Information processing method and device and electronic equipment
Through the abnormality detection model, the timing data is classified and statistics and abnormal threshold judgment is solved, and the problem of insufficient detection accuracy and real-time in the prior art is achieved, and more efficient and reliable abnormality detection is achieved.
Patent Information
- Application Number
- CN202510399782.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-18
AI Technical Summary
The existing data detection model has problems with insufficient detection accuracy and real-time performance in time-series data scenarios, which affects the accuracy of abnormal detection and may pose risks to the stable operation of the business system.
The abnormality detection model is used to classify and count the detection data, and determine whether the sub-data corresponding to each dimension parameter is abnormal through the abnormality threshold. The abnormality threshold is determined by the abnormality detection model based on the sample data to reduce the deviation of artificially set thresholds.
It improves the efficiency and accuracy of abnormal detection, reduces the dependence on manual intervention, and enhances the reliability of the model in abnormal detection.
Smart Images

Figure CN120337062A_ABST
Abstract
Description
Technical Field
[0001] This application relates to, but is not limited to, the field of computer technology, and particularly relates to an information processing method, apparatus, and electronic device. Background Art
[0002] With the rapid development of big data and artificial intelligence technologies, the real-time data generated by enterprise business platforms has shown explosive growth, and the scale and complexity of the data have continued to climb. This has posed huge challenges to traditional data detection methods. The current mainstream data detection models have obvious limitations in the scenario of time-series data, and their detection accuracy and real-time performance are difficult to meet business requirements, which not only affects the accuracy of anomaly detection but may also pose potential risks to the stable operation of business systems. Summary of the Invention
[0003] Embodiments of this application are expected to provide an information processing method, apparatus, and electronic device.
[0004] The technical solution of this application is implemented as follows:
[0005] In a first aspect, an embodiment of this application provides an information processing method, and the method includes:
[0006] Obtain detection data including at least two monitoring parameters;
[0007] Input the detection data into an anomaly detection model to detect whether the sub-data corresponding to each dimension parameter is abnormal, and obtain the detection result;
[0008] Wherein, the sub-data corresponding to the dimension parameter is obtained by classifying and statistically analyzing the detection data according to the parameter value dimension of the monitoring parameter;
[0009] Wherein, the detection result is determined based on the anomaly threshold corresponding to each dimension parameter, and the anomaly threshold is obtained by the anomaly detection model according to sample data.
[0010] In a second aspect, an embodiment of this application provides an information processing apparatus, and the apparatus includes:
[0011] An obtaining unit, configured to obtain detection data including at least two monitoring parameters;
[0012] A detection unit, configured to input the detection data into an anomaly detection model to detect whether the sub-data corresponding to each dimension parameter is abnormal, and obtain the detection result;
[0013] Wherein, the sub-data corresponding to the dimension parameter is obtained by classifying and statistically analyzing the detection data according to the parameter value dimension of the monitoring parameter;
[0014] Among them, the detection result is determined based on the anomaly thresholds corresponding to the respective dimensional parameters, and the anomaly thresholds are obtained by the anomaly detection model according to the sample data.
[0015] In a third aspect, an embodiment of the present application provides an electronic device, which includes: a processor and a memory;
[0016] The memory stores a computer program that can run on the processor;
[0017] The processor executes the computer program stored in the memory to implement the steps of the above information processing method.
[0018] In a fourth aspect, an embodiment of the present application provides a storage medium that stores a computer program, and when the computer program is executed by at least one processor, the steps of the above information processing method are implemented.
[0019] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program or instruction, and when the computer program or instruction is executed by a processor, the steps of the above information processing method are implemented.
[0020] An embodiment of the present application provides an information processing method, device, and electronic device, which obtain detection data including at least two monitoring parameters; input the detection data into an anomaly detection model to detect whether the sub-data corresponding to each dimensional parameter is abnormal, and obtain a detection result; among them, the sub-data corresponding to the dimensional parameter is obtained by classifying and counting the detection data according to the parameter value dimension of the monitoring parameter; among them, the detection result is determined based on the anomaly thresholds corresponding to the respective dimensional parameters, and the anomaly thresholds are obtained by the anomaly detection model according to the sample data. In this way, the optimal thresholds of each dimensional parameter are determined based on the anomaly detection model, which improves the efficiency and reduces the deviation of manually setting the thresholds, reduces the dependence on manual intervention, and at the same time enhances the accuracy and reliability of the model in anomaly detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 is a schematic flowchart of an optional information processing method provided by an embodiment of the present application;
[0022] Figure 2 is a schematic flowchart of an optional information processing method provided by an embodiment of the present application;
[0023] Figure 3 is a schematic monitoring structure diagram of the anomaly detection model and the traditional time series monitoring model provided by an embodiment of the present application;
[0024] Figure 4 is a schematic diagram of the reconstruction loss in the training stage and the verification stage provided by an embodiment of the present application;
[0025] Figure 5 Schematic structural diagram of an optional information processing device provided for the embodiments of the present application;
[0026] Figure 6 Schematic structural diagram of an electronic device provided for the embodiments of the present application. Detailed implementation manners
[0027] In order to enable those skilled in the art to better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present application.
[0028] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products or devices.
[0029] Referring to "embodiments" herein means that the specific features, structures or characteristics described in connection with the embodiments can be included in at least one embodiment of the present application. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0030] The embodiments of the present application provide a method for information processing, which is applied to an electronic device. Referring to Figure 1 as shown, the method includes the following steps:
[0031] Step 101, obtain the data to be detected including at least two monitoring parameters.
[0032] In the embodiments of the present application, the data to be detected may be time-series data that needs to be detected and is stored in a data warehouse, that is, time-series data. For example, the data sampled at a preset sampling frequency within the first time period constitutes the data to be detected with a time series, and this data can be stored in the form of a list.
[0033] In the embodiments of the present application, the data to be detected may include at least two monitoring parameters (also referred to as monitoring fields), and the monitoring parameters may be the fields that need to be monitored key points in the data to be detected. The parameter value of each monitoring parameter may include one or more different dimension parameters (also called dimensional fields). The dimension parameters are used to define the range to which the parameter value of the monitoring parameter to be monitored belongs. The parameter value of the monitoring parameter may be a field value in text form or a field value in numerical form.
[0034] Exemplarily, assume that the data table includes fields such as region field, commodity price field, sales volume field, profit field, and profit margin field, and these fields may be monitoring parameters. Among them, the field value of the region field is of text type and includes different dimension parameters such as Beijing, Shanghai, Guangzhou, and Shenzhen; the field values of the sales volume field and the profit field are of numerical type. Through this data table, the sales volume and profit information of different regions can be obtained.
