Abnormality identification method, device and equipment for time series data stream, medium and product
By combining online anomaly detection and offline change point identification with a two-stage collaborative sensing scheme, local and global anomalies in time-series data streams are identified, solving the problems of rapid response and accurate identification in existing technologies. This achieves efficient anomaly identification and calibration, and improves the accuracy of time-series data streams.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TENCENT TECHNOLOGY (SHENZHEN) CO LTD
- Filing Date
- 2026-04-16
- Publication Date
- 2026-05-15
AI Technical Summary
Existing technologies cannot simultaneously satisfy rapid anomaly response and accurate change point identification in time-series data streams, and lack effective handling of missing points, resulting in a decrease in anomaly identification accuracy.
A two-stage collaborative sensing scheme is adopted, which identifies local anomalies through the first abnormal data point and global structural anomalies through the second abnormal data point. The two are combined to generate anomaly identification results. A method combining online anomaly detection and offline change point identification is used for calibration to reduce errors caused by changes in data distribution.
It improves the accuracy of anomaly identification in time-series data streams, can quickly respond to instantaneous anomalies and correct misjudgments, adapts to data distribution drift, and improves the accuracy and timeliness of identification.
Smart Images

Figure CN122045781A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of anomaly detection technology, and in particular to a method, apparatus, device, medium and product for anomaly identification of time-series data streams. Background Technology
[0002] Anomaly detection in time series data is an important technology in the fields of data mining and intelligent operation and maintenance.
[0003] In related technologies, it is generally assumed that normal data has strong predictability in the time dimension, while abnormal data will disrupt this time series dependence. Therefore, the prediction model calculates the predicted value based on the historical data distribution of the time series, and then the error between the predicted value and the actual observed value in the time series is used as the anomaly score to screen and identify the abnormal data points in the time series.
[0004] However, when the distribution of historical data on which the prediction model relies continues to deviate from the actual performance of the time series data, the prediction model will accumulate prediction errors over time, thereby affecting the accuracy of anomaly identification results. Summary of the Invention
[0005] This application provides a method, apparatus, device, medium, and product for anomaly identification of time-series data streams. The technical solution provided by this application includes the following aspects.
[0006] According to one aspect of the embodiments of this application, an anomaly identification method for time-series data streams is provided, the method comprising: At least two data points are received in chronological order, and the at least two data points constitute a time-series data stream. The first abnormal data point in the time-series data stream is obtained. The first abnormal data point represents a data point that deviates from the data distribution pattern presented by the time-series data stream in the first historical period. Obtain the second abnormal data point in the time-series data stream, where the second abnormal data point represents a data point that is abnormal in the statistical characteristic dimension; Anomaly identification results of the time-series data stream are generated based on the first and second abnormal data points.
[0007] According to one aspect of the embodiments of this application, an anomaly identification device for time-series data streams is provided, the device comprising: The receiving module is configured to receive at least two data points in chronological order, wherein the at least two data points constitute a time-series data stream; The first acquisition module is used to acquire a first abnormal data point in the time-series data stream, wherein the first abnormal data point represents a data point that deviates from the data distribution pattern presented by the time-series data stream in a first historical period. The second acquisition module is used to acquire a second abnormal data point in the time-series data stream, wherein the second abnormal data point represents a data point that is abnormal in the statistical characteristic dimension; The generation module is used to generate anomaly identification results of the time-series data stream based on the first abnormal data point and the second abnormal data point.
[0008] According to one aspect of the embodiments of this application, a computer device is provided, the computer device including a processor and a memory, the memory storing a computer program, the computer program being loaded and executed by the processor to implement the above-described method for anomaly identification of time-series data streams.
[0009] According to one aspect of the embodiments of this application, a computer-readable storage medium is provided, wherein a computer program is stored in the computer-readable storage medium, the computer program being loaded and executed by a processor to implement the above-described method for anomaly identification of time-series data streams.
[0010] According to one aspect of the embodiments of this application, a computer program product is provided, the computer program product including a computer program stored in a computer-readable storage medium, and a processor reading from the computer-readable storage medium and executing the computer program to implement the above-described method for anomaly identification of time-series data streams.
[0011] The technical solution provided in this application can bring the following beneficial effects: When identifying outliers in a time-series data stream, the first outlier is identified by analyzing the data distribution patterns over historical periods. This allows for the capture of local anomalies and rapid response to transient anomalies. The second outlier is identified by analyzing the statistical characteristics of the time-series data stream, capturing global structural anomalies. Combining the first and second outliers yields the overall anomaly identification result. As data distribution shifts over time, the statistical characteristics of the time-series data stream change. Therefore, correcting the first outlier with the second outlier avoids misjudgments based solely on data distribution, reduces cumulative errors caused by changes in data distribution, and improves the accuracy of anomaly identification in the time-series data stream. Attached Figure Description
[0012] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0013] Figure 1 This is a schematic diagram of a computer system provided in one embodiment of this application; Figure 2 This is a flowchart of an anomaly identification method for time-series data streams provided in one embodiment of this application; Figure 3 This is a flowchart of anomaly identification for a timing data stream provided in one embodiment of this application; Figure 4 This is a flowchart of an anomaly identification method for time-series data streams provided in another embodiment of this application; Figure 5 This is a schematic diagram of an abnormal data point calibration process provided in one embodiment of this application; Figure 6 This is a schematic diagram of an abnormal data point calibration process provided in another embodiment of this application; Figure 7 This is a flowchart of an anomaly identification method for time-series data streams provided in another embodiment of this application; Figure 8 This is a schematic diagram illustrating a method for obtaining historical data sequences according to an embodiment of this application; Figure 9 This is a schematic diagram of an online anomaly detection process provided in one embodiment of this application; Figure 10 This is a schematic diagram of the detection results of online anomaly detection provided in one embodiment of this application; Figure 11 This is a flowchart of an anomaly identification method for time-series data streams provided in another embodiment of this application; Figure 12 This is a schematic diagram of the detection result of offline change point recognition provided in one embodiment of this application; Figure 13 This is a schematic diagram of the architecture of an anomaly recognition system provided in one embodiment of this application; Figure 14 This is a flowchart of missing point processing provided in one embodiment of this application; Figure 15 This is a block diagram of an anomaly identification device for a timing data stream provided in one embodiment of this application; Figure 16 This is a block diagram of an anomaly identification device for a timing data stream provided in another embodiment of this application; Figure 17 This is a structural block diagram of a computer device provided in one embodiment of this application. Detailed Implementation
[0014] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be further described in detail below with reference to the accompanying drawings. Exemplary embodiments will be described in detail here, examples of which are illustrated in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0015] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to any or all possible combinations including one or more of the associated listed items.
[0016] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, this information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another.
[0017] First, a brief introduction to the relevant technologies involved in the embodiments of this application will be given: Time Series Change Point Detection (TSP) refers to the technique of identifying the point in time series data where statistical characteristics (such as mean and variance) change abruptly. The aim is to divide a non-stationary sequence into several relatively stationary subsequences.
[0018] Anomaly detection refers to the process of detecting data instances in time series data that deviate significantly from the majority of data instances.
[0019] Dynamic programming (DP) is a method for solving complex problems by decomposing them into relatively simpler subproblems. Dynamic programming breaks down complex problems into multiple overlapping subproblems, avoiding redundant computation by storing solutions to these subproblems, thus efficiently solving problems with optimal substructure. The core of dynamic programming lies in defining the states and constructing the state transition equations, which are solved step-by-step using bottom-up or memoized search methods.
[0020] Pruned Exact Linear Time (PELT) Algorithm: A dynamic programming-based exact linear time change point detection algorithm that reduces computational complexity by pruning while ensuring the global optimum. This application uses this algorithm for change point detection.
[0021] Seasonal-Trend decomposition using Loess (STL decomposition) is a method that decomposes a time series into a trend term, a seasonal term, and a residual term to remove periodic fluctuations and extract outlier signals.
[0022] Please refer to Figure 1 This illustration shows a schematic diagram of a computer system provided in one embodiment of this application. The computer system 100 includes a terminal 120 and a server 140.
[0023] The device type of terminal 120 includes, but is not limited to, at least one of the following: game consoles, desktop computers, smartphones, tablets, e-book readers, extended reality (XR) devices, Moving Picture Experts Group Audio Layer III (MP3) players, Moving Picture Experts Group Audio Layer IV (MP4) players, and laptop computers. The following embodiments use a desktop computer as an example.
[0024] Terminal 120 is connected to server 140 via a wireless network or a wired network.
[0025] Those skilled in the art will understand that the number of the aforementioned devices can be more or less. For example, there may be only one device, or there may be dozens or hundreds of devices, or even more. This application does not limit the number or type of devices.
[0026] Server 140 includes at least one of a single server, multiple servers, a cloud computing platform, and a virtualization center. Optionally, server 140 undertakes the primary computing task, and terminal 120 undertakes the secondary computing task; or, server 140 undertakes the secondary computing task, and terminal 120 undertakes the primary computing task; or, server 140 and terminal 120 collaborate on computing using a distributed computing architecture.
[0027] It is worth noting that the server 140 described above can be implemented as a physical server or as a cloud server in the cloud. In some embodiments, the server 140 can also be implemented as a node in a blockchain system.
[0028] Optionally, the anomaly identification method for time-series data streams provided in this application embodiment can be implemented independently by the terminal 120, independently by the server 140, or jointly by the terminal 120 and the server 140, and is not limited here.
[0029] Change point detection and anomaly detection in time series data are crucial technologies in data mining and intelligent operations and maintenance. Based on different processing modes and algorithm principles, these technologies are mainly divided into two categories: offline change point detection and online anomaly detection, encompassing various techniques from traditional statistical methods to deep learning models.
[0030] In large-scale, diverse real-world traffic data streams, the change point detection and anomaly detection techniques used for time series data suffer from the following problems: Problem 1: Offline change point identification lacks flexibility and cannot cope with unexpected situations. On the one hand, many traditional methods make a strong assumption about the Gaussian distribution of data, resulting in poor robustness to non-stationary or noisy real-world data. Furthermore, these traditional methods often rely on a fixed number of change points or a threshold for breakpoint detection, lacking sufficient algorithmic flexibility and failing to adapt to changing real-world business scenarios. On the other hand, these change point detection algorithms require accumulating offline data over a certain period for change point detection, making it impossible to provide timely responses to sudden anomalies.
[0031] Problem 2: Online anomaly detection based on deep learning prediction models has high latency and cannot meet online requirements: The detection model also faces problems such as high inference latency and difficulty in cold start, which weakens the practicality of the model; in addition, deploying the detection model requires a lot of resources.
[0032] Issue 3: Lack of effective handling of missing data points: Current offline change point identification and online anomaly detection methods lack discussion and effective handling of missing data points. However, in real-world business scenarios, due to various unstable factors such as data capture, network latency, and service updates, incoming data frequently exhibits missing data points. This includes occasional missing data points as well as missing data points lasting for hours or days. Previous detection algorithms may fail in such situations.
[0033] In other words, the anomaly identification methods for time series provided by related technologies cannot simultaneously satisfy the requirements of fast anomaly response and accurate change point identification, and are also not robust to missing points.
[0034] Based on this, this application provides a two-stage collaborative sensing scheme for anomaly identification in time-series data streams, which solves the above problems through one or more of the following embodiments.
[0035] Please refer to Figure 2 The diagram illustrates a flowchart of an anomaly identification method for a time-series data stream according to an embodiment of this application. The method is executed by an electronic device, which may optionally be implemented as... Figure 1 The terminal 120 or server 140 in this embodiment are used as examples to illustrate the method being executed by server 140. This embodiment can be implemented as an independent embodiment or in combination with any other embodiment; no limitation is imposed here.
[0036] The method may include at least one of the following steps (210~240).
[0037] Step 210: Receive at least two data points in chronological order, where the at least two data points constitute a time-series data stream.
[0038] Among them, time-series data stream refers to a data stream consisting of at least two data points arranged in a time sequence. That is, the received data is arranged according to the arrival time or recording time of the data points to obtain a time-series data stream.
[0039] In some embodiments, the above-mentioned at least two data points can be implemented as data points received continuously in chronological order; or they can be implemented as data points received intermittently in chronological order (at fixed time intervals or non-fixed time intervals), without limitation.
[0040] A data point is a timestamped data record in a data sequence formed by a time-series data stream. The timestamp refers to the arrival time or recording time of the data point. The data point reception process is implemented within a unit time interval. For example, a data point is a data record collected within a pre-set period.
[0041] In some embodiments, the data structure of the data points includes: (1) Timestamp: Used to indicate the time when a data point is arrived or recorded; (2) Data value: used to indicate the observation value collected by the above timestamp.
[0042] Optionally, the data structure of the data points may also include at least one of the following: (1) Status flag: used to mark whether data points are missing or abnormal; (2) Source identifier: used to indicate the source of the data point; for example, data source device identifier, data source server identifier, data source terminal identifier.
[0043] In some embodiments, the aforementioned time-series data stream can be a data stream output from the service side or a data stream output from the sensor, and no limitation is made here.
