Abnormal traffic flow detection method and system based on dynamic graph
By constructing dynamic graphs and contrastive learning models, combined with spatiotemporal data augmentation and time-map encoders, the lag and misjudgment problems of traffic flow detection in existing technologies are solved, and accurate positioning and stable detection of abnormal areas in urban road networks are achieved.
Patent Information
- Application Number
- CN202510897386.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-01
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2045-07-01
AI Technical Summary
Existing traffic flow detection technologies are unable to reflect the dynamic spatiotemporal changes of urban road networks in real time, resulting in lag and misjudgment in anomaly detection, and lack of collaborative analysis of anomalies in local road segments and the overall road network status.
An abnormal traffic flow detection method based on dynamic graphs is adopted. By acquiring urban road network data and vehicle trajectory data, a traffic flow tensor is constructed, the similarity and proximity between sub-regions are calculated, similarity graphs and proximity graphs are fused to perform spatiotemporal data augmentation, and a temporal graph encoder and a contrastive learning model are used for training to detect abnormal traffic flow.
It enables in-depth mining of the spatiotemporal characteristics of traffic flow, improves the accuracy and stability of abnormal traffic flow detection, and can accurately identify abnormal areas in complex traffic scenarios.
Smart Images

Figure CN120412286A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of abnormal traffic flow detection, and particularly to an abnormal traffic flow detection method and system based on a dynamic graph. Background Art
[0002] The detection of abnormal urban traffic flow is a core requirement for the optimization and emergency management of intelligent transportation systems. The current mainstream methods mainly rely on the traffic statistical information collected by fixed sensors or the threshold warning mechanism based on historical data. Although such methods can identify significant traffic fluctuations, they are limited by the static analysis framework and are difficult to depict the dynamic spatio-temporal variation characteristics of traffic flow in complex road networks.
[0003] In recent years, the abnormal traffic flow detection technology based on graph neural networks has improved the traffic flow detection accuracy by modeling the road network topology relationship. However, it usually adopts a fixed graph structure and cannot reflect the dynamic evolution characteristics of traffic states in real time, resulting in a lag in abnormal detection. At the same time, existing models mostly focus on single spatial or temporal scale features and lack the collaborative analysis of the correlation between local road section anomalies and the global road network state, which is prone to misjudgment due to the one-sidedness of feature expression.
[0004] The above technical defects make it difficult for existing systems to meet the requirements of real-time and accurate positioning of abnormal areas in high-dynamic urban road networks, restricting the improvement of the active response ability of traffic management. Summary of the Invention
[0005] Embodiments of the present invention provide an abnormal traffic flow detection method and system based on a dynamic graph, which can improve the accuracy of abnormal traffic flow detection.
[0006] To achieve the above object, the embodiments of the present application adopt the following technical solutions.
[0007] According to the first aspect of the present invention, an abnormal traffic flow detection method based on a dynamic graph is provided, including: obtaining urban road network data, and dividing the city into several sub-regions according to the urban road network data; obtaining vehicle trajectory data, with a time interval of Divide time periods, count the traffic flow of sub-regions in each time period, and construct a traffic flow tensor; calculate the similarity between sub-regions according to the traffic flow tensor to construct a similarity graph; obtain the spatial information of the sub-regions and construct an adjacency graph according to the spatial information; fuse the similarity graph and the adjacency graph to obtain an approximate graph; perform time data augmentation on the traffic flow tensor and at the same time perform spatial data augmentation on the approximate graph to construct the local view and global view of the sub-regions in each time period; use a temporal graph encoder to construct a contrastive learning model, and input the local view and global view of the historical time period into the contrastive learning model for training; extract the temporal graph encoder from the trained contrastive learning model, obtain the traffic flow and approximate graph of the sub-regions in the current time period, use the traffic flow as the node attribute corresponding to the sub-regions in the approximate graph, input it into the temporal graph encoder, and obtain the embedding vector of the sub-regions in the current time period; construct a sliding window, collect the embedding vectors within the sliding window, use the Local Outlier Factor algorithm to detect the abnormal embedding vectors within the sliding window, and find the sub-regions with abnormal traffic flow in the current time period according to the abnormal embedding vectors.
[0008] According to an embodiment of the present invention, the urban road network data includes: the spatial information of the city and the spatial information and topological information of the urban road network.
[0009] According to an embodiment of the present invention, the sub-region includes a region number and the spatial information of the sub-region. The spatial information includes the longitude and latitude range, and the topological information includes the connection relationship between urban roads.
[0010] According to an embodiment of the present invention, obtain vehicle trajectory data with a time interval of Divide time periods, count the traffic flow of sub-regions in each time period, and construct a traffic flow tensor, including: obtaining vehicle trajectory data, extracting the start and end trajectories in the vehicle trajectory data, projecting them to the sub-regions according to the start and end points of the start and end trajectories to obtain the start region number and end region number of the start and end trajectories, and counting the traffic flow of the sub-regions in each time period according to the start region number, start time, end region number and end time of the start and end trajectories. The traffic flow includes out-flow and in-flow. The out-flow represents the traffic flow starting from the sub-region, and the in-flow represents the traffic flow arriving at the sub-region; construct a traffic flow tensor with the number of sub-regions, the number of time periods and the traffic flow as the shape.
[0011] According to an embodiment of the present invention, calculate the similarity between sub-regions according to the traffic flow tensor to construct a similarity graph, including: obtaining the historical traffic flow of the sub-regions according to the traffic flow tensor, calculating the Pearson correlation coefficient between the historical traffic flows of the sub-regions, and using the Pearson correlation coefficient as the similarity between the sub-regions; taking several sub-regions with the highest similarity to each sub-region as its similar regions; using the sub-regions as nodes, establishing edges between the sub-regions and their similar regions and constructing a similarity graph; the edge weight in the similarity graph is the similarity between the nodes.
[0012] According to an embodiment of the present invention, obtaining the spatial information of sub-regions, and constructing an adjacency graph based on the spatial information, includes: obtaining the spatial information of sub-regions, calculating the centers of sub-regions according to the spatial information, and calculating the distances between sub-regions according to the centers of sub-regions; taking a number of sub-regions closest to each sub-region as its adjacent regions; using sub-regions as nodes, establishing edges between a sub-region and its adjacent regions and constructing an adjacency graph; the edge weights in the adjacency graph are the distances between nodes.
[0013] According to an embodiment of the present invention, fusing a similarity graph and an adjacency graph to obtain an approximation graph, includes: the nodes of the approximation graph are the same as the nodes in the similarity graph and the adjacency graph, the edges of the approximation graph are the union of the edges in the similarity graph and the adjacency graph, calculating the approximation degree between nodes according to the similarity and the distance, and taking the approximation degree between nodes as the edge weights of the approximation graph. The calculation formula for the approximation degree is:
[0014] ;
[0015] wherein, represents any node in the approximation graph, represents any node adjacent to in the approximation graph, represents the approximation degree between node and node in the approximation graph, is the edge weight between the corresponding nodes and node in the similarity graph, is the edge weight between the corresponding nodes and node in the adjacency graph, is a hyperparameter.
[0016] According to an embodiment of the present invention, time data augmentation is performed on the traffic flow tensor, and spatial data augmentation is performed on the approximate graph to construct local views and global views of sub-regions in each time period, including: adding Gaussian noise to the traffic flow tensor and then scaling it to obtain a first traffic flow tensor; randomly selecting a distortion ratio for each sub-region, randomly selecting a distortion window of the traffic flow tensor for each sub-region in the time period dimension, and stretching or compressing the traffic flow within the distortion window according to the distortion ratio to obtain a second traffic flow tensor; obtaining the adjacency matrix of the neighboring graph, performing heat kernel graph diffusion calculation on the adjacency matrix to obtain the diffusion adjacency matrix of the neighboring graph; setting the edge weights of the approximate graph as the similarity between nodes to obtain a global time graph; calculating and updating the edge weights of the approximate graph according to the diffusion adjacency matrix and the global time graph to obtain a global approximate graph; if an edge in the approximate graph exists in both the diffusion adjacency matrix and the global time graph, representing the element value in the diffusion adjacency matrix as the distance between nodes, representing the edge weight in the global time graph as the similarity between nodes, calculating the approximation degree between nodes according to the distance between nodes and the similarity between nodes, and updating the edge weight of an edge in the approximate graph using the approximation degree between nodes; otherwise, obtaining the distance between nodes from the neighboring graph, representing the edge weight in the global time graph as the similarity between nodes, calculating the approximation degree between nodes according to the distance between nodes and the similarity between nodes, and updating the edge weight of an edge in the approximate graph using the approximation degree between nodes; until the edge weights of all edges in the approximate graph are updated to obtain a global approximate graph; obtaining the traffic flow of the sub-region in each time period from the first traffic flow tensor as the first traffic flow, obtaining the approximate graph of each time period, and taking the first traffic flow as the node attribute in the approximate graph according to the correspondence between nodes and sub-regions in each time period to obtain the local view of the sub-region in each time period; obtaining the traffic flow of the sub-region in each time period from the second traffic flow tensor as the second traffic flow, obtaining the global approximate graph of each time period, and taking the second traffic flow as the node attribute in the global approximate graph according to the correspondence between nodes and sub-regions in each time period to obtain the global view of the sub-region in each time period.
