Network element anomaly prediction method and device, network equipment, medium and program product

By classifying the network element operation data and forward noise processing, diffusion exception index data is generated, and using Transformer and U-Net neural network training models, the data imbalance in core network element anomaly prediction is solved, and prediction performance and network stability are improved.

CN120475429AActive Publication Date: 2025-08-12CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510686794.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-08-12
Estimated Expiration
2045-05-26

AI Technical Summary

Technical Problem

In the prior art, the frequency of faults in the core network key network element occurs very low, resulting in serious imbalance in network element index data. The existing network element abnormal model is difficult to effectively learn and predict abnormalities, resulting in poor prediction performance and inability to effectively warn.

Method used

By classifying network element operation data by index type, performing forward noise addition processing to build a noise addition index sequence, fusing normal index data and noise addition index sequence, generating diffusion exception index data, using Transformer encoder and U-Net neural network for data fusion and denoising, and constructing network element timing data to train anomaly prediction model.

Benefits of technology

It effectively alleviates the problem of network element data imbalance, improves the prediction model's learning and prediction ability of abnormal indicators, enhances the detection ability of network element anomalies, and improves the stability and reliability of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120475429A_ABST
    Figure CN120475429A_ABST
Patent Text Reader

Abstract

The invention provides a network element anomaly prediction method and device, network equipment, a medium and a program product, and relates to the technical field of wireless communication. The network element anomaly prediction method comprises the following steps: dividing collected network element operation data in a core network into normal index data and original anomaly index data based on different index types; performing forward noise addition processing based on a time sequence on the original abnormal index data, and constructing a noise addition index sequence; fusing the corresponding normal index data and the noise adding index sequence based on the time sequence to obtain a fused sequence; performing inverse operation of forward noise addition processing on the fusion sequence to obtain diffusion anomaly index data; and constructing network element time sequence data based on the normal index data and the diffusion anomaly index data so as to train an anomaly prediction model based on the network element time sequence data. According to the technical scheme of the invention, the problem of network element data imbalance is effectively relieved, and the learning capability of the prediction model on abnormal indexes and the prediction capability on network element anomalies are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of wireless communication technology, and in particular to a network element anomaly prediction method, a network element anomaly prediction device, a network device, a computer-readable storage medium, and a computer program product. Background Art

[0002] In modern communication networks, the core network, as a key hub of the communication network, is of vital importance for its stability and reliability. Although network element failures occur very rarely, once a key core network element fails, it will cause millions of terminal devices to perceive the network anomaly in a very short time (usually within a few minutes) and trigger a large number of registration or session re-establishment requests, seriously affecting the network service quality and user experience. Therefore, there is an urgent need for a solution that can detect network element indicator anomalies in advance to prevent network element failures.

[0003] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute prior art known to ordinary technicians in the field. Summary of the Invention

[0004] The purpose of the present disclosure is to provide a network element anomaly prediction method, a network element anomaly prediction device, a network device, a storage medium and a computer program product, which at least to a certain extent overcome the problem of poor performance of network element fault prediction in related technologies.

[0005] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by practice of the present disclosure.

[0006] According to one aspect of the present disclosure, a network element anomaly prediction method is provided, comprising: dividing the collected network element operation data in the core network into normal indicator data and original abnormal indicator data based on different indicator types; performing time-series-based forward noise processing on the original abnormal indicator data to construct a noisy indicator sequence; fusing the corresponding normal indicator data and the noisy indicator sequence based on the time series to obtain a fused sequence; performing an inverse operation of the forward noise processing on the fused sequence to obtain diffused abnormal indicator data; constructing network element time series data based on the normal indicator data and the diffused abnormal indicator data, training an anomaly prediction model based on the network element time series data, and performing a network element anomaly prediction operation based on the trained anomaly prediction model.

[0007] In one embodiment of the present disclosure, a time-series-based forward noise addition process is performed on the original abnormal indicator data to construct a noise-added indicator sequence, including: constructing multiple moments based on the time series, and determining the original abnormal indicator data as abnormal data at the initial moment; starting from the initial moment, gradually adding real noise values to the abnormal data based on the multiple moments to obtain the noise-added indicator sequence.

[0008] In one embodiment of the present disclosure, gradually adding real noise values to the abnormal data based on the multiple moments includes: performing the addition of the real noise value between two adjacent moments based on the attenuation coefficient and the noise data that obeys the normal distribution in the time series.

[0009] In one embodiment of the present disclosure, the corresponding normal indicator and the noisy indicator sequence are fused based on the time series to obtain a fused sequence, including: converting the normal indicator data into an indicator data vector; inputting the indicator data vector into a Transformer encoder to perform an encoding operation to obtain a normal encoding vector; performing a fusion operation on the normal encoding vector and the noisy indicator sequence to obtain the fused sequence.

[0010] In one embodiment of the present disclosure, a fusion operation is performed on the normal coding vector and the noisy indicator sequence to obtain the fused sequence, including: inputting the normal coding vector and the noisy indicator sequence into a cross-attention layer based on the time sequence; in the cross-attention layer, taking the noisy indicator sequence as a query and the normal coding vector as a key value, calculating the attention weight between the noisy indicator sequence and the normal coding vector, so that the noisy indicator sequence focuses on key information in the normal indicator data; and integrating the key information into the noisy indicator sequence to obtain the fused sequence.

[0011] In one embodiment of the present disclosure, a fusion operation is performed on the normal coding vector and the noisy indicator sequence to obtain the fused sequence, including: performing a layer normalization operation on the noisy indicator sequence to obtain a normalized sequence; compressing the normal coding vector into a fixed-length representation based on global pooling; extracting a scaling factor and an offset from the fixed-length representation based on a multi-layer perceptron; and adjusting the normalization parameters of the normalized sequence based on the scaling factor and the offset to fuse information in the normal indicator data into the noisy indicator sequence to obtain the fused sequence.

