A ghost asset detection method and system based on causal inference and perturbation propagation

CN122840352APending Publication Date: 2026-09-29STATE GRID QINGHAI ELECTRIC POWER COMPANY +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611207245.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-11
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0005]针对现有技术的以上缺陷或改进需求,本发明提供了一种基于因果推断与扰动传播的幽灵资产检测方法,其目的在于,解决现有基于静态台账与配置扫描的比对方法严重依赖台账的完整性和扫描频率,无法发现台账中本就缺失的幽灵资产,且无法检测不产生网络流量的隐藏行为的技术问题,以及现有基于阈值与规则的单指标异常检测方法无法区分异常是由已知组件故障引起还是由未知的幽灵资产导致,缺乏根源定位能力,且难以发现行为复杂、影响间接的隐蔽资产的技术问题,以及现有基于关联分析与拓扑依赖的故障定位方法需要预先知道组件间的完整依赖拓扑,无法适用于依赖关系未知或存在隐藏交互的幽灵资产场景的技术问题

Benefits of technology

1、本发明由于采用了步骤(2)和步骤(3),其通过时间卷积因果发现模型从纯数据驱动的角度自动构建扰动传播因果图,并利用排列重要性验证方法对因果边进行统计学验证,因此无需依赖任何静态台账、配置清单或先验拓扑知识,仅需通用的运维指标数据即可发现系统中存在的隐藏依赖关系,因此能够解决现有基于静态台账与配置扫描的比对方法严重依赖台账的完整性和扫描频率,无法发现台账中本就缺失的幽灵资产,且无法检测不产生网络流量的隐藏行为的技术问题;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122840352A_ABST
    Figure CN122840352A_ABST
Patent Text Reader

Abstract

This invention discloses a ghost asset detection method based on causal inference and perturbation propagation. It employs a collaborative strategy of "causal discovery + counterfactual attribution + ghost asset profiling" to achieve comprehensive coverage of ghost assets from causal discovery to precise location and behavioral characterization. Its core innovation lies in the ability of the temporal convolutional causal discovery model to indirectly discover hidden confounding factors; hidden assets leave traces in the causal structure as unobserved confounding factors. This invention automatically constructs a perturbation propagation causal graph from the system's time-series monitoring data, then locates logical gaps through causal path analysis, and finally uses counterfactual inference to depict ghost asset profiles. The entire process does not rely on any ledger or topological prior knowledge, thus solving the technical problems of existing comparison methods based on static ledgers and configuration scanning failing to discover ghost assets that are missing from the ledger and failing to detect hidden behaviors that do not generate network traffic.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of power system operation and maintenance monitoring and abnormal asset detection technology, and more specifically, relates to a ghost asset detection method and system based on causal inference and disturbance propagation. Background Technology

[0002] Ghost assets in a power system refer to hidden assets or abnormal components that exist in the system, consume resources, and have an impact, but are not effectively registered, monitored, or included in the regular management system. These assets may exist in the form of unregistered services, hidden processes, unreasonable external dependencies, or periodic abnormal tasks. They are not reflected in static ledgers or configuration lists, but they actually participate in system operation, interfere with normal monitoring, and become blind spots for fault tracing and performance optimization.

[0003] Currently, common methods for detecting ghost assets include the following: The first method is a comparison method based on static ledgers and configuration scanning. It pre-maintains a complete power asset ledger (such as IP addresses, service ports, process lists, etc.) and obtains the list of currently online assets through periodic scanning or proxy reporting. The two are then compared to identify abnormal assets that are not registered in the ledger. This method is simple to implement. 2. Threshold and rule-based single-indicator anomaly detection method: This method sets static or dynamic thresholds for key operation and maintenance indicators such as CPU utilization, memory usage, and network latency. When an indicator continuously exceeds the threshold, an alarm is triggered. This type of method can detect some resource consumption anomalies. 3. Fault location method based on association analysis and topology dependency: It analyzes the call chain or dependency relationship between system components. When a component fails, it traces upstream along the dependency relationship to locate the root cause.

[0004] However, all of the above-mentioned methods for detecting ghost assets have some significant drawbacks: 1. Existing comparison methods based on static ledgers and configuration scanning heavily rely on the completeness of the ledgers and the scanning frequency, making it impossible to discover ghost assets that are missing from the ledgers and to detect hidden behaviors that do not generate network traffic. 2. Existing single-index anomaly detection methods based on thresholds and rules cannot distinguish whether anomalies are caused by known component failures or unknown ghost assets, lacking root cause localization capabilities and making it difficult to discover hidden assets with complex behavior and indirect impact. 3. Existing fault location methods based on correlation analysis and topology dependency require prior knowledge of the complete dependency topology between components (such as service mesh, call chain tracing system), which cannot be applied to ghost asset scenarios where the dependency relationship is unknown or there are hidden interactions. Summary of the Invention

[0005] To address the aforementioned deficiencies or improvement needs of existing technologies, this invention provides a ghost asset detection method based on causal inference and perturbation propagation. Its purpose is to solve the technical problems of existing comparison methods based on static ledgers and configuration scanning, which heavily rely on the completeness of the ledger and scanning frequency, failing to detect ghost assets that are inherently missing from the ledger, and failing to detect hidden behaviors that do not generate network traffic; existing single-indicator anomaly detection methods based on thresholds and rules, which cannot distinguish whether anomalies are caused by known component failures or unknown ghost assets, lacking root cause localization capabilities, and struggling to detect complex, indirectly impactful hidden assets; and existing fault location methods based on correlation analysis and topological dependencies, which require prior knowledge of the complete dependency topology between components, making them unsuitable for ghost asset scenarios with unknown dependencies or hidden interactions.

[0006] To achieve the above objectives, according to one aspect of the present invention, a method for detecting ghost assets based on causal inference and perturbation propagation is provided, comprising the following steps: (1) Obtain multiple original operation and maintenance monitoring data generated during the operation of the power monitoring system, preprocess all original operation and maintenance monitoring data to obtain a standardized multidimensional time series matrix. The rows in the standardized multidimensional time series matrix are the time steps corresponding to the original operation and maintenance monitoring data, and the columns are the monitoring indicators corresponding to the original operation and maintenance monitoring data. (2) Perform causal structure learning on the standardized multidimensional time series matrix obtained in step (1) to obtain the initial causal adjacency matrix; (3) Extract all elements with non-zero weight values ​​from the initial causal adjacency matrix obtained in step (2), set the node pairs corresponding to each element as candidate causal edges, perform a significance test on each candidate causal edge, and obtain the processed causal adjacency matrix based on the significance test results of all candidate causal edges. (4) Input the processed causal adjacency matrix obtained in step (3) into the graph convolutional network for encoding to obtain the node structure feature matrix; (5) Input the node structure feature matrix obtained in step (4) into the pre-trained ghost asset detection model to obtain the ghost asset detection results.

[0007] Preferably, step (1) involves obtaining multiple raw operation and maintenance monitoring data generated during the operation of the power monitoring system from various nodes and middleware of the power monitoring system, including CPU utilization, memory utilization, network latency, query rate per second of each microservice, and disk input / output. The preprocessing process in step (1) is as follows: First, all original operation and maintenance monitoring data are cleaned, that is, outliers are removed and missing values ​​are filled in to obtain multiple cleaned operation and maintenance monitoring data; then, all cleaned operation and maintenance monitoring data are resampled and aligned according to a uniform sampling interval to obtain multiple time-series aligned operation and maintenance monitoring data; finally, all time-series aligned operation and maintenance monitoring data are organized into a standardized multi-dimensional time series matrix, where the rows are the time steps corresponding to the original operation and maintenance monitoring data and the columns are the monitoring indicators corresponding to the original operation and maintenance monitoring data. The monitoring metrics corresponding to the operation and maintenance monitoring data include CPU utilization, memory utilization, network latency, queries per second for each microservice, and disk input / output.

[0008] Preferably, step (2) includes the following sub-steps: (2-1) Use dilated convolutional neural networks to extract time series features and encode the interaction between variables of the standardized multidimensional time series matrix obtained in step (1) so as to obtain multiple monitoring indicators corresponding to the standardized multidimensional time series matrix as multiple nodes, and high-dimensional feature tensors between the node pairs formed by the i-th node and the j-th node, where i≠j, and i and j are both ∈[1, the total number of nodes corresponding to the standardized multidimensional time series matrix N]; (2-2) The high-dimensional feature tensor between each node pair obtained in step (2-1) is mapped to a scalar through the attention mechanism, which serves as the causal effect weight of the node pair; (2-3) Obtain all node pairs whose causal effect weights exceed the preset threshold θ from all the causal effect weights obtained in step (2-2), and construct an initial causal adjacency matrix based on all the obtained node pairs; where the rows of the initial causal adjacency matrix are source nodes and the columns are target nodes.