[0044] Step 220: Obtain the first abnormal data point in the time-series data stream.
[0045] The first abnormal data point refers to a data point that deviates from the data distribution pattern presented by the time-series data stream in the first historical period. That is, the regular data distribution presented by the time-series data stream in the first historical period is used as a reference to determine whether the received new data point deviates from the regular distribution. If it deviates, it is said that the data point is the first abnormal data point.
[0046] Optionally, the above data distribution patterns include uniform distribution, normal distribution, exponential distribution, power law distribution, periodic distribution, step distribution, long-tailed distribution, mixed distribution, asymmetric distribution, etc., which are not limited here.
[0047] In some embodiments, the determination of deviation from the data distribution pattern presented in the first historical time period can be achieved by calculating the first degree of deviation of the data points relative to the regular data distribution. For example, data points whose first degree of deviation reaches a preset first deviation threshold are regarded as abnormal data points.
[0048] Optionally, the aforementioned first deviation can be achieved by calculating at least one of the following quantification data: (1) Standard scores of data points and data sequences within the first historical period; (2) Calculate the percentiles of the data sequence within the first historical period (e.g., P99 and P1); calculate the deviation of the data points from the percentiles; (3) Calculate the entropy of the data sequence within the first historical time period; calculate the entropy increment of the data sequence after adding data points; (4) Fit the expression function corresponding to the data distribution pattern in the first time period; predict the predicted value of the timestamp corresponding to the data point through the expression function; calculate the difference between the actual value indicated by the data point and the predicted value.
[0049] In some embodiments, anomaly detection is performed on the time-series data stream based on the data distribution pattern presented within a first historical time period, thereby detecting a first anomalous data point contained in the time-series data stream. Here, the data distribution pattern of the time-series data stream refers to the distribution pattern of data points within the first time period (e.g., the first historical time period) of the time-series data stream.
[0050] Optionally, the aforementioned first time period range can be implemented as at least one of the following: (1) The time period from the start time of the time-series data stream to the current time; (2) The time period from the time corresponding to the abnormal data point of the previous record in the time-series data stream to the current time; (3) The current time is the termination time and the first preset duration is the preceding time period.
[0051] Optionally, the anomaly detection method for time-series data streams can be implemented as at least one of the following: (1) Based on sliding window statistics: In a schematic manner, a sliding window with a first preset step size is maintained for the time-series data stream. The sliding window includes the latest W data points in the time-series data stream. When a new data point is received, the old data points at the end of the sliding window are removed. The statistical indicators corresponding to the sliding window are maintained in real time. For the received new data point, the standardized score of the new data point is calculated in combination with the statistical indicators. If the standardized score of the new data point reaches the first score threshold, the new data point is output as the first abnormal data point.
[0052] Optionally, the statistical indicators corresponding to the sliding window include at least one of the mean μ and standard deviation σ corresponding to the data points within the sliding window.
[0053] (2) Incremental Clustering: Since normal data forms dense clusters, while outliers are isolated points that cannot be classified into any cluster, incremental clustering can be used to view the detection of outliers as a problem of whether a data point can be classified into a cluster formed by normal data.
[0054] Intuitively, a set of dynamically changing micro-clusters is maintained in memory. These micro-clusters are obtained by clustering data points in a time-series data stream. Each micro-cluster records its center, radius, weight (number of data points included), and timestamp. When a new data point is received, the distance from the new data point to all micro-cluster centers is calculated. If the distance of a new data point to a micro-cluster is less than the micro-cluster radius, the new data point is merged into that micro-cluster, and the center and weight of the micro-cluster are updated (incremental update). If the distance of a new data point to any micro-cluster is greater than the micro-cluster radius, a new micro-cluster corresponding to the new data point is created. If a data point in the time-series data stream cannot be merged into any cluster with a weight greater than a first weight threshold within the first time window, or if the weight of the micro-cluster it belongs to is continuously lower than the first weight threshold, then the data point is output as the first abnormal data point.
[0055] (3) Prediction models based on deep learning: By using a temporal neural network to model the historical data sequence in a time-series data stream, the predicted values of future data points can be obtained through the temporal neural network. The difference between the predicted value and the actual value is used to determine whether it is an abnormal data point.
[0056] In a schematic manner, a pre-trained temporal neural network is acquired; and a historical data sequence within a first historical period is acquired from a temporal data stream; the historical data sequence is input into the temporal neural network, and a first predicted value corresponding to a future first timestamp is predicted by the temporal neural network; a first data point is acquired from the temporal data stream, the first data point including a first timestamp and a first data value; the first data value corresponding to the first data point is compared with the first predicted value, and if the difference between the first data value and the first predicted value reaches a preset difference requirement, the first data point is output as a first abnormal data point.
[0057] Optionally, the aforementioned temporal neural network can be implemented as at least one of the following: Recurrent Neural Network (RNN), Long Short-Term Memory (LSTM), Deep Recurrent Neural Network (DRNN), Transformer, etc., without limitation.
[0058] (4) Generative and Reconstruction Models: Generative models are used to learn the latent representation or generation distribution of normal data in sample data. During the inference stage, normal samples can be reconstructed or generated well, while abnormal samples usually show large reconstruction errors or low generation probabilities, and anomaly scores are given for data points accordingly.
[0059] In a schematic way, the first data point in the time series data stream is input into the pre-trained generative model to obtain the anomaly probability value corresponding to the first data point. When the anomaly probability value reaches the first probability threshold, the first data point is output as the first anomaly data point.
[0060] Optionally, the above generative model can be implemented as at least one of the following: autoencoder (AE), variational autoencoder (VAE), generative adversarial network (GAN), etc., without limitation.
[0061] It is worth noting that, in addition to the above-mentioned anomaly detection method, the identification of the first abnormal data point in the embodiments of this application can also be achieved through online density estimation, STL decomposition, etc., without limitation.
[0062] Step 230: Obtain the second abnormal data point in the time-series data stream.
[0063] The second abnormal data point refers to a data point that is abnormal in the dimension of statistical characteristics (features). That is, the statistical characteristics of the data sequence in which the data point is located are used to measure whether the data point conforms to the normal pattern corresponding to the data sequence.
[0064] Statistical characteristics are used to describe the features and patterns of data from an overall perspective. Optionally, statistical characteristics include at least one of the following statistical indicators: mean, variance, median, standard deviation, skewness, and kurtosis. No limitation is made here.
[0065] In some embodiments, the determination of whether a data point is abnormal in terms of statistical characteristics can be achieved by calculating the second degree of deviation of the data point from the statistical index of the data sequence. For example, data points whose second degree of deviation reaches a preset second deviation threshold are regarded as abnormal data points.
[0066] Optionally, the aforementioned second degree of deviation can be achieved by calculating at least one of the following quantification data: (1) The standardized score corresponding to the data point, wherein the standardized score is calculated based on the data value corresponding to the data point, the mean of the data sequence, and the standard deviation; (2) Mahalanobis distance between the data point and the distribution center (mean vector) corresponding to the data sequence, wherein the Mahalanobis distance is calculated by the data value of the data point and the mean vector of the data sequence.
[0067] For example, if most of the data in the data sequence corresponding to the time series data stream follows a normal distribution, then the standardized values of normal data points in the data sequence are usually distributed in the interval [-3,3]. When the standardized value of a certain data point in the data sequence is not in the above interval (for example, 5), it indicates that the data point is an abnormal data point.
[0068] In some embodiments, change point identification is performed on the time-series data stream based on its statistical characteristics to identify second anomalous data points contained within the time-series data stream. These statistical characteristics are obtained by calculating the statistical characteristics of data points within a second time period of the time-series data stream.
[0069] Optionally, the aforementioned second time period range can be implemented as at least one of the following: (1) The time period from the start time of the time-series data stream to the current time; (2) The time period from the time corresponding to the abnormal data point of the previous record in the time-series data stream to the current time; (3) The current time is the termination time and the second preset time is the preceding time period.
[0070] Optionally, the first time period range corresponding to anomaly detection and the second time period range of change point detection can be the same or different, and no limitation is imposed here.
[0071] Alternatively, the variable point recognition method can achieve at least one of the following: (1) Segmentation-based algorithms: Find the optimal segmentation point for the time-series data stream to maximize the homogeneity within each segment and the difference between segments, thereby identifying the variable points in the time-series data stream as the second abnormal data points for output.
[0072] Optionally, the segmentation-based algorithm includes at least one of the following: Optimal Partitioning (OP), Binary Segmentation (BinSeg), PELT algorithm, Window-based / SlidingWindow algorithm, neighborhood enumeration and dynamic programming (SegNeigh) algorithm, etc., without limitation.
[0073] (2) Algorithms based on probability density ratio and likelihood ratio: Among them, the change point identification based on probability density ratio means that significant change points are identified as change points by calculating the probability density ratio of adjacent time periods; the change point identification based on likelihood ratio means that significant jump points are identified as the second abnormal data points by calculating the difference in log-likelihood ratio of adjacent time periods.
[0074] Optionally, the change point identification algorithm based on probability density ratio includes at least one of Cumulative SUM (CUSUM), Bayesian change point detection, etc.
[0075] Optionally, the change point identification algorithm based on likelihood ratio includes at least one of the following: Likelihood Ratio Test (LRT), score function approximation algorithm, generalized likelihood ratio algorithm, etc., without limitation.
[0076] (3) Subspace model method: Embed the time-series data stream into the trajectory matrix or state-space model, and extract the principal subspace through methods such as singular value decomposition. When the structure of the principal subspace changes significantly, it is determined that there is a change point at the corresponding time position, and the change point is output as the second abnormal data point.
[0077] Optionally, the subspace model method includes at least one of principal component detection (PCP), matrix factorization, singular spectrum transformation, and subspace identification, etc., without limitation.
[0078] (4) Clustering and segmentation methods: By combining a sliding window with a bottom-up segmentation strategy, the overall sequence structure is fitted by repeatedly dividing and merging intervals. The optimal set of segmentation points is selected, and the segmentation points are output as the second outlier data points.
[0079] Optionally, the clustering and segmentation methods include at least one of the following: online time series segmentation algorithm (Sliding Window And Bottom-up, SWAB), multi-stage clustering with polynomial fitting (MSCPF), and time series subsequence clustering (TS3C), without limitation.
[0080] It is worth noting that the first and second abnormal data points can be obtained sequentially. For example, the first abnormal data point can be obtained first, followed by the second abnormal data point, or vice versa. The first and second abnormal data points can also be obtained in parallel, without limitation. That is, the execution order of steps 220 and 230 is not restricted. Figure 2 The order of steps in the process.
[0081] Step 240: Generate anomaly identification results for the time-series data stream based on the first and second anomalous data points.
[0082] In some embodiments, the first abnormal data point and the second abnormal data point are fused to obtain the anomaly identification result of the time-series data stream.
[0083] Optionally, the fusion method for the first abnormal data point and the second abnormal data point can be implemented as at least one of the following: (1) Take the union between the first abnormal data point and the second abnormal data point as the anomaly identification result of the time series data stream; (2) The intersection between the first abnormal data point and the second abnormal data point is taken as the anomaly identification result of the time series data stream; (3) Use the second abnormal data point to calibrate the first abnormal data point to obtain the abnormal identification result of the time series data stream.
[0084] In some embodiments, the anomaly identification result indicates at least one abnormal data point in the time-series data stream; in response to the generated anomaly identification result, the time-series data stream is subjected to anomaly response processing based on the abnormal data point indicated by the anomaly identification result.
[0085] Optionally, the anomaly response processing includes at least one of the following: issuing an anomaly alarm for the anomaly data point, correcting the anomaly data point, and adding an anomaly marker to the status flag bit corresponding to the anomaly data point in the time-series data stream. This is not limited here.
[0086] For example, please refer to Figure 3 It illustrates a flowchart of anomaly identification of a time-series data stream provided by an exemplary embodiment of this application. A data stream 310 is composed of continuously received data points. Anomaly detection is performed on the A data stream 310 to obtain a first abnormal data point 321. Change point identification is performed on the A data stream 310 to obtain a second abnormal data point 322. The first abnormal data point 321 and the second abnormal data point 322 are combined to generate an anomaly identification result 330 corresponding to the A data stream 310.
[0087] In summary, when identifying anomalous data points in a time-series data stream, identifying the first anomalous data point through the data distribution of the time-series data stream can capture local anomalies, enabling rapid response to instantaneous anomalies. Identifying the second anomalous data point through the statistical characteristics of the time-series data stream can capture global structural anomalies. Combining the first and second anomalous data points yields the anomaly identification result. As the data distribution drifts over time, the statistical characteristics of the time-series data stream change. Therefore, by correcting the first anomalous data point with the second anomalous data point, misjudgments based on the data distribution-based identification of the first anomalous data point can be avoided, reducing the cumulative error caused by changes in data distribution and improving the accuracy of anomaly identification in the time-series data stream.
