Abnormal computing power detection method and device applied to computing power optical network

By applying federated learning and multi-model fusion theory to a computing power optical network, an abnormal computing power detection mechanism is designed, which solves the shortcomings of anomaly detection in the computing power optical network, realizes efficient anomaly detection and data privacy protection, and improves the performance and reliability of the network.

CN120979747APending Publication Date: 2025-11-18SONGSHAN LAB
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511189689.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-25
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

The lack of effective methods for detecting abnormal computing power in existing optical computing networks affects network performance and reliability.

Method used

By applying federated learning and multi-model fusion theory to the computing power optical network, an abnormal computing power detection mechanism is designed. By utilizing the collaboration between client nodes and aggregation service nodes, combined with log data cleaning, word segmentation processing, and time-series relationship capture models, an anomaly detection model is trained to achieve anomaly detection of computing power nodes.

Benefits of technology

It improves the performance and reliability of the computing power optical network, ensures the continuity of user services and data privacy and security, and enables real-time anomaly detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979747A_ABST
    Figure CN120979747A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses an abnormal computing power detection method and device applied to a computing power optical network. A specific embodiment of the method comprises the following steps: synchronizing a log data set of each client computing power node to a server aggregation node; performing data cleaning and word segmentation processing on each piece of log data to generate a log vocabulary, and obtaining a log vocabulary set; inputting the log vocabulary set into a pre-trained sequential relationship capture model to obtain a sequential relationship set; according to each client computing power node, training the initial computing power node anomaly detection model to obtain a trained computing power node anomaly detection model; and inputting the log data set and the time sequence relation set into a computing power node anomaly detection model to obtain an abnormal computing power node detection result. According to the implementation mode, data and privacy security is guaranteed on the computing power node, real-time anomaly detection is carried out, and the performance and reliability of the computing power optical network system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments disclosed herein relate to the field of abnormal computing power detection, and specifically to an abnormal computing power detection method and apparatus applied in optical computing networks. Background Technology

[0002] With the widespread use of the internet and the rapid development of related technologies, optical computing networks distribute computing tasks and data across multiple computing nodes, leveraging collaboration and communication between these nodes to jointly complete complex computational tasks. This enables high-quality delivery and flow of various computing and storage resources. Collaboration between the computing resource layer and the network forwarding layer is crucial for ensuring network performance. Anomaly detection systems provide vital information about node status, while collaborative computing network orchestration systems make more intelligent resource management and scheduling decisions to ensure network efficiency, reliability, and performance optimization. Computing network orchestration, combined with OpenStack's underlying resource management and Kubernetes' container orchestration, utilizes the Kubernetes protocol for the deployment and operation of microservice systems, achieving deep integration and efficient management of computing, storage, and network resources. Therefore, there is an urgent need for a method for detecting anomalies in computing nodes to improve the performance and reliability of optical computing network systems. Summary of the Invention

[0003] The summary portion of this disclosure is intended to provide a brief overview of the concepts, which will be described in detail in the detailed description portion. This summary portion is not intended to identify key or essential features of the claimed technical solutions, nor is it intended to limit the scope of the claimed technical solutions.

[0004] Some embodiments of this disclosure propose methods, apparatuses, electronic devices, and computer-readable media for detecting abnormal computing power in optical computing networks, in order to solve the technical problems mentioned in the background section above.

[0005] In a first aspect, some embodiments of this disclosure provide a method for detecting abnormal computing power in a computing power optical network. The method includes: synchronizing log datasets from each client computing power node to a server-side aggregation node, wherein one client computing power node corresponds to one log data; performing data cleaning and word segmentation on each log data to generate a log vocabulary, thus obtaining a log vocabulary set; inputting the log vocabulary set into a pre-trained temporal relation capture model to obtain a temporal relation set, wherein one log vocabulary set corresponds to one temporal relation; training an initial computing power node anomaly detection model based on each client computing power node to obtain a trained computing power node anomaly detection model; and inputting the log dataset and the temporal relation set into the aforementioned computing power node anomaly detection model to obtain an abnormal computing power node detection result.

[0006] Secondly, some embodiments of this disclosure provide an abnormal computing power detection device applied in a computing power optical network. The device includes: a synchronization unit configured to synchronize the log datasets of each client computing power node to a server aggregation node, wherein one client computing power node corresponds to one log data; a cleaning unit configured to perform data cleaning and word segmentation on each log data to generate a log vocabulary, thereby obtaining a log vocabulary set; a first input unit configured to input the above log vocabulary set into a pre-trained temporal relation capture model to obtain a temporal relation set, wherein one log vocabulary set corresponds to one temporal relation; a training unit configured to train an initial computing power node anomaly detection model based on each client computing power node to obtain a trained computing power node anomaly detection model; and a second input unit configured to input the log dataset and the temporal relation set into the above computing power node anomaly detection model to obtain an abnormal computing power node detection result.