[0009] Preferably, step (3) includes the following sub-steps: (3-1) Extract all elements with non-zero weight values ​​in the initial causal adjacency matrix obtained in step (2), and take the node pair (u,v) corresponding to each element in the initial causal adjacency matrix as a candidate causal edge. Construct a time series prediction model based on the Long Short-Term Memory Network (LSTM) for the candidate causal edge. Input the data of the corresponding column of node u in the node pair (u,v) in the standardized multidimensional time series matrix obtained in step (1) into the time series prediction model corresponding to node u. Obtain the true value of node u at the next time step from the standardized multidimensional time series matrix, and use the trained LSTM model to obtain the predicted value of node u at the next time step. Here, node u and node v represent the u-th monitoring index and the v-th monitoring index in the standardized multidimensional time series matrix obtained in step (1), respectively. u and v ∈ [1, the total number of nodes corresponding to the element]; (3-2) Calculate the error between the predicted value and the true value of node u obtained in step (3-1) at the next time step as the baseline prediction error; randomly shuffle the position of the uth monitoring index in the standardized multidimensional time series matrix obtained in step (1), and input the feature column of the shuffled node u in the standardized multidimensional time series matrix obtained in step (1) back into the LSTM model corresponding to node u to obtain a new prediction value, and calculate the error between the new prediction value and the true value as the perturbation prediction error; (3-3) Determine whether the difference between the perturbation prediction error obtained in step (3-2) and the baseline prediction error is greater than the preset threshold λ. If so, it means that the candidate causal edge corresponding to the node pair (u,v) really exists, and the candidate causal edge is retained. Then proceed to step (3-4); otherwise, delete the candidate causal edge and set its corresponding element in the initial causal adjacency matrix to 0. (3-4) For all remaining elements in the initial causal adjacency matrix with non-zero weight values, repeat the above steps (3-3) until all candidate causal edges corresponding to them have been processed, thus obtaining the processed initial causal adjacency matrix.

[0010] Preferably, step (4) includes the following sub-steps: (4-1) Based on the processed causal adjacency matrix obtained in step (3), a directed graph is constructed. Each node in the directed graph corresponds to the monitoring index in the standardized multidimensional time series matrix in step (1), and each directed edge corresponds to the candidate causal edge that has been tested for significance and retained in step (3). (4-2) For each node in the directed graph obtained in step (4-1), the windowed time series feature with dimension N×16 obtained by slicing the standardized multidimensional time series matrix obtained in step (1) through a sliding window is used as the initial feature vector corresponding to the node. An initial node feature matrix with dimension N×N is constructed based on the initial feature vectors corresponding to all nodes, where N represents the total number of monitoring indicators in the standardized multidimensional time series matrix obtained in step (1), that is, the total number of nodes in the directed graph obtained in step (4-1). (4-3) Input the directed graph obtained in step (4-1) and the initial node feature matrix obtained in step (4-2) into the graph convolutional network for encoding to obtain a node structure feature matrix with dimension N×32; wherein the graph convolutional network contains two graph convolutional layers, the first layer has 16 input channels and 64 output channels, and the second layer has 64 input channels and 32 output channels.

[0011] Preferably, step (5) includes the following sub-steps: (5-1) Input the node structure feature matrix obtained in step (4) into the multi-head graph attention module in the pre-trained ghost asset detection model to obtain the enhanced feature matrix; (5-2) Input the enhanced feature matrix obtained in step (5-1) into the two fully connected network and softmax classifier in the ghost asset detection model to obtain the ghost asset profile label probability matrix corresponding to each node; (5-3) Set the index position of each node with a probability value greater than the confidence threshold μ in the image tag probability matrix obtained in step (5-2) to 1, and set the index position of each node with a probability value less than or equal to the confidence threshold μ to 0, so as to obtain the ghost asset node indicator vector, and set all nodes with a value of 1 in the ghost asset node indicator vector as target nodes. (5-4) Obtain the corresponding column data of each target node obtained in step (5-3) in the standardized multidimensional time series matrix obtained in step (1), and concatenate it with the position of the maximum probability value of each node in the ghost asset profile label probability matrix obtained in step (5-2) to generate a structured ghost asset description text as the description information of the target node. (5-5) Summarize the description information of all target nodes obtained in step (5-4) to generate ghost asset detection results, which include a list of ghost asset nodes, profile categories, behavioral feature descriptions, and suspected influence range.

[0012] Preferably, the specific structure of the ghost asset detection model is as follows: The first layer is the data preprocessing and feature extraction module. Its input is an initial multidimensional time series matrix of dimension T×N composed of multiple original operation and maintenance monitoring data. This layer first normalizes the initial multidimensional time series matrix, mapping the numerical range of each column of monitoring indicators to the interval [0, 1] to obtain a normalized multidimensional time series matrix. Then, a sliding window mechanism is used to slice the normalized multidimensional time series matrix to obtain an initial node feature matrix of dimension N×16 composed of the initial time series feature vectors of all nodes in the normalized multidimensional time series matrix and output it. Here, T represents the time step, i.e. the total number of observation times, and N represents the total number of observation variables, i.e. the number of monitoring indicators. The second layer is the causal structure learning module. Its input is the initial node feature matrix with a dimension of N×16 output from the first layer. This layer first uses an extended convolutional neural network to extract temporal features and encode the interaction between variables in the initial node feature matrix to obtain multiple monitoring indicators as multiple nodes, and a high-dimensional feature tensor between the node pairs formed by the i-th node and the j-th node. Then, through an attention mechanism, the high-dimensional feature tensor between each node pair is mapped to a scalar as the causal effect weight of the node pair. Finally, all node pairs whose causal effect weights exceed a preset threshold θ are obtained from all the obtained causal effect weights, and an initial causal adjacency matrix with a dimension of N×N is constructed and output based on all the obtained node pairs. The rows of the initial causal adjacency matrix are source nodes, and the columns are target nodes, where i≠j, and i and j are both ∈ [1, N]. The third layer is the causal edge saliency testing module. Its inputs are the initial causal adjacency matrix (N×N) output from the second layer and the initial node feature matrix (N×16) output from the first layer. This layer first extracts all elements with non-zero weight values ​​from the initial causal adjacency matrix. The node pair (u, v) corresponding to each element in the initial causal adjacency matrix is ​​then used as a candidate causal edge. A time-series prediction model based on a Long Short-Term Memory (LSTM) network is constructed for this candidate causal edge. This LSM model contains two hidden layers, each with 64 hidden units. The data of node u in the node pair (u, v) corresponding to the column in the initial node feature matrix is ​​input into the corresponding LSM model to obtain the predicted value of node u at the next time step. Finally, the predicted value of node u at the next time step is obtained from the initial node feature matrix. The system first calculates the error between the predicted value and the true value to obtain the baseline prediction error. Then, it randomly shuffles the time order of the corresponding columns of node u in the initial node feature matrix and re-inputs the shuffled data into the long short-term memory network model corresponding to node u to obtain a new prediction value. The system then calculates the error between the new prediction value and the true value to obtain the perturbation prediction error. Subsequently, it determines whether the difference between the perturbation prediction error and the baseline prediction error is greater than a preset threshold λ. If so, it determines that the candidate causal edge truly exists and retains the candidate causal edge; otherwise, it deletes the candidate causal edge and sets the corresponding element value in the initial causal adjacency matrix to 0. Finally, the above processing is performed on all remaining elements in the initial causal adjacency matrix with non-zero weight values ​​to obtain the processed causal adjacency matrix and output it. The fourth layer is a graph structure encoding module. Its input is the processed causal adjacency matrix of dimension N×N output from the third layer and the initial node feature matrix of dimension N×16 output from the first layer. This layer first constructs a directed graph based on the processed causal adjacency matrix. Each node in the directed graph corresponds to a monitoring index in the standardized multidimensional time series matrix, and each directed edge corresponds to a candidate causal edge that has been tested for saliency and retained. Then, the directed graph and the initial node feature matrix are input into a graph convolutional network for encoding to obtain a node structure feature matrix of dimension N×32 and output it. The fifth layer is the ghost asset detection module. Its input is the node structure feature matrix with a dimension of N×32 output from the fourth layer. This layer first inputs the node structure feature matrix into the multi-head graph attention module to obtain the enhanced feature matrix. Then, the enhanced feature matrix is ​​input into two fully connected network layers and a softmax classifier to obtain the ghost asset profile label probability matrix corresponding to each node and output it. Layer 6 is the result generation and output module. Its input is the N×C ghost asset profile label probability matrix output from Layer 5. This layer first sets the index position of each node in the profile label probability matrix whose probability value is greater than the confidence threshold μ to 1, and sets the index position of each node whose probability value is less than or equal to the confidence threshold μ to 0, to obtain the ghost asset node indicator vector. All nodes with a value of 1 in the ghost asset node indicator vector are taken as target nodes, and the column data corresponding to each target node in the standardized multidimensional time series matrix obtained in Layer 1 is obtained. Then, the column data corresponding to each target node in the standardized multidimensional time series matrix is ​​concatenated with the position of the maximum probability of each node in the ghost asset profile label probability matrix output from Layer 5 to generate a structured ghost asset description text as the description information of the target node. Finally, the description information of all target nodes is summarized to generate the ghost asset detection result, which includes a list of ghost asset nodes, profile category, behavioral feature description, and suspected influence range.

