MR user portrait generation system based on data mining
The MR user profile generation system based on data mining solves the problem that traditional systems cannot reflect changes in user behavior in real time. It enables dynamic adjustment of user profiles and stable response under high-frequency interaction, improving the synchronicity and robustness of the interactive experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HUNAN XIANGJIANG SHUTU INFORMATION TECH INNOVATION CENT CO LTD
- Filing Date
- 2026-01-16
- Publication Date
- 2026-04-10
AI Technical Summary
Traditional MR user profile generation systems are prone to data lag and profile drift when multiple scenarios are running in parallel or behaviors are frequently switching. They cannot reflect changes in user behavior in a timely manner, resulting in a fixed profile update cycle with a lack of flexible adjustment, which affects the synchronicity and immersion of virtual and real interaction.
The MR user profile generation system based on data mining includes a behavior pattern analysis module, a profile trend inference module, an anomaly evolution analysis module, and a periodic adjustment and optimization module. It generates a mixed reality user behavior association model, identifies key behavior nodes and trends, optimizes the profile update cycle, and achieves dynamic adjustment.
It improves the accuracy of behavior pattern recognition and the continuity of trend inference, ensures the stable evolution and consistent response of user profiles in complex scenarios, enhances the robustness and update sensitivity of the system under high-frequency interaction, optimizes the segmented revision of profile update cycle, and improves the coordination of interactive experience.
Smart Images

Figure CN121542859B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer human-computer interaction, and in particular to an MR user portrait generation system based on data mining. BACKGROUND
[0002] The technical field of computer human-computer interaction relates to the implementation of information exchange and instruction response between users and computer systems, and its core matters include the collection of input information, the identification of user intent, the generation of interface feedback, and the collaborative processing of multi-modal interaction methods. This technical field comprehensively utilizes computer vision, speech recognition, posture tracking, and environmental perception methods to achieve the interactive fusion of virtual space and real environment, so that users can complete instruction input and environmental control through natural actions, speech, or visual focus. The development of human-computer interaction technology has promoted the formation of virtual reality, augmented reality, and mixed reality scenarios, and gradually expanded towards intelligence and immersion. Among them, the traditional MR user portrait generation system refers to a feature modeling method based on user behavior data in a mixed reality environment. Its technical matters are how to form a portrait model that reflects individual user characteristics in a virtual and real fusion scenario. The traditional system collects raw interaction data such as user head posture, hand movements, gaze points, and speech content, and then uses statistical analysis methods to extract and classify features from the data, mapping them as behavior labels or feature vectors to describe user preferences, habits, and interaction patterns.
[0003] The traditional mixed reality user portrait generation method relies on feature extraction of static behavior data and lacks dynamic modeling of the coupling relationship between action changes and scene responses. In the case of multiple scenarios running in parallel or frequent behavior switching, it is easy to cause data lag and portrait drift, making it impossible to predict the stage changes of user behavior. This results in a fixed portrait update cycle that lacks flexibility. When there are abnormal interactions or environmental disturbances, the model has difficulty in reflecting preference changes in a timely manner, causing portrait deviation accumulation and system response delay, which further affects the synchronization and immersion of virtual and real interactions, and weakens the adaptability of the portrait in a multi-dimensional environment and the stability of user experience. SUMMARY
[0004] The purpose of the present application is to solve the shortcomings in the prior art, and the MR user portrait generation system based on data mining is proposed.
[0005] In order to achieve the above-mentioned purpose, the present application adopts the following technical solution, the MR user portrait generation system based on data mining comprises:
[0006] The behavior mode analysis module obtains action features of a user in a mixed reality scene, environment response states and interaction node distributions, analyzes the association structure of the behavior mode and scene adaptability, identifies key behavior nodes and time sequence characteristics, combines the superposition effect of multi-dimensional scene influence factors, and generates a mixed reality user behavior association model;
[0007] The image trend deduction module extracts action frequencies of key behavior nodes and scene response superposition effects based on the mixed reality user behavior association model, performs matching analysis on the association of the behavior mode and scene adaptability, identifies a user preference high-occurrence stage, and obtains a multi-dimensional behavior image trend deduction table;
[0008] The abnormal evolution analysis module extracts time intervals and duration of abnormal behaviors in user interaction records according to the multi-dimensional behavior image trend deduction table, classifies evolution paths of the same abnormal behaviors, and generates a user interaction abnormal evolution trajectory set;
[0009] The cycle adjustment optimization module calls the user interaction abnormal evolution trajectory set, combines scene response values and time sequence delays in a jurisdictional section, filters a target user group in a risk section, performs segmented revision on an image update cycle value, and obtains a dynamic image update cycle optimization table.
[0010] As a further scheme of the application, the mixed reality user behavior association model includes behavior mode classification, key node distribution structure and multi-dimensional scene influence factor mapping relationship, the multi-dimensional behavior image trend deduction table includes a trend label group, node behavior characteristics and a prediction priority interval, the user interaction abnormal evolution trajectory set includes abnormal interval distribution, abnormal duration and cycle classification results, and the dynamic image update cycle optimization table includes a target user list, cycle revision parameters and delay association factors.
[0011] As a further scheme of the application, the behavior mode analysis module includes:
[0012] The dynamic feature analysis submodule obtains user action features, environment response states and interaction node distribution data, aligns the three signals according to a time axis, extracts behavior mutation points, locates response differences between behavior characteristics and scene changes, and generates a behavior deviation amount.
[0013] The factor association analysis submodule extracts signal delay segments and behavior characteristic response sequences according to the behavior deviation amount, counts delay lengths and response sequences, judges signal association directions, determines the number of factor trigger sequences in a lag section, and generates a factor association lag structure amount.
[0014] The behavior mode modeling submodule extracts a scene response variable point and a factor signal linkage period based on the factor correlation lag structure quantity, compares signal response frequency and time delay, identifies linkage times and average delay ratio, analyzes correlation and linkage frequency mapping among three signals, and generates a mixed reality user behavior correlation model.
