Training method of anomaly recognition model, anomaly recognition method, equipment and medium

By converting time series data into picture form for feature extraction, the calculation burden and inefficiency caused by manual feature engineering and complex components in the prior art are solved, and efficient abnormal identification is achieved.

CN120337073APending Publication Date: 2025-07-18ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510442814.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

When using models for abnormal identification, the prior art requires manual feature engineering and complex components such as self-attention mechanisms and memory networks, resulting in increased computational burden, reduced processing efficiency, and difficulty in capturing timing relationships, affecting the accuracy and efficiency of the model.

Method used

Map time series data into pixel values to generate picture form, extract and identify feature through exception recognition model, avoid manual feature engineering and complex components, simplify data structures, and reduce computational burden.

Benefits of technology

The model's learning ability and processing efficiency of timing relationships is improved, accurate exception recognition is achieved, and computational burden is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337073A_ABST
    Figure CN120337073A_ABST
Patent Text Reader

Abstract

The invention provides a training method of an anomaly recognition model, an anomaly recognition method, equipment and a medium. The method comprises the following steps: acquiring a plurality of pieces of time sequence data of a sample object in a sample time period, mapping the value of each piece of time sequence data into a pixel value, and generating a sample picture of which the pixel point arrangement sequence is matched with the time arrangement sequence according to the time arrangement sequence of the plurality of pieces of time sequence data and the corresponding pixel value; inputting the sample picture into an exception recognition model to enable the exception recognition model to perform feature extraction on the sample picture to obtain picture features, and performing exception recognition based on the picture features to obtain a prediction recognition result of the sample object; and training the anomaly recognition model based on the difference between the prediction recognition result and the real recognition result of the sample object, wherein the prediction recognition result and the real recognition result are used for identifying whether the sample object is abnormal or not.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of this specification relate to the field of artificial intelligence technology, and in particular, to a method for training an anomaly recognition model, an anomaly recognition method, a device, and a medium. Background Art

[0002] With the continuous development of artificial intelligence technology, using models for anomaly recognition has been applied in various industries. For example, there are various application scenarios such as using models to identify abnormal trading accounts and using models to identify whether a device is abnormal. However, using models for anomaly recognition still faces several challenges and limitations in practical applications.

[0003] For example, in order to improve the model's learning ability for the dynamic changes of time series data and thus achieve more accurate anomaly recognition, in addition to integrating complex components such as self-attention mechanisms and memory networks into the model architecture, it is also necessary to provide the model with long time series data as input. However, this method greatly increases the computational burden, resulting in a significant reduction in the processing efficiency of the model. Summary of the Invention

[0004] In view of this, one or more embodiments of this specification provide the following technical solutions:

[0005] According to a first aspect of one or more embodiments of this specification, a method for training an anomaly recognition model is proposed, and the method includes:

[0006] Obtain multiple time series data of a sample object within a sample time period, map the values of each time series data to pixel values, and generate a sample image with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple time series data and the corresponding pixel values;

[0007] Input the sample image into the anomaly recognition model, so that the anomaly recognition model extracts image features from the sample image, and performs anomaly recognition based on the image features to obtain a predicted recognition result of the sample object;

[0008] Train the anomaly recognition model based on the difference between the predicted recognition result and the true recognition result of the sample object, where the predicted recognition result and the true recognition result are used to indicate whether the sample object has an anomaly.

[0009] According to a second aspect of one or more embodiments of this specification, an anomaly recognition method is proposed, and the method includes:

[0010] Obtain multiple pieces of time-series data of a target object within a target time period, map the values of each piece of time-series data to pixel values, and generate a target image with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series data and the corresponding pixel values;

[0011] Input the target image into a pre-trained anomaly recognition model, so that the anomaly recognition model extracts image features from the target image, performs anomaly recognition based on the image features, and obtains a predicted recognition result of the target object, where the predicted recognition result is used to identify whether the target object has an anomaly.

[0012] According to a third aspect of one or more embodiments of this specification, an electronic device is proposed, including: a processor; a memory for storing processor-executable instructions; wherein, the processor realizes the steps of the method as described in the first aspect or the second aspect above by running the executable instructions.

[0013] According to a fourth aspect of one or more embodiments of this specification, a computer-readable storage medium is proposed, on which computer instructions are stored, and when the instructions are executed by a processor, the steps of the method as described in the first aspect or the second aspect above are realized.

[0014] According to a fifth aspect of one or more embodiments of this specification, a computer program product is proposed, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps of the method as described in the first aspect or the second aspect above are realized.

[0015] As can be seen from the above embodiments, this specification maps the values of each piece of time-series data to pixel values, and generates a sample image according to the time arrangement order of the multiple pieces of time-series data and the corresponding pixel values, so that the arrangement order of pixel points matches the time arrangement order of the time-series data, realizing the conversion of time-series data into a picture form. This conversion not only retains the potential time-series relationship in the time-series data, but also the model can directly extract this potential time-series relationship from the picture without integrating complex components such as self-attention mechanisms and memory networks into the model architecture. And this conversion also simplifies the data structure of the time-series data, thereby effectively reducing the amount of input data and reducing the computational burden. In this way, both the learning ability of the model for time-series relationships and the processing efficiency of the model are improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 is a schematic diagram of the architecture of an anomaly recognition service system provided by an exemplary embodiment.

[0017] Figure 2 is a flowchart of a training method for an anomaly recognition model provided by an exemplary embodiment.

[0018] Figure 3 It is a schematic structural diagram of an anomaly recognition model provided by an exemplary embodiment.

[0019] Figure 4 It is a flowchart of a training method for an anomaly recognition model in a transaction recognition scenario provided by an exemplary embodiment.

[0020] Figure 5 It is a schematic diagram of a pictorial dataset provided by an exemplary embodiment.

[0021] Figure 6 It is a flowchart of an anomaly recognition method provided by an exemplary embodiment.

[0022] Figure 7 It is a schematic structural diagram of a device provided by an exemplary embodiment.

[0023] Figure 8 It is a block diagram of a training device for an anomaly recognition model provided by an exemplary embodiment.

[0024] Figure 9 It is a block diagram of an anomaly recognition device provided by an exemplary embodiment. Detailed implementation manners

[0025] The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this specification are all information and data authorized by the user or fully authorized by all parties. And the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or refuse.

[0026] With the continuous development of artificial intelligence technology, using models for anomaly recognition has been applied in various industries. For example, there are various application scenarios such as using models to identify abnormal trading accounts and using models to identify whether a device is abnormal. However, using models for anomaly recognition still faces several challenges and limitations in actual applications.

[0027] For example, when using a machine learning-based model for anomaly detection, technicians often need to manually perform feature engineering. Since manual feature engineering relies on experts' profound understanding of the domain and their keen insight into data, this means that for different application scenarios, domain experts may need to customize the design of feature extraction methods, increasing the complexity and cost of the project. In addition, since the features designed manually are difficult to cover all potential data patterns, the performance of the model may be limited. It can be seen that manual feature engineering is not only time-consuming but also requires profound professional knowledge, restricting the model development efficiency and scalability.

[0028] Another example is that when dealing with time-series data, traditional machine learning-based models (such as decision tree models) often fail to capture the potential time-series relationships in the input data, making it difficult to achieve accurate anomaly detection. To improve the model's learning ability for the dynamic changes in time-series data and thus achieve more accurate anomaly detection, in addition to integrating complex components such as self-attention mechanisms and memory networks into the model architecture, it is also necessary to provide the model with long time-series data as input. However, this method greatly increases the computational burden, resulting in a significant reduction in the processing efficiency of the model.

[0029] Based on this, this specification provides a training method for an anomaly detection model, which can learn the potential time-series relationships in time-series data and achieve accurate anomaly detection without technicians manually performing feature engineering, without integrating complex components such as self-attention mechanisms and memory networks into the model, and without providing the model with long time-series data as input.

[0030] In implementation, first, obtain multiple time-series data of a sample object within a sample time period, map the values of each time-series data to pixel values, and generate a sample image with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple time-series data and the corresponding pixel values; then, input the sample image into the anomaly detection model so that the anomaly detection model extracts image features from the sample image, and performs anomaly detection based on the image features to obtain the predicted detection result of the sample object; finally, train the anomaly detection model based on the difference between the predicted detection result and the true detection result of the sample object, where the predicted detection result and the true detection result are used to identify whether the sample object has an anomaly.

[0031] In the above technical solution, by mapping the values of each piece of time-series data to pixel values and generating a sample image according to the time arrangement order of multiple pieces of time-series data and the corresponding pixel values, the arrangement order of pixel points is matched with the time arrangement order of time-series data, realizing the conversion of time-series data into a picture form, thus avoiding the need for technicians to manually perform feature engineering. Moreover, this conversion not only preserves the potential time-series relationship in the time-series data, but also the model can directly extract this potential time-series relationship from the picture without integrating complex components such as self-attention mechanisms and memory networks into the model architecture. Furthermore, this conversion simplifies the data structure of time-series data, thereby effectively reducing the amount of input data and lowering the computational burden. In this way, both the learning ability of the model for time-series relationships and the processing efficiency of the model are improved.

[0032] The anomaly recognition method provided in this specification can be applied to any scenario that requires anomaly recognition. This specification does not limit the application scenario and only takes the following scenarios as examples for illustrative purposes:

[0033] Exemplarily, it is applied to a transaction scenario:

[0034] As is well known, money laundering is a criminal act that poses a serious threat to financial security and social stability. The anomaly recognition method provided in this specification can be used to identify accounts involved in money laundering. For example, obtain multiple pieces of time-series transaction data of any account within a target time period, map the values of each piece of time-series transaction data to pixel values, generate a target image with the arrangement order of pixel points matching the time arrangement order according to the time arrangement order of multiple pieces of time-series transaction data and the corresponding pixel values, input the target image into the anomaly recognition model, so that the anomaly recognition model extracts image features from the target image, and perform anomaly recognition based on the image features to obtain the predicted recognition result of this account. This predicted recognition result is used to identify whether this account is involved in money laundering. Since the anomaly recognition method provided in this specification converts time-series transaction data into a picture form, it not only preserves the potential time-series relationship in the time-series transaction data, but also the model can directly extract this potential time-series relationship from the picture without integrating complex components such as self-attention mechanisms and memory networks into the model architecture, enabling the model to output a more accurate predicted recognition result. Moreover, this conversion simplifies the data structure of time-series data, thereby effectively reducing the amount of input data and lowering the computational burden. In this way, both the learning ability of the model for time-series relationships and the processing efficiency of the model are improved.