[0012] In one embodiment of the present disclosure, an inverse operation of the forward denoising process is performed on the fused sequence to obtain diffusion anomaly index data, including: generating an inverse denoising model based on a neural network having an encoding layer and a decoding layer; inputting the fused sequence into the inverse denoising model and performing a multi-step iterative denoising operation as an inverse operation of the forward denoising process; configuring an iteration termination condition based on the multiple moments, so as to stop the iteration operation when detecting that the multi-step iterative denoising operation satisfies the iteration termination condition, and obtain the diffusion anomaly index data.

[0013] In one embodiment of the present disclosure, the fused sequence is input into the inverse denoising model, and a multi-step iterative denoising operation is performed, including: in an initial iterative denoising cycle, the fused sequence is input into the encoding layer to perform feature extraction on the fused sequence based on the encoding layer to obtain indicator feature information; the indicator feature information is input into the decoding layer to predict noise based on the indicator feature information and the noise distribution at the current moment to obtain a predicted noise value; the predicted noise value is subtracted from the fused sequence to obtain denoised data of the iterative denoising cycle, and the denoised data is used as input information of the encoding layer of the next iterative denoising cycle.

[0014] In one embodiment of the present disclosure, generating an inverse denoising model based on a neural network having an encoding layer and a decoding layer also includes: calculating an error value between the corresponding predicted noise value and the true noise value; calculating a mean square error based on the error value; and if it is detected that the mean square error is greater than an error threshold, optimizing the inverse denoising model.

[0015] In one embodiment of the present disclosure, network element time series data is constructed based on the normal indicator data and the diffusion abnormality indicator data to train an abnormality prediction model based on the network element time series data, including: aligning the normal indicator data and the diffusion abnormality indicator data based on the time series to obtain aligned indicator data; merging the aligned indicator data belonging to the same time period based on timestamp information to obtain corresponding data samples to obtain the network element time series data based on multiple data samples on the time series; adding a sample label to each of the data samples to train the abnormality prediction model based on the sample label.

[0016] According to another aspect of the present disclosure, a network element anomaly prediction device is provided, including: a division module, used to divide the collected network element operation data in the core network into normal indicator data and original abnormal indicator data based on different indicator types; a noise processing module, used to perform time-series-based forward noise processing on the original abnormal indicator data to construct a noisy indicator sequence; a fusion module, used to fuse the corresponding normal indicator data and the noisy indicator sequence based on the time series to obtain a fused sequence; an inverse operation module, used to perform an inverse operation of the forward noise processing on the fused sequence to obtain diffused abnormal indicator data; a model training module, used to construct network element time series data based on the normal indicator data and the diffused abnormal indicator data, so as to train an anomaly prediction model based on the network element time series data, and perform network element anomaly prediction operations based on the trained anomaly prediction model.

[0017] According to another aspect of the present disclosure, a network device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; the processor is configured to execute the network element abnormality prediction method of the first aspect by executing the executable instructions.

[0018] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned network element abnormality prediction method is implemented.

[0019] According to another aspect of the present disclosure, a computer program product is provided, on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned network element abnormality prediction method is implemented.

[0020] The network element anomaly prediction solution provided by the embodiments of the present disclosure can clearly distinguish between normal and original abnormal situations by classifying network element operation data according to indicator type, performing forward noise addition processing on the original abnormal indicator data, and constructing a noisy indicator sequence, thereby enriching the expression form and diversity of the abnormal data. Furthermore, the normal indicator data is integrated with the noisy indicator sequence so that the characteristics and rules of the normal data can guide the abnormal data processing, and the inverse operation of the forward noise addition is performed to generate the diffusion abnormal indicator data, which can further mine the potential abnormal characteristics. The network element time series data is constructed based on the normal indicator data and the diffusion abnormal indicator data. Through the randomness of the forward noise addition, the probability sampling of the reverse denoising and the conditional constraints of the normal data, a large amount of diversified, reasonable and time-series-compliant diffusion abnormal indicator data is generated from the limited original abnormal data, effectively alleviating the imbalance problem of network element data and improving the prediction model's learning of abnormal indicators and the prediction ability of network element anomalies.

[0021] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The accompanying drawings are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification, are used to explain the principles of the present disclosure. Obviously, the drawings described below are only some embodiments of the present disclosure, and those skilled in the art can derive other drawings based on these drawings without inventive effort.

[0023] Figure 1 A flowchart of a method for predicting network element abnormality according to an embodiment of the present disclosure is shown;

[0024] Figure 2 A flowchart showing another network element abnormality prediction method according to an embodiment of the present disclosure is shown;

[0025] Figure 3 A flowchart of another network element abnormality prediction method according to an embodiment of the present disclosure is shown;

[0026] Figure 4 A flowchart showing another network element abnormality prediction method according to an embodiment of the present disclosure is shown;

[0027] Figure 5 A schematic diagram illustrating another network element abnormality prediction solution in an embodiment of the present disclosure is shown;

[0028] Figure 6 A schematic diagram of a network element abnormality prediction device according to an embodiment of the present disclosure is shown;

[0029] Figure 7 A structural block diagram of a computer device in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0030] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be embodied in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0031] In addition, the accompanying drawings are merely schematic illustrations of the present disclosure and are not necessarily drawn to scale. Identical reference numerals in the figures denote identical or similar parts, and thus repetitive descriptions thereof will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically separate entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0032] In modern communications networks, the stable operation of key core network elements is crucial. Once a key core network element fails, it will usually cause millions of terminal devices to perceive the network anomaly within just a few minutes. These terminal devices will then trigger a large number of registration or session re-establishment requests, greatly impacting the normal operation of the network. Therefore, early perception of network element indicator anomalies and subsequent prevention of network element failures are of great significance to maintaining the stability of key network elements.

