A method and system for intelligent early warning of leased network quality
By constructing a global micro-packet loss prediction model and multimodal fusion recognition technology, the problem of timely detection and handling of micro-packet loss issues in traditional network monitoring methods has been solved, realizing intelligent early warning and dynamic monitoring of leased network, and improving network quality and user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ANHUI SANQI JIYU NETWORK TECH CO LTD
- Filing Date
- 2026-03-06
- Publication Date
- 2026-06-02
AI Technical Summary
Traditional network monitoring methods cannot detect and handle micro-packet loss issues in dedicated networks in a timely manner, which affects the stability, continuity and security of business in high-concurrency business scenarios and degrades the user experience.
Multi-source packet loss time-series data is acquired by a sliding time window collector. A global micro-packet loss prediction model is constructed by fusing the multi-source packet loss time-series data using a federated learning framework. A multi-modal fusion identification is performed by combining the CNN-GAN combined model to locate the root cause of the anomaly, and a reinforcement learning model is invoked to dynamically adjust the monitoring strategy.
It enables timely detection and accurate assessment of micro-packet loss issues in leased network, improves the efficiency and accuracy of network quality monitoring, enhances user experience and system security, and increases adaptability and resilience.
Smart Images

Figure CN122137733A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network quality monitoring technology, and in particular to an intelligent early warning method and system for dedicated line network quality. Background Technology
[0002] With the rapid development of network technology, network quality monitoring technology is increasingly being applied in high-concurrency services and microservice architectures. As a crucial infrastructure ensuring the stable operation of critical services, the stability and reliability of leased networks are of paramount importance. However, in actual network operation, leased networks frequently experience micro-packet loss, posing a significant challenge to network quality monitoring.
[0003] Traditional network monitoring methods primarily rely on preset thresholds for alerts. Specifically, the system only triggers an alarm mechanism when the network packet loss rate reaches or exceeds a preset fixed threshold. However, this method has significant limitations when dealing with micro-packet loss issues in dedicated network lines, particularly in the following scenarios: On the one hand, the business may not experience packet loss in the short term, or the packet loss rate may not reach the preset threshold. However, there may be persistent micro-packet loss over a longer period of time (such as several hours or even more than a day). Traditional monitoring methods only focus on whether the short-term packet loss rate exceeds the threshold, and cannot effectively detect this long-term, micro-packet loss trend, resulting in the micro-packet loss problem not being detected and handled in a timely manner.
[0004] On the other hand, in traditional business scenarios, such minor packet loss may have a small impact on operations, and businesses may not be sensitive to it. However, in high-concurrency business scenarios, the impact of minor packet loss is amplified. Because high-concurrency businesses have extremely high requirements for the real-time performance and accuracy of data transmission, even minor packet loss can lead to data loss or business errors, thereby affecting the normal operation of the business.
[0005] The limitations of the aforementioned traditional monitoring methods have led to a series of key technical issues: 1. Efficiency Issues: Traditional network monitoring methods cannot detect and handle micro-packet loss issues in a timely manner, causing micro-packet loss to persist and thus affecting business stability. For example, in some financial transaction businesses with extremely high real-time requirements, micro-packet loss may lead to delays or loss of transaction data transmission, affecting the smooth progress of transactions and reducing business processing efficiency.
[0006] 2. Effectiveness Issues: Because traditional monitoring methods cannot detect long-term trends in micro-packet loss, they are prone to missing micro-packet loss issues. This may result in some potential network problems not being resolved in a timely manner, affecting business continuity and reliability. For example, in a company's critical business systems, continuous micro-packet loss may gradually accumulate, eventually causing system failures and business interruptions.
[0007] 3. User Experience Issues: Failure to detect and address micro-packet loss issues in a timely manner can lead to slow data loading and page lag when using network services. These problems are particularly pronounced in high-concurrency scenarios, thus degrading the user experience. For example, in online video playback, micro-packet loss can cause video stuttering and audio desynchronization, affecting the user's viewing experience.
[0008] 4. Security Issues: Failure to promptly detect and handle micro-packet loss issues may lead to the loss or corruption of business data during transmission, thereby affecting the overall security of the system. For example, in business systems involving sensitive user information, data loss may result in the leakage of user information, posing serious security risks to users and the enterprise. Summary of the Invention
[0009] The purpose of this invention is to provide a method and system for intelligent early warning of leased network quality, which can promptly detect micro-packet loss problems in leased networks, accurately determine the root cause of anomalies, and realize intelligent early warning and dynamic monitoring strategy adjustment, so as to solve at least one of the above-mentioned problems in the prior art.
[0010] In a first aspect, the present invention provides an intelligent early warning method for leased line network quality, the method specifically comprising: Multi-source packet loss time series data are acquired by a sliding time window collector, and a global micro-packet loss prediction model is constructed by fusing the multi-source packet loss time series data using a federated learning framework. The global micro-packet loss prediction model is used to fit the current packet loss time series data to generate the corresponding predicted data sequence; Multi-timescale comparative analysis is performed based on the fused multi-source packet loss time series data and predicted data sequence to detect data offset. If offset is detected, a multimodal image generation engine is activated to generate a multimodal image set including packet loss rate curve, spectrum and wavelet transform. Based on a multimodal image set, a CNN-GAN combined model is called to perform multimodal fusion recognition to determine whether there are continuous fluctuation features and to locate the root cause of the anomaly. Based on the output of multimodal fusion identification and the location results of abnormal root causes, the alarm confidence is evaluated to trigger an alarm, and the reinforcement learning model is invoked to dynamically adjust the monitoring strategy in combination with historical alarm feedback.
[0011] Secondly, the present invention provides a dedicated line network quality intelligent early warning system, the system specifically comprising: The data acquisition module is used to acquire multi-source packet loss time series data through a sliding time window collector, and to fuse the multi-source packet loss time series data using a federated learning framework to build a global micro-packet loss prediction model. The time series prediction module is used to fit the current packet loss time series data using a global micro-packet loss prediction model and generate the corresponding predicted data sequence. The offset detection module is used to perform multi-timescale comparative analysis based on the fused multi-source packet loss time series data and the predicted data sequence to detect data offset. If an offset is detected, the multimodal image generation engine is started to generate a multimodal image set including packet loss rate curve, spectrum and wavelet transform. The anomaly localization module is used to perform multimodal fusion recognition based on a multimodal image set by calling a CNN-GAN combined model to determine whether there are continuous fluctuation features and to locate the root cause of the anomaly. The alarm triggering module is used to evaluate the alarm confidence based on the output of multimodal fusion identification and the location results of abnormal root causes to trigger an alarm, and to call the reinforcement learning model to dynamically adjust the monitoring strategy in combination with historical alarm feedback.
[0012] Thirdly, the present invention provides a computer device, comprising: a memory and a processor, and a computer program stored in the memory, wherein when the computer program is executed on the processor, it implements the intelligent early warning method for leased network quality as described in any of the above methods.
[0013] Fourthly, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the intelligent early warning method for leased network quality as described in any of the above methods.
[0014] Compared with the prior art, the present invention has at least one of the following technical effects: 1. This invention can promptly detect micro-packet loss issues in leased network and accurately determine the root cause of the anomaly, enabling intelligent early warning and dynamic monitoring strategy adjustment, thereby improving the efficiency of leased network quality monitoring, enhancing user experience, and ensuring system security.
[0015] 2. This invention enables precise intelligent early warning and dynamic monitoring strategy optimization for micro-packet loss issues in leased network, effectively improving the timeliness, accuracy, and adaptability of network quality monitoring.
[0016] 3. This invention utilizes a federated learning framework to integrate multi-source packet loss time-series data to construct a global model, which not only protects the data privacy of each dedicated line node, but also integrates the data features of multiple nodes, thereby improving the accuracy and generalization ability of the micro-packet loss prediction model.
[0017] 4. This invention detects data offset through multi-timescale comparative analysis, which can promptly identify abnormal changes in packet loss data and generate a multimodal image set to provide rich and intuitive data support for subsequent accurate judgment of abnormal features and location of root causes.
