Emergency operation and maintenance anomaly detection system and method based on double network time sequence staggered learning

By employing a dual-network temporal interleaved learning method, the problem of inaccurate identification caused by temporal misalignment and data anomalies in emergency communication networks was solved. This method enables collaborative identification and credibility assessment of local mutations and trend anomalies, thereby improving the accuracy of anomaly detection and early warning capabilities.

CN122640331APending Publication Date: 2026-08-25XINGHE SHUTOU (NANJING) DIGITAL TECHNOLOGY CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611116506.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-27
Publication Date
2026-08-25

AI Technical Summary

Technical Problem

Existing technologies in emergency communication networks and emergency management information systems suffer from problems such as timing misalignment, data loss, sudden noise, and redundant conflicts, leading to inaccurate anomaly identification results. In particular, when local high disturbances and persistent anomalies are intertwined, it is difficult to effectively identify and locate the anomaly boundaries, resulting in false triggering and insufficient reliability of early warnings.

Method used

A dual-network temporal interleaved learning method is adopted. By using dual-scale temporal segmentation and dual-network interleaved feedback correction, combined with temporal continuity reliability classification, a dual-path temporal sample set of short-range and long-range temporal segments is constructed. The first and second detection networks are used to learn local fluctuation and continuous evolution characteristics, respectively, to perform collaborative anomaly discrimination. Reliability judgment and level classification are then performed by combining the continuity relationship between adjacent temporal intervals.

Benefits of technology

It improves the accuracy and reliability of anomaly detection during emergency operation and maintenance, reduces false alarms from noise and lag in identifying continuous anomalies, realizes the transformation of operation and maintenance mode from passive firefighting to proactive prevention, and provides a basis for tiered handling decisions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122640331A_ABST
    Figure CN122640331A_ABST
Patent Text Reader

Abstract

The application discloses an emergency operation and maintenance anomaly detection system and method based on double-network time sequence staggered learning, relates to the technical field of emergency operation and maintenance anomaly detection, and performs directional collection, time alignment, anomaly identification and correction on emergency operation and maintenance full-link information system node operation data to construct a standardized operation and maintenance time sequence dataset; further, short-range time sequence segments and long-range time sequence segments are extracted according to time advancing relations and are respectively input into a first detection network and a second detection network to realize parallel learning of local fluctuation characteristics and continuous evolution characteristics; on this basis, collaborative anomaly discrimination is completed through double-network staggered feedback, and in combination with the continuation relation of the anomaly segments in adjacent time sequence intervals, anomaly event credibility evaluation, grade division and early warning information output are completed, so that the accuracy, reliability and graded early warning capability of emergency operation and maintenance anomaly detection are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of emergency operation and maintenance anomaly detection technology for government information systems, and is particularly applicable to the intelligent operation and maintenance support of emergency communication networks and emergency management information systems. Specifically, it relates to an emergency operation and maintenance anomaly detection system and method based on dual-network temporal interleaving learning. Background Technology

[0002] In the current "smart emergency response" operation and maintenance scenario, the operating status of emergency communication networks and emergency management information systems changes rapidly, there are many business stages, and the types of participating nodes are complex. The data reported by different terminals generally differ in terms of collection frequency, time base and data format, which can easily cause problems such as timing misalignment, data loss, sudden noise and redundant conflicts, thereby affecting the accuracy of anomaly identification results.

[0003] Most existing time-series anomaly detection methods focus on a single time scale. Some methods emphasize identifying localized abrupt anomalies such as short-term spikes, traffic surges, sudden increases in response latency, and service interruptions. While they possess some transient response capabilities, they are insufficient in characterizing anomalous processes such as continuous system state shifts, slow degradation, and trend instability. Other methods emphasize long-term time-series modeling and can identify continuous evolutionary features, but they still have shortcomings in anomaly initiation boundary location, early fluctuation capture, and random noise differentiation. Especially during emergency operations and maintenance, real anomalies often do not simply manifest as instantaneous abrupt changes or single trend deviations, but rather as a mixture of localized high disturbances and persistent anomalies. Without a multi-scale collaborative analysis mechanism, problems such as delayed identification of persistent anomalies, numerous instantaneous false triggers, unclear anomaly boundaries, and insufficient warning reliability are easily caused. Therefore, there is an urgent need for an emergency operations and maintenance anomaly detection system and method that can take into account both localized abrupt changes and continuous evolution, improve the reliability of anomaly discrimination through dual-network interleaved learning, and combine temporal continuity relationships to complete reliability assessment and level classification. Summary of the Invention

[0004] To address the shortcomings of existing technologies, this invention proposes an emergency operation and maintenance anomaly detection system and method based on dual-network temporal interleaved learning. By combining dual-scale temporal segmentation and dual-network interleaved feedback correction with temporal continuity reliability grading, it achieves the technical effect of balancing transient and trend anomaly identification, reducing false alarms and missed alarms, and improving the accuracy of tiered early warning.

[0005] The technical solution to achieve the objective of this invention is as follows:

[0006] On the one hand, the emergency operation and maintenance anomaly detection method based on dual-network temporal interleaved learning includes the following steps:

[0007] Collect operational data from information system nodes, perform time alignment and anomaly correction processing, and obtain an operation and maintenance time-series dataset;

[0008] Based on the operation and maintenance time series dataset, short-term and long-term time series segments are extracted according to the time progression relationship to obtain a dual-path time series sample set;

[0009] The dual-path time series sample set is input into the first detection network and the second detection network respectively, and local fluctuation and continuous evolution feature learning is performed to obtain transient abnormal response and trend abnormal representation to construct dual-network anomaly set;

[0010] Based on the dual-network anomaly set, interleaved learning processing is performed. High-perturbation segments are fed back to the second detection network to correct the continuous anomaly boundary, and continuous deviation from the anomaly segment is fed back to the first detection network to suppress transient anomaly response, thus obtaining the collaborative anomaly discrimination result.

[0011] Based on the collaborative anomaly discrimination results, the credibility of the abnormal event is determined and the level is classified by combining the continuity relationship of the abnormal segment in adjacent time intervals, and the anomaly detection results and early warning information are output.

[0012] Furthermore, staggered learning processing is performed to generate collaborative anomaly detection results, including:

[0013] Based on the pre-training results of the first and second detection networks, preset transient anomaly judgment thresholds and preset trend anomaly representation thresholds are initialized respectively, serving as a unified benchmark for staggered learning.

[0014] Traverse each time series unit in the dual-network anomaly set, identify the high-perturbation segments that repeatedly appear in the transient anomaly response, and feed them back to the second detection network to correct the trend anomaly characterization threshold and persistent anomaly boundary of the corresponding long-range time series segments.

[0015] Identify anomalous segments that continuously deviate from the trend anomaly representation and feed them back to the first detection network to perform suppression correction or enhancement correction on the transient anomaly response value at the corresponding time position;

[0016] The corrected transient anomaly response value and the trend anomaly characterization value are weighted and fused to obtain the collaborative anomaly discrimination value and encapsulate it to generate the collaborative anomaly discrimination result.

[0017] Further credibility determination includes:

[0018] The collaborative anomaly discrimination results are subjected to initial screening of anomaly time sequence units and aggregation of continuous anomaly segments to form a set of continuous anomaly segments;

[0019] For each consecutive abnormal segment, adjacent time intervals are defined forward and backward based on the start and end time units of the segment. The proportion of abnormal time units in adjacent time intervals is counted to obtain the abnormal continuity of adjacent intervals.

[0020] A temporal continuity credibility factor is constructed based on the number of consecutive temporal units in a segment and the abnormal continuity of adjacent intervals; a dual-network feature matching credibility factor is constructed based on the coverage of abnormal segments with high-disturbance segments and continuously deviating abnormal segments; and a data validity credibility factor is constructed based on the proportion of empty temporal units in the data corresponding to the segment and the coverage proportion of long-term missing labels.

[0021] A fusion process is performed on each credibility factor to obtain the credibility value of the abnormal event. The abnormal event level is classified according to the credibility value and untrustworthy abnormal events are eliminated.

[0022] Furthermore, methods for obtaining highly perturbated segments include:

[0023] Traverse all time-series units within the dual-network anomaly set and mark time-series units whose transient anomaly response values ​​exceed the preset transient anomaly judgment threshold as high-perturbation time-series units;

[0024] Using the time series coverage of a single long-range time series segment as the statistical interval, a continuous time series segment that appears multiple times within the same long-range time series segment and contains a preset number of consecutive high-perturbation time series units is defined as a high-perturbation segment. Its starting time series unit number, ending time series unit number, average transient abnormal response value within the segment, and frequency of occurrence are marked.

[0025] Furthermore, methods for obtaining continuously deviating abnormal segments include:

[0026] Traverse all time series units in the dual network anomaly set and mark time series units whose trend anomaly representation values ​​exceed the preset trend anomaly representation threshold as trend deviation time series units.

[0027] A time series segment consisting of trend deviation time series units with a consecutive number reaching a preset consecutive threshold is defined as a continuous deviation abnormal segment, and its starting time series unit number, ending time series unit number, and average trend abnormality characterization value within the segment are marked.

[0028] Furthermore, the first detection network performs local fluctuation feature learning on short-range time segments to obtain transient anomaly responses, including:

[0029] Perform parameter-by-parameter standardization on the core performance parameters within the short-range time segment to generate a standardized input feature matrix that matches the input dimension of the first detection network;

[0030] The standardized input feature matrix is ​​sequentially input into the multi-scale one-dimensional convolution module and the gated temporal unit module of the coding segment to extract local fluctuation features under different time receptive fields and obtain high-dimensional abstract coding features.

[0031] The high-dimensional abstract encoded features are input into the one-dimensional deconvolution module of the decoding segment, and the output is a core performance parameter reconstruction matrix with the same dimension as the input.

[0032] Normalization is performed on the parameter-by-parameter reconstruction error between the standardized input feature matrix and the core performance parameter reconstruction matrix, and the normalized error is mapped back to the original time series link to generate a transient abnormal response.

[0033] Furthermore, the second detection network performs continuous evolution feature learning on long-range time segments to obtain trend anomaly representations, including:

[0034] The core performance parameters and auxiliary operating parameters within the long-range time series segment are fused with features, and the fused parameters are standardized to generate a standardized input feature matrix.

[0035] The standardized input feature matrix is ​​input into the stacked bidirectional long short-term memory network module and the multi-head temporal self-attention module of the encoding segment to extract the continuous evolution features within the long temporal interval and obtain the encoded output features.

[0036] The encoded output features are input into the fully connected decoding module and the bidirectional long short-term memory network module of the decoding segment, and the output is a reconstruction matrix of all node running parameters.

[0037] Normalization is performed on the parameter-by-parameter trend deviation error between the input feature matrix and the reconstructed matrix of all node running parameters. The normalized error is then mapped back to the original time series link to generate a trend anomaly representation.

