Abnormality detection method and device for time series data, electronic equipment and computer program product
By sliding a window on a time-series data queue and combining short-term and long-term trend analysis, anomaly warning information is generated, which solves the problem of low accuracy of anomaly detection results in existing technologies and achieves more accurate anomaly detection.
Patent Information
- Application Number
- CN202510874649.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-10-28
AI Technical Summary
Existing technologies that use trend detection to obtain anomaly detection results have low accuracy and a high number of false alarms.
By employing a sliding window technique to slide across a time-series data queue and combining short-term and long-term trend analysis, abnormal early warning information is generated.
By combining short-term and long-term trend analysis, the accuracy of anomaly detection results is improved, avoiding false alarms or missed alarms.
Smart Images

Figure CN120850140A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing, and more specifically, to a method, apparatus, electronic device, and computer program product for detecting anomalies in time-series data. Background Technology
[0002] Anomaly detection is a crucial task in modern data analytics and monitoring systems. It is widely used in fields such as financial market analysis, network intrusion detection, production process monitoring, and medical diagnosis. The purpose of anomaly detection is to identify anomalous patterns or events from massive amounts of data, which may indicate potential problems, attacks, or significant changes.
[0003] Among the existing algorithms for anomaly detection, there are few trend-related algorithms, and most of them are based on a single trend. However, the accuracy of anomaly detection results obtained by existing technologies through trend detection is not high enough, and there are many false alarms.
[0004] There is currently no effective solution to the problem of low accuracy in anomaly detection results obtained by trend detection in the existing technologies mentioned above. Summary of the Invention
[0005] This invention provides a method, apparatus, electronic device, and computer program product for anomaly detection of time-series data, to at least solve the technical problem of low accuracy of anomaly detection results obtained by trend detection in the prior art.
[0006] According to one aspect of the present invention, an anomaly detection method for time series data is provided, comprising: acquiring a time series queue to be analyzed comprising a plurality of time series data to be analyzed, wherein the time series data to be analyzed comprises at least: real-time monitoring data and a plurality of historical monitoring data; sliding a preset sliding window on the time series queue to be analyzed to obtain window data corresponding to the preset sliding window after each sliding, wherein the window data is the average value of the time series data to be analyzed within the preset sliding window; detecting a short-term trend of the window data based on a plurality of window data in a first window sequence, wherein the first window sequence comprises: a first number of window data, and the first window sequence comprises at least: window data determined based on the preset sliding window covering the real-time monitoring data, the short-term trend being used to at least represent the first window sequence. The system detects whether multiple window data points in the first window sequence show a trend change; if the short-term trend indicates a trend change in multiple window data points in the first window sequence, it detects the long-term trend of the window data points based on multiple window data points in the second window sequence, wherein the second window sequence includes: a second number of window data points, the second number being greater than the first number, and the second window sequence includes at least: window data points determined based on a preset sliding window covering the real-time monitoring data, and window data points determined based on a preset sliding window covering the historical monitoring data, the long-term trend being used at least to indicate whether multiple window data points in the second window sequence show a trend change; if the long-term trend indicates a trend change in multiple window data points in the second window sequence, it generates an abnormal warning message.
[0007] Optionally, the method further includes: updating the time series queue to be analyzed according to time changes when the short-term trend indicates that no trend change has occurred in the multiple window data in the first window sequence.
[0008] Optionally, the process of using a preset sliding window to slide on the time series queue to obtain window data corresponding to the preset sliding window after each slide includes: determining the preset sliding window that meets a preset time span; sliding the preset sliding window in order from the first to the last position of the time series queue to obtain multiple window data, wherein the multiple time series data to be analyzed in the time series queue are arranged in chronological order, and the real-time monitoring data is arranged at the first position of the time series queue to be analyzed; sorting the multiple window data according to the position of the preset sliding window that determines the window data on the time series queue to obtain a candidate window sequence, wherein the position of the preset sliding window on the time series queue to be analyzed is positively correlated with the position of the generated window data in the candidate window sequence; and truncating the window sequence to be analyzed according to a preset number, starting from the first position of the candidate window sequence, wherein the preset number includes a first number and a second number, and the window sequence to be analyzed includes a first window sequence truncated according to the first number and a second window sequence truncated according to the second number.
[0009] Optionally, sliding the preset sliding window in the order from the first to the last position of the time series queue to obtain multiple window data includes: determining the preset sliding window after each movement on the time series queue as a candidate sliding window; calculating the average value of the multiple time series data covered by the candidate sliding window to obtain the average value of the window data corresponding to the candidate sliding window; allocating window data time to the average value of the window data based on the data time of the multiple time series data covered by the candidate sliding window; and determining the window data corresponding to the candidate sliding window based on the average value of the window data and the window data time determined by the same candidate sliding window.
[0010] Optionally, after acquiring a time series queue including multiple time series data to be analyzed, the method further includes: analyzing multiple historical monitoring data in the time series queue using a preset prediction model to obtain predicted monitoring data corresponding to a preset time, wherein the preset time is determined based on the data acquisition time of the real-time monitoring data; detecting the difference between the predicted monitoring data and the real-time monitoring data; generating an alarm message if the difference exceeds a first difference threshold; and determining to slide a preset sliding window on the time series queue to be analyzed if the difference does not exceed a second difference threshold, obtaining window data corresponding to the preset sliding window after each slide, wherein the second difference threshold is less than the first difference threshold.
[0011] Optionally, there are multiple predicted monitoring data and multiple real-time monitoring data. The preset time includes multiple preset time periods that correspond to both the predicted monitoring data and the real-time monitoring data. Detecting the difference between the predicted monitoring data and the real-time monitoring data includes calculating the mean error of multiple preset monitoring data and multiple real-time monitoring data within the preset time period. If the mean square error is greater than a preset mean square error threshold, it is determined that the difference exceeds the preset difference threshold.