[0018] 5. This invention generates time-series curves, spectrograms, and wavelet transform spectrograms of packet loss rate, respectively, to display the characteristics of packet loss data from different dimensions, comprehensively reflecting the time, frequency, and time-frequency characteristics of packet loss, which helps to accurately identify abnormal patterns.
[0019] 6. This invention uses a CNN-GAN combined model for multimodal fusion recognition, giving full play to the advantages of convolutional neural network feature extraction and generative adversarial network discrimination classification, accurately judging continuous fluctuation features and locating the root cause of anomalies.
[0020] 7. This invention constructs a generative adversarial network and optimizes the discriminator, utilizing its powerful feature learning and classification capabilities to accurately output confidence probability values representing continuous fluctuation features, providing a reliable basis for judging anomalies.
[0021] 8. This invention constructs a training set based on historical data and trains a neural network classification model, enabling the model to learn the characteristic patterns of different abnormal root causes, laying the foundation for accurate inference of abnormal root cause categories in the future.
[0022] 9. This invention inputs a global feature tensor into a pre-trained model for inference, generates a probability distribution vector through feature transformation and calculation, and selects the category with the highest confidence as the target root cause, thereby improving the accuracy of anomaly root cause localization.
[0023] 10. This invention calculates the comprehensive alarm confidence based on multiple factors and makes alarm decisions. It calls a reinforcement learning model and combines historical feedback to dynamically adjust the monitoring strategy, thereby achieving adaptive optimization of the monitoring strategy and improving the monitoring effect. Attached Figure Description
[0024] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 This is a flowchart illustrating an intelligent early warning method for leased network quality according to an embodiment of the present invention; Figure 2 This is a schematic diagram of the structure of a dedicated line network quality intelligent early warning system provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present invention. Detailed Implementation
[0026] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.
[0027] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.
[0028] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.
[0029] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."
[0030] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0031] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0032] In this application embodiment, the entity executing the process includes a terminal device. This terminal device includes, but is not limited to, devices capable of executing the methods disclosed in this application, such as servers, computers, smartphones, and tablets. Figure 1 A flowchart illustrating an embodiment of the intelligent early warning method for leased network quality disclosed in this invention is shown below, detailed in the following description: S101: Multi-source packet loss time series data is acquired by a sliding time window collector, and a global micro-packet loss prediction model is constructed by fusing the multi-source packet loss time series data using a federated learning framework. S102, use the global micro-packet loss prediction model to fit the current packet loss time series data and generate the corresponding prediction data sequence; S103, based on the fused multi-source packet loss time series data and the predicted data sequence, perform multi-time scale comparative analysis to detect data offset. If an offset is detected, start the multimodal image generation engine to generate a multimodal image set including packet loss rate curve, spectrum and wavelet transform. S104, based on a multimodal image set, calls the CNN-GAN combined model to perform multimodal fusion recognition to determine whether there are continuous fluctuation features and locate the root cause of the anomaly; S105: Based on the output of multimodal fusion identification and the location results of abnormal root causes, evaluate the alarm confidence to trigger an alarm, and call the reinforcement learning model to dynamically adjust the monitoring strategy in combination with historical alarm feedback.
[0033] In this embodiment, a sliding time window collector is used to acquire multi-source packet loss time-series data. The sliding time window collector can continuously collect packet loss-related time-series data from various monitoring points of the leased network according to a preset time interval and window size. This data covers packet loss information in different locations, different devices, and different business scenarios, ensuring the comprehensiveness and diversity of the data.
[0034] After acquiring multi-source packet loss time-series data, a federated learning framework is used to fuse this data. The federated learning framework allows each data source to train its model locally, sharing and aggregating only the model parameters, without requiring centralized transmission of the original data, thus effectively protecting data privacy and security. Through the federated learning framework, packet loss time-series data from different domains are fused to construct a global micro-packet loss prediction model. This model can comprehensively consider information from multiple data sources, more accurately capturing the characteristics and patterns of micro-packet loss in leased line networks.
[0035] The pre-constructed global micro-packet loss prediction model is used to fit the currently collected packet loss time-series data. Through learning and analyzing historical data, the global micro-packet loss prediction model has grasped the changing trends and patterns of packet loss rate. When current packet loss time-series data is input, the model can generate a corresponding predicted data sequence based on its internal learning mechanism. This predicted data sequence reflects the possible changes in the packet loss rate of the leased network over a future period, providing important evidence for subsequent anomaly detection and early warning.
[0036] Based on the fused multi-source packet loss time-series data and the generated predicted data sequence, multi-time-scale comparative analysis is performed to detect data offset. This analysis compares the actual collected packet loss data and the predicted data across different time dimensions (e.g., short-term, medium-term, long-term). By setting reasonable thresholds and judgment rules, it detects whether there is an offset between the actual and predicted data. If a data offset is detected, it indicates a possible anomaly in the leased network, at which point the multimodal image generation engine is activated.
[0037] The multimodal image generation engine generates a multimodal image set, including a packet loss rate curve, a spectrogram, and a wavelet transform graph, based on the detected data offset. The packet loss rate curve visually displays the trend of packet loss rate over time; the spectrogram analyzes the lost signal in the frequency domain, revealing its frequency characteristics; and the wavelet transform graph analyzes the lost signal from both time and frequency dimensions, more accurately capturing its local features. These three types of images reflect the packet loss situation of the leased network from different perspectives, providing rich information for subsequent anomaly identification.
[0038] Based on the generated multimodal image set, a CNN-GAN combined model is used for multimodal fusion recognition. CNNs (Convolutional Neural Networks) possess powerful feature extraction capabilities, effectively extracting and analyzing various features from multimodal images; GANs (Generative Adversarial Networks) can further improve the model's recognition accuracy and robustness through adversarial training between the generator and discriminator. The CNN-GAN combined model combines the feature extraction capabilities of CNNs with the generative adversarial mechanism of GANs, enabling it to determine whether continuous fluctuation features exist in multimodal images.
[0039] If continuous fluctuations are observed, it indicates an anomaly in the leased network. Further investigation is needed to pinpoint the root cause. Through in-depth analysis of multimodal images and by combining information such as network topology and device status, the specific cause of the micro-packet loss problem can be determined, such as a network device malfunction, line aging, or external interference.
[0040] Based on the output of multimodal fusion recognition and the results of anomaly root cause localization, the alarm confidence level is evaluated. The alarm confidence level comprehensively considers factors such as the prominence of the anomaly features and the severity of the anomaly root cause, used to determine whether an alarm needs to be triggered and the urgency level of the alarm. When the alarm confidence level reaches a preset threshold, the alarm mechanism is triggered to promptly notify relevant personnel for handling.
[0041] Simultaneously, a reinforcement learning model is invoked to dynamically adjust monitoring strategies based on historical alarm feedback. The reinforcement learning model can learn the optimal monitoring strategy based on the handling and effectiveness of historical alarms. For example, if a monitoring strategy is ineffective in handling a specific type of micro-packet loss, the reinforcement learning model will adjust and optimize the strategy based on historical feedback information to improve the accuracy and effectiveness of subsequent monitoring. Through continuous learning and adjustment, the intelligent early warning method for leased network quality can adapt to the ever-changing network environment and business needs.
[0042] This embodiment can promptly detect and handle micro-packet loss issues in leased network, improve service stability, continuity and reliability, enhance user experience, and ensure system security.
[0043] In some embodiments, step S101 above, which involves acquiring multi-source packet loss time-series data through a sliding time window collector, fusing the multi-source packet loss time-series data using a federated learning framework, and constructing a global micro-packet loss prediction model, specifically includes: Local packet loss time series data of each node is obtained by a sliding time window collector deployed at multiple dedicated line nodes. Based on local packet loss time series data, each dedicated line node is used as a client of federated learning to train a local micro-packet loss prediction model. After training is complete, the local model parameters of each client are encrypted and uploaded to the federated learning server; Based on the federated learning server, a secure aggregation algorithm is used to aggregate the local model parameters of multiple clients to obtain the global model parameters. The global model parameters are distributed to each client, enabling the client to update its local model based on the global model parameters; Repeat the federated learning training steps until the global model converges to obtain the global micro-packet loss prediction model.