[0088] In some optional embodiments, online anomaly detection and offline change point identification are performed on the time-series data stream. Online anomaly detection acts as a "sentinel," using local window data to respond to traffic mutations with low latency. Offline change point identification acts as a "backup," using global identification based on long-term historical data to correct the results of online anomaly detection. This solves the problem of cumulative errors in online anomaly detection over time, thus constructing a closed-loop system that is "agile and self-consistent online, and globally corrected offline."
[0089] Please refer to Figure 4 This document illustrates a flowchart of an anomaly identification method for time-series data streams provided in one embodiment of this application. Embodiments of this application can be implemented as independent embodiments or in combination with any other embodiments, and are not limited herein.
[0090] The method may include at least one of the following steps (410~440).
[0091] Step 410: Receive at least two data points in chronological order, with the at least two data points forming a time-series data stream.
[0092] Among them, time-series data stream refers to a data stream consisting of at least two data points arranged in a time sequence. That is, the received data is arranged according to the arrival time or recording time of the data points to obtain a time-series data stream.
[0093] Step 420: Perform online anomaly detection on the time-series data stream in the first cycle to obtain the first abnormal data point in the time-series data stream within the first cycle.
[0094] The first abnormal data point refers to a data point that deviates from the data distribution pattern presented by the time-series data stream within the first historical time period. That is, using the regular data distribution presented by the time-series data stream within the first historical time period as a reference, it is determined whether the received new data point deviates from this regular distribution. If it does, then the data point is considered the first abnormal data point. In this embodiment, the first historical time period is the historical time period prior to the first cycle.
[0095] The first cycle is the time unit that meets the online correction requirements of the time-series data stream. Optionally, the first cycle can be implemented with time granularity such as seconds, minutes, hours, or days.
[0096] Optionally, the duration of the first cycle can be at least one of the following: (1) Pre-set fixed cycle duration.
[0097] (2) The cycle length is dynamically adjusted according to the business requirements corresponding to the time-series data stream; for example, when the business corresponding to the time-series data stream is financial transaction business, the first cycle can be set to minute-level or second-level cycle to capture transaction transient fluctuations in a timely manner; for another example, when the business corresponding to the time-series data stream is industrial inspection, the first cycle can be set to hour-level or day-level cycle to adapt to the slow-changing inspection of production rhythm.
[0098] (3) The period length is obtained by dynamically scaling the real-time load of the business corresponding to the time-series data stream. For example, the period length of the first period is negatively correlated with the real-time load of the business. That is, the period is shortened when the business is under high load to improve sensitivity.
[0099] (4) The period duration is adaptively adjusted according to the data distribution drift rate. The data distribution drift rate represents the speed at which the data distribution changes over time. The data distribution drift rate can be implemented as the Wasserstein rate, the rate estimated based on KL divergence, etc., and is not limited here. The period duration of the first period is negatively correlated with the distribution drift rate. That is, the faster the distribution drifts, the shorter the first period.
[0100] Optionally, the online anomaly detection method performed on the time-series data stream in the first cycle can be implemented as at least one of the following: Anomaly detection methods based on sliding window statistics, incremental clustering, deep learning-based prediction models, and generative and reconstruction models are not limited here.
[0101] Step 430: Perform offline change point identification on the time series data stream in the second period to obtain the second abnormal data point in the time series data stream where the statistical characteristics are abnormal in the second period.
[0102] The second outlier data point refers to a data point that exhibits anomalies in statistical characteristics. It's worth noting that the second outlier data point can also be referred to as a change point in the time-series data stream.
[0103] In this embodiment of the application, the duration of the first cycle is shorter than the duration of the second cycle. That is, online anomaly detection is real-time detection based on a short cycle, while offline change point identification is offline detection based on a long cycle.
[0104] The second period is a time unit that meets the requirements for offline global recognition of time-series data streams. Optionally, the second period can be implemented with time granularity such as seconds, minutes, hours, days, weeks, months, grades, etc., without limitation here.
[0105] Alternatively, the duration of the second cycle can be implemented as at least one of the following: (1) Pre-set fixed cycle duration.
[0106] (2) The cycle length is dynamically adjusted according to the business requirements corresponding to the time-series data stream; for example, when the business corresponding to the time-series data stream is financial transaction business, the second cycle can be set to a daily cycle; for another example, when the business corresponding to the time-series data stream is industrial testing, the first cycle can be set to a weekly or monthly cycle.
[0107] (3) The period duration is obtained by dynamically scaling the real-time load of the business corresponding to the time-series data stream. For example, the period duration of the second period is negatively correlated with the real-time load of the business.
[0108] (4) The period duration is adaptively adjusted according to the data distribution drift rate. The data distribution drift rate represents the speed at which the data distribution changes over time. The data distribution drift rate can be implemented as the Wasserstein rate, the rate estimated based on KL divergence, etc., and is not limited here. The period duration of the second period is negatively correlated with the distribution drift rate. That is, the faster the distribution drifts, the shorter the second period.
[0109] In one example, the first cycle is implemented as a minute-level cycle and the second cycle is implemented as a day-level cycle. For example, the first cycle is 10 minutes and the second cycle is 1 day. In another example, the first cycle is implemented as a second-level cycle and the second cycle is implemented as an hour-level cycle. For example, the first cycle is 30 seconds and the second cycle is 12 hours.
[0110] Optionally, the offline change point identification method performed on the time-series data stream in the second cycle includes at least one of the following: segmentation-based algorithms, probability density ratio and likelihood ratio-based algorithms, subspace model methods, clustering and segmentation methods, etc., which are not limited here.
[0111] In this embodiment, a combination of short-cycle online anomaly detection and long-cycle offline change point identification is used. Short-cycle online anomaly detection enables high-timeliness response to large-scale traffic waveform changes, while long-cycle offline change point identification ensures high accuracy of anomaly identification results for time-series data streams. This allows for the simultaneous achievement of "high-timeliness response" and "high-accuracy identification" in anomaly identification of time-series data streams. It can handle sudden anomaly scenarios in a timely manner, provide low-latency anomaly detection, and also cope with long-term regular changes in traffic caused by operational operations, configuration changes, etc., as well as scenarios that require accurate judgment from a global perspective.
[0112] It is worth noting that steps 420 and 430 can be implemented as independent steps or as combined steps, and no limitation is made here.
[0113] Step 440: Use the second abnormal data point to calibrate the first abnormal data point to obtain the anomaly identification result of the time-series data stream.
[0114] In this embodiment of the application, since the duration of the second cycle is longer than that of the first cycle, the time range corresponding to the second cycle includes at least one first cycle, and the second abnormal data point corresponding to the second cycle can be used to calibrate the first abnormal data point corresponding to the first cycle contained therein.
[0115] In other words, by using the results of offline change point identification, which focuses on global and accurate identification, the results of online anomaly detection are calibrated, so that the online and offline stages can corroborate and complement each other in multiple indicator dimensions, thus taking into account both the timeliness and accuracy requirements of anomaly identification for time-series data streams; and the correction of the first anomaly data point by the second anomaly data point can also ensure the accuracy of subsequent online anomaly detection when combined with historical information for prediction, avoiding misjudgment due to the accumulation of errors over time.
[0116] In some embodiments, after obtaining the first abnormal data point, the first abnormal data point is stored as a historical abnormal data point in the historical information database at the first interval position corresponding to the first period. The historical information database is used to store historical abnormal data points existing in the time-series data stream. That is, during the online anomaly detection process, the first abnormal data point obtained by online anomaly detection is stored in the historical information database for persistent storage, so as to be used for real-time anomaly alarm for abnormal data points, and to determine the sequence range representing the data distribution during subsequent online anomaly detection.
[0117] In some embodiments, in response to obtaining a second abnormal data point, the historical abnormal data point in the historical information database within the second interval position corresponding to the second period is updated using the second abnormal data point.
[0118] In other words, abnormal data points obtained from online anomaly detection are stored in a historical information database. Then, abnormal data points obtained from offline change point identification are used to correct the abnormal data points stored in the historical information database. Since offline change point identification uses longer-term historical data to identify change points compared to online anomaly detection, the identification results are based on a global perspective, resulting in higher accuracy. Thus, while achieving low-latency anomaly response through online anomaly detection, the results of online anomaly detection can also be corrected through offline change point identification. This avoids the cumulative error caused by the passage of time when the historical information database is used to construct the data distribution of the time-series data stream in the subsequent online anomaly detection process, which would lead to a decrease in anomaly detection accuracy and ensure the accuracy of anomaly identification for the time-series data stream.
[0119] In some embodiments, updating historical abnormal data points within a second interval corresponding to the second period in the historical information database using second abnormal data points includes at least one of the following: (1) For the second abnormal data point of the i-th timestamp, and if the historical abnormal data point of the i-th timestamp is not recorded in the historical information database, add a data record of the historical abnormal data point of the i-th timestamp in the historical information database, where i is a positive integer.
[0120] For example, such as Figure 5As shown, this is a schematic diagram of an abnormal data point calibration process provided by an exemplary embodiment of this application. Database A 510 records data points A 511, B 512, C 513, and D 514. An abnormal data point set 520 corresponding to the second period is obtained through offline variable point identification. The abnormal data point set 520 includes data point E 521. Since the timestamp corresponding to data point E 521 is not recorded as an abnormal data point in database A 510, data point E 521 is inserted into the position corresponding to the timestamp in database A 510.
[0121] In other words, by using offline change point identification to supplement the trend inflection points and morphological change points that are ignored by online anomaly detection, we can avoid missing abnormal data points, make up for the accuracy shortcomings sacrificed by online anomaly detection in pursuit of real-time performance, and improve the comprehensiveness and robustness of anomaly identification in time-series data streams.
[0122] (2) If there is a historical abnormal data point with the j-th timestamp recorded in the historical information database, and there is no second abnormal data point with the j-th timestamp, delete the data record of the historical abnormal data point with the j-th timestamp in the historical information database, where j is a positive integer.
[0123] For example, such as Figure 6 As shown, this is a schematic diagram of an abnormal data point calibration process provided in an exemplary embodiment of this application. The B database 610 records data points F 611, G 612, H 613, and I 614. The B abnormal data point set 620 corresponding to the second period is obtained through offline variable point identification. The B abnormal data point set 620 includes data point G 612. Since the second interval position corresponding to the second period in the B database 610 includes data points G 612 and H 613, and data point H 613 does not appear in the B abnormal data point set 620, data point H 613 is deleted from the B database 610.
[0124] In other words, online anomaly detection is often limited by the local data view and the requirement for rapid response of time-series data streams, and is prone to misjudging noise, spikes or short-term fluctuations, resulting in some invalid anomaly alarms. By using offline change point identification to delete non-abnormal data points obtained from online anomaly detection from the global change point identification results, false alarms caused by online anomaly detection can be eliminated, and the accuracy and reliability of the overall anomaly detection results of time-series data streams can be improved.
[0125] In some embodiments, the input strategy of the prediction model is updated based on a historical information database. The prediction model is used to perform traffic prediction for the identification of a first abnormal data point. The input strategy is used to indicate the sequence range of historical data sequences input to the prediction model.
[0126] In some embodiments, the prediction model described above is a mathematical model or machine learning model used in the online anomaly detection process to predict abnormal data points.
[0127] In other words, by correcting the historical information database with the second abnormal data point obtained through offline change point detection, the corrected historical information database is used to determine the range of historical data sequences of the prediction model during online anomaly detection. This can improve the accuracy of the historical data used by the prediction model, avoid prediction bias caused by the distribution evolution of time-series data streams in the time dimension, and improve the reliability of online anomaly detection.
[0128] In some embodiments, after obtaining the first abnormal data point, the method further includes: triggering an abnormal alarm for the first abnormal data point; after calibrating the first abnormal data point with the second abnormal data point, the method further includes: if the second abnormal data point does not include the first abnormal data point for which the abnormal alarm was triggered, rolling back the abnormal alarm for the first abnormal data point.
[0129] In other words, after calibrating the detection results of online anomaly detection using the detection results of offline change point identification, false alarms of non-abnormal data points are also revoked to ensure the accuracy of the alarm.
[0130] In summary, when identifying anomalous data points in a time-series data stream, identifying the first anomalous data point through the data distribution of the time-series data stream can capture local anomalies, enabling rapid response to instantaneous anomalies. Identifying the second anomalous data point through the statistical characteristics of the time-series data stream can capture global structural anomalies. Combining the first and second anomalous data points yields the anomaly identification result. As the data distribution drifts over time, the statistical characteristics of the time-series data stream change. Therefore, by correcting the first anomalous data point with the second anomalous data point, misjudgments based on the data distribution-based identification of the first anomalous data point can be avoided, reducing the cumulative error caused by changes in data distribution and improving the accuracy of anomaly identification in the time-series data stream.
[0131] In some optional embodiments, online anomaly detection uses historical data sequences to predict future time points, and detects anomaly data points by comparing the differences between the predicted values and the actual observed values. Please refer to [reference needed]. Figure 7 This document illustrates a flowchart of an anomaly identification method for time-series data streams provided in one embodiment of this application. Embodiments of this application can be implemented as independent embodiments or in combination with any other embodiments, and are not limited herein.