[0013] Preferably, the ghost asset detection model is trained through the following steps: (A1) Obtain a multi-source heterogeneous dataset from the power monitoring system network environment, and divide the multi-source heterogeneous dataset into a training set and a test set in an 8:2 ratio; (A2) Perform data preprocessing on the training set obtained in step (A1) to obtain the preprocessed training set; (A3) Input the preprocessed training set obtained in step (A2) into the causal structure learning module to obtain the initial causal adjacency matrix; (A4) Perform a causal edge significance test on the initial causal adjacency matrix obtained in step (A3) to obtain the processed causal adjacency matrix; (A5) Input the processed causal adjacency matrix obtained in step (A4) into the graph convolutional network for encoding to obtain the node structure feature matrix; (A6) Input the node structure feature matrix obtained in step (A5) into the ghost asset detection model to obtain the cross-entropy loss function. Based on the cross-entropy loss function, update the network parameters of the ghost asset detection model using the backpropagation algorithm to obtain the initially trained ghost asset detection model. (A7) Use the test set obtained in step (A1) to test the ghost asset detection model that has been initially trained in step (A6) until the detection accuracy reaches the optimal level, so as to obtain the final trained ghost asset detection model.

[0014] Preferably, step (A2) specifically involves: first, cleaning the training set obtained in step (A1); then, resampling and aligning the cleaned training set according to a uniform time frequency; subsequently, constructing a multi-dimensional time series matrix from the aligned training set; and finally, normalizing the multi-dimensional time series matrix through the data preprocessing and feature extraction module, and slicing the normalized multi-dimensional time series matrix through a sliding window mechanism to obtain an initial node feature matrix of dimension N×16 as the preprocessed training set. Step (A3) is as follows: First, the dilated convolutional neural network in the causal structure learning module is used to extract temporal features and encode the interaction between variables in the preprocessed training set to obtain multiple monitoring indicators corresponding to the preprocessed training set as multiple nodes, and a high-dimensional feature tensor between the node pairs consisting of the i-th node and the j-th node, where i≠j and i and j are both ∈[1,N]. Then, the high-dimensional feature tensor between each node pair is mapped to a scalar through an attention mechanism, which serves as the causal effect weight of the node pair. Finally, all node pairs whose causal effect weights exceed a preset threshold θ are obtained from all the obtained causal effect weights, and an initial causal adjacency matrix is ​​constructed based on all the obtained node pairs. The rows of the initial causal adjacency matrix are source nodes, and the columns are target nodes. Step (A4) specifically involves the following steps: First, based on the causal edge saliency test module, extract all elements with non-zero weight values ​​from the initial causal adjacency matrix. For each element, the corresponding node pair (u, v) in the initial causal adjacency matrix is ​​used as a candidate causal edge. A time-series prediction model based on a long short-term memory network is constructed for this candidate causal edge. The data of the corresponding column of node u in the preprocessed training set is input into the long short-term memory network model to obtain the predicted value of node u at the next time step. The error between the predicted value and the true value is then calculated as the baseline prediction error. Next, the nodes u are randomly shuffled. In the preprocessed training set, the shuffled data is re-input into the Long Short-Term Memory network model to obtain new predicted values. The error between the new predicted value and the true value is calculated as the perturbation prediction error. Then, it is determined whether the difference between the perturbation prediction error and the baseline prediction error is greater than a preset threshold λ. If it is, the candidate causal edge is retained; otherwise, the candidate causal edge is deleted and its corresponding element value in the initial causal adjacency matrix is ​​set to 0. Finally, the above processing is performed on all remaining elements in the initial causal adjacency matrix with non-zero weight values ​​to obtain the processed causal adjacency matrix. Step (A5) is as follows: First, a directed graph is established based on the processed causal adjacency matrix. Each node in the directed graph corresponds to a monitoring index in the preprocessed training set, and each directed edge corresponds to a candidate causal edge that has been tested for significance and retained. Then, the initial node feature matrix corresponding to the directed graph and the preprocessed training set is input into the graph structure encoding module to obtain a node structure feature matrix with a dimension of N×32. Step (A6) is as follows: First, the node structure feature matrix is ​​input into the multi-head graph attention module in the ghost asset detection model to obtain the enhanced feature matrix. Then, the enhanced feature matrix is ​​input into two fully connected layers and a softmax classifier to obtain the ghost asset profile label probability matrix corresponding to each node. Subsequently, the cross-entropy loss function is calculated based on the ghost asset profile label probability matrix and the pre-labeled real label matrix in the training set. Then, based on the cross-entropy loss function, the gradient of all trainable network parameters of the graph structure encoding module and the ghost asset detection module is calculated using the backpropagation algorithm to obtain the gradient values ​​of each parameter. Subsequently, the Adam optimizer is used to update the network parameters based on the calculated gradient values. Finally, the above process is repeated until the cross-entropy loss function converges or reaches the preset maximum number of training rounds to obtain the trained ghost asset detection model. Step (A7) specifically involves the following steps: First, the test set is processed sequentially using the preprocessing steps (A2), the causal structure learning steps (A3), the causal edge saliency testing steps (A4), and the graph convolutional network encoding steps (A5) to obtain the node structure feature matrix corresponding to the test set. Then, this node structure feature matrix is ​​input into the pre-trained ghost asset detection model to obtain the ghost asset profile label probability matrix corresponding to each node in the test set. The ghost asset detection result is then generated through the result generation and output module. This ghost asset detection result includes a list of ghost asset nodes, profile categories, behavioral feature descriptions, and the scope of suspected influence. Finally, based on the ghost asset detection result and the pre-labeled real labels in the test set, the accuracy, precision, recall, and F1 score are calculated to obtain the final trained ghost asset detection model.

[0015] According to another aspect of the present invention, a ghost asset detection system based on causal inference and perturbation propagation is provided, comprising the following modules: The first module is used to acquire multiple raw operation and maintenance monitoring data generated during the operation of the power monitoring system, and to preprocess all raw operation and maintenance monitoring data to obtain a standardized multidimensional time series matrix. The rows in the standardized multidimensional time series matrix are the time steps corresponding to the raw operation and maintenance monitoring data, and the columns are the monitoring indicators corresponding to the raw operation and maintenance monitoring data. The second module is used to perform causal structure learning on the standardized multidimensional time series matrix obtained by the first module in order to obtain the initial causal adjacency moments. The third module is used to extract all elements with non-zero weight values ​​from the initial causal adjacency matrix obtained by the second module, set the node pair corresponding to each element as a candidate causal edge, perform a significance test on each candidate causal edge, and obtain the processed causal adjacency matrix based on the significance test results of all candidate causal edges. The fourth module is used to input the processed causal adjacency matrix obtained in the third module into the graph convolutional network for encoding in order to obtain the node structure feature matrix. The fifth module is used to input the node structure feature matrix obtained from the fourth module into the pre-trained ghost asset detection model to obtain ghost asset detection results.