[0038] Furthermore, short-range and long-range time-series segments are extracted to obtain a dual-path time-series sample set, including:

[0039] Based on the ascending order of the calibrated timestamps, and with the timing unit number as the unique timing anchor point, a continuous timing context chain is constructed.

[0040] The timing context chain is continuously slid segmented using a preset short-range fixed length and a preset short-range step size, and the short-range timing segments are extracted using the core performance parameters within the short-range timing segments as the main data body.

[0041] Continuous sliding segmentation is performed with a preset long-range fixed length and a preset long-range step size, and long-range time series segments are extracted with all node running parameters as the main data body.

[0042] A unique segment identifier is generated for each time series segment, and the starting time series unit number, ending time series unit number, and center time series unit number are marked. The center time series unit number is used as the unique association key to establish a time series mapping index table between short-range time series segments and long-range time series segments.

[0043] Differential sample validity checks are performed on the two time series segments respectively, and invalid samples with the proportion of empty time series units and the proportion of long-term missing label coverage exceeding their respective preset thresholds are removed to form a two-channel time series sample set.

[0044] Further anomaly correction handling includes:

[0045] The abnormal types of information system node operation data are classified into missing abnormal data, mutation abnormal data, and redundant abnormal data.

[0046] For missing data, short-term missing data is filled by linear interpolation of adjacent valid time series units, and long-term missing data is filled by time-weighted average of valid data from the same period in history and labeled with long-term missing data.

[0047] For abrupt abnormal data, a sliding time window is used to identify abnormal values, and the values ​​in the corresponding parameter fields of a preset number of consecutive valid time series units are replaced and corrected.

[0048] For redundant abnormal data, retain the only valid entry with the highest timestamp accuracy and complete checksum. Once the data entry is corrected, an anomaly correction tag is generated synchronously.

[0049] Secondly, this invention provides an emergency operation and maintenance anomaly detection system based on dual-network temporal interleaving learning, including a data acquisition module, a sample segmentation module, a dual-network learning module, an interleaving correction module, and a judgment and early warning module:

[0050] Data acquisition module: Collects operational data from information system nodes and performs time alignment and anomaly correction to obtain an operation and maintenance time-series dataset;

[0051] Sample segmentation module: Based on the operation and maintenance time series dataset, extract short-range time series segments and long-range time series segments to obtain a dual-path time series sample set;

[0052] Dual-network learning module: Input the dual-path time series sample sets into the first detection network and the second detection network respectively, perform local fluctuation feature learning and continuous evolution feature learning respectively, obtain transient abnormal response and trend abnormal representation, and construct dual-network anomaly set;

[0053] Interleaving correction module: Based on the dual network anomaly set, interleaving learning processing is performed. Highly perturbation segments are fed back to the second detection network to correct the continuous anomaly boundary, and continuously deviating anomaly segments are fed back to the first detection network to suppress transient anomaly response, so as to obtain the collaborative anomaly discrimination result.

[0054] Judgment and early warning module: Based on the collaborative anomaly discrimination results, combined with the continuity relationship of anomaly segments in adjacent time intervals, the module performs credibility judgment and level classification of anomaly events, and outputs anomaly detection results and early warning information.

[0055] Compared with the prior art, the advantages of this invention are as follows:

[0056] 1. By constructing a dual-path time series sample set combining short-range and long-range time series segments, and by using the first and second detection networks to learn local fluctuation characteristics and continuous evolution characteristics respectively, it can simultaneously identify transient and trend anomalies in the emergency operation and maintenance scenarios of intelligent emergency-related information systems, improve the comprehensiveness and accuracy of anomaly detection under complex IT infrastructure conditions, and is particularly suitable for intelligent operation and maintenance support of emergency department command and dispatch platforms and emergency communication networks;

[0057] 2. By establishing a dual-network temporal staggered learning mechanism, high-disturbance segments are fed back to the second detection network to correct the boundaries of continuous anomalies, and continuously deviating anomaly segments are fed back to the first detection network to suppress instantaneous false triggers. In addition, credibility judgment and level classification are performed by combining the continuity relationship of adjacent time intervals. This can effectively reduce noise false alarms, improve the problem of lag in continuous anomaly identification, improve the reliability of anomaly judgment results and early warning classification capabilities, provide emergency management departments with a basis for graded disposal decisions, and realize the transformation of operation and maintenance mode from passive firefighting to proactive prevention. Attached Figure Description

[0058] Figure 1 Flowchart of an emergency operation and maintenance anomaly detection method based on dual-network temporal interleaved learning;

[0059] Figure 2 This is a flowchart illustrating the dual-network learning structure and anomaly representation generation process in this invention.

[0060] Figure 3 This is a flowchart of the credibility determination and level classification of abnormal events in this invention;

[0061] Figure 4 This is a structural diagram of the emergency operation and maintenance anomaly detection system based on dual-network temporal interleaved learning in this invention. Detailed Implementation

[0062] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present invention and the specific features in the embodiments are detailed descriptions of the technical solution of the present invention, rather than limitations thereof.

[0063] Example 1:

[0064] This invention discloses an emergency operation and maintenance anomaly detection method based on dual-network temporal interleaved learning, comprising the following steps:

[0065] S1: Collect information system node operation data during emergency operation and maintenance, and perform time alignment and anomaly correction processing to obtain operation and maintenance time series dataset.

[0066] S2: Based on the operation and maintenance time series dataset, perform time series segmentation and context organization on continuous data segments according to the time progression relationship, extract short-range time series segments reflecting local mutation characteristics and long-range time series segments reflecting continuous evolution characteristics, and form a dual-path time series sample set.

[0067] S3: Input the dual-path time series sample set into the first detection network and the second detection network respectively. The first detection network performs local fluctuation feature learning on the short-range time series segment to obtain transient abnormal response, and the second detection network performs continuous evolution feature learning on the long-range time series segment to obtain trend abnormal representation, thus constructing a dual-network anomaly set.

[0068] S4: Based on the dual-network anomaly set, interleaved learning processing is performed according to the correspondence of the same temporal position. The high-perturbation segments that repeatedly appear in the transient anomaly response are fed back to the second detection network to correct the continuous anomaly boundary, and the continuously deviating anomaly segments in the trend anomaly representation are fed back to the first detection network to suppress the transient anomaly response, forming a collaborative anomaly discrimination result.

[0069] S5: Based on the collaborative anomaly discrimination results, combined with the continuity relationship of anomaly segments in adjacent time intervals, perform credibility judgment and level classification on anomaly events, and output the corresponding anomaly detection results and early warning information.

[0070] refer to Figure 1 , Figure 1 This is a flowchart of an emergency operation and maintenance anomaly detection method based on dual-network temporal interleaved learning.

[0071] In step S1, information system node operation data is collected during emergency operation and maintenance, and time alignment and anomaly correction processing are performed to obtain an operation and maintenance time series dataset, including:

[0072] S101: Targeted collection and standardized conversion of node operation data in the emergency operation and maintenance information system.

[0073] Define the data collection boundaries and specifications for information system operation data corresponding to the entire emergency operation and maintenance business chain. The entire emergency operation and maintenance business chain covers the entire process of emergency response initiation, fault handling, on-site operation and maintenance, and system recovery. The collection boundary is all terminal nodes included in the emergency operation and maintenance management system, including government cloud server clusters, command and dispatch platform nodes, video surveillance terminals, emergency communication gateways, database servers, and network switching equipment. Divide the information system operation data to be collected into two categories: core performance parameters and auxiliary operation parameters, and implement differentiated and targeted collection.

[0074] Specifically, core performance parameters are defined as transient and sensitive parameters that directly reflect the emergency operation status of the information system. These parameters cover six categories: CPU utilization, memory usage, disk I / O throughput, network latency, API response time, and database connection pool usage. A fixed collection frequency of 10 milliseconds is set to perform high-frequency synchronous collection of core performance parameters, accurately capturing the transient changes in system performance under emergency scenarios. Auxiliary operation parameters are defined as slowly changing state parameters that reflect the overall operation status of the information system. These parameters cover three categories: service process status, cumulative system online time, and business module availability. A fixed collection frequency of 1 second is set to perform low-frequency collection of auxiliary operation parameters. This ensures full coverage of operation status data while reducing resource consumption on the collection and storage sides, completing the targeted collection of information system operation data across the entire emergency operation and maintenance chain.

[0075] A unified structured transformation is performed on all collected information system node operation data to generate standardized data entries, each containing five fixed fields: source data type identifier, original timestamp, original value, unique identifier of the acquisition terminal, and data belonging to the business stage. Among them, the source data type identifier is a unique type code that distinguishes core performance parameters from auxiliary operation parameters, the unique identifier of the acquisition terminal is the unique hardware serial number (SN code) of the corresponding device, and the data belonging to the business stage is the code of the emergency operation and maintenance full business link node to which the corresponding data belongs. The structured transformation eliminates the heterogeneous differences in data format among multiple acquisition terminals, forming a standardized data source subset of information system node operation data.

[0076] S102: Time alignment processing of information system node operation data based on a unified time base.

[0077] A unified time reference with millisecond-level precision and UTC+8 time zone, synchronized with the National Time Service Center, is adopted. The local system clocks of all acquisition terminals are synchronized with the unified time reference via the NTP network time protocol. The clock deviation value between the local clock of each acquisition terminal and the unified time reference is calculated. A clock deviation threshold of 50 milliseconds is preset. This threshold is determined based on the minimum duration of transient characteristics of core performance parameters in emergency operation and maintenance scenarios, which is usually 10-50 milliseconds and does not exceed 5 times the minimum acquisition cycle of core performance parameters, so as to avoid distortion of transient characteristics caused by timing misalignment. For acquisition terminals whose clock deviation value exceeds the preset clock deviation threshold, linear offset calibration is performed on the original timestamps of the standardized data entries they acquire based on the clock deviation value. The original timestamps are superimposed with the corresponding clock deviation compensation amount to generate calibrated timestamps, thereby eliminating clock synchronization errors caused by asynchronous acquisition from multiple terminals.

[0078] A fixed-duration time series unit of 100 milliseconds is set as the smallest time series unit for time series processing. Each time series unit is a continuous, non-overlapping, equally spaced time series interval, and each time series unit corresponds to a unique time series unit number. All standardized data entries from the standardized data source subset of information system node operation data are mapped to a continuous time series grid with a unified time reference as the coordinate axis according to the calibrated timestamps. All information system node operation data entries within the same time series unit are aggregated to form a time series parameter group for information system node operation, with the time series unit as the unit. Time series units without valid standardized data entries are marked as empty time series units, and a time series integrity tag is generated synchronously to strictly distinguish between empty time series units and valid time series units with a value of 0, avoiding data misjudgment in subsequent feature extraction stages. Specifically, an empty time series unit is one where no collected data is reported, and a valid time series unit with a value of 0 is one where the collected and reported value is valid operating condition data. Time alignment processing of all information system node operation data is completed, and the time-normalized information system node operation data is output.

