Abnormal detection threshold determination method and device, and product

By updating the parameters of the Gaussian surrogate model and the dynamic anomaly detection threshold generation method of the Gaussian process, the problem that the traditional method cannot adapt to the changes in time series data is solved, and higher detection accuracy and system reliability are achieved.

CN120675762APending Publication Date: 2025-09-19BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510812506.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Traditional real-time risk alert detection methods use fixed alert thresholds for anomaly detection, which cannot adapt to changes in online time series data, resulting in high missed alert and false alarm rates.

Method used

The Gaussian surrogate model is used to update parameters, and the anomaly detection threshold of time series data is dynamically adjusted through the Gaussian process. The anomaly detection threshold is dynamically generated by utilizing the probabilistic abstract representation of the Gaussian process and the predicted distribution data of the objective function value.

Benefits of technology

The accuracy of anomaly detection results is improved, so that the anomaly detection threshold can adapt to the changes in time series data, reducing the missed alarm rate and false alarm rate, and improving the overall performance and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675762A_ABST
    Figure CN120675762A_ABST
Patent Text Reader

Abstract

The invention provides an anomaly detection threshold determination method and device, electronic equipment, a storage medium and a computer program product, relates to the technical field of computers, in particular to the technical fields of artificial intelligence, big data analysis, anomaly detection and the like, and can be applied to anomaly detection scenes. According to the specific implementation scheme, according to a historical anomaly detection threshold value and a target function value corresponding to a historical parameter value combination on the basis of generating the historical anomaly detection threshold value, parameters of a Gaussian agent model are updated, and an updated agent model is obtained; determining a target parameter value combination from a parameter space according to prediction distribution data represented by the update proxy model; and according to the target parameter value combination, determining a target anomaly detection threshold value used for carrying out anomaly detection on the time sequence data in the target time period. According to the invention, the anomaly detection threshold can adapt to the change of the time series data, and the accuracy of the anomaly detection result for the time series data can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, specifically to technical fields such as artificial intelligence, big data analysis, and anomaly detection, and in particular to a method, device, electronic device, storage medium, and computer program product for determining anomaly detection thresholds, which can be applied to scenarios such as anomaly detection of time series data. Background Art

[0002] Traditional real-time risk alert detection methods rely on fixed alert thresholds for anomaly detection. These thresholds rely on manual configuration and cannot adapt to changes in online time series data, resulting in high rates of missed alerts and false positives. Summary of the Invention

[0003] The present disclosure provides a method, apparatus, electronic device, storage medium, and computer program product for determining an anomaly detection threshold.

[0004] According to a first aspect, a method for determining an anomaly detection threshold is provided, comprising: updating parameters of a Gaussian proxy model according to an objective function value corresponding to a historical anomaly detection threshold and a historical parameter value combination based on which the historical anomaly detection threshold is generated, to obtain an updated proxy model, wherein the Gaussian proxy model represents a proxy model that uses a Gaussian process as an objective function; determining a target parameter value combination from a parameter space according to predicted distribution data represented by the updated proxy model, wherein the predicted distribution data is used to represent predicted data of the objective function value corresponding to a candidate parameter value combination in the parameter space; and determining a target anomaly detection threshold for performing anomaly detection on time series data within a target time period according to the target parameter value combination.

[0005] According to a second aspect, a device for determining an anomaly detection threshold is provided, including: a model updating unit, configured to update the parameters of a Gaussian proxy model according to the historical anomaly detection threshold and the objective function value corresponding to the historical parameter value combination based on which the historical anomaly detection threshold is generated, to obtain an updated proxy model, wherein the Gaussian proxy model represents a proxy model that uses a Gaussian process as the objective function; a parameter determination unit, configured to determine a target parameter value combination from a parameter space according to predicted distribution data represented by the updated proxy model, wherein the predicted distribution data is used to represent predicted data of the objective function value corresponding to the candidate parameter value combination in the parameter space; a threshold determination unit, configured to determine a target anomaly detection threshold for performing anomaly detection on time series data within a target time period according to the target parameter value combination.

[0006] According to a third aspect, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so as to enable the at least one processor to execute the method described in any implementation manner of the first aspect.

[0007] According to a fourth aspect, a non-transitory computer-readable storage medium storing computer instructions is provided, where the computer instructions are used to cause a computer to execute the method as described in any implementation of the first aspect.

[0008] According to a fifth aspect, a computer program product is provided, comprising: a computer program, which implements the method described in any implementation manner of the first aspect when executed by a processor.

[0009] According to the technology disclosed in the present invention, a method and device for determining anomaly detection thresholds are provided. By updating the parameters of a Gaussian proxy model based on the historical anomaly detection thresholds and the objective function values ​​corresponding to the historical parameter value combinations based on which the historical anomaly detection thresholds are generated, the predicted data of the objective function values ​​corresponding to the candidate parameter value combinations in the parameter space are updated. Thus, a target parameter value combination can be selected from the parameter space based on the updated predicted data to generate a target anomaly detection threshold for anomaly detection of time series data within a target time period, thereby providing a dynamic update method for the anomaly detection threshold, so that the anomaly detection threshold can adapt to changes in the time series data, and help to improve the accuracy of anomaly detection results for time series data.

[0010] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] The accompanying drawings are provided to facilitate a better understanding of the present invention and do not constitute a limitation of the present disclosure. Figure 1 is an exemplary system architecture diagram in which an embodiment of the present disclosure may be applied; Figure 2 is a flowchart of an embodiment of a method for determining an anomaly detection threshold according to the present disclosure; Figure 3 A schematic diagram of an application scenario of the method for determining an anomaly detection threshold according to this embodiment; Figure 4 is a flowchart of another embodiment of a method for determining an abnormality detection threshold according to the present disclosure; Figure 5is a structural diagram of an embodiment of a device for determining an abnormality detection threshold according to the present disclosure; Figure 6 It is a schematic diagram of the structure of a computer system suitable for implementing the embodiments of the present disclosure. DETAILED DESCRIPTION

[0012] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding. These details should be considered as merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0013] In the technical solutions disclosed herein, the collection, storage, use, processing, transmission, provision and disclosure of user personal information involved comply with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0014] Figure 1 An exemplary architecture 100 is shown to which the method and apparatus for determining an anomaly detection threshold of the present disclosure can be applied.

[0015] like Figure 1 As shown, system architecture 100 may include terminal devices 101, 102, and 103, a network 104, and a server 105. The communication connections between terminal devices 101, 102, and 103 constitute a topological network, and network 104 is used to provide a medium for communication links between terminal devices 101, 102, and 103 and server 105. Network 104 may include various connection types, such as wired or wireless communication links or fiber optic cables.

[0016] Terminal devices 101, 102, and 103 can be hardware devices or software that support network connection for data interaction and data processing. When terminal devices 101, 102, and 103 are hardware, they can be various electronic devices that support network connection, information acquisition, interaction, display, processing, and other functions, including but not limited to smartphones, tablet computers, e-book readers, laptop computers, and desktop computers. When terminal devices 101, 102, and 103 are software, they can be installed in the electronic devices listed above. They can be implemented as multiple software or software modules, for example, to provide distributed services, or they can be implemented as a single software or software module. No specific limitations are given here.

