Network fault diagnosis method and system based on 5G communication gateway

By collecting and processing multimodal data of 5G communication gateways, building a correlation matrix and performing graph timing modeling, the misjudgment and poor generalization caused by a single modal data source in the existing technology is solved, and efficient and accurate detection and analysis of 5G network failures are achieved.

CN120343602AInactive Publication Date: 2025-07-18SHENZHEN MEIGAO ELECTRONIC EQUIPMENT CO LTD SUZHOU BRANCH +1
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202510543281.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-07-18
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing 5G network fault diagnosis technologies are mostly based on single mode data sources, which are difficult to comprehensively reflect the operating status of 5G communication gateways at different protocol levels, and lack effective abnormal data screening and noise reduction strategies, resulting in misjudgment or misjudgment of the model; at the same time, it is not possible to combine the time evolution and topological dependence characteristics between nodes, making it difficult to capture abnormal diffusion patterns across time steps, resulting in poor generalization of the diagnostic model.

Method used

Collect multimodal data of 5G communication gateways, perform abnormal data screening and preprocessing, build a correlation matrix, calculate Mahayana distance and feature weights, use LSTM neural network for graph timing modeling, backtrack the upstream path of abnormal nodes, and perform log secure storage.

Benefits of technology

It improves the accuracy and generalization ability of abnormal detection, can capture the timing dependencies and dynamic changes between nodes, enhances the ability to adapt to complex network environments, and ensures data security and integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120343602A_ABST
    Figure CN120343602A_ABST
Patent Text Reader

Abstract

The invention discloses a network fault diagnosis method and system based on a 5G communication gateway, and relates to the technical field of network fault diagnosis, and the method comprises the steps: collecting the multimodal data of the 5G communication gateway, calculating the data features, and carrying out the abnormal data screening; the method comprises the following steps: performing data preprocessing to form a correlation matrix, extracting an observation vector of an event window, calculating a mahalanobis distance and making an abnormal mark to construct an initial weight vector, determining feature weighting output by using a steepest descent method, optimizing a feature weight, obtaining a fusion feature vector, selecting high-correlation features to determine an edge weight, and constructing a snapshot sequence of different time windows. According to the method, the observation vector in the event window is extracted, the mahalanobis distance is calculated, collaborative anomalies between the features can be captured from multiple angles, the feature weight is optimized through the steepest descent method, the model can pay more attention to the most important feature of anomaly detection when the mahalanobis distance is calculated, and the detection accuracy is improved. Therefore, the overall detection effect is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network fault diagnosis, and particularly to a network fault diagnosis method and system based on a 5G communication gateway. Background Art

[0002] With the rapid deployment and wide application of 5G communication technology, the structure of communication networks has become increasingly complex, the number of network nodes has increased sharply, communication protocols have become highly diversified, and the dynamics and heterogeneity of network states have also been significantly enhanced. Traditional network operation and maintenance means mainly rely on static rules, manual experience or simple abnormal threshold settings, and it has been difficult to meet the requirements of network fault detection and location in the 5G environment with high concurrency, low latency and multi-access. In recent years, data-driven intelligent diagnosis methods have gradually emerged. By using multi-source data such as network traffic characteristics and alarm logs, and combining machine learning and deep learning models for anomaly detection and root cause analysis, it has become the mainstream direction to improve the intelligent level of network operation and maintenance;

[0003] However, existing 5G network fault diagnosis technologies are mostly based on single-modal data sources, which are difficult to comprehensively reflect the operating states of 5G communication gateways at different protocol levels. At the same time, there is a lack of effective screening and noise reduction strategies for abnormal disturbances such as outliers and noise in the data, which easily leads to misjudgment or missed judgment of the model; in addition, when constructing a node relationship model, most technologies fail to combine the time evolution and topological dependence characteristics between nodes, making it difficult to capture the abnormal diffusion patterns across time steps, and lacking the ability to dynamically optimize the feature importance, resulting in poor generalization of the diagnosis model and difficulty in adapting to the feature changes under different service loads. Summary of the Invention

[0004] In view of the above existing problems, the present invention is proposed.

[0005] Therefore, the present invention provides a network fault diagnosis method based on a 5G communication gateway to solve the problems that existing 5G network fault diagnosis technologies are mostly based on single-modal data sources, which are difficult to comprehensively reflect the operating states of 5G communication gateways at different protocol levels, and at the same time, there is a lack of effective screening and noise reduction strategies for abnormal disturbances such as outliers and noise in the data, which easily leads to misjudgment or missed judgment of the model; in addition, when constructing a node relationship model, most technologies fail to combine the time evolution and topological dependence characteristics between nodes, making it difficult to capture the abnormal diffusion patterns across time steps, and lacking the ability to dynamically optimize the feature importance, resulting in poor generalization of the diagnosis model and difficulty in adapting to the feature changes under different service loads.