[0033] However, in the current network environment, the probability of network element failure is extremely low, which makes it difficult to collect network element abnormal indicator data. As a result, there is a serious imbalance in the existing network element indicator data: up to 99.9% of the data is normal indicator data, while abnormal indicator data accounts for only 0.01%. Using this severely unbalanced data to train the network element anomaly model, categories with small sample sizes are difficult to fully learn during the training process, and their features cannot be effectively captured and memorized by the model. As a result, the model's prediction performance for abnormal indicator data types with small sample sizes is extremely poor, or even completely loses its prediction ability, making it difficult to play an effective early warning role in practical applications.

[0034] In the present disclosure, by classifying network element operation data according to indicator type, it is possible to clearly distinguish normal and original abnormal situations, perform forward noise processing on the original abnormal indicator data, construct a noisy indicator sequence, and enrich the expression form and diversity of the abnormal data. Furthermore, the normal indicator data is fused with the noisy indicator sequence so that the characteristics and rules of the normal data can guide the abnormal data processing, and the inverse operation of forward noise is performed to generate diffusion abnormal indicator data, which can further mine potential abnormal features. Network element time series data is constructed based on normal indicator data and diffusion abnormal indicator data. Through the randomness of forward noise, the probability sampling of reverse denoising and the conditional constraints of normal data, a large amount of diversified, reasonable and time-series-compliant diffusion abnormal indicator data is generated from limited original abnormal data, effectively alleviating the problem of network data imbalance and improving the prediction model's ability to learn abnormal indicators and predict network element abnormalities.

[0035] To facilitate understanding, several terms involved in this application are first explained below.

[0036] Diffusion model: In machine learning, a diffusion model or diffusion probability model is a type of latent variable model, a Markov chain trained using variational estimation. The goal of a diffusion model is to learn the latent structure of a dataset by modeling how data points diffuse in the latent space.

[0037] U-Net: It is an encoder-decoder architecture based on convolutional neural networks (CNN). Its core design is to achieve feature extraction and accurate restoration of input data through a symmetrical encoding and decoding structure and "skip connection".

[0038] The following describes in more detail the various steps of the network element anomaly prediction method in this exemplary implementation with reference to the accompanying drawings and embodiments.

[0039] Figure 1 A flow chart of a network element abnormality prediction method in an embodiment of the present disclosure is shown.

[0040] like Figure 1 As shown, a network element abnormality prediction method according to an embodiment of the present disclosure includes:

[0041] Step S102 : The collected network element operation data in the core network is divided into normal indicator data and original abnormal indicator data based on different indicator types.

[0042] In some embodiments, in the core network, the indicator types include network element resource usage indicators (such as CPU utilization, memory utilization), network performance indicators (such as network throughput, latency, packet loss rate), and signaling-related indicators (such as signaling success rate, number of signaling interactions), etc. Based on these indicators of different natures, the network element operation data can be classified into normal indicator data and original abnormal indicator data (i.e., indicator data that deviates from the normal range, indicating possible faults or abnormalities).

[0043] Step S104: performing time-series-based forward noise processing on the original abnormal indicator data to construct a noise indicator sequence.

[0044] In some embodiments, in actual communication network scenarios, network element data may be subject to various noise interferences. Starting from the initial original abnormal indicator data, noise is superimposed according to a certain rule based on the time series. As the noise addition step progresses, the noise ratio in the data gradually increases, forming a noisy indicator sequence. The indicator data in the sequence gradually evolves from the original abnormal data to data closer to pure noise. In this process, the model can learn the changing rules of this data distribution and establish a mapping relationship between the original data and the noise.

[0045] Step S106: fusing the corresponding normal indicator data and the noisy indicator sequence based on the time series to obtain a fused sequence.

[0046] In some embodiments, normal indicator data reflects the status and rules of the network element during normal operation, and is fused with the noisy indicator sequence. The fused sequence refers to a sequence in which normal indicator data and noisy abnormal data are spliced in time sequence or feature-mixed. After different normal data samples (such as normal indicators in different time periods) are fused with abnormal data with different degrees of noise, diverse input conditions will be generated, so that the starting point of reverse denoising (fused sequence) itself has a rich feature combination.

[0047] Step S108 , performing the inverse operation of the forward denoising process on the fused sequence to obtain diffusion anomaly indicator data.

[0048] In some embodiments, reverse denoising (the inverse operation of forward denoising) can be understood as a probabilistic process of reversely sampling and restoring the original data from the noise distribution.

[0049] In some embodiments, the diffusion model refers to gradually converting data into noise through a forward diffusion (forward noise addition) process, and then recovering the original data from the noise through a reverse diffusion (reverse noise reduction) process. In network element anomaly prediction, forward noise addition corresponds to the forward diffusion of the diffusion model, which constructs a data-to-noise conversion path. The fusion of normal indicator data and noisy indicator sequences is an extension of the diffusion model, which introduces additional conditional information to constrain and guide data generation. Reverse noise reduction corresponds to the reverse diffusion process of the diffusion model, which removes noise by training the model, recovers abnormal data, and ultimately realizes the prediction of network element anomalies.

[0050] Step S110 , constructing network element time series data based on normal indicator data and diffusion abnormality indicator data, training an abnormality prediction model based on the network element time series data, and performing network element abnormality prediction operations based on the trained abnormality prediction model.