[0007] Thirdly, some embodiments of this disclosure provide an electronic device, including: one or more processors; and a storage device having one or more programs stored thereon, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation of the first aspect above.

[0008] Fourthly, some embodiments of this disclosure provide a computer-readable medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the method described in any of the implementations of the first aspect above.

[0009] The above embodiments of this disclosure have the following beneficial effects: The abnormal computing power detection method applied to optical computing power networks through some embodiments of this disclosure applies federated learning to optical computing power networks. Based on the design process of the optical computing power network orchestration system, an abnormal computing power detection mechanism is designed, and a federated abnormal computing power detection architecture is designed in conjunction with the detection mechanism. The architecture includes collaboration between client nodes and aggregation service nodes, fully considering the distributed characteristics and data privacy requirements of the edge computing environment. The federated collaborative multi-model fusion theory model is applied to the abnormal computing power detection of the optical computing power network's computing power management layer. Log data generated by computing power nodes is used as input to the federated collaborative multi-model fusion theory model. The abnormal probability output by the model is used to determine whether a node is abnormal. If normal, computing power services can be provided; if abnormal, corresponding processing is required to ensure the continuity and reliability of user services when processing computing tasks. This disclosure provides an innovative abnormal node detection scheme that balances data privacy and performance, ensuring the continuity and reliability of user services in the optical computing power network during operation. It achieves real-time anomaly detection while ensuring data and privacy security at computing power nodes, improving the performance and reliability of the optical computing power network system. Attached Figure Description

[0010] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and elements are not necessarily drawn to scale.

[0011] Figure 1 This is a flowchart of some embodiments of the abnormal computing power detection method applied in optical computing networks according to the present disclosure;

[0012] Figure 2 This is a schematic diagram of the structure of some embodiments of the abnormal computing power detection device applied in optical computing networks according to the present disclosure;

[0013] Figure 3 This is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present disclosure. Detailed Implementation

[0014] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0015] It should also be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described in this disclosure can be combined with each other.

[0016] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0017] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0018] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0019] This disclosure will now be described in detail with reference to the accompanying drawings and embodiments.

[0020] Figure 1 This is a flowchart 100 of some embodiments of an abnormal computing power detection method applied to a computing power optical network, which is based on some embodiments of this disclosure. The abnormal computing power detection method applied to a computing power optical network includes the following steps:

[0021] Step 101: Synchronize the log datasets of each client computing node to the server aggregation node.

[0022] In some embodiments, the execution entity (e.g., a computing device) of the abnormal computing power detection method applied in a computing power optical network can synchronize the log datasets of each client computing power node to the server aggregation node. Here, one client computing power node corresponds to one log dataset.

[0023] For example, the log datasets of each client computing node can be synchronized to the server-side aggregation node. The aggregation node S is located at the center of the scene, and the set of computing nodes is represented by C={1,2,...,M}. Node m is distributed within the coverage area of ​​the aggregation edge service node according to an independent homogeneous Poisson point process. The distance from node m to the aggregation edge service node S is denoted as dis. m,S , (x S ,y S The symbol () represents the location of server node S. The computing power of computing node m is represented by its storage size (memory). m The computing power is represented by C. m C m =F m / t m , of which F m t represents the number of floating-point operations performed by node m within a time window. m C is the length of the time window. m This represents the number of floating-point operations per second performed on node m.

[0024] .

[0025] Step 102: Perform data cleaning and word segmentation on each log data to generate a log vocabulary, thus obtaining a log vocabulary set.

[0026] In some embodiments, the aforementioned execution entity may perform data cleaning and word segmentation on each log data to generate a log vocabulary and obtain a log vocabulary set.

[0027] In practice, the aforementioned implementing entity can perform data cleaning and word segmentation on each log data item through the following steps to generate a log vocabulary:

[0028] The first step is to clean the log data to obtain cleaned log data. Here, data cleaning and word segmentation are performed on the log data generated by the computing power nodes. Redundant log information is removed, and the event occurrence time and key information describing the core operations or status in the logs are retained. The time is then converted into the corresponding English time.

