Anomaly detection method, electronic device, storage medium, and program
By acquiring multi-source anomaly detection correlation data and adjusting it using dynamic conflict coefficients, the problem of insufficient detection accuracy caused by single data-driven methods in existing technologies is solved, achieving high reliability and accuracy in anomaly detection for business systems.
Patent Information
- Application Number
- CN202610447901.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-07
- Publication Date
- 2026-08-25
AI Technical Summary
Existing anomaly detection technologies suffer from insufficient accuracy and comprehensiveness due to their reliance on single data-driven approaches, making it difficult to meet the high reliability requirements of business systems for anomaly detection.
By acquiring anomaly detection correlation and fusion data from the target business system, initial anomaly detection results are generated using multiple independent anomaly detection models, and then adjusted based on evidence theory and dynamic conflict coefficients to generate the target anomaly detection results.
It improves the accuracy and reliability of anomaly detection, avoids the problems of missed detection and false detection caused by the limitations of algorithms or data adaptation deviations of single models, and enhances the stability and consistency of detection results.
Smart Images

Figure CN122634415A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the fields of artificial intelligence and financial technology, and in particular to an anomaly detection method, electronic device, storage medium and program. Background Technology
[0002] In the daily operation of business systems, massive amounts of multi-dimensional business data are continuously generated, specifically covering various types such as transaction data, account data, and user behavior data. This type of data contains a wealth of implicit information related to the business operation status and user operation patterns, and is the core data foundation for realizing the detection of abnormal behavior in business systems and ensuring the stable and secure operation of business systems.
[0003] However, existing anomaly detection technologies generally employ a single data-driven detection model architecture. In real-world business scenarios, anomaly behavior often results from the interaction of multiple data types. Limited by the feature boundaries of a single data type, the one-sidedness of data dimensions can easily lead to missed or false detections of anomalies, ultimately resulting in insufficient accuracy and comprehensiveness of the detection results, making it difficult to meet the high reliability requirements of business systems for anomaly detection. Summary of the Invention
[0004] This invention provides an anomaly detection method, apparatus, electronic device, storage medium, and program, which can improve the accuracy and reliability of anomaly detection in business systems.
[0005] According to one aspect of the present invention, an anomaly detection method is provided, comprising: Obtain anomaly detection correlation and fusion data from the target business system; Anomaly detection is performed on the target business system based on the anomaly detection association fusion data to obtain initial anomaly detection results; A basic anomaly probability is generated based on the initial anomaly detection results described above; The dynamic conflict coefficient is dynamically adjusted based on the factors associated with the conflict coefficient, and the basic anomaly probability is adjusted based on the dynamic conflict coefficient to obtain the target anomaly detection result.
[0006] According to another aspect of the present invention, an anomaly detection device is provided, comprising: The anomaly detection correlation and fusion data acquisition module is used to acquire anomaly detection correlation and fusion data of the target business system; The initial anomaly detection result determination module is used to perform anomaly detection on the target business system based on the anomaly detection association fusion data to obtain an initial anomaly detection result; The basic anomaly probability generation module is used to generate basic anomaly probabilities based on the initial anomaly detection results. The target anomaly detection result determination module is used to dynamically adjust the dynamic conflict coefficient based on the conflict coefficient correlation factors, and adjust the basic anomaly probability based on the dynamic conflict coefficient to obtain the target anomaly detection result.
[0007] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the anomaly detection method according to any embodiment of the present invention.
[0008] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the anomaly detection method according to any embodiment of the present invention.
[0009] According to another aspect of the present invention, a computer program product is also provided, comprising a computer program that, when executed by a processor, implements the anomaly detection method described in any embodiment of the present invention.
[0010] This invention acquires anomaly detection correlation and fusion data of the target business system, and performs anomaly detection on the target business system based on the anomaly detection correlation and fusion data to obtain initial anomaly detection results. After obtaining the initial anomaly detection results, basic anomaly probabilities are generated based on the initial anomaly detection results corresponding to each anomaly detection model, and dynamic conflict coefficients are dynamically adjusted based on conflict coefficient correlation factors. Furthermore, the basic anomaly probabilities are adjusted based on the dynamic conflict coefficients to obtain the target anomaly detection results. The above solution solves the problem of missed and false detections of abnormal behavior caused by the one-sidedness of data dimensions in existing anomaly detection methods, and can improve the accuracy and reliability of anomaly detection in business systems.
[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0013] Figure 1 This is a flowchart of an anomaly detection method provided in Embodiment 1 of the present invention; Figure 2 This is a flowchart of an anomaly detection method provided in Embodiment 2 of the present invention; Figure 3 This is a flowchart of an anomaly detection method provided in Embodiment 3 of the present invention; Figure 4 This is a schematic diagram of an anomaly detection device provided in Embodiment 4 of the present invention; Figure 5 This is a schematic diagram of the structure of an electronic device provided in Embodiment 5 of the present invention. Detailed Implementation
[0014] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0015] It should be noted that the terms "first," "second," and "target," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0016] Example 1 Figure 1 This is a flowchart of an anomaly detection method provided in Embodiment 1 of the present invention. This embodiment is applicable to situations where multiple initial anomaly detection results are fused based on a dynamically adjustable dynamic conflict coefficient to obtain a target anomaly detection result. This method can be executed by an anomaly detection device, which can be implemented in software and / or hardware, and is generally integrated into an electronic device. This electronic device can be a terminal device or a server device, as long as it can execute the anomaly detection method. The present invention does not limit the specific type of electronic device. Correspondingly, as... Figure 1 As shown, the method includes the following operations: S110. Obtain the anomaly detection association and fusion data of the target business system.
[0017] The target business system can be the business system to be subjected to anomaly detection. Anomaly detection associated fusion data can be a data set obtained by fusing anomaly detection associated data from the target business system. Anomaly detection associated data can be a data set that has spatiotemporal, logical, or causal relationships with various abnormal events during anomaly detection work on the target business system. For example, anomaly detection associated data can include, but is not limited to, structured data such as transaction system databases and account management databases, semi-structured data such as login logs, application programming interface data, and operation trajectories, as well as unstructured data such as customer text feedback, news data, and voice recordings. This embodiment of the invention does not limit the specific content included in the anomaly detection associated data.
