A dynamic confrontation cross-domain time series anomaly detection method and system
Patent Information
- Application Number
- CN202511498701.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-20
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2045-10-20
AI Technical Summary
首先,现有方法往往依赖于源域的丰富数据集进行模型训练,这可能导致其对目标域特征的适应性不足
本发明构建基于Vision Transformer的时间序列Patch化方法,能够捕获时间序列的多尺度局部模式和跨周期依赖,有效解决现有方法在长时间序列建模中局部特征表达不足、计算复杂度过高的问题。
Smart Images

Figure CN121302205B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of time series anomaly detection technology, and in particular to a dynamic method and system for detecting cross-domain time series anomalies. Background Technology
[0002] The statements in this section are merely background information related to the present invention and do not necessarily constitute prior art.
[0003] With the rapid development of the Industrial Internet, intelligent manufacturing, and smart cities, massive amounts of real-time monitoring equipment and sensors are constantly generating high-dimensional, multi-source time-series data. The continuous growth in data volume and the high complexity of system operation make potential anomalies more concealed and difficult to identify. Failure to detect anomalies in a timely and accurate manner can lead to production failures, equipment damage, or safety accidents, resulting in severe economic losses and social risks. Time-series anomaly detection, as a key means of ensuring the stability and operational security of critical infrastructure, has received widespread attention and application in numerous fields such as industrial equipment monitoring, financial risk early warning, cybersecurity protection, and medical and health diagnosis. The goal of time-series anomaly detection is to identify and handle potential anomalies in real time to ensure the normal operation and security of the system. Cross-domain time-series anomaly detection aims to effectively identify and detect abnormal patterns and trends in multiple domains through knowledge transfer and information sharing between different domains. Existing cross-domain time-series anomaly detection work often leverages the rich datasets and experience of the source domain to build efficient feature extraction and learning mechanisms. Then, through cross-domain transfer learning methods, knowledge from the source domain is transferred to the target domain, and finally, real-time anomaly detection is performed in the target domain. Cross-domain time series anomaly detection requires simultaneously addressing differences in data characteristics, dynamic features, and data distribution across different domains. It leverages knowledge and information sharing across different domains to improve the ability to identify potential anomalies, thus demonstrating greater practical value in numerous application areas.
[0004] Existing cross-domain time series anomaly detection methods have achieved knowledge transfer and multi-source anomaly detection to some extent, but still face many challenges. First, existing methods often rely on rich datasets from the source domain for model training, which may lead to insufficient adaptability to features in the target domain. Due to significant differences in data distribution characteristics between the source and target domains, directly transferring knowledge from the source domain to the target domain can easily lead to a decline in model performance. Especially when covariate and concept shifts exist, the model may fail to accurately capture anomalous features in the target domain. Second, in the feature extraction and fusion process, existing methods typically employ fixed feature mappings or uniform data preprocessing strategies, ignoring the heterogeneity of data features across different domains. For example, forcing a uniform input format may lead to information loss, noise redundancy, or mapping distortion, thereby weakening the model's ability to represent multi-dimensional related features and its cross-domain generalization ability. Finally, data contamination also seriously affects the effectiveness of cross-domain time series anomaly detection. Most current methods assume that the training set consists only of normal samples, an assumption that is often difficult to hold in practical applications. The presence of anomalous samples can not only cause the model to learn abnormal patterns incorrectly and deviate from the distribution of normal samples, but it can also increase the complexity of the model and significantly reduce its ability to identify anomalous samples. Summary of the Invention
[0005] To address the technical problems mentioned above, this invention provides a dynamic adversarial cross-domain time series anomaly detection method and system. This invention uses a pre-trained large language model to achieve semantic encoding and input optimization of domain knowledge, enabling the model to receive semantic guidance before feature modeling. It employs a causal-global hybrid attention mechanism to improve the structural modeling and accuracy of long time series; a dynamic weighted discrimination strategy to weaken the impact of anomalous samples on the training process, improving overall robustness; and a dual-path dynamic adversarial optimization to achieve cross-domain feature alignment and anomaly detection. Ultimately, this significantly improves the accuracy and generalization performance of cross-domain time series anomaly detection.
[0006] To achieve the above objectives, the present invention adopts the following technical solution: The first aspect of the present invention provides a dynamic method for detecting cross-domain time series anomalies.