[0006] To solve the above technical problems, the present invention provides the following technical solutions:

[0007] In a first aspect, the present invention provides a network fault diagnosis method based on a 5G communication gateway, which includes:

[0008] Collect multimodal data of the 5G communication gateway, calculate data features, and screen out abnormal data;

[0009] Perform data preprocessing to form a correlation matrix, extract the observation vector of the event window, calculate the Mahalanobis distance to make abnormal marks to construct the initial weight vector, use the steepest descent method to determine the feature weighted output, optimize the feature weights, obtain the fused feature vector, select highly correlated features to determine the edge weights, and construct snapshot sequences of different time windows;

[0010] Construct the node third-order feature tensor, perform graph convolutional layer operations according to the snapshot sequence, perform graph time series modeling on the embedding vectors of the same node across multiple time steps based on the LSTM neural network, perform abnormal score calculation, and perform node anomaly determination;

[0011] Trace back to the upstream nodes of the abnormal nodes, count the association paths, generate readable logs, and perform secure log storage.

[0012] As a preferred solution of the network fault diagnosis method based on the 5G communication gateway described in the present invention, wherein: the extraction of the observation vector of the event window, the calculation of the Mahalanobis distance to make abnormal marks to construct the initial weight vector, the use of the steepest descent method to determine the feature weighted output, the optimization of the feature weights, the obtaining of the fused feature vector, the selection of highly correlated features to determine the edge weights, and the construction of snapshot sequences of different time windows include,

[0013] Normalize the data feature vectors after abnormal data screening and align the timestamps, calculate the Pearson correlation coefficients of different types of feature data, and form the correlation matrix C;

[0014] Based on the historical correlation threshold, screen out the feature pairs with Pearson correlation coefficients greater than or equal to the historical correlation threshold, and extract the observation vector at time t of the event window;

[0015] Take the observed values of two features in the past M windows, calculate the subsample mean and the two-dimensional covariance matrix, and calculate the Mahalanobis distance observed at the current time t for each feature combination;

[0016] Calculate the ratio of the number of occurrences of each feature in the statistical abnormal marks to the total number of statistical abnormal windows as the single-feature abnormal correlation index value, and perform normalization calculation on all values as the initial value of the weight vector;

[0017] Use the steepest descent method to optimize the feature weights, and define the observed label of each window in the window sequence as O t : If a collaborative anomaly occurs in this window, then O t is 1, otherwise it is 0;

[0018] For the historical Q windows, determine the feature weighted output, and define the loss function as the weighted mean square error L(w);

[0019] Perform feature fusion according to the optimal feature weight vector as the feature description of each acquisition node;

[0020] Using the fused eigenvalue of each window, define the state feature of the node in the feature space and encode it as the high-dimensional embedding vector of the node. The state feature includes the fused feature vector, acquisition device node, network element, and service unit;

[0021] Combine the correlation matrix C to select the edge weights corresponding to the highly correlated feature pairs, and form the adjacency matrix with the edge weights at each moment;

[0022] Construct a weighted graph according to the edge weights of each node and each pair of nodes for different time windows to form a sequence of temporal snapshots.

[0023] As an optimal scheme of the network fault diagnosis method based on the 5G communication gateway of the present invention, wherein: constructing the third-order feature tensor of the node, performing graph convolutional layer operations according to the snapshot sequence, and performing graph temporal modeling on the embedding vectors of the same node across multiple time steps based on the LSTM neural network, performing anomaly score calculation, and performing node anomaly determination, including,

[0024] Construct a third-order feature tensor based on the total number of nodes within the detected fault range, fused eigenvalue, and sliding window length;

[0025] For the graph snapshots of the temporal snapshot sequence, use the standard GNN layer to perform graph convolutional layer operations;

[0026] Input the embedding vectors of the same node across multiple time steps into the temporal modeling layer, perform graph temporal modeling based on the LSTM neural network, and use the Sigmoid classification layer to calculate the anomaly score for the final embedding vector;

[0027] Use the calibrated training set to select the cross-entropy loss function to calculate the loss between the true label and the predicted value. Use the chain rule to backpropagate the gradient from the output layer to the graph convolutional layer and the temporal model, and then to the input parameters. Use the Adam optimizer to perform gradient descent optimization and update the parameters of each layer. Stop the iteration when the loss of the model no longer significantly decreases during continuous iteration, and output the model parameters;

[0028] After completion of training, output the anomaly probability scores of each node, and use the sum of the historical mean and standard deviation as the anomaly threshold. If the anomaly probability score of a node is greater than or equal to the anomaly threshold, it is determined that the node is abnormal.

