On-line anomaly detection method and equipment for autonomous controllable power business system, and medium
By fine-tuning and training the pre-trained large language model through a combination of self-supervision and supervised learning, the problems of high data requirements and low mobility in traditional log anomaly analysis are solved, efficient log anomaly detection is achieved, labeling costs are reduced, and the generalization ability of the model is improved.
Patent Information
- Application Number
- CN202510742921.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-05
- Publication Date
- 2025-09-12
AI Technical Summary
Traditional log anomaly analysis based on machine learning technology has problems such as high data requirements and annotation costs, low portability and poor scalability, and insufficient generalization capabilities for abnormal patterns.
A combination of self-supervised learning and supervised learning is used to fine-tune and train the pre-trained large language model. The pre-trained large language model is fine-tuned through self-supervised learning, the model is fine-tuned using sample log data, and the large language model is trained in combination with supervised learning to generate a target large language model for anomaly detection.
It reduces the dependence on labeled data, improves the portability and scalability of the model, enhances the generalization ability of the model, and reduces the labeling cost.
Smart Images

Figure CN120632722A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of log data anomaly detection, and in particular to an online anomaly detection method, device and medium for an autonomous and controllable power business system. Background Art
[0002] Logs are a crucial type of data used by various software and hardware systems to record their operational status. They describe the system's historical operational status and details. Operations engineers often need to examine and analyze log data in scenarios such as troubleshooting and security checks. The rapid development of big data technology has led to the ever-increasing scale of modern data centers. Complex systems generate tens of millions of log records daily, and even a system operating on a medium-sized network can easily generate over terabytes of logs per day. The sheer volume and variety of log data makes it difficult for operations engineers to rely on simple keyword searches or regular expression matching for manual analysis. This not only creates a heavy and tedious workload, but also significantly tests the domain expertise of operations personnel. Only with extensive experience processing specific log features can appropriate filtering rules be established. Therefore, applying machine learning to empower machines, capturing system operational anomalies in real-time or near-real time to automate log analysis, is a key path to achieving intelligent and autonomous operations in future data centers.
[0003] However, the traditional method of log anomaly analysis based on machine learning technology has the following problems:
[0004] (1) High data requirements and labeling costs. Traditional deep learning models usually rely on a large amount of labeled data for training. In the log anomaly detection task, a large number of normal and abnormal logs need to be manually labeled to ensure the quality and diversity of the data. This process is both time-consuming and labor-intensive.
[0005] The high demand for labeled data limits the application of traditional methods in data-scarce environments and also increases the cost of model training and maintenance.
[0006] (2) Low portability and poor scalability. Traditional deep learning models are usually trained for specific systems and log data formats, so they have poor portability. When the model needs to be migrated to a new system or a new log data format, it often needs to be retrained or even redesigned.
[0007] The model has poor scalability and limited cross-system and cross-platform applications, resulting in a large workload of manual adjustment and retraining when deployed in multiple environments.
[0008] (3) Insufficient generalization capabilities for abnormal patterns. Traditional models typically require a large amount of historical data to capture various types of abnormal patterns, and these models typically only perform well within the distribution range of the training data. When the system changes or new abnormal patterns emerge, the model has difficulty responding effectively.
[0009] The models have poor generalization capabilities and are prone to overfitting, which leads to performance degradation when faced with new types of anomalies that have not been seen before. In particular, the model effects are unstable in scenarios where the environment changes rapidly. Summary of the Invention
[0010] The present invention provides an online anomaly detection method, device and medium for an autonomous and controllable electric power business system, so as to reduce the dependence on labeled data, lower the labeling cost, improve the portability and scalability, and enhance the generalization ability of the model.
[0011] According to one aspect of the present invention, a method for online anomaly detection in an autonomous and controllable power business system is provided, comprising:
[0012] Acquire original log data of the power system, and preprocess the original log data to obtain sample log data;
[0013] Based on the sample log data, fine-tuning the pre-trained large language model in a self-supervised learning manner to obtain a large language model to be used;
[0014] Based on the sample log data, training the large language model to be used in a supervised learning manner to obtain a target large language model;
[0015] Anomaly detection is performed on newly added log data in the power system using the target large language model to obtain a target anomaly detection result.
[0016] In a possible implementation, preprocessing the original log data to obtain sample log data includes:
[0017] Cleaning the original log data to obtain log data to be formatted;
[0018] Formatting the log data to be formatted to obtain log data to be processed, wherein the log data to be processed includes at least one of a timestamp, a log level, a process ID, a thread ID, a source, a message content, an error code, an error message, a request ID, a session ID, and a user identifier;
[0019] Vectorization is performed on the log data to be processed to obtain the sample log data.
[0020] In a possible implementation, the vectorizing the log data to be processed to obtain the sample log data includes:
[0021] Use the WordPiece tokenization method to split the log data to be processed into subword units and generate an embedding vector corresponding to each subword unit;
[0022] The sample log data is determined based on the embedding vectors of all the sub-word units.
[0023] In a possible implementation, the vectorizing the log data to be processed to obtain the sample log data includes:
[0024] Inputting the log data to be processed into a pre-trained Transformer model to obtain a word vector output by the Transformer model corresponding to the log data to be processed;
[0025] The word vector is determined as the sample log data, wherein the word vector includes context information.