[0035] In some embodiments, obtaining the data to be detected including at least two monitoring parameters includes:
[0036] Obtaining the data corresponding to each sampling time point within the first time period at the first frequency; and forming the data to be detected according to the data at each sampling time point.
[0037] In the embodiments of the present application, the first frequency may be determined based on the data refresh frequency or may be set regularly according to actual needs, so as to pull new data to be detected regularly, so as to input the new data to be detected into the anomaly detection model.
[0038] Exemplarily, sampling data at a sampling frequency of 1 minute within one day, and the data sampled every day can be the data to be detected with 24×60 = 1440 time series points (i.e., sampling time points).
[0039] It should be noted that since the sampling frequencies of various time series data may be different (such as 1 minute, 5 minutes), it is necessary to obtain the sampling frequency of the time series data, judge the data missing situation of the data to be detected according to the sampling frequency, and perform data preprocessing on the data to be detected, such as removing the dates with too much missing data.
[0040] Step 102: Input the data to be detected into the anomaly detection model, detect whether the sub-data corresponding to each dimension parameter is abnormal, and obtain the detection result.
[0041] Among them, the sub-data corresponding to the dimension parameter is obtained by classifying and counting the data to be detected according to the parameter value dimension of the monitoring parameter.
[0042] Among them, the detection result is determined based on the anomaly threshold corresponding to each dimension parameter, and the anomaly threshold is obtained by the anomaly detection model according to the sample data.
[0043] In the embodiments of the present application, the sub-data corresponding to the dimension parameter is obtained by classifying and statistically analyzing the data to be detected according to the parameter value dimension of the monitoring parameter. Exemplarily, the sub-data corresponding to the dimension parameter may be obtained by classifying and statistically analyzing the parameter values of the monitoring parameter to obtain multiple different dimension parameters corresponding to the monitoring parameter. Exemplarily, the Structured Query Language (SQL) can be used to query the sub-data corresponding to each dimension parameter from the data to be detected with each dimension parameter of the monitoring parameter as the filtering condition.
[0044] In the embodiments of the present application, the anomaly detection model can be understood as a trained anomaly detection model. In the embodiments of the present application, the anomaly detection model can be a deep learning model based on data reconstruction error.
[0045] In the embodiments of the present application, the anomaly detection model is a model used to identify abnormal patterns or abnormal values in data. The anomaly detection model can learn from the sample data to establish the patterns or characteristics of normal data, so as to judge whether the newly input data is abnormal. In the embodiments of the present application, the anomaly detection model is used to detect the sub-data corresponding to each dimension parameter of the monitoring parameter in the data to be detected, so as to judge whether there is an abnormal detection result for the sub-data corresponding to each dimension parameter in the data to be detected.
[0046] In the embodiments of the present application, the detection result can be the conclusion obtained after the anomaly detection model detects the data to be detected, indicating whether there is an abnormality in the sub-data corresponding to each dimension parameter.
[0047] In the embodiments of the present application, the anomaly threshold can be the boundary value for judging whether the sub-data corresponding to each dimension parameter is abnormal. The anomaly detection model will learn and determine the thresholds corresponding to different dimension parameters according to the sample data. When a certain index of the sub-data corresponding to the dimension parameter in the newly input data to be detected exceeds or is lower than the corresponding anomaly threshold, it is considered that the sub-data is abnormal.
[0048] In the embodiments of the present application, the sample data can be time-series data obtained within the historical time at the current moment. The sample data is used to train the anomaly detection model. The model learns and analyzes the sample data to understand the characteristics and patterns of normal data, and then determines the anomaly threshold.
[0049] In the embodiment of the present application, after obtaining the data to be detected including at least two monitoring parameters, the data to be detected is input into an anomaly detection model trained with sample data. Since in the training stage of this anomaly detection model, through learning and analyzing the sample data, the anomaly thresholds corresponding to each dimension parameter are obtained, and these thresholds define the range of normal fluctuations of the data. Therefore, the anomaly detection model will check each sub-data corresponding to the dimension parameter one by one according to these anomaly thresholds to determine whether it exceeds the normal range. Finally, the anomaly detection model outputs the detection result to obtain the sub-data corresponding to the dimension parameter with an abnormal situation.
[0050] Further, the sub-data corresponding to the dimension parameter with an abnormal situation is stored in an anomaly data table, an anomaly warning message is generated, and the anomaly warning message and the anomaly data table are sent to the corresponding person in charge in the form of emails, messages, etc. In this way, it helps users to timely discover the abnormal patterns in the data and ensure the data quality in the data warehouse.
[0051] The embodiment of the present application provides an information processing method, which obtains the data to be detected including at least two monitoring parameters; inputs the data to be detected into an anomaly detection model to detect whether the sub-data corresponding to each dimension parameter is abnormal to obtain a detection result; wherein, the sub-data corresponding to the dimension parameter is obtained by classifying and counting the data to be detected according to the parameter value dimension of the monitoring parameter; wherein, the detection result is determined based on the anomaly thresholds corresponding to each dimension parameter, and the anomaly thresholds are obtained by the anomaly detection model according to the sample data. In this way, the optimal thresholds of each dimension parameter are determined based on the anomaly detection model, which improves the efficiency and reduces the deviation of manually setting the thresholds, reduces the dependence on manual intervention, and at the same time enhances the accuracy and reliability of the model in anomaly detection.
[0052] In some embodiments, as shown in Figure 2 the determination of the anomaly detection model in step 102 can be achieved through the following steps:
[0053] Step 201: Use the anomaly detection model to be trained to preprocess the sample data to obtain the sample sub-data sequence of each dimension parameter.
[0054] Among them, the sample sub-data sequence includes the sample sub-data corresponding to different time series points.
[0055] In the embodiment of the present application, the sample data includes the sample data for model training and the sample processing result, and the sample processing result includes whether the sample data is normal or abnormal.
[0056] In the embodiments of the present application, the preprocessing of sample data can be understood as a series of transformation and processing operations performed on the sample data, so as to make the data more suitable for the learning of the model. The preprocessing includes but is not limited to data cleaning, data standardization, data encoding, etc.; among them, data cleaning can include but is not limited to removing noise and handling missing values, data standardization can include but is not limited to making the data have a unified scale, and data encoding includes converting non-numerical data into numerical data.