[0044] In this embodiment, sliding time window collectors are deployed on multiple key nodes of the leased network. These collectors continuously collect local packet loss time-series data at each leased node according to a pre-set time window size and sliding step. For example, the time window can be set to 10 minutes per window, with a sliding step of 5 minutes. This allows the collector to acquire packet loss data for a new 10-minute time period every 5 minutes, thus comprehensively and meticulously recording the packet loss situation of each node at different times, providing a rich and accurate data foundation for subsequent model training.
[0045] Each dedicated line node acts as a client for federated learning. Using the local packet loss time-series data collected by each client, a local micro-packet loss prediction model is independently trained. During training, each client, based on its own data characteristics, employs appropriate machine learning algorithms (such as neural network algorithms) to learn and analyze the data, in order to build a model capable of initially predicting local packet loss. For example, a client's local data may exhibit a high packet loss rate during a specific time period. Through training, the local model can learn this pattern, thereby making a preliminary prediction of potential packet loss during that time period.
[0046] After each client completes the training of its local micro-packet loss prediction model, to protect data privacy and security and prevent model parameters from being leaked or tampered with during transmission, the locally trained model parameters are encrypted. Common symmetric or asymmetric encryption algorithms can be used to ensure the confidentiality and integrity of the parameters during transmission. After encryption, the encrypted local model parameters are uploaded to the federated learning server.
[0047] After receiving encrypted local model parameters uploaded by each client, the federated learning server uses a secure aggregation algorithm to aggregate these parameters. This algorithm can merge model parameters from multiple clients to obtain global model parameters without revealing the original data and model parameters of each client. For example, this algorithm can integrate valid information from the model parameters of each client through specific mathematical operations and encryption mechanisms, removing noise caused by individual differences, thereby obtaining global model parameters that reflect the packet loss characteristics of the entire leased network.
[0048] The federated learning server distributes the aggregated global model parameters to each client. Upon receiving these parameters, each client updates its locally trained micro-packet loss prediction model. By integrating the global model parameters into the local model, the local model not only retains features trained on its own data but also absorbs feature information from other clients' data, thereby improving the model's accuracy and generalization ability.
[0049] After the global model parameters are distributed and the local model is updated, the local model training phase begins again. Each client uses the updated local model to collect new local packet loss time-series data and performs a new round of training based on the new data. After training, the local model parameters are encrypted and uploaded to the federated learning server for aggregation. Then, the new global model parameters are distributed to the clients to update their local models. This process is iterated, repeating the federated learning training steps until the global model converges. When the global model converges, it means that the model's prediction performance on the data from each client has reached a relatively stable and optimal state. The resulting global micro-packet loss prediction model can accurately and comprehensively predict micro-packet loss in the leased network, providing a reliable basis for subsequent network quality early warning.
[0050] In some embodiments, step S102 above, which involves fitting the current packet loss time series data using a global micro-packet loss prediction model to generate a corresponding prediction data sequence, specifically includes: Standardize and preprocess the current packet loss time series data acquired in real time by the sliding time window collector; The standardized preprocessed current packet loss time series data is input into the global micro-packet loss prediction model. The forward propagation calculation is performed through the multi-layer neural network inside the global micro-packet loss prediction model to obtain a set of packet loss rate prediction values for future periods. Based on the set of predicted packet loss rates, a predicted data sequence corresponding to the current observation period is generated in chronological order.
[0051] In this embodiment, the sliding time window collector continuously acquires real-time packet loss time-series data of the leased network. This data may vary significantly in numerical range and distribution characteristics due to factors such as the acquisition environment and equipment differences. To better adapt the data to the input requirements of the global micro-packet loss prediction model and improve the model's training effect and prediction accuracy, this real-time acquired packet loss time-series data needs to be standardized preprocessed. Standardization preprocessing can employ common methods, such as scaling the data according to certain rules to ensure its numerical range falls within a specific interval, or normalizing the data to give it similar statistical characteristics, such as a mean of 0 and a standard deviation of 1. Such preprocessing eliminates the influence of different dimensions and abnormal fluctuations between data points, providing standardized and uniform data input for subsequent model processing. For example, if the acquired packet loss rate data ranges from 0% to 50%, after standardization preprocessing, it may be mapped to the 0-1 interval, making data collected from different nodes and at different times comparable.
[0052] The preprocessed data is input into the global micro-packet loss prediction model for forward propagation calculation. The standardized, preprocessed current packet loss time-series data is then fed into the pre-built global micro-packet loss prediction model. This model employs a multi-layered neural network structure. These neural network layers, through specific connection methods and weight parameters, can perform complex nonlinear transformations and feature extraction on the input data. When data enters the model, it begins at the input layer and proceeds through each hidden layer for forward propagation calculation. In each layer, neurons perform calculations based on the input data and their own weights, biases, and other parameters, and pass the results to the next layer. Through the forward propagation calculation of the multi-layered neural network, the model can fully explore the potential patterns and features in the packet loss time-series data, thereby predicting the packet loss rate for future periods. For example, the model may learn the changing trends of the packet loss rate over different time periods and its correlation with factors such as network traffic, and then make reasonable inferences about future situations based on these patterns.
[0053] After forward propagation calculations by the multi-layer neural network within the global micro-packet loss prediction model, a set of predicted packet loss rates for future time periods is obtained. These predicted values reflect the model's estimation of packet loss rates at different future time points. To make the prediction results more intuitive and easier for subsequent analysis and processing, a predicted data sequence corresponding to the current observation period needs to be generated based on this set of predicted packet loss rates in chronological order. For example, if the current observation period is the past hour, and one data point is collected every 10 minutes, then the predicted data sequence can generate one predicted value every 10 minutes according to the time span of the next hour, forming a data sequence containing 6 predicted values. This sequence can clearly show the model's prediction of future changes in packet loss rates, providing important data support for subsequent steps such as data offset detection and anomaly identification.
[0054] In some embodiments, in step S103 above, the step of performing multi-timescale comparative analysis based on the fused multi-source packet loss time-series data and predicted data sequence to detect data offset, and if offset is detected, activating the multimodal image generation engine to generate a multimodal image set including packet loss rate curves, spectrograms, and wavelet transform graphs, specifically includes: The fused multi-source packet loss time series data and the predicted data sequence are time-aligned to obtain the packet loss data sequence. Based on the packet loss data sequence, feature comparison calculations are performed on multiple preset time statistical scales to obtain the contrast values at each scale. Based on the comparison results of the contrast values at each scale with their respective preset thresholds, a comprehensive determination is made as to whether data shift has occurred. When a data offset is determined to occur, based on the packet loss data sequence, a multimodal image generation model is used to generate a packet loss rate time series curve for the first mode, a packet loss spectrum for the second mode, and a wavelet transform time spectrum for the third mode. Aggregate the packet loss rate time series curve, packet loss spectrum, and wavelet transform time spectrum, and output a multimodal image set.
[0055] In this embodiment, since the fused multi-source packet loss time-series data and the predicted data sequence may come from different data sources, and the collection time points may not correspond exactly, time alignment processing is required to accurately perform subsequent comparative analysis. The time alignment process can be based on a unified time benchmark, matching and integrating data corresponding to the same time point in the multi-source packet loss time-series data and the predicted data sequence. For example, if the multi-source packet loss time-series data is collected at 10-minute intervals, while the predicted data sequence is generated at 5-minute intervals, then interpolation, aggregation, and other methods are needed to unify them to the same time interval, ultimately obtaining a complete packet loss data sequence with one-to-one time point correspondence. This sequence integrates raw and predicted information from multiple domains, providing a comprehensive data foundation for subsequent analysis.