[0026] In one possible implementation, fine-tuning the pre-trained large language model in a self-supervised learning manner based on the sample log data to obtain the large language model to be used includes:
[0027] Partially masking the sample log data to obtain masked log data;
[0028] Based on the mask log data and the sample log data, the pre-trained large language model is fine-tuned to obtain the large language model to be used.
[0029] In a possible implementation, the training of the to-be-used large language model in a supervised learning manner based on the sample log data to obtain a target large language model includes:
[0030] Inputting the sample log data into the large prediction model to be used, and obtaining an abnormal inference result output by the large language model to be used;
[0031] Determining an abnormality inference result corresponding to the sample log data, and determining a normal log, an abnormal log, and a difficult log from the sample log data based on the abnormality inference result;
[0032] The large model to be used is retrained based on the exception log and the difficulty log to obtain the target large language model.
[0033] In a possible implementation, determining normal logs, abnormal logs, and difficult logs from the sample log data based on the abnormality inference result includes:
[0034] The sample log data with a correct anomaly inference result is regarded as a normal log, and the sample log data with an incorrect anomaly inference result is regarded as an abnormal log;
[0035] Assume that the normal log is N={p1,p2,…,p n}, where n is the total number of normal logs;
[0036] Assume that the abnormal log is A={a1,a2,…,a m}, where m is the total number of exception logs, and n>>m;
[0037] The difficulty log is defined as
[0038]
[0039] is the normal log p after the tth round of training i The loss function
[0040] Then the next round of training set can be expressed as
[0041] T t+1 =D t ∪A.
[0042] In a possible implementation, the method further includes:
[0043] During fine-tuning of the pre-trained large language model or training of the to-be-used large language model, processing a weight matrix of the pre-trained large language model or the to-be-used large language model based on a low-rank matrix;
[0044] Training the pre-trained large language model or the to-be-used large language model based on the processed weight matrix;
[0045] The weight matrix is W, with a dimension of m*n; the low-rank matrix A has a dimension of m*r; the low-rank matrix B has a dimension of r*n, where r is much smaller than m and n so that:
[0046] W'=W+ΔW=W+AB
[0047] Among them, A and B are low-rank matrices with dimensions much smaller than the weight matrix W;
[0048] The overall objective function is
[0049]
[0050] in,
[0051]
[0052] x i is the instruction of the i-th sample, y i,t The tth label of the i-th sample, y i,<t The first t-1 labels of the i-th sample, F w+Δw is a model function with parameters w+Δw.
[0053] According to another aspect of the present invention, there is provided an online anomaly detection device for an autonomous and controllable power business system, comprising:
[0054] A log data acquisition module is used to acquire original log data of the power system and pre-process the original log data to obtain sample log data;
[0055] A self-supervised learning module is used to fine-tune the pre-trained large language model in a self-supervised learning manner based on the sample log data to obtain a large language model to be used;
[0056] A supervised learning module is used to train the large language model to be used in a supervised learning manner based on the sample log data to obtain a target large language model;
[0057] The detection result determination module is used to perform anomaly detection on the newly added log data in the power system through the target large language model to obtain a target anomaly detection result.
[0058] In one possible implementation, the log data acquisition module includes:
[0059] The log data cleaning submodule is used to clean the original log data to obtain log data to be formatted;
[0060] a log data formatting submodule, configured to format the log data to be formatted to obtain log data to be processed, wherein the log data to be processed includes at least one of a timestamp, a log level, a process ID, a thread ID, a source, a message content, an error code, an error message, a request ID, a session ID, and a user identifier;
[0061] The log data vectorization submodule is used to perform vectorization processing on the log data to be processed to obtain the sample log data.
[0062] In one possible implementation, the log data vectorization submodule is specifically used to:
[0063] Use the WordPiece tokenization method to split the log data to be processed into subword units and generate an embedding vector corresponding to each subword unit;
[0064] The sample log data is determined based on the embedding vectors of all the sub-word units.
[0065] In one possible implementation, the log data vectorization submodule is further configured to:
[0066] Inputting the log data to be processed into a pre-trained Transformer model to obtain a word vector output by the Transformer model corresponding to the log data to be processed;
[0067] The word vector is determined as the sample log data, wherein the word vector includes context information.
[0068] In one possible implementation, the self-supervised learning module includes:
[0069] a masked log data determination submodule, configured to partially mask the sample log data to obtain masked log data;
[0070] The large model fine-tuning submodule is used to fine-tune the pre-trained large language model based on the mask log data and the sample log data to obtain the large language model to be used.
[0071] In one possible implementation, there is a supervised learning module, including:
[0072] An abnormal inference result determination submodule, configured to input the sample log data into the large prediction model to be used, and obtain an abnormal inference result output by the large language model to be used;
[0073] a log determination submodule, configured to determine an abnormal inference result corresponding to the sample log data, and determine normal logs, abnormal logs, and difficult logs from the sample log data based on the abnormal inference result;
[0074] A retraining submodule is used to retrain the large model to be used based on the abnormal log and the difficult log to obtain the target large language model.
[0075] In one possible implementation, the log determination submodule is specifically configured to:
[0076] The sample log data with a correct anomaly inference result is regarded as a normal log, and the sample log data with an incorrect anomaly inference result is regarded as an abnormal log;
[0077] Assume that the normal log is N={p1,p2,…,p n}, where n is the total number of normal logs;
[0078] Assume that the abnormal log is A={a1,a2,…,a m}, where m is the total number of exception logs, and n>>m;
[0079] The difficulty log is defined as
[0080]
[0081] is the normal log p after the tth round of training i The loss function
[0082] Then the next round of training set can be expressed as
[0083] T t+1 =D t ∪A.