[0007] A dynamic adversarial method for cross-domain time series anomaly detection includes: Time series data from multiple source domains are processed to obtain time series sets from different domains; Feature extraction is performed on each time series in the time series collection to obtain a time series feature representation; Semantic encoding is performed on the domain prior knowledge related to time series in each source domain to obtain domain knowledge feature representation; Vector transformation is performed on the time series feature representation and the domain knowledge feature representation. The domain knowledge semantic vector is placed at the front of the time series feature vector input, and the fused feature set is obtained by concatenation. Structural modeling and semantic constraints are performed on each fusion feature in the fusion feature set to obtain a reconstructed feature set that maintains structural and semantic consistency. Based on the reconstructed features in the reconstructed feature set and the time series in the time series set, the reconstruction error is determined, the reconstruction error is standardized, and the weight of each time series in the time series set is adaptively assigned. Based on the weighted time series set and the reconstructed feature set, a dual-path adversarial learning mechanism is introduced to construct a generator and a discriminator and achieve cross-domain potential feature alignment through alternating optimization to complete model training; based on the time series data to be predicted, the trained model is used to calculate the anomaly score and output the potential anomaly.
[0008] Furthermore, feature extraction is performed on each time series in the time series set to obtain a time series feature representation. The method includes: dividing each time series in the time series set into several local continuous subsequence segments according to a fixed-length window, and mapping each subsequence segment to a unified vector space through low-dimensional linear projection to obtain a time series feature representation.
[0009] Furthermore, semantically encode the prior knowledge of each source domain related to the time series to obtain domain knowledge feature representations. The method includes: converting the prior knowledge of each source domain related to the time series into natural language descriptions to construct a domain knowledge text set; dividing each domain knowledge description in the domain knowledge text set into several sub-word units; embedding each sub-word unit using a pre-trained word vector embedding layer of a large language model to obtain semantic vector representations; and aggregating all semantic vector representations within the same domain to obtain domain knowledge feature representations.
[0010] Furthermore, structural modeling and semantic constraints are applied to each fused feature in the fused feature set to obtain a reconstructed feature set that maintains both structural and semantic consistency; the methods include: An encoder is used to perform hierarchical iterative calculations on each fused feature using LayerNorm, causal attention mechanism, feedforward neural network and residual structure to obtain the encoded feature set; A decoder is used to decode the encoded feature set, and a bidirectional multi-head attention mechanism is used to establish global dependencies to obtain the reconstructed feature set.
[0011] Furthermore, the reconstruction error is standardized and the weights of each time series in the time series set are adaptively assigned. The method includes: standardizing the reconstruction error and performing dynamic weight calculation based on the standardized error, assigning low weights to potentially anomalous time series during training, and assigning high weights to normal time series.
[0012] Furthermore, based on the weighted time series set and the reconstructed feature set, a dual-path adversarial learning mechanism is introduced to construct a generator and a discriminator and achieve cross-domain latent feature alignment through alternating optimization to complete model training. The method includes: optimizing the discriminator through binary cross-entropy loss in the real data path, generating adversarial examples for the time series reconstruction module that generates the reconstructed feature set in the generated data path, guiding the discriminator to learn the difference features between the generated samples and the real samples, and achieving collaborative optimization of the generator and discriminator through alternating training.
[0013] A second aspect of the present invention provides a dynamic anti-cross-domain time series anomaly detection system.
[0014] A dynamic adversarial cross-domain time series anomaly detection system includes: The data preprocessing module is configured to process time series data from multiple source domains to obtain time series sets from different domains; The time series structuring module is configured to extract features from each time series in the time series set to obtain a time series feature representation. The domain knowledge semantic encoding module is configured to: semantically encode the domain prior knowledge related to time series in each source domain to obtain domain knowledge feature representation; The feature fusion module is configured to: perform vector transformation on the time series feature representation and the domain knowledge feature representation, place the domain knowledge semantic vector at the front end of the time series feature vector input, and concatenate them to obtain the fused feature set; The time series reconstruction module is configured to perform structural modeling and semantic constraints on each fusion feature in the fusion feature set to obtain a reconstructed feature set that maintains structural and semantic consistency. The dynamic weighted identification module is configured to: determine the reconstruction error based on the reconstructed features in the reconstructed feature set and the time series in the time series set; standardize the reconstruction error and adaptively assign weights to each time series in the time series set. The cross-domain anomaly detection module is configured to: based on the weighted time series set and the reconstructed feature set, introduce a dual-path adversarial learning mechanism to build a generator and a discriminator and achieve cross-domain potential feature alignment through alternating optimization to complete model training; based on the time series data to be predicted, use the trained model to calculate anomaly scores and output potential anomalies.
[0015] A third aspect of the present invention provides a computer device comprising: A processor, adapted to execute computer programs; A computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the dynamic adversarial cross-domain time series anomaly detection method described in the first aspect above.
[0016] A fourth aspect of the present invention provides a computer-readable storage medium storing a computer program adapted to be loaded by a processor and to execute steps in the dynamic adversarial cross-domain time series anomaly detection method described in the first aspect above.
[0017] The fifth aspect of the present invention provides a computer program product or computer program.
[0018] This invention provides a computer program product or computer program comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the steps of the dynamic adversarial cross-domain time series anomaly detection method described in the first aspect above.
