Order-based business system exception root cause positioning method and device and electronic equipment
By performing image format conversion, spatiotemporal reconstruction, and anomaly prediction and recognition on multidimensional data from the order business system, an anomaly causal dependency graph is generated, which solves the problem of low anomaly detection accuracy in the order business system and improves the system's stability and performance.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- PARK DO CREDIT CO LTD
- Filing Date
- 2025-09-15
- Publication Date
- 2026-05-12
AI Technical Summary
Existing technologies for anomaly root cause localization in order business systems suffer from low anomaly detection accuracy, excessive redundant data, and slow localization speed. This is mainly because the internal relationships of high-dimensional time-series data are not detected, and the dependency graph does not consider temporal causal relationships.
By acquiring multidimensional business datasets, image format conversion, spatiotemporal reconstruction anomaly identification, and anomaly prediction identification are performed to generate an anomaly causal dependency graph. Combined with the anomaly root cause report generation model, dynamic adjustments are made to improve the accuracy of anomaly detection and the speed of root cause localization.
It improved the accuracy of anomaly detection and the speed of root cause localization in the order processing system, enhanced the system's stability and performance, and reduced system losses.
Smart Images

Figure CN121095591B_ABST
Abstract
Description
Technical Field
[0001] The embodiments disclosed herein relate to the field of computer technology, and more specifically to an anomaly root cause localization method, apparatus, and electronic device based on an order business system. Background Technology
[0002] With the development of computer technology, various systems are constantly emerging. A system typically undertakes various data processing tasks, making anomaly detection and root cause determination increasingly important to improve system stability and reduce losses. For anomaly root cause localization in order processing systems, the common approach is as follows: A variational autoencoder is used to reconstruct and detect anomalies in the acquired system dataset, obtaining a system anomaly information set. Then, a dependency graph of the system data is generated. Finally, a random walk algorithm is used to perform root cause analysis on the dependency graph, obtaining an anomaly root cause information set.
[0003] However, in practice, it has been found that when using the above method to locate the root cause of anomalies in the order business system, the following technical problems often occur: First, since the system dataset is high-dimensional time-series data containing various correlation indicators, reconstructing anomaly detection only through variational autoencoders cannot detect the internal correlations of the data, resulting in low anomaly detection accuracy. Second, the dependency graph only extracts the dependencies between system data without considering the temporal causal relationships between system data, resulting in a large amount of erroneous and redundant data in the generated anomaly root cause information, leading to low anomaly root cause location accuracy. Consequently, it takes a long time to locate anomalies in the system, resulting in low anomaly root cause location speed and reduced system stability and performance.
[0004] The information disclosed in this background section is only intended to enhance the understanding of the background of the present disclosure concept, and therefore may contain information that does not constitute prior art known to those skilled in the art. Summary of the Invention
[0005] The summary portion of this disclosure is intended to provide a brief overview of the concepts, which will be described in detail in the detailed description portion. This summary portion is not intended to identify key or essential features of the claimed technical solutions, nor is it intended to limit the scope of the claimed technical solutions.
[0006] Some embodiments of this disclosure propose methods, apparatus, and electronic devices for locating the root causes of anomalies in an order business system to solve one or more of the technical problems mentioned in the background section above.
[0007] In a first aspect, some embodiments of this disclosure provide a method for anomaly root cause localization based on an order business system, comprising: acquiring a multidimensional business dataset of the order business system, wherein the multidimensional business data includes at least one of the following: order data, memory data, and bandwidth data; performing image format conversion on the multidimensional business dataset to obtain a business image dataset; performing spatiotemporal reconstruction anomaly identification on the multidimensional business dataset to obtain a business reconstruction anomaly identification information set; performing anomaly prediction identification on the business image dataset to obtain a business anomaly prediction information set; and generating a method for targeting the multidimensional business data based on the business reconstruction anomaly identification information set and the business anomaly prediction information set. The system generates a business anomaly dataset; it performs indicator correlation analysis on the aforementioned multidimensional business dataset to obtain an anomaly correlation indicator dataset that is related to the aforementioned business anomaly dataset; based on the aforementioned anomaly correlation indicator dataset, it generates a business anomaly causal dependency graph of the aforementioned multidimensional business dataset; based on the aforementioned business anomaly causal dependency graph, it performs second-order anomaly root cause localization on the aforementioned business anomaly dataset to obtain a business anomaly root cause information set; it inputs the aforementioned business anomaly dataset and the aforementioned business anomaly root cause information set into an anomaly root cause report generation model to obtain a business anomaly root cause report, and based on the aforementioned business anomaly root cause report, it dynamically adjusts the aforementioned order business system.
[0008] Secondly, some embodiments of this disclosure provide an anomaly root cause localization device based on an order business system, comprising: an acquisition unit configured to acquire a multidimensional business dataset of the order business system, wherein the multidimensional business data includes at least one of the following: order data, memory data, and bandwidth data; an image format conversion unit configured to perform image format conversion on the multidimensional business dataset to obtain a business image dataset; a spatiotemporal reconstruction anomaly identification unit configured to perform spatiotemporal reconstruction anomaly identification on the multidimensional business dataset to obtain a business reconstruction anomaly identification information set; an anomaly prediction identification unit configured to perform anomaly prediction identification on the business image dataset to obtain a business anomaly prediction information set; and a first generation unit configured to generate, based on the business reconstruction anomaly identification information set and the business anomaly prediction information set, a first generation unit. The system includes: a business anomaly dataset for the aforementioned multidimensional business dataset; an indicator correlation analysis unit configured to perform indicator correlation analysis on the aforementioned multidimensional business dataset to obtain an anomaly-related indicator dataset that is correlated with the aforementioned business anomaly dataset; a second generation unit configured to generate a business anomaly causal dependency graph of the aforementioned multidimensional business dataset based on the aforementioned anomaly-related indicator dataset; an anomaly root cause localization unit configured to perform second-order anomaly root cause localization on the aforementioned business anomaly dataset based on the aforementioned business anomaly causal dependency graph to obtain a business anomaly root cause information set; and a dynamic adjustment unit configured to input the aforementioned business anomaly dataset and the aforementioned business anomaly root cause information set into an anomaly root cause report generation model to obtain a business anomaly root cause report, and to dynamically adjust the aforementioned order business system based on the aforementioned business anomaly root cause report.
[0009] Thirdly, some embodiments of this disclosure provide an electronic device, including: one or more processors; and a storage device having one or more programs stored thereon, such that when the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any implementation of the first aspect.
[0010] Fourthly, some embodiments of this disclosure provide a computer-readable medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the method as described in any of the implementations of the first aspect.
[0011] The above embodiments of this disclosure have the following beneficial effects: The anomaly root cause localization method based on the order business system in some embodiments of this disclosure can quickly discover anomaly information in the order business system, improve the speed of root cause localization, and improve the stability and performance of the order business system. Specifically, the reasons for the low speed of related anomaly root cause localization and the reduction of system stability and performance are as follows: Since the system dataset is high-dimensional time-series data containing various index correlations, only using variational autoencoder to reconstruct anomaly detection cannot detect the internal correlation of data, resulting in low anomaly detection accuracy. Furthermore, the dependency graph only extracts the dependency relationships between system data, without considering the temporal causal relationships between system data, resulting in a large amount of erroneous redundant data in the generated anomaly root cause information, leading to low anomaly root cause localization accuracy. Consequently, it takes a long time to localize anomalies in the system, resulting in low anomaly root cause localization speed and reduced system stability and performance. Based on this, the anomaly root cause localization method based on the order business system in some embodiments of this disclosure can first obtain a multi-dimensional business dataset of the order business system, wherein the multi-dimensional business data includes at least one of the following: order data, memory data, and bandwidth data. Here, the multi-dimensional business dataset is used for subsequent anomaly detection and identification. Secondly, the aforementioned multidimensional business dataset undergoes image format conversion to obtain a business image dataset. Here, converting one-dimensional data into two-dimensional data allows for a more comprehensive extraction of feature information from different dimensions of the time-series data. Next, spatiotemporal reconstruction anomaly identification is performed on the aforementioned multidimensional business dataset to obtain a business reconstruction anomaly identification information set. Here, since normal data constitutes a significant proportion of the multidimensional business data, historical global reconstruction is performed on the multidimensional business data. Data with significant differences between the reconstructed and original data is identified as anomalous data, thus capturing the overall distribution of the multidimensional business data and improving the accuracy of anomaly detection. Following this, anomaly prediction identification is performed on the aforementioned business image dataset to obtain a business anomaly prediction information set. Here, anomaly prediction identification predicts data for future times, capturing local nonlinear information in the multidimensional business data and improving the accuracy of anomaly detection. Subsequently, based on the aforementioned business reconstruction anomaly identification information set and the aforementioned business anomaly prediction information set, a business anomaly dataset is generated for the aforementioned multidimensional business dataset. Here, the reconstruction and prediction anomaly detection methods are combined for detection; the two methods complement each other, further improving the accuracy of anomaly detection and reducing false positives and false negatives. Next, an indicator correlation analysis is performed on the aforementioned multidimensional business dataset to obtain an anomaly correlation indicator dataset that is related to the aforementioned business anomaly dataset. Here, the correlation between business anomaly data can be accurately extracted, facilitating subsequent causal generation. Then, based on the aforementioned anomaly correlation indicator dataset, a business anomaly causal dependency graph of the aforementioned multidimensional business dataset is generated.Here, further extracting the causal relationships between multi-dimensional business data can reduce the data volume of the business anomaly causal dependency graph and lower the load on the order business system. Then, based on the aforementioned business anomaly causal dependency graph, second-order anomaly root cause localization is performed on the aforementioned business anomaly dataset to obtain a business anomaly root cause information set. This improves the accuracy of anomaly root cause localization, shortens the time required to accurately locate the root cause of anomalies, and increases localization efficiency. Finally, the aforementioned business anomaly dataset and the aforementioned business anomaly root cause information set are input into the anomaly root cause report generation model to obtain a business anomaly root cause report, and based on the aforementioned business anomaly root cause report, the aforementioned order business system is dynamically adjusted. Here, the business anomaly root cause report can improve user experience and provide a comprehensive understanding of anomalies, shorten the dynamic adjustment time of the system due to anomalies, improve system stability and performance, and reduce system losses. Therefore, this method for locating the root cause of anomalies in an order business system can improve the accuracy of anomaly detection by performing pre-anomaly detection based on reconstruction and prediction of multi-dimensional business data. Furthermore, by locating the root cause through the anomaly detection results, adjustments can be made to the order business system. This method can identify problems in the system in advance, improve the accuracy of root cause location, and enhance system performance and stability. Attached Figure Description
[0012] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and elements are not necessarily drawn to scale.
