly attention score vector, and a first normal attention score vector. The reconstructed time series feature vector can be understood as a feature vector obtained by reconstructing the time series feature vector to be detected. Optionally, the reconstructed time series feature vector can be determined according to the first reconstruction attention score vector and the time series feature vector to be detected. For example, the first reconstruction attention score vector and the time series feature vector to be detected are multiplied point by point to obtain the reconstructed time series feature vector.
[0042] Specifically, in the target anomaly detection model, the discrete time series data, the approximate component, and the detail component are respectively mapped to a low-dimensional continuous vector space through the feature encoding network to obtain each feature vector, and a multi-modal attention mechanism is introduced in the feature encoding to calculate the attention scores of each data point in each feature vector to form the first attention score vector, which is used to reflect the correlation between different frequency bands. And the time series feature vector to be detected is reconstructed to obtain the reconstructed time series feature vector.
[0043] In this embodiment, the first attention score vector is calculated based on the multi-modal attention mechanism to reflect the correlation between different frequency bands, thereby enhancing the discrimination between anomaly points and normal points.
[0044] S140. Through the contrastive learning network in the target anomaly detection model, calculate the anomaly score of the time series data to be detected at each data point according to the first attention score vector, the time series feature vector, and the reconstructed time series feature vector, and determine the anomaly detection result of the time series data to be detected according to the anomaly score.
[0045] Among them, the contrastive learning network is a powerful unsupervised or self-supervised learning method, which is widely used in feature learning of various data modalities such as images, texts, and speeches. Its core idea is to pull similar samples closer and push dissimilar samples farther away, so as to learn the internal structure and semantic information of the data.
[0046] Specifically, through the contrastive learning network, according to the first attention score vector, the time series feature vector, and the reconstructed time series feature vector, the difference between normal points and anomaly points is strengthened, and the loss between normal points and reconstructed points is calculated to enhance the model's ability to identify anomaly points and normal points, and based on the anomaly score of each data point, an anomaly determination is made, and the anomaly detection result is output based on the threshold judgment.
[0047] Exemplarily, the method for determining the anomaly detection result of the time series data to be detected according to the anomaly score can be as follows: for each data point in the time series data to be detected, determine the anomaly detection result corresponding to the anomaly score of the data point based on threshold judgment; or, according to the anomaly scores of the data points in the time series data to be detected, determine the anomaly detection result of the time series data to be detected within a period of time. For example, calculate the average anomaly score of the data points in the time series data to be detected. If it is determined based on threshold judgment that the average anomaly score is greater than the score threshold, it is determined that the time series data to be detected is abnormal; if it is determined based on threshold judgment that the average anomaly score is less than or equal to the score threshold, it is determined that the time series data to be detected is normal.
[0048] In the technical solution of the embodiment of the present invention, by obtaining the time series data to be detected and inputting the time series data to be detected into the target anomaly detection model; performing frequency domain decomposition on the time series data to be detected through the frequency domain decomposition network in the target anomaly detection model to obtain detail components and approximation components; through the feature encoding network in the target anomaly detection model, calculating the first attention score vector and the reconstructed time series feature vector based on the multi-modal attention mechanism and the time series data to be detected, the detail components and the approximation components; through the contrastive learning network in the target anomaly detection model, calculating the anomaly score of the time series data to be detected at each time point according to the first attention score vector, the time series feature vector and the reconstructed time series feature vector, and determining the anomaly detection result of the time series data to be detected according to the anomaly score. By adopting a combination of frequency domain decomposition, multi-modal attention mechanism and contrastive learning, the robustness and accuracy of the anomaly detection model are enhanced from multiple angles, and the detection accuracy for different types of anomalies can be improved, especially for handling multiple types of anomalies in non-stationary time series data.
[0049] Embodiment 2
[0050] Figure 2 It is a flowchart of an anomaly detection method for time series data provided in Embodiment 2 of the present invention. In this embodiment, the frequency domain decomposition network, the feature encoding network and the contrastive learning network in the above embodiment are further defined. As Figure 2 shown, the method includes:
[0051] S210. Obtain the time series data to be detected and input the time series data to be detected into the target anomaly detection model.