[0019] Compared with the prior art, the beneficial effects of the present invention are: This invention constructs a time series patching method based on Vision Transformer, which can capture multi-scale local patterns and cross-period dependencies of time series, effectively solving the problems of insufficient local feature representation and excessive computational complexity in existing methods for long-term series modeling.
[0020] This invention constructs autoencoders for different domains and maps sequence fragments from each domain to a unified latent representation space, thereby achieving a unified representation of multi-source heterogeneous time series and breaking through the strict dependence of traditional methods on the number of input channels and sequence format.
[0021] This invention uses a pre-trained large language model to semantically encode domain knowledge and fuse it with time series features, explicitly introducing semantic information from different domains to achieve dynamic alignment of domain features, avoiding the problem of confusion between features from different domains, thereby improving the model's generalization detection capability on new domain data.
[0022] The "causal-global" hybrid attention mechanism designed in this invention introduces causal attention at the encoder end to ensure the causality of time dependencies, and introduces bidirectional multi-head attention at the decoder end to enhance the global context modeling capability. It can solve the problem of insufficient long-range dependency modeling in existing methods, thereby achieving more stable and accurate time series reconstruction.
[0023] The dynamic weighted discrimination mechanism proposed in this invention automatically reduces the influence of potential abnormal samples during the training process by standardizing and dynamically weighting the reconstruction error. This effectively improves the problem of existing methods being susceptible to abnormal contamination and interference, thereby enhancing the model's ability to distinguish between normal and abnormal patterns.
[0024] This invention is based on a dual-path adversarial learning framework. By optimizing the adversarial relationship between the generator and the discriminator, it not only makes the distribution of generated samples closer to the distribution of normal samples, but also improves the stability of cross-domain feature alignment and the ability to identify abnormal patterns. Attached Figure Description
[0025] The accompanying drawings, which form part of this invention, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an improper limitation of the invention.
[0026] Figure 1 This is a flowchart illustrating the dynamic adversarial cross-domain time series anomaly detection method according to an embodiment of the present invention; Figure 2 This is a diagram illustrating the cross-domain anomaly detection structure according to an embodiment of the present invention; Figure 3 This is a structural diagram of the dynamic adversarial cross-domain time series anomaly detection system shown in an embodiment of the present invention; Figure 4 This is a structural diagram of a computer device shown in an embodiment of the present invention. Detailed Implementation
[0027] The present invention will be further described below with reference to the accompanying drawings and embodiments.
[0028] It should be noted that the following detailed description is illustrative and intended to provide further explanation of the invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.
[0029] It should be noted that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of exemplary embodiments according to the invention. As used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise. Furthermore, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0030] As described in the background section, existing cross-domain time series anomaly detection methods generally suffer from problems such as difficulty in unifying data feature differences, easy confusion of domain features, and susceptibility of training data to interference from anomalous samples. To address these issues, this invention provides a dynamic adversarial cross-domain time series anomaly detection method and system. By constructing a unified feature representation, introducing domain knowledge, and designing a dynamic weighted adversarial learning mechanism, it solves at least one of the aforementioned problems. The specific solutions of this invention are described in detail below through several embodiments.
[0031] This invention provides a dynamic adversarial cross-domain time series anomaly detection method, comprising: First, using a lightweight autoencoder to map time series data from different domains to a unified latent space, achieving a unified representation of multi-source heterogeneous time series, thereby overcoming the strict dependence of traditional methods on the number of input channels and sequence format. Simultaneously, based on a pre-trained large language model, predefined domain knowledge is semantically encoded to construct a domain semantic space, and domain knowledge and time series features are jointly modeled to achieve dynamic alignment between the semantic space and the feature space, thus providing the model with explicit domain identification information to alleviate the cross-domain feature confusion problem. Building upon this, a time series reconstruction module based on a "causal-global" hybrid attention mechanism is designed. This module maintains the causality of the time series at the encoder end and enhances the global dependency modeling capability at the decoder end, thereby improving the model's ability to learn long-range dependencies and ensuring the stability of the sequence reconstruction results. Finally, a dynamic weighted discrimination strategy based on reconstruction error is designed. During adversarial training, the training weights of samples are adaptively adjusted according to the reconstruction error, assigning lower weights to potentially anomalous samples that are difficult to reconstruct, thereby weakening the adverse effects of anomalous contamination samples on the overall training. The weighted reconstructed data and the original data are input together into the discriminator. A dual-path adversarial learning mechanism is used to alternately optimize the generator and discriminator, ensuring that the generated sample distribution more closely approximates the real data distribution and improving the discriminator's ability to distinguish between normal and abnormal patterns. Through the collaborative optimization of the overall architecture, this invention can achieve accurate identification of abnormal patterns under cross-domain conditions while ensuring the integrity and stability of feature representation, thereby improving the model's adaptability in complex time-series data environments and the efficiency of cross-domain anomaly detection.