[0056] To comprehensively detect data offset, it is necessary to analyze the packet loss data sequence at different time scales. Multiple different statistical time scales can be preset, such as short time scales (e.g., 10 minutes), medium time scales (e.g., 1 hour), and long time scales (e.g., 1 day). At each statistical time scale, feature extraction and comparative calculations are performed on the packet loss data sequence. For example, at a short time scale, the average, maximum, and minimum packet loss rates can be calculated; at a medium time scale, the trend and fluctuation range of the packet loss rate can be analyzed; and at a long time scale, the periodic variation of the packet loss rate can be observed. Through these calculations, contrast values are obtained at each statistical time scale. These metrics can reflect the characteristic changes of the packet loss data sequence at that scale from different perspectives.
[0057] Based on the comparison results of the contrast values at each scale with their respective preset thresholds, a comprehensive determination is made as to whether a data shift has occurred. For each time statistical scale, a corresponding threshold needs to be preset. These thresholds are determined comprehensively based on factors such as historical data of the leased network, business requirements, and network quality standards. The contrast value at each scale is compared with the corresponding preset threshold. If the contrast value at a certain scale exceeds its preset threshold, it indicates an abnormal change in the packet loss data sequence at that time scale. However, an anomaly at only one scale does not necessarily mean that a data shift has occurred; therefore, a comprehensive judgment is needed based on the comparison results of all scales. For example, if the contrast values at short and medium time scales both exceed the threshold, while the contrast value at a long time scale is close to the threshold but does not exceed it, considering the business scenario and network characteristics, a data shift can be determined. Conversely, if the contrast value at only one scale slightly exceeds the threshold, while other scales are normal, it may only be a localized, occasional fluctuation and not considered a data shift.
[0058] When a data offset is detected, multiple modal graphs are generated based on the packet loss data sequence. Specifically, a multimodal image generation model generates a packet loss rate time-series curve for the first modality, a packet loss spectrum for the second modality, and a wavelet transform time-spectrum graph for the third modality. The packet loss rate time-series curve visually displays the change in packet loss rate over time; the fluctuations of the curve clearly show the magnitude and trend of the packet loss rate at different time points. The packet loss spectrum analyzes the packet loss rate signal in the frequency domain, reflecting the distribution of different frequency components in the packet loss rate signal, which helps to identify whether there are periodic fluctuations in the packet loss rate. The wavelet transform time-spectrum graph combines information from both the time and frequency domains, simultaneously displaying the changes in the packet loss rate at different times and frequencies, which is crucial for analyzing the local characteristics and non-stationary properties of the packet loss rate. By generating these three different modal graphs, the packet loss data sequence can be visualized from multiple perspectives, providing rich information for subsequent anomaly analysis and judgment.
[0059] The generated packet loss rate time-series curves, packet loss spectrum graphs, and wavelet transform spectrum graphs are aggregated to form a complete multimodal image set. This image set integrates graphs from different modalities, allowing analysts to view multiple pieces of information simultaneously in a unified interface, providing a more comprehensive and accurate understanding of the characteristics and anomalies of the packet loss data sequence. For example, analysts can observe the multimodal image set and compare the features displayed in different graphs to quickly locate the time period and frequency range of packet loss anomalies, thus providing strong support for further pinpointing the root cause of the anomaly and taking appropriate measures.
[0060] Furthermore, the step of generating a time-series curve of packet loss rate for the first mode, a packet loss spectrum for the second mode, and a wavelet transform time-series spectrum for the third mode based on the packet loss data sequence using a multimodal image generation model specifically includes: Based on the packet loss data sequence and its corresponding timestamp, a time series curve of packet loss rate changing with time is plotted in a time coordinate system to generate the time series curve of the first mode. After preprocessing the lost data sequence by frequency domain transformation, the frequency domain amplitude spectrum is calculated using the Fourier transform algorithm, and the frequency domain amplitude spectrum is plotted in the frequency coordinate system to generate the lost spectrum of the second mode. Time-frequency analysis is performed on the lost data sequence. Its energy distribution on the time-frequency plane is calculated by continuous wavelet transform, and the energy distribution is visualized as a grayscale or color image to generate the wavelet transform time-frequency spectrum of the third mode.
[0061] In this embodiment, the packet loss rate value and precise timestamp information corresponding to each data point are extracted from the acquired packet loss data sequence. These timestamps accurately record the specific time when each packet loss data point was generated, providing a basis for subsequent location of the data point in the time coordinate system. Next, a two-dimensional time coordinate system is established, where the horizontal axis represents time and the vertical axis represents the packet loss rate. Then, according to the chronological order of the timestamps, each data point in the packet loss data sequence is located sequentially in the time coordinate system. Specifically, for each data point, its position on the horizontal axis is determined by its corresponding timestamp, and its position on the vertical axis is determined by its packet loss rate value, and a marker point is drawn at that position. Finally, these marker points are connected sequentially according to time order to form a continuous curve. This curve clearly shows the trend of packet loss rate changes over time, such as whether the packet loss rate continues to rise, fall, or remain stable within a certain period of time, thus generating a time-series curve of packet loss rate for the first mode. This image can intuitively reflect the dynamic changes of packet loss rate in the time dimension, providing an important basis for analyzing short-term and long-term changes in network quality.
[0062] Before generating the packet loss spectrum, the packet loss data sequence needs to undergo frequency domain transformation preprocessing. This preprocessing mainly aims to convert the packet loss data from the time domain to the frequency domain for subsequent frequency domain analysis. Preprocessing methods may include zero-mean normalization to eliminate DC components and make the data more suitable for frequency domain transformation. After preprocessing, the packet loss data sequence is calculated using the Fourier transform algorithm. The Fourier transform is an important tool for converting time-domain signals to frequency-domain signals. This algorithm can decompose the packet loss data sequence into a superposition of sine and cosine components of different frequencies, thus obtaining the frequency domain amplitude spectrum. The frequency domain amplitude spectrum reflects the intensity of each frequency component in the packet loss data. Next, a two-dimensional frequency coordinate system is established, where the horizontal axis represents frequency and the vertical axis represents amplitude. Then, according to the amplitude of each frequency component in the frequency domain amplitude spectrum, corresponding marker points are plotted in the frequency coordinate system. Specifically, for each frequency component, its position on the horizontal axis is determined by its frequency value, and its position on the vertical axis is determined by its amplitude value, and a marker point is plotted at that position. Finally, these marker points are connected to form a curve representing the frequency domain amplitude as a function of frequency, thus generating the packet loss spectrum of the second mode. This image helps analysts understand the distribution of different frequency components in the packet loss data, such as whether there is a particular frequency of packet loss that is more prominent, providing important clues for locating the frequency characteristics of network faults.
[0063] When performing time-frequency analysis on packet loss data sequences, the continuous wavelet transform method is employed. The continuous wavelet transform is an effective tool capable of simultaneously analyzing the time and frequency domain characteristics of signals in the time-frequency plane. First, a suitable wavelet basis function is selected. The choice of wavelet basis function affects the results of the time-frequency analysis; different business scenarios and network characteristics may require different wavelet basis functions to obtain the best analysis results. Then, the selected continuous wavelet transform algorithm is used to calculate the energy distribution of the packet loss data sequence. Through calculation, the energy distribution of the packet loss data in the time-frequency plane can be obtained. The energy distribution reflects the intensity of the packet loss data at different times and frequencies, revealing the dynamic changes of the packet loss phenomenon in the time-frequency domain. Next, the calculated energy distribution is visualized. Visualization can be performed using grayscale or color images. If using a grayscale image, areas with higher energy intensity are represented by brighter grayscale values, and areas with lower energy intensity are represented by darker grayscale values. If using a color image, different colors can be assigned according to the energy intensity; for example, high energy intensity is represented by red, and low energy intensity by blue, etc. This visualization method clearly displays the energy distribution in the image, generating a wavelet transform time-frequency spectrum of the third mode. This image simultaneously shows the changes in packet loss data in both time and frequency dimensions, providing analysts with more comprehensive and detailed network quality information. This helps to more accurately pinpoint the timing and frequency range of packet loss problems, thus providing strong support for resolving network faults.