[0052] Among them, the target anomaly detection model includes a frequency domain decomposition network, a feature encoding network and a contrastive learning network; the feature encoding network includes: a feature extraction sub-network and a multi-modal attention sub-network.
[0053] S220. Perform frequency-domain decomposition on the time series data to be detected using discrete wavelet transform through a frequency-domain decomposition network, obtaining detail components in multiple frequency bands and an approximation component.
[0054] Specifically, discrete wavelet transform (DWT) uses a set of filters to filter and downsample the time series signal, decomposing the signal into an approximation component and detail components. These filters include a low-pass filter and a high-pass filter. The high-pass filter is used to extract high-frequency components, obtaining detail components in multiple frequency bands; the low-pass filter is used to extract low-frequency components, obtaining an approximation component, thereby realizing multi-scale analysis of the time series data to be detected, effectively separating different types of anomalies and avoiding interference between them, and further improving the detection accuracy.
[0055] Exemplarily, Figure 3 is the architecture diagram of the target anomaly detection model. As Figure 3 shown, the process of performing frequency-domain decomposition on the time series data to be detected using discrete wavelet transform can be expressed as: where, represents the detail components in multiple frequency bands obtained by decomposition, K is the total number of frequency bands, represents the approximation component obtained by decomposition. In multi-level decomposition, the approximation component at the highest level usually contains the most basic shape information of the signal. Therefore, the approximation component can be selected as the first-level approximation component.
[0056] S230. Extract the time series feature vector of the time series data to be detected, the detail component feature vector of the detail components, and the approximation component feature vector corresponding to the approximation component through the feature extraction sub-network.
[0057] Among them, the feature extraction sub-network is used to extract the features of the input data. The feature extraction sub-network can include an upsampling module and an encoding module. The encoding module can use Embedding technology to map the discrete time series data, approximation component, and detail components into a low-dimensional continuous vector space.
[0058] Specifically, the time series feature vector is obtained by extracting features from the time series data to be detected through the feature extraction sub-network, the detail component feature vector is obtained by extracting features from the detail components, and the approximation component feature vector is obtained by extracting features from the approximation component.
[0059] S240. Initialize the time series feature vector, detail component feature vector, and approximation component feature vector respectively based on the multi-modal attention mechanism through the multi-modal attention sub-network, and calculate the first attention score vector and the reconstructed time series feature vector according to the initialization results.
[0060] Among them, the multi-modal attention sub-network is a neural network structure for processing multi-modal data. Its core is to capture the correlation and importance between different modalities through the attention mechanism, so as to better fuse and utilize multi-modal information.
[0061] Specifically, through the multi-modal attention sub-network, the time series feature vector, the detail component feature vector, and the approximate component feature vector are respectively initialized based on the multi-modal attention mechanism to obtain their corresponding attention triples: Query, Key, and Value. Calculate the first attention score vector and the reconstructed time series feature vector according to the initialized attention triples.
[0062] As an optional implementation manner of this embodiment, the step of respectively initializing the time series feature vector, the detail component feature vector, and the approximate component feature vector based on the multi-modal attention mechanism includes: initializing the time series feature vector to obtain the query vector, key vector, and value vector of the time series data to be detected, initializing the detail component feature vector to obtain the query vector and key vector of the detail component, and initializing the approximate component feature vector to obtain the query vector and key vector of the approximate component.
[0063] Exemplarily, as Figure 3 shown, initialize the time series feature vector to obtain the query, key, and value of the time series data. As Initialize each frequency band detail component in the detail component feature vector to obtain the query vector and key vector of the detail components of each frequency band. As Initialize the approximate component feature vector to obtain the query and key of the approximate component, such as: Among them, are the weight vectors of the query, key, and value corresponding to the time series data in sequence, and are the weight vectors of the query and key corresponding to the detail component in sequence, and are the weight vectors of the query and key corresponding to the approximate component in sequence.