[0012] Optionally, using a preset sliding window to slide on the time series queue to be analyzed, and obtaining the window data corresponding to the preset sliding window after each slide, includes: performing differential calculation on multiple time series data to be analyzed in the time series queue to obtain a differential time series sequence; and using a preset sliding window to slide on the differential time series sequence to obtain the window data corresponding to the preset sliding window after each slide.
[0013] According to another aspect of the present invention, an anomaly detection device for time series data is also provided, comprising: an acquisition module, configured to acquire a time series queue to be analyzed comprising a plurality of time series data to be analyzed, wherein the time series data to be analyzed comprises at least: real-time monitoring data and a plurality of historical monitoring data; a determination module, configured to slide a preset sliding window on the time series queue to be analyzed, and obtain window data corresponding to the preset sliding window after each slide, wherein the window data is the average value of the time series data to be analyzed within the preset sliding window; and a first detection module, configured to detect a short-term trend of the window data based on a plurality of window data in a first window sequence, wherein the first window sequence comprises: a first number of window data, and the first window sequence comprises at least: window data determined based on the preset sliding window covering the real-time monitoring data, the short-term trend being used to at least represent the first The first detection module is used to detect whether a trend change occurs in multiple window data in the first window sequence; the second detection module is used to detect the long-term trend of the window data based on multiple window data in the second window sequence when the short-term trend indicates a trend change in multiple window data in the first window sequence, wherein the second window sequence includes: a second number of window data, the second number being greater than a first number, and the second window sequence includes at least: window data determined based on a preset sliding window covering the real-time monitoring data, and window data determined based on a preset sliding window covering the historical monitoring data, the long-term trend being used to indicate at least whether a trend change occurs in multiple window data in the second window sequence; the generation module is used to generate abnormal warning information when the long-term trend indicates a trend change in multiple window data in the second window sequence.
[0014] According to another aspect of the present invention, an electronic device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the above-described method for detecting anomalies in timing data through the computer program.
[0015] According to another aspect of the present invention, a computer program product is also provided, including computer instructions that, when executed by a processor, implement the steps of the above-described method for detecting anomalies in timing data.
[0016] In the embodiments described above, short-term trend analysis can quickly respond to real-time changes in data, while long-term trend analysis can identify potential and persistent abnormal trends. By combining short-term and long-term trend analysis, abnormal changes in time-series data can be identified more accurately, avoiding false alarms or missed alarms that may be caused by single-time-scale analysis. Thus, by combining short-term and long-term trends, the technical effect of improving the accuracy of anomaly detection results is achieved, thereby solving the technical problem of low accuracy of anomaly detection results obtained by trend detection in the prior art. Attached Figure Description
[0017] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0018] Figure 1 This is a flowchart of an anomaly detection method for time-series data according to an embodiment of the present invention;
[0019] Figure 2 This is a flowchart of a sequence anomaly detection algorithm method based on long and short-term trends according to an embodiment of the present invention;
[0020] Figure 3 This is a schematic diagram of an anomaly detection device for time-series data according to an embodiment of the present invention;
[0021] Figure 4 This is a structural block diagram of a computer terminal according to an embodiment of the present invention. Detailed Implementation
[0022] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0023] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0024] According to an embodiment of the present invention, an embodiment of an anomaly detection method for time-series data is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0025] Figure 1 This is a flowchart of an anomaly detection method for time-series data according to an embodiment of the present invention, such as... Figure 1 As shown, the method includes the following steps:
[0026] Step S102: Obtain a time series queue to be analyzed, which includes multiple time series data to be analyzed, wherein the time series data to be analyzed includes at least: real-time monitoring data and multiple historical monitoring data;
[0027] Step S104: Use a preset sliding window to slide on the time series queue to be analyzed, and obtain the window data corresponding to the preset sliding window after each slide, wherein the window data is the average value of the time series data to be analyzed within the preset sliding window;
[0028] Step S106: Based on multiple window data in the first window sequence, detect the short-term trend of the window data, wherein the first window sequence includes: a first number of window data, and the first window sequence includes at least: window data determined based on a preset sliding window covering real-time monitoring data, and the short-term trend is used to indicate at least whether the multiple window data in the first window sequence show a trend change;
[0029] Step S108: When the short-term trend indicates that multiple window data in the first window sequence have a trend change, the long-term trend of the window data is detected based on the multiple window data in the second window sequence. The second window sequence includes: a second number of window data, which is greater than the first number, and the second window sequence includes at least: window data determined based on a preset sliding window covering real-time monitoring data, and window data determined based on a preset sliding window covering historical monitoring data. The long-term trend is used at least to indicate whether multiple window data in the second window sequence have a trend change.
[0030] Step S110: When multiple window data in the long-term trend representation second window sequence show a trend change, generate an anomaly warning message.
[0031] In the embodiments described above, short-term trend analysis can quickly respond to real-time changes in data, while long-term trend analysis can identify potential and persistent abnormal trends. By combining short-term and long-term trend analysis, abnormal changes in time-series data can be identified more accurately, avoiding false alarms or missed alarms that may be caused by single-time-scale analysis. Thus, by combining short-term and long-term trends, the technical effect of improving the accuracy of anomaly detection results is achieved, thereby solving the technical problem of low accuracy of anomaly detection results obtained by trend detection in the prior art.
[0032] In step S102 above, multiple time series data to be analyzed in the time series queue can be arranged in reverse order according to the data generation time or data acquisition time of each time series data to be analyzed. That is, the time series data to be analyzed that is closer to the current time is closer to the head of the queue, so as to facilitate the extraction of the time series data to be analyzed that is closest to the current time from the time series queue for anomaly detection.
[0033] It should be noted that the closer the time series data to the current time is, the greater its impact on the anomaly detection results. Therefore, placing the time series data closer to the current time at the head of the queue can increase the importance of the time series data closer to the current time and avoid the impact of outdated data on the detection results.
[0034] In step S102 above, the real-time monitoring data can be one or more data that have not been detected, such as multiple real-time monitoring data collected within a preset time period, wherein the data generation time or data collection time corresponding to each real-time monitoring data is within the preset time period.