[0029] The second step involves segmenting the cleaned log data to obtain a log vocabulary. After data cleaning, the log data is segmented according to basic semantic units. Although the semantics of log data may have an infinite number of combinations, the basic semantic units are finite, forming a vocabulary. By querying and integrating the basic semantic units in the vocabulary, the complete semantics of the entire sentence can be obtained.

[0030] Step 103: Input the above log vocabulary set into the pre-trained temporal relation capture model to obtain the temporal relation set.

[0031] In some embodiments, the execution entity can input the log vocabulary set into a pre-trained temporal relation capture model to obtain a temporal relation set. Each log vocabulary set corresponds to one temporal relation. The temporal relation capture model can be a CNN-BiLSTM classification model used to capture data sequence information and contextual relationships (temporal relations). For example, the temporal relation capture model may include the BERT model.

[0032] In practice, the aforementioned execution entity can perform the following processing steps for each log vocabulary in the aforementioned log vocabulary set:

[0033] The first step is to input the aforementioned log vocabulary into the multi-layered encoding layers of the aforementioned temporal relation capture model to obtain the log word vector sequence. The BERT model employs multi-layered Transformer encoding layers, each containing a self-attention layer and a feedforward neural network. In the self-attention layer, the input embedding vector is multiplied by three randomly generated weight matrices qW, kW, and vW, resulting in three new vector representations: query Q, key W, and value E, respectively. x(i) represents the initial input embedding vector, D... q D w and D e The query weight matrix, key weight matrix, and value weight matrix are randomly generated and randomly initialized learnable parameter matrices. These matrices are used to perform linear transformations on the initial embedding vector x(i), mapping it to three different feature spaces: query, key, and value, respectively, to extract feature dimensions from the text suitable for the attention mechanism. Next, these three vectors are used for attention calculation to capture the contextual information of the input sequence (log vocabulary). ,in, The scaling factor is used to mitigate the problem of excessively large attention scores caused by the increase in vector dimension. BERT employs a multi-head attention mechanism, which scales and normalizes the attention scores using Sofmax. The outputs of multiple heads are concatenated to obtain a comprehensive representation, which can then be further transformed using linear transformations and activation functions to obtain the final word vectors (log word vector sequences).

[0034] .

[0035] .

[0036] The second step involves extracting comprehensive features from the aforementioned log word vector sequence to generate a comprehensive feature vector. For example, a text CNN-BiLSTM classification model is used to capture data sequence information and contextual relationships for the log word vector sequence x. i After being encoded into a fixed-length vector representation by the BERT model, that is, B(x) i )=[h1,h2,…,h L A one-dimensional convolutional neural network is used to analyze B(x). i Local feature extraction is performed using convolutional kernel u to capture local features of different sizes. For each kernel size g, a convolution operation is performed to calculate the local feature value P obtained after convolution and activation function processing. u The following formula is given, where F(·) represents the ReLU activation function, and B(x) represents the ReLU activation function. i ) i:j+g-1 'b' represents the number of words extracted, and 'b' is a learnable bias term that adds a flexible adjustment term to the local features extracted by convolution, helping the model to more accurately adapt to log data and uncover abnormal features.

[0037] .

[0038] After convolution, the feature vector J is obtained. u It captures local features at specific locations and sizes in the input log vocabulary, for each feature vector J u Perform max pooling for feature vector J u It contains a series of numerical values, and the eigenvector is represented as J. u =[j1, j2,…,j k ], where k is the dimension of the feature vector, and the max pooling operation selects the largest of these values. The feature vector J generated by the max pooling layer for each convolutional kernel u is... u The pooled eigenvalues ​​P are then processed to obtain the eigenvalues. u Next, the pooled feature vectors are concatenated, A i=Concatenate({P u} U u=1 ), where A i This represents the comprehensive feature vector of the i-th log word vector sequence, where each log vocabulary x... i A corresponding A will be generated. i This integrated feature vector will become the input to the subsequent bidirectional long short-term memory network, used to learn the temporal context information of the text sequence (log vocabulary).

[0039] The third step is to generate the forward hidden state sequence and the backward hidden state sequence corresponding to the above-mentioned comprehensive feature vector. The comprehensive feature vector A... i As the forward and backward inputs to the BiLSTM, a forward hidden state sequence and a backward hidden state sequence are generated.