[0018] In this embodiment of the invention, the business system to be detected for anomalies can be considered as the target business system. When performing anomaly detection on the target business system, a pre-defined data access adapter can be used to uniformly collect data from different sources and in different formats within the target business system; the collected data is collectively referred to as anomaly detection associated data. Based on this, the anomaly detection associated data can be further fused to obtain anomaly detection associated fused data for the target business system, which serves as reference data for subsequent anomaly detection processes.
[0019] S120. Perform anomaly detection on the target business system based on the anomaly detection association fusion data to obtain initial anomaly detection results.
[0020] The initial anomaly detection result can be a set of multiple anomaly detection results obtained by performing anomaly detection on the target business system using multiple independent anomaly detection models based on the anomaly detection association fusion data.
[0021] Accordingly, after acquiring the anomaly detection correlation and fusion data of the target business system, the anomaly detection correlation and fusion data can be input into multiple independent anomaly detection models. Each model then performs anomaly detection on the target business system, resulting in a set of multiple anomaly detection results. For example, the anomaly detection models may include, but are not limited to, repayment ability models, credit trend models, user operation risk models, and system operation indicator anomaly models. The corresponding anomaly detection models can be flexibly configured according to the actual anomaly detection needs. This embodiment of the invention does not limit the specific type of anomaly detection model. The repayment ability model can be a model used to quantitatively assess the debt repayment ability of an entity. The credit trend model can be a quantitative analysis model that predicts the future direction and magnitude of changes in the entity's credit status based on historical credit data and dynamic characteristic indicators. The user operation risk model can be a quantitative risk identification and early warning model constructed for user violations, errors, or malicious behavior in business operations. The system operation indicator anomaly model can be a quantitative monitoring and early warning model that identifies deviations of indicators from the normal baseline and predicts the risk of failure based on the full system operation data.
[0022] S130. Generate basic anomaly probabilities based on the initial anomaly detection results.
[0023] Among them, the anomaly base probability can be used to quantify the degree of confidence in the initial anomaly detection results.
[0024] Accordingly, after obtaining the initial anomaly detection results, each initial anomaly detection result can be used as evidence, and based on the reasoning rules of evidence theory, the basic anomaly probability corresponding to each initial anomaly detection result can be generated.
[0025] S140. Dynamically adjust the dynamic conflict coefficient based on the factors associated with the conflict coefficient, and adjust the basic anomaly probability based on the dynamic conflict coefficient to obtain the target anomaly detection result.
[0026] The conflict coefficient correlation factors can be various elements that directly or indirectly affect the value and representation effect of the conflict coefficient in evidence theory. For example, conflict coefficient correlation factors may include, but are not limited to, the credibility of the initial anomaly detection results, the performance indicators of the anomaly detection model, and the number and independence of the initial anomaly detection results. This embodiment of the invention does not limit the specific content included in the conflict coefficient correlation factors. The dynamic conflict coefficient can be a conflict coefficient in evidence theory that can be dynamically adjusted according to the conflict coefficient correlation factors. The target anomaly detection result can be an anomaly detection result obtained by fusing the initial anomaly detection results based on evidence theory.
[0027] Accordingly, after generating the basic anomaly probabilities based on the initial anomaly detection results, this scheme does not directly use the static conflict coefficient for calculation. Instead, it dynamically adjusts the conflict coefficient under the dynamic evidence theory framework based on the conflict coefficient correlation factors to obtain a dynamic conflict coefficient that adapts to the current detection scenario. On this basis, the generated basic anomaly probabilities can be specifically corrected based on this dynamic conflict coefficient, thereby outputting accurate target anomaly detection results. In other words, the target anomaly detection results can be obtained by fusing the initial anomaly detection results.
[0028] Therefore, the anomaly detection method provided by this invention, through an adjustable dynamic conflict coefficient, solves the problem of poor data fusion performance under high-conflict evidence, thereby improving the accuracy and reliability of target anomaly detection results. Simultaneously, fusing the initial anomaly detection results of multiple independent anomaly detection models to obtain the target anomaly detection result fully integrates the technical advantages and detection characteristics of different models, avoiding the problems of missed detections and false detections caused by the limitations of a single model or data adaptation bias. Furthermore, this solution leverages the complementarity and correlation of evidence from multiple models to effectively improve the adaptability of the anomaly detection algorithm to complex scenarios and edge data, thus ensuring the stability and consistency of detection results in different application environments.
[0029] This invention acquires anomaly detection correlation and fusion data of the target business system, and performs anomaly detection on the target business system based on the anomaly detection correlation and fusion data to obtain initial anomaly detection results. After obtaining the initial anomaly detection results, basic anomaly probabilities are generated based on the initial anomaly detection results corresponding to each anomaly detection model, and dynamic conflict coefficients are dynamically adjusted based on conflict coefficient correlation factors. Furthermore, the basic anomaly probabilities are adjusted based on the dynamic conflict coefficients to obtain the target anomaly detection results. The above solution solves the problem of missed and false detections of abnormal behavior caused by the one-sidedness of data dimensions in existing anomaly detection methods, and can improve the accuracy and reliability of anomaly detection in business systems.
[0030] Example 2 Figure 2 This is a flowchart of an anomaly detection method provided in Embodiment 2 of the present invention. This embodiment is a specific embodiment based on the above embodiment. In this embodiment, a specific optional implementation method for dynamically adjusting the dynamic conflict coefficient based on the reliability of the initial anomaly detection result and the performance indicators of each anomaly detection model is given. Correspondingly, as... Figure 2 As shown, the method in this embodiment may include: S210. Obtain the anomaly detection association and fusion data of the target business system.