[0035] In step S102 above, the historical monitoring data can be data that has been detected in the past.
[0036] In step S104 above, the value of each window data can be the average of multiple time series data to be analyzed covered by the corresponding preset sliding window; the data time represented by each window data can be obtained from the average time of the data time (such as data acquisition time or data generation time) of multiple time series data to be analyzed covered by the corresponding preset sliding window, or it can be determined from the midpoint of the time period covered by the corresponding preset sliding window.
[0037] In step S106 above, the first window sequence consists of multiple window data for short-term trend detection, and all window data in the first window sequence can be obtained based on real-time monitoring data.
[0038] In step S106 above, the first window sequence includes at least window data determined based on a preset sliding window covering real-time monitoring data, which enables the window data in the first window sequence to represent the trend changes of the real-time monitoring data, thereby achieving accurate detection of trend changes.
[0039] In step S106 above, the short-term trend can be determined by fitting multiple window data in the first window sequence. If a peak appears in the fitted part, it indicates whether the window data in the first window sequence has changed trend, that is, the time series data to be analyzed in the time series queue to be analyzed has undergone instantaneous change within the time period covered by the first window sequence.
[0040] In step S106 above, the short-term trend can be determined by calculating the slope of multiple window data in the first window sequence. If the slope changes abruptly, it indicates that the window data in the first window sequence also shows a trend change, that is, the time series data to be analyzed in the time series queue to be analyzed has a momentary change within the time period covered by the first window sequence.
[0041] It should be noted that instantaneous mutations determined based on short-term trends may be within the design margin and can regress instantaneously after the mutation. Therefore, they cannot be used as the basis for anomaly detection. Thus, in addition to determining that an instantaneous mutation has occurred based on short-term trends, long-term trend detection is also required to determine whether the instantaneous mutation is a change that affects the overall trend of the time series data to be analyzed.
[0042] In step S108 above, the second window sequence is a series of window data used for long-term trend detection. The window data in the second window sequence can be obtained based on real-time monitoring data and historical monitoring data.
[0043] In step S108 above, the long-term trend can be determined by fitting multiple window data in the second window sequence. If a peak appears in the fitted part, it indicates whether the window data in the second window sequence has changed trend, that is, the time series data to be analyzed in the time series queue has undergone an overall mutation. If the time series data to be analyzed has undergone an overall mutation, it can be said that the time series data to be analyzed has deviated from the design target, and it can be determined that a data anomaly has occurred, thus realizing the anomaly detection of the time series data.
[0044] In step S108 above, the short-term trend can be determined by calculating the slope of multiple window data in the second window sequence. If the slope changes abruptly, it indicates that the window data in the second window sequence also shows a trend change.
[0045] As an optional embodiment, the method further includes: updating the time series queue to be analyzed according to time changes when no trend change occurs in the multiple window data in the short-term trend representation first window sequence.
[0046] In the above embodiments of this application, if no trend change occurs in the multiple window data in the short-term trend representation first window sequence, it indicates that no instantaneous change has occurred in the time series queue to be analyzed, and therefore there is no need to perform long-term trend detection. In this case, the device providing the time series queue to be analyzed can continue to operate, and then continue to collect newly generated real-time monitoring data, and realize continuous detection of the time series queue to be analyzed based on the newly collected real-time monitoring data.
[0047] As an optional embodiment, the process of using a preset sliding window to slide on the time series queue to obtain the window data corresponding to the preset sliding window after each slide includes: determining a preset sliding window that meets a preset time span; sliding the preset sliding window in the order from the first to the last position of the time series queue to obtain multiple window data, wherein the multiple time series data to be analyzed in the time series queue are arranged in chronological order, and the real-time monitoring data is arranged at the first position of the time series queue to be analyzed; sorting the multiple window data according to the position of the preset sliding window of the determined window data on the time series queue to obtain a candidate window sequence, wherein the position of the preset sliding window in the time series queue to be analyzed is positively correlated with the position of the generated window data in the candidate window sequence; starting from the first position of the candidate window sequence, truncating the window sequence to be analyzed according to a preset number, wherein the preset number includes a first number and a second number, and the window sequence to be analyzed includes a first window sequence truncated according to the first number and a second window sequence truncated according to the second number.
[0048] The embodiments described above in this application utilize sliding window technology to dynamically analyze data changes over different time spans, thereby gaining a more comprehensive understanding of the trends in time series data. By using a preset sliding window, multiple time series data points in the time series queue to be analyzed can be compressed. Multiple time series data points covered by the same preset sliding window are integrated into a single window of data. The preset sliding window is moved multiple times to obtain each window of data. These windows are then sorted according to their positions on the time series queue to be analyzed, resulting in a sequence of windows to be analyzed. From this sequence, a first window sequence for short-term trend detection and a second window sequence for long-term trend detection can be extracted, completing the data preparation for both short-term and long-term trend detection. Through the generation and sorting of window data, segmented analysis of time series data is achieved, solving the technical problem of quickly locating abnormal changes in large amounts of time series data and improving the efficiency and accuracy of anomaly detection.
[0049] As an optional embodiment, the preset sliding window is slid in order from the first to the last position of the time series queue to be analyzed, and multiple window data are obtained by: determining the preset sliding window after each movement on the time series queue to be analyzed as a candidate sliding window; calculating the average value of the multiple time series data to be analyzed covered by the candidate sliding window to obtain the average value of the window data corresponding to the candidate sliding window; allocating window data time to the average value of the window data according to the data time of the multiple time series data to be analyzed covered by the candidate sliding window; and determining the window data corresponding to the candidate sliding window based on the average value of the window data and the window data time determined by the same candidate sliding window.
[0050] The embodiments described above in this application, by calculating the average value of multiple time-series data to be analyzed covered by a sliding window, can smooth out fluctuations in time-series data and more clearly display data trends. For example, when data fluctuations are large, calculating the average value through a sliding window can filter out short-term fluctuations and identify the long-term trend of the data. This technical solution, through the calculation of window data and time allocation, solves the technical problem of how to effectively identify trend changes in time-series data, and improves the stability and reliability of anomaly detection.