[0029] As an optimal scheme of the network fault diagnosis method based on the 5G communication gateway of the present invention, wherein: tracing back the upstream nodes of the abnormal node, including,

[0030] For all nodes detected as abnormal, trace back the adjacent edges of their maximum abnormal distribution, find the upstream nodes connected by the maximum edge weight, and form the root cause link association path;

[0031] Output the abnormal node list, abnormal probability score, and root cause link association path.

[0032] As a preferred solution of the network fault diagnosis method based on the 5G communication gateway described in the present invention, wherein: the statistical association path and generating readable logs include,

[0033] Statistically analyze the abnormal probability distribution of all nodes within the current time window;

[0034] According to the root cause link association path, capture the third-order feature tensor data of the nodes, generate an operation report, and save it as structured text and readable logs.

[0035] As a preferred solution of the network fault diagnosis method based on the 5G communication gateway described in the present invention, wherein: the acquisition of 5G communication gateway multimodal data, calculation of data features, and abnormal data screening include,

[0036] Perform high-frequency data sampling on the physical layer, link layer, and network layer of the 5G communication gateway respectively to collect multimodal raw data;

[0037] Select the window length and calculate data features within the window, including mean, standard deviation, change rate, maximum value, and minimum value, to form a data feature vector. Use the principal component analysis method PCA to denoise the collected data of different layers, and use the local outlier factor algorithm LOF to detect obvious outliers in the denoised data in real time. Mark and remove the data points determined as abnormal by LOF for abnormal data screening.

[0038] As a preferred solution of the network fault diagnosis method based on the 5G communication gateway described in the present invention, wherein: the secure storage of logs includes,

[0039] Store the log files, protect the transmission link using the TLS protocol, use the AES-256 strong encryption algorithm for the transmission content, and use the message authentication code MAC for integrity verification.

[0040] In a second aspect, the present invention provides a system for the network fault diagnosis method based on the 5G communication gateway, including,

[0041] A data feature construction module that collects multimodal data from the 5G communication gateway and constructs a feature vector;

[0042] A feature correlation analysis module that extracts the observation vector within the event window, calculates the Mahalanobis distance to achieve initial abnormal marking, and performs weighted optimization through the steepest descent method;

[0043] A time window snapshot generation module determines the edge weights between nodes and constructs a graph snapshot sequence;

[0044] An anomaly detection module constructs a node third-order feature tensor, processes the node features of each time snapshot, performs time series modeling, and conducts anomaly score calculation and node anomaly determination;

[0045] A path association module traces back to the upstream nodes of the nodes determined to be abnormal and analyzes the impact paths;

[0046] A secure storage module generates structured and readable logs and conducts secure transmission and storage of the logs.

[0047] In a third aspect, the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and: when the computer program is executed by the processor, any step of the network fault diagnosis method based on a 5G communication gateway as described in the first aspect of the present invention is implemented.

[0048] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and: when the computer program is executed by the processor, any step of the network fault diagnosis method based on a 5G communication gateway as described in the first aspect of the present invention is implemented.

[0049] The beneficial effects of the present invention are as follows: By extracting the observation vectors in the event window and calculating the Mahalanobis distance, the collaborative anomalies between features can be captured from multiple perspectives. By optimizing the feature weights using the steepest descent method, the model can pay more attention to the most important features for anomaly detection when calculating the Mahalanobis distance, thereby improving the overall detection effect. By dynamically adjusting the weights, the importance difference of features is strengthened, further improving the anomaly detection effect. By accurately modeling the nodes and edge weights at each moment, the temporal dependence relationship and dynamic changes between nodes can be effectively captured. By using standard graph neural network layers to perform graph convolution operations on the time series snapshot sequence, the spatial relationship and time features between nodes are effectively fused, enabling the model to perform excellently in capturing the time-varying characteristics, spatial associations, and historical dependencies of nodes in time series data, and being able to more accurately identify anomalies in cross-time periods and complex structures. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.

[0051] Figure 1This is a flow chart of the network fault diagnosis method based on the 5G communication gateway in Example 1.

[0052] Figure 2 This is a structural diagram of the network fault diagnosis system based on the 5G communication gateway in Example 1. DETAILED DESCRIPTION

[0053] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the accompanying drawings.

[0054] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0055] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.

[0056] Example 1, reference From Figure 1 to Figure 2 , which is the first embodiment of the present invention, and provides a network fault diagnosis method based on a 5G communication gateway, comprising the following steps:

[0057] S1, collects multimodal data of 5G communication gateway, calculates data features and screens abnormal data;

[0058] Preferably, collecting multimodal data of 5G communication gateways, calculating data features and screening abnormal data includes:

[0059] High-frequency data sampling is performed on the physical layer (RSRP, SINR), link layer (packet loss rate, MAC retransmission number), network layer (number of active connections, number of UDP packet losses, TCP link establishment delay, and protocol layer (number of valid / abnormal signaling messages)) of the 5G communication gateway to collect multi-modal raw data, including KPIs, signaling messages, traffic anomalies, and protocol logs;

[0060] The window length is selected and data features including mean, standard deviation, rate of change, maximum and minimum are calculated within the window to form a data feature vector. The principal component analysis method PCA is used to reduce the noise of the collected data at different layers, and the local outlier factor algorithm LOF is used to detect obvious outliers in the denoised data in real time. The data points judged as abnormal by LOF are marked and removed for abnormal data screening.