[0084] In one possible implementation, an online anomaly detection device for an autonomous and controllable power business system further includes a low-rank training module, specifically configured to:
[0085] During fine-tuning of the pre-trained large language model or training of the to-be-used large language model, processing a weight matrix of the pre-trained large language model or the to-be-used large language model based on a low-rank matrix;
[0086] Training the pre-trained large language model or the to-be-used large language model based on the processed weight matrix;
[0087] The weight matrix is W, with a dimension of m*n; the low-rank matrix A has a dimension of m*r; the low-rank matrix B has a dimension of r*n, where r is much smaller than m and n so that:
[0088] W'=W+ΔW=W+AB
[0089] Among them, A and B are low-rank matrices with dimensions much smaller than the weight matrix W;
[0090] The overall objective function is
[0091]
[0092] in,
[0093]
[0094] x i is the instruction of the i-th sample, y i,t The tth label of the i-th sample, y i,<t The first t-1 labels of the i-th sample, F w+Δw is a model function with parameters w+Δw.
[0095] According to another aspect of the present invention, an electronic device is provided, comprising:
[0096] at least one processor;
[0097] and a memory communicatively connected to the at least one processor; wherein,
[0098] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the online anomaly detection method for the autonomous and controllable power business system described in any embodiment of the present invention.
[0099] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the online anomaly detection method for an autonomous and controllable power business system described in any embodiment of the present invention when executed.
[0100] The technical solution of the embodiment of the present invention includes: obtaining the original log data of the power system, preprocessing the original log data to obtain sample log data; based on the sample log data, fine-tuning the pre-trained large language model in a self-supervised learning manner to obtain the large language model to be used; based on the sample log data, training the large language model to be used in a supervised learning manner to obtain a target large language model; using the target large language model to perform anomaly detection on the newly added log data in the power system to obtain a target anomaly detection result. This solves the technical problems of traditional anomaly detection methods, such as high data requirements and labeling costs, low mobility and poor scalability, and insufficient generalization capabilities for abnormal patterns. It reduces the reliance on labeled data, reduces labeling costs, improves mobility and scalability, and enhances the generalization capabilities of the model.
[0101] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0102] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0103] Figure 1 A flowchart of an online anomaly detection method for an autonomous and controllable power business system provided by an embodiment of the present invention;
[0104] Figure 2 A flowchart of another method for online anomaly detection in an autonomous and controllable power business system provided by an embodiment of the present invention;
[0105] Figure 3 A schematic diagram of the structure of an online anomaly detection device for an autonomous and controllable power business system provided by an embodiment of the present invention;
[0106] Figure 4 A schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0107] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0108] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0109] Figure 1 This is a flowchart of an autonomous and controllable power business system online anomaly detection method provided by an embodiment of the present invention. This embodiment is applicable to the case of online time series data anomaly detection of power business systems. Figure 1 As shown, the method specifically includes the following steps:
[0110] S110 : Acquire original log data of the power system, pre-process the original log data, and obtain sample log data.
[0111] Logs, as a type of data widely present in information systems, are often scattered throughout the system. This is especially true for distributed and large-scale software, where different nodes and components continuously generate and accumulate logs. Therefore, log collection is the first step in log anomaly detection. Common log collection tools include Logstash, Flume, Fluentd, and Kafka. Through continuous, real-time data collection, data can be centrally stored or pushed to consumers for subsequent processing via a publish-subscribe model.
[0112] In power business systems, raw log data is typically unstructured text information, containing a significant amount of noise and redundant information. Therefore, data preprocessing is crucial and directly impacts the quality of subsequent model training. The goal of preprocessing is to remove noise and extract effective features, enabling the model to accurately understand the log data. It's also important to note that preprocessing raw log data essentially involves processing each raw log entry within the raw log data.
[0113] In one possible implementation, the original log data is preprocessed to obtain sample log data, including: cleaning the original log data to obtain log data to be formatted; formatting the log data to be formatted to obtain log data to be processed, and vectorizing the log data to be processed to obtain sample log data.
[0114] Among them, the log data to be formatted refers to the log data that needs to be formatted after cleaning the original log data, the data to be processed refers to the log data that needs to be vectorized, and the sample log data refers to the data obtained after vectorization processing, which serves as the sample for the subsequent training model.
[0115] The log data to be processed includes at least one of a timestamp, a log level, a process ID, a thread ID, a source, a message content, an error code, an error message, a request ID, a session ID, and a user identifier, that is, the data to be formatted is formatted to obtain log data to be processed including the above items.
[0116] As you can understand, cleaning raw log data involves processing punctuation, irrelevant numbers, and redundant information. Punctuation marks in logs (such as commas, periods, question marks, and parentheses) typically do not contain useful semantic information and are unhelpful for subsequent analysis or modeling. For example, a log may contain descriptive text (such as "Request started (INFO)"), but punctuation marks like parentheses and commas do not provide useful information for analysis.
[0117] Furthermore, numbers in logs may sometimes represent version numbers, counters, etc., but these numbers are not necessarily helpful for anomaly detection or other analysis tasks. For example, the version number may not be important for log analysis and can be removed.
