Method, device and equipment for determining comprehensive alarm decision, medium and product
By decomposing the live streaming metric dataset and dynamically adjusting the threshold using a three-sigma statistical model, Kalman filtering, and Bayesian change point detection algorithms, the problem of insufficient adaptability and anomaly detection capability in the live streaming platform's alarm strategy was solved. This achieved highly accurate alarm decision-making, reduced false alarm and false negative rates, and ensured the stability of the live streaming system.
Patent Information
- Application Number
- CN202511531176.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-24
- Publication Date
- 2026-01-23
AI Technical Summary
The alarm strategies of live streaming platforms lack adaptability, have insufficient anomaly detection capabilities, insufficient multi-source data fusion, lack closed-loop optimization mechanisms, and have poor adaptability to complex scenarios, resulting in high false alarm rates and high false negative rates, making it difficult to cope with high concurrency, low latency, and strong real-time scenarios.
The live streaming index dataset is decomposed using the first preset processing algorithm. The dynamic threshold is dynamically determined using the target three sigma statistical model and the preset adjustment mechanism. Combined with Kalman filtering and Bayesian change point detection algorithms, the threshold set is dynamically adjusted to form a comprehensive alarm decision.
It improved the anomaly detection capability and alarm accuracy of the live streaming system, reduced the false alarm and false negative rates, and ensured the stable operation of the live streaming business.
Smart Images

Figure CN121397252A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of data processing technology, and in particular to a method, apparatus, device, medium, and product for determining comprehensive alarm decisions. Background Technology
[0002] With the rapid development of live streaming technology and the continuous growth of user scale, the stability and reliability of live streaming platforms (such as TV live streaming and online live streaming) have become key factors in ensuring user experience and platform operation. However, live streaming systems face a variety of complex challenges during operation, such as network fluctuations, equipment failures, sudden traffic spikes, and malicious attacks. These factors may cause abnormal situations such as live streaming video stuttering, screen tearing, and black screens, directly affecting user experience and even causing major broadcast accidents.
[0003] Currently, live streaming platforms generally adopt alarm strategies based on fixed thresholds, triggering alarms by setting static thresholds (such as fixed upper and lower limits for metrics like traffic, concurrency, and latency). However, these static alarm models have significant shortcomings: Lack of adaptability: Static thresholds cannot be dynamically adjusted based on real-time business scenarios (such as promotional activities or holiday traffic peaks) or system status (such as aging equipment or network congestion), leading to increased false alarm rates during periods of drastic traffic fluctuations and increased risk of missed alarms during periods of low traffic. Insufficient anomaly detection capabilities: Traditional methods rely on a single statistical model (such as Three Sigma). The traditional methods, while adhering to the "principle of [missing information]", struggle to capture nonlinear and non-Gaussian distributed anomalies, exhibiting particularly low sensitivity to trend changes (such as slow performance degradation) and local anomalies (such as sudden traffic spikes). Insufficient multi-source data fusion: Live streaming platforms involve multi-dimensional data (such as time-series traffic, user behavior, and network status), but existing methods typically analyze single indicators in isolation, lacking comprehensive utilization of contextual information, leading to biased and unreliable alarm decisions. Lack of closed-loop optimization mechanisms: Alarm parameters (such as thresholds) rely on manual experience, making dynamic optimization based on historical alarm performance (such as false alarm rate and false negative rate) difficult, resulting in gradual performance degradation over long-term operation. Poor adaptability to complex scenarios: Live streaming systems need to cope with complex scenarios such as high concurrency, low latency, and strong real-time requirements, but traditional methods struggle to balance alarm sensitivity and stability, leading to delayed responses to sudden traffic spikes or structural failures. Summary of the Invention
[0004] This disclosure provides a method, apparatus, device, medium, and product for determining comprehensive alarm decisions, which improves the anomaly detection capability and alarm accuracy of live streaming systems.
[0005] Firstly, a comprehensive alarm decision-making method is provided, including:
[0006] The live index data set is decomposed by using a first preset processing algorithm to obtain a residual component of the live index data set;
[0007] Based on a target three-sigma statistical model, a preset adjustment mechanism is used to dynamically determine a dynamic threshold corresponding to each data segment in the residual component to obtain a first threshold set; the first threshold set is composed of a basic dynamic threshold corresponding to each data segment; wherein the target three-sigma statistical model is determined based on the residual component; the preset adjustment mechanism includes an entropy weight adjustment mechanism, a trend correction adjustment mechanism and a fractal correction adjustment mechanism;
[0008] The first threshold set is corrected by using a Kalman filtering algorithm to obtain a second threshold set after correction;
[0009] Based on an abnormal data label and a real-time data stream, a Bayesian change point detection algorithm is used to dynamically adjust the second threshold set to determine a target threshold set; the abnormal data label is used for abnormal data judgment on the real-time data stream;
[0010] Based on the target threshold set and the abnormal data label, a comprehensive alarm decision is determined.
[0011] In a second aspect, a device for determining a comprehensive alarm decision is provided, comprising:
[0012] A decomposition module is configured to decompose a live index data set by using a first preset processing algorithm to obtain a residual component of the live index data set;
[0013] A first threshold set determination module is configured to determine a dynamic threshold corresponding to each data segment in the residual component based on a target three-sigma statistical model by using a preset adjustment mechanism to obtain a first threshold set; the first threshold set is composed of a basic dynamic threshold corresponding to each data segment; wherein the target three-sigma statistical model is determined based on the residual component; the preset adjustment mechanism includes an entropy weight adjustment mechanism, a trend correction adjustment mechanism and a fractal correction adjustment mechanism;
[0014] A second threshold set determination module is configured to correct the first threshold set by using a Kalman filtering algorithm to obtain a second threshold set after correction;
[0015] A target threshold set determination module is configured to dynamically adjust the second threshold set by using a Bayesian change point detection algorithm based on an abnormal data label and a real-time data stream to determine a target threshold set; the abnormal data label is used for abnormal data judgment on the real-time data stream;
[0016] A comprehensive alarm decision determination module is configured to determine a comprehensive alarm decision based on the target threshold set and the abnormal data label.
[0017] In a third aspect, an electronic device is provided, comprising:
[0018] at least one processor; and,
[0019] a memory connected with the at least one processor; wherein,
[0020] the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the method for determining the integrated alarm decision as in the first aspect above.
[0021] In a fourth aspect, a computer readable storage medium is provided, having stored thereon a computer program, which, when executed by a processor, implements the method for determining the integrated alarm decision as in the first aspect above.
[0022] In a fifth aspect, a computer program product is provided, comprising a computer program which, when executed by a processor, implements the method for determining the integrated alarm decision as in the first aspect above.
