Silent anomaly handling methods, systems, devices, and program products

CN122734476APending Publication Date: 2026-09-11北京科杰科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610841255.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-11
Publication Date
2026-09-11

AI Technical Summary

Technical Problem

[0004]本申请实施例提供了一种静默异常处理方法、系统、设备和程序产品,可以解决现有技术中无法有效检测、量化和修复无明显特征的系统静默异常的问题

Benefits of technology

[0016] Fifthly, embodiments of this application provide a computer program product that, when run on a computer device, causes the computer device to execute the silent exception handling method described in any of the first aspects above.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122734476A_ABST
    Figure CN122734476A_ABST
Patent Text Reader

Abstract

This application relates to the field of computer intelligent operation and maintenance technology, and provides a method, system, device, and program product for handling silent anomalies. The method includes: constructing a dynamic steady-state benchmark characterizing the health state of the system; identifying silent anomalies indicating steady-state drift by comparing the dynamic characteristics of runtime sequence data with the benchmark; after identifying the anomaly, calculating and verifying a symmetry-breaking matrix to quantify the degree of anomaly deviation and locate the anomaly dimension; constructing an adaptive time-domain parity-flipping detection operator based on the matrix, and generating a micro-perturbation sequence applied to the anomaly dimension to awaken the silent anomaly into a monitorable explicit deviation; finally, monitoring the explicit deviation and adjusting the target operating platform accordingly to complete the correction of the silent anomaly. This application can accurately identify, quantify, and locate silent anomalies, and achieve a fully automated closed-loop process from detection to self-healing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of computer intelligent operation and maintenance technology, and in particular relates to a silent anomaly handling method, system, device and program product. Background Technology

[0002] With the widespread application of distributed architectures such as big data and microservices, the operating state of modern computer systems (hereinafter referred to as the target runtime platform) exhibits complex characteristics of high dimensionality, strong coupling, and dynamic changes. Besides easily perceptible explicit faults such as service outages and program crashes, a type of gradual steady-state drift problem, namely silent anomalies, is also prevalent in systems. These anomalies are characterized by a persistent, structural shift in one or more system operating metrics, leading to a gradual deterioration of the system's steady state, but without triggering any program exceptions, generating error logs, or exceeding the static thresholds set by conventional monitoring.

[0003] Current mainstream operation and maintenance monitoring technologies mainly rely on fixed threshold comparisons and log event analysis. These methods can only identify explicit faults such as single-point metric exceeding limits or clear error messages, and have a natural blind spot for multi-dimensional, slowly evolving silent anomalies. Essentially, existing technologies lack a mechanism that can delve into the underlying dynamics of the system and proactively detect invisible risks. This leads to the long-term accumulation of silent anomalies, which may eventually trigger sudden major failures without any warning, posing significant threats to system stability and data security. Therefore, existing technologies have a technical deficiency in effectively detecting, quantifying, and repairing silent system anomalies that lack obvious characteristics. Summary of the Invention

[0004] This application provides a method, system, device, and program product for handling silent anomalies, which can solve the problem in the prior art that it is impossible to effectively detect, quantify, and repair silent anomalies without obvious characteristics.

[0005] In a first aspect, embodiments of this application provide a method for handling silent anomalies, including:

[0006] Based on the time series data of the target operating platform under quasi-steady-state conditions, a dynamic steady-state benchmark characterizing the health state of the target operating platform system is constructed. Real-time acquisition of runtime timing data of the target operating platform; by comparing the dynamic characteristics of the runtime timing data with the dynamic steady-state benchmark, identification of silent anomalies indicating steady-state drift of the target operating platform; After identifying the silent anomaly, a symmetry breaking matrix is ​​calculated, and a valid symmetry breaking matrix is ​​locked by performing a time-series verification on the symmetry breaking matrix to quantify the degree of deviation of the silent anomaly and locate the anomaly dimension. Based on the effective symmetry-broken matrix, a time-domain parity-flipping detector is constructed, and a micro-perturbation sequence is generated; The micro-perturbation sequence is applied to the anomaly dimension to awaken the silent anomaly into a detectable explicit deviation; The system monitors the explicit deviation caused by the micro-perturbation sequence and adjusts the target operating platform according to the explicit deviation to correct the silent anomaly under the constraints of a preset fault tolerance mechanism.

[0007] In one possible implementation of the first aspect, the dynamic steady-state benchmark includes a standard eigenvalue spectrum; the step of identifying silent anomalies indicating steady-state drift of the target operating platform by comparing the dynamic characteristics of the runtime timing data with the dynamic steady-state benchmark includes: Based on the dynamic characteristics of the runtime sequence data, the real-time eigenvalue spectrum is calculated; By calculating the structural residual between the real-time eigenvalue spectrum and the standard eigenvalue spectrum, it is determined whether the target operating platform has experienced temporal symmetry breaking, thereby identifying the silent anomaly.

[0008] In one possible implementation of the first aspect, the dynamic steady-state benchmark includes a benchmark Lie algebra generator matrix; the step of calculating a symmetry breaking matrix after identifying the quiescent anomaly, and locking a valid symmetry breaking matrix by performing a time-series verification on the symmetry breaking matrix, includes: Based on the dynamic characteristics of the runtime sequence data under the silent anomaly, a real-time anomaly Lie algebra generator matrix is ​​calculated. The difference operation is performed between the real-time anomaly Lie algebra generator matrix and the baseline Lie algebra generator matrix to obtain the symmetry breaking matrix. The effective symmetry breaking matrix is ​​locked by performing time-series verification on the symmetry breaking matrix of multiple consecutive sliding windows.

