Abnormal time sequence detection method and related equipment
By segmenting and matching historical time series signals in an industrial environment and expanding the number of normal samples in the anomaly detection model, the data imbalance problem is solved and the training effect and accuracy of the anomaly detection model are improved.
Patent Information
- Application Number
- CN202410356483.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-26
- Publication Date
- 2025-09-26
AI Technical Summary
In industrial environments, due to data imbalance, the anomaly detection model has weak feature learning effects on abnormal samples, affecting detection accuracy.
By obtaining historical time series signals, dividing them into signal subsequences with fixed window lengths, extracting abnormal and normal window samples, using feature encoders to match similar normal window samples, expanding the number of samples, and using normal and abnormal sample pairs to train the classifier model to ensure data balance.
Without increasing the cost of additional data collection, the training effect and detection accuracy of the anomaly detection model are improved, and the number of abnormal samples is increased by matching normal samples to ensure data balance.
Smart Images

Figure CN120705747A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of industry, and in particular to an abnormal timing detection method and related equipment. Background Art
[0002] Abnormal time series detection has a wide range of applications in industry, such as stock market anomaly detection, sales anomaly detection, traffic flow anomaly detection, abnormal weather detection, etc.
[0003] In real-world industrial environments, anomalies are extremely rare. This can lead to severe data imbalance in the training data for anomaly detection models: a very small number of abnormal samples, but a large number of normal samples. This causes the anomaly detection model to favor learning the characteristics of normal samples, making it less effective at learning the characteristics of abnormal samples, which in turn affects the final training results. Ultimately, the trained anomaly detection model suffers from insufficient accuracy when used for anomaly time series detection. Summary of the Invention
[0004] The embodiments of the present application provide an abnormal time series detection method and related equipment. The related equipment may include an abnormal time series detection device, an electronic device, a computer-readable storage medium and a computer program product, which can improve the training effect of the anomaly detection model and improve the anomaly detection effect without increasing additional data collection costs.
[0005] The present invention provides a method for detecting abnormal timing, including:
[0006] Acquire a historical time series signal, and divide the historical time series signal into a plurality of signal subsequences as window samples according to a preset fixed window length;
[0007] Extracting a first abnormal window sample where the abnormal signal is located, and extracting a normal window sample preceding the first abnormal window sample as a first normal window sample;
[0008] Extracting a second normal window sample with a similar distribution to the first normal window sample from the remaining normal window samples, and extracting an abnormal window sample preceding the second normal window sample as a second abnormal window sample;
[0009] Splicing the first normal window sample with the first abnormal window sample to obtain a first normal-abnormal sample pair, and splicing the second normal window sample with the second abnormal window sample to obtain a second normal-abnormal sample pair;
[0010] Using the first normal-abnormal sample pair and the second normal-abnormal sample pair to train a classifier model to obtain a trained classifier model;
[0011] The trained classifier model is used to detect the time series signal to be detected.
[0012] The step of extracting a second normal signal window having a similar distribution to the first normal signal window from the remaining normal signal windows comprises:
[0013] Determine, from the signal window samples, remaining normal window samples except the first normal window samples;
[0014] Using a feature encoder to extract a first window feature vector of the first normal window sample and a second window feature vector of the remaining normal window samples;
[0015] Based on the first window feature vector and the second window feature vector, performing feature matching on the remaining normal window samples and the first normal window samples to obtain a matching result;
[0016] According to the matching result, second normal window samples having a distribution similar to that of the first normal window samples are determined from the signal window samples.
[0017] In one embodiment, performing feature matching on the remaining normal window samples and the first normal window sample based on the first window feature vector and the second window feature vector includes:
[0018] Calculating the cosine similarity between the first window feature vector and the second window feature vector;
[0019] When the cosine similarity is higher than a preset threshold, the corresponding remaining normal window samples are determined as second normal window samples having a distribution similar to that of the first normal window samples.
[0020] In one embodiment, before extracting the first window feature vector of the first normal window sample and the second window feature vectors of the remaining normal window samples using a feature encoder, the method further includes:
[0021] Acquire a historical time series signal, and divide the historical time series signal into a plurality of signal subsequences as window samples according to a preset fixed window length;
[0022] Extracting a window where a normal signal is located from the window samples as an initial training sample;
[0023] The feature encoder is obtained by training based on the initial training sample.
[0024] In one embodiment, the first normal-abnormal sample pair and the second normal-abnormal sample pair are used to train a classifier model to obtain a trained classifier model, including:
[0025] A preset feature extraction model is used to respectively extract a first normal sample feature vector and a first abnormal sample feature vector corresponding to the first normal-abnormal sample pair, and a second normal sample feature vector and a second abnormal sample feature vector corresponding to the second normal-abnormal sample pair;
[0026] Inputting the first normal sample feature vector and the first abnormal sample feature vector into a preset classifier model for classification to obtain a first predicted sample category;
[0027] Inputting the second normal sample feature vector and the second abnormal sample feature vector into a preset classifier model for classification to obtain a second predicted sample category;
[0028] Based on the first predicted sample category and the first normal-abnormal sample pair, and the second predicted sample category and the second normal-abnormal sample pair, the preset classifier model and the preset feature extraction model are converged to obtain the trained classifier model and the trained feature extraction model.
[0029] In one embodiment, calculating the loss function according to the first predicted sample category and the second predicted sample category to obtain the model loss value includes the following steps:
[0030] According to the first predicted sample category and the second predicted sample category, statistically predicting the number of normal samples and the number of predicted abnormal samples;
[0031] Calculating a prediction ratio according to the number of predicted normal samples and the number of predicted abnormal samples;
[0032] According to the first predicted sample category and the corresponding first normal-abnormal sample pair, and the second predicted sample category and the corresponding second normal-abnormal sample pair, substituting them into the loss function to calculate a category loss value;
[0033] A model loss value is determined according to the predicted ratio and the category loss value.
[0034] In one embodiment, the method of using a preset feature extraction model to extract a first normal sample feature vector and a first abnormal sample feature vector corresponding to the first normal-abnormal sample pair, and a second normal sample feature vector and a second abnormal sample feature vector corresponding to the second normal-abnormal sample pair, includes:
[0035] A preset first feature extraction model is used to respectively extract a first normal sample feature vector and a first abnormal sample feature vector corresponding to the first normal-abnormal sample pair;
[0036] A preset second feature extraction model is used to respectively extract a second normal sample feature vector and a second abnormal sample feature vector corresponding to the second normal-abnormal sample pair, and the first feature extraction model and the second feature extraction model share model parameters.