[0017] According to an embodiment of the present invention, training a contrastive learning model by inputting a local view and a global view of a historical time period includes: inputting the local view and the global view of the historical time period into an online network and a target network of the contrastive learning model respectively; encoding node events and edge events using a temporal graph encoder to obtain local embedding vectors and global embedding vectors; inputting the local embedding vectors and the global embedding vectors into a projection head to obtain local contrast vectors and global contrast vectors; predicting the local contrast vectors using a prediction head of the online network to obtain local prediction vectors; calculating the mean squared error between the local prediction vectors and the global contrast vectors to obtain a local loss; inputting the local view and the global view into the target network and the online network of the contrastive learning model respectively, and after the above steps, obtaining a global loss; adding the local loss and the global loss to obtain a total loss, and finally updating the parameters of the contrastive learning model through the total loss.
[0018] According to an embodiment of the present invention, a temporal graph encoder includes: A temporal graph encoder is a deep learning model for dynamic graphs that can model a graph as a series of node events and edge events and capture long-term dependencies of nodes; The temporal graph encoder includes a storage module, a message function module, a message aggregation module, a storage update module, and an embedding module. The storage module is responsible for storing the memory vectors of nodes. The message function module is responsible for calculating timestamp events and generating message vectors. The message aggregation module is used to aggregate multiple message vectors related to the same node in the same batch of training data. The storage update module updates the memory vectors according to the message vectors and the memory vectors. The embedding module is responsible for embedding the memory vectors of nodes to obtain embedding vectors.
[0019] According to an embodiment of the present invention, a node event occurs at a single node and represents updating the attributes of the node in a certain time period, including: An edge event occurs at a pair of nodes. If there is no edge between the pair of nodes in the previous time period, the edge event represents adding a new edge and edge weight between the pair of nodes in the current time period. Otherwise, the edge event represents updating the edge weight between the pair of nodes in the current time period.
[0020] According to an embodiment of the present invention, a contrastive learning model includes: The online network includes a temporal graph encoder, a projection head, and a prediction head. The target network includes a temporal graph encoder and a projection head; The temporal graph encoder and the projection head in the online network have the same structure and initial parameters as those in the target network.
[0021] According to an embodiment of the present invention, the parameter update method of the contrastive learning model includes:
[0022] ;
[0023] Wherein, represents the parameters of the online network, Represent the parameters of the target network, Represent the total loss, Represent the total loss in the online network Gradient, Represent the learning rate, Represent the Adam optimizer for optimizing network parameters; the parameters of the target network According to the online network parameters Perform momentum update, Is the momentum coefficient.
[0024] According to an embodiment of the present invention, a sliding window is constructed, the embedding vectors within the sliding window are collected, the local outlier factor algorithm is used to detect the abnormal embedding vectors within the sliding window, and the sub-regions with abnormal traffic flow in the current time period are found according to the abnormal embedding vectors, including: constructing a sliding window with a size of The sliding window is used to collect the embedding vectors of all sub-regions in the current time period and the historical Number of time periods, calculate the local outlier factors of all embedding vectors within the sliding window using the local outlier factor algorithm, sort the local outlier factors, and obtain the top Proportion of embedding vectors with the largest local outlier factors as candidate abnormal embedding vectors, determine whether the candidate abnormal embedding vectors are in the current time period, and if so, use the candidate abnormal embedding vectors as abnormal embedding vectors; finally, all sub-regions corresponding to the abnormal embedding vectors are used as sub-regions with abnormal traffic flow in the current time period.
[0025] The second aspect of the present invention provides an abnormal traffic flow detection system based on a dynamic graph, including:
[0026] Sub-region division module: used to divide the city into several sub-regions according to urban road network data;
[0027] Traffic flow tensor construction module: used to obtain vehicle trajectory data, divide time periods, count the traffic flow of sub-regions in each time period, and construct a traffic flow tensor;
[0028] Approximate graph generation module: used to calculate the similarity between sub-regions according to the traffic flow tensor, construct a similarity graph, construct a proximity graph according to the spatial information of sub-regions, and fuse the similarity graph and the proximity graph to obtain an approximate graph;
[0029] Spatio-temporal data enhancement module: used to perform time data enhancement on the traffic flow tensor, and at the same time perform spatial data enhancement on the approximate graph to construct local views and global views of sub-regions in each time period;
[0030] Contrast training module: used to input the local views and global views of historical time periods into a contrast learning model for training;
[0031] Anomaly detection module: It is used to extract a temporal graph encoder from the trained contrastive learning model, take the traffic flow of the sub-region in the current time period as the node attributes corresponding to the sub-region in the approximate graph, input it into the temporal graph encoder to obtain the embedding vector of the sub-region in the current time period; construct a sliding window, collect the embedding vectors within the sliding window, use the Local Outlier Factor algorithm to detect the abnormal embedding vectors within the sliding window, and find out the sub-regions with abnormal traffic flow in the current time period according to the abnormal embedding vectors.
[0032] The third aspect of the present invention provides an electronic device, including: a processor and a memory for storing executable instructions that can run on the processor, wherein when the processor is used to run the executable instructions, the executable instructions execute the steps in the above method.
[0033] The fourth aspect of the present invention further provides a non-transitory computer-readable storage medium, on which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, the steps in the above method are implemented.
[0034] The beneficial effects of the present invention are as follows: The present invention provides a method and system for detecting abnormal traffic flow based on a dynamic graph, which innovatively integrates four core modules: approximate graph construction, spatio-temporal data augmentation, temporal graph encoder, and contrastive learning model, and realizes the in-depth mining and discriminative representation learning of the spatio-temporal characteristics of traffic flow. While effectively capturing the complex spatio-temporal dependence relationships in traffic flow, this method and system are outstanding in terms of the stability and accuracy of detecting abnormal traffic flow in complex traffic scenarios, providing a new solution for traffic flow anomaly detection, and at the same time providing valuable reference for the application of dynamic graph neural networks in the field of spatio-temporal data mining. Description of the Drawings
[0035] Through the following description of the embodiments of the present invention with reference to the drawings, the above content and other objects, features, and advantages of the present invention will become clearer. In the drawings:
[0036] Figure 1 Shows a flowchart of a method for detecting abnormal traffic flow based on a dynamic graph according to an embodiment of the present invention;
[0037] Figure 2 Shows a schematic diagram of fusing a proximity graph and a similarity graph into an approximate graph according to an embodiment of the present invention;
[0038] Figure 3 Shows a schematic diagram of a contrastive learning model with a temporal graph encoder according to an embodiment of the present invention;
[0039] Figure 4 Shows a block diagram of the structure of a system for detecting abnormal traffic flow based on a dynamic graph according to an embodiment of the present invention;
[0040] Figure 5 shows a schematic structural diagram of an electronic device according to an embodiment of the present invention;
[0041] Figure 6 shows a schematic structural diagram of a non - temporary computer - readable storage medium according to an embodiment of the present invention. Detailed implementation manners
[0042] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present invention. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a thorough understanding of the embodiments of the present invention. However, obviously, one or more embodiments can be implemented without these specific details. In addition, in the following description, descriptions of well - known structures and technologies are omitted to avoid unnecessarily obscuring the concepts of the present invention.
[0043] The terms used herein are merely for describing specific embodiments and are not intended to limit the present invention. The terms "including", "comprising", etc. used herein indicate the presence of features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0044] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those of ordinary skill in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification, and should not be interpreted in an idealized or overly rigid manner.