[0015] As a further scheme of the application, the image trend deduction module comprises:
[0016] The behavior mode extraction submodule extracts key node action frequency based on the mixed reality user behavior correlation model, screens sequences of actions exceeding a reference range, identifies abnormal action features, analyzes abnormal action proportion, identifies weighted abnormal frequency of sequences of actions exceeding the reference range, and obtains an abnormal frequency ratio;
[0017] The frequency rule matching submodule calls the abnormal frequency ratio, combines node behavior mode and factor path quantity, identifies frequency rule comparison items, adjusts node abnormal offset according to task proportion on a factor path, and obtains a behavior rule priority index;
[0018] The trend level determination submodule extracts a numerical interval corresponding to a node based on the behavior rule priority index, sets a node level division interval group, assigns a level identifier according to an index value falling into an interval, sorts to determine a trend level, and generates a multi-dimensional behavior image trend deduction table.
[0019] As a further scheme of the application, the abnormal evolution analysis module comprises:
[0020] The abnormal record screening submodule collects time points of user abnormal triggering and ending according to the multi-dimensional behavior image trend deduction table, identifies time intervals between adjacent abnormalities, screens records exceeding a reference interval value, and generates an abnormal time interval sequence;
[0021] The abnormal period division submodule calls the abnormal time interval sequence, counts continuous occurrence times of the same type of abnormal events, and uses a formula according to abnormal duration, interval time, and scene load indicators:
[0022] ;
[0023] calculates an abnormal period distribution trend value, and establishes an abnormal period distribution stage;
[0024] wherein, represents an abnormal period distribution trend value, represents a duration of the jth abnormal event, represents an average duration of the abnormal event, represents a maximum duration of the abnormal event, represents a weight index, and m represents a total number of the abnormal events;
[0025] The periodic evolution classification submodule calls the abnormal period distribution stage, identifies the abnormal events of the same type of periodic evolution, identifies the evolution fluctuation difference, classifies and archives according to the difference threshold, and generates a user interaction abnormal evolution track set.
[0026] As a further scheme of the present application, the periodic adjustment optimization module comprises:
[0027] The trend sequence identification submodule calls the user interaction abnormal evolution track set, extracts the incremental change value, judges the trend upward interval according to the cumulative amplitude and fluctuation amplitude, marks the key user group, and generates a user trend abnormality identification list;
[0028] The response characteristic identification submodule calls the user number in the user trend abnormality identification list, identifies the scene response value and response delay in the section, combines the delay distribution and fluctuation frequency, analyzes the user response difference, and obtains the user response characteristic difference value;
[0029] The periodic revision submodule identifies the periodic revision item structure according to the user response characteristic difference value and the corresponding period of the trend section, analyzes the periodic offset degree and the frequency distribution amplitude, analyzes the periodic revision offset degree, combines the original period structure difference, adjusts the portrait inspection frequency and time distribution, and obtains a dynamic portrait update period optimization table.
[0030] As a further scheme of the present application, the incremental change value refers to time series processing of user interaction data in the user interaction abnormal evolution track set, and calculating the difference value between consecutive time points as the incremental change value.
[0031] The trend upward interval is judged according to the cumulative amplitude and fluctuation amplitude, that is, when the incremental change value is in a continuous time period, the cumulative amplitude continuously exceeds a preset threshold, and the fluctuation amplitude remains within a preset threshold, the trend upward interval is judged.
[0032] As a further scheme of the present application, the system further comprises a trace analysis module:
[0033] The trace analysis module collects the response difference and scene disturbance characteristics of high-frequency users based on the dynamic portrait update period optimization table, judges whether the disturbance characteristics have consistency, identifies the trace attribution node, and forms a user behavior disturbance trace mapping diagram.
[0034] The user behavior disturbance trace mapping diagram comprises a disturbance consistency feature group and a trace node positioning result.
[0035] As a further scheme of the present application, the trace analysis module comprises:
[0036] The response difference extraction submodule checks the high-frequency user response time and the scene change sequence based on the dynamic image update period optimization table, identifies the synchronization deviation of the response time difference and the scene change rate, filters the time points and user numbers whose deviation exceeds the stable interval, and generates a user response deviation list;
[0037] The disturbance consistency discrimination submodule extracts the scene disturbance sequence according to the user response deviation list, compares the disturbance amplitude and direction of the deviation time points, identifies the continuous consistent disturbance section and records the interval overlapping with the deviation time points, and generates a response disturbance consistency section table;
[0038] The traceability attribution recognition submodule extracts the node path of the user number according to the response disturbance consistency section table, traces the node response sequence and signal transmission in the overlapping section, identifies the response abnormal frequency of the signal source node, and forms a user behavior disturbance traceability mapping diagram.
[0039] Compared with the prior art, the advantages and positive effects of the present application are:
[0040] In the present application, through multi-dimensional analysis of action features, environmental response states and interactive node distribution in a mixed reality scene, deep identification and dynamic correlation of behavior features in a time sequence structure are realized, a comprehensive model reflecting user behavior rules and scene adaptability can be generated, the frequency change and response superposition relationship of key nodes are extracted, the accuracy of behavior pattern recognition and the continuity of trend extrapolation are improved, the prediction of preference stages and the adaptive matching of feature mapping are realized in the image generation process, the stable evolution and response consistency of the user portrait in a complex scene are ensured, through tracking analysis of abnormal behavior distribution and evolution path, the segmented revision and risk section screening of the image update period are optimized, the robustness and update sensitivity of the system under high-frequency interaction are enhanced, the traceability and consistency of the disturbance features are determined, and the reliability of image dynamic adjustment and the coordination of overall interactive experience are improved. BRIEF DESCRIPTION OF DRAWINGS
[0041] Figure 1 The system flowchart of the present application;
[0042] Figure 2 The behavior pattern analysis module flowchart in the present application;
[0043] Figure 3 The image trend extrapolation module flowchart in the present application;
[0044] Figure 4 The abnormal evolution analysis module flowchart in the present application;
[0045] Figure 5 The cycle adjustment optimization module flowchart in the present application;
[0046] Figure 6A traceability analysis module flowchart in the present application. DETAILED DESCRIPTION
[0047] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application is further described in detail below in combination with the drawings and examples. It should be understood that the specific examples described herein are only used to explain the present application and do not limit the present application.