[0037] In one embodiment, based on the first predicted sample category and the first normal-abnormal sample pair, and the second predicted sample category and the second normal-abnormal sample pair, the preset classifier model is converged to obtain a trained classifier model, including:
[0038] Calculate a loss function based on the first predicted sample category and the second predicted sample category to obtain a model loss value;
[0039] Updating the parameters of the classifier model and the feature extraction model based on the back propagation algorithm according to the model loss value;
[0040] When the model loss value no longer decreases, the current classifier model and the feature extraction model are used as the trained classifier model and the trained feature extraction model.
[0041] In one embodiment, updating the parameters of the classifier model and the feature extraction model based on the back propagation algorithm according to the model loss value includes:
[0042] updating the parameters of the first feature extraction model based on the back propagation algorithm according to the model loss value;
[0043] The parameters of the second feature extraction model are updated according to the parameters of the first feature extraction model.
[0044] In one embodiment, the trained classifier model is used to detect the time series signal to be detected, including:
[0045] Acquire a time series signal to be detected, and divide the time series signal to be detected into a plurality of signal subsequences as windows to be detected according to a preset fixed window length;
[0046] Extracting the feature vector to be detected of the window to be detected using the trained feature extraction model;
[0047] Input the feature vector to be detected into the trained classifier model for detection, and output the abnormal sample category or normal sample category corresponding to the window to be detected
[0048] Accordingly, an embodiment of the present application provides an abnormal timing detection device, comprising:
[0049] a segmentation unit, configured to obtain a historical time series signal and segment the historical time series signal into a plurality of signal subsequences as window samples according to a preset fixed window length;
[0050] an extraction unit, configured to extract a first abnormal window sample where the abnormal signal is located, and extract a normal window sample preceding the first abnormal window sample as a first normal window sample;
[0051] a matching unit, configured to extract a second normal window sample having a similar distribution to the first normal window sample from the remaining normal window samples, and extract an abnormal window sample preceding the second normal window sample as a second abnormal window sample;
[0052] an amplification unit, configured to concatenate the first normal window sample with the first abnormal window sample to obtain a first normal-abnormal sample pair, and concatenate the second normal window sample with the second abnormal window sample to obtain a second normal-abnormal sample pair;
[0053] a training unit, configured to train a classifier model using the first normal-abnormal sample pair and the second normal-abnormal sample pair to obtain a trained classifier model;
[0054] The detection unit is used to detect the time series signal to be detected using the trained classifier model.
[0055] The sub-device includes a processor and a memory, wherein the memory stores multiple instructions, and the processor loads the instructions to execute the steps in the abnormal timing detection method provided in the embodiment of the present application.
[0056] An embodiment of the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the steps of the abnormal timing detection method provided in the embodiment of the present application are implemented.
[0057] In addition, an embodiment of the present application also provides a computer program product, including a computer program or instructions, which, when executed by a processor, implements the steps in the abnormal timing detection method provided in the embodiment of the present application.
[0058] An embodiment of the present application provides an abnormal time series detection method and related equipment, which can obtain a historical time series signal and divide the historical time series signal into multiple signal subsequences as window samples according to a preset fixed window length; extract a first abnormal window sample where the abnormal signal is located, and extract a normal window sample before the first abnormal window sample as the first normal window sample; extract a second normal window sample with a similar distribution to the first normal window sample from the remaining normal window samples, and extract an abnormal window sample before the second normal window sample as the second abnormal window sample; splice the first normal window sample with the first abnormal window sample to obtain a first normal-abnormal sample pair, and splice the second normal window sample with the second abnormal window sample to obtain a second normal-abnormal sample pair; use the first normal-abnormal sample pair and the second normal-abnormal sample pair to train a classifier model to obtain a trained classifier model; and use the trained classifier model to detect the time series signal to be detected. This application learns the feature distribution of the first normal window sample before the sparse first abnormal window sample window, and extracts the second normal window sample with a distribution similar to the first normal window sample based on feature matching, and then determines the second abnormal window sample. Because the number of normal samples is large, the matching accuracy is high. This method can expand the number of samples without increasing the cost of additional data collection. In addition, this application uses the form of normal-abnormal sample pairs to train the model, which can ensure the balance of normal-abnormal sample data. This improves the training effect of the anomaly detection model and improves the anomaly detection effect without increasing the cost of additional data collection. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0060] Figure 1 Schematic diagram of a scenario of an abnormal time series detection method provided in an embodiment of the present application;
[0061] Figure 2 This is a first flow chart of the abnormal timing detection method provided by an embodiment of the present application;
[0062] Figure 3 is a second flow chart of the abnormal timing detection method provided in an embodiment of the present application;
[0063] Figure 4 is a structural diagram of an abnormal timing detection device provided in an embodiment of the present application;
[0064] Figure 5 is a structural diagram of an electronic device provided in an embodiment of the present application;
[0065] Figure 6 It is a schematic flow chart of the model training method provided in an embodiment of the present application. DETAILED DESCRIPTION
[0066] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts are within the scope of protection of this application.
[0067] The present invention provides an abnormal timing detection method and related equipment, which may include an abnormal timing detection device, an electronic device, a computer-readable storage medium, and a computer program product. The abnormal timing detection device may be integrated into an electronic device, such as a terminal or a server.
[0068] It is understandable that the abnormal time sequence detection method of this embodiment can be executed on the terminal, on the server, or jointly by the terminal and the server. The above examples should not be construed as limiting the present application.
[0069] like Figure 1 As shown, a terminal and a server jointly perform an abnormal timing detection method as an example. The abnormal timing detection system provided in the embodiment of the present application includes a terminal 10 and a server 11, etc. The terminal 10 and the server 11 are connected via a network, such as a wired or wireless network connection, wherein the abnormal timing detection device can be integrated into the server.