[0045] Embodiments of the present invention provide an abnormal traffic flow detection method based on a dynamic graph, including: obtaining urban road network data, dividing the city into several sub - regions according to the urban road network data; obtaining vehicle trajectory data, with a time interval of Divide time periods, count the traffic flow in each sub-region for each time period, and construct a traffic flow tensor; calculate the similarity between sub-regions based on the traffic flow tensor to construct a similarity graph; obtain the spatial information of the sub-regions and construct a proximity graph based on the spatial information; fuse the similarity graph and the proximity graph to obtain an approximate graph; perform temporal data augmentation on the traffic flow tensor and simultaneously perform spatial data augmentation on the approximate graph to construct local and global views of the sub-regions for each time period; use a temporal graph encoder to construct a contrastive learning model, and input the local and global views of historical time periods into the contrastive learning model for training; extract the temporal graph encoder from the trained contrastive learning model, obtain the traffic flow of the sub-regions and the approximate graph for the current time period, use the traffic flow as the node attribute corresponding to the sub-regions in the approximate graph, input it into the temporal graph encoder, and obtain the embedding vectors of the sub-regions for the current time period; construct a sliding window, collect the embedding vectors within the sliding window, use the Local Outlier Factor algorithm to detect the abnormal embedding vectors within the sliding window, and find the sub-regions with abnormal traffic flow for the current time period based on the abnormal embedding vectors.
[0046] Figure 1 FIG. shows a flowchart of an abnormal traffic flow detection method based on a dynamic graph according to an embodiment of the present invention.
[0047] As Figure 1 shown, the abnormal traffic flow detection method based on a dynamic graph in this embodiment includes operations S10 to S70.
[0048] In operation S10, obtain urban road network data, and divide the city into several sub-regions according to the urban road network data.
[0049] In operation S20, obtain vehicle trajectory data, and use the time interval as Divide time periods, count the traffic flow in each sub-region for each time period, and construct a traffic flow tensor.
[0050] In operation S30, calculate the similarity between sub-regions based on the traffic flow tensor, construct a similarity graph, obtain the spatial information of the sub-regions, construct a proximity graph, and fuse the similarity graph and the proximity graph to obtain an approximate graph.
[0051] In operation S40, perform temporal data augmentation on the traffic flow tensor and simultaneously perform spatial data augmentation on the approximate graph to construct local and global views of the sub-regions for each time period.
[0052] In operation S50, use a temporal graph encoder to construct a contrastive learning model, and input the local and global views of historical time periods into the contrastive learning model for training.
[0053] In operation S60, extract the temporal graph encoder from the trained contrastive learning model, obtain the traffic flow and approximate graph of the sub-region in the current time period, use the traffic flow as the node attribute corresponding to the sub-region in the approximate graph, and input it into the temporal graph encoder to obtain the embedding vector of the sub-region in the current time period.
[0054] In operation S70, construct a sliding window, collect the embedding vectors within the sliding window, use the Local Outlier Factor (LOF) algorithm to detect the abnormal embedding vectors within the sliding window, and find the sub-regions with abnormal traffic flow in the current time period based on the abnormal embedding vectors.
[0055] According to an embodiment of the present invention, obtain urban road network data and perform regional division processing to obtain a number of sub-regions. Construct a traffic flow tensor based on vehicle trajectory data, and generate local and global views of traffic flow through dynamic graph modeling and multi-view data augmentation. Input the local and global views into a contrastive learning model for training, and use a temporal graph encoder to capture the spatio-temporal evolution characteristics of traffic flow. Through a sliding window mechanism, combined with the Local Outlier Factor (LOF) algorithm, detect abnormal embedding vectors that deviate from the spatio-temporal pattern, so as to achieve accurate positioning of abnormal regions in urban traffic flow. Through multi-stage joint modeling and contrastive learning mechanisms, effectively improve the accuracy and robustness of traffic anomaly detection.
[0056] According to an embodiment of the present invention, obtain urban road network data, and divide the city into a number of sub-regions according to the urban road network data, including: the urban road network data includes the spatial information of the city and the spatial information and topological information of the urban road network; the sub-region includes a region number and the spatial information of the sub-region, the spatial information includes the longitude and latitude range, and the topological information includes the connection relationship between urban roads.
[0057] According to an embodiment of the present invention, the obtained spatial information and topological information data of the urban road network refer to the geographical location information data composed of urban expressways, main roads, secondary roads and branch roads divided by road grades and the data covering the topological connection relationship of roads; based on the obtained spatial information and topological information data of the urban road network, form a sub-region division result, and finally construct a sub-region set.
[0058] According to an embodiment of the present invention, the sub-region set is shown in formula (1):
[0059]
[0060] Wherein, represents the sub-region set, represents the number of sub-regions, represents the th sub-region, and the sub-region includes a region number and the spatial information of the sub-region, the spatial information includes the longitude and latitude range, and the topological information includes the connection relationship between urban roads.
[0061] According to an embodiment of the present invention, the obtained urban road network data is processed by sub-region division, so as to comprehensively and accurately determine the urban traffic distribution characteristics by analyzing the sub-region division results and traffic flow data.
[0062] According to an embodiment of the present invention, vehicle trajectory data is obtained, and taking the time interval as the time periods are divided, and the traffic flow of each sub-region in each time period is counted to construct a traffic flow tensor, including: obtaining vehicle trajectory data, extracting the start and end trajectories in the vehicle trajectory data, projecting them onto the sub-region according to the start point and end point of the start and end trajectories to obtain the start region number and end region number of the start and end trajectories, and counting the traffic flow of each sub-region in each time period according to the start region number, start time, end region number and end time of the start and end trajectories. The traffic flow includes out-flow and in-flow. The out-flow represents the traffic flow starting from the sub-region, and the in-flow represents the traffic flow arriving at the sub-region; a traffic flow tensor is constructed with the number of sub-regions, the number of time periods and the traffic flow as the shape.
[0063] According to an embodiment of the present invention, preferably, the vehicle trajectory data is segmented at a time interval of 30 minutes as shown in formula (2):
[0064]
[0065] wherein, represents the set of divided time periods, represents the number of time periods, represents the th time period, and adjacent time periods satisfy the condition .
[0066] According to an embodiment of the present invention, according to the start and end trajectories in the vehicle trajectory data, the in-flow of the sub-region in the time period and the out-flow are counted. The initial values of the in-flow and the out-flow are both 0. Analyze the vehicle trajectory data. If the start time of the vehicle trajectory data shows that it enters the sub-region from other sub-regions within the time period , then . If the end time of the vehicle trajectory shows that it enters other sub-regions from the sub-region within the time period , then . According to the in-flow and the out-flow , the traffic flow is constructed.
[0067] According to an embodiment of the present invention, a traffic flow tensor is constructed for a shape according to the number of sub-regions , the number of time periods , and the traffic flow . .
[0068] According to an embodiment of the present invention, vehicle trajectory data containing multi-dimensional spatio-temporal features is structurally analyzed and flow modeled, so as to comprehensively characterize the dynamic evolution law of urban traffic by constructing a traffic flow tensor and improve the accuracy of urban traffic state analysis.
[0069] According to an embodiment of the present invention, the similarity between sub-regions is calculated based on the traffic flow tensor, and a similarity graph is constructed, including: obtaining the historical traffic flow of the sub-regions according to the traffic flow tensor, calculating the Pearson correlation coefficient between the historical traffic flows of the sub-regions, and using the Pearson correlation coefficient as the similarity between the sub-regions; taking several sub-regions with the highest similarity to each sub-region as its similar regions; using the sub-regions as nodes, establishing edges between the sub-regions and their similar regions and constructing a similarity graph; the edge weight in the similarity graph is the similarity between the nodes.
[0070] According to an embodiment of the present invention, based on the traffic flow tensor , the historical traffic flow of the sub-regions is obtained, and the single-day traffic flow feature similarity between the sub-region and the sub-region is calculated based on the Pearson coefficient. Further, the calculation method of the inflow similarity between the sub-region in the time period and the sub-region is shown in formula (3):
[0071]
[0072] where represents the inflow similarity between the sub-region in the time period and the sub-region , represents the inflow of the sub-region in the time period , represents the average inflow of the sub-region in the 48 time periods of the previous historical day in the time period , represents the inflow of the sub-region in the time period , represents the average inflow of the sub-region in the 48 time periods of the previous historical day in the time period .