[0061] Through multi-dimensional anomaly detection and data security protection, significant beneficial effects are brought to the overall solution. The multi-modal data collected from the 5G communication gateway covers multiple key performance indicators (KPIs) and signaling data at the physical layer, link layer, network layer, and protocol layer, enabling the model to comprehensively understand and capture the state changes of the communication network at different levels. The collection of multi-modal data enhances the system's adaptability to complex communication network environments, provides richer input features, and lays a solid foundation for subsequent anomaly detection and fault analysis. PCA can extract the most representative information from the data through dimensionality reduction technology and reduce information loss, thereby enhancing the efficiency and accuracy of subsequent models in processing high-dimensional data. The denoised data is more stable, reducing interference with anomaly detection and ensuring the reliability of anomaly detection results. The application of the Local Outlier Factor (LOF) algorithm can detect obvious outliers in the data in real-time and eliminate these abnormal data. The LOF algorithm identifies abnormal data points based on local density changes and can flexibly handle different types of anomalies, especially being highly sensitive to local anomalies.

[0062] S2. Perform data preprocessing to form a correlation matrix, extract the observation vectors of the event window, calculate the Mahalanobis distance for anomaly marking to construct an initial weight vector, use the steepest descent method to determine the feature-weighted output, optimize the feature weights, obtain the fused feature vector, select highly correlated features to determine the edge weights, and construct snapshot sequences for different time windows;

[0063] Preferably, extract the observation vectors of the event window, calculate the Mahalanobis distance for anomaly marking to construct an initial weight vector, use the steepest descent method to determine the feature-weighted output, optimize the feature weights, obtain the fused feature vector, select highly correlated features to determine the edge weights, and construct snapshot sequences for different time windows, including

[0064] Normalize the data feature vectors after abnormal data screening and align the timestamps, calculate the Pearson correlation coefficients of different types of feature data, and form a correlation matrix C (used to quantitatively describe the correlation degree between all features), expressed as:

[0065]

[0066] where C i,j represents the Pearson correlation coefficient between the i-th feature and the j-th feature within the statistical window, n represents the total number of statistical windows, x i,k,nor and x j,k,nor respectively represent the standardized values of the i-th and j-th features at the k-th sampling point, μ i and μ j respectively represent the averages of the i-th and j-th features, σ i and σ jrespectively represent the standard deviations of the i-th and j-th features;

[0067] Based on the historical correlation threshold, filter the feature pairs with Pearson correlation coefficients greater than or equal to the historical correlation threshold, and extract the observation vector at event window t, denoted as:

[0068]

[0069] where represents the observed values of the i-th and j-th features in the t-time window, [x i,k,nor ,x j,k,nor T represents the transpose of the standardized values of the i-th and j-th features at the k-th sampling point, transposing the original one-row two-dimensional array into a one-column two-dimensional array;

[0070] Take the observed values of two features in the past M windows and calculate the subsample mean and the two-dimensional covariance matrix and calculate the Mahalanobis distance observed at the current time t for each feature combination denoted as:

[0071]

[0072] According to the historical empirical quantile value, for the Mahalanobis distance exceeding the historical empirical quantile value, it is determined that the binary collaborative anomaly of this feature occurs at time t, and an anomaly mark is made;

[0073] Calculate the ratio of the number of occurrences in each feature statistical anomaly mark to the total number of statistical anomaly windows as the single-feature anomaly correlation index value, and perform normalization calculation on all values as the initial value of the weight vector;

[0074] Use the steepest descent method to optimize the feature weights, and define the observed label of each window in the window sequence as O t : If a collaborative anomaly occurs in this window, O t is 1, otherwise it is 0;

[0075] For the historical Q windows, determine the feature weighted output, denoted as:

[0076] S t = w T x t ;

[0077] where S t represents the feature weighted output of the t-th window, w T represents the transpose calculation of the weight vector w, x t represents the standardized data feature vector of the t-th window;

[0078] ​Define the loss function as the weighted mean squared error \(L(w)\), which is expressed as:

[0079]

[0080] Calculate the gradient of the loss function with respect to the weight vector \(w\), use the Adam optimizer for gradient descent optimization to update the weights, and stop the iteration when the loss calculated in consecutive iterations no longer decreases significantly, and output the optimal feature weight vector;

[0081] According to the optimal feature weight vector as the feature description of each acquisition node, perform feature fusion, which is expressed as:

[0082]

[0083] where \(x\) f,t represents the fused feature vector of time window \(t\), represents the transpose of the optimal feature weight vector;

[0084] Using the fused feature values of each window, define the state features of the nodes in the feature space and encode them as the high-dimensional embedding vectors of the nodes. The state features include the fused feature vector, the acquisition device node, the network element, and the service unit;

[0085] Combine the correlation matrix \(C\) to select the edge weights corresponding to the highly correlated feature pairs, and form the adjacency matrix with the edge weights at each moment, which is expressed as:

[0086]

[0087] where \(A\) i,j \((t)\) represents the edge weight of the \(i\)-th and \(j\)-th features at time window \(t\), represents the historical maximum Mahalanobis distance;

[0088] Construct a weighted graph according to the edge weights of each node and each pair of nodes for different time windows to form a sequence of temporal snapshots.

[0089] By normalizing the feature vectors after abnormal data screening and aligning the timestamps, the differences caused by different time and data scales can be effectively eliminated. By calculating the Pearson correlation coefficients of different types of feature data and generating the correlation matrix, it helps to extract the most representative and influential features from high-dimensional data, improving the prediction accuracy and stability of the model;

[0090] By extracting the observation vectors in the event window and calculating the Mahalanobis distance, the collaborative anomalies between features can be captured from multiple perspectives. Especially in a multi-dimensional space, the linkage between the calculation of the Mahalanobis distance and the optimal feature fusion effectively improves the accuracy of anomaly detection and the adaptive ability of the system. By measuring the statistical differences between features, the Mahalanobis distance can accurately mark those data points with significant differences from the historical patterns, which provides strong support for subsequent anomaly marking. And by optimizing the feature weights using the steepest descent method, the model can pay more attention to the most important features for anomaly detection when calculating the Mahalanobis distance, thus improving the overall detection effect;

[0091] During the process of calculating the statistical anomaly marks of each feature and optimizing the feature weights based on the steepest descent method, the weight allocation of the features can be optimized, enabling the model to more precisely focus on the features most valuable for anomaly detection during the training process. By dynamically adjusting the weights, the importance differences of the features are strengthened, further improving the effect of anomaly detection;

[0092] With the determination of the optimal feature weight vector, feature fusion is carried out based on this, effectively enhancing the expression ability and comprehensive utilization efficiency of the features. Feature fusion can not only combine the information of different features but also reduce the negative impact of redundant information on the model, thereby improving the generalization ability of the model;

[0093] The high-dimensional embedding vectors provide rich information for subsequent graph model analysis, thus improving the effect of graph spectrum modeling and the accuracy of the network structure. By accurately modeling the nodes and edge weights at each moment, the temporal dependence relationship and dynamic changes between nodes can be effectively captured, further enhancing the performance of the model in processing temporal data;

[0094] The combination of these steps enables the system to not only make accurate anomaly judgments at static moments but also handle the dynamic changes of temporal data, enhancing the adaptability of the overall system to complex heterogeneous data and improving the accuracy of fault prediction and anomaly detection.

[0095] S3. Construct a node third-order feature tensor, perform graph convolutional layer operations according to the snapshot sequence, perform graph temporal modeling on the embedding vectors of the same node across multiple time steps based on the LSTM neural network, calculate the anomaly score, and determine node anomalies;

[0096] Preferably, constructing a node third-order feature tensor, performing graph convolutional layer operations according to the snapshot sequence, performing graph temporal modeling on the embedding vectors of the same node across multiple time steps based on the LSTM neural network, calculating the anomaly score, and determining node anomalies includes,

[0097] Construct a third-order feature tensor based on the total number of nodes in the detected fault range, the fused eigenvalue, and the sliding window length;

[0098] For the graph snapshots of the time series snapshot sequence, perform graph convolution operations using standard GNN layers;

[0099] Input the embedding vectors of the same node across multiple time steps into the time series modeling layer, and perform graph time series modeling based on the LSTM neural network, expressed as:

[0100]

[0101] where H (g+1) (t) represents the node embedding vector of the g+1 layer in time window t, σ represents the ReLU activation function, represents the normalized adjacency matrix, H (g) (t) represents the node embedding vector of the g layer in time window t (initialized as the node fusion feature vector), W (g) represents the graph convolution layer weight;

[0102]

[0103] where represents the final embedding vector of node i at time t, represents the embedding vector of node i at time t in the L-th layer;

[0104] Use the Sigmoid classification layer to score the anomaly scores of the final embedding vectors;

[0105] Use the calibrated training set to select the cross-entropy loss function to calculate the loss between the true label and the predicted value. Use the chain rule to backpropagate the gradient from the output layer to the graph convolution layer, the time series model, and then to the input parameters. Use the Adam optimizer to perform gradient descent optimization and update the parameters of each layer. Stop the iteration when the loss of the model no longer decreases significantly during continuous iterations, and output the model parameters;

[0106] After training, output the anomaly probability scores of each node, and use the sum of the historical mean and standard deviation as the anomaly threshold. If the anomaly probability score of a node is greater than or equal to the anomaly threshold, it is judged that the node is abnormal.