[0035] Of course, the anomaly recognition method provided in this specification can also be applied to the recognition of any abnormal behavior such as fraud recognition, credit risk recognition, and cash-out behavior recognition in a transaction scenario, and its predicted recognition result is used to identify whether there is an anomaly in the account.

[0036] Exemplarily, it is applied to the device monitoring scenario:

[0037] In the device monitoring scenario, the anomaly recognition method provided in this specification can monitor the operating state of a device, including but not limited to fault monitoring and energy consumption monitoring. For example, multiple pieces of sequential operation data of the device within a target time period are obtained, the values of each piece of sequential operation data are mapped to pixel values, and a sample image with a pixel point arrangement order matching the time arrangement order is generated according to the time arrangement order of the multiple pieces of sequential operation data and the corresponding pixel values; the sample image is input into the anomaly recognition model, so that the anomaly recognition model extracts image features from the sample image, and anomaly recognition is performed based on the image features to obtain a predicted recognition result of the sample object, and this predicted recognition result is used to identify whether the device is faulty or whether the device has abnormal energy consumption. Since the anomaly recognition method provided in this specification converts sequential operation data into a picture form, it not only retains the potential sequential relationship in the sequential operation data, but also the model can directly extract this potential sequential relationship from the picture, and without integrating complex components such as self-attention mechanisms and memory networks in the model architecture, the model can output a more accurate predicted recognition result. Moreover, this conversion also simplifies the data structure of the sequential data, thereby effectively reducing the amount of input data and reducing the computational burden. In this way, both the learning ability of the model for sequential relationships and the processing efficiency of the model are improved.

[0038] Exemplarily, it is applied to the health monitoring scenario:

[0039] In the health monitoring scenario, the anomaly recognition method provided in this specification can monitor the physiological characteristic data of a device. For example, multiple pieces of sequential physiological characteristic data of a user within a target time period are obtained, the values of each piece of sequential physiological characteristic data are mapped to pixel values, and a sample image with a pixel point arrangement order matching the time arrangement order is generated according to the time arrangement order of the multiple pieces of sequential physiological characteristic data and the corresponding pixel values; the sample image is input into the anomaly recognition model, so that the anomaly recognition model extracts image features from the sample image, and anomaly recognition is performed based on the image features to obtain a predicted recognition result of the sample object, and this predicted recognition result is used to identify whether the user is healthy. Since the anomaly recognition method provided in this specification converts sequential physiological characteristic data into a picture form, it not only retains the potential sequential relationship in the sequential physiological characteristic data, but also the model can directly extract this potential sequential relationship from the picture, and without integrating complex components such as self-attention mechanisms and memory networks in the model architecture, the model can output a more accurate predicted recognition result. Moreover, this conversion also simplifies the data structure of the sequential data, thereby effectively reducing the amount of input data and reducing the computational burden. In this way, both the learning ability of the model for sequential relationships and the processing efficiency of the model are improved.

[0040] It should be noted that this specification only provides an exemplary description of the application scenarios and does not limit the application scenarios. The methods provided in this specification can also be applied to network security scenarios to identify whether abnormal events occur in the network; they can also be applied to stock market monitoring scenarios to identify whether the stock market fluctuates abnormally or whether there are potential market manipulation behaviors.

[0041] In an illustrated embodiment, the execution subject of the method provided in this specification is an electronic device. The electronic device can be a mobile terminal such as a mobile phone, a tablet device, a personal digital assistant (PDA), a wearable device (such as smart glasses, smart watches, etc.), and this specification does not limit this.

[0042] In another illustrated embodiment, the execution subject of the method provided in this specification is a server. The server can be a physical server including an independent host, or the server can be a virtual server hosted by a host cluster. In another illustrated embodiment, the execution subject of the method provided in this specification is an abnormal recognition service system, and this system can be Figure 1 the system shown.

[0043] Figure 1 It is a schematic diagram of the architecture of an abnormal recognition service system provided by an exemplary embodiment. As Figure 1 shown, the system can include a server 11, a network 12, and several electronic devices, such as a personal computer (PC) 13, a mobile phone 14, etc.

[0044] The server 11 can be a physical server including an independent host, or the server 11 can be a virtual server hosted by a host cluster. During operation, the server 11 can run the server-side program of a certain application to implement the related functions of the application. For example, when the server 11 runs the program of the abnormal recognition service, it can be implemented as a corresponding abnormal recognition service platform.

[0045] PC 13 and mobile phone 14 are only some types of electronic devices that users can use. In fact, users can obviously also use electronic devices such as the following types: tablet devices, laptop computers, personal digital assistants (PDAs), wearable devices (such as smart glasses, smart watches, etc.). One or more embodiments of this specification do not limit this. During operation, the electronic device can run the program on the client side of a certain application to implement the related functions of the application. For example, when the electronic device runs the program of the anomaly recognition service, it can be implemented as the client of the anomaly recognition service. Among them, the application program of the client side of the above anomaly recognition service can be started and run on the electronic device. The program on the client side can be a native application installed on the electronic device, or the program on the client side can be a mini program, a fast application or other similar forms. Of course, when using web technologies such as HTML5 or similar, the related functions can be implemented through the page displayed by the browser. Here, the browser can be an independent browser application or a browser module embedded in some applications.

[0046] Regarding the network 12 for the interaction between electronic devices such as PC 13 and mobile phone 14 and the server 11, it can be specifically selected to use wired or wireless networks to achieve communication based on the communication methods supported by the corresponding electronic devices. This specification does not limit this. For example, PC 13 can support both wired and wireless communications, so wired or wireless networks can be used for communication according to needs, while mobile phone 14 usually only supports wireless communication, so wireless networks can be used for communication.

[0047] Exemplarily, the training method of the anomaly recognition model provided by the embodiments of this specification can be executed by any one of the above-mentioned client or the above-mentioned server. For example, the server obtains multiple pieces of time-series data of a sample object within a sample time period, maps the values of each piece of time-series data to pixel values, generates a sample picture with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series data and the corresponding pixel values, inputs the sample picture into the anomaly recognition model, so that the anomaly recognition model extracts picture features from the sample picture, performs anomaly recognition based on the picture features, and obtains the predicted recognition result of the sample object; trains the anomaly recognition model based on the difference between the predicted recognition result and the true recognition result of the sample object.

[0048] Exemplarily, the training method of the anomaly recognition model provided by the embodiments of this specification can be completed through the cooperation of the above-mentioned client and the above-mentioned server. For example, the client collects multiple pieces of time-series data of a sample object within a sample time period and uploads the multiple pieces of time-series data to the server; the server maps the value of each piece of time-series data to a pixel value, generates a sample picture with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series data and the corresponding pixel values, inputs the sample picture into the anomaly recognition model so that the anomaly recognition model extracts features from the sample picture to obtain picture features, performs anomaly recognition based on the picture features to obtain the predicted recognition result of the sample object; and trains the anomaly recognition model based on the difference between the predicted recognition result and the true recognition result of the sample object.

[0049] Similarly, the anomaly recognition method provided by the embodiments of this specification can be executed by any one of the above-mentioned client or the above-mentioned server.

[0050] For example, deploy the anomaly recognition model to the client. The client obtains multiple pieces of time-series data of a target object within a target time period, maps the value of each piece of time-series data to a pixel value, generates a target picture with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series data and the corresponding pixel values, and inputs the target picture into the anomaly recognition model to obtain the predicted recognition result of the target object. Another example is to deploy the anomaly recognition model to the server. The server obtains multiple pieces of time-series data of a target object within a target time period, maps the value of each piece of time-series data to a pixel value, generates a target picture with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series data and the corresponding pixel values, and inputs the target picture into the anomaly recognition model to obtain the predicted recognition result of the target object.

[0051] The anomaly recognition method provided by the embodiments of this specification can be realized through the cooperation of the above-mentioned client and the above-mentioned server. Exemplarily, the client collects multiple pieces of time-series data of a target object within a target time period and uploads the multiple pieces of time-series data to the server; the server maps the value of each piece of time-series data to a pixel value, generates a target picture with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series data and the corresponding pixel values, and inputs the target picture into the anomaly recognition model to obtain the predicted recognition result of the target object.

[0052] It should be noted that this specification only exemplarily describes the cooperation method between the client and the server and does not limit it. The specific cooperation method can be set arbitrarily according to actual needs.

[0053] Next, this specification gives an exemplary description of the training process of the anomaly recognition model:

[0054] Figure 2 is a flowchart of a method for training an anomaly recognition model provided by an exemplary embodiment. The execution subject of this method can be Figure 1 the system shown, or any device. This specification does not limit this. The method includes:

[0055] S201, obtain multiple pieces of time series data of a sample object within a sample time period, map the values of each piece of time series data to pixel values, and generate a sample picture with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time series data and the corresponding pixel values.

[0056] Among them, the sample object can be any object. For example, the sample object can be any user, any user account, any device, any stock, etc. This specification does not limit the sample object. In one embodiment, the type of the sample object can be different in different application scenarios. Exemplarily, in the transaction recognition scenario, the sample object is any user account; in the health monitoring scenario, the sample object is any user; in the device monitoring scenario, the sample object is any device; in the stock market detection scenario, the sample object is any stock. That is to say, the type of the sample object can be set according to the requirements of the actual application scenario, and this specification does not limit the type of the sample object.

[0057] The sample time period can be any time period. For example, the sample time period can be the last minute before the current moment, or the last hour before the current moment, or the last day before the current moment, or the last week before the current moment, or the last month before the current moment, etc. This specification does not limit the sample time period. In one embodiment, the time length of the sample time period can be different in different application scenarios. Exemplarily, in the transaction recognition scenario, the sample time period can be the last week before the current moment, or the last month before the current moment. Exemplarily, in the health monitoring scenario, the sample time period can be the last minute before the current moment (for example, obtain the electrocardiogram of the user in the last minute), or the last week before the current moment (for another example, obtain the blood pressure of the user in the last week). That is to say, the time length of the sample time period can be set according to the requirements of the actual application scenario, and this specification does not limit the sample time period.