[0031] In an optional embodiment of the present invention, the step of obtaining the anomaly detection association fusion data of the target business system may include: obtaining the data distribution status and core business element information of the target business system; and obtaining the anomaly detection association fusion data of the target business system when it is determined that the change in the data distribution status is greater than a preset threshold, or when it is determined that the core business element information is updated.
[0032] Here, data distribution status can be a comprehensive representation of the probability of data occurrence, central tendency, and dispersion characteristics within the target business system. Core business element information can be a collective term for the core components and key constraints supporting business operations within the target business system. Preset thresholds can be pre-defined thresholds for the magnitude of data changes.
[0033] Specifically, when acquiring anomaly detection correlation and fusion data from a target business system, the data distribution status within the system can be determined using relevant testing algorithms or statistical methods such as analysis of variance. Simultaneously, the core business element information of the target business system can be monitored. If the change in the data distribution status of the target business system exceeds a preset threshold, such as 30%, or if the core business element information changes, the anomaly detection process can be initiated to acquire the anomaly detection correlation and fusion data from the target business system. This solution triggers the collection and fusion of anomaly detection correlation data when the target business system experiences anomalies, significantly improving the timeliness of anomaly detection response.
[0034] Optionally, a fixed time period can be set to perform the above-mentioned anomaly detection associated fusion data acquisition operation.
[0035] In an optional embodiment of the present invention, obtaining the anomaly detection correlation fusion data of the target business system may include: obtaining the anomaly detection correlation data of the target business system; when the data type of the anomaly detection correlation data is determined to be relational data, determining a first fusion weight for each relational anomaly detection correlation data based on the data quality and historical detection contribution of each anomaly detection correlation data; fusing each relational anomaly detection correlation data according to the first fusion weight to obtain a fusion result of the relational anomaly detection correlation data; when the data type of the anomaly detection correlation data is determined to be non-relational data, determining a second fusion weight for each non-relational anomaly detection correlation data through an attention mechanism; fusing each non-relational anomaly detection correlation data according to the second fusion weight to obtain a fusion result of the non-relational anomaly detection correlation data; and determining the anomaly detection correlation fusion data of the target business system based on the fusion result of the relational anomaly detection correlation data and the fusion result of the non-relational anomaly detection correlation data.
[0036] Among them, relational data can be structured data organized based on a relational model. Data quality can be an indicator used to quantify the core attributes of data, such as completeness, accuracy, and timeliness. Historical detection contribution can be the degree to which associated data improves the accuracy of anomaly detection. The first fusion weight can be the core reference weight parameter used in the data fusion processing of relational data. Non-relational data can be data types that do not follow a relational model and do not require a fixed table structure. For example, non-relational data can include, but is not limited to, semi-structured data and unstructured data, etc. This embodiment of the invention does not limit the specific type of non-relational data. The second fusion weight can be the core reference weight parameter used in the data fusion processing of non-relational data.
[0037] Specifically, the target business system can use pre-defined data access adapters, such as log adapters, text parsing adapters, or speech-to-text adapters, to achieve unified collection of anomaly detection related data from different sources and in different formats. Simultaneously, the access process supports dynamic configuration of data source parameters such as IP (Internet Protocol) address, port, access permissions, and data update frequency. Furthermore, data sources can be added or removed according to business anomaly detection needs. After acquiring the anomaly detection related data from the target business system, the data type of the anomaly detection related data can be determined. If the anomaly detection related data is relational data, a first fusion weight can be dynamically calculated based on the data quality and historical detection contribution of the relational anomaly detection related data. Based on this, the various relational anomaly detection related data can be fused according to the first fusion weight to obtain the fusion result of the relational anomaly detection related data. Optionally, the update cycle of the first fusion weight can be adaptively adjusted according to the data change frequency; for example, the weight is updated hourly when the data changes frequently, and daily when the data is stable. The above solution avoids the drawbacks of traditional fixed weights that cannot adapt to changes in data state, ensuring that high-quality and high-contribution data occupies a reasonable weight in the fusion process, and improving the reliability of the relational data fusion result.
[0038] If the anomaly detection associated data is non-relational data, the importance weights of different types of data, i.e. the second fusion weights, can be automatically learned by a neural network model based on the attention mechanism. This allows for the accurate capture of semantic associations and dynamic interaction information between heterogeneous data, and the deep fusion of semi-structured feature vectors with the semantic feature vectors of unstructured data to obtain the fusion result of non-relational anomaly detection associated data.
[0039] Building upon this foundation, the fusion results of relational anomaly detection data and non-relational anomaly detection data can be further fused to output a standardized, unified fusion feature vector. This feature vector will then be used as the anomaly detection fusion data in subsequent anomaly analysis processes. This solution, based on real-time fusion of multi-dimensional anomaly detection data, can fully reconstruct the business operation chain and system operating status at the time of an anomaly occurrence. It effectively avoids misjudgments and missed detections caused by single data dimensions and incomplete information, thereby significantly improving the accuracy and reliability of detection.
[0040] Optionally, after obtaining the anomaly detection association data of the target business system, the method may further include: filling in missing values in the anomaly detection association data according to the data type of the anomaly detection association data; marking and correcting outliers in the anomaly detection association data; removing duplicate values in the anomaly detection association data; and extracting multimodal features from the anomaly detection association data.
[0041] After acquiring the anomaly detection correlation data from the target business system, preprocessing can be performed on missing values, outliers, and duplicate values in the accessed data. Specifically, for missing values, a dynamic imputation strategy can be adopted based on the data type. For example, numerical data can be imputed using the mean based on a sliding window, categorical data can be imputed using the mode based on semantic similarity, and missing key sensitive data can be marked as pending verification. For outliers, they can be identified through a combination of statistical methods and business rules. Non-malicious outliers can be corrected, while malicious outliers can be initially marked and their original data retained. For duplicate values, deduplication can be performed based on unique data identifiers, retaining the latest or complete data records.