[0009] In one possible implementation of the first aspect, the time-series data includes a system state vector across multiple dimensions; generating a micro-perturbation sequence includes: A steady-state target state vector is calculated by applying the time-domain parity-flipping detector to the system state vector at the current moment; The micro-disturbance sequence is determined based on the steady-state target state vector and the system state vector at the current moment.

[0010] In one possible implementation of the first aspect, the preset fault tolerance mechanism includes at least one of the following: iterative convergence determination rule, maximum iteration limit rule, and disturbance circuit breaker rollback rule.

[0011] In one possible implementation of the first aspect, the time-domain parity-flipping probe operator is constructed using a Lie group exponential mapping rule, and the time-domain parity-flipping probe operator takes the form of: P = exp(α·ΔG); where P is the time-domain parity flip detector, exp is the Lie group exponential mapping operation, α is the adaptive intensity coefficient, and ΔG is the effective symmetry breaking matrix.

[0012] In one possible implementation of the first aspect, the step of applying the micro-perturbation sequence before applying it to the anomaly dimension further includes: On the digital twin model of the target operating platform, the operation of applying the micro-perturbation sequence is rehearsed; The step of applying the micro-perturbation sequence to the anomalous dimension is performed only if the result of the pre-simulation satisfies the preset safety constraints.

[0013] Secondly, embodiments of this application provide a silent anomaly handling system, including: The benchmark modeling module is used to construct a dynamic steady-state benchmark characterizing the health state of the target operating platform system based on time series data of the target operating platform under quasi-steady-state conditions. The real-time detection module is used to collect runtime timing data of the target operating platform in real time, and identify silent anomalies that indicate steady-state drift of the target operating platform by comparing the dynamic characteristics of the runtime timing data with the dynamic steady-state benchmark. The anomaly analysis module is used to calculate a symmetry breaking matrix after the silent anomaly is identified, and to lock a valid symmetry breaking matrix by performing time-series verification on the symmetry breaking matrix, so as to quantify the deviation degree of the silent anomaly and locate the anomaly dimension. The self-healing control module is used to construct a time-domain parity flip detection operator based on the effective symmetry breaking matrix and generate a micro-perturbation sequence; apply the micro-perturbation sequence to the anomaly dimension to awaken the silent anomaly into a monitorable explicit deviation; and monitor the explicit deviation caused by the micro-perturbation sequence, and adjust the target operating platform according to the explicit deviation to complete the correction of the silent anomaly under the constraint of a preset fault tolerance mechanism.

[0014] Thirdly, embodiments of this application provide a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the silent exception handling method described in any one of the first aspects above.

[0015] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the silent exception handling method described in any one of the first aspects.

[0016] Fifthly, embodiments of this application provide a computer program product that, when run on a computer device, causes the computer device to execute the silent exception handling method described in any of the first aspects above.

[0017] This application's embodiments, by constructing a dynamic steady-state benchmark and comparing the dynamic characteristics of real-time data to identify temporal symmetry breaking, can accurately identify silent anomalies that are undetectable by traditional monitoring methods, lacking logs and alarms. This fills the monitoring blind spots of existing technologies and eliminates potential major faults in their infancy. By calculating and performing time-series verification on the symmetry breaking matrix, the effective symmetry breaking matrix is ​​locked, which not only achieves precise quantification of the system's deviation from steady state but also accurately locates the root dimension causing the anomaly, providing a reliable basis for subsequent precise intervention and avoiding misoperation of irrelevant dimensions. By constructing an adaptive temporal parity flip detection operator based on the effective symmetry breaking matrix and generating a micro-perturbation sequence, a safe and controllable perturbation can be adaptively applied according to the severity of the anomaly, actively awakening latent silent anomalies into observable explicit deviations, achieving safe detection of unknown risks. By performing self-healing repair under the constraints of a preset fault tolerance mechanism, the entire automated repair process is ensured to be safe, controllable, and without business intrusion. This establishes a fully automated closed loop from the detection, location, quantification, and wake-up of silent anomalies to self-healing, thereby improving operational efficiency.

[0018] It is understood that the beneficial effects of the second to fifth aspects mentioned above can be found in the relevant descriptions in the first aspect mentioned above, and will not be repeated here. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 This is a flowchart illustrating a silent exception handling method according to an embodiment of this application; Figure 2 This is a schematic diagram of the structure of a silent anomaly handling system according to an embodiment of this application; Figure 3This is a schematic diagram of the interaction timing between the self-healing control module and the target operating platform according to an embodiment of this application; Figure 4 This is a schematic diagram of the structure of the computer device provided in the embodiments of this application. Detailed Implementation

[0021] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0022] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0023] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0024] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."

[0025] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0026] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0027] Please see Figure 1 This application provides a method for handling silent anomalies. This method identifies progressively developing latent faults by analyzing the dynamic structural changes of the target operating platform and capturing the breaking of temporal symmetry.

[0028] S101, Based on the time series data of the target operating platform under quasi-steady-state conditions, construct a dynamic steady-state benchmark characterizing the health state of the target operating platform system.

[0029] The target operating platform refers to a computer system that runs a distributed architecture.

[0030] Quasi-steady-state operating condition: refers to the period when the target operating platform is in a healthy and stable operating state, without significant version iteration, large-scale traffic fluctuations, or manual operation and maintenance.