[0058] Multiple time series data refers to multiple continuous or discrete data sequences collected for a sample object within a sample time period. Each time series data is associated with a specific time and can reflect the dynamic change characteristics of the sample object in the time dimension. In one embodiment, in different application scenarios, the data content of the time series data can be different. Exemplarily, in a transaction recognition scenario, the time series data is time series transaction data, which is the transaction record of any user account at any moment. Exemplarily, in a health monitoring scenario, the time series data is time series physiological feature data, which is the physiological feature data of any user at any moment. Exemplarily, in a device monitoring scenario, the time series data is time series operation data, which is the operation data of any device at any moment. That is, the data content of the time series data can be set according to the requirements of the actual application scenario, and this specification does not limit the data content of the time series data.

[0059] In one embodiment, the multiple time series data can be sourced from system logs, monitoring devices, sensors, or other data collection means, and this specification does not limit this. In one embodiment, the time series data includes two parts: a timestamp and the corresponding observed value, and this observed value is the value of the time series data. Of course, the time series data can also include more or less content, and this specification does not limit the data structure of the time series data.

[0060] In this specification, any numerical mapping method can be adopted to map the values of each time series data to pixel values. Exemplarily, the standard normalization method is adopted to map the values of each time series data to pixel values. For example, using the standard normalization method, the values of each time series data are mapped to the numerical range of 0 to 255 to obtain the pixel values corresponding to each time series data. Exemplarily, the piecewise linear mapping method is adopted to map the values of each time series data to pixel values. For example, the value range of the time series data is divided into multiple intervals, and each interval corresponds to a fixed pixel value. By determining the interval to which the value of each time series data belongs, the value of each time series data is mapped to the pixel value corresponding to the corresponding interval. Exemplarily, the logarithmic transformation method is adopted to map the values of each time series data to pixel values. For example, for time series data with a large value range and uneven distribution, the values of each time series data can be logarithmically transformed first, and then the standard normalization method is used to map the logarithmically transformed values to the numerical range of 0 to 255 to obtain the pixel values corresponding to each time series data. Exemplarily, the exponential transformation method is adopted to map the values of each time series data to pixel values. For example, for time series data with a small value transformation, the values of each time series data can be exponentially transformed first, and then the standard normalization method is used to map the logarithmically transformed values to the numerical range of 0 to 255 to obtain the pixel values corresponding to each time series data.

[0061] It should be noted that this specification only exemplarily illustrates the numerical mapping method and does not limit it. Since the data content of time-series data in different application scenarios is different, the data characteristics of time-series data in different application scenarios are also different. Therefore, a suitable numerical mapping method can be selected according to the data characteristics of time-series data in the actual application scenario, and this specification does not limit it.

[0062] In this specification, when generating a sample image, it is necessary to ensure that the arrangement order of pixel points in the sample image matches the time arrangement order of the corresponding time-series data. That is to say, if time-series data A is arranged before time-series data B, then the pixel points corresponding to time-series data A are located before the pixel values corresponding to time-series data B; if time-series data C is arranged after time-series data D, then the pixel points corresponding to time-series data C are located after the pixel points corresponding to time-series data D.

[0063] In one embodiment, a sample image can be generated by generating a pixel value matrix. Among them, generating a sample image with the arrangement order of pixel points matching the time arrangement order according to the time arrangement order of multiple time-series data and the corresponding pixel values includes: arranging the pixel values corresponding to multiple time-series data into a pixel value matrix according to the time arrangement order of multiple time-series data, and converting the pixel value matrix into a picture form to obtain the sample image.

[0064] In another embodiment, a sample image can be generated by constructing a two-dimensional grid. Among them, generating a sample image with the arrangement order of pixel points matching the time arrangement order according to the time arrangement order of multiple time-series data and the corresponding pixel values includes: constructing a two-dimensional grid, and sequentially filling the pixel values corresponding to the time-series data into the two-dimensional grid in the order of rows or columns according to the time arrangement order of multiple time-series data; converting the pixel values in the two-dimensional grid into a picture form to obtain the sample image. It should be noted that this specification only exemplarily illustrates the implementation manner of "generating a sample image with the arrangement order of pixel points matching the time arrangement order according to the time arrangement order of the multiple time-series data and the corresponding pixel values", and does not limit it. Any other method not mentioned in this specification can also be used to generate the sample image.

[0065] In one embodiment, the size of the sample image is fixed. Among them, the fixed size of the sample image means that the horizontal size and / or vertical size of the sample image is fixed. Exemplarily, both the horizontal size and the vertical size of the sample image are fixed. In this case, the number of multiple time-series data needs to match the size of the sample image, and the number of multiple time-series data is also fixed. That is to say, the number of multiple time-series data of sample object A in the sample time period is the same as the number of multiple time-series data of sample object B in the sample time period.

[0066] For example, if the sensor collects time-series data every 10 minutes, then the number of multiple time-series data of sample object A within a day is 144, and the number of multiple time-series data of sample object B within a day is also 144. Correspondingly, the size of the sample image can be 6*24, or 12*12, or 24*6, etc.

[0067] Another example is that the time-series data is time-series transaction data. As is well known, time-series transaction data is generated based on the transaction records of user accounts, and the number of transaction records of different user accounts is not the same. To make the number of multiple time-series data match the size of the sample image, the multiple time-series data can be aggregated. Exemplarily, obtaining multiple time-series data of a sample object within a sample time period includes: obtaining multiple original time-series data of the sample object within the sample time period; dividing the sample time period into multiple sub-time periods with equal time intervals, and performing statistical processing on the time-series data within each sub-time period to obtain the time-series data corresponding to each sub-time period. In this way, the number of time-series data of the sample object is the same as the number of sub-time periods of the sample time period, making the number of time-series data of different sample objects the same. Among them, the length of the sub-time period can be determined by the size of the sample image. For example, if the size of the sample image is 7*24 and the sample time period is 7 days, then the sub-time period can be one hour; another example is that if the size of the sample image is 12*12 and the sample time period is 12 days, then the sub-time period can be two hours.

[0068] Exemplarily, the horizontal size of the sample image is fixed, while the vertical size is not fixed. For example, generating a sample image with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of multiple time-series data and the corresponding pixel values includes: generating a row of pixel points with the pixel values corresponding to the first M time-series data according to the time arrangement order of multiple time-series data and the horizontal size of the sample image, and repeatedly executing to generate a row of pixel points with the pixel values corresponding to the first M time-series data among the remaining time-series data until the number of the remaining time-series data is 0. Among them, M is the horizontal size of the sample image. For example, if the size of the sample image is 7*24, where 7 is the vertical size of the sample image and 24 is the horizontal size of the sample image, then M is 24.

[0069] Exemplarily, the vertical dimension of the sample picture is fixed, while the horizontal dimension is not. For example, according to the time arrangement order of multiple time-series data and the corresponding pixel values, generating a sample picture whose pixel point arrangement order matches the time arrangement order includes: according to the time arrangement order of multiple time-series data and the vertical dimension of the sample picture, generating a column of pixel points from the pixel values corresponding to the first X time-series data, and repeatedly executing to generate a column of pixel points from the pixel values corresponding to the first X time-series data among the remaining time-series data until the number of the remaining time-series data is 0. Wherein, X is the horizontal dimension of the sample picture. For example, the size of the sample picture is 7*24, where 7 is the vertical dimension of the sample picture and 24 is the horizontal dimension of the sample picture, then X is 7.

[0070] In another embodiment, the size of the sample picture is not fixed and is determined based on the data attributes of the time-series data. Exemplarily, according to the time arrangement order of multiple time-series data and the corresponding pixel values, generating a sample picture whose pixel point arrangement order matches the time arrangement order includes: determining the size of the sample picture to be generated based on the data attributes of multiple time-series data; generating a sample picture whose pixel point arrangement order matches the time arrangement order according to the size of the sample picture to be generated, the time arrangement order of multiple time-series data, and the corresponding pixel values.

[0071] Exemplarily, the data attributes of multiple time-series data include the number of multiple time-series data. Determining the size of the sample picture to be generated based on the data attributes of multiple time-series data includes: determining the size of the sample picture to be generated based on the number of multiple time-series data. For example, determining the size of the sample picture to be generated based on the number of multiple time-series data includes: factorizing the number of multiple time-series data to obtain multiple groups of alternative values, each group of alternative values including a first value and a second value, and the product of the first value and the second value in a group of alternative values is the number of the multiple time-series data; selecting from the multiple groups of alternative values the group of alternative values with the smallest difference between the first value and the second value, taking the first value in this group of alternative values as the horizontal dimension of the sample picture, and taking the second value in this group of alternative values as the vertical dimension of the sample picture.

[0072] For another example, determining the size of the sample picture to be generated based on the number of multiple time-series data includes: taking the square root of the number of multiple time-series data, rounding up the value obtained by taking the square root to obtain a third value, and taking the third value as the horizontal dimension and the vertical dimension of the sample picture.

[0073] Exemplarily, the data attributes of multiple time series data include the periodic attributes of the multiple time series data. Determining the size of the sample picture to be generated based on the data attributes of the multiple time series data includes: determining the size of the sample picture to be generated based on the periodic attributes of the multiple time series data. For example, the periodic attributes of the multiple time series data include the number of periods of the multiple time series data and the number of time series data within one period. Determining the size of the sample picture to be generated based on the periodic attributes of the multiple time series data includes: using the number of periods of the multiple time series data as the horizontal size of the sample picture and the number of time series data within one period as the vertical size of the sample picture; or, using the number of periods of the multiple time series data as the vertical size of the sample picture and the number of time series data within one period as the horizontal size of the sample picture.

[0074] It should be noted that this specification only takes the data attributes as quantity and periodic attributes as examples to illustrate the data attributes exemplarily. Of course, the data attributes can also be other attributes, and this specification does not limit this. And this specification only exemplarily illustrates the process of determining the size of the sample picture. Of course, any method not mentioned in this specification can also be used to determine the size of the sample picture, and this specification does not limit this.