[0042] After data preprocessing, data with different dimensions and scales can be converted into a unified format and scale. Specifically, structured data can be standardized to unify the data scope. Key features can be extracted from semi-structured data, such as login time, login IP, or device model in login logs, and converted into structured features. Natural language processing techniques can be used to extract semantic features from unstructured data, such as word embeddings or topic models. Speech data is first converted into text through speech recognition before feature extraction, ultimately converting all types of data into a unified feature vector format.
[0043] At the same time, sensitive data after preprocessing can be de-identified, for example by using encryption, masking, or replacement, to ensure data security and compliance while retaining data availability.
[0044] S220. Perform anomaly detection on the target business system based on the anomaly detection association fusion data to obtain initial anomaly detection results.
[0045] S230. Generate basic anomaly probabilities based on the initial anomaly detection results.
[0046] S240. Determine the reliability of the initial anomaly detection results and the performance indicators of each anomaly detection model.
[0047] The reliability of the initial anomaly detection results can be an indicator used to quantitatively evaluate the reliability of the initial anomaly detection results. The performance indicators of the anomaly detection model can be core parameters used to quantitatively evaluate the quality of the anomaly detection model. For example, the performance indicators of the anomaly detection model may include, but are not limited to, false positive rate, false negative rate, and detection latency. This embodiment of the invention does not limit the specific types of indicators included in the performance indicators of the anomaly detection model.
[0048] Specifically, after determining the initial anomaly detection results of the target business system through multiple anomaly detection models, the reliability of the initial anomaly detection results can be determined based on the confidence level of the anomaly detection models. Simultaneously, the performance metrics of each anomaly detection model can be obtained.
[0049] S250. Based on the reliability of the initial anomaly detection results and the performance indicators of each anomaly detection model, dynamically adjust the dynamic conflict coefficient.
[0050] Accordingly, after determining the credibility of the initial anomaly detection results and the performance metrics of each anomaly detection model, a dynamic conflict coefficient can be generated based on the credibility value of the initial anomaly detection results and the performance metric parameters of each anomaly detection model. This coefficient characterizes the degree of contradiction or conflict between the initial anomaly detection results, thereby improving the accuracy and reliability of multi-model fusion detection and reducing the risk of misjudgment caused by single-model detection bias or multi-model result conflict. Furthermore, the dynamic conflict coefficient can adaptively adjust according to changes in model performance metrics under different detection scenarios, exhibiting strong scenario adaptability and flexibility, and significantly enhancing the practicality and generalization ability of the present invention.
[0051] In an optional embodiment of the present invention, the step of dynamically adjusting the dynamic conflict coefficient based on the credibility of the initial anomaly detection result and the performance index of each anomaly detection model may include: generating credibility weights based on the credibility of the initial anomaly detection result and the performance index of each anomaly detection model; determining the global conflict degree of the basic anomaly probability; and dynamically adjusting the dynamic conflict coefficient based on the credibility weights and the global conflict degree.
[0052] The credibility weight can be a weighting coefficient assigned based on the reliability of the initial anomaly detection results. The global conflict level can be a comprehensive indicator used to quantify the overall degree of contradiction and inconsistency among multiple pieces of evidence.
[0053] In this embodiment of the invention, when dynamically adjusting the dynamic conflict coefficient based on the credibility of the initial anomaly detection results and the performance indicators of each anomaly detection model, a credibility weight is first generated based on the credibility of the initial anomaly detection results and the performance indicators of each anomaly detection model. Simultaneously, the global conflict degree is determined based on the basic anomaly probability corresponding to the initial anomaly detection results. Based on this, a dynamic conflict coefficient is generated according to the credibility weight and the global conflict degree, providing a more accurate and comprehensive quantitative reference for subsequent fusion decisions of multi-model detection results, thus helping to improve the accuracy and stability of the target anomaly detection results.
[0054] In a specific example, the dynamic conflict coefficient can be calculated based on the following formula: ; in, The dynamic conflict coefficient, For global conflict level, is the confidence weight of the k-th initial anomaly detection result, and N is the number of initial anomaly detection results.
[0055] S260. Dynamically adjust the dynamic conflict coefficient based on the factors associated with the conflict coefficient, and adjust the basic anomaly probability based on the dynamic conflict coefficient to obtain the target anomaly detection result.
[0056] This invention acquires anomaly detection correlation and fusion data of a target business system, and performs anomaly detection on the target business system based on this data to obtain initial anomaly detection results. After obtaining the initial anomaly detection results, basic anomaly probabilities are generated based on the initial anomaly detection results corresponding to each anomaly detection model. Simultaneously, the reliability of the initial anomaly detection results and the performance indicators of each anomaly detection model are determined, and the dynamic conflict coefficient is dynamically adjusted based on the reliability of the initial anomaly detection results and the performance indicators of each anomaly detection model. Further, the basic anomaly probabilities are adjusted based on the dynamic conflict coefficient to obtain the target anomaly detection result. This solution solves the problem of missed and false detections of abnormal behavior caused by the one-sidedness of data dimensions in existing anomaly detection methods, and can improve the accuracy and reliability of anomaly detection in business systems.
[0057] Example 3 Figure 3 This is a flowchart of an anomaly detection method provided in Embodiment 3 of the present invention. This embodiment is a specific implementation based on the above embodiment. In this embodiment, optional implementation operations are given after dynamically adjusting the dynamic conflict coefficient according to the conflict coefficient correlation factors and adjusting the basic anomaly probability according to the dynamic conflict coefficient to obtain the target anomaly detection result. Correspondingly, as Figure 3 As shown, the method in this embodiment may include: S310. Obtain the anomaly detection association and fusion data of the target business system.
[0058] S320. Perform anomaly detection on the target business system based on the anomaly detection association fusion data to obtain initial anomaly detection results.
[0059] S330. Generate basic anomaly probabilities based on the initial anomaly detection results.
[0060] S340. Dynamically adjust the dynamic conflict coefficient based on the factors associated with the conflict coefficient, and adjust the basic anomaly probability based on the dynamic conflict coefficient to obtain the target anomaly detection result.