[0031] Time-series data refers to system state vectors collected in chronological order across multiple dimensions (including CPU utilization, memory usage, number of active connections in the database connection pool, etc.).

[0032] Dynamic steady-state benchmark: refers to the benchmark data used to characterize the health state of a system, which is constructed by analyzing the dynamic characteristics of time series data under quasi-steady-state conditions. It includes the benchmark Lie algebra generator matrix and the standard eigenvalue spectrum.

[0033] In this embodiment, the system collects a large amount of multidimensional time-series data (e.g., CPU utilization, memory usage, active connections in the database connection pool, etc.) from the target operating platform during a stable operating period without version iterations, large-scale traffic fluctuations, or manual maintenance operations for several consecutive days. The system ensures that the collection window is in a quasi-steady state by using preset quantitative indicators (e.g., load fluctuation amplitude threshold, instantaneous jump rate threshold of single-dimensional indicators). Based on these steady-state sample data, the system performs standardized preprocessing, uses a kernel density estimation algorithm to fit its high-dimensional probability distribution, and converts it into a statistically equivalent dynamic potential energy field. Under healthy steady-state conditions, this potential energy field exhibits a normal steady-state potential well, and the system state vector converges to the vicinity of the global optimum of the potential well. By modeling and analyzing the dynamic characteristics of the health data, the system extracts and solidifies a set of dynamic steady-state benchmarks that can uniquely characterize the health state. These dynamic steady-state benchmarks mainly include the benchmark Lie algebra generator matrix and the standard eigenvalue spectrum, as well as the steady-state critical thresholds statistically generated based on steady-state historical data.

[0034] After establishing a dynamic steady-state benchmark, the method enters the real-time online monitoring phase.

[0035] S102, real-time acquisition of runtime sequence data of the target operating platform, and identification of silent anomalies indicating steady-state drift of the target operating platform by comparing the dynamic characteristics of the runtime sequence data with the dynamic steady-state benchmark.

[0036] Among them, runtime sequence data refers to the system state vector sequence collected in real time during the online operation phase of the target operating platform.

[0037] Dynamic characteristics: refers to the eigenvalue spectrum extracted from time series data.

[0038] Silent anomaly: refers to an abnormal state in which one or more operating indicators of the system experience a continuous and structural deviation, leading to a gradual deterioration of the system's steady state, but without triggering any program exceptions, generating error logs, or exceeding the static thresholds set by regular monitoring.

[0039] Steady-state drift refers to the process by which changes in the dynamic structure of a system lead to the destruction of time-domain symmetry, causing the system to gradually deviate from a healthy steady state.

[0040] In this embodiment, the system continuously collects real-time operational data using a sliding window of fixed length. For each window that passes the quasi-steady-state access check, the system extracts the real-time eigenvalue spectra of its forward and reverse temporal state matrices and calculates structural residuals by comparing them with the aforementioned standard eigenvalue spectra. When the system's steady state drifts, i.e., a silent anomaly occurs, its dynamic structure changes, leading to a disruption of temporal symmetry. This disruption is manifested in deviations in dynamic characteristics. When the structural residual exceeds the steady-state critical threshold, it is determined that the target operating platform has experienced a temporal symmetry structural disruption, thus identifying the silent anomaly. By capturing this deviation, the system identifies the silent anomaly.

[0041] In an optional implementation, the dynamic steady-state benchmark includes a standard eigenvalue spectrum; S102 identifies silent anomalies indicating steady-state drift of the target operating platform by comparing the dynamic characteristics of the runtime timing data with the dynamic steady-state benchmark, specifically including: Step a1: Based on the dynamic characteristics of the runtime sequence data, the real-time eigenvalue spectrum is calculated.

[0042] Among them, the real-time eigenvalue spectrum refers to the set of eigenvalues ​​extracted from the runtime sequence data of the current sliding window.

[0043] Specifically, a state matrix is ​​constructed from the multidimensional time-series data within the sliding window. All eigenvalues ​​of the matrix are obtained through matrix decomposition. These eigenvalues ​​are then arranged in descending order to form a real-time eigenvalue spectrum.

[0044] Step a2: By calculating the structural residual between the real-time eigenvalue spectrum and the standard eigenvalue spectrum, it is determined whether the target operating platform has experienced temporal symmetry breaking, thereby identifying the silent anomaly.

[0045] Among them, structural residuals refer to the difference between the real-time eigenvalue spectrum and the standard eigenvalue spectrum.

[0046] Temporal symmetry breaking refers to a state in which the dynamic structure of a system changes, resulting in the destruction of temporal symmetry. It is determined by the structural residual between the real-time eigenvalue spectrum and the standard eigenvalue spectrum exceeding a preset threshold.

[0047] Specifically, the eigenvalues ​​at the same position in the real-time eigenvalue spectrum are subtracted from the eigenvalues ​​at the same position in the standard eigenvalue spectrum. The difference at each position is calculated, and the square root of the sum of the squares of all the differences is taken. The result is the structural residual.

[0048] In this embodiment, a real-time eigenvalue spectrum is calculated based on the collected runtime sequence data. Then, the structural residual between this real-time eigenvalue spectrum and the standard eigenvalue spectrum is calculated to quantify the degree of temporal symmetry violation. When this structural residual exceeds a preset dynamic threshold derived from historical data, temporal symmetry breaking is determined, thereby identifying a silent anomaly. Compared to single-point numerical comparison, this spectral structure comparison method is more resistant to random noise interference, improving the accuracy and robustness of detection.

