Alarm event causal discovery method based on topological neural point process

By encoding the alarm event log and continuous time-long short-term memory network model, combined with system topological connections, the causal relationship of alarm events is solved, and the root cause analysis and credible causal discovery of text-type alarm data are realized.

CN120354936APending Publication Date: 2025-07-22CHINA UNIV OF GEOSCIENCES (WUHAN)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510348822.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The existing alarm causal analysis methods mainly use binary alarm data, ignoring text-type alarm event data and system topological connections, resulting in unreliable causal relationship identification and difficult to provide effective decision support for operators.

Method used

By encoding the alarm event log, a topological neural point process model is constructed using a continuous-time short-term memory network, the conditional causal intensity and normalized conditional causal intensity are designed, and the causal relationship between alarms is identified based on the system topological connection.

Benefits of technology

The root cause analysis of the text-type alarm event data is realized, which improves the credibility of causal discovery, removes false causal relationships, and provides a reliable causal propagation path.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354936A_ABST
    Figure CN120354936A_ABST
Patent Text Reader

Abstract

The invention discloses an alarm event causal discovery method based on a topological neural point process, and relates to the field of industrial process monitoring and alarm monitoring, and the alarm event causal discovery method based on the topological neural point process mainly comprises the steps: carrying out the coding of an alarm event log, and obtaining an alarm event vector and a training set; constructing a topological neural point process model by using a continuous-time long-short-term memory network; according to the training set, utilizing a likelihood function to train the topological neural point process model to obtain a trained topological neural point process model; predicting data to be measured by using the trained topological neural point process model to obtain a condition intensity value; and a final causal relationship is obtained by combining the designed causal relationship indexes and threshold values. According to the alarm event causal discovery method based on the topological neural point process provided by the invention, the root analysis of the alarm can be realized by directly utilizing the alarm event data of the text type, and the credibility of causal discovery is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of industrial process monitoring and alarm monitoring, and more specifically, to a method for discovering the causality of alarm events based on a topological neural point process. Background Art

[0002] In modern industrial systems, all levels and operating units are interconnected. After a fault occurs, it may spread and evolve along the material flow, information flow, and energy flow, causing serious production accidents. How to ensure the safe, stable, and efficient operation of the production process is an urgent concern in the industrial community. As a core component of modern industrial facilities, the monitoring and alarm system constantly monitors the operating status of the production process to ensure safe and stable operation. However, with the reduction of the configuration cost of alarm variables, a large number of alarm signals are triggered under abnormal conditions, and the key alarms related to faults are submerged, making it difficult for operators to take countermeasures.

[0003] By identifying the causal relationships between a large number of alarms, the root cause alarms can be located along the causal path to solve the alarm problem from the source. Although there are some alarm causal analysis methods at present, they mainly use binary alarm data, which is still numerical data in essence, ignoring the text-type alarm event data that is easy to obtain, contains more information, and is directly related to faults in the alarm system. Moreover, the current pure data-driven methods ignore the topological connections between systems, which easily lead to false causal relationships, making the identified alarm causal propagation paths unreliable and difficult to provide effective decision support for operators.

[0004] Therefore, how to directly utilize the text-type alarm event data and consider the topological connections of the actual industrial process to achieve the causal discovery and root cause analysis of alarm events is particularly important.

[0005] The above content is only used to assist in understanding the technical solution of the present invention, and does not represent an admission that the above content is prior art. Summary of the Invention

[0006] The purpose of the present invention is to provide a method for discovering the causality of alarm events based on a topological neural point process, which can directly utilize the text-type alarm event data to achieve the root cause analysis of alarms and improve the credibility of causal discovery.

[0007] The present invention provides a method for discovering the causality of alarm events based on a topological neural point process, including the following steps: S1: Encode the alarm event log to obtain an alarm event vector; obtain a training set according to the alarm event vector; S2: Use a continuous-time long short-term memory network to construct a topological neural point process model; S3: Construct a likelihood function, and train the topological neural point process model using the likelihood function based on the training set to obtain a trained topological neural point process model; use the trained topological neural point process model to predict the data to be measured to obtain a conditional intensity value; S4: Obtain a conditional causal intensity based on the conditional intensity value, and obtain the causal relationship between alarms based on the conditional causal intensity.