[0061] S350. Generate anomaly detection result correction rules based on the business rules of the target business system.
[0062] Business rules can be a series of formal, executable guidelines, regulations, and logic used to define, constrain, and guide how various business activities in the target business system are carried out. Anomaly detection result correction rules can be a digital rule system generated based on the business rules of the target business system, which can be flexibly configured, managed, and executed in the rule engine.
[0063] Specifically, the business rules of the target business system can be sorted, decomposed, and adapted to form a set of anomaly detection result correction rules that can be flexibly configured, uniformly managed, and automatically executed in the rule engine. In a specific example, the business rules of the target business system can be transformed into correction conditions, correction methods, and execution priorities for anomaly detection results based on changes in the business scenario.
[0064] S360. Correct the target anomaly detection result according to the anomaly detection result correction rule.
[0065] Correspondingly, after generating anomaly detection result correction rules based on the business rules of the target business system, when the target business system detects an anomaly, the rule engine can automatically call the corresponding correction rules to verify, adjust, or correct the target anomaly detection result, thus obtaining a corrected target anomaly detection result. This process not only ensures that business data and execution results strictly conform to the underlying business logic of the target business system, guaranteeing the standardization of business execution and the accuracy of data, but also flexibly adapts to the personalized needs of various business scenarios and complex and ever-changing business changes, effectively improving the flexibility and adaptability of anomaly correction.
[0066] Optionally, distributed caching technology can be used to cache the aforementioned anomaly detection associated fusion data and the corrected target anomaly detection results in real time. The cache validity period can be dynamically adjusted according to the data update frequency. When the data source is updated or the fusion strategy is adjusted, the fusion results are updated in real time and synchronized to subsequent detection modules to ensure that subsequent layered detection modules use the latest fusion.
[0067] S370. Perform first dataset anomaly detection on the anomaly detection associated fusion data according to the dynamically updated multi-dimensional anomaly matching rules, and filter the second anomaly detection associated fusion data according to the anomaly detection results of the first dataset.
[0068] The multi-dimensional anomaly matching rule can be anomaly judgment rule that integrates multiple attribute dimensions. For example, the multi-dimensional anomaly matching rule may include, but is not limited to, basic business rules and risk threshold rules. This embodiment of the invention does not limit the specific content included in the multi-dimensional anomaly matching rule. The anomaly detection result of the first dataset can be the anomaly detection result obtained by matching anomaly detection association fusion data with anomaly rules. The secondary anomaly detection association fusion data can be anomaly detection association fusion data where the multi-dimensional anomaly matching rule was not matched.
[0069] Accordingly, after completing the data fusion operations of the above different dimensions, the multi-dimensional anomaly matching rules in the pre-built rule base can be quickly matched and detected with the anomaly detection associated fusion data. Samples that clearly match the anomaly matching rules are directly marked as high-risk anomalies; samples that perfectly match the normal judgment rules are directly marked as normal. The remaining samples that are not clearly judged can be used as secondary anomaly detection associated fusion data to enter the second-layer anomaly detection process. This layer of anomaly detection uses streaming computing technology, which can ensure that the anomaly detection latency is controlled within milliseconds, meeting the requirements of real-time detection. Optionally, the multi-dimensional anomaly matching rules can be dynamically configured and updated in real time according to the actual anomaly type to adapt to changes in business scenarios and iterations of anomaly characteristics.
[0070] S380. Based on the target machine learning model, perform secondary anomaly detection on the secondary anomaly detection associated fusion data and the corrected target anomaly detection results to obtain the anomaly detection results of the second dataset.
[0071] The target machine learning model can be a machine learning model used for secondary anomaly detection. The anomaly detection results of the second dataset can be obtained by performing secondary anomaly detection on the associated and fused data of the secondary anomaly detection and the corrected target anomaly detection results.
[0072] Correspondingly, after filtering the secondary anomaly detection associated fusion data based on the anomaly detection results of the first dataset, the secondary anomaly detection associated fusion data and the corrected target anomaly detection results can be input into the target detection model for anomaly detection, thereby obtaining the anomaly detection results of the second dataset.
[0073] The target machine learning model can be constructed into a multi-model fusion machine learning detection framework, specifically comprising two core components: a base model trained on historical data and an incremental model dynamically updated based on real-time data using online learning algorithms. This framework employs a combination of deep learning and traditional machine learning models, training dedicated sub-models for different types of abnormal behavior, and then fusing the outputs of each sub-model through model ensemble techniques to improve the accuracy of the base detection. The incremental model can absorb new fused data features in real time and dynamically adjust model parameters, effectively avoiding performance degradation caused by changes in data distribution. Its update frequency can be flexibly set according to the amount of data; for example, a parameter iteration is completed every 1000 new data points. Furthermore, the framework supports an adaptive model selection mechanism. Based on the data dimension, distribution characteristics, and business scenario attributes of the dynamically fused data, combined with model performance evaluation metrics such as AUC (Area Under the ROC Curve), precision, and recall, it dynamically selects the optimal model combination to execute the detection task and outputs anomaly probability values between 0 and 1.
[0074] S390. Perform deep anomaly detection on the anomaly detection association fusion data and the corrected target anomaly detection result according to the anomaly detection entity association graph to obtain the third dataset anomaly detection result.
[0075] The anomaly detection entity association graph can serve as a data association carrier for anomaly detection scenarios. The anomaly detection results of the third dataset can be obtained by performing deep anomaly detection based on the anomaly detection entity association graph.
[0076] Specifically, while performing anomaly detection on the first dataset based on the dynamically updated multi-dimensional anomaly matching rules, the business entities in the target business system and the relationships between them can be determined based on the anomaly detection associated fusion data and the corrected target anomaly detection results.
[0077] Based on this, an anomaly detection entity association graph can be constructed, using business entities as nodes and the relationships between these entities as edges. In a specific example, nodes can be entities such as accounts, transactions, and channels, and edges can be the relationships between entities, such as account-transaction association, transaction-channel association, or account-account association.