[0057] In the embodiments of the present application, the sample sub-data sequence can be understood as classifying and sorting the sample data according to the dimension parameters to obtain the sample sub-data corresponding to each dimension parameter, and sliding on the sample sub-data according to a preset time window to obtain the sample sub-data corresponding to different time series points. It should be noted that each sample sub-data sequence corresponds to a specific dimension parameter and contains the sample sub-data corresponding to the dimension parameter at different time series points.
[0058] In some embodiments, step 201 can be implemented by using the anomaly detection model to be trained to preprocess the sample data to obtain the sample sub-data sequences of each dimension parameter through the following steps:
[0059] Step 211: Classify and count the sample data according to the monitoring parameter value dimension respectively to obtain the sample sub-data corresponding to each dimension parameter;
[0060] Step 212: For the sample sub-data corresponding to each dimension parameter, intercept the sample sub-data by using a preset time window to obtain the sample sub-data sequence corresponding to the dimension parameter.
[0061] Among them, the sample sub-data sequence includes the sample sub-data corresponding to different time series points.
[0062] In the embodiments of the present application, the number of time series points included in the preset time window is the same as or different from the number of time series points included in the first period. If they are the same, there is no need to intercept and divide the sub-data corresponding to each dimension parameter in the data to be detected; if they are different, it is necessary to intercept and divide the sub-data corresponding to each dimension parameter in the data to be detected so that the number of time series points in the divided sub-data is the same as the number of time series points in the preset time window. In this way, the consistency of the data length is ensured during the process of the model processing the data.
[0063] In the embodiments of the present application, the parameter values of the monitoring parameters are classified and counted to obtain multiple different dimension parameters corresponding to the monitoring parameters, such as {f1, f2,..., f I}, using SQL to query the sample sub-data corresponding to each dimension parameter of the monitoring parameter from the data to be detected as a filtering condition; further, for the sample sub-data corresponding to each dimension parameter, the preset time window is cyclically slid with a preset sliding step size, and in ascending order with the time stamp as the condition, each dimension parameter f i corresponding to different time points t n of the sample sub-data v n of the sample sub-data sequence
[0064] It should be noted that the sample sub-data corresponding to at least adjacent time points may overlap or may not overlap; if the size of the preset sliding step is the same as the size of the preset time window, the sample sub-data corresponding to adjacent time points do not overlap; if the size of the preset sliding step is smaller than the size of the preset time window, the sample sub-data corresponding to adjacent time points overlap.
[0065] Step 202: Perform feature processing on the sample sub-data corresponding to each time point in the sample sub-data sequence respectively to obtain a reference feature sequence of the sample sub-data of the dimension parameter.
[0066] In the embodiment of the present application, since the numerical data involved in the sample data, such as commodity prices, sales amounts, profits, and profit margins, usually have certain regularities, and the sample sub-data is part of the sample data, therefore, feature processing can be a series of operations performed on the sample sub-data to extract, transform, or select the information valuable for subsequent analysis and model training in the data, and convert the original data of the sample sub-data into a representation form that can better reflect the internal characteristics and laws of the data. In the embodiment of the present application, feature processing includes one or more operations of feature calculation, feature extraction, and feature screening.
[0067] In the embodiment of the present application, the reference feature sequence of the sample sub-data can be understood as, for the sample sub-data sequence of each dimension parameter, after performing feature processing on the sample sub-data corresponding to each time point in the sample sub-data sequence respectively, an ordered sequence composed of a series of feature values is obtained. It should be noted that the reference feature sequence of the sample sub-data includes the feature information of each time point under this dimension parameter after feature processing, which is an important data basis for subsequent abnormal detection model training and reference, helping the model learn the feature patterns of normal data so as to detect abnormal data.
[0068] In some embodiments, step 202 of performing feature processing on the sample sub-data corresponding to each time point in the sample sub-data sequence respectively to obtain a reference feature sequence of the sample sub-data of the dimension parameter can be implemented through the following steps:
[0069] Step 221: Feature extraction is performed on the sample sub-data corresponding to each time series point of the sample sub-data sequence to obtain an initial reference feature sequence of the dimension parameters.
[0070] In the embodiment of the present application, the initial reference feature sequence may be a sequence of feature values arranged in chronological order obtained by performing feature extraction on the sample sub-data of each time series point in the sample sub-data sequence. The initial reference feature sequence is the basis for subsequent analysis and modeling.
[0071] It can be understood that the electronic device can extract simple features such as mean, variance, maximum value, minimum value, slope, and kurtosis from the sample sub-data corresponding to each time series point of the sample sub-data sequence. Of course, complex features such as autocorrelation coefficient, cross-correlation coefficient, and Fourier transform coefficient can also be extracted from the sample sub-data corresponding to each time series point of the sample sub-data sequence. Shape features based on time series, such as the duration of rise and fall, the number and position of peaks, can also be extracted, so as to obtain an initial reference feature sequence of the sample sub-data sequence corresponding to the dimension parameters. In this way, the original sample sub-data contains a large amount of complex information, and it is difficult to discover the internal laws and patterns of the data directly. Through feature extraction, the high-dimensional and complex original data can be simplified into representative low-dimensional features. The initial reference feature sequences generated for different dimension parameters facilitate cross-dimensional comparative analysis.
[0072] Step 222: Feature screening is performed on the initial reference features according to the correlation between each initial reference feature in the initial reference feature sequence and the sample processing result, where the sample data includes the sample processing result.
[0073] In the embodiment of the present application, the sample processing result is used to characterize whether the sample data is normal or abnormal.
[0074] It can be understood that the electronic device calculates the correlation between each initial reference feature in the initial reference feature sequence and the sample processing result, and screens the initial reference features according to the magnitude of the correlation, and selects the initial reference features with high correlation with the sample processing result. In this way, irrelevant or redundant features are removed, thereby improving the training efficiency and prediction accuracy of the model.
[0075] Of course, the electronic device can also evaluate the importance of the screened initial reference features for the anomaly detection model, so as to help screen out the most useful features for the model. Exemplarily, after training the anomaly detection model, randomly permute the values of a certain feature, and then observe the changes in model performance (such as accuracy, recall rate, F1 value, etc.). If the model performance drops significantly, it indicates that this feature is important for the model. For each reference feature in the initial reference feature sequence, perform the permutation operation in turn, and determine the feature importance order according to the degree of change in model performance. In this way, by screening out the most useful features for the anomaly detection model, the interference of noise and irrelevant features to the model can be reduced, enabling the model to focus more on learning patterns related to anomalies.
[0076] Step 223: Perform feature dimensionality reduction on the screened initial reference features to obtain a sample sub-data reference feature sequence.