[0079] S103: Hierarchical anomaly identification and correction processing for time-series regularized data.

[0080] Three types of fixed abnormal data are predefined with clear judgment boundaries: missing abnormal data (time series data marked as empty time series units with no valid standardized data entries); abrupt abnormal data (abnormal operating condition values ​​whose numerical fluctuations exceed the reasonable range of parameter statistics); and redundant abnormal data (invalid data entries that are repeatedly collected or have conflicting values ​​within the same time series dimension). For the runtime sequence parameter group of the information system node within each time series unit after time series normalization, a full classification and identification of abnormal data is performed.

[0081] For abruptly abnormal data, the sliding window 3σ criterion is used for identification. A sliding time window with a length of 100 consecutive time units is set. The sample mean and sample standard deviation are calculated based on the effective data of the target parameter field within the window. Values ​​that exceed the reasonable fluctuation range of ±3σ are identified as abruptly abnormal data.

[0082] For missing anomalous data, based on the temporal integrity tag, the corresponding data marked as empty temporal units are directly identified as missing anomalous data;

[0083] For redundant abnormal data, a preset business rule matching method is used for identification. The preset business rules include: if there are two or more data entries under the same acquisition terminal, the same parameter field, and the same calibrated timestamp, it is determined as duplicate data acquisition; if the value of the same parameter field in the same time series unit exceeds the upper or lower limit of the normal operating performance baseline of the information system, it is determined as numerical conflict data, such as preset thresholds for CPU utilization not exceeding 95%, memory occupancy not exceeding 90%, and network latency not exceeding 500ms. The above thresholds are determined based on the 99th percentile of the historical normal operating data of the emergency management system for more than 3 years; the adaptation and adjustment rules for different equipment models / business scenarios are as follows: for high-performance server clusters, the CPU utilization threshold can be increased to 98%, and the memory occupancy threshold can be increased to 95%; for business scenarios during peak emergency response periods, the network latency threshold can be increased to 1000ms; the judgment logic for exceeding the threshold is: if the parameter value exceeds the corresponding threshold in 3 consecutive time series units, it is determined as numerical conflict data, and a single exceedance is determined as normal fluctuation; both types of data belong to redundant abnormal data.

[0084] Set up a tiered anomaly correction strategy to perform differentiated correction processing on all identified anomaly data:

[0085] For missing data, a threshold of 5 consecutive time series units is set as the missing type classification. For short-term missing data with 5 or fewer consecutive missing time series units, data completion is performed using linear interpolation of the corresponding parameter fields of adjacent valid time series units. For long-term missing data with more than 5 consecutive missing time series units, data completion is performed using the time-weighted average of valid time series data from the same period within the past 7 natural days under the same device, business stage, and working conditions. The closer the historical data is to the current time, the higher the weight. The weight coefficients are inversely proportional to the time distance and the total weight is 1. Simultaneously, long-term missing labels are marked on the completed data.

[0086] For abruptly abnormal data, after identification using the sliding window 3σ criterion, the data is not directly replaced. Instead, it is labeled as abruptly abnormal and the original value is retained. Replacement correction is only performed when the abruptly abnormal data is determined to be single-point random noise, i.e., there is no other abnormal data within the three consecutive time units before and after it. For abruptly abnormal data that is determined to be a suspected real anomaly, the original value is retained for subsequent feature learning by the first detection network to avoid premature elimination of transient abrupt features.

[0087] For redundant and abnormal data, prioritize retaining the unique and valid entry with the highest original timestamp accuracy and complete data checksum reported by the acquisition terminal, and delete the rest of duplicate and redundant data.

[0088] After completing the correction of all abnormal data, abnormal correction tags are generated synchronously for all data entries that have undergone correction operations. Finally, the corrected full information system node runtime sequence data and corresponding tags are output.

[0089] S104: Standardized construction of operation and maintenance time series datasets.

[0090] Using a 100-millisecond time series unit as the smallest data unit under a unified time benchmark, and following the ascending order of time progression, the runtime sequence data of all information system nodes that have completed anomaly correction processing, along with the corresponding time series integrity markers, anomaly correction tags, and long-term missing tags, are uniformly collected and standardized. This process clarifies four core field fields for each data entry: a unique time series identifier, calibrated timestamp information, node runtime parameter field, and tag field. The unique time series identifier is generated by combining "time series unit number + unique identifier of the acquisition terminal + parameter field code," serving as the unique primary key for each data entry to avoid data duplication and conflicts. Ultimately, this results in a standardized operation and maintenance time series dataset covering the entire emergency operation and maintenance business chain, all device nodes, and all parameter fields.

[0091] In step S2, based on the operation and maintenance time-series dataset, continuous data segments are segmented and context-organized according to their temporal progression. Short-range time-series segments reflecting local mutation characteristics and long-range time-series segments reflecting continuous evolution characteristics are extracted to form a dual-path time-series sample set, including:

[0092] S201: Construction of time-series context benchmarks for operation and maintenance time-series datasets.

[0093] Using a standardized operation and maintenance time-series dataset as the sole input, and a time-series unit with a fixed duration of 100 milliseconds as the smallest granularity, and based on the ascending order of calibrated timestamps, a continuous time-series context chain is constructed. The time-series context chain uses the time-series unit number as the unique time-series anchor point, completely connecting the runtime time-series data of all information system nodes under the same data acquisition terminal with a unique identifier and the same data belonging to the same business stage. It synchronously associates the time-series integrity tag, anomaly correction tag, and long-term missing tag corresponding to each data, clarifying the contextual relationship of the working condition data corresponding to each time-series unit.

[0094] Based on the abnormal characteristics of emergency operation and maintenance scenarios, the core rules for time-series segmentation are defined: core performance parameters are used as the core carrier of transient mutation features, and the full set of parameters including core performance parameters and auxiliary operation parameters are used as the complete carrier of continuous evolution features. This defines parameter boundaries and time constraints for the directional extraction of dual-path time-series segments, ensuring that the segmented time-series segments can fully match the feature learning objectives of the subsequent dual networks.

[0095] S202: Directed extraction and context organization of short-range time segments.

[0096] The short-range time series segment is a continuous time series data unit that focuses on a local time series interval and is used to capture the transient change characteristics of system operating conditions. Its extraction and context organization process is as follows:

[0097] The core performance parameters for short-range time-series segments are defined as follows: The fixed length of a short-range time-series segment is 20 consecutive time-series units. The quantification method for determining the fixed length of a short-range time-series segment is to statistically analyze the average duration of 10 typical emergency operation and maintenance transient anomalies, such as API response timeouts and database connection pool exhaustion, and then take the number of time-series units corresponding to the 95th percentile value. The adaptation adjustment rules for different emergency operation and maintenance business stages or equipment types are as follows: for database server nodes, the length can be adjusted to 30 time-series units; for network switching equipment nodes, the length can be adjusted to 15 time-series units. The verification standard for the reasonableness of the values ​​is: under the fixed length of the short-range time-series segment, the complete capture rate of transient anomaly features is not less than 98%. The sliding segment step size is set to 1 time-series unit to ensure that adjacent short-range time-series segments continuously overlap, covering all time-series positions in the operation and maintenance time-series dataset without omission, and avoiding missed detection of transient anomaly features.

[0098] Perform sliding time series segmentation and fragment organization: According to the time progression relationship, the time series context chain is continuously slid segmented with a set length and step size to generate several consecutive short-range time series fragments; each short-range time series fragment uses core performance parameters as the only data subject, retains the full granular data of the original 100-millisecond time series unit, does not perform any downsampling or smoothing processing, and fully preserves the fluctuation details within the local time series interval; simultaneously, all label fields within the corresponding time series range are associated with each short-range time series fragment to complete the fragment-level context organization.

[0099] Standardized encapsulation of short-range time-series segments: A unique segment identifier is generated for each short-range time-series segment, clearly marking its five core positioning fields: start time-series unit number, end time-series unit number, center time-series unit number, unique identifier of the acquisition terminal, and data belonging to the service stage. Among them, the center time-series unit number is the time-series unit number corresponding to the midpoint of the time-series coverage of the segment, which serves as the unique anchor point for subsequent dual-path sample time-series alignment; finally, a standardized set of short-range time-series segments is formed.

[0100] S203: Targeted extraction and context organization of long-range time-series segments.

[0101] The long-range time series segment is a continuous time series data unit that covers the entire operating condition evolution cycle and is used to capture the characteristics of the continuous deterioration trend of the system's operating state. Its extraction and context organization process is as follows:

[0102] The core performance parameters for long-range time-series segmentation are defined as follows: the fixed length of the long-range time-series segment is 2000 consecutive time-series units, corresponding to a duration of 200 seconds. The fixed length of the long-range time-series segment is determined by statistically analyzing the average evolution cycle of eight typical emergency operation and maintenance trend anomalies, such as memory leaks and disk performance degradation, and taking the number of time-series units corresponding to the 90th percentile value. The adaptation adjustment rules for different emergency operation and maintenance business stages or equipment types are as follows: for peak emergency response periods, the length can be adjusted to 1000 time-series units; for routine operation and maintenance periods, the length can be adjusted to 3000 time-series units. The verification standard for the reasonableness of the values ​​is: under the fixed length of the long-range time-series segment, the advance identification time of trend anomalies is not less than 30 seconds. The sliding segmentation step size is set to 10 time-series units to ensure that trend features are covered without omissions while reducing sample redundancy and reducing the computational resource consumption for subsequent feature learning.

[0103] Perform sliding time series segmentation and fragment organization: According to the time progression relationship, with the fixed length and sliding segment step size set above, perform continuous sliding segmentation on the time series context chain to generate several continuous long-term time series fragments; each long-term time series fragment uses the full node operating parameters of core performance parameters + auxiliary operating parameters as the data body, completely retains the full-link information of the working condition evolution within the time series interval, and synchronously associates all tag fields within the corresponding time series range for each long-term time series fragment, completes fragment-level context organization, and ensures that the continuous evolution process of the system's operating state can be completely restored.

[0104] Standardized encapsulation of long-range time-series segments: A unique segment identifier is generated for each long-range time-series segment, clearly marking its five core positioning fields: start time-series unit number, end time-series unit number, center time-series unit number, unique identifier of the acquisition terminal, and data belonging to the service stage. Among them, the center time-series unit number is the time-series unit number corresponding to the midpoint of the time-series coverage of the segment. It is completely consistent with the positioning field system of short-range time-series segments, providing a unified benchmark for the subsequent construction of the time-series correspondence of dual-path samples; finally, a standardized set of long-range time-series segments is formed.

[0105] S204: Standardized construction and compliance verification of dual-channel timing sample sets.