[0051] In this embodiment, by classifying network element operation data according to indicator type, normal and original abnormal situations can be clearly distinguished, and the original abnormal indicator data is forward-noised to construct a noisy indicator sequence, thereby enriching the expression form and diversity of the abnormal data. Furthermore, the normal indicator data is fused with the noisy indicator sequence so that the characteristics and rules of the normal data can guide the abnormal data processing, and the inverse operation of the forward noisy operation is performed to generate the diffusion abnormal indicator data, which can further mine the potential abnormal characteristics. The network element time series data is constructed based on the normal indicator data and the diffusion abnormal indicator data. Through the randomness of the forward noisy operation, the probability sampling of the reverse denoising and the conditional constraints of the normal data, a large amount of diversified, reasonable and time-series-compliant diffusion abnormal indicator data is generated from the limited original abnormal data, effectively alleviating the imbalance problem of network data, and improving the prediction model's learning of abnormal indicators and the prediction ability of network element abnormalities.

[0052] In one embodiment of the present disclosure, a time-series-based forward noise addition process is performed on the original abnormal indicator data to construct a noise addition indicator sequence, including:

[0053] Construct multiple moments based on time series, and determine the original abnormal indicator data as the abnormal data at the initial moment; starting from the initial moment, gradually add real noise values to the abnormal data based on multiple moments to obtain the noisy indicator sequence.

[0054] In this embodiment, by superimposing noise at multiple moments and stages, a single original abnormal data is expanded into a time series containing different noise intensities (such as anomalies with slight noise interference to anomalies with severe noise pollution), which provides a rich intermediate state for subsequent reverse denoising to generate diverse abnormal data. Even if the original abnormal data is scarce, the noise addition process can generate a large number of intermediate samples (x2, x3, ... x3) through the randomness of the noise and the time series combination. T-1 ), these samples can be used as additional training data to alleviate the problem of insufficient abnormal samples. In addition, the noise addition process based on the real noise value enables the model to adapt to the actual noise interference in the network element data, and the generated abnormal data is more consistent with the characteristics of the on-site environment, thereby enhancing the generalization ability and detection accuracy of the subsequent abnormal prediction model in real scenarios.

[0055] In one embodiment of the present disclosure, real noise values are gradually added to abnormal data based on multiple moments, including: adding real noise values between two adjacent moments based on an attenuation coefficient and noise data that obeys a normal distribution in time series.

[0056] In some embodiments, T moments are constructed, each of which corresponds to abnormal data after noise addition. Time 1 is the original abnormal data, denoted as x1, and time 2 is denoted as x2. Noise is added at each moment, and the noise addition formula is shown in formula (1):

[0057]

[0058] Among them, x t-1 and x t Represents the abnormal data at time t-1 and time t, α t It is generally a hyperparameter greater than 0 and less than 1, that is, the attenuation coefficient, which decreases as time increases, ε t Represents the noise added in step t, which conforms to the normal distribution.

[0059] In this embodiment, the intensity of noise addition is controlled by orderly decreasing the attenuation coefficient (such as decreasing with increasing time step), so that the abnormal data is gradually and controllably degraded from the initial state to pure noise, and a time-series data degradation path that conforms to physical laws is constructed. Real noise data that obeys the normal distribution is introduced, and the random interference (such as Gaussian white noise) to the network element indicators in actual operation is simulated, thereby enhancing the authenticity and scene fit of the noisy data. This noise addition method that combines regularity and randomness not only provides a clear inverse operation target for reverse denoising, but also generates diversified intermediate samples containing different noise intensities by superimposing noise at multiple moments, effectively expanding the time series feature space of abnormal data.

[0060] like Figure 2 As shown, in one embodiment of the present disclosure, the corresponding normal indicator and noise indicator sequences are fused based on the time sequence to obtain a fused sequence, including:

[0061] Step S202: convert the normal indicator data into an indicator data vector.

[0062] In some embodiments, the original indicators (such as CPU utilization and throughput) are normalized, the correlation between adjacent time steps is extracted through a sliding window, the time series information is embedded in the vector, and non-numeric indicators (such as network element type and alarm level) are converted into fixed-length vectors using one-hot encoding, so that the model can process mixed-type data, and the processed numerical features and category features are spliced by dimension to form a complete indicator data vector.

[0063] Step S204: Input the indicator data vector into the Transformer encoder to perform encoding operations to obtain a normal encoding vector.

[0064] In some embodiments, the indicator data vector is input into the Transformer encoder for encoding, which can capture long-range dependencies and contextual information in the data.

[0065] Step S206: Perform a fusion operation on the normal coding vector and the noise index sequence to obtain a fused sequence.

[0066] In this embodiment, the temporal patterns of normal indicators (such as periodic fluctuations and the correlation between load and response time) are extracted through Transformer encoding and injected into the noisy sequence as constraints, so that the generated abnormal data is more consistent with the physical logic of network element operation. The fusion process retains the core features of the abnormal data (such as sudden fluctuations) and introduces the contextual information of the normal mode, so that the subsequent prediction model can learn the "abnormality in the normal", which is conducive to enhancing the model's ability to detect anomalies.

[0067] In one embodiment of the present disclosure, a fusion operation is performed on the normal coding vector and the noise index sequence to obtain a fused sequence, including:

[0068] The normal encoding vector and the noised indicator sequence are input into the cross attention layer based on the time sequence.

[0069] In the cross-attention layer, the noisy indicator sequence is used as the query and the normal encoding vector is used as the key value. The attention weight between the noisy indicator sequence and the normal encoding vector is calculated, so that the noisy indicator sequence focuses on the key information in the normal indicator data.

[0070] The key information is integrated into the noised indicator sequence to obtain a fused sequence.

[0071] In some embodiments, assuming that the noisy indicator sequence is X and the normal encoding vector is Z, X is projected into the query (Query) and Z is projected into the key (Key) and value (Value) space. By calculating the attention weight, the noisy indicator sequence X can focus on the key information in the normal encoding vector Z. The attention output, that is, the key information is spliced or added with the original noisy sequence to obtain the fused sequence.