[0048] In the description of the present application, it should be understood that the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer" and the like indicate the orientation or positional relationship shown in the drawings, and are only used to facilitate the description of the present application and simplify the description, and do not indicate or imply that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present application. In addition, in the description of the present application, the meaning of "a plurality of" is two or more, unless otherwise explicitly and specifically limited.
[0049] Please refer to Figure 1 The MR user portrait generation system based on data mining comprises:
[0050] The behavior pattern analysis module obtains the action characteristics, environmental response state and interaction node distribution of the user in the mixed reality scene, analyzes the correlation structure of the behavior pattern and the scene adaptability, identifies the key behavior nodes and time sequence characteristics, and generates a mixed reality user behavior correlation model in combination with the superposition effect of the multi-dimensional scene influence factors;
[0051] The portrait trend deduction module extracts the action frequency of the key behavior nodes and the superposition effect of the scene response based on the mixed reality user behavior correlation model, performs matching analysis on the correlation of the behavior pattern and the scene adaptability, identifies the high-frequency user preference stage, and obtains a multi-dimensional behavior portrait trend deduction table;
[0052] The abnormal evolution analysis module extracts the time interval and duration of abnormal behavior in the user interaction record according to the multi-dimensional behavior portrait trend deduction table, judges the distribution stage of high-frequency abnormality, classifies the evolution path of similar abnormality, and generates a user interaction abnormal evolution trajectory set;
[0053] The cycle adjustment optimization module calls the user interaction abnormal evolution trajectory set, combines the scene response value and time sequence delay in the jurisdiction section, filters the target user group in the risk section, performs segmented revision on the portrait update cycle value, and obtains a dynamic portrait update cycle optimization table;
[0054] The traceability analysis module collects the response difference of high-frequency users and the scene disturbance characteristics based on a dynamic image update cycle optimization table, judges whether the disturbance characteristics have consistency, identifies the traceability attribution node, and forms a user behavior disturbance traceability mapping diagram.
[0055] The mixed reality user behavior association model includes behavior pattern classification, key node distribution structure, and multi-dimensional scene influence factor mapping relationship. The multi-dimensional behavior image trend deduction table includes trend label group, node behavior characteristics, and prediction priority interval. The user interaction abnormal evolution track set includes abnormal interval distribution, abnormal duration, and cycle classification result. The dynamic image update cycle optimization table includes target user list, cycle revision parameter, and delay correlation factor. The user behavior disturbance traceability mapping diagram includes disturbance consistency feature group and traceability node positioning result.
[0056] Please refer to Figure 2 The behavior pattern analysis module includes:
[0057] The dynamic feature analysis submodule obtains user action characteristics, environment response state, and interaction node distribution data, aligns the three signals according to the time axis, extracts behavior mutation points, locates the response difference between behavior characteristics and scene changes, and generates behavior deviation amount;
[0058] User signal data is obtained, the signals are aligned according to the time axis, the user action timestamp is matched with the latest environment response and interaction node timestamp, for example, a 20-millisecond time window, behavior mutation points are extracted, action frequency or type change time points are identified through sliding window analysis, for example, within a 10-second window, the frequency of click actions increases from 1 times per second to 5 times per second, which exceeds the historical mean value by 3 standard deviations, 09:01:30 is identified as a mutation point, the response difference between behavior characteristics and scene changes is located, and the user action characteristics and environment response state before and after the mutation point are compared, for example, at 09:01:30, the user submits an order action, and the API response time increases from 200 milliseconds to 800 milliseconds, the response time increment is determined, the response difference exceeds the 50% threshold, the difference is marked, and the behavior deviation amount is generated.
[0059] The factor correlation analysis submodule extracts the signal delay segment and the behavior characteristic response order according to the behavior deviation amount, counts the delay length and the response order, judges the signal correlation direction, measures the number of factor trigger orders in the lag segment, and generates the factor correlation lag structure amount;
[0060] According to the behavior deviation amount, it is indicated that the order action submitted by the user U001 causes the API response time to be prolonged, the signal delay segment is extracted, and the behavior characteristic response sequence is from the action initiation to the API return. The delay segment is the signal delay segment, the behavior characteristic response sequence in the delay segment is the user submitting the order action, processing the API request, database query, and API response return, the delay length is 800 milliseconds, and the response sequence is [User_Submit_Order, System_API_Call, Database_Query, API_Response_Return]. The signal correlation direction is determined. Through the causal relationship test of similar behaviors and API response delays in historical data, if the increase in the user order submission frequency leads the increase in the API response delay, and the p value is less than 0.05, it is determined that the correlation direction is that the user behavior causes the response delay. The number of factor trigger sequences in the lag segment is determined. In the 800 millisecond delay segment, the slow database query is the key factor, and the trigger sequence occurs before the API response delay. In 1000 similar events, 850 times are the user order submission, slow database query, and API delay sequence. The factor correlation lag structure quantity is generated.
[0061] The behavior pattern modeling submodule extracts the scene response variable point and the factor signal linkage period based on the factor correlation lag structure quantity, compares the signal response frequency and the time delay, identifies the linkage frequency and the average delay ratio, analyzes the correlation and linkage frequency mapping among the three signals, and generates the mixed reality user behavior correlation model.
[0062] Based on the factor correlation lag structure quantity, it is indicated that the order action submitted by the user U001 causes the API response delay, the delay is 800 milliseconds, the user behavior triggers the delay, the factor trigger sequence is 850 times, the scene response variable point and the factor signal linkage period are extracted, the API response return time is identified as the scene response variable point, the 800 millisecond interval from the user action initiation to the API response return is marked as the factor signal linkage period, the signal response frequency and the time delay are compared, the linkage period occurs 500 times, the average time delay is 750 milliseconds, the normal time delay is 200 milliseconds, the linkage frequency and the average delay ratio are identified, the linkage frequency is 500 times, the average delay ratio is 3.75, the correlation and linkage frequency mapping among the three signals are analyzed, the user action characteristic (order submission), the environment response state (database CPU utilization), and the interaction node distribution data (order submission button click heat) are analyzed, and the linkage period correlation relationship is found. The rule is that when the user frequently clicks the order submission button and the database CPU utilization is more than 80%, the API delay linkage frequency is high, and the average delay ratio is 3.75. The rule confidence is 0.9, the support degree is 0.15, and the mixed reality user behavior correlation model is generated.