[0077] It can be understood that in order to further explore various feature information and improve model performance, the principal component analysis (PCA) method can be used to process the screened initial reference features, that is, perform feature dimensionality reduction on the screened initial reference features, so as to obtain a sample sub-sub-data reference feature sequence. In this way, by constructing a feature construction and processing method that does not rely on prior experience, the applicability of the anomaly detection method in data operation and maintenance is improved.
[0078] It should be noted that PCA is an unsupervised linear dimensionality reduction algorithm. Its core idea is to transform a set of variables that may be correlated through orthogonal transformation into a set of linearly uncorrelated variables, and these new variables are called principal components. When processing the screened initial reference features, it will find the main change directions in the data and project the high-dimensional data into a new low-dimensional space.
[0079] In one implementable manner, the process of using PCA to process the screened initial reference features may include:
[0080] First, perform standardization processing on the screened initial reference features to avoid large differences in the scales of different features, which may affect the calculation results of the principal components.
[0081] Secondly, calculate the covariance matrix for the standardized data. The covariance matrix describes the correlation between different features. For a data set containing p features, its covariance matrix is a p×p matrix, and the element (u,v) in the matrix represents the covariance between the u-th feature and the v-th feature. If two features are highly correlated, the corresponding element value of these two features in the covariance matrix will be relatively large.
[0082] Then, perform eigenvalue decomposition on the covariance matrix to obtain eigenvalues and corresponding eigenvectors. The eigenvalues represent the amount of variance contained in each principal component, and the eigenvectors represent the directions of the principal components. Generally, the eigenvectors are sorted in descending order of eigenvalues.
[0083] Furthermore, select the principal components according to the set dimensionality reduction target or according to the cumulative variance contribution rate. The cumulative variance contribution rate refers to the proportion of the sum of the variances of the first k principal components to the total variance. For example, if the set cumulative variance contribution rate reaches 95%, it can be determined to retain the first k principal components, so that the data after dimensionality reduction can retain 95% of the information of the original data.
[0084] Finally, the selected first k eigenvectors form a transformation matrix of p×k. Multiply the original filtered initial reference feature data by this transformation matrix to obtain the reference feature sequence of the sample sub-data after dimensionality reduction.
[0085] Based on this, since there may still be some noise and redundant features in the filtered initial reference features, PCA can remove the noise and redundant information that have less impact on the data variation by projecting the data onto the main variation directions. At the same time, the dimension of the data after dimensionality reduction is reduced, the amount of calculation is reduced, and the amount of data that the model needs to process during training is greatly reduced.
[0086] Step 203: Fuse the sample sub-data at each time series point in the sample sub-data sequence with the sample sub-data reference features at the corresponding time series point in the sample sub-data reference feature sequence to obtain the sample sub-data feature sequence of the dimension parameter.
[0087] In the embodiment of the present application, the sample sub-data feature sequence includes the sample sub-data and the sample sub-data reference features corresponding to each time series point.
[0088] It can be understood that for the sample sub-data sequence and the sample sub-data reference feature sequence corresponding to each dimension parameter, the sample sub-data at each time series point in the sample sub-data sequence can be fused with the sample sub-data reference features at the corresponding time series point in the sample sub-data reference feature sequence, such as feature splicing, so as to obtain the sample sub-data feature sequence of the dimension parameter. In this way, after combining the original data information with the processed feature information, the formed sample sub-data feature sequence contains richer information, provides a more comprehensive data basis for subsequent analysis and model training, enables the model to better capture the rules and anomalies in the data, and improves the accuracy and reliability of prediction.
[0089] Step 204: Encode and reconstruct the sample sub-data feature sequence to obtain the reconstructed sample sub-data feature sequence of the dimension parameter.
[0090] In the embodiments of the present application, the anomaly detection model may be constructed based on a Long Short-Term Memory (LSTM) network. LSTM is a special type of Recurrent Neural Network (RNN) that can learn and process long-term dependencies in time series data. Traditional RNNs face the problem of vanishing or exploding gradients when dealing with long sequences, while LSTM effectively solves the above problems by introducing a gating mechanism (input gate, forget gate, and output gate), enabling the network to better remember long-term information.
[0091] In the embodiments of the present application, the anomaly detection model includes an encoding module and a decoding module. The encoding module and the decoding module in the anomaly detection model are used to encode and reconstruct the sample sub-data feature sequence to obtain a reconstructed sample sub-data feature sequence with dimensional parameters.
[0092] It can be understood that step 204 of encoding and reconstructing the sample sub-data feature sequence to obtain a reconstructed sample sub-data feature sequence with dimensional parameters can be achieved through the following steps:
[0093] Step 241: Sequentially encode the sample sub-data features in the sample sub-data feature sequence according to the order of time series points to obtain intermediate hidden state vectors.
[0094] Among them, the intermediate hidden state vectors represent the dependencies between the sample sub-data features corresponding to each time series point in the sample sub-data feature sequence with dimensional parameters.
[0095] In the embodiments of the present application, after obtaining the sample sub-data feature sequence, the encoding module in the anomaly detection model can be used to sequentially encode the sample sub-data features corresponding to each time series point according to the order of time series points in the sample sub-data feature sequence, so as to obtain intermediate hidden state vectors that represent the dependencies between the sample sub-data features corresponding to each time series point in the sample sub-data feature sequence with dimensional parameters. In this way, by encoding the sample sub-data feature sequence according to the order of time series points, the generated intermediate hidden state vectors can effectively capture the dynamic change laws of dimensional parameters at different time series points, explicitly represent the dependencies between adjacent or strided time series features (such as short-term fluctuations and long-term trends), and provide richer time series context information for downstream tasks.
[0096] Step 242: Sequentially reconstruct the intermediate hidden state vectors according to the order of time series points to obtain a reconstructed sample sub-data feature sequence corresponding to the dimensional parameters.
[0097] In the embodiment of the present application, after the electronic device encodes the sample sub-data features in the sample sub-data feature sequence in sequence according to the time sequence points to obtain the intermediate hidden state vectors, the decoding module in the anomaly detection model can be used to continue to reconstruct the data of each intermediate hidden state vector in sequence according to the time sequence points to obtain the reconstructed sample sub-data feature sequence corresponding to the dimension parameter. In this way, the data reconstruction process decodes the reconstructed feature sequence in reverse through the hidden state vector, forcing the model to learn low-dimensional and dense feature representations, thereby stripping the noise and non-essential associations in the original data, enhancing the robustness of the model to data loss and outliers, and at the same time improving the generalization ability across scenarios.