[0008] The present invention also provides a computer program product, including a computer program, which implements the steps of the above-mentioned method for discovering the causal relationship of alarm events based on topological neural point processes when executed by a processor.

[0009] Implementing the method for discovering the causal relationship of alarm events based on topological neural point processes provided by the present invention has the following beneficial effects: Aiming at the problem that text alarm event data in an alarm system is difficult to be directly used for calculation and modeling, and the existing pure data-driven causal analysis methods ignore the actual physical connections of the system, the present invention proposes a method for discovering the causal relationship of alarm events based on topological neural point processes to achieve root cause analysis of alarms; specifically, the present invention proposes a new modeling method based on alarm coding and CTLSTM neural point processes to model the alarm event sequence; the present invention designs a new measure of causal relationship based on conditional intensity values, the conditional causal intensity CCI, to identify the Granger causal relationship between alarms, and a normalized conditional causal intensity NCCI to measure the strength of the causal relationship between alarms, introducing a new measure of causal relationship; the present invention establishes a topological matrix by identifying the connection relationships between various parts of the system, which can provide constraint conditions for causal relationship reasoning to remove false causal relationships, creating a new method for causal reasoning under topological constraints; the present invention proposes a method for calculating the causal relationship threshold based on the generation of alternative event sequences, generating alternative sequences of the original event sequence based on the multinomial distribution for calculating the threshold. Description of the Drawings

[0010] The present invention will be further described below in conjunction with the drawings and embodiments. In the drawings: Figure 1 is a flowchart of the method for discovering the causal relationship of alarm events based on topological neural point processes provided by the present invention; Figure 2 is a schematic diagram of the method for discovering the causal relationship of alarm events based on topological neural point processes provided by the present invention; Figure 3 is a framework diagram of the modeling of the alarm event sequence provided by the present invention; Figure 4 is a schematic diagram of the conditional causal intensity provided by the present invention; Figure 5It is a schematic diagram of the system topology connection provided by the present invention; Figure 6 It is a causal relationship diagram provided by the present invention. Detailed implementation manners

[0011] For a clearer understanding of the technical features, objectives, and effects of the present invention, the detailed implementation manners of the present invention will now be described in detail with reference to the accompanying drawings.

[0012] Figure 1 It shows a schematic diagram of the causal discovery method for alarm events based on the topological neural point process in this embodiment. In this embodiment, the causal discovery method for alarm events based on the topological neural point process includes the following steps: S1: Encode the alarm event log to obtain an alarm event vector; according to the alarm event vector, obtain a training set; In an exemplary embodiment, the encoding of the alarm event log to obtain an alarm event vector is as follows: , ,

[0013] where S is the alarm event sequence, represents the i th alarm event, represents the length of the sequence, represents the alarm type of the alarm, represents the time when the alarm occurs, represents the alarm event vector, represents the identity function to capture time features; is the embedding matrix of the alarm, which can be updated during the modeling process; is the alarm type after one-hot encoding; S2: Use a continuous-time long short-term memory network to construct a topological neural point process model; In an exemplary embodiment, step S2 specifically includes: using a continuous-time long short-term memory network to construct a topological neural point process model, as follows: , , , , , , , , Among them, 、 、 and respectively represent the candidate memory unit, input gate, forget gate, and output gate of the m +(1)th alarm event; is the sigmoid function, is the sigmoid function, 、 、 、 、 、 、 、 、 、 respectively represent the weight matrices under different gate mechanisms, represents the m th element in the encoded alarm event sequence, 、 、 、 、 respectively represent the bias vectors under different gate mechanisms, represents the m-th moment, represents the target state 's input gate, represents the target state 's forget gate, 、 、 、 respectively represent the weight matrices under different gate mechanisms of the target state , 、 respectively represent the bias vectors under different gate mechanisms of the target state , represents the initial state of the memory unit, represents the Hadamard product; c ( t ) represents a continuous function used to control the to decay over time; represents the exponential function, represents the parameter controlling the decay rate, is the softplus function, is the hidden layer state at the t moment, is the tanh function, and Represents the conditional intensity function for each type of alarm, represents the alarm weight matrix, represents the conditional intensity function for the entire alarm event sequence, i.e., the conditional intensity value; S3: Construct a likelihood function. According to the training set, use the likelihood function to train the topological neural point process model to obtain a trained topological neural point process model; use the trained topological neural point process model to predict the data to be measured to obtain the conditional intensity value; In an exemplary embodiment, the likelihood function is as follows: , where L is the likelihood function, and are conditional intensity functions.