[0106] Based on the temporal coverage of long-range time series segments, a many-to-one mapping index table between short-range and long-range time series segments is established to clarify the correspondence between each long-range time series segment and all short-range time series segments within its coverage range. For any short-range time series segment, its corresponding long-range time series segment is all long-range time series segments covering the central temporal unit of that short-range segment. During the interleaved learning process, when processing the high-perturbation features of a short-range time series segment, it is fed back to all long-range time series segments covering that short-range segment. When processing the continuous deviation features of a long-range time series segment, it is fed back to all short-range time series segments within the coverage range of that long-range segment, thus solving the feedback misalignment problem caused by temporal center mismatch.

[0107] Set differentiated sample validity verification rules to remove low-confidence invalid samples:

[0108] For short-range time series fragment sets, invalid samples with more than 10% of empty time series units within the fragment are removed, and low-confidence samples with more than 5% of long-term missing label coverage are removed to ensure the data integrity for learning local mutation features.

[0109] For long-range time series fragment sets, invalid samples with more than 5% of the fragments containing empty time series units are removed, and low-confidence samples with more than 3% of the long-term missing label coverage are removed to ensure the continuity of the trend of continuous evolution feature learning.

[0110] The set of short-range time-series segments that pass the verification is encapsulated into a short-range time-series sample subset, and the set of long-range time-series segments that pass the verification is encapsulated into a long-range time-series sample subset. The two subsets together constitute a dual-path time-series sample set. The corresponding time-series mapping index table is output synchronously to complete all segmentation and organization processing, providing standardized input for the dual-network feature learning in subsequent steps.

[0111] In step S3, the dual-path time-series sample sets are input into the first detection network and the second detection network, respectively. The former performs local fluctuation feature learning on short-range time-series segments to obtain transient anomaly responses, while the latter performs continuous evolution feature learning on long-range time-series segments to obtain trend anomaly representations. This constructs a dual-network anomaly set, including:

[0112] S301: Architecture pre-construction and initialization of dual-path detection network.

[0113] A dual-path detection network architecture, fully adapted to the dual-path temporal sample set, is pre-constructed, consisting of a first detection network and a second detection network. Both networks employ a temporal autoencoder architecture based on normal operating condition feature learning to achieve accurate identification of abnormal features through unsupervised learning. The specific architecture is defined as follows:

[0114] The first detection network architecture is defined as follows: For the input characteristics of short-range temporal sample subsets, a lightweight multi-scale local temporal autoencoder architecture is set up. The input dimension matches the fixed length and parameter dimension of the short-range temporal segment, namely 20 consecutive temporal units × 6 types of core performance parameters. The network encoding segment is set with 3 sets of multi-scale one-dimensional convolution modules and gated temporal unit modules in sequence, and the decoding segment is set with a one-dimensional deconvolution module symmetrical to the encoding segment. Each multi-scale one-dimensional convolutional module consists of three parallel one-dimensional convolutional layers, a batch normalization layer, and a LeakyReLU activation function layer. The kernel widths of the three one-dimensional convolutional layers along the time dimension are set to 2, 3, and 5, respectively, corresponding to temporal receptive fields covering 2, 3, and 5 consecutive temporal units. The number of output channels of each convolutional layer is set to 16, the kernel stride is fixed at 1, and the edge padding is set to equal length padding to ensure that the temporal length before and after convolution remains consistent, adapting to the capture of local fluctuation features at different periods. The negative slope of the LeakyReLU activation function is set to 0.1. The gated temporal unit module consists of a dual-gated structure of update gate and reset gate. The hidden layer dimension is set to 32, and a dropout layer is set after the gated temporal unit module with a dropout rate of 0.2. This effectively filters out the smooth fluctuation noise in normal operation and retains the effective signal of abrupt change features. No long-distance temporal dependency calculation is introduced throughout the process, and only the fluctuation feature extraction within the local temporal interval is focused. The number of output channels of the one-dimensional deconvolution module in the decoding section is consistent with the number of input channels of the corresponding coding layer, with a stride of 1 and equal-length edge padding. The activation function is a linear activation function. The network output is the reconstruction result of the core performance parameters that is completely consistent with the input dimension. This is used to calculate the reconstruction error of the local temporal interval, thereby characterizing the degree of transient anomaly.

[0115] The second detection network architecture is defined as follows: A deep long-range dependent temporal autoencoder architecture is set up to address the input characteristics of the long-range temporal sample subset. The input dimension matches the fixed length and parameter dimension of the long-range temporal segment, i.e., 2000 consecutive temporal units × 9 types of information system operation data, including 6 types of core performance parameters + 3 types of auxiliary operation parameters. The network encoding segment sequentially sets up a 2-layer bidirectional long short-term memory (Bi-LSTM) network module, a multi-head temporal self-attention module, and a fully connected encoding module. The decoding segment sets up a fully connected decoding module and a bidirectional long short-term memory network module symmetrical to the encoding segment. Each layer of the bidirectional long short-term memory network (LSTM) module consists of concatenated forward and backward LSTM units. The hidden layer dimension is set to 128, and the initial value of the forget gate bias is set to 1.0. A dropout layer with a dropout rate of 0.3 is set after each Bi-LSTM module to avoid the long-term gradient vanishing problem and to capture the forward and backward evolution dependencies of performance parameters. The multi-head temporal self-attention module sets up 8 parallel attention heads, each with a dimension of 64. It calculates the feature association weights of each temporal unit within the temporal interval through a scaled dot product attention mechanism. The output features are processed by layer normalization and then residually connected with the output of the previous Bi-LSTM module to avoid information loss during long-term feature transmission and to strengthen the continuous bias. The network employs a weighted approach to determine trend features deviating from the normal range, enabling continuous evolution feature learning over long time intervals. The fully connected encoding module consists of two fully connected layers: the first layer has 256 nodes, the second layer has 128 nodes, and ReLU activation is used. A dropout layer with a dropout rate of 0.2 is included in between. Similarly, the fully connected decoding module also consists of two fully connected layers: the first layer has 256 nodes, and the second layer has 256 nodes, with ReLU activation. The Bi-LSTM module in the decoding section has a hidden layer dimension of 128, and the output layer uses a linear activation function, with the output dimension matching the input dimension. The network output is a reconstruction result of all node parameters, identical to the input dimension, used to calculate the trend deviation over long time intervals, thus characterizing the degree of trend anomaly.

[0116] Dual-path network pre-training and initialization: A historical normal operating condition time-series dataset of the same type of equipment and the same business phase under emergency operation and maintenance scenarios is used. The dataset specifically consists of continuous normal operating data from more than 100 different models of equipment, covering the entire business phase of emergency response, for a duration of no less than 30 days, with a total sample size of no less than 1 million time-series units. The data collection and preprocessing standards are completely consistent with step S1. The training and validation sets are divided according to time order, with the first 80% as the training set and the last 20% as the validation set, ensuring that the data distribution of the validation set is consistent with the training set and has no overlap. Unsupervised pre-training is performed on the first and second detection networks respectively, with the optimization objective being the minimization of reconstruction error. The complete expression of the reconstruction error loss function is: For the first detection network, the loss function... ,in, For the first feature matrix of the input matrix One element, For the reconstructed matrix One element, To determine the total number of elements in the input feature matrix, an L2 regularization term is added with a regularization coefficient of 0.00001. Similarly, for the second detection network, the loss function... An L2 regularization term with a regularization coefficient of 0.00001 was added to complete the initial convergence of the network weights. During pre-training, the batch size was set to 32, the AdamW optimizer was used, the initial learning rate was set to 0.0001, the weight decay coefficient was set to 0.00001, and the training epochs were set to 100. An early stopping mechanism was adopted, in which the reconstruction error was calculated as the average mean squared error (first detection network) / average absolute error (second detection network) of all samples in the validation set. The criterion for no decrease was that the decrease in the reconstruction error of the validation set for 10 consecutive epochs was less than 10. -6 Training was terminated when the reconstruction error on the validation set failed to decrease for 10 consecutive rounds to avoid overfitting. The validation set for the first detection network consisted of short-range time-series segments of normal operating conditions from the same source as the training set, while the validation set for the second detection network consisted of long-range time-series segments of normal operating conditions from the same source. The validation set comprised 20% of the total training dataset for each network. After pre-training, the feature extraction weights for the network's encoding segments were fixed, and only the reconstruction error calculation channel for the decoding segments remained active, providing a standardized inference basis for subsequent feature learning and anomaly representation generation.

[0117] S302: Local fluctuation feature learning and transient anomaly response generation of the first detection network.

[0118] Using the short-range time-series sample subset output from step S2 as the sole input, and the pre-trained first detection network as the feature learning carrier, local fluctuation feature learning and transient anomaly response calculation are performed. The specific process is as follows:

[0119] For each short-range time-series segment in the short-range time-series sample subset, based on the mean and standard deviation of the normal operating condition dataset used in the pre-training stage, the core performance parameters within the segment are subjected to parameter-by-parameter Z-Score standardization to eliminate the interference of different parameter scale differences on feature learning, and a standardized input feature matrix is ​​generated. The matrix dimension is completely matched with the input dimension of the first detection network, that is, a 20×6 two-dimensional feature matrix.

[0120] The standardized input feature matrix is ​​input into the first detection network. First, through three sets of multi-scale one-dimensional convolutional modules in the encoding segment, multi-granularity local fluctuation features covering 2, 3, and 5 consecutive temporal units in the temporal receptive field are extracted respectively. The number of output channels of each one-dimensional convolutional layer is set to 16. After equal-length padding convolution operation, the temporal length of each output feature remains unchanged at 20, and the dimension of a single output feature is 20×16. The multi-granularity features output by the three parallel convolutions are spliced ​​and fused along the channel dimension to obtain a multi-scale fused feature with a dimension of 20×48, forming a comprehensive feature map containing fluctuation information of different periods. This comprehensive feature map fully covers the feature dimensions corresponding to various types of transient anomalies in emergency operation and maintenance scenarios, including peak impacts, short-term overloads, and small-amplitude continuous disturbances. It solves the technical problem of single-scale one-dimensional convolution not comprehensively capturing features of different periodic abrupt changes. After batch normalization and LeakyReLU activation, the comprehensive feature map completes the parallel extraction and effective activation of fluctuation features of different periods, resulting in activated multi-scale features with a dimension of 20×48. This activated multi-scale feature is then input into a gated time-series unit module. The update gate controls the retention ratio of features at the current time, while the reset gate controls the forgetting ratio of features at historical time, filtering out conventional fluctuation noise caused by normal system start-up and shutdown and load stabilization. The high-perturbation feature components corresponding to transient mutations in the comprehensive feature map are enhanced. The gated temporal unit module outputs a high-dimensional abstract encoded feature with a dimension of 20×32 to complete the deep learning of local fluctuation features. Finally, the high-dimensional abstract features output by encoding are input into the one-dimensional deconvolution module of the decoding segment. The one-dimensional deconvolution module of the decoding segment adopts a convolution kernel width and channel number setting that is completely symmetrical with that of the encoding segment. Based on the multi-scale comprehensive features extracted from the encoding segment, accurate reconstruction is achieved to ensure that the reconstructed features can completely restore the local fluctuation details of different periods of the input temporal sequence and avoid the loss of information of mutation features during the reconstruction process. After performing feature dimension restoration and temporal length reconstruction, the output is a 20×6 core performance parameter reconstruction matrix that is completely consistent with the input dimension.