[0063] Please refer to Figure 3 , the image trend deduction module comprises:
[0064] The behavior pattern extraction submodule extracts the key node action frequency based on the mixed reality user behavior association model, using the formula:
[0065] ;
[0066] The key node action frequency is extracted, the action sequence that exceeds the benchmark range is screened, the abnormal action feature is identified, the abnormal action proportion is analyzed, the weighted abnormal frequency of the action sequence that exceeds the benchmark range is identified, and the abnormal frequency ratio is obtained.
[0067] wherein, represents the key node action frequency, represents the real-time frequency of the i-th action, represents the mean of the action frequency, represents the standard deviation of the action frequency, represents the weighting coefficient of the i-th action, represents the total number of action sequences.
[0068] Based on the mixed reality user behavior association model, the model contains, for example, the association rule "user frequently clicks the login button and the average response delay is greater than 500 milliseconds, resulting in a 20% increase in database CPU utilization", using the formula: The key node action frequency is extracted, for example, through the model, it is identified that "login button click" and "submit order button click" are key node actions, and the frequency is monitored in real time. Among them, represents the key node action frequency, the higher the value, the greater the degree of deviation of the key node action from normal behavior, and the more important the action deviation impact. represents the real-time frequency of the i-th action, for example, in the last one minute, the user U001 clicks the login button times, and clicks the submit order button times. represents the mean of the action frequency, the value of which represents the average occurrence frequency of the action under normal historical conditions, for example, according to the data of the same period in the past week, the mean of the login button click frequency is times / minute, and the mean of the submit order button click frequency is times / minute. represents the standard deviation of the action frequency, the value of which represents the normal fluctuation range of the action frequency, for example, the standard deviation of the login button click frequency is times / minute, and the standard deviation of the submit order button click frequency is times / minute. represents the weighting coefficient of the i-th action, a weight coefficient of the action, the value of which reflects the importance of the action in the entire user behavior pattern and the degree of influence on system performance, the weight coefficient being set in reference to the strength and frequency of the association of the action with the anomaly in the mixed reality user behavior association model, for example, the login operation is considered to be a high-risk operation, and if the abnormal frequency has a significant impact on the system, therefore ; the submit order operation is directly associated with business transactions, and the abnormal frequency thereof has a greater impact on the business, therefore , the weight coefficient ranges from 0 to 1 and is set through expert experience and historical fault data analysis, for example, if a certain action has caused two P1 level faults in the past three months, the weight coefficient thereof is set to 0.9, and if it has caused five P2 level faults, the weight coefficient thereof is set to 0.7, , represents the total number of action sequences, in this example , (login button click and submit order button click);
[0069] The operation logic and purpose of the formula are as follows: first, the absolute deviation of the real-time frequency of each key action from the historical mean value is calculated, and then the normalized standard deviation is divided to obtain the degree of deviation from the normal level, ensuring the comparability between different actions, the absolute value of the normalized deviation is taken to measure whether the deviation is high or low, the weight coefficient of the action is multiplied to give different weights to actions of different importance, and the sum of all weighted deviations is obtained to obtain a comprehensive key node action frequency , which quantifies the overall abnormality of the current user behavior, and highlights the key actions that have a greater impact on the system;
[0070] The above parameters are substituted into the formula for calculation:
[0071] For login button click ( ): ;
[0072] For submit order button click ( ): ;
[0073] The final calculation ;
[0074] The sequences of actions that exceed the reference range are screened, for example, the "reference range" is set to be the mean value plus or minus 2 standard deviations, that is , for the login button, the reference range is , and the real-time frequency 15 exceeds this range, for the submit order button, the reference range is , the current action sequence of the user U001 is filtered as exceeding the benchmark range, and an abnormal action feature is identified. For the filtered sequence, it is identified that the login button click frequency is abnormally high and the order submission button click frequency is abnormally high as the main abnormal features. The abnormal action proportion is analyzed, and in this example, 2 out of 2 key actions are abnormal, and the abnormal action proportion is , the weighted abnormal frequency of the sequence of actions exceeding the benchmark range is identified, and in this example, the weighted abnormal frequency of the sequence is , and the abnormal frequency ratio is obtained.
[0075] The frequency rule matching submodule calls the abnormal frequency ratio, combines the node behavior pattern and the number of factor paths, identifies the frequency rule comparison item, adjusts the node abnormal offset according to the task proportion on the factor path, and obtains the behavior rule priority index;
[0076] The abnormal frequency ratio is associated with the high-frequency click of the login button and the order submission button, and the mixed reality user behavior association model indicates that it involves 3 main factor paths, which are related to API response delay and database load increase. The frequency rule comparison item is identified, and the observed frequency rule matches the "abnormal submission mode" in the historical anomaly library with high degree of matching. Adjust the node abnormal offset according to the task proportion on the factor path, and in the abnormal submission mode factor path, the order submission button click is the core link, and the task proportion is 0.9; the login button click is the pre-link, and the task proportion is 0.7. The task proportion is determined through historical data analysis. The abnormal offset of the login button is adjusted from 2.5 to 3.9, and the abnormal offset of the order submission button is adjusted from 3.0 to 5.16. The adjustment factor 0.8 controls the adjustment range, and the behavior rule priority index 9.06 is obtained according to the sensitivity setting of the business scenario.
[0077] The trend level determination submodule extracts the numerical interval corresponding to the node based on the behavior rule priority index, sets the node level division interval group, assigns the level identifier according to the index value falling into the interval, sorts to determine the trend level, and generates a multi-dimensional behavior portrait trend deduction table.