[0032] Figure 1This is a flowchart illustrating a dynamic adversarial cross-domain time series anomaly detection method according to an embodiment of the present invention; see reference. Figure 1 The method includes the following steps: (1) Data preprocessing For raw time-series data from different fields such as industrial equipment operation monitoring, network security intrusion detection, spacecraft mission status monitoring, and server cluster operation and maintenance, a unified preprocessing operation is first performed to obtain time-series sets from different fields, ensuring the comparability and consistency of data from different sources at the input level. The fields from which the data originate are defined. The multivariate time series is Among them, in timestamp The observed value at that location is , For time step, Representation of domain The number of channels within the sequence is considered. To address the differences in sampling frequency, dimensionality, and missing values among multi-source heterogeneous time series, a unified strategy is employed in the preprocessing stage. Specifically, interpolation methods and smoothing filters are used to fill in missing values and repair breakpoints, eliminating noise interference and ensuring the continuity and stability of the sequence. Furthermore, sequence normalization and stabilization operations are utilized to mitigate the differences in data distribution across different domains. Based on this, a sliding window is used to segment long sequences to ensure consistency in input sequence length and controllability of the modeling process. Finally, for length mismatches caused by insufficient sequence ends during window segmentation, mirror padding is used to complete the segmentation, ensuring that all time series have a uniform scale and structure at the input stage.
[0033] (2) Time series structuring processing After data preprocessing, the original time series is divided into locally continuous patch segments according to fixed-length windows. ,in, Representation of domain The j-th patch is then used. Afterwards, each subsequence segment is encoded to form a low-dimensional dense vector representation, which serves as the basic input unit for subsequent feature modeling. This approach can reduce input dimensionality and computational complexity while preserving multi-scale dynamic patterns and cross-period dependencies in the time series. For sequences from different domains with inconsistent feature dimensions, an autoencoder is further constructed for each source domain. It is used to learn the local feature distribution within the domain and represents each patch. Mapping to a unified vector space This enables the preprocessing and unified feature extraction of multi-source heterogeneous time series data, resulting in a unified time series feature representation.
[0034] Unlike most methods that encode each time point individually, this embodiment can capture time series patterns and multi-scale dependencies across periods, thereby solving the problem of insufficient local feature representation in long-term series modeling and reducing overall computational complexity.
[0035] (3) Semantic encoding of domain knowledge To address the issues of dynamic differences and distribution shifts in data across different domains, semantic encoding of domain knowledge is introduced to mitigate the impact of cross-domain discrepancies. Specifically, prior knowledge related to time series, such as equipment operating conditions, physical characteristics, and general abnormal states, is transformed into natural language descriptions, constructing a predefined set of domain knowledge text. Based on this, the Byte-Pair Encoding method is first used to divide each domain knowledge description into several sub-word units. ,in, Representation of domain For the m-th sub-word unit, a cross-domain semantic association is constructed. Subsequently, each sub-word unit is embedded using a pre-trained word vector embedding layer of a large language model to obtain a semantic vector representation. ,in, Representation of domain The embedding representation of the m-th sub-word unit is then used. Subsequently, the embeddings of all sub-words within the same domain are aggregated to obtain the domain knowledge feature representation. , where n represents the number of sub-word units.
[0036] Unlike existing methods that simply introduce domain information as posterior labels, this embodiment can explicitly introduce domain semantic vectors to achieve dynamic alignment of cross-domain features, thereby improving the problem of feature confusion between different domains and enhancing the model's generalization detection capability on new domain data.
[0037] (4) Fusion of time series features and domain knowledge features After obtaining the time series feature representation and the domain knowledge feature representation, the two are fused to simultaneously preserve the dynamic change patterns of the time series and the semantic prior information of the domain knowledge. Unlike traditional methods that only introduce domain knowledge in the later stages, this invention optimizes the input design by placing the domain knowledge before the time series features, allowing the model to obtain explicit domain knowledge before processing the time series features, thereby providing semantic guidance for subsequent sequence modeling. Specifically, the domain knowledge vector obtained after semantic encoding... Local features of time series Feature concatenation is performed to obtain the fused input. In this process, domain knowledge features are placed at the front end of the sequence features as input, allowing the model to first receive and parse the identifying semantic information provided by the domain knowledge, and then dynamically capture the local patterns and cross-period dependencies of the time series, thereby obtaining a set of time series features containing domain knowledge.