[0132] The method may include at least one of the following steps (421-424).
[0133] Step 421: Obtain the historical data sequence of the time-series data stream within the first historical time period.
[0134] Optionally, the aforementioned first historical period can be implemented as at least one of the following: (1) The time period from the start time of the time-series data stream to the current time; (2) The time period from the time corresponding to the abnormal data point of the previous record in the time-series data stream to the current time; (3) The current time is the termination time and the first preset duration is the preceding time period.
[0135] In some embodiments, a historical information database is provided to store historical anomalous data points existing in the time-series data stream. Illustratively, based on the historical information database, the first moment corresponding to the anomalous data point of the previous record in the time-series data stream is determined. The time period from the first moment to the second moment in the time-series data stream is taken as the first historical time period, and the sequence of data points from the first moment to the second moment in the time-series data stream is taken as the historical data sequence. Here, the anomalous data point of the previous record refers to the historical anomalous data point with the latest timestamp among the historical anomalous data points recorded in the historical information database.
[0136] Alternatively, the second moment described above can be implemented as at least one of the following: (1) The current moment; (2) The start time of the first cycle; (3) The timestamp that is N timestamps before the current time and N timestamp away from the current time. For example, if the current time is T, then the second timetamp is TN. (4) The timestamp that is M timestamps before the start time of the first cycle and M timestamp away from the current time. For example, if the start time of the first cycle is T, then the second timetamp is TM.
[0137] For example, such as Figure 8 As shown, it illustrates a schematic diagram of a historical data sequence acquisition method provided by an exemplary embodiment of this application. The system maintains a C database 810, which records multiple historical abnormal data points recorded within a historical period. These historical abnormal data points are abnormal data points verified by obtaining a first abnormal data point through online abnormal detection and a second abnormal data point through offline variable point identification.
[0138] Determine the target timestamp corresponding to the latest historical abnormal data point 811 among multiple historical abnormal data points. Take the target timestamp as the starting time and the time point N times before the current first timestamp to be predicted and N times away from the current first timestamp to be predicted as the ending time to determine the first historical time period. Extract the data point sequence of the first historical time period from the B data stream 800 as the historical data sequence 820.
[0139] Step 422: Based on historical data sequence prediction, obtain the first predicted value of the time-series data stream at the first timestamp.
[0140] In this embodiment of the application, the time-series data stream contains at least one first data point in the first period, that is, at least one first data point is received in the first period. The first data point includes a first timestamp and a first data value. The first timestamp is used to indicate the time when the first data point arrives or is recorded, and the first data value is used to indicate the observation value collected at the first timestamp.
[0141] In some embodiments, the first data point further includes at least one of a first status flag and a first source identifier, wherein the first status flag is used to record whether the first data point is missing or abnormal, and the first source identifier is used to indicate the source of the first data point.
[0142] In this embodiment, online anomaly detection is achieved through STL decomposition. STL decomposition is a method for decomposing a time series into a trend term, a seasonal term, and a residual term.
[0143] The trend term indicates the changing trend of data points in a historical data series, representing non-periodic changes over time. Optionally, the changing trend of data points relative to the overall historical data series includes linear trends and / or logical growth trends. Linear trends are suitable for business scenarios where data points increase or decrease linearly over time, while logical growth trends are suitable for business scenarios where there is an upper limit to the growth of data points.
[0144] The seasonality term is used to indicate the periodic repetition of data points in a historical data series. In some embodiments, the seasonality term represents the periodic variation characteristics of data points between preset periods, used to characterize periodic changes in the time series.
[0145] Optionally, the duration of the aforementioned preset period can be preset by the system or obtained by dividing the time span of the first historical period. Optionally, the aforementioned preset period can be implemented as a period in units of years, quarters, months, days, hours, etc. In some embodiments, the seasonal item can also be referred to as the periodic item.
[0146] The residual term is used to indicate the part of a historical data series that remains after removing the trend and seasonal terms. It represents data fluctuations that cannot be explained by the trend and seasonal terms. The residual term can be regarded as random noise, with no obvious pattern and a mean of 0.
[0147] Schematic, the method of predicting the first predicted value of a time-series data stream at a first time stamp based on historical data sequences includes: decomposing the historical data sequence to obtain a first trend term, a first seasonal term, and a first residual term corresponding to the historical data sequence. The first trend term indicates the long-term trend of data points in the historical data sequence, the first seasonal term indicates the periodic repetition of data in the historical data sequence, and the first residual term indicates random noise in the historical data sequence; obtaining the second trend term, the second seasonal term, and the second residual term corresponding to the first residual term at a first future step size. The second trend term is the prediction result of the first trend term at the first future step size, the second seasonal term is the prediction result of the first seasonal term at the first future step size, and the second residual term is the prediction result of the first residual term at the first future step size, with the first future step size associated with the first time stamp; and synthesizing the second trend term, the second seasonal term, and the second residual term to obtain the first predicted value of the time-series data stream at the first time stamp.
[0148] For example, as shown in Formula 1, it illustrates the approach for historical data sequences. STL decomposition: Formula 1: .
[0149] in, The first trend term is the long-term, slow-moving component extracted after low-pass filtering of historical data sequences using LOESS (Local Estimation of Scatterplot Smoothing). It represents the trend of the historical data sequence after removing seasonality and randomness; that is, the first trend term. The output is controlled by median filtering or smoothing parameters. The larger the smoothing parameter, the stiffer the trend line, and the less sensitive it is to short-term fluctuations. The first-season term refers to a data pattern of fixed length that repeats within a given period. It is obtained by removing the trend term and smoothing with LOESS from the sequence values of historical data at each period position (e.g., the same day of each week). It is a periodic component with a mean of 0 in a historical data series, the first seasonal term. The variation is controlled by the period length and the seasonal smoothing parameter. The larger the seasonal smoothing parameter, the smaller the change in the seasonal value at the same position in adjacent periods, and the more stable the seasonal pattern shown by the historical data series. The first residual term refers to the part remaining after subtracting the trend and seasonal terms from the historical data series. It is white noise independent of the data distribution and represents measurement errors, irregular short-term shocks, and complex data patterns that the decomposition model failed to capture.
[0150] The first future step size is the time step size predicted when predicting the predicted value through STL decomposition. In some embodiments, the first future step size can be implemented as the time interval between the termination time of the first historical period and the first timestamp.
[0151] In one example, the STL decomposition of a historical data sequence can be implemented as follows: U1, initialization; Indicative, initialization of the hypothetical seasonal term Alternatively, the initial trend can be estimated using a pre-defined smoothing method.
[0152] U2, inner loop (updates trends and seasons); The inner loop contains two main sub-steps, which are typically repeated n times to converge: U21, De-seasonalize and Update Trend; Schematic diagram of calculating deseasoned sequences That is, the current iteration minus the current seasonal term; for Perform LOESS smoothing to obtain a new trend term. ; U22, de-trend and update seasonality. Schematic diagram of calculating detrending sequences ,at this time, It includes seasonality and residuals; for each seasonal position j (1≤j≤m), the data values for that position in all periods are collected, and their average is calculated to obtain a preliminary seasonal sequence of length m; this sequence of length m is then smoothed using LOESS to eliminate high-frequency noise in the residuals, resulting in the smoothed seasonal term. ;Adjustment This ensures that the sum over a complete cycle is zero, guaranteeing that the trend term represents the true average level.
[0153] U3, outer loop (handling outliers / robustness); If outliers exist in the historical data sequence, they will distort the LOESS smoothing result. The outer loop addresses this issue by assigning lower weights to outliers. Indicatively, calculating residuals: After the inner loop completes, calculate the current residual. Robust weights are calculated using a biweight function, which calculates weights based on the magnitude of the residuals. ; calculate the weights The smoothing process is applied to the next inner loop's LOESS.
[0154] U4, output result.
[0155] After the outer loop finishes, the final decomposition result trend term is output. Seasonal items and residuals .
[0156] After decomposing to obtain the first trend term, the first seasonal term, and the first residual term, predictions are performed on the first trend term, the first seasonal term, and the first residual term respectively to obtain the second trend term, the second seasonal term, and the second residual term.
[0157] In some embodiments, the trend term represents the long-term trend of the data and is usually relatively smooth. Therefore, it is suitable to use some models that can capture long-term patterns for prediction. Thus, at least one of linear regression, multinomial regression, or autoregressive integrated moving average (ARIMA) models can be used to fit and predict the future value of the first trend term to obtain the second trend term.
[0158] In some embodiments, since the seasonal term is a periodically repeating pattern, its prediction mainly depends on how to extend past patterns to the future. Therefore, at least one of the following can be used to fit and predict the future value of the first seasonal term to obtain the second seasonal term.
[0159] Optionally, the first machine learning model mentioned above includes at least one of the following: a bidirectional gated recurrent unit (BiGRU), a recurrent neural network, a long short-term memory network, a deep recurrent neural network, and a Transformer, without limitation.
[0160] In some embodiments, the residual term is the remaining part after decomposition, which is usually considered as random noise. The way it is treated determines whether the model can capture unconventional fluctuations. Therefore, the residual term can be treated as white noise, or at least one of the following can be used to fit and predict the first residual term to obtain the second residual term.
[0161] Optionally, the second machine learning model mentioned above includes at least one of extreme gradient boosting (XGBoost), gated recurrent unit (GRU), BiGRU, etc., without limitation.
[0162] Indicative, first predicted value As shown in Formula 2: Formula 2: .
[0163] in, The second trend term, For the second season item, This is the second residual term. The number of data points in the historical data sequence. The first future step size.
[0164] For example, STL decomposition uses input data with a 10-minute granularity of length t (in stable conditions, a length of 1008 data points, i.e., 7 days of data) as the data decomposition, and predicts the values of the next h points (h=3) to obtain the final predicted value. .
[0165] Step 423: Based on the difference between the first data value and the first predicted value, obtain the first detection result of the first data point.
[0166] The first detection result is used to indicate the deviation of the first data point from the data distribution of the time-series data stream.
[0167] In this embodiment, the future trend of the sequence is predicted by combining the data distribution presented by the historical data sequence, thereby obtaining a first predicted value. Online anomaly detection is achieved by comparing the difference between the first predicted value and the first data value obtained by actual observation, thus ensuring the detection efficiency of online anomaly detection.
[0168] In some embodiments, the absolute difference between a first data value and a first predicted value is obtained; if the absolute difference between the first data value and the first predicted value reaches a first difference threshold, the first data point is determined as a first abnormal data point and used as a first detection result; if the absolute difference between the first data value and the first predicted value does not reach the first difference threshold, the first data point is determined as a normal data point and used as a first detection result.
[0169] In other embodiments, historical error information of the time-series data stream within a second historical period is obtained. The historical error information is used to indicate the error between the data value and the predicted value of a data point in the time-series data stream. Based on the difference between the first data value and the first predicted value, current error information corresponding to the first data point is obtained. If the difference between the current error information and the historical error information reaches a first error threshold, the first data point is determined as a first abnormal data point as a first detection result. If the difference between the current error information and the historical error information does not reach the first error threshold, the first data point is determined as a normal data point as a first detection result.
[0170] Optionally, the historical error information includes at least one of the historical root mean square error (RMSE) and the historical average maximum error.
[0171] The historical average RMSE is the average root mean square error of all data points within a past normal data window (i.e., the historical data sequence). This normal data window is updated by sliding; once an abnormal data point is detected, the normal data window is reset.
[0172] The historical average maximum error is the average of the maximum errors of each time window (e.g., the current first data point and several neighboring data points) within a normal data window over the past period.
[0173] Optionally, the current error information includes at least one of the current RMSE and the current maximum error. The current RMSE is the root mean square error calculated within the current time window centered on the first data point (including the first data point and the k data points before and after it). The current maximum error is the maximum absolute value of all errors within the aforementioned current time window.
[0174] For the current first timestamp, the first predicted value is obtained through the aforementioned STL decomposition and prediction. Then, the error between the first predicted value and the first data value is calculated. Based on this, the current RMSE and the current maximum error are constructed.
[0175] Optionally, the window length of the current time window can be a preset fixed value or a dynamic value determined according to the length of the historical data sequence, and there is no limitation here.
[0176] In some embodiments, when the historical error information includes the historical average RMSE and the current error information includes the current RMSE, the anomaly determination of the first data point is achieved through the following formula three: Formula 3: .
[0177] in, This is the error threshold corresponding to the judgment rule.
[0178] In some embodiments, when the historical error information includes the historical average maximum error and the current error information includes the current maximum error, the anomaly determination of the first data point is achieved through the following formula four: Formula 4: .
[0179] in, This is the error threshold corresponding to the judgment rule.
[0180] It is worth noting that the above two judgment rules can also be combined to realize the anomaly judgment of the first data point. When either judgment rule satisfies the above conditions, the first data point is output as the first abnormal data point, and the first detection result is obtained.