[0070] The server 11 can be used to: obtain a historical time series signal and, based on a preset fixed window length, divide the historical time series signal into multiple signal subsequences as window samples; extract a first abnormal window sample where the abnormal signal is located, and extract a normal window sample preceding the first abnormal window sample as the first normal window sample; extract a second normal window sample with a similar distribution to the first normal window sample from the remaining normal window samples, and extract an abnormal window sample preceding the second normal window sample as the second abnormal window sample; concatenate the first normal window sample with the first abnormal window sample to obtain a first normal-abnormal sample pair, and concatenate the second normal window sample with the second abnormal window sample to obtain a second normal-abnormal sample pair; and train a classifier model using the first normal-abnormal sample pair and the second normal-abnormal sample pair to obtain a trained classifier model. The server 11 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The abnormal timing detection method or device disclosed in this application, wherein multiple servers can be composed into a blockchain, and the servers are nodes on the blockchain.
[0071] The terminal 10 can be used to detect the time series signal to be detected using a trained classifier model. The terminal 10 can include a mobile phone, an intelligent voice interaction device, a smart home appliance, an in-vehicle terminal, an aircraft, a tablet computer, a laptop computer, or a personal computer (PC). The terminal 10 can also be configured with a client, which can be an application client or a browser client.
[0072] It should be noted that the order of description of the following embodiments is not intended to limit the preferred order of the embodiments.
[0073] This embodiment will be described from the perspective of an abnormal time series detection device, which can be integrated into an electronic device, such as a server or terminal. The method of using normal and abnormal samples to train a model is applied to abnormal time series detection, and can also be extended to other fields such as time series prediction, time series completion, and other scenarios. Figure 2 and Figure 6 As shown, the specific process of the abnormal timing detection method can be as follows:
[0074] S101 : Acquire a historical time series signal, and divide the historical time series signal into a plurality of signal subsequences as window samples according to a preset fixed window length.
[0075] Timing signals are a series of pulse signals used to synchronize and control operations in digital circuits or computer systems. They occur in a specific time sequence to ensure that each component transmits, processes, and stores data at the correct time.
[0076] The historical time series signals in this application are signal samples with normal signal segments and abnormal signal segments marked.
[0077] The window has a fixed length and is a way to evenly slice the signal data. This application uses a rolling time window with a fixed window length. The time series signal is stored in the window object, and the previous window object is discarded after each rolling.
[0078] According to a fixed window length, the historical time series signal is divided into multiple signal subsequences in sequence as window samples.
[0079] S102 : Extract a first abnormal window sample where the abnormal signal is located, and extract a normal window sample preceding the first abnormal window sample as a first normal window sample.
[0080] The abnormal window sample is the signal subsequence containing the abnormal signal. The normal window sample is the signal subsequence without the abnormal signal. The first abnormal window sample is the signal subsequence containing the abnormal signal, and the first normal window sample is the normal window sample immediately preceding the first abnormal window sample.
[0081] In actual industrial environments, abnormal situations occur very rarely, so the number of extracted abnormal signals is sparse, and therefore the number of extracted first abnormal window samples is also small.
[0082] In this application, the previous normal window sample of the first abnormal window sample is used as the first normal window sample. If the previous window sample of the first abnormal window sample is an abnormal window sample, the extraction continues until the first normal window sample is found.
[0083] S103 : Extract a second normal window sample having a similar distribution to the first normal window sample from the remaining normal window samples, and extract an abnormal window sample preceding the second normal window sample as a second abnormal window sample.
[0084] The second normal window sample is a signal subsequence with a similar feature distribution to the first normal window sample, and the second abnormal window sample is an abnormal window sample preceding the second normal window sample.
[0085] A second normal window sample with a similar distribution to the first normal window sample is extracted from the remaining normal window samples, and then a second abnormal window sample is found based on the second normal window sample, so that the training sample data can be expanded and the training accuracy can be improved without increasing the additional data collection cost.
[0086] In one embodiment, extracting a second normal signal window having a distribution similar to that of the first normal signal window from the remaining normal signal windows comprises the following steps:
[0087] Determine, from the signal window samples, remaining normal window samples except the first normal window samples;
[0088] Using a feature encoder to extract a first window feature vector of the first normal window sample and a second window feature vector of the remaining normal window samples;
[0089] Based on the first window feature vector and the second window feature vector, performing feature matching on the remaining normal window samples and the first normal window samples to obtain a matching result;
[0090] According to the matching result, second normal window samples having a distribution similar to that of the first normal window samples are determined from the signal window samples.
[0091] The first window feature vector is a feature vector corresponding to the first normal window sample, and the second window feature vector is a feature vector corresponding to the second normal window sample.
[0092] In one embodiment, before extracting the first window feature vector of the first normal window sample and the second window feature vectors of the remaining normal window samples using a feature encoder, the following steps are further included:
[0093] Acquire a historical time series signal, and divide the historical time series signal into a plurality of signal subsequences as window samples according to a preset fixed window length;
[0094] Extracting a window where a normal signal is located from the window samples as an initial training sample;
[0095] The feature encoder is obtained by training based on the initial training sample.
[0096] Among them, the feature encoder of this application adopts the TS2Vec pre-training method to train the normal sample feature encoder. The weights do not participate in the training and are only used for feature extraction. The feature encoder adopts an encoder and decoder structure. Because normal window signals account for the vast majority in actual scenarios and the amount of data is very sufficient, the feature encoder pre-trained with normal samples is more effective and conducive to matching between features. The encoder consists of three components: an input projection layer, a timestamp masking module, and a dilated convolution layer. For each sample, the input projection layer is actually a fully connected layer, and its function is to map the signal at timestamp t into a high-dimensional latent vector. The timestamp masking module randomly masks the high-dimensional latent vector to generate an enhanced context view. The dilated convolution layer has 10 residual blocks, each of which contains 2 1-D convolution layers to extract the temporal context representation between the signal fields of each timestamp.
[0097] In a specific embodiment, the performing feature matching on the remaining normal window samples and the first normal window sample based on the first window feature vector and the second window feature vector includes the following steps:
[0098] Calculating the cosine similarity between the first window feature vector and the second window feature vector;
[0099] When the cosine similarity is higher than a preset threshold, the corresponding remaining normal window samples are determined as second normal window samples having a distribution similar to that of the first normal window samples.
[0100] S104: Concatenate the first normal window sample and the first abnormal window sample to obtain a first normal-abnormal sample pair, and concatenate the second normal window sample and the second abnormal window sample to obtain a second normal-abnormal sample pair.
[0101] The above operations not only increase the number of normal and abnormal sample pairs, but also ensure that the number of normal samples and abnormal samples is consistent, thus ensuring the balance between the data.