[0098] Step 205: Based on the reconstructed sample sub-data feature sequence and the sample sub-data feature sequence, adjust the network parameters of the anomaly detection model to be trained so that the trained anomaly detection model meets the convergence condition.
[0099] In the embodiment of the present application, the electronic device can compare the features of the reconstructed sample sub-data feature sequence and the sample sub-data feature sequence to obtain a comparison result, determine the loss based on the comparison result, and then adjust the network parameters such as the weight coefficients of the anomaly detection model to be trained based on the loss, so that the loss of the features output by the trained anomaly detection model converges.
[0100] It can be understood that step 205 of adjusting the network parameters of the anomaly detection model to be trained based on the reconstructed sample sub-data feature sequence and the sample sub-data feature sequence so that the trained anomaly detection model meets the convergence condition can be achieved through the following steps:
[0101] Step 251: Based on the similarity between the sample sub-data features at each time sequence point in the sample sub-data feature sequence and the reconstructed sample sub-data features at the corresponding time sequence point in the reconstructed sample sub-data feature sequence, determine the reconstruction loss corresponding to each time sequence point under the dimension parameter, so as to obtain the reconstruction loss sequence of the dimension parameter;
[0102] Step 252: Perform a fusion process on the reconstruction losses in the reconstruction loss sequence to obtain the target loss of the dimension parameter; adjust the network parameters of the anomaly detection model to be trained according to the target losses of each dimension parameter.
[0103] Here, the electronic device obtains the sample sub-data feature sequence for each dimension parameter f i in which each time sequence point t n of the sample sub-data feature x n , and the reconstructed sample sub-data feature sequence in which the corresponding time sequence point t n of the reconstructed sample sub-data feature x' nDetermine the dimension parameter f based on the difference i at each time point t n corresponding reconstruction loss |x n - x' n |, thereby obtaining the dimension parameter f i reconstruction loss sequence {|x1 - x1'|, |x2 - x2'|,..., |x n - x' n |}. Further, average the reconstruction losses in the reconstruction loss sequence to obtain the target loss of the dimension parameter f i target loss Determine the final target loss according to the average value of the mean square errors of the target losses of each dimension parameter; according to the final target loss, use stochastic gradient descent to iteratively update the network parameters of the anomaly detection model to be trained. In this way, adjusting the network parameters of the anomaly detection model to be trained according to the target losses of each dimension parameter can enable the model to specifically optimize the network parameters of the dimensions and time points with larger reconstruction losses, and improve the model's ability to identify abnormal data.
[0104] In some embodiments, the anomaly detection model is trained for at least multiple rounds, and the method further includes: obtaining the reconstruction loss sequences of the dimension parameters in each round of training process of the anomaly detection model, thereby obtaining multiple reconstruction loss sequences; determining the maximum reconstruction loss based on the multiple reconstruction loss sequences, and using it as the anomaly threshold of the dimension parameter.
[0105] In the embodiments of the present application, the maximum reconstruction loss can be the loss value with the largest reconstruction loss among the multiple reconstruction loss sequences of the dimension parameter. Among them, when the anomaly detection model is trained for N rounds, the maximum reconstruction loss can be determined through the following two methods
[0106] First, in each round of training process of the anomaly detection model, each dimension parameter corresponds to a reconstruction loss sequence. At this time, the maximum reconstruction loss of the dimension parameter in each round can be obtained, thereby obtaining N maximum reconstruction losses of the dimension parameter. Select the largest maximum reconstruction loss from the N maximum reconstruction losses to obtain the maximum reconstruction loss of the dimension parameter, and use it as the anomaly threshold of the dimension parameter.
[0107] Second, in each round of training process of the anomaly detection model, each dimension parameter corresponds to a reconstruction loss sequence, thereby obtaining N reconstruction loss sequences of the dimension parameter; select the largest reconstruction loss from the N reconstruction loss sequences to obtain the maximum reconstruction loss of the dimension parameter, and use it as the anomaly threshold of the dimension parameter.
[0108] In the embodiments of the present application, since the anomaly detection model may be trained for multiple rounds, that is, iterated multiple times, in each round of training process of the anomaly detection model, each dimension parameter f iEach corresponds to a reconstruction loss sequence {|x1 - x1′|, |x2 - x2′|,..., |x n - x′ n |}, after N rounds of training, each dimensional parameter f i corresponds to N reconstruction loss sequences; at this time, based on each dimensional parameter f i corresponding to N reconstruction loss sequences, the maximum reconstruction loss of the dimensional parameter f i can be determined and used as the anomaly threshold R of the dimensional parameter f i . In this way, the data of different dimensional parameters are significantly different in terms of distribution and fluctuation characteristics. By obtaining the reconstruction loss sequence through multiple rounds of training, the dynamic changes of the data under each dimensional parameter can be captured. Using the maximum reconstruction loss as the anomaly threshold can cover the normal data fluctuation range, ensure that the reconstruction loss of normal data is within the normal data fluctuation range, improve the reliability of the anomaly detection model, and improve the accuracy of anomaly detection.
[0109] In some embodiments, step 102 inputs the data to be detected into the anomaly detection model, detects whether the sub - data corresponding to each dimensional parameter is abnormal, and obtains the detection result, which can be realized through the following steps:
[0110] Use the anomaly detection model to process the sub - data corresponding to the dimensional parameter to obtain the target reconstruction loss corresponding to each dimensional parameter; based on the target reconstruction loss and the anomaly threshold corresponding to the dimensional parameter, obtain the detection result.
[0111] In the embodiments of the present application, obtaining the detection result based on the target reconstruction loss and the anomaly threshold corresponding to the dimensional parameter can be represented by the following formula (1):
[0112]
[0113] where, is abnormal(x) represents the anomaly detection result of the sub - data x corresponding to each dimensional parameter in the data to be detected, RLOSS(x) represents the reconstruction loss corresponding to the dimensional parameter, and r represents the anomaly threshold corresponding to the dimensional parameter. If the reconstruction loss corresponding to the dimensional parameter is greater than the anomaly threshold, it indicates that the sub - data corresponding to the dimensional parameter is abnormal, which can be expressed as is abnormal(x) (x) = 1; similarly, if the reconstruction loss corresponding to the dimensional parameter is less than or equal to the anomaly threshold, it indicates that the sub - data corresponding to the dimensional parameter is normal, which can be expressed as is abnormal(x) (x) = 0.