[0023] The embodiment of the present disclosure discloses a method, device, equipment, medium and product for determining comprehensive alarm decision, which comprises: decomposing a live index data set by using a first preset processing algorithm to obtain a residual component of the live index data set; determining a dynamic threshold corresponding to each data segment in the residual component by using a preset adjustment mechanism based on a target three-sigma statistical model to obtain a first threshold set; the first threshold set is composed of a basic dynamic threshold corresponding to each data segment; wherein the target three-sigma statistical model is determined based on the residual component; the preset adjustment mechanism comprises an entropy weight adjustment mechanism, a trend correction adjustment mechanism and a fractal correction adjustment mechanism; correcting the first threshold set by using a Kalman filtering algorithm to obtain a second threshold set after correction; dynamically adjusting the second threshold set by using a Bayesian change point detection algorithm based on an abnormal data label and a real-time data stream to determine a target threshold set; the abnormal data label is used for abnormal data judgment on the real-time data stream; determining a comprehensive alarm decision based on the target threshold set and the abnormal data label. The technical solution dynamically determines the basic dynamic threshold corresponding to each data segment of the residual component based on the target three-sigma statistical model and in combination with the entropy weight, trend correction and fractal correction three adjustment mechanisms to form the first threshold set, realizes accurate capture of data characteristics and individualized adjustment of the threshold, and improves the adaptability and flexibility of abnormal detection; then the first threshold set is corrected by using the Kalman filtering algorithm to obtain a more accurate and stable second threshold set, which further improves the reliability of the threshold; based on the abnormal data label and the real-time data stream, the second threshold set is dynamically adjusted by using the Bayesian change point detection algorithm to determine the target threshold set, which enhances the response capability to real-time data changes and effectively reduces the false positive and false negative rates; finally, the comprehensive alarm decision is determined based on the target threshold set and the abnormal data label, which improves the abnormal detection capability and alarm accuracy of the live system and ensures the stable operation of the live service.
[0024] It should be understood that the content described in this part is not intended to identify key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the embodiments of the present disclosure. Other features of the embodiments of the present disclosure will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following will briefly introduce the drawings needed to be used in the embodiments description. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and other drawings can also be obtained by those skilled in the art without creative labor.
[0026] Figure 1is a flow chart of a comprehensive alarm decision determination method provided by an embodiment of the present disclosure;
[0027] Figure 2 is a result schematic diagram of a basic dynamic threshold provided by an embodiment of the present disclosure;
[0028] Figure 3 is an execution process schematic diagram of another comprehensive alarm decision determination method provided by an embodiment of the present disclosure;
[0029] Figure 4 is a structure schematic diagram of a comprehensive alarm decision determination device provided by an embodiment of the present disclosure;
[0030] Figure 5 is a structure schematic diagram of an electronic device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION
[0031] In order to enable persons skilled in the art to better understand the scheme of the embodiments of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by persons skilled in the art without creative labor should fall within the scope of protection of the present disclosure.
[0032] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily mean a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the present disclosure described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0033] Embodiment one
[0034] Figure 1A flowchart of a method for determining an integrated alarm decision provided by Embodiment One of the present disclosure. The embodiment can be applicable to the case of determining an integrated alarm decision. The method can be executed by an integrated alarm decision determining apparatus, which can be realized in the form of hardware and / or software. The integrated alarm decision determining apparatus can be configured in an electronic device, including but not limited to a computer, a computer, an electronic device, and a server, and other devices with data processing capabilities. As shown in FIG. 8, the method comprises the following steps. Figure 1
[0035] S110, decomposing the live index dataset by using a first preset processing algorithm to obtain a residual component of the live index dataset.
[0036] In this embodiment, the first preprocessing algorithm can be an algorithm for decomposing the live index dataset. For example, the first preprocessing algorithm can be a seasonal trend decomposition using Loess (STL) algorithm. STL can be a method for time series analysis, which helps to analyze and understand different change patterns in data by decomposing the time series into seasonal components, trend components, and residual components.
[0037] Specifically, the STL algorithm can be used to decompose the live index dataset to extract the residual component of the live index dataset. The residual component can be unexplained local fluctuations and abnormal signals. At the same time, the trend component and the seasonal component of the live index dataset can also be extracted to obtain a decomposition feature set. For example, the STL algorithm can be expressed as:
[0038]
[0039] wherein, is the live index dataset; is the trend component, reflecting the overall growth or decline trend; is the seasonal component, indicating periodic fluctuations (such as intra-day or periodic changes); is the residual component, containing unexplained local fluctuations and abnormal signals. Through STL decomposition, the trend, seasonal, and residual parts can be extracted respectively, so that subsequent detection of abnormal fluctuations can be more accurate, ensuring the sensitivity and stability of the television platform alarm in different time periods.
[0040] S120, determining, based on the target three-sigma statistical model, a dynamic threshold corresponding to each data segment in the residual component by using a preset adjustment mechanism, to obtain a first threshold set; the first threshold set is composed of a basic dynamic threshold corresponding to each data segment; wherein the target three-sigma statistical model is determined based on the residual component; the preset adjustment mechanism includes an entropy weight adjustment mechanism, a trend correction adjustment mechanism, and a fractal correction adjustment mechanism.
[0041] In this embodiment, the target three-sigma statistical model can be an extended statistical model, wherein the extended statistical model is an extension and improvement of the traditional principle, aiming to improve the accuracy and adaptability of anomaly detection. The extended statistical model dynamically adjusts the threshold according to the characteristics of the data (such as randomness, trend deviation, and complexity), thereby improving the accuracy and robustness of anomaly detection. The target three-sigma statistical model (i.e., the extended statistical model) is constructed for the residual component of the live index data set.
[0042] As described above, the data in the residual component can be segmented by using a sliding window to obtain each data segment. The dynamic threshold corresponding to each data segment in the residual component can be determined by using a preset adjustment mechanism to obtain a first threshold set, and the first threshold set is composed of a basic dynamic threshold corresponding to each data segment.
[0043] The preset adjustment mechanism can dynamically adjust the alarm threshold according to the randomness, trend deviation, and complexity of the data distribution to obtain the first threshold set. The preset adjustment mechanism can include an entropy weight adjustment mechanism, a trend correction adjustment mechanism, and a fractal correction adjustment mechanism. The entropy weight adjustment mechanism can adjust the threshold according to the randomness of the data. The greater the randomness of the data, the more appropriate the threshold is relaxed. The trend correction adjustment mechanism removes the trend component in the data, so that the target three-sigma statistical model can more accurately detect abnormal values. The fractal correction adjustment mechanism can adjust the threshold according to the complexity of the data. The greater the complexity of the data, the more appropriate the threshold is relaxed.
[0044] S130, based on the abnormal data label, using a Kalman filter algorithm to correct the first threshold set to obtain a second threshold set after correction.
[0045] Specifically, after obtaining the first threshold set, the first threshold set can be predicted and corrected based on the abnormal data label by using a Kalman filter algorithm. The principle of the Kalman filter update formula can be expressed as:
[0046]
[0047]
[0048] wherein, the posterior estimate (corrected state) obtained after fusion , can be the predicted (prior) state, which can represent the prediction (prior estimate) of the state at time based on the state at time before reaching the observation ; can be the Kalman gain, which determines the weight of the observation and the prediction on the final estimate; can be the actual observation value (real-time indicator data), which can take the first threshold set and the auxiliary anomaly label as the observation input of Kalman , or as a reference for weight adjustment. can represent the observation matrix, which is used to map the state to the observation space, can represent the error covariance of the prediction, can represent the measurement noise covariance. It needs to be explained that the Kalman filter is used to estimate and correct the first threshold set in real time. Its input includes the predicted state (from history or model) and real-time observation
[0049] (which can be the residual statistics of the current time, the anomaly data label, or some threshold observation value based on real-time data). Kalman will produce a predicted (prior) state (prediction of the threshold / parameter at the current or next time) at time ; combined with the observation value updated to the posterior state (corrected threshold estimate).