[0013] Figure 1 This is a flowchart of some embodiments of the anomaly root cause localization method based on the order business system disclosed herein;
[0014] Figure 2 This is a schematic diagram of the structure of some embodiments of the anomaly root cause localization device based on the order business system disclosed herein;
[0015] Figure 3 This is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present disclosure. Detailed Implementation
[0016] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.
[0017] It should also be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described in this disclosure can be combined with each other.
[0018] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.
[0019] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0020] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.
[0021] This disclosure will now be described in detail with reference to the accompanying drawings and embodiments.
[0022] Figure 1 A flow 100 of some embodiments of the anomaly root cause localization method for an order-based business system according to the present disclosure is shown. The anomaly root cause localization method for an order-based business system includes the following steps:
[0023] Step 101: Obtain the multidimensional business dataset of the order business system.
[0024] In some embodiments, the execution entity (e.g., an electronic device) of the above-described anomaly root cause localization method based on the order business system can obtain the multidimensional business dataset of the order business system through a wired or wireless connection, wherein the multidimensional business data is time-series data. The aforementioned order business system may be an order system used to store and process credit information related to users and enterprises. The multidimensional business data in the aforementioned multidimensional business dataset may be different types of data generated by the order business system. For example, the aforementioned multidimensional business dataset may include, but is not limited to, at least one of the following: memory information, system bandwidth information, system response information, system order information, order turnover information, and order conversion rate information.
[0025] Step 102: Convert the image format of the multidimensional business dataset to obtain the business image dataset.
[0026] In some embodiments, the aforementioned execution entity can perform image format conversion on the aforementioned multidimensional business dataset to obtain a business image dataset. The business image data in the aforementioned business image dataset can be images representing the feature information of the multidimensional business data in image form. The aforementioned business image data can have the horizontal axis representing the time series length and the vertical axis representing data of different dimensions. In practice, the aforementioned execution entity can use a time series imaging method (series2img) to perform image format conversion on the aforementioned multidimensional business dataset to obtain the business image dataset. It should be noted that image format conversion can transform a one-dimensional time-series format multidimensional business dataset into a two-dimensional image format business image dataset, which can improve the extraction of different dimensional features of the time-series data and enhance the feature extraction and anomaly detection capabilities for subsequent spatiotemporal reconstruction anomaly identification.
[0027] Step 103: Perform spatiotemporal reconstruction anomaly identification on the multidimensional business dataset to obtain a business reconstruction anomaly identification information set.
[0028] In some embodiments, the aforementioned execution entity may perform spatiotemporal reconstruction anomaly identification on the aforementioned multidimensional business dataset to obtain a business reconstruction anomaly identification information set. The business reconstruction anomaly identification information in the aforementioned business reconstruction anomaly identification information set may be business image data where, after data reconstruction of the business image data, the similarity difference between the reconstructed data and the original business image data is greater than or equal to a preset similarity threshold. The preset similarity threshold may be a pre-set critical value used to determine whether the business image data is abnormal data.
[0029] In some optional implementations of certain embodiments, the above-mentioned spatiotemporal reconstruction anomaly identification of the multidimensional business dataset to obtain a business reconstruction anomaly identification information set may include the following steps:
[0030] The first step involves inputting the aforementioned multidimensional business dataset into the first convolutional extraction network of the reconstructed spatial feature extraction network to obtain a first business spatial feature vector set. This reconstructed spatial feature extraction network further includes a second convolutional extraction network and a fully connected layer. The reconstructed spatial feature extraction network can be a deep neural network that extracts spatial dependencies and local patterns from the input multidimensional business dataset. The first convolutional extraction network can be a convolutional neural network that uses filters to perform one-dimensional convolutions on the input multidimensional business dataset along the time series to process and analyze the multidimensional spatial features at each time point. The first convolutional extraction network can include a convolutional layer with a 3*1 kernel and a 2*2 time-step-based global max pooling layer with a Tanh (Hyperbolic Tangent) activation function. The second convolutional extraction network can be a convolutional neural network with the same network structure as the first convolutional extraction network, but with different inputs and outputs.
[0031] The second step is to input the first business space feature vector set into the second convolutional extraction network to obtain the second business space feature vector set.
[0032] The third step is to input the second service space feature vector set into the fully connected layer to obtain the third service space feature vector set.
[0033] The fourth step involves inputting the aforementioned multidimensional business dataset into the forward long short-term memory neural network included in the reconstructed time feature extraction network to obtain the first business time feature vector set. The reconstructed time feature extraction network also includes a backward long short-term memory neural network. The reconstructed time feature extraction network can be a deep neural network with a bidirectional structure, which facilitates capturing the forward and backward temporal dependencies of the business image dataset to extract comprehensive time features.
[0034] The fifth step is to input the first business time feature vector set into the inverse long short-term memory neural network to obtain the second business time feature vector set.
[0035] The sixth step involves using an attention mechanism to fuse the third business space feature vector set and the second business time feature vector set, resulting in a business spatiotemporal fusion feature vector set. This attention mechanism can be a dynamic adjustment mechanism that adjusts the level of attention given to different features in the input third business space feature vector set and the second business time feature vector set. The feature fusion can be a weighted summation of the third business space feature vector set and the second business time feature vector set.
[0036] Step 7: Input the aforementioned business spatiotemporal fusion feature vector set into the time-gated encoder included in the business spatiotemporal feature reconstruction coding network to obtain the business temporal latent feature vector set. The business spatiotemporal feature reconstruction coding network further includes a business-aware decoder. The business spatiotemporal feature reconstruction coding network can be a deep neural network that performs spatiotemporal feature reconstruction on the input business spatiotemporal fusion feature vector set. The time-gated encoder can be an encoder that maps the business spatiotemporal fusion feature vector set to a latent representation, i.e., a business temporal latent feature vector set, to estimate the latent spatial distribution information of the business spatiotemporal fusion feature vector set, and further extract the temporal features of the business spatiotemporal fusion feature vector set. For example, the time-gated encoder can be a GRU (Gate Recurrent Unit) network. The business temporal latent feature vectors in the business temporal latent feature vector set can characterize the business spatiotemporal fusion feature vectors. The business-aware decoder can be a deep neural network that remaps the input business temporal latent feature vector set back to the original space, i.e., the space where the business spatiotemporal fusion feature vector set resides, to achieve data reconstruction. For example, the business-aware decoder can be a multilayer perceptron.
[0037] The eighth step is to input the above-mentioned business time-series potential feature vector set into the business-aware decoder to obtain a multi-dimensional business reconstruction dataset, which serves as the business reconstruction anomaly identification information set.
[0038] Step 104: Perform anomaly prediction and identification on the business image dataset to obtain a business anomaly prediction information set.
[0039] In some embodiments, the aforementioned execution entity may perform anomaly prediction and identification on the aforementioned business image dataset to obtain a business anomaly prediction information set. The business anomaly prediction information in the aforementioned business anomaly prediction information set may be business image data that deviates from the data distribution pattern of the business image dataset.