[0040] The fourth step involves concatenating the forward hidden state sequence with the reverse hidden state sequence to obtain a concatenated vector, which serves as the temporal relationship. For example, concatenating the hidden states of the forward and reverse LSTMs (forward hidden state sequences and reverse hidden state sequences) yields the output vector of the BiLSTM, denoted as h. t , where h t W represents the hidden layer output vector at time t. t Let b represent the weight matrix. t Let represent the bias vector at time t. This represents the hidden state (forward hidden state sequence) of a forward LSTM (from the beginning of the sequence to time t), which encodes the temporal dependencies "from front to back" (such as the antecedent association of events in log data). (The reverse hidden state sequence) is the opposite. Finally, a fully connected layer is used to connect h. t Mapping this to the target category (abnormal computing power or normal computing power) and applying softmax processing, we obtain the probability distribution y = softmax = (Wh) for each category. t +b), where W is the weight matrix of the fully connected layer, b is the output bias, and the loss X(θ) is calculated using the cross-entropy function, |D n | represents the number of samples in the local dataset, x is the input sample, y is the corresponding ground truth label, and F θ (x) is the prediction result obtained by forward computation based on the local model parameters θ on the current client computing node n, 1 / |D n | is the reciprocal of the number of samples, representing the average loss per sample.

[0041] .

[0042] .

[0043] Step 104: Train the initial computing power node anomaly detection model based on each client computing power node to obtain the trained computing power node anomaly detection model.

[0044] In some embodiments, the aforementioned execution entity can train the initial computing power node anomaly detection model based on each client computing power node to obtain a trained computing power node anomaly detection model. The initial computing power node anomaly detection model may refer to a server-client federated collaborative model.

[0045] For example, a server-client federated collaborative model can be used to capture the local model parameters θ for the i-th data sample. n The error can be defined by the dataset D of computing power node n. n loss function on Define the computing power node dataset as The training objective of the federated learning algorithm is to find an optimal global model θ by solving the following optimization problem. * Make dataset D n Minimize the global loss function F(θ) on the surface.

[0046] .

[0047] .

[0048] In practice, the aforementioned implementing entity can train the initial computing power node anomaly detection model through the following steps:

[0049] The first step is to perform the following processing steps for each client computing node:

[0050] 1. Download the initial computing power node anomaly detection model to the local machine of the aforementioned client computing power node. Initial global model download: Starting from round r, aggregate the edge service nodes to initialize a global model θ. n The log vocabulary is distributed to all computing nodes C={1,2,...,M} as a local neural network model m0. This model uses BERT model to represent the semantics of the log vocabulary, uses CNN to extract local features of the log vocabulary, and then uses BiLSTM to learn the temporal relationship of the log vocabulary. Finally, it is classified through fully connected layers and softmax function. Its function is to determine whether the computing nodes are abnormal nodes.

[0051] 2. Using the log data of the aforementioned client computing nodes, the initial computing node anomaly detection model is trained to obtain the trained client node anomaly detection model.

[0052] For example, after receiving the initial computing node anomaly detection model θ0, computing node m will transfer its local data D. m The model is trained using the local neural network model m0 as input to the computing node. The model's predicted values ​​and the true values ​​are used as input to the cross-entropy loss function to calculate the model's performance on the local data D in this round. m loss value F m The stochastic gradient descent method is used, and the loss value F is... m Taking the partial derivative, the weight parameters of the local neural network model m0 are updated. For any edge node n, a different step size factor μ can be taken, controlling the "magnitude" of the model parameter update and determining the distance the parameters move in the opposite direction of the gradient during each gradient descent, thus obtaining the model trained in this round. To balance training speed and stability, the participants undergo M rounds of local training in this round r. The system then determines whether i=M holds true; if so, it updates the weight parameters of the local neural network model on the client side. .

[0053] .

[0054] 3. Determine the network parameters of the above node anomaly detection model.

[0055] The second step involves aggregating the anomaly detection models of each client node with their corresponding network parameters to obtain the trained computing power node anomaly detection model. Computing power node m then uploads its locally updated model. The data is then routed to the server-side aggregation node. The computing node m will update the local model. The parameters are sent to the server aggregation node S. The server aggregation node S receives the model parameters uploaded from all computing power nodes m, and the aggregation result is the global neural network model parameters for this round. .

[0056] .

[0057] In practice, for the network parameters corresponding to each client node anomaly detection model, the following processing steps are performed:

[0058] First, determine whether the training epochs corresponding to the above network parameters are the preset epochs. Check if r=R is true; if not, let r=r+1. .