[0118] Furthermore, logs may contain redundant component identifiers, status codes, execution environments, and other information that may not directly impact data cleaning and subsequent processing. For example, logs may contain multiple copies of the same error message or status information. Cleaning up redundant content can help improve data quality.
[0119] Specifically, to effectively clean data, punctuation can be removed by using regular expressions to remove all non-alphanumeric symbols. If numbers in the logs are not helpful for anomaly detection (such as timestamps), they can be removed directly. Furthermore, text normalization can be performed by converting all letters to lowercase to avoid vocabulary inconsistencies caused by different case.
[0120] In this embodiment, after the original log data is cleaned, it can be formatted to obtain the log data to be formatted. Formatting refers to formatting the linear log information and extracting the important attributes of the log in chronological order. The data to be processed mainly includes the following:
[0121] Timestamp: The time the log was recorded. Log level: For example, DEBUG, INFO, WARNING, ERROR, or CRITICAL. Process / Thread ID: The process or thread that generated the log. Source: The module, component, or service from which the log originated. Message Content: The core information of the log. Error Code / Message: Such as the exception message or error code when the error occurred. Request / Session ID: Identifies a specific request or session. User Information: When user operations are involved, information such as user identification and permissions is provided.
[0122] In one possible implementation, vectorization is performed on log data to be processed to obtain sample log data, including: splitting the log data to be processed into subword units using a WordPiece tokenization method, and generating an embedding vector corresponding to each subword unit; and determining the sample log data based on the embedding vectors of the subword units.
[0123] It is understandable that the log data to be processed may include multiple log messages. For each log message, the log message can be used as input text, and the WordPiece tokenization method can be used to split the log message into sub-word units. Then, each sub-word unit is mapped to an embedding vector, and a corresponding embedding vector is generated for each sub-word unit in the log message. Finally, the embedding vectors of all sub-word units in the log message are combined to form a high-dimensional vector representation. This vector representation is the vector format of the log message under the WordPiece tokenization method, that is, the sample log data is generated, and the sample log data includes the vector format corresponding to each log message.
[0124] In an embodiment of the present invention, WordPiece tokenization is further introduced, which is a method widely used in many language modeling studies. WordPiece first incorporates all characters and symbols into its basic vocabulary. Instead of relying on the frequency of word pairs, it selects word pairs that maximize the likelihood of training data. It trains the language model starting from the basic vocabulary, selects the word pairs with the highest likelihood, and adds them to the vocabulary. Then, the language model is trained again based on the new vocabulary. Until the required vocabulary size is reached. For example, the rare word "datablockscanner" will be split into more common subwords: "data", "block", "scan", "ner". In this way, the number of unregistered words is reduced and their meaning is captured. The reason why the present invention chooses WordPiece is that it can effectively handle unregistered words and reduce the size of the vocabulary. Compared with other tokenization (chunking) methods, WordPiece is more effective. For example, a tokenization strategy based on space / stem / camel case nomenclature may result in many unregistered words and a larger vocabulary.
[0125] In one possible implementation, the log data to be processed may be vectorized to obtain sample log data by: inputting the log data to be processed into a pre-trained Transformer model, obtaining a word vector output by the Transformer model corresponding to the log data to be processed; and determining the word vector as the sample log data.
[0126] Among them, the word vector includes context information.
[0127] Specifically, to overcome the limitations of traditional word vectorization methods, context-sensitive word vector models have emerged in recent years, such as BERT, GPT, and T5. These models can generate different word vectors based on context, allowing the same word to have different vector representations in different contexts. The Llama model, based on a large-scale pre-trained Transformer model, generates more refined and context-sensitive word vectors, making it particularly suitable for processing log data with complex context and ambiguous meanings.
[0128] Unlike Word2Vec, the Llama model (and other similar pre-trained models) learns long-range dependencies between words through a self-attention mechanism and adjusts the representation of each word based on the context of the entire sentence. This enables Llama to capture subtle changes in words in different contexts, providing richer and more dynamic semantic information.
[0129] The Llama model is particularly useful in log data analysis, helping to identify and represent deep semantic relationships that might be lost in traditional word vectorization methods. For example, the word "failed" and "login" in the phrase "failed log in" may have different semantic meanings in a specific context. The Llama model can produce a more accurate vector representation based on the context of the entire log message.
[0130] Therefore, the log data to be processed can be input into a pre-trained Transformer model, namely the Llama model, to obtain the word vectors output by the Transformer model corresponding to the log data to be processed; and the word vectors are determined as sample log data.
[0131] S120: Based on the sample log data, fine-tune the pre-trained large language model in a self-supervised learning manner to obtain the large language model to be used.
[0132] After preprocessing, the original log data is converted into sample log data in vector form, which can be used to train the model.
[0133] Among them, the pre-trained large language model can be a pre-trained large language model such as Llama, because this type of model is pre-trained on massive data, can capture deep semantic information, and has strong context understanding capabilities.
[0134] In one possible implementation, based on the sample log data, the pre-trained large language model is fine-tuned in a self-supervised learning manner to obtain the large language model to be used, including: partially masking the sample log data to obtain masked log data; based on the masked log data and the sample log data, the pre-trained large language model is fine-tuned to obtain the large language model to be used.