[0051] As an optional embodiment, after acquiring a time series queue including multiple time series data to be analyzed, the method further includes: analyzing multiple historical monitoring data in the time series queue using a preset prediction model to obtain predicted monitoring data corresponding to a preset time, wherein the preset time is determined based on the data acquisition time of the real-time monitoring data; detecting the difference between the predicted monitoring data and the real-time monitoring data; generating an alarm message if the difference exceeds a first difference threshold; and determining to slide a preset sliding window on the time series queue to be analyzed if the difference does not exceed a second difference threshold, obtaining window data corresponding to the preset sliding window after each slide, wherein the second difference threshold is less than the first difference threshold.
[0052] The embodiments described above in this application, by introducing a preset prediction model, can predict future data trends based on historical data. By comparing real-time monitoring data with predicted monitoring data, abnormal changes can be quickly identified. If the difference between the monitoring data and the predicted monitoring data exceeds a first difference threshold, it indicates that the deviation between the predicted monitoring data and the real-time monitoring data is too large, meaning that the real-time monitoring data has deviated from the normal operating conditions, and therefore an alarm can be directly triggered. If the difference between the monitoring data and the predicted monitoring data does not exceed a second difference threshold, it indicates that the predicted monitoring data and the real-time monitoring data are close, and the threshold cannot be used for anomaly detection. Therefore, a sliding window approach is needed to extract window data for long-term and short-term trend detection, and based on the long-term and short-term trend detection, it is determined whether the time series data to be analyzed has anomalies.
[0053] The embodiments described above in this application achieve early warning of anomalies by comparing the prediction model with real-time data, solving the technical problem of how to predict anomalies before data changes, and improving the system's early warning capability and response speed.
[0054] As an optional embodiment, there are multiple predictive monitoring data and real-time monitoring data. The preset time includes multiple preset time points corresponding to both the predictive monitoring data and the real-time monitoring data. Detecting the difference between the predictive monitoring data and the real-time monitoring data includes calculating the mean error of multiple preset monitoring data and multiple real-time monitoring data within a preset time period. If the mean square error is greater than a preset mean square error threshold, it is determined that the difference exceeds a preset difference threshold.
[0055] In the above embodiments of this application, by calculating the mean square error between the predicted monitoring data and the real-time monitoring data, the difference between the two can be quantified, thereby more objectively judging whether there is an anomaly. Through the calculation of the mean square error, the quantitative analysis of anomaly detection is realized, solving the technical problem of how to objectively judge the data difference and improving the scientificity and accuracy of anomaly detection.
[0056] As an optional embodiment, the window data corresponding to the preset sliding window after each sliding is obtained by sliding a preset sliding window on the time series queue to be analyzed. This includes: performing differential calculation on multiple time series data to be analyzed in the time series queue to obtain a differential time series sequence; and sliding the preset sliding window on the differential time series sequence to obtain the window data corresponding to the preset sliding window after each sliding.
[0057] In the above embodiments of this application, differential calculation is performed on multiple time series data to be analyzed in the time series queue to be analyzed, that is, the difference between two adjacent time series data to be analyzed in the time series queue to be analyzed is calculated. By performing differential calculation on the time series queue to be analyzed, trend or periodic changes in the sequence can be eliminated, and a relatively stable new sequence, namely the differential time series sequence, can be obtained. Then, based on the stable differential time series sequence, the detection of long and short time trends can be performed more accurately.
[0058] The present invention also provides a preferred embodiment, which provides an anomaly detection algorithm based on long and short-term trends, which can achieve trend monitoring in the case of data anomaly detection.
[0059] It should be noted that trend monitoring is important for many types of data, especially time-related data. It can not only monitor whether there are anomalies in the current data, but also predict whether there will be anomalies in the future data.
[0060] It should be noted that most time series-based algorithms require a large number of timestamps. For data with fewer timestamps, long-term and short-term trend monitoring algorithms can make up for the inability to use time series monitoring algorithms.
[0061] Figure 2 This is a flowchart of a sequence anomaly detection algorithm method based on long and short-term trends according to an embodiment of the present invention, as shown below. Figure 2 As shown, the steps are as follows:
[0062] Step S201: Collect raw data from the device and save it to the database.
[0063] Step S202: Divide the dataset stored in the database into a training set and a test set, and perform preprocessing such as filling in null values and replacing outliers in the training set data.
[0064] Step S203: Input the training dataset into the prediction algorithm module, wherein the prediction algorithm uses an autoencoder deep learning algorithm to obtain prediction data.
[0065] Step S204: Long-term and short-term trend monitoring.
[0066] Optionally, the mean squared error (MSE) of the predicted and tested values is calculated, i.e.: An alarm is triggered if the value exceeds a threshold T; otherwise, a long-term and short-term trend monitoring algorithm is used to monitor the real-time test data.
[0067] As an optional example, the trend monitoring algorithm includes trend calculation. This algorithm uses the ARIAM (Autoregressive Differential Moving Average) algorithm to calculate the trend, specifically including:
[0068] Step S2041: Differential calculation yields a relatively stable new sequence.
[0069] Step S2042: Move the data by a window of a specific size to obtain the average value.
[0070] Step S2043: Perform autoregression on the data obtained in step S2042 to obtain the final data trend (such as the window sequence to be analyzed). The window size is adaptively selected according to the original data (the long-term trend should include historical data, and the short-term trend is determined according to the length of the test data). Calculate the long-term trend coefficient Trend_L and the short-term trend coefficient Trend_S. If the Trend_S of the real-time monitored data is at its peak (maximum or minimum), check the value of Trend_L. If Trend_L is at its peak or near-peak, issue an alert.
[0071] It's important to note that Autoregressive (AR) is a time series forecasting model primarily used to predict future data points. In an autoregressive model, future data points are predicted based on past data points. In other words, an autoregressive model assumes a linear relationship between future and past data, using historical data to predict future data.