[0102] S105 : Use the first normal-abnormal sample pair and the second normal-abnormal sample pair to train a classifier model to obtain a trained classifier model.
[0103] In one embodiment, training a classifier model using the first normal-abnormal sample pair and the second normal-abnormal sample pair to obtain a trained classifier model includes the following steps:
[0104] A preset feature extraction model is used to respectively extract a first normal sample feature vector and a first abnormal sample feature vector corresponding to the first normal-abnormal sample pair, and a second normal sample feature vector and a second abnormal sample feature vector corresponding to the second normal-abnormal sample pair;
[0105] Inputting the first normal sample feature vector and the first abnormal sample feature vector into a preset classifier model for classification to obtain a first predicted sample category;
[0106] Inputting the second normal sample feature vector and the second abnormal sample feature vector into a preset classifier model for classification to obtain a second predicted sample category;
[0107] Based on the first predicted sample category and the first normal-abnormal sample pair, and the second predicted sample category and the second normal-abnormal sample pair, the preset classifier model and the preset feature extraction model are converged to obtain the trained classifier model and the trained feature extraction model.
[0108] The feature extraction model can use two transformer structure models with shared parameters to extract the features of the first normal-abnormal sample pair and the second normal-abnormal sample pair, respectively, and specifically includes the following steps:
[0109] A preset first feature extraction model is used to respectively extract a first normal sample feature vector and a first abnormal sample feature vector corresponding to the first normal-abnormal sample pair;
[0110] A preset second feature extraction model is used to respectively extract a second normal sample feature vector and a second abnormal sample feature vector corresponding to the second normal-abnormal sample pair, and the first feature extraction model and the second feature extraction model share model parameters.
[0111] When the feature extraction model inputs the first normal-abnormal sample pair, it extracts the first normal sample features corresponding to the first normal window sample, and the first abnormal window sample features corresponding to the first abnormal window sample. When the model inputs the second normal-abnormal sample pair, it extracts the feature vector corresponding to the second normal window sample, and the second abnormal sample feature vector corresponding to the second abnormal window sample.
[0112] The transformer structure model includes an encoding module and a decoding module. This application uses the encoding module for feature extraction. There can be multiple encoding modules and decoding modules, or one each. Multiple encoding modules with the same structure are stacked, and the input of each encoding module is the output of the next encoding module.
[0113] Before entering the lowest-level encoding module, the feature extraction model also includes a word embedding encoding layer and a position encoding layer to map the input sample pairs into feature matrices.
[0114] Among them, position encoding can be implemented using the following formula:
[0115] PE(pos,2i)=sin(pos / 100002i / d)
[0116] PE(pos,2i+1)=sin(pos / 100002i / d)
[0117] Among them, pos represents the signal field at a certain position, and i represents the i-th dimension.
[0118] In one embodiment, each encoding module includes a self-attention layer and a position-based fully connected feedforward neural network layer. Specifically, as follows:
[0119] Self-attention layer: The understanding of all relevant timings can be integrated into the sample pair currently being processed through convolution operations, with the aim of learning the temporal dependencies of the sample window and capturing the internal structure of the sample window. Specifically, the weight matrix whose parameters are not shared can be first multiplied with the feature matrix to obtain three matrices, which can be denoted as q, k and v respectively. In one embodiment, the similarity of two of the matrices (such as q and k) can be used to represent the weight of another matrix (such as v). The weight represents the degree of correlation and importance between the current signal field and other signal fields. The weight can be multiplied by another matrix to obtain the local feature information of each signal field. Among them, commonly used similarity functions include dot product, splicing, perceptron, etc. When the preset feature extraction model is trained for the first time, the weight matrix is randomly generated, and multiple trainings can optimize the weight matrix.
[0120] Position fully connected feedforward neural network layer: The position fully connected feedforward neural network can include multiple, specifically, the number is the same as the number of signal fields, and each feedforward neural network processes a local feature matrix. Each node of the position fully connected feedforward neural network layer is connected to all nodes output by the previous layer (such as the self-attention layer), wherein a node of the position fully connected feedforward neural network layer is called a neuron in the position fully connected feedforward neural network layer, and the number of neurons in the position fully connected feedforward neural network layer can be determined according to the needs of the actual application. Each feedforward neural network includes at least two layers of linear activation functions. In order to improve the expressive power of the model, a layer of activation function can be added to add nonlinear factors. In an embodiment of the present invention, the activation function is "relu (rectified linear unit)". If the output of the self-attention layer is represented by Z and the output of the word embedding coding layer is represented by x, then the processing of the position fully connected feedforward neural network is expressed by the formula:
[0121] FFN(x)=max(0,xW1+b1)W2+b2
[0122] Where b1 and b2 represent the biases, and W1 and W2 represent the weight matrices. The values of b1, b2, W1, and W2 can be adjusted over multiple training sessions to enable the encoding module to more accurately extract features from sample pairs.
[0123] In one embodiment, based on the first predicted sample category and the first normal-abnormal sample pair, and the second predicted sample category and the second normal-abnormal sample pair, converging the preset classifier model to obtain a trained classifier model includes the following steps:
[0124] Calculate a loss function based on the first predicted sample category and the second predicted sample category to obtain a model loss value;
[0125] Updating the parameters of the classifier model and the feature extraction model based on the back propagation algorithm according to the model loss value;
[0126] When the model loss value no longer decreases, the current classifier model and the feature extraction model are used as the trained classifier model and the trained feature extraction model.
[0127] Among them, back propagation algorithm Back propagation (BP, back propagation) is the abbreviation of "error back propagation". It is a common method used in combination with optimization methods (such as gradient descent method) to train artificial neural networks.
[0128] Its basic idea is:
[0129] (1) First calculate the state and activation value of each layer until the last layer (i.e. the signal is forward propagated);
[0130] (2) Calculate the error of each layer. The error calculation process is carried forward from the last layer (that is, the error is back-propagated);
[0131] (3) Calculate the gradient of each neuron connection weight;
[0132] (4) Update the parameters according to the gradient descent rule (the goal is to reduce the error).
[0133] Iterate the above steps until the stopping criterion is met.
[0134] Among them, the classifier model can adopt a support vector machine model. Support vector machines (SVM) are a two-classification model, and its basic model is a linear classifier with the largest interval defined in the feature space.
