Wireless network fault root cause positioning method and device based on dynamic knowledge graph
By combining dynamic knowledge graphs and large language models, the accuracy and efficiency problems of traditional wireless network fault root cause localization methods are solved, realizing automated and interpretable fault root cause localization and improving wireless network operation and maintenance efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- INSPUR TIANYUAN COMM INFORMATION SYST CO LTD
- Filing Date
- 2025-12-19
- Publication Date
- 2026-05-01
AI Technical Summary
Traditional methods for locating the root cause of wireless network faults rely on human experience and have low accuracy. Static knowledge graphs cannot adapt to dynamic changes in the network, resulting in unstable and inaccurate location results.
By adopting a dynamic knowledge graph-based approach, alarm connection edges are updated by mining historical alarm data. Combined with an operation and maintenance knowledge base and a large language model, root cause localization of faults is achieved, realizing an end-to-end automated process from alarm perception to root cause output.
It improves the accuracy and efficiency of fault location, reduces reliance on human experience, provides interpretable location results, and enhances the efficiency of wireless network operation and maintenance.
Smart Images

Figure CN121967178A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of wireless network operation and maintenance technology, and in particular to a method and apparatus for locating the root cause of wireless network faults based on dynamic knowledge graphs. Background Technology
[0002] As the complexity of wireless network architecture increases, encompassing multiple domains including wireless, access, transmission, and environmental factors, fault monitoring and root cause analysis have become core pain points in operations and maintenance. Traditional wireless network fault root cause analysis primarily relies on human experience or static knowledge graph analysis.
[0003] However, traditional methods for locating the root cause of wireless network faults have significant limitations in accuracy. On one hand, analysis based on manual methods relies heavily on the individual skills and experience of maintenance experts. The skill levels of different experts vary, and human judgment is easily influenced by subjective factors, making it difficult to guarantee the stability and accuracy of the location results. On the other hand, while static knowledge graphs can be used for analysis, they suffer from inaccurate or outdated information, resulting in low accuracy in locating the root cause of faults. Summary of the Invention
[0004] This invention provides a method and apparatus for locating the root cause of wireless network faults based on dynamic knowledge graphs, in order to solve the problem of low location accuracy in existing wireless network fault root cause location methods.
[0005] This invention provides a method for locating the root cause of wireless network faults based on dynamic knowledge graphs, comprising: Obtain alarm descriptions and the current knowledge graph, which is obtained by updating nodes and / or connecting edges of the historical knowledge graph; the connecting edges include alarm connecting edges; the alarm connecting edges are obtained by mining association rules between historical alarm data; Retrieve inference background information that matches the alarm description from the operation and maintenance knowledge base; The reasoning background information and the alarm description are input into the large language model, and the root cause localization result of the alarm description is generated based on the large language model and the current knowledge graph.
[0006] According to the present invention, a method for locating the root cause of wireless network faults based on dynamic knowledge graphs, wherein retrieving reasoning background information matching the alarm description from an operation and maintenance knowledge base includes: Extract the retrieval vector of the alarm description, wherein the retrieval vector includes at least one of keyword vector, complete semantic vector and sparse vector; Initial relevant information matching the retrieval vector is retrieved from the operation and maintenance knowledge base, and the reasoning background information is obtained by filtering from the initial relevant information. The operation and maintenance knowledge base is built based on a vector database.
[0007] According to the present invention, a method for locating the root cause of wireless network faults based on dynamic knowledge graphs includes the following steps for updating the alarm connection edge: Calculate the contribution ratio of each relevant alarm event in the historical alarm data to the fault event, and determine the target associated node of the fault event based on the contribution ratio; the occurrence time of each relevant alarm event is earlier than the occurrence time of the fault event. Aggregate alarm event sets within a preset time window from the historical alarm data, perform causal relationship verification on the alarm events in the alarm event set, and obtain causal relationship nodes; The alarm connection edges are updated based on the connection edges between the fault event and the target associated node, and the connection edges between the causal associated nodes.
[0008] According to the present invention, a method for locating the root cause of wireless network faults based on dynamic knowledge graphs is provided, wherein the attributes of the alarm connection edge include the association duration; and the causal association nodes include primary alarm nodes and secondary alarm nodes. The first association duration between the target associated node and the fault event is determined based on the time interval between the occurrence of the target associated node and the fault event; The second association duration between the causal nodes is determined based on the occurrence time interval between the primary alarm node and the secondary alarm node.
[0009] According to the present invention, a method for locating the root cause of wireless network faults based on dynamic knowledge graphs, in the first update, the historical knowledge graph is the initial knowledge graph, and the construction steps of the initial knowledge graph include: Collect multi-dimensional network data; the multi-dimensional network data includes network topology data of network devices and alarm propagation relationships of alarm data; Using the network devices and the alarm data as nodes, topology connection edges are constructed based on the network topology data, and alarm connection edges are constructed based on the alarm propagation relationship; the network devices include transmission network elements, wireless network elements, and environmental control rooms; The initial knowledge graph is constructed based on the nodes and the connecting edges between them.
[0010] According to the present invention, a method for locating the root cause of wireless network faults based on dynamic knowledge graphs is provided, wherein the multi-dimensional network data further includes: device configuration data, performance data, operation and maintenance knowledge, and spatiotemporal information; The device configuration data and the performance data are used to determine the node attributes of the network device nodes; The operational knowledge is used to determine the node attributes of the alarm node; The spatiotemporal information is used to determine the association duration of the alarm connection edge.
[0011] According to the present invention, a method for locating the root cause of wireless network faults based on dynamic knowledge graphs includes the following steps in constructing the operation and maintenance knowledge base: Obtain initial operation and maintenance corpus; the initial operation and maintenance corpus includes resource models, business entities, and operation and maintenance knowledge; The initial operation and maintenance corpus is sliced according to semantics, and the semantic vector of each slice is extracted; The operation and maintenance knowledge base is constructed based on the semantic vectors of each slice.
[0012] The present invention also provides a wireless network fault root cause localization device based on dynamic knowledge graph, comprising: The acquisition unit acquires an alarm description and a current knowledge graph, wherein the current knowledge graph is obtained by updating nodes and / or connecting edges of a historical knowledge graph; the connecting edges include alarm connecting edges; the alarm connecting edges are obtained by mining association rules between historical alarm data; The retrieval unit retrieves reasoning background information that matches the alarm description from the operation and maintenance knowledge base; The fusion reasoning unit inputs the reasoning background information and the alarm description into the large language model, and generates the fault root cause localization result of the alarm description based on the large language model combined with the current knowledge graph.
