Abnormity detection method, device and equipment for operation and maintenance monitoring curve and medium

By converting operation and maintenance monitoring data into curves and setting business-related coordinate ranges, combined with anomaly detection models, the problem of misjudgment in operation and maintenance monitoring was solved, and more accurate anomaly detection was achieved.

CN121904385AInactive Publication Date: 2026-04-21JINBAOXIN SOCIAL SECURITY CARD TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
JINBAOXIN SOCIAL SECURITY CARD TECH CO LTD
Filing Date
2026-01-22
Publication Date
2026-04-21
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing anomaly detection methods in the field of operation and maintenance monitoring are based on statistical principles, which leads to a large number of misjudgments and makes it impossible to accurately identify anomalies in operation and maintenance monitoring curves.

Method used

By acquiring operation and maintenance monitoring data and converting it into curves, setting coordinate ranges closely related to business thresholds, and processing it using an anomaly detection model, and combining it with historical labeled data to learn real anomaly patterns in business scenarios, the accuracy of detection is improved.

Benefits of technology

It achieves more accurate anomaly detection, avoids misjudgments caused by the lack of spatial scale constraints in traditional methods, improves the pertinence of anomaly identification and the accuracy of detection, and meets the needs of operation and maintenance business.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121904385A_ABST
    Figure CN121904385A_ABST
Patent Text Reader

Abstract

The invention discloses an operation and maintenance monitoring curve anomaly detection method and device, equipment and a medium, and relates to the technical field of operation and maintenance monitoring, and the method comprises the steps: obtaining to-be-processed operation and maintenance monitoring data, and converting the to-be-processed operation and maintenance monitoring data into an operation and maintenance monitoring curve graph; the operation and maintenance monitoring curve graph is subjected to constraint display according to the target coordinate range; the target coordinate range is determined according to a comparison result of the to-be-processed operation and maintenance monitoring data and a preset value; preprocessing the operation and maintenance monitoring curve graph to obtain a processed curve graph; processing the processed curve graph through an anomaly detection model to obtain an anomaly detection result; the anomaly detection model is obtained by training according to a sample data set and a corresponding anomaly labeling result; the anomaly detection result comprises a probability value that the operation and maintenance monitoring curve graph is an abnormal curve. According to the method and the device, more accurate anomaly detection meeting business requirements is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of operation and maintenance monitoring technology, and in particular to a method, device, equipment and medium for anomaly detection of operation and maintenance monitoring curves. Background Technology

[0002] With the rapid development of internet technology, application systems are becoming increasingly complex, with hundreds of applications, dozens of middleware, and databases running simultaneously. This has led to a proliferation of operation and maintenance monitoring metrics and a massive increase in data volume. Anomaly detection, as a core pre-operational step in operations and maintenance, directly impacts the effectiveness of subsequent processes such as fault location and root cause analysis. Anomaly detection can automatically capture fluctuations that deviate from normal trends through real-time analysis of monitoring curves, facilitating rapid fault location and shortening the time affected by faults. Therefore, in order to provide early warning of potential risks, anomaly detection of operation and maintenance monitoring curves is particularly important.

[0003] Currently, the relevant technology uses the 3-signa algorithm, which is based on statistical principles and uses the mean and standard deviation of data to determine whether discrete values ​​exist, thus identifying anomalies. However, in the field of operations and maintenance monitoring, this purely statistical method based on the degree of dispersion deviates from the actual business-related anomalies in the operations and maintenance space, and may even lead to misjudgments, resulting in poor anomaly detection accuracy. Summary of the Invention

[0004] The purpose of this application is to provide a method, device, equipment, and medium for anomaly detection of operation and maintenance monitoring curves.

[0005] To achieve the above objectives, this application provides the following solution: Firstly, this application provides a method for anomaly detection of operation and maintenance monitoring curves, including: The system acquires the operation and maintenance monitoring data to be processed and converts it into an operation and maintenance monitoring curve. The operation and maintenance monitoring curve is displayed under constraints according to a target coordinate range. The target coordinate range is determined based on the comparison between the operation and maintenance monitoring data to be processed and a preset value. The operation and maintenance monitoring curve is preprocessed to obtain the processed curve. The processed curve is processed by an anomaly detection model to obtain an anomaly detection result; the anomaly detection model is trained based on the sample dataset and the corresponding anomaly labeling results; the anomaly detection result includes the probability value that the operation and maintenance monitoring curve is an anomaly curve, the anomaly curve refers to the anomaly in the operation and maintenance monitoring data to be processed in a second preset time range within a first preset time range, and the collection time of the operation and maintenance monitoring data to be processed in the second preset time range is after the collection time of the operation and maintenance monitoring data to be processed in the first preset time range.

[0006] Secondly, this application provides an anomaly detection device for operation and maintenance monitoring curves, the device comprising: The acquisition module is used to acquire the operation and maintenance monitoring data to be processed and convert the data into an operation and maintenance monitoring curve; the operation and maintenance monitoring curve is displayed under constraints according to a target coordinate range; the target coordinate range is determined based on the comparison result between the operation and maintenance monitoring data to be processed and a preset value; The preprocessing module is used to preprocess the operation and maintenance monitoring curve to obtain the processed curve. An anomaly detection module is used to process the processed curve graph through an anomaly detection model to obtain an anomaly detection result. The anomaly detection model is trained based on the sample dataset and the corresponding anomaly labeling results. The anomaly detection result includes the probability value that the operation and maintenance monitoring curve graph is an anomaly curve. The anomaly curve refers to the anomaly in the operation and maintenance monitoring data to be processed within a second preset time range within a first preset time range. The collection time of the operation and maintenance monitoring data to be processed within the second preset time range is after the collection time of the operation and maintenance monitoring data to be processed within the first preset time range.

[0007] Thirdly, this application provides a computer device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the anomaly detection method for the operation and maintenance monitoring curve described in any one of the above-mentioned methods.

[0008] Fourthly, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the anomaly detection method for the operation and maintenance monitoring curve described in any of the above-mentioned applications.

[0009] According to the specific embodiments provided in this application, the following technical effects are disclosed: This application provides an anomaly detection method, apparatus, device, and medium for operation and maintenance monitoring curves. The method includes: acquiring operation and maintenance monitoring data to be processed and converting the data into an operation and maintenance monitoring curve; displaying the curve according to a target coordinate range; the target coordinate range is determined based on a comparison between the data and preset values; preprocessing the curve to be processed to obtain a processed curve; processing the processed curve using an anomaly detection model to obtain an anomaly detection result; the anomaly detection model is trained based on a sample dataset and corresponding anomaly annotation results; the anomaly detection result includes the probability value that the operation and maintenance monitoring curve is an anomaly curve, where an anomaly curve refers to an anomaly in the operation and maintenance monitoring data within a second preset time range within a first preset time range, and the data collection time of the data within the second preset time range is after the data collection time of the data within the first preset time range.