[0135] Specifically, in the self-supervised learning phase, a masking method will be used to train the model. The model will receive a set of continuous log entries, one of which (such as the fifth log) will be masked. The task is for the model to predict the masked content based on the remaining log entries. This process can help the model understand the inherent patterns of log data and discover abnormal log information or log information that does not conform to the normal pattern. The model will predict the content of the masked fifth log by learning the remaining 9 logs (including timestamps, log levels, service names, messages, etc.). During this process, the model will take into account the contextual connections between the logs, such as the status of the previous and subsequent services (such as ServiceB connection failure, ServiceA processing the request, etc.), and related error information (such as ERROR and TIMEOUT).
[0136] S130 : Based on the sample log data, the large language model is trained in a supervised learning manner to obtain a target large language model.
[0137] In this embodiment, based on the sample log data, the pre-trained large language model is fine-tuned in a self-supervised learning manner to obtain the large language model to be used. Then, the large language model to be used can be trained in a supervised learning manner to obtain the target large language model.
[0138] It should also be noted that the sample log data used for fine-tuning the pre-trained large language model can be the same as or different from the sample log data used to train the large language model to be used, but both are obtained by preprocessing the obtained original sample data.
[0139] Specifically, sample log data contains characteristic information about log events, including their temporal trends, component status, and potential anomaly patterns. By analyzing sample log data, the model can identify anomalous patterns within the data. For example, the model can determine whether the log messages at a given moment conform to the normal operation of the system or whether there are any sudden anomalies. During supervised learning, the large language model to be used can output log anomaly prediction results. Based on these output log anomaly prediction results and actual anomaly results, the large language model to be used can be further adjusted and optimized, ultimately obtaining the target large language model.
[0140] The technical solution of the embodiment of the present invention first fine-tunes the model through unsupervised learning, and then trains it in a supervised manner, which solves the technical problem of traditional machine learning methods relying on a large amount of labeled data, and achieves efficient reasoning and task adaptation without the need for additional labeled data. Because large models are often pre-trained on large-scale data sets, they have mastered many common knowledge structures. When applied to the log data of the power business system, the knowledge learned by the pre-trained model in other fields can be transferred to the power system through transfer learning. This method is particularly suitable for few-sample learning, because even if there are few samples in a specific task of the power business, the model can still use the knowledge learned during pre-training to perform reasoning.
[0141] S140. Perform anomaly detection on newly added log data in the power system using a target large language model to obtain a target anomaly detection result.
[0142] Specifically, when the power business system generates new log data, it can be pre-processed and input into the target large language model to obtain the anomaly detection result output by the target large language model.
[0143] The technical solution of the embodiment of the present invention includes: obtaining the original log data of the power system, preprocessing the original log data to obtain sample log data; based on the sample log data, fine-tuning the pre-trained large language model in a self-supervised learning manner to obtain the large language model to be used; based on the sample log data, training the large language model to be used in a supervised learning manner to obtain a target large language model; using the target large language model to perform anomaly detection on the newly added log data in the power system to obtain a target anomaly detection result. This solves the technical problems of traditional anomaly detection methods, such as high data requirements and labeling costs, low mobility and poor scalability, and insufficient generalization capabilities for abnormal patterns. It reduces the reliance on labeled data, reduces labeling costs, improves mobility and scalability, and enhances the generalization capabilities of the model.
[0144] Figure 2 This is a flowchart of another method for online anomaly detection in an autonomous and controllable power business system provided by an embodiment of the present invention. Based on the above embodiment, this embodiment can introduce positive and negative sample selection and training strategies and low-rank training strategies. Figure 2 As shown, the method specifically includes the following steps:
[0145] S210 : Acquire original log data of the power system, pre-process the original log data, and obtain sample log data.
[0146] S220: Based on the sample log data, fine-tune the pre-trained large language model in a self-supervised learning manner to obtain the large language model to be used.
[0147] S230: Input the sample log data into the large prediction model to be used, and obtain the abnormal inference result output by the large language model to be used.
[0148] S240: Determine an abnormal inference result corresponding to the sample log data, and determine normal logs, abnormal logs, and difficult logs from the sample log data based on the abnormal inference result.
[0149] Among them, the normal log can be the sample log data whose abnormal inference result is consistent with the actual situation, and the abnormal log can be the sample log data whose abnormal inference result is greatly different from the actual situation.
[0150] In practical applications, normal log samples in power business systems typically far outnumber abnormal log samples. Therefore, a special training strategy can be employed: during each training session, the model first infers all normal logs. Then, the normal logs with the largest discrepancy between the inferred and actual results are selected as new training samples. This introduces more "difficult" samples to improve the model's discriminative ability.
[0151] In a possible implementation, determining normal logs, abnormal logs, and difficult logs from the sample log data based on the abnormality inference result includes:
[0152] Assume that the normal log is N={p1,p2,…,p n}, where n is the total number of normal logs.
[0153] Assume that the abnormal log is A={a1,a2,…,a m}, where m is the total number of exception logs, and usually n>>m.
[0154] The difficulty log is defined as
[0155]
[0156] is the normal log p after the tth round of training i The loss function
[0157] Then the next round of training set can be expressed as
[0158] T t+1 =D t ∪A
[0159] In this way, the ratio of positive and negative samples can be adjusted to 3:7, thereby solving the problem of sample imbalance and enabling the model to learn the characteristics of abnormal logs more effectively.
[0160] S250: Retrain the large model based on the abnormal logs and the difficult logs to obtain a target large language model.