[0078] After constructing the anomaly detection entity association graph, association features can be extracted using graph embedding techniques to identify anomalous subgraphs within the graph. These anomalous subgraphs are then labeled with associated anomalous behaviors and used as the anomaly detection results for the third dataset. Optionally, the node attributes and edge weights of the anomaly detection entity association graph can be updated in real time based on the dynamically fused feature data.
[0079] S3100. Based on the anomaly detection results of the first dataset, the anomaly detection results of the second dataset, and the anomaly detection results of the third dataset, determine the comprehensive anomaly detection result of the target business system.
[0080] Among them, the comprehensive anomaly detection result can be a comprehensive anomaly detection judgment conclusion determined by integrating and analyzing the anomaly detection results of the first dataset, the second dataset, and the third dataset.
[0081] Correspondingly, the anomaly detection results from the first, second, and third datasets can be fused using preset fusion rules to obtain a comprehensive anomaly detection result for the target business system. This solution, through a layered architecture of rapid rule base filtering, accurate judgment using machine learning models, and graph neural network association mining, ensures efficient anomaly detection while enhancing the ability to identify complex, correlated anomalies, thereby effectively reducing false positives and false negatives during the anomaly detection process.
[0082] Optionally, if the overall anomaly detection result is greater than a first preset risk threshold, the risk level of the target business system is determined to be high risk, and the emergency warning mechanism of the target business system is triggered. This may include, but is not limited to, timely notification of staff and freezing of account transactions. If the overall anomaly detection result is less than a second preset risk threshold, the risk level of the target business system is determined to be low risk. If the overall anomaly detection result is greater than or equal to the second preset risk threshold, and less than or equal to the first preset risk threshold, the risk level of the target business system is determined to be medium risk, and the manual review mechanism of the target business system is triggered. For example, the first preset risk threshold can be 0.8, and the second preset risk threshold can be 0.2. This embodiment of the invention does not limit the specific values of the first and second preset risk thresholds.
[0083] Optionally, after determining the comprehensive anomaly detection results of the target business system, the data preprocessing strategy, dynamic fusion strategy, and anomaly detection model can be optimized in real time based on the detection results and business feedback to achieve end-to-end adaptive optimization. Specifically, features can be extracted from samples marked as anomalies but confirmed as normal by manual review to analyze the causes of false alarms, such as unreasonable fusion strategies, model parameter deviations, or improper rule settings. Information such as the fusion characteristics of falsely reported samples and detection process data can be recorded. Simultaneously, backtracking analysis can be performed on samples that were not detected but were subsequently found to be anomalies to extract key features of missed samples and analyze the causes of missed alarms, such as insufficient data fusion, the model failing to capture new anomaly features, or missing rules. Furthermore, key indicators such as the model's detection accuracy, false alarm rate, false negative rate, and detection latency can be calculated periodically to assess whether the current performance of the target business system meets the preset requirements.
[0084] Furthermore, based on the results of false positive and false negative analysis, data cleaning and standardization parameters, such as missing value imputation methods or outlier identification thresholds, can be adjusted to improve data preprocessing quality. Simultaneously, based on detection performance evaluation results, the selection logic of the fusion algorithm, weight calculation rules, and fusion dimension priorities can be adjusted; for example, if the false positive rate of a certain type of data source is high, its weight in the fusion can be reduced. In addition, false positive and false negative samples can be added to the model training set, and the parameters of the base model and incremental model can be updated through an incremental learning mechanism, while simultaneously optimizing the decision rules in the rule base and the construction logic of the association graph.
[0085] In addition, the optimized strategies and models can be verified in real time. If the performance is improved after optimization, the optimization results are retained; if the performance is not improved or even degraded, the configuration before optimization is rolled back and the optimization direction is re-analyzed, thus forming a closed-loop iterative mechanism of "detection-feedback-optimization-verification" to ensure continuous optimization of system performance.
[0086] Optionally, abnormal detection results can be visualized and real-time alerts can be provided to support staff in conducting real-time monitoring and timely intervention.
[0087] On the one hand, the dashboard can display key indicators, such as the number of real-time abnormal transactions, the distribution of high, medium or low risk anomalies, the trend of false positive and false negative rates, and the efficiency of multi-source data fusion. It can also display detailed information about abnormal samples, such as account information, transaction characteristics, fusion process data and the basis for detection results. It can also display the relationship graph structure of related anomalies, intuitively presenting the relationship between anomalies.
[0088] On the other hand, different early warning methods can be set according to the level of abnormal risk. High-risk anomalies can be alerted in real time through multiple channels, such as system pop-ups, SMS, telephone, or email; medium-risk anomalies can be alerted through system notifications; and low-risk anomalies can be logged. Early warning information may include, but is not limited to, the type of anomaly, the risk level, the account / transaction information involved, and suggested handling measures, to support risk control personnel in responding and handling quickly.
[0089] Optionally, applying the anomaly detection scheme provided in this embodiment of the invention to financial institutions such as banks or securities firms can not only provide them with accurate and efficient risk prevention and control technical support, reduce compliance costs and operational risks, but also adapt to the rapid evolution of business and risk models in the digital transformation of finance, providing important technical reference for the construction of intelligent risk control systems in the financial industry, and has broad application prospects and industry value.