[0014] S4: Obtain the conditional causal intensity according to the conditional intensity value, and obtain the causal relationship between alarms according to the conditional causal intensity; In an exemplary embodiment, the obtaining the conditional causal intensity according to the conditional intensity value is as follows: , , , where, and represent calculating the future conditional intensity of considering only the history of alarm , and represent calculating the conditional intensity of and considering the history of both alarms , represents the conditional causal intensity from alarm to ; In another exemplary embodiment, the obtaining the conditional causal intensity according to the conditional intensity value is as follows:

[0015] , , , where, and represent calculating considering only the history of alarm Future conditional intensity, and represents calculating while considering the alarm and history to calculate conditional intensity, represents the conditional causal intensity from the alarm to ; For each item of the topological matrix, it represents the topological relationship between process elements; the system topology includes the connections between units and the connections of process elements, and the location of each alarm variable can be represented by a process element p represents, and represent two separate edges, represents the set of all undirected edges in the topological relationship; when it means that there is a topological connection between and , and the topological matrix is a symmetric matrix containing only 0 and 1 elements.

[0016] In an exemplary embodiment, obtaining the causal relationship between alarms according to the conditional causal intensity includes: based on the conditional causal intensity, calculating the CCI value between each alarm: CCI greater than 0 indicates an excitatory type of causal relationship between alarms, and CCI less than 0 indicates an inhibitory type of causal relationship between alarms.

[0017] In an exemplary embodiment, the method for discovering the causal relationship of alarm events based on the topological neural point process further includes: normalizing the conditional causal intensity to obtain the normalized conditional causal intensity; obtaining the causal relationship between alarms according to the normalized conditional causal intensity; In an exemplary embodiment, normalizing the conditional causal intensity to obtain the normalized conditional causal intensity is as shown in the formula: , where, represents the normalized conditional causal intensity from the alarm to ; In an exemplary embodiment, obtaining the causal relationship between alarms according to the normalized conditional causal intensity includes: when the normalized conditional causal intensity is greater than 0, it indicates that there is an excitatory causal relationship between the alarm to ; when the normalized conditional causal intensity is less than 0, to there is an inhibitory causal relationship; when When it is equal to 0, to there is no causal relationship.

[0018] In an exemplary embodiment, the method for discovering the causal relationship of alarm events based on the topological neural point process further includes: calculating a causal relationship threshold using an alternative sequence; obtaining the final causal relationship between alarms according to the normalized conditional causal intensity and the causal relationship threshold; In an exemplary embodiment, the calculating a causal relationship threshold using an alternative sequence includes: given an alarm event sequence S , generating a plurality of alternative sequences ; the plurality of alternative sequences follow a multinomial distribution and satisfy the following conditions: is the same length as S ; the number of unique alarm tags tag in S is the same as that in ; the probability of each alarm tag occurring in S is equal to its proportion in ; using the trained topological neural point process model to predict the plurality of alternative sequences to obtain alternative sequence conditional intensity values; obtaining alternative sequence conditional causal intensities according to the alternative sequence conditional intensity values, normalizing the alternative sequence conditional causal intensities to obtain normalized alternative sequence conditional causal intensities; calculating the mean of the normalized alternative sequence conditional causal intensities, and then adding or subtracting 6 times the standard deviation to obtain the causal relationship threshold ;