[0072] According to an embodiment of the present invention, an embodiment of an anomaly detection device for time series data is also provided. It should be noted that the anomaly detection device for time series data can be used to execute the anomaly detection method for time series data in the embodiment of the present invention, and the anomaly detection method for time series data in the embodiment of the present invention can be executed in the anomaly detection device for time series data.
[0073] Figure 3 This is a schematic diagram of an anomaly detection device for time-series data according to an embodiment of the present invention, such as... Figure 3As shown, the device may include: an acquisition module 31, configured to acquire a queue of time series data to be analyzed, comprising multiple time series data to be analyzed, wherein the time series data to be analyzed includes at least: real-time monitoring data and multiple historical monitoring data; a determination module 33, configured to slide a preset sliding window on the queue of time series data to be analyzed, and obtain window data corresponding to the preset sliding window after each slide, wherein the window data is the average value of the time series data to be analyzed within the preset sliding window; and a first detection module 35, configured to detect the short-term trend of window data based on multiple window data in a first window sequence, wherein the first window sequence includes: a first number of window data, and the first window sequence includes at least: window data determined based on a preset sliding window covering real-time monitoring data, and the short-term trend is used to represent at least the first window The first detection module 37 is used to detect the long-term trend of window data based on multiple window data in the second window sequence when the short-term trend indicates a trend change in multiple window data in the first window sequence. The second window sequence includes a second number of window data, which is greater than the first number. The second window sequence includes at least two window data points: window data determined by a preset sliding window covering real-time monitoring data and window data determined by a preset sliding window covering historical monitoring data. The long-term trend is used to indicate whether a trend change has occurred in multiple window data in the second window sequence. The second detection module 39 is used to generate an abnormal warning message when the long-term trend indicates a trend change in multiple window data in the second window sequence.
[0074] It should be noted that the acquisition module 31 in this embodiment can be used to execute step S102 in this application embodiment, the determination module 33 in this embodiment can be used to execute step S104 in this application embodiment, the first detection module 35 in this embodiment can be used to execute step S106 in this application embodiment, the second detection module 37 in this embodiment can be used to execute step S108 in this application embodiment, and the generation module 39 in this embodiment can be used to execute step S110 in this application embodiment. The examples and application scenarios implemented by the above modules and corresponding steps are the same, but are not limited to the content disclosed in the above embodiments.
[0075] In the embodiments described above, short-term trend analysis can quickly respond to real-time changes in data, while long-term trend analysis can identify potential and persistent abnormal trends. By combining short-term and long-term trend analysis, abnormal changes in time-series data can be identified more accurately, avoiding false alarms or missed alarms that may be caused by single-time-scale analysis. Thus, by combining short-term and long-term trends, the technical effect of improving the accuracy of anomaly detection results is achieved, thereby solving the technical problem of low accuracy of anomaly detection results obtained by trend detection in the prior art.
[0076] As an optional embodiment, the apparatus further includes: an update submodule, configured to update the time series queue to be analyzed according to time changes when no trend change occurs in the multiple window data in the short-term trend representation of the first window sequence.
[0077] As an optional embodiment, the determining module includes: a first determining unit, configured to determine the preset sliding window that conforms to a preset time span; a sliding unit, configured to slide the preset sliding window in the order from the first to the last position of the time series queue to be analyzed, to obtain multiple window data, wherein the multiple time series data to be analyzed in the time series queue are arranged in chronological order, and the real-time monitoring data is arranged at the first position of the time series queue to be analyzed; a sorting unit, configured to sort the multiple window data according to the position of the preset sliding window that determines the window data in the time series queue to be analyzed, to obtain a candidate window sequence, wherein the position of the preset sliding window in the time series queue to be analyzed is positively correlated with the position of the generated window data in the candidate window sequence; and a truncating unit, configured to truncate the window sequence to be analyzed according to a preset number, starting from the first position of the candidate window sequence, wherein the preset number includes: a first number and a second number, and the window sequence to be analyzed includes: a first window sequence truncated according to the first number and a second window sequence truncated according to the second number.
[0078] As an optional embodiment, the determining module includes: a second determining unit, configured to determine the preset sliding window after each movement on the time series queue to be analyzed as a candidate sliding window; a calculation unit, configured to calculate the average value of the multiple time series data to be analyzed covered by the candidate sliding window to obtain the average value of the window data corresponding to the candidate sliding window; an allocation unit, configured to allocate window data time to the average value of the window data based on the data time of the multiple time series data to be analyzed covered by the candidate sliding window; and a third determining unit, configured to determine the window data corresponding to the candidate sliding window based on the average value of the window data determined by the same candidate sliding window and the window data time.
[0079] As an optional embodiment, the device further includes: an analysis submodule, configured to, after acquiring a time series queue including multiple time series data to be analyzed, analyze multiple historical monitoring data in the time series queue using a preset prediction model to obtain predicted monitoring data corresponding to a preset time, wherein the preset time is determined based on the data acquisition time of the real-time monitoring data; a detection submodule, configured to detect the difference between the predicted monitoring data and the real-time monitoring data; a first determination submodule, configured to generate an alarm message if the difference exceeds a first difference threshold; and a second determination submodule, configured to, if the difference does not exceed a second difference threshold, determine to slide a preset sliding window on the time series queue to be analyzed to obtain window data corresponding to the preset sliding window after each slide, wherein the second difference threshold is less than the first difference threshold.
[0080] As an optional embodiment, there are multiple predicted monitoring data and multiple real-time monitoring data. The preset time includes multiple preset time periods corresponding to both the predicted monitoring data and the real-time monitoring data. The detection submodule includes a calculation subunit for calculating the mean error of multiple preset monitoring data and multiple real-time monitoring data within the preset time period. In this case, if the mean square error is greater than a preset mean square error threshold, it is determined that the difference exceeds the preset difference threshold.
[0081] As an optional embodiment, the determining module includes: a differential calculation unit, used to perform differential calculation on multiple time series data to be analyzed in the time series queue to obtain a differential time series sequence; and a fourth determining unit, used to slide a preset sliding window on the differential time series sequence to obtain window data corresponding to the preset sliding window after each slide.