[0049] S103, after identifying the silent anomaly, a symmetry breaking matrix is ​​calculated, and a valid symmetry breaking matrix is ​​locked by performing a time-series verification on the symmetry breaking matrix, so as to quantify the deviation degree of the silent anomaly and locate the anomaly dimension.

[0050] Among them, the symmetry-broken matrix refers to the difference matrix between the dynamic generator matrix and the reference generator matrix under real-time abnormal conditions.

[0051] Timing verification refers to the consistency verification of a symmetry-broken matrix within multiple consecutive sliding windows to filter out transient noise and spurious coupling.

[0052] Effective symmetric broken matrix: refers to a symmetric broken matrix that is confirmed to be real and persistent after time-series verification.

[0053] Anomaly dimension: refers to the specific system indicator dimension that causes silent anomalies to occur.

[0054] In this embodiment, a symmetry breaking matrix is ​​calculated. A single calculated matrix may be affected by transient noise; therefore, by performing a time-series verification on the symmetry breaking matrix, a true and continuously existing valid symmetry breaking matrix is ​​identified. This valid matrix quantifies the degree to which silent anomalies deviate from a healthy steady state, and by analyzing its structure, the specific dimension of the anomaly (e.g., database connection pool or message queue backlog) can be located.

[0055] In one optional implementation, the dynamic steady-state benchmark includes a benchmark Lie algebra generator matrix; after identifying the quiescent anomaly, S103 calculates a symmetry breaking matrix and locks a valid symmetry breaking matrix by performing a time-series verification on the symmetry breaking matrix, specifically including: Step b1: Based on the dynamic characteristics of the runtime sequence data under the silent anomaly, a real-time anomaly Lie algebra generator matrix is ​​calculated.

[0056] Among them, the real-time anomaly Lie algebra generator matrix refers to the dynamic generator matrix extracted from the runtime sequence data under silent anomaly states.

[0057] Specifically, based on the system state vector sequence during the silent abnormal period, the variation law of the state vector between adjacent time steps is analyzed, and by fitting the local dynamic mapping relationship, the generator matrix that can characterize the instantaneous dynamics of the system during this period is solved.

[0058] Step b2: Perform a difference operation between the real-time abnormal Lie algebra generator matrix and the baseline Lie algebra generator matrix to obtain the symmetry breaking matrix.

[0059] Specifically, the elements at the same positions in the real-time abnormal Lie algebra generator matrix and the benchmark Lie algebra generator matrix are subtracted respectively to obtain a new matrix, which is the symmetry breaking matrix.

[0060] Step b3 involves performing a time-series verification on the symmetry breaking matrix of multiple consecutive sliding windows to lock the effective symmetry breaking matrix.

[0061] Specifically, for multiple consecutive sliding windows, the symmetry breaking matrix corresponding to each window is calculated. The trend of the norm (or the amplitude of the elements in the matrix) of these matrices over time is observed: if a matrix appears only briefly in a single window and its norm quickly returns to normal, it is considered an artifact caused by random noise or instantaneous data jitter and is ignored; if a matrix persists in multiple consecutive windows and its norm stably deviates from zero, it is determined to be a symmetry breaking matrix caused by a real structural problem, and the matrix is ​​locked as a valid symmetry breaking matrix.

[0062] In this embodiment, the method based on Lie algebra generators captures structural changes in the system at a deeper dynamic level, making the quantification of anomalies more accurate. Then, by performing time-series verification on the symmetry breaking matrices of multiple consecutive sliding windows, the valid symmetry breaking matrix is ​​locked.

[0063] In an optional embodiment, step b3 involves performing a time-series verification on the symmetry breaking matrices of multiple consecutive sliding windows to lock the effective symmetry breaking matrix, specifically including: Step c1: Cache the symmetry breaking matrix calculated in multiple consecutive sliding windows within a continuous time period.

[0064] Step c2: Observe the changing trend of the symmetry-broken matrix or its norm over time.

[0065] Specifically, for each symmetric-broken matrix in the cache, its norm is calculated. If a symmetric-broken matrix appears only briefly in a single window and its norm quickly returns to normal, it is considered an artifact caused by random noise or instantaneous data jitter and is filtered out. If a symmetric-broken matrix persists in multiple consecutive windows and its norm stably deviates from zero, it is identified as a symmetric-broken matrix caused by a real structural problem.

[0066] Step c3 identifies the symmetric breaking matrix as persistent and stable and locks it as a valid symmetric breaking matrix.

[0067] In this embodiment of the application, the reliability of anomaly location is improved by the above timing verification, and erroneous repair operations caused by misjudgment are avoided.

[0068] S104. Based on the effective symmetry-broken matrix, a time-domain parity-flipping detector is constructed, and a micro-perturbation sequence is generated.

[0069] Among them, the time-domain parity flip detector is a mathematical transformation operator built on an effective symmetry-breaking matrix to break the metastable equilibrium of a system, and its strength is matched with the severity of the anomaly.

[0070] Micro-disturbance sequence: refers to a small, non-intrusive disturbance signal applied to the anomaly dimension, used to awaken latent anomalies into observable explicit deviations.

[0071] In this embodiment, a temporal parity flip detection operator is constructed based on the effective symmetry breaking matrix obtained in the previous step. The strength of this operator is adaptively determined according to the severity of the anomaly. Then, this operator is used to generate a small, non-intrusive perturbation sequence. Applying this perturbation sequence to the previously located anomaly dimension can disrupt the metastable equilibrium of the anomaly, amplifying the originally latent state drift and thus awakening it as an explicit deviation that can be captured by conventional monitoring tools. In this way, latent anomalies are awakened as explicit deviations.