[0181] In other words, a historical benchmark for the normal fluctuation range of time-series data streams is established by using the historical average RMSE and the historical average maximum error. By comparing the current error of the first data point with the historical benchmark, it is determined whether the data points of the time-series data stream have changed significantly, thereby realizing online anomaly detection of data points. Since the aforementioned historical benchmark is updated over time, the online anomaly detection process has environmental adaptability. Furthermore, since the detection of anomaly data points is entirely based on historical data, the output is in an unsupervised / semi-supervised mode, enabling rapid deployment and low-cost maintenance.
[0182] In some embodiments, it was found in algorithm experiments that if the input data is relatively stable, the algorithm would be too sensitive if the same judgment threshold as for general data is used. Therefore, the judgment strategy and the error threshold for anomaly judgment are dynamically adjusted by combining the judgment of data stability.
[0183] In a schematic manner, the stationarity detection result of the historical data sequence is obtained, which is used to indicate the change of the statistical characteristics of the historical data sequence over time; when the stationarity detection result indicates that the historical data sequence is a stationary sequence, a first error value is obtained as a first error threshold; when the stationarity detection result indicates that the historical data sequence is a non-stationary sequence, a second error value is obtained as the first error threshold; the first error value is greater than the second error value.
[0184] Optionally, the detection method for the stationarity detection result of the historical data series can be at least one of the KPSS test (Kwiatkowski-Phillips-Schmidt-Shin test) and the ADF test (Augmented Dickey-Fuller test), without limitation.
[0185] In other words, if the sequence was previously identified as a stationary sequence, a stricter threshold will be used to determine anomalies, preventing false positives. If the current first data point is identified as the first anomalous data point, the historical error will be reset, the anomalous data point location information will be updated, and a cold start duration of a first duration will be set to prevent multiple detections. This avoids the online anomaly detection algorithm from being too sensitive, reduces the number of normal data points being falsely reported as anomalous data points, and improves the accuracy of online anomaly detection.
[0186] Step 424: Based on the first detection results corresponding to at least one first data point, determine the first abnormal data point from at least one first data point.
[0187] In some embodiments, to further improve the accuracy of online anomaly detection, dynamic rules are set to perform secondary judgment on the first data point, thereby solving the possible false positives and false negatives caused by a single prediction algorithm. Illustratively, a second detection result corresponding to the first data point is obtained based on at least one dynamic rule. The second detection result is used to indicate the anomaly of the first data point under the judgment of the dynamic rule. Based on the first and second detection results corresponding to each first data point within a first period, a first abnormal data point is determined from at least one first data point.
[0188] Optionally, the dynamic rules include at least one of the following: (1) Oscillation and pullback rule: In a schematic manner, the waveform of the data within the first window containing the first data point in the time-series data stream is obtained; the peak and trough frequencies corresponding to the data waveform within the first window are calculated; when the peak and trough frequencies reach a first frequency threshold, the first quantile of the first data sequence within the first window relative to the second data sequence within the second window is calculated, where the second window is a historical period that includes and is greater than the first window; based on the difference between the first quantile and the first data value, a second detection result is obtained. The first window mentioned above can be a data window formed by a historical data sequence; or, the first window mentioned above can be a data window in a time-series data stream centered on the first data point and containing Q data points before and after it, without any limitation.
[0189] Peak-trough frequency is the total or average number of times a peak (local highest point) and a trough (local lowest point) occur in the data sequence in the first window per unit time. It is an indicator for measuring the intensity of data fluctuations or the speed of oscillation.
[0190] Optionally, the first quantile includes at least one of P99 (99th percentile) and P1 (1st percentile).
[0191] Specifically, after the data sequence within the first window is determined to be oscillating data, the P99 and P1 quantiles are used for the oscillating data, and a dynamic window length threshold (50% for 1 day and 30% for 7 days) is used to determine whether the current first data point exceeds the normal fluctuation of the historical window data.
[0192] Among them, the aforementioned dynamic window length threshold As shown in Formula 5: Formula 5: .
[0193] in, Used to indicate the current window length (the window length of the second window) used to calculate the historical quantiles (P99, P1). Used to indicate the length of time-series data streams within one day. This is used to indicate the data length corresponding to a time-series data stream within 7 days. As can be seen, this dynamic window length threshold... It decreases linearly as the window length increases.
[0194] The above dynamic window length threshold Based on this, the normal fluctuation range is as follows: Normal fluctuation limit = P99 + threshold × (P99 - P1); The lower limit of normal fluctuation = P1 - threshold × (P99 - P1).
[0195] In other words, by using the oscillation fallback rule, data points are allowed to expand outward by a certain proportion from the original quantile range. If a data point still exceeds the expanded range, it is determined to be the first abnormal data point. This avoids false detection of data point anomalies and improves the accuracy of online anomaly detection when the time series data stream exhibits oscillating characteristics.
[0196] (2) Amplitude variation rules: Among them, the amplitude variation rule is an anomaly detection method based on comparing local fluctuation amplitude with historical typical fluctuation amplitude. Illustratively, the method involves acquiring the third data sequence within a third window prior to the first timestamp; calculating the absolute difference between the first data value and each data value in the third data sequence, and taking the maximum absolute difference as the maximum amplitude difference of the first data point relative to the third data sequence; obtaining the historical amplitude difference corresponding to the third data sequence within the third window, which indicates the average intensity of data value fluctuations in the third data sequence; and obtaining the second detection result based on the difference between the maximum amplitude difference and the historical amplitude difference.
[0197] In some embodiments, when the maximum amplitude difference is greater than a preset multiple of the historical amplitude difference, the first data point is taken as the first abnormal data point, and a second detection result is obtained.
[0198] That is, the maximum amplitude difference between the current first data point and the third data sequence in the third window before the first timestamp is calculated. If the maximum amplitude difference is greater than a preset multiple of the historical amplitude difference in the third window, then the first data point is considered to be abnormal.
[0199] Specifically, the amplitude variation rules include the following processing steps: U1, calculate the maximum amplitude difference of the first data point.
[0200] To illustrate, for the current first timestamp t, take its corresponding first data value Y. t ; trace back through all data points within the past third window in the time-series data stream; calculate the first data value Y. t The absolute value of the difference between the first data point and each data point in the third window is taken as the maximum value, which is recorded as the maximum amplitude difference corresponding to the first data point. This maximum amplitude difference measures the maximum fluctuation amplitude of the current moment relative to the most recent short-term window.
[0201] U2 calculates the historical amplitude difference within the third window.
[0202] Take a longer historical window as the third window (e.g., the past 7 days). For each time s within the window, calculate the maximum amplitude difference between that time and the preceding third window using the above method to obtain a set of historical amplitude difference values. Summarize the historical amplitude difference values, for example, by taking the mean or median as the historical amplitude difference. The historical amplitude difference represents the average intensity of short-term fluctuations in history.
[0203] U3, anomaly detection for the first data point.
[0204] The maximum amplitude difference of the first data point is compared with the historical amplitude difference. If the difference exceeds a preset multiple, the first data point is judged as the first abnormal data point. In one example, the preset multiple is 2 times. It is worth noting that the preset multiple can also be dynamically adjusted according to the actual scenario. For example, for sensitive business, the preset multiple can be set to 1.5 times, and for more robust business, the preset multiple can be set to 3 times. There is no limitation here.
[0205] In other words, since anomaly prediction through STL decomposition and prediction, as well as oscillation fallback rules, relies on the long-term trend characteristics of the data stream, anomaly detection is supplemented by introducing a short-term fluctuation perspective through amplitude variation rules. That is, amplitude variation rules focus on the local comparison between the current data point and the data points within the past short window. It can instantly capture drastic amplitude changes in a short period of time, even if such changes are still within the "average acceptable" range in long-term statistics, thereby reducing the underreporting of abnormal data points. It is sensitive to sudden anomalies such as instantaneous spikes and drops, making up for the shortcomings of anomaly prediction through STL decomposition and prediction and oscillation fallback rules. It is also sensitive to sudden local jumps, ensuring the accuracy of online anomaly detection.
[0206] In one example, such as Figure 9 As shown, it illustrates a schematic diagram of an online anomaly detection process provided by an exemplary embodiment of this application. For the first data point 901 in the first period of the C data stream 900, three branches are used to realize the anomaly detection of the first data point 901, including STL decomposition and prediction branch 910, oscillation fallback rule branch 920, and amplitude variation rule branch 930. Among them, STL decomposition and prediction branch 910 outputs the first detection result 911, oscillation fallback rule branch 920 outputs the second detection result 921, and amplitude variation rule branch 930 outputs the third detection result 931.
[0207] In some embodiments, when at least one of the first detection result 911, the second detection result 921, and the third detection result 931 indicates that the first data point 901 is an abnormal data point, the first data point 901 is output as the first abnormal data point.
[0208] In other embodiments, when the first detection result 911, the second detection result 921, and the third detection result 931 all indicate that the first data point 901 is an abnormal data point, the first data point 901 is output as the first abnormal data point.
[0209] In other embodiments, when the number of results indicating that the first data point 901 is an abnormal data point in the first detection result 911, the second detection result 921, and the third detection result 931 reaches a first quantity threshold, the first data point 901 is output as the first abnormal data point.
[0210] For example, please refer to Figure 10 The figure shows a schematic diagram of the detection results of online anomaly detection provided by an exemplary embodiment of this application. For D data stream 1000, four abnormal data points are obtained through online anomaly detection, as shown in the figure, including J data point 1001, K data point 1002, M data point 1003 and N data point 1004.
[0211] In summary, when identifying anomalous data points in a time-series data stream, identifying the first anomalous data point through the data distribution of the time-series data stream can capture local anomalies, enabling rapid response to instantaneous anomalies. Identifying the second anomalous data point through the statistical characteristics of the time-series data stream can capture global structural anomalies. Combining the first and second anomalous data points yields the anomaly identification result. As the data distribution drifts over time, the statistical characteristics of the time-series data stream change. Therefore, by correcting the first anomalous data point with the second anomalous data point, misjudgments based on the data distribution-based identification of the first anomalous data point can be avoided, reducing the cumulative error caused by changes in data distribution and improving the accuracy of anomaly identification in the time-series data stream.
[0212] In some optional embodiments, offline change point identification is implemented using a dynamic programming algorithm to identify structural inflection points and abrupt changes in the time-series data stream over long periods, thereby ensuring the accuracy of offline change point identification. Please refer to [link / reference]. Figure 11 This document illustrates a flowchart of an anomaly identification method for time-series data streams provided in one embodiment of this application. Embodiments of this application can be implemented as independent embodiments or in combination with any other embodiments, and are not limited herein.
[0213] The method may include at least one of the following steps (431-433).
[0214] Step 431: Obtain the periodic data sequence corresponding to the second period in the time-series data stream.
[0215] The second period is a time unit that meets the requirements for offline global recognition of time-series data streams. Optionally, the second period can be implemented with time granularity such as seconds, minutes, hours, days, weeks, months, grades, etc., without limitation here.
[0216] Alternatively, the duration of the second cycle can be implemented as at least one of the following: (1) Pre-set fixed cycle duration.
[0217] (2) The cycle length is dynamically adjusted according to the business requirements corresponding to the time-series data stream; for example, when the business corresponding to the time-series data stream is financial transaction business, the second cycle can be set to a daily cycle; for another example, when the business corresponding to the time-series data stream is industrial testing, the first cycle can be set to a weekly or monthly cycle.
[0218] (3) The period duration is obtained by dynamically scaling the real-time load of the business corresponding to the time-series data stream. For example, the period duration of the second period is negatively correlated with the real-time load of the business.
[0219] (4) The period duration is adaptively adjusted according to the data distribution drift rate. The data distribution drift rate represents the speed at which the data distribution changes over time. The data distribution drift rate can be implemented as the Wasserstein rate, the rate estimated based on KL divergence, etc., and is not limited here. The period duration of the second period is negatively correlated with the distribution drift rate. That is, the faster the distribution drifts, the shorter the second period.
[0220] In this embodiment of the application, the sequence of data points formed by the time-series data stream in the second period is used as the periodic data sequence, and the periodic data sequence includes at least one candidate data point.
[0221] Step 432: At least one second data point is obtained by searching within the periodic data sequence based on dynamic programming.
[0222] The second data point is used to indicate the data point in the periodic data sequence where the statistical characteristics of the data change.
[0223] This example illustrates how dynamic programming is used to traverse candidate data points in a periodic data sequence to identify structurally variable points as second data points. It's worth noting that the traversal and selection of second data points can also be implemented using at least one of the following methods: full combinatorial traversal, greedy traversal, random sampling traversal, or priority queue-based traversal; these are not limited here.
[0224] In some embodiments, the PELT algorithm is used to identify change points in periodic data sequences. The PELT algorithm is a dynamic programming-based exact linear time change point detection algorithm. Illustratively, a first cost function is obtained, which measures the data fluctuation within the periodic data sequence. At least one second data point is searched from the periodic data sequence with the objective of minimizing the function value of the first cost function.
[0225] In other words, using the PELT algorithm to identify change points in periodic data sequences can reduce the computational complexity of the algorithm while ensuring that the global optimal solution is found. This balances computational efficiency and segmentation accuracy, thereby reducing the computational complexity of offline change point identification for periodic data sequences and improving the efficiency of offline change point identification.