[0107] By constructing the time series snapshot sequence and combining it with anomaly data screening, the system can continuously monitor the state changes of nodes within multiple time windows, and identify abnormal nodes in real time. Through multi-level analysis of time series data, potential anomalies on long time scales can be identified and responses can be made in a timely manner. The anomaly data screening process makes the time series snapshot sequence more accurate by detecting and removing outliers in real time, avoiding the impact of incorrect anomaly labels on time series analysis;

[0108] By constructing a third-order feature tensor and inputting the cross-time-step embedding vectors of nodes into an LSTM neural network, the dynamic changes of nodes in the time series can be fully captured. This process can effectively handle the time-varying characteristics of nodes in time-series data, enabling the model to not only make predictions at a certain moment but also learn the laws of node state changes over time, improving the model's ability to identify abnormal behaviors, especially those that occur across multiple time steps.

[0109] Use standard Graph Neural Network (GNN) layers to perform graph convolution operations on the time-series snapshot sequence, effectively fusing the spatial relationships and time features between nodes. Through graph convolution operations, the system can better understand the local and global structures between nodes, while extracting potential patterns and dependencies in the graph spectrum. The application of the LSTM neural network further strengthens the model's memory ability in graph time-series modeling, especially in capturing long-term dependencies between nodes and time-series behaviors. LSTM can process time-series data with long time spans through its gating structure. When calculating the anomaly score, use a Sigmoid classification layer to perform anomaly scoring on the final embedding vector, which can directly give the anomaly degree of each node at the current moment.

[0110] Calibrate with historical data. The above steps enable the model to perform excellently in capturing the time-varying characteristics, spatial associations, and historical dependencies of nodes in time-series data, and can more accurately identify anomalies in cross-time periods and complex structures. Through the combination of deep learning and graph neural networks, the system shows extremely high flexibility and accuracy when dealing with heterogeneous data and time-series graph modeling, thereby enhancing the anomaly detection and prediction capabilities and improving the stability and fault prevention capabilities of the overall system.

[0111] S4. Trace back to the upstream nodes of the abnormal nodes, count the associated paths, generate readable logs, and perform secure log storage.

[0112] Preferably, tracing back to the upstream nodes of the abnormal nodes includes

[0113] For all nodes detected as abnormal, trace back the adjacent edges of their maximum anomaly distribution, find the upstream nodes connected by the maximum edge weight, and form a root cause link association path.

[0114] Output the list of abnormal nodes, the anomaly probability scores, and the root cause link association paths.

[0115] By backtracking the maximum abnormal distribution adjacent edges of abnormal nodes to find the connected upstream nodes, the source of the anomaly can be accurately identified and located. The formation of the root cause link not only helps to understand the path of anomaly propagation but also reveals the causal relationship of the anomaly, which is of great significance for the fault diagnosis of the entire system. Because it can help developers or system administrators identify and solve the root problems in the system, rather than just dealing with the surface abnormal phenomena. Precise root cause analysis can greatly improve the speed of fault recovery and reduce the system downtime.

[0116] Furthermore, statistically correlate paths and generate readable logs, including,

[0117] Statistically analyze the abnormal probability distribution of all nodes within the current time window;

[0118] According to the root cause link association path, capture the third-order feature tensor data of the nodes and generate a running report, which is saved as structured text and readable logs.

[0119] By generating readable logs and recording the abnormal probability distribution of all nodes within the current time window, the logs not only provide real-time monitoring and auditing functions for system operation but also provide retrospective support for future fault analysis. These log data provide a detailed record of system behavior, facilitating the review, analysis, and further optimization of abnormal events in the later stage.

[0120] Furthermore, perform secure storage of logs, including,

[0121] Store the log files, protect the transmission link using the TLS protocol, encrypt the transmission content using the AES-256 strong encryption algorithm, and perform integrity verification using the message authentication code MAC.

[0122] Through the storage and transmission of log files, using the TLS protocol to protect the transmission link and the AES-256 encryption algorithm to encrypt the content, ensuring the confidentiality and integrity of data during transmission. This measure greatly enhances data security, preventing data from being intercepted or tampered with during transmission. At the same time, using the message authentication code (MAC) for integrity verification to ensure that the transmitted data has not been tampered with, providing end-to-end security protection.