[0064] As an alternative implementation of this embodiment, according to the initialization result, the first attention score vector and the reconstructed time series feature vector include: calculating a first reconstructed attention score vector according to the query vector and the key vector of the time series data to be detected; calculating a first abnormal attention score vector according to the query vector and the key vector of the detail component; calculating a first normal attention score vector according to the query vector and the key vector of the approximate component; and determining the product of the value vector of the time series data to be detected and the first reconstructed attention score vector as the reconstructed time series feature vector.
[0065] Among them, the first attention score vector includes: a first reconstructed attention score vector, a first abnormal attention score vector, and a first normal attention score vector. The first abnormal attention score vector is used to prominently represent the abnormal part in the time series data to be detected, and the first normal attention score vector is used to prominently represent the normal part in the time series data to be detected.
[0066] Specifically, in order to make the attention scores more stable, scaling and normalization operations are performed. Divide the attention scores by a scaling factor, where the scaling factor is the square root of the dimension d of the time feature sequence This helps to avoid the vanishing or explosion of gradients caused by too large dot product results. Use the Softmax function to normalize the scaled attention scores so that the values of the attention scores are between 0 and 1, representing the relative importance of each element to all other elements. In addition, before calculating the attention scores, the query vector and the key vector can also be sampled to ensure the consistency of the data size.
[0067] Exemplarily, as Figure 3 shown, the first reconstructed attention score vector can be expressed as:
[0068]
[0069] The first abnormal attention score vector can be expressed as:
[0070]
[0071] The first normal attention score vector can be expressed as:
[0072]
[0073] S250. Through the contrastive learning network, calculate the reconstruction loss sequence according to the reconstructed time series feature vector and the time series feature vector, calculate the difference loss sequence according to the first abnormal attention score vector and the first normal attention score vector, and calculate the similarity loss sequence according to the first normal attention score vector and the first reconstructed attention score vector.
[0074] Among them, the reconstruction loss is used to measure the difference between the time series data to be detected and the reconstructed time series feature vector to ensure that the model has good reconstruction ability. The similarity loss enhances the model's ability to capture normal patterns by minimizing the symmetric KL divergence between normal attention and reconstructed attention. The difference loss enhances the distinction between abnormal features and normal features by maximizing the symmetric KL divergence between abnormal attention and normal attention.
[0075] Specifically, Figure 3 As shown, the tth element in the reconstruction loss sequence can be expressed as the tth feature in the reconstructed time series feature vector and the tth feature in the time series feature vector The difference between
[0076] The tth element in the difference loss sequence can be expressed as the first abnormal attention score vector The t-th first abnormal attention score in and the first normal attention score vector The t-th first normal attention score in The divergence between them can be, for example:
[0077]
[0078] The tth element in the similarity loss sequence can be represented as the first normal attention score vector The t-th first abnormal attention score in and the first reconstructed attention score vector The t-th first reconstruction attention score in The divergence between them can be, for example:
[0079]
[0080] In some cases, the gradient may become very large or very small, causing unstable training. Through the detach function, and Separate it from the computational graph to avoid exploding or vanishing gradients.
[0081] In contrastive learning, this embodiment enhances the model's ability to recognize anomalies by calculating the difference loss between normal points and abnormal points, and introduces KL divergence to measure the difference between normal and abnormal attention scores and the similarity between normal and reconstructed attention, so as to enhance the model's recognition of normal and abnormal patterns.
[0082] S260. Through the contrast learning network, add and normalize the difference loss sequence and the similarity loss sequence to obtain a normalized sequence, and perform element-wise multiplication on the normalized sequence and the reconstruction loss sequence to obtain the anomaly score for each data point in the time series data to be detected.
[0083] Specifically, the anomaly score sequence corresponding to the time series data to be detected can be expressed as:
[0084]
[0085] where is the anomaly score sequence corresponding to the time series data to be detected, which contains the anomaly score for each data point in the time series data to be detected; ⊙ represents element-wise multiplication.