[0135] The learning strategy of SVM is to maximize the margin, which can be formalized as a problem of solving convex quadratic programming, which is equivalent to minimizing the regularized hinge loss function.
[0136] In one embodiment, calculating the loss function according to the first predicted sample category and the second predicted sample category to obtain the model loss value includes the following steps:
[0137] According to the first predicted sample category and the second predicted sample category, statistically predicting the number of normal samples and the number of predicted abnormal samples;
[0138] Calculating a prediction ratio according to the number of predicted normal samples and the number of predicted abnormal samples;
[0139] According to the first predicted sample category and the corresponding first normal-abnormal sample pair, and the second predicted sample category and the corresponding second normal-abnormal sample pair, substituting them into the loss function to calculate a category loss value;
[0140] A model loss value is determined according to the predicted ratio and the category loss value.
[0141] In order to make the constructed second normal-anomaly sample pair consistent with the true first normal-anomaly sample pair classification logits, we impose an L1 constraint on the logits between the two to ensure that the probability of belonging to a normal sample is consistent and the probability of belonging to an abnormal sample is consistent.
[0142] Specifically, it can be expressed by the following formula:
[0143] logits_match = SVM (second normal sample feature vector, second abnormal sample feature vector)
[0144] logits_true=SVM(first normal sample feature vector, first abnormal sample feature vector)
[0145] L1_loss=|logits_match,logits_true|
[0146] In deep learning, logits are the output of the final fully connected layer. Usually, in a neural network, logits are generated first, and then the probability of belonging to a certain category is obtained through the sigmoid function or softmax function.
[0147] Since the samples in this application are in the form of normal-abnormal sample pairs, when the prediction is correct, the number of predicted normal samples is equal to the number of predicted abnormal samples. This application calculates the ratio of predicted normal samples to predicted abnormal samples to obtain the predicted ratio, and further calculates the category loss value based on the predicted ratio to obtain the model loss value.
[0148] In one embodiment, since the first feature extraction model and the second feature extraction model share parameters, updating the parameters of the feature extraction model based on the back propagation algorithm according to the model loss value may include the following steps:
[0149] updating the parameters of the first feature extraction model based on the back propagation algorithm according to the model loss value;
[0150] The parameters of the second feature extraction model are updated according to the parameters of the first feature extraction model.
[0151] Only back propagation is used to calculate the parameters of the first feature extraction model, and the parameters of the second feature extraction model are kept consistent with the parameters of the first feature extraction model, which can reduce the complexity of model training.
[0152] S106 , using the trained classifier model to detect the time series signal to be detected.
[0153] The method of using normal and abnormal samples to train the model provided in this embodiment is applied to abnormal time series detection and can also be extended to other fields such as time series prediction, time series completion and other scenarios. For the specific steps of time series detection, please refer to the next embodiment and Figure 3 Description.
[0154] As can be seen from the above, this embodiment can obtain a historical time series signal, and divide the historical time series signal into multiple signal subsequences as window samples according to a preset fixed window length; extract the first abnormal window sample where the abnormal signal is located, and extract the normal window sample before the first abnormal window sample as the first normal window sample; extract a second normal window sample with a similar distribution to the first normal window sample from the remaining normal window samples, and extract the abnormal window sample before the second normal window sample as the second abnormal window sample; splice the first normal window sample with the first abnormal window sample to obtain a first normal-abnormal sample pair, and splice the second normal window sample with the second abnormal window sample to obtain a second normal-abnormal sample pair; use the first normal-abnormal sample pair and the second normal-abnormal sample pair to train a classifier model to obtain a trained classifier model; use the trained classifier model to detect the time series signal to be detected. This application learns the feature distribution of the first normal window sample before the sparse first abnormal window sample window, and extracts the second normal window sample with a distribution similar to the first normal window sample based on feature matching, and then determines the second abnormal window sample. Because the number of normal samples is large, the matching accuracy is high. This method can expand the number of samples without increasing the cost of additional data collection. In addition, this application uses the form of normal-abnormal sample pairs to train the model, which can ensure the balance of normal-abnormal sample data. This improves the training effect of the anomaly detection model and improves the anomaly detection effect without increasing the cost of additional data collection.
[0155] According to the method described in the previous embodiment, the following will be further described in detail by taking the abnormal timing detection device as an example of being specifically integrated into a terminal device. The embodiment of the present application provides an abnormal timing detection method, such as Figure 3 As shown, the specific process of the abnormal timing detection method can be as follows:
[0156] 201. Acquire a time series signal to be detected, and divide the time series signal to be detected into multiple signal subsequences as windows to be detected according to a preset fixed window length.
[0157] 202. The terminal uses the trained feature extraction model to extract the feature vector to be detected of the window to be detected.
[0158] 203. The terminal inputs the feature vector to be detected into the trained classifier model for detection, and outputs the abnormal sample category or the normal sample category corresponding to the window to be detected.
[0159] Since the present application learns the feature distribution of the first normal window sample before the sparse first abnormal window sample window, and extracts the second normal window sample with a distribution similar to the first normal window sample based on feature matching, and then determines the second abnormal window sample, because the number of normal samples is large, the matching accuracy is high. This method can expand the number of samples without increasing the cost of additional data collection. In addition, the present application uses the form of normal-abnormal sample pairs to train the model, which can ensure the balance of normal-abnormal sample data. This improves the training effect of the anomaly detection model and improves the anomaly detection effect without increasing the cost of additional data collection.
[0160] In order to better implement the above method, the embodiment of the present application also provides an abnormal timing detection device, such as Figure 4 As shown, the abnormal time series detection device may include a segmentation unit 301, an extraction unit 302, a matching unit 303, an amplification unit 304, a training unit 305, and a detection unit 306, as follows:
[0161] The segmentation unit 301 is configured to obtain a historical time series signal and segment the historical time series signal into a plurality of signal subsequences as window samples according to a preset fixed window length;
[0162] An extraction unit 302 is configured to extract a first abnormal window sample where the abnormal signal is located, and extract a normal window sample preceding the first abnormal window sample as a first normal window sample;
[0163] The matching unit 303 is configured to extract a second normal window sample having a similar distribution to the first normal window sample from the remaining normal window samples, and extract an abnormal window sample preceding the second normal window sample as a second abnormal window sample;
[0164] an amplification unit 304, configured to concatenate the first normal window sample with the first abnormal window sample to obtain a first normal-abnormal sample pair, and concatenate the second normal window sample with the second abnormal window sample to obtain a second normal-abnormal sample pair;
[0165] A training unit 305 is configured to train a classifier model using the first normal-abnormal sample pair and the second normal-abnormal sample pair to obtain a trained classifier model;
[0166] The detection unit 306 is configured to detect the time series signal to be detected using the trained classifier model.