[0017] The server 105 may be a server that provides various services, for example, a backend processing server that obtains time series data generated by the terminal devices 101, 102, and 103 and performs anomaly detection on the time series data according to a dynamically updated anomaly detection threshold. As an example, the server 105 may be a cloud server.

[0018] It should be noted that a server can be either hardware or software. When a server is hardware, it can be implemented as a distributed server cluster consisting of multiple servers, or as a single server. When a server is software, it can be implemented as multiple software programs or software modules (for example, software or software modules used to provide distributed services), or as a single software program or software module. This is not specifically limited here.

[0019] It should also be noted that the methods for determining anomaly detection thresholds provided in the embodiments of the present disclosure are generally executed by a server, but this does not preclude the possibility of execution by a terminal device, or of a server and a terminal device cooperating with each other. Accordingly, the various components (e.g., various units) included in the apparatus for determining anomaly detection thresholds may be entirely located in the server, entirely located in the terminal device, or separately located in the server and the terminal device.

[0020] It should be understood that Figure 1 The number of terminal devices, networks, and servers described is merely illustrative. Any number of terminal devices, networks, and servers may be provided as needed. When the electronic device on which the method for determining anomaly detection thresholds is executed does not need to transmit data with other electronic devices, the system architecture may include only the electronic device (e.g., terminal device or server) on which the method for determining anomaly detection thresholds is executed.

[0021] Please refer to Figure 2 , Figure 2 A data processing flow diagram of a method for determining an anomaly detection threshold provided in an embodiment of the present disclosure. In process 200, the following steps are included: Step 201 : Update the parameters of the Gaussian surrogate model according to the objective function value corresponding to the combination of the historical anomaly detection threshold and the historical parameter value based on which the historical anomaly detection threshold is generated.

[0022] In this embodiment, the execution subject of the method for determining the abnormality detection threshold (for example, Figure 1 The server in the example ( ) can update the parameters of the Gaussian surrogate model according to the objective function value corresponding to the historical anomaly detection threshold and the historical parameter value combination based on which the historical anomaly detection threshold is generated.

[0023] The historical anomaly detection threshold is used to detect anomalies in time series data within a historical time period. A time period is typically a fixed duration, such as 24 hours. The historical time period can be multiple time periods up to the current time, such as all statistically analyzed time periods up to the current time, or a single time period up to the current time.

[0024] Time series data refers to data recorded in chronological order, reflecting the values ​​of one or more variables at different points in time. The time dimension of this data allows it to capture trends, periodicity, volatility, and other time-related patterns in variables over time, making it valuable for analyzing the behavior of dynamic systems, predicting future trends, and making time-based decisions. For time series data within a historical time period, if the value at a particular moment exceeds the historical anomaly detection threshold, the time series data at that moment is considered anomalous. The aforementioned execution entity can collect the data values ​​of the same parameter at various moments from the log file and statistically generate the time series data.

[0025] In the financial field, time series data includes stock price data and foreign exchange rate data; in the meteorological environment field, time series data includes meteorological monitoring data and hydrological data; in the industrial equipment operation field, time series data includes system load data and energy consumption data; in the medical and health field, time series data includes patient vital signs data and disease incidence data; in the network traffic detection field, time series data includes network traffic, traffic burst rate, and connection number data.

[0026] The Gaussian surrogate model represents a surrogate model that uses a Gaussian process as its objective function. In anomaly detection scenarios, the Gaussian surrogate model is a probabilistic, abstract representation of the operating state of the system that generates time series data, reflecting the operating characteristics of the system at different points in time. It captures the data distribution patterns of the system under normal operating conditions, namely, that most normal data points are concentrated within a specific range of values, and the changes between these data points are relatively smooth and continuous.

[0027] The objective function value corresponding to the historical parameter value combination used to generate the historical anomaly detection threshold represents the overall performance of anomaly detection results obtained by using the historical anomaly detection threshold on time series data. This objective function is calculated using the objective function. The objective function is used to measure the effectiveness of the anomaly detection threshold in actual anomaly detection applications. For example, the objective function value represents the accuracy and recall of anomaly detection results. The parameter value combination is a set of key characteristic variables that quantitatively describe the operating state of the running system and influence anomaly detection results. It comprehensively characterizes the operating characteristics of the running system near the boundary between normal and abnormal conditions from multiple dimensions.

[0028] A Gaussian process is a probabilistic model that can be viewed as an infinite-dimensional Gaussian distribution, defined by a mean function and a covariance function (kernel function). The Gaussian process assumes that the values ​​of the objective function in the parameter space follow a joint Gaussian distribution, which can describe the uncertainty and correlation of the objective function. The kernel function plays a key role in this, constructing the covariance matrix of the Gaussian process, describing the similarities between different points in the parameter space and thus reflecting the structural characteristics of the objective function.

[0029] In Bayesian optimization, it is necessary to know the uncertainty of the objective function at unsampled points in the parameter space. Gaussian processes can provide this uncertainty information. For example, given a number of known sampling points (historical parameter value combinations), a Gaussian process can provide the predicted mean (representing the best guess of the objective function value at that point) and variance (representing a measure of the uncertainty of the objective function value at that point) of the objective function value at a new sampling point (candidate parameter value combination).

[0030] The parameter space includes multiple parameters. A specific parameter value is assigned to each parameter to obtain a sampling point, i.e., a parameter value combination. Using a preset calculation method, an anomaly detection threshold can be generated based on the multiple parameter values ​​in the parameter value combination.

[0031] Gaussian processes typically assume that the objective function is smooth. This is reasonable in many practical problems, such as in physics experiments or machine learning hyperparameter optimization, where the output of the objective function often does not jump dramatically with small changes in the input. This smoothness assumption makes Gaussian processes well suited for modeling objective functions with continuously varying characteristics.

[0032] For example, for each time period ending in the current time period, the corresponding historical parameter value combination and objective function value are added to the dataset. The dataset contains the historical anomaly detection thresholds for all time periods up to the current time period, along with the objective function values ​​corresponding to the historical parameter value combinations used to generate these thresholds. Based on the dataset, the parameters of the Gaussian surrogate model, namely the parameters of the mean function and the kernel function, are updated.

[0033] For example, for the mean function, based on the new data points in the dataset, appropriate statistical methods (such as maximum likelihood estimation) are used to re-estimate the parameters of the mean function so that the mean function can better reflect the changes in the central tendency of the dataset. For example, if the mean function was originally assumed to be a linear function, the slope and intercept parameters of this linear function can be refitted using the new data.

[0034] For the kernel function, we use the new dataset and optimization methods (such as gradient descent) to re-estimate the kernel function's hyperparameters (such as length scale and signal variance). This step is to enable the kernel function to more accurately capture the similarities between sample points and the nonlinear relationships in the data, thereby improving the Gaussian process's modeling accuracy for the target function.