[0121] For each short-range time series segment, the overall mean square error (MSE) between the input feature matrix and the reconstruction matrix is ​​first calculated as the overall reconstruction error of that segment. Then, the single-step reconstruction error corresponding to each time series unit is further calculated. The single-step reconstruction error is calculated by weighting the reconstruction errors of six core performance parameters within the corresponding time series unit. The weights for CPU utilization, API response time, and database connection pool utilization (three transiently sensitive parameters) are set to 0.2; the weights for memory utilization and disk I / O throughput are set to 0.15; and the weight for network latency is set to 0.1, with a total weight of 1. The quantification of these weights uses the Analytic Hierarchy Process (AHP), and more than 10 experts in emergency operations and maintenance are invited to conduct pairwise comparisons of the abnormal sensitivity of the parameters. The system constructs a judgment matrix and calculates a weight vector. The dynamic adjustment rules for different business scenarios are as follows: For database business scenarios, the database connection pool utilization weight can be increased to 0.3, while the weights of other parameters are proportionally decreased; for network transmission business scenarios, the network latency weight can be increased to 0.2, while the weights of other parameters are proportionally decreased. The verification standard for the rationality of the weights is: the accuracy of transient anomaly identification under this weight allocation is no less than 95%, enhancing the anomaly response accuracy for core mutation-sensitive parameters. The single-step reconstruction error is then mapped to the 0-1 interval through min-max normalization to generate the transient anomaly response value corresponding to that time series unit. The closer the transient anomaly response value is to 1, the higher the degree to which the performance fluctuation of that time series unit deviates from the normal feature distribution, and the greater the probability of a transient anomaly.

[0122] Based on the center time unit number and time unit number of short-range time series segments, the transient anomaly response values ​​at the time unit level output by all short-range time series segments are mapped back to the original time series link under a unified time reference. For cases where the same time series segment is covered by multiple sliding short-range time series segments, the transient anomaly response value at the center position of that time series segment is assigned a weight of 0.5, while the response values ​​of the covering segments at other non-center positions are assigned equal weights, with a total weight of 1. This weighted calculation yields the final transient anomaly response value for that time series segment, improving the anomaly response sensitivity at the center time series position. Finally, a transient anomaly response covering the entire time series link, with time series units as the smallest granularity, is generated, synchronously associated with the unique identifier of the acquisition terminal corresponding to each time series unit, the data's service stage, and the time series integrity tag.

[0123] S303: Continuous evolution feature learning and trend anomaly representation generation of the second detection network.

[0124] Using the long-range time-series sample subset output from step S2 as the sole input, and the pre-trained second detection network as the feature learning vehicle, continuous evolution feature learning and trend anomaly representation calculation are performed. The specific process is as follows:

[0125] For each long-range time-series segment in the long-range time-series sample subset, feature alignment and fusion are first performed on the core performance parameters and auxiliary operating parameters within the segment. For the auxiliary operating parameters with a 1-second acquisition frequency, the nearest neighbor interpolation method is used to interpolate them to a 100-millisecond time-series unit granularity to ensure that the time-series lengths of the two types of parameters are completely consistent. Then, using the time-series unit as the smallest granularity, the 6 types of core performance parameters and 3 types of auxiliary operating parameters are concatenated into a 9-dimensional unified feature vector. Based on the mean and standard deviation of the normal operating condition dataset used in the pre-training stage, parameter-by-parameter Z-Score standardization is performed on the fused unified feature vector to eliminate the interference of different parameter scale differences on feature learning, generating a standardized input feature matrix. The matrix dimension is completely matched with the input dimension of the second detection network, i.e., a 2000×9 two-dimensional feature matrix.

[0126] The standardized input feature matrix is ​​input into the second detection network. First, it passes through a two-layer stacked bidirectional long short-term memory (Bi-LSTM) network module in the coding segment. The first layer of the Bi-LSTM network module receives a standardized input feature matrix with a dimension of 2000×9. The hidden layer dimension of both the forward and backward LSTM units is set to 128. After concatenating the forward and backward output features, the first layer output feature dimension is 2000×256. The temporal correlation features output by the first layer are directly used as the input of the second layer. The second layer Bi-LSTM network module performs a second long temporal dependency deepening learning based on the first layer output features. The output feature dimension remains unchanged at 2000×256, forming a deep temporal feature containing full-cycle working condition evolution dependency information. This deep temporal feature fully captures the entire evolution logic of system performance from normal to deteriorating trend within a 200-second time interval, solving the technical problem of insufficient learning of slowly changing trend features in long time intervals by single-layer recurrent networks. This 2000×256 deep temporal feature is then input into a multi-head temporal self-attention module, where eight parallel attention heads calculate the feature correlation between each temporal unit in parallel. Based on the normal operating condition feature distribution benchmark and normal feature center vector learned in the pre-training stage encoding segment, the Mahalanobis distance between the deep feature of each temporal unit and the normal feature center vector is calculated. The normal feature center vector is the mean vector of the encoded output features of all normal samples in the pre-training validation set. Using the 95th percentile of the Mahalanobis distance of normal samples in the pre-training validation set as a preset deviation threshold, segments where the distance of three or more consecutive temporal units continuously exceeds this deviation threshold are identified as temporal segments continuously deviating from the normal distribution. Further scaling is then applied to these segments. The dot product attention mechanism maps the feature correlation of this type of segment to higher attention weights, weakening the invalid interference of single random fluctuations. The output attention features are normalized by layers and then residually connected with the deep temporal features output by the previous Bi-LSTM module. The output feature dimension remains 2000×256, avoiding dimensional misalignment and information loss in the long-term feature transmission, and completing the deep learning of continuously evolving features. Finally, the high-dimensional abstract features of the encoded output are input into the fully connected decoding module and the bidirectional long short-term memory network module of the decoding segment. The bidirectional long short-term memory network module of the decoding segment uses the same hidden layer dimension setting as the encoding segment. Based on the full-cycle deep temporal features extracted from the encoding segment, a complete trend-level reconstruction is achieved. By gradually restoring the temporal dimension and feature dimension, the accuracy of the trend deviation error calculation is ensured. After performing feature dimension restoration and temporal length reconstruction, the output is a 2000×9 full node running parameter reconstruction matrix with the same input dimension.

[0127] For each long-range time series segment, the overall mean absolute error (MAE) between the input feature matrix and the reconstructed matrix is ​​first calculated as the overall trend deviation error of that long-range time series segment. Further, the single-step trend deviation error corresponding to each time series unit is calculated. The single-step trend deviation error is calculated by weighting the sum of the mean absolute errors of the 9-dimensional feature vectors within the corresponding time series unit. The total weight of the core performance parameters is set to 0.7, the total weight of the auxiliary operating parameters is set to 0.3, and the weights within each type of parameter are equally distributed. The quantification method for these weights is based on the statistical analysis of the abnormal contribution of core parameters and auxiliary parameters in historical abnormal data. The abnormal contribution of the core parameters is approximately 2.3 times that of the auxiliary parameters, so approximate values ​​of 0.7 and 0.3 are used. Different industries... The dynamic adjustment rules under the service phase are as follows: For the peak period of emergency response, the weight of core performance parameters can be increased to 0.8, and the weight of auxiliary operation parameters can be decreased to 0.2; for the daily operation and maintenance phase, the weight of core performance parameters can be decreased to 0.6, and the weight of auxiliary operation parameters can be increased to 0.4; The verification standard for the rationality of the weight is: the advance identification time of trend anomalies under this weight allocation is not less than 30 seconds, highlighting the dominant role of the trend evolution of performance parameters; then the single-step trend deviation error is mapped to the 0-1 interval through min-max normalization to generate the trend anomaly characterization value corresponding to the time series unit. The closer the trend anomaly characterization value is to 1, the higher the degree of continuous deviation of the performance state of the time series unit from the normal evolution trend, and the greater the probability of trend anomaly.

[0128] Based on the center time series unit number and time series unit number of long-range time series segments, the time series unit-level trend anomaly representation values ​​output by all long-range time series segments are mapped back to the original time series link under a unified time reference. For cases where the same time series unit is covered by multiple sliding long-range time series segments, the trend anomaly representation value at the center position of the time series unit is assigned a weight of 0.5, and the trend anomaly representation values ​​of the other non-center covering segments are assigned equal weights, with a total weight of 1. The weighted calculation yields the final trend anomaly representation value of the time series unit, improving the trend identification accuracy of the long time series center segment. Finally, a trend anomaly representation covering the entire time series link with the time series unit as the smallest granularity is generated, synchronously associated with the unique identifier of the acquisition terminal corresponding to each time series unit, the data belonging to the service stage, and the anomaly correction label.

[0129] S304: Standardized construction of dual network anomaly sets.

[0130] Using the time series unit number under a unified time base as the unique association anchor point, temporal alignment and structured encapsulation are performed on transient anomaly responses and trend anomaly representations at the same time series location to construct a dual-network anomaly set. The specific process is as follows:

[0131] Based on the time-series mapping index table output in step S2, verify the time-series matching of transient abnormal response values ​​and trend abnormal characterization values ​​corresponding to the same time-series unit number. Ensure that the two types of characterization values ​​strictly correspond to the information system node operation data of the same acquisition terminal, the same data belonging to the same business stage, and the same time-series location, and eliminate the characterization deviation caused by time-series misalignment.

[0132] A unique anomaly representation key is generated for each time series unit. The anomaly representation key is generated by combining "time series unit number + unique identifier of acquisition terminal", which is fully compatible with the unique time series identifier system defined in step S1. With the anomaly representation key as the core, the transient anomaly response value, trend anomaly representation value and associated label field of the corresponding time series unit are encapsulated to form a standardized unit-level anomaly representation entry.

[0133] Following the ascending order of the time-series unit numbers, all unit-level anomaly representation entries are concatenated to form a dual network anomaly set covering the entire emergency operation and maintenance business link, the entire time-series dimension, and all device nodes.

[0134] refer to Figure 2 , Figure 2 This is a flowchart of the dual-network learning structure and anomaly representation generation process.

[0135] In step S4, through staggered learning, highly perturbated segments in the transient anomaly response are fed back to the second detection network to correct the persistent anomaly boundary, and persistently deviating anomaly segments in the trend anomaly representation are fed back to the first detection network to suppress the transient anomaly response, forming a collaborative anomaly discrimination result, including:

[0136] S401: Temporal alignment and staggered learning baseline initialization for dual network anomaly sets.