[0161] That is, based on the training set T t+1 =D t ∪A treats the large model as retraining to obtain the target large language model.
[0162] S260. Perform anomaly detection on newly added log data in the power system using a target large language model to obtain a target anomaly detection result.
[0163] In a possible implementation, the method further includes: during fine-tuning of a pre-trained large language model or training of the large language model to be used, processing a weight matrix of the pre-trained large language model or the large language model to be used based on a low-rank matrix; and training the pre-trained large language model or the large language model to be used based on the processed weight matrix.
[0164] Specifically, low-rank training strategies can be used in both self-supervised training and supervised training, that is, the LoRA algorithm is used during training.
[0165] The core idea of the LoRA fine-tuning method is to adaptively fine-tune the model by introducing a low-rank matrix into the original weights of the pre-trained model, rather than updating the parameters of the entire model. This enables the model to be effectively adjusted to a specific task while maintaining fewer additional parameters. The core idea of LoRA is to decompose some weight matrices in the model into the product of low-rank matrices. For example, assuming that there is a weight matrix W with a dimension of m*n in the original model, LoRA introduces a low-rank matrix A (with a dimension of m*r) and B (with a dimension of r*n), where r is much smaller than m and n so that:
[0166] W'=W+ΔW=W+AB
[0167] Among them, A and B are low-rank matrices with dimensions much smaller than the original matrix W, so this approach significantly reduces the number of parameters and computational overhead.
[0168] Therefore, the overall objective function is
[0169]
[0170] in,
[0171]
[0172] x i is the instruction of the i-th sample, y i,t The tth label of the i-th sample, y i,<t The first t-1 labels of the i-th sample, F w+Δw is a model function with parameters w+Δw.
[0173] In one possible implementation, in traditional deep learning models, since the models are often trained for specific systems or log data in a specific format, they have significant adaptability issues when migrating to new systems or facing new log formats. Every time faced with a new environment, it is usually necessary to redesign or retrain the model, which consumes a lot of time and resources. To overcome this challenge, the present invention can adopt an in-context learning method. The core idea of this method is to help large models infer and learn through contextual information by providing representative error samples.
[0174] Specifically, when encountering a new system, the model can quickly adjust its inference strategy by using specific error samples and their associated contextual information collected from the new system, without having to rely on large amounts of labeled data or redesign the network structure. This approach not only improves the model's migration capabilities but also enables it to maintain high accuracy and robustness when faced with new log formats, reducing the cost and complexity of retraining. Through this mechanism, the model can flexibly respond to a variety of environments and effectively reason based on contextual information, thereby improving the universality and adaptability of deep learning models.
[0175] Prompt word template: error sample and contextual reasoning template
[0176] 1. Error type description:
[0177] Error Type: [Error Category / Error Code]
[0178] Error message: [specific error message]
[0179] Error occurred at: [timestamp]
[0180] Error occurred on: [system / platform name]
[0181] 2. Error context information:
[0182] System environment: [hardware configuration, operating system, version, etc.]
[0183] Related operations: [the operation or task that was in progress when the error occurred]
[0184] Contextual data: [log information, configuration files, input data related to the error, etc.]
[0185] Network status: [Network connection status or network latency information, if applicable]
[0186] External dependencies: [If any, the status of external services, APIs, databases]
[0187] 3. Historical error samples:
[0188] Past Error Samples: [Historical error or similar error type and its solution]
[0189] Error reproduction steps: [How to reproduce the error steps]
[0190] 4. Reasoning task requirements:
[0191] Task Objective: [A clear reasoning task, such as diagnosing an error, predicting the source of a problem, and providing a solution]
[0192] Expected results: [Expected reasoning results, such as the root cause of the error, optimization suggestions, etc.]
[0193] 5. Model inference output format:
[0194] Inference results: [Inference results output by the model]
[0195] Solution suggestion: [The model infers the wrong solution based on the context]
[0196] Priority: [priority of error handling, such as urgent, important, ignorable, etc.]
[0197] The technical solutions of the embodiments of the present invention include at least the following technical effects:
[0198] (1) Few-shot learning framework based on large models
[0199] The present invention solves the dependence of traditional machine learning methods on large amounts of labeled data by introducing a few-sample learning technology of large-scale pre-trained models, and achieves efficient reasoning and task adaptation without the need for additional labeled data. Large models are often pre-trained on large-scale data sets and have mastered many common knowledge structures. When applied to the log data of the power business system, the knowledge learned by the pre-trained model in other fields can be transferred to the power system through transfer learning. This method is particularly suitable for few-sample learning, because even if there are few samples in a specific task of the power business, the model can still use the knowledge learned during pre-training to perform reasoning. The core innovation of this technical framework lies in how to perform fast and accurate reasoning in a new task environment through the model's prior knowledge and natural language task descriptions.
[0200] (2) Cross-task transfer capability
[0201] The technical solution of this invention enables cross-task transfer learning by understanding task descriptions. Even without task-specific data, the model can infer and execute new tasks based on prior knowledge and language descriptions. This technical feature enhances the system's adaptability and flexibility in diverse application scenarios, particularly enabling efficient performance across multiple domains and tasks.
[0202] (3) Efficient anomaly detection and semantic reasoning capabilities
[0203] This invention offers significant advantages in applications such as anomaly detection. Through few-shot learning, the model can identify and infer complex anomaly patterns in the absence of labeled data, making it particularly useful in scenarios where samples are scarce or data labeling is difficult. The innovation of this technology lies in leveraging the deep knowledge of pre-trained models for anomaly detection and inference, significantly improving processing efficiency and accuracy.