[0035] Taking network traffic anomaly detection as an example, network traffic data is typically recorded in the form of time series data, including traffic flow per second, traffic burst rate, and number of connections. This data can reflect the network's operating status and traffic patterns. For example, network traffic is typically higher during business hours and lower at night or during non-business hours. The Gaussian proxy model analyzes historical network traffic data, including traffic trends, connection number fluctuations, and abnormal traffic patterns. It then incorporates business factors such as the network environment (such as network bandwidth and server load) and security requirements (such as sensitivity to different types of network attacks) to model anomaly detection results under different parameter combinations using a Gaussian process.

[0036] In the network traffic anomaly detection scenario, the objective function measures the effectiveness of anomaly detection results for network traffic data, for example, by weighting precision and recall. Precision represents the proportion of network traffic data predicted to be anomalies that are truly anomalies; recall represents the proportion of network traffic data correctly predicted to be anomalies among all actual anomalies. The weightings of precision and recall can be adjusted based on the network's importance and security requirements. For example, for traffic detection on core network devices, the weighting of recall can be increased to ensure timely detection of network attacks; whereas for edge network devices, the weighting of accuracy can be appropriately increased to reduce false positives.

[0037] The system analyzes historical anomaly detection results for different parameter combinations in historical traffic data, evaluates precision and recall, and calculates the objective function value. These values ​​serve as supervisory information to adjust the mean and kernel parameters of the Gaussian process, improving the Gaussian proxy model's ability to fit historical traffic data and predict new parameter combinations. For example, if a parameter combination performs well in detecting anomalies like DDoS (Distributed Denial of Service) attacks but poorly in detecting malicious scans, the updated Gaussian proxy model will balance these two factors to guide subsequent operations in selecting the optimal parameter combination.

[0038] For example, monitoring industrial equipment during operation generates a large amount of time-series data, including temperature, pressure, vibration, and current. This data reflects the equipment's operational status. For example, during equipment startup and shutdown, data fluctuations can be significant, easily leading to false alarms. Meanwhile, during stable operation, minor anomalies can be easily missed.

[0039] The Gaussian surrogate model analyzes historical equipment operating data, including characteristics such as temperature change rate, pressure fluctuation amplitude, and vibration frequency distribution. Based on business requirements such as equipment operating stage and load variations, it uses a Gaussian process to model anomaly detection results under different parameter combinations. When updating the Gaussian surrogate model's parameters, it analyzes historical anomaly detection thresholds and corresponding objective function values ​​(such as accuracy and recall) to learn the inherent patterns and anomaly characteristics of industrial equipment operating data, thereby dynamically adjusting the model parameters. For example, the threshold range can be automatically relaxed to reduce false positives due to the large data fluctuations during equipment startup; during stable operation, the threshold range can be tightened to improve detection of minor anomalies.

[0040] In some optional implementations of this embodiment, the Gaussian proxy model includes a fused kernel function obtained by fusing multiple kernel functions. The number and type of the multiple kernel functions can be flexibly set according to the requirements of the anomaly detection scenario.

[0041] For example, the fusion kernel function is derived by fusing the RBF (Radial Basis Function) kernel function with the Matérn kernel function. The RBF kernel function has global and smooth characteristics, capable of capturing global trends and long-term dependencies in the entire input space. It has good fit for the overall structure of the data and is suitable for describing relatively smooth phenomena. The Matérn kernel function controls the smoothness of the function through its smoothness parameter. When the smoothness parameter is small, it can better capture local changes and irregular fluctuations in the data and is suitable for non-smooth or irregular data.

[0042] The combination of the two not only retains the RBF kernel function's grasp of the global trend, but also effectively captures the local complex structure through the Matérn kernel function, making the Gaussian surrogate model more flexible in processing data with different characteristics and able to adapt to both smooth and non-smooth data patterns.

[0043] In this implementation, the execution entity may perform step 201 as follows: updating the parameters of the fusion kernel function in the Gaussian proxy model according to the objective function value corresponding to the historical anomaly detection threshold and the combination of historical parameter values ​​based on which the historical anomaly detection threshold is generated.

[0044] In this implementation, the parameters of the fusion kernel function in the Gaussian proxy model are updated according to the objective function value corresponding to the historical anomaly detection threshold and the historical parameter value combination based on which the historical anomaly detection threshold is generated, so that the Gaussian proxy model is more flexible in processing data with different characteristics and can adapt to both smooth and non-smooth data patterns.

[0045] Step 202 : determining a target parameter value combination from the parameter space based on the predicted distribution data represented by the updated proxy model.

[0046] In this embodiment, the execution entity may determine a target parameter value combination from the parameter space according to the predicted distribution data represented by the update agent model.

[0047] The predicted distribution data is used to represent the predicted data of the objective function value corresponding to the candidate parameter value combination in the parameter space, including the mean and variance.

[0048] By updating the updated mean function in the surrogate model, the mean corresponding to each candidate parameter value combination in the parameter space can be determined; by updating the updated kernel function in the surrogate model, the variance corresponding to each candidate parameter value combination in the parameter space can be determined.

[0049] In this embodiment, an acquisition function (Acquisition Function) can be used to judge the pros and cons of candidate parameter value combinations based on the predictive distribution data represented by the updated proxy model, and guide the selection of the next parameter value combination (target parameter value combination). Acquisition functions, such as PI (Probability of Improvement), EI (Expected Improvement), and LCB (Lower Confidence Bound), are key tools for balancing exploration and exploitation. Exploration refers to sampling areas where knowledge of the objective function is insufficient, in order to obtain more information to reduce uncertainty about the objective function. Simply put, it is to try areas that are currently less understood in order to discover possible better solutions.

[0050] Utilization refers to further sampling and optimizing areas that demonstrate good performance based on the existing knowledge about the objective function. In other words, it is about making full use of known information and conducting in-depth exploration near the current optimal solution in the hope of finding a better solution or confirming the optimality of the current solution.

[0051] The acquisition function needs to strike a balance between these two. If exploration is performed exclusively without exploitation, the acquired useful information may not be effectively utilized, resulting in a waste of computational resources. Conversely, if exploitation is performed exclusively without exploration, the algorithm may be trapped in a local optimum and unable to find the global optimal solution. Therefore, the design of the acquisition function needs to strike a balance between exploration and exploitation, ensuring that known information is effectively utilized while also appropriately exploring unknown areas, thereby improving the overall efficiency and effectiveness of the optimization.

[0052] In some optional implementations of this embodiment, the execution entity may perform step 202 in the following manner: determining a target parameter value combination from the parameter space based on the predicted distribution data and historical anomaly detection results within a historical time period.

[0053] As an example, feature extraction is performed on historical anomaly detection results within a historical time period to obtain anomaly detection feature data; based on the predicted distribution data and the anomaly detection feature data, a target parameter value combination is determined from the parameter space.