[0073] According to an embodiment of the present invention, according to the sub-region and the sub-region the inflow similarity between and the outflow similarity calculate the similarity between the sub-regions and the sub-region For the sub-region set except for the sub-region among the sub-regions, calculate their similarity with the sub-region in the time period and sort them in ascending order, select the first sub-regions with the smallest similarity, and construct them as the similar regions of the sub-region in the time period In the time period the similarity calculation method between the sub-region and the sub-region is shown in formula (4):
[0074]
[0075] wherein represents the inflow similarity between the sub-region in the time period and the sub-region represents the outflow similarity between the sub-region in the time period and the sub-region .
[0076] According to an embodiment of the present invention, according to the similar regions of the sub-region construct the set of similar edges between sub-regions in the time period ; combine the set of similar edges with the sub-region set take the sub-region as the node to obtain the similarity graph in the time period wherein, the weight of the edge between the sub-region and the sub-region in the similarity graph is equal to and the similarity between ]>.
[0077] According to an embodiment of the present invention, the similarity between sub-regions in a sub-region set is calculated based on the traffic flow tensor and the Pearson coefficient, thereby constructing a similarity graph, effectively improving the accuracy of traffic flow correlation analysis.
[0078] According to an embodiment of the present invention, spatial information of sub-regions is obtained, and a proximity graph is constructed based on the spatial information, including: obtaining spatial information of sub-regions, calculating sub-region centers based on the spatial information, and calculating distances between sub-regions based on the sub-region centers; taking several sub-regions closest to each sub-region as its proximity regions; using sub-regions as nodes, establishing edges between sub-regions and their proximity regions and constructing a proximity graph; the edge weights in the proximity graph are the distances between the nodes.
[0079] According to an embodiment of the present invention, based on the spatial information of urban road network data and the sub-region set , calculate the sub-region center The sub-region center and calculate the sub-region With the sub-area set except The Euclidean distance between subregions, where is the size of the sub-region set; after sorting the Euclidean distance in ascending order, select the sub-region The first one with the smallest Euclidean distance Sub-regions are constructed into sub-regions Neighboring areas , neighboring areas The expression of is shown in formula (5):
[0080]
[0081] in, Indicates sub-area neighboring areas, Indicates returning the parameter set corresponding to the minimum value that meets the conditions. Represents a sub-region set Middle sub-regions, Indicates excluding subregions from the full set R After the collection elements, Represents a sub-region set Middle sub-regions, Indicates sub-area With sub-region The Euclidean distance between .
[0082] According to an embodiment of the present invention, based on the adjacent area Construct a set of adjacent edges between sub-regions , The expression of is shown in formula (6):
[0083]
[0084] Among them, represents the set of adjacent edges between sub-regions, represents the th sub-region in the set of sub-regions, represents the th sub-region in the set of sub-regions, represents the sub-region and the sub-region The normalized Euclidean distance between them, represents the th adjacent region of the sub-region.
[0085] According to an embodiment of the present invention, the set of adjacent edges is combined with the set of sub-regions Taking the sub-region as a node, an adjacent graph is obtained, where the weight of the edge between the sub-region and the sub-region is equal to and The normalized Euclidean distance between them.
[0086] According to an embodiment of the present invention, by constructing an adjacent graph, the spatial association relationship between sub-regions is comprehensively and accurately characterized.
[0087] According to an embodiment of the present invention, the similarity graph and the adjacent graph are fused to obtain an approximate graph, including: the nodes of the approximate graph are the same as those in the similarity graph and the adjacent graph, the edges of the approximate graph are the union of the edges in the similarity graph and the adjacent graph, the approximation degree between nodes is calculated according to the similarity and distance, and the approximation degree between nodes is used as the edge weight of the approximate graph.
[0088] Figure 2 shows a schematic diagram of fusing the adjacent graph and the similarity graph into an approximate graph according to an embodiment of the present invention;
[0089] As Figure 2 shown, according to the Euclidean distance and Pearson similarity between sub-regions, an adjacent graph and a similarity graph are constructed. After fusing the adjacent graph and the similarity graph, the nodes and edges in the adjacent graph and the similarity graph exist in the approximate graph.
[0090] According to an embodiment of the present invention, fusing an adjacent graph and a similar graph to obtain an approximate graph includes: the nodes of the approximate graph are the same as those in the similar graph and the adjacent graph, the edges of the approximate graph are the union of the edges in the similar graph and the adjacent graph, calculating the approximation degree between nodes according to the similarity and distance, and using the approximation degree between nodes as the edge weight of the approximate graph. The calculation method of the approximation degree is shown in formula (7):
[0091]
[0092] Wherein, represents any node in the approximate graph, represents the approximate graph and any adjacent node, represents the node in the approximate graph and the node the approximation degree between, is the corresponding node in the similar graph and the node the edge weight between, is the corresponding node in the adjacent graph and the node the edge weight between, is a hyperparameter.
[0093] According to an embodiment of the present invention, according to the adjacent edge set and the time period the union of the similar edge sets construct the time period the approximate edge set , the time period the approximate edge set is represented as shown in formula (8):
[0094]
[0095] Wherein, represents the dynamic approximate edge set of the time period , is the adjacent edge set, represents the time period the similar edge set .
[0096] According to an embodiment of the present invention, fusing the adjacent graph and the time period the similar graph to obtain the time period the approximate graph , wherein, represents the sub-region set, represents the time period The dynamic approximate edge set; according to the weights of the edges in the proximity graph and the time period The weights of the similar graph edges , calculate to obtain the time period The weights of the approximate graph edges .
[0097] According to an embodiment of the present invention, the proximity graph and the similar graph are fused to obtain the dual characteristics of sub-region spatial proximity and traffic flow similarity. Dynamically reconstruct the traffic flow association network to accurately extract the dynamic approximate relationships between sub-regions.
[0098] According to an embodiment of the present invention, time data augmentation is performed on the traffic flow tensor, and at the same time, spatial data augmentation is performed on the approximate graph to construct the local view and the global view of each sub-region in each time period, including: adding Gaussian noise to the traffic flow tensor and then scaling it to obtain the first traffic flow tensor; randomly selecting a distortion ratio for each sub-region, in the time period dimension, randomly selecting a distortion window of the traffic flow tensor for each sub-region, and stretching or compressing the traffic flow within the distortion window according to the distortion ratio to obtain the second traffic flow tensor; obtaining the adjacency matrix of the proximity graph, performing heat kernel graph diffusion calculation on the adjacency matrix to obtain the diffusion adjacency matrix of the proximity graph; setting the edge weights of the approximate graph as the similarity between nodes to obtain the global time graph; calculating and updating the edge weights of the approximate graph according to the diffusion adjacency matrix and the global time graph to obtain the global approximate graph; if an edge in the approximate graph exists in both the diffusion adjacency matrix and the global time graph, representing the element value in the diffusion adjacency matrix as the distance between nodes, representing the edge weight in the global time graph as the similarity between nodes, calculating the approximation degree between nodes according to the distance between nodes and the similarity between nodes, and updating the edge weight of a certain edge in the approximate graph using the approximation degree between nodes; otherwise, obtaining the distance between nodes from the proximity graph, representing the edge weight in the global time graph as the similarity between nodes, calculating the approximation degree between nodes according to the distance between nodes and the similarity between nodes, and updating the edge weight of a certain edge in the approximate graph using the approximation degree between nodes; until the edge weights of all edges in the approximate graph are updated to obtain the global approximate graph; obtaining the traffic flow of each sub-region in each time period from the first traffic flow tensor as the first traffic flow, obtaining the approximate graph of each time period, and taking the first traffic flow as the node attribute in the approximate graph according to the correspondence between nodes and sub-regions in each time period to obtain the local view of each sub-region in each time period; obtaining the traffic flow of each sub-region in each time period from the second traffic flow tensor as the second traffic flow, obtaining the global approximate graph of each time period, and taking the second traffic flow as the node attribute in the global approximate graph according to the correspondence between nodes and sub-regions in each time period to obtain the global view of each sub-region in each time period.