[0072] In this embodiment, the normal coding vector and the noisy indicator sequence are input into the cross-attention layer, and the attention weight is calculated with the noisy indicator sequence as the query and the normal coding vector as the key value, so as to realize adaptive learning of abnormal data on normal patterns. By utilizing the association modeling capability of the cross-attention mechanism, the noisy indicator sequence can dynamically focus on the key features in the normal indicator data, so as to effectively integrate the prior knowledge of the normal pattern into the noisy indicator sequence.

[0073] In one embodiment of the present disclosure, a fusion operation is performed on the normal coding vector and the noise index sequence to obtain a fused sequence, including:

[0074] Perform layer normalization on the noised indicator sequence to obtain a normalized sequence.

[0075] Compress the normal encoding vector into a fixed-length representation based on global pooling.

[0076] The scaling factor and offset are extracted from the fixed-length representation based on a multi-layer perceptron.

[0077] The normalization parameters of the normalized sequence are adjusted based on the scaling factor and the offset to fuse the information in the normal indicator data into the noisy indicator sequence to obtain a fused sequence.

[0078] In some embodiments, a standard layer normalization is performed on the noisy indicator sequence X, and the normal encoding vector Z is mapped to a scaling factor γ and an offset β through a linear layer. The scaling factor γ and the offset β are then used to adjust the normalized sequence, as shown in Equation (2):

[0079] X T =γ⊙X+β (2)

[0080] Here, the symbol ⊙ refers to element-by-element multiplication (Hadamard product)

[0081] A fused sequence is obtained based on the adjusted results.

[0082] In this embodiment, by performing layer normalization on the noise indicator sequence and dynamically generating scaling factors and offsets to adjust the normalization parameters based on the normal coding vector, flexible constraints of normal data on the distribution of abnormal data are achieved. By using global pooling and multi-layer perceptrons to extract scaling factors and offsets from the normal coding vector, the normalization process of the noise sequence can be adaptively adjusted according to the statistical characteristics of the normal indicators, so that the distribution of abnormal data is closer to the normal mode while retaining the abnormal characteristics, thereby effectively enhancing the authenticity and logical consistency of the generated data.

[0083] like Figure 3 As shown, in one embodiment of the present disclosure, the inverse operation of the forward denoising process is performed on the fused sequence to obtain diffusion anomaly index data, including:

[0084] Step S302: Generate an inverse denoising model based on a neural network having an encoding layer and a decoding layer.

[0085] In some embodiments, the encoding layer is used to capture global and local dependencies of the data, and the decoding layer is used to gradually reconstruct detailed information to achieve a mapping from abstract features to original data distribution.

[0086] In some embodiments, U-Net is used as a neural network with encoding and decoding layers. In the abnormal data generation scenario, its multi-scale feature fusion capability can effectively combine the temporal regularity of normal data with the abnormal features of noisy data to generate diffusion anomaly indicators that are more in line with business logic, thereby improving the training effect of subsequent anomaly detection models.

[0087] Step S304: input the fused sequence into the reverse denoising model to perform a multi-step iterative denoising operation as the reverse operation of the forward denoising process.

[0088] In some embodiments, iterative denoising refers to starting from the fusion sequence (corresponding to the final noisy state of the forward noise addition), and the model predicts the noise component at the current moment in each iteration. For example, at step t, the model outputs the noise ε based on the features extracted by the coding layer and the current noisy data. t The predicted value ε t′ .

[0089] The predicted noise ε t′ Subtract it from the noisy data to get the denoised data xt-1 =x t -ε t′ , data x t-1 This process is repeated as input for the next iteration, gradually reducing the noise ratio in the data and approaching the original abnormal data.

[0090] Step S306 , configuring an iteration termination condition based on multiple moments, so as to stop the iteration operation when detecting that the multi-step iterative denoising operation meets the iteration termination condition, and obtain diffusion anomaly indicator data.

[0091] In some embodiments, configuring the iteration termination condition based on multiple moments can balance the denoising effect and computational efficiency, thereby ensuring the rationality of the generated data.

[0092] In this embodiment, by constructing a reverse denoising model with an encoding-decoding structure, multi-step iterative denoising is performed on the fused sequence and terminated based on conditions. The encoder-decoder architecture effectively extracts complex features in the fused sequence. Combined with the inverse process of forward noisiness, it is beneficial to restore the details of the original abnormal data. In addition, the multi-step iterative denoising mechanism enables the diffusion model to learn the hierarchical nature of the noise distribution by gradually reducing the noise, generating more diverse and authentic abnormal data, which is beneficial to making the generated abnormal data conform to the physical laws of network element operation and enhancing the business value of the abnormal data.

[0093] like Figure 4 As shown, in one embodiment of the present disclosure, the fused sequence is input into the reverse denoising model, and a multi-step iterative denoising operation is performed, including:

[0094] Step S402: In an initial iterative denoising cycle, the fused sequence is input into a coding layer, so as to perform feature extraction on the fused sequence based on the coding layer to obtain indicator feature information.

[0095] Step S404: input the indicator feature information into the decoding layer to predict the noise based on the indicator feature information and the noise distribution at the current moment to obtain a predicted noise value.

[0096] Step S406: subtract the predicted noise value from the fused sequence to obtain denoised data of the iterative denoising cycle, so as to use the denoised data as input information of the coding layer of the next iterative denoising cycle.

[0097] In this embodiment, an iterative noise prediction and removal mechanism is constructed in the reverse denoising model. Through multiple rounds of iteration, the model gradually separates the noise components from the fused sequence while retaining abnormal features that deviate from the normal pattern. In each round of iteration, the timing features and noise distribution information extracted by the coding layer are used by the decoding layer to predict noise. During the iteration process, the model learns the timing dependency of the data (such as the correlation between traffic changes and response time), so that the generated abnormal data conforms to the physical laws of network element operation and reduces non-real abnormal fluctuations.