[0086] S270. Through the contrast learning network, determine the anomaly detection result of the time series data to be detected according to the anomaly score.
[0087] The technical solution of the embodiment of the present invention is as follows: by obtaining the time series data to be detected and inputting the time series data to be detected into the target anomaly detection model; performing frequency domain decomposition on the time series data to be detected through the frequency domain decomposition network in the target anomaly detection model to obtain the detail component and the approximation component; extracting the time series feature vector of the time series data to be detected, the detail component feature vector of the detail component, and the approximation component feature vector corresponding to the approximation component respectively through the feature extraction sub-network; initializing the time series feature vector, the detail component feature vector, and the approximation component feature vector respectively based on the multi-modal attention mechanism through the multi-modal attention sub-network, and calculating the first attention score vector and the reconstructed time series feature vector according to the initialization result; through the contrast learning network in the target anomaly detection model, calculating the anomaly score of the time series data to be detected at each time point according to the first attention score vector, the time series feature vector, and the reconstructed time series feature vector, and determining the anomaly detection result of the time series data to be detected according to the anomaly score. By adopting the combination of frequency domain decomposition, multi-modal attention mechanism and contrast learning, the robustness and accuracy of the anomaly detection model are enhanced from multiple perspectives, and the detection accuracy for different types of anomalies can be improved, especially for handling multiple anomaly types in non-stationary time series data.
[0088] As an optional embodiment of the present invention, the training steps of the target anomaly detection model are as follows:
[0089] A. Obtain the time series sample data and input the time series sample data into the initial anomaly detection model.
[0090] Among them, the time series sample data can be understood as a set of sample data points arranged in chronological order. The initial anomaly detection model can be understood as an anomaly detection model that has not been trained or has not been fully trained.
[0091] Exemplarily, the way to obtain the time series training sample data can be to obtain the historical time series data of power equipment or obtain data from web pages and databases, and obtain it after data preprocessing.
[0092] B. Process the time series sample data through the frequency domain decomposition network and the feature encoding network in the initial anomaly detection model to obtain a time series sample feature vector, a reconstructed time series sample feature vector, a second reconstructed attention score vector, a second anomaly attention score vector, and a second normal attention score vector.
[0093] Among them, the second anomaly attention score vector is used to prominently represent the abnormal part in the time series sample data, and the second normal attention score vector is used to prominently represent the normal part in the time series sample data.
[0094] Specifically, input the time series sample data into the frequency domain decomposition network for frequency domain grading to obtain the detail component and the approximate component of the time series sample data; extract features from the time series sample data through the feature extraction sub-network in the feature encoding network to obtain a time series sample feature vector, extract features from the detail component of the time series sample data to obtain a sample detail component feature vector, and extract features from the approximate component of the time series sample data to obtain a sample approximate component feature vector. Through the multi-modal attention sub-network in the feature encoding network, initialize the time series sample feature vector, the sample detail component feature vector, and the sample approximate component feature vector respectively based on the multi-modal attention mechanism. Calculate the second reconstructed attention score vector according to the query vector and the key vector of the time series sample data obtained by initialization; calculate the second anomaly attention score vector according to the query vector and the key vector of the sample detail component feature vector obtained by initialization; calculate the second normal attention score vector according to the query vector and the key vector of the sample approximate component feature vector obtained by initialization; determine the product of the value vector of the time series sample feature vector and the second reconstructed attention score vector as the reconstructed time series sample feature vector.
[0095] C. Calculate the total loss function value through the contrast learning network in the initial anomaly detection model according to the time series sample feature vector, the reconstructed time series sample feature vector, and the second attention score vector.
[0096] Specifically, through the contrastive learning network, based on the first attention score vector, the time series feature vector, and the reconstructed time series feature vector, the difference between normal points and abnormal points is strengthened, and the loss between normal points and reconstructed points is calculated to enhance the model's recognition ability of abnormal points and normal points. And based on the loss function value between the time series sample feature vector and the reconstructed time series sample feature vector, and the loss function value between the second attention score vector, the total loss function value is calculated for training the model parameters of the initial anomaly detection model.