[0064] In some embodiments, step S104 above, which involves calling a CNN-GAN combined model to perform multimodal fusion recognition based on a multimodal image set to determine whether continuous fluctuation features exist and to locate the root cause of the anomaly, specifically includes: Based on a multimodal image set, a convolutional neural network is used to extract the depth visual features of each individual image to obtain multiple single-modal feature maps. Multiple unimodal feature maps are fused across modalities to generate a global feature tensor; The global feature tensor is input into the discriminator network of the generative adversarial network, and the discriminator network determines whether there are continuous fluctuation features in the image. If continuous fluctuation features exist, the pre-trained root cause classification model is invoked based on the global feature tensor to infer the abnormal root cause category associated with the continuous fluctuation features.
[0065] In this embodiment, a convolutional neural network (CNN) is activated to process each image in the multimodal image set. CNNs possess powerful feature extraction capabilities; through a series of convolutional layers, pooling layers, and other structures, they can automatically learn various features in the image. For the packet loss rate curve of the first modality, the CNN extracts features related to the packet loss rate trend from the image's pixel information, such as the rise, fall, and fluctuation amplitude of the curve. These features are presented in the form of feature maps, where each point represents the feature information extracted from the corresponding region in the image. Similarly, for the packet loss spectrum of the second modality, the CNN extracts the distribution features of different frequency components in the spectrum, such as the intensity changes of high-frequency and low-frequency components, generating corresponding single-modal feature maps. For the wavelet transform image of the third modality, the CNN captures the features of the time-frequency domain energy distribution in the image, such as regions of concentrated energy and trends in energy change, also generating corresponding single-modal feature maps. Through this process, multiple single-modal feature maps corresponding to the three modal images are obtained, which provide basic data for subsequent cross-modal fusion.
[0066] After obtaining multiple single-modal feature maps, cross-modal fusion is required. The purpose of cross-modal fusion is to integrate features extracted from different modalities to obtain more comprehensive and integrated information. In practice, feature concatenation can be used. First, a suitable dimension is determined, and the single-modal feature maps are arranged and combined according to that dimension. For example, if each single-modal feature map is a two-dimensional matrix, they can be concatenated along a third dimension to form a three-dimensional global feature tensor. This global feature tensor contains feature information from three different modalities, comprehensively reflecting the characteristics of the lost packet data in multiple aspects, including the time domain, frequency domain, and time-frequency domain. The global feature tensor generated through cross-modal fusion provides richer data support for subsequent determination of whether continuous fluctuation features exist.
[0067] Generative Adversarial Networks (GANs) consist of a generator and a discriminator. In this embodiment, the discriminator network is primarily used to determine whether continuous fluctuation features exist in an image. The global feature tensor generated in the previous step is input into the discriminator network. The discriminator network is pre-trained and possesses the ability to distinguish between normal features and those exhibiting continuous fluctuation features. When processing the input global feature tensor, the discriminator network analyzes and judges it. It extracts various feature patterns from the global feature tensor and compares them with pre-learned normal feature patterns and patterns exhibiting continuous fluctuation features. If the feature patterns in the global feature tensor match patterns exhibiting continuous fluctuation features, the discriminator network determines that continuous fluctuation features exist in the image; otherwise, it determines that continuous fluctuation features do not exist. Through the judgment of the discriminator network, it is possible to quickly and accurately determine whether the multimodal image set contains continuous fluctuation features reflecting the micro-packet loss problem of the leased line network.
[0068] When the discriminator network determines that continuous fluctuation features exist in an image, it indicates a potential micro-packet loss problem in the leased line network, requiring further investigation to pinpoint the root cause. To this end, a pre-trained root cause classification model is invoked. This model, trained on a large dataset of labeled root causes, possesses the ability to infer the root cause category based on input features. The global feature tensor corresponding to the continuous fluctuation features is input into the root cause classification model, which performs in-depth analysis and processing. It extracts key features related to the root cause from the global feature tensor and matches and infers these features against pre-learned root cause patterns. Ultimately, the root cause classification model outputs the root cause category associated with the continuous fluctuation features, such as network equipment failure, line aging, or external interference. This method accurately pinpoints the root cause of micro-packet loss in the leased line network, providing targeted guidance for subsequent network maintenance and optimization.
[0069] Furthermore, the step of inputting the global feature tensor into the discriminator network of the generative adversarial network, and using the discriminator network to determine whether there are continuous fluctuation features in the image, specifically includes: A generative adversarial network (GAN) consisting of a generator subnetwork and a discriminator subnetwork is constructed and equipped with a multimodal image training dataset with wave pattern category labels. The multimodal image training dataset is input into the generative adversarial network for adversarial training. The generator network generates simulated images, which are then mixed with real images and input into the discriminator network. The discriminator network is optimized by minimizing the adversarial loss and classification loss of the discriminator network. The global feature tensor is input into the trained generative adversarial network, and forward propagation is performed through multiple fully connected layers inside the discriminator network to output a confidence probability value that represents the existence of continuous fluctuating features. Based on the comparison between the confidence probability value and the preset probability threshold, a final discrimination signal is generated to determine whether continuous fluctuation characteristics exist.
[0070] In this embodiment, a generative adversarial network (GAN) is constructed, comprising a generator subnetwork and a discriminator subnetwork. The generator subnetwork generates simulated images by learning the distribution characteristics of real images, aiming to generate data as similar as possible to real images, thus adversarially competing with the discriminator subnetwork during training. The discriminator subnetwork is responsible for judging the input images, distinguishing between real images and simulated images generated by the generator. Furthermore, to enable the discriminator network to identify continuous fluctuation features, a multimodal image training dataset with fluctuation pattern category labels is required. This training dataset contains multimodal images under various conditions, and each image is labeled with its corresponding fluctuation pattern category, such as whether continuous fluctuation features are present or absent, providing accurate basis for subsequent adversarial training.
[0071] The prepared multimodal image training dataset is input into the constructed generative adversarial network (GAN) to initiate adversarial training. During training, the generator network begins to function, generating simulated multimodal images based on input random noise or latent variables. These simulated images strive to resemble real images in features to confuse the discriminator network. Subsequently, the simulated images generated by the generator are mixed with real images and input into the discriminator network. The discriminator network needs to judge the input images, distinguishing between real and simulated images, and also classifying them according to the wave pattern category labels. To optimize the performance of the discriminator network, a method of minimizing the adversarial loss and classification loss of the discriminator network is adopted. The adversarial loss measures the discriminator network's ability to distinguish between real and simulated images, while the classification loss measures the accuracy of the discriminator network in judging the wave pattern category of the image. By continuously adjusting the parameters of the discriminator network to minimize both the adversarial loss and the classification loss, the accuracy of the discriminator network in judging continuous wave features is improved.
[0072] After sufficient adversarial training, the discriminator network in the generative adversarial network (GAN) acquires the ability to accurately determine whether continuous fluctuation features exist in an image. At this point, the previously generated global feature tensor is input into the trained GAN. After entering the discriminator network, the global feature tensor undergoes forward propagation calculations through multiple fully connected layers. These fully connected layers perform weighted summations and other operations on the various features in the global feature tensor, gradually extracting and integrating feature information. Through this series of forward propagation calculations, a confidence probability value representing the presence of continuous fluctuation features is finally output. This confidence probability value reflects the likelihood that the discriminator network considers the image corresponding to the input global feature tensor to contain continuous fluctuation features; its value typically ranges from 0 to 1, with values closer to 1 indicating a higher probability of continuous fluctuation features.
[0073] After obtaining the confidence probability value, it needs to be compared with a preset probability threshold. The preset probability threshold is a standard value set according to the actual application scenario and requirements, used to determine whether continuous fluctuation features exist. If the confidence probability value is greater than or equal to the preset probability threshold, it indicates that the discriminator network considers the input image to have a high probability of containing continuous fluctuation features, and a final discrimination signal indicating the presence of continuous fluctuation features is generated. Conversely, if the confidence probability value is less than the preset probability threshold, it is considered that the input image does not contain continuous fluctuation features, and a final discrimination signal indicating the absence of continuous fluctuation features is generated. In this way, the presence of continuous fluctuation features in an image can be accurately and effectively determined, providing important basis for subsequent anomaly root cause location and alarm triggering.