[0078] Based on the behavior rule priority index 9.06, the node value interval is extracted. For high-risk user behavior, the value interval is preset: 0-3 is normal, 3-6 is attention, 6-10 is warning, and above 10 is emergency. The node level division interval group is set, the value interval is corresponding to the "normal", "attention", "warning", "emergency" level mark, the interval division is based on the correlation analysis of the index value and the P1, P2 failure probability in the historical data, the index value is distributed according to the interval to assign the level mark, 9.06 falls into the interval [6, 10), and the level mark is assigned as "warning". The trend level is determined by sorting, the 9.06 of the user U001 is ranked third, the trend level is determined as "warning", and the multi-dimensional behavior portrait trend deduction table is generated;
[0079] Table 1: Behavior portrait trend deduction table
[0080] ;
[0081] As shown in Table 1, the behavior portrait trend deduction table shows that the behavior rule priority index of the user U001 is 9.06, the corresponding trend level mark is "warning", and the abnormal nodes "LoginButton" and "SubmitFormButton" and the abnormal actions "high login click frequency" and "high form submission click frequency" that cause the level are recorded. This table provides a macroscopic insight into the user behavior trend.
[0082] Please refer to Figure 4 , the abnormal evolution analysis module includes:
[0083] The abnormal record screening submodule collects the time points of user abnormal triggering and ending according to the multi-dimensional behavior portrait trend deduction table, identifies the time interval between adjacent abnormalities, screens the records exceeding the benchmark interval value, and generates an abnormal time interval sequence;
[0084] According to the multi-dimensional behavior portrait trend deduction table, the trend level of the user U001 is "warning", the time points of user abnormal triggering and ending are collected, and the triggering and ending time points of the last three abnormal events (index higher than the normal threshold) of the user U001 are collected from the historical behavior data of the user U001. The first abnormal event starts at 08:00:00 and ends at 08:30:00, the second abnormal event starts at 09:00:00 and ends at 09:15:00, and the third abnormal event starts at 10:30:00 and ends at 10:45:00. The time interval between adjacent abnormalities is identified, the interval between the first and second abnormalities is 30 minutes, and the interval between the second and third abnormalities is 75 minutes. The records exceeding the benchmark interval value are screened, the benchmark interval value is set as 60 minutes, which is determined according to the abnormal event interval time length statistics in the historical data. The 30-minute interval does not exceed the benchmark value and is excluded, the 75-minute interval exceeds the benchmark value and is retained, and an abnormal time interval sequence is generated.
[0085] The abnormal period division sub-module calls the abnormal time interval sequence, counts the number of continuous occurrences of the same type of abnormal event, and uses the formula:
[0086]
[0087] The abnormal period distribution trend value is calculated, and the abnormal period distribution stage is established.
[0088] wherein, represents the abnormal period distribution trend value, represents the duration of the jth abnormal event, represents the average duration of the abnormal event, represents the maximum duration of the abnormal event, represents the weight index, and m represents the total number of abnormal events.
[0089] For example, the abnormal time interval sequence of user U001 is and the number of continuous occurrences of the same type of abnormal event is counted in combination with the latest abnormal event data of the user, for example, user U001 has 5 continuous occurrences of the abnormal event of "high login click frequency" in the past 24 hours, and the durations of the events are 10 minutes, 8 minutes, 12 minutes, 7 minutes, and 13 minutes, respectively. According to the abnormal duration, interval time, and scene load index, the abnormal period distribution trend value is calculated using the formula, wherein, represents the abnormal period distribution trend value, which quantifies the degree of fluctuation of the duration of the abnormal event, and gives higher weight to the abnormal event with shorter duration, which helps to identify the abnormal pattern that is frequent and unstable in duration and rapidly evolving. represents the duration of the jth abnormal event, which is directly calculated from the start and end time points of the abnormal event, for example, the duration of the first abnormal event is minutes, the second is minutes, the third is minutes, the fourth is minutes, and the fifth is minutes. represents the average duration of the abnormal event, which is calculated as the arithmetic mean of all abnormal event durations, in this example, minutes. represents the maximum duration of the abnormal event, which is the maximum value among the durations of the analyzed abnormal events, in this example, minutes. minutes. a representative weight index, whose value is used to adjust the weight of short duration anomalies, for example, when a value of 1 indicates that the anomaly events with relatively short duration are given a moderate level of extra attention, the value is set through historical data analysis and experimental verification, for example, by monitoring the prediction accuracy of subsequent system failures under different values, the value of 1 is determined when the prediction accuracy is the highest, representing the total number of anomaly events, in this case ;
[0090] The operation logic and purpose of the formula are as follows: first, calculate the absolute deviation of the duration of each anomaly event from the average duration, to measure the degree of deviation from the normal duration level, and weight it by the weight factor , which particularly emphasizes those anomaly events with relatively short duration (i.e. the value is small, so that the weight factor is large), because such anomalies indicate more rapid and frequent system fluctuations or intermittent problems, sum all the weighted deviations to get a comprehensive anomaly period distribution trend value , which can more sensitively reflect the volatility and potential burstiness characteristics of anomaly duration;
[0091] Substitute the above parameters into the formula to calculate:
[0092] For ( minutes): ;
[0093] For ( minutes): ;
[0094] For ( minutes): ;
[0095] For ( minutes): ;
[0096] For ( minutes): ;
[0097] Finally, calculate ;
[0098] The results show that the duration of abnormal events of user U001 fluctuates greatly, there are obvious short-term and long-term abnormal duration, and the overall abnormal period presents a fluctuation period characteristic, indicating the instability of the behavior pattern, which is crucial for subsequent identification of period evolution fluctuation difference, according to the calculated abnormal period distribution trend value , it is compared with the preset threshold value, for example, set “stable period”, “fluctuation period”, “outbreak period”, the threshold value is determined by the correlation analysis of different values in historical data and the actual user experience influence degree, in this example falls into the interval , so the abnormal period distribution stage is established as “fluctuation period”.