[0082] Embodiments of the present invention can provide an electronic device, which can be a computer terminal, and the computer terminal can be any one of a group of computer terminal devices. Optionally, in this embodiment, the computer terminal can also be replaced by a mobile terminal or other terminal device.
[0083] Optionally, in this embodiment, the computer terminal may be located in at least one of a plurality of network devices in a computer network.
[0084] In this embodiment, the computer terminal described above can execute the program code for the following steps in the anomaly detection method for time series data: acquiring a time series queue to be analyzed, comprising multiple time series data to be analyzed, wherein the time series data to be analyzed includes at least: real-time monitoring data and multiple historical monitoring data; sliding a preset sliding window on the time series queue to be analyzed to obtain window data corresponding to the preset sliding window after each slide, wherein the window data is the average value of the time series data to be analyzed within the preset sliding window; detecting the short-term trend of the window data based on multiple window data in a first window sequence, wherein the first window sequence includes: a first number of window data, and the first window sequence includes at least: window data determined based on a preset sliding window covering real-time monitoring data, wherein the short-term trend is at least This is used to indicate whether a trend change has occurred in multiple window data in the first window sequence; when the short-term trend indicates a trend change in multiple window data in the first window sequence, the long-term trend of the window data is detected based on multiple window data in the second window sequence, wherein the second window sequence includes: a second number of window data, the second number being greater than the first number, and the second window sequence includes at least: window data determined based on a preset sliding window covering real-time monitoring data, and window data determined based on a preset sliding window covering historical monitoring data, and the long-term trend is used at least to indicate whether a trend change has occurred in multiple window data in the second window sequence; when the long-term trend indicates a trend change in multiple window data in the second window sequence, an abnormal warning message is generated.
[0085] Figure 4 This is a structural block diagram of a computer terminal according to an embodiment of the present invention, such as... Figure 4 As shown, the computer terminal 40 may include one or more (only one is shown in the figure) processors 42 and memory 44.
[0086] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the time-series data anomaly detection method and apparatus in this embodiment of the invention. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby realizing the aforementioned time-series data anomaly detection method. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to the terminal 40 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0087] The processor can invoke information and application programs stored in memory via a transmission device to perform the following steps: acquiring a queue of time series data to be analyzed, comprising multiple time series data to be analyzed, wherein the time series data to be analyzed includes at least: real-time monitoring data and multiple historical monitoring data; sliding a preset sliding window over the queue of time series data to be analyzed to obtain window data corresponding to the preset sliding window after each slide, wherein the window data is the average value of the time series data to be analyzed within the preset sliding window; detecting the short-term trend of the window data based on multiple window data in a first window sequence, wherein the first window sequence includes: a first number of window data, and the first window sequence includes at least: window data determined based on a preset sliding window covering real-time monitoring data, and the short-term trend is at least used to represent... The system indicates whether a trend change has occurred in multiple window data points within a first window sequence. If a short-term trend indicates a trend change in multiple window data points within the first window sequence, a long-term trend is detected based on multiple window data points within a second window sequence. The second window sequence includes a second number of window data points, which is greater than the first number. The second window sequence includes at least two window data points: window data determined by a preset sliding window covering real-time monitoring data and window data determined by a preset sliding window covering historical monitoring data. The long-term trend is used at least to indicate whether a trend change has occurred in multiple window data points within the second window sequence. If a long-term trend indicates a trend change in multiple window data points within the second window sequence, an anomaly warning is generated.
[0088] Optionally, the processor may also execute program code that performs the following steps: if no trend change occurs in the multiple window data in the first window sequence representing the short-term trend, update the time series queue to be analyzed according to the time change.
[0089] Optionally, the processor may also execute program code for the following steps: determining a preset sliding window that meets a preset time span; sliding the preset sliding window in order from the first to the last position of the time series queue to be analyzed, obtaining multiple window data, wherein the multiple time series data to be analyzed in the time series queue are arranged in chronological order, and the real-time monitoring data is arranged at the first position of the time series queue to be analyzed; sorting the multiple window data according to the position of the preset sliding window of the window data in the time series queue to be analyzed, obtaining a candidate window sequence, wherein the position of the preset sliding window in the time series queue to be analyzed is positively correlated with the position of the generated window data in the candidate window sequence; taking the first position of the candidate window sequence as the starting point, truncating the window sequence to be analyzed according to a preset number, wherein the preset number includes: a first number and a second number, and the window sequence to be analyzed includes: a first window sequence truncated according to the first number and a second window sequence truncated according to the second number.
[0090] Optionally, the processor may also execute program code that performs the following steps: determining a preset sliding window after each movement on the time series queue to be analyzed as a candidate sliding window; calculating the average value of multiple time series data to be analyzed covered by the candidate sliding window to obtain the average value of the window data corresponding to the candidate sliding window; allocating window data time to the average value of the window data based on the data time of the multiple time series data to be analyzed covered by the candidate sliding window; and determining the window data corresponding to the candidate sliding window based on the average value of the window data and the window data time determined by the same candidate sliding window.
[0091] Optionally, the processor may also execute program code for the following steps: analyzing multiple historical monitoring data in the time series queue to be analyzed using a preset prediction model to obtain predicted monitoring data corresponding to a preset time, wherein the preset time is determined based on the data acquisition time of the real-time monitoring data; detecting the difference between the predicted monitoring data and the real-time monitoring data; generating an alarm message if the difference exceeds a first difference threshold; and determining to slide a preset sliding window on the time series queue to be analyzed if the difference does not exceed a second difference threshold, obtaining window data corresponding to the preset sliding window after each slide, wherein the second difference threshold is less than the first difference threshold.
[0092] Optionally, there are multiple predictive monitoring data and real-time monitoring data. The preset time includes multiple preset time points corresponding to both the predictive monitoring data and the real-time monitoring data. The processor can also execute program code that performs the following steps: calculate the mean error of multiple preset monitoring data and multiple real-time monitoring data within the preset time period, wherein, if the mean square error is greater than a preset mean square error threshold, it is determined that the difference exceeds a preset difference threshold.