[0075] In an illustrated embodiment, the sample time period includes multiple periods. For example, the sample time period includes 3 periods, 5 periods, 7 periods, 10 periods, 30 periods, etc., and this specification does not limit the number of periods included in the sample time period. Optionally, the periods included in the sample time period can be time periods, and this time period can be years, months, days, hours, minutes, seconds, etc. In this case, the time series data can be periodic or non-periodic. Optionally, the time series data is periodic data, and the periods included in the sample time period can be the change periods of the time series data.

[0076] In one embodiment, when performing feature extraction on a picture, usually several adjacent pixel points are analyzed. If the pixel points corresponding to the same time node in different periods are located in the same row or the same column of the picture, then during the process of performing feature extraction, the change situation of the sample object across multiple periods at the same time node can be captured. Exemplarily, generating a sample picture with the pixel point arrangement order matching the time arrangement order according to the time arrangement order and the corresponding pixel values of the multiple time series data includes: for multiple time series data within the same period, generating a row of pixel points or a column of pixel points according to the time arrangement order and the corresponding pixel values of each time series data; arranging the row pixel points or column pixel points corresponding to each period in sequence to form a sample picture.

[0077] For example, the sample time period includes 7 cycles. According to the time arrangement order of multiple time series data and the corresponding pixel points in the first cycle, the first row of pixel points or the first column of pixel points is generated; according to the time arrangement order of multiple time series data and the corresponding pixel points in the second cycle, the second row of pixel points or the second column of pixel points is generated; according to the time arrangement order of multiple time series data and the corresponding pixel points in the third cycle, the third row of pixel points or the third column of pixel points is generated, and so on.

[0078] Of course, the time series data of one cycle can also generate multiple rows of pixel points or multiple columns of pixel points. In another embodiment, according to the time arrangement order of multiple time series data and the corresponding pixel values, a sample picture with a pixel point arrangement order matching the time arrangement order is generated, including: for multiple time series data within the same cycle, according to the time arrangement order of each time series data and the corresponding pixel values, two rows of pixel points or two columns of pixel points are generated; the two rows of pixel points or two columns of pixel points corresponding to each cycle are arranged in sequence to form a sample picture.

[0079] In another illustrated embodiment, the sample time period may also include only one cycle. In another illustrated embodiment, the sample time period may not include a complete cycle. This specification does not limit this. When the sample time period includes only one cycle, or the sample time period does not include a complete cycle, it is only necessary to generate a sample picture with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of multiple time series data and the corresponding pixel values.

[0080] In one illustrated embodiment, any piece of time series data includes N - dimensional values, where N is any positive integer. Exemplarily, the time series data is time series transaction data, and any piece of time series transaction data includes the values of 6 dimensions: income amount, transfer - out amount, number of income transactions, number of transfer - out transactions, number of income transaction counterparts, and number of transfer - out transaction counterparts. Exemplarily, the time series data is time series physiological characteristic data, and any piece of time series physiological characteristic data includes the values of 4 dimensions: heart rate, blood pressure, blood sugar, and blood oxygen.

[0081] When the time series data includes N - dimensional values, a channel of the sample picture can be generated for each dimensional value. Exemplarily, mapping the values of each piece of time series data to pixel values, and according to the time arrangement order of multiple time series data and the corresponding pixel values, generating a sample picture with a pixel point arrangement order matching the time arrangement order, including: mapping each dimensional value of each piece of time series data to a pixel value, obtaining N pixel values corresponding to each piece of time series data respectively, and according to the time arrangement order of multiple time series data and the corresponding N pixel values, generating an N - channel sample picture with a pixel point arrangement order matching the time arrangement order. Among them, the time series data corresponds one - to - one with the pixel points in the N - channel sample picture, and the pixel values of any pixel point in the N channels are respectively the N different pixel values corresponding to the corresponding time series data.

[0082] Exemplarily, the time-series data is time-series transaction data, and any piece of time-series transaction data includes values in six dimensions: income amount, transfer-out amount, number of income transactions, number of transfer-out transactions, number of income transaction counterparts, and number of transfer-out transaction counterparts. Map the income amounts in multiple pieces of time-series transaction data to first pixel values, and generate the first channel of a sample image with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series transaction data and the corresponding first pixel values; map the transfer-out amounts in multiple pieces of time-series transaction data to second pixel values, and generate the second channel of the sample image with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series transaction data and the corresponding second pixel values; map the number of income transactions in multiple pieces of time-series transaction data to third pixel values, and generate the third channel of the sample image with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series transaction data and the corresponding third pixel values, and so on, finally obtaining a 6-channel sample image.

[0083] It should be noted that this specification mentions multiple numerical mapping methods for mapping the values of time-series data to pixel values, and the adoption of the numerical mapping method can be determined according to the data characteristics of the time-series data. When the time-series data includes values in N dimensions, the data characteristics of the values in different dimensions may be different. Therefore, different data mapping methods can be adopted for the values in different dimensions, and this specification does not limit this.

[0084] In an illustrated embodiment, on the one hand, considering that the quantity of time-series data of some types of sample objects is unstable within the sample time period, and on the other hand, considering that if the quantity of time-series data is too large, the size of the generated sample image will be large and the amount of calculation generated will also be large, this specification provides a preprocessing method for time-series data. Among them, obtaining multiple pieces of time-series data of a sample object within the sample time period includes: obtaining multiple pieces of original time-series data of the sample object within the sample time period; dividing the sample time period into multiple sub-time periods with equal time intervals, and performing statistical processing on the time-series data within each sub-time period to obtain the time-series data corresponding to each sub-time period. This time interval can be any time interval, for example, 1 minute, 1 hour, etc.

[0085] Among them, the statistical processing can be any kind of statistical processing such as summation processing, averaging processing, maximum value processing, minimum value processing, etc. This specification does not limit the statistical processing. In one embodiment, different statistical processing methods can be adopted for different types of time-series data. Exemplarily, when the time-series data is time-series transaction data, the time-series transaction data within each sub-time period can be cumulatively summed to obtain the time-series transaction data corresponding to each sub-time period. Exemplarily, when the time-series data is time-series operation data, the maximum value time-series operation data or the minimum value time-series operation data within each sub-time period can be obtained to obtain the time-series operation data corresponding to each sub-time period.

[0086] In this specification, multiple time-series data of a sample object are converted into a picture form and then anomaly recognition is performed. In order to obtain a more accurate prediction and recognition result, when performing anomaly recognition, not only the time-series data of the sample object can be referred to, but also the static attribute data of the sample object can be referred to. In this way, the sample object can be analyzed more comprehensively, and then a more accurate prediction and recognition result can be obtained. Among them, the static attribute data is data that does not change with time. Exemplarily, taking the sample object as a user account, the static attribute data can be the registration time of the user account, the account type of the user account, etc. Exemplarily, taking the sample object as a user, the static attribute data can be the birthday, gender, etc. of the user.

[0087] Therefore, this specification also provides a method for converting multiple time-series data and static attribute data of a sample object into a picture form. In one shown implementation manner, a sample picture with a pixel point arrangement order matching the time arrangement order is generated according to the time arrangement order of the multiple time-series data and the corresponding pixel values, including: obtaining the static attribute data of the sample object, mapping the value of the static attribute data to a pixel value, and replicating the pixel value according to the number of the multiple time-series data; generating a first channel of the sample picture according to the time arrangement order of the multiple time-series data and the corresponding pixel values, with the pixel point arrangement order matching the time arrangement order; generating a second channel of the sample picture according to the replicated pixel values corresponding to the static attribute data.

[0088] Since time series data changes over time, the number of time series data is not the same as the number of static attribute data. Therefore, when generating a sample image based on time series data and static attribute data, not only will the values of the static attribute data be mapped to pixel values, but the pixel values will also be replicated according to the number of multiple time series data. The number of pixel values corresponding to the values of the time series data is the same as the number of pixel values corresponding to the values of the static attribute data. Thus, the first channel of the sample image can be generated based on the pixel values corresponding to the values of the time series data, and the second channel of the sample image can be generated based on the pixel values corresponding to the values of the static attribute data. In this way, when extracting features for any pixel point in the image subsequently, the image features can be comprehensively extracted from the time series data and the static attribute data, making the extracted image features more accurate.

[0089] It should be noted that the time series data can include N-dimensional values, and the static attribute data can include Z-dimensional values. When the time series data includes N-dimensional values and the static attribute data includes Z-dimensional values, each dimension value of each time series data is mapped to a pixel value to obtain N pixel values corresponding to each time series data respectively. According to the time arrangement order of multiple time series data and the corresponding N-dimensional values, N first channels of the sample image with the pixel point arrangement order matching the time arrangement order are generated; among them, the time series data corresponds one-to-one with the pixel points in the N first channels of the sample image, and the pixel values of any pixel point in the N first channels are respectively the N different pixel values corresponding to the corresponding time series data; each dimension value of the static attribute data is mapped to a pixel value to obtain Z pixel values corresponding to the static attribute data. For each of the Z pixel values, the pixel value is replicated according to the number of multiple time series data, and Z second channels of the sample image are generated according to the replicated pixel values corresponding to the static attribute data.

[0090] S202, input the sample image into the anomaly recognition model, so that the anomaly recognition model extracts image features from the sample image and performs anomaly recognition based on the image features to obtain the predicted recognition result of the sample object.

[0091] The anomaly recognition model is a model used to identify whether there is an anomaly in the input object. The anomaly recognition model can adopt any model structure, and this specification does not limit it. Only taking Figure 3 the shown anomaly recognition model as an example, the model structure of the anomaly recognition model is described exemplarily.

[0092] As Figure 3As shown, the model structure of the anomaly recognition model is a CNN (Convolutional Neural Network) based on a residual convolution module. The anomaly recognition model includes a linear embedding layer, Y residual convolution modules, and a fully connected layer. The sample image is input into the anomaly recognition model. The sample image first passes through the linear embedding layer to increase the dimension of the sample image, thereby enhancing the embedding expression ability of the anomaly recognition model. Exemplarily, the sample image is increased from 6 channels to 32 channels. Then, after the sample image is dimensionally increased, it enters Y residual convolution modules. Each residual convolution module is composed of a two-dimensional convolutional layer, an instance normalization layer, and a non-linear activation layer (such as ReLU) spliced together. It should be noted that Figure 3 the dashed line in

[0093] is used to represent the residual connection. That is, the output of the previous residual convolution module is used as the input of the next residual convolution module. This can effectively alleviate the problems of gradient disappearance and gradient explosion, and improve the convergence speed and stability of the anomaly recognition model. The output of the last residual convolution module is used as the input of the fully connected layer. The fully connected layer is used to expand and evaluate the image features (tensors) input by the last residual convolution module and then output the classification result. An output of 0 represents that the sample object has no anomaly, and an output of 1 represents that the sample object has an anomaly.