[0013] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the wireless network fault root cause localization method based on dynamic knowledge graph as described above.
[0014] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the wireless network fault root cause localization method based on dynamic knowledge graph as described above.
[0015] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the wireless network fault root cause localization method based on dynamic knowledge graph as described above.
[0016] The present invention provides a method and apparatus for root cause localization of wireless network faults based on dynamic knowledge graphs. First, it utilizes historical alarm data mining to update alarm connection edges to adapt to dynamic network changes. Second, it combines enhanced retrieval from an operation and maintenance knowledge base, enabling fault reasoning to have strong domain knowledge support. Finally, it uses a large model to fuse knowledge graphs and reasoning background information for reasoning, thus streamlining the end-to-end process from alarm perception to root cause output, automating fault diagnosis, and providing more interpretable and accurate localization results, thereby effectively improving the operation and maintenance efficiency of wireless networks. Attached Figure Description
[0017] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0018] Figure 1 This is one of the flowcharts of the wireless network fault root cause localization method based on dynamic knowledge graph provided by the present invention; Figure 2 This is a schematic diagram of the method for retrieving reasoning background information provided by the present invention; Figure 3 This is a flowchart illustrating the parallel mining method for dual-channel association rules provided by the present invention; Figure 4 This is a schematic diagram of the current knowledge graph provided by the present invention; Figure 5 This is the second flowchart of the wireless network fault root cause localization method based on dynamic knowledge graph provided by the present invention. Figure 6 This is a schematic diagram illustrating the construction process of the knowledge graph and operation and maintenance knowledge base provided by this invention; Figure 7 This is a schematic diagram of the structure of the wireless network fault root cause localization device based on dynamic knowledge graph provided by the present invention. Figure 8 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0020] It should be noted that traditional methods rely on manual fault location. Due to the complex fault propagation paths in wireless, access, transmission, and environmental domains, traditional methods depend on the experience of operations and maintenance experts, which is time-consuming and labor-intensive, with an average fault location time exceeding one hour. Furthermore, these methods are prone to misjudgment due to differences in experience and incomplete data collection. Additionally, methods based on static knowledge graphs suffer from inaccurate or outdated data such as network element topology and port-related resource data, leading to biases in the correlation analysis between alarms and faults and making it impossible to accurately locate the root cause.
[0021] To address the aforementioned problems, this invention provides a method for locating the root cause of wireless network faults based on dynamic knowledge graphs, thereby achieving more accurate, efficient, and automated fault root cause location. Figure 1 This is one of the flowcharts illustrating the wireless network fault root cause localization method based on dynamic knowledge graphs provided by this invention, such as... Figure 1 As shown, the method includes: Step 110: Obtain the alarm description and the current knowledge graph.
[0022] Here, alarm descriptions refer to textual information received in real time by the fault management system that reflects abnormal network conditions, such as specific fault descriptions like wireless network element outages, fiber optic cable interruptions, or high port error rates. Additionally, the current knowledge graph here refers to a graph structure that reflects the actual network status at the current moment, based on historical knowledge graphs and updated in real time with the latest network resource changes and newly mined rules.
[0023] Specifically, the system first receives fault alarm information reported by the monitoring system in real time and extracts the text description as the alarm description. Simultaneously, it acquires the dynamically updated knowledge graph maintained by the system, using the latest knowledge graph as the current knowledge graph. The current knowledge graph is obtained by updating nodes and / or edges of historical knowledge graphs; the edges include alarm edges; and the alarm edges are obtained by mining association rules between historical alarm data.
[0024] Here, the historical knowledge graph refers to a graph constructed based on the network state at past moments, containing the basic attributes and connectivity relationships of network devices. Historical alarm data refers to the massive amount of alarm records accumulated in the network over a past period. Alarm connection edges refer to the edges in the knowledge graph that connect different network elements or alarm nodes; specifically, they refer to the propagation relationships or causal connections between alarms discovered through analysis of historical data.
[0025] In detail, to ensure the timeliness of the knowledge graph, it needs to be dynamically updated. Dynamic updates are triggered when network resources are updated, new rules are discovered, or by maintenance personnel. This iteration is achieved primarily through two dimensions: firstly, updating nodes in the graph based on actual changes in network resources, such as adding base stations or adjusting ports; and secondly, analyzing massive amounts of historical alarm data using association rule mining algorithms to extract implicit association rules between different alarms, such as primary and secondary alarm relationships and alarm propagation delays, and transforming these rules into alarm connection edges in the knowledge graph. Thus, through this dynamic updating method, the discovered new rules and resources are integrated into the historical knowledge graph, generating a current knowledge graph consistent with the current network state, providing an accurate data foundation for subsequent fault reasoning.
[0026] It should be noted that by constructing and dynamically updating the knowledge graph, the problem of traditional static knowledge graphs being unable to adapt to frequent changes in wireless network topology is solved. In particular, by mining historical alarm data to generate alarm connection edges, it is possible to discover hidden fault propagation relationships across domains, making up for the limitations of relying solely on manual experience to configure rules, and ensuring that the analytical evidence on which fault location depends is real-time and complete.
[0027] Step 120: Retrieve inference background information that matches the alarm description from the operation and maintenance knowledge base.
[0028] Here, the operations and maintenance knowledge base refers to a database storing professional knowledge in this field. Its content includes unstructured or semi-structured data such as equipment manufacturer's operations and maintenance manuals, communication industry standards, historical fault handling cases, and expert experience summaries. Here, the inference background information refers to knowledge fragments highly relevant to the specific alarm that have occurred, selected from the aforementioned vast knowledge base. Examples include standard troubleshooting steps for a certain type of alarm, explanations of common causes, or similar historical solutions.
[0029] Specifically, the obtained alarm descriptions are used as search criteria to perform searches and matches within a pre-built operations and maintenance knowledge base. To improve matching accuracy, semantic understanding techniques are typically employed to calculate the semantic similarity between the alarm descriptions and various document fragments in the knowledge base. Alternatively, keyword matching can be used to precisely extract the most relevant entries to the current fault from a massive amount of documents. Understandably, these matched knowledge entries constitute the reasoning background information, providing the necessary domain-specific professional knowledge context for subsequent large-scale model reasoning, and avoiding the illusion problem that may occur in general models lacking professional background.
[0030] It should be noted that using the reasoning background information obtained through retrieval as an external knowledge source effectively supplements the specific domain operation and maintenance knowledge missing when relying solely on model parameters. This allows the fault analysis process to not only rely on general logical reasoning ability but also on solid industry standards and expert experience, thereby significantly improving the professionalism and credibility of the analysis conclusions.