[0098] In one embodiment of the present disclosure, a reverse denoising model is generated based on a neural network having an encoding layer and a decoding layer, further comprising:

[0099] Calculate the error value between the corresponding predicted noise value and the actual noise value; calculate the mean square error based on the error value; if it is detected that the mean square error is greater than the error threshold, optimize the inverse denoising model.

[0100] In some embodiments, the mean square error is the loss function, and the goal is to enable the inverse denoising model to accurately predict the noise added at each time step, thereby gradually restoring the original data during the denoising process, and calculating the mean square error between the predicted noise value and the actual noise value. The smaller the error, the better the effect of the denoising model.

[0101] In this embodiment, by constructing a reverse denoising model optimization mechanism based on mean square error (MSE), during the reverse denoising model training process, by calculating the error between the predicted noise value and the actual noise value, and using the mean square error as a quantitative indicator, the degree of prediction deviation of the model for the noise distribution can be accurately measured. If the mean square error is greater than the preset error threshold, it indicates that the current prediction effect of the model has not met expectations. At this time, performing optimization operations on the model can effectively correct the model prediction deviation, so that it can more accurately learn the noise addition rules during the forward denoising process.

[0102] In one embodiment of the present disclosure, network element time series data is constructed based on normal indicator data and diffusion abnormality indicator data to train an abnormality prediction model based on the network element time series data, including:

[0103] Based on the time series, the normal indicator data and the diffusion anomaly indicator data are aligned to obtain the aligned indicator data; based on the timestamp information, the aligned indicator data belonging to the same time period are merged to obtain the corresponding data samples, so as to obtain the network element time series data based on multiple data samples in the time series; a sample label is added to each data sample to train the anomaly prediction model based on the sample label.

[0104] In some embodiments, the abnormality prediction model can select a variety of machine learning or deep learning models, such as decision trees, random forests, support vector machines, etc. in machine learning, recurrent neural networks (RNNs) and their variants long short-term memory networks (LSTMs), gated recurrent units (GRUs), or convolutional neural networks (CNNs) in deep learning.

[0105] like Figure 5 As shown, a network element time series data construction solution according to an embodiment of the present disclosure includes a data preprocessing module 502 , an indicator generation module 504 and an indicator evaluation module 506 .

[0106] The input data of the data pre-processing module 502 includes historical data of network element indicators, which include information on various indicators of the network element during its past operation.

[0107] The processing process of the data preprocessing module 502 includes: inputting the historical data of network element indicators into the Transformer encoder for encoding operation. The Transformer encoder uses technologies such as the self-attention mechanism to obtain a feature vector, that is, an indicator data vector, which can effectively capture the long-distance dependencies and context information in the data.

[0108] After encoding, the network element indicator historical data is converted into a feature vector and output by the data pre-processing module 502 to prepare for subsequent fusion with the abnormal indicator data, ie, the original abnormal indicator data.

[0109] The input of the indicator generation module 504 includes the original abnormal indicator data and the indicator data vector.

[0110] The original abnormal indicator data network element abnormal indicator is the network element indicator data that has been identified to have abnormal conditions.

[0111] The indicator data vector, i.e., the eigenvector, represents normal indicator data information.

[0112] The processing of the indicator generation module 504 includes:

[0113] The abnormal indicators of network elements are gradually noised. The added noise is Gaussian noise. According to a certain time sequence and rules, noise is gradually superimposed on the abnormal indicator data at different times, so that it gradually evolves into a noisy indicator sequence.

[0114] The noisy indicator sequence is fused with the feature vector (representing normal indicator data) obtained by the data preprocessing module.

[0115] In some embodiments, transformer encoding is used to embed normal indicator data collected on the network element into the input sequence, and fuse it with the noisy indicator sequence through a cross-attention layer or an adaptive layer normalization layer, thereby achieving effective modeling of conditional data information.

[0116] The U-Net network is used for gradual noise reduction. U-Net is a neural network with an encoder-decoder structure and skip connections. It can use the encoding layer to extract the features of the fusion sequence, and then use the decoding layer to predict the noise based on these features and the current noise distribution, and gradually remove the noise.

[0117] In some embodiments, by training a neural network (such as U-Net), fusing the conditional data encoded by the tansformer, and gradually denoising from pure noise, the real data model is finally generated from pure noise x T Starting from the initial step, through multi-step iterative prediction and noise removal, the original data x0 is gradually restored. Each step t of the reverse process corresponds to the inverse operation of the forward process. It is necessary to learn the distribution characteristics of the noise to achieve the mapping from noise to data.

[0118] The indicator generation module 504 outputs diffusion anomaly indicator data.

[0119] The indicator evaluation module 506 inputs the actual noise value and the predicted noise value.

[0120] The actual noise value refers to the noise data actually added during the forward noise addition process.

[0121] The predicted noise value is the noise data predicted by the U-Net network during the reverse denoising process.

[0122] The processing process of the indicator evaluation module 506 includes: using a loss function such as the mean square error to calculate the loss value (LOSS) between the predicted noise and the actual noise to measure the difference between the actual noise value and the predicted noise value. The mean square error quantifies the accuracy of the model prediction by calculating the average of the squares of the difference between the predicted noise and the actual noise.

[0123] The performance of the model is evaluated based on the calculated loss value. If the loss value is large, it means that the model's noise prediction accuracy is poor, and the model (such as the U-Net network in the inverse denoising model) needs to be optimized and adjusted, such as adjusting network parameters, retraining, etc., to improve the model's ability to predict noise and the quality of generated abnormal indicator data.

[0124] Furthermore, diverse abnormal data is generated through the diffusion model, and the normal network element data collected on the current network is integrated to form network element time series data including normal and abnormal indicators, and finally generate high-quality network element operation data.