[0094] Among them, the anomaly recognition model extracts image features from the sample image, including: the anomaly recognition model performs a convolution operation on the sample image to obtain image features. Among them, the convolutional kernel of the convolution operation satisfies at least one of the following conditions:

[0095] (1) The size of the convolutional kernel is positively correlated with the size of the sample image.

[0096] That is, the larger the size of the sample image, the larger the size of the convolutional kernel. In this way, when the size of the sample image is large, fast convolution operations can still be performed, improving the running speed of the anomaly recognition model; the smaller the size of the sample image, the smaller the size of the convolutional kernel. In this way, the loss of details in the sample image can be avoided.

[0097] (2) When the sample time period includes multiple cycles, the convolutional kernel of the convolution operation covers at least the pixel points corresponding to the same time node in adjacent cycles of the sample image.

[0098] When the sample time period includes multiple cycles, the periodic characteristics of the sample object can also help in the anomaly recognition of the sample object. Therefore, when setting the convolutional kernel size, it is necessary to ensure that the convolutional kernel can extract the periodic characteristics of the sample object, that is, the convolutional kernel of the convolutional operation should cover at least the pixel points of the object in the same time period in adjacent cycles in the sample image.

[0099] Exemplarily, when multiple time series data within one cycle correspond to a row of pixel points or a column of pixel points in the sample image, the size of the convolutional kernel is at least 2*2, and of course it can also be 3*3 or even larger. Exemplarily, when multiple time series data within one cycle correspond to two rows of pixel points or two columns of pixel points in the sample image, the size of the convolutional kernel is at least 3*3, and of course it can also be 4*4 or even larger.

[0100] S203. Train the anomaly recognition model based on the difference between the predicted recognition result and the true recognition result of the sample object, where the predicted recognition result and the true recognition result are used to identify whether the sample object has an anomaly.

[0101] The true recognition result of the sample object can be a result manually labeled, a result machine-labeled, or a result obtained by other means, and this specification does not limit this. In this specification, the predicted recognition result is the result predicted by the anomaly recognition model, and this predicted recognition result may be a correct result or an incorrect result, while the true recognition result is the correct result.

[0102] When training the anomaly recognition model based on the difference between the predicted recognition result and the true recognition result of the sample object, any loss function (such as binary cross-entropy loss) and / or optimizer (such as Adam optimizer) can be used to update the model parameters of the anomaly recognition model, and this specification does not limit this. After the anomaly recognition model is trained, the effect of this anomaly recognition model can be evaluated. If the effect of the anomaly recognition model is good, the model output can be saved. If the effect of the anomaly recognition model is not good, the model parameters or the model structure need to be further adjusted.

[0103] Exemplarily, taking the transaction recognition scenario as an example, an exemplary description of the training method of the anomaly recognition model provided in this specification is as follows:

[0104] Such as Figure 4As shown, obtain the second-level transaction data of the sample object within 24 hours in the past 7 days, and perform hourly data aggregation on the obtained second-level transaction data. That is, accumulate and sum the second-level transaction data within each hour to obtain the corresponding income amount, transfer amount, number of income transactions, number of transfer transactions, number of income transaction counterparts, and number of transfer transaction counterparts for each hour, and generate a structured data set. Use the standard normalization method to normalize the structured data set, scale the data in the structured data set to the range of [0, 255], and then transform the data into image-form data of (C, H, W), where C = 6, H = 7, W = 24, C corresponds to 6 channels (income amount, transfer amount, number of income transactions, number of transfer transactions, number of income transaction counterparts, and number of transfer transaction counterparts), the height is 7 (the period is in days, and each period corresponds to a row of pixel points), and the width is 24 (24 hours in a day, corresponding to 24 pixel points). Construct the image-based data set in the above manner (as Figure 5 shown, the part enclosed by the black frame in the picture represents the sample picture of a sample object, Figure 5 only taking two channels as an example for an exemplary description of the sample picture), and split the image-based data set into a training set and a test set according to the ratio of 8:2. That is, 80% of the data is used for model training so that the model can learn the patterns and features in the time-series transaction data; the remaining 20% of the data is used for model testing to evaluate the generalization ability and performance of the model on unseen data. This splitting method ensures that the model can be fully learned during the training process and effectively verified during the testing stage.

[0105] Specifically, after the model training is completed, the model is evaluated. The main evaluation metric is AUC (Area Under the ROC Curve), and the AUC threshold is set to 0.9. When AUC is less than 0.9, it is determined that the model fails the verification and the model parameters or structure need to be further adjusted; when AUC is greater than or equal to 0.9, it is determined that the model passes the verification and the model output can be saved. After the model passes the verification and is saved, we will use the data in the test set to perform inference testing on the model. This step aims to evaluate the classification performance of the model on data not involved in training and ensure that the model can accurately judge the suspiciousness of new transaction data. By inputting the sample pictures in the test set into the trained model, the model will classify and label each sample and output its predicted recognition result.

[0106] In the above technical solutions, this specification maps the values of each piece of timing data to pixel values, and generates a sample picture according to the time arrangement order of multiple pieces of timing data and the corresponding pixel values, so that the arrangement order of pixel points matches the time arrangement order of the timing data, realizing the conversion of the timing data into a picture form. This conversion not only preserves the potential timing relationship in the timing data, but also the model can directly extract this potential timing relationship from the picture without integrating complex components such as self-attention mechanisms and memory networks into the model architecture. Moreover, this conversion simplifies the data structure of the timing data, thereby effectively reducing the amount of input data and reducing the computational burden. In this way, both the learning ability of the model for timing relationships and the processing efficiency of the model are improved.

[0107] Moreover, this specification converts the timing data within one period into a row of pixel points or a column of pixel points, so that the sample picture can well present the periodicity of the timing data, enabling the anomaly recognition model to more easily extract the periodic characteristics of the timing data, and thus being able to more accurately perform anomaly recognition on the sample object, improving the accuracy of the model.

[0108] Furthermore, this specification converts the timing data and static attribute data of the sample object into a picture form together. In this way, when the anomaly recognition model performs anomaly recognition, it can refer not only to the timing data of the sample object, but also to the static attribute data of the sample object, thereby being able to more accurately perform anomaly recognition on the sample object, improving the accuracy of the model.

[0109] Figure 6 is a flowchart of an anomaly recognition method provided by an exemplary embodiment. The execution subject of this method can be Figure 1 the system shown, or any device. This specification does not limit the execution subject. The method includes:

[0110] S601, obtain multiple pieces of timing data of the target object within the target time period, map the values of each piece of timing data to pixel values, and generate a target picture with the arrangement order of pixel points matching the time arrangement order according to the time arrangement order of the multiple pieces of timing data and the corresponding pixel values.

[0111] Among them, the target object can be any object. For example, the target object can be any user, any user account, any device, any stock, etc., and this specification does not limit the target object. In one embodiment, in different application scenarios, the type of the target object can be different. Exemplarily, in the transaction recognition scenario, the target object is any user account; in the health monitoring scenario, the target object is any user; in the device monitoring scenario, the target object is any device; in the stock market detection scenario, the target object is any stock. That is to say, the type of the target object can be set according to the requirements of the actual application scenario, and this specification does not limit the type of the target object.

[0112] The target time period can be any time period. For example, the target time period can be one minute before the current moment, or one hour before the current moment, or one day before the current moment, or one week before the current moment, or one month before the current moment, etc., and this specification does not limit the target time period. In one embodiment, in different application scenarios, the time length of the target time period can be different. Exemplarily, in the transaction recognition scenario, the target time period can be one week before the current moment, or one month before the current moment. Exemplarily, in the health monitoring scenario, the target time period can be one minute before the current moment (for example, obtaining the electrocardiogram of the user in the previous minute), or one week before the current moment (for example, obtaining the blood pressure of the user in the previous week). That is to say, the time length of the target time period can be set according to the requirements of the actual application scenario, and this specification does not limit the target time period.

[0113] Multiple time series data refers to multiple continuous or discrete data sequences collected for the target object within the target time period. Each time series data is associated with a specific time and can reflect the dynamic change characteristics of the target object in the time dimension. In one embodiment, in different application scenarios, the data content of the time series data can be different. Exemplarily, in the transaction recognition scenario, the time series data is time series transaction data, and the time series transaction data is the transaction record of any user account at any moment. Exemplarily, in the health monitoring scenario, the time series data is time series physiological characteristic data, and the time series physiological characteristic data is the physiological characteristic data of any user at any moment. Exemplarily, in the device monitoring scenario, the time series data is time series operation data, and the time series operation data is the operation data of any device at any moment. That is to say, the data content of the time series data can be set according to the requirements of the actual application scenario, and this specification does not limit the data content of the time series data.

[0114] In one embodiment, the multiple pieces of time-series data may be sourced from system logs, monitoring devices, sensors, or other data collection means, which are not limited in this specification. In one embodiment, the time-series data includes two parts: a timestamp and the corresponding observed value, where the observed value is the value of the time-series data. Of course, the time-series data may also include more or less content, and this specification does not limit the data structure of the time-series data.