[0093] Optionally, the processor may also execute program code that performs the following steps: performs differential calculations on multiple time series data to be analyzed in the time series queue to obtain a differential time series sequence; and slides a preset sliding window on the differential time series to obtain the window data corresponding to the preset sliding window after each slide.
[0094] Those skilled in the art will understand that Figure 4 The structure shown is for illustrative purposes only. The computer terminal can also be a smartphone (such as an Android phone, an iOS phone, etc.), a tablet computer, a mobile internet device (MID), a PAD, and other terminal devices. Figure 4 This does not limit the structure of the aforementioned electronic device. For example, computer terminal 40 may also include components that are more... Figure 4 The more or fewer components shown (such as network interfaces, display devices, etc.), or having the same Figure 4 The different configurations shown.
[0095] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a computer program instructing the hardware related to the terminal device. The computer program can be stored in a non-volatile medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, etc.
[0096] Embodiments of the present invention also provide a non-volatile storage medium. Optionally, in this embodiment, the aforementioned non-volatile storage medium can be used to store the program code executed by the anomaly detection method for timing data provided in the above embodiments.
[0097] Optionally, in this embodiment, the non-volatile storage medium may be located in any computer terminal in a group of computer terminals in a computer network, or in any mobile terminal in a group of mobile terminals.
[0098] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: acquiring a time series queue to be analyzed, comprising multiple time series data to be analyzed, wherein the time series data to be analyzed includes at least: real-time monitoring data and multiple historical monitoring data; detecting short-term trends of window data based on multiple window data in a first window sequence, wherein the first window sequence includes: a first number of window data, and the first window sequence includes at least: window data determined based on a preset sliding window covering real-time monitoring data, and the short-term trend is used at least to indicate whether a trend change has occurred in the multiple window data in the first window sequence; in the short-term trend indicating a first When multiple window data points in a window sequence show a trend change, the long-term trend of the window data is detected based on the multiple window data points in a second window sequence. The second window sequence includes a second number of window data points, which is greater than the first number. The second window sequence includes at least two types of window data points: window data points determined by a preset sliding window covering real-time monitoring data and window data points determined by a preset sliding window covering historical monitoring data. The long-term trend is used to indicate whether multiple window data points in the second window sequence show a trend change. When the long-term trend indicates that multiple window data points in the second window sequence have shown a trend change, an anomaly warning is generated.
[0099] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: updating the time series queue to be analyzed according to time changes when no trend change occurs in multiple window data in the short-term trend representation first window sequence.
[0100] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: determining a preset sliding window that conforms to a preset time span; sliding the preset sliding window in the order from the first to the last position of the time series queue to be analyzed, obtaining multiple window data, wherein the multiple time series data to be analyzed in the time series queue are arranged in chronological order, and the real-time monitoring data is arranged at the first position of the time series queue to be analyzed; sorting the multiple window data according to the position of the preset sliding window of the window data in the time series queue to be analyzed, obtaining a candidate window sequence, wherein the position of the preset sliding window in the time series queue to be analyzed is positively correlated with the position of the generated window data in the candidate window sequence; starting from the first position of the candidate window sequence, truncating the window sequence to be analyzed according to a preset number, wherein the preset number includes: a first number and a second number, and the window sequence to be analyzed includes: a first window sequence truncated according to the first number and a second window sequence truncated according to the second number.
[0101] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: determining a preset sliding window after each movement on the time series queue to be analyzed as a candidate sliding window; calculating the average value of multiple time series data to be analyzed covered by the candidate sliding window to obtain the average value of window data corresponding to the candidate sliding window; allocating window data time to the average value of window data based on the data time of multiple time series data to be analyzed covered by the candidate sliding window; and determining the window data corresponding to the candidate sliding window based on the average value of window data and the window data time determined by the same candidate sliding window.
[0102] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: analyzing multiple historical monitoring data in the time series queue to be analyzed using a preset prediction model to obtain predicted monitoring data corresponding to a preset time, wherein the preset time is determined based on the data acquisition time of the real-time monitoring data; detecting the difference between the predicted monitoring data and the real-time monitoring data; generating an alarm message if the difference exceeds a first difference threshold; and determining to slide a preset sliding window on the time series queue to be analyzed if the difference does not exceed a second difference threshold, obtaining window data corresponding to the preset sliding window after each slide, wherein the second difference threshold is less than the first difference threshold.
[0103] Optionally, in this embodiment, there are multiple predictive monitoring data and real-time monitoring data, and the preset time includes multiple preset times corresponding to both the predictive monitoring data and the real-time monitoring data. The non-volatile storage medium is configured to store program code for performing the following steps: calculating the mean error of multiple preset monitoring data and multiple real-time monitoring data within the preset time period, wherein, if the mean square error is greater than a preset mean square error threshold, it is determined that the difference exceeds a preset difference threshold.
[0104] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: performing differential calculations on multiple time series data to be analyzed in the time series queue to obtain a differential time series sequence; and using a preset sliding window to slide on the differential time series to obtain window data corresponding to the preset sliding window after each slide.
[0105] Embodiments of the present invention also provide a computer program product, including a computer program. Optionally, in this embodiment, when the computer program is executed by a processor, it implements the steps of the anomaly detection method for timing data provided in the above embodiments.