[0019] In an exemplary embodiment, the above-mentioned method for discovering causal relationships of alarm events based on topological neural point processes can also be implemented in the following manner. In this embodiment, the alarm event (Alarm&Event, A&E) logs recorded in the alarm system are directly used to discover the causal relationships between alarms. Since the alarm event data is text data and is difficult to directly model and analyze, the alarm event data is first encoded, and each alarm event is encoded into a high-dimensional numerical vector. On this basis, a neural point process modeling method based on alarm encoding and continuous-time long short-term memory network (CTLSTM) is used to establish a neural point process model for each type of alarm event respectively, and learn the influence relationships between different alarms from historical alarm events. Then, a causal relationship metric based on conditional intensity values, that is, conditional causal intensity, is designed to identify the causal relationships and causal intensities between alarms. Finally, the topological connections between systems are extracted using piping and instrumentation diagrams and process flow diagrams to remove spurious causal relationships without actual physical connections, so as to obtain the final alarm causal relationship and propagation path diagram. Figure 2 is a schematic diagram of the method for discovering causal relationships of alarm events based on topological neural point processes; the specific steps of the method for discovering causal relationships of alarm events based on topological neural point processes are as follows: (1) Neural point process modeling of alarm event sequences: For the alarm event sequence, this embodiment proposes a neural point process modeling method based on alarm encoding and CTLSTM to simulate and learn the conditional intensity functions of different alarms; the input is the historical alarm event sequence, and the output is the conditional intensity value of the alarm; specifically, given an alarm event sequence , which contains a series of alarm events recorded in chronological order, where represents the length of the sequence, represents the i -th alarm event, which can be expressed as:

[0020] where represents the tag of the alarm, that is, the alarm type, represents the time when the alarm occurs; first, the text-type alarm events are encoded into vectors as the input of CTLSTM; in this embodiment, the alarm encoding takes into account the occurrence time and type of the alarm to capture the temporal characteristics and type characteristics of the alarm, and the encoded vector of the alarm event can be expressed as:

[0021] where represents the identity function to capture the time characteristics; is the embedding matrix for alarms, which can be updated during the modeling process. is the alarm vector after one-hot encoding; Figure 3 is the framework diagram for modeling the alarm event sequence; compared with the traditional LSTM, CTLSTM can model event sequences with different time intervals and is more suitable for modeling alarm event data; the vector obtained after encoding the alarm events , can be used as the input of CTLSM. The m +(1)th alarm event candidate memory unit , input gate , forget gate and output gate are updated through the following formula:

[0022] where represents the m th element in the encoded alarm event sequence, represents the weight matrix under different gate mechanisms, b represents the bias vector; is the sigmoid function, is the tanh function; In CTLSTM, the initial state of the memory unit is used to represent, and the decayed target state is represented by ; at time , c ( t ) is used as a continuous function to control to decay over time. For , it also has an input gate and a forget gate , which are represented as:

[0023] Then, the initial state of the memory unit and the decayed target state can be calculated as:

[0024] where represents the Hadamard product; according to the above formula, c ( t ) is derived as:

[0025] where is a parameter for controlling the attenuation rate and is calculated as follows:

[0026] Then, at the time t the hidden layer state h( t ) can be calculated as:

[0027] Through the above process, the historical alarm event sequence is embedded into the hidden layer state h( t ); Next, it is necessary to simulate and learn the conditional intensity function of each type of alarm event from the hidden layer state, and the conditional intensity function of each alarm type can be expressed as:

[0028] where is the softplus function, represents the weight matrix of the alarm , which is updated and learned during model training; for the entire alarm event sequence, its conditional intensity function is the sum of the conditional intensity functions of each alarm type, that is:

[0029] The weight matrices in all the above formulas will be learned during the model training process; in terms of model training, the commonly used maximum likelihood method is adopted here. By constructing the likelihood function of the neural point process model and maximizing this likelihood function, the model training is completed; the likelihood function is expressed as:

[0030] where is the sum of the logarithmic intensity functions of historical events, is the integral of the conditional intensity function at time ; After completing the modeling of the historical alarm event sequence using the above steps, the conditional intensity function of each alarm type can be simulated and learned to calculate the conditional intensity of future alarm events.

[0031] (2) Measurement design of conditional causal intensity and discovery of alarm causal relationships: The purpose of this embodiment is to discover the causal relationships between alarm events and then locate the alarm root causes; therefore, based on the conditional intensity values calculated by the neural point process model, a new measure for judging the causal relationships between alarms is designed here. This design idea comes from Granger causality, and it analyzes whether there are causal relationships between variables through the predictive relationships between variables; the definition of Granger causality is that if variablesX and Y historical information of, predict Y the future value of is better than only considering Y the history of, then the variable X is Y the reason for; Therefore, a causal measure called Conditional Causal Intensity (CCI) is designed to analyze the causal relationship between alarm events; Its specific meaning is: If the history data of alarm and are considered simultaneously, the future conditional intensity of will increase or decrease (corresponding to excitation effect and inhibition effect respectively), compared with only considering the history data of, then it is considered that alarm is the reason for; Specifically, when only considering the history of alarm to calculate the future conditional intensity of, it can be calculated by the following formula:

[0032] Next, when considering the history of alarm and simultaneously to calculate the conditional intensity of, it can be calculated by the following formula:

[0033] Then, by comparing the calculation results of the conditional intensity of alarm when considering different historical information, the conditional causal intensity CCI can be calculated as:

[0034] where represents the conditional causal intensity value from alarm to ; By calculating the conditional causal intensity between alarms, their Granger causal relationship can be identified.