[0090] This invention acquires anomaly detection correlation and fusion data of a target business system, and performs anomaly detection on the target business system based on the anomaly detection correlation and fusion data to obtain initial anomaly detection results. After obtaining the initial anomaly detection results, basic anomaly probabilities are generated based on the initial anomaly detection results corresponding to each anomaly detection model, and dynamic conflict coefficients are dynamically adjusted based on conflict coefficient correlation factors. Further, the basic anomaly probabilities are adjusted based on the dynamic conflict coefficients to obtain target anomaly detection results. After obtaining target anomaly detection results, anomaly detection result correction rules are generated based on the business rules of the target business system, and the target anomaly detection results are corrected based on the anomaly detection result correction rules to obtain corrected target anomaly detection results. Further, anomaly detection is performed on the anomaly detection correlation and fusion data of the first dataset based on dynamically updated multi-dimensional anomaly matching rules, and secondary anomaly detection correlation and fusion data of the first dataset are filtered based on the anomaly detection results of the first dataset. Then, secondary anomaly detection is performed on the secondary anomaly detection correlation and fusion data of the second dataset and the corrected target anomaly detection results based on the target machine learning model to obtain second dataset anomaly detection results. Simultaneously, after obtaining corrected target anomaly detection results, deep anomaly detection is performed on the anomaly detection correlation and fusion data of the third dataset and the corrected target anomaly detection results based on the anomaly detection entity correlation graph to obtain third dataset anomaly detection results. Furthermore, based on the anomaly detection results of the first, second, and third datasets, the comprehensive anomaly detection result for the target business system is determined. This solution addresses the issues of missed and false detections of abnormal behavior caused by the limited data dimensions in existing anomaly detection methods, thereby improving the accuracy and reliability of anomaly detection in business systems.
[0091] In the technical solution disclosed herein, the information collected is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data all comply with the relevant laws, regulations and standards of the relevant countries and regions, necessary confidentiality measures have been taken, and they do not violate public order and good morals. Corresponding operation entry points are provided for users to choose to authorize or refuse.
[0092] It should be noted that, in this embodiment of the invention, a corresponding operation entry can be provided to the user, allowing the user to choose to agree to or reject the automated decision result; if the user chooses to reject, the process will proceed to the expert decision-making process.
[0093] It should be noted that any arrangement or combination of the technical features in the above embodiments also falls within the protection scope of this invention.
[0094] Example 4 Figure 4 This is a schematic diagram of an anomaly detection device provided in Embodiment 4 of the present invention, as shown below. Figure 4 As shown, the device includes: an anomaly detection correlation fusion data acquisition module 410, an initial anomaly detection result determination module 420, a basic anomaly probability generation module 430, and a target anomaly detection result determination module 440, wherein: The anomaly detection association fusion data acquisition module 410 is used to acquire anomaly detection association fusion data of the target business system.
[0095] The initial anomaly detection result determination module 420 is used to perform anomaly detection on the target business system based on the anomaly detection association fusion data to obtain the initial anomaly detection result.
[0096] The basic anomaly probability generation module 430 is used to generate basic anomaly probabilities based on the initial anomaly detection results.
[0097] The target anomaly detection result determination module 440 is used to dynamically adjust the dynamic conflict coefficient based on the conflict coefficient correlation factors, and adjust the basic anomaly probability based on the dynamic conflict coefficient to obtain the target anomaly detection result.
[0098] This invention acquires anomaly detection correlation and fusion data of the target business system, and performs anomaly detection on the target business system based on the anomaly detection correlation and fusion data to obtain initial anomaly detection results. After obtaining the initial anomaly detection results, basic anomaly probabilities are generated based on the initial anomaly detection results corresponding to each anomaly detection model, and dynamic conflict coefficients are dynamically adjusted based on conflict coefficient correlation factors. Furthermore, the basic anomaly probabilities are adjusted based on the dynamic conflict coefficients to obtain the target anomaly detection results. The above solution solves the problem of missed and false detections of abnormal behavior caused by the one-sidedness of data dimensions in existing anomaly detection methods, and can improve the accuracy and reliability of anomaly detection in business systems.
[0099] Optionally, the target anomaly detection result determination module 440 is specifically used to: determine the credibility of the initial anomaly detection result and the performance indicators of each anomaly detection model; wherein, the anomaly detection model is used to perform anomaly detection on the target business system based on the anomaly detection association fusion data to obtain the initial anomaly detection result; and dynamically adjust the dynamic conflict coefficient based on the credibility of the initial anomaly detection result and the performance indicators of each anomaly detection model.
[0100] Optionally, the target anomaly detection result determination module 440 is further configured to: generate credibility weights based on the credibility of the initial anomaly detection result and the performance indicators of each anomaly detection model; determine the global conflict degree of the basic anomaly probability; and dynamically adjust the dynamic conflict coefficient based on the credibility weights and the global conflict degree.
[0101] Optionally, the anomaly detection association fusion data acquisition module 410 is specifically used to: acquire the data distribution status and core business element information of the target business system; and acquire the anomaly detection association fusion data of the target business system when it is determined that the change in the data distribution status is greater than a preset threshold, or when it is determined that the core business element information is updated.
[0102] Optionally, the anomaly detection association fusion data acquisition module 410 is further configured to: acquire anomaly detection association data of the target business system; when the data type of the anomaly detection association data is determined to be relational data, determine a first fusion weight for each relational anomaly detection association data based on the data quality and historical detection contribution of each anomaly detection association data; fuse each relational anomaly detection association data according to the first fusion weight to obtain a fusion result of the relational anomaly detection association data; when the data type of the anomaly detection association data is determined to be non-relational data, determine a second fusion weight for each non-relational anomaly detection association data through an attention mechanism; fuse each non-relational anomaly detection association data according to the second fusion weight to obtain a fusion result of the non-relational anomaly detection association data; and determine the anomaly detection association fusion data of the target business system based on the fusion result of the relational anomaly detection association data and the fusion result of the non-relational anomaly detection association data.
[0103] Optionally, the above apparatus may further include a target anomaly detection result correction module, used to generate anomaly detection result correction rules according to the business rules of the target business system; and to correct the target anomaly detection result according to the anomaly detection result correction rules.
[0104] Optionally, the above apparatus may further include a hierarchical anomaly detection module, used to perform first dataset anomaly detection on the anomaly detection association fusion data according to dynamically updated multi-dimensional anomaly matching rules, and to filter second anomaly detection association fusion data according to the first dataset anomaly detection results; to perform second anomaly detection on the second anomaly detection association fusion data and the corrected target anomaly detection results according to the target machine learning model, to obtain second dataset anomaly detection results; to perform deep anomaly detection on the anomaly detection association fusion data and the corrected target anomaly detection results according to the anomaly detection entity association graph, to obtain third dataset anomaly detection results; and to determine the comprehensive anomaly detection result of the target business system based on the first dataset anomaly detection result, the second dataset anomaly detection result, and the third dataset anomaly detection result.