[0016] In summary, compared with the prior art, the above-described technical solutions conceived by this invention can achieve the following beneficial effects: 1. Because the present invention adopts steps (2) and (3), it automatically constructs the perturbation propagation causal graph from a purely data-driven perspective through the temporal convolutional causal discovery model, and uses the permutation importance verification method to statistically verify the causal edges. Therefore, it does not need to rely on any static ledger, configuration list or prior topology knowledge. It only needs general operation and maintenance indicator data to discover the hidden dependencies in the system. Therefore, it can solve the technical problem that the existing comparison method based on static ledger and configuration scanning relies heavily on the integrity of the ledger and the scanning frequency, cannot discover ghost assets that are missing in the ledger, and cannot detect hidden behaviors that do not generate network traffic. 2. Due to the adoption of step (5), this invention innovatively introduces counterfactual reasoning into the field of operation and maintenance anomaly analysis. By constructing a structural equation model based on variational autoencoder to simulate the normal causal transmission mechanism, it can separate the normal part transmitted by known components and the abnormal part caused by unknown ghost assets from the observation data, and realize the accurate attribution and quantification of hidden factors. Therefore, it can solve the technical problems of existing single-index anomaly detection methods based on thresholds and rules that cannot distinguish whether the anomaly is caused by the failure of known components or by unknown ghost assets, lack the ability to locate the root cause, and have difficulty in discovering hidden assets with complex behavior and indirect impact. 3. Because the present invention adopts steps (4) and (6), it encodes the topological structure information of nodes through graph convolutional networks and fuses the node structure feature matrix and residual feature matrix through multi-head graph attention mechanism. It can fully consider the interaction relationship between ghost assets and their surrounding nodes, avoid analyzing individual nodes in isolation, and at the same time, the multi-category profile label system provides fine-grained descriptions of ghost asset behavior, providing operation and maintenance personnel with intuitive and understandable troubleshooting directions, forming a complete closed loop from data to decision. Therefore, it can solve the technical problem that the existing fault location method based on correlation analysis and topological dependency requires prior knowledge of the complete dependency topology between components and cannot be applied to ghost asset scenarios with unknown dependency relationships or hidden interactions. Attached Figure Description

[0017] Figure 1 This is a flowchart of the ghost asset detection method based on causal inference and disturbance propagation of the present invention; Figure 2 This is a schematic diagram of the ghost asset detection model used in the method of this invention. Detailed Implementation

[0018] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention. Furthermore, the technical features involved in the various embodiments of this invention described below can be combined with each other as long as they do not conflict with each other.

[0019] It should be noted that in the description of the embodiments of the present invention, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element. The terms "upper," "lower," etc., indicating orientation or positional relationships based on the orientation or positional relationships shown in the accompanying drawings, are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present invention. Those skilled in the art can understand the specific meaning of the above terms in the present invention according to the specific circumstances.

[0020] Furthermore, the technical solutions of the various embodiments of the present invention can be combined with each other, but only if they are feasible for those skilled in the art. If the combination of technical solutions is contradictory or cannot be implemented, it should be considered that such combination of technical solutions does not exist and is not within the scope of protection claimed by the present invention.

[0021] The core idea of ​​this invention is to provide a ghost asset detection method based on causal inference and perturbation propagation. It employs a collaborative strategy of "causal discovery + counterfactual attribution + ghost asset profiling" to achieve comprehensive coverage of ghost assets from causal discovery to precise location and behavioral characterization. Its core innovation lies in the ability of the temporal convolutional causal discovery model to indirectly discover hidden confounding factors; hidden assets leave traces in the causal structure as unobserved confounding factors. This invention automatically constructs a perturbation propagation causal graph from the system's time-series monitoring data, then locates logical discontinuities through causal path analysis, and finally uses counterfactual inference to depict ghost asset profiles. The entire process does not rely on any ledgers or topological prior knowledge, requiring only general operational indicator data.

[0022] like Figure 1 As shown, this invention provides a ghost asset detection method based on causal inference and perturbation propagation, comprising the following steps: (1) Obtain multiple original operation and maintenance monitoring data generated during the operation of the power monitoring system, preprocess all original operation and maintenance monitoring data to obtain a standardized multidimensional time series matrix. The rows in the standardized multidimensional time series matrix are the time steps corresponding to the original operation and maintenance monitoring data, and the columns are the monitoring indicators corresponding to the original operation and maintenance monitoring data. Specifically, this step involves obtaining multiple raw operation and maintenance monitoring data generated during the operation of the power monitoring system from various nodes and middleware of the power monitoring system, including CPU utilization, memory utilization, network latency, query rate per second of each microservice, and disk input / output. The preprocessing in this step is as follows: First, all original operation and maintenance monitoring data are cleaned, i.e., outliers are removed and missing values ​​are filled in to obtain multiple cleaned operation and maintenance monitoring data. Then, all cleaned operation and maintenance monitoring data are resampled and aligned at a uniform sampling interval (1 second in this invention) to ensure that all cleaned operation and maintenance monitoring data remain synchronized in the time dimension, so as to obtain multiple time-series aligned operation and maintenance monitoring data. Finally, all time-series aligned operation and maintenance monitoring data are organized into a standardized multi-dimensional time series matrix, where the rows are the time steps corresponding to the original operation and maintenance monitoring data, and the columns are the monitoring indicators corresponding to the original operation and maintenance monitoring data.

[0023] Specifically, the monitoring metrics corresponding to the operation and maintenance monitoring data include CPU utilization, memory utilization, network latency, queries per second for each microservice, and disk input / output.

[0024] (2) Perform causal structure learning on the standardized multidimensional time series matrix obtained in step (1) to obtain the initial causal adjacency matrix (which contains all potential perturbation propagation paths). This step (2) includes the following sub-steps: (2-1) The standardized multidimensional time series matrix obtained in step (1) is subjected to temporal feature extraction and variable interaction encoding by using an extended convolutional neural network to obtain multiple monitoring indicators corresponding to the standardized multidimensional time series matrix as multiple nodes, and high-dimensional feature tensors between node pairs formed by the i-th node and the j-th node, where i≠j, and i and j are both ∈[1, the total number of nodes corresponding to the standardized multidimensional time series matrix is ​​N].

[0025] Specifically, the dilated convolutional neural network consists of three convolutional layers with dilation rates of 1, 2, and 4, a kernel size of 3, and 32 channels. (2-2) The high-dimensional feature tensor between each node pair obtained in step (2-1) is mapped to a scalar through the attention mechanism, which serves as the causal effect weight of the node pair; (2-3) Obtain all node pairs whose causal effect weights exceed the preset threshold θ from all the causal effect weights obtained in step (2-2), and construct an initial causal adjacency matrix based on all the obtained node pairs (the rows of the initial causal adjacency matrix are source nodes and the columns are target nodes); the preset threshold θ ranges from 0.5 to 0.95, preferably 0.75.

[0026] The advantage of this step (2) is that it uses the multi-scale receptive field of dilated convolution to capture the interaction of variables under different time delays, and combines the attention mechanism to realize the automatic measurement and interpretable screening of causal effects without the need to pre-set the causal structure prior.