[0167] Optionally, in some embodiments of the present application, the matching unit may include a selection subunit, a first extraction subunit, a matching subunit, and a determination subunit, as follows:
[0168] A selection subunit, configured to determine, from the signal window samples, remaining normal window samples except the first normal window samples;
[0169] a first extraction subunit, configured to extract a first window feature vector of the first normal window sample and a second window feature vector of the remaining normal window samples using a feature encoder;
[0170] a matching subunit, configured to perform feature matching on the remaining normal window samples and the first normal window sample based on the first window feature vector and the second window feature vector, to obtain a matching result;
[0171] The determination subunit is configured to determine, from the signal window samples, second normal window samples whose distribution is similar to that of the first normal window samples according to the matching result.
[0172] Optionally, in some embodiments of the present application, the training unit may further include a second extraction subunit, a classification subunit, and a training subunit, as follows:
[0173] A second extraction subunit is configured to respectively extract a first normal sample feature vector and a first abnormal sample feature vector corresponding to the first normal-abnormal sample pair, and a second normal sample feature vector and a second abnormal sample feature vector corresponding to the second normal-abnormal sample pair using a preset feature extraction model;
[0174] A classification subunit, configured to input the first normal sample feature vector and the first abnormal sample feature vector into a preset classifier model for classification to obtain a first predicted sample category;
[0175] A training subunit is used to converge the preset classifier model and the preset feature extraction model based on the first predicted sample category and the first normal-abnormal sample pair, and the second predicted sample category and the second normal-abnormal sample pair, to obtain the trained classifier model and the trained feature extraction model.
[0176] Optionally, in some embodiments of the present application, the detection unit includes a subunit, a third feature extraction subunit, and an output subunit, as follows:
[0177] an acquisition subunit, configured to acquire a time series signal to be detected, and divide the time series signal to be detected into a plurality of signal subsequences as windows to be detected according to a preset fixed window length;
[0178] A third extraction subunit is used to extract the feature vector to be detected of the window to be detected by using the trained feature extraction model;
[0179] The output subunit is used to input the feature vector to be detected into the trained classifier model for detection, and output the abnormal sample category or normal sample category corresponding to the window to be detected.
[0180] As can be seen from the above, this embodiment can obtain a historical time series signal through the segmentation unit 301, and divide the historical time series signal into multiple signal subsequences as window samples according to a preset fixed window length; extract the first abnormal window sample where the abnormal signal is located through the extraction unit 302, and extract the normal window sample before the first abnormal window sample as the first normal window sample; extract the second normal window sample with a similar distribution to the first normal window sample from the remaining normal window samples through the matching unit 303, and extract the abnormal window sample before the second normal window sample as the second abnormal window sample; through the amplification unit 304, it is used to splice the first normal window sample with the first abnormal window sample to obtain a first normal-abnormal sample pair, and splice the second normal window sample with the second abnormal window sample to obtain a second normal-abnormal sample pair; through the training unit 305, it is used to use the first normal-abnormal sample pair and the second normal-abnormal sample pair to train a classifier model to obtain a trained classifier model; through the detection unit 306, it is used to use the trained classifier model to detect the time series signal to be detected. This application learns the feature distribution of the first normal window sample before the sparse first abnormal window sample window, and extracts the second normal window sample with a distribution similar to the first normal window sample based on feature matching, and then determines the second abnormal window sample. Because the number of normal samples is large, the matching accuracy is high. This method can expand the number of samples without increasing the cost of additional data collection. In addition, this application uses the form of normal-abnormal sample pairs to train the model, which can ensure the balance of normal-abnormal sample data. This improves the training effect of the anomaly detection model and improves the anomaly detection effect without increasing the cost of additional data collection.
[0181] The present application also provides an electronic device, such as Figure 5 , which shows a schematic diagram of the structure of an electronic device involved in an embodiment of the present application. The electronic device may be a terminal or a server, etc. Specifically:
[0182] The electronic device may include one or more processing core processors 401, one or more computer-readable storage media memories 402, a power supply 403, an input unit 404 and other components. Those skilled in the art will understand that Figure 5 The electronic device structure shown in the figure does not constitute a limitation of the electronic device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange components differently.
[0183] Processor 401 is the control center of the electronic device. It connects all parts of the electronic device using various interfaces and circuits. It performs various functions of the electronic device and processes data by running or executing software programs and / or modules stored in memory 402 and accessing data stored in memory 402. Optionally, processor 401 may include one or more processing cores. Preferably, processor 401 may integrate an application processor and a modem processor. The application processor primarily handles the operating system, user interface, and application programs, while the modem processor primarily handles wireless communications. It is understood that the modem processor may not be integrated into processor 401.
[0184] The memory 402 can be used to store software programs and modules. The processor 401 executes various functional applications and data processing by running the software programs and modules stored in the memory 402. The memory 402 may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc.; the data storage area may store data created according to the use of the electronic device, etc. In addition, the memory 402 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage device. Accordingly, the memory 402 may also include a memory controller to provide the processor 401 with access to the memory 402.
[0185] The electronic device also includes a power supply 403 for supplying power to various components. Preferably, the power supply 403 can be logically connected to the processor 401 via a power management system, thereby enabling the power management system to manage charging, discharging, and power consumption. The power supply 403 can also include one or more DC or AC power supplies, a recharging system, a power failure detection circuit, a power converter or inverter, a power status indicator, and other arbitrary components.
[0186] The electronic device may further include an input unit 404, which may be configured to receive input digital or character information and generate keyboard, mouse, joystick, optical or trackball signal inputs related to user settings and function control.