[0226] Optionally, the type of the first cost function mentioned above includes at least one of L2 (mean change), L1 (median change), normal distribution, Poisson distribution, etc.
[0227] In one example, the first cost function is implemented as shown in Equation 6: Formula Six: .
[0228] in, The value represents a periodic data sequence, with cost set to the internal variance L2, m being the number of variable points, and p being the penalty term coefficient. The penalty term coefficient is used to indicate that during the search process for the second data point, the mean of the periodic data sequence is used to replace the weight of any data point.
[0229] Optionally, the aforementioned penalty coefficient can be implemented as a pre-set fixed value or as an adaptive adjustment value.
[0230] In some embodiments, when the penalty term coefficient in the first cost function is implemented as an adaptive adjustment value, the method further includes: dynamically adjusting the penalty term coefficient according to at least one iterative rule during the process of searching for a second data point from a periodic data sequence with the objective of minimizing the function value of the first cost function.
[0231] Optionally, the iteration rules include at least one of the following: (1) In the process of searching for subsequences in the periodic data sequence, if the density of the second data point found in the subsequence reaches the first density requirement, the penalty term coefficient is increased; (2) In the process of searching for a subsequence in the periodic data sequence, if no second data point is found in the subsequence and the stationarity of the subsequence is lower than the first stationarity threshold, the penalty term coefficient is reduced.
[0232] In one example, the penalty term coefficient is set as shown in Formula 7: Formula 7: .
[0233] Where n is the sequence length, Let be the sequence variance, and k be the initial threshold. In one example, k=50.
[0234] Under the penalty term coefficient indicated by Formula 7 above, when the number of change points in the subsequence is too dense, this part will iteratively increase the penalty term, that is, decrease the k value; if there are no change points in the subsequence and the subsequence cannot pass the stationarity test, the average of the current k value and the previous k value will be taken as the new k value.
[0235] That is, by dynamically and adaptively adjusting the penalty term coefficient, when the number of change points in the subsequence is too dense, the penalty term in the first cost function will be iteratively increased. When there are no change points in the subsequence and the subsequence cannot pass the stationarity test, the penalty term in the first cost function will be reduced. This suppresses and alleviates the overfitting (too dense change points) or underfitting (missing change points) situation when the PELT algorithm is used to search for change points, thereby improving the robustness of offline change point identification.
[0236] Step 433: Filter at least one second data point to obtain at least one second abnormal data point.
[0237] In this embodiment, dynamic programming is used to find structural change points in long-term periodic data sequences. The core advantage of dynamic programming is to find the globally optimal segmentation method. By comprehensively considering the periodic data sequence, it ensures that the combined positions of all identified change points minimize the total error, thereby improving the accuracy of offline change point identification. It accurately identifies structural changes within the periodic data sequence, filters noise within the period, effectively distinguishes between normal periodic fluctuations and true structural abrupt changes, and guarantees the accuracy of change point identification. Furthermore, dynamic programming maintains high computational efficiency under long-term data, avoiding the computational explosion problem associated with combinations of data points.
[0238] In some embodiments, in order to further filter out change points, an importance assessment value for each change point (second data point) is also calculated during offline change point identification to determine whether the sequence distribution after the change point is similar to the distribution of the current period.
[0239] The aforementioned importance assessment value measures the similarity between the data distribution after the change point and the reference benchmark.
[0240] Indicatively, based on the difference between the data distribution after the second data point in the time-series data stream and the data distribution of the periodic data sequence, the importance assessment value corresponding to the second data point is calculated; the second data point whose importance assessment value meets the importance requirement is regarded as the second abnormal data point.
[0241] In one example, using the mean of the last day as a benchmark, the variance of the sequence after the breakpoint is calculated based on the mean of the last day, as shown in Formula 8: Formula 8: .
[0242] in, This is the importance assessment value. The sequence length of the periodic data sequence. This is the time index of the k-th second data point (the change point). It is the i-th candidate data point in a periodic data sequence. This is the average of the last day.
[0243] In some embodiments, when the importance assessment value corresponding to the second data point reaches a first importance threshold, the second data point is output as the second anomalous data point. That is, when the importance assessment value corresponding to the second data point is small, it indicates that the sequence after the change point is similar to the distribution of the day, and the change point may not be important; conversely, it indicates that the distribution has changed significantly, and the change point is more important. By combining the importance assessment value of the change point for screening, false change points and transient disturbances in the previous change point search results are filtered out, so that the final output second anomalous data point is a node with permanent changes in the time series data stream, avoiding over-interpretation of transient noise and effectively improving the accuracy and reliability of offline change point identification. At the same time, in sequences with multiple change points, early change points may be important, but their actual influence may be diluted or covered over time and with the occurrence of subsequent change points. Therefore, combining importance assessment to achieve substation screening establishes a hierarchical structure of change points, ignoring change points that have little impact on future states, solving the cumulative error caused by change point drift, and further improving the accuracy of prediction models / prediction tasks in online anomaly detection.
[0244] For example, please refer to Figure 12 The figure shows a schematic diagram of the detection result of offline change point identification provided by an exemplary embodiment of this application. For E data stream 1200, two abnormal data points are obtained through offline change point identification, as shown in the figure, including X data point 1201 and Y data point 1202.
[0245] In summary, when identifying anomalous data points in a time-series data stream, identifying the first anomalous data point through the data distribution of the time-series data stream can capture local anomalies, enabling rapid response to instantaneous anomalies. Identifying the second anomalous data point through the statistical characteristics of the time-series data stream can capture global structural anomalies. Combining the first and second anomalous data points yields the anomaly identification result. As the data distribution drifts over time, the statistical characteristics of the time-series data stream change. Therefore, by correcting the first anomalous data point with the second anomalous data point, misjudgments based on the data distribution-based identification of the first anomalous data point can be avoided, reducing the cumulative error caused by changes in data distribution and improving the accuracy of anomaly identification in the time-series data stream.
[0246] In some optional embodiments, the anomaly identification method for time-series data streams provided in this application can be applied to anomaly identification systems. For example, please refer to... Figure 13 The diagram illustrates the architecture of an anomaly identification system 1300 provided in an exemplary embodiment of this application.
[0247] The anomaly detection system 1300 includes four core components: a missing point processing module 1310, an online anomaly detection module 1320, an offline change point detection module 1330, and a collaboration module 1340. These components work together to achieve a combination of rapid response and accurate identification in change point detection.
[0248] Among them, the missing point processing module 1310 is the first step in data governance. It adopts a hierarchical strategy to handle missing situations of different types and durations: long missing points are reset or truncated, and short missing points are filled and smoothed. It aims to provide a high-quality and complete data foundation for online anomaly detection and offline change point identification modules, and ensure that online detection can automatically recover after data failure.
[0249] In some embodiments, such as Figure 14 As shown, a flowchart of missing point processing provided by an exemplary embodiment of this application is illustrated, including the following steps: Step 1401: Input multi-indicator time series data stream; Step 1402: Identify missing points and missing regions; After receiving the input multi-indicator time-series data stream, the system first identifies missing points and missing intervals in the data stream. Missing points can be a single missing data point or multiple consecutive missing data points; missing intervals can be characterized by the time span corresponding to the missing data points.
[0250] Step 1403: Determine whether the missing duration has reached the first duration threshold. If yes, proceed to step 1404; otherwise, proceed to step 1405. After identifying the missing interval, the system further determines whether the missing duration corresponding to the missing interval reaches a first duration threshold. The first duration threshold can be preset according to the business scenario, sampling granularity, or detection cycle. For example, at a sampling granularity of 10 minutes, a continuous missing interval with more than a certain number of sampling points can be regarded as a long missing interval, while intervals below the threshold can be regarded as short missing intervals.
[0251] Step 1404: Perform long missing data handling, state reset or interval phase to prevent the distorted history from continuing to propagate; When the duration of missing data reaches a first duration threshold, the system performs long-missing data processing. Long-missing data processing can include at least one operation such as state reset, interval truncation, or marking the interval as unsuitable for prediction input. The reason for using this approach is that prolonged consecutive missing data often leads to significant distortion in the distribution of subsequent sequences. If the corresponding interval is directly input into the online prediction or offline recognition module, it can easily cause abnormal judgments to deviate from the actual business state. Therefore, by resetting or truncating long-missing intervals, the continuous propagation of invalid historical information can be avoided.
[0252] Step 1405: Perform short missing data processing, including padding and smoothing, to maintain sequence continuity; When the duration of the missing data does not reach the first duration threshold, the system performs short-missing data processing. Short-missing data processing may include at least one operation such as padding based on neighboring data points, interpolation based on temporal continuity, and smoothing the padded sequence. By padding and smoothing the short-missing intervals, more complete input data can be provided for subsequent online anomaly detection and offline change point identification while preserving the continuity of the original sequence as much as possible.
[0253] Step 1406: Update historical information and mark abnormal interval status; Step 1407: Output the processed sequence for subsequent detection. Step 1408: Distribute to the online anomaly detection module and the offline change point recognition module.
[0254] In some embodiments, regardless of whether long or short missing interval processing is performed, the system can further update historical information. For example, for long missing intervals, the system can mark in the historical information database that the corresponding interval has been reset or truncated; for short missing intervals, the system can mark in the historical information database that the corresponding interval has been padded and smoothed. By recording the governance process, auxiliary information can be provided for subsequent collaborative calibration, alarm judgment, and prediction window adjustment.
[0255] After handling long or short missing data, the system outputs the processed time-series data sequence and distributes it to the online anomaly detection module and the offline change point identification module. Thus, the online anomaly detection module can quickly identify anomalies based on a more continuous and reliable data sequence, while the offline change point identification module can perform global change point identification based on a more stable long-period sequence.
[0256] Furthermore, in some embodiments, the missing point handling process not only improves the quality of a single detection input but also influences subsequent prediction strategies by linking with a historical information database. For example, when the system confirms that a long missing interval has disrupted the previous historical statistical distribution, it can discard some historical data before the interval in subsequent predictions; while when the system confirms that a short missing interval has had its continuity restored through padding, the corresponding window is allowed to continue participating in online prediction and offline recognition. Thus, missing point handling is no longer just a pre-process cleaning but forms part of a closed loop together with online detection, offline recognition, and collaborative calibration.
[0257] Therefore, this embodiment improves the robustness of the proposed solution to missing data in complex business environments and enhances the stability of subsequent anomaly identification and change point detection by following the process of "identifying missing points - determining the duration of missing data - distinguishing between long and short missing data - implementing different governance strategies - updating historical information - outputting the processed sequence".
[0258] The online anomaly detection module 1320 provides low-latency anomaly detection, running in 10-minute cycles. Each time, it judges whether a point with a 20-minute delay is an anomaly. Based on STL decomposition and trend smoothing fitting model, it makes real-time judgments on traffic mutations.
[0259] The offline change point recognition module 1330 serves as the system's precise recognition layer, operating on a daily cycle. Based on long-term, full-volume historical data including the current day, it employs an improved PELT algorithm with threshold adaptation to perform global optimal path search.
[0260] The collaborative module 1340 is a key "correction" layer connecting online and offline detection results. It uses the globally optimal and more accurate results provided by the offline change point recognition module to verify and correct the historical information database of online anomaly detection, thereby correcting the misjudgments and omissions of online detection, ensuring the accuracy of historical information, and realizing a closed loop of "online agile response and offline global calibration".
[0261] These four components form a closed loop through a "real-time perception-offline correction" mechanism, which collaboratively solves the problem of cumulative error in the prediction model over time, and achieves a balance between timeliness and accuracy in complex traffic scenarios.
[0262] When providing anomaly identification for time-series data streams, the anomaly detection system 1300 operates through a logic of "data governance - real-time detection - global verification." In other words, the architecture of the anomaly detection system 1300 includes the following three core steps: Step 1: Data Access and Missing Point Handling. The anomaly detection system 1300 continuously receives multi-indicator time-series data streams from the business side, performing basic cleaning and missing point management on the input data points. A tiered processing strategy is adopted for different types and durations of missing data: long-term missing data with significant impact is reset or removed; scattered missing data is completed and smoothed, outputting a structurally complete and quality-controllable sequence, providing a unified data foundation for subsequent online and offline analysis.
[0263] Step Two: Online Anomaly Detection and Real-time Output. The online anomaly detection module 1320 performs anomaly detection on the processed time-series data stream at a high frequency, and outputs anomaly information in real time to drive alarms and policy linkage. The online anomaly detection provided by the online anomaly detection module 1320 focuses on rapid response to short-term fluctuations and sudden anomalies, combining multi-indicator information and preset rules for comprehensive judgment, and recording detection results and intermediate states.
[0264] Step 3: Offline Change Point Identification and Global Calibration. Over a preset daily period, the offline change point identification module 1330 performs global change point identification and importance assessment based on recent historical data, forming the change point distribution and key structural information of the current data stream. The collaborative module 1340 uses the offline identification results to perform secondary verification and necessary historical corrections on the online detection results generated in Step 2, thereby achieving a global grasp of long-term trend changes, completing the collaborative calibration of the online modules, and improving the overall accuracy and stability of the identification.