[0099] The period evolution classification submodule calls the abnormal period distribution stage, identifies the same type of abnormal events of period evolution, identifies the evolution fluctuation difference, classifies and archives according to the difference threshold value, and generates a user interaction abnormal evolution track set;
[0100] Call the “fluctuation period” of the abnormal period distribution stage, identify the same type of abnormal events of period evolution, classify the “high login click frequency” abnormal event of user U001 with the same type of abnormal events in the “fluctuation period” in the historical record, and identify similar feature abnormal events in user U002, identify the evolution fluctuation difference, calculate the difference of the abnormal period distribution trend value G, the average abnormal duration, and the abnormal frequency ratio F of the same type of abnormal events after classification, the difference is quantified by calculating the normalized distance of multi-dimensional values, the distance value is 0.35, and the difference threshold value is set as 0.8. The threshold value is determined by historical abnormal event clustering analysis and domain expert experience, and is used to distinguish different evolution tracks. 0.35 is less than 0.8, the same type of abnormal events of U001 and U002 belong to the same evolution track, and are archived to the “high-frequency login fluctuation evolution track” category, and a user interaction abnormal evolution track set is generated.
[0101] Please refer to Figure 5 , the period adjustment and optimization module includes:
[0102] The trend sequence identification submodule calls the user interaction abnormal evolution track set, extracts the incremental change value, judges the trend rising interval according to the cumulative amplitude and fluctuation amplitude, and marks the key user group, and generates a user trend abnormality identification list;
[0103] The incremental change value refers to the time series processing of the user interaction data in the user interaction abnormal evolution track set, and the difference value between consecutive time points is calculated as the incremental change value;
[0104] a trend rising interval is determined when the accumulated increment continuously exceeds a preset threshold and the fluctuation amplitude remains within the preset threshold in the continuous time period;
[0105] The user interaction abnormal evolution trajectory set includes a "high-frequency login fluctuation evolution trajectory". The trajectory describes a sequence of abnormal periodic distribution trend values G of the user U001 changing over time. The increment change value is extracted. The increment change value is obtained by performing time series processing on the user interaction data in the user interaction abnormal evolution trajectory set and calculating the difference between consecutive time points as the increment change value. For example, the abnormal periodic distribution trend values G of the user U001 in the past five monitoring periods (every day) are [10.0, 10.5, 11.2, 12.0, 13.116], and the increment change value between consecutive time points is calculated as [0.5, 0.7, 0.8, 1.116]. A trend rising interval is determined according to the accumulated increment and the fluctuation amplitude, and a key user group is marked. When the accumulated increment continuously exceeds a preset threshold and the fluctuation amplitude remains within the preset threshold in the continuous time period, a trend rising interval is determined. For example, the "preset threshold_accumulated increment" is set to 2.0, which means that when the accumulated increment exceeds 2 units, the trend rising is considered to be significant. For example, when the G value increases from 10 to 12, it represents a clear transition from the "stable period" to the "fluctuation period", so 2.0 is set. The "preset threshold_fluctuation amplitude" is set to 0.5 (standard deviation), which means that when the increment fluctuation is less than 0.5, the trend rising is relatively stable rather than dramatic. For example, if the G value continues to rise while the increment fluctuates dramatically, it indicates that the trend is unstable and is not suitable for determining a continuous rising trend. The increment change value [0.5, 0.7, 0.8, 1.116] is analyzed by a sliding window of 3 periods (e.g., 3 days). The cumulative increment of the first window [0.5, 0.7, 0.8] is 0.5+0.7+0.8=2.0, and the standard deviation (fluctuation amplitude) is 0.12. The cumulative increment of the second window [0.7, 0.8, 1.116] is 0.7+0.8+1.116=2.616, and the standard deviation is 0.21. Since the cumulative increment 2.616 of the second window is greater than the preset threshold 2.0, and the fluctuation amplitude 0.21 is less than the preset threshold 0.5, it is determined that the time period corresponding to the window is a trend rising interval, and the user U001 is marked as a key user group. A user trend anomaly identification list is generated.
[0106] Table 2: User trend anomaly identification list
[0107] ;
[0108] Referring to Table 2, the user trend anomaly identification list explicitly lists the trend rising interval of user U001 starting from 09:00:00 on October 26 and ending at 12:00:00 on October 26, during which the trend index (G) rises from 10.0 to 13.116, and notes that the main abnormal action is "high login click frequency", and this table provides key information of the user with abnormal trend.
[0109] The response characteristic identification submodule calls the user number in the user trend anomaly identification list, identifies the scene response value and response delay in the section, combines the delay distribution and fluctuation frequency, analyzes the user response difference, and obtains the user response characteristic difference value;
[0110] Call the user number U001 in the list, continuously monitor the API response time of the "login" operation for user U001 in the trend rising interval, identify the response delay, combine the delay distribution and fluctuation frequency, and count the average delay of the "login" operation in the interval 0.8 seconds, the standard deviation 0.2 seconds, the event frequency of the response delay exceeding 1.0 seconds 20 times / hour, analyze the user response difference, the current average delay 0.8 seconds compared with the historical normal average delay 0.2 seconds, the delay difference ratio 3.0, the current delay standard deviation 0.2 seconds compared with the historical normal standard deviation 0.05 seconds, the difference ratio 3.0, the current high delay frequency 20 times / hour compared with the historical normal 5 times / hour, the difference ratio 3.0, the difference ratio weighted summation, the user response characteristic difference value 7.5.
[0111] The period revision submodule identifies the period revision item structure according to the user response characteristic difference value and the corresponding period of the trend section, analyzes the period offset degree and the frequency distribution amplitude, analyzes the period revision offset degree, combines the original period structure difference, adjusts the image inspection frequency and time distribution, and obtains the dynamic image update period optimization table.