[0054] Specifically, various features in the anomaly detection feature data are fused to form a comprehensive feature vector; according to the anomaly detection scenario requirements and the importance of the features, weights are assigned to the mean, variance and each feature vector in the comprehensive feature vector of the predicted distribution data; based on the mean, variance and vector features, and their respective weights, the scores of each candidate parameter value combination in the parameter space are calculated; and the candidate parameter value combination with the highest score is determined as the target parameter value combination.

[0055] Taking the network traffic anomaly detection scenario as an example, the collection function evaluates candidate parameter value combinations based on the mean, variance, and anomaly detection characteristics of the network environment and time period from historical network traffic anomaly detection results. For example, for high-bandwidth network environments and network traffic data during working hours, parameter value combinations that increase traffic detection sensitivity are prioritized to adapt to network traffic changes and business needs.

[0056] Taking the industrial equipment operation monitoring scenario as an example, the acquisition function evaluates candidate parameter value combinations based on the predicted mean and variance, as well as anomaly detection feature data such as equipment type and operating stage from historical operation test results. For example, for high-speed rotating equipment and during the startup phase, combinations that increase vibration monitoring sensitivity are prioritized to adapt to changes in equipment operating status and business needs.

[0057] In this implementation, when determining target parameter value combinations from the parameter space, historical detection results are further considered, allowing the selection of target parameter value combinations to better align with the changing risks of actual anomaly detection scenarios. Historical detection results provide realistic feedback on alert effectiveness, helping the acquisition function identify effective parameter combinations in different scenarios and over time. This not only improves sampling accuracy and reduces blind exploration, but also further enhances the adaptability of target parameter value combinations to actual anomaly detection scenarios.

[0058] In some optional implementations of this embodiment, the above-mentioned execution entity can determine the target parameter value combination in the following manner: first, perform feature extraction on the historical anomaly detection results to determine the dimensional features that affect the sampling probability of the candidate parameter value combination under multiple preset feature dimensions; and determine the target parameter value combination from the parameter space based on the predicted distribution data and the dimensional features.

[0059] In this implementation, multiple preset feature dimensions can be flexibly set according to the specific anomaly detection scenario, such as business type dimension, user behavior dimension, risk level dimension, and alarm frequency dimension.

[0060] In the business type dimension, data is classified according to business type, and risk characteristics of different business types are extracted; in the user behavior dimension, user behavior patterns are analyzed and risk characteristics related to user behavior are extracted; in the risk level dimension, data is classified according to the severity of abnormal events, and characteristics of different risk levels are extracted; in the alarm frequency dimension, the frequency of alarm triggering is analyzed and alarm frequency characteristics are extracted.

[0061] As an example, according to the anomaly detection scenario requirements and the importance of each dimensional feature, weights are assigned to the mean, variance, and dimensional feature vectors of the predicted distribution data; based on the mean, variance, and dimensional feature vectors, as well as their respective weights, the scores of each candidate parameter value combination in the parameter space are calculated; the candidate parameter value combination with the highest score is determined as the target parameter value combination

[0062] In the process of determining the target parameter value combination from the parameter space, further based on the dimensional features under multiple preset feature dimensions in the historical detection results, the selection of the target parameter value combination can be more in line with the risk changes of the actual anomaly detection scenario, which helps to further improve the adaptability of the target parameter value combination to the actual anomaly detection scenario.

[0063] In some optional implementations of this embodiment, the multiple preset feature dimensions include an anomaly detection scene dimension and a time dimension.

[0064] In this implementation, the above-mentioned execution entity can execute the process of determining the target parameter value combination in the following manner: first, perform feature extraction on the historical anomaly detection results to determine the scene features that characterize the abnormal characteristics of the abnormal event in the anomaly detection scene dimension and the time features that characterize the abnormal characteristics of the abnormal event in the time dimension; then, determine the target parameter value combination from the parameter space based on the predicted distribution data, scene features and time features.

[0065] The abnormal characteristics of abnormal events in the dimension of abnormal detection scenarios generally refer to the differences in the frequency and pattern of abnormal events in different abnormal detection scenarios, and the impact of these differences on the stability of the risk warning system's prediction results. The specific manifestations are: Abnormal event volatility refers to the degree of variability in the frequency and intensity of abnormal events across different scenarios. Scenarios with high volatility mean that abnormal events occur more randomly and are difficult to predict.

[0066] Data sparsity: In some scenarios, the number of abnormal events is small, resulting in insufficient historical data and increasing the uncertainty of risk assessment for the scenario.

[0067] Business complexity: The more complex the business processes and user behaviors involved in the scenario, the more elusive its risk characteristics are, which increases the uncertainty of model predictions.

[0068] The abnormal characteristics of abnormal events in the time dimension generally refer to the regular patterns of abnormal events in the time dimension, which are specifically manifested as follows: Periodicity within a certain timeframe. For example, intraday periodicity means the probability of an abnormal event occurring varies at different times of the day. For example, the incidence of abnormal events at night may be higher than that during the day. Weekly periodicity means the probability of an abnormal event occurring varies on different days of the week. For example, the incidence of abnormal events on weekends may be higher than that on weekdays.

[0069] Special periodicity: The probability of abnormal events occurring in specific time periods (such as holidays, promotional events, etc.) increases significantly.

[0070] In this implementation, the acquisition function can be improved to incorporate scene uncertainty factors and time periodic factors. Through the improved acquisition function, the target parameter value combination is determined from the parameter space based on the predicted distribution data, scene characteristics and time characteristics.

[0071] Specifically, the scene uncertainty is determined according to the scene characteristics and used as a weight factor. The improved sampling function is:

[0072] in, Represents the weight factor corresponding to the uncertainty of the scene, represents the original acquisition function, Represents an acquisition function that incorporates scene uncertainty.

[0073] The acquisition function is adjusted according to the time characteristics. Under the time periodicity constraint, the improved acquisition function can be expressed as:

[0074] in, Indicates the current time, Indicates a known time period (such as 24 hours). Represents a collection function that incorporates time periodicity. This allows the collection function to automatically adjust sampling priorities within periodic time periods. For example, during periods of high incidence of abnormal events (such as certain hours determined based on historical data), the collection function's value will be relatively high, increasing the likelihood of sampling during these periods and better capturing risk fluctuations. Furthermore, you can also set multi-frequency periodic constraints based on actual business cycles (such as the difference between weekdays and weekends).

[0075] Finally, combining scene uncertainty and time periodicity, the improved acquisition function can be expressed as:

[0076] in, Represents the improved acquisition function.

[0077] When selecting new sampling points, the acquisition function will comprehensively consider the uncertainty and time periodicity of the scene, perform sampling more effectively, and obtain a target parameter value combination that is more suitable for the actual anomaly detection scenario.

[0078] In this implementation, the improved acquisition function can better adapt to complex business scenarios and time changes based on predicted distribution data, scenario characteristics and time characteristics, making the dynamic adjustment of alarm parameters more intelligent and efficient.