[0097] In an optional embodiment, the second attention score vector includes a second normal attention score vector, a second abnormal attention score vector, and a second reconstructed attention score vector.
[0098] Calculating the total loss function value through the contrastive learning network in the initial anomaly detection model according to the reconstructed time series sample feature vector, the reconstructed time series sample feature vector, and the second attention score vector includes:
[0099] Calculating the reconstruction loss function value according to the reconstructed time series sample feature vector and the time series sample feature vector; calculating the difference loss function value according to the divergence between the second abnormal attention score vector and the second normal attention score vector; calculating the similarity loss function value according to the divergence between the second normal attention score vector and the second reconstructed attention score vector; determining the weighted sum of the similarity loss function and the difference loss function as the contrast loss function value, and determining the sum of the contrast loss function value and the reconstruction loss function value as the total loss function value.
[0100] Exemplarily, the second reconstruction loss function value The calculation formula is:
[0101]
[0102] The second difference loss function value The calculation formula is:
[0103]
[0104] The second similarity loss function value The calculation formula is:
[0105]
[0106] The total loss function value The calculation formula is:
[0107]
[0108] Wherein, α1 is the weight of the second reconstruction loss function value, α2 is the weight of the second difference loss function value, α3 is the weight of the second similarity loss function value, and L is the total loss function value; wherein, Y t is the feature at time t in the time series sample feature vector, is the feature at time t in the reconstructed time series sample feature vector; is the second normal attention score at time t in the second normal attention score vector, is the second abnormal attention score at time t in the second abnormal attention score vector, is the second reconstruction attention score at time t in the second reconstruction attention score vector.
[0109] D. Adjust the model parameters of the initial anomaly detection model according to the total loss function value to obtain a target anomaly detection model.
[0110] Specifically, based on the trained target anomaly detection model, the anomaly detection result of the time series data to be detected can be determined.
[0111] Embodiment III
[0112] Figure 4 This is a schematic structural diagram of an anomaly detection device for time series data provided in Embodiment III of the present invention. As Figure 4 shown, the device includes: a data input module 310, a frequency domain decomposition module 320, a frequency domain decomposition module 320, and a contrast learning module 340; wherein,
[0113] The data input module 310 is configured to obtain the time series data to be detected and input the time series data to be detected into the target anomaly detection model;
[0114] The frequency domain decomposition module 320 is configured to perform frequency domain decomposition on the time series data to be detected through the frequency domain decomposition network in the target anomaly detection model to obtain a detail component and an approximation component;
[0115] The feature encoding module 330 is configured to calculate a first attention score vector and a reconstructed time series feature vector based on the multi-modal attention mechanism and the time series data to be detected, the detail component, and the approximation component through the feature encoding network in the target anomaly detection model;
[0116] The contrast learning module 340 is configured to calculate the anomaly score of the time series data to be detected at each time point according to the first attention score vector, the time series feature vector, and the reconstructed time series feature vector through the contrast learning network in the target anomaly detection model, and determine the anomaly detection result of the time series data to be detected according to the anomaly score.
[0117] In the technical solution of the embodiment of the present invention, by obtaining the time series data to be detected and inputting the time series data to be detected into the target anomaly detection model; performing frequency domain decomposition on the time series data to be detected through the frequency domain decomposition network in the target anomaly detection model to obtain the detail component and the approximation component; through the feature encoding network in the target anomaly detection model, based on the multi-modal attention mechanism and the time series data to be detected, the detail component and the approximation component, calculating the first attention score vector and the reconstructed time series feature vector; through the contrastive learning network in the target anomaly detection model, calculating the anomaly score of the time series data to be detected at each time point according to the first attention score vector, the time series feature vector and the reconstructed time series feature vector, and determining the anomaly detection result of the time series data to be detected according to the anomaly score; by adopting a combination method of frequency domain decomposition, multi-modal attention mechanism and contrastive learning, enhancing the robustness and accuracy of the anomaly detection model from multiple angles, being able to improve the detection accuracy of different types of anomalies, especially being able to handle multiple types of anomalies in non-stationary time series data.