[0114] In the embodiments of the present application, first, an anomaly detection model is used to preprocess the data to be detected, and sub-data sequences of each dimension parameter are obtained; wherein, the sub-data sequences include sub-data corresponding to different time points; in this way, the data to be detected is divided into sub-data sequences according to the dimension parameters, and the data can be deeply analyzed from different dimensions, and anomalies in each dimension can be accurately captured, avoiding false positives or missed detections of anomalies caused by mixed data. Then, feature processing is performed on the sub-data corresponding to each time point in the sub-data sequence to obtain a sub-data reference feature sequence of the dimension parameter; the sub-data of each time point in the sub-data sequence is fused with the sub-data reference feature of the corresponding time point in the sub-data reference feature sequence to obtain a sub-data feature sequence of the dimension parameter; in this way, the sub-data feature sequence formed by fusing the sub-data of each dimension parameter with the reference feature contains richer information, can more comprehensively reflect the data change, and enables the model to more accurately identify anomalies. Finally, the sub-data feature sequence is encoded and reconstructed to obtain a reconstructed sub-data feature sequence of the dimension parameter; based on the reconstructed sub-data feature sequence of each dimension parameter and the corresponding sub-data feature sequence, the target reconstruction loss corresponding to each dimension parameter is obtained, and based on the target reconstruction loss corresponding to each dimension parameter and the corresponding anomaly threshold, the detection result of whether the sub-data corresponding to the dimension parameter is abnormal is obtained. By encoding and reconstructing the sub-data feature sequence, comparing the reconstruction result with the original data, calculating the target reconstruction loss and comparing it with the anomaly threshold to detect anomalies, it can adapt to the characteristics of data in different dimensions and ensure the reliability of the detection result.
[0115] It should be noted that the present application also monitors the data to be detected through a traditional time series monitoring model, and uses the traditional time series monitoring model and the anomaly detection model provided by the embodiments of the present application to detect the data to be detected respectively, and obtains monitoring results, as Figure 3 shown, the abscissa represents time, and the ordinate represents the parameter value of the monitoring parameter. Further, the performance indicators of the two models, such as precision_score, recall_score_score, F1 value, and accuracy (Accuracy, ACC), are evaluated using the monitoring results, as shown in Table 1. Obviously, it can be seen that the anomaly detection model provided by the embodiments of the present application has better performance in detecting anomalies in data than the traditional time series monitoring model, and the accuracy has increased by 2.2%. At the same time, the reconstruction loss of each iteration round of the anomaly detection model provided by the embodiments of the present application during the training phase and the reconstruction loss of the corresponding iteration round during the validation phase are also given, as Figure 4 shown, obviously, it can be seen that the reconstruction losses corresponding to the anomaly detection model during the training phase and the validation phase are relatively small.
[0116] Precision Recall F1 Score Accuracy Traditional Time Series Monitoring Model 0.625 0.7143 0.6667 0.9565 TsF-LSTM-AE 0.8182 0.75 0.7826 0.9783
[0117] Table 1
[0118] Next, an information processing method for monitoring financial data in a data warehouse provided by an embodiment of the present application will be described with a realizable scenario.
[0119] With the rapid development of enterprise business, data has become a crucial asset for enterprises. To fully explore the value of data assets, enterprise-level data warehouses have emerged. An enterprise-level data warehouse is used to manage and organize various types of data involved in the daily business of an enterprise, and it is a subject-oriented, integrated, and continuously changing data set over time. An enterprise-level data warehouse generally includes parts such as a data source, data storage and management, data analysis, and a front-end platform. Among them, the data storage and management module is the core, which is responsible for extracting data from the data source system, performing cleaning, transformation, and integration operations, and organizing and managing data according to data themes, providing strong support for the analysis and decision-making of enterprises. Therefore, the data quality in the data storage and management module largely determines the application value of the data warehouse, and financial data, as a key component among them, reflects various indicators and quality levels of enterprise economic activities.
[0120] At the same time, the rapid growth of enterprise data volume and the continuous improvement of data complexity have brought new challenges to the management and maintenance of data warehouses. Under the relevant technical conditions, the monitoring means of data warehouse financial data mainly rely on data inspection methods based on fixed rules or thresholds, and this method highly depends on the background experience of developers in business and data content. Moreover, once new financial indicator data appears, the original rules are often difficult to adapt, bringing difficulties to automated monitoring.
[0121] To solve the above problems, an embodiment of the present application proposes an information processing method for monitoring financial data in a data warehouse that integrates tsfresh automatic feature extraction and Long Short Term Memory Auto-Encoder (LSTM-AE) prediction. The method includes:
[0122] The first step: Based on the financial fields to be monitored in the data warehouse (corresponding to the above-mentioned monitoring parameters), obtain the historical data time series of the financial fields (corresponding to the above-mentioned sample data); according to the dimensional fields (i.e., the field values of the financial fields) of the financial fields to be monitored and the data update time, screen the historical data time series to obtain the data of each dimensional field f i in the financial fields to be monitored (corresponding to the sample sub-data of each dimensional parameter above).
[0123] The second step is to perform a sliding window process on the data of each dimensional field f i to construct a time series record sequence In an enterprise-level data warehouse, data such as commodity prices, turnover, and profit margins usually have certain regularities. Therefore, tsfresh can be used to automatically extract features from time series record sequences to generate an initial feature group F (corresponding to the initial reference feature sequence mentioned above); according to the correlation magnitude, features are screened to obtain the top S (such as 50) features ranked by importance, which form a feature group (corresponding to the sample sub-data reference feature sequence). To further explore feature information and improve model performance, PCA analysis is used to process the feature group, thereby further exploring the information of various features. Thus, a feature construction and processing method that does not rely on prior experience is constructed to improve the applicability of the anomaly detection method in data warehouse operation and maintenance. In this way, by using tsfresh to extract and construct a feature group, a rich feature set is automatically extracted from the time series data in the data warehouse, saving the time of manual feature engineering and providing a consistent feature extraction and selection process, which helps to improve the generalization ability of the model. Based on PCA analysis and mining of the effective information in the rich feature data, the model effect and performance are further optimized.
[0124] In the third step, the data under each dimensional field f i is concatenated with the corresponding feature group to obtain the feature data sequence under each dimensional field f i as the input data sequence of the anomaly detection model. It should be noted that parameters such as the step size of the feature data sequence need to be set to form a fixed-length input data sequence set as the training data set.