[0072] In one optional implementation, the time-domain parity-flipping detector is constructed using the Lie group exponential mapping rule, and the time-domain parity-flipping detector has the form: P=exp(α·ΔG); where P is the time-domain parity-flipping detector, exp is the Lie group exponential mapping operation, α is the adaptive intensity coefficient, and ΔG is the effective symmetry breaking matrix.

[0073] Among them, the adaptive strength coefficient is a coefficient calculated based on the norm of the effective symmetry breaking matrix, which is used to control the perturbation strength.

[0074] Effective symmetric broken matrix: refers to a symmetric broken matrix that is locked through time-series verification.

[0075] The Lie group exponential mapping operation refers to the exponential operation that maps Lie algebra elements to Lie group elements. This operation is invertible.

[0076] In this embodiment, the time-domain parity-flipping detector is constructed as follows: using the product of the adaptive intensity coefficient and the effective symmetry-breaking matrix as a parameter, a Lie group exponential mapping operation is performed on this parameter, and the result is the time-domain parity-flipping detector. The time-domain parity-flipping detector is constructed based on the Lie group exponential mapping rule, and the invertibility of this mapping ensures that the operator has invertible transformation capabilities.

[0077] In an optional implementation, the time-series data includes a system state vector across multiple dimensions; S104 generates a micro-perturbation sequence, specifically including: Step d1 involves applying the time-domain parity-flipping detector to the system state vector at the current moment to calculate a steady-state target state vector.

[0078] Among them, the steady-state target state vector refers to the target operating state vector that the system should ideally recover to after transforming the current system state through the time-domain parity flip detector operator.

[0079] Specifically, the system state vector at the current moment is operated on with the constructed time-domain parity flip detector to obtain a theoretical steady-state target state vector, which represents the target operating point that the system should recover to under the current conditions.

[0080] Step d2: Determine the micro-disturbance sequence based on the steady-state target state vector and the system state vector at the current moment.

[0081] Specifically, the elements in the steady-state target state vector and the current system state vector that are in the same dimension are subtracted respectively to obtain the difference in each dimension. These differences are then arranged into a sequence in dimensional order, which is the micro-disturbance sequence.

[0082] In this embodiment of the application, by generating perturbations based on the target difference as described above, the wake-up operation has a clear physical meaning and a clear path, ensuring the accuracy of the perturbation.

[0083] To further enhance operational safety, in one optional implementation, before applying the minute perturbation sequence to the anomaly dimension, the method further includes: Step e1: On the digital twin model of the target operating platform, the operation of applying the micro-perturbation sequence is rehearsed.

[0084] Among them, the digital twin model refers to a virtual mirror model that is synchronized in real time with the state of the target operating platform.

[0085] Step e2: Apply the micro-perturbation sequence to the anomalous dimension if and only if the result of the pre-simulation satisfies the preset security constraints.

[0086] Among them, security constraints refer to a set of pre-defined rules used to assess operational risks, including stability conditions for key business indicators and thresholds for system state deterioration.

[0087] Specifically, the operation of applying a perturbation sequence is simulated on a digital twin model to evaluate whether the simulation results meet safety constraints (e.g., whether key business indicators are stable, and whether the system will enter a worse state). The applied operation is only executed on the real target operating platform if the simulation results indicate that the operation is safe.

[0088] In this embodiment of the application, the risk of automatic intervention in the production environment is reduced by using a pre-rehearsal and then execution mechanism.

[0089] S105, apply the micro-perturbation sequence to the anomaly dimension to awaken the silent anomaly into a detectable explicit deviation, and monitor the explicit deviation caused by the micro-perturbation sequence, and adjust the target operating platform according to the explicit deviation to complete the correction of the silent anomaly under the constraint of a preset fault tolerance mechanism.

[0090] Among them, explicit deviation refers to the deviation of the system state that has been amplified and can be captured by conventional monitoring tools.

[0091] A pre-defined fault-tolerance mechanism refers to a set of rules used to ensure the safety and controllability of the self-healing process. This mechanism includes: an iterative convergence determination rule to determine whether the repair process has reached its expected goal; a maximum iteration limit rule to prevent the repair process from falling into an infinite loop; and a disturbance circuit breaker rollback rule to abort the operation and roll back to a safe state when the repair operation is detected to have caused a deterioration in the system state. This mechanism provides a safety guarantee for the self-healing process.

[0092] In this embodiment, after a silent anomaly is successfully awakened as a dominant deviation, the system continuously monitors the dominant deviation caused by a sequence of minute disturbances and iteratively adjusts the control commands to the target operating platform based on changes in this deviation. The entire repair process is carried out under the constraints of a preset fault-tolerance mechanism to complete the final correction of the silent anomaly and restore the system to a healthy steady state.