[0118] Optionally, the feature encoding network includes a feature extraction sub-network and a multi-modal attention sub-network.
[0119] Optionally, the feature encoding module includes:
[0120] A feature extraction unit, configured to extract the time series feature vector of the time series data to be detected, the detail component feature vector of the detail component, and the approximation component feature vector corresponding to the approximation component respectively through the feature extraction sub-network;
[0121] A multi-modal attention unit, configured to initialize the time series feature vector, the detail component feature vector, and the approximation component feature vector respectively based on the multi-modal attention mechanism through the multi-modal attention sub-network, and calculate the first attention score vector and the reconstructed time series feature vector according to the initialization result.
[0122] Optionally, the multi-modal attention unit includes:
[0123] An initialization sub-unit, configured to initialize the time series feature vector to obtain the query vector, key vector, and value vector of the time series data to be detected, initialize the detail component feature vector to obtain the query vector and key vector of the detail component, and initialize the approximation component feature vector to obtain the query vector and key vector of the approximation component;
[0124] A reconstruction attention score calculation sub-unit, configured to calculate the first reconstruction attention score vector according to the query vector and key vector of the time series data to be detected;
[0125] An abnormal attention score calculation sub-unit, configured to calculate a first abnormal attention score vector according to the query vector and the key vector of the detailed component;
[0126] A normal attention score calculation sub-unit, configured to calculate a first normal attention score vector according to the query vector and the key vector of the approximate component;
[0127] A time series reconstruction sub-unit, configured to determine the product of the value vector of the time series data to be detected and the first reconstructed attention score vector as the reconstructed time series feature vector.
[0128] Optionally, the contrastive learning module is specifically configured to:
[0129] Calculate a reconstruction loss sequence according to the reconstructed time series feature vector and the time series feature vector through the contrastive learning network;
[0130] Calculate a difference loss sequence according to the first abnormal attention score vector and the first normal attention score vector;
[0131] Calculate a similarity loss sequence according to the first normal attention score vector and the first reconstructed attention score vector;
[0132] Add and normalize the difference loss sequence and the similarity loss sequence to obtain a normalized sequence, and perform element-wise multiplication on the normalized sequence and the reconstruction loss sequence to obtain the anomaly score of each data point in the time series data to be detected.
[0133] Optionally, the frequency domain decomposition module is specifically configured to:
[0134] Perform frequency domain decomposition on the time series data to be detected by using discrete wavelet transform through the frequency domain decomposition network to obtain detailed components in multiple frequency bands and one approximate component.
[0135] Optionally, the training steps of the target anomaly detection model are:
[0136] Obtain time series sample data, and input the time series sample data into the initial anomaly detection model;
[0137] Process the time series sample data through the frequency domain decomposition network and the feature encoding network in the initial anomaly detection model to obtain a time series sample feature vector, a reconstructed time series sample feature vector, and a second attention score vector;
[0138] Calculate the total loss function value according to the time series sample feature vector, the reconstructed time series sample feature vector, and the second attention score vector through the contrastive learning network in the initial anomaly detection model;
[0139] Adjust the model parameters of the initial anomaly detection model according to the total loss function value to obtain a target anomaly detection model.
[0140] Optionally, the second attention score vector includes a second normal attention score vector, a second anomaly attention score vector, and a second reconstruction attention score vector. Correspondingly, calculating the total loss function value according to the reconstructed time series sample feature vector, the reconstructed time series sample feature vector, and the second attention score vector through the contrastive learning network in the initial anomaly detection model includes:
[0141] Calculate a reconstruction loss function value according to the reconstructed time series sample feature vector and the time series sample feature vector;
[0142] Calculate a difference loss function value according to the divergence between the second anomaly attention score vector and the second normal attention score vector;
[0143] Calculate a similarity loss function value according to the divergence between the second normal attention score vector and the second reconstruction attention score vector;
[0144] Determine the weighted sum of the similarity loss function and the difference loss function as the contrast loss function value, and determine the sum of the contrast loss function value and the reconstruction loss function value as the total loss function value.