[0099] According to an embodiment of the present invention, Gaussian noise is added to each element in the traffic flow tensor to obtain a jittered traffic flow tensor . The jittered traffic flow tensor is globally scaled to obtain a first traffic flow tensor . The operations of adding Gaussian noise and global scaling are shown in Formulas (9) and (10):
[0100]
[0101]
[0102] wherein, represents the traffic flow of the sub-region after jittering during the time period , represents the traffic flow of the sub-region during the time period , represents a random variable that follows a zero-mean Gaussian distribution , represents the noise variance, represents the first traffic flow tensor of the sub-region during the time period , represents a scaling factor generated according to the normal distribution , represents the variance of the scaling factor.
[0103] According to an embodiment of the present invention, a window with a size of is randomly selected from the sub-region in the traffic flow tensor . The window is distorted with a distortion ratio of and a range of to obtain a distorted window with a size of . Linear interpolation is performed on the distorted window area in the time series to obtain a second traffic flow tensor .
[0104] wherein, the window distortion ratio , represents the upper bound of distortion, represents the lower bound of distortion; the distorted window range is expressed as: , wherein, represents the traffic flow of the sub-region , represents a moment in the time series of the randomly selected sub-region , represents the size of the distorted window.
[0105] According to an embodiment of the present invention, the adjacency matrix adjacent to FIG is subjected to a heat kernel diffusion operation to obtain a diffusion adjacency matrix . Based on the adjacency matrix of the approximate graph , a global time graph is constructed. The weight of the edge in the global time graph is consistent with the weight of the similarity graph . Among them, the heat kernel diffusion process is shown in formula (11):
[0106]
[0107] Where is the diffusion adjacency matrix, represents the natural exponential function, represents the diffusion time, represents the adjacency matrix of the adjacent graph diagonal matrix.
[0108] According to an embodiment of the present invention, according to the weights of the edges of the diffusion adjacency matrix and the weights of the edges of the global time graph, the weights of the edges of the approximate graph are updated. Specifically: for the edges that exist in both the diffusion adjacency matrix and the global time graph, according to the weights of the edges representing distance in the diffusion adjacency matrix and the weights of the edges representing similarity in the global time graph, the weights of the edges of the approximate graph are recalculated using formula (7). For the edges that only exist in the global time graph, according to the distance between sub-regions and the weights of the edges representing similarity in the global time graph, the weights of the edges of the approximate graph are recalculated using formula (7) until the weights of all the edges in the approximate graph are updated, and finally the global approximate graph is obtained.
[0109] According to an embodiment of the present invention, the sub-region and its neighbor nodes are used to construct a sub-graph set of the sub-region ; the traffic flow of the sub-region in each time period is obtained from the first traffic flow tensor as the first traffic flow . The approximate graph of each time period is obtained. In each time period , according to the correspondence between the nodes and the sub-region , the first traffic flow is used as the approximate graph The node attributes in each time period of the local view ; Obtain the sub-region from the second traffic flow tensor in each time period of the traffic flow as the second traffic flow , obtain the global approximate graph for each time period , in each time period , according to the correspondence between the nodes and the sub-region regard the second traffic flow as the node attributes in the global approximate graph to obtain the sub-region in each time period of the global view , in the time period of the sub-region of the local view and the global view are calculated as shown in formulas (12) and (13):
[0110]
[0111]
[0112] where represents the local view of the sub-region , represents the strong time enhancement operation, represents the length of the sampled time series, represents from to the time instance of the sub-graph set containing the sub-region , is the traffic flow tensor, represents the adjacency matrix of the approximate graph, represents the weak time enhancement operation, represents the adjacency matrix of the global approximate graph.
[0113] According to the embodiments of the present invention, by performing noise perturbation and scaling processing on the traffic flow tensor, the robustness of the model to random interference is enhanced. Based on the strong time enhancement tensor generated by window distortion and linear interpolation, the non-linear fluctuations and local mutation characteristics of the traffic flow are effectively captured. Through the spatial enhancement view constructed by heat kernel diffusion and global time graph fusion, the dynamic spatial correlation between sub-regions is modeled.
[0114] According to an embodiment of the present invention, a contrastive learning model is constructed using a temporal graph encoder. The local view and global view of the historical time period are input into the contrastive learning model for training, including: inputting the local view and global view of the historical time period into the online network and target network of the contrastive learning model respectively; encoding node events and edge events using the temporal graph encoder to obtain local embedding vectors and global embedding vectors; inputting the local embedding vectors and global embedding vectors into a projection head to obtain local contrast vectors and global contrast vectors; predicting the local contrast vectors using the prediction head of the online network to obtain local prediction vectors; calculating the mean square error between the local prediction vectors and the global contrast vectors to obtain a local loss; inputting the local view and global view into the target network and online network of the contrastive learning model respectively, and obtaining a global loss through the above steps; adding the local loss and the global loss to obtain a total loss, and finally updating the parameters of the contrastive learning model through the total loss.
[0115] According to an embodiment of the present invention, the temporal graph encoder is a deep learning model for dynamic graphs, which can model a graph as a series of node events and edge events and capture the long-term dependencies of nodes; the temporal graph encoder includes a storage module, a message function module, a message aggregation module, a storage update module, and an embedding module. The storage module is responsible for storing the memory vectors of nodes, the message function module is responsible for calculating timestamp events and generating message vectors, the message aggregation module is used to aggregate multiple message vectors related to the same node in the same batch of training data, the storage update module updates the memory vectors according to the message vectors and memory vectors, and the embedding module is responsible for embedding the memory vectors of nodes to obtain embedding vectors.
[0116] According to an embodiment of the present invention, a node event occurs at a single node, indicating the update of the node's attributes in a certain time period; an edge event occurs at a node pair. If there is no edge between the node pair in the previous time period, the edge event indicates the addition of a new edge and edge weight between the node pair in the current time period, otherwise the edge event indicates the update of the edge weight between the node pair in the current time period.
[0117] According to an embodiment of the present invention, exemplarily, a set of events is constructed based on the changes between multiple approximate graphs within a certain time interval among them , where represents the event at time and includes two types of node events and edge events where represents the attributes of the sub-region at time , that is, the node event of node . If the sub-region Indicates adding a sub-region of the node attribute, otherwise it indicates updating the sub-region of the node attribute, represents the sub-region at a certain moment and the edge weight of the sub-region , that is, the node and the node of the edge event. If the node and the node of the edge first appears in the event set , it indicates adding the edge weight, otherwise it indicates updating the edge weight.
[0118] According to an embodiment of the present invention, the time graph encoder constructs the node attributes and edge weights related to any sub-region before a certain moment into the memory vector of the node , and stores it in the storage module of the time graph encoder.
[0119] According to an embodiment of the present invention, according to the event set , in the message function module, for each node event related to the sub-region , a message function for updating the corresponding memory vector in the storage module of the time graph encoder is generated. For each edge event related to the sub-region , two message functions for updating the memory vector are generated. The message functions when the node event and the edge event occur are shown in formulas (14), (15) and (16) respectively:
[0120]
[0121]
[0122]
[0123] Among them, represents the message of the node where the node event occurs at a certain moment , represents the memory vector of the node before a certain moment , represents the node event of the node at a certain moment , A message function that implements the splicing operation on the input vector, Indicates at The node where the edge event occurs at the moment Of the message, Indicates the node Before at The memory vector of the moment, Indicates the time embedding vector, Indicates The node at the moment And the node Of the edge event, Indicates at The node where the edge event occurs at the moment Of the message.
[0124] According to an embodiment of the present invention, in the message aggregation module, the messages generated by multiple events involving the same node in the same training batch are aggregated, and the operation of aggregating the messages involving the node Is as shown in formula Shown:
[0125]
[0126] Among them, Indicates the message after the aggregation operation on the message involving the node , Indicates that there are Messages involving the node In the current batch training, Indicates that in the current batch, the node involved Of the Message.
[0127] According to an embodiment of the present invention, according to the aggregated message, in the storage update module, the gated recurrent unit is used to update the memory vector in the storage module of the time graph encoder, and the calculation processes of the update process are respectively as shown in formula (18), formula (19), formula (20) and formula (21):
[0128]
[0129]
[0130]
[0131]
[0132] Among them, Indicates the update gate in the gated recurrent unit, Refers to the Sigmoid activation function, represents the trainable parameter matrix in the update gate, represents a node at the memory vector before time represents the message after the aggregation operation involving node represents the trainable bias vector in the update gate, represents the reset gate in the gated recurrent unit, represents the trainable parameter matrix in the reset gate, represents the trainable bias vector in the reset gate, represents the candidate state in the gated recurrent unit, represents the trainable parameter matrix in the candidate state, represents the dot product between vectors, represents the trainable bias vector in the candidate state, at time, the memory vector updated for node
[0133] According to an embodiment of the present invention, the memory vector updated for node at time is used as the embedding vector of the time graph encoder and stored in the embedding module of the time graph encoder.