[0115] In this specification, any numerical mapping method can be adopted to map the values of each piece of time-series data to pixel values. Exemplarily, the standard normalization method is used to map the values of each piece of time-series data to pixel values. For example, using the standard normalization method, the values of each piece of time-series data are mapped to the numerical range of 0 to 255 to obtain the pixel values corresponding to each piece of time-series data. Exemplarily, the piecewise linear mapping method is used to map the values of each piece of time-series data to pixel values. For example, the value range of the time-series data is divided into multiple intervals, and each interval corresponds to a fixed pixel value. By determining the interval to which the value of each piece of time-series data belongs, the value of each piece of time-series data is mapped to the pixel value corresponding to the corresponding interval. Exemplarily, the logarithmic transformation method is used to map the values of each piece of time-series data to pixel values. For example, for time-series data with a large value range and uneven distribution, the values of each piece of time-series data can be logarithmically transformed first, and then the standard normalization method is used to map the logarithmically transformed values to the numerical range of 0 to 255 to obtain the pixel values corresponding to each piece of time-series data. Exemplarily, the exponential transformation method is used to map the values of each piece of time-series data to pixel values. For example, for time-series data with a small value transformation, the values of each piece of time-series data can be exponentially transformed first, and then the standard normalization method is used to map the logarithmically transformed values to the numerical range of 0 to 255 to obtain the pixel values corresponding to each piece of time-series data.

[0116] It should be noted that this specification only gives an exemplary description of the numerical mapping method and does not limit it. Since the data content of the time-series data in different application scenarios is different, resulting in different data characteristics of the time-series data in different application scenarios, a suitable numerical mapping method can be selected according to the data characteristics of the time-series data in the actual application scenario, which is not limited in this specification.

[0117] In this specification, when generating the target image, it is necessary to ensure that the arrangement order of the pixel points in the target image matches the time arrangement order of the corresponding time-series data. That is to say, if time-series data A is arranged before time-series data B, then the pixel points corresponding to time-series data A are located before the pixel values corresponding to time-series data B; if time-series data C is arranged after time-series data D, then the pixel points corresponding to time-series data C are located after the pixel points corresponding to time-series data D.

[0118] In one embodiment, a target picture can be generated by generating a pixel value matrix. Among them, generating a target picture with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of multiple time series data and the corresponding pixel values includes: arranging the pixel values corresponding to the multiple time series data into a pixel value matrix according to the time arrangement order of the multiple time series data, and converting the pixel value matrix into a picture form to obtain the target picture.

[0119] In another embodiment, a target picture can be generated by constructing a two-dimensional grid. Among them, generating a target picture with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of multiple time series data and the corresponding pixel values includes: constructing a two-dimensional grid, and sequentially filling the pixel values corresponding to the time series data into the two-dimensional grid in the order of rows or columns according to the time arrangement order of the multiple time series data; converting the pixel values in the two-dimensional grid into a picture form to obtain the target picture. It should be noted that this specification only gives an exemplary illustration of the implementation manner of "generating a target picture with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple time series data and the corresponding pixel values", and does not limit it. Any other method not mentioned in this specification can also be used to generate the target picture.

[0120] In one embodiment, the size of the target picture is fixed. Among them, the fixed size of the target picture means that the horizontal size and / or the vertical size of the target picture is fixed. Exemplarily, both the horizontal size and the vertical size of the target picture are fixed. In this case, the number of multiple time series data needs to match the size of the target picture, and the number of multiple time series data is also fixed. That is to say, the number of multiple time series data of target object A in the target time period is the same as the number of multiple time series data of target object B in the target time period.

[0121] For example, if the sensor collects time series data every 10 minutes, then the number of multiple time series data of target object A in a day is 144, and the number of multiple time series data of target object B in a day is also 144. Correspondingly, the size of the target picture can be 6*24, or 12*12, or 24*6, etc.

[0122] For another example, the time-series data is time-series transaction data. As is well known, time-series transaction data is generated based on the transaction records of user accounts, and the number of transaction records of different user accounts is not the same. To make the number of multiple time-series data match the size of the target image, the multiple time-series data can be aggregated. Exemplarily, obtaining multiple time-series data of a target object within a target time period includes: obtaining multiple original time-series data of the target object within the target time period; dividing the target time period into multiple sub-time periods with equal time intervals, and performing statistical processing on the time-series data within each sub-time period to obtain the time-series data corresponding to each sub-time period. In this way, the number of time-series data of the target object is the same as the number of sub-time periods of the target time period, making the number of time-series data of different target objects the same. Among them, the length of the sub-time period can be determined by the size of the target image. For example, if the size of the target image is 7*24 and the target time period is 7 days, then the sub-time period can be one hour; for another example, if the size of the target image is 12*12 and the target time period is 12 days, then the sub-time period can be two hours.

[0123] Exemplarily, the horizontal size of the target image is fixed, while the vertical size is not fixed. For example, generating a target image with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of multiple time-series data and the corresponding pixel values includes: generating a row of pixel points with the pixel values corresponding to the first M time-series data according to the time arrangement order of the multiple time-series data and the horizontal size of the target image, and repeatedly executing to generate a row of pixel points with the pixel values corresponding to the first M time-series data among the remaining time-series data until the number of the remaining time-series data is 0. Among them, M is the horizontal size of the target image. For example, if the size of the target image is 7*24, where 7 is the vertical size of the target image and 24 is the horizontal size of the target image, then M is 24.

[0124] Exemplarily, the vertical size of the target image is fixed, while the horizontal size is not fixed. For example, generating a target image with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of multiple time-series data and the corresponding pixel values includes: generating a column of pixel points with the pixel values corresponding to the first X time-series data according to the time arrangement order of the multiple time-series data and the vertical size of the target image, and repeatedly executing to generate a column of pixel points with the pixel values corresponding to the first X time-series data among the remaining time-series data until the number of the remaining time-series data is 0. Among them, X is the vertical size of the target image. For example, if the size of the target image is 7*24, where 7 is the vertical size of the target image and 24 is the horizontal size of the target image, then X is 7.

[0125] In another embodiment, the size of the target image is not fixed, but is determined based on the data attributes of the time series data. Exemplarily, generating a target image whose pixel point arrangement order matches the time arrangement order according to the time arrangement order of multiple time series data and the corresponding pixel values includes: determining the size of the target image to be generated based on the data attributes of the multiple time series data; generating a target image whose pixel point arrangement order matches the time arrangement order according to the size of the target image to be generated, the time arrangement order of the multiple time series data and the corresponding pixel values.

[0126] Exemplarily, the data attributes of the multiple time series data include the number of the multiple time series data. Based on the data attributes of the multiple time series data, the size of the target image to be generated is determined, including: based on the number of the multiple time series data, the size of the target image to be generated is determined. For example, based on the number of the multiple time series data, the size of the target image to be generated is determined, including: factoring the number of the multiple time series data to obtain multiple groups of alternative values, each group of alternative values includes a first value and a second value, and the product of the first value and the second value in a group of alternative values is the number of the multiple time series data; selecting a group of alternative values with the smallest difference between the first value and the second value from the multiple groups of alternative values, using the first value in the group of alternative values as the horizontal size of the target image, and using the second value in the group of alternative values as the vertical size of the target image.

[0127] For example, based on the number of multiple time series data, the size of the target image to be generated is determined, including: taking the square root of the number of multiple time series data, rounding up the value obtained by the square root to obtain a third value, and using the third value as the horizontal and vertical sizes of the target image.

[0128] Exemplarily, the data attributes of the multiple time series data include the periodic attributes of the multiple time series data. Based on the data attributes of the multiple time series data, the size of the target image to be generated is determined, including: based on the periodic attributes of the multiple time series data, the size of the target image to be generated is determined. For example, the periodic attributes of the multiple time series data include the number of periods of the multiple time series data and the number of time series data in one period. Based on the periodic attributes of the multiple time series data, the size of the target image to be generated is determined, including: using the number of periods of the multiple time series data as the horizontal size of the target image, and using the number of time series data in one period as the vertical size of the target image; or, using the number of periods of the multiple time series data as the vertical size of the target image, and using the number of time series data in one period as the horizontal size of the target image.

[0129] It should be noted that this specification only takes the data attributes of quantity and cycle attributes as examples to illustrate the data attributes exemplarily. Of course, the data attributes can also be other attributes, and this specification does not limit this. Moreover, this specification only exemplarily illustrates the process of determining the size of the target picture. Of course, any method not mentioned in this specification can also be used to determine the size of the target picture, and this specification does not limit this.

[0130] In an illustrated embodiment, the target time period includes multiple cycles. For example, the target time period includes 3 cycles, 5 cycles, 7 cycles, 10 cycles, 30 cycles, etc., and this specification does not limit the number of cycles included in the target time period. Optionally, the cycles included in the target time period can be time cycles, and the time cycle can be years, months, days, hours, minutes, seconds, etc. In this case, the time series data may or may not have periodicity. Optionally, the time series data is data with periodicity, and the cycles included in the target time period can be the change cycles of the time series data.

[0131] In an embodiment, when extracting features from a picture, several adjacent pixel points are usually analyzed. If the pixel points corresponding to the same time node in different cycles are located in the same row or the same column of the picture, then during the process of feature extraction, the change situation of the target object across multiple cycles at the same time node can be captured. Exemplarily, according to the time arrangement order and corresponding pixel values of multiple time series data, generating a target picture with the pixel point arrangement order matching the time arrangement order includes: for multiple time series data within the same cycle, generating a row of pixel points or a column of pixel points according to the time arrangement order and corresponding pixel values of each time series data; arranging the row pixel points or column pixel points corresponding to each cycle in sequence to form the target picture.

[0132] For example, the target time period includes 7 cycles. According to the time arrangement order and corresponding pixel points of multiple time series data within the first cycle, generating the first row of pixel points or the first column of pixel points; according to the time arrangement order and corresponding pixel points of multiple time series data within the second cycle, generating the second row of pixel points or the second column of pixel points; according to the time arrangement order and corresponding pixel points of multiple time series data within the third cycle, generating the third row of pixel points or the third column of pixel points, and so on.

[0133] Of course, the timing data of one cycle can also generate multiple rows or columns of pixel points. In another embodiment, according to the time arrangement order of multiple pieces of timing data and the corresponding pixel values, a target picture with a pixel point arrangement order matching the time arrangement order is generated, including: for multiple pieces of timing data within the same cycle, according to the time arrangement order of each piece of timing data and the corresponding pixel values, generate two rows or two columns of pixel points; arrange the two rows or two columns of pixel points corresponding to each cycle in sequence to form the target picture.

[0134] In another illustrated embodiment, the target time period may also include only one cycle. In another illustrated embodiment, the target time period may not include a complete cycle. This specification does not limit this. When the target time period includes only one cycle, or when the target time period does not include a complete cycle, it is only necessary to generate a target picture with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of multiple pieces of timing data and the corresponding pixel values.