[0093] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0094] For the silent anomaly handling method described in the above embodiments, please refer to [link / reference]. Figure 2This application also provides a silent anomaly handling system, which includes: The benchmark modeling module is used to construct a dynamic steady-state benchmark characterizing the health state of the target operating platform system based on time series data of the target operating platform under quasi-steady-state conditions. The real-time detection module is used to collect runtime timing data of the target operating platform in real time, and identify silent anomalies that indicate steady-state drift of the target operating platform by comparing the dynamic characteristics of the runtime timing data with the dynamic steady-state benchmark. The anomaly analysis module is used to calculate a symmetry breaking matrix after the silent anomaly is identified, and to lock a valid symmetry breaking matrix by performing time-series verification on the symmetry breaking matrix, so as to quantify the deviation degree of the silent anomaly and locate the anomaly dimension. The self-healing control module is used to construct a time-domain parity flip detection operator based on the effective symmetry breaking matrix and generate a micro-perturbation sequence; apply the micro-perturbation sequence to the anomaly dimension to awaken the silent anomaly into a monitorable explicit deviation; and monitor the explicit deviation caused by the micro-perturbation sequence, and adjust the target operating platform according to the explicit deviation to complete the correction of the silent anomaly under the constraint of a preset fault tolerance mechanism.

[0095] It should be noted that the information interaction and execution process between the above-mentioned components are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, and they will not be repeated here.

[0096] In one specific embodiment, the following will be combined with the appendix Figure 1 To be continued Figure 3 This application provides a detailed description of one specific embodiment. This embodiment is applied to a distributed big data platform and aims to automate the entire process of handling silent anomalies on the platform. This process relies on, for example... Figure 2 The silent anomaly handling system shown interacts with the target operating platform.

[0097] First, in the offline modeling stage, corresponding Figure 1S101 in the process is executed by the baseline modeling module. A stable runtime period of 7 consecutive days without version iterations, large-scale traffic fluctuations, or manual maintenance operations is selected for the target platform. Five-dimensional time-series runtime data, including CPU utilization, JVM heap memory usage, active database connection pool connections, average request processing time, and message queue backlog, are collected at a fixed sampling frequency of 100Hz. The system ensures the collection window is in a quasi-steady state by using preset quantitative indicators (e.g., load fluctuation amplitude less than 10%, instantaneous jump rate of single-dimensional indicators less than 5%; where the 10% and 5% thresholds are obtained by statistically analyzing the fluctuation distribution of historical stable runtime data at the 95th percentile). Based on these steady-state sample data, the system performs standardized preprocessing, uses a kernel density estimation algorithm to fit its high-dimensional probability distribution, and maps it according to the probability negative logarithm formula. Transform the probability distribution into a statistically equivalent dynamic potential field. The kernel function used is a Gaussian kernel with a bandwidth of [missing information]. Determined by Scott's rule: Where n is the number of samples and d is the data dimension; for multidimensional data, a diagonal bandwidth matrix is ​​used. V(x) represents the statistically equivalent potential field function, P(x) represents the steady-state operating probability density function of the target platform, and x represents the system state vector. Under healthy steady-state conditions, this potential field behaves as a normal steady-state potential well, and the system state vector converges to the vicinity of the global optimum of this potential well. Subsequently, based on this steady-state potential field, the system solves for and solidifies the benchmark Lie algebra generator matrix (whose actual norm approaches zero, e.g., 0.03) and the standard eigenvalue spectrum. Simultaneously, based on the 95th quantile of the eigenvalue spectrum residuals from 7 days of steady-state historical data, a steady-state critical threshold of 0.05 is statistically generated. These collectively constitute the dynamic steady-state benchmark for subsequent comparisons.

[0098] During the platform's online operation phase, the corresponding Figure 1 S102 in the process is executed by the real-time detection module. The system continuously collects real-time operating data in a fixed 10-second sliding window. For each window that passes the quasi-steady-state access check, the system extracts the real-time eigenvalue spectra of its forward and reverse time-series state matrices and calculates the structural residuals with the aforementioned standard eigenvalue spectra. Under a specific operating condition, the calculated structural residual of the eigenvalue spectrum for the current window is 0.23, which is significantly greater than the steady-state critical threshold of 0.05. Therefore, the system determines that the target operating platform has experienced a time-domain symmetric structural failure and identifies a silent anomaly. At this time, the platform itself does not issue any alarms, confirming the concealment of the anomaly.

[0099] After an anomaly is detected, the process proceeds to S103, where the anomaly analysis module performs its work. The system uses the data from the current anomaly window to reconstruct the statistical equivalent potential field under the abnormal operating condition. The original normal steady-state potential pit splits or evolves into one or more shallow metastable potential pits, and the system state falls into a metastable point, confirming the existence of the silent anomaly. Next, using the state vector of the final window state as a reference point, a first-order Taylor expansion of the anomalous potential field is performed, and the dynamic Jacobian matrix is ​​obtained. (For example, the dynamic Jacobian matrix can be estimated from discrete time series data using the existing local linear regression method.) According to the formula The real-time anomaly Lie algebra generator matrix is ​​calculated. .in, For real-time anomaly Lie algebra generator matrix, For the dynamic Jacobian matrix, Let be the transpose of the dynamic Jacobian matrix. This is a predefined matrix symmetry operator. Subsequently, difference operations are performed. Obtain the symmetry-broken matrix .in, It is a symmetric broken matrix. For real-time anomaly Lie algebra generator matrix, The matrix is ​​a generator matrix of the baseline Lie algebra. The calculated Frobenius norm of this matrix is ​​0.87, significantly higher than the random noise filtering threshold of 0.5, confirming it as a structurally true symmetry violation. Finally, through analysis of six consecutive sliding windows... By performing time-series verification, transient noise and spurious coupling were filtered out, and a valid symmetric breaking matrix was finally identified. It was also determined that the anomalies mainly originated from two dimensions: database connection pool and message queue backlog.