[0035] (3) Normalization of conditional causal intensity and calculation of causal intensity: However, due to the large differences in the lengths of different sequences and the number of alarm events occurring in the sequences, the CCI values between alarms in different sequences vary greatly and are difficult to directly compare; Therefore, next, in this embodiment, a new normalization method is defined according to the calculation method of conditional causal intensity to measure the causal intensity between alarms, so that the range of conditional causal intensity is within (-1, 1); The normalized conditional causal intensity NCCI is defined as:

[0036] wherein represents the normalized conditional causal strength value from the alarm to ; theoretically, when is greater than 0, it indicates that there is an excitatory causal relationship from the alarm to ; when is less than 0, to has an inhibitory causal relationship; when is equal to 0, to has no causal relationship. However, due to the influence of factors such as noise, the NCCI between two unrelated alarm events is not necessarily strictly 0, but has a certain value; therefore, in the final analysis of causal relationships, this embodiment proposes a new threshold calculation method, and the specific content is given in point (5).

[0037] (4) Process topology identification and removal of spurious causal relationships: Existing alarm causal analysis methods are mainly pure data-driven methods that ignore the topological connections between systems; to solve this problem, system topology will be considered in alarm causal reasoning; a schematic diagram of the system topology is shown in Figure 5 ; the system topology includes connections between units and connections of process elements, and the location of each alarm variable can be represented by a process element p ; then, the topological relationship between process elements can be represented by a matrix T, and each item of matrix T can be expressed as:

[0038] wherein and represent two separate edges, represents the set of all undirected edges in the topological relationship; when is true, it indicates that there is a topological connection between and , and the topological matrix is a symmetric matrix containing only 0 and 1 elements, that is ; based on the prior knowledge of the process, as well as the process flow diagram and piping and instrumentation diagram, the connection relationship between systems can be analyzed and the topological matrix can be constructed; After considering the system topology, there will be a constraint condition when calculating the conditional strength, that is, only when there is a topological connection between two alarms, it is necessary to calculate the CCI and NCCI between them; therefore, when considering the history of alarms and to calculate When calculating the conditional strength, the formula can be modified to:

[0039] By extracting the system topology as a constraint condition for alarm causal relationship reasoning, false causal relationships without actual physical connections can be avoided, and finally a causal relationship diagram can be obtained.

[0040] (5) Threshold calculation and causal relationship judgment based on surrogate data generation: Based on the analysis in point (3), this embodiment proposes a threshold calculation method based on surrogate event sequence generation; given an alarm event sequence S , multiple surrogate sequences are generated for calculating the NCCI; the surrogate sequence should be the same length as S , and the probability of an alarm occurring is the same; specifically, follows a multinomial distribution and satisfies the following conditions: is the same length as S ; the number of unique alarm tags tag in S is the same as that in ; the probability of each alarm tag occurring in S is equal to its proportion in The threshold is determined by calculating the mean of the NCCI obtained from multiple surrogate sequences, plus or minus 6 times the standard deviation; when , if , it means there is an excitatory causal relationship from to , otherwise there is no causal relationship between them; conversely, when , if , it means there is an inhibitory causal relationship from to ; otherwise, there is no causal relationship between them.

[0041] In an exemplary embodiment, in some embodiments, the above-mentioned alarm event causal discovery method based on topological neural point process can also be implemented in the following manner.