[0040] Furthermore, in the process of adopting technical solutions to address the technical problems mentioned in the background, the following technical issues often arise: Since the business image dataset contains multi-dimensional time-series data, anomaly prediction and identification primarily focus on dependencies at the capture time, leading to low accuracy in anomaly identification, reduced stability and security of the order business system, and increased system loss rate. A conventional solution to these technical problems is to use a two-dimensional Transformer model to perform anomaly identification on the business image dataset, obtaining a business anomaly prediction information set. However, this conventional solution still has the following problems: The Transformer's self-attention mechanism requires calculating the attention score of each element and all other elements in the sequence, but some elements have low influence rates and can be disregarded, resulting in a large amount of computation, wasting significant computing resources, and reducing the speed and efficiency of anomaly identification. Considering the shortcomings of conventional solutions, and combined with the company's advantages / current state of anomaly prediction and identification technology, we decided to adopt the following solution:
[0041] In some optional implementations of certain embodiments, the above-described anomaly prediction and identification of the business image dataset to obtain a business anomaly prediction information set may include the following steps:
[0042] The first step involves embedding the aforementioned business image dataset to obtain a set of business visual feature vectors. These business visual feature vectors characterize the local spatial correlations of the business image dataset. In practice, the execution entity can first divide each business image data in the dataset into blocks to generate a set of block-based business image data. Then, a fully connected layer is used to linearly project this set of block-based business image data onto the hidden layer dimension of the model, resulting in the set of business visual feature vectors.
[0043] The second step involves performing positional encoding on each business visual feature vector in the aforementioned business visual feature vector set to obtain a business positional encoding vector set. The business positional encoding vectors in this set characterize the encoder's understanding of the temporal context of the input business visual feature vector set within the business sequence, thus representing the positional information of the business visual feature vector within the set. In practice, the execution entity can perform the following determination steps for each business visual feature vector in the aforementioned business visual feature vector set: First, in response to determining that the positional order of the business visual feature vector in the aforementioned business visual feature vector set is an integer multiple of 2, the dot product of the positional order and the number of business visual feature vectors included in the aforementioned business visual feature vector set is determined as the first sine position value. Next, the embedding dimension of the aforementioned business visual feature vector is determined, along with the dot product of a function base 10000 and the ratio of the dot product of 2 and each dimension of the business visual feature vector to the embedding dimension, as the second sine position value, resulting in a second sine position value set. Finally, the sine function value representing the ratio of the first sine position value set to the second sine position value set is determined as the business positional encoding vector. Then, in response to determining that the positional order of the aforementioned business visual feature vectors in the aforementioned business visual feature vector set is not an integer multiple of 2, the dot product of the positional order and the number of business visual feature vectors included in the aforementioned business visual feature vector set is determined as the first cosine position value. The dot product of the embedding dimension of the aforementioned business visual feature vectors and the exponential function value of the ratio of the dot product of each dimension of the business visual feature vector to the embedding dimension (base 10000) is determined as the second cosine position value, resulting in the second cosine position value set. The cosine function value of the ratio of the first cosine position value and the second cosine position value is determined as the business position encoding vector set.
[0044] It should be noted that the location encoding process, by incorporating the number of business visual feature vectors included in the business visual feature vector set into the sine and cosine functions, maintains the smoothness and monotonicity of the dot product even as the number of business visual feature vectors in the set increases. This allows for a more accurate reflection of distance differences between locations, maintaining a clear distance perception even between distant locations. Furthermore, by adding the embedding dimension of the aforementioned business visual feature vectors to the sine and cosine functions, anisotropy caused by sampling from low-frequency sine functions at high embedding dimensions can be reduced. This decreases the similarity between business visual feature vectors, enabling location encoding to more effectively utilize the embedding vector space to distinguish different locations, thereby reducing anisotropy.
[0045] The third step is to perform feature fusion on the above-mentioned business location encoding vector set and the above-mentioned business visual feature vector set to obtain the business fusion feature vector set.
[0046] The fourth step involves inputting the aforementioned business fusion feature vector set into the multi-head sparse self-attention mechanism layer of the business sequence encoder to obtain a business-intra-sequence sparse feature vector set. This business sequence encoder further includes multiple residual connections and normalization layers, and multiple feedforward neural networks. The business sequence encoder can be a deep neural network that extracts intra-type temporal dependencies and intra-type dependencies from input business fusion feature vectors of the same type. The business sequence encoder can be a Transformer model consisting of a cascaded multi-head sparse self-attention mechanism layer, multiple residual connections and normalization layers, and multiple feedforward neural networks. The multi-head sparse self-attention mechanism layer can be a self-attention mechanism layer that selects the top-K attention weights and performs a weighted summation. The top-K can be determined based on specific circumstances and is not limited here. The aforementioned business-intra-sequence sparse feature vector set can be obtained through the following steps: First, perform a first linear transformation on the business fusion feature vector set to obtain a key matrix set. Second, perform a second linear transformation on the business fusion feature vector set to obtain a value matrix set. Finally, perform a third linear transformation on the aforementioned business location encoding vector set and the business fusion feature vector set to obtain a query matrix. Next, the transposes of the query matrix and key matrix are multiplied and scaled to obtain the initial attention weight set. Then, the top-K initial attention weights are selected from the initial attention weight set as the target attention weight set. Next, the target attention weight set is normalized to obtain the attention weight set. Finally, the attention weight set and the value matrix set are weighted and summed to obtain the business-specific sparse feature vector set. The multiple residual connections and normalization layers mentioned above can be the Add&Norm (Residual Connection&LayerNorm) layers in the Transformer. There can be up to four of these layers.
[0047] The fifth step involves sequentially inputting the aforementioned sparse feature vector set of services into the aforementioned residual connections and normalization layers and the aforementioned feedforward neural networks to obtain the time-series feature vector set of services within the sequence.
[0048] The sixth step is to perform feature transpose processing on the above-mentioned business visual feature vector set to obtain the transposed business visual feature vector set. The transposed business visual feature vectors in the transposed business visual feature vector set can be feature vectors obtained by transposing the horizontal and vertical axes of the business visual feature vectors.
[0049] Step 7: Input the transposed service visual feature vector set into the inter-sequence multi-head self-attention mechanism layer of the inter-sequence encoder to obtain the inter-sequence feature vector set. The intra-sequence encoder and the inter-sequence encoder are executed concurrently. The inter-sequence encoder further includes multiple residual connections and normalization layers, and multiple feedforward neural networks. The inter-sequence encoder can be a deep neural network that performs feature vector dependency correlation between different types of transposed service visual feature vector sets (e.g., system memory data, system bandwidth data, system response data). Alternatively, the inter-sequence encoder can be a deep neural network that replaces the scaling factor of the existing Transformer's self-attention mechanism with the arithmetic square root of the number of different dimensions included in the service image data, and omits the position encoding step.
[0050] The eighth step involves sequentially inputting the aforementioned inter-service feature vector set into multiple residual connections and normalization layers and multiple feedforward neural networks to obtain the inter-sequence service time-series feature vector set.
[0051] The ninth step involves concatenating the intra-sequence business time-series feature vector sets and inter-sequence business time-series feature vector sets to obtain a business sequence association feature vector set. The business sequence association feature vectors in this set represent both the preservation of intra-type associations and the capture of inter-type dependencies, thus predicting the output for future time steps.
[0052] Step 10 involves inputting the aforementioned business sequence-related feature vector set into the fully connected layer to obtain a business anomaly prediction information set, and then dynamically adjusting the order business system based on this information set. For details on the implementation of this step, please refer to steps 105-109.
[0053] The above formula and related content, as an inventive point of this disclosure, solve the technical problem mentioned in the background art: "Since the business image dataset includes time-series data with multiple dimensions, the dependence on capture time is mainly focused during anomaly prediction and identification, resulting in low accuracy of anomaly identification, low stability and security of the order business system, and increased system loss rate." Solving these factors can improve the accuracy of anomaly identification, enhance the stability and security of the order business system, and reduce the system loss rate. To achieve this effect, this disclosure first performs data embedding and positional encoding on the business image dataset, which can improve the accuracy of the generated feature vectors. Positional encoding, by adding the number and embedding dimension of the included business visual feature vectors to the cosine or sine function, enables the positional encoding to accurately perceive distance differences and anisotropic phenomena. Next, a multi-head coefficient self-attention mechanism is applied to the business fusion feature vector set, which can reduce the computation of elements with low influence, focusing only on the top-K elements, thus reducing computational load and speed. Then, feature extraction is performed on the business coefficient feature vector set both within and between sequences. This preserves the correlation within sequences and captures the dependencies between sequences, improving the cross-dimensional information and temporal sequence of the feature vectors. Finally, after concatenating the feature vectors between and within sequences to achieve anomaly identification, the order business system is dynamically adjusted. This improves the accuracy of anomaly identification, allows for early identification and adjustment of the causes of system anomalies, enhances system stability and security, and reduces losses caused by system anomalies.
[0054] Step 105: Generate a business anomaly dataset for the multidimensional business dataset based on the business reconstruction anomaly identification information set and the business anomaly prediction information set.