[0187] Although not shown, the electronic device may further include a display unit, etc., which will not be described in detail here. Specifically, in this embodiment, the processor 401 in the electronic device will load the executable files corresponding to the processes of one or more application programs into the memory 402 according to the following instructions, and the processor 401 will run the application programs stored in the memory 402 to implement various functions as follows:
[0188] An embodiment of the present application provides an abnormal time series detection method and related equipment, which can obtain a historical time series signal and divide the historical time series signal into multiple signal subsequences as window samples according to a preset fixed window length; extract a first abnormal window sample where the abnormal signal is located, and extract a normal window sample before the first abnormal window sample as the first normal window sample; extract a second normal window sample with a similar distribution to the first normal window sample from the remaining normal window samples, and extract an abnormal window sample before the second normal window sample as the second abnormal window sample; splice the first normal window sample with the first abnormal window sample to obtain a first normal-abnormal sample pair, and splice the second normal window sample with the second abnormal window sample to obtain a second normal-abnormal sample pair; use the first normal-abnormal sample pair and the second normal-abnormal sample pair to train a classifier model to obtain a trained classifier model; and use the trained classifier model to detect the time series signal to be detected. This application learns the feature distribution of the first normal window sample before the sparse first abnormal window sample window, and extracts the second normal window sample with a distribution similar to the first normal window sample based on feature matching, and then determines the second abnormal window sample. Because the number of normal samples is large, the matching accuracy is high. This method can expand the number of samples without increasing the cost of additional data collection. In addition, this application uses the form of normal-abnormal sample pairs to train the model, which can ensure the balance of normal-abnormal sample data. This improves the training effect of the anomaly detection model and improves the anomaly detection effect without increasing the cost of additional data collection.
[0189] The specific implementation of the above operations can be found in the previous embodiments and will not be repeated here.
[0190] As can be seen from the above, this embodiment can obtain a historical time series signal, and divide the historical time series signal into multiple signal subsequences as window samples according to a preset fixed window length; extract the first abnormal window sample where the abnormal signal is located, and extract the normal window sample before the first abnormal window sample as the first normal window sample; extract a second normal window sample with a similar distribution to the first normal window sample from the remaining normal window samples, and extract the abnormal window sample before the second normal window sample as the second abnormal window sample; splice the first normal window sample with the first abnormal window sample to obtain a first normal-abnormal sample pair, and splice the second normal window sample with the second abnormal window sample to obtain a second normal-abnormal sample pair; use the first normal-abnormal sample pair and the second normal-abnormal sample pair to train a classifier model to obtain a trained classifier model; use the trained classifier model to detect the time series signal to be detected. This application learns the feature distribution of the first normal window sample before the sparse first abnormal window sample window, and extracts the second normal window sample with a distribution similar to the first normal window sample based on feature matching, and then determines the second abnormal window sample. Because the number of normal samples is large, the matching accuracy is high. This method can expand the number of samples without increasing the cost of additional data collection. In addition, this application uses the form of normal-abnormal sample pairs to train the model, which can ensure the balance of normal-abnormal sample data. This improves the training effect of the anomaly detection model and improves the anomaly detection effect without increasing the cost of additional data collection.
[0191] Those skilled in the art will appreciate that all or part of the steps in the various methods of the above embodiments may be accomplished by instructions, or by controlling related hardware through instructions. The instructions may be stored in a computer-readable storage medium and loaded and executed by a processor.
[0192] To this end, an embodiment of the present application provides a computer-readable storage medium storing a plurality of instructions that can be loaded by a processor to execute the steps of any of the abnormal timing detection methods provided in the embodiments of the present application. For example, the instructions can execute the following steps:
[0193] An embodiment of the present application provides an abnormal time series detection method and related equipment, which can obtain a historical time series signal and divide the historical time series signal into multiple signal subsequences as window samples according to a preset fixed window length; extract a first abnormal window sample where the abnormal signal is located, and extract a normal window sample before the first abnormal window sample as the first normal window sample; extract a second normal window sample with a similar distribution to the first normal window sample from the remaining normal window samples, and extract an abnormal window sample before the second normal window sample as the second abnormal window sample; splice the first normal window sample with the first abnormal window sample to obtain a first normal-abnormal sample pair, and splice the second normal window sample with the second abnormal window sample to obtain a second normal-abnormal sample pair; use the first normal-abnormal sample pair and the second normal-abnormal sample pair to train a classifier model to obtain a trained classifier model; and use the trained classifier model to detect the time series signal to be detected. This application learns the feature distribution of the first normal window sample before the sparse first abnormal window sample window, and extracts the second normal window sample with a distribution similar to the first normal window sample based on feature matching, and then determines the second abnormal window sample. Because the number of normal samples is large, the matching accuracy is high. This method can expand the number of samples without increasing the cost of additional data collection. In addition, this application uses the form of normal-abnormal sample pairs to train the model, which can ensure the balance of normal-abnormal sample data. This improves the training effect of the anomaly detection model and improves the anomaly detection effect without increasing the cost of additional data collection.
[0194] The specific implementation of the above operations can be found in the previous embodiments and will not be repeated here.
[0195] The computer-readable storage medium may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0196] Since the instructions stored in the computer-readable storage medium can execute the steps in any of the abnormal timing detection methods provided in the embodiments of the present application, the beneficial effects that can be achieved by any of the abnormal timing detection methods provided in the embodiments of the present application can be achieved. Please refer to the previous embodiments for details and will not be repeated here.
[0197] According to one aspect of the present application, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods provided in various optional implementations of the aforementioned abnormal timing detection.
[0198] The above is a detailed introduction to an abnormal timing detection method and related equipment provided in an embodiment of the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for technical personnel in this field, based on the ideas of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A method for detecting abnormal timing, characterized in that: include: Acquire a historical time series signal, and divide the historical time series signal into a plurality of signal subsequences as window samples according to a preset fixed window length; Extracting a first abnormal window sample where the abnormal signal is located, and extracting a normal window sample preceding the first abnormal window sample as a first normal window sample; Extracting a second normal window sample with a similar distribution to the first normal window sample from the remaining normal window samples, and extracting an abnormal window sample preceding the second normal window sample as a second abnormal window sample; Splicing the first normal window sample with the first abnormal window sample to obtain a first normal-abnormal sample pair, and splicing the second normal window sample with the second abnormal window sample to obtain a second normal-abnormal sample pair; Using the first normal-abnormal sample pair and the second normal-abnormal sample pair to train a classifier model to obtain a trained classifier model; The trained classifier model is used to detect the time series signal to be detected.