[0059] Second, in response to the determination that the above training rounds are not the preset rounds, the client node anomaly detection model is marked as an unqualified client node anomaly detection model, and the corresponding client computing power node is instructed to continue training the client node anomaly detection model. Otherwise, all computing power nodes m use the global neural network model parameters issued by the server aggregation node. The local log information is cleaned and features are extracted according to the format of dataset D. The data is then input into a multi-model fusion network structure to extract features, and finally the classification result is determined.

[0060] Step 105: Input the log dataset and time series relationship set into the above computing power node anomaly detection model to obtain the abnormal computing power node detection results.

[0061] In some embodiments, the execution entity can input the log dataset and time-series relation set into the computing power node anomaly detection model to obtain anomaly computing power node detection results. For example, classifying computing power nodes and filtering out anomaly computing power nodes: The model parameters are represented by a softmax function and mapped to a probability space to obtain the probabilities of the computing power nodes in the sample sequence being normal and abnormal, respectively. , Based on the number of final probability values ​​obtained, among which, , h represents the conditional probability that log data i belongs to category 0 or 1, respectively. i It is the encoded feature vector (temporal relationship) of the computing power node anomaly detection model for the input. , Let b0 and b1 be the weight vectors for the corresponding categories, and exp(.) be the bias terms. The exponential function mapping ensures non-negativity of the probability and amplifies the differences. The numerator is the matching degree between the category and the feature, and the denominator is the sum of the matching degrees of all categories used for normalization. If > If it is classified as normal, then it is classified as abnormal.

[0062] .

[0063] .

[0064] Further reference Figure 2 As an implementation of the methods shown in the above figures, this disclosure provides some embodiments of an abnormal computing power detection device applied in a computing power optical network. These device embodiments are similar to... Figure 1 Corresponding to the method embodiments shown, this abnormal computing power detection device applied to computing power optical networks can be specifically applied to various electronic devices.

[0065] like Figure 2As shown, an abnormal computing power detection device 200 applied in a computing power optical network in some embodiments includes: a synchronization unit 201, a cleaning unit 202, a first input unit 203, a training unit 204, and a second input unit 205. The system includes a synchronization unit 201, configured to synchronize the log datasets of each client computing power node to the server aggregation node, where one client computing power node corresponds to one log data; a cleaning unit 202, configured to perform data cleaning and word segmentation on each log data to generate a log vocabulary, resulting in a log vocabulary set; a first input unit 203, configured to input the log vocabulary set into a pre-trained temporal relation capture model to obtain a temporal relation set, where one log vocabulary set corresponds to one temporal relation; a training unit 204, configured to train the initial computing power node anomaly detection model based on each client computing power node, resulting in a trained computing power node anomaly detection model; and a second input unit 205, configured to input the log dataset and the temporal relation set into the computing power node anomaly detection model to obtain anomaly computing power node detection results.

[0066] It is understandable that the units described in the abnormal computing power detection device 200 applied in the computing power optical network are similar to the reference units. Figure 1 The steps in the described method correspond to each other. Therefore, the operations, features, and beneficial effects described above for the method are also applicable to the abnormal computing power detection device 200 and its constituent units applied in the computing power optical network, and will not be repeated here.

[0067] The following is for reference. Figure 3 It illustrates a schematic diagram of the structure of an electronic device (such as a computing device) suitable for implementing some embodiments of the present disclosure. Figure 3 The electronic device shown is merely an example and should not be construed as limiting the functionality or scope of the embodiments of this disclosure. Figure 3 As shown, the computer device includes a processor, memory, and network interface connected via a system bus. The memory may include non-volatile storage media and internal memory. The non-volatile storage media may store the operating system and computer programs. The computer programs include program instructions that, when executed, cause the processor to execute any abnormal computing power detection method applied in a computing power optical network. The processor provides computing and control capabilities to support the operation of the entire computer device. The internal memory provides an environment for the execution of the computer programs in the non-volatile storage media. When executed by the processor, the computer programs cause the processor to execute any abnormal computing power detection method applied in a computing power optical network. The network interface is used for network communication, such as sending assigned tasks. Those skilled in the art will understand that... Figure 3The structure shown is merely a block diagram of a portion of the structure related to the present disclosure and does not constitute a limitation on the computer device to which the present disclosure is applied. A specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0068] It should be understood that the processor can be a Central Processing Unit (CPU), but it can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among these, a general-purpose processor can be a microprocessor or any conventional processor.