[0055] In some embodiments, the execution entity can generate a business anomaly dataset for the multidimensional business dataset based on the business reconstruction anomaly identification information set and the business anomaly prediction information set. The business anomaly data in the business anomaly dataset can be multidimensional business data existing only in the business reconstruction anomaly identification information set and also in the business anomaly prediction information set. As an example, the execution entity can first determine the Euclidean distance between each business reconstruction anomaly identification information in the business reconstruction anomaly identification information set and the corresponding business image data in the business image dataset, as a reconstruction distance value set; and determine the Euclidean distance between each business anomaly prediction information in the business anomaly prediction information set and the corresponding business image data in the business image dataset, as a prediction distance value set. Then, an anomaly similarity threshold is determined using the POT algorithm (Peaks-Over-Threshold). Finally, the first weight values of the reconstruction distance value set and the prediction distance value set are determined using the entropy weight method. Subsequently, the sum of the products of the first weight value and each reconstructed distance value in the reconstructed distance value set, and the sum of the products of the second weight value and each predicted distance value in the predicted distance value set are determined, and these sums are used as the anomaly value set. Finally, at least one business image data with anomaly values greater than or equal to the anomaly similarity threshold is selected from the above business image dataset and used as the business reconstruction anomaly identification information set.
[0056] Step 106: Perform indicator correlation analysis on the multidimensional business dataset to obtain an abnormal correlation indicator dataset that is related to the business abnormal dataset.
[0057] In some embodiments, the aforementioned executing entity can perform indicator correlation analysis on the aforementioned multidimensional business dataset to obtain an anomaly-related indicator dataset that is correlated with the aforementioned business anomaly dataset. The anomaly-related indicator data in the anomaly-related indicator dataset can be multidimensional business data that is correlated with the business anomaly data. In practice, the aforementioned executing entity can utilize the FP-Growth algorithm to perform indicator correlation analysis on the multidimensional business dataset to obtain an anomaly-related indicator dataset that is correlated with the aforementioned business anomaly dataset.
[0058] In some optional implementations of certain embodiments, the above-mentioned indicator correlation analysis of the multidimensional business dataset to obtain an abnormal correlation indicator dataset that is correlated with the above-mentioned business abnormal dataset may include the following steps:
[0059] The first step is to randomly generate a set of business association rules based on the aforementioned business anomaly dataset and multidimensional business dataset. The business association rule in this set can be a single rule randomly selected from the aforementioned business anomaly dataset and multidimensional business dataset. For example, the business association rule could be the rule {abnormal order volume} → {low order conversion rate}. The business association rule includes four parts: whether the attribute from the aforementioned business anomaly dataset and multidimensional business dataset is in the business association rule, the position of the attribute in the business association rule, and the value range of the attribute. As an example, the executing entity can randomly select the attribute set, the antecedent and consequent of the association rule, and the value range set from the aforementioned business anomaly dataset and multidimensional business dataset to obtain the business association itemset.
[0060] The second step involves vector encoding the aforementioned business association rule set to obtain a business association rule vector set, which serves as the initial business rule population. The business association rules in this vector set can be represented by feature vectors. These business association rule vectors can be {EN_j, AC_j, LB_j, UB_j}. EN_j indicates whether the j-th attribute exists in the business association rule; EN_j = 1 indicates existence, and EN_j = 0 indicates non-existence. AC_j indicates whether the j-th attribute belongs to the antecedent or consequent in the business association rule; AC_j = 1 indicates the j-th attribute belongs to the antecedent, and AC_j = 0 indicates the j-th attribute belongs to the consequent. LB_j and UB_j can represent the lower and upper bounds of the interval for the j-th attribute, respectively. For example, the business association rule vector could be {1, 0, 127, 0.75}. Each initial business rule in the initial business rule population can represent a business association rule.
[0061] The third step involves generating a set of population fitness functions for the initial population of business rules. This set includes: a population confidence function, a population understandability function, a population attribute amplitude function, and a population maximum information coefficient function. The population confidence function represents the probability that the consequent will be true when the antecedent is true in a business association rule. The population understandability function is the ratio of the number of consequent attributes to the total number of attributes in a business association rule; shorter rules are easier to understand, while longer rules are more likely to contain unimportant or redundant information, making the business association rule inaccurate, unreliable, and lacking in value. The population attribute amplitude function is the ratio of the interval width to the attribute value range; it measures the average size of the value interval for each attribute in the business association rule, with smaller amplitudes indicating more accurate, reliable, and meaningful business association rules. The maximum information coefficient function measures the linear and non-linear correlations between attributes.
[0062] The fourth step is to input the initial business rule population into the population fitness function set to obtain the initial fitness set of business individuals.
[0063] The fifth step involves generating an initial external archive of the initial population and selected target initial business rule individuals based on the aforementioned initial fitness set of business individuals. The initial external archive can be a data table used to store non-dominated solutions, i.e., Pareto optimal solutions, generated in each iteration. Pareto optimal solutions are non-dominated in terms of population confidence function, population comprehensibility function, population attribute amplitude function, and population maximum information coefficient function. For example, A dominating B can mean that initial business rule individual A is not superior to initial business rule individual B in terms of population confidence function, population comprehensibility function, population attribute amplitude function, and population maximum information coefficient function, and is at least larger than B in one initial fitness value.
[0064] As an example, the aforementioned execution entity can first, for each initial business rule individual included in the aforementioned initial business rule population, select at least one initial business rule individual from the initial business rule population whose corresponding initial fitness group is greater than or equal to the initial fitness group of the business individual corresponding to the initial business rule individual, thus obtaining an initial dominant business rule sub-cluster; and select at least one initial business rule individual from the initial business rule population whose corresponding initial fitness group is less than the initial fitness group of the aforementioned initial business rule individual, thus obtaining an initial dominated business rule sub-cluster. Next, select at least one initial business rule individual from the aforementioned initial dominant business rule sub-cluster that is an empty set, thus obtaining a first target dominant initial business rule population. Subsequently, determine at least one initial business rule individual whose initial dominated business rule sub-cluster, corresponding to each initial business rule individual included in the first target dominant initial business rule population, has an empty number of initial business rule individuals minus 1, as a second target dominant initial business rule population. Repeat this step until each initial business rule individual is assigned to a target dominant initial business rule population, thus obtaining a target dominant initial business rule population. Next, the population crowding degree of each target-dominated initial business rule population in the target-dominated initial business rule population cluster is determined, resulting in a population crowding degree set. Population crowding degree characterizes the individual distribution density of the target-dominated initial business rule population. In practice, the aforementioned execution entity can perform the following population crowding degree determination steps for each target-dominated initial business rule population in the target-dominated initial business rule population cluster: First, determine the order of the target-dominated initial business rule population using a fast non-dominated sorting algorithm, obtaining a sequence of target initial business rule individuals. Second, determine the target difference between the next target initial business rule individual and the previous target initial business rule individual in each target initial business rule individual sequence, obtaining a target difference set, which serves as the individual crowding degree set. Third, normalize the individual crowding degree set to obtain a normalized individual crowding degree set, and determine the sum of the normalized individual crowding degree sets as the population crowding degree. Finally, the initial business rule population for the first target domination is stored in an external archive, resulting in the initial population external archive. The initial business rule individual with the highest individual crowding is selected from the initial business rule population for the first target domination and used as the selected target initial business rule individual. Sixth step: Based on the initial business rule population, the following determination steps are performed:
[0065] Sub-step 1 involves updating the initial business rule population based on the number of executions of the aforementioned determination steps, a preset execution threshold, the filtered target initial business rule individuals, and an external archive adjustment factor, resulting in an updated business rule population. The preset execution threshold can be a pre-defined maximum number of executions of the determination steps. The external archive adjustment factor measures the global and local search capabilities of the initial business rule individuals included in the initial business rule population. When the number of executions is 1, the external archive adjustment factor is 0.7.
[0066] Sub-step 2 involves inputting the updated business rule population into the aforementioned population fitness function set to obtain the updated fitness set for individual business rules.
[0067] Sub-step 3: Update the initial external population archive based on the fitness set of the business individuals to obtain the updated external population archive.
[0068] As an example, the aforementioned execution entity can update the initial population external archive according to the preset external archive update rules and the generation implementation method of the initial population external archive in step 5 above, based on the fitness set of the updated business individuals, to obtain the updated population external archive. The preset external archive update rules may include: First, if the updated business rule individual is dominated by any initial business rule individual included in the initial population external archive, then the updated business rule individual is added to the initial population external archive; Second, if the updated business rule individual dominates at least one initial business rule individual included in the initial population external archive, then the updated business rule individual replaces at least one initial business rule individual; Third, if the updated business rule individual and the initial business rule individuals included in the initial population external archive do not dominate each other, then the updated business rule individual is added to the initial population external archive.
[0069] Sub-step 4: In response to determining that the number of updated business rule individuals included in the updated external archive of the population is greater than or equal to a preset archive threshold, individual removal is performed on the updated external archive of the population to obtain a removed external archive. The preset archive threshold can be a pre-defined maximum value of individuals that the initial external archive of the population can include. The individual removal can be performed on the updated business rule individuals with the lowest individual crowding.