[0031] Step 130: Input the reasoning background information and the alarm description into the large language model, and generate the fault root cause localization result of the alarm description based on the large language model combined with the current knowledge graph.
[0032] Here, the root cause localization result refers to the conclusion about the root cause of the fault after analysis. It usually includes the specific network element that caused the fault, the fault type, and the logical chain of reasoning.
[0033] Specifically, firstly, the acquired alarm descriptions and retrieved reasoning background information can be concatenated or formatted to construct input prompts for the large language model. Simultaneously, leveraging the graph understanding capabilities of the large language model or through graph computing interfaces, the current knowledge graph is introduced into the reasoning process. After receiving this multimodal information, the large language model performs semantic analysis on the alarm descriptions by combining them with background knowledge, and then performs logical deduction along the topological paths and alarm connection edges in the current knowledge graph to investigate possible fault propagation paths. Ultimately, it identifies the root cause node that triggered the alarm and generates natural language text containing the root cause conclusion and the reasoning process.
[0034] It should be noted that traditional knowledge graphs are mostly static, storing only fixed topologies and rules, and cannot dynamically adapt to network resource updates. Furthermore, using large models alone lacks network domain expertise, and the reasoning conclusions lack interpretability. Therefore, by integrating structured graph knowledge with unstructured operational knowledge, the advantages of large language models in natural language processing and logical reasoning are fully utilized. This achieves a comprehensive judgment process similar to that of human experts, not only quickly locating the root causes of complex cross-domain faults but also providing clear explanations of the reasoning process. This enables intelligent and automated fault handling, significantly reducing reliance on human experience.
[0035] The wireless network fault root cause localization method based on dynamic knowledge graph provided in this embodiment first utilizes historical alarm data mining to update alarm connection edges to adapt to dynamic network changes; secondly, it combines enhanced retrieval from the operation and maintenance knowledge base to provide fault reasoning with strong domain knowledge support; finally, it uses a large model to fuse knowledge graph and reasoning background information for reasoning, thus streamlining the end-to-end process from alarm perception to root cause output, automating fault diagnosis, providing more interpretable and accurate localization results, and effectively improving the operation and maintenance efficiency of wireless networks.
[0036] To further improve the accuracy of the root cause localization results, based on any of the above embodiments, step 120 includes: Extract the retrieval vector of the alarm description; Initial relevant information matching the retrieval vector is retrieved from the operation and maintenance knowledge base, and the reasoning background information is obtained by filtering from the initial relevant information. The operation and maintenance knowledge base is built based on a vector database.
[0037] Here, a retrieval vector refers to the numerical form that converts the alarm description into a computer-readable mathematical expression for comparison. Retrieval vectors include at least one of keyword vectors, complete semantic vectors, and sparse vectors. Keyword vectors are discretized representations that focus on specific entities, proper nouns, or alarm codes within the text, aiming to capture key identifiers. Complete semantic vectors are high-dimensional, dense vectors mapped to the entire text using a deep learning model; they emphasize expressing the overall meaning and context of the text, rather than simply matching literal symbols. Sparse vectors, on the other hand, are vector representations with extremely high dimensionality but very few non-zero elements. In the operations and maintenance field, they are often combined with domain-specific weights to emphasize obscure words or specific terms that are unimportant in general contexts but highly distinctive in the professional domain.
[0038] Here, "initial relevant information" refers to a preliminary set of candidate documents retrieved from the database that are relatively close in vector space distance, before undergoing fine-grained re-sorting or denoising processing. Furthermore, "operational knowledge base" specifically refers to a storage system built on vector database technology. It not only stores the text of knowledge content, but more importantly, it stores the vector data of this content after embedding transformation to support rapid high-dimensional similarity search.
[0039] Specifically, firstly, multi-dimensional feature extraction is performed on the acquired alarm descriptions. For example, natural language processing techniques can be used to segment and extract key information from the alarm descriptions, identifying core words such as alarm titles and network element names, and constructing keyword vectors. Simultaneously, a pre-trained large language model or a specialized embedding model is used to transform the alarm descriptions into dense, complete semantic vectors to capture their deep semantics. Furthermore, a terminology dictionary in the wireless network domain can be combined to calculate the domain weights of each word in the alarm descriptions, generating sparse vectors.
[0040] Next, these three types of vectors can be used as query conditions to perform parallel or combined searches in the operation and maintenance knowledge base built on a vector database. For example, keyword vectors can be used to match tags or indexes in the database, complete semantic vectors can be used to find semantically similar documents in a dense space, and sparse vectors can be used to find records containing high-weight domain terms in a sparse index. The results returned by these three search methods are aggregated to form the initial relevant information.
[0041] Finally, these initial relevant information can be further filtered, for example by deduplication, reordering, or setting a similarity threshold to remove noisy data with low relevance. The high-quality content that is ultimately retained is confirmed as the background information for inference.
[0042] In one embodiment, Figure 2 This is a schematic diagram of the method for retrieving reasoning background information provided by the present invention, such as... Figure 2 As shown in the flowchart, the method provides a detailed illustration of the complete retrieval enhancement generation process, from problem input (alarm description) to final answer generation (fault root cause localization result).
[0043] First, it can receive "questions" input by users and feed them into the "Embedding model" for processing. The model performs multi-dimensional feature extraction and transformation on the input questions, generating "keywords" for precise matching, dense "vectors" for semantic representation, and "sparse vectors" for sparse retrieval.
[0044] Next, these three generated feature representations can be used to initiate multi-path parallel retrieval within the "Wireless AI Native Database." Specifically, keyword matching in the "full-text index" can be used, dense vectors can be used for semantic similarity matching in the "vector index," sparse vectors can be used for weighted matching in the "sparse vector index," and a "graph index" can be combined to obtain structured relational knowledge. Then, the candidate information retrieved from these different-dimensional indexes is aggregated and input into the "Tensor Reranker" for unified scoring and reordering to filter out the high-quality reasoning background information most relevant to the question.
[0045] Finally, the reordered and filtered reasoning background information is used as context, and input together with the original question (alarm description) into the "LLM" (Large Language Model). Through deep reasoning by combining the input professional knowledge and question, the LLM ultimately outputs "citation generation" containing specific "answers" and relevant evidence, thereby completing the intelligent localization and explanation of the root cause of the fault.