[0042] This embodiment designs an alarm system based on the VAM platform model to verify the effectiveness of the method; the data used comes from the VAM platform, and a large number of alarms are generated by triggering faults to generate A&E logs. In the VAM model, the fault numbered "MAL 15" is a typical fault: Fail Absorber Circulation Pump; when this fault occurs, the flow controller FC430 quickly drops to 0 and an alarm is generated; this is because FC430 is used to maintain the absorber circulation flow; afterwards, the fault will spread along the material flow path, affecting the entire operation process of the absorber, and more and more alarms will appear in succession; therefore, this embodiment collects the alarm event data of this fault for one week, including 13 alarm variables, and the names and corresponding descriptions of these variables are given in Table 1; Table 1: Alarm variable names and corresponding descriptions in the VAM model

[0043] As Figure 2 shown, the proposed method mainly includes the neural point process modeling of the alarm event sequence, the causal relationship identification based on CCI, the causal strength measurement based on NCCI, the causal relationship reasoning based on topological constraints, and the threshold calculation and causal relationship judgment, so as to realize the discovery of the causal relationship and root cause analysis of alarm events; 1. Neural point process modeling of the alarm event sequence: The input of the model is the alarm event sequence collected for one week , and the output is the conditional intensity value of the alarm; first, according to the time and type characteristics of the alarm event, the text event is encoded as a vector, which is used as the input of CTLSTM, a CTLSTM model is established, the historical alarm event sequence is encoded as the hidden layer state h(t), then a conditional intensity function is established for each type of alarm event, and the likelihood function is designed as the training objective of the model, so as to establish the neural point process model of the alarm event sequence; the framework diagram of the alarm event sequence modeling is given in Figure 3 ; 2. Causal relationship identification based on CCI: Based on the designed causal metric, that is, the conditional causal intensity CCI, calculate the CCI values between each alarm; CCI greater than 0 indicates that there is an excitatory type of causal relationship between the alarms, and CCI less than 0 indicates that there is an inhibitory type of causal relationship between the alarms; the schematic diagram of the conditional causal intensity CCI is given in Figure 4 , including two types of influence relationships: excitation and inhibition; 3. Causal strength measurement based on NCCI: Calculate the normalized conditional causal intensity NCCI between each alarm to measure the causal strength. The larger the absolute value of NCCI, the stronger the causal relationship; 4. Causal relationship reasoning based on topological constraints: Based on the prior knowledge of the process, as well as the process flow diagram and the piping & instrumentation diagram, a topological connection diagram between systems can be constructed, which can be used as a constraint condition for causal relationship reasoning, that is, only when there is an actual physical connection between two process elements where the alarms are located, the CCI and NCCI between them are calculated; A schematic diagram of the system topology is shown in Figure 5 and includes different process units and process elements; 5. Threshold calculation and causal relationship judgment: Based on the original alarm event sequence S , multiple alternative sequences are generated according to the multinomial distribution and the conditions it needs to satisfy. The normalized conditional causal intensity is calculated according to the same process, and the average value of multiple groups of results plus or minus six times the variance is used as the threshold for causal relationship judgment , which is compared with the NCCI between alarms to obtain the causal relationship matrix between alarms; When there is a causal relationship between two alarms, the corresponding element in the matrix is 1, otherwise it is 0; Figure 6 Figure 10 shows the causal relationship diagram obtained by using the proposed method; The performance of the method can be represented by the accuracy and the misidentification rate; Their calculation formulas are:

[0044]

[0045] where represents the number of correctly identified elements (including 0 and 1) except the diagonal elements in the causal matrix of the proposed method; N represents the number of all elements (including 0 and 1) except the diagonal elements in the causal matrix; represents the number of correctly identified causal edges (only including 1) in the causal matrix of the proposed method; represents the number of causal edges (only including 1) in the actual causal matrix; In addition, to prove the effectiveness of the proposed method, three other methods are compared here; including two methods using alarm event data: the traditional Hawkes process and the topological Hawkes process, and a method using binary alarm sequences: transfer entropy; The results obtained by different methods are as follows: Table 2: Causal discovery results of different methods

[0046] Table 2 shows that the proposed method has high performance in alarm event causal discovery; Therefore, it can be concluded that the proposed method for alarm event causal discovery based on topological neural point process is effective.

[0047] This embodiment provides a computer program product, including a computer program which, when executed by a processor, implements the steps of the above-mentioned method for discovering the causality of alarm events based on topological neural point processes.

[0048] The embodiments of the present invention have been described above in conjunction with the accompanying drawings. However, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative rather than restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can also make many forms without departing from the spirit and scope protected by the claims of the present invention, and these all fall within the protection scope of the present invention.