[0050] Therefore, Kalman not only corrects the threshold estimate at the current time, but also outputs the prediction at the next time, thereby affecting the subsequent time; it is not only used for instantaneous correction at a single time, but also smoothes and tracks the evolution of the threshold over time (the memory / smoothing characteristics are controlled by the state equation and the noise covariance).
[0051] It can be known that based on the anomaly data label, the first threshold set is predicted and corrected by using the Kalman filter algorithm, and the corrected second threshold set can be obtained.
[0052] S140, based on the anomaly data label and the real-time data stream, the second threshold set is dynamically adjusted by using the Bayesian variable point detection algorithm to determine the target threshold set; the anomaly data label is used for anomaly data judgment on the real-time data stream.
[0053] Specifically, a real-time data stream can be acquired, which can be online running continuous to come business monitoring indicators (such as a series of traffic, concurrency, error code collected every 30s / 60s), used to trigger detection and update the model in real time.
[0054] According to the above description, the abnormal data label can be used for abnormal data determination on the real-time data stream. Based on the abnormal data label and the real-time data stream, the second threshold set can be dynamically adjusted by using the Bayesian change point detection algorithm to determine the target threshold set. The Bayesian change point detection algorithm can be an algorithm based on the Bayesian statistical framework, which is used to detect the change point in the time series data. The change point refers to the sudden change of the potential parameter in the data sequence, which can indicate the change of the data generation process. The Bayesian change point detection algorithm identifies these change points by calculating the posterior probability of the change point occurrence.
[0055] The simplified formula of the principle of the Bayesian change point detection algorithm can be expressed as:
[0056]
[0057] Wherein, The posterior probability of the change point occurring at time t can be expressed as: The posterior probability of the change point occurring at time t can be expressed as: The posterior probability of the change point occurring at time t can be expressed as: The likelihood function under the condition of data before the change point can be expressed as: The prior probability can be expressed as:
[0058] It needs to be explained that the Kalman filter provides an adaptive state estimation method for smooth adjustment of the threshold; the Bayesian change point detection can identify the time point when the data structure changes dramatically, so as to quickly respond to the sudden traffic change in the TV platform and ensure the dynamic adaptability of the alarm strategy.
[0059] S150, determining a comprehensive alarm decision based on the target threshold set and the abnormal data label.
[0060] In this embodiment, after obtaining the target threshold set and the abnormal data label, a comprehensive alarm decision can be generated according to the target threshold set and the abnormal data label.
[0061] The embodiment provides a method for determining an integrated alarm decision, comprising: decomposing a live broadcast index data set by using a first preset processing algorithm to obtain a residual component of the live broadcast index data set; determining a dynamic threshold corresponding to each data segment in the residual component by using a preset adjustment mechanism based on a target three-sigma statistical model to obtain a first threshold set; the first threshold set is composed of a basic dynamic threshold corresponding to each data segment; wherein the target three-sigma statistical model is determined based on the residual component; the preset adjustment mechanism comprises an entropy weight adjustment mechanism, a trend correction adjustment mechanism and a fractal correction adjustment mechanism; correcting the first threshold set by using a Kalman filtering algorithm to obtain a second threshold set after correction; dynamically adjusting the second threshold set by using a Bayesian change point detection algorithm based on an abnormal data label and a real-time data stream to determine a target threshold set; the abnormal data label is used for abnormal data judgment on the real-time data stream; determining an integrated alarm decision based on the target threshold set and the abnormal data label. The technical scheme improves the accuracy and reliability of live broadcast system anomaly detection, reduces the false positive and false negative rates, and guarantees the stable operation of the live broadcast service.
[0062] As an optional implementation of the embodiment, the method for determining an integrated alarm decision provided by the embodiment further comprises, before the step of decomposing the live broadcast index data set by using the first preset processing algorithm:
[0063] 1) acquiring multi-source live broadcast index data.
[0064] In the embodiment, the multi-source live broadcast index data can be various index data of a live broadcast platform collected through multiple channels. For example, the multi-source live broadcast index data can be various index data of a live broadcast platform collected through real-time logs, user behaviors and network traffic, and used for constructing multi-source live broadcast index data containing time sequence, space and context information.
[0065] According to the above description, the multi-source data can also be acquired by a target television playing area, a video signal stream, through a capture card, a signal capture module, or directly from a television operation platform to capture a digital video stream; the target television playing area refers to a specific television content playing area, such as a certain channel, a certain program, an advertisement playing area, etc., which is a main monitoring object for subsequent video recognition and alarm; the video signal stream is a video stream signal output from a television or an operator set-top box, which can be a standard format such as HDMI, IPTV stream, TS stream, etc. The digital video stream is captured through a capture card, a signal capture module, or directly from a television operation platform. Tools such as FFMPEG and GStreamer are used to decode and frame extract the stream. The original data support is provided for subsequent image analysis to ensure the consistency and timeliness of the recognition result; the real-time and integrity of the video data are ensured to provide a basis for accurate judgment of the system.
[0066] 2) Based on a second preset processing algorithm, multi-scale time domain decomposition is performed on the preprocessed multi-source live indicator data to determine the live indicator data set; the live indicator data set includes the preprocessed live indicator data.
[0067] Specifically, after obtaining the multi-source live indicator data, the multi-source indicator data can be preprocessed to obtain preprocessed multi-source live indicator data. The preprocessing can include outlier rejection and noise filtering of the multi-source indicator data.
[0068] According to the above description, after obtaining the preprocessed multi-source live indicator data, the second preset processing algorithm can be used to perform multi-scale time domain decomposition on the preprocessed multi-source live indicator data, and then the live indicator data set can be determined.
[0069] Specifically, the live indicator data set refers to a data set obtained after data preprocessing and second preset processing algorithm decomposition, which is noise-removed, abnormal point-removed, and multi-scale smoothed. It can include: long-term trend component (long-term, low-frequency part) and short-term component after wavelet / filter smoothing (denoised time series value).
[0070] In this embodiment, the second preset processing algorithm can be an algorithm for multi-scale time domain decomposition. For example, the second preset processing algorithm can be wavelet transform. The formula of wavelet transform is:
[0071]
[0072] wherein, is the multi-source live indicator data of the live indicator at time , such as traffic, concurrency number; is a selected wavelet basis function used to capture local features of data; is a scale parameter, controlling the stretching of the wavelet function, reflecting different frequency components; is a shift parameter, used to locate the position of data in the time domain. The above formula decomposes the original data into multiple scale components through wavelet transform, separates the long-term trend and short-term noise, and provides a smooth data basis for subsequent anomaly detection and threshold tuning. For a TV platform, it can more accurately capture the multi-scale characteristics of traffic fluctuations, thereby reducing the interference of noise on alarms.