[0125] In the fourth step, an anomaly detection model based on LSTM-AE is constructed. Among them, an encoding module (encoder) and a decoding module (decoder) are constructed based on LSTM. The encoder obtains the input data sequence under each dimensional field as a fixed-size input vector, and uses the memory unit of LSTM to combine the dependencies between multiple data points in the time series to encode the input vector under each dimensional field to obtain an intermediate hidden state vector, which can be a low-dimensional feature vector. Further, the decoder reconstructs the input sequence data with a fixed size from the intermediate hidden state vector to obtain the reconstructed sequence data under each dimensional field; based on the reconstructed sequence data and the input data sequence, through a loss function, the mean square error under each dimensional field is calculated, and the average value of the mean square errors under all dimensional fields is used as the reconstruction error (corresponding to the reconstruction loss mentioned above), and the model parameters of the anomaly detection model are iteratively updated using stochastic gradient descent. In this way, based on the LSTM-AE model architecture, the long-term dependencies between data are captured, and by evaluating the reconstruction error of the time series data, the autoencoder automatically determines the optimal threshold, improving the efficiency and reducing the bias of manually setting the threshold. This method reduces the dependence on manual intervention and enhances the accuracy and reliability of the model in anomaly detection.
[0126] In the fifth step, the reconstruction error is used to generate an anomaly threshold for detecting data (i.e., the field values of the monitored financial fields) under the corresponding dimensional fields. This anomaly threshold constructs a field value anomaly warning check function. If the actual field value in the data warehouse exceeds the predicted field value range, the corresponding data is recorded as abnormal data, connected to the data warehouse, and the abnormal data is written into the abnormal data table.
[0127] Here, for the set of reconstruction errors under each dimensional field in the training dataset, the maximum reconstruction error in the set of reconstruction errors under each dimensional field is used as the anomaly threshold for anomaly detection. If the reconstruction error exceeds this anomaly threshold, it is judged as abnormal data.
[0128] Here, an abnormal data result set is constructed. According to the data refresh frequency and actual needs, a timed monitoring scheduling mechanism is set. Whenever the monitoring is started, new field data records are pulled in regularly and input into the anomaly detection model to generate a flag indicating whether the data corresponding to each dimensional field actually updated in the data warehouse is abnormal (corresponding to the above detection result, marked as 1, the detection result is abnormal, marked as 0, the detection result is normal). Among them, the flag indicating whether the data corresponding to each dimensional field is abnormal can be marked by formula (1). Further, if the actually updated data in the data warehouse contains an abnormal flag, the corresponding data is recorded as abnormal data, connected to the data warehouse, the abnormal data is written into the abnormal data table, an abnormal value warning document is generated, the abnormal data table is synchronously updated, an abnormal value warning document is generated, and the corresponding person in charge is notified in the form of email, etc., to monitor data problems in a timely manner. By querying the data information in the abnormal data table, the relevant responsible persons for each abnormal data in the abnormal data table are obtained, and an abnormal alarm message is triggered, and the abnormal data entry and data reference range are sent to the responsible person for timely processing. Ensure the data quality of the data warehouse.
[0129] Here, for the information processing method for monitoring the financial data in the data warehouse that integrates tsfresh automatic feature extraction and LSTM-AE prediction, the algorithm logic is as follows:
[0130]
[0131] Among them, F is the data time series obtained from the data warehouse, X is the data used for input into the LSTM-AE model after windowing processing and automatic feature extraction, H is the intermediate result encoded by the encoder module, X' is the data reconstructed by the decoder module based on the encoding result, Loss is the loss used to update the model parameters for each batch, R is the reconstruction error, a is the anomaly threshold based on the set of reconstruction errors, and A is the set of abnormal data.
[0132] As can be seen from the above, the embodiments of the present application provide a general-purpose automatic monitoring mechanism that does not rely on existing experience. Tsfresh is used to extract features from financial data, fully considering the seasonality and regularity of financial data, and mining rich feature information from it. Then, the LSTM-AE model is introduced to model the financial data and its trend changes, infer the abnormal threshold of the data, so as to effectively judge the data interval, capture and alarm abnormal data, help developers control the data quality, and realize the intelligent operation and maintenance of data quality. At the same time, the information processing method provided by the embodiments of the present application has high generality and scalability, and can easily adapt to various tables and data sets in the data warehouse. This method provides a comprehensive processing flow, from data source monitoring to automatically sending emails to notify relevant responsible persons, ensuring timely response to abnormal situations, realizing automation from data monitoring to notification and alarm, and improving the efficiency of data processing and the accuracy of abnormal response.
[0133] Embodiments of the present application provide an information processing device. Refer to Figure 5 As shown, the information processing device 5 includes:
[0134] An obtaining unit 501, configured to obtain the data to be detected including at least two monitoring parameters;
[0135] A detecting unit 502, configured to input the data to be detected into an anomaly detection model, detect whether the sub-data corresponding to each dimension parameter is abnormal, and obtain a detection result;
[0136] Wherein, the sub-data corresponding to the dimension parameter is obtained by classifying and counting the data to be detected according to the parameter value dimension of the monitoring parameter;
[0137] Wherein, the detection result is determined based on the abnormal threshold corresponding to each dimension parameter, and the abnormal threshold is obtained by the anomaly detection model according to the sample data.
[0138] Based on the foregoing embodiments, embodiments of the present application provide an electronic device. Refer to Figure 6 As shown, the electronic device 6 includes: a processor 601 and a memory 602, wherein,
[0139] The memory 602 stores a computer program that can run on the processor 601;
[0140] The processor 601 executes the computer program stored in the memory 602 to implement the following steps:
[0141] Obtain the data to be detected including at least two monitoring parameters;
[0142] Input the data to be detected into an anomaly detection model, detect whether the sub-data corresponding to each dimension parameter is abnormal, and obtain a detection result;
[0143] Among them, the sub-data corresponding to the dimension parameter is obtained by classifying and counting the data to be detected according to the parameter value dimension of the monitoring parameter.
[0144] Among them, the detection result is determined based on the anomaly threshold corresponding to each dimension parameter, and the anomaly threshold is obtained by the anomaly detection model according to the sample data.
[0145] The method provided by the embodiment of the present application can be directly embodied as a software module combination executed by the processor 601. The software module can be located in the storage medium, and the storage medium is located in the memory 602. The processor 601 reads the executable instructions included in the software module in the memory 602 and combines the necessary hardware to complete the method provided by the embodiment of the present application.
[0146] As an example, the processor 601 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor can be a microprocessor or any conventional processor, etc.
[0147] It should be noted that for the specific implementation process of the steps executed by the processor in this embodiment, reference can be made to the steps in the method provided in the above embodiment, which will not be elaborated here.
[0148] The embodiment of the present application provides a storage medium that stores a computer program. When the computer program is executed by at least one processor, it implements the steps in the method provided in the above embodiment, which will not be elaborated here.