[0010] Compared with existing technologies, this solution acquires and transforms the operation and maintenance monitoring data into operation and maintenance monitoring curves, visualizing the time trend and fluctuation characteristics of the data. This avoids the neglect of trend information by traditional pure numerical analysis. Furthermore, by setting a coordinate range closely related to business thresholds, it dynamically adapts to the characteristics of different monitoring indicators, ensuring that the curve shape accurately reflects the business situation. This solves the misjudgment problem caused by the lack of spatial scale constraints in traditional methods and improves the targeting of anomaly identification. The solution also pre-processes the operation and maintenance monitoring curves to be processed, enhancing the stability of the curve features. This allows subsequent models to focus more on capturing real anomaly signals rather than random fluctuations. The processed curves are then input into an anomaly detection model trained based on sample data and annotation results. According to the anomaly detection model, the feature information of the curves is accurately extracted, and the model learns the real anomaly patterns in the business scenario by combining historical annotation data. This solves the misjudgment problem caused by the pure statistical judgment of the traditional 3-sigma algorithm, thus determining accurate anomaly detection results. Simultaneously, it clarifies the anomaly time range of the anomaly curve within the entire time collection range, achieving more accurate anomaly detection that meets business needs. Attached Figure Description

[0011] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0012] Figure 1 A schematic diagram illustrating the degree of data dispersion in the prior art as provided in an embodiment of this application; Figure 2This is a schematic diagram of the application environment for an anomaly detection method for operation and maintenance monitoring curves according to an embodiment of this application; Figure 3 A flowchart illustrating an anomaly detection method for operation and maintenance monitoring curves provided in an embodiment of this application; Figure 4 A schematic diagram of a normal curve provided in an embodiment of this application; Figure 5 A schematic diagram of an anomaly curve provided in an embodiment of this application; Figure 6 This is a schematic diagram illustrating server disk usage monitoring data according to an embodiment of this application. Figure 7 This is a schematic diagram illustrating another method for monitoring server disk usage according to an embodiment of this application. Figure 8 This is a schematic diagram of the anomaly detection process of the operation and maintenance monitoring curve provided in an embodiment of this application; Figure 9 A flowchart illustrating a method for processing a processed curve graph using an anomaly detection model to obtain an anomaly detection result, provided in an embodiment of this application. Figure 10 This is a schematic diagram illustrating an anomaly detection process using a CNN model, provided as an embodiment of this application. Figure 11 This is a flowchart illustrating a method for constructing an anomaly detection model according to an embodiment of this application. Figure 12 A schematic diagram of a normal sample dataset provided in an embodiment of this application; Figure 13 A schematic diagram of another normal sample dataset provided in an embodiment of this application; Figure 14 A schematic diagram of an abnormal sample dataset provided in an embodiment of this application; Figure 15 A schematic diagram of another abnormal sample dataset provided in an embodiment of this application; Figure 16 This application provides a schematic diagram illustrating the relationship between the number of training rounds and performance metrics. Figure 17 A schematic diagram illustrating an anomaly detection process for operation and maintenance monitoring curves provided in this application embodiment; Figure 18 A schematic diagram of an operation and maintenance monitoring curve provided in an embodiment of this application; Figure 19 A schematic diagram of a server rising state provided in an embodiment of this application; Figure 20A schematic diagram of server inbound bandwidth provided for embodiments of this application; Figure 21 A schematic diagram of the functional modules of an anomaly detection device for operation and maintenance monitoring curves provided in this application embodiment; Figure 22 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation

[0013] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0014] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0015] The relevant technology employs the 3-signa algorithm, which is based on statistical principles and divides the normal range according to the degree of data dispersion. For example, when a value deviates from the overall mean by more than three times the standard deviation, it is judged as abnormal. Please see [link / reference]. Figure 1 As shown, taking [1,1,1,1,1,1,1,1,1,1,1,2,1,1,1,1,1,1,1,1,1] as an example, when a set of values ​​are all very close, the mean of this data set is approximately 1.05. Because most values ​​are highly concentrated around 1, the standard deviation is extremely small. In this case, the deviation of 2 from the mean will far exceed 3 times the standard deviation. According to the rules of the 3-sigma algorithm, 2 would be marked as an outlier. However, in operation and maintenance monitoring, if this data set represents CPU utilization, both 1% and 2% are within the normal range of low load. Whether it is 1% or 2%, it belongs to the normal state of idle CPU resources, has no impact on system stability, and is completely in line with business expectations. In this case, the 3-sigma algorithm judges it as an anomaly simply because 2 is slightly different from other data in terms of numerical distribution. This is obviously out of touch with the actual business logic of operation and maintenance monitoring, leading to misjudgment and poor anomaly detection accuracy.

[0016] To address the aforementioned shortcomings, this application provides an anomaly detection method for operation and maintenance monitoring curves. Compared with existing technologies, this solution acquires and processes the operation and maintenance monitoring data to be processed into operation and maintenance monitoring curves, visualizing the time trend and fluctuation characteristics of the data. This avoids the neglect of trend information in traditional pure numerical analysis. Furthermore, by setting a coordinate range closely related to business thresholds, it dynamically adapts to the characteristics of different monitoring indicators, ensuring that the curve shape accurately reflects the business situation. This solves the misjudgment problem caused by the lack of spatial scale constraints in traditional methods, improving the targeting of anomaly identification. The application also pre-processes the operation and maintenance monitoring curves to be processed, enhancing the stability of the curve features. This allows subsequent models to focus more on capturing real anomaly signals rather than random fluctuations. The processed curve is then input into an anomaly detection model trained based on sample data and annotation results. According to the anomaly detection model, the feature information of the curve is accurately extracted, and the model learns the real anomaly patterns in the business scenario by combining historical annotation data. This solves the misjudgment problem caused by pure statistical judgment in the traditional 3-sigma algorithm, thus determining accurate anomaly detection results. Simultaneously, it clarifies the anomaly time range of the anomaly curve within the entire time collection range, achieving more accurate anomaly detection that meets business needs.