[0046] The method provided in this invention significantly improves the recall and accuracy of knowledge retrieval by integrating keywords, complete semantics, and sparse vectors into a hybrid retrieval mechanism. The complete semantic vector addresses the problem of traditional keyword matching failing to understand synonyms or implicit semantics, such as associating "station outage" with "cell unavailable." Keyword vectors and sparse vectors effectively compensate for the semantic drift problem that may occur with dense vectors when handling precise matching of specific alarm error codes or device models. This multi-path recall strategy ensures that the inference background information input to the large model possesses broad semantic relevance and accurately covers key domain technical details, thus providing high-quality knowledge support for subsequent fault root cause localization and improving the accuracy of fault root cause localization.
[0047] It should be noted that existing empirical rules have issues such as incomplete feature-based alarm analysis, failing to cover alarm propagation relationships in complex scenarios. To address this issue, based on any of the above embodiments, the update steps for alarm connection edges include: Calculate the contribution ratio of each relevant alarm event in the historical alarm data to the fault event, and determine the target associated node of the fault event based on the contribution ratio; the occurrence time of each relevant alarm event is earlier than the occurrence time of the fault event. Aggregate alarm event sets within a preset time window from the historical alarm data, perform causal relationship verification on the alarm events in the alarm event set, and obtain causal relationship nodes; The alarm connection edges are updated based on the connection edges between the fault event and the target associated node, and the connection edges between the causal associated nodes.
[0048] Here, relevant alarm events refer to specific alarm records in the historical alarm dataset that occurred earlier than the target fault event. These can be used as feature inputs to analyze the potential relationship between the alarm event and the fault. Fault events refer to specific network anomalies that are the target of analysis, such as fiber optic cable breaks or network element disconnections. These can be understood as alarm events, i.e., alarm nodes. Contribution percentage refers to the calculated importance weight of a certain type of relevant alarm event in determining whether a specific fault event has occurred. This weight reflects the strong statistical correlation between the two. Therefore, the target associated node here refers to alarm type nodes selected based on contribution percentage that have a significant indicative role in fault location.
[0049] Furthermore, the time window here refers to a specific time period divided in order to capture the temporal relationship between events when processing continuous alarm data streams. Here, the alarm event set refers to the collection of all alarm records falling within the same time window. Therefore, causal relationship nodes refer to alarm node pairs confirmed to have a fault propagation relationship after sequence mining and verification.
[0050] Specifically, a dual-channel parallel mining mechanism can be used to update the alarm connection edges in the knowledge graph. First, in the first channel, a single fault event can be used as a trigger point to backtrack historical alarm data and select relevant alarm events from a period prior to the fault. For example, gradient boosting tree algorithms such as LightGBM can be used for regression analysis to calculate the contribution ratio of each relevant alarm event to the fault event. That is, each relevant alarm event is used as a feature, and the fault event is used as a label, calculating the contribution ratio of the features to the label. Then, based on a preset contribution ratio threshold, alarm types with high contribution ratios can be identified as target associated nodes, and their connection relationships with the fault event can be established.
[0051] Meanwhile, in the second channel, historical alarm data can be streamed, with preset time windows such as 15 minutes and sliding steps set to aggregate alarms falling within the window into alarm event sets. Then, sequence mining algorithms such as PrefixSpan or FP-Growth can be used to extract frequent itemsets, and causal relationship verification can be performed in conjunction with domain knowledge to identify causal association nodes with temporal propagation characteristics.
[0052] Finally, perform data consistency verification. For example, the intersection of the relationship between the fault events mined by the first channel and the target associated nodes, and the relationship between the causal associated nodes mined by the second channel can be taken. The connection relationships mined by both channels can be transformed into alarm connection edges in the knowledge graph to update the graph structure.
[0053] In one embodiment, Figure 3 This is a flowchart illustrating the parallel mining method for dual-channel association rules provided by the present invention, as shown below. Figure 3 As shown, the process mainly consists of two parallel mining channels, a result fusion step, and a final update confirmation step.
[0054] Specifically, the left side of the process includes two parallel mining tasks: the upper channel performs "Association Rule Mining Based on LightGBM Regression," which focuses on analyzing the importance of features in the model and filtering key association rules based on feature proportions. The lower channel performs "Frequent Itemset Mining Based on Causal Relationship Spatiotemporal Sequences," which focuses on analyzing the time series and causal logic of the data and filtering the mined frequent itemsets based on parameters such as confidence and support. The preliminary rules obtained from the mining of these two channels are then converged in the middle "Mining Rule Result Fusion" step. Here, rules from different algorithm sources are integrated, for example, the intersection of association rules obtained from the two channels is taken as the final fused rule result. Finally, the fused rule result enters the "Manual Confirmation Triggers Knowledge Graph Update" step, that is, after manual review and confirmation, the system is officially triggered to update the knowledge graph, injecting the newly discovered fault association knowledge into the graph.
[0055] It should be noted that the alarm association rules are automatically completed through a dual-channel parallel mining mechanism, and the knowledge graph supports resource updates and the accumulation of human experience, adapting to dynamic changes in the network.
[0056] The method provided in this invention constructs a complementary rule mining system by combining feature importance analysis based on regression algorithms and spatiotemporal correlation analysis based on sequence mining. The former excels at discovering statistically strong correlations, enabling rapid location of key alarm signals leading to faults. The latter excels at capturing fault propagation chains with temporal characteristics, reconstructing complex fault evolution processes. Understandably, this dual-channel mechanism effectively solves the problems of incomplete mining and numerous false associations associated with single algorithms, significantly enriching the coverage and accuracy of alarm connection edges in the knowledge graph, and providing more complete rule support for subsequent root cause reasoning.
[0057] Based on any of the above embodiments, the attributes of the alarm connection edge include the association duration; the causal association node includes the primary alarm node and the secondary alarm node; The first association duration between the target associated node and the fault event is determined based on the time interval between the occurrence of the target associated node and the fault event; The second association duration between the causal nodes is determined based on the occurrence time interval between the primary alarm node and the secondary alarm node.
[0058] Here, the association duration quantifies the time interval between two associated nodes during fault propagation or concurrency, representing the time validity constraint of fault inference. Here, primary and secondary alarm nodes are further role definitions for causally associated node pairs. In a directed alarm propagation edge, the node located upstream of the propagation path and occurring earlier is the primary alarm node, and the node located downstream and triggered by the former is the secondary alarm node. Here, the first association duration specifically refers to the time difference between highly correlated alarms and faults mined based on statistical correlation; additionally, the second association duration specifically refers to the time difference between primary and secondary alarms mined based on time series data.
[0059] Specifically, while establishing alarm connection edges, the association duration attribute is calculated and assigned to them. For target associated nodes identified through regression analysis, the time difference between the alarm occurrence time and the fault event occurrence time corresponding to the target associated node in historical alarm data can be statistically analyzed as the first association duration. This duration attribute is used to describe the typical lead time for the alarm to predict the occurrence of the fault.