[0123] This embodiment also provides a system for the network fault diagnosis method based on a 5G communication gateway, including a data feature construction module that collects multimodal data from the 5G communication gateway and constructs feature vectors;

[0124] A feature correlation analysis module that extracts observation vectors within an event window, calculates the Mahalanobis distance to achieve initial anomaly marking, and performs weighted optimization through the method of steepest descent;

[0125] The time window snapshot generation module determines the edge weights between nodes and constructs a graph snapshot sequence;

[0126] The anomaly detection module constructs a node third-order feature tensor, processes the node features of each time snapshot, performs time-series modeling, and scores anomaly scores and determines node anomalies;

[0127] The path association module traces back to its upstream nodes and analyzes the impact paths for the nodes determined to be abnormal;

[0128] The secure storage module generates structured readable logs and performs secure transmission and storage of the logs.

[0129] This embodiment also provides a computer device applicable to the case of a network fault diagnosis method based on a 5G communication gateway, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the network fault diagnosis method based on a 5G communication gateway as proposed in the above embodiment.

[0130] The computer device may be a terminal. The computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device may be a touch layer covered on the display screen, or a button, a trackball, or a touchpad provided on the computer device housing, or an external keyboard, a touchpad, or a mouse, etc.

[0131] This embodiment also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the network fault diagnosis method based on a 5G communication gateway as proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random Access Memory, abbreviated as SRAM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, abbreviated as EEPROM), erasable programmable read-only memory (Erasable Programmable Read Only Memory, abbreviated as EPROM), programmable read-only memory (Programmable Red-Only Memory, abbreviated as PROM), read-only memory (Read-Only Memory, abbreviated as ROM), magnetic memory, flash memory, magnetic disk or optical disc.

[0132] In summary, by extracting the observation vectors in the event window and calculating the Mahalanobis distance, the present invention can capture the collaborative anomalies between features from multiple perspectives. By optimizing the feature weights through the steepest descent method, the model can pay more attention to the most important features for anomaly detection when calculating the Mahalanobis distance, thereby improving the overall detection effect. By dynamically adjusting the weights, the importance difference of features is strengthened, further improving the anomaly detection effect. By accurately modeling the nodes and edge weights at each moment, the temporal dependence relationship and dynamic changes between nodes can be effectively captured. By performing graph convolution operations on the temporal snapshot sequence using standard graph neural network layers, the spatial relationship and time features between nodes are effectively fused, enabling the model to perform excellently in capturing the time-varying characteristics, spatial associations, and historical dependencies of nodes in temporal data, and being able to more accurately identify anomalies in cross-time periods and complex structures.

[0133] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.

Claims

1. A network fault diagnosis method based on a 5G communication gateway, characterized in that, Including: Collecting multi-modal data of 5G communication gateways, calculating data features and screening out abnormal data; Performing data preprocessing to form a correlation matrix, extracting observation vectors of event windows, calculating Mahalanobis distances to make abnormal markings to construct an initial weight vector, using the steepest descent method to determine the feature weighted output, optimizing the feature weights to obtain a fused feature vector, selecting highly correlated features to determine edge weights, and constructing snapshot sequences of different time windows; Constructing a node third-order feature tensor, performing graph convolutional layer operations according to the snapshot sequence, performing graph temporal modeling on the embedding vectors of the same node across multiple time steps based on the LSTM neural network, scoring abnormal scores, and determining node anomalies; Backtracking the upstream nodes of abnormal nodes, counting the associated paths, generating readable logs, and securely storing the logs.

2. The network fault diagnosis method based on a 5G communication gateway according to claim 1, wherein: The extraction of the observation vector of the event window, calculating the Mahalanobis distance to make abnormal markings to construct an initial weight vector, using the steepest descent method to determine the feature weighted output, optimizing the feature weights to obtain a fused feature vector, selecting highly correlated features to determine edge weights, and constructing snapshot sequences of different time windows includes: Normalizing the data feature vectors after abnormal data screening and aligning timestamps, calculating the Pearson correlation coefficients of different types of feature data, and forming a correlation matrix C; Based on the historical correlation threshold, screening out feature pairs with Pearson correlation coefficients greater than or equal to the historical correlation threshold, and extracting the observation vector at time t of the event window; Taking the observed values of two features in the past M windows, calculating the subsample mean and two-dimensional covariance matrix, and calculating the Mahalanobis distance of the current time t observation for each feature combination; Calculating the ratio of the number of occurrences in each feature statistical abnormal marking to the total number of statistical abnormal windows as the single-feature abnormal correlation index value, and performing normalization calculation on all values as the initial value of the weight vector; Optimize the feature weights using the steepest descent method, and define the observed label of each window in the window sequence as O t : If a collaborative anomaly occurs in this window, then O t is 1, otherwise it is 0; For the historical Q windows, determining the feature weighted output, and defining the loss function as the weighted mean square error L(w); Using the optimal feature weight vector as the feature description of each acquisition node for feature fusion; Using the fused feature values of each window to define and encode the state features of the nodes in the feature space as the high-dimensional embedding vectors of the nodes, and the state features include fused feature vectors, acquisition device nodes, network elements, and service units; Combining the correlation matrix C to select the edge weights corresponding to highly correlated feature pairs, and forming an adjacency matrix with the edge weights at each moment; Constructing weighted graphs for different time windows according to the edge weights of each node and each pair of nodes to form a temporal snapshot sequence.