[0135] In an illustrated embodiment, any piece of timing data includes N-dimensional values, where N is any positive integer. Exemplarily, the timing data is timing transaction data, and any piece of timing transaction data includes the values of 6 dimensions: income amount, transfer amount, number of income transactions, number of transfer transactions, number of income transaction counterparts, and number of transfer transaction counterparts. Exemplarily, the timing data is timing physiological feature data, and any piece of timing physiological feature data includes the values of 4 dimensions: heart rate, blood pressure, blood sugar, and blood oxygen.

[0136] When the timing data includes N-dimensional values, a channel of the target picture can be generated for each dimension of the value. Exemplarily, mapping the values of each piece of timing data to pixel values, and according to the time arrangement order of multiple pieces of timing data and the corresponding pixel values, generating a target picture with a pixel point arrangement order matching the time arrangement order, including: mapping each dimension of the value of each piece of timing data to a pixel value, obtaining N pixel values corresponding to each piece of timing data respectively, and generating an N-channel target picture with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of multiple pieces of timing data and the corresponding N pixel values. Among them, the timing data corresponds one-to-one with the pixel points in the N-channel target picture, and the pixel values of any pixel point in the N channels are respectively the N different pixel values corresponding to the corresponding timing data.

[0137] Exemplarily, the time-series data is time-series transaction data, and any piece of time-series transaction data includes values in 6 dimensions: income amount, transfer-out amount, number of income transactions, number of transfer-out transactions, number of income transaction counterparts, and number of transfer-out transaction counterparts. Map the income amounts in multiple pieces of time-series transaction data to first pixel values, and generate the first channel of the target image with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series transaction data and the corresponding first pixel values; map the transfer-out amounts in multiple pieces of time-series transaction data to second pixel values, and generate the second channel of the target image with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series transaction data and the corresponding second pixel values; map the number of income transactions in multiple pieces of time-series transaction data to third pixel values, and generate the third channel of the target image with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series transaction data and the corresponding third pixel values, and so on. Finally, a 6-channel target image is obtained.

[0138] It should be noted that this specification mentions multiple numerical mapping methods for mapping the values of time-series data to pixel values, and the adoption of the numerical mapping method can be determined according to the data characteristics of the time-series data. When the time-series data includes values in N dimensions, the data characteristics of the values in different dimensions may be different. Therefore, different data mapping methods can be adopted for the values in different dimensions, and this specification does not limit this.

[0139] In an illustrated embodiment, on the one hand, considering that the quantity of time-series data of some types of target objects is unstable within the target time period, and on the other hand, considering that if the quantity of time-series data is too large, the size of the generated target image will be large and the amount of calculation generated will also be large, this specification provides a preprocessing method for time-series data. Among them, obtaining multiple pieces of time-series data of a target object within a target time period includes: obtaining multiple pieces of original time-series data of the target object within the target time period; dividing the target time period into multiple sub-time periods with equal time intervals, and performing statistical processing on the time-series data within each sub-time period to obtain the time-series data corresponding to each sub-time period. This time interval can be any time interval, for example, 1 minute, 1 hour, etc.

[0140] Among them, the statistical processing can be any one of summation processing, averaging processing, maximum value taking processing, minimum value taking processing, etc., and this specification does not limit the statistical processing. In one embodiment, different statistical processing methods can be adopted for different types of time series data. Exemplarily, when the time series data is time series transaction data, the time series transaction data within each sub-time period can be cumulatively summed to obtain the time series transaction data corresponding to each sub-time period. Exemplarily, when the time series data is time series operation data, the maximum value time series operation data or the minimum value time series operation data within each sub-time period can be obtained to obtain the time series operation data corresponding to each sub-time period.

[0141] In this specification, multiple time series data of the target object are converted into a picture form and then anomaly recognition is performed. In order to obtain a more accurate prediction and recognition result, when performing anomaly recognition, not only the time series data of the target object can be referred to, but also the static attribute data of the target object can be referred to. In this way, the target object can be analyzed more comprehensively, and then a more accurate prediction and recognition result can be obtained. Among them, the static attribute data is data that does not change with time. Exemplarily, taking the target object as a user account, the static attribute data can be the registration time of the user account, the account type of the user account, etc. Exemplarily, taking the target object as a user, the static attribute data can be the birthday, gender, etc. of the user.

[0142] Therefore, this specification also provides a method for converting multiple time series data and static attribute data of the target object into a picture form. In one illustrated embodiment, a target picture with a pixel point arrangement order matching the time arrangement order is generated according to the time arrangement order of multiple time series data and the corresponding pixel values, including: obtaining the static attribute data of the target object, mapping the value of the static attribute data to a pixel value, and replicating the pixel value according to the number of multiple time series data; generating the first channel of the target picture according to the time arrangement order of multiple time series data and the corresponding pixel values, with the pixel point arrangement order matching the time arrangement order; generating the second channel of the target picture according to the replicated pixel values corresponding to the static attribute data.

[0143] Since the time-series data changes over time, the number of time-series data is not the same as the number of static attribute data. Therefore, when generating the target image based on the time-series data and the static attribute data, not only the values of the static attribute data are mapped to pixel values, but also the pixel values are replicated according to the number of multiple time-series data. The number of pixel values corresponding to the values of the time-series data is the same as the number of pixel values corresponding to the values of the static attribute data. Thus, the first channel of the target image can be generated based on the pixel values corresponding to the values of the time-series data, and the second channel of the target image can be generated based on the pixel values corresponding to the values of the static attribute data. In this way, when extracting features of any pixel point in the image subsequently, the image features can be comprehensively extracted from the time-series data and the static attribute data, making the extracted image features more accurate.

[0144] It should be noted that the time-series data can include N-dimensional values, and the static attribute data can include Z-dimensional values. When the time-series data includes N-dimensional values and the static attribute data includes Z-dimensional values, each dimension value of each time-series data is mapped to a pixel value to obtain N pixel values corresponding to each time-series data respectively. According to the time arrangement order of multiple time-series data and the corresponding N-dimensional values, N first channels of the target image with the pixel point arrangement order matching the time arrangement order are generated; among them, the time-series data corresponds one-to-one with the pixel points in the N first channels of the target image, and the pixel values of any pixel point in the N first channels are respectively the N different pixel values corresponding to the corresponding time-series data; each dimension value of the static attribute data is mapped to a pixel value to obtain Z pixel values corresponding to the static attribute data. For each of the Z pixel values, the pixel value is replicated according to the number of multiple time-series data, and Z second channels of the target image are generated according to the replicated pixel values corresponding to the static attribute data.

[0145] S602. Input the target image into the pre-trained anomaly recognition model, so that the anomaly recognition model extracts image features from the target image, and performs anomaly recognition based on the image features to obtain the predicted recognition result of the target object, and the predicted recognition result is used to identify whether the target object has an anomaly.

[0146] In one embodiment, the pre-trained anomaly recognition model is obtained through Figure 2 the anomaly recognition model trained by the shown embodiment.

[0147] The anomaly recognition model is a model for identifying whether an input object has an anomaly. The anomaly recognition model can adopt any model structure, and this specification does not limit it. Only taking Figure 3 the shown anomaly recognition model as an example, the model structure of the anomaly recognition model is exemplarily described.

[0148] Such as Figure 3As shown, the model structure of the anomaly recognition model is a CNN (Convolutional Neural Network) based on a residual convolution module. The anomaly recognition model includes a linear embedding layer, N residual convolution modules, and a fully connected layer. The target image is input into the anomaly recognition model. First, the target image passes through the linear embedding layer to increase the dimension of the target image, thereby enhancing the embedding expression ability of the anomaly recognition model. Exemplarily, the target image is increased in dimension from 6 channels to 32 channels. Then, after the target image is increased in dimension, it enters N residual convolution modules. Each residual convolution module is composed of a two-dimensional convolutional layer, an instance normalization layer, and a non-linear activation layer (such as ReLU) spliced together. It should be noted that Figure 3 the dotted line in is used to represent the residual connection, that is, the output of the previous residual convolution module is used as the input of the next residual convolution module. This can effectively alleviate the problems of gradient disappearance and gradient explosion, and improve the convergence speed and stability of the anomaly recognition model. The output of the last residual convolution module is used as the input of the fully connected layer. The fully connected layer is used to expand and evaluate the image features (tensors) input by the last residual convolution module and then output the classification result. Output 0 represents that the target object has no anomaly, and output 1 represents that the target object has an anomaly.

[0149] In an illustrated embodiment, the anomaly recognition model performs a convolution operation on the target image through a convolution kernel to obtain image features. Since the target image in this specification has the characteristic of temporality, in order to better extract potential temporal features from the target image, a suitable convolution kernel can be selected for the convolution operation.

[0150] Among them, the anomaly recognition model extracts image features from the target image, including: the anomaly recognition model performs a convolution operation on the target image to obtain image features. Among them, the convolution kernel of the convolution operation satisfies at least one of the following conditions:

[0151] (1) The size of the convolution kernel is positively correlated with the size of the target image.

[0152] That is, the larger the size of the target image, the larger the size of the convolution kernel. In this way, when the size of the target image is large, fast convolution operations can still be performed, improving the running speed of the anomaly recognition model; the smaller the size of the target image, the smaller the size of the convolution kernel. In this way, the loss of details in the target image can be avoided.

[0153] (2) When the target time period includes multiple cycles, the convolution kernel of the convolution operation covers at least the pixel points corresponding to the same time node in adjacent cycles in the target image.

[0154] When the target time period includes multiple cycles, the periodic characteristics of the target object can also help in the anomaly recognition of the target object. Therefore, when setting the convolutional kernel size, it is necessary to ensure that the convolutional kernel can extract the periodic characteristics of the target object, that is, the convolutional kernel of the convolutional operation covers at least the pixel points of the object in the same time period in adjacent cycles in the target image.

[0155] Exemplarily, when multiple pieces of time series data within one cycle correspond to a row of pixel points or a column of pixel points in the target image, the size of this convolutional kernel is at least 2*2, and of course it can also be 3*3 or even larger. Exemplarily, when multiple pieces of time series data within one cycle correspond to two rows of pixel points or two columns of pixel points in the target image, the size of this convolutional kernel is at least 3*3, and of course it can also be 4*4 or even larger.