[0137] Using the dual network anomaly set output in step S3 as the sole input, the timing unit number as the sole timing anchor point, and the timing mapping index table output in step S2 as the timing correspondence benchmark, a secondary timing alignment check of the dual-path anomaly representations is completed. This ensures that under the same anomaly representation primary key, the transient anomaly response value and the trend anomaly representation value strictly correspond to the information system node operation data with the same unique identifier of the acquisition terminal, the same data belonging to the same business stage, and the same timing position, thus completely eliminating timing misalignment deviations. The initialization of core benchmark parameters for interleaved learning is completed synchronously: Based on the dual-path network pre-training results in step S301, a preset transient anomaly judgment threshold is set as the 99th quantile of the transient anomaly response values ​​output by all short-range time-series segments under normal operating conditions within the pre-training validation set of the first detection network; a preset trend anomaly representation threshold is set as the 95th quantile of the trend anomaly representation values ​​output by all long-range time-series segments under normal operating conditions within the pre-training validation set of the second detection network. The design basis for this quantile value is that the false alarm rate tolerance of trend anomalies is relatively high, and the false alarm rate of normal samples corresponding to the 95th quantile value is about 5%; the statistical quantile values ​​corresponding to both types of thresholds can be dynamically adjusted according to the false alarm rate requirements. The adjustment rule is as follows: when the required false alarm rate is less than 1%, the quantile value is adjusted to the 99th quantile; when the allowed false alarm rate is 10%, the quantile value is adjusted to the 90th quantile; the triggering conditions for updating the quantile values ​​of the two types of thresholds are consistent; the above thresholds are the unified benchmark for anomaly segment identification during interleaved learning, and are consistent with the normal operating condition feature distribution throughout the pre-training stage.

[0138] S402: Transient high-perturbation segment identification and continuous abnormal boundary correction of the second detection network.

[0139] Based on the initialized staggered learning baseline, short-range features are fed back into the long-range network to dynamically correct persistent anomaly boundaries. The specific process is as follows:

[0140] Traverse all time series units within the dual-network anomaly set, and identify time series units whose transient anomaly response values ​​exceed the preset transient anomaly judgment threshold as high-perturbation time series units. Based on the time series mapping index table, using the time series coverage range of a single long-range time series segment as the statistical interval, define continuous time series segments that appear 3 or more times within the same long-range time series segment, each containing 2 or more consecutive high-perturbation time series units as recurring high-perturbation segments. Label each high-perturbation segment with its starting time series unit number, ending time series unit number, average transient anomaly response value within the segment, and frequency of occurrence, thus completing the standardized identification and localization of high-perturbation segments.

[0141] All identified high-perturbation segments are fed back to the second detection network according to their temporal position correspondence, and two levels of continuous anomaly boundary correction are performed: The first level is anomaly judgment threshold correction. Based on the occurrence frequency of high-perturbation segments, the preset trend anomaly representation threshold of the corresponding long-range time-series interval is dynamically lowered. The threshold is lowered by 5% for each increase in occurrence frequency, with a maximum reduction of no more than 30%, which solves the problem of insufficient sensitivity of long-range networks to early repeated transient anomalies. The second level is anomaly segment boundary correction. The time-series unit where the high-perturbation segment first appears is corrected as the starting boundary of the corresponding continuous anomaly segment, and the time-series unit where the high-perturbation segment last disappears is corrected as the ending boundary of the corresponding continuous anomaly segment, which solves the boundary lag problem of trend anomaly recognition in long-range networks. After the correction is completed, the updated trend anomaly representation is output, completing the positive feedback loop from short-range features to long-range networks.

[0142] S403: Identification of continuous deviation from abnormal sections and suppression of instantaneous false triggering of the first detection network.

[0143] Based on the initialized staggered learning baseline, long-range features are fed back to the short-range network to suppress transient anomalous responses. The specific process is as follows:

[0144] Traverse all time series units within the dual-network anomaly set, and identify time series units whose trend anomaly representation values ​​exceed the preset trend anomaly representation threshold as trend deviation time series units; define continuous time series segments where three or more consecutive time series units are trend deviation time series units as persistent deviation anomaly segments, which is completely consistent with the time series segment judgment rule for persistent deviation from normal distribution in step S303; label each persistent deviation anomaly segment with its starting time series unit number, ending time series unit number, and average trend anomaly representation value within the segment, thus completing the standardized identification and location of persistent deviation anomaly segments.

[0145] All identified persistent deviation anomaly segments are fed back to the first detection network according to their temporal position correspondence, and two levels of false trigger suppression processing are performed: The first level is false anomaly suppression, which directly determines a single-point time unit whose transient anomaly response value exceeds the preset transient anomaly judgment threshold, but whose corresponding temporal position does not fall into any persistent deviation anomaly segment, and which has no other continuous high-disturbance time unit within the 10 adjacent time units before and after it as a transient false trigger, and lowers the transient anomaly response value of the time unit to below the preset transient anomaly judgment threshold to eliminate false alarms caused by single-point random noise; The second level is real anomaly enhancement, which for high-disturbance time units that fall into persistent deviation anomaly segments, its transient anomaly response value is reduced to below the preset transient anomaly judgment threshold. The transient anomaly response value is multiplied by an amplification factor of 1.2. This amplification factor is designed based on the fact that the probability of a transient anomaly within a continuously deviating anomaly segment corresponding to a real anomaly is 1.2 times that of a normal transient anomaly. The quantification method is to statistically determine the proportion of real anomalies between transient anomalies within and outside the continuously deviating segment in 1000 historical anomaly events. The adjustment rules for this amplification factor under different anomaly scenarios are as follows: for high-risk anomaly scenarios, the amplification factor can be increased to 1.5; for low-risk anomaly scenarios, the amplification factor can be decreased to 1.1 to enhance the transient response sensitivity of real anomaly events. After the correction is completed, the updated transient anomaly response is output, completing the reverse feedback loop from long-range features to the short-range network.

[0146] S404: Generation and standardized encapsulation of collaborative anomaly detection results after dual-path feedback.

[0147] Based on the transient anomaly response and trend anomaly representation after bidirectional feedback correction, a fusion calculation of the dual-path anomaly representations is performed to generate standardized collaborative anomaly discrimination results. The specific process is as follows:

[0148] Using the time series unit number as a unique anchor point, a weighted fusion calculation is performed on the corrected transient anomaly response value and the corrected trend anomaly characterization value at the same time series position to generate the collaborative anomaly discrimination value corresponding to that time series unit. The weight of the transient anomaly response value is set to 0.6, the weight of the trend anomaly characterization value is set to 0.4, and the total weight is 1. This weight allocation is based on the immediate risk of transient sudden anomalies in emergency operation and maintenance scenarios and the business characteristics of higher priority in handling, while also taking into account the early warning value of trend degradation. After verification with historical anomaly samples, a balance between anomaly detection sensitivity and accuracy can be achieved. The value range of the collaborative anomaly discrimination value is 0-1. The closer the value is to 1, the higher the probability that the time series position is a real anomaly event.

[0149] A unique collaborative anomaly discrimination primary key is generated for each time series unit. The collaborative anomaly discrimination primary key is generated by combining "time series unit number + unique identifier of acquisition terminal", which is fully compatible with the anomaly characterization primary key system defined in step S3 and the unique time series identifier system defined in step S1. With the collaborative anomaly discrimination primary key as the core, the collaborative anomaly discrimination value, the corrected transient anomaly response value, the corrected trend anomaly characterization value, and the associated tag field of the corresponding time series unit are encapsulated to form a standardized unit-level collaborative anomaly discrimination entry.

[0150] Following the ascending order of the time-series unit numbers, all unit-level collaborative anomaly detection entries are concatenated to form a collaborative anomaly detection result covering the entire emergency operation and maintenance business link, the entire time-series dimension, and all device nodes.

[0151] In step S5, based on the collaborative anomaly discrimination results and combined with the continuity relationship of anomaly segments in adjacent time intervals, the credibility judgment and level classification of the anomaly events are performed, and the corresponding anomaly detection results and early warning information are output, including:

[0152] S501: Initial screening of abnormal time sequence units and aggregation of continuous abnormal segments in collaborative anomaly discrimination results.

[0153] Using the collaborative anomaly discrimination result output in step S4 as the sole input and the time unit number as the sole time anchor point, the initial screening of anomalous time units and the standardized aggregation of continuous anomalous segments are completed. The specific process is as follows:

[0154] Setting the initial screening benchmark for abnormal time-series units: Based on the interleaved learning benchmark parameters initialized in step S401, a collaborative anomaly judgment threshold is set. This threshold is a weighted fusion value of a preset transient anomaly judgment threshold and a preset trend anomaly representation threshold. The weight allocation is consistent with the weight of the collaborative anomaly discrimination value calculation in step S404, that is, the weight of the preset transient anomaly judgment threshold is 0.6 and the weight of the preset trend anomaly representation threshold is 0.4, ensuring that the anomaly judgment benchmark is consistent with the dual-network feature learning system throughout the process; all unit-level collaborative anomaly discrimination entries within the collaborative anomaly discrimination results are traversed, and time-series units whose collaborative anomaly discrimination values ​​exceed the collaborative anomaly judgment threshold are identified as abnormal time-series units, thus completing the initial screening of abnormal time-series units.

[0155] Consecutive anomalous fragment aggregation: According to the ascending order of the time sequence unit numbers, the anomalous time sequence units that have been initially screened are continuously aggregated. The aggregation rules are completely consistent with the anomalous segment judgment rules mentioned above: a continuous time sequence segment consisting of two or more consecutive anomalous time sequence units is defined as an initial continuous anomalous fragment; for two adjacent initial continuous anomalous fragments, if the number of time sequence units between them is less than or equal to 5, they are merged into the same continuous anomalous fragment to eliminate the fragmentation problem of anomalous events caused by small intervals.

[0156] Standardized encapsulation of abnormal segments: A unique segment identifier is generated for each aggregated continuous abnormal segment, clearly marking its starting time series unit number, ending time series unit number, number of consecutive time series units in the segment, average collaborative anomaly discrimination value within the segment, unique identifier of associated acquisition terminal, data belonging to business stage, and covered associated label fields. The associated label fields include time series integrity marker label, anomaly correction label, and long-term missing label, which are fully compatible with the label system defined in step S1. Finally, a standardized set of continuous abnormal segments is formed, providing standardized input for subsequent credibility determination.

[0157] S502: Quantitative determination of the credibility of abnormal events based on temporal continuity relationship.

[0158] Taking a standardized set of continuous anomaly segments as input, and combining the continuity relationship of the anomaly segments in adjacent time intervals, a multi-dimensional credibility quantification of the anomaly event is performed. The specific process is as follows:

[0159] Adjacent temporal intervals are defined as follows: For each continuous anomalous segment, the adjacent temporal interval is defined by extending 200 consecutive temporal units forward from the starting temporal unit number of the segment and extending 200 consecutive temporal units backward from the ending temporal unit number of the segment. The length of this interval covers 10 times the duration of short-range temporal segments and 1 / 10 the duration of long-range temporal segments, taking into account both local mutations and the continuity correlation analysis of global trends. The proportion of anomalous temporal units within the adjacent temporal interval is defined as the anomalous continuity of the adjacent interval. The complete calculation formula is: Adjacent interval anomalous continuity = (Number of anomalous temporal units in the forward adjacent interval + Number of anomalous temporal units in the backward adjacent interval) / (Total number of temporal units in the forward adjacent interval + Total number of temporal units in the backward adjacent interval). The statistical boundaries of the numerator are: the forward adjacent interval is 200 temporal units forward from the starting temporal unit of the anomalous segment, and the backward adjacent interval is 200 temporal units backward from the ending temporal unit of the anomalous segment. The diffusion and continuity characteristics of anomalous events in the temporal dimension are quantified.