[0038] (5) Time series reconstruction In obtaining fusion characteristics Next, time-series reconstruction is performed to address the issues of insufficient long-range dependency modeling and difficulties in semantic fusion in cross-domain time series. The reconstruction module employs a pre-trained large language model based on a hybrid attention mechanism, introducing causal attention and bidirectional multi-head attention mechanisms to model time dependencies, and combining semantic domain knowledge vectors to achieve dynamic context capture and feature reconstruction for cross-domain tasks. Specifically, the Encoder part will fuse features... Through layer-by-layer iterative computation using LayerNorm, causal attention mechanism, feedforward neural network, and residual structure, the model ensures that it captures local dynamic patterns while preserving long-range dependency information. The computation process is represented as follows:
[0039]
[0040] in, This indicates the LayerNorm operation. Indicates in the field Inner Layer output at position The vector, Represents a feedforward neural network. This represents a multi-head attention mechanism. Causal masks are used in the Encoder. Operation, ensuring the first Each position only focuses on information not exceeding its current position. The causal attention mechanism is formalized as:
[0041]
[0042] in, , , From The obtained number The query matrix, key matrix, and value matrix of the layer. Let be the dimension of the key matrix. This is the causal mask matrix. Next, the Encoder output features are decoded, and a bidirectional multi-head attention mechanism is used to establish global dependencies. In the Decoder, the computation process for each layer is as follows:
[0043]
[0044] in, This indicates the LayerNorm operation. Indicates in the field Inner Layer output at position The vector, Represents a feedforward neural network. This indicates a multi-head attention mechanism, using a bidirectional multi-head attention mechanism. , guarantee the Each position can focus on all information; the multi-head attention mechanism is formalized as follows:
[0045] in, , , From The obtained number The query matrix, key matrix, and value matrix of the layer. Let be the dimension of the key matrix. Through this step, a reconstructed feature set that maintains both structural and semantic consistency is finally obtained.
[0046] This invention introduces causal attention at the encoder level to ensure the causality and directionality of time-series dependencies, and bidirectional multi-head attention at the decoder level to enhance global contextual dependency modeling. Unlike traditional single attention mechanisms, this design can both avoid causal dependency errors and enhance the ability to capture long-range dependencies, effectively solving the problem of insufficient reconstruction accuracy of existing cross-domain reconstruction models in long-term series.
[0047] (6) Dynamic weighted identification After time series reconstruction, the reconstruction error between the reconstructed results and the original samples is dynamically weighted to achieve adaptive discrimination. This step aims to reduce the adverse effects of outlier or difficult-to-reconstruct samples on model training and improve the model's ability to recognize normal sample patterns. Specifically, for the domain... The Middle Each sample at the timestamp Observations at The corresponding reconstruction error is calculated as follows:
[0048] in, Output for the time series reconstruction module. for Calculation of norm. and Representation of domain The reconstruction error is calculated by taking the mean and standard deviation of the reconstruction error for all samples. The standardized reconstruction error is then expressed as:
[0049] Dynamic weighting is applied based on this standardized error to reduce the impact of outlier samples on the training process. The calculation process is as follows:
[0050] in, Representation of domain Internal timestamp First Dynamic weights for each sample This represents a function related to the number of training steps, with weights dynamically adjusted gradually as training progresses. Finally, the weighted reconstructed data and the original input data are fed into the discriminator. Weighted training improves the discriminator's ability to learn normal patterns and identify abnormal patterns.
[0051] This embodiment standardizes the reconstruction error and dynamically weights it to reduce the impact of outliers on the training process. Unlike existing training methods that are susceptible to interference from outliers, this embodiment significantly reduces the perturbation of model parameters by noisy samples, thereby improving the accuracy of outlier pattern recognition and the robustness of the model.
[0052] (7) Cross-domain anomaly detection Based on a dual-path adversarial learning framework, this invention employs an alternating optimization strategy to train the generator and discriminator, comprehensively achieving cross-domain anomaly detection. Specifically, the discriminator is optimized using binary cross-entropy loss in the real data path, while adversarial examples are generated through a time-series reconstruction module in the generated data path. This guides the discriminator to learn the differences between generated and real samples, achieving collaborative optimization of the generator and discriminator through alternating training. Unlike existing adversarial networks that only use single-path training, this invention forms a dynamic game through alternating optimization. This not only ensures that the distribution of generated samples is closer to the real distribution but also significantly enhances the discriminator's ability to detect cross-domain anomaly patterns. The generator's loss function is calculated as follows:
[0053] in, Represents a generator. Indicates the discriminator, Representation of domain No. One input sample, For dynamic weights, This represents the dynamic balance coefficient used to adjust the reconstruction and adversarial weights. The discriminator loss function is calculated as follows:
[0054] Finally, during the testing phase, anomalies are determined based on the degree of deviation in the reconstruction error of the samples, thus achieving cross-domain anomaly detection. The cross-domain anomaly detection structure diagram is shown below. Figure 2 As shown. Test sample The anomaly score can be calculated as follows:
[0055] in, It is the average reconstruction error of the entire sample. For time step.