3. The network fault diagnosis method based on a 5G communication gateway according to claim 2, characterized in that: The construction of the node third-order feature tensor, performing graph convolutional layer operations according to the snapshot sequence, performing graph temporal modeling on the embedding vectors of the same node across multiple time steps based on the LSTM neural network, scoring abnormal scores, and determining node anomalies includes: Constructing a third-order feature tensor based on the total number of nodes within the detected fault range, fused feature values, and sliding window length; Performing graph convolutional layer operations on the graph snapshots of the temporal snapshot sequence using standard GNN layers; Input the embedding vectors of the same node across multiple time steps into the time series modeling layer, perform graph time series modeling based on the LSTM neural network, and use the Sigmoid classification layer to score the anomaly score for the final embedding vector; Use the calibrated training set to select the cross-entropy loss function to calculate the loss between the true label and the predicted value. Use the chain rule to backpropagate the gradient from the output layer to the graph convolutional layer, the time series model, and then to the input parameters. Use the Adam optimizer to perform gradient descent optimization and update the parameters of each layer. Stop the iteration when the loss of the model no longer decreases significantly during continuous iterations, and output the model parameters; After training, output the anomaly probability scores of each node, and use the sum of the historical mean and standard deviation as the anomaly threshold. If the anomaly probability score of a node is greater than or equal to the anomaly threshold, it is determined that the node is abnormal.

4. The network fault diagnosis method based on a 5G communication gateway according to claim 3, wherein: The upstream nodes of the traced abnormal nodes include For all nodes detected as abnormal, trace back the adjacent edges of their maximum anomaly distribution, find the upstream nodes connected by the maximum edge weight, and form the root cause link association path; Output the list of abnormal nodes, the anomaly probability scores, and the root cause link association path.

5. The network fault diagnosis method based on a 5G communication gateway according to claim 4, characterized in that: The statistical association path and generate readable logs include Statistically analyze the anomaly probability distribution of all nodes within the current time window; According to the root cause link association path, capture the third-order feature tensor data of the nodes, generate a running report, and save it as structured text and readable logs.

6. The network fault diagnosis method based on a 5G communication gateway according to claim 5, characterized in that: The acquisition of 5G communication gateway multimodal data, calculation of data features, and screening of abnormal data include Perform high-frequency data sampling on the physical layer, link layer, and network layer of the 5G communication gateway to collect multimodal raw data; Select the window length and calculate data features within the window, including mean, standard deviation, change rate, maximum value, and minimum value, to form a data feature vector. Use the principal component analysis method PCA to denoise the collected data of different layers, and use the local outlier factor algorithm LOF to detect obvious outlier data in real time for the denoised data. Mark and remove the data points determined as abnormal by LOF to perform abnormal data screening.

7. The network fault diagnosis method based on a 5G communication gateway according to claim 6, characterized in that: The secure storage of logs includes Store the log files, use the TLS protocol to protect the transmission link, use the AES-256 strong encryption algorithm for the transmission content, and use the message authentication code MAC for integrity verification.

8. A system for a network fault diagnosis method based on a 5G communication gateway, based on the network fault diagnosis method based on a 5G communication gateway according to any one of claims 1 to 7, characterized in that: Include The data feature construction module collects multimodal data from the 5G communication gateway and constructs a feature vector; The feature correlation analysis module extracts the observation vectors within the event window, calculates the Mahalanobis distance to achieve initial anomaly marking, and performs weighted optimization through the steepest descent method; The time window snapshot generation module determines the edge weights between nodes and constructs a graph snapshot sequence; The anomaly detection module constructs a node third-order feature tensor, processes the node features of each time snapshot, performs time series modeling, performs anomaly score scoring and node anomaly determination; The path association module traces back the upstream nodes of the nodes determined as abnormal and analyzes the impact path; The secure storage module generates structured readable logs and performs secure transmission and storage of the logs.

9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that: When the processor executes the computer program, the steps of the network fault diagnosis method based on the 5G communication gateway according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, the steps of the network fault diagnosis method based on the 5G communication gateway according to any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Fault diagnosis method and system for power distribution system

    CN120512431A

  • Method and system for monitoring running state of sludge treatment equipment

    CN121026240A

  • A sludge treatment equipment operation state monitoring method and system

    CN121026240B

  • Information analysis method and device based on artificial intelligence and big data, and medium

    CN121388802A

  • An information analysis method, device and medium based on artificial intelligence and big data

    CN121388802B