[0160] Multi-dimensional credibility factor calculation: Focusing on the core dimension of temporal continuity, and combining the credibility of dual-network feature matching and data validity, a three-dimensional credibility factor system is constructed. The value range of each factor is 0-1.

[0161] Temporal continuity reliability factor: This factor reflects the temporal continuity characteristics of anomaly segments and the continuity relationship between adjacent intervals. The calculation formula is: Temporal continuity reliability factor = min(1, number of continuous temporal units in the segment / 20 + continuity of anomalies in adjacent intervals). The derivation of this formula is as follows: Based on the temporal continuity characteristics of anomaly events, the longer the continuous duration and the higher the continuity of adjacent intervals, the higher the anomaly reliability. The design is based on the correlation between the continuous duration and reliability of 1000 historical anomaly events, with a correlation coefficient reaching 0.85. The physical meaning of the parameters is as follows: number of continuous temporal units in the segment / 20 represents the completeness of the anomaly segment relative to the length of the short-range temporal segment; continuity of anomalies in adjacent intervals represents the temporal continuity of the anomaly event. The diffusion degree of the order dimension, where the value 20 is the standard fixed length of the short-range time segment, in units of time units. Normalization is performed using this as the denominator to characterize the length integrity of the abnormal segment relative to a single set of standard transient detection units. The boundary conditions for the value are: the number of consecutive time units of the segment ≥ 2, and the anomaly continuity of adjacent intervals ∈ [0,1]. Therefore, the value range of the time continuity reliability factor is [0.1,1]. Compared with the reliability calculation formula known in the field, this formula considers both the continuity of the abnormal segment itself and the continuity of adjacent intervals, which can more accurately reflect the authenticity of the abnormal event. The rationale for the difference is that abnormal events in emergency operation and maintenance scenarios usually have obvious time continuity characteristics.

[0162] Dual-network feature matching confidence factor: reflects the degree of matching between the abnormal segment and the dual-network abnormal representation. If the abnormal segment covers both the recurring high-perturbation segment and the continuously deviating abnormal segment identified in step S4, the factor value is 1.0; if it covers only one type of abnormal segment, the factor value is 0.7; if it does not cover either, the factor value is 0.3, which is completely consistent with the staggered learning feature system in step S4.

[0163] Data validity credibility factor: reflects the quality credibility of the original data corresponding to the abnormal fragment. If the proportion of time series units covered by long-term missing labels in the abnormal fragment is 0 and the proportion of empty time series units is less than 5%, the factor value is 1.0; if the proportion of long-term missing labels does not exceed 10% and the proportion of empty time series units does not exceed 10%, the factor value is 0.6; otherwise, the factor value is 0.3, which is completely consistent with the data preprocessing rules in step S1.

[0164] Final credibility calculation and grading of abnormal events: A weighted fusion of credibility factors across three dimensions is performed, with the weights allocated as follows: temporal continuity credibility factor 0.5, dual-network feature matching credibility factor 0.3, and data validity credibility factor 0.2, for a total weight of 1. This weight allocation aligns with the business pattern that real anomalies in emergency operation and maintenance scenarios generally possess temporal continuity. Temporal continuity is used as the core dimension for judging the authenticity of anomalies, dual-network feature matching as the dual-path technical verification dimension, and data validity as the basic quality constraint. The weights are determined by measuring historical anomaly samples using the entropy weight method. The dynamic adjustment rule under different data quality scenarios is: when the overall data is lacking… When the loss rate is higher than 10%, the weight of the data validity credibility factor can be increased to 0.3, and the weight of the time series continuity credibility factor can be decreased to 0.4; when the data quality is good, the weight of the time series continuity credibility factor can be increased to 0.6, and the weight of the data validity credibility factor can be decreased to 0.1; the verification standard for the rationality of the weight is: under this weight allocation, the elimination rate of unreliable abnormal events is not less than 90%, and the retention rate of real abnormal events is not less than 95%, highlighting the core judgment role of time series continuity relationship, and calculating the credibility value of abnormal events, with a value range of 0-1. The closer the value is to 1, the higher the probability that the abnormal event is a real working condition abnormality. Simultaneously complete the credibility classification: credibility value ≥ 0.8 is a high credibility anomaly event, 0.6 ≤ credibility value < 0.8 is a medium credibility anomaly event, 0.4 ≤ credibility value < 0.6 is a low credibility anomaly event, and credibility value < 0.4 is an untrustworthy anomaly event, which is excluded from subsequent classification and early warning output; the above classification is divided into equal intervals with a step size of 0.2, which is determined based on the credibility distribution statistics of historical anomaly samples in emergency operation and maintenance, and corresponds to four operation and maintenance handling levels: immediate handling, key investigation, tracking and observation, and false alarm elimination, which are compatible with the four-level anomaly event classification system.

[0165] S503: Classification of abnormal events based on credibility and abnormal characteristics.

[0166] Taking graded and reliable anomalies as the object, and combining the risk level requirements of emergency operation and maintenance scenarios, a standardized level classification of anomalies is implemented. The specific process is as follows: using the anomaly credibility value, the continuous duration of the anomaly segment, the average value of the collaborative anomaly discrimination value, and the type of associated parameters as the core judgment dimensions, and aligning with the risk handling priorities of emergency operation and maintenance, anomalies are divided into four levels. The judgment boundaries and business implications of each level are clear and implementable.

[0167] Level 1: The judgment criteria are high-confidence abnormal events, abnormal segments with a continuous duration of ≥100 time series units, and the average value of collaborative anomaly discrimination value within the segment ≥0.9. Furthermore, the events must be associated with at least one of the core performance parameters, namely database connection pool utilization, memory utilization, and API response time. These are urgent anomalies that pose an immediate risk of failure to the corresponding information system and may lead to security incidents or interruptions in emergency response. These events are given the highest priority for handling.

[0168] Level 2: The judgment rules are high-confidence abnormal events, abnormal segments with a continuous duration of ≥50 time units, and the average value of the collaborative anomaly discrimination value within the segment ≥0.8, or medium-confidence abnormal events, abnormal segments with a continuous duration of ≥100 time units, and associated with core performance parameters; corresponding to important anomalies that seriously deviate from the normal range of system performance and may cause a significant performance drop or secondary failures, and are given high priority for handling.

[0169] Level 3: The judgment rules are medium confidence anomalies, anomaly segments with a continuous duration of ≥20 time units, and a mean value of collaborative anomaly discrimination value within the segment ≥0.7, or low confidence anomalies, anomaly segments with a continuous duration of ≥50 time units, and associated core performance parameters or auxiliary operating parameters; corresponding to general anomalies where the system performance slightly deviates from the normal range and does not temporarily affect the core operating capabilities, which are given routine handling priority.

[0170] Level 4: The judgment rules are low-confidence abnormal events, abnormal segments with a continuous duration of ≥10 time units, and the average value of the collaborative anomaly discrimination value within the segment ≥0.6; corresponding to the system performance showing a potential deterioration trend and no immediate operational risk, which is a suggestive anomaly and is given priority for tracking and observation.

[0171] After completing the classification, each abnormal event is labeled with a corresponding abnormal level code, forming a standardized set of hierarchical abnormal events that is fully compatible with all the time sequence systems and identification systems mentioned above.

[0172] S504: Standardized output of anomaly detection results and early warning information.

[0173] A unique identifier is generated for each graded anomaly event. This identifier is generated by combining the "starting time sequence unit number + unique identifier of the acquisition terminal + anomaly level code". With the unique identifier of the anomaly event as the core, the full information of the corresponding anomaly event is encapsulated, including: unique identifier of the acquisition terminal, system / node name, data to the business stage, anomaly start time, anomaly end time, continuous duration of the anomaly segment, anomaly level, confidence value, associated anomaly performance parameters, core anomaly feature description, and associated tag fields. The anomaly start time is generated by converting the calibrated timestamp corresponding to the starting time sequence unit number. Finally, anomaly detection results covering the entire business link and all system nodes are generated, and corresponding level early warning information is pushed to complete the full-process emergency operation and maintenance anomaly detection.

[0174] refer to Figure 3 , Figure 3 This is a flowchart for determining the credibility and classifying the level of abnormal events.

[0175] This embodiment constructs an operation and maintenance time-series dataset covering the entire business chain, all equipment nodes, and all parameter fields by standardizing the collection, time alignment, and anomaly correction of information system node operation data during emergency operation and maintenance. Based on this, continuous data segments are segmented and context-organized according to their temporal progression, extracting short-range time-series segments reflecting local mutation characteristics and long-range time-series segments reflecting continuous evolution characteristics. These are then input into a first detection network and a second detection network, respectively, forming a dual-network anomaly set targeting transient and trend anomalies. Furthermore, this invention utilizes an interleaved learning mechanism to feed back repeatedly occurring high-perturbation segments in transient anomaly responses to the second detection network to correct persistent anomaly boundaries, and to feed back persistently deviating anomaly segments in trend anomaly representations to the first detection network to suppress transient anomaly responses, forming a collaborative anomaly discrimination result. Subsequently, combining the continuity relationship of anomaly segments in adjacent time-series intervals, a reliable quantitative judgment and level classification are performed on the anomaly events, outputting the corresponding anomaly detection results and early warning information. Compared with existing technologies, this invention can more accurately identify complex anomalies that are intertwined with local mutations and continuous evolution in emergency operation and maintenance scenarios, and improve the authenticity of anomaly detection results, boundary characterization ability, and the practicality of early warning classification.

[0176] Example 2:

[0177] This invention discloses an emergency operation and maintenance anomaly detection system based on dual-network temporal interleaving learning, including a data acquisition module, a sample segmentation module, a dual-network learning module, an interleaving correction module, and a judgment and early warning module.

[0178] Data acquisition module: Collects operational data of information system nodes during emergency operation and maintenance, performs time alignment and anomaly correction processing, and obtains operation and maintenance time series dataset.

[0179] Sample Segmentation Module: Based on the operation and maintenance time series dataset, the module performs time series segmentation and context organization on continuous data segments according to the time progression relationship, extracts short-range time series segments reflecting local mutation characteristics and long-range time series segments reflecting continuous evolution characteristics, and forms a dual-path time series sample set.