[0056] This invention can be applied to various cross-domain time series anomaly detection tasks, including but not limited to scenarios such as industrial equipment monitoring, network security protection, and high-reliability system operation status monitoring. The data types processed include multimodal and multi-source heterogeneous time series signals, covering various feature forms such as physical quantities (e.g., flow rate, current, temperature), logical states (e.g., valve opening / closing, task execution flags), and system performance indicators (e.g., CPU utilization, network traffic). For example, in industrial control system scenarios, for sensor data and system log data (e.g., water level, flow rate, valve status, motor current, CPU load, memory usage, network traffic, etc.) collected from safe water treatment systems (SWaT dataset) or server clusters (SMD dataset), this invention achieves feature alignment and anomaly pattern recognition between different subsystems or server nodes through a unified cross-domain feature representation and semantic guidance mechanism, effectively detecting abnormal behaviors caused by equipment aging, system failures, or network attacks. In high-reliability system status monitoring scenarios, this invention can be used to analyze time series signals related to telemetry and task execution (e.g., power, radiation, temperature, and task execution status parameters), achieving cross-domain anomaly identification and status prediction under different task environments.
[0057] The above combination Figure 1 The dynamic adversarial cross-domain time series anomaly detection method provided by the embodiments of the present invention has been described in detail. Next, the dynamic adversarial cross-domain time series anomaly detection system provided by the embodiments of the present invention will be described in conjunction with the accompanying drawings.
[0058] Figure 3 This is a schematic diagram of the structure of a dynamic adversarial cross-domain time series anomaly detection system according to an embodiment of the present invention, with reference to... Figure 3 The system described in this invention includes: The data preprocessing module is configured to: process time series data from multiple source domains to obtain time series sets from different domains; preprocess multi-source time series data, including missing value repair, sequence stabilization and length padding, to ensure that the data has consistency and comparability before being input into the subsequent modeling module, thereby solving the problems of missing values and asynchronous alignment difficulties in existing multi-source time series data; The time series structuring module is configured to: extract features from each time series in the time series set to obtain time series feature representations; divide the preprocessed original long series into several locally continuous subsequences (Patches) and realize feature representation through low-dimensional dense vectorization to capture cross-period dependencies and reduce computational complexity, thereby solving the problems of insufficient local feature representation and excessive computational overhead in existing methods for long-term series modeling; The domain knowledge semantic encoding module is configured to: semantically encode the prior knowledge of each source domain and time series to obtain the domain knowledge feature representation; by organizing the original text description of the domain knowledge, perform word segmentation, segmentation and preprocessing on the domain knowledge text, and semantically encode the text based on the pre-trained large language model to obtain the corresponding semantic vector representation, thereby realizing the transformation of unstructured domain knowledge into vectorized representation; The feature fusion module is configured to: perform vector transformation on time series feature representations and domain knowledge feature representations, place the domain knowledge semantic vector at the front end of the time series feature vector input, and concatenate them to obtain a fused feature set; and concatenate the semantic vector output by the joint modeling domain knowledge semantic encoding module and the time series feature representation obtained by local modeling of the time series, place the domain knowledge semantic vector at the front end of the time series feature input, and concatenate the two to obtain a time series feature set containing domain knowledge. By explicitly introducing domain identifiers, the domain semantics guide the modeling of time series features, thereby improving the problems of domain feature confusion and semantic loss in cross-domain modeling. The time series reconstruction module is configured to: perform structural modeling and semantic constraints on each fused feature in the fused feature set to obtain a reconstructed feature set that maintains structural and semantic consistency; and perform deep modeling on the input fused features through a pre-trained large language model based on a hybrid attention mechanism. The encoder uses causal attention to focus only on historical information to maintain sequential dependencies, while the decoder uses bidirectional multi-head attention to integrate the global context, thereby ensuring both causal directionality and the modelability of global dependencies, achieving robust reconstruction of time series data, and solving the problem that existing reconstruction models are insufficient in capturing long-range dependencies. The dynamic weighted discrimination module is configured to: determine the reconstruction error based on the reconstructed features in the reconstructed feature set and the time series in the time series set; standardize the reconstruction error and adaptively assign weights to each time series in the time series set; by standardizing the reconstruction error of the samples and calculating dynamic weights, assign lower weights to potentially abnormal samples and higher weights to normal samples during training; and input the weighted samples into the discriminator to participate in adversarial training, so as to weaken the interference of abnormal contamination samples on the overall training process, thereby improving the model's ability to identify real abnormal patterns. The cross-domain anomaly detection module is configured to: based on the weighted time series set and the reconstructed feature set, introduce a dual-path adversarial learning mechanism to build a generator and a discriminator and achieve cross-domain potential feature alignment through alternating optimization to complete model training; based on the time series data to be predicted, use the trained model to calculate anomaly scores and output potential anomalies to achieve cross-domain time series anomaly detection.