[0112] According to the user response characteristic difference value and the corresponding period of the trend segment, for example, the response characteristic difference value of user U001 is 7.5, and the current image inspection period is once a day, the period revision item structure is identified, for example, based on the response characteristic difference value 7.5 (belonging to the medium-high risk), it is identified that the "image inspection frequency" and "inspection time distribution" need to be revised, the period offset degree and the frequency distribution amplitude are analyzed, according to the preset rule, when the difference value is in the interval [5, 10), it is recommended to adjust the inspection frequency from once a day to once every 6 hours, so the period offset degree is 24 hours-6 hours=18 hours, the fluctuation amplitude (standard deviation) of the response characteristic difference value of user U001 in the past 24 hours is analyzed, for example, it is 1.5, which indicates that the difference value fluctuates to a certain extent, the period revision offset degree is analyzed, the revision offset degree is high, which indicates that significant period adjustment is needed, combined with the original period structure difference, the image inspection frequency and time distribution are adjusted, the image inspection frequency of user U001 is adjusted from once a day to once every 6 hours, and the inspection time distribution is adjusted to focus on its trend rising interval (for example, 09:00-12:00 and 18:00-21:00 every day) for more intensive inspection, and regular inspection is performed in non-key periods, and a dynamic image update period optimization table is generated;
[0113] Table 3: Dynamic image update period optimization table
[0114] ;
[0115] As shown in Table 3, the dynamic image update period optimization table is based on the user response characteristic difference value of user U001 being 7.5, and the recommended image inspection frequency is once every 6 hours, and the recommended inspection time distribution is specified as focusing on the 09:00-12:00 and 18:00-21:00 time periods, and this table realizes dynamic optimization of the image update strategy.
[0116] Please refer to Figure 6 , the traceability analysis module includes:
[0117] The response difference extraction submodule checks the high-frequency user response time and scene change sequence based on the dynamic image update period optimization table, identifies the synchronization deviation of the response time difference and the scene change rate, filters the time points and user numbers whose deviation exceeds the stable interval, and generates a user response offset list;
[0118] Based on the dynamic image update period optimization table, the recommended image inspection frequency and the key attention period of the user U001 are obtained, the high-frequency user response time and the scene change sequence are checked, the user U001 "login" operation response time is monitored in the period, and the corresponding scene change sequence is recorded, such as server CPU utilization rate, database connection pool usage rate change, the synchronous deviation of response time difference and scene change rate is identified, the response time difference is calculated, the scene change rate of server CPU utilization rate and database connection pool usage rate is calculated, the Pearson correlation coefficient of the response time difference sequence and each scene change rate sequence at zero lag (i.e. at the same time) is calculated, it is found that the correlation coefficient exceeds the stable interval, there is a synchronous deviation, the time points and user numbers whose deviations exceed the stable interval are screened, and the stable interval is set to Pearson correlation coefficient [-0.5, 0.5], the time points and user U001 exceeding this interval are screened, and a user response deviation list is generated.
[0119] The disturbance consistency discrimination sub-module extracts the scene disturbance sequence according to the user response deviation list, compares the disturbance amplitude and direction of the deviation time point, identifies the continuous consistent disturbance section and records the interval overlapping with the deviation time point, and generates a response disturbance consistency section table;
[0120] According to the user response deviation list, the list contains time points, user U001, response time difference, and scene change of CPU utilization rate and database connection pool usage rate, the scene disturbance sequence is extracted, the historical data related to CPU utilization rate and database connection pool usage rate is extracted from the monitoring log to form a detailed time sequence, the disturbance amplitude and direction of the deviation time point are compared, the disturbance amplitude and direction of CPU utilization rate and database connection pool usage rate are identified, the continuous consistent disturbance section is identified and the overlapping interval is recorded, through sequence analysis, it is identified that the continuous consistent disturbance section, CPU utilization rate is continuously higher than 75%, and database connection pool usage rate is continuously higher than 85%, indicating continuous high load, the time points in the user response deviation list are contained in this disturbance section, the overlapping interval is recorded, and a response disturbance consistency section table is generated.
[0121] The traceability attribution identification sub-module extracts the node path of the user number according to the response disturbance consistency section table, traces the node response order and signal transmission in the overlapping section, identifies the response abnormal frequency of the signal source node, and forms a user behavior disturbance traceability mapping diagram;
[0122] According to the response disturbance consistency section table, it is indicated that the user U001 experienced response deviation caused by continuous high CPU utilization and high database connection pool usage during the specified period, the node path of the user number is extracted, the complete node path of the user U001 is tracked for the "login" operation performed in the overlapping section, the node response order and signal transmission in the overlapping section are tracked, in the overlapping section, the node path is tracked in detail, it is found that after a service sends a request to another service, it fails to respond in time, and the delay is the direct cause of the slow subsequent response, the response abnormal frequency of the signal source node is identified, according to the tracking result, the database service is determined as the signal source node of this disturbance, because it first shows abnormal response on the link, in the continuous high load disturbance section, the number of events in which the response delay of the database service exceeds the set threshold is counted, and a user behavior disturbance tracing mapping diagram is formed, in the disturbance section, the number of events in which the response delay of the database service exceeds the set threshold is counted, and a user behavior disturbance tracing mapping diagram is formed.
[0123] The above is only a preferred embodiment of the present application, and does not limit the present application in other forms. Any skilled person in the art can modify or change the above disclosed technical content to equivalent embodiments applied to other fields, but any simple modification, equivalent change and modification made according to the technical essence of the present application to the above embodiments without departing from the technical solution content of the present application still belongs to the protection scope of the present application technical solution.