[0017] This application provides an anomaly detection method for operation and maintenance monitoring curves, which can be applied to, for example... Figure 2 The application environment of the anomaly detection method for the operation and maintenance monitoring curve shown is illustrated. This application environment includes: terminal 102, server 104, and a data storage system. Terminal 102 communicates with server 104 via a network. The data storage system stores the operation and maintenance monitoring data to be processed acquired by server 104. The data storage system can be set up independently, integrated into server 104, or placed in the cloud or on other servers. Terminal 102 can send the acquired operation and maintenance monitoring data to be processed to server 104. After receiving the data, server 104 performs preprocessing and anomaly detection processing to obtain the anomaly detection result. Furthermore, in some embodiments, the anomaly detection method for the operation and maintenance monitoring curve can also be implemented independently by server 104 or terminal 102. For example, terminal 102 can directly perform preprocessing and anomaly detection processing on the operation and maintenance monitoring data to be processed to obtain the anomaly detection result.

[0018] The terminal 102 can be, but is not limited to, various desktop computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, and smart in-vehicle devices. Portable wearable devices can include smartwatches, smart bracelets, and head-mounted devices. The server 104 can be implemented using a standalone server or a server cluster composed of multiple servers, or it can be a cloud server.

[0019] The anomaly detection method for operation and maintenance monitoring curves provided in this embodiment can be applied to anomaly detection in different system operation and maintenance fields, such as electronic social security card systems.

[0020] In one exemplary embodiment, such as Figure 3 As shown, an anomaly detection method for operation and maintenance monitoring curves is provided. This method is executed by a computer device, specifically by a terminal or server alone, or by both a terminal and a server. In this embodiment, the method is applied to... Figure 2 Taking server 104 as an example, the explanation includes the following steps S201 to S203. Wherein: Step S201: Obtain the operation and maintenance monitoring data to be processed and convert it into an operation and maintenance monitoring curve; the operation and maintenance monitoring curve is displayed under constraints according to the target coordinate range; the target coordinate range is determined based on the comparison result between the operation and maintenance monitoring data to be processed and the preset value.

[0021] It should be noted that the above-mentioned operation and maintenance monitoring data to be processed refers to the data that needs to be monitored for the items to be tested. The items to be tested may include, for example, CPU utilization and disk I / O utilization.

[0022] Optionally, the aforementioned operation and maintenance monitoring data to be processed can be obtained from external devices, imported from blockchain or database, or obtained from real-time monitoring of the items to be tested. This embodiment does not limit the method of obtaining the operation and maintenance monitoring data to be processed.

[0023] The process of acquiring pending operation and maintenance monitoring data includes: acquiring test items; test items include: CPU utilization, disk I / O utilization, and disk read / write latency; receiving and responding to business monitoring instructions, calling the data acquisition interface corresponding to the test items, and acquiring the pending operation and maintenance monitoring data.

[0024] It should be noted that the aforementioned business monitoring commands are customized according to different application systems on different devices. For example, they could be the `dd` command, and the data acquisition interface could be the Prometheus interface. The `dd` command is a tool used for data copying and conversion in Linux systems. Because it allows control over data read / write intensity via parameters, it is often used as a lightweight load testing tool.

[0025] For example, when the test item is CPU utilization, the `dd` command can perform a task that consumes computing resources but involves no I / O operations. During this process, `dd` continuously reads and processes data, constantly occupying CPU resources, causing CPU utilization to rise, in order to obtain the corresponding operational monitoring data. When the test item is disk I / O utilization, the `dd` command performs actual disk read and write operations to obtain the corresponding operational monitoring data.

[0026] Among them, Prometheus is an open-source monitoring system that uses node_exporter (a node monitoring plugin) deployed on a server to collect hardware and system metrics (including CPU utilization, disk I / O rate, disk read / write latency, etc.) in real time and stores the data in time-series format.

[0027] Understandably, the alarm time points for the monitoring curve are first defined. For example, a preset time range of pending operation and maintenance monitoring data is selected, and a value is taken every minute to form multiple consecutive values, thus creating the operation and maintenance monitoring curve. This preset time range can be customized according to actual needs, such as 30 minutes. The operation and maintenance monitoring curve can be a straight line, a curve, or other line segments with abrupt changes.

[0028] Within a first preset time range, an abnormal curve appears at the last second preset time. This abnormality could be, for example, a large fluctuation, which constitutes an abnormal curve. The first preset time range is, for example, 30 minutes, and the second preset time range is, for example, the last 5 minutes. Taking a 30-minute first preset time range and a 5-minute second preset time range as an example, the maintenance monitoring curve typically exhibits significant fluctuations within the first five minutes after an alarm occurs due to an anomaly. If there is fluctuation in the first 25 minutes but no fluctuation in the last 5 minutes, it usually indicates recovery, signifying a normal curve. Please refer to [link to relevant documentation]. Figure 4 As shown in the figure, this is a normal curve, including the low-fluctuation normal curve a and the low-fluctuation curve b that appears in the following five minutes. Please refer to [link / reference]. Figure 5 As shown in the figure, the abnormal curves, including curves c and d, are both curves that show significant fluctuations in the last five minutes.

[0029] After obtaining the operation and maintenance monitoring data to be processed, the data can be transformed into operation and maintenance monitoring graphs, including: Determine whether the pending operation and maintenance monitoring data exceeds the preset value; the preset value is determined according to business rules. When the preset value is exceeded, the operation and maintenance monitoring data to be processed is mapped according to the preset value to obtain the mapped value; the horizontal axis value range is determined according to the time information of the operation and maintenance monitoring data to be processed, and the vertical axis value range is determined according to the mapped value to construct the target coordinate range and generate the operation and maintenance monitoring curve.

[0030] Specifically, the aforementioned operation and maintenance monitoring curve includes a coordinate range, which refers to the display canvas of the curve. This range can be based on time information on the horizontal axis and the operation and maintenance monitoring data to be processed on the vertical axis. The numerical ranges of the horizontal and vertical axes are determined to construct the target coordinate range. The target coordinate range of the operation and maintenance monitoring curve is a key factor in determining whether it can truly reflect the system state. By combining numerical values ​​with spatial scales, it effectively compensates for the shortcomings of the traditional 3-sigma algorithm, which relies solely on pure numerical statistics. First, a preset value is determined according to business rules. For example, an anomaly threshold is used as a preset value based on business rules. It is then determined whether the operation and maintenance monitoring data to be processed exceeds the preset value. If it does, the data is mapped according to the preset value to obtain the mapped value. Then, the numerical range of the horizontal axis is determined based on the time information of the data, and the data is normalized to the mapped value to determine the numerical range of the vertical axis, thus constructing the target coordinate range and generating the operation and maintenance monitoring curve.