[0265] The aforementioned anomaly detection system 1300 can provide offline change point detection and online anomaly detection services for time-series data streams to the business platform through pre-designed interfaces.
[0266] Optionally, the pre-designed interface described above can be implemented as at least one of the following: batch processing interface, embedded library / software development kit (SDK) interface, Hypertext Transfer Protocol (HTTP) interface, Remote Procedure Call (RPC) interface, etc., without limitation.
[0267] The inputs of the above interfaces are shown in Table 1, and the outputs are shown in Tables 2 and 3.
[0268] Table 1 indicates the request parameters of the interface, Table 2 indicates the return parameters of offline change point detection, and Table 3 indicates the return parameters of online anomaly detection.
[0269]
[0270] Table 1.
[0271]
[0272] Table 2.
[0273]
[0274] Table 3.
[0275] For example, the online anomaly detection service allows the platform to call the detection interface at 10-minute intervals, outputting whether a point from 20 minutes ago is an anomaly; if so, it also returns the anomaly type. The offline change point identification service allows the platform to call the interface at daily intervals, outputting the identified change points in the entire data stream and returning the change point importance assessment value, allowing the platform to further filter valid change points.
[0276] It is worth noting that the call time intervals provided by the above-mentioned online anomaly detection service and offline change point identification service are illustrative examples and can be dynamically adjusted to other time intervals according to actual business needs, without limitation here.
[0277] Before using the solution proposed in this application, the anomaly identification schemes for time-series data streams used in related technologies could not simultaneously meet the requirements of latency and recall, and lacked generalization ability for online data samples with different distributions, and could not effectively handle sudden missing data situations. The offline change point detection module of this application was tested on 15 online real model data samples, with four indicators for each sample. The results are shown in Tables 4 and 5 below. Table 4 indicates the single-indicator results of the experiment, and Table 5 indicates the multi-indicator results of the experiment. These indicators include: Accuracy (ACC), which indicates the proportion of correct predictions among all predictions, measuring overall judgment ability; Precision (P), which indicates how many of the data points predicted as anomalies are actually anomalies; Recall (R), which indicates how many of the truly anomaly data points were successfully predicted; and F1 score, which indicates the harmonic mean of precision and recall, comprehensively reflecting the performance of both.
[0278]
[0279] Table 4.
[0280]
[0281] Table 5.
[0282] The online anomaly detection module of this application was tested on 20 samples of real online traffic data, and the results are shown in Table 6.
[0283]
[0284] Table 6.
[0285] The online anomaly detection module of this application achieved a recall rate of 90.5% in online real data testing, meeting the recall requirements; the offline change point recognition module achieved a recall rate of 100% on multiple indicators, with an overall recall rate of 94.6% and an F1 value of 89.8%, providing secondary calibration assurance for online anomaly detection.
[0286] The following are embodiments of the apparatus described in this application, which can be used to execute the embodiments of the method described in this application. For details not disclosed in the apparatus embodiments of this application, please refer to the embodiments of the method described in this application.
[0287] Please refer to Figure 15 This diagram illustrates a block diagram of an anomaly detection device for a time-series data stream according to an embodiment of this application. The device includes the following modules: The receiving module 1510 is configured to receive at least two data points in chronological order, wherein the at least two data points constitute a time-series data stream; The first acquisition module 1520 is used to acquire a first abnormal data point in the time-series data stream, wherein the first abnormal data point represents a data point that deviates from the data distribution pattern presented by the time-series data stream in the first historical period. The second acquisition module 1530 is used to acquire a second abnormal data point in the time-series data stream, wherein the second abnormal data point represents a data point that is abnormal in the statistical characteristic dimension. The generation module 1540 is used to generate anomaly identification results of the time-series data stream based on the first abnormal data point and the second abnormal data point.
[0288] In some optional embodiments, the first acquisition module 1520 is further configured to perform online anomaly detection on the time-series data stream in a first period to obtain the first abnormal data point existing in the time-series data stream within the first period; And / or, The second acquisition module 1530 is further configured to perform offline change point identification on the time-series data stream in a second period to obtain the second abnormal data point in which the statistical characteristics of the time-series data stream are abnormal in the second period.
[0289] In some optional embodiments, the time-series data stream includes at least one first data point within the first period, the first data point including a first timestamp and a first data value; like Figure 16 As shown, the first acquisition module 1520 further includes: Sequence acquisition unit 1521 is used to acquire the historical data sequence of the time-series data stream within the first historical time period; Prediction unit 1522 is used to predict the first predicted value of the time-series data stream at the first timestamp based on the historical data sequence; The comparison unit 1523 is used to obtain a first detection result of the first data point based on the difference between the first data value and the first predicted value. The first detection result is used to indicate the deviation of the first data point from the data distribution of the time-series data stream. The generation unit 1524 is used to determine the first abnormal data point from the at least one first data point based on the first detection result corresponding to the at least one first data point.
[0290] In some optional embodiments, the prediction unit 1522 is further configured to decompose the historical data sequence to obtain a first trend term, a first seasonal term, and a first residual term corresponding to the historical data sequence. The first trend term is used to indicate the long-term trend of data points in the historical data sequence, the first seasonal term is used to indicate the periodic data repetition in the historical data sequence, and the first residual term is used to indicate random noise in the historical data sequence. The prediction unit 1522 is further configured to obtain a second trend term corresponding to the first trend term under the first future step, a second seasonal term corresponding to the first seasonal term under the first future step, and a second residual term corresponding to the first residual term under the first future step. The second trend term is the prediction result of the first trend term under the first future step, the second seasonal term is the prediction result of the first seasonal term under the first future step, and the second residual term is the prediction result of the first residual term under the first future step. The first future step is associated with the first timestamp. The prediction unit 1522 is further configured to synthesize the second trend term, the second seasonal term, and the second residual term to obtain the first predicted value of the time series data stream at the first timestamp.
[0291] In some optional embodiments, the comparison unit 1523 is further configured to obtain historical error information of the time-series data stream within a second historical period, the historical error information being used to indicate the error between the data value and the predicted value of the data point in the time-series data stream; The comparison unit 1523 is further configured to obtain the current error information corresponding to the first data point based on the difference between the first data value and the first predicted value; The comparison unit 1523 is further configured to determine the first data point as the first abnormal data point as the first detection result when the difference between the current error information and the historical error information reaches a first error threshold. The comparison unit 1523 is further configured to determine the first data point as a normal data point as the first detection result when the difference between the current error information and the historical error information does not reach the first error threshold.
[0292] In some optional embodiments, the comparison unit 1523 is further configured to obtain the stationarity detection result of the historical data sequence, the stationarity detection result being used to indicate the change of the statistical characteristics of the historical data sequence over time; The comparison unit 1523 is further configured to obtain a first error value as the first error threshold when the stationary detection result indicates that the historical data sequence is a stationary sequence; The comparison unit 1523 is further configured to obtain a second error value as the first error threshold when the stationary detection result indicates that the historical data sequence is a non-stationary sequence; the first error value is greater than the second error value.
[0293] In some optional embodiments, the generation unit 1524 is further configured to obtain a second detection result corresponding to the first data point based on at least one dynamic rule, wherein the second detection result is used to indicate the abnormal situation of the first data point under the determination of the dynamic rule. The generation unit 1524 is further configured to determine the first abnormal data point from the at least one first data point based on the first detection result and the second detection result corresponding to each first data point in the first period; The dynamic rules include at least one of the following: The data waveform within the first window containing the first data point in the time-series data stream is obtained; the peak and trough frequencies corresponding to the data waveform within the first window are calculated; when the peak and trough frequencies reach a first frequency threshold, the first quantile of the first data sequence within the first window relative to the second data sequence within the second window is calculated, where the second window is a historical time period that includes and is greater than the first window; based on the difference between the first quantile and the first data value, the second detection result is obtained. Obtain the third data sequence within the third window prior to the first timestamp; calculate the absolute difference between the first data value and each data value in the third data sequence, and take the maximum value among the absolute differences as the maximum amplitude difference of the first data point relative to the third data sequence; obtain the historical amplitude difference corresponding to the third data sequence within the third window, the historical amplitude difference being used to indicate the average intensity of data value fluctuations in the third data sequence; and obtain the second detection result based on the difference between the maximum amplitude difference and the historical amplitude difference.
[0294] In some optional embodiments, the second acquisition module 1530 further includes: Sequence acquisition unit 1531 is used to acquire the periodic data sequence corresponding to the second period in the time-series data stream; Search unit 1532 is used to search for at least one second data point in the periodic data sequence based on dynamic programming. The second data point is used to indicate the data point in the periodic data sequence where the statistical characteristics of the data change. The filtering unit 1533 is used to filter the at least one second data point to obtain at least one second abnormal data point.
[0295] In some optional embodiments, the search unit 1532 is further configured to obtain a first cost function, which is used to measure the data fluctuation within the periodic data sequence; The search unit 1532 is further configured to search for the at least one second data point from the periodic data sequence with the objective of minimizing the function value of the first cost function.
[0296] In some optional embodiments, the first cost function includes a penalty term coefficient, which is used to indicate that during the search process for the second data point, the mean of the periodic data sequence is used to replace the weight of any data point; The search unit 1532 is further configured to dynamically adjust the penalty term coefficient with at least one iterative rule during the process of searching for the second data point from the periodic data sequence with the objective of minimizing the function value of the first cost function; The iteration rules include at least one of the following: During the search for subsequences in the periodic data sequence, if the density of the second data points found in the subsequence reaches the first density requirement, the penalty term coefficient is increased. During the search for a subsequence in the periodic data sequence, if the second data point is not found in the subsequence and the sequence stationarity of the subsequence is lower than the first stationarity threshold, the penalty term coefficient is reduced.
[0297] In some optional embodiments, the filtering unit 1533 is further configured to calculate the importance assessment value corresponding to the second data point based on the difference between the data distribution after the second data point in the time-series data stream and the data distribution of the periodic data sequence; The filtering unit 1533 is further configured to identify the second data point whose importance assessment value meets the importance requirement as the second abnormal data point.
[0298] In some optional embodiments, the generation module 1540 is further configured to calibrate the first abnormal data point using the second abnormal data point to obtain the abnormal identification result of the time-series data stream.
[0299] In some optional embodiments, the first abnormal data point is obtained by detecting the time-series data stream in a first cycle, and the second abnormal data point is obtained by detecting the time-series data stream in a second cycle, wherein the cycle length of the first cycle is shorter than the cycle length of the second cycle. The device further includes: Storage module 1550 is used to store the first abnormal data point as a historical abnormal data point in the first interval position corresponding to the first period in the historical information database. The historical information database is used to store the historical abnormal data points existing in the time-series data stream. The generation module 1540 further includes: The update unit 1541 is used to update the historical abnormal data points in the historical information database within the second interval position corresponding to the second period in response to obtaining the second abnormal data point.
[0300] In some optional embodiments, the update unit 1541 is further configured to, for the second abnormal data point of the i-th timestamp, add a data record of the historical abnormal data point of the i-th timestamp in the historical information database when the historical abnormal data point of the i-th timestamp is not recorded in the historical information database, where i is a positive integer; And / or, The update unit 1541 is further configured to delete the data record of the historical abnormal data point of the j-th timestamp in the historical information database when the historical abnormal data point of the j-th timestamp is recorded in the historical information database and there is no second abnormal data point of the j-th timestamp. Here, j is a positive integer.
[0301] In some optional embodiments, the first acquisition module 1520 is further configured to update the input strategy of the prediction model based on the historical information database, the prediction model being used to perform traffic prediction for the identification process of the first abnormal data point, and the input strategy being used to indicate the sequence range of the historical data sequence input to the prediction model.
[0302] In some alternative embodiments, the apparatus further includes: Alarm module 1560 is used to trigger an abnormal alarm for the first abnormal data point; The alarm module 1560 is further configured to roll back the abnormal alarm for the first abnormal data point if the second abnormal data point does not include the first abnormal data point that executed the abnormal alarm.
[0303] It should be noted that the apparatus provided in the above embodiments is only illustrated by the division of the above functional modules when implementing its functions. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the content structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.
[0304] Please refer to Figure 17 This diagram illustrates a structural block diagram of a computer device 1700 provided in one embodiment of this application. The computer device 1700 can be a terminal and / or a server, used to implement the anomaly identification method for time-series data streams provided in the above embodiments. Specifically: Typically, computer device 1700 includes a processor 1701 and a memory 1702.
[0305] Processor 1701 may include one or more processing cores, such as a quad-core processor, an octa-core processor, etc. Processor 1701 may be implemented using at least one hardware form selected from DSP (Digital Signal Processing), FPGA (Field Programmable Gate Array), and PLA (Programmable Logic Array). Processor 1701 may also include a main processor and a coprocessor. The main processor, also known as a CPU (Central Processing Unit), is used to process data in the wake-up state; the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, processor 1701 may integrate a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content required to be displayed on the screen. In some embodiments, processor 1701 may also include an AI (Artificial Intelligence) processor, which is used to handle computational operations related to machine learning.