[0059] In some embodiments, the time series structuring processing module is specifically configured to: divide each time series in the time series set into several local continuous subsequence segments according to a fixed-length window, and map each subsequence segment to a unified vector space through low-dimensional linear projection to obtain a time series feature representation.
[0060] In some embodiments, the domain knowledge semantic encoding module is specifically configured to: convert the prior domain knowledge related to time series in each source domain into natural language descriptions to construct a domain knowledge text set; divide each domain knowledge description in the domain knowledge text set into several sub-word units; embed each sub-word unit using a pre-trained word vector embedding layer of a large language model to obtain a semantic vector representation; and aggregate all semantic vector representations within the same domain to obtain a domain knowledge feature representation.
[0061] In some embodiments, the time series reconstruction module is specifically configured to: use an encoder to perform hierarchical iterative calculations of LayerNorm, causal attention mechanism, feedforward neural network and residual structure on each fused feature to obtain an encoded feature set; use a decoder to decode the encoded feature set and use a bidirectional multi-head attention mechanism to establish global dependencies to obtain a reconstructed feature set.
[0062] In some embodiments, the dynamic weighted identification module is specifically configured to: standardize the reconstruction error and perform dynamic weight calculation based on the standardized error, assigning low weights to potentially anomalous time series and high weights to normal time series during training.
[0063] In some embodiments, the cross-domain anomaly detection module is specifically configured as follows: the real data path optimizes the discriminator through binary cross-entropy loss, the generated data path generates adversarial examples for the time series reconstruction module that generates the reconstructed feature set, guides the discriminator to learn the difference features between the generated samples and the real samples, and achieves collaborative optimization of the generator and the discriminator through alternating training.
[0064] According to embodiments of the present invention, the dynamic anti-cross-domain time series anomaly detection system can correspond to the execution of the methods described in the embodiments of the present invention, and the above and other operations and / or functions of each module of the dynamic anti-cross-domain time series anomaly detection system are respectively for implementing Figure 1 For the sake of brevity, the corresponding processes of each method in the code will not be elaborated here.
[0065] See Figure 4 The diagram shows the structure of a computer device, which includes a processor, a communication interface, and a computer-readable storage medium. The processor, communication interface, and computer-readable storage medium are connected via a bus or other means. The communication interface is used to receive and send data. The computer-readable storage medium can be stored in the computer device's memory. The computer-readable storage medium stores computer programs, including program instructions, and the processor executes the program instructions stored in the computer-readable storage medium. The processor (or CPU, Central Processing Unit) is the computing and control core of the computer device, adapted to implement one or more instructions, specifically adapted to load and execute one or more instructions to achieve the corresponding steps in the embodiment of the dynamic anti-cross-domain time series anomaly detection method.
[0066] This embodiment provides a computer-readable storage medium (Memory), which is a memory device in a computer device used to store programs and data. It is understood that the computer-readable storage medium here can include both the built-in storage medium in the computer device and extended storage media supported by the computer device. The computer-readable storage medium provides storage space that stores the processing system of the computer device. Furthermore, this storage space also contains one or more instructions suitable for loading and execution by the processor. These instructions can be one or more computer programs (including program code). It should be noted that the computer-readable storage medium here can be high-speed RAM memory or non-volatile memory, such as at least one disk storage device; optionally, it can also be at least one computer-readable storage medium located remotely from the aforementioned processor.
[0067] In one embodiment, the computer-readable storage medium stores one or more instructions; the processor loads and executes one or more instructions stored in the computer-readable storage medium to implement the corresponding steps in the above embodiment of the dynamic anti-cross-domain time series anomaly detection method.
[0068] This embodiment provides a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the corresponding steps in the above-described embodiment of the dynamic adversarial cross-domain time series anomaly detection method.
[0069] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of hardware embodiments, software embodiments, or embodiments combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0070] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0071] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0072] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0073] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.