[0031] For example, consider a set of monitoring data representing server disk usage, assuming the values ​​for a certain period are [1,1,1,2,1,1,1]. Please refer to [link to relevant documentation]. Figure 6 As shown, if the maximum value of the Y-axis is set to 1, the vertical axis scale is extremely compressed. The value 2 will exceed the upper limit of the coordinate system, resulting in a sharp, precipitous drop on the curve. From a purely visual perspective, this characteristic of exceeding the upper limit is easily misjudged as an anomaly. However, in actual operation and maintenance scenarios, memory usage rates of 1% and 2% are both within the safe range of low-load business operations. Such fluctuations themselves pose no risk. The 3-sigma algorithm will also misjudge this because the deviation of 2 from the mean exceeds three times the standard deviation (due to the concentration of data leading to a very small standard deviation). The unreasonable amplification of the Y-axis scale further exacerbates this misjudgment.

[0032] Please see Figure 7 As shown, conversely, when the maximum value of the Y-axis is set to 100, which corresponds to the business threshold range of 0%-100% memory utilization, the curves for the same set of data will exhibit completely different shapes: both 1 and 2 are distributed in the flat area at the bottom of the vertical axis, with almost no obvious fluctuations in the curves, intuitively reflecting the business status of being "in the safe range". This shape is highly consistent with business rules, avoiding misjudgments caused by scale distortion, and enabling the "fluctuation amplitude" of the operation and maintenance monitoring curve to be directly related to the "business risk level", rather than simply depending on the statistical dispersion of the values.

[0033] For values ​​exceeding the Y-axis range of (0, 100) (such as disk usage reaching 105%), normalization to 100 can be performed, for example, mapping 105 to 100. This further ensures the stability of the coordinate scale: it preserves the abnormal characteristics of "reaching the business upper limit" on the curve (such as the curve continuously peaking at 100), while avoiding the imbalance of the graph scale caused by the numerical value exceeding the limit. This processing allows anomalies exceeding the upper limit to be clearly identified under a uniform scale. When faced with such data, the 3-sigma algorithm may miss the detection because the deviation of 105 from the mean (such as 95) is less than 3 times the standard deviation, thus masking business risks.

[0034] In this step, the X-axis range is set to (0, 30), and the Y-axis range is set to (0, 100). This coordinate setting aligns with the percentage thresholds of most operational metrics, integrating the anomaly threshold into data visualization. This allows changes in the curve's shape to directly point to anomalies in a business context, rather than statistically significant "outliers." This combination completely solves the problems of "misjudging normal fluctuations" and "missing hidden risks" caused by the 3-sigma algorithm being out of touch with business scenarios, making anomaly detection more closely aligned with actual operational needs.

[0035] Step S202: Preprocess the operation and maintenance monitoring curve to obtain the processed curve.

[0036] Step S203: The processed curve is processed by an anomaly detection model to obtain an anomaly detection result. The anomaly detection model is trained based on the sample dataset and the corresponding anomaly labeling results. The anomaly detection result includes the probability value that the operation and maintenance monitoring curve is an anomaly curve. An anomaly curve refers to the anomaly in the operation and maintenance monitoring data to be processed within a second preset time range within a first preset time range. The collection time of the operation and maintenance monitoring data to be processed within the second preset time range is after the collection time of the operation and maintenance monitoring data to be processed within the first preset time range.

[0037] It is understood that the above anomaly detection model can be used to detect anomalies in monitoring curves and obtain anomaly detection results. These results include the probability value that the operation and maintenance monitoring curve is an abnormal curve, with the probability value ranging from 0 to 1. When the probability value is 0, it indicates that the operation and maintenance monitoring curve is normal; when the probability value is 1, it indicates that the operation and maintenance monitoring curve is abnormal. Optionally, this anomaly detection model can be, for example, a CNN model or an RNN model.

[0038] Specifically, please see Figure 8As shown, taking the anomaly detection model as a CNN model as an example, after obtaining the operation and maintenance monitoring curve, the operation and maintenance monitoring curve is processed by dimensionality reduction, normalization and other processes to obtain the processed curve. Then, the processed curve is processed by the CNN model to obtain the anomaly classification result. The anomaly classification result can include 0 and 1, where 1 indicates that the operation and maintenance monitoring curve is abnormal and 0 indicates that the operation and maintenance monitoring curve is normal.

[0039] Understandably, the training of the anomaly detection model involves first acquiring a sample dataset and labeling it. Each sample dataset is labeled with corresponding anomaly annotations, including both normal and abnormal sample datasets. After training the anomaly detection model, the processed graphs are then processed again to obtain the anomaly detection results. The anomaly curves in the abnormal sample dataset are the monitoring curves that exhibit anomalies within the first preset time range and the last preset time range. For example, the first preset time range is 30 minutes, and the second preset time range is 5 minutes. Since the anomaly annotations during model training indicate anomalies in the pending maintenance monitoring data within the second preset time range of the first preset time range, the anomaly curves in the anomaly detection results obtained after processing by the anomaly detection model also indicate anomalies in the pending maintenance monitoring data within the second preset time range of the first preset time range.

[0040] This embodiment anchors the chronological relationship along the time dimension (e.g., using the past 30 minutes as the first range and the last 5 minutes as the second preset time range). This allows for the construction of a normal baseline based on historical data (the first preset time range) for reference, while also precisely focusing on abnormal changes in recent data (the second preset time range), enabling targeted monitoring of potential risks in the latest time period. This hierarchical setting of time ranges avoids the traditional approach of judging the entire time series, ensuring the timeliness of anomaly detection by prioritizing newly occurring or ongoing anomalies. Furthermore, the contextual support of historical data reduces misjudgments of isolated fluctuations, making anomaly results more aligned with the actual needs of "timely detection and handling of recent faults" in operational scenarios, thus improving the accuracy and practicality of detection.

[0041] In one embodiment, a specific implementation method is also provided for processing the processed curve graph through an anomaly detection model to obtain an anomaly detection result. Please refer to [link to relevant documentation]. Figure 9 As shown, the method includes: Step S301: The processed curve is processed by performing feature extraction through a convolutional layer to obtain local feature information; the local feature information includes: abrupt change information at a certain moment, and rising or falling information over a certain time range.

[0042] Step S302: Local feature information is introduced into nonlinear features through activation function layers to obtain feature maps.

[0043] Step S303: The feature map is downsampled through a pooling layer to obtain multi-dimensional information.