[0106] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0107] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0108] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0109] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0110] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0111] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a non-volatile storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a non-volatile storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned non-volatile storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0112] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for anomaly detection in time-series data, characterized in that, include: Obtain a time series queue to be analyzed, which includes multiple time series data to be analyzed, wherein the time series data to be analyzed includes at least: real-time monitoring data and multiple historical monitoring data; A preset sliding window is used to slide on the time series queue to be analyzed, and the window data corresponding to the preset sliding window after each slide is obtained, wherein the window data is the average value of the time series data to be analyzed within the preset sliding window; Based on multiple window data in a first window sequence, a short-term trend of the window data is detected, wherein the first window sequence includes: a first number of window data, and the first window sequence includes at least: window data determined based on a preset sliding window covering the real-time monitoring data, and the short-term trend is at least used to indicate whether a trend change occurs in multiple window data in the first window sequence; When the short-term trend indicates a trend change in multiple window data in the first window sequence, a long-term trend of the window data is detected based on multiple window data in the second window sequence. The second window sequence includes a second number of window data, which is greater than a first number. The second window sequence includes at least two window data: window data determined based on a preset sliding window covering the real-time monitoring data and window data determined based on a preset sliding window covering the historical monitoring data. The long-term trend is used to indicate at least whether a trend change has occurred in multiple window data in the second window sequence. When a trend change occurs in multiple window data points within the second window sequence, an anomaly warning message is generated.
2. The method according to claim 1, characterized in that, The method further includes: If no trend change occurs in the short-term trend representation of multiple window data in the first window sequence, the time series queue to be analyzed is updated according to the time change.
3. The method according to claim 1, characterized in that, The window data corresponding to the preset sliding window after each slide, obtained by sliding the preset sliding window over the time series queue to be analyzed, includes: Determine the preset sliding window that meets the preset time span; The preset sliding window is slid in the order from the first to the last position of the time series queue to be analyzed to obtain multiple window data. The multiple time series data to be analyzed in the time series queue are arranged in chronological order, and the real-time monitoring data is arranged at the first position of the time series queue to be analyzed. Multiple window data are sorted according to the position of the preset sliding window that determines the window data in the time series queue to be analyzed, to obtain a candidate window sequence, wherein the position of the preset sliding window in the time series queue to be analyzed is positively correlated with the position of the generated window data in the candidate window sequence; Starting from the first position of the candidate window sequence, the window sequence to be analyzed is truncated according to a preset number, wherein the preset number includes: a first number and a second number, and the window sequence to be analyzed includes: the first window sequence truncated according to the first number, and the second window sequence truncated according to the second number.
4. The method according to claim 3, characterized in that, The preset sliding window is slid in order from the first to the last element of the time series queue to be analyzed, resulting in multiple sets of window data, including: Each time the preset sliding window moves on the time series queue to be analyzed, it is determined as a candidate sliding window; The average value of the multiple time series data to be analyzed covered by the candidate sliding window is calculated to obtain the average value of the window data corresponding to the candidate sliding window; Based on the data time of the multiple time series data to be analyzed covered by the candidate sliding window, a window data time is allocated to the average value of the window data. The window data corresponding to the candidate sliding window is determined based on the average value of the window data and the window data time determined by the same candidate sliding window.
5. The method according to claim 1, characterized in that, After acquiring a queue of time series data to be analyzed, which includes multiple time series data to be analyzed, the method further includes: A preset prediction model is used to analyze multiple historical monitoring data in the time series queue to be analyzed, and the predicted monitoring data corresponding to the preset time is obtained, wherein the preset time is determined based on the data acquisition time of the real-time monitoring data. Detect the difference between the predicted monitoring data and the real-time monitoring data; If the difference exceeds a first difference threshold, an alarm message is generated; If the difference does not exceed the second difference threshold, a preset sliding window is used to slide on the time series queue to be analyzed, and window data corresponding to the preset sliding window after each slide is obtained, wherein the second difference threshold is less than the first difference threshold.
6. The method according to claim 5, characterized in that, The predicted monitoring data and the real-time monitoring data are multiple, and the preset time includes multiple preset time points corresponding to both the predicted monitoring data and the real-time monitoring data. Detecting the differences between the predicted monitoring data and the real-time monitoring data includes: Calculate the mean error of multiple preset monitoring data and multiple real-time monitoring data within the preset time period, wherein if the mean square error is greater than a preset mean square error threshold, determine that the difference exceeds the preset difference threshold.
7. The method according to claim 1, characterized in that, The window data corresponding to the preset sliding window after each sliding motion is obtained by sliding a preset sliding window over the time series queue to be analyzed, including: Differential calculations are performed on multiple time series data to be analyzed in the time series queue to obtain a differential time series sequence; A preset sliding window is used to slide over the differential time series to obtain the window data corresponding to the preset sliding window after each slide.
8. An anomaly detection device for time-series data, characterized in that, include: The acquisition module is used to acquire a time series queue to be analyzed, which includes multiple time series data to be analyzed, wherein the time series data to be analyzed includes at least: real-time monitoring data and multiple historical monitoring data; The determination module is used to slide a preset sliding window on the time series queue to be analyzed, and obtain the window data corresponding to the preset sliding window after each slide, wherein the window data is the average value of the time series data to be analyzed within the preset sliding window; The first detection module is used to detect the short-term trend of the window data based on a plurality of window data in the first window sequence, wherein the first window sequence includes: a first number of window data, and the first window sequence includes at least: window data determined based on the preset sliding window covering the real-time monitoring data, and the short-term trend is used to indicate at least whether a trend change has occurred in the plurality of window data in the first window sequence; The second detection module is configured to detect the long-term trend of the window data based on the multiple window data in the second window sequence when the short-term trend indicates a trend change in the multiple window data in the first window sequence. The second window sequence includes a second number of window data, which is greater than a first number. The second window sequence includes at least the window data determined based on the preset sliding window covering the real-time monitoring data and the window data determined based on the preset sliding window covering the historical monitoring data. The long-term trend is used to indicate at least whether a trend change has occurred in the multiple window data in the second window sequence. The generation module is used to generate abnormal warning information when a trend change occurs in multiple window data in the second window sequence representing the long-term trend.
9. An electronic device comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor is configured to execute the anomaly detection method for timing data according to any one of claims 1 to 7 through the computer program.
10. A computer program product comprising computer instructions, characterized in that, When the computer instructions are executed by the processor, they implement the steps of the anomaly detection method for time-series data according to any one of claims 1 to 7.
Citation Information
Cited By
Key event reminding method, related equipment and storage medium
CN121747301A