[0073] As an optional implementation of the present embodiment, the target three-sigma statistical model is used to dynamically determine the dynamic threshold corresponding to each data segment in the residual component by using a preset adjustment mechanism to obtain a first threshold set, including:
[0074] 1) The residual component is intercepted by using a sliding window to obtain each data segment in the residual component; wherein each time segment corresponds to a time point.
[0075] It should be noted that each data in the residual component of the live indicator data set can be a time data sequence. A sliding window of a specified length can be constructed in advance, and the residual component is intercepted by using the sliding window to obtain each data segment in the residual component, and each time segment corresponds to a time point.
[0076] 2) For each data segment, the threshold of the target three-sigma statistical model can be adjusted by using an entropy weight adjustment mechanism, a trend correction adjustment mechanism, and a fractal correction adjustment mechanism to obtain each initial dynamic threshold corresponding to the data segment; wherein the entropy weight adjustment mechanism is used to dynamically adjust the threshold according to the randomness of the data distribution in the data segment; the trend correction adjustment mechanism is used to dynamically adjust the threshold according to the trend deviation of the data segment; and the fractal correction adjustment mechanism is used to dynamically adjust the threshold according to the data complexity of the data segment.
[0077] Specifically, for any data segment, the Sigma threshold of the target three-sigma statistical model can be adjusted by using the entropy weight adjustment mechanism, the trend correction adjustment mechanism, and the fractal correction adjustment mechanism to obtain each initial dynamic threshold corresponding to the current data segment; each initial dynamic threshold can be obtained by adjusting the threshold of the target three-sigma statistical model by using the entropy weight adjustment mechanism, the trend correction adjustment mechanism, and the fractal correction adjustment mechanism.
[0078] According to the above description, the entropy weight adjustment mechanism is used to dynamically adjust the threshold according to the randomness of the data distribution in the current data segment to obtain the initial dynamic threshold adjusted by the entropy weight adjustment mechanism. The initial dynamic threshold obtained by adjusting the Sigma threshold of the target three-sigma statistical model by using the entropy weight adjustment mechanism can be expressed as Then we have
[0079]
[0080] wherein, may represent the time point The mean of the current data segment of the residual data calculated by a sliding window; may represent the time point The standard deviation of the current data segment of the residual data calculated by a sliding window; may be an entropy weight adjustment factor, which is adjusted according to the actual business scenario and the degree of flow fluctuation, and the value is between 0 and 1; may represent the time point The entropy value of the current data segment of the residual data calculated by a sliding window, which is used to measure the randomness and uncertainty of the data distribution of the current data segment, and the calculation method is:
[0081]
[0082] wherein, may represent the probability of data falling into each segment in a sliding window. Wherein, the segment refers to the interval bin used to calculate the entropy The sliding window can be 60 minutes, and the data segment of the sliding window can be divided into 5 intervals (for example, divided according to the numerical range or divided according to the quantile): interval 1: , interval 2: , , interval 5: . The sample frequency in each interval is used for entropy calculation. The implementation can be selected: equal-width binning, equal-frequency binning (quantile), or custom segmentation based on business thresholds, depending on the data distribution and stability. The above formula introduces the concept of data entropy on the basis of traditional By weighting the randomness of data (entropy value), the threshold can be automatically increased when the data fluctuates greatly (high entropy), reducing false positives; and the threshold can be reduced when the data is relatively stable, improving sensitivity. For a television platform, this dynamic adjustment can better cope with the flow difference between peak and trough periods, thereby achieving accurate alarm; the entropy value calculation of data can automatically relax the threshold when the data fluctuates greatly (high entropy), reducing the risk of false positives.
[0083] Specifically, the initial dynamic threshold obtained by adjusting the Sigma threshold of the target three-sigma statistical model using the fractal correction adjustment mechanism can be represented as Then we have
[0084]
[0085] wherein, may represent the trend deviation at time the mean of the current data segment of the residual data calculated by a sliding window; may represent the trend deviation at time the standard deviation of the current data segment of the residual data calculated by a sliding window; may be a dynamic adjustment factor, which dynamically changes relative to the traditional fixed factor 3 due to the influence of trend deviation, may be represented as:
[0086]
[0087] wherein, is a trend correction coefficient, used to adjust the influence degree of the trend deviation in the threshold value, and is a positive number, which is adjusted according to the actual fluctuation; may represent the trend deviation at time , which is defined as the difference between the actual index value and the predicted trend value. The predicted trend is obtained by linear regression or other time series models. The above formula considers the deviation caused by trend changes in actual business into the threshold setting. When the actual traffic is significantly higher or lower than the trend prediction, the value is larger, so that is increased, and the threshold value is relaxed or tightened, so as to avoid frequent false alarms or omissions caused by trend deviation, and more accurately capture the short-term trend changes in the television platform caused by promotional activities, holidays and other factors, and enhance the adaptability of the alarm system.
[0088] Specifically, the initial dynamic threshold value obtained by adjusting the Sigma threshold value of the target three-sigma statistical model by using the trend correction adjustment mechanism can be represented as , then:
[0089]
[0090] wherein, may represent the trend deviation at time the mean of the current data segment of the residual data calculated by a sliding window; may represent the trend deviation at time the standard deviation of the current data segment of the residual data calculated by a sliding window; is the signal fractal dimension measured at time , which is used to reflect the complexity and self-similarity of the data, and is obtained by box counting method or related dimension estimation; is the benchmark fractal dimension (such as 1.5), which represents the expected complexity of the data under normal operation; The fractal correction factor is used to amplify or suppress the influence of the fractal dimension deviation on the threshold value, and its value can be obtained by offline experiments to achieve the best match.
[0091] The above formula uses the fractal dimension to describe the complex structure characteristics of the data. When the live index presents high complexity, ) the abnormal threshold is automatically increased to reduce noise interference; otherwise, the threshold is reduced to capture minor abnormalities. This method is particularly suitable for scenarios where the data structure may change due to business adjustments and emergencies in the television platform, and can adaptively adjust the alarm strategy to improve the robustness of anomaly detection.
[0092] 3) Determine the basic dynamic threshold corresponding to the data segment based on each initial dynamic threshold.
[0093] Specifically, the Sigma threshold of the target three-sigma statistical model is adjusted through the entropy weight adjustment mechanism, the trend correction adjustment mechanism, and the fractal correction adjustment mechanism to obtain each initial dynamic threshold corresponding to each data segment. For each initial dynamic threshold corresponding to any data segment, each initial dynamic threshold can be processed through weighted fusion or decision logic, and then the basic dynamic threshold corresponding to the data segment can be determined.
[0094] 4) Based on the basic dynamic threshold corresponding to each data segment, the first threshold set is constructed; the first threshold set includes the basic dynamic threshold corresponding to each time point.