[0044] Step S304: Convert the multi-dimensional information into a one-dimensional vector through a flattening layer, and then integrate the one-dimensional vector through a fully connected layer to obtain global features.

[0045] Step S305: Process the global features using a classification function to obtain the anomaly detection result.

[0046] Specifically, after obtaining the inverted curve, a convolution kernel of a preset size can be obtained. This kernel is then used as a sliding window to slide pixel-by-pixel across the processed curve to perform convolution operations. A weighted summation operation is performed on the pixel values ​​within each sliding window to convert the morphological changes of the curve within a local region into feature values, thus obtaining local feature information. This local feature information includes: abrupt changes in value at a certain moment, and an upward or downward trend over a specific time range.

[0047] Understandably, taking an anomaly detection model as an example of a CNN model, mathematically, convolution is an integral transformation, but in deep learning, it can be expressed by the following formula: ; Where I represents the processed graph, and K represents the convolution kernel, also known as a filter. Let S(i,j) represent the convolution operation, where i and j represent the local feature values ​​on the output feature map, i and j represent the position indices of the local feature values, i.e. the element positions in the i-th row and j-th column of the output feature map, and m and n represent the element indices inside the convolution kernel K, i.e. the element positions in the m-th row and n-th column of the convolution kernel when traversing the convolution kernel.

[0048] Please see [the image / document]. Figure 10As shown, after obtaining the post-processed curve, feature extraction is performed through a convolutional layer to obtain local feature information. This local feature information includes: abrupt changes at a specific moment, and increases or decreases over a certain time range. A ReLU activation function is used to introduce non-linear features, enhancing the generalization ability of the feature extraction model and obtaining a feature map. This feature map is then downsampled through a pooling layer to reduce data dimensionality, prevent overfitting, and obtain multi-dimensional information. The data then enters a flatten layer to convert the multi-dimensional information into a one-dimensional vector, and finally a fully connected layer to connect all features. Finally, a SoftMax function is used for classification to obtain the probability value of whether the operation and maintenance monitoring curve is an abnormal curve. This probability value can include values ​​from 0 to 1, such as 0.1, 0.2, and 0.7. Curves with probability values ​​greater than a preset probability threshold are identified as abnormal curves.

[0049] In this embodiment, the convolutional layer's ability to extract local features accurately identifies micro-level changes with business significance in the operation and maintenance curve, such as a sudden jump in CPU utilization from 20% to 90% within one minute, breaking through the dependence of traditional statistical methods on the overall distribution. Introducing nonlinear features through activation function layers can fit complex anomaly patterns, such as sudden non-periodic shifts within periodic fluctuations; and pooling layers preserve key features through dimensionality reduction, enhancing the model's resistance to noise; the integration of global features can correlate local changes at different times, achieving a holistic judgment of anomalies. Through this layered processing, the model can capture both instantaneous anomalies and understand trend anomalies, and the final output more closely matches the anomaly judgment logic that combines local fluctuations with global trends in operation and maintenance scenarios, significantly improving detection accuracy.

[0050] This embodiment also provides a specific implementation method for constructing the anomaly detection model; please refer to [link to relevant documentation]. Figure 11 As shown, the method includes: Step S401: Obtain the sample dataset and the corresponding anomaly annotation results; the sample dataset includes normal sample dataset and abnormal sample dataset.

[0051] Step S402: Divide the sample dataset into a training set and a test set according to a preset partitioning rule.

[0052] Step S403: Input the training set into the initial network model to obtain the output result.

[0053] Step S404: Based on the output results and anomaly labeling results, construct a loss function, and iteratively train the parameters in the initial network model according to minimizing the loss function to obtain the network model to be tested.

[0054] Step S405: Input the test set into the network model to be tested for performance testing, and select the network model with the best performance index as the anomaly detection model; the performance index includes at least one of the following: accuracy, recall, and FI score.

[0055] Specifically, the aforementioned sample dataset includes normal sample datasets and abnormal sample datasets. This dataset may include multiple graphs, for example, up to 5000 graphs, including straight lines, straight lines with small fluctuations, descending straight lines with small angles of inclination, ascending straight lines with small angles of inclination, straight lines with abnormal drops in the first 25 points, straight lines with abnormal increases in the first 25 points, and curves with small fluctuations. Please refer to [link / reference]. Figures 12-13 As shown, Figure 12 and Figure 13 These are all schematic diagrams of normal sample datasets, including: (a) a schematic diagram of a straight line dataset, (b) a schematic diagram of a straight line sample dataset with small fluctuations, and (c) a schematic diagram of a descending straight line sample dataset with a small slope angle. Figure 13 (d) is a schematic diagram of a sample dataset of rising straight lines with a small inclination angle; (e) is a schematic diagram of a sample dataset of straight lines with an abnormal drop in the first 25 points; (f) is a schematic diagram of a sample dataset of straight lines with an abnormal increase in the first 25 points; and (g) is a schematic diagram of a sample dataset of curves with small fluctuation amplitude. Here, "small fluctuation" means the fluctuation trend is less than the preset trend, "small inclination angle" means the inclination angle is less than the preset angle, and "small fluctuation amplitude" means the fluctuation amplitude is less than the preset amplitude.

[0056] Please see Figures 14-15 As shown, Figure 14 and Figure 15 These are all schematic diagrams of abnormal sample datasets, including: (a) a schematic diagram of a curve sample dataset with large fluctuations, (b) a schematic diagram of a curve sample dataset with a sudden drop in the last five minutes, and (c) a schematic diagram of a curve sample dataset with a sudden increase in the last five minutes. Figure 15 (d) is a schematic diagram of a curve sample dataset with multiple sudden drops in the last five minutes, (e) is a schematic diagram of a curve sample dataset with a sudden increase in the first 25 minutes and a sudden increase in the last 5 minutes, and (f) is a schematic diagram of a curve sample dataset with a sudden increase in the last 5 minutes.

[0057] After obtaining the normal and abnormal sample datasets, they can be divided into training and test sets. The training set is used to train the anomaly detection model, and the test set is used to test the trained model to obtain the anomaly detection result. During the dataset splitting, the `train_test_split` function from the Python scikit-learn module can be called to divide the dataset into training and validation sets. A split ratio of 8:2 can be set, with 80% of the dataset used as the training set and 20% as the test set. This allows for performance evaluation at the end of each epoch, helping developers monitor for overfitting or underfitting. Then, the optimizer is configured. Choosing the Adam optimizer allows for adaptive adjustment of the learning rate and typically performs well on most tasks. The loss function is set to the categorical cross-entropy loss function, and performance evaluation metrics are defined, including accuracy, recall, and F1 score.