2. The abnormal time sequence detection method according to claim 1, characterized in that: The step of extracting a second normal signal window having a similar distribution to the first normal signal window from the remaining normal signal windows comprises: Determine, from the signal window samples, remaining normal window samples except the first normal window samples; Using a feature encoder to extract a first window feature vector of the first normal window sample and a second window feature vector of the remaining normal window samples; Based on the first window feature vector and the second window feature vector, performing feature matching on the remaining normal window samples and the first normal window samples to obtain a matching result; According to the matching result, second normal window samples having a distribution similar to that of the first normal window samples are determined from the signal window samples.
3. The abnormal time sequence detection method according to claim 2, characterized in that: The performing feature matching on the remaining normal window samples and the first normal window samples based on the first window feature vector and the second window feature vector includes: Calculating the cosine similarity between the first window feature vector and the second window feature vector; When the cosine similarity is higher than a preset threshold, the corresponding remaining normal window samples are determined as second normal window samples having a distribution similar to that of the first normal window samples.
4. The abnormal time sequence detection method according to claim 2, characterized in that: Before extracting the first window feature vector of the first normal window sample and the second window feature vectors of the remaining normal window samples using the feature encoder, the method further includes: Acquire a historical time series signal, and divide the historical time series signal into a plurality of signal subsequences as window samples according to a preset fixed window length; Extracting a window where a normal signal is located from the window samples as an initial training sample; The feature encoder is obtained by training based on the initial training sample.
5. The abnormal time sequence detection method according to claim 1, characterized in that: Using the first normal-abnormal sample pair and the second normal-abnormal sample pair to train a classifier model to obtain a trained classifier model, comprising: A preset feature extraction model is used to respectively extract a first normal sample feature vector and a first abnormal sample feature vector corresponding to the first normal-abnormal sample pair, and a second normal sample feature vector and a second abnormal sample feature vector corresponding to the second normal-abnormal sample pair; Inputting the first normal sample feature vector and the first abnormal sample feature vector into a preset classifier model for classification to obtain a first predicted sample category; Inputting the second normal sample feature vector and the second abnormal sample feature vector into a preset classifier model for classification to obtain a second predicted sample category; Based on the first predicted sample category and the first normal-abnormal sample pair, and the second predicted sample category and the second normal-abnormal sample pair, the preset classifier model and the preset feature extraction model are converged to obtain the trained classifier model and the trained feature extraction model.
6. The abnormal time sequence detection method according to claim 5, characterized in that: The method of using a preset feature extraction model to extract a first normal sample feature vector and a first abnormal sample feature vector corresponding to the first normal-abnormal sample pair, and a second normal sample feature vector and a second abnormal sample feature vector corresponding to the second normal-abnormal sample pair, includes: A preset first feature extraction model is used to respectively extract a first normal sample feature vector and a first abnormal sample feature vector corresponding to the first normal-abnormal sample pair; A preset second feature extraction model is used to respectively extract a second normal sample feature vector and a second abnormal sample feature vector corresponding to the second normal-abnormal sample pair, and the first feature extraction model and the second feature extraction model share model parameters.
7. The abnormal time sequence detection method according to claim 6, characterized in that: Based on the first predicted sample category and the first normal-abnormal sample pair, and the second predicted sample category and the second normal-abnormal sample pair, the preset classifier model is converged to obtain a trained classifier model, including: Calculate a loss function based on the first predicted sample category and the second predicted sample category to obtain a model loss value; Updating the parameters of the classifier model and the feature extraction model based on the back propagation algorithm according to the model loss value; When the model loss value no longer decreases, the current classifier model and the feature extraction model are used as the trained classifier model and the trained feature extraction model.
8. The abnormal time sequence detection method according to claim 7, characterized in that: The calculating a loss function according to the first predicted sample category and the second predicted sample category to obtain a model loss value includes: According to the first predicted sample category and the second predicted sample category, statistically predicting the number of normal samples and the number of predicted abnormal samples; Calculating a prediction ratio according to the number of predicted normal samples and the number of predicted abnormal samples; According to the first predicted sample category and the corresponding first normal-abnormal sample pair, and the second predicted sample category and the corresponding second normal-abnormal sample pair, substituting them into the loss function to calculate a category loss value; A model loss value is determined according to the predicted ratio and the category loss value.
9. The abnormal time sequence detection method according to claim 7, characterized in that: The updating of parameters of the classifier model and the feature extraction model based on the back propagation algorithm according to the model loss value includes: updating the parameters of the first feature extraction model based on the back propagation algorithm according to the model loss value; The parameters of the second feature extraction model are updated according to the parameters of the first feature extraction model.
10. The abnormal time sequence detection method according to claim 1, characterized in that: The trained classifier model is used to detect the time series signal to be detected, including: Acquire a time series signal to be detected, and divide the time series signal to be detected into a plurality of signal subsequences as windows to be detected according to a preset fixed window length; Extracting the feature vector to be detected of the window to be detected using the trained feature extraction model; The feature vector to be detected is input into the trained classifier model for detection, and the abnormal sample category or normal sample category corresponding to the window to be detected is output.
11. An abnormal timing detection device, characterized in that: include: a segmentation unit, configured to obtain a historical time series signal and segment the historical time series signal into a plurality of signal subsequences as window samples according to a preset fixed window length; an extraction unit, configured to extract a first abnormal window sample where the abnormal signal is located, and extract a normal window sample preceding the first abnormal window sample as a first normal window sample; a matching unit, configured to extract a second normal window sample having a similar distribution to the first normal window sample from the remaining normal window samples, and extract an abnormal window sample preceding the second normal window sample as a second abnormal window sample; an amplification unit, configured to concatenate the first normal window sample with the first abnormal window sample to obtain a first normal-abnormal sample pair, and concatenate the second normal window sample with the second abnormal window sample to obtain a second normal-abnormal sample pair; a training unit, configured to train a classifier model using the first normal-abnormal sample pair and the second normal-abnormal sample pair to obtain a trained classifier model; The detection unit is used to detect the time series signal to be detected using the trained classifier model.
12. An electronic device, characterized in that: It comprises a memory and a processor; the memory stores an application program, and the processor is used to run the application program in the memory to perform the operations in the abnormal timing detection method according to any one of claims 1 to 10.
13. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor to execute the steps in the abnormal timing detection method according to any one of claims 1 to 10.
14. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the steps of the abnormal timing detection method according to any one of claims 1 to 10 are implemented.