[0095] It can be known that after obtaining the basic dynamic threshold corresponding to each data segment, the basic dynamic threshold corresponding to each data segment can be combined to obtain the first threshold set.
[0096] As an optional implementation of the embodiment, the determination method of the comprehensive alarm decision provided by the embodiment further includes:
[0097] The live index data set is detected for abnormal data using a second preset processing algorithm to obtain the abnormal data label.
[0098] In the embodiment, the second preset processing algorithm can be an algorithm for detecting abnormal data. For example, the second preset processing algorithm can be a local outlier factor algorithm (Local Outlier Factor, LOF). The LOF algorithm can be an algorithm for identifying outliers (abnormal points) in data. It determines whether a point is an outlier by evaluating the density of the point in the local neighborhood. Specifically, the LOF algorithm compares the density of a point with its neighboring points. If the density of a point is significantly lower than that of its neighboring points, the point is considered an outlier.
[0099] Specifically, the live streaming metric dataset is processed using a second pre-defined processing algorithm to detect abnormal data and obtain the abnormal data labels. These abnormal data labels (output by methods such as LOF) represent local anomalies identified within the sliding window (e.g., an LOF score exceeding a threshold is marked as abnormal). These labels serve as one of the reference inputs for subsequent multi-model decision-making and Kalman correction.
[0100] Following the above description, the formula for the Local Outlier Factor (LOF) method can be expressed as:
[0101]
[0102] in, It can represent the data point to be detected. It can represent data points The neighborhood set; It can represent data points Locally accessible density, used to measure The density of surrounding points; It can be of Neighboring points, It can represent data points Locally accessible density, used to measure The density of surrounding points. The LOF algorithm can capture local outliers when the data distribution does not meet the normality assumption. Compare LOF results with extended... By combining models, local abnormal data caused by sudden events or abnormal operations in the television platform can be effectively identified, reducing the false alarm rate.
[0103] As an optional implementation of this embodiment, the method for determining comprehensive alarm decisions provided in this embodiment, after determining the comprehensive alarm decision based on the target threshold set and the abnormal data labels, further includes:
[0104] 1) Execute the comprehensive alarm decision and collect the alarm feedback results generated after the comprehensive alarm decision is executed.
[0105] It is understood that after determining the comprehensive alarm decision based on the target threshold set and abnormal data labels, the comprehensive alarm decision can be run, and alarm feedback results generated after the decision is executed can be collected. These alarm feedback results can include: manually confirmed true / false alarms and operation and maintenance response results.
[0106] 2) Based on the alarm feedback results, the set of learnable parameters in the comprehensive alarm decision-making process is updated using a preset learning algorithm to obtain an optimized set of parameters.
[0107] Specifically, after obtaining the alarm feedback result, the alarm feedback result can be taken as a feedback to form an instant reward signal, and the preset learning algorithm can use the instant reward signal to update the learnable parameter set in the comprehensive alarm decision determination process to obtain an optimized parameter set.
[0108] The learnable parameter set includes at least one of a learnable parameter of a preset adjustment mechanism, a learnable parameter of a Kalman filter algorithm, a learnable parameter of a Bayesian change point detection algorithm, a learnable parameter of a preset learning algorithm, and a learnable parameter of a second preset processing algorithm. For example, the learnable parameter set can include a threshold adjustment factor , or some learnable parameters of Kalman / Bayesian. It should be noted that the learnable parameter set can include an entropy weight factor , a trend correction coefficient , a fractal correction factor , a fusion weight in the preset adjustment mechanism; a process noise covariance Q, a measurement noise covariance R, and an initial error covariance P0 (and a learnable gain adjustment strategy if an adaptive Kalman is used) in the Kalman filter; a prior probability / hazard rate in the Bayesian change point detection, parameters of a likelihood function (such as assumed distribution parameters) for controlling change point sensitivity; a learning rate , a discount factor , an action set (such as adjusting which weights / factors), a reward function definition (based on accuracy / falsely alarm / misreport / response time delay construction) in the reinforcement learning layer (Q-learning); a LOF neighborhood size k, a LOF judgment threshold, and the like in the auxiliary detector threshold. That is, the learnable parameter set can include both upper-layer statistical / fusion parameters and lower-layer filter / change point algorithm hyperparameters.
[0109] In this embodiment, the preset learning algorithm can be a pre-set algorithm, such as a Q-learning algorithm (or other online learners). Based on the Q-learning algorithm, the alarm feedback is learned, and the parameters in the Kalman filter and the Bayesian change point detection are automatically adjusted to further optimize the real-time dynamic threshold to obtain an optimized parameter set.
[0110] The principle formula of the Q-learning algorithm is:
[0111]
[0112] wherein, can represent the expected return of taking action in state . , which can represent the learning rate, can determine the degree of influence of new information; , which can represent the immediate reward signal, can be defined based on the alarm accuracy, false alarm rate; , which can represent the discount factor, is used to measure the importance of future rewards; , which can represent the next state, , which can be in the state , which can be the next optional action.
[0113] Through reinforcement learning, the threshold tuning parameters can be continuously adjusted according to the actual alarm effect. The real-time feedback reward signal enables the model to adaptively optimize the early warning strategy in the TV service scenario, improving the overall alarm accuracy and response efficiency.
[0114] 3) Based on the optimized parameter set, updating the comprehensive alarm decision.
[0115] Specifically, after obtaining the optimized parameter set, a weighted fusion strategy can be used to update the comprehensive alarm decision. For example, the target threshold set, the abnormal data label, and the optimized parameter set can be fused to form an updated comprehensive alarm decision. The updated comprehensive alarm decision is determined again using the optimized parameter set and continues to run online. This cycle is continuous and gradually improved. By establishing this closed-loop feedback mechanism, the actual alarm events and service response data are used to periodically evaluate the accuracy of the comprehensive alarm decision, and the parameters are continuously optimized based on historical feedback to obtain a continuously updated model strategy, ensuring that the system maintains optimal early warning performance in a constantly changing TV service environment.
[0116] The embodiment also provides an execution process for determining a target threshold based on fusion entropy weight, trend correction, and fractal correction, which specifically includes:
[0117] 1) Data acquisition and preprocessing:
[0118] Data acquisition: Real-time data acquisition is performed using the log server of the live broadcast platform, including the number of viewers, the number of concurrent connections, traffic, error code statistics, etc. Historical data is captured through an Application Programming Interface (API) at regular intervals (every minute), combined with the daily, weekly, and monthly statistical data stored in the database. Data transmission uses an encrypted channel and is stored in a high-performance time series database.
[0119] Data preprocessing: Abnormal data elimination: Use Principle: preliminary elimination of obvious abnormal data. Wavelet transform decomposition: use discrete wavelet transform to decompose the data at multiple scales, separate long-term trends and short-term noise. For data collected every minute: data collection time window: 60 minutes; wavelet basis: Daubechies 4; scale parameter a: value range is 1,8; translation parameter b: corresponding to the data time scale; using RESTful API polling, data packet encryption transmission protocol, and data storage format (such as JSON or CSV), the collection record is: timestamp: 2025-03-01 10:00:00; traffic: 4500 Mbps; concurrent number: 25000; error code: 2.