[0027] (3) Extract all elements with non-zero weight values ​​from the initial causal adjacency matrix obtained in step (2), set the node pairs corresponding to each element as candidate causal edges, perform a significance test on each candidate causal edge, and obtain the processed causal adjacency matrix based on the significance test results of all candidate causal edges. Step (3) includes the following sub-steps: (3-1) Extract all elements with non-zero weight values ​​in the initial causal adjacency matrix obtained in step (2), and take the node pair (u,v) corresponding to each element in the initial causal adjacency matrix as a candidate causal edge. Construct a time series prediction model based on Long Short-Term Memory (LSTM) network for the candidate causal edge (the model contains 2 layers of long short-term memory hidden layers, each layer has 64 hidden units). Input the data of the corresponding column of node u in the node pair (u,v) in the standardized multidimensional time series matrix obtained in step (1) into the time series prediction model corresponding to node u. Obtain the true value of node u at the next time step from the standardized multidimensional time series matrix, and use the trained LSTM model to obtain the predicted value of node u at the next time step. Node u and node v represent the u-th monitoring index and the v-th monitoring index in the standardized multidimensional time series matrix obtained in step (1), respectively. u and v ∈ [1, the total number of nodes corresponding to the element]; (3-2) Calculate the error between the predicted value and the true value of node u obtained in step (3-1) at the next time step as the baseline prediction error; randomly shuffle the position of the uth monitoring index in the standardized multidimensional time series matrix obtained in step (1), and input the feature column of the shuffled node u in the standardized multidimensional time series matrix obtained in step (1) back into the LSTM model corresponding to node u to obtain a new prediction value, and calculate the error between the new prediction value and the true value as the perturbation prediction error; (3-3) Determine whether the difference between the perturbation prediction error obtained in step (3-2) and the baseline prediction error is greater than the preset threshold λ (its value range is 0.01 to 0.5, preferably 0.05). If so, it means that the candidate causal edge corresponding to the node pair (u,v) truly exists (i.e., it has passed the significance test), and retain the candidate causal edge, then proceed to step (3-4). Otherwise, delete the candidate causal edge and set its corresponding element in the initial causal adjacency matrix to 0; (3-4) For all remaining elements in the initial causal adjacency matrix with non-zero weight values, repeat the above steps (3-3) until all candidate causal edges corresponding to them have been processed, thus obtaining the processed initial causal adjacency matrix. The advantage of this step (3) is that it introduces the idea of ​​counterfactual comparison, constructs perturbation samples by randomly shuffling the time sequence of the target variables, and uses the change of LSTM prediction error as the criterion for causal significance, effectively eliminating pseudo-causal edges.

[0028] (4) Input the processed causal adjacency matrix obtained in step (3) into the graph convolutional network for encoding to obtain the node structure feature matrix; Step (4) includes the following sub-steps: (4-1) Establish a directed graph based on the processed causal adjacency matrix obtained in step (3). Each node in the directed graph corresponds to the monitoring index in the standardized multidimensional time series matrix in step (1), and each directed edge corresponds to the candidate causal edge that has been tested for significance and retained in step (3).

[0029] (4-2) For each node in the directed graph obtained in step (4-1), the windowed time series feature with dimension N×16 obtained by slicing the standardized multidimensional time series matrix obtained in step (1) through a sliding window (window size is 16, step size is 1) (where N is the total number of monitoring indicators in the standardized multidimensional time series matrix obtained in step (1), i.e. the total number of nodes in the directed graph obtained in step (4-1)) is used as the initial feature vector corresponding to the node, and an initial node feature matrix with dimension N×N is constructed based on the initial feature vectors corresponding to all nodes. (4-3) Input the directed graph obtained in step (4-1) and the initial node feature matrix obtained in step (4-2) into the graph convolutional network for encoding (the graph convolutional network contains two graph convolutional layers, the first layer has 16 input channels and 64 output channels, and the second layer has 64 input channels and 32 output channels) to obtain a node structure feature matrix with dimension N×32; (5) Input the node structure feature matrix obtained in step (4) into the pre-trained ghost asset detection model to obtain ghost asset detection results; Step (5) includes the following sub-steps: (5-1) Input the node structure feature matrix obtained in step (4) into the multi-head graph attention module in the pre-trained ghost asset detection model (by calculating the attention coefficient between each node and its neighbors, the features of the neighboring nodes are weighted and aggregated) to obtain the enhanced feature matrix; (5-2) Input the enhanced feature matrix obtained in step (5-1) into the two fully connected network and softmax classifier in the ghost asset detection model to obtain the ghost asset profile label probability matrix corresponding to each node; (5-3) Set the index position of each node with a probability value greater than the confidence threshold μ in the image tag probability matrix obtained in step (5-2) to 1, and set the index position of each node with a probability value less than or equal to the confidence threshold μ to 0, so as to obtain the ghost asset node indicator vector, and set all nodes with a value of 1 in the ghost asset node indicator vector as target nodes. (5-4) Obtain the corresponding column data of each target node obtained in step (5-3) in the standardized multidimensional time series matrix obtained in step (1), and concatenate it with the position of the maximum probability value of each node in the ghost asset profile label probability matrix obtained in step (5-2) to generate a structured ghost asset description text as the description information of the target node. (5-5) Summarize the description information of all target nodes obtained in step (5-4) to generate ghost asset detection results (which include a list of ghost asset nodes, profile categories, behavioral feature descriptions, and suspicious influence range).

[0030] The advantages of the above steps (1) to (5) are: an end-to-end detection framework of "causal discovery + interpretable output" is constructed. First, a perturbation propagation topology with high confidence is obtained through causal structure learning and significance testing. Then, the temporal and structural information is fused through graph convolution and multi-head attention for intelligent discrimination. Finally, a structured description containing portrait category and behavioral features is output, realizing the automation, accuracy and interpretability of ghost asset detection.

[0031] like Figure 2 As shown, the specific structure of the ghost asset detection model of this invention is as follows: The first layer is the data preprocessing and feature extraction module. Its input is an initial multidimensional time series matrix of dimension T×N composed of multiple original operation and maintenance monitoring data. This layer first normalizes the initial multidimensional time series matrix, mapping the numerical range of each column of monitoring indicators to the interval [0, 1] to obtain a normalized multidimensional time series matrix. Then, a sliding window mechanism is used to slice the normalized multidimensional time series matrix to obtain an initial node feature matrix of dimension N×16 composed of the initial time series feature vectors of all nodes in the normalized multidimensional time series matrix and output it. Here, T represents the time step, that is, the total number of observation times, and N represents the total number of observation variables, that is, the number of monitoring indicators.

[0032] The second layer is the causal structure learning module. Its input is the initial node feature matrix with a dimension of N×16 output from the first layer. This layer first uses an extended convolutional neural network to extract temporal features and encode the interaction between variables in the initial node feature matrix to obtain multiple monitoring indicators as multiple nodes, and a high-dimensional feature tensor between the node pairs formed by the i-th node and the j-th node. Then, through an attention mechanism, the high-dimensional feature tensor between each node pair is mapped to a scalar as the causal effect weight of the node pair. Finally, all node pairs whose causal effect weights exceed a preset threshold θ are obtained from all the obtained causal effect weights, and an initial causal adjacency matrix with a dimension of N×N is constructed and output based on all the obtained node pairs. The rows of the initial causal adjacency matrix are source nodes, and the columns are target nodes, where i≠j, and i and j are both ∈ [1, N].

[0033] The third layer is the causal edge saliency testing module. Its inputs are the initial causal adjacency matrix (N×N) output from the second layer and the initial node feature matrix (N×16) output from the first layer. This layer first extracts all elements with non-zero weight values ​​from the initial causal adjacency matrix. The node pair (u, v) corresponding to each element in the initial causal adjacency matrix is ​​then used as a candidate causal edge. A time-series prediction model based on a Long Short-Term Memory (LSTM) network is constructed for this candidate causal edge. This LSM model contains two hidden layers, each with 64 hidden units. The data of node u in the node pair (u, v) corresponding to the column in the initial node feature matrix is ​​input into the corresponding LSM model to obtain the predicted value of node u at the next time step. Finally, the predicted value of node u at the next time step is obtained from the initial node feature matrix. The system first calculates the error between the predicted value and the true value to obtain the baseline prediction error. Then, it randomly shuffles the time order of the corresponding columns of node u in the initial node feature matrix and re-inputs the shuffled data into the long short-term memory network model corresponding to node u to obtain a new prediction value. The system then calculates the error between the new prediction value and the true value to obtain the perturbation prediction error. Subsequently, it determines whether the difference between the perturbation prediction error and the baseline prediction error is greater than a preset threshold λ. If so, it determines that the candidate causal edge truly exists and retains the candidate causal edge; otherwise, it deletes the candidate causal edge and sets the corresponding element value in the initial causal adjacency matrix to 0. Finally, the above processing is performed on all remaining elements in the initial causal adjacency matrix with non-zero weight values ​​to obtain the processed causal adjacency matrix and output it.

[0034] The fourth layer is a graph structure encoding module. Its input is the processed causal adjacency matrix with a dimension of N×N output from the third layer and the initial node feature matrix with a dimension of N×16 output from the first layer. This layer first constructs a directed graph based on the processed causal adjacency matrix. Each node in the directed graph corresponds to a monitoring index in the standardized multidimensional time series matrix, and each directed edge corresponds to a candidate causal edge that has been tested for saliency and retained. Then, the directed graph and the initial node feature matrix are input into a graph convolutional network for encoding to obtain a node structure feature matrix with a dimension of N×32 and output it.