[0204] This paper addresses the problem of traditional models relying on large amounts of labeled data and complex training processes for specific tasks by introducing a small-sample learning approach based on large models. By leveraging the knowledge of large-scale pre-trained models, this paper can be directly applied to reasoning and decision-making for new tasks without additional labeled data, significantly improving task adaptability and generalization capabilities.
[0205] Specifically, the main advantage of this invention is that it enables efficient cross-task transfer, reducing the need for large amounts of labeled data and the cost of manual annotation. Furthermore, by leveraging the prior knowledge of pre-trained models, it enables fast and effective reasoning in unknown environments, improving the system's adaptability and flexibility in different application scenarios.
[0206] The applicants also tested their proposed method. The model was first trained on public datasets such as BGL, and then subjected to few-shot inference on a business dataset from a power grid. Despite having almost no new business logs, the model maintained an accuracy rate exceeding 92%. Furthermore, due to the model's strong semantic reasoning capabilities, it was also able to perform root cause analysis on abnormal logs, further demonstrating the model's practical applicability.
[0207] Figure 3 This is a schematic diagram of the structure of an online abnormality detection device for an autonomous and controllable power business system provided by an embodiment of the present invention. Figure 3 As shown, the device includes:
[0208] The log data acquisition module 310 is used to acquire original log data of the power system and pre-process the original log data to obtain sample log data;
[0209] A self-supervised learning module 320 is configured to fine-tune the pre-trained large language model based on the sample log data in a self-supervised learning manner to obtain a large language model to be used;
[0210] A supervised learning module 330 is configured to train the large language model to be used in a supervised learning manner based on the sample log data to obtain a target large language model;
[0211] The detection result determination module 340 is configured to perform anomaly detection on the newly added log data in the power system using the target large language model to obtain a target anomaly detection result.
[0212] In one possible implementation, the log data acquisition module 310 includes:
[0213] The log data cleaning submodule is used to clean the original log data to obtain log data to be formatted;
[0214] a log data formatting submodule, configured to format the log data to be formatted to obtain log data to be processed, wherein the log data to be processed includes at least one of a timestamp, a log level, a process ID, a thread ID, a source, a message content, an error code, an error message, a request ID, a session ID, and a user identifier;
[0215] The log data vectorization submodule is used to perform vectorization processing on the log data to be processed to obtain the sample log data.
[0216] In one possible implementation, the log data vectorization submodule is specifically used to:
[0217] Use the WordPiece tokenization method to split the log data to be processed into subword units and generate an embedding vector corresponding to each subword unit;
[0218] The sample log data is determined based on the embedding vectors of all the sub-word units.
[0219] In one possible implementation, the log data vectorization submodule is further configured to:
[0220] Inputting the log data to be processed into a pre-trained Transformer model to obtain a word vector output by the Transformer model corresponding to the log data to be processed;
[0221] The word vector is determined as the sample log data, wherein the word vector includes context information.
[0222] In one possible implementation, the self-supervised learning module 320 includes:
[0223] a masked log data determination submodule, configured to partially mask the sample log data to obtain masked log data;
[0224] The large model fine-tuning submodule is used to fine-tune the pre-trained large language model based on the mask log data and the sample log data to obtain the large language model to be used.
[0225] In one possible implementation, there is a supervised learning module 330, including:
[0226] An abnormal inference result determination submodule, configured to input the sample log data into the large prediction model to be used, and obtain an abnormal inference result output by the large language model to be used;
[0227] a log determination submodule, configured to determine an abnormal inference result corresponding to the sample log data, and determine normal logs, abnormal logs, and difficult logs from the sample log data based on the abnormal inference result;
[0228] A retraining submodule is used to retrain the large model to be used based on the abnormal log and the difficult log to obtain the target large language model.
[0229] In one possible implementation, the log determination submodule is specifically configured to:
[0230] The sample log data with a correct anomaly inference result is regarded as a normal log, and the sample log data with an incorrect anomaly inference result is regarded as an abnormal log;
[0231] Assume that the normal log is N={p1,p2,…,p n}, where n is the total number of normal logs;
[0232] Assume that the abnormal log is A={a1,a2,…,a m}, where m is the total number of exception logs, and n>>m;
[0233] The difficulty log is defined as
[0234]
[0235] is the normal log p after the tth round of training i The loss function
[0236] Then the next round of training set can be expressed as
[0237] T t+1 =D t ∪A.
[0238] In one possible implementation, an online anomaly detection device for an autonomous and controllable power business system further includes a low-rank training module, specifically configured to:
[0239] During fine-tuning of the pre-trained large language model or training of the to-be-used large language model, processing a weight matrix of the pre-trained large language model or the to-be-used large language model based on a low-rank matrix;
[0240] Training the pre-trained large language model or the to-be-used large language model based on the processed weight matrix;
[0241] The weight matrix is W, with a dimension of m*n; the low-rank matrix A has a dimension of m*r; the low-rank matrix B has a dimension of r*n, where r is much smaller than m and n so that:
[0242] W'=W+ΔW=W+AB
[0243] Among them, A and B are low-rank matrices with dimensions much smaller than the weight matrix W;
[0244] The overall objective function is
[0245]
[0246] x i is the instruction of the i-th sample, y i,t The tth label of the i-th sample, y i,<t The first t-1 labels of the i-th sample, F w+Δw is a model function with parameters w+Δw.