[0306] The memory 1702 may include one or more computer-readable storage media, which may be non-transitory. The memory 1702 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices or flash memory devices. In some embodiments, the non-transitory computer-readable storage media in the memory 1702 is used to store a computer program configured to be executed by one or more processors to implement the above-described method for anomaly identification of time-series data streams.
[0307] In some embodiments, the computer device 1700 may also optionally include other components 1703: a peripheral device interface and at least one peripheral device. The processor 1701, memory 1702, and peripheral device interface can be connected via a bus or signal lines. Each peripheral device can be connected to the peripheral device interface via a bus, signal lines, or a circuit board. Specifically, the peripheral device includes at least one of: radio frequency circuitry, a display screen, audio circuitry, and a power supply.
[0308] Those skilled in the art will understand that Figure 17 The structure shown does not constitute a limitation on the computer device 1700, and may include more or fewer components than shown, or combine certain components, or use different component arrangements.
[0309] In an exemplary embodiment, a computer-readable storage medium is also provided, wherein a computer program is stored in the storage medium, and the computer program, when executed by a processor, implements the above-described method for anomaly identification of timing data streams. Optionally, the computer-readable storage medium may include: ROM (Read-Only Memory), RAM (Random Access Memory), SSD (Solid State Drives), or optical disc, etc. The random access memory may include ReRAM (Resistance Random Access Memory) and DRAM (Dynamic Random Access Memory).
[0310] In an exemplary embodiment, a computer program product is also provided, the computer program product including a computer program stored in a computer-readable storage medium. A processor of a terminal device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, causing the terminal device to perform the aforementioned anomaly identification method for timing data streams.
[0311] It should be noted that the data collection and processing in this application should strictly comply with the requirements of relevant national laws and regulations, obtain the informed consent or separate consent of the personal information subject, and carry out subsequent data use and processing within the scope of laws and regulations and the authorization of the personal information subject.
[0312] It should be understood that "multiple" as mentioned herein includes two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. Furthermore, the step numbers described herein are merely illustrative of one possible execution order. In some other embodiments, the steps may not be executed in numerical order, such as two steps with different numbers being executed simultaneously, or two steps with different numbers being executed in the reverse order of the illustration. This application does not limit this.
[0313] The above description is merely an exemplary embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A method for anomaly identification in a time-series data stream, characterized in that, The method includes: At least two data points are received in chronological order, and the at least two data points constitute a time-series data stream. Online anomaly detection is performed on the time-series data stream in the first period to obtain the first abnormal data point in the time-series data stream within the first period. The first abnormal data point represents a data point that deviates from the data distribution pattern of the time-series data stream in the first historical period. Offline variable point identification is performed on the time-series data stream in the second period to obtain a second abnormal data point in the time-series data stream where the statistical characteristics are abnormal in the second period. The second abnormal data point represents a data point that is abnormal in the statistical characteristic dimension. Anomaly identification results of the time-series data stream are generated based on the first and second abnormal data points.
2. The method according to claim 1, characterized in that, The time-series data stream contains at least one first data point within the first period, and the first data point includes a first timestamp and a first data value. The step of performing online anomaly detection on the time-series data stream in a first period to obtain the first abnormal data point in the time-series data stream within the first period includes: Obtain the historical data sequence of the time-series data stream within the first historical time period; Based on the historical data sequence, a first predicted value of the time-series data stream at the first timestamp is obtained; Based on the difference between the first data value and the first predicted value, a first detection result of the first data point is obtained. The first detection result is used to indicate the deviation of the first data point from the data distribution of the time-series data stream. Based on the first detection results corresponding to the at least one first data point, the first abnormal data point is determined from the at least one first data point.
3. The method according to claim 2, characterized in that, The step of predicting the first predicted value of the time-series data stream at the first timestamp based on the historical data sequence includes: The historical data sequence is decomposed to obtain a first trend term, a first seasonal term, and a first residual term corresponding to the historical data sequence. The first trend term is used to indicate the long-term trend of data points in the historical data sequence, the first seasonal term is used to indicate the periodic data repetition in the historical data sequence, and the first residual term is used to indicate random noise in the historical data sequence. Obtain the second trend term corresponding to the first trend term under the first future step, the second seasonal term corresponding to the first seasonal term under the first future step, and the second residual term corresponding to the first residual term under the first future step. The second trend term is the prediction result of the first trend term under the first future step, the second seasonal term is the prediction result of the first seasonal term under the first future step, and the second residual term is the prediction result of the first residual term under the first future step. The first future step is associated with the first timestamp. The second trend term, the second seasonal term, and the second residual term are synthesized to obtain the first predicted value of the time series data stream at the first timestamp.
4. The method according to claim 2 or 3, characterized in that, The step of obtaining a first detection result for the first data point based on the difference between the first data value and the first predicted value includes: The historical error information of the time-series data stream within the second historical time period is obtained, and the historical error information is used to indicate the error between the data value and the predicted value of the data point in the time-series data stream. Based on the difference between the first data value and the first predicted value, the current error information corresponding to the first data point is obtained; If the difference between the current error information and the historical error information reaches a first error threshold, the first data point is determined as the first abnormal data point and used as the first detection result. If the difference between the current error information and the historical error information does not reach the first error threshold, the first data point is determined as a normal data point and used as the first detection result.
5. The method according to claim 4, characterized in that, The method further includes: Obtain the stationarity detection result of the historical data sequence, the stationarity detection result being used to indicate the change of the statistical characteristics of the historical data sequence over time; If the stationary detection result indicates that the historical data sequence is a stationary sequence, a first error value is obtained as the first error threshold. If the stationary detection result indicates that the historical data sequence is a non-stationary sequence, a second error value is obtained as the first error threshold; the first error value is greater than the second error value.
6. The method according to claim 2 or 3, characterized in that, The step of determining the first abnormal data point from the at least one first data point based on the first detection results corresponding to the at least one first data point includes: A second detection result corresponding to the first data point is obtained based on at least one dynamic rule, and the second detection result is used to indicate the abnormal situation of the first data point under the determination of the dynamic rule. Based on the first detection result and the second detection result corresponding to each first data point within the first period, the first abnormal data point is determined from the at least one first data point; The dynamic rules include at least one of the following: The data waveform within the first window containing the first data point in the time-series data stream is obtained; the peak and trough frequencies corresponding to the data waveform within the first window are calculated; when the peak and trough frequencies reach a first frequency threshold, the first quantile of the first data sequence within the first window relative to the second data sequence within the second window is calculated, where the second window is a historical time period that includes and is greater than the first window; based on the difference between the first quantile and the first data value, the second detection result is obtained. Obtain the third data sequence within the third window prior to the first timestamp; calculate the absolute difference between the first data value and each data value in the third data sequence, and take the maximum value among the absolute differences as the maximum amplitude difference of the first data point relative to the third data sequence; obtain the historical amplitude difference corresponding to the third data sequence within the third window, the historical amplitude difference being used to indicate the average intensity of data value fluctuations in the third data sequence; and obtain the second detection result based on the difference between the maximum amplitude difference and the historical amplitude difference.
7. The method according to any one of claims 1 to 3, characterized in that, The offline change point identification performed on the time-series data stream in the second period to obtain a second abnormal data point in which the statistical characteristics of the time-series data stream are abnormal within the second period includes: Obtain the periodic data sequence corresponding to the second period in the time-series data stream; At least one second data point is obtained by searching within the periodic data sequence based on dynamic programming. The second data point is used to indicate the data point in the periodic data sequence where the statistical characteristics of the data change. By filtering the at least one second data point, at least one second abnormal data point is obtained.
8. The method according to claim 7, characterized in that, The process of searching for at least one second data point within the periodic data sequence based on dynamic programming includes: Obtain a first cost function, which is used to measure the data fluctuation within the periodic data sequence; The at least one second data point is obtained from the periodic data sequence with the objective of minimizing the function value of the first cost function.
9. The method according to claim 8, characterized in that, The first cost function includes a penalty term coefficient, which is used to indicate that during the search process for the second data point, the mean of the periodic data sequence is used to replace the weight of any data point. The method further includes: In the process of searching for the second data point from the periodic data sequence with the objective of minimizing the function value of the first cost function, the coefficient of the penalty term is dynamically adjusted according to at least one iterative rule; The iteration rules include at least one of the following: During the search for subsequences in the periodic data sequence, if the density of the second data points found in the subsequence reaches the first density requirement, the penalty term coefficient is increased. During the search for a subsequence in the periodic data sequence, if the second data point is not found in the subsequence and the sequence stationarity of the subsequence is lower than the first stationarity threshold, the penalty term coefficient is reduced.
10. The method according to claim 7, characterized in that, The step of filtering the at least one second data point to obtain at least one second abnormal data point includes: Based on the difference between the data distribution after the second data point in the time-series data stream and the data distribution of the periodic data sequence, the importance assessment value corresponding to the second data point is calculated. The second data point whose importance assessment value meets the importance requirement is designated as the second outlier data point.
11. The method according to any one of claims 1 to 3, characterized in that, The generation of the anomaly identification result of the time-series data stream based on the first and second anomaly data points includes: The first abnormal data point is calibrated using the second abnormal data point to obtain the abnormal identification result of the time-series data stream.
12. The method according to claim 11, characterized in that, The first abnormal data point is obtained by detecting the time-series data stream in a first cycle, and the second abnormal data point is obtained by detecting the time-series data stream in a second cycle, wherein the cycle length of the first cycle is shorter than the cycle length of the second cycle. After performing online anomaly detection on the time-series data stream in a first period to obtain the first abnormal data point in the time-series data stream within the first period, the method further includes: The first abnormal data point is stored as a historical abnormal data point in the first interval position corresponding to the first period in the historical information database. The historical information database is used to store historical abnormal data points existing in the time-series data stream. The step of calibrating the first abnormal data point using the second abnormal data point to obtain the anomaly identification result of the time-series data stream includes: In response to obtaining the second abnormal data point, the historical abnormal data point in the second interval position corresponding to the second period in the historical information database is updated using the second abnormal data point.
13. The method according to claim 12, characterized in that, The step of using the second abnormal data point to update the historical abnormal data point in the historical information database within the second interval corresponding to the second period includes: For the second abnormal data point with the i-th timestamp, if the historical abnormal data point with the i-th timestamp is not recorded in the historical information database, a new data record for the historical abnormal data point with the i-th timestamp is added to the historical information database, where i is a positive integer; If the historical abnormal data point with the j-th timestamp is recorded in the historical information database, and there is no second abnormal data point with the j-th timestamp, then delete the data record of the historical abnormal data point with the j-th timestamp from the historical information database, where j is a positive integer.
14. The method according to claim 12, characterized in that, After responding to obtaining the second abnormal data point and using the second abnormal data point to update the historical abnormal data points in the historical information database within the second interval position corresponding to the second period, the method further includes: Based on the historical information database, the input strategy of the prediction model is updated. The prediction model is used to perform traffic prediction for the identification process of the first abnormal data point. The input strategy is used to indicate the sequence range of the historical data sequence input to the prediction model.
15. The method according to any one of claims 1 to 3, characterized in that, After performing online anomaly detection on the time-series data stream in a first period to obtain the first abnormal data point in the time-series data stream within the first period, the method further includes: Trigger an anomaly alarm for the first abnormal data point; After generating the anomaly identification result of the time-series data stream based on the first and second anomaly data points, the method further includes: If the second abnormal data point does not include the first abnormal data point for which an abnormal alarm was executed, roll back the abnormal alarm for the first abnormal data point.
16. An anomaly detection device for a time-series data stream, characterized in that, The device includes: The receiving module is configured to receive at least two data points in chronological order, wherein the at least two data points constitute a time-series data stream; The first acquisition module is used to perform online anomaly detection on the time-series data stream in a first period to obtain the first abnormal data point in the time-series data stream within the first period. The first abnormal data point represents a data point that deviates from the data distribution pattern of the time-series data stream in a first historical period. The second acquisition module is used to perform offline change point identification on the time series data stream in the second period to obtain a second abnormal data point in which the statistical characteristics of the time series data stream are abnormal in the second period. The second abnormal data point represents a data point that is abnormal in the statistical characteristic dimension. The generation module is used to generate anomaly identification results of the time-series data stream based on the first abnormal data point and the second abnormal data point.
17. A computer device, characterized in that, The computer device includes a processor and a memory, the memory storing a computer program, which is loaded and executed by the processor to implement the anomaly identification method for time-series data streams as described in any one of claims 1 to 15.
18. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which is loaded and executed by a processor to implement the anomaly identification method for time-series data streams as described in any one of claims 1 to 15.
19. A computer program product, characterized in that, The computer program product includes a computer program stored in a computer-readable storage medium, and a processor reads from and executes the computer program to implement the anomaly identification method for time-series data streams as described in any one of claims 1 to 15.