[0060] Furthermore, for causal association nodes identified through sequence mining, the time interval between the occurrence of the primary alarm node and the occurrence of the secondary alarm node can be calculated during the mining of frequent itemsets and set as the second association duration. This duration attribute is used to describe the rate at which the fault propagates between network elements or layers. Ultimately, this association duration data is stored as edge attributes in the knowledge graph. For example, the edge pointing from "BBU optical module alarm" to "R_LOS alarm" carries the association duration "5 minutes".
[0061] The method provided in this invention assigns a time dimension attribute to the connections in a knowledge graph. By quantifying the association duration, subsequent large models, when using the current knowledge graph for reasoning, can not only determine the cause of the fault but also, based on whether the time interval meets expectations, determine whether the alarm is truly the root cause of the fault. Therefore, this alarm propagation relationship with a time window attribute effectively filters out interfering alarms that, although matching in type, have excessively large time spans, thereby significantly improving the anti-interference capability and accuracy of fault root cause localization in complex network environments.
[0062] Based on any of the above embodiments, during the first update, the historical knowledge graph is an initial knowledge graph, and the steps for constructing the initial knowledge graph include: Collect multi-dimensional network data; the multi-dimensional network data includes network topology data of network devices and alarm propagation relationships of alarm data; Using the network devices and the alarm data as nodes, topology connection edges are constructed based on the network topology data, and alarm connection edges are constructed based on the alarm propagation relationship; the network devices include transmission network elements, wireless network elements, and environmental control rooms; The initial knowledge graph is constructed based on the nodes and the connecting edges between them.
[0063] Here, the initial knowledge graph refers to the baseline graph reflecting the network infrastructure and common fault logic constructed in the initial stage, before dynamic updates and rule mining. Multi-dimensional network data refers to the raw materials used to construct the graph, covering physical layer connection information and logical layer alarm correlation information. Specifically, network topology data refers to data describing the connection relationships between various physical entities in the network, such as fiber optic connections, network port connections, and device affiliation. Alarm propagation relationships refer to the causal transmission chains between different types of alarms, determined based on expert experience or pre-defined rules.
[0064] In addition, here, transmission network elements refer to network devices responsible for data carrying and transmission, such as PTN and OTN equipment; wireless network elements refer to devices responsible for wireless signal coverage and access, such as base stations, BBUs, and RRUs; and environmental protection rooms refer to infrastructure nodes that provide power and environmental protection. Here, topology connection edges and alarm connection edges are two different types of edges in the graph representing physical connections and logical effects, respectively.
[0065] Specifically, firstly, a full set of multi-dimensional network data is collected from the operator's fault management system or integrated resource system through a standardized interface. Next, based on a predefined graph pattern, the collected entities are mapped to graph nodes. More specifically, 2G / 4G / 5G base stations can be mapped to wireless network element nodes, optical transmission equipment to transmission network element nodes, communication hubs or access equipment rooms to environmental monitoring room nodes, and the definitions of various alarms can be mapped to alarm nodes.
[0066] Subsequently, topological connection edges can be constructed based on network topology data. For example, physical connections between transmission network elements and wireless network elements can be established based on service activation circuit information, and the attribution relationships between equipment and equipment rooms can be established based on the relationships between equipment and equipment rooms in the integrated resource system. Simultaneously, initial alarm connection edges can be constructed based on telecommunications industry-specific operation and maintenance manuals and expert rules. For example, connecting the "power outage" alarm node with the "base station outage" alarm node indicates that abnormal power supply will cause base station service interruption. Ultimately, these nodes and edges together form an initial knowledge graph with cross-domain characteristics.
[0067] In one embodiment, the constructed knowledge graph can be visualized, for example, by using different legends according to node type. Figure 4 This is a schematic diagram of the current knowledge graph provided by the present invention, such as... Figure 4 As shown, node types include wireless network elements, transmission network elements, environmental monitoring rooms, and alarms. Topology connections are represented by straight lines, alarm relationships (alarm connections) are represented by unidirectional arrows, transmission network elements are represented by circles, wireless network elements by triangles, environmental monitoring rooms by cylinders, and alarms by polygons. Figure 4 As shown, alarm A and alarm B are connected to the same transmission network element N1, and are linked by an arrow, indicating that the alarm propagation relationship between alarm A and alarm B is intra-network element propagation. Alarm A and alarm F are connected to transmission network elements N1 and N5 respectively, and a connection is established between transmission network elements N1 and N5, indicating that the alarm propagation relationship between alarm A and alarm F is cross-network element propagation.
[0068] In addition, the knowledge graph also includes interactive features, which highlight the current node and its associated edges when a node selection operation is received.
[0069] The method provided in this invention breaks down the siloed data management barriers between different disciplines in traditional operation and maintenance systems by constructing an initial knowledge graph covering three major domains: transmission, wireless, and environmental. It supports the mining and reasoning of cross-domain fault propagation relationships across wireless, access, transmission, and environmental domains, eliminating reliance on expert experience and reducing fault location time by more than 50%. Furthermore, by integrating physical topology and logical alarm associations into the same graph structure, subsequent fault location can not only analyze problems with single devices but also trace cross-domain sources along physical connections and logical dependencies, laying a solid data foundation for resolving complex cross-level and cross-disciplinary network faults.
[0070] Based on any of the above embodiments, multi-dimensional network data also includes: device configuration data, performance data, operation and maintenance knowledge, and spatiotemporal information; The device configuration data and the performance data are used to determine the node attributes of the network device nodes; The operational knowledge is used to determine the node attributes of the alarm node; The spatiotemporal information is used to determine the association duration of the alarm connection edge.
[0071] Here, device configuration data refers to data describing the static characteristics of network elements, such as the maximum capacity of wireless base stations, the upper and lower limits of transmission network element port rates, and other configuration data. Performance data refers to dynamic indicators reflecting the operating status of network elements, such as port optical power, bit error rate, and CPU utilization. Operational knowledge here specifically refers to the standardized definition of alarms, including standard naming of alarm titles and alarm level definitions. Additionally, spatiotemporal information here refers to the geographical coordinates of the fault and alarm occurrences, as well as precise timestamp data.
[0072] Specifically, after constructing the skeleton of nodes and edges, their attribute information is further enriched. For network device nodes, device configuration data can be parsed to write the device's unique identifier (ID), name, type, and manufacturer information into the node attributes. At the same time, performance data is accessed, and status information such as real-time optical power or traffic thresholds of key ports are dynamically attached to the nodes.