[0074] Furthermore, the pre-training steps of the root cause classification model specifically include: Based on historical anomalous events and their confirmed root cause categories, an anomalous classification training dataset is constructed with one-hot encoding of root cause categories as labels. Based on the input dimension and the number of output categories of the anomaly classification training dataset, a neural network classification model with multiple fully connected hidden layers is constructed. The anomaly classification training dataset is input into the neural network classification model for training. The model's predicted values are calculated through forward propagation, and the cross-entropy loss value is calculated by combining the true labels. Then, the parameters of the neural network classification model are iteratively optimized through backpropagation and gradient descent algorithms to obtain the root cause classification model.
[0075] In this embodiment, a large amount of historical anomaly data is collected, covering various problems that occurred during the operation of the leased network. For each historical anomaly, a professional analysis and confirmation process is used to determine its corresponding root cause category. For example, possible root cause categories include network equipment failure, line aging, and external interference. After determining the root cause category of each historical anomaly, these events are labeled using one-hot encoding of root cause categories. One-hot encoding is a method to convert categorical variables into a form that is easier for machine learning algorithms to understand. It creates a binary vector for each category, with only the position corresponding to the category set to 1, and the remaining positions set to 0. In this way, an anomaly classification training dataset labeled with one-hot root cause category encoding is constructed. This dataset contains rich historical anomaly information and its corresponding accurate root cause labels, providing a solid data foundation for subsequent model training.
[0076] After constructing the anomaly classification training dataset, a neural network classification model needs to be built based on the input dimension and the number of output categories. The input dimension refers to the number of features contained in each training sample. These features can be various relevant information extracted from historical anomaly events, such as packet loss rate patterns and network traffic fluctuations. The number of output categories corresponds to the number of root cause categories, i.e., the different types of anomaly root causes identified earlier. Based on this information, a neural network classification model with multiple fully connected hidden layers is constructed. The role of the fully connected hidden layers is to perform complex nonlinear transformations on the input features. Through the combination of multiple hidden layers, the model can learn a deeper level of correlation between input features and output categories. Each hidden layer contains a certain number of neurons, which are connected and computed through weights and biases. These parameters will be optimized and adjusted during subsequent training.
[0077] The constructed anomaly classification training dataset is input into the neural network classification model to begin the training process. During training, forward propagation is performed first. The model receives the features of the input training samples, calculates them through each hidden layer, and finally outputs a predicted value. This predicted value represents the probability distribution that the model believes the sample belongs to each root cause category. Then, the model's predicted value is compared with the true root cause category labels, and the cross-entropy loss value is calculated. The cross-entropy loss value is a commonly used metric to measure the difference between the model's prediction and the true label; the smaller the value, the more accurate the model's prediction. Next, the loss value is propagated from the output layer to the input layer using the backpropagation algorithm, calculating the contribution of each parameter to the loss value, i.e., the gradient. Finally, the gradient descent algorithm is used to iteratively optimize the parameters of the neural network classification model based on the calculated gradient. In each iteration, the model adjusts the parameters in the opposite direction of the gradient, gradually reducing the loss value. After multiple iterations of training, when the loss value reaches a relatively stable, small value, the model is considered to have converged. The neural network classification model obtained at this point is the root cause classification model, which has the ability to accurately infer the anomaly root cause category based on input features.
[0078] Furthermore, the step of inferring the abnormal root cause classification model based on the global feature tensor and outputting the abnormal root cause category associated with the continuous fluctuation features specifically includes: The global feature tensor is input into the root cause classification model for feature transformation and calculation, resulting in a set of output values representing the confidence levels of different abnormal root cause categories. The output values are normalized to generate a probability distribution vector, where each element of the probability distribution vector corresponds to the confidence level of a predefined candidate root cause category. The candidate root cause category with the highest confidence level is selected as the target root cause category associated with the continuous fluctuation feature based on the probability distribution vector.
[0079] In this embodiment, the global feature tensor is input into a pre-trained root cause classification model. The root cause classification model has a specific structure and parameter settings, and it performs a series of complex feature transformations and computations on the input global feature tensor. These operations are determined during the pre-training phase by learning from a large amount of historical data and corresponding root cause categories. The purpose is to extract key information related to the anomalous root cause category from the global feature tensor and ultimately generate a set of output values. These output values represent the confidence level of different anomalous root cause categories, that is, the probability that the model considers the input global feature tensor to belong to each predefined anomalous root cause category.
[0080] After obtaining the output values representing the confidence levels of different root cause categories, these output values need to be normalized to more intuitively represent the probability proportion of each category. Normalization transforms the output values according to certain rules, limiting their value range to a specific interval, and ensuring that the sum of all output values is 1. After normalization, a probability distribution vector is generated. In this probability distribution vector, each element corresponds to the confidence level of a predefined candidate root cause category, with a value ranging from 0 to 1. The closer the value is to 1, the greater the probability that the category is the true root cause category.
[0081] After generating the probability distribution vector, each element in the vector is compared and analyzed to find the element with the largest value. The predefined candidate root cause category corresponding to this element is the candidate root cause category with the highest confidence. This candidate root cause category with the highest confidence is then determined as the target root cause category associated with the continuous fluctuation characteristics. In this way, the most likely abnormal root cause causing the continuous fluctuation characteristics can be accurately identified from multiple candidate root cause categories. This provides a crucial basis for subsequent alarm triggering and monitoring strategy adjustments, thereby more effectively solving the micro-packet loss problem in leased line networks and ensuring the stable operation of network quality and services.
[0082] In some embodiments, step S105 above, which involves evaluating the alarm confidence level to trigger an alarm based on the output of multimodal fusion identification and the location result of the abnormal root cause, and dynamically adjusting the monitoring strategy by invoking a reinforcement learning model in conjunction with historical alarm feedback, specifically includes: Based on the confidence probability value used to characterize the existence of continuous fluctuation characteristics, the abnormal root cause category associated with the continuous fluctuation characteristics, and the historical accuracy of the abnormal root cause category, the comprehensive alarm confidence of the current event is calculated through a preset confidence evaluation matrix. Based on the comparison between the overall alarm confidence level and the current dynamic alarm threshold, a decision is made on whether to trigger an immediate alarm. After making an alarm decision, the reinforcement learning model is invoked, and the current set of monitoring strategy parameters is used as the state representation, and the adjustment action of the monitoring strategy parameter set is output. After the adjustment action is performed, the alarm feedback data generated thereafter is collected, and the alarm feedback data is converted into a reward signal and sent back to the reinforcement learning model to update the model parameters.
[0083] In this embodiment, a confidence probability value representing the existence of continuous fluctuation features is obtained from the output of multimodal fusion recognition. This value reflects the credibility of the system's judgment that continuous fluctuation features exist. Simultaneously, the anomaly root cause category associated with the continuous fluctuation features is identified, and the historical accuracy of this anomaly root cause category in historical data is obtained. This accuracy reflects the reliability of the anomaly root cause category in past judgments. Then, using a preset confidence evaluation matrix, the obtained confidence probability value, anomaly root cause category, and its historical accuracy are used as input parameters. The matrix is then used to calculate the comprehensive alarm confidence level for the current event through preset rules and weight allocation. This comprehensive alarm confidence level comprehensively considers multiple factors such as the probability of the fluctuation features' existence and the reliability of the anomaly root cause, providing a more comprehensive and accurate basis for determining whether to trigger an alarm.