[0120] Abnormal value detection process: within a 60-minute window, if the mean value of the collected data traffic is , the standard deviation is , then the upper and lower limits of data anomaly are , and data records exceeding this range will be marked as abnormal and excluded.
[0121] 2) Determine the threshold value using the preset adjustment mechanism:
[0122] Entropy weight adjustment mechanism: calculate the mean value and standard deviation of the data in the sliding window (60 minutes); calculate the data entropy :
[0123]
[0124] Among them, the data is divided into 5 intervals, and the frequency statistics are used to obtain the interval probability ; further, the data in the 60-minute window is divided into 5 intervals. Interval 1: , interval 2: , interval 3: , interval 4: , interval 5: , count the number of samples in each interval, and calculate the probability of each interval = the number of samples in this interval / total number of samples. Parameter setting: entropy weight factor: ; the threshold formula can be expressed as:
[0125]
[0126] Trend correction mechanism: use historical data to build a simple linear regression model to predict trends, calculate the trend deviation (the average of the difference between actual value and predicted value). Parameter setting: trend correction coefficient ; threshold formula:
[0127]
[0128]
[0129] Fractal correction mechanism: The fractal dimension of the signal is calculated using the box counting method. ; Benchmark fractal dimension Set to 1.5, which is an empirical value under normal conditions; Parameter setting: fractal correction factor Threshold formula:
[0130]
[0131] Comprehensive fusion: A weighted fusion strategy is used to obtain the final dynamic threshold. :
[0132]
[0133] The initial weights are set as follows: , , The parameters are dynamically adjusted based on actual feedback. Table 1 shows the parameter setting instructions.
[0134] Table 1 Parameter Setting Instructions
[0135]
[0136] Figure 2 This is a schematic diagram of a basic dynamic threshold result provided in this embodiment, as shown below. Figure 2 As shown, the manual threshold differs significantly from the true value of the indicator and is a fixed value. However, the threshold determined by this technical solution through a combination of entropy, trend, and fractal mechanisms has the same trend as the true value of the indicator and can change dynamically.
[0137] As can be seen from the above, by combining the three mechanisms of entropy, trend and fractal, the system can automatically relax the threshold when the flow fluctuates greatly to prevent false alarms; when the flow is stable or the trend deviation is small, the threshold is reduced to achieve early warning.
[0138] Furthermore, Figure 3 This embodiment also provides a schematic diagram illustrating the execution process of another comprehensive alarm decision determination method. For example... Figure 3 As shown, it specifically includes:
[0139] Data Acquisition: During peak live broadcast periods on a certain television platform, the operation and maintenance monitoring platform was used to collect multi-dimensional data in real time, including server load, network traffic, service response time, error codes, and memory usage. Data was automatically uploaded to the central data warehouse via SNMP, log collectors, and application programming interfaces (APIs). The data update frequency was set to every 30 seconds. The collected data is shown in Table 2.
[0140] Table 2 Data Collection Description
[0141]
[0142] Data preprocessing: including outlier rejection and multi-scale decomposition using wavelet transform to separate long-term trend and short-term noise to determine live indicator dataset.
[0143] Determine the first threshold set using the preset adjustment mechanism: STL decomposition is performed on each monitoring indicator to extract trend component, seasonal component and residual component; entropy, trend and fractal correction mechanism is used to construct initial threshold, and parameter value is adjusted combined with the characteristics of each indicator: for traffic indicators: , , ; for concurrent connections: , , . Get the basic dynamic threshold of each indicator (the first threshold set).
[0144] Abnormal data label determination: local outlier detection is performed on each indicator using LOF algorithm to obtain abnormal data label; and the abnormal data label is used as the input of subsequent multi-model decision.
[0145] Real-time alarm generation: the dynamic threshold result based on the extended (including entropy, trend, fractal adjustment) and the LOF detection result are weighted and fused to obtain a comprehensive alarm decision; the comprehensive alarm decision is a "score / judgment" from several sources (each source is called ) fused into a total abnormal score according to the weight , and then is compared with one or more thresholds to obtain the final alarm level. These sources include (but are not limited to) dynamic threshold candidates (entropy / trend / fractal), auxiliary abnormal labels (such as LOF score or binary label), Kalman / Bayes corrected threshold deviation and other business indicators;
[0146] Further, there are detection sources (or indicators / models) to generate decision / score (for example judgment score from extended , LOF score, threshold relative deviation corrected by Kalman), each source is assigned a weight . The fusion formula can be expressed as:
[0147]
[0148] wherein, It can be the first The output of a model / indicator (which can be...) Binary, or it can be (abnormal probability or score); It can be the first Each model / indicator corresponds to a weight (the sum of the weights is usually normalized to 1); Different models or metrics can be indexed. In this embodiment, live stream traffic, concurrent connections, and error code statistics are used as different dimensions. Each dimension can be further fused into a model, and differentiated weights can be set for different metrics, such as traffic weight 0.5, concurrency weight 0.3, and error code weight 0.2. The configuration of each parameter is shown in Table 3.
[0149] Table 3 Parameter Configuration Instructions
[0150]
[0151] Real-time optimization and closed-loop feedback: Kalman filtering is used to correct the dynamic thresholds of each indicator in real time, and Bayesian change point detection is used to capture sudden events; the parameter update frequency is set to every minute, and the state estimate is dynamically adjusted according to new data. A real-time alarm feedback channel is established to feed back alarm triggering, actual business response, and operation and maintenance intervention effects to the Q-learning algorithm; the Q-learning algorithm is used to adaptively update optimizable parameters (such as fusion weights and adjustment factors), with the Q-learning formula as before and a learning rate set. Discount Factor The aforementioned technical solution, through trend correction and fractal correction mechanisms, successfully identifies abnormal traffic fluctuations caused by large-scale events, triggering early warnings and assisting the operations and maintenance team in rapidly expanding resources, thus avoiding service interruptions caused by traffic overload. The closed-loop feedback mechanism enables the system to adapt, quickly adjusting alarm thresholds in scenarios such as sudden traffic surges and business changes, achieving stable and efficient operations and maintenance management.
[0152] This technical solution involves multi-source data acquisition, data preprocessing and wavelet transform decomposition, and expansion. The fusion of statistical modeling and adjustment mechanisms, auxiliary anomaly detection, real-time dynamic threshold tuning, adaptive reinforcement learning tuning, and multi-model decision fusion, among which the fusion A dynamic benchmark model, entropy weight sensitivity tuning mechanism, trend correction algorithm, and fractal correction method are used to construct an adaptive, scene-aware, trend-robust, and anomaly-accurate dynamic threshold tuning and intelligent alarm model in real-time TV playback monitoring. This model enables dynamic optimization and adjustment of thresholds based on context such as time, scene, and channel, overcoming the bottleneck of false alarms and missed alarms in static alarm models. The system can learn from historical behavior and continuously optimize alarm logic, constructing a closed loop of automated and intelligent operation and maintenance. The beneficial effects of the above technical solution include:
[0153] (1) Through fusion Dynamic benchmark model, entropy weight sensitivity tuning mechanism, trend correction algorithm and fractal correction method, in the real-time monitoring of television broadcast, a dynamic threshold tuning and intelligent alarm model with self-adaptation, scene perception, trend robustness and accurate abnormality identification is constructed, which realizes the dynamic optimization and adjustment of threshold with time, scene, channel and other contexts, breaks through the bottleneck of false alarm and missed alarm of static alarm model; improve the accuracy and response speed of complex broadcast abnormality (such as screen, black screen, lag, etc.) identification, and strengthen the safety broadcast protection; the system can self-learn and continuously optimize the alarm logic according to the historical behavior, and construct the automation and intelligent closed loop of operation and maintenance; enhance the nonlinear anomaly detection capability, effectively identify the trend and structural potential fault signals, and realize early warning.