[0035] The fifth layer is the ghost asset detection module. Its input is the node structure feature matrix with a dimension of N×32 output from the fourth layer. This layer first inputs the node structure feature matrix into the multi-head graph attention module to obtain the enhanced feature matrix. Then, the enhanced feature matrix is ​​input into two fully connected network layers and a softmax classifier to obtain the ghost asset profile label probability matrix corresponding to each node and output it.

[0036] Layer 6 is the result generation and output module. Its input is the N×C ghost asset profile label probability matrix output from Layer 5. This layer first sets the index position of each node in the profile label probability matrix whose probability value is greater than the confidence threshold μ to 1, and sets the index position of each node whose probability value is less than or equal to the confidence threshold μ to 0, to obtain the ghost asset node indicator vector. All nodes with a value of 1 in the ghost asset node indicator vector are taken as target nodes, and the column data corresponding to each target node in the standardized multidimensional time series matrix obtained in Layer 1 is obtained. Then, the column data corresponding to each target node in the standardized multidimensional time series matrix is ​​concatenated with the position of the maximum probability of each node in the ghost asset profile label probability matrix output from Layer 5 to generate a structured ghost asset description text as the description information of the target node. Finally, the description information of all target nodes is summarized to generate the ghost asset detection result (which includes a list of ghost asset nodes, profile category, behavioral feature description, and suspicious influence range).

[0037] The ghost asset detection model of this invention is trained through the following steps: (A1) Obtain a multi-source heterogeneous dataset from the power monitoring system network environment, and divide the multi-source heterogeneous dataset into a training set and a test set in an 8:2 ratio; Specifically, the multi-source heterogeneous dataset contains operation and maintenance monitoring data from multiple dimensions, such as CPU utilization, memory utilization, network latency, query rate per second of each microservice, and disk input / output, which are used to record the values ​​of observed variables and their changes over time.

[0038] (A2) Perform data preprocessing on the training set obtained in step (A1) to obtain the preprocessed training set.

[0039] Specifically, this step involves the following steps: First, the training set obtained in step (A1) is cleaned (i.e., outliers are removed and missing values ​​are filled in); then, the cleaned training set is resampled and aligned at a uniform time frequency (1 second in this invention); subsequently, the aligned training set is constructed into a multidimensional time series matrix; finally, the multidimensional time series matrix is ​​normalized using the data preprocessing and feature extraction module (i.e., the numerical range in the multidimensional time series matrix is ​​uniformly mapped to the [0, 1] interval), and the normalized multidimensional time series matrix is ​​sliced ​​using a sliding window mechanism (window size is 16, step size is 1) to obtain an initial node feature matrix of dimension N×16 as the preprocessed training set.

[0040] (A3) Input the preprocessed training set obtained in step (A2) into the causal structure learning module to obtain the initial causal adjacency matrix.

[0041] Specifically, this step involves the following steps: First, the dilated convolutional neural network in the causal structure learning module is used to extract temporal features and encode interactions between variables on the preprocessed training set. This yields multiple monitoring indicators corresponding to the preprocessed training set as multiple nodes, and a high-dimensional feature tensor between node pairs consisting of the i-th node and the j-th node, where i ≠ j and i and j are both ∈ [1, N]. Then, an attention mechanism is used to map the high-dimensional feature tensor between each node pair to a scalar, which serves as the causal effect weight for that node pair. Finally, all node pairs whose causal effect weights exceed a preset threshold θ are obtained from all the obtained causal effect weights, and an initial causal adjacency matrix is ​​constructed based on all the obtained node pairs. The rows of this initial causal adjacency matrix are source nodes, and the columns are target nodes.

[0042] (A4) Perform a causal edge significance test on the initial causal adjacency matrix obtained in step (A3) to obtain the processed causal adjacency matrix.

[0043] Specifically, this step involves: First, based on the causal edge saliency test module, extracting all elements with non-zero weight values ​​from the initial causal adjacency matrix. The node pair (u, v) corresponding to each element in the initial causal adjacency matrix is ​​then used as a candidate causal edge. A time-series prediction model based on a Long Short-Term Memory (LSTM) network is constructed for this candidate causal edge. The data of the corresponding column of node u in the preprocessed training set from the node pair (u, v) is input into the LSM network model to obtain the predicted value of node u at the next time step. The error between this predicted value and the true value is then calculated as the baseline prediction error. Next, the values ​​of node u in the preprocessed training set are randomly shuffled. The time order of the corresponding columns in the processed training set is shuffled and then input back into the Long Short-Term Memory network model to obtain new predicted values. The error between the new predicted value and the true value is calculated as the perturbation prediction error. Then, it is determined whether the difference between the perturbation prediction error and the baseline prediction error is greater than a preset threshold λ. If it is, the candidate causal edge is retained; otherwise, the candidate causal edge is deleted and its corresponding element value in the initial causal adjacency matrix is ​​set to 0. Finally, the above processing is performed on all remaining elements in the initial causal adjacency matrix with non-zero weight values ​​to obtain the processed causal adjacency matrix.

[0044] (A5) Input the processed causal adjacency matrix obtained in step (A4) into the graph convolutional network for encoding to obtain the node structure feature matrix.

[0045] Specifically, this step involves first establishing a directed graph based on the processed causal adjacency matrix. Each node in this directed graph corresponds to a monitoring metric in the preprocessed training set, and each directed edge corresponds to a candidate causal edge that has undergone saliency testing and been retained. Then, the initial node feature matrix corresponding to this directed graph and the preprocessed training set is input into the graph structure encoding module (i.e., a graph convolutional network, which contains two graph convolutional layers: the first layer has 16 input channels and 64 output channels, and the second layer has 64 input channels and 32 output channels) to obtain a node structure feature matrix with a dimension of N×32.

[0046] (A6) Input the node structure feature matrix obtained in step (A5) into the ghost asset detection model to obtain the cross-entropy loss function. Based on the cross-entropy loss function, update the network parameters of the ghost asset detection model using the backpropagation algorithm to obtain the initially trained ghost asset detection model.

[0047] Specifically, this step involves the following steps: First, the node structure feature matrix is ​​input into the multi-head graph attention module of the ghost asset detection model to obtain an enhanced feature matrix. Then, the enhanced feature matrix is ​​input into two fully connected layers and a softmax classifier to obtain the ghost asset profile label probability matrix for each node. Subsequently, the cross-entropy loss function is calculated based on the ghost asset profile label probability matrix and the pre-labeled real label matrix in the training set. Then, based on the cross-entropy loss function, the gradient of all trainable network parameters of the graph structure encoding module and the ghost asset detection module is calculated using the backpropagation algorithm to obtain the gradient values ​​of each parameter. Subsequently, the Adam optimizer is used to update the network parameters based on the calculated gradient values. Finally, the above process is repeated until the cross-entropy loss function converges or reaches the preset maximum number of training rounds (200 rounds in this invention) to obtain the trained ghost asset detection model.

[0048] (A7) Use the test set obtained in step (A1) to test the ghost asset detection model that has been initially trained in step (A6) until the detection accuracy reaches the optimal level, so as to obtain the final trained ghost asset detection model.

[0049] Specifically, this step involves first performing the preprocessing process in step (A2), the causal structure learning process in step (A3), the causal edge saliency test process in step (A4), and the graph convolutional network encoding process in step (A5) on the test set sequentially to obtain the node structure feature matrix corresponding to the test set. Then, this node structure feature matrix is ​​input into the pre-trained ghost asset detection model to obtain the ghost asset profile label probability matrix corresponding to each node in the test set. The ghost asset detection result is then generated through the result generation and output module, which includes a list of ghost asset nodes, profile category, behavioral feature description, and suspicious influence range. Finally, based on the ghost asset detection result and the pre-labeled real labels in the test set, the accuracy, precision, recall, and F1 score are calculated to obtain the final trained ghost asset detection model.