[0070] Sub-step 5 involves filtering the removed external archives to obtain target filtering business rule individuals. These target filtering business rule individuals can be the updated business rule individuals with the highest individual crowding from the removed external archives.
[0071] Sub-step 6: Based on the updated business rule population and the initial external population archive, update the external archive adjustment factor to obtain the updated external archive adjustment factor.
[0072] As an example, the aforementioned execution entity can first determine the convergence stability of the external archive after removing the updated business rules corresponding to the initial external archive by using the external archive convergence function, thus obtaining a convergence set.
[0073]
[0074] Wherein, C(X) i ,ND) represents the degree of convergence corresponding to the external archive convergence function. ρ(X) i X) represents the i-th individual X that removes the update business rule. i The degree of dominance of the initial business rule individual X included in the initial population external archive, i.e., the difference in the initial fitness group of the business individuals, takes a value in the range [0, 1]. i Let represent the i-th newly added initial business rule individual to the archive outside the initial population. X represents the individual located at X. i The initial business rule individuals previously added to the external archive of the initial population. ND represents the external archive of the initial population. f j (X i ) represents X i The initial fitness of the j-th business entity. j (X) represents the initial fitness of the j-th business individual in X. m represents the number of initial fitness values of business individuals included in the initial fitness group, which is 4. f jmax f represents the maximum initial fitness of at least one initial business rule individual included in the external archive of the initial population for the j-th business individual. jmin This represents the minimum initial fitness of at least one initial business rule individual included in the external archive of the initial population for the j-th business individual. X represents i Dominate X.
[0075] Then, the highest convergence value is selected from the set of convergence values to obtain the target convergence value. Next, the sum of the product of the exponential function value (base e, exponent of -2.24 and the target convergence value) and 4, and 1, is determined as the convergence denominator. Finally, the ratio of 1 to the convergence denominator is determined as the external archiving adjustment factor.
[0076] Sub-step 7: In response to determining that the number of executions is greater than or equal to the preset execution number threshold, the multiple multi-dimensional business data corresponding to the multiple updated business rule individuals included in the external archive of the updated population are identified as an abnormal correlation indicator dataset.
[0077] Optionally, after performing the following determination steps based on the initial business rule population, the above method may further include the following steps:
[0078] In response to the determination that the number of executions is less than the aforementioned preset execution threshold, the external archives after removal, the updated business rule population, the target filtered business rule individual, and the updated external archive adjustment factor are respectively determined as the initial external archive population, the initial business rule population, the filtered target initial business rule individual, and the external archive adjustment factor. The sum of the number of executions and the preset value is determined as the number of executions, and the above determination step is executed again. The preset value can be a pre-defined value. For example, the preset value can be 1.
[0079] In some optional implementations of certain embodiments, updating the initial business rule population based on the number of times the determination step has been executed, a preset execution number threshold, the individual target initial business rules after filtering, and an external archive adjustment factor to obtain an updated business rule population may include the following steps:
[0080] The first step is to perform the following update steps for each individual initial business rule included in the aforementioned initial business rule population:
[0081] Sub-step 1: Based on the aforementioned number of executions and the aforementioned preset execution threshold, determine the individual screening probability value and the update stage balance factor. The individual screening probability value represents the probability of an initial business rule individual being removed. The update stage balance factor represents the probability of the initial business rule population undergoing different update stages for population updates. These different update stages may include: a population exploration stage, a population development stage, and a population screening stage. The population exploration stage can be the update stage for individuals within the initial business rule population. The population development stage can be the population update resulting from the interactions between initial business rule individuals included in the initial business rule population. The population screening stage can be the stage for updating population diversity based on the probability of an initial business rule individual being removed.
[0082] As an example, the aforementioned execution entity can first determine the difference between the product of 0.1 and 0.05 and the number of executions, and the ratio to a preset execution count threshold, as the individual screening probability value. Secondly, it can determine the product of 1 and the difference between the ratio of the number of executions and twice the preset execution count threshold, and the initial update stage balance factor, as the update stage balance factor. The initial update stage balance factor can be a pre-set random number ranging from (0, 1).
[0083] Sub-step 2, in response to determining that the aforementioned initial business rule individual is an individual in the target initial business rule population, performs a first position update on the initial business rule individual based on the aforementioned external archive adjustment factor and the aforementioned number of executions, obtaining a first updated business rule individual. The target initial business rule population is a population generated based on the external archive adjustment factor and the initial business rule population. As an example, the executing entity can first determine the number of initial business rule individuals included in the aforementioned external archive adjustment factor and the aforementioned initial business rule population, using this as the stage update value. Secondly, it can determine multiple initial business rule individuals whose sequential position in the initial business rule population is less than or equal to the aforementioned stage update value as the target initial business rule population. Then, using the position update formula of the White Whale optimization algorithm in the exploration phase, it performs a first position update on the aforementioned initial business rule individual based on the aforementioned number of executions, obtaining a first updated business rule individual.
[0084] Sub-step 3: In response to determining that the initial business rule individual is an individual in the remaining initial business rule population, the initial business rule individual is updated in the second position according to the above-mentioned number of executions, the above-mentioned preset number of executions threshold and the filtered target initial business rule individual, to obtain the second updated business rule individual, wherein the above-mentioned remaining initial business rule population is the population obtained after removing the target initial business rule population from the initial business rule population.
[0085] As an example, the aforementioned execution entity can use the White Whale optimization algorithm to update the position formula during the development phase. Based on the aforementioned number of executions, the aforementioned preset execution number threshold, and the aforementioned filtered target initial business rule individual, the entity can perform a second position update on the aforementioned initial business rule individual to obtain the second updated business rule individual.
[0086] Sub-step 4 involves correcting the position of either the first updated business rule individual or the second updated business rule individual to obtain a first corrected business rule individual, which serves as the updated business rule individual. Specifically, the first corrected business rule individual in the first corrected business rule population can be obtained by detecting the updated value range of either the first or second updated business rule individual. If the updated value range is detected to exceed the value range of the corresponding initial business rule individual, it is corrected to an individual within the corresponding value range.
[0087] Sub-step 5: In response to determining that the individual screening probability value is greater than or equal to the update stage balance factor, the initial business rule individual is updated in a third position based on the individual screening probability value, the number of executions, and the preset execution threshold, resulting in the third-updated business rule individual. As an example, the executing entity can, in response to determining that the individual screening probability value is greater than or equal to the update stage balance factor, use the position update formula of the beluga optimization algorithm in the whale fall stage to update the initial business rule individual in a third position based on the individual screening probability value, the number of executions, and the preset execution threshold, resulting in the third-updated business rule population.
[0088] Sub-step 6: Correct the position of the third updated business rule individual to obtain the second corrected business rule individual, which will be used as the updated business rule individual.
[0089] Step 107: Generate a causal dependency graph of business anomalies based on the anomaly correlation index dataset.
[0090] In some embodiments, the aforementioned execution entity can generate a business anomaly causal dependency graph of the aforementioned multidimensional business dataset based on the aforementioned anomaly correlation index dataset. This business anomaly causal dependency graph can be a directed acyclic graph generated by constructing a relationship network from multiple multidimensional business data that have correlation and causal relationships.
[0091] As an example, the aforementioned execution entity can use a random walk algorithm to generate a causal dependency graph of business anomalies in the aforementioned multidimensional business dataset based on the aforementioned anomaly correlation index dataset.
[0092] In some optional implementations of certain embodiments, generating the business anomaly causal dependency graph of the multidimensional business dataset based on the aforementioned anomaly correlation index dataset may include the following steps:
[0093] The first step is to obtain a set of historical business anomaly root cause information that has the same anomaly type as the aforementioned business anomaly dataset. This set of historical business anomaly root cause information can contain hardware or software information that occurred before the current time and caused the order processing system to malfunction.
[0094] The second step involves fusing the aforementioned historical business anomaly root cause information set and the aforementioned anomaly correlation indicator dataset to obtain the target business anomaly indicator dataset. The target business anomaly indicator data in this dataset can be the anomaly indicator data resulting from the fusion of the historical business anomaly root cause information set and the aforementioned anomaly correlation indicator dataset. In practice, the executing entity can first perform data preprocessing and standardization on the aforementioned historical business anomaly root cause information set and the aforementioned anomaly correlation indicator dataset to obtain standardized historical business anomaly root cause information set and standardized anomaly correlation indicator dataset. Then, entity recognition and relation extraction are performed on the standardized historical business anomaly root cause information set and the standardized anomaly correlation indicator dataset to obtain root cause triplet sets and correlation indicator triplet sets. Finally, semantic fusion is performed on the root cause triplet sets and the correlation indicator triplet sets to obtain the target business anomaly indicator dataset.
[0095] The third step involves performing causal relationship analysis on the aforementioned target business anomaly indicator dataset to obtain a business anomaly causal dataset. The causal data in this dataset can be derived from target business anomaly indicator data that have causal relationships with each other within the target business anomaly indicator dataset. In practice, the executing entity can first utilize a causal random forest algorithm to perform causal relationship analysis on the target business anomaly indicator dataset to obtain the business anomaly causal dataset.