[0154] (2) By combining image classification and anomaly detection mechanisms, the false positive rate and false negative rate are reduced; Systematic replacement of manual monitoring, 7x24 hours real-time monitoring and response are realized; Fusion of context understanding and alarm level evaluation, promote the "perception-judgment-response" closed loop intelligent operation and maintenance; Support multi-dimensional data integration and display, improve information processing and fault location efficiency; The model and strategy can be flexibly deployed according to region, channel and scene, and have good horizontal expansion capability.
[0155] Embodiment two
[0156] Figure 4 is a structural schematic diagram of a comprehensive alarm decision determination device provided by the second embodiment of the present disclosure; as Figure 4 shown, the device comprises a decomposition module 210, a first threshold set determination module 220, a second threshold set determination module 230, a target threshold set determination module 240, and a comprehensive alarm decision determination module 250.
[0157] The decomposition module 210 is configured to decompose a live index data set by using a first preset processing algorithm to obtain a residual component of the live index data set.
[0158] The first threshold set determination module 220 is configured to dynamically determine a dynamic threshold corresponding to each data segment in the residual component by using a preset adjustment mechanism based on a target three-sigma statistical model to obtain a first threshold set; the first threshold set is composed of a basic dynamic threshold corresponding to each data segment; wherein the target three-sigma statistical model is determined based on the residual component; the preset adjustment mechanism includes an entropy weight adjustment mechanism, a trend correction adjustment mechanism and a fractal correction adjustment mechanism.
[0159] The second threshold set determination module 230 is configured to correct the first threshold set by using a Kalman filter algorithm to obtain a second threshold set after correction.
[0160] The target threshold set determination module 240 is configured to dynamically adjust the second threshold set based on the abnormal data label and the real-time data stream by using a Bayesian change point detection algorithm to determine a target threshold set.
[0161] The comprehensive alarm decision determination module 250 is configured to determine a comprehensive alarm decision based on the target threshold set and the abnormal data label.
[0162] Embodiment two of the present disclosure provides a determination apparatus of a comprehensive alarm decision, which improves the accuracy and reliability of live streaming system anomaly detection, reduces the false positive and false negative rates, and guarantees the stable operation of live streaming services.
[0163] Further, the first threshold set determination module 220 is further configured to:
[0164] The residual components are intercepted by using a sliding window to obtain each data segment in the residual components; each time segment corresponds to a time point.
[0165] For each data segment, the threshold of the target three-sigma statistical model is adjusted by an entropy weight adjustment mechanism, a trend correction adjustment mechanism and a fractal correction adjustment mechanism to obtain each initial dynamic threshold corresponding to the data segment; the entropy weight adjustment mechanism is configured to dynamically adjust the threshold according to the randomness of the data distribution in the data segment; the trend correction adjustment mechanism is configured to dynamically adjust the threshold according to the trend deviation of the data segment; and the fractal correction adjustment mechanism is configured to dynamically adjust the threshold according to the data complexity of the data segment.
[0166] The basic dynamic threshold corresponding to the data segment is determined based on each initial dynamic threshold.
[0167] The first threshold set is constructed based on the basic dynamic threshold corresponding to each data segment; the first threshold set includes the basic dynamic threshold corresponding to each time point.
[0168] Further, the apparatus further includes:
[0169] The abnormal data label determination module is configured to perform abnormal data detection on the live streaming index data set by using a second preset processing algorithm to obtain the abnormal data label.
[0170] Further, the apparatus further includes:
[0171] The execution module is configured to execute the comprehensive alarm decision and collect an alarm feedback result generated after the execution of the comprehensive alarm decision.
[0172] The parameter updating module is configured to update a set of learnable parameters in the comprehensive alarm decision determination process based on the alarm feedback result and by using a preset learning algorithm, to obtain an optimized set of parameters.
[0173] The decision updating module is configured to update the comprehensive alarm decision based on the optimized set of parameters.
[0174] Further, the set of learnable parameters includes at least one of a learnable parameter of a preset adjustment mechanism, a learnable parameter of a Kalman filter algorithm, a learnable parameter of a Bayesian change point detection algorithm, a learnable parameter of a preset learning algorithm, and a learnable parameter of a second preset processing algorithm.
[0175] Further, the apparatus further includes:
[0176] The data acquisition module is configured to acquire multi-source live streaming index data.
[0177] The live streaming index data set determination module is configured to perform multi-scale time domain decomposition on the preprocessed multi-source live streaming index data based on a second preset processing algorithm, to determine the live streaming index data set; the live streaming index data set includes the preprocessed live streaming index data.
[0178] The apparatus for determining a comprehensive alarm decision provided in the embodiments of the present disclosure can execute the method for determining a comprehensive alarm decision provided in any of the embodiments of the present disclosure, and has the corresponding function modules and beneficial effects of executing the method.
[0179] Embodiment Three
[0180] Figure 5 A structural schematic diagram of an electronic device 10 that can be used to implement the embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The components shown here, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the embodiments of the present disclosure described and / or claimed in this document.
[0181] As Figure 5As shown, the electronic device 10 includes at least one processor 11, and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., connected to the at least one processor 11 in communication. The memory stores a computer program executable by the at least one processor 11, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0182] A plurality of components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc., an output unit 17, such as various types of displays, a speaker, etc., a storage unit 18, such as a magnetic disk, an optical disk, etc., and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.
[0183] The processor 11 can be various general and / or special-purpose processing components having processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microprocessor, etc. The processor 11 performs various methods and processes described above, such as the determination method of the integrated alarm decision.
[0184] In some embodiments, the determination method of the integrated alarm decision can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the determination method of the integrated alarm decision described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to perform the determination method of the integrated alarm decision by any other appropriate means, such as by means of firmware.
[0185] The various embodiments of the systems and techniques described above can be implemented in digital electronic circuitry, integrated circuitry, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system on a chip systems (SOCs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0186] Computer programs used to implement embodiments of the present disclosure can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer program, when executed, can cause instructions described in flow charts and / or block diagrams to be implemented on the computer. The computer program can be executed entirely on a machine, partially on a machine, partially on a machine as a standalone software package and partially on a remote machine, or entirely on a remote machine or server.