[0058] After dividing the training and test sets, set the initial training parameters, such as 5 training epochs. In each epoch, the model will traverse the entire training set once, updating the weights. Set the batch size to 64, meaning the model will use 64 samples as a batch for computation. Using batch training can accelerate the training process and help the model converge stably. Input the training set into the initial network model, which will then process it sequentially through convolutional layers, activation function layers, pooling layers, flattening layers, and fully connected layers to obtain the output result.

[0059] After obtaining the output results, a loss function can be constructed based on the output results and the anomaly labeling results. The initial network model to be constructed is then optimized by minimizing the loss function to obtain the network model to be tested. Based on the difference between the output results and the labeling results, the parameters in the initial network model are updated to achieve the purpose of training the initial network model. The anomaly labeling results mentioned above can be the results obtained by manually annotating the sample dataset.

[0060] Optionally, updating the parameters in the initial network model to be constructed may involve updating matrix parameters such as the weight matrix and bias matrix in the initial network model. These weight and bias matrices include, but are not limited to, the matrix parameters in the convolutional layers, pooling layers, exponent layers, and fully connected layers of the initial network model.

[0061] When updating the parameters of the initial network model using the loss function, if the loss function indicates that the initial network model has not converged, the parameters in the model are adjusted to make the initial network model converge, thus obtaining the network model to be tested. Initial network model convergence can be defined as the difference between the output of the initial network model and the anomaly labeling results being less than a preset threshold, or the rate of change of the difference between the output and the anomaly labeling results approaching a certain low value. When the calculated loss function is small, or the difference between it and the loss function output from the previous iteration approaches 0, the initial network model is considered to have converged, and the network model to be tested is obtained. Optionally, the above sample dataset may also include a validation set to verify the model's performance.

[0062] Please see Figure 16 As shown, Figure 16 The horizontal X-axis on the left represents the number of training rounds, and the vertical Y-axis represents the accuracy. The blue curve is the accuracy of the training set, and the yellow curve is the accuracy of the validation set. As can be seen from the left graph, as the number of training rounds increases, the accuracy of both the training and validation sets continuously improves. After a certain number of rounds, the accuracy can no longer be improved and tends to stabilize. In other words, increasing the number of training rounds no longer has an effect. This graph clearly illustrates the good training effect. Figure 16 In the right-hand graph, the horizontal X-axis represents the number of training rounds, and the vertical Y-axis represents the loss rate. The blue curve represents the loss rate of the training set, and the yellow curve represents the loss rate of the validation set. As can be seen from the right-hand graph, as the number of training rounds increases, the loss rates of both the training and validation sets continuously decrease. After a certain number of rounds, the loss rate can no longer decrease and tends to stabilize. This means that increasing the number of training rounds no longer has any effect. This graph clearly illustrates the good training effect.

[0063] After processing the processed curve graph through an anomaly detection model to obtain the anomaly detection results, the method also includes: Receive and respond to the anomaly cause lookup command, determine the anomaly information based on the anomaly detection results; the anomaly information includes at least one of the following: anomaly item, anomaly cause; and perform fault handling based on the anomaly information.

[0064] Please see Figure 17 As shown, after determining the anomaly detection model, the `dd` command is used to stress test CPU and disk I / O. The monitoring and maintenance data to be processed is obtained through the Prometheus interface and converted into an operation and maintenance monitoring curve. Please refer to [link to relevant documentation]. Figure 18As shown, the left graph is the CPU utilization curve, and the right graph is the disk I / O utilization curve. These curves are input into an anomaly detection model for anomaly detection processing to obtain the anomaly detection results. When an anomaly is detected, the server with the displayed IP address can be logged into, and commands such as `ps`, `top`, and `iotop` can be used to obtain the anomaly item and its cause. Fault handling can then be performed based on the anomaly item and its cause. Alternatively, a server can be shut down, and the Prometheus interface can be called to obtain the monitoring curve to be processed; see [link to relevant documentation](link to documentation). Figure 19 As shown, Figure 19 This is a graph illustrating the server's rising status. Upon detecting an anomaly, commands such as SSH and ping are used to test whether the server has crashed and recovered. The server's bandwidth is stress-tested using iperf3, and the monitoring graph is obtained through the Prometheus interface. Please refer to [link / reference]. Figure 20 As shown, Figure 20 This is a graph illustrating the inbound bandwidth of the server. When an anomaly is detected, you can log in to the server with the displayed IP address and use commands such as ps, top, and sar to find the specific cause of the anomaly.

[0065] After obtaining the anomaly detection results, view the anomaly information, which includes the anomaly items and their causes. The anomaly items include various anomalies such as server CPU usage, server memory usage, and database memory usage, and the corresponding IP addresses are displayed. Then, based on these anomaly items, find the corresponding faulty IP address, and then find the corresponding anomaly cause through login, and complete the business recovery.

[0066] In this embodiment, an anomaly detection model is used to identify features in the monitoring curve sample dataset. Based on the different annotation results of normal and abnormal data in the sample dataset, an anomaly detection model is trained that can distinguish whether the image monitoring curve diagram is normal or abnormal. This allows the anomaly detection result (normal or abnormal) of the monitoring curve to be processed to be obtained by inputting an image of the monitoring curve into the anomaly detection model in a real production environment.

[0067] This application provides an anomaly detection method for operation and maintenance monitoring curves. The method includes: acquiring operation and maintenance monitoring data to be processed and converting it into an operation and maintenance monitoring curve; displaying the operation and maintenance monitoring curve according to a target coordinate range; the target coordinate range is determined based on a comparison between the operation and maintenance monitoring data to be processed and a preset value; preprocessing the operation and maintenance monitoring curve to obtain a processed curve; processing the processed curve using an anomaly detection model to obtain an anomaly detection result; the anomaly detection model is trained based on a sample dataset and corresponding anomaly annotation results; the anomaly detection result includes the probability value that the operation and maintenance monitoring curve is an anomaly curve, where an anomaly curve refers to an anomaly in the operation and maintenance monitoring data to be processed within a second preset time range within a first preset time range, and the acquisition time of the operation and maintenance monitoring data to be processed within the second preset time range is after the acquisition time of the operation and maintenance monitoring data to be processed within the first preset time range. Compared with existing technologies, this solution acquires and transforms the operation and maintenance monitoring data into operation and maintenance monitoring curves, visualizing the time trend and fluctuation characteristics of the data. This avoids the neglect of trend information by traditional pure numerical analysis. Furthermore, by setting a coordinate range closely related to business thresholds, it dynamically adapts to the characteristics of different monitoring indicators, ensuring that the curve shape accurately reflects the business situation. This solves the misjudgment problem caused by the lack of spatial scale constraints in traditional methods and improves the targeting of anomaly identification. The solution also pre-processes the operation and maintenance monitoring curves to be processed, enhancing the stability of the curve features. This allows subsequent models to focus more on capturing real anomaly signals rather than random fluctuations. The processed curves are then input into an anomaly detection model trained based on sample data and annotation results. According to the anomaly detection model, the feature information of the curves is accurately extracted, and the model learns the real anomaly patterns in the business scenario by combining historical annotation data. This solves the misjudgment problem caused by the pure statistical judgment of the traditional 3-sigma algorithm, thus determining accurate anomaly detection results. Simultaneously, it clarifies the anomaly time range of the anomaly curve within the entire time collection range, achieving more accurate anomaly detection that meets business needs.