[0125] In this embodiment, a network element abnormality indicator generation scheme is based on a diffusion model. The diffusion model is a generation model based on a probabilistic process. It generates data by gradually introducing noise and removing the noise in the reverse process. The original network element abnormality indicator data is gradually noisy and converted into Gaussian noise to complete forward diffusion. In the denoising process, the conditional input feature indicator is fused with the generated Gaussian noise and input into the U-NET network architecture to gradually complete denoising. Finally, high-quality network element abnormality indicator data is generated under the guidance of the conditional input.

[0126] It should be noted that the above figures are merely illustrative of the processes included in the methods according to exemplary embodiments of the present disclosure and are not intended to be limiting. It is readily understood that the processes illustrated in the above figures do not indicate or limit the temporal order of these processes. Furthermore, it is readily understood that these processes may be executed synchronously or asynchronously, for example, in multiple modules.

[0127] Refer to the following Figure 6 The network element abnormality prediction device 600 according to the embodiment of the present disclosure is described. Figure 6 The network element anomaly prediction device 600 shown is merely an example and should not limit the functions and scope of use of the embodiments of the present disclosure.

[0128] The network element anomaly prediction device 600 is implemented in the form of a hardware module. The components of the network element anomaly prediction device 600 may include, but are not limited to: a partitioning module 602 for partitioning the collected network element operation data in the core network into normal indicator data and original abnormal indicator data based on different indicator types; a noise processing module 604 for performing time-series-based forward noise processing on the original abnormal indicator data to construct a noisy indicator sequence; a fusion module 606 for fusing the corresponding normal indicator data and the noisy indicator sequence based on time series to obtain a fused sequence; an inverse operation module 608 for performing the inverse operation of the forward noise processing on the fused sequence to obtain diffuse abnormal indicator data; and a model training module 610 for constructing network element time series data based on the normal indicator data and the diffuse abnormal indicator data, training an anomaly prediction model based on the network element time series data, and performing network element anomaly prediction operations based on the trained anomaly prediction model.

[0129] Those skilled in the art will appreciate that various aspects of the present disclosure may be implemented as systems, methods, or program products. Therefore, various aspects of the present disclosure may be implemented in the following forms: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, which may be collectively referred to herein as "circuits," "modules," or "systems."

[0130] Refer to the following Figure 7The electronic device 700 according to this embodiment of the present disclosure is described below. The electronic device 700 may be a network device or a terminal. Figure 7 The electronic device 700 shown is merely an example and should not limit the functions and scope of use of the embodiments of the present disclosure.

[0131] like Figure 7 As shown, electronic device 700 is implemented as a general-purpose computing device. Components of electronic device 700 may include, but are not limited to, the aforementioned at least one processing unit 710, the aforementioned at least one storage unit 720, and a bus 730 connecting various system components (including storage unit 720 and processing unit 710).

[0132] The storage unit stores program codes, which can be executed by the processing unit 710, so that the processing unit 710 performs the steps described in the "Exemplary Method" section of the present disclosure according to various exemplary embodiments. For example, the processing unit 710 can perform the following steps: Figure 1 The described scheme.

[0133] The storage unit 720 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 7201 and / or a cache 7202 , and may further include a read-only memory unit (ROM) 7203 .

[0134] The storage unit 720 may also include a program / utility 7204 having a set (at least one) of program modules 7205, such program modules 7205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0135] Bus 730 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0136] The electronic device 700 can also communicate with one or more external devices 770 (e.g., a keyboard, a pointing device, a Bluetooth device, etc.), one or more devices that enable a user to interact with the electronic device 700, and / or any device that enables the electronic device 700 to communicate with one or more other computing devices (e.g., a router, a modem, etc.). Such communication can occur via an input / output (I / O) interface 750. Furthermore, the electronic device 700 can also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network such as the Internet) via a network adapter 760. As shown, the network adapter 760 communicates with other modules of the electronic device 700 via a bus 730. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with the electronic device 700, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0137] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0138] In exemplary embodiments of the present disclosure, a computer-readable storage medium is also provided, on which is stored a program product capable of implementing the aforementioned methods of this specification. In some possible implementations, various aspects of the present disclosure may also be implemented in the form of a program product comprising program code. When the program product is executed on an electronic device, the program code is configured to cause the electronic device to execute the steps described in the aforementioned "Exemplary Methods" section of this specification according to various exemplary embodiments of the present disclosure.

[0139] According to an embodiment of the present disclosure, a program product for implementing the above-mentioned method can be implemented in a portable compact disc read-only memory (CD-ROM) and include program code, and can be run on an electronic device, such as a personal computer. However, the program product of the present disclosure is not limited thereto. In this document, a readable storage medium can be any tangible medium that includes or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0140] The program product may be implemented in any combination of one or more readable media. The readable medium may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0141] A computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0142] The program code embodied on the readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0143] The program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, and the like, as well as conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a stand-alone software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device may be connected to the user computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0144] It should be noted that although several modules or units of the device for action execution are mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be concretized in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units to be concretized.

[0145] Furthermore, although the steps of the method of the present disclosure are described in a particular order in the accompanying drawings, this does not require or imply that the steps must be performed in this particular order, or that all steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps.

[0146] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0147] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the disclosure disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the appended claims.

Claims

1. A network element anomaly prediction method, characterized in that: include: The collected network element operation data in the core network is divided into normal indicator data and original abnormal indicator data based on different indicator types; Performing time-series-based forward noise processing on the original abnormal indicator data to construct a noise indicator sequence; fusing the corresponding normal indicator data and the noise-added indicator sequence based on the time series to obtain a fused sequence; performing an inverse operation of the forward denoising process on the fused sequence to obtain diffusion anomaly indicator data; Network element time series data is constructed based on the normal indicator data and the diffusion abnormality indicator data, an abnormality prediction model is trained based on the network element time series data, and a network element abnormality prediction operation is performed based on the trained abnormality prediction model.