[0156] In the above technical solution, this specification maps the values of each piece of time series data to pixel values, and generates a sample image according to the time arrangement order of the multiple pieces of time series data and the corresponding pixel values, so that the arrangement order of the pixel points matches the time arrangement order of the time series data, realizing the conversion of time series data into a picture form. This conversion not only retains the potential time series relationship in the time series data, but also the model can directly extract this potential time series relationship from the picture without integrating complex components such as self-attention mechanisms and memory networks in the model architecture. Moreover, this conversion simplifies the data structure of the time series data, thereby effectively reducing the input data volume and reducing the computational burden. In this way, both the learning ability of the model for time series relationships and the processing efficiency of the model are improved.

[0157] Moreover, this specification converts the time series data within one cycle into a row of pixel points or a column of pixel points, so that the sample image can well present the periodicity of the time series data, enabling the anomaly recognition model to more easily extract the periodic characteristics of the time series data, and then being able to more accurately perform anomaly recognition on the sample object, improving the accuracy of the model.

[0158] Moreover, this specification converts the time series data and static attribute data of the sample object into a picture form together. In this way, when the anomaly recognition model performs anomaly recognition, it can refer not only to the time series data of the sample object, but also to the static attribute data of the sample object, thereby being able to more accurately perform anomaly recognition on the sample object and improving the accuracy of the model.

[0159] Figure 7 It is a schematic structural diagram of a device provided by an exemplary embodiment. Please refer to Figure 7, at the hardware level, the device includes a processor 702, an internal bus 704, a network interface 706, a memory 708, and a non-volatile memory 710. Of course, it may also include other hardware required for other functions. One or more embodiments of this specification can be implemented in software. For example, the processor 702 reads the corresponding computer program from the non-volatile memory 710 into the memory 708 and then runs it. Of course, in addition to the software implementation, one or more embodiments of this specification do not exclude other implementation methods, such as logical devices or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logical unit, and can also be hardware or logical devices.

[0160] Please refer to Figure 8 , the training device for the anomaly recognition model can be applied to a device as shown in Figure 7 to implement the technical solutions of this specification. Among them, the training device for the anomaly recognition model can include:

[0161] An image generation unit 801, configured to obtain multiple pieces of time-series data of a sample object within a sample time period, map the values of each piece of time-series data to pixel values, and generate a sample image with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series data and the corresponding pixel values;

[0162] An anomaly recognition unit 802, configured to input the sample image into an anomaly recognition model, so that the anomaly recognition model extracts image features from the sample image, and performs anomaly recognition based on the image features to obtain a predicted recognition result of the sample object;

[0163] A model training unit 803, configured to train the anomaly recognition model based on the difference between the predicted recognition result and the true recognition result of the sample object, where the predicted recognition result and the true recognition result are used to identify whether the sample object has an anomaly.

[0164] Optionally, the sample time period includes multiple cycles; the image generation unit 801 is configured to, for multiple pieces of time-series data within the same cycle, generate a row of pixel points or a column of pixel points according to the time arrangement order of each piece of time-series data and the corresponding pixel values; and arrange the row pixel points or column pixel points corresponding to each cycle in sequence to form the sample image.

[0165] Optionally, the anomaly recognition unit 802 is configured to perform a convolution operation on the sample image through the anomaly recognition model to obtain the image features;

[0166] Among them, the convolution kernel of the convolution operation satisfies at least one of the following conditions:

[0167] The size of the convolutional kernel is positively correlated with the size of the sample picture;

[0168] When the sample time period includes multiple cycles, the convolutional kernel of the convolutional operation covers at least the pixel points corresponding to the same time node in adjacent cycles in the sample picture.

[0169] Optionally, any piece of time series data includes N-dimensional values, where N is any positive integer; the picture generation unit 801 is configured to map each dimension value of each piece of time series data to a pixel value, obtain N pixel values corresponding to each piece of time series data respectively, and generate an N-channel sample picture with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time series data and the corresponding N pixel values;

[0170] Among them, the time series data corresponds one-to-one with the pixel points in the N-channel sample picture, and the pixel values of any pixel point in the N channels are respectively N different pixel values corresponding to the corresponding time series data.

[0171] Optionally, the picture generation unit 801 is configured to obtain multiple pieces of original time series data of the sample object within the sample time period;

[0172] The sample time period is divided into multiple sub-time periods with equal time intervals, and the time series data within each sub-time period is statistically processed to obtain the time series data corresponding to each sub-time period.

[0173] Optionally, the picture generation unit 801 is configured to obtain the static attribute data of the sample object, map the value of the static attribute data to a pixel value, and copy the pixel value according to the number of the multiple pieces of time series data; generate the first channel of the sample picture according to the time arrangement order of the multiple pieces of time series data and the corresponding pixel values, with the pixel point arrangement order matching the time arrangement order; generate the second channel of the sample picture according to the copied pixel values corresponding to the static attribute data.

[0174] Please refer to Figure 9 and the anomaly recognition device can be applied to devices such as Figure 7 shown to implement the technical solutions of this specification. Among them, the anomaly recognition device may include:

[0175] The picture generation unit 901 is configured to obtain multiple pieces of time series data of the target object within the target time period, map the values of each piece of time series data to pixel values, and generate a target picture with the pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time series data and the corresponding pixel values;

[0176] Anomaly recognition unit 902 is configured to input the target picture into a pre-trained anomaly recognition model, so that the anomaly recognition model extracts features from the target picture to obtain picture features, performs anomaly recognition based on the picture features, and obtains a predicted recognition result of the target object, where the predicted recognition result is used to identify whether the target object has an anomaly.

[0177] Based on the same concept as the above method, this specification also provides an electronic device, including: a processor; a memory for storing instructions executable by the processor; wherein, the processor realizes the steps of the method as described in any one of the above embodiments by running the executable instructions.

[0178] Based on the same concept as the above method, this specification also provides a computer-readable storage medium, on which computer instructions are stored, and when the instructions are executed by a processor, the steps of the method as described in any one of the above embodiments are realized.

[0179] Based on the same concept as the above method, this specification also provides a computer program product, including computer programs / instructions, and when the computer programs / instructions are executed by a processor, the steps of the method as described in any one of the above embodiments are realized.

Claims

1. A training method for an anomaly recognition model, the method comprising: Obtaining multiple pieces of time-series data of a sample object within a sample time period, mapping the values of each piece of time-series data to pixel values, and generating a sample image with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series data and the corresponding pixel values; Inputting the sample image into the anomaly recognition model, so that the anomaly recognition model extracts image features from the sample image, and performs anomaly recognition based on the image features to obtain a predicted recognition result of the sample object; Training the anomaly recognition model based on the difference between the predicted recognition result and the true recognition result of the sample object, where the predicted recognition result and the true recognition result are used to indicate whether the sample object has an anomaly.

2. The method according to claim 1, wherein the sample time period includes multiple cycles; the generating a sample image with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series data and the corresponding pixel values includes: For multiple pieces of time-series data within the same cycle, generating a row of pixel points or a column of pixel points according to the time arrangement order of each piece of time-series data and the corresponding pixel values; Sequentially arranging the row pixel points or column pixel points corresponding to each cycle to form the sample image.

3. The method according to claim 1, wherein the anomaly recognition model extracts image features from the sample image to obtain image features, including: The anomaly recognition model performs a convolution operation on the sample image to obtain the image features; Wherein, the convolution kernel of the convolution operation satisfies at least one of the following conditions: The size of the convolution kernel is positively correlated with the size of the sample image; When the sample time period includes multiple cycles, the convolution kernel of the convolution operation covers at least the pixel points corresponding to the same time node in adjacent cycles in the sample image.

4. The method according to claim 1, wherein any piece of time-series data includes N-dimensional values, and N is any positive integer; the mapping the values of each piece of time-series data to pixel values, and generating a sample image with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series data and the corresponding pixel values includes: Mapping each dimension value of each piece of time-series data to a pixel value, obtaining N pixel values corresponding to each piece of time-series data respectively, and generating an N-channel sample image with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple pieces of time-series data and the corresponding N pixel values; Wherein, the time-series data corresponds one-to-one with the pixel points in the N-channel sample image, and the pixel values of any pixel point in the N channels are respectively the N different pixel values corresponding to the corresponding time-series data.

5. The method according to claim 1, wherein the obtaining multiple pieces of time-series data of a sample object within a sample time period includes: Obtaining multiple pieces of original time-series data of the sample object within the sample time period; Divide the sample time period into multiple sub-time periods with equal time intervals, and perform statistical processing on the time-series data within each sub-time period to obtain the time-series data corresponding to each sub-time period.

6. The method according to claim 1, wherein generating a sample picture with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple time-series data and the corresponding pixel values comprises: Obtain the static attribute data of the sample object, map the value of the static attribute data to a pixel value, and replicate the pixel value according to the number of the multiple time-series data; Generate a first channel of the sample picture according to the time arrangement order of the multiple time-series data and the corresponding pixel values, with the pixel point arrangement order matching the time arrangement order; Generate a second channel of the sample picture according to the replicated pixel values corresponding to the static attribute data.

7. An anomaly recognition method, the method comprising: Obtain multiple time-series data of a target object within a target time period, map the value of each time-series data to a pixel value, and generate a target picture with a pixel point arrangement order matching the time arrangement order according to the time arrangement order of the multiple time-series data and the corresponding pixel values; Input the target picture into a pre-trained anomaly recognition model, so that the anomaly recognition model extracts picture features from the target picture, performs anomaly recognition based on the picture features, and obtains a predicted recognition result of the target object, where the predicted recognition result is used to identify whether the target object has an anomaly.

8. An electronic device, characterized in that, Comprising: A processor; A memory for storing processor-executable instructions; wherein, the processor runs the executable instructions to implement the steps of the method according to any one of claims 1-7.

9. A computer-readable storage medium, characterized in that, Stored thereon are computer instructions, which when executed by the processor implement the steps of the method according to any one of claims 1-7.

10. A computer program product, characterized in that, Comprising a computer program / instructions, which when executed by the processor implement the steps of the method according to any one of claims 1-7.