[0096] The fourth step is to determine the set of business processing components corresponding to the aforementioned dataset of anomaly-related indicators. These components can be physical or software components of the order business system corresponding to the anomaly-related indicator data. For example, the set of business processing components may include, but is not limited to, at least one of the following: virtual machines, switches, storage devices, system code defects, thread pool memory leaks, and interface configuration errors. In practice, the executing entity can first parse and process the system structure document information set of the order business system to obtain the system component set. Then, it can extract components from the historical business anomaly root cause information set to obtain the initial component set. Finally, through expert experience, the system component set and the initial component set are supplemented and corrected to obtain the business processing component set.
[0097] The fifth step involves constructing a correlation graph between the aforementioned business anomaly causal dataset and the aforementioned business processing flow component set, resulting in an anomaly indicator correlation causal graph. This anomaly indicator correlation causal graph can be a weighted directed acyclic graph. In practice, the executing entity can first construct an undirected graph from the business anomaly causal dataset, obtaining a business undirected graph. Next, edges corresponding to the business processing flow component set in the business undirected graph are deleted, resulting in a deleted business undirected graph. Then, edges corresponding to the historical business anomaly root cause information set in the deleted business undirected graph are added, resulting in an added business undirected graph. Then, the Peter-Clark (PC) algorithm is used to perform causal correlation analysis on the added business undirected graph, obtaining the anomaly indicator causal graph. Finally, the anomaly indicator causal graph and the anomaly correlation indicator dataset are matched, obtaining a matching result set. Finally, the population fitness function value set corresponding to at least one successfully matched result is normalized, determined as an edge weight value set, and added to the anomaly indicator causal graph, resulting in the anomaly indicator correlation causal graph.
[0098] Step 6: Add the above business processing component set to the above abnormal indicator correlation causal graph to obtain the business abnormality causal dependency graph.
[0099] Step 108: Based on the causal dependency graph of business anomalies, perform second-order anomaly root cause localization on the business anomaly dataset to obtain the business anomaly root cause information set.
[0100] In some embodiments, the aforementioned execution entity can perform second-order anomaly root cause localization on the aforementioned business anomaly dataset based on the aforementioned business anomaly causal dependency graph, thereby obtaining a business anomaly root cause information set. The business anomaly root cause information in the aforementioned business anomaly root cause information set can be information about the root cause of the anomaly obtained by tracing the cause of the business anomaly data. As an example, the aforementioned execution entity can use a random walk algorithm to perform second-order anomaly root cause localization on the aforementioned business anomaly dataset based on the aforementioned business anomaly causal dependency graph, thereby obtaining a business anomaly root cause information set.
[0101] Furthermore, in the process of adopting technical solutions to address the technical problems mentioned in the background, the following technical issues often arise: Due to the intricate relationships and multiple call metrics involved in the causal dependency graph of business anomalies, the root cause localization process is time-consuming, resulting in low accuracy and system stability. A conventional solution to these issues typically involves using a single-step random walk algorithm to perform second-order root cause localization on the aforementioned business anomaly dataset based on the causal dependency graph, thus obtaining the root cause information set. However, this conventional solution still suffers from the following problems: Root cause localization of the causal dependency graph only considers single-step dependencies, ignoring the impact of historical walks and upstream / downstream nodes on the anomaly propagation probability. Additionally, the presence of numerous nodes in the causal dependency graph leads to low accuracy in root cause localization, further prolonging the time required for dynamic system adjustments, increasing system loss rates, and reducing system stability and performance. Considering the shortcomings of the conventional solution and the advantages / current state of our company's root cause localization technology, we have decided to adopt the following solution:
[0102] In some optional implementations of certain embodiments, the above-mentioned second-order anomaly root cause localization of the above-mentioned business anomaly dataset based on the above-mentioned business anomaly causal dependency graph to obtain a business anomaly root cause information set may include the following steps:
[0103] The first step is to determine the initial weight value set of the target dependency edge set in the aforementioned business anomaly causal dependency graph. Here, the target dependency edges in the target dependency edge set are dependency edges without weight values. The initial weight values can be the mutual information between the two dependency nodes connected by the target dependency edge.
[0104] The second step is to add the initial set of weight values to the above business anomaly causal dependency graph to obtain the business anomaly directed weighted causal graph.
[0105] The third step involves determining the first-order anomaly propagation probability matrix of the aforementioned directed weighted causal graph of business anomalies, based on the set of dependency edge weight values. The first-order anomaly propagation probability values in this matrix characterize the anomaly propagation probability of a dependent node traversing to an adjacent dependent node with an in-degree dependency edge. For example, the executing entity can first determine the groups of dependent edges with in-degree to each dependent node in the aforementioned directed weighted causal graph of business anomalies, obtaining a target in-degree dependency edge group set. Then, it determines the sum of the dependency edge weight values corresponding to each target in-degree dependency edge group in the target in-degree dependency edge group set, obtaining a target in-degree edge weight value set. Finally, it determines the ratio of the dependency edge weight value of each target in-degree dependency edge in the target in-degree dependency edge group set to the target in-degree edge weight value of the target in-degree dependency edge group to which the target in-degree dependency edge belongs, as the anomaly propagation probability value, thus obtaining the first-order anomaly propagation probability matrix.
[0106] Fourth, for each business anomaly data point in the above business anomaly dataset, perform the following root cause localization steps:
[0107] Sub-step 1: Based on the first-order anomaly propagation probability matrix, perform a single-step forward random walk on the dependent nodes corresponding to the abnormal business data to obtain a forward walk node set. The forward walk nodes in this set can be dependent nodes that have an in-degree relationship with the dependent nodes corresponding to the abnormal business data. The node similarity value set corresponding to the abnormal business data can be a set of node similarity values between at least one dependent node that has an in-degree relationship with the dependent node corresponding to the abnormal business data and the abnormal dependent node. As an example, the execution entity can first filter out the node walk probability values from the node walk probability value set, selecting the top preset number of nodes in descending order of value, to obtain the target node walk probability value set. This preset number can be a predetermined value, for example, 10. Then, the dependent nodes corresponding to the target node walk probability value set are determined as the forward walk node set.
[0108] Sub-step 2: For each forward-walking node in the forward-walking node set, perform the following node walking steps:
[0109] The first sub-step involves performing a second-order forward walk on the forward walk nodes based on the out-degree node set and the first-order anomaly propagation probability matrix, resulting in a second-order forward walk probability value set. Here, the out-degree nodes in the out-degree node set can be dependent nodes that have an out-degree relationship with the forward walk nodes. The aforementioned second-order forward walk probability values can represent the probability that a forward walk node will continue walking along its out-degree nodes. As an example, the execution entity can first determine the first-order anomaly propagation probability values of the anomaly dependent nodes and forward walk nodes corresponding to the abnormal business data, as the first historical walk probability values. Then, it determines the first-order anomaly propagation probability values of each out-degree node and forward walk node in the out-degree node set, as the forward anomaly propagation probability value set. Finally, it determines the first and second weight values of the forward anomaly propagation probability value set and the first historical walk probability values. Finally, the sum of the product of the first weight value and each forward anomaly propagation probability value in the forward anomaly propagation probability value set, and the product of the second weight value and the first historical walk probability value, is determined to obtain the second-order forward walk probability value set.
[0110] The second sub-step, in response to determining that the set of second-order forward walk probability values is all less than or equal to a preset walk probability threshold, performs second-order reverse walk processing on the forward walk nodes based on the in-degree node set of the forward walk nodes and the first-order anomaly propagation probability matrix, obtaining a set of second-order reverse walk probability values. Here, the in-degree nodes in the in-degree node set can be dependent nodes that have an in-degree relationship with the forward walk nodes. The preset walk probability threshold can be a pre-set probability threshold for determining whether to perform a reverse or forward walk. For example, the preset walk probability threshold can be 0.6. As an example, the execution entity can first determine the first-order anomaly propagation probability values of the abnormal dependent nodes corresponding to the above-mentioned business anomaly data and the above-mentioned forward walk nodes, as the second historical walk probability values. Then, it determines the first-order anomaly propagation probability values of each in-degree node in the in-degree node set and the forward walk nodes, as the reverse anomaly propagation probability value set. Afterward, it determines the first reverse weight value and the second reverse weight value of the reverse anomaly propagation probability value set and the second historical walk probability value. Finally, the sum of the product of the first reverse weight value and each reverse anomaly propagation probability value in the reverse anomaly propagation probability value set, and the product of the second reverse weight value and the second historical walk probability value, is determined to obtain the second-order reverse walk probability value set.
[0111] The third sub-step, in response to determining that the set of second-order reverse walk probability values is all less than or equal to a preset walk probability threshold, determines the in-situ dwell probability value of the forward walk node, and identifies the forward walk node as the next walk node of the forward walk node. Here, the aforementioned in-situ dwell probability value can characterize the probability value of the forward walk node remaining in the forward walk node. In practice, the aforementioned executing entity can determine the in-situ dwell probability value as the difference between 1 and each second-order forward walk probability value in the second-order forward walk probability value set and each second-order reverse walk probability value in the second-order reverse walk probability value set.