[0079] Step 203: Determine a target anomaly detection threshold for performing anomaly detection on the time series data within the target time period according to the target parameter value combination.

[0080] In this embodiment, the execution entity may determine a target anomaly detection threshold for performing anomaly detection on time series data within a target time period according to a combination of target parameter values.

[0081] In this embodiment, the target anomaly detection threshold can be obtained by calculating multiple parameter values ​​in the target parameter value combination according to a preset calculation formula.

[0082] The target time period can be the next time after the current time period. Continuing with the example of a 24-hour time period, in response to the end of a time period, the above steps 201-203 are used to obtain the target anomaly detection threshold for the time series data in the next time period.

[0083] Steps 201-203 above can be used to dynamically generate target anomaly detection thresholds for time series data in different scenarios across different technical fields. In particular, the feature extraction of time series data in the scenario and time dimensions, as well as the acquisition function's consideration of scenario uncertainty and temporal periodicity, matches the characteristics of time series data, improving the adaptability of the target anomaly detection threshold to time series data.

[0084] In some optional implementations of this embodiment, the target parameter value combination includes a basic threshold and an offset parameter value representing abnormal characteristics of an abnormal event in multiple preset feature dimensions relative to the basic threshold.

[0085] Taking multiple preset feature dimensions as business type dimension, user behavior dimension, risk level dimension, and alarm frequency dimension as an example, the offset parameter values ​​include business type offset parameter values, user behavior offset parameter values, risk level offset parameter values, and alarm frequency offset parameter values ​​that correspond one to one with the business type dimension, user behavior dimension, risk level dimension, and alarm frequency dimension.

[0086] In this implementation, the execution subject may perform step 203 in the following manner: determining a target anomaly detection threshold by combining a basic threshold and an offset parameter value.

[0087] As an example, the offset parameter values ​​corresponding to multiple preset feature dimensions are combined to obtain a total offset parameter value; the total offset parameter value is used as the increase ratio of the basic threshold to obtain the target anomaly detection threshold.

[0088] Among them, the basic threshold is based on the IQR (Interquartile Range), a statistic that measures the degree of data dispersion. It represents the difference between the 75th percentile (Q3, the upper quartile) and the 25th percentile (Q1, the lower quartile) in the data, that is, IQR = Q3 - Q1. The IQR reflects the distribution range of the middle 50% of observations in the data. Compared with the range (the difference between the maximum and minimum values), the IQR is more robust and less susceptible to extreme values.

[0089] In anomaly detection, IQR can effectively identify outliers in data. Anomaly detection methods based on IQR usually adopt the following rules: First, sort the data and calculate the 25th percentile (Q1) and 75th percentile (Q3). Next, calculate the IQR: IQR = Q3 - Q1. Then, set a multiplier k (usually 1.5 or 3) and define values ​​in the data that are less than Q1 - k × IQR or greater than Q3 + k × IQR as outliers.

[0090] In this implementation, the parameters in the target parameter value combination are clarified, and the target anomaly detection threshold is determined based on the target parameter value combination. On the basis of the basic threshold, the offset parameter values ​​corresponding to multiple preset feature dimensions are referenced, thereby improving the accuracy of the target anomaly detection threshold and its adaptability to the anomaly detection scenario.

[0091] In some optional implementations of this embodiment, the plurality of preset feature dimensions include an anomaly detection scene dimension and a time dimension. In this implementation, the parameter space includes three parameters: a basic threshold parameter, a scene offset parameter, and a time offset parameter.

[0092] In this implementation, the execution entity may perform the target anomaly detection threshold determination process in the following manner: determine the target anomaly detection threshold by combining the basic threshold, the scene offset parameter value, and the time offset parameter value.

[0093] Among them, the scene offset parameter value represents the degree of deviation of the abnormal characteristics of the abnormal event in the abnormal detection scene dimension relative to the basic threshold, and the time offset parameter value represents the degree of deviation of the abnormal characteristics of the abnormal event in the time dimension relative to the basic threshold.

[0094] As an example, the above execution entity can calculate the target anomaly detection threshold using the following formula:

[0095] in, 、 、 and They represent the target anomaly detection threshold, basic threshold, scene offset parameter value, and time offset parameter value respectively.

[0096] Taking the network traffic anomaly detection scenario as an example, the base threshold is determined based on the statistical characteristics of historical network traffic data and serves as the baseline for measuring normal network traffic. The scenario offset parameter value reflects the differences in anomaly characteristics under different network environments (such as varying network bandwidth and server configuration). For example, in a high-bandwidth network environment, the base traffic threshold value will be increased accordingly, while the offset parameter value will be dynamically adjusted based on the network device load and historical traffic patterns. The time offset parameter value takes into account the variability of network traffic over different time periods. For example, during business hours, when network traffic is typically high, the time offset parameter value may appropriately relax the threshold range. However, at night or during non-business hours, when network traffic is low, the time offset parameter value may tighten the threshold range to improve detection of anomalous traffic.

[0097] Taking the industrial equipment operation monitoring scenario as an example, the basic threshold is determined based on the statistical characteristics of historical equipment operation data and serves as the basic boundary for measuring normal equipment operation. The scenario offset parameter value reflects the differences in abnormal characteristics under different equipment types and operating modes. For example, for high-speed rotating equipment, the scenario offset parameter value of the vibration amplitude threshold is dynamically adjusted based on scenario factors such as equipment speed and load. The time offset parameter value takes into account the changes in abnormal characteristics at different time periods during equipment operation. For example, during the equipment startup and shutdown phases, the time offset parameter value is adjusted accordingly to accommodate large data fluctuations.

[0098] In this implementation, the target anomaly detection threshold is determined by combining a base threshold, a scenario offset parameter, and a time offset parameter. This allows the threshold to be dynamically adjusted based on different scenarios and time periods. This dynamic adjustment mechanism more accurately adapts to changing data characteristics in different anomaly detection scenarios, improving anomaly detection accuracy. Furthermore, it effectively reduces false positives and false negatives, increasing risk detection rates, and enabling more accurate and timely risk monitoring and response, enhancing the overall performance and reliability of the system.

[0099] Continue to see Figure 3 , Figure 3Schematic diagram 300 of an application scenario of the method for determining anomaly detection thresholds according to this embodiment. A server 301 collects time series data from a terminal device 302 in real time and performs anomaly detection on the time series data within a time period (24 hours). In response to the completion of anomaly detection corresponding to each time period, the server updates the parameters of a Gaussian surrogate model based on the historical anomaly detection threshold and the target function value corresponding to the combination of historical parameter values ​​used to generate the historical anomaly detection threshold, thereby obtaining an updated surrogate model. The Gaussian surrogate model represents a surrogate model that uses a Gaussian process as the target function. A sampling function is used to determine a target parameter value combination from a parameter space based on the predicted distribution data represented by the updated surrogate model. The predicted distribution data is used to represent predicted data of the target function value corresponding to the candidate parameter value combination in the parameter space. Based on the target parameter value combination, a target anomaly detection threshold for performing anomaly detection on the time series data within the target time period is determined.