[0105] The above-described anomaly detection device can execute the anomaly detection method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method. Technical details not described in detail in this embodiment can be found in the anomaly detection method provided in any embodiment of the present invention.
[0106] Since the anomaly detection device described above is capable of executing the anomaly detection method in the embodiments of the present invention, those skilled in the art can understand the specific implementation and various variations of the anomaly detection device in this embodiment based on the anomaly detection method described in the embodiments of the present invention. Therefore, how the anomaly detection device implements the anomaly detection method in the embodiments of the present invention will not be described in detail here. Any device used by those skilled in the art to implement the anomaly detection method in the embodiments of the present invention falls within the scope of protection of this application.
[0107] Example 5 Figure 5 A schematic diagram of an electronic device 10, which can be used to implement embodiments of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0108] like Figure 5 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0109] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0110] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as anomaly detection methods.
[0111] In some embodiments, the anomaly detection method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the anomaly detection method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the anomaly detection method by any other suitable means (e.g., by means of firmware).
[0112] Optionally, the anomaly detection method may include: acquiring anomaly detection correlation and fusion data of the target business system; performing anomaly detection on the target business system based on the anomaly detection correlation and fusion data to obtain initial anomaly detection results; generating basic anomaly probabilities based on each of the initial anomaly detection results; dynamically adjusting the dynamic conflict coefficient based on the conflict coefficient correlation factors, and adjusting the basic anomaly probabilities based on the dynamic conflict coefficient to obtain the target anomaly detection result.
[0113] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0114] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0115] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0116] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0117] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0118] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0119] It should be understood that the various forms of processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0120] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. An anomaly detection method, characterized in that, include: Obtain anomaly detection correlation and fusion data from the target business system; Anomaly detection is performed on the target business system based on the anomaly detection association fusion data to obtain initial anomaly detection results; A basic anomaly probability is generated based on the initial anomaly detection results described above; The dynamic conflict coefficient is dynamically adjusted based on the factors associated with the conflict coefficient, and the basic anomaly probability is adjusted based on the dynamic conflict coefficient to obtain the target anomaly detection result.
2. The method according to claim 1, characterized in that, The dynamic adjustment of the dynamic conflict coefficient based on the factors related to the conflict coefficient includes: The reliability of the initial anomaly detection results and the performance metrics of each anomaly detection model are determined; wherein, the anomaly detection model is used to perform anomaly detection on the target business system based on the anomaly detection correlation fusion data to obtain the initial anomaly detection results; The dynamic conflict coefficient is dynamically adjusted based on the reliability of the initial anomaly detection results and the performance indicators of each anomaly detection model.
3. The method according to claim 2, characterized in that, The step of dynamically adjusting the dynamic conflict coefficient based on the reliability of the initial anomaly detection results and the performance metrics of each anomaly detection model includes: A confidence weight is generated based on the confidence of the initial anomaly detection results and the performance metrics of each anomaly detection model. Determine the global conflict degree of the basic anomaly probability; The dynamic conflict coefficient is dynamically adjusted based on the credibility weight and the global conflict degree.
4. The method according to claim 1, characterized in that, The acquisition of anomaly detection correlation and fusion data of the target business system includes: Obtain the data distribution status and core business element information of the target business system; If the change in the data distribution state is determined to be greater than a preset threshold, or if the core business element information is determined to be updated, the anomaly detection associated fusion data of the target business system is obtained.
5. The method according to claim 1, characterized in that, The acquisition of anomaly detection correlation and fusion data of the target business system includes: Obtain the anomaly detection associated data of the target business system; When it is determined that the data type of the anomaly detection associated data is relational data, the first fusion weight of each relational anomaly detection associated data is determined based on the data quality and historical detection contribution of each anomaly detection associated data. The relational anomaly detection associated data are fused according to the first fusion weight to obtain the fusion result of the relational anomaly detection associated data; When it is determined that the data type of the anomaly detection associated data is non-relational data, the second fusion weight of each non-relational anomaly detection associated data is determined through an attention mechanism; The non-relational anomaly detection associated data are fused according to the second fusion weight to obtain the fusion result of the non-relational anomaly detection associated data; Based on the fusion results of the relational anomaly detection association data and the non-relational anomaly detection association data, the anomaly detection association fusion data of the target business system is determined.
6. The method according to claim 1, characterized in that, After obtaining the target anomaly detection result, the following is also included: Generate anomaly detection result correction rules based on the business rules of the target business system; The target anomaly detection result is corrected according to the anomaly detection result correction rule.
7. The method according to claim 6, characterized in that, After obtaining the target anomaly detection result, the following is also included: The first dataset anomaly detection is performed on the anomaly detection associated fusion data according to the dynamically updated multi-dimensional anomaly matching rules, and the second dataset anomaly detection associated fusion data is filtered according to the anomaly detection results of the first dataset. Based on the target machine learning model, secondary anomaly detection is performed on the secondary anomaly detection associated fusion data and the corrected target anomaly detection results to obtain the anomaly detection results of the second dataset. Based on the anomaly detection entity association graph, deep anomaly detection is performed on the anomaly detection association fusion data and the corrected target anomaly detection results to obtain the third dataset anomaly detection results. Based on the anomaly detection results of the first dataset, the second dataset, and the third dataset, the comprehensive anomaly detection result of the target business system is determined.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that is executed by the at least one processor to enable the at least one processor to perform the anomaly detection method according to any one of claims 1-7.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the anomaly detection method according to any one of claims 1-7.
10. A computer program product, characterized in that, It includes a computer program / instruction, wherein the computer program / instruction, when executed by a processor, implements the anomaly detection method according to any one of claims 1-7.