[0145] The anomaly detection device for time series data provided by the embodiments of the present invention can execute the anomaly detection method for time series data provided by any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method.
[0146] Embodiment 4
[0147] Figure 5 FIG. shows a schematic structural diagram of an electronic device 10 that can be used to implement the embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present invention described herein and / or claimed.
[0148] As Figure 5As shown, the electronic device 10 includes at least one processor 11 and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0149] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0150] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the anomaly detection method for time series data.
[0151] In some embodiments, the anomaly detection method for time series data can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the anomaly detection method for time series data described above can be executed. Alternatively, in other embodiments, the processor 11 can be configured to execute the anomaly detection method for time series data in any other appropriate manner (e.g., by means of firmware).
[0152] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0153] In some embodiments, the anomaly detection method for time series data can be implemented as a computer program that is invisibly contained in a computer program product. The computer program, when executed by a processor, implements the anomaly detection method for time series data of the present invention. A computer program product can be understood as a software product that mainly implements its solution through a computer program. The computer program for implementing the method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing devices, such that when the computer program is executed by the processor, the functions / operations specified in the flowchart and / or block diagram are implemented. The computer program can be executed entirely on the machine, partially on the machine, executed partially on the machine as an independent software package and partially on a remote machine, or executed entirely on a remote machine or server.
[0154] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of machine-readable storage media would include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0155] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0156] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0157] A computing system can include a client and a server. The client and the server are generally far from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0158] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and this is not limited herein.
[0159] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. An anomaly detection method for time series data, characterized in that, Including: Obtain the time series data to be detected, and input the time series data to be detected into the target anomaly detection model; Perform frequency domain decomposition on the time series data to be detected through the frequency domain decomposition network in the target anomaly detection model to obtain detail components and approximate components; Through the feature encoding network in the target anomaly detection model, calculate the first attention score vector and the reconstructed time series feature vector based on the multi-modal attention mechanism and the time series data to be detected, the detail components and the approximate components; Through the contrast learning network in the target anomaly detection model, calculate the anomaly score of the time series data to be detected at each time point according to the first attention score vector, the time series feature vector and the reconstructed time series feature vector, and determine the anomaly detection result of the time series data to be detected according to the anomaly score.
2. The method according to claim 1, wherein The feature encoding network includes a feature extraction sub-network and a multi-modal attention sub-network; the step of calculating the first attention score vector and the reconstructed time series feature vector through the feature encoding network in the target anomaly detection model based on the multi-modal attention mechanism and the time series data to be detected, the detail components and the approximate components includes: Extract the time series feature vector of the time series data to be detected, the detail component feature vector of the detail components and the approximate component feature vectors corresponding to the approximate components respectively through the feature extraction sub-network; Through the multi-modal attention sub-network, initialize the time series feature vector, the detail component feature vector and the approximate component feature vectors respectively based on the multi-modal attention mechanism, and calculate the first attention score vector and the reconstructed time series feature vector according to the initialization results.
3. The method according to claim 2, characterized in that, The step of initializing the time series feature vector, the detail component feature vector and the approximate component feature vectors respectively based on the multi-modal attention mechanism, and calculating the first attention score vector and the reconstructed time series feature vector according to the initialization results includes: Initialize the time series feature vector to obtain the query vector, key vector and value vector of the time series data to be detected, initialize the detail component feature vector to obtain the query vector and key vector of the detail components, and initialize the approximate component feature vector to obtain the query vector and key vector of the approximate components; Calculate the first reconstructed attention score vector according to the query vector and key vector of the time series data to be detected; Calculate the first anomaly attention score vector according to the query vector and key vector of the detail components; Calculate the first normal attention score vector according to the query vector and key vector of the approximate components; Determine the product of the value vector of the time series data to be detected and the first reconstructed attention score vector as the reconstructed time series feature vector.