[0100] In this embodiment, a method for determining anomaly detection thresholds is provided. By updating the parameters of the Gaussian proxy model based on the historical anomaly detection thresholds and the objective function values ​​corresponding to the historical parameter value combinations based on which the historical anomaly detection thresholds are generated, the predicted data of the objective function values ​​corresponding to the candidate parameter value combinations in the parameter space are updated. Thus, a target parameter value combination can be selected from the parameter space based on the updated predicted data to generate a target anomaly detection threshold for anomaly detection of time series data within a target time period, thereby providing a dynamic update method for the anomaly detection threshold, so that the anomaly detection threshold can adapt to changes in time series data, which helps to improve the accuracy of anomaly detection results for time series data.

[0101] In some optional implementations of this embodiment, the execution entity may further perform the following operations before executing step 201: First, based on the review results of the historical anomaly detection results within the historical time period, the accuracy and recall of the historical anomaly detection results are determined; then, based on the accuracy and recall, the objective function value corresponding to the historical parameter value combination is determined.

[0102] The target personnel can check the historical anomaly detection results and obtain the compliance results. For example, the review results include confirmed risk, false positive, no impact, blocked for 1 day, blocked for 7 days, etc.

[0103] The accuracy and recall of anomaly detection can be determined based on the matching results. Accuracy represents the proportion of samples predicted as anomalies that are truly anomalies. Recall represents the proportion of samples correctly predicted as anomalies among all actual anomalies. Furthermore, a weighted balance is applied to the accuracy and recall to determine the objective function value.

[0104] As an example, the objective function value can be calculated by the following formula: represents the objective function value, Indicates accuracy and recall The balance coefficient.

[0105] In this implementation, a specific objective function is provided. While focusing on the accuracy of anomaly detection results, it also emphasizes the comprehensive identification of abnormal samples. It can balance the false positives and false negatives of anomaly detection and help improve the accuracy of the updated proxy model.

[0106] In some optional implementations of this embodiment, the above-mentioned execution entity can perform the accuracy and recall rate determination process in the following manner: first, determine the confidence level of the review result based on the result type of the review result; then, determine the accuracy and recall rate based on the review result and the confidence level.

[0107] As an example, for various review results such as confirmed risk, false positive, no impact, blocked for 1 day, and blocked for 7 days, their credibility and weights are set as follows: Risk (High Confidence): Indicates a confirmed anomaly with a higher weight (e.g., 1.0).

[0108] False positive (low confidence): indicates a normal sample that is mistakenly detected as an anomaly, with a low weight (such as 0.1).

[0109] No impact (medium confidence): indicates that the detected anomaly has no actual impact and has a medium weight (e.g., 0.5).

[0110] Block for 1 day (low confidence): indicates a temporarily blocked detection result with a low weight (such as 0.2).

[0111] Blocked for 7 days (low confidence): indicates detection results that were blocked for a longer period of time and has a lower weight (such as 0.2).

[0112] For the accuracy ( ), the labeling results with high confidence weight will increase the weight of TP (True Positive), which may improve the accuracy; the labeling results with low confidence weight will increase the weight of FP (False Positive), which may reduce the accuracy. ), the annotation results with high confidence weight will increase the weight of TP, which may improve the recall rate; the annotation results with low confidence weight will increase the weight of FN (False Negative), which may reduce the recall rate.

[0113] In this implementation, different credibility weights are set for different types of matching results, which can make the calculation of precision and recall more realistic, improve the accuracy of precision and recall, and thus improve the accuracy of the objective function value.

[0114] In some optional implementations of this embodiment, the above-mentioned execution subject may further perform the following operations: perform anomaly detection on the time series data within the target time period according to the target anomaly detection threshold to obtain a target anomaly detection result.

[0115] For example, in the field of network security, abnormal behavior can be detected by monitoring network traffic time series data. For example, a target anomaly detection threshold can be set at traffic exceeding 100 megabytes (MB) per second or a burst rate exceeding 20 MB per second. When monitoring network traffic within a target time period, if traffic consistently exceeds the threshold during a certain period, this may indicate that the network is under a DDoS (Distributed Denial of Service) attack. This triggers an anomaly alarm, and timely action can prevent network downtime.

[0116] As another example, monitoring transaction amounts and frequency in time series data is crucial for e-commerce platform transaction monitoring. The target anomaly detection threshold is set at a transaction amount exceeding 1 million yuan per minute or a transaction frequency exceeding 10 transactions per second. If both the transaction amount and frequency exceed the threshold within the target time period, it may indicate malicious fraud or cash-out activity. The system will then trigger an anomaly alert to quickly verify the authenticity of the transaction and prevent financial losses.

[0117] In this implementation, the dynamically determined target anomaly detection threshold helps to improve the accuracy of the target anomaly detection result.

[0118] Continue to refer Figure 4 , shows a schematic process 400 of another embodiment of a method for determining an anomaly detection threshold according to the present disclosure. In process 400, the following steps are included: Step 401 : Determine the accuracy and recall of the historical anomaly detection results based on the review results of the historical anomaly detection results obtained according to the historical anomaly detection threshold.

[0119] Step 402 : Determine, based on the accuracy and recall rate, the objective function value corresponding to the combination of historical parameter values ​​on which the historical anomaly detection threshold is generated.

[0120] Step 403 : Update the parameters of the Gaussian proxy model according to the objective function value corresponding to the combination of the historical anomaly detection threshold and the historical parameter value to obtain an updated proxy model.

[0121] Among them, the Gaussian proxy model characterization adopts the Gaussian process as the proxy model of the objective function, and adopts the fusion kernel function obtained by fusing multiple kernel functions.

[0122] Step 404 : extract features from the historical anomaly detection results to determine scene features that characterize the abnormal characteristics of the abnormal event in the anomaly detection scene dimension and time features that characterize the abnormal characteristics of the abnormal event in the time dimension.

[0123] Step 405 : Determine a target parameter value combination from the parameter space based on the predicted distribution data, scene characteristics, and time characteristics.

[0124] Step 406 : Determine a target anomaly detection threshold by combining the basic threshold scene offset parameter value and the time offset parameter value in the target parameter value combination.

[0125] Among them, the scene offset parameter value represents the degree of deviation of the abnormal characteristics of the abnormal event in the abnormal detection scene dimension relative to the basic threshold, and the time offset parameter value represents the degree of deviation of the abnormal characteristics of the abnormal event in the time dimension relative to the basic threshold.

[0126] Step 407 : Perform anomaly detection on the time series data within the target time period according to the target anomaly detection threshold to obtain a target anomaly detection result.

[0127] In this implementation, the above steps 401-407 are iteratively performed in units of time periods to dynamically determine the target anomaly detection threshold and target anomaly detection result corresponding to each time period.