[0068] Based on the same inventive concept, this application also provides an anomaly detection device for implementing the aforementioned operation and maintenance monitoring curve. The solution provided by this device is similar to the solution described in the above method. Therefore, the specific limitations in one or more anomaly detection device embodiments of operation and maintenance monitoring curves provided below can be found in the limitations of the anomaly detection method for operation and maintenance monitoring curves described above, and will not be repeated here.

[0069] In one exemplary embodiment, such as Figure 21 As shown, an anomaly detection device for operation and maintenance monitoring curves is provided. The device includes: The acquisition module 510 is used to acquire the operation and maintenance monitoring data to be processed and convert the data into an operation and maintenance monitoring curve; the operation and maintenance monitoring curve is displayed under constraints according to the target coordinate range; the target coordinate range is determined based on the comparison result between the operation and maintenance monitoring data to be processed and the preset value; The preprocessing module 520 is used to preprocess the operation and maintenance monitoring curve to obtain the processed curve. The anomaly detection module 530 is used to process the processed curve graph through the anomaly detection model to obtain the anomaly detection result. The anomaly detection model is trained based on the sample dataset and the corresponding anomaly labeling results. The anomaly detection result includes the probability value that the operation and maintenance monitoring curve graph is an anomaly curve. An anomaly curve refers to the anomaly in the operation and maintenance monitoring data to be processed within a second preset time range within a first preset time range. The collection time of the operation and maintenance monitoring data to be processed within the second preset time range is after the collection time of the operation and maintenance monitoring data to be processed within the first preset time range.

[0070] As an optional implementation, the acquisition module 510 is specifically used for: Determine whether the pending operation and maintenance monitoring data exceeds the preset value; the preset value is determined according to business rules. When the preset value is exceeded, the operation and maintenance monitoring data to be processed will be mapped according to the preset value to obtain the mapped value; The horizontal axis value range is determined based on the time information of the operation and maintenance monitoring data to be processed, and the vertical axis value range is determined based on the mapping value. The target coordinate range is constructed, and the operation and maintenance monitoring curve is generated.

[0071] As an optional implementation, the anomaly detection module 530 is specifically used for: The processed curve is processed through a convolutional layer to extract features, which yields local feature information. Local feature information includes: abrupt changes at a certain moment, and rising or falling information over a certain time range. Local feature information is introduced into nonlinear features through activation function layers to obtain feature maps; The feature map is downsampled through a pooling layer to obtain multi-dimensional information; Multi-dimensional information is converted into a one-dimensional vector through a flattening layer, and the one-dimensional vector is then integrated and processed through a fully connected layer to obtain global features; The global features are processed by a classification function to obtain the anomaly detection results.

[0072] As an optional implementation, the anomaly detection module 530 is also used for: The convolution operation is performed by sliding a convolution kernel of a preset size as a sliding window on the processed curve pixel by pixel. The pixel values ​​within each sliding window are weighted and summed to convert the morphological changes of the curves in the local area into feature values, thus obtaining local feature information.

[0073] As an optional implementation, the anomaly detection model is constructed through the following steps: Obtain the sample dataset and the corresponding anomaly annotation results; the sample dataset includes normal sample datasets and anomaly sample datasets. The sample dataset is divided into a training set and a test set according to a preset partitioning rule; The training set is input into the initial network model to obtain the output result; Based on the output results and anomaly labeling results, a loss function is constructed. By minimizing the loss function, the parameters in the initial network model are iteratively trained to obtain the network model to be tested. Input the test set into the network model under test for performance testing, and select the network model with the best performance index as the anomaly detection model; the performance index includes at least one of the following: accuracy, recall, and FI score.

[0074] As an optional implementation, the acquisition module 510 is specifically used for: Obtain the items to be tested; the items to be tested include: CPU utilization and disk I / O utilization. Receive and respond to business monitoring instructions, call the data acquisition interface corresponding to the item to be tested, and obtain the operation and maintenance monitoring data to be processed.

[0075] As an optional implementation, the above-described apparatus is further used for: Receive and respond to an anomaly cause lookup command, and determine anomaly information based on anomaly detection results; the anomaly information includes at least one of the following: anomaly item, anomaly cause; Fault handling based on abnormal information.

[0076] The anomaly detection device for operation and maintenance monitoring curves provided in this application embodiment acquires and processes operation and maintenance monitoring data into operation and maintenance monitoring curves, visualizing the time trend and fluctuation characteristics of the data. This avoids the neglect of trend information by traditional pure numerical analysis. Furthermore, by setting a coordinate range closely related to business thresholds, it dynamically adapts to the characteristics of different monitoring indicators, ensuring that the curve shape accurately reflects the business situation. This solves the misjudgment problem caused by the lack of spatial scale constraints in traditional methods, improving the targeting of anomaly identification. The device also pre-processes the operation and maintenance monitoring curves to be processed, enhancing the stability of the curve features. This allows subsequent models to focus more on capturing real anomaly signals rather than random fluctuations. The processed curve is then input into an anomaly detection model trained based on sample data and annotation results. According to the anomaly detection model, the feature information of the curve is accurately extracted, and the real anomaly patterns in the business scenario are learned by combining historical annotation data. This solves the misjudgment problem caused by pure statistical judgment in the traditional 3-sigma algorithm, thereby determining accurate anomaly detection results. Simultaneously, it clarifies the abnormal time range of the anomaly curve within the entire time collection range, achieving more accurate anomaly detection that meets business needs.

[0077] In one exemplary embodiment, a computer device is provided, which may be a server or a terminal, and its internal structure diagram may be as follows. Figure 22 As shown, this computer device includes a processor, memory, input / output interfaces (I / O), and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operating system and computer programs stored in the non-volatile storage media. The database stores video tag processing data. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When the computer program is executed by the processor, it implements an anomaly detection method for operation and maintenance monitoring curves.