[0084] In one possible implementation, the construction steps of the preset confidence assessment matrix include: constructing a three-dimensional confidence assessment matrix, where the row dimension corresponds to the confidence probability value range of continuous fluctuation features (e.g., 0-0.3, 0.3-0.6, 0.6-1), the column dimension corresponds to the anomaly root cause category (e.g., hardware failure, link congestion), and the depth dimension corresponds to the historical accuracy range (e.g., 0-0.4, 0.4-0.7, 0.7-1). Each cell in the matrix stores the basic confidence score under the corresponding parameter combination, with a score range of 0 to 100. The higher the score, the greater the probability that the current event is a real failure. In terms of weight allocation, the confidence probability value of continuous fluctuation features accounts for 50% of the weight, the anomaly root cause category accounts for 30% of the weight, and the historical accuracy accounts for 20% of the weight, to highlight the dominant role of real-time fluctuation features. Based on expert experience and historical data statistics, the basic scores of each cell in the matrix are initialized. For example, when the confidence probability of continuous fluctuation characteristics is 0.8 (high fluctuation), the root cause of the anomaly is hardware failure (high-risk category), and the historical accuracy is 0.9 (high reliability), the base score of the corresponding cell is set to 90 points; while when the fluctuation probability is 0.2 (low fluctuation), the root cause is protocol configuration error (low-risk category), and the historical accuracy is 0.3 (low reliability), the score is set to 20 points. A dynamic calibration mechanism is established to periodically update the matrix score based on new alarm data: if an alarm under a certain parameter combination is manually verified as a real fault, the score of the corresponding cell is increased by 10%; if it is a false alarm, the score is decreased by 15%, ensuring that the matrix adapts to changes in the network environment.
[0085] After obtaining the overall alarm confidence level for the current event, it is compared with the current dynamic alarm threshold. The current dynamic alarm threshold is not fixed but dynamically adjusted based on factors such as the actual network operation and historical alarm data to ensure accurate and timely alarm triggering under different network environments. If the overall alarm confidence level is greater than or equal to the current dynamic alarm threshold, it indicates a high risk of the current event, which may seriously impact the quality of the leased network. In this case, a decision is made to trigger an immediate alarm so that relevant personnel can take timely measures to address the issue. Conversely, if the overall alarm confidence level is less than the current dynamic alarm threshold, the risk of the current event is considered low, and an immediate alarm is not triggered at this time, but its subsequent development will be continuously monitored.
[0086] After making an alert decision, a reinforcement learning model needs to be invoked to dynamically adjust the monitoring strategy. First, the current monitoring strategy parameter set is organized and encoded so that it can serve as the state representation input to the reinforcement learning model. This parameter set includes various settings related to network monitoring, such as data acquisition frequency and analysis algorithm parameters, which directly affect the accuracy and timeliness of monitoring. Upon receiving the state representation, the reinforcement learning model, based on its internally learned strategies and experience, outputs adjustments to the monitoring strategy parameter set. These adjustments might include increasing the data acquisition frequency to improve sensitivity to network conditions, or adjusting analysis algorithm parameters to more accurately identify anomalies.
[0087] Based on the adjustment actions output by the reinforcement learning model, the current monitoring strategy parameter set is modified and updated accordingly, and the new monitoring strategy is immediately implemented. After the new monitoring strategy is implemented, subsequent alarm feedback data is continuously collected. This feedback data includes information such as whether a network failure has actually occurred, the type of failure, and the scope of its impact. Then, the collected alarm feedback data is organized and analyzed, and transformed into reward signals that the reinforcement learning model can understand. The reward signal reflects the effectiveness of the adjusted monitoring strategy in practical application. If the new monitoring strategy can more accurately detect and handle network problems, a positive reward is given; conversely, if false alarms or missed alarms occur, a negative reward is given. Finally, the reward signal is fed back to the reinforcement learning model. The model updates and optimizes its own parameters based on the reward signal to improve its ability to make more accurate decisions in similar situations in the future, thereby achieving dynamic adaptive adjustment of the monitoring strategy.
[0088] Reference Figure 2 An embodiment of the present invention provides a dedicated line network quality intelligent early warning system 2, the system 2 specifically comprising: Data acquisition module 201 is used to acquire multi-source packet loss time series data through a sliding time window collector, and to fuse multi-source packet loss time series data and build a global micro-packet loss prediction model using a federated learning framework. The time series prediction module 202 is used to fit the current packet loss time series data using a global micro-packet loss prediction model to generate the corresponding prediction data sequence; The offset detection module 203 is used to perform multi-timescale comparative analysis based on the fused multi-source packet loss time series data and the predicted data sequence to detect data offset. If an offset is detected, the multimodal image generation engine is started to generate a multimodal image set including packet loss rate curve, spectrum and wavelet transform. The anomaly localization module 204 is used to perform multimodal fusion recognition based on a multimodal image set by calling a CNN-GAN combined model to determine whether there are continuous fluctuation features and to locate the root cause of the anomaly. The alarm triggering module 205 is used to evaluate the alarm confidence based on the output of multimodal fusion identification and the location results of abnormal root causes to trigger an alarm, and to call the reinforcement learning model to dynamically adjust the monitoring strategy in combination with historical alarm feedback.
[0089] It is understandable that, such as Figure 1 The content of the intelligent early warning method embodiment for leased network quality shown is applicable to the embodiment of the intelligent early warning system for leased network quality shown. The specific functions implemented by the embodiment of the intelligent early warning system for leased network quality are the same as those shown in the figure. Figure 1 The implementation method for intelligent early warning of leased network quality shown is the same as that described above, and the beneficial effects achieved are also the same. Figure 1 The beneficial effects achieved by the intelligent early warning method for leased network quality shown in the embodiment are also the same.
[0090] It should be noted that the information interaction and execution process between the above systems are based on the same concept as the method embodiments of the present invention. For details on their specific functions and technical effects, please refer to the method embodiments section, which will not be repeated here.
[0091] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the system can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0092] Reference Figure 3 The present invention also provides a computer device 3, including: a memory 302 and a processor 301, and a computer program 303 stored in the memory 302. When the computer program 303 is executed on the processor 301, it implements the leased line network quality intelligent early warning method as described in any of the above methods.
[0093] The computer device 3 may be a desktop computer, laptop, handheld computer, or cloud server, etc. The computer device 3 may include, but is not limited to, a processor 301 and a memory 302. Those skilled in the art will understand that... Figure 3 The computer device 3 is merely an example and does not constitute a limitation on the computer device 3. It may include more or fewer components than shown in the figure, or combine certain components, or different components, such as input / output devices, network access devices, etc.
[0094] The processor 301 can be a Central Processing Unit (CPU), but it can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.
[0095] In some embodiments, the memory 302 may be an internal storage unit of the computer device 3, such as a hard disk or memory of the computer device 3. In other embodiments, the memory 302 may be an external storage device of the computer device 3, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the computer device 3. Furthermore, the memory 302 may include both internal and external storage units of the computer device 3. The memory 302 is used to store the operating system, applications, boot loader, data, and other programs, such as the program code of the computer program. The memory 302 can also be used to temporarily store data that has been output or will be output.
[0096] This invention also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the intelligent early warning method for leased network quality as described in any of the above methods.
[0097] In this embodiment, if the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to a photographing device / terminal device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electrical carrier signals or telecommunication signals.
[0098] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0099] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0100] In the embodiments disclosed in this application, it should be understood that the disclosed devices / terminal equipment and methods can be implemented in other ways. For example, the device / terminal equipment embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling or direct coupling or communication connection may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0101] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
Claims
1. A method for intelligent early warning of leased network quality, characterized in that, The method specifically includes: Multi-source packet loss time series data are acquired by a sliding time window collector, and a global micro-packet loss prediction model is constructed by fusing the multi-source packet loss time series data using a federated learning framework. The global micro-packet loss prediction model is used to fit the current packet loss time series data to generate the corresponding predicted data sequence; Multi-timescale comparative analysis is performed based on the fused multi-source packet loss time series data and predicted data sequence to detect data offset. If offset is detected, a multimodal image generation engine is activated to generate a multimodal image set including packet loss rate curve, spectrum and wavelet transform. Based on a multimodal image set, a CNN-GAN combined model is called to perform multimodal fusion recognition to determine whether there are continuous fluctuation features and to locate the root cause of the anomaly. Based on the output of multimodal fusion identification and the location results of abnormal root causes, the alarm confidence is evaluated to trigger an alarm, and the reinforcement learning model is invoked to dynamically adjust the monitoring strategy in combination with historical alarm feedback.