[0074] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A dynamic adversarial cross-domain time series anomaly detection method, which achieves feature alignment and anomaly pattern recognition of different subsystems, and can effectively detect abnormal behavior caused by equipment aging or system failure, characterized in that, include: For sensor data and system log data collected in the safe water treatment system, including water level, flow rate, valve status, and motor current, time series data from multiple source domains are processed to obtain time series sets from different domains: preprocessing of multi-source time series data; Feature extraction is performed on each time series in the time series set to obtain the time series feature representation: the preprocessed original long sequence is divided into several locally continuous subsequences, and the feature representation is achieved through low-dimensional dense vectorization; Semantic encoding is performed on the prior knowledge of each source domain and time series to obtain the domain knowledge feature representation: by organizing the original text description of the domain knowledge, the domain knowledge text is segmented, divided and preprocessed, and semantically encoded based on the pre-trained large language model to obtain the corresponding semantic vector representation, thereby realizing the transformation of unstructured domain knowledge into vectorized representation; Vector transformation is performed on the time series feature representation and the domain knowledge feature representation. The domain knowledge semantic vector is placed at the front end of the time series feature vector input, and the two are concatenated to obtain the fused feature set: the semantic vector output by the domain knowledge semantic encoding module of joint modeling and the time series feature representation obtained by local modeling of time series are concatenated to obtain the time series feature set containing domain knowledge. For each fused feature in the fused feature set, structural modeling and semantic constraints are performed to obtain a reconstructed feature set that maintains structural and semantic consistency. An encoder is used to perform hierarchical iterative calculations on each fused feature using LayerNorm, causal attention mechanism, feedforward neural network, and residual structure to obtain an encoded feature set. A decoder is used to decode the encoded feature set, and a bidirectional multi-head attention mechanism is used to establish global dependencies to obtain the reconstructed feature set. Based on the reconstructed features in the reconstructed feature set and the time series in the time series set, the reconstruction error is determined. The reconstruction error is standardized and the weight of each time series in the time series set is adaptively assigned. By standardizing the reconstruction error and performing dynamic weight calculation based on the standardized error, potentially abnormal time series are assigned low weights during training, while normal time series are assigned high weights. Based on the weighted time series set and the reconstructed feature set, a dual-path adversarial learning mechanism is introduced to construct a generator and a discriminator and achieve cross-domain potential feature alignment through alternating optimization to complete model training; based on the time series data to be predicted, the trained model is used to calculate the anomaly score and output the potential anomaly.
2. The dynamic adversarial cross-domain time series anomaly detection method according to claim 1, characterized in that, Semantic encoding is performed on the prior knowledge of each source domain related to time series to obtain domain knowledge feature representations. The method includes: converting the prior knowledge of each source domain related to time series into natural language descriptions to construct a domain knowledge text set; dividing each domain knowledge description in the domain knowledge text set into several sub-word units; embedding each sub-word unit using a pre-trained word vector embedding layer of a large language model to obtain semantic vector representations; and aggregating all semantic vector representations within the same domain to obtain domain knowledge feature representations.
3. The dynamic adversarial cross-domain time series anomaly detection method according to claim 1, characterized in that, Based on the weighted time series set and the reconstructed feature set, a dual-path adversarial learning mechanism is introduced to construct a generator and a discriminator. Cross-domain potential feature alignment is achieved through alternating optimization to complete model training. The method includes: the discriminator is optimized through binary cross-entropy loss in the real data path, and adversarial examples are generated for the time series reconstruction module that generates the reconstructed feature set in the generated data path. This guides the discriminator to learn the difference features between the generated samples and the real samples. Cooperative optimization of the generator and discriminator is achieved through alternating training.
4. A dynamic adversarial cross-domain time series anomaly detection system, employing the dynamic adversarial cross-domain time series anomaly detection method as described in any one of claims 1-3, characterized in that, include: The data preprocessing module is configured to process time series data from multiple source domains to obtain time series sets from different domains; The time series structuring module is configured to extract features from each time series in the time series set to obtain a time series feature representation. The domain knowledge semantic encoding module is configured to: semantically encode the domain prior knowledge related to time series in each source domain to obtain domain knowledge feature representation; The feature fusion module is configured to: perform vector transformation on the time series feature representation and the domain knowledge feature representation, place the domain knowledge semantic vector at the front end of the time series feature vector input, and concatenate them to obtain the fused feature set; The time series reconstruction module is configured to perform structural modeling and semantic constraints on each fusion feature in the fusion feature set to obtain a reconstructed feature set that maintains structural and semantic consistency. The dynamic weighted identification module is configured to: determine the reconstruction error based on the reconstructed features in the reconstructed feature set and the time series in the time series set; standardize the reconstruction error and adaptively assign weights to each time series in the time series set. The cross-domain anomaly detection module is configured to: based on the weighted time series set and the reconstructed feature set, introduce a dual-path adversarial learning mechanism to build a generator and a discriminator and achieve cross-domain potential feature alignment through alternating optimization to complete model training; based on the time series data to be predicted, use the trained model to calculate anomaly scores and output potential anomalies.
5. A computer device, characterized in that, A processor, adapted to execute computer programs; A computer-readable storage medium storing a computer program, which, when executed by the processor, implements the steps of the dynamic adversarial cross-domain time series anomaly detection method as described in any one of claims 1-3.
6. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program adapted to be loaded by a processor and to execute the steps of the dynamic adversarial cross-domain time series anomaly detection method as described in any one of claims 1-3.
7. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps in the dynamic adversarial cross-domain time series anomaly detection method as described in any one of claims 1-3.
Citation Information
Patent Citations
Multi-modal large model method based on layered visual injection and mixed attention mechanism
CN120047785A
Mixing anomaly detection method for non-uniform multivariate time series
CN120508977A