[0134] According to an embodiment of the present invention, the time graph encoder can efficiently model the time-evolving graph structure and node interactions. By combining graph neural networks and time encoding, it captures the long-term dependencies of traffic flow by storing and updating node memories. On this basis, through the incremental update of the memory vector by the gated recurrent unit, it captures the long-term dependencies and dynamic evolution patterns of traffic flow.
[0135] Figure 3 Shows a schematic diagram of a contrastive learning model with a time graph encoder according to an embodiment of the present invention.
[0136] As Figure 3 shown, the contrastive learning model augments the input traffic flow tensor data into local views and global views, and sends them to an online network and a target network with a time graph encoder and a projection head for processing respectively. The online network outputs a prediction vector, and the target network outputs a contrastive feature vector. The model is trained by calculating the local loss between the two.
[0137] According to an embodiment of the present invention, the local view of the sub-region obtained after data augmentation Encode the time graph encoders of the online network and the target network in the contrastive learning model respectively to obtain the local embedding vector and the global embedding vector of the sub-region as shown in Formulas (22) and (23):
[0138]
[0139]
[0140] wherein, represents the local embedding vector of the sub-region , represents the time graph encoder in the online network, represents the local view of the sub-region , represents the global embedding vector of the sub-region , represents the global view of the sub-region , represents the time graph encoder in the target network.
[0141] According to an embodiment of the present invention, input the local embedding vector and the global embedding vector of the sub-region into the projection heads of the online network and the target network in the contrastive learning model respectively for feature mapping, to obtain the local contrast vector and the global contrast vector of the sub-region , and the feature mapping process is as shown in Formulas (24) and (25):
[0142]
[0143]
[0144] wherein, represents the local contrast vector of the sub-region , represents the projection head composed of a linear layer, a batch normalization layer, a rectified linear unit and a linear layer in the online network, represents the local embedding vector of the sub-region , represents the global contrast vector of the sub-region , represents the projection head composed of a linear layer, a batch normalization layer, a rectified linear unit and a linear layer in the target network, represents the global embedding vector of the sub-region .
[0145] According to an embodiment of the present invention, a sub-region of the local comparison vector is input into a multi-layer perceptron having the same structure as the projection head in the online network to obtain a local prediction vector . The local prediction vector is aligned with the global comparison vector of the target network, and a local loss is calculated. The local loss function is as shown in formula (26):
[0146]
[0147] wherein, represents the local loss, represents the local prediction vector and the dot product of the global prediction vector , represents the norm of the local prediction vector, represents the norm of the global prediction vector.
[0148] According to an embodiment of the present invention, the process of obtaining the local prediction vector is as shown in formula (27):
[0149]
[0150] wherein, represents the local prediction vector of the sub-region , represents the multi-layer perception in the online network, represents the sub-region of the local comparison vector.
[0151] According to an embodiment of the present invention, the global comparison vector of the sub-region is input into a multi-layer perceptron in the online network to obtain a global prediction vector and align it with the local comparison vector of the target network, calculate the global loss, and add the local loss and the global loss to obtain the total loss function of the contrast learning model. The total loss function is as shown in formula (28):
[0152]
[0153] wherein, represents the total loss function, represents the local loss function, represents the global loss function.
[0154] According to an embodiment of the present invention, the local view and the global view of the traffic flow tensor are input into a contrastive learning model for training. According to the total loss of the contrastive learning model and the Adam optimizer, the network parameters of the contrastive learning model are updated to obtain the temporal graph encoder in the trained contrastive learning model. The process of updating the network parameters is shown in formulas (29) and (30):
[0155]
[0156]
[0157] wherein, represents the parameters in the online network, represents the Adam optimizer, represents the total loss of the contrastive learning model of the gradient, represents the learning rate, represents the parameters in the target network, represents the momentum coefficient.
[0158] According to an embodiment of the present invention, in the traffic flow anomaly detection task, the contrastive learning model can effectively learn the discriminative feature representation of the traffic flow, thereby improving the performance of anomaly detection. The contrastive learning model can capture the spatio-temporal dependence relationship of the traffic flow, and by comparing the feature differences between normal samples and abnormal samples, enhance the model's ability to identify abnormal patterns.
[0159] According to an embodiment of the present invention, the temporal graph encoder is extracted from the trained contrastive learning model, the traffic flow and the approximate graph of the sub-region in the current time period are obtained, the traffic flow is used as the node attribute corresponding to the sub-region in the approximate graph, and input into the temporal graph encoder to obtain the embedding vector of the sub-region in the current time period.
[0160] According to an embodiment of the present invention, obtain the traffic flow in the current time period , according to the traffic flow tensor construct the approximate graph in the current time period , use the traffic flow as the node attribute corresponding to the sub-region in the approximate graph to obtain the event set in the current time period.
[0161] According to an embodiment of the present invention, input the event set in the current time period into the trained temporal graph encoder to obtain the embedding vector
[0162] According to an embodiment of the present invention, a sliding window is constructed, the embedded vectors within the sliding window are collected, and the local outlier factor algorithm is used to detect the outlier embedded vectors within the sliding window. The sub-regions with abnormal traffic flow in the current time period are found based on the outlier embedded vectors, including: constructing a sliding window with a size of and using the sliding window to collect the embedded vectors of all sub-regions in the current time period and the historical time periods. The local outlier factors of all the embedded vectors within the sliding window are calculated using the local outlier factor algorithm, the local outlier factors are sorted, and the top embedded vectors with the largest local outlier factors are obtained as candidate outlier embedded vectors. It is determined whether the candidate outlier embedded vectors are in the current time period. If so, the candidate outlier embedded vectors are used as outlier embedded vectors; finally, the sub-regions corresponding to all the outlier embedded vectors are used as the sub-regions with abnormal traffic flow in the current time period.
[0163] According to an embodiment of the present invention, a sliding window is used to collect the set of embedded vectors within the sliding window of the current time period . The process of collecting the set of embedded vectors within the sliding window is shown in formula (31):
[0164]
[0165] where represents the set of sliding windows of the current time period , represents the embedded vector of the sub-region at time , represents the time span of the sliding window, represents the sub-region , represents the set of sub-regions.
[0166] According to an embodiment of the present invention, using the local outlier factor algorithm, the local outlier factor of each embedded vector within the sliding window of the current time period is calculated;
[0167] According to an embodiment of the present invention, all the local outlier factors are sorted in descending order, and the top proportion of the embedded vectors with the highest local outlier factor values are selected as candidate outlier embedded vectors ;
[0168] According to an embodiment of the present invention, it is determined the moment corresponding to the candidate outlier embedded vector Whether it is the current time period , if satisfied , then mark the candidate abnormal embedding vector as the final abnormal embedding vector;
[0169] According to an embodiment of the present invention, the sub-region corresponding to the final abnormal embedding vector is used as the abnormal area location of urban traffic flow in the current time period .
[0170] According to an embodiment of the present invention, the local outlier factor algorithm is used to calculate the outlier factor of the embedding vector, without relying on a global fixed threshold or a unified standard to detect outliers, thereby reducing the possibility of false alarms or missed detections. The sparse outliers are filtered through a sliding window mechanism to ensure that the historical traffic flow trends are fully considered when detecting outliers, avoiding the high false positive rate problem caused by the method of using a fixed threshold or a specific ratio to select abnormal areas within a certain time period.
[0171] Based on the above abnormal traffic flow detection method based on a dynamic graph, the present invention also provides an abnormal traffic flow detection system based on a dynamic graph. The following will be combined with Figure 4 to describe this system in detail.
[0172] Figure 4 shows a structural block diagram of an abnormal traffic flow detection system based on a dynamic graph according to an embodiment of the present invention.
[0173] As Figure 4 shown, the abnormal traffic flow detection system 400 based on a dynamic graph in this embodiment includes a sub-region division module 410, a traffic flow tensor construction module 420, an approximate graph generation module 430, a spatio-temporal data enhancement module 440, a contrast training module 450, and an abnormal detection module 460.