[0180] Dual-network learning module: The dual-path time series sample sets are input into the first detection network and the second detection network respectively. The first detection network performs local fluctuation feature learning on the short-range time series segments to obtain transient abnormal responses, and the second detection network performs continuous evolution feature learning on the long-range time series segments to obtain trend abnormal representations, thus constructing a dual-network anomaly set.

[0181] Interleaved correction module: Based on the dual-network anomaly set, interleaved learning processing is performed according to the correspondence of the same temporal position. The high-perturbation segments that recur in the transient anomaly response are fed back to the second detection network to correct the continuous anomaly boundary, and the continuously deviating anomaly segments in the trend anomaly representation are fed back to the first detection network to suppress the transient anomaly response, forming a collaborative anomaly discrimination result.

[0182] Judgment and early warning module: Based on the collaborative anomaly discrimination results and combined with the continuity relationship of anomaly segments in adjacent time intervals, the module performs credibility judgment and level classification on anomaly events, and outputs the corresponding anomaly detection results and early warning information.

[0183] refer to Figure 4 , Figure 4 This is a structural diagram of an emergency operation and maintenance anomaly detection system based on dual-network temporal interleaved learning.

[0184] The specific functional implementation of each module is described in the relevant content of the emergency operation and maintenance anomaly detection method based on dual-network temporal interleaving learning described in Example 1, and will not be repeated here.

[0185] The above description is merely a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of the present invention should also be considered within the scope of protection of the present invention.

Claims

1. An emergency operation and maintenance anomaly detection method based on dual-network temporal interleaved learning, characterized in that, Includes the following steps: Collect operational data from information system nodes, perform time alignment and anomaly correction processing, and obtain an operation and maintenance time-series dataset; Based on the operation and maintenance time series dataset, short-term and long-term time series segments are extracted according to the time progression relationship to obtain a dual-path time series sample set; The dual-path time series sample set is input into the first detection network and the second detection network respectively, and local fluctuation and continuous evolution feature learning is performed to obtain transient abnormal response and trend abnormal representation to construct dual-network anomaly set; Based on the dual-network anomaly set, interleaved learning processing is performed. High-perturbation segments are fed back to the second detection network to correct the continuous anomaly boundary, and continuous deviation from the anomaly segment is fed back to the first detection network to suppress transient anomaly response, thus obtaining the collaborative anomaly discrimination result. Based on the collaborative anomaly discrimination results, the credibility of the abnormal event is determined and the level is classified by combining the continuity relationship of the abnormal segment in adjacent time intervals, and the anomaly detection results and early warning information are output.

2. The emergency operation and maintenance anomaly detection method based on dual-network temporal interleaved learning as described in claim 1, characterized in that, Perform staggered learning processing to generate collaborative anomaly detection results, including: Based on the pre-training results of the first and second detection networks, preset transient anomaly judgment thresholds and preset trend anomaly representation thresholds are initialized respectively, serving as a unified benchmark for staggered learning. Traverse each time series unit in the dual-network anomaly set, identify the high-perturbation segments that repeatedly appear in the transient anomaly response, and feed them back to the second detection network to correct the trend anomaly characterization threshold and persistent anomaly boundary of the corresponding long-range time series segments. Identify anomalous segments that continuously deviate from the trend anomaly representation and feed them back to the first detection network to perform suppression correction or enhancement correction on the transient anomaly response value at the corresponding time position; The corrected transient anomaly response value and the trend anomaly characterization value are weighted and fused to obtain the collaborative anomaly discrimination value and encapsulate it to generate the collaborative anomaly discrimination result.

3. The emergency operation and maintenance anomaly detection method based on dual-network temporal interleaved learning as described in claim 1, characterized in that, Perform credibility determination on abnormal events, including: The collaborative anomaly discrimination results are subjected to initial screening of anomaly time sequence units and aggregation of continuous anomaly segments to form a set of continuous anomaly segments; For each consecutive abnormal segment, adjacent time intervals are defined forward and backward based on the start and end time units of the segment. The proportion of abnormal time units in adjacent time intervals is counted to obtain the abnormal continuity of adjacent intervals. A temporal continuity credibility factor is constructed based on the number of consecutive temporal units in a segment and the abnormal continuity of adjacent intervals; a dual-network feature matching credibility factor is constructed based on the coverage of abnormal segments with high-disturbance segments and continuously deviating abnormal segments; and a data validity credibility factor is constructed based on the proportion of empty temporal units in the data corresponding to the segment and the coverage proportion of long-term missing labels. A fusion process is performed on each credibility factor to obtain the credibility value of the abnormal event. The abnormal event level is classified according to the credibility value and untrustworthy abnormal events are eliminated.

4. The emergency operation and maintenance anomaly detection method based on dual-network temporal interleaved learning as described in claim 2, characterized in that, Methods for obtaining highly perturbated segments include: Traverse all time-series units within the dual-network anomaly set and mark time-series units whose transient anomaly response values ​​exceed the preset transient anomaly judgment threshold as high-perturbation time-series units; Using the time series coverage of a single long-range time series segment as the statistical interval, a continuous time series segment that appears multiple times within the same long-range time series segment and contains a preset number of consecutive high-perturbation time series units is defined as a high-perturbation segment. Its starting time series unit number, ending time series unit number, average transient abnormal response value within the segment, and frequency of occurrence are marked.

5. The emergency operation and maintenance anomaly detection method based on dual-network temporal interleaved learning as described in claim 2, characterized in that, Methods for obtaining continuously deviating abnormal segments include: Traverse all time series units in the dual network anomaly set and mark time series units whose trend anomaly representation values ​​exceed the preset trend anomaly representation threshold as trend deviation time series units. A time series segment consisting of trend deviation time series units with a consecutive number reaching a preset consecutive threshold is defined as a continuous deviation abnormal segment, and its starting time series unit number, ending time series unit number, and average trend abnormality characterization value within the segment are marked.

6. The emergency operation and maintenance anomaly detection method based on dual-network temporal interleaved learning as described in claim 1, characterized in that, The first detection network performs local fluctuation feature learning on short-range time segments to obtain transient anomaly responses, including: Perform parameter-by-parameter standardization on the core performance parameters within the short-range time segment to generate a standardized input feature matrix that matches the input dimension of the first detection network; The standardized input feature matrix is ​​sequentially input into the multi-scale one-dimensional convolution module and the gated temporal unit module of the coding segment to extract local fluctuation features under different time receptive fields and obtain high-dimensional abstract coding features. The high-dimensional abstract encoded features are input into the one-dimensional deconvolution module of the decoding segment, and the output is a core performance parameter reconstruction matrix with the same dimension as the input. Normalization is performed on the parameter-by-parameter reconstruction error between the standardized input feature matrix and the core performance parameter reconstruction matrix, and the normalized error is mapped back to the original time series link to generate a transient abnormal response.

7. The emergency operation and maintenance anomaly detection method based on dual-network temporal interleaved learning as described in claim 1, characterized in that, The second detection network performs continuous evolution feature learning on long-range time segments to obtain trend anomaly representations, including: The core performance parameters and auxiliary operating parameters within the long-range time series segment are fused with features, and the fused parameters are standardized to generate a standardized input feature matrix corresponding to the long-range time series segment. The standardized input feature matrix is ​​input into the stacked bidirectional long short-term memory network module and the multi-head temporal self-attention module of the encoding segment to extract the continuous evolution features in the long temporal interval and obtain the encoded output features. The encoded output features are input into the fully connected decoding module and the bidirectional long short-term memory network module of the decoding segment, and the output is a reconstruction matrix of all node running parameters. Normalization is performed on the parameter-by-parameter trend deviation error between the standardized input feature matrix corresponding to the long-range time series segment and the reconstructed matrix of all node running parameters. The normalized error is then mapped back to the original time series link to generate a trend anomaly representation.

8. The emergency operation and maintenance anomaly detection method based on dual-network temporal interleaved learning as described in claim 1, characterized in that, Short-range and long-range time-series segments are extracted to obtain a dual-path time-series sample set, including: Based on the ascending order of the calibrated timestamps, and with the timing unit number as the unique timing anchor point, a continuous timing context chain is constructed. The timing context chain is continuously slid segmented using a preset short-range fixed length and a preset short-range step size, and the short-range timing segments are extracted using the core performance parameters within the short-range timing segments as the main data body. Continuous sliding segmentation is performed with a preset long-range fixed length and a preset long-range step size, and long-range time series segments are extracted with all node running parameters as the main data body. A unique segment identifier is generated for each time series segment, and the starting time series unit number, ending time series unit number, and center time series unit number are marked. The center time series unit number is used as the unique association key to establish a time series mapping index table between short-range time series segments and long-range time series segments. Differential sample validity checks are performed on the two time series segments respectively, and invalid samples with the proportion of empty time series units and the proportion of long-term missing label coverage exceeding their respective preset thresholds are removed to form a two-channel time series sample set.

9. The emergency operation and maintenance anomaly detection method based on dual-network temporal interleaved learning as described in claim 1, characterized in that, Perform anomaly correction on node runtime data, including: The abnormal types of information system node operation data are classified into missing abnormal data, mutation abnormal data, and redundant abnormal data. For missing data, short-term missing data is filled by linear interpolation of adjacent valid time series units, and long-term missing data is filled by time-weighted average of valid data from the same period in history and labeled with long-term missing data. For abrupt abnormal data, a sliding time window is used to identify abnormal values, and the values ​​in the corresponding parameter fields of a preset number of consecutive valid time series units are replaced and corrected. For redundant abnormal data, retain the only valid entry with the highest timestamp accuracy and complete checksum. Once the data entry is corrected, an anomaly correction tag is generated synchronously.

10. An emergency operation and maintenance anomaly detection system based on dual-network temporal interleaved learning, used to implement the emergency operation and maintenance anomaly detection method based on dual-network temporal interleaved learning as described in any one of claims 1-9, characterized in that, It includes a data acquisition module, a sample segmentation module, a dual-network learning module, an interleaving correction module, and a judgment and early warning module. The data acquisition module collects operational data from information system nodes and performs time alignment and anomaly correction to obtain an operation and maintenance time-series dataset. The sample segmentation module extracts short-range and long-range time-series segments based on the operation and maintenance time-series dataset to obtain a dual-path time-series sample set. The dual-network learning module inputs the dual-path time series sample sets into the first detection network and the second detection network respectively, performs local fluctuation feature learning and continuous evolution feature learning respectively, obtains transient abnormal response and trend abnormal characterization, and constructs dual-network anomaly set; The interleaving correction module performs interleaving learning processing based on the dual-network anomaly set. It feeds back highly perturbation segments to the second detection network to correct persistent anomaly boundaries and feeds back persistently deviating anomaly segments to the first detection network to suppress transient anomaly responses, thus obtaining collaborative anomaly discrimination results. The judgment and early warning module, based on the collaborative anomaly discrimination results and combined with the continuity relationship of the anomaly segments in adjacent time intervals, performs credibility judgment and level classification on the anomaly events, and outputs anomaly detection results and early warning information.