[0073] In addition, for alarm nodes, the standard name, explanation, and handling suggestions of the alarm can be written into the node attributes according to the standard specifications in operation and maintenance knowledge. For alarm connection edges, the collected historical spatiotemporal information can be used to count the typical time difference between the occurrence of an upstream alarm and the occurrence of a downstream alarm in a specific geographical area, such as the same data center or the same optical cable route, and this time difference can be assigned as the association duration attribute to the corresponding alarm connection edge.
[0074] It should be noted that by introducing equipment configuration, performance, operation and maintenance knowledge, and spatiotemporal information, the semantic connotation of the knowledge graph is greatly enriched. Among them, equipment and performance attributes enable the large model to consider individual differences and equipment status during inference, such as low optical power but not interrupted; standardized alarm attributes eliminate ambiguity in alarm descriptions from different manufacturers; and the association duration determined based on spatiotemporal information introduces spatiotemporal constraints to the graph inference, enabling fault location to exclude false alarms that are topologically connected but physically too far apart or whose temporal logic is inconsistent, thereby significantly improving the precision and robustness of root cause localization.
[0075] Based on any of the above embodiments, the steps for constructing an operations and maintenance knowledge base include: Obtain initial operation and maintenance corpus; the initial operation and maintenance corpus includes resource models, business entities, historical cases, and operation and maintenance knowledge; The initial operation and maintenance corpus is sliced according to semantics, and the semantic vector of each slice is extracted; The operation and maintenance knowledge base is constructed based on the semantic vectors of each slice.
[0076] Here, the initial operations and maintenance (O&M) corpus refers to the raw data set used to populate the knowledge base, which can be obtained by integrating resource models, business entities, and O&M knowledge. The resource model refers to the abstract definition and metadata description of various hardware devices, logical resources, and their interrelationships in the network. Business entities refer to detailed descriptions of specific network object instances or business events, such as the meaning of specific alarm codes or parameters of specific device models. O&M knowledge here specifically refers to unstructured or semi-structured documentation, covering industry standards, O&M manuals, operating procedures, and historical case reviews.
[0077] Specifically, the first step is to comprehensively collect and integrate data. For example, initial operation and maintenance corpora can be obtained from fault management systems, document servers, and expert experience bases. This includes not only resource models and business entity data such as the hierarchical definitions of base stations and cells, but also a large amount of unstructured operation and maintenance knowledge, such as policy standards, operation and maintenance manuals, operation manuals, fault cases, historical reports, etc.
[0078] Next, natural language processing techniques can be used to clean and semantically segment these corpora. To maintain the contextual coherence of knowledge, long documents are typically segmented into appropriately sized text segments, such as 256 or 512 tokens, based on paragraph or chapter titles or semantic pauses. Subsequently, pre-trained embedding models, such as BERT and its variants, can be used to transform each text segment into a fixed-dimensional semantic vector. Finally, these semantic vectors and their corresponding original text content can be stored in a vector database, and an efficient index structure, such as the HNSW index, can be built to complete the construction of the operations and maintenance knowledge base, enabling rapid matching of operations and maintenance knowledge.
[0079] The method provided in this invention uses semantic slicing and vectorization construction techniques to unify resource models, business entities, and operational knowledge into high-dimensional semantic vectors. This not only overcomes the limitations of traditional keyword search in handling synonyms and polysemous words, but also ensures the contextual integrity of search results through reasonable slicing granularity. This provides accurate and rich knowledge background for subsequent fault reasoning based on search enhancement, thereby significantly improving the professionalism and accuracy of fault localization.
[0080] Based on any of the above embodiments Figure 5 This is the second flowchart of the wireless network fault root cause localization method based on dynamic knowledge graph provided by the present invention, as follows: Figure 5As shown, this method comprises four core stages: rule mining, knowledge graph construction, model inference, and result display. First, in the underlying data processing stage, a "dual-channel parallel rule mining mechanism" is used to mine the correlations between alarms from historical and real-time data using machine learning algorithms. The newly mined rules, as "rule supplementation and update," are then fed into the "Dynamic Knowledge Graph Construction for Wireless Networks" module. This module combines network topology data with the newly mined rules to construct and refresh the connection relationships between nodes in real time, forming a dynamic knowledge graph reflecting the current network state.
[0081] Subsequently, the constructed dynamic knowledge graph provides "graph reasoning support" to the upper layer, and the data flow enters the "fault reasoning framework based on retrieval-enhanced generation (RAG)". In this framework, the topological paths and alarm propagation chains in the knowledge graph are combined with the retrieved operation and maintenance knowledge, and a large language model is used to analyze and infer fault scenarios. For example, if the input parameter is "event ID", it automatically queries the fault database for related alarms and topological data to trigger the reasoning process.
[0082] Finally, the conclusions obtained from model analysis are transmitted to the top-level "Fault Root Cause Location and Visualization" module through the "Inference Result Presentation" stage. This module presents the root cause nodes, reasoning paths, and related evidence to users in a visual format, completing the end-to-end fault location process. For example, fault events are presented in list format, including event ID, name (such as "Transmission Fiber Breakage Fault Event"), event level, occurrence time, network element name, specialty, and city; filtering by specialty and city is supported.
[0083] It should be noted that the model analysis details page can also display the inference model conclusions based on the output of the large model on the left, namely the fault root cause localization results provided by this embodiment of the invention, and the rule model conclusions based on the output of the traditional rule engine, while displaying the knowledge graph related to the current event on the right, facilitating cross-validation by operations and maintenance personnel. In addition, accuracy statistics can be performed, such as presenting the fault root cause localization F1 accuracy in the form of a line chart or bar chart, supporting filtering by time period and professional dimension. Thus, end-to-end fully automated processes are achieved from fault occurrence to rule mining, then to graph update, then to root cause inference, and finally to result display. Furthermore, the inference process has traceable capabilities for knowledge graph exploration and display, and feature analysis step presentation, enhancing operational trust.
[0084] This invention provides a method for root cause localization of wireless network faults based on the fusion of dynamic knowledge graphs and large models. The method includes: constructing a dynamic knowledge graph of the wireless network that integrates network topology, alarms, performance, association rules, and operational knowledge. Its nodes include wireless network elements, transmission network elements, alarm instances, etc., and its edges include topological relationships and alarm propagation relationships with time window attributes. A parallel mining mechanism based on machine learning and sequence mining is used to automatically mine fault association rules to update the knowledge graph. An operational knowledge base is constructed, and multi-dimensional matching and reasoning are performed by fusing the knowledge graph with a large model to output the root cause of the fault and the reasoning process. The reasoning process here is, for example, "Transmission network element - Transmission LOS fault caused by external power supply failure," and the reasoning process includes knowledge graph exploration and multi-feature association analysis.