2. The network element abnormality prediction method according to claim 1, characterized in that: Performing time-series-based forward noise processing on the original abnormal indicator data to construct a noise indicator sequence, including: Constructing multiple moments based on the time series, and determining the original abnormal indicator data as abnormal data at the initial moment; Starting from the initial moment, real noise values are gradually added to the abnormal data based on the multiple moments to obtain the noise-added indicator sequence.

3. The network element abnormality prediction method according to claim 2, characterized in that: Gradually adding real noise values to the abnormal data based on the multiple moments, comprising: Addition of the actual noise value between two adjacent moments is performed based on an attenuation coefficient and noise data that obeys a normal distribution in the time series.

4. The network element abnormality prediction method according to claim 2, characterized in that: The corresponding normal indicator and the noise indicator sequence are fused based on the time sequence to obtain a fused sequence, including: Converting the normal indicator data into an indicator data vector; Input the indicator data vector into the Transformer encoder to perform encoding operation to obtain a normal encoding vector; A fusion operation is performed on the normal coding vector and the noise-added indicator sequence to obtain the fused sequence.

5. The network element abnormality prediction method according to claim 4, characterized in that: Performing a fusion operation on the normal coding vector and the noise-added indicator sequence to obtain the fused sequence includes: Inputting the normal encoding vector and the noise indicator sequence into a cross attention layer based on the time sequence; In the cross attention layer, the noisy indicator sequence is used as a query and the normal code vector is used as a key value to calculate the attention weight between the noisy indicator sequence and the normal code vector so that the noisy indicator sequence focuses on the key information in the normal indicator data; The key information is integrated into the noise-added indicator sequence to obtain the fused sequence.

6. The network element anomaly prediction method according to claim 4, characterized in that: Performing a fusion operation on the normal coding vector and the noise-added indicator sequence to obtain the fused sequence includes: Perform layer normalization on the noised indicator sequence to obtain a normalized sequence; Compressing the normal encoding vector into a fixed-length representation based on global pooling; extracting a scaling factor and an offset from the fixed-length representation based on a multi-layer perceptron; A normalization parameter of the normalized sequence is adjusted based on the scaling factor and the offset to fuse information in the normal indicator data into the noisy indicator sequence to obtain the fused sequence.

7. The network element anomaly prediction method according to claim 4, characterized in that: Performing an inverse operation of the forward denoising process on the fused sequence to obtain diffusion anomaly indicator data includes: Generate an inverse denoising model based on a neural network with encoding and decoding layers; Inputting the fused sequence into the reverse denoising model and performing a multi-step iterative denoising operation as the reverse operation of the forward denoising process; Iteration termination conditions are configured based on the multiple moments, so that when it is detected that the multi-step iterative denoising operation meets the iterative termination conditions, the iterative operation is stopped and the diffusion anomaly indicator data is obtained.

8. The network element anomaly prediction method according to claim 7, characterized in that: The fused sequence is input into the reverse denoising model to perform a multi-step iterative denoising operation, including: In an initial iterative denoising cycle, the fused sequence is input into the coding layer, so as to perform feature extraction on the fused sequence based on the coding layer to obtain indicator feature information; Inputting the indicator feature information into the decoding layer to predict noise based on the indicator feature information and the noise distribution at the current moment to obtain a predicted noise value; The predicted noise value is subtracted from the fused sequence to obtain denoised data of the iterative denoising cycle, so as to use the denoised data as input information of the coding layer of the next iterative denoising cycle.

9. The network element anomaly prediction method according to claim 8, characterized in that: Generate an inverse denoising model based on a neural network with encoding and decoding layers, and also include: Calculating an error value between the corresponding predicted noise value and the actual noise value; Calculating a mean square error based on the error value; If it is detected that the mean square error is greater than an error threshold, an optimization operation is performed on the inverse denoising model.

10. The network element abnormality prediction method according to claim 1, characterized in that: Constructing network element time series data based on the normal indicator data and the diffusion abnormality indicator data, so as to train an abnormality prediction model based on the network element time series data, including: Aligning the normal indicator data and the diffusion abnormality indicator data based on the time sequence to obtain aligned indicator data; Based on the timestamp information, the alignment indicator data belonging to the same time period are merged to obtain corresponding data samples, so as to obtain the network element time series data based on the multiple data samples in the time series; A sample label is added to each of the data samples to train an anomaly prediction model based on the sample label.

11. A network element anomaly prediction device, characterized in that: include: A classification module is used to classify the collected network element operation data in the core network into normal indicator data and original abnormal indicator data based on different indicator types; A noise processing module is used to perform time series-based forward noise processing on the original abnormal indicator data to construct a noise indicator sequence; a fusion module, configured to fuse the corresponding normal indicator data and the noise-added indicator sequence based on the time series to obtain a fused sequence; an inverse operation module, configured to perform an inverse operation of the forward denoising process on the fused sequence to obtain diffusion anomaly indicator data; A model training module is used to construct network element time series data based on the normal indicator data and the diffusion abnormality indicator data, to train an abnormality prediction model based on the network element time series data, and to perform network element abnormality prediction operations based on the abnormality prediction model obtained through training.

12. A network device, characterized in that: include: processor; as well as a memory for storing executable instructions of the processor; The processor is configured to execute the network element abnormality prediction method according to any one of claims 1 to 10 by executing the executable instructions.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the network element abnormality prediction method according to any one of claims 1 to 10 is implemented.

14. A computer program product having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the network element abnormality prediction method according to any one of claims 1 to 10 is implemented.

Citation Information

Patent Citations

  • Sample generation method and related equipment

    CN117911258A

  • Sensor anomaly detection method based on conditional diffusion probability model and related system

    CN119513761A

  • Detecting anomalies in an internet of things network

    US20170102978A1