[0112] The fourth sub-step is to determine, in response to the determination that there is at least one second-order forward walk probability value in the set of second-order forward walk probability values that is greater than the above-mentioned preset walk probability threshold, to determine the dependent node set corresponding to at least one second-order forward walk probability value as the next walk node of the forward walk node.
[0113] The fifth sub-step is to determine, in response to the determination that there is at least one second-order reverse walk probability value in the set of second-order reverse walk probability values that is greater than a preset walk probability threshold, to determine the set of dependent nodes corresponding to at least one second-order reverse walk probability value as the set of next walk nodes of the forward walk node.
[0114] Sub-step 4, in response to the root cause localization step's walk count being greater than or equal to a preset walk count threshold, generates a business anomaly root cause information set based on the node access path set, and dynamically adjusts the order business system based on the business anomaly root cause information set. The node access count set can be a set of node access paths formed by the dependent nodes corresponding to the aforementioned business anomaly data and the next walk node set corresponding to the preset walk count threshold. The preset walk count threshold can be a pre-set maximum value for random walks. For example, the preset walk count threshold can be 10. In practice, the executing entity can first determine the node access count set of each dependent node included in the node access path set. Secondly, it can sort the node access count set in descending order to obtain a node access count sequence. Then, it can filter out the multidimensional business datasets corresponding to the dependent nodes with the top preset number of node access counts from the node access count sequence, determining them as the business anomaly root cause information set. Finally, it can dynamically adjust the order business system based on the business anomaly root cause information set.
[0115] Fifth, in response to the fact that the number of walks in the root cause localization step is less than a preset walk threshold, the next walk node set is determined as the forward walk node set, and the sum of the walk count and the preset value is determined as the walk count, so as to execute the above root cause localization step again.
[0116] The above-mentioned technical solution and its related content, as an inventive point of this disclosure, solve the second technical problem mentioned in the background: "Because the root cause localization of the causal dependency graph of business anomalies only considers single-step dependency relationships, it ignores the impact of historical walk processes and upstream and downstream nodes on the probability of anomaly propagation, and there are a large number of nodes in the causal dependency graph of business anomalies, resulting in low accuracy of anomaly root cause localization, which in turn prolongs the time for dynamic system adjustment, increases the system loss rate, and reduces system stability and performance." If the above factors are solved, the accuracy of anomaly root cause localization can be improved, thereby shortening the time for dynamic system adjustment, reducing the system loss rate, and improving system stability and performance. To achieve this effect, this disclosure firstly determines the initial weight of the target dependency edge through the mutual information of two dependent nodes, and determines the first-order anomaly propagation probability matrix, which can improve the accuracy of the directed weighted causal graph of business anomalies and provide transition probabilities for subsequent second-order walks. Secondly, for each business anomaly data, the forward walk node set is determined, and the direct cause nodes of anomaly propagation are initially explored, reducing the search space, improving efficiency, and avoiding unnecessary calculations by focusing on high-probability nodes, thus providing a basis for second-order walks. Then, for each forward-walking node, a second-order walk (forward, reverse, and origin stop) is performed to search for root causes. This considers the anomaly propagation probabilities of the previous, current, and next nodes, allowing for the capture of deeper root causes and avoiding the limitations of focusing only on direct dependencies. The reverse second-order walk expands the search direction, preventing the forward walk from getting stuck in local optima to some extent. The origin stop avoids directional errors caused by forced walks, improving the stability and completeness of the walk. Afterward, when the number of walks in the root cause localization step is greater than or equal to a preset walk threshold, the number of visits determines the business anomaly root cause information set, improving the accuracy of root cause localization, shortening the time for dynamic system adjustments, reducing system loss rate, and improving system stability and performance. Finally, when the number of walks in the root cause localization step is greater than or equal to the preset walk threshold, the root cause localization step is executed again. This fully explores possible paths, avoids premature termination of the walk, and further improves the accuracy of root cause localization, system stability, and performance.
[0117] Step 109: Input the business anomaly dataset and the business anomaly root cause information set into the anomaly root cause report generation model to obtain the business anomaly root cause report, and make dynamic adjustments to the order business system based on the business anomaly root cause report.
[0118] In some embodiments, the aforementioned execution entity can input the aforementioned business anomaly dataset and the aforementioned business anomaly root cause information set into the anomaly root cause report generation model to obtain a business anomaly root cause report, and dynamically adjust the aforementioned order business system based on the aforementioned business anomaly root cause report. The aforementioned anomaly root cause report generation model can be a large language model that visualizes the input business anomaly dataset and the aforementioned business anomaly root cause information set to form an analysis report. For example, the aforementioned anomaly root cause report generation model can be an LLM (Large Language Model) model. The aforementioned dynamic adjustments can include, but are not limited to, at least one of the following: increasing memory, restarting the order business system.
[0119] Further reference Figure 2 As an implementation of the methods shown in the above figures, this disclosure provides some embodiments of an anomaly root cause localization device based on an order business system. These device embodiments are similar to... Figure 1 Corresponding to the method embodiments shown, this anomaly root cause localization device based on the order business system can be specifically applied to various electronic devices.
[0120] like Figure 2 As shown, an anomaly root cause localization device 200 based on an order business system includes: an acquisition unit 201, an image format conversion unit 202, a spatiotemporal reconstruction anomaly recognition unit 203, an anomaly prediction recognition unit 204, a first generation unit 205, an indicator correlation analysis unit 206, a second generation unit 207, an anomaly root cause localization unit 208, and a dynamic adjustment unit 209.
[0121] It is understandable that the units and references described in the anomaly root cause localization device 200 based on the order business system are... Figure 1 The steps in the described method correspond accordingly. Therefore, the operations, features, and beneficial effects described above for the method also apply to the anomaly root cause localization device 200 and its constituent units based on the order business system, and will not be repeated here.
[0122] The following is for reference. Figure 3 It shows a schematic diagram of the structure of an electronic device (e.g., an electronic device) 300 suitable for implementing some embodiments of the present disclosure. Figure 3 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments of this disclosure.
[0123] like Figure 3As shown, the electronic device 300 may include a processing unit (e.g., a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage device 308 into a random access memory (RAM) 303. The RAM 303 also stores various programs and data required for the operation of the electronic device 300. The processing unit 301, ROM 302, and RAM 303 are interconnected via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.
[0124] Typically, the following devices can be connected to I / O interface 305: input devices 306 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 307 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 308 including, for example, magnetic tapes, hard disks, etc.; and communication devices 309. Communication device 309 allows electronic device 300 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 3 An electronic device 300 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively. Figure 3 Each box shown can represent a device or multiple devices as needed.
[0125] In particular, according to some embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of this disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication device 309, or installed from storage device 308, or installed from ROM 302. When the computer program is executed by processing device 301, it performs the functions defined in the methods of some embodiments of this disclosure.
[0126] It should be noted that, in some embodiments of this disclosure, the computer-readable medium described above may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In some embodiments of this disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of this disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.
[0127] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.
[0128] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device. The aforementioned computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: Steps 101-109.
[0129] Computer program code for performing operations of some embodiments of this disclosure can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0130] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0131] The units described in some embodiments of this disclosure can be implemented in software or hardware. The described units can also be housed in a processor; for example, a processor may be described as including an acquisition unit, an image format conversion unit, a spatiotemporal reconstruction anomaly recognition unit, an anomaly prediction recognition unit, a first generation unit, an indicator correlation analysis unit, a second generation unit, an anomaly root cause localization unit, and a dynamic adjustment unit. The names of these units do not necessarily limit the specific unit; for example, the acquisition unit may also be described as "a unit for acquiring multidimensional business datasets from an order business system."
[0132] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.
[0133] The above description is merely a selection of preferred embodiments of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in the embodiments of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described inventive concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions disclosed in the embodiments of this disclosure.