[0247] Figure 4 Schematic diagram of the structure of an electronic device provided for an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0248] like Figure 4As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which is communicatively connected to the at least one processor 11. The memory stores a computer program that can be executed by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12, and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0249] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0250] The processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the online anomaly detection method for an autonomous and controllable power business system.
[0251] In some embodiments, the method for online anomaly detection of an autonomous and controllable electric power business system may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the method for online anomaly detection of an autonomous and controllable electric power business system described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to execute the method for online anomaly detection of an autonomous and controllable electric power business system in any other appropriate manner (e.g., by means of firmware).
[0252] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0253] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0254] In the context of the present invention, computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage medium can include but is not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage medium can be a machine-readable signal medium. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0255] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0256] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0257] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0258] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0259] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A method for online anomaly detection in an autonomous and controllable power business system, characterized in that: include: Acquire original log data of the power system, and preprocess the original log data to obtain sample log data; Based on the sample log data, fine-tuning the pre-trained large language model in a self-supervised learning manner to obtain a large language model to be used; Based on the sample log data, training the large language model to be used in a supervised learning manner to obtain a target large language model; Anomaly detection is performed on newly added log data in the power system using the target large language model to obtain a target anomaly detection result.
2. The method according to claim 1, characterized in that The preprocessing of the original log data to obtain sample log data includes: Cleaning the original log data to obtain log data to be formatted; Formatting the log data to be formatted to obtain log data to be processed, wherein the log data to be processed includes at least one of a timestamp, a log level, a process ID, a thread ID, a source, a message content, an error code, an error message, a request ID, a session ID, and a user identifier; Vectorization is performed on the log data to be processed to obtain the sample log data.
3. The method according to claim 2, characterized in that The vectorizing the log data to be processed to obtain the sample log data includes: Use the WordPiece tokenization method to split the log data to be processed into subword units and generate an embedding vector corresponding to each subword unit; The sample log data is determined based on the embedding vectors of all the sub-word units.
4. The method according to claim 2, characterized in that The vectorizing the log data to be processed to obtain the sample log data includes: Inputting the log data to be processed into a pre-trained Transformer model to obtain a word vector output by the Transformer model corresponding to the log data to be processed; The word vector is determined as the sample log data, wherein the word vector includes context information.
5. The method according to claim 1, wherein The method of fine-tuning the pre-trained large language model in a self-supervised learning manner based on the sample log data to obtain the large language model to be used includes: Partially masking the sample log data to obtain masked log data; Based on the mask log data and the sample log data, the pre-trained large language model is fine-tuned to obtain the large language model to be used.
6. The method according to claim 1, characterized in that The step of training the large language model to be used in a supervised learning manner based on the sample log data to obtain a target large language model includes: Inputting the sample log data into the large prediction model to be used, and obtaining an abnormal inference result output by the large language model to be used; Determining an abnormality inference result corresponding to the sample log data, and determining a normal log, an abnormal log, and a difficult log from the sample log data based on the abnormality inference result; The large model to be used is retrained based on the exception log and the difficulty log to obtain the target large language model.
7. The method according to claim 6, characterized in that The determining of normal logs, abnormal logs, and difficult logs from the sample log data based on the abnormal inference result includes: The sample log data with a correct anomaly inference result is regarded as a normal log, and the sample log data with an incorrect anomaly inference result is regarded as an abnormal log; Assume that the normal log is N={p1,p2,…,p n }, where n is the total number of normal logs; Assume that the abnormal log is A={a1,a2,…,a m }, where m is the total number of exception logs, and n>>m; The difficulty log is defined as is the normal log p after the tth round of training i The loss function Then the next round of training set can be expressed as T t+1 =D t ∪A.
8. The method according to claim 1, characterized in that The method further comprises: During fine-tuning of the pre-trained large language model or training of the to-be-used large language model, processing a weight matrix of the pre-trained large language model or the to-be-used large language model based on a low-rank matrix; Training the pre-trained large language model or the to-be-used large language model based on the processed weight matrix; The weight matrix is W, with a dimension of m*n; the low-rank matrix A has a dimension of m*r; the low-rank matrix B has a dimension of r*n, where r is much smaller than m and n so that: W'=W+ΔW=W+AB Among them, A and B are low-rank matrices with dimensions much smaller than the weight matrix W; The overall objective function is in, x i is the instruction of the i-th sample, y i,t The tth label of the i-th sample, y i,<t The first t-1 labels of the i-th sample, F w+Δw is a model function with parameters w+Δw.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the online anomaly detection method for the autonomous and controllable power business system according to any one of claims 1 to 8.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the online anomaly detection method for an autonomous and controllable power business system according to any one of claims 1 to 8 when executed.
Citation Information
Patent Citations
Log analysis method and device and electronic equipment
CN118057402A
Unsupervised log anomaly detection method independent of log parser
CN118227361A
Concurrent multipoint log anomaly detection method based on self-supervised learning
CN118567939A
Semantic log analysis system based on large language model
CN118606286A
Log detection method, device and equipment and computer storage medium
CN118760663A
Cited By
System debugging method and device, equipment, storage medium and program product
CN121364991A
Method and device for detecting abnormal operation behavior of software system and medium
CN121456684A