[0050] Those skilled in the art will readily understand that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for detecting ghost assets based on causal inference and perturbation propagation, characterized in that, Includes the following steps: (1) Obtain multiple original operation and maintenance monitoring data generated during the operation of the power monitoring system, preprocess all original operation and maintenance monitoring data to obtain a standardized multidimensional time series matrix. The rows in the standardized multidimensional time series matrix are the time steps corresponding to the original operation and maintenance monitoring data, and the columns are the monitoring indicators corresponding to the original operation and maintenance monitoring data. (2) Perform causal structure learning on the standardized multidimensional time series matrix obtained in step (1) to obtain the initial causal adjacency matrix; (3) Extract all elements with non-zero weight values ​​from the initial causal adjacency matrix obtained in step (2), set the node pairs corresponding to each element as candidate causal edges, perform a significance test on each candidate causal edge, and obtain the processed causal adjacency matrix based on the significance test results of all candidate causal edges. (4) Input the processed causal adjacency matrix obtained in step (3) into the graph convolutional network for encoding to obtain the node structure feature matrix; (5) Input the node structure feature matrix obtained in step (4) into the pre-trained ghost asset detection model to obtain the ghost asset detection results.

2. The ghost asset detection method based on causal inference and perturbation propagation according to claim 1, characterized in that, Step (1) is to obtain multiple raw operation and maintenance monitoring data generated during the operation of the power monitoring system from various nodes and middleware of the power monitoring system, including CPU utilization, memory utilization, network latency, query rate per second of each microservice, and disk input and output. The preprocessing process in step (1) is as follows: First, all original operation and maintenance monitoring data are cleaned, that is, outliers are removed and missing values ​​are filled in to obtain multiple cleaned operation and maintenance monitoring data; then, all cleaned operation and maintenance monitoring data are resampled and aligned according to a uniform sampling interval to obtain multiple time-series aligned operation and maintenance monitoring data; finally, all time-series aligned operation and maintenance monitoring data are organized into a standardized multi-dimensional time series matrix, where the rows are the time steps corresponding to the original operation and maintenance monitoring data and the columns are the monitoring indicators corresponding to the original operation and maintenance monitoring data. The monitoring metrics corresponding to the operation and maintenance monitoring data include CPU utilization, memory utilization, network latency, queries per second for each microservice, and disk input / output.

3. The ghost asset detection method based on causal inference and perturbation propagation according to claim 1 or 2, characterized in that, Step (2) includes the following sub-steps: (2-1) Use dilated convolutional neural networks to extract time series features and encode the interaction between variables of the standardized multidimensional time series matrix obtained in step (1) so as to obtain multiple monitoring indicators corresponding to the standardized multidimensional time series matrix as multiple nodes, and the high-dimensional feature tensor between the node pair formed by the i-th node and the j-th node, where i≠j, and i and j are both ∈[1, the total number of nodes corresponding to the standardized multidimensional time series matrix N]; (2-2) The high-dimensional feature tensor between each node pair obtained in step (2-1) is mapped to a scalar through the attention mechanism, which serves as the causal effect weight of the node pair; (2-3) Obtain all node pairs whose causal effect weights exceed the preset threshold θ from all the causal effect weights obtained in step (2-2), and construct an initial causal adjacency matrix based on all the obtained node pairs; where the rows of the initial causal adjacency matrix are source nodes and the columns are target nodes.

4. The ghost asset detection method based on causal inference and disturbance propagation according to any one of claims 1 to 3, characterized in that, Step (3) includes the following sub-steps: (3-1) Extract all elements with non-zero weight values ​​in the initial causal adjacency matrix obtained in step (2), and take the node pair (u,v) corresponding to each element in the initial causal adjacency matrix as a candidate causal edge. Construct a time series prediction model based on the Long Short-Term Memory Network (LSTM) for the candidate causal edge. Input the data of the corresponding column of node u in the node pair (u,v) in the standardized multidimensional time series matrix obtained in step (1) into the time series prediction model corresponding to node u. Obtain the true value of node u at the next time step from the standardized multidimensional time series matrix, and use the trained LSTM model to obtain the predicted value of node u at the next time step. Node u and node v represent the u-th monitoring index and the v-th monitoring index in the standardized multidimensional time series matrix obtained in step (1), respectively. u and v ∈ [1, the total number of nodes corresponding to the element]; (3-2) Calculate the error between the predicted value and the true value of node u obtained in step (3-1) at the next time step as the baseline prediction error; randomly shuffle the position of the uth monitoring index in the standardized multidimensional time series matrix obtained in step (1), and input the feature column of the shuffled node u in the standardized multidimensional time series matrix obtained in step (1) back into the LSTM model corresponding to node u to obtain a new prediction value, and calculate the error between the new prediction value and the true value as the perturbation prediction error; (3-3) Determine whether the difference between the perturbation prediction error obtained in step (3-2) and the baseline prediction error is greater than the preset threshold λ. If so, it means that the candidate causal edge corresponding to the node pair (u,v) really exists, and the candidate causal edge is retained. Then proceed to step (3-4); otherwise, delete the candidate causal edge and set its corresponding element in the initial causal adjacency matrix to 0. (3-4) For all remaining elements in the initial causal adjacency matrix with non-zero weight values, repeat the above steps (3-3) until all candidate causal edges corresponding to them have been processed, thus obtaining the processed initial causal adjacency matrix.

5. The ghost asset detection method based on causal inference and perturbation propagation according to claim 4, characterized in that, Step (4) includes the following sub-steps: (4-1) Based on the processed causal adjacency matrix obtained in step (3), a directed graph is constructed. Each node in the directed graph corresponds to the monitoring index in the standardized multidimensional time series matrix in step (1), and each directed edge corresponds to the candidate causal edge that has been tested for significance and retained in step (3). (4-2) For each node in the directed graph obtained in step (4-1), the windowed time series feature with dimension N×16 obtained by slicing the standardized multidimensional time series matrix obtained in step (1) through a sliding window is used as the initial feature vector corresponding to the node. An initial node feature matrix with dimension N×N is constructed based on the initial feature vectors corresponding to all nodes, where N represents the total number of monitoring indicators in the standardized multidimensional time series matrix obtained in step (1), that is, the total number of nodes in the directed graph obtained in step (4-1). (4-3) Input the directed graph obtained in step (4-1) and the initial node feature matrix obtained in step (4-2) into the graph convolutional network for encoding to obtain a node structure feature matrix with dimension N×32; wherein the graph convolutional network contains two graph convolutional layers, the first layer has 16 input channels and 64 output channels, and the second layer has 64 input channels and 32 output channels.

6. The ghost asset detection method based on causal inference and perturbation propagation according to claim 5, characterized in that, Step (5) includes the following sub-steps: (5-1) Input the node structure feature matrix obtained in step (4) into the multi-head graph attention module in the pre-trained ghost asset detection model to obtain the enhanced feature matrix; (5-2) Input the enhanced feature matrix obtained in step (5-1) into the two fully connected network and softmax classifier in the ghost asset detection model to obtain the ghost asset profile label probability matrix corresponding to each node; (5-3) Set the index position of each node with a probability value greater than the confidence threshold μ in the image tag probability matrix obtained in step (5-2) to 1, and set the index position of each node with a probability value less than or equal to the confidence threshold μ to 0, so as to obtain the ghost asset node indicator vector, and set all nodes with a value of 1 in the ghost asset node indicator vector as target nodes. (5-4) Obtain the corresponding column data of each target node obtained in step (5-3) in the standardized multidimensional time series matrix obtained in step (1), and concatenate it with the position of the maximum probability value of each node in the ghost asset profile label probability matrix obtained in step (5-2) to generate a structured ghost asset description text as the description information of the target node. (5-5) Summarize the description information of all target nodes obtained in step (5-4) to generate ghost asset detection results, which include a list of ghost asset nodes, profile categories, behavioral feature descriptions, and suspected influence range.