[0149] The embodiment of the present application provides a computer program product, including a computer program or instruction. When the computer program or instruction is executed by the processor, it implements the steps in the method provided in the above embodiment, which will not be elaborated here.
[0150] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a hardware embodiment, a software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) that contain computer-usable program code.
[0151] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the functions specified in one or more flows Figure 1 or more flows and / or blocks Figure 1 or means for realizing the functions specified in one or more blocks.
[0152] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means realizes the functions specified in one or more flows Figure 1 or more flows and / or blocks Figure 1 or means for realizing the functions specified in one or more blocks.
[0153] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for realizing the functions specified in one or more flows Figure 1 or more flows and / or blocks Figure 1 or means for realizing the functions specified in one or more blocks.
[0154] As mentioned above, it is only a preferred embodiment of the present application and is not used to limit the protection scope of the present application.
Claims
1. An information processing method, the method comprising: Obtaining data to be detected including at least two monitoring parameters; Inputting the data to be detected into an anomaly detection model to detect whether the sub-data corresponding to each dimension parameter is abnormal, and obtaining the detection result; Wherein, the sub-data corresponding to the dimension parameter is obtained by classifying and counting the data to be detected according to the parameter value dimension of the monitoring parameter; Wherein, the detection result is determined based on the anomaly threshold corresponding to each dimension parameter, and the anomaly threshold is obtained by the anomaly detection model according to the sample data.
2. The method according to claim 1, the determination of the anomaly detection model includes: Using the anomaly detection model to be trained to preprocess the sample data to obtain a sample sub-data sequence of each dimension parameter; wherein, the sample sub-data sequence includes sample sub-data corresponding to different time points; Performing feature processing on the sample sub-data corresponding to each time point in the sample sub-data sequence to obtain a sample sub-data reference feature sequence of the dimension parameter; Fusing the sample sub-data at each time point in the sample sub-data sequence with the sample sub-data reference feature corresponding to the same time point in the sample sub-data reference feature sequence to obtain a sample sub-data feature sequence of the dimension parameter; Encoding and reconstructing the sample sub-data feature sequence to obtain a reconstructed sample sub-data feature sequence of the dimension parameter; Based on the reconstructed sample sub-data feature sequence and the sample sub-data feature sequence, adjusting the network parameters of the anomaly detection model to be trained so that the trained anomaly detection model meets the convergence condition.
3. The method according to claim 2, the adjusting the network parameters of the anomaly detection model to be trained based on the reconstructed sample sub-data feature sequence and the sample sub-data feature sequence so that the trained anomaly detection model meets the convergence condition includes: Based on the difference between the sample sub-data feature at each time point in the sample sub-data feature sequence and the reconstructed sample sub-data feature corresponding to the same time point in the reconstructed sample sub-data feature sequence, determining the reconstruction loss corresponding to each time point under the dimension parameter, thereby obtaining a reconstruction loss sequence of the dimension parameter; Performing fusion processing on the reconstruction losses in the reconstruction loss sequence to obtain the target loss of the dimension parameter; adjusting the network parameters of the anomaly detection model to be trained according to the target losses of each dimension parameter.
4. The method according to claim 3, the anomaly detection model is trained for at least multiple rounds, and the method further includes: Obtaining the reconstruction loss sequence of the dimension parameter in each round of training process of the anomaly detection model, thereby obtaining multiple reconstruction loss sequences; Determining the maximum reconstruction loss based on the multiple reconstruction loss sequences and using it as the anomaly threshold of the dimension parameter.
5. The method according to any one of claims 2 to 4, the preprocessing the sample data to obtain a sample sub-data sequence corresponding to each dimension parameter respectively includes: Classify and statistically analyze the sample data according to the monitoring parameter value dimension respectively to obtain sample sub-data corresponding to each dimension parameter; For the sample sub-data corresponding to each dimension parameter, intercept the sample sub-data by using a preset time window to obtain a sample sub-data sequence corresponding to the dimension parameter; wherein, the sample sub-data sequence includes sample sub-data corresponding to different time series points.
6. The method according to any one of claims 2 to 4, wherein the performing feature processing on the sample sub-data corresponding to each time series point in the sample sub-data sequence respectively to obtain a sample sub-data reference feature sequence of the dimension parameter includes: Performing feature extraction on the sample sub-data corresponding to each time series point in the sample sub-data sequence respectively to obtain an initial reference feature sequence of the dimension parameter; Performing feature screening on the initial reference features according to the correlation between each initial reference feature in the initial reference feature sequence and the sample processing result, wherein the sample data includes the sample processing result; Performing feature dimensionality reduction on the screened initial reference features to obtain the sample sub-data reference feature sequence.
7. The method according to any one of claims 2 to 4, wherein the encoding and reconstruction of the sample sub-data feature sequence to obtain a reconstructed sample sub-data feature sequence of the dimension parameter includes: Sequentially encoding the sample sub-data features in the sample sub-data feature sequence according to the time series point order to obtain intermediate hidden state vectors; The intermediate hidden state vectors represent the dependency relationships between the sample sub-data features corresponding to each time series point in the sample sub-data feature sequence of the dimension parameter; Sequentially performing data reconstruction on each of the intermediate hidden state vectors according to the time series point order to obtain a reconstructed sample sub-data feature sequence corresponding to the dimension parameter.
8. The method according to any one of claims 1 to 4, wherein the detecting whether the sub-data corresponding to each dimension parameter is abnormal to obtain the detection result includes: Using the anomaly detection model to process the sub-data corresponding to the dimension parameter to obtain target reconstruction losses corresponding to each dimension parameter; Obtaining the detection result based on the target reconstruction loss and the anomaly threshold corresponding to the dimension parameter.
9. An information processing device, the device includes: An obtaining unit, configured to obtain data to be detected including at least two monitoring parameters; A detecting unit, configured to input the data to be detected into an anomaly detection model to detect whether the sub-data corresponding to each dimension parameter is abnormal and obtain the detection result; wherein the sub-data corresponding to the dimension parameter is obtained by classifying and statistically analyzing the data to be detected according to the parameter value dimension of the monitoring parameter; wherein the detection result is determined based on the anomaly threshold corresponding to each dimension parameter, and the anomaly threshold is obtained by the anomaly detection model according to the sample data.
10. An electronic device, the electronic device comprising: A processor and a memory; The memory stores a computer program that can run on the processor; The processor executes the computer program stored in the memory to implement the information processing method according to any one of claims 1 to 8.
Citation Information
Cited By
Abnormality processing method and device, storage medium, electronic equipment and product
CN122022992A