Claims

1. A method for discovering the causality of alarm events based on a topological neural point process, characterized in that, Including the following steps: S1: Encode the alarm event log to obtain an alarm event vector; obtain a training set according to the alarm event vector; S2: Use a continuous-time long short-term memory network to construct a topological neural point process model; S3: Construct a likelihood function, and train the topological neural point process model using the likelihood function according to the training set to obtain a trained topological neural point process model; use the trained topological neural point process model to predict the data to be measured to obtain a conditional intensity value; S4: Obtain the conditional causal intensity according to the conditional intensity value, and obtain the causal relationship between alarms according to the conditional causal intensity.

2. The method for discovering the causality of alarm events based on the topological neural point process according to claim 1, characterized in that The encoding of the alarm event log to obtain an alarm event vector is as follows: , , , where S is the alarm event sequence, represents the i th alarm event, represents the length of the sequence, represents the alarm type of the alarm, represents the time when the alarm occurs, represents the alarm event vector, represents the identity function to capture time features; is the embedding matrix of the alarm, which can be updated during the modeling process; is the alarm type after one-hot encoding of the vector.

3. The method for discovering the causality of alarm events based on the topological neural point process according to claim 1, wherein Step S2 specifically includes: using a continuous-time long short-term memory network to construct a topological neural point process model, as follows: , , , , , , , , Among them, , , and respectively represent the candidate memory unit, input gate, forget gate, and output gate of the m +(1)th alarm event ; is the sigmoid function, , , , , , , , , , respectively represent the weight matrices under different gate mechanisms, represents the m th element in the encoded alarm event sequence, , , , , respectively represent the bias vectors under different gate mechanisms, represents the m-th moment, represents the input gate of the target state , represents the forget gate of the target state , , , , respectively represent the weight matrices under different gate mechanisms of the target state , , respectively represent the bias vectors under different gate mechanisms of the target state , represents the initial state of the memory unit, represents the Hadamard product; c ( t ) represents a continuous function for controlling the decay of to over time; represents the exponential function, represents the parameter for controlling the decay rate, is the softplus function, is the hidden layer state at the t th moment, is the tanh function, and represent the conditional intensity functions for each alarm type, represents the weight matrix of the alarm , Represents the conditional intensity function of the entire alarm event sequence, i.e., the conditional intensity value.

4. The method for discovering the causality of alarm events based on the topological neural point process according to claim 1, wherein The likelihood function is as follows: , Among them, L is the likelihood function, and is the conditional intensity function.

5. The method for discovering the causality of alarm events based on the topological neural point process according to claim 1, wherein The obtaining of the conditional causal intensity according to the conditional intensity value is as follows: , , , Among them, and indicate that only the history of alarms is considered to calculate the future conditional intensity, and indicate that the history of both alarms and is considered to calculate the conditional intensity, indicates the conditional causal intensity from alarm to the conditional causal intensity.

6. The method for discovering the causality of alarm events based on the topological neural point process according to claim 1, wherein The obtaining of the conditional causal intensity according to the conditional intensity value is as follows: , , , Among them, and represent calculating the future conditional intensity of only considering the history of alarms, and and represent calculating the conditional intensity of while considering the history of both alarms and ; represents the conditional causal intensity from alarm to ; is each item of the topological matrix, representing the topological relationship between process elements; the system topology includes the connections between units and the connections of process elements, and the position where each alarm variable is located can be represented by a process element p ; and represent two separate edges, represents the set of all undirected edges in the topological relationship; when is the case, it means that there is a topological connection between and , and the topological matrix is a symmetric matrix containing only 0 and 1 elements.

7. The causal discovery method of alarm events based on topological neural point process according to claim 1, characterized in that The alarm event causal discovery method based on a topological neural point process further includes: normalizing the conditional causal intensity to obtain a normalized conditional causal intensity; obtaining the causal relationship between alarms according to the normalized conditional causal intensity.

8. The method for discovering the causality of alarm events based on the topological neural point process according to claim 7, wherein The alarm event causal discovery method based on a topological neural point process further includes: calculating a causal relationship threshold using an alternative sequence; obtaining the final causal relationship between alarms according to the normalized conditional causal intensity and the causal relationship threshold.

9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the alarm event causal discovery method based on a topological neural point process according to any one of claims 1-8.