[0174] The sub-region division module 410 is used to divide the city into several sub-regions according to urban road network data. In one embodiment, the sub-region division module 410 can be used to perform the operation S10 described above, which will not be elaborated here.
[0175] The traffic flow tensor construction module 420 is used to obtain vehicle trajectory data, divide time periods, count the traffic flow in each sub-region in each time period, and construct a traffic flow tensor. In one embodiment, the traffic flow tensor construction module 420 can be used to perform the operation S20 described above, which will not be elaborated here.
[0176] The approximate graph generation module 430 is used to calculate the similarity between sub-regions based on the traffic flow tensor, construct a similarity graph, construct a proximity graph according to the spatial information of the sub-regions, and fuse the similarity graph and the proximity graph to obtain an approximate graph. In one embodiment, the approximate graph generation module 430 can be used to perform the operation S30 described above, which will not be elaborated here.
[0177] The spatio-temporal data augmentation module 440 is used to perform time data augmentation on the traffic flow tensor, and at the same time perform spatial data augmentation on the approximate graph to construct local views and global views of the sub-regions in each time period. In one embodiment, the spatio-temporal data augmentation module 440 can be used to perform the operation S40 described above, which will not be elaborated here.
[0178] The contrast training module 450 is used to input the local views and global views of historical time periods into the contrast learning model for training. In one embodiment, the contrast training module 450 can be used to perform the operation S50 described above, which will not be elaborated here.
[0179] The anomaly detection module 460 is used to extract a temporal graph encoder from the trained contrast learning model, take the traffic flow of the sub-regions in the current time period as the node attributes corresponding to the sub-regions in the approximate graph, input it into the temporal graph encoder to obtain the embedding vectors of the sub-regions in the current time period; construct a sliding window, collect the embedding vectors within the sliding window, use the local outlier factor algorithm to detect the outlier embedding vectors within the sliding window, and find the sub-regions with abnormal traffic flow in the current time period according to the outlier embedding vectors. In one embodiment, the anomaly detection module 460 can be used to perform the operation S60 and the operation S70 described above, which will not be elaborated here.
[0180] Figure 5 The structural schematic diagram of an electronic device suitable for implementing the abnormal traffic flow detection method based on a dynamic graph according to an embodiment of the present invention is shown.
[0181] As Figure 5 shown, the electronic device according to an embodiment of the present invention includes: a memory 510 and a processor 520. The memory 510 includes an internal memory and a non-volatile storage medium, and is used to store executable instructions that can run on the processor. The non-volatile storage medium stores an operating system and a computer program, and when the computer program is executed by the processor 520, it is used to implement the method of any one of the above embodiments. The processor 520 is used to implement the steps of the abnormal traffic flow detection method based on a dynamic graph in the foregoing embodiments when executing the computer program.
[0182] Figure 6 The structural schematic diagram of a non-transitory computer-readable storage medium suitable for implementing the abnormal traffic flow detection method based on a dynamic graph according to an embodiment of the present invention is shown.
[0183] As Figure 6 shown, a non - temporary computer - readable storage medium 600 according to an embodiment of the present invention stores a computer program 610. When the computer program 610 is executed by a processor 520, it implements the steps of the abnormal traffic flow detection method based on a dynamic graph in the foregoing embodiments.
[0184] The above are only the preferred embodiments of the present application, and do not limit the patent scope of the present application. Any equivalent structural or equivalent process transformation made by using the content of the specification and drawings of the present application, or directly or indirectly applied to other related technical fields, shall be equally included in the patent protection scope of the present application.
Claims
1. An abnormal traffic flow detection method based on a dynamic graph, characterized in that, The method includes: Obtain urban road network data, and divide the city into several sub-regions according to the urban road network data; Obtain vehicle trajectory data and divide time periods at a time interval of to count the traffic flow in each sub-region during each time period and construct a traffic flow tensor; Calculate the similarity between sub-regions according to the traffic flow tensor, and construct a similarity graph; Obtain the spatial information of the sub-regions, and construct an adjacency graph according to the spatial information; Fuse the similarity graph and the adjacency graph to obtain an approximate graph; Perform time data augmentation on the traffic flow tensor, and at the same time perform spatial data augmentation on the approximate graph to construct local views and global views of the sub-regions in each time period; Use a temporal graph encoder to construct a contrastive learning model, and input the local views and global views of the historical time periods into the contrastive learning model for training; Extract the temporal graph encoder from the trained contrastive learning model, obtain the traffic flow of the sub-regions in the current time period and the approximate graph, use the traffic flow as the node attributes corresponding to the sub-regions in the approximate graph, and input them into the temporal graph encoder to obtain the embedding vectors of the sub-regions in the current time period; Construct a sliding window, collect the embedding vectors within the sliding window, use the Local Outlier Factor (LOF) algorithm to detect the abnormal embedding vectors within the sliding window, and find the sub-regions with abnormal traffic flow in the current time period according to the abnormal embedding vectors.
2. The abnormal traffic flow detection method based on a dynamic graph according to claim 1, characterized in that, The urban road network data includes the spatial information of the city and the spatial information and topological information of the urban road network; The sub-regions include a region number and the spatial information of the sub-regions. The spatial information includes the longitude and latitude range, and the topological information includes the connection relationship between urban roads.
3. The abnormal traffic flow detection method based on a dynamic graph according to claim 1, characterized in that, The vehicle trajectory data is obtained, with a time interval of The time periods are divided, the traffic flow in each sub-region in each time period is counted, and a traffic flow tensor is constructed, including: Obtain vehicle trajectory data, extract the start and end trajectories in the vehicle trajectory data, project them to the sub-regions according to the start and end points of the start and end trajectories to obtain the start region number and end region number of the start and end trajectories, and count the traffic flow of the sub-regions in each time period according to the start region number, start time, end region number, and end time of the start and end trajectories. The traffic flow includes out-flow and in-flow. The out-flow represents the traffic flow departing from the sub-region, and the in-flow represents the traffic flow arriving at the sub-region; construct a traffic flow tensor with the number of sub-regions, the number of time periods, and the traffic flow as the shape.
4. The abnormal traffic flow detection method based on a dynamic graph according to claim 1, wherein, The calculating the similarity between sub-regions according to the traffic flow tensor and constructing a similarity graph includes: Obtain the historical traffic flow of the sub-regions according to the traffic flow tensor, calculate the Pearson correlation coefficient between the historical traffic flows of the sub-regions, and use the Pearson correlation coefficient as the similarity between sub-regions; take several sub-regions with the highest similarity to each sub-region as its similar regions; use the sub-regions as nodes, establish edges between the sub-regions and their similar regions, and construct a similarity graph; the edge weights in the similarity graph are the similarities between nodes.
5. The abnormal traffic flow detection method based on a dynamic graph according to claim 1, characterized in that, The obtaining the spatial information of the sub-regions and constructing an adjacency graph according to the spatial information includes: Obtain the spatial information of the sub-regions, calculate the centers of the sub-regions according to the spatial information, and calculate the distances between the sub-regions according to the centers of the sub-regions; take several sub-regions closest to each sub-region as its neighboring regions; use the sub-regions as nodes, establish edges between the sub-regions and their neighboring regions, and construct a neighboring graph; the edge weights in the neighboring graph are the distances between the nodes.
6. The abnormal traffic flow detection method based on a dynamic graph according to claim 1, characterized in that The fusion of the similarity graph and the neighboring graph to obtain an approximate graph includes: The nodes of the approximate graph are the same as the nodes in the similarity graph and the neighboring graph, the edges of the approximate graph are the union of the edges in the similarity graph and the neighboring graph, calculate the approximation degree between the nodes according to the similarity and the distance, and use the approximation degree between the nodes as the edge weights of the approximate graph. The calculation formula of the approximation degree is: ; Among them, represents any node in the approximate graph, represents in the approximate graph any adjacent node, represents the node in the approximate graph and node the approximation degree between, is the corresponding node in the similarity graph and node the edge weight between, is the corresponding node in the proximity graph and node the edge weight between, is a hyperparameter.