[0100] Next, steps S104 and S105 are executed by the self-healing control module, and its interaction timing with the target operating platform is as follows: Figure 3 As shown. First, based on the effective symmetry breaking matrix obtained in the previous step... Through formula Calculate the adaptive strength coefficient .in, For adaptive strength coefficient, Let be the Frobenius norm of the symmetric broken matrix, and min be the minimization function. In this embodiment, since... Calculated The upper limit is clamped to 2.0. Then, the time-domain parity-flipping probe operator P is constructed using the Lie group exponential mapping formula P=exp(α·ΔG). Here, P is the time-domain parity-flipping probe operator, exp(·) is the Lie group exponential mapping operation, α is the adaptive intensity coefficient, and ΔG is the effective symmetry breaking matrix. Next, using the formula... Calculate the theoretical steady-state target state vector. .in, Let P be the steady-state target state vector, and let P be the time-domain parity flip detector operator. The target state is the state vector at the end of the window. Based on this target state, the system generates a smooth, micro-perturbation sequence that meets business security constraints (e.g., state transition time less than 500ms) and precisely applies it to the two anomaly dimensions of the located database connection pool and message queue backlog. After the perturbation is applied, the state deviation of the relevant dimensions is significantly amplified (e.g., the amplification factor is about 2 times), waking up the latent anomaly into an explicit deviation. After successful wake-up, the system enters the iterative repair process: the self-healing control module receives the real-time state after the perturbation from the target operating platform, evaluates the current convergence, and adjusts the strategy according to the evaluation results; if the convergence condition is not met, the next round of perturbation or repair instructions is applied, and the above wake-up and monitoring steps are repeated. In this iteration, the norm of the repaired symmetric broken matrix drops to 0.07 (example value), which is less than the preset convergence threshold (e.g., 0.1), and the self-healing repair is determined to be complete. The entire process is carried out safely under the constraints of a preset fault tolerance mechanism, which includes, but is not limited to: a maximum iteration limit (e.g., 8 times) and a perturbation circuit breaker rollback rule (e.g., triggering rollback when the intensity increase exceeds 30%).

[0101] In another application scenario, such as high-frequency trading systems with high real-time requirements, the technical solution of this application is also applicable, but some parameters can be adjusted according to the scenario. The sliding window duration is set to 2 seconds, corresponding to 200 sampling points; the state transition time during the self-healing process is 100 milliseconds; and the maximum number of iterations is set to 3. When the repair attempt fails to complete after exceeding this number, the system triggers an alarm and switches to manual intervention. Under this configuration, the warning time after an anomaly occurs is within 2 seconds, and the wake-up or repair decision is completed within the hundreds of milliseconds.

[0102] In one alternative implementation, for fine control of the adaptive wake-up process, the adaptive strength coefficient... The calculation can employ nonlinear functions to achieve smoother and more precise matching of perturbation strength. For example, the sigmoid function can be used for calculation: .in, For adaptive strength coefficient, is the preset maximum disturbance strength (e.g., 3.0), and k is a parameter controlling the kurtosis of the function. It is a natural constant. is the symmetry breaking intensity of the current anomaly, and c is the midpoint of the response (e.g., it can be set to a noise threshold of 0.5). After calculation using this nonlinear function, when the silent anomaly intensity is slightly higher than the noise threshold, the output adaptive intensity coefficient... When the anomaly intensity is small, it generates weak perturbations; when the anomaly intensity increases significantly, the output adaptive intensity coefficient... It will grow rapidly to near its limit, generating strong perturbations. This strategy assigns perturbations of varying intensities to anomalies of different severity, making the system more intelligent and secure in handling anomalies of varying severity.

[0103] In one optional implementation, the silent anomaly handling system integrates or associates a digital twin model that is synchronized in real time with the target operating platform's state. After calculating a micro-disturbance sequence, the self-healing control module first applies this sequence to the digital twin model to predict the system state at the next time step. When the prediction result meets all preset safety constraints (e.g., a decrease in the norm of the symmetric breaking matrix, and no negative fluctuations in key business indicators), the disturbance sequence is then applied to the actual target operating platform. If the simulation results indicate a risk (e.g., database connection pool jitter exceeding limits), the self-healing operation is aborted and an alarm is triggered.

[0104] This application also provides a computer device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor, wherein the processor executes the computer program to implement the steps in any of the above method embodiments.

[0105] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps in the various method embodiments described above.

[0106] This application provides a computer program product that, when run on a computer device, enables the computer device to execute the steps described in the various method embodiments above.

[0107] Figure 4 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Figure 4 As shown, the computer device of this embodiment includes: at least one processor 40 ( Figure 4 (Only one is shown in the diagram), memory 41, and computer program 42 stored in the memory 41 and executable on the at least one processor 40, wherein the processor 40 executes the computer program 42 to implement the steps in any of the above-described silent exception handling method embodiments.

[0108] The computer device may include, but is not limited to, a processor 40 and a memory 41. Those skilled in the art will understand that... Figure 4 The examples of computer devices are merely examples and do not constitute a limitation on computer devices. They may include more or fewer components than shown in the illustration, or combinations of certain components, or different components. For example, they may also include input / output devices, network access devices, etc.

[0109] The processor 40 may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.

[0110] In some embodiments, the memory 41 may be an internal storage unit of the computer device, such as a hard disk or memory. In other embodiments, the memory 41 may be an external storage device of the computer device, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc. Furthermore, the memory 41 may include both internal and external storage units of the computer device. The memory 41 is used to store the operating system, applications, bootloader, data, and other programs, such as the program code of the computer program. The memory 41 can also be used to temporarily store data that has been output or will be output.