[0069] In one embodiment, the processor is used to run a computer program stored in a memory to perform the following steps: synchronizing the log datasets of each client computing node to the server aggregation node, wherein one client computing node corresponds to one log data; performing data cleaning and word segmentation on each log data to generate a log vocabulary, thus obtaining a log vocabulary set; inputting the log vocabulary set into a pre-trained temporal relation capture model to obtain a temporal relation set, wherein one log vocabulary set corresponds to one temporal relation; training an initial computing node anomaly detection model based on each client computing node to obtain a trained computing node anomaly detection model; and inputting the log dataset and the temporal relation set into the computing node anomaly detection model to obtain anomaly computing node detection results.

[0070] This disclosure also provides a computer-readable storage medium storing a computer program, which includes program instructions. When the program instructions are executed, the method implemented can be referred to various embodiments of the abnormal computing power detection method applied to computing power optical networks.

[0071] The aforementioned computer-readable storage medium may be an internal storage unit of the computer device described in the foregoing embodiments, such as the hard disk or memory of the computer device. Alternatively, the aforementioned computer-readable storage medium may be an external storage device of the computer device, such as a plug-in hard disk, SmartMedia Card (SMC), Secure Digital (SD) card, or Flash Card equipped on the computer device.

[0072] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0073] The above description is merely a selection of preferred embodiments of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in the embodiments of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described inventive concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions disclosed in the embodiments of this disclosure.

Claims

1. An abnormal computing power detection method applied in a computing power optical network, characterized in that, The method comprises the following steps: synchronizing log data sets of each client computing power node to a server aggregation node, wherein one client computing power node corresponds to one log data; performing data cleaning and word segmentation processing on each log data to generate a log vocabulary table and obtain a log vocabulary table set; inputting the log vocabulary table set into a pre-trained time sequence relationship capturing model to obtain a time sequence relationship set, wherein one log vocabulary table set corresponds to one time sequence relationship; training an initial computing power node anomaly detection model according to each client computing power node to obtain a trained computing power node anomaly detection model; inputting the log data set and the time sequence relationship set into the computing power node anomaly detection model to obtain an abnormal computing power node detection result.

2. The method of claim 1, wherein, The method comprises the following steps: for each log vocabulary table in the log vocabulary table set, the following processing steps are performed: inputting the log vocabulary table into a multi-layer encoding layer included in the time sequence relationship capturing model to obtain a log word vector sequence; performing comprehensive feature extraction on the log word vector sequence to generate a comprehensive feature vector; generating a forward hidden state sequence and a reverse hidden state sequence corresponding to the comprehensive feature vector; splicing the forward hidden state sequence and the reverse hidden state sequence to obtain a splicing vector as a time sequence relationship.

3. The method of claim 2, wherein, The method comprises the following steps: for each client computing power node, the following processing steps are performed: downloading an initial computing power node anomaly detection model to the client computing power node locally; training the initial computing power node anomaly detection model through the log data of the client computing power node to obtain a trained client node anomaly detection model; determining network parameters of the node anomaly detection model; aggregating each client node anomaly detection model and the corresponding network parameters to obtain a trained computing power node anomaly detection model.

4. The method of claim 1, wherein, The method comprises the following steps: performing data cleaning on the log data to obtain cleaned log data; performing word segmentation processing on the cleaned log data to obtain a log vocabulary table.

5. The method of claim 3, wherein, The method comprises the following steps: for the network parameters corresponding to each client node anomaly detection model, the following processing steps are performed: determining whether the training round corresponding to the network parameters is a preset round; in response to determining that the training round is not the preset round, marking the client node anomaly detection model as an unqualified client node anomaly detection model and instructing the corresponding client computing power node to continue training the client node anomaly detection model.

6. An abnormal computing power detection device applied in a computing power optical network, characterized in that, The method comprises the following steps: a synchronization unit configured to synchronize log data sets of each client computing power node to a server aggregation node, wherein one client computing power node corresponds to one log data; The cleaning unit is configured to perform data cleaning and word segmentation processing on each log data to generate a log vocabulary table, and obtain a log vocabulary table set; The first input unit is configured to input the log vocabulary table set into a pre-trained time sequence relationship capturing model to obtain a time sequence relationship set, wherein one log vocabulary table set corresponds to one time sequence relationship; The training unit is configured to train an initial computing power node anomaly detection model according to each client computing power node, and obtain a trained computing power node anomaly detection model; The second input unit is configured to input the log data set and the time sequence relationship set into the computing power node anomaly detection model to obtain an abnormal computing power node detection result.

7. An electronic device, comprising: comprising: one or more processors; a memory device having stored thereon one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 5.

8. A computer readable medium characterized by a computer program is stored thereon, wherein the computer program is executed by a processor to implement the method according to any one of claims 1 to 5.