[0187] In the context of the present embodiments, a computer-readable storage medium can be a tangible medium that can contain or store computer programs for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium will include one or more lines of electrical connections, portable computer disks, hard disk drives, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), optical fibers, portable compact disc read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0188] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0189] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), blockchain network, and the Internet.
[0190] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. A server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service.
[0191] It should be understood that the various forms of flow shown above can be re-ordered, added to, or deleted from without departing from the scope of the present disclosure. For example, the steps recited in the embodiments of the present disclosure can be executed in parallel, in series, or in a different order, as long as the desired results of the technical solutions of the embodiments of the present disclosure can be achieved, and the present disclosure is not limited herein.
[0192] The specific implementation described above does not constitute a limitation on the protection scope of the embodiments of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the embodiments of the present disclosure should be included in the protection scope of the embodiments of the present disclosure.
[0193] The embodiments of the present disclosure also provide a computer program product, comprising a computer program and / or instructions, which, when executed by a processor, implement the method for determining an integrated alarm decision as provided by any of the embodiments of the present disclosure.
[0194] The computer program product, in the implementation, can be written in one or more programming languages or combinations thereof to implement computer program codes for performing operations of the embodiments of the present disclosure, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" language or similar programming languages. The program codes can be executed entirely on a user computer, partially on a user computer, as an independent software package, partially on a user computer and partially on a remote computer, or entirely on a remote computer or server. In the case involving a remote computer, the remote computer can be connected to the user computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, through the Internet by using an Internet service provider).
[0195] Note that the above are only preferred embodiments of the embodiments of the present disclosure and the technical principles applied. Those skilled in the art will understand that the embodiments of the present disclosure are not limited to the specific embodiments herein, and those skilled in the art can make various obvious changes, readjustments, and substitutions without departing from the protection scope of the embodiments of the present disclosure. Therefore, although the embodiments of the present disclosure have been described in more detail through the above embodiments, the embodiments of the present disclosure are not limited to the above embodiments, and can include more other equivalent embodiments without departing from the concept of the embodiments of the present disclosure, and the scope of the embodiments of the present disclosure is determined by the scope of the appended claims.
Claims
1. A method for determining comprehensive alarm decisions, characterized in that, include: The live streaming metric dataset is decomposed using a first preset processing algorithm to obtain the residual components of the live streaming metric dataset. Based on the target three sigma statistical model, a preset adjustment mechanism is used to dynamically determine the dynamic thresholds corresponding to each data segment in the residual components to obtain a first threshold set; the first threshold set is composed of the basic dynamic thresholds corresponding to each data segment; wherein, the target three sigma statistical model is determined based on the residual components; the preset adjustment mechanism includes an entropy weight adjustment mechanism, a trend correction adjustment mechanism, and a fractal correction adjustment mechanism; The first threshold set is corrected using the Kalman filter algorithm to obtain the corrected second threshold set; Based on abnormal data labels and real-time data streams, the second threshold set is dynamically adjusted using a Bayesian change point detection algorithm to determine the target threshold set; the abnormal data labels are used to determine abnormal data in the real-time data stream. A comprehensive alarm decision is determined based on the target threshold set and the abnormal data labels.
2. The method according to claim 1, characterized in that, The target three-sigma statistical model utilizes a preset adjustment mechanism to dynamically determine the dynamic thresholds corresponding to each data segment in the residual components, thereby obtaining a first threshold set, including: The residual components are truncated using a sliding window to obtain each data segment in the residual components; wherein each time segment corresponds to a time point. For each data segment, the thresholds of the target three-sigma statistical model are adjusted using an entropy weight adjustment mechanism, a trend correction adjustment mechanism, and a fractal correction adjustment mechanism to obtain the initial dynamic thresholds corresponding to the data segment. Specifically, the entropy weight adjustment mechanism dynamically adjusts the thresholds based on the randomness of the data distribution in the data segment; the trend correction adjustment mechanism dynamically adjusts the thresholds based on the trend deviation of the data segment; and the fractal correction adjustment mechanism dynamically adjusts the thresholds based on the data complexity of the data segment. The basic dynamic threshold corresponding to the data segment is determined based on each initial dynamic threshold. Based on the basic dynamic thresholds corresponding to each data segment, the first threshold set is constructed; the first threshold set includes the basic dynamic thresholds corresponding to each time point.
3. The method according to claim 1, characterized in that, The method further includes: The second preset processing algorithm is used to detect abnormal data in the live streaming indicator dataset to obtain the abnormal data labels.
4. The method according to claim 3, characterized in that, After determining the comprehensive alarm decision based on the target threshold set and the abnormal data labels, the method further includes: Execute the comprehensive alarm decision and collect the alarm feedback results generated after the comprehensive alarm decision is executed; Based on the alarm feedback results, the set of learnable parameters in the comprehensive alarm decision-making process is updated using a preset learning algorithm to obtain an optimized set of parameters. The comprehensive alarm decision is updated based on the optimized parameter set.
5. The method according to claim 4, characterized in that, The set of learnable parameters includes at least one of the following: learnable parameters of a preset adjustment mechanism, learnable parameters of a Kalman filter algorithm, learnable parameters of a Bayesian change point detection algorithm, learnable parameters of a preset learning algorithm, and learnable parameters of a second preset processing algorithm.
6. The method according to claim 1, characterized in that, Before decomposing the live streaming metric dataset using the first preset processing algorithm, the method further includes: Obtain multi-source live streaming metrics data; Based on the second preset processing algorithm, the preprocessed multi-source live streaming indicator data is decomposed into multi-scale time domain to determine the live streaming indicator dataset; the live streaming indicator dataset includes the preprocessed live streaming indicator data.
7. A device for determining comprehensive alarm decisions, characterized in that, include: The decomposition module is used to decompose the live streaming indicator dataset using a first preset processing algorithm to obtain the residual components of the live streaming indicator dataset. The first threshold set determination module is used to dynamically determine the dynamic thresholds corresponding to each data segment in the residual components based on the target three sigma statistical model and using a preset adjustment mechanism to obtain the first threshold set; the first threshold set is composed of the basic dynamic thresholds corresponding to each data segment; wherein, the target three sigma statistical model is determined based on the residual components; the preset adjustment mechanism includes an entropy weight adjustment mechanism, a trend correction adjustment mechanism, and a fractal correction adjustment mechanism; The second threshold set determination module is used to modify the first threshold set using the Kalman filter algorithm to obtain the modified second threshold set. The target threshold set determination module is used to dynamically adjust the second threshold set based on abnormal data labels and real-time data stream using a Bayesian change point detection algorithm to determine the target threshold set; the abnormal data labels are used to determine abnormal data in the real-time data stream; The comprehensive alarm decision determination module is used to determine a comprehensive alarm decision based on the target threshold set and the abnormal data labels.
8. An electronic device, characterized in that, include: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the method for determining a comprehensive alarm decision as described in any one of claims 1-6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by the processor, the program implements the method for determining the comprehensive alarm decision as described in any one of claims 1-6.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the method for determining comprehensive alarm decisions as described in any one of claims 1-6.