[0078] Those skilled in the art will understand that Figure 22 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0079] In one exemplary embodiment, a computer device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described method embodiments.

[0080] In one exemplary embodiment, a computer-readable storage medium is provided storing a computer program that, when executed by a processor, implements the steps in the above-described method embodiments.

[0081] In one exemplary embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above-described method embodiments.

[0082] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.

[0083] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM).

[0084] The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0085] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0086] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. Furthermore, those skilled in the art will recognize that, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A method for anomaly detection in operation and maintenance monitoring curves, characterized in that, The anomaly detection method for the operation and maintenance monitoring curve includes: The system acquires the operation and maintenance monitoring data to be processed and converts it into an operation and maintenance monitoring curve. The operation and maintenance monitoring curve is displayed under constraints according to a target coordinate range. The target coordinate range is determined based on the comparison between the operation and maintenance monitoring data to be processed and a preset value. The operation and maintenance monitoring curve is preprocessed to obtain the processed curve. The processed curve is processed by an anomaly detection model to obtain an anomaly detection result; the anomaly detection model is trained based on the sample dataset and the corresponding anomaly labeling results; the anomaly detection result includes the probability value that the operation and maintenance monitoring curve is an anomaly curve, the anomaly curve refers to the anomaly in the operation and maintenance monitoring data to be processed in a second preset time range within a first preset time range, and the collection time of the operation and maintenance monitoring data to be processed in the second preset time range is after the collection time of the operation and maintenance monitoring data to be processed in the first preset time range.

2. The anomaly detection method for operation and maintenance monitoring curves according to claim 1, characterized in that, The process of converting the unprocessed operation and maintenance monitoring data into an operation and maintenance monitoring curve graph includes: Determine whether the pending operation and maintenance monitoring data exceeds the preset value; the preset value is determined according to business rules; When the preset value is exceeded, the operation and maintenance monitoring data to be processed is mapped according to the preset value to obtain the mapped value; The horizontal axis value range is determined based on the time information of the operation and maintenance monitoring data to be processed, and the vertical axis value range is determined based on the mapping value. The target coordinate range is constructed, and the operation and maintenance monitoring curve is generated.

3. The anomaly detection method for operation and maintenance monitoring curves according to claim 1, characterized in that, The anomaly detection model includes: convolutional layers, activation function layers, pooling layers, flattening layers, and fully connected layers; The processed curve is then processed through an anomaly detection model to obtain anomaly detection results, including: The processed curve is processed by the convolutional layer to extract features, thereby obtaining local feature information. The local feature information includes: abrupt change information at a certain moment, and rising or falling information over a certain time range. The local feature information is introduced into nonlinear features through the activation function layer to obtain a feature map; The feature map is downsampled using a pooling layer to obtain multi-dimensional information. The multi-dimensional information is converted into a one-dimensional vector through the flattening layer, and the one-dimensional vector is integrated and processed through the fully connected layer to obtain global features; The global features are processed by a classification function to obtain the anomaly detection result.

4. The anomaly detection method for operation and maintenance monitoring curves according to claim 3, characterized in that, The processed curve is passed through the convolutional layer for feature extraction to obtain local feature information, including: A convolution operation is performed by sliding a convolution kernel of a preset size as a sliding window on the processed curve pixel by pixel. A weighted summation operation is performed on the pixel values ​​within each sliding window to convert the morphological change information of the curve in the local area into feature values, thereby obtaining the local feature information.

5. The anomaly detection method for operation and maintenance monitoring curves according to claim 1, characterized in that, The anomaly detection model is constructed through the following steps: Obtain the sample dataset and the corresponding anomaly annotation results; the sample dataset includes normal sample datasets and anomaly sample datasets. The sample dataset is divided into a training set and a test set according to a preset partitioning rule; The training set is input into the initial network model to obtain the output result; Based on the output results and the anomaly labeling results, a loss function is constructed, and the parameters in the initial network model are iteratively trained according to minimizing the loss function to obtain the network model to be tested. The test set is input into the network model to be tested for performance testing, and the network model with the best performance index is selected as the anomaly detection model; the performance index includes at least one of the following: accuracy, recall, and FI score.

6. The anomaly detection method for operation and maintenance monitoring curves according to claim 1, characterized in that, Obtain pending operation and maintenance monitoring data, including: Obtain the items to be tested; the items to be tested include: CPU utilization and disk I / O utilization. Receive and respond to the business monitoring instruction, call the data acquisition interface corresponding to the item to be tested, and obtain the operation and maintenance monitoring data to be processed.

7. The anomaly detection method for operation and maintenance monitoring curves according to claim 1, characterized in that, After processing the processed curve graph using an anomaly detection model to obtain the anomaly detection result, the method further includes: Receive and respond to an anomaly cause lookup command, and determine anomaly information based on the anomaly detection result; the anomaly information includes at least one of the following: anomaly item, anomaly cause; Fault handling is performed based on the aforementioned abnormal information.

8. An anomaly detection device for operation and maintenance monitoring curves, characterized in that, The anomaly detection device for the operation and maintenance monitoring curve includes: The acquisition module is used to acquire the operation and maintenance monitoring data to be processed and convert the data into an operation and maintenance monitoring curve; the operation and maintenance monitoring curve is displayed under constraints according to a target coordinate range; the target coordinate range is determined based on the comparison result between the operation and maintenance monitoring data to be processed and a preset value; The preprocessing module is used to preprocess the operation and maintenance monitoring curve to obtain the processed curve. An anomaly detection module is used to process the processed curve graph through an anomaly detection model to obtain an anomaly detection result. The anomaly detection model is trained based on the sample dataset and the corresponding anomaly labeling results. The anomaly detection result includes the probability value that the operation and maintenance monitoring curve graph is an anomaly curve. The anomaly curve refers to the anomaly in the operation and maintenance monitoring data to be processed within a second preset time range within a first preset time range. The collection time of the operation and maintenance monitoring data to be processed within the second preset time range is after the collection time of the operation and maintenance monitoring data to be processed within the first preset time range.

9. A computer device, comprising: The memory and processor contain a computer program stored in the memory and executable on the processor, characterized in that the processor executes the computer program to implement the steps of the anomaly detection method for the operation and maintenance monitoring curve according to any one of claims 1-7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the anomaly detection method for the operation and maintenance monitoring curve as described in any one of claims 1-7.