[0111] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of this application can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to a device / computer equipment, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks.

[0112] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0113] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0114] In the embodiments provided in this application, it should be understood that the disclosed apparatus / computer devices and methods can be implemented in other ways. For example, the apparatus / computer device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings or direct couplings or communication connections may be through some interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.

[0115] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0116] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A method for handling silent anomalies, characterized in that, include: Based on the time series data of the target operating platform under quasi-steady-state conditions, a dynamic steady-state benchmark characterizing the health state of the target operating platform system is constructed. Real-time acquisition of runtime timing data of the target operating platform; by comparing the dynamic characteristics of the runtime timing data with the dynamic steady-state benchmark, identification of silent anomalies indicating steady-state drift of the target operating platform; After identifying the silent anomaly, a symmetry breaking matrix is ​​calculated, and a valid symmetry breaking matrix is ​​locked by performing a time-series verification on the symmetry breaking matrix to quantify the degree of deviation of the silent anomaly and locate the anomaly dimension. Based on the effective symmetry-broken matrix, a time-domain parity-flipping detector is constructed, and a micro-perturbation sequence is generated; The micro-perturbation sequence is applied to the anomaly dimension to awaken the silent anomaly into a detectable explicit deviation; The system monitors the explicit deviation caused by the micro-perturbation sequence and adjusts the target operating platform according to the explicit deviation to complete the correction of the silent anomaly under the constraint of a preset fault tolerance mechanism.

2. The method according to claim 1, characterized in that, The dynamic steady-state benchmark includes a standard eigenvalue spectrum; the step of identifying silent anomalies indicating steady-state drift of the target operating platform by comparing the dynamic characteristics of the runtime timing data with the dynamic steady-state benchmark includes: Based on the dynamic characteristics of the runtime sequence data, the real-time eigenvalue spectrum is calculated; By calculating the structural residual between the real-time eigenvalue spectrum and the standard eigenvalue spectrum, it is determined whether the target operating platform has experienced temporal symmetry breaking, thereby identifying the silent anomaly.

3. The method according to claim 1 or 2, characterized in that, The dynamic steady-state benchmark includes a benchmark Lie algebra generator matrix; after identifying the quiescent anomaly, a symmetry breaking matrix is ​​calculated, and a valid symmetry breaking matrix is ​​locked by performing a time-series verification on the symmetry breaking matrix, including: Based on the dynamic characteristics of the runtime sequence data under the silent anomaly, a real-time anomaly Lie algebra generator matrix is ​​calculated. The difference operation is performed between the real-time anomaly Lie algebra generator matrix and the baseline Lie algebra generator matrix to obtain the symmetry breaking matrix. The effective symmetry breaking matrix is ​​locked by performing time-series verification on the symmetry breaking matrix of multiple consecutive sliding windows.

4. The method according to claim 1, characterized in that, The time-series data includes a system state vector across multiple dimensions; generating a micro-perturbation sequence includes: A steady-state target state vector is calculated by applying the time-domain parity-flipping detector to the system state vector at the current moment; The micro-disturbance sequence is determined based on the steady-state target state vector and the system state vector at the current moment.

5. The method according to claim 1, characterized in that, The preset fault tolerance mechanism includes at least one of the following: iterative convergence determination rule, maximum iteration limit rule, and disturbance circuit breaker rollback rule.

6. The method according to claim 1, characterized in that, The time-domain parity-flipping detector is constructed using the Lie group exponential mapping rule, and its form is as follows: P = exp(α·ΔG); where P is the time-domain parity flip detector, exp is the Lie group exponential mapping operation, α is the adaptive intensity coefficient, and ΔG is the effective symmetry breaking matrix.

7. The method according to claim 1, characterized in that, The step of applying the micro-perturbation sequence before applying it to the anomaly dimension further includes: On the digital twin model of the target operating platform, the operation of applying the micro-perturbation sequence is rehearsed; The step of applying the micro-perturbation sequence to the anomalous dimension is performed only if the result of the pre-simulation satisfies the preset safety constraints.

8. A silent anomaly handling system, characterized in that, include: The benchmark modeling module is used to construct a dynamic steady-state benchmark characterizing the health state of the target operating platform system based on time series data of the target operating platform under quasi-steady-state conditions. The real-time detection module is used to collect runtime timing data of the target operating platform in real time, and identify silent anomalies that indicate steady-state drift of the target operating platform by comparing the dynamic characteristics of the runtime timing data with the dynamic steady-state benchmark. The anomaly analysis module is used to calculate a symmetry breaking matrix after the silent anomaly is identified, and to lock a valid symmetry breaking matrix by performing time-series verification on the symmetry breaking matrix, so as to quantify the deviation degree of the silent anomaly and locate the anomaly dimension. The self-healing control module is used to construct a time-domain parity flip detection operator based on the effective symmetry breaking matrix and generate a micro-perturbation sequence; apply the micro-perturbation sequence to the anomaly dimension to awaken the silent anomaly into a monitorable explicit deviation; and monitor the explicit deviation caused by the micro-perturbation sequence, and adjust the target operating platform according to the explicit deviation to complete the correction of the silent anomaly under the constraint of a preset fault tolerance mechanism.

9. A computer device, characterized in that, The method includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the method as claimed in any one of claims 1 to 7.

10. A computer program product, characterized in that, Includes a computer program that, when run, implements the method as described in any one of claims 1 to 7.