Claims
1. A MR user profiling system based on data mining, characterized by, The system includes: The behavior pattern analysis module acquires the user's action characteristics, environmental response status and interaction node distribution in the mixed reality scene, analyzes the correlation structure between behavior patterns and scene adaptability, identifies key behavior nodes and time series characteristics, and generates a mixed reality user behavior correlation model by combining the superposition effect of multi-dimensional scene influencing factors. The behavior pattern analysis module includes: The dynamic feature parsing submodule acquires user action features, environmental response status and interaction node distribution data, aligns the three signals by the time axis, extracts behavioral mutation points, locates the response differences between behavioral features and scene changes, and generates behavioral deviation. The factor association analysis submodule extracts the signal delay segment and the sequence of behavioral feature responses based on the behavioral deviation amount, counts the delay length and the order of responses, determines the signal association direction, measures the number of factor triggering sequences within the lag segment, and generates the factor association lag structure quantity. The behavior pattern modeling submodule extracts the scene response variable point and the linkage period of factor signal based on the factor correlation lag structure quantity, compares the signal response frequency and time delay, identifies the linkage number and average delay ratio, analyzes the correlation and linkage frequency mapping between the three signals, and generates a mixed reality user behavior correlation model. Based on the mixed reality user behavior association model, the profile trend inference module extracts the action frequency and scene response superposition effect of key behavior nodes, performs matching analysis on the correlation between behavior patterns and scene adaptability, identifies the high-incidence stage of user preferences, and obtains a multi-dimensional behavior profile trend inference table. The profile trend inference module includes: The behavior pattern extraction submodule extracts the frequency of key node actions based on the mixed reality user behavior association model, filters sequences of actions that exceed the benchmark range, identifies abnormal action features, analyzes the proportion of abnormal actions, identifies the weighted abnormal frequency of sequences of actions that exceed the benchmark range, and obtains the abnormal frequency ratio. The frequency pattern matching submodule calls the abnormal frequency ratio, combines the node behavior pattern and the number of factor paths, identifies frequency pattern comparison items, adjusts the node abnormal offset according to the task proportion on the factor path, and obtains the behavior pattern priority index. The trend level determination submodule extracts the numerical range corresponding to the node based on the behavior pattern priority index, sets the node level division interval group, assigns the level label according to the index value falling into the interval, sorts and determines the trend level, and generates a multi-dimensional behavior profile trend inference table. The abnormal evolution analysis module extracts the time interval and duration of abnormal behaviors in user interaction records based on the multi-dimensional behavior profile trend inference table, classifies the evolution paths of similar abnormalities, and generates a set of user interaction abnormal evolution trajectories. The abnormal evolution analysis module includes: The abnormal record screening submodule collects the time points of user abnormal triggering and ending based on the multi-dimensional behavior profile trend inference table, identifies the time interval between adjacent abnormalities, filters records that exceed the benchmark interval value, and generates an abnormal time interval sequence. The anomaly period segmentation submodule calls the anomaly time interval sequence to count the number of consecutive occurrences of the same type of anomaly event. Based on the anomaly duration, interval time, and scenario load indicators, the following formula is used: ; The abnormal period distribution trend value is calculated to establish an abnormal period distribution stage; wherein, representing an abnormal cycle distribution trend value, representing a duration of the jth abnormal event, representing an average duration of the abnormal event, representing a maximum duration of the abnormal event, representing a weight index, m representing a total number of the abnormal events; The period evolution classification submodule calls the abnormal period distribution stage to identify abnormal events of the same type of period evolution, identify evolution fluctuation differences, classify and archive according to the difference threshold, and generate a user interaction abnormal evolution trajectory set; The period adjustment optimization module calls the user interaction abnormal evolution trajectory set, combines the scene response value and time delay in the jurisdiction section, filters the target user group in the risk section, segmentally revises the portrait update period value, and obtains a dynamic portrait update period optimization table; The period adjustment optimization module comprises: The trend sequence identification submodule calls the user interaction abnormal evolution trajectory set, extracts the incremental change value, judges the trend rising interval according to the cumulative amplitude and fluctuation amplitude, marks the key user group, and generates a user trend abnormality identification list; The response characteristic identification submodule calls the user number in the user trend abnormality identification list, identifies the scene response value and response delay in the section, combines the delay distribution and fluctuation frequency, analyzes the difference of user response, and obtains a user response characteristic difference value; The period revision submodule identifies the period revision item structure according to the user response characteristic difference value and the corresponding period of the trend section, analyzes the period offset degree and frequency distribution amplitude, analyzes the period revision offset degree, combines the original period structure difference, adjusts the portrait inspection frequency and time distribution, and obtains a dynamic portrait update period optimization table. 2.The MR user profiling system based on data mining of claim 1, wherein, The mixed reality user behavior correlation model comprises a behavior mode classification, a key node distribution structure, and a multi-dimensional scene influence factor mapping relationship. The multi-dimensional behavior portrait trend deduction table comprises a trend label group, a node behavior feature, and a prediction priority interval. The user interaction abnormal evolution trajectory set comprises an abnormal interval distribution, an abnormal duration, and a period classification result. The dynamic portrait update period optimization table comprises a target user list, a period revision parameter, and a delay correlation factor. 3.The MR user profiling system based on data mining of claim 1, wherein, The incremental change value refers to time series processing of user interaction data in the user interaction abnormal evolution trajectory set, and calculating the difference between consecutive time points as the incremental change value. When the incremental change value is continuously greater than the preset threshold and the fluctuation amplitude remains within the preset threshold, the trend rising interval is determined. 4.The MR user profiling system based on data mining of claim 1, wherein, The system further comprises a traceability analysis module: The traceability analysis module acquires the response difference and scene disturbance characteristics of high-frequency users based on the dynamic portrait update period optimization table, determines whether the disturbance characteristics are consistent, identifies the traceability attribution node, and forms a user behavior disturbance traceability mapping diagram. The user behavior disturbance traceability mapping diagram comprises a disturbance consistency feature group and a traceability node positioning result. 5.The MR user profiling system based on data mining of claim 4, wherein, The traceability analysis module comprises: The response difference extraction submodule checks the high-frequency user response time and scene change sequence based on the dynamic portrait update period optimization table, identifies the synchronization deviation of the response time difference and the scene change rate, filters the time points and user numbers whose deviation exceeds the stable interval, and generates a user response deviation list. The disturbance consistency discrimination submodule extracts a scene disturbance sequence according to the user response offset list, compares disturbance amplitudes and directions at offset time points, identifies continuous consistent disturbance sections, and records intervals overlapping with the offset time points, to generate a response disturbance consistency section table; The source attribution identification submodule extracts a node path of a user number according to the response disturbance consistency section table, traces node response sequences and signal transmission in the overlapping sections, identifies response abnormal frequencies of signal source nodes, and forms a user behavior disturbance source mapping diagram.
Citation Information
Patent Citations
Abnormal login identification method, abnormal login identification device and electronic equipment
CN113378127A
Abnormal transaction intelligent monitoring and analysis system and method based on AI drive
CN119624465A