Claims
1. A method for locating the root cause of anomalies in an order business system, comprising: Obtain the multidimensional business dataset of the order business system, wherein the multidimensional business data includes at least one of the following: order data, memory data, and bandwidth data; The multidimensional business dataset is converted into an image format to obtain a business image dataset; The process of performing spatiotemporal reconstruction anomaly identification on the multidimensional business dataset to obtain a business reconstruction anomaly identification information set includes: inputting the multidimensional business dataset into a first convolutional extraction network included in the reconstruction spatial feature extraction network to obtain a first business spatial feature vector set, wherein the reconstruction spatial feature extraction network further includes a second convolutional extraction network and a fully connected layer; inputting the first business spatial feature vector set into the second convolutional extraction network to obtain a second business spatial feature vector set; inputting the second business spatial feature vector set into the fully connected layer to obtain a third business spatial feature vector set; and inputting the multidimensional business dataset into a forward long short-term memory neural network included in the reconstruction temporal feature extraction network to obtain a first business temporal feature vector set, wherein the reconstruction temporal feature extraction network... The feature extraction network further includes: a reverse long short-term memory neural network; inputting the first business time feature vector set into the reverse long short-term memory neural network to obtain a second business time feature vector set; using an attention mechanism, performing feature fusion on the third business space feature vector set and the second business time feature vector set to obtain a business spatiotemporal fusion feature vector set; inputting the business spatiotemporal fusion feature vector set into the time-series gated encoder included in the business spatiotemporal feature reconstruction coding network to obtain a business time-series latent feature vector set, wherein the business spatiotemporal feature reconstruction coding network further includes: a business-aware decoder; inputting the business time-series latent feature vector set into the business-aware decoder to obtain a multi-dimensional business reconstruction dataset, which serves as a business reconstruction anomaly identification information set; Anomaly prediction and identification are performed on the business image dataset to obtain a business anomaly prediction information set; Based on the business reconstruction anomaly identification information set and the business anomaly prediction information set, a business anomaly dataset is generated for the multidimensional business dataset. Perform indicator correlation analysis on the multidimensional business dataset to obtain an abnormal correlation indicator dataset that is correlated with the business abnormal dataset; Based on the abnormal correlation index dataset, generate a business abnormality causal dependency graph of the multidimensional business dataset; Based on the business anomaly causal dependency graph, second-order anomaly root cause localization is performed on the business anomaly dataset to obtain a business anomaly root cause information set. The business anomaly dataset and the business anomaly root cause information set are input into the anomaly root cause report generation model to obtain a business anomaly root cause report, and the order business system is dynamically adjusted based on the business anomaly root cause report.
2. The method according to claim 1, wherein, The step of performing indicator correlation analysis on the multidimensional business dataset to obtain an abnormal correlation indicator dataset that is correlated with the business abnormal dataset includes: Based on the business anomaly dataset and the multidimensional business dataset, a business association rule set is randomly generated; The business association rule set is vector-encoded to obtain a business association rule vector set, which serves as the initial business rule population. Generate a set of population fitness functions for the initial business rule population, wherein the set of population fitness functions includes: population confidence function, population intelligibility function, population attribute amplitude function and population maximum information coefficient function; The initial business rule population is input into the population fitness function set to obtain the initial fitness set of business individuals; Based on the initial fitness set of the business individuals, generate the initial external archive of the initial population and the target initial business rule individuals after screening; Based on the initial business rule population, the following determination steps are performed: Based on the number of times the determination step has been executed, the preset execution number threshold, the individual target initial business rules after screening, and the external archive adjustment factor, the initial business rule population is updated in stages to obtain the updated business rule population. The updated business rule population is input into the population fitness function set to obtain the updated fitness set of business individuals; The initial external population archive is updated based on the fitness set of individual business units to obtain the updated external population archive. In response to the determination that the number of updated business rule individuals included in the updated external archive of the population is greater than or equal to a preset archive threshold, individuals are removed from the updated external archive of the population to obtain the removed external archive. Filter the removed external archives to obtain the target filtering business rule individuals; Based on the updated business rule population and the initial external population archive, the external archive adjustment factor is updated to obtain the updated external archive adjustment factor; In response to determining that the number of executions is greater than or equal to the preset execution count threshold, the multiple multidimensional business data corresponding to the multiple updated business rule individuals included in the updated external archive of the population are identified as an abnormal correlation indicator dataset.
3. The method according to claim 2, wherein, After performing the following determination steps based on the initial business rule population, the method further includes: In response to determining that the number of executions is less than the preset execution threshold, the external archive after removal, the updated business rule population, the target filtered business rule individual, and the external archive adjustment factor after update are respectively determined as the initial population external archive, the initial business rule population, the filtered target initial business rule individual, and the external archive adjustment factor. The sum of the number of executions and the preset value is determined as the number of executions, so that the determination step is executed again.
4. The method according to claim 2, wherein, The step involves updating the initial business rule population in stages based on the number of times the determination step has been executed, a preset execution number threshold, the individual target initial business rules after screening, and an external archive adjustment factor, to obtain an updated business rule population, including: For each individual initial business rule included in the initial business rule population, perform the following update steps: Based on the number of executions and the preset execution threshold, determine the individual screening probability value and the update phase balance factor; In response to determining that the initial business rule individual is an individual in the target initial business rule population, the initial business rule individual is updated in the first position according to the external archive adjustment factor and the number of executions to obtain the first updated business rule individual, wherein the target initial business rule population is a population generated according to the external archive adjustment factor and the initial business rule population; In response to determining that the initial business rule individual is an individual in the remaining initial business rule population, the initial business rule individual is updated in a second position according to the number of executions, the preset execution number threshold, and the filtered target initial business rule individual to obtain the second updated business rule individual, wherein the remaining initial business rule population is the population obtained by removing the target initial business rule population from the initial business rule population; The position of the first updated business rule individual or the second updated business rule individual is corrected to obtain the first corrected business rule individual, which is then used as the updated business rule individual; In response to determining that the individual screening probability value is greater than or equal to the update stage balance factor, the initial business rule individual is updated in the third position according to the individual screening probability value, the number of executions, and the preset execution number threshold, to obtain the third updated business rule individual; The position of the third updated business rule individual is corrected to obtain the second corrected business rule individual, which is then used as the updated business rule individual.
5. The method according to claim 1, wherein, The step of generating a business anomaly causal dependency graph of the multidimensional business dataset based on the anomaly correlation index dataset includes: Obtain a set of historical business anomaly root cause information with the same anomaly type as the business anomaly dataset; The historical business anomaly root cause information set and the anomaly correlation indicator dataset are correlated and fused to obtain the target business anomaly indicator dataset. A causal relationship analysis was performed on the target business anomaly indicator dataset to obtain a business anomaly causal dataset; Determine the set of business processing components corresponding to the dataset of anomaly-related indicators; A correlation graph is constructed between the business anomaly causal dataset and the business processing flow component set to obtain an anomaly indicator correlation causal graph. The business processing component set is added to the anomaly indicator correlation causal graph to obtain the business anomaly causal dependency graph.
6. An anomaly root cause localization device based on an order business system, comprising: The acquisition unit is configured to acquire a multidimensional business dataset from the order business system, wherein the multidimensional business data includes at least one of the following: order data, memory data, and bandwidth data; An image format conversion unit is configured to convert the image format of the multidimensional business dataset to obtain a business image dataset. The spatiotemporal reconstruction anomaly identification unit is configured to perform spatiotemporal reconstruction anomaly identification on the multidimensional business dataset to obtain a business reconstruction anomaly identification information set. This includes: inputting the multidimensional business dataset into a first convolutional extraction network included in the reconstruction spatial feature extraction network to obtain a first business spatial feature vector set, wherein the reconstruction spatial feature extraction network further includes a second convolutional extraction network and a fully connected layer; inputting the first business spatial feature vector set into the second convolutional extraction network to obtain a second business spatial feature vector set; inputting the second business spatial feature vector set into the fully connected layer to obtain a third business spatial feature vector set; and inputting the multidimensional business dataset into a forward long short-term memory neural network included in the reconstruction temporal feature extraction network to obtain a first business temporal feature vector. The reconstructed temporal feature extraction network further includes: a reverse long short-term memory neural network; inputting the first business temporal feature vector set into the reverse long short-term memory neural network to obtain a second business temporal feature vector set; using an attention mechanism, performing feature fusion on the third business spatial feature vector set and the second business temporal feature vector set to obtain a business spatiotemporal fusion feature vector set; inputting the business spatiotemporal fusion feature vector set into the temporal gating encoder included in the business spatiotemporal feature reconstruction coding network to obtain a business temporal latent feature vector set, wherein the business spatiotemporal feature reconstruction coding network further includes: a business-aware decoder; inputting the business temporal latent feature vector set into the business-aware decoder to obtain a multidimensional business reconstruction dataset, which serves as a business reconstruction anomaly identification information set; An anomaly prediction and identification unit is configured to perform anomaly prediction and identification on the business image dataset to obtain a business anomaly prediction information set. The first generation unit is configured to generate a business anomaly dataset for the multidimensional business dataset based on the business reconstruction anomaly identification information set and the business anomaly prediction information set. The indicator correlation analysis unit is configured to perform indicator correlation analysis on the multidimensional business dataset to obtain an abnormal correlation indicator dataset that is correlated with the business abnormal dataset. The second generation unit is configured to generate a business anomaly causal dependency graph of the multidimensional business dataset based on the anomaly correlation index dataset. The anomaly root cause localization unit is configured to perform second-order anomaly root cause localization on the business anomaly dataset based on the business anomaly causal dependency graph to obtain a business anomaly root cause information set. The dynamic adjustment unit is configured to input the business anomaly dataset and the business anomaly root cause information set into the anomaly root cause report generation model to obtain a business anomaly root cause report, and to dynamically adjust the order business system based on the business anomaly root cause report.
7. An electronic device, comprising: One or more processors; Storage device, on which one or more programs are stored, When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1-5.
8. A computer-readable medium having a computer program stored thereon, wherein, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-5.