2. The method according to claim 1, characterized in that, The process of acquiring multi-source packet loss time-series data through a sliding time window collector, fusing the multi-source packet loss time-series data using a federated learning framework, and constructing a global micro-packet loss prediction model specifically includes: Local packet loss time series data of each node is obtained by a sliding time window collector deployed at multiple dedicated line nodes. Based on local packet loss time series data, each dedicated line node is used as a client of federated learning to train a local micro-packet loss prediction model. After training is complete, the local model parameters of each client are encrypted and uploaded to the federated learning server; Based on the federated learning server, a secure aggregation algorithm is used to aggregate the local model parameters of multiple clients to obtain the global model parameters. The global model parameters are distributed to each client, enabling the client to update its local model based on the global model parameters; Repeat the federated learning training steps until the global model converges to obtain the global micro-packet loss prediction model.
3. The method according to claim 1, characterized in that, The method involves multi-timescale comparative analysis based on the fused multi-source packet loss time-series data and predicted data sequences to detect data shifts. If a shift is detected, a multimodal image generation engine is activated to generate a multimodal image set containing packet loss rate curves, spectrograms, and wavelet transform graphs. Specifically, this includes: The fused multi-source packet loss time series data and the predicted data sequence are time-aligned to obtain the packet loss data sequence. Based on the packet loss data sequence, feature comparison calculations are performed on multiple preset time statistical scales to obtain the contrast values at each scale. Based on the comparison results of the contrast values at each scale with their respective preset thresholds, a comprehensive determination is made as to whether data shift has occurred. When a data offset is determined to occur, based on the packet loss data sequence, a multimodal image generation model is used to generate a packet loss rate time series curve for the first mode, a packet loss spectrum for the second mode, and a wavelet transform time spectrum for the third mode. Aggregate the packet loss rate time series curve, packet loss spectrum, and wavelet transform time spectrum, and output a multimodal image set.
4. The method according to claim 3, characterized in that, The process involves generating a time-series curve of packet loss rate for the first mode, a packet loss spectrum for the second mode, and a wavelet transform time-series spectrum for the third mode based on the packet loss data sequence using a multimodal image generation model. Specifically, this includes: Based on the packet loss data sequence and its corresponding timestamp, a time series curve of packet loss rate changing with time is plotted in a time coordinate system to generate the time series curve of the first mode. After preprocessing the lost data sequence by frequency domain transformation, the frequency domain amplitude spectrum is calculated using the Fourier transform algorithm, and the frequency domain amplitude spectrum is plotted in the frequency coordinate system to generate the lost spectrum of the second mode. Time-frequency analysis is performed on the lost data sequence. The energy distribution on the time-frequency plane is calculated by continuous wavelet transform, and the energy distribution is visualized as a grayscale or color image to generate the wavelet transform time-frequency spectrum of the third mode.
5. The method according to claim 1, characterized in that, The process of using a multimodal image set and calling a CNN-GAN combined model for multimodal fusion recognition to determine the presence of continuous fluctuation features and locate the root cause of the anomaly specifically includes: Based on a multimodal image set, a convolutional neural network is used to extract the depth visual features of each individual image to obtain multiple single-modal feature maps. Multiple unimodal feature maps are fused across modalities to generate a global feature tensor; The global feature tensor is input into the discriminator network of the generative adversarial network, and the discriminator network determines whether there are continuous fluctuation features in the image. If continuous fluctuation features exist, the pre-trained root cause classification model is invoked based on the global feature tensor to infer the abnormal root cause category associated with the continuous fluctuation features.
6. The method according to claim 5, characterized in that, The step of inputting the global feature tensor into the discriminator network of the generative adversarial network, and using the discriminator network to determine whether there are continuous fluctuation features in the image, specifically includes: A generative adversarial network (GAN) consisting of a generator subnetwork and a discriminator subnetwork is constructed and equipped with a multimodal image training dataset with wave pattern category labels. The multimodal image training dataset is input into the generative adversarial network for adversarial training. The generator network generates simulated images, which are then mixed with real images and input into the discriminator network. The discriminator network is optimized by minimizing the adversarial loss and classification loss of the discriminator network. The global feature tensor is input into the trained generative adversarial network, and forward propagation is performed through multiple fully connected layers inside the discriminator network to output a confidence probability value that represents the existence of continuous fluctuating features. Based on the comparison between the confidence probability value and the preset probability threshold, a final discrimination signal is generated to determine whether continuous fluctuation characteristics exist.
7. The method according to claim 5, characterized in that, The pre-training steps of the root cause classification model specifically include: Based on historical anomalous events and their confirmed root cause categories, an anomalous classification training dataset is constructed with one-hot encoding of root cause categories as labels. Based on the input dimension and the number of output categories of the anomaly classification training dataset, a neural network classification model with multiple fully connected hidden layers is constructed. The anomaly classification training dataset is input into the neural network classification model for training. The model's predicted values are calculated through forward propagation, and the cross-entropy loss value is calculated by combining the true labels. Then, the parameters of the neural network classification model are iteratively optimized through backpropagation and gradient descent algorithms to obtain the root cause classification model.
8. The method according to claim 7, characterized in that, The method, based on the global feature tensor, invokes a pre-trained root cause classification model for inference, outputting the abnormal root cause categories associated with continuous fluctuation features, specifically including: The global feature tensor is input into the root cause classification model for feature transformation and calculation, resulting in a set of output values representing the confidence levels of different abnormal root cause categories. The output values are normalized to generate a probability distribution vector, where each element of the probability distribution vector corresponds to the confidence level of a predefined candidate root cause category. The candidate root cause category with the highest confidence level is selected as the target root cause category associated with the continuous fluctuation feature based on the probability distribution vector.
9. The method according to any one of claims 6 to 8, characterized in that, The process of evaluating alarm confidence based on the output of multimodal fusion identification and the location results of abnormal root causes to trigger alarms, and dynamically adjusting monitoring strategies by invoking a reinforcement learning model in conjunction with historical alarm feedback, specifically includes: Based on the confidence probability value used to characterize the existence of continuous fluctuation characteristics, the abnormal root cause category associated with the continuous fluctuation characteristics, and the historical accuracy of the abnormal root cause category, the comprehensive alarm confidence of the current event is calculated through a preset confidence evaluation matrix. Based on the comparison between the overall alarm confidence level and the current dynamic alarm threshold, a decision is made on whether to trigger an immediate alarm. After making an alarm decision, the reinforcement learning model is invoked, and the current set of monitoring strategy parameters is used as the state representation, and the adjustment action of the monitoring strategy parameter set is output. After the adjustment action is performed, the alarm feedback data generated thereafter is collected, and the alarm feedback data is converted into a reward signal and sent back to the reinforcement learning model to update the model parameters.
10. A dedicated network quality intelligent early warning system, characterized in that, The system specifically includes: The data acquisition module is used to acquire multi-source packet loss time series data through a sliding time window collector, and to fuse the multi-source packet loss time series data using a federated learning framework to build a global micro-packet loss prediction model. The time series prediction module is used to fit the current packet loss time series data using a global micro-packet loss prediction model and generate the corresponding predicted data sequence. The offset detection module is used to perform multi-timescale comparative analysis based on the fused multi-source packet loss time series data and the predicted data sequence to detect data offset. If an offset is detected, the multimodal image generation engine is started to generate a multimodal image set including packet loss rate curve, spectrum and wavelet transform. The anomaly localization module is used to perform multimodal fusion recognition based on a multimodal image set by calling a CNN-GAN combined model to determine whether there are continuous fluctuation features and to locate the root cause of the anomaly. The alarm triggering module is used to evaluate the alarm confidence based on the output of multimodal fusion identification and the location results of abnormal root causes to trigger an alarm, and to call the reinforcement learning model to dynamically adjust the monitoring strategy in combination with historical alarm feedback.