[0128] Compared with the above-mentioned process 200, the process 500 of the method for determining the anomaly detection threshold in this embodiment specifically describes the process of determining the objective function value, the process of determining the target parameter value combination, the process of determining the target anomaly detection threshold, and the anomaly detection process based on the target anomaly detection threshold, so that the anomaly detection threshold can adapt to the changes in time series data, which helps to improve the accuracy of the anomaly detection results for time series data.

[0129] Continue to refer Figure 5 As an implementation of the methods shown in the above figures, the present disclosure provides an embodiment of a device for determining an abnormality detection threshold. Figure 2 Corresponding to the method embodiment shown, the system can be specifically applied to various electronic devices.

[0130] like Figure 5As shown, the device 500 for determining the anomaly detection threshold includes: a model updating unit 501, which is configured to update the parameters of the Gaussian proxy model according to the historical anomaly detection threshold and the objective function value corresponding to the historical parameter value combination based on which the historical anomaly detection threshold is generated, to obtain an updated proxy model, wherein the Gaussian proxy model represents the proxy model using a Gaussian process as the objective function; a parameter determination unit 502, which is configured to determine the target parameter value combination from the parameter space according to the predicted distribution data represented by the updated proxy model, wherein the predicted distribution data is used to represent the predicted data of the objective function value corresponding to the candidate parameter value combination in the parameter space; a threshold determination unit 503, which is configured to determine the target anomaly detection threshold for performing anomaly detection on the time series data within the target time period according to the target parameter value combination.

[0131] In some optional implementations of this embodiment, the parameter determination unit 502 is further configured to: determine the target parameter value combination from the parameter space based on the predicted distribution data and the historical anomaly detection results obtained according to the historical anomaly detection threshold.

[0132] In some optional implementations of this embodiment, the parameter determination unit 502 is further configured to: perform feature extraction on the historical anomaly detection results, determine the dimensional features that affect the sampling probability of the candidate parameter value combination under multiple preset feature dimensions; and determine the target parameter value combination from the parameter space based on the predicted distribution data and the dimensional features.

[0133] In some optional implementations of this embodiment, the multiple preset feature dimensions include an anomaly detection scenario dimension and a time dimension, and the parameter determination unit 502 is further configured to: perform feature extraction on the historical anomaly detection results, determine the scene features that characterize the abnormal characteristics of the abnormal event in the anomaly detection scenario dimension and the time features that characterize the abnormal characteristics of the abnormal event in the time dimension; and determine the target parameter value combination from the parameter space based on the predicted distribution data, the scene features and the time features.

[0134] In some optional implementations of this embodiment, the Gaussian proxy model includes a fused kernel function obtained by fusing multiple kernel functions, and the model updating unit 501 is further configured to: update the parameters of the fused kernel function in the Gaussian proxy model according to the objective function value corresponding to the combination of the historical anomaly detection threshold and the historical parameter value based on which the historical anomaly detection threshold is generated.

[0135] In some optional implementations of this embodiment, the target parameter value combination includes a basic threshold and an offset parameter value that characterizes the abnormal characteristics of an abnormal event under multiple preset feature dimensions relative to the basic threshold, and the threshold determination unit 503 is further configured to: determine the target abnormality detection threshold in combination with the basic threshold and the offset parameter value.

[0136] In some optional implementations of this embodiment, the multiple preset feature dimensions include an anomaly detection scene dimension and a time dimension, and the threshold determination unit 503 is further configured to: determine the target anomaly detection threshold in combination with the basic threshold, the scene offset parameter value and the time offset parameter value, wherein the scene offset parameter value represents the degree of offset of the abnormal characteristics of the abnormal event in the anomaly detection scene dimension relative to the basic threshold, and the time offset parameter value represents the degree of offset of the abnormal characteristics of the abnormal event in the time dimension from the basic threshold.

[0137] In some optional implementations of this embodiment, the above-mentioned device also includes: a function value determination unit (not shown in the figure), which is configured to: determine the accuracy and recall rate of the historical anomaly detection results based on the review results of the historical anomaly detection results obtained according to the historical anomaly detection threshold; and determine the objective function value corresponding to the historical parameter value combination based on the accuracy and the recall rate.

[0138] In some optional implementations of this embodiment, the function value determination unit is further configured to: determine the confidence of the review result based on the result type of the review result; and determine the accuracy and the recall rate in combination with the review result and the confidence.

[0139] In some optional implementations of this embodiment, the above-mentioned device also includes: an anomaly detection unit (not shown in the figure), which is configured to: perform anomaly detection on the time series data within the target time period according to the target anomaly detection threshold to obtain a target anomaly detection result.

[0140] In this embodiment, a device for determining anomaly detection thresholds is provided. By updating the parameters of the Gaussian proxy model based on the historical anomaly detection thresholds and the objective function values ​​corresponding to the historical parameter value combinations based on which the historical anomaly detection thresholds are generated, the prediction data of the objective function values ​​corresponding to the candidate parameter value combinations in the parameter space are updated. Thus, a target parameter value combination can be selected from the parameter space based on the updated prediction data to generate a target anomaly detection threshold for anomaly detection of time series data within a target time period, thereby providing a dynamic update method for the anomaly detection threshold, so that the anomaly detection threshold can adapt to changes in time series data, which helps to improve the accuracy of anomaly detection results for time series data.

[0141] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that when the at least one processor executes, it can implement the method for determining the abnormality detection threshold described in any of the above embodiments.

[0142] According to an embodiment of the present disclosure, the present disclosure further provides a readable storage medium storing computer instructions, which are used to enable a computer to implement the method for determining an abnormality detection threshold described in any of the above embodiments when executed.

[0143] An embodiment of the present disclosure provides a computer program product, which, when executed by a processor, can implement the method for determining an anomaly detection threshold described in any of the above embodiments.

[0144] Figure 6 A schematic block diagram of an example electronic device 600 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are provided as examples only and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0145] like Figure 6 As shown, device 600 includes a computing unit 601, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 602 or a computer program loaded from a storage unit 608 into a random access memory (RAM) 603. RAM 603 may also store various programs and data required for the operation of device 600. Computing unit 601, ROM 602, and RAM 603 are interconnected via a bus 604. An input / output (I / O) interface 605 is also connected to bus 604.

[0146] Various components in device 600 are connected to I / O interface 605, including an input unit 606, such as a keyboard, mouse, etc.; an output unit 607, such as various types of displays, speakers, etc.; a storage unit 608, such as a magnetic disk, optical disk, etc.; and a communication unit 609, such as a network card, modem, wireless communication transceiver, etc. The communication unit 609 allows device 600 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0147] Computing unit 601 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Computing unit 601 performs the various methods and processes described above, such as the method for determining anomaly detection thresholds. For example, in some embodiments, the method for determining anomaly detection thresholds can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed onto device 600 via ROM 602 and / or communication unit 609. When the computer program is loaded into RAM 603 and executed by computing unit 601, one or more steps of the method for determining anomaly detection thresholds described above can be performed. Alternatively, in other embodiments, computing unit 601 can be configured to perform the method for determining anomaly detection thresholds via any other suitable means (e.g., via firmware).