[0085] Finally, the fault events are visualized. This solves the problems of low fault location accuracy, weak cross-domain analysis capability, high reliance on manual labor in the diagnostic analysis process, and the disconnect between knowledge and models in existing technologies, and realizes intelligent and automated fault handling.
[0086] Based on any of the above embodiments Figure 6 This is a schematic diagram illustrating the construction process of the knowledge graph and operation and maintenance knowledge base provided by this invention, such as... Figure 6 As shown: First, the first branch focuses on building the skeleton of the knowledge graph. It takes "network topology" data as input, covering the physical and logical connections of 2G / 4G / 5G wireless networks, as well as access, aggregation, backbone transmission networks, and environmental monitoring equipment in data centers; and "association rules," including alarm and fault association logic within and across disciplines. This data is processed by the "topology data analysis model" and the "NetworkX graph tool" is used to generate the graph, ultimately outputting a structured "knowledge graph," which provides a graphical representation of the entire network topology and association rules.
[0087] Secondly, the second branch focuses on the vectorization of entity information. Input data includes "resource entities" (such as specific objects like wireless base stations, transmission equipment, data centers, and environmental facilities) and "business entities" (involving dynamic data such as resources, alarms, performance, configuration, and logs). After being parsed by the "entity analysis model," this entity data is "segmented," that is, divided into fine-grained information units. Subsequently, this segmented information is input into the "Embedding model," transformed into a high-dimensional vector representation, thus constructing an operations and maintenance knowledge base, laying the foundation for subsequent semantic-based entity retrieval and analysis.
[0088] Finally, the third branch is responsible for the in-depth processing of unstructured operations and maintenance (O&M) knowledge. This involves collecting "O&M knowledge," primarily including O&M manuals, operation manuals, and historical fault reports. These documents are first structured and parsed using a "document analysis model," and then "segmented" into independent knowledge fragments. These knowledge fragments are then processed through two paths: firstly, a "data extraction model" extracts key information to build a "large model knowledge base" to support knowledge question answering for large language models; secondly, the data is directly input into an "Embedding model" to generate semantic vectors to support knowledge retrieval based on vector similarity.
[0089] It should be noted that these three branches collaborated to complete the process of building a dynamic knowledge graph and knowledge base that can be understood and reasoned about by intelligent algorithms, from raw network data.
[0090] Based on any of the above embodiments Figure 7 This is a schematic diagram of the structure of the wireless network fault root cause localization device based on dynamic knowledge graph provided by the present invention, as shown below. Figure 7 As shown, the device includes: The acquisition unit 710 acquires the alarm description and the current knowledge graph, wherein the current knowledge graph is obtained by updating the nodes and / or connecting edges of the historical knowledge graph; the connecting edges include alarm connecting edges; the alarm connecting edges are obtained by mining the association rules between historical alarm data; The retrieval unit 720 retrieves reasoning background information that matches the alarm description from the operation and maintenance knowledge base; The fusion reasoning unit 730 inputs the reasoning background information and the alarm description into the large language model, and generates the fault root cause localization result of the alarm description based on the large language model combined with the current knowledge graph.
[0091] The wireless network fault root cause localization device based on dynamic knowledge graph provided in this embodiment first utilizes historical alarm data mining to update alarm connection edges to adapt to dynamic network changes; secondly, it combines enhanced retrieval with the operation and maintenance knowledge base to provide fault reasoning with strong domain knowledge support; finally, it uses a large model to fuse knowledge graph and reasoning background information for reasoning, thus opening up the end-to-end process from alarm perception to root cause output, achieving automated fault diagnosis, providing more interpretable and accurate localization results, and effectively improving the operation and maintenance efficiency of wireless networks.
[0092] Based on any of the above embodiments, the retrieval unit is specifically used for: Extract the retrieval vector of the alarm description, wherein the retrieval vector includes at least one of keyword vector, complete semantic vector and sparse vector; Initial relevant information matching the retrieval vector is retrieved from the operation and maintenance knowledge base, and the reasoning background information is obtained by filtering from the initial relevant information. The operation and maintenance knowledge base is built based on a vector database.
[0093] Based on any of the above embodiments, the device further includes a map updating unit, which is specifically used for: Calculate the contribution ratio of each relevant alarm event in the historical alarm data to the fault event, and determine the target associated node of the fault event based on the contribution ratio; the occurrence time of each relevant alarm event is earlier than the occurrence time of the fault event. Aggregate alarm event sets within a preset time window from the historical alarm data, perform causal relationship verification on the alarm events in the alarm event set, and obtain causal relationship nodes; The alarm connection edges are updated based on the connection edges between the fault event and the target associated node, and the connection edges between the causal associated nodes.
[0094] Based on any of the above embodiments, the attributes of the alarm connection edge include the association duration; the causal association node includes the primary alarm node and the secondary alarm node; The first association duration between the target associated node and the fault event is determined based on the time interval between the occurrence of the target associated node and the fault event; The second association duration between the causal nodes is determined based on the occurrence time interval between the primary alarm node and the secondary alarm node.
[0095] Based on any of the above embodiments, during the first update, the historical knowledge graph is an initial knowledge graph. The device further includes a graph construction unit, which is specifically used for: Collect multi-dimensional network data; the multi-dimensional network data includes network topology data of network devices and alarm propagation relationships of alarm data; Using the network devices and the alarm data as nodes, topology connection edges are constructed based on the network topology data, and alarm connection edges are constructed based on the alarm propagation relationship; the network devices include transmission network elements, wireless network elements, and environmental control rooms; The initial knowledge graph is constructed based on the nodes and the connecting edges between them.
[0096] Based on any of the above embodiments, the multi-dimensional network data further includes: device configuration data, performance data, operation and maintenance knowledge, and spatiotemporal information; The device configuration data and the performance data are used to determine the node attributes of the network device nodes; The operational knowledge is used to determine the node attributes of the alarm node; The spatiotemporal information is used to determine the association duration of the alarm connection edge.
[0097] Based on any of the above embodiments, the device further includes a knowledge base construction unit, which is specifically used for: Obtain initial operation and maintenance corpus; the initial operation and maintenance corpus includes resource models, business entities, and operation and maintenance knowledge; The initial operation and maintenance corpus is sliced according to semantics, and the semantic vector of each slice is extracted; The operation and maintenance knowledge base is constructed based on the semantic vectors of each slice.