4. The method according to claim 3, characterized in that The step of calculating the anomaly score of each data point in the time series data to be detected through the contrast learning network according to the first attention score vector, the time series feature vector and the reconstructed time series feature vector includes: Through the contrast learning network, calculate a reconstruction loss sequence based on the reconstructed time series feature vector and the time series feature vector; Calculate a difference loss sequence based on the first abnormal attention score vector and the first normal attention score vector; Calculate a similarity loss sequence based on the first normal attention score vector and the first reconstruction attention score vector; Add and normalize the difference loss sequence and the similarity loss sequence to obtain a normalized sequence, and perform element-wise multiplication on the normalized sequence and the reconstruction loss sequence to obtain the anomaly score of each data point in the time series data to be detected.
5. The method according to claim 1, wherein Perform frequency domain decomposition on the time series data to be detected through the frequency domain decomposition network to obtain detail components and an approximation component, including: Through the frequency domain decomposition network, perform frequency domain decomposition on the time series data to be detected using discrete wavelet transform to obtain detail components in multiple frequency bands and an approximation component.
6. The method according to any one of claims 1-5, characterized in that The training steps of the target anomaly detection model are: Obtain time series sample data and input the time series sample data into the initial anomaly detection model; Process the time series sample data through the frequency domain decomposition network and the feature encoding network in the initial anomaly detection model to obtain a time series sample feature vector, a reconstructed time series sample feature vector, and a second attention score vector; Through the contrast learning network in the initial anomaly detection model, calculate the total loss function value based on the time series sample feature vector, the reconstructed time series sample feature vector, and the second attention score vector; Adjust the model parameters of the initial anomaly detection model according to the total loss function value to obtain the target anomaly detection model.
7. The method according to claim 6, characterized in that, The second attention score vector includes a second normal attention score vector, a second abnormal attention score vector, and a second reconstruction attention score vector; correspondingly, the calculating the total loss function value through the contrast learning network in the initial anomaly detection model according to the reconstructed time series sample feature vector, the reconstructed time series sample feature vector, and the second attention score vector includes: Calculate a reconstruction loss function value based on the reconstructed time series sample feature vector and the time series sample feature vector; Calculate a difference loss function value according to the divergence between the second abnormal attention score vector and the second normal attention score vector; Calculate a similarity loss function value according to the divergence between the second normal attention score vector and the second reconstruction attention score vector; Determine the weighted sum of the similarity loss function and the difference loss function as the contrast loss function value, and determine the sum of the contrast loss function value and the reconstruction loss function value as the total loss function value.
8. An anomaly detection device for time series data, characterized in that Include: A data input module for obtaining the time series data to be detected and inputting the time series data to be detected into the target anomaly detection model; A frequency domain decomposition module for performing frequency domain decomposition on the time series data to be detected through the frequency domain decomposition network in the target anomaly detection model to obtain detail components and an approximation component; A feature encoding module, configured to calculate a first attention score vector and a reconstructed time series feature vector based on a multi-modal attention mechanism, the time series data to be detected, the detail component, and the approximation component through a feature encoding network in the target anomaly detection model; A contrastive learning module, configured to calculate an anomaly score of the time series data to be detected at each time point according to the first attention score vector, the time series feature vector, and the reconstructed time series feature vector through a contrastive learning network in the target anomaly detection model, and determine an anomaly detection result of the time series data to be detected according to the anomaly score.
9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the anomaly detection method for time series data according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and when the computer instructions are executed by a processor, the anomaly detection method for time series data according to any one of claims 1-7 is implemented.
Citation Information
Cited By
Online anomaly detection method, device and equipment for traditional Chinese medicine pelleting machine and storage medium
CN120850172A