7. For an abnormal traffic flow detection method based on a dynamic graph as described in claim 1, where time data augmentation is performed on the traffic flow tensor, and at the same time, spatial data augmentation is performed on the approximate graph to construct local and global views of sub-regions in each time period, it is characterized in that including: Add Gaussian noise to the traffic flow tensor and then scale it to obtain a first traffic flow tensor; Randomly select a distortion ratio for each sub-region, and in the time period dimension, randomly select a distortion window of the traffic flow tensor for each sub-region, and stretch or compress the traffic flow within the distortion window according to the distortion ratio to obtain a second traffic flow tensor; Obtain the adjacency matrix of the neighboring graph, perform heat kernel graph diffusion calculation on the adjacency matrix to obtain the diffusion adjacency matrix of the neighboring graph; set the edge weights of the approximate graph as the similarity between the nodes to obtain a global time graph; calculate and update the edge weights of the approximate graph according to the diffusion adjacency matrix and the global time graph to obtain a global approximate graph; If an edge in the approximate graph exists in both the diffusion adjacency matrix and the global time graph, represent the element value in the diffusion adjacency matrix as the distance between the nodes, represent the edge weight in the global time graph as the similarity between the nodes, calculate the approximation degree between the nodes according to the distance between the nodes and the similarity between the nodes, and use the approximation degree between the nodes to update the edge weight of an edge in the approximate graph; otherwise, obtain the distance between the nodes from the neighboring graph, represent the edge weight in the global time graph as the similarity between the nodes, calculate the approximation degree between the nodes according to the distance between the nodes and the similarity between the nodes, and use the approximation degree between the nodes to update the edge weight of an edge in the approximate graph; until the update of the edge weights of all edges in the approximate graph is completed, obtain a global approximate graph; Obtain the traffic flow of the sub-regions in each time period from the first traffic flow tensor as the first traffic flow, obtain the approximate graph of each time period, and use the first traffic flow as the node attribute in the approximate graph according to the corresponding relationship between the nodes and the sub-regions in each time period to obtain the local view of the sub-regions in each time period; Obtain the traffic flow of the sub-regions in each time period from the second traffic flow tensor as the second traffic flow, obtain the global approximate graph of each time period, and use the second traffic flow as the node attribute in the global approximate graph according to the corresponding relationship between the nodes and the sub-regions in each time period to obtain the global view of the sub-regions in each time period.
8. The abnormal traffic flow detection method based on a dynamic graph according to claim 1, wherein The time graph encoder is a deep learning model for dynamic graphs, which can model a graph as a series of node events and edge events and capture the long-term dependencies of nodes; The time graph encoder includes a storage module, a message function module, a message aggregation module, a storage update module, and an embedding module. The storage module is responsible for storing the memory vectors of nodes. The message function module is responsible for calculating timestamp events and generating message vectors. The message aggregation module is used to aggregate multiple message vectors related to the same node in the same batch of training data. The storage update module updates the memory vectors according to the message vectors and the memory vectors. The embedding module is responsible for embedding the memory vectors of nodes to obtain embedding vectors.
9. The abnormal traffic flow detection method based on a dynamic graph according to claim 1, wherein The contrastive learning model includes an online network and a target network; The online network includes a time graph encoder, a projection head, and a prediction head. The target network includes a time graph encoder and a projection head. The time graph encoder and the projection head in the online network have the same structure and initial parameters as those in the target network.
10. The abnormal traffic flow detection method based on a dynamic graph according to claim 1, characterized in that, The step of inputting the local view and the global view of the historical time period into the contrastive learning model for training includes: Inputting the local view and the global view of the historical time period into the online network and the target network of the contrastive learning model respectively; Encoding node events and edge events using the time graph encoder to obtain local embedding vectors and global embedding vectors; Inputting the local embedding vectors and the global embedding vectors into the projection head to obtain local contrastive vectors and global contrastive vectors; Predicting the local contrastive vectors using the prediction head of the online network to obtain local prediction vectors; Calculating the mean square error between the local prediction vectors and the global contrastive vectors to obtain a local loss; Inputting the local view and the global view into the target network and the online network of the contrastive learning model respectively, and obtaining a global loss through the above steps; Adding the local loss and the global loss to obtain a total loss, and finally updating the parameters of the contrastive learning model through the total loss.
11. The abnormal traffic flow detection method based on a dynamic graph according to claim 1, characterized in that, The step of constructing a sliding window, collecting the embedding vectors within the sliding window, detecting the abnormal embedding vectors within the sliding window using the local outlier factor algorithm, and finding the sub-regions with abnormal traffic flow in the current time period based on the abnormal embedding vectors includes: Construct a sliding window with a size of , and use the sliding window to collect the embedding vectors of all sub-regions in the current time period and the historical time periods. Calculate the local outlier factor of all the embedding vectors within the sliding window using the local outlier factor algorithm, sort the local outlier factors, and obtain the top proportion of the embedding vectors with the largest local outlier factors as candidate outlier embedding vectors. Determine whether the candidate outlier embedding vectors are in the current time period. If so, regard the candidate outlier embedding vectors as outlier embedding vectors; finally, regard all the sub-regions corresponding to the outlier embedding vectors as the sub-regions with abnormal traffic flow in the current time period.
12. The abnormal traffic flow detection method based on a dynamic graph according to claim 8, characterized in that, The node event occurs at a single node, indicating the update of the node's attributes in a certain time period; The edge event occurs at a pair of nodes. If there is no edge between the pair of nodes in the previous time period, the edge event indicates the addition of a new edge and edge weights between the pair of nodes in the current time period. Otherwise, the edge event indicates the update of the edge weights between the pair of nodes in the current time period.
13. A method for detecting abnormal traffic flow based on a dynamic graph according to claim 10, characterized in that, The parameter update method of the contrastive learning model is: ; Among them, represents the parameters of the online network, represents the parameters of the target network, represents the total loss, represents the total loss in the online network of the gradient, represents the learning rate, represents the Adam optimizer for optimizing network parameters; the parameters of the target network are updated with momentum according to the online network parameters is the momentum coefficient. 14. An abnormal traffic flow detection system based on a dynamic graph, characterized in that, Implementing an abnormal traffic flow detection method based on dynamic graphs according to any one of claims 1 to 13 above, including: A sub-region division module: used to divide a city into several sub-regions according to urban road network data; A traffic flow tensor construction module: used to obtain vehicle trajectory data, divide time periods, count the traffic flow of sub-regions in each time period, and construct a traffic flow tensor; Approximate Graph Generation Module: It is used to calculate the similarity between sub-regions according to the traffic flow tensor, construct a similarity graph, construct an adjacency graph according to the spatial information of the sub-regions, and fuse the similarity graph and the adjacency graph to obtain an approximate graph; Spatio-Temporal Data Augmentation Module: It is used to perform temporal data augmentation on the traffic flow tensor, and at the same time perform spatial data augmentation on the approximate graph to construct local views and global views of the sub-regions in each time period; Contrastive Training Module: It is used to input the local views and the global views in the historical time period into a contrastive learning model for training; Anomaly Detection Module: It is used to extract a temporal graph encoder from the trained contrastive learning model, use the traffic flow of the sub-regions in the current time period as the node attributes corresponding to the sub-regions in the approximate graph, input it into the temporal graph encoder to obtain the embedding vectors of the sub-regions in the current time period; construct a sliding window, collect the embedding vectors within the sliding window, use the local outlier factor algorithm to detect the abnormal embedding vectors within the sliding window, and find the sub-regions with abnormal traffic flow in the current time period according to the abnormal embedding vectors.
15. An electronic device, characterized in that, It at least includes: a processor and a memory for storing executable instructions that can run on the processor, wherein: When the processor is used to run the executable instructions, the executable instructions execute the steps in a method for detecting abnormal traffic flow based on a dynamic graph according to any one of claims 1 to 13 above.
16. A non-transitory computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are executed by the processor, the steps in a method for detecting abnormal traffic flow based on a dynamic graph according to any one of claims 1 to 13 above are implemented.
Citation Information
Patent Citations
City fine-grained flow prediction method and system based on time-space comparison self-supervision
CN113962460A
Traffic flow prediction model construction method and prediction method based on adaptive dynamic graph
CN116187555A
Regional anomaly detection method based on urban sub-region hotspot intersection mining
CN116631195A
Encrypted traffic anomaly detection method and device based on deep learning
CN116933195A
Multi-view fusion space-time dynamic graph convolutional network urban traffic flow prediction method
CN116935649A
Cited By
Multi-vehicle cooperative trajectory prediction method and system based on federated learning
CN120808608A
A multi-vehicle cooperative trajectory prediction method and system based on federated learning
CN120808608B