[0148] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0149] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable anomaly detection threshold determination device, so that when the program code is executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0150] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of machine-readable storage media may include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0151] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0152] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.

[0153] A computer system may include a client and a server. The client and server are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, establishing a client-server relationship. The server can be a cloud server, also known as a cloud computing server or cloud host. This server is a host product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosts and virtual private server (VPS) services. It can also be a server in a distributed system or a server integrated with blockchain.

[0154] According to the technical solution of the embodiments of the present disclosure, a method and device for determining an anomaly detection threshold are provided. By updating the parameters of the Gaussian proxy model according to the historical anomaly detection threshold and the objective function value corresponding to the historical parameter value combination based on which the historical anomaly detection threshold is generated, the prediction data of the objective function value corresponding to the candidate parameter value combination in the parameter space is updated, so that the target parameter value combination can be selected from the parameter space according to the updated prediction data to generate the target anomaly detection threshold for anomaly detection of time series data within the target time period, thereby providing a dynamic update method for the anomaly detection threshold, so that the anomaly detection threshold can adapt to the changes in the time series data, which helps to improve the accuracy of the anomaly detection results for the time series data.

[0155] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions provided by this disclosure can be achieved. This is not a limitation herein.

[0156] The above specific embodiments do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.

Claims

1. A method for determining an anomaly detection threshold, comprising: updating the parameters of the Gaussian surrogate model according to the objective function value corresponding to the combination of the historical anomaly detection threshold and the historical parameter value based on which the historical anomaly detection threshold is generated, to obtain an updated surrogate model, wherein the Gaussian surrogate model represents a surrogate model that uses a Gaussian process as the objective function; Determining a target parameter value combination from a parameter space based on the predicted distribution data represented by the update agent model, wherein the predicted distribution data is used to represent predicted data of the target function value corresponding to the candidate parameter value combination in the parameter space; A target anomaly detection threshold for performing anomaly detection on the time series data within a target time period is determined based on the target parameter value combination.

2. The method according to claim 1, wherein Determining a target parameter value combination from a parameter space based on the predicted distribution data represented by the updated proxy model includes: The target parameter value combination is determined from the parameter space based on the predicted distribution data and the historical anomaly detection results obtained according to the historical anomaly detection threshold.

3. The method according to claim 2, wherein: Determining the target parameter value combination from the parameter space based on the predicted distribution data and the historical anomaly detection results obtained according to the historical anomaly detection threshold includes: Performing feature extraction on the historical anomaly detection results to determine dimensional features that affect the sampling probability of the candidate parameter value combination under multiple preset feature dimensions; The target parameter value combination is determined from the parameter space based on the predicted distribution data and the dimensional features.

4. The method according to claim 3, wherein: The plurality of preset feature dimensions include anomaly detection scene dimension and time dimension, and The feature extraction of the historical anomaly detection results to determine the dimensional features that affect the sampling probability of the candidate parameter value combination under multiple preset feature dimensions includes: Performing feature extraction on the historical anomaly detection results to determine scene features characterizing the abnormal characteristics of the abnormal event in the anomaly detection scene dimension and time features characterizing the abnormal characteristics of the abnormal event in the time dimension; and Determining the target parameter value combination from the parameter space based on the predicted distribution data and the dimensional features includes: The target parameter value combination is determined from the parameter space based on the predicted distribution data, the scene characteristics and the time characteristics.

5. The method according to claim 1, wherein The Gaussian proxy model includes a fusion kernel function obtained by fusing multiple kernel functions, and The updating of the parameters of the Gaussian surrogate model according to the objective function value corresponding to the historical anomaly detection threshold and the combination of historical parameter values ​​based on which the historical anomaly detection threshold is generated includes: The parameters of the fusion kernel function in the Gaussian proxy model are updated according to the objective function value corresponding to the historical anomaly detection threshold and the combination of historical parameter values ​​based on which the historical anomaly detection threshold is generated.

6. The method according to claim 1, wherein The target parameter value combination includes a basic threshold and an offset parameter value representing the abnormal characteristics of the abnormal event in multiple preset feature dimensions relative to the basic threshold, and Determining a target anomaly detection threshold for performing anomaly detection on time series data within a target time period according to the target parameter value combination includes: The target anomaly detection threshold is determined by combining the basic threshold and the offset parameter value.

7. The method according to claim 6, wherein: The plurality of preset feature dimensions include anomaly detection scene dimension and time dimension, and The determining the target anomaly detection threshold by combining the basic threshold and the offset parameter value includes: The target anomaly detection threshold is determined in combination with the basic threshold, the scene offset parameter value and the time offset parameter value, wherein the scene offset parameter value represents the degree of offset of the abnormal characteristics of the abnormal event in the abnormal detection scene dimension relative to the basic threshold, and the time offset parameter value represents the degree of offset of the abnormal characteristics of the abnormal event in the time dimension from the basic threshold.

8. The method according to claim 1, wherein Before updating the parameters of the Gaussian proxy model according to the historical anomaly detection threshold and the objective function value corresponding to the combination of historical parameter values ​​based on which the historical anomaly detection threshold is generated to obtain the updated proxy model, the method further includes: Determining the accuracy and recall of the historical anomaly detection results based on the review results of the historical anomaly detection results obtained according to the historical anomaly detection threshold; Determine the objective function value corresponding to the combination of historical parameter values ​​according to the accuracy and the recall rate.

9. The method according to claim 8, wherein Determining the accuracy and recall of the historical anomaly detection results based on the review results of the historical anomaly detection results obtained according to the historical anomaly detection threshold includes: Determining the confidence level of the review result according to the result type of the review result; The precision and recall are determined based on the review result and the confidence level.

10. The method according to claim 1, wherein Also includes: According to the target anomaly detection threshold, anomaly detection is performed on the time series data within the target time period to obtain a target anomaly detection result.

11. A device for determining an anomaly detection threshold, comprising: a model updating unit configured to update parameters of a Gaussian surrogate model according to an objective function value corresponding to a combination of a historical anomaly detection threshold and a historical parameter value based on which the historical anomaly detection threshold is generated, thereby obtaining an updated surrogate model, wherein the Gaussian surrogate model represents a surrogate model that uses a Gaussian process as an objective function; a parameter determination unit configured to determine a target parameter value combination from a parameter space based on prediction distribution data represented by the update agent model, wherein the prediction distribution data is used to represent prediction data of an objective function value corresponding to a candidate parameter value combination in the parameter space; The threshold determination unit is configured to determine a target anomaly detection threshold for performing anomaly detection on the time series data within a target time period according to the target parameter value combination.

12. An electronic device, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 10.

13. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer instructions are used to cause the computer to execute the method according to any one of claims 1 to 10.

14. A computer program product comprising: A computer program which, when executed by a processor, implements the method according to any one of claims 1 to 10.