[0098] Figure 8 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 8 As shown, the electronic device may include a processor 810, a communication interface 820, a memory 830, and a communication bus 840, wherein the processor 810, the communication interface 820, and the memory 830 communicate with each other through the communication bus 840. The processor 810 can call logical instructions in the memory 830 to execute a wireless network fault root cause localization method based on dynamic knowledge graph. The method includes: acquiring an alarm description and a current knowledge graph, wherein the current knowledge graph is obtained by updating nodes and / or connecting edges of a historical knowledge graph; the connecting edges include alarm connecting edges; the alarm connecting edges are obtained based on association rule mining between historical alarm data; retrieving inference background information matching the alarm description from an operation and maintenance knowledge base; inputting the inference background information and the alarm description into a large language model, and generating a fault root cause localization result of the alarm description based on the large language model combined with the current knowledge graph.
[0099] Furthermore, the logical instructions in the aforementioned memory 830 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0100] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the wireless network fault root cause localization method based on dynamic knowledge graph provided by the above methods. The method includes: obtaining an alarm description and a current knowledge graph, wherein the current knowledge graph is obtained by updating nodes and / or connecting edges of a historical knowledge graph; the connecting edges include alarm connecting edges; the alarm connecting edges are obtained based on association rule mining between historical alarm data; retrieving inference background information matching the alarm description from an operation and maintenance knowledge base; inputting the inference background information and the alarm description into a large language model; and generating a fault root cause localization result of the alarm description based on the large language model combined with the current knowledge graph.
[0101] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the wireless network fault root cause localization method based on dynamic knowledge graph provided by the above methods. This method includes: acquiring an alarm description and a current knowledge graph, wherein the current knowledge graph is obtained by updating nodes and / or connecting edges of a historical knowledge graph; the connecting edges include alarm connecting edges; the alarm connecting edges are obtained based on association rule mining between historical alarm data; retrieving inference background information matching the alarm description from an operation and maintenance knowledge base; inputting the inference background information and the alarm description into a large language model; and generating a fault root cause localization result of the alarm description based on the large language model combined with the current knowledge graph.
[0102] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0103] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0104] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for locating the root cause of wireless network faults based on dynamic knowledge graphs, characterized in that, include: Obtain the alarm description and the current knowledge graph, which is obtained by updating the nodes and / or connecting edges of the historical knowledge graph; the connecting edges include alarm connecting edges. The alarm connection edges are obtained based on association rules mined from historical alarm data; Retrieve inference background information that matches the alarm description from the operation and maintenance knowledge base; The reasoning background information and the alarm description are input into the large language model, and the root cause localization result of the alarm description is generated based on the large language model and the current knowledge graph.
2. The wireless network fault root cause localization method based on dynamic knowledge graph according to claim 1, characterized in that, The reasoning background information retrieved from the operation and maintenance knowledge base that matches the alarm description includes: Extract the retrieval vector of the alarm description, wherein the retrieval vector includes at least one of keyword vector, complete semantic vector and sparse vector; Initial relevant information matching the retrieval vector is retrieved from the operation and maintenance knowledge base, and the reasoning background information is obtained by filtering from the initial relevant information. The operation and maintenance knowledge base is built based on a vector database.
3. The wireless network fault root cause localization method based on dynamic knowledge graph according to claim 1, characterized in that, The update steps for the alarm connection edge include: Calculate the contribution ratio of each relevant alarm event in the historical alarm data to the fault event, and determine the target associated node of the fault event based on the contribution ratio; the occurrence time of each relevant alarm event is earlier than the occurrence time of the fault event; Aggregate alarm event sets within a preset time window from the historical alarm data, perform causal relationship verification on the alarm events in the alarm event set, and obtain causal relationship nodes; The alarm connection edges are updated based on the connection edges between the fault event and the target associated node, and the connection edges between the causal associated nodes.
4. The wireless network fault root cause localization method based on dynamic knowledge graph according to claim 3, characterized in that, The attributes of the alarm connection edge include the association duration; the causal association nodes include primary alarm nodes and secondary alarm nodes; The first association duration between the target associated node and the fault event is determined based on the time interval between the occurrence of the target associated node and the fault event; The second association duration between the causal nodes is determined based on the occurrence time interval between the primary alarm node and the secondary alarm node.
5. The wireless network fault root cause localization method based on dynamic knowledge graph according to any one of claims 1 to 4, characterized in that, During the initial update, the historical knowledge graph is the initial knowledge graph, and the construction steps of the initial knowledge graph include: Collect multi-dimensional network data; the multi-dimensional network data includes network topology data of network devices and alarm propagation relationships of alarm data; Using the network devices and the alarm data as nodes, topology connection edges are constructed based on the network topology data, and alarm connection edges are constructed based on the alarm propagation relationship; the network devices include transmission network elements, wireless network elements, and environmental control rooms; The initial knowledge graph is constructed based on the nodes and the connecting edges between them.
6. The wireless network fault root cause localization method based on dynamic knowledge graph according to claim 5, characterized in that, The multi-dimensional network data also includes: device configuration data, performance data, operation and maintenance knowledge, and spatiotemporal information; The device configuration data and the performance data are used to determine the node attributes of the network device nodes; The operational knowledge is used to determine the node attributes of the alarm node; The spatiotemporal information is used to determine the association duration of the alarm connection edge.
7. The wireless network fault root cause localization method based on dynamic knowledge graph according to any one of claims 1 to 4, characterized in that, The steps for constructing the operation and maintenance knowledge base include: Obtain initial operation and maintenance corpus; the initial operation and maintenance corpus includes resource models, business entities, and operation and maintenance knowledge; The initial operation and maintenance corpus is sliced according to semantics, and the semantic vector of each slice is extracted; The operation and maintenance knowledge base is constructed based on the semantic vectors of each slice.
8. A wireless network fault root cause localization device based on dynamic knowledge graph, characterized in that, include: The acquisition unit acquires an alarm description and a current knowledge graph, wherein the current knowledge graph is obtained by updating nodes and / or connecting edges of a historical knowledge graph; the connecting edges include alarm connecting edges. The alarm connection edges are obtained based on association rules mined from historical alarm data; The retrieval unit retrieves reasoning background information that matches the alarm description from the operation and maintenance knowledge base; The fusion reasoning unit inputs the reasoning background information and the alarm description into the large language model, and generates the fault root cause localization result of the alarm description based on the large language model combined with the current knowledge graph.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the wireless network fault root cause localization method based on dynamic knowledge graph as described in any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the wireless network fault root cause localization method based on dynamic knowledge graph as described in any one of claims 1 to 7.