7. The ghost asset detection method based on causal inference and perturbation propagation according to claim 6, characterized in that, The specific structure of the ghost asset detection model is as follows: The first layer is the data preprocessing and feature extraction module. Its input is an initial multidimensional time series matrix of dimension T×N composed of multiple original operation and maintenance monitoring data. This layer first normalizes the initial multidimensional time series matrix, mapping the numerical range of each column of monitoring indicators to the interval [0, 1] to obtain a normalized multidimensional time series matrix. Then, a sliding window mechanism is used to slice the normalized multidimensional time series matrix to obtain an initial node feature matrix of dimension N×16 composed of the initial time series feature vectors of all nodes in the normalized multidimensional time series matrix and output it. Here, T represents the time step, i.e. the total number of observation times, and N represents the total number of observation variables, i.e. the number of monitoring indicators. The second layer is the causal structure learning module. Its input is the initial node feature matrix with a dimension of N×16 output from the first layer. This layer first uses an extended convolutional neural network to extract temporal features and encode the interaction between variables on the initial node feature matrix to obtain multiple monitoring indicators as multiple nodes, and a high-dimensional feature tensor between the node pair formed by the i-th node and the j-th node. Then, the high-dimensional feature tensor between each node pair is mapped to a scalar through the attention mechanism, which serves as the causal effect weight of the node pair. Finally, all node pairs whose causal effect weights exceed a preset threshold θ are obtained from all the obtained causal effect weights, and an initial causal adjacency matrix of dimension N×N is constructed and output based on all the obtained node pairs. The rows of the initial causal adjacency matrix are source nodes, and the columns are target nodes, where i≠j, and i and j are both ∈[1, N]. The third layer is the causal edge saliency testing module. Its inputs are the initial causal adjacency matrix of dimension N×N output from the second layer and the initial node feature matrix of dimension N×16 output from the first layer. This layer first extracts all elements with non-zero weight values ​​from the initial causal adjacency matrix. The node pair (u, v) corresponding to each element in the initial causal adjacency matrix is ​​then used as a candidate causal edge. A time-series prediction model based on a Long Short-Term Memory (LSTM) network is constructed for this candidate causal edge. This LSM network model contains two hidden layers, each with 64 hidden units. The node u in the node pair (u, v) is then used as a candidate causal edge. The data in the corresponding column of the node feature matrix is ​​input into the long short-term memory network model corresponding to node u to obtain the predicted value of node u at the next time step. The actual value of node u at the next time step is obtained from the initial node feature matrix. The error between the predicted value and the actual value is calculated to obtain the baseline prediction error. Then, the time order of the corresponding column of node u in the initial node feature matrix is ​​randomly shuffled. The shuffled data is input into the long short-term memory network model corresponding to node u again to obtain a new prediction value. The error between the new prediction value and the actual value is calculated to obtain the perturbation prediction error. Subsequently, it is determined whether the difference between the perturbation prediction error and the baseline prediction error is greater than the preset threshold λ. If so, the candidate causal edge is determined to exist and is retained. Otherwise, the candidate causal edge is deleted and its corresponding element value in the initial causal adjacency matrix is ​​set to 0. Finally, the above processing is performed on all remaining elements in the initial causal adjacency matrix with non-zero weight values ​​to obtain the processed causal adjacency matrix and output it. The fourth layer is a graph structure encoding module. Its input is the processed causal adjacency matrix of dimension N×N output from the third layer and the initial node feature matrix of dimension N×16 output from the first layer. This layer first constructs a directed graph based on the processed causal adjacency matrix. Each node in the directed graph corresponds to a monitoring index in the standardized multidimensional time series matrix, and each directed edge corresponds to a candidate causal edge that has been tested for saliency and retained. Then, the directed graph and the initial node feature matrix are input into a graph convolutional network for encoding to obtain a node structure feature matrix of dimension N×32 and output it. The fifth layer is the ghost asset detection module, which takes as input the node structure feature matrix with dimension N×32 output from the fourth layer. This layer first inputs the node structure feature matrix into the multi-head graph attention module to obtain the enhanced feature matrix. Then, the enhanced feature matrix is ​​input into two fully connected networks and a softmax classifier to obtain the probability matrix of ghost asset profile labels for each node and output it. The 6th layer is the result generation and output module. Its input is the ghost asset profile label probability matrix with dimension N×C output from the 5th layer. This layer first sets the index position corresponding to each node in the profile label probability matrix with a probability value greater than the confidence threshold μ to 1, and sets the index position corresponding to each node with a probability value less than or equal to the confidence threshold μ to 0, so as to obtain the ghost asset node indicator vector. Then, all nodes with a value of 1 in the ghost asset node indicator vector are taken as target nodes, and the column data corresponding to each target node in the standardized multidimensional time series matrix obtained in the 1st layer are obtained. Subsequently, the column data in the standardized multidimensional time series matrix of each target node is concatenated with the position of the maximum probability of each node in the ghost asset profile label probability matrix output by the 5th layer to generate a structured ghost asset description text as the description information of the target node. Finally, the description information of all target nodes is summarized to generate the ghost asset detection result, which includes a list of ghost asset nodes, profile category, behavioral feature description, and suspicious influence range.

8. The ghost asset detection method based on causal inference and perturbation propagation according to claim 7, characterized in that, The ghost asset detection model is trained through the following steps: (A1) Obtain a multi-source heterogeneous dataset from the power monitoring system network environment, and divide the multi-source heterogeneous dataset into a training set and a test set in an 8:2 ratio; (A2) Perform data preprocessing on the training set obtained in step (A1) to obtain the preprocessed training set; (A3) Input the preprocessed training set obtained in step (A2) into the causal structure learning module to obtain the initial causal adjacency matrix; (A4) Perform a causal edge significance test on the initial causal adjacency matrix obtained in step (A3) to obtain the processed causal adjacency matrix; (A5) Input the processed causal adjacency matrix obtained in step (A4) into the graph convolutional network for encoding to obtain the node structure feature matrix; (A6) Input the node structure feature matrix obtained in step (A5) into the ghost asset detection model to obtain the cross-entropy loss function. Based on the cross-entropy loss function, update the network parameters of the ghost asset detection model using the backpropagation algorithm to obtain the initially trained ghost asset detection model. (A7) Use the test set obtained in step (A1) to test the ghost asset detection model that has been initially trained in step (A6) until the detection accuracy reaches the optimal level, so as to obtain the final trained ghost asset detection model.

9. The ghost asset detection method based on causal inference and perturbation propagation according to claim 8, characterized in that, Step (A2) specifically involves first cleaning the training set obtained in step (A1); then resampling and aligning the cleaned training set at a uniform time frequency. Subsequently, the aligned training set is constructed into a multi-dimensional time series matrix. Finally, the multi-dimensional time series matrix is ​​normalized through the data preprocessing and feature extraction module, and the normalized multi-dimensional time series matrix is ​​sliced ​​through the sliding window mechanism to obtain an initial node feature matrix of dimension N×16 as the preprocessed training set. Step (A3) is as follows: First, the dilated convolutional neural network in the causal structure learning module is used to extract temporal features and encode the interaction between variables on the preprocessed training set, so as to obtain multiple monitoring indicators corresponding to the preprocessed training set as multiple nodes, and the high-dimensional feature tensor between the node pair formed by the i-th node and the j-th node, where i≠j, and i and j are both ∈[1, N]; Then, the high-dimensional feature tensor between each node pair is mapped to a scalar through an attention mechanism, which serves as the causal effect weight of the node pair. Finally, all node pairs whose causal effect weights exceed a preset threshold θ are obtained from all the obtained causal effect weights, and an initial causal adjacency matrix is ​​constructed based on all the obtained node pairs. The rows of the initial causal adjacency matrix are source nodes, and the columns are target nodes. Step (A4) is as follows: First, according to the causal edge saliency test module, extract all elements with non-zero weight values ​​in the initial causal adjacency matrix. Take the node pair (u, v) corresponding to each element in the initial causal adjacency matrix as a candidate causal edge. Construct a time series prediction model based on a long short-term memory network for the candidate causal edge. Input the data of the corresponding column of node u in the preprocessed training set into the long short-term memory network model to obtain the predicted value of node u at the next time step. Calculate the error between the predicted value and the true value as the baseline prediction error. Then, the time order of the corresponding column of node u in the preprocessed training set is randomly shuffled, and the shuffled data is input into the long short-term memory network model again to obtain a new prediction value. The error between the new prediction value and the true value is calculated as the perturbation prediction error. Subsequently, it is determined whether the difference between the perturbation prediction error and the baseline prediction error is greater than the preset threshold λ. If so, the candidate causal edge is retained; otherwise, the candidate causal edge is deleted and its corresponding element value in the initial causal adjacency matrix is ​​set to 0. Finally, the above processing is performed on all remaining elements in the initial causal adjacency matrix with non-zero weight values ​​to obtain the processed causal adjacency matrix. Step (A5) is as follows: First, a directed graph is established based on the processed causal adjacency matrix. Each node in the directed graph corresponds to a monitoring index in the preprocessed training set, and each directed edge corresponds to a candidate causal edge that has been tested for significance and retained. Then, the directed graph and the initial node feature matrix corresponding to the preprocessed training set are input into the graph structure encoding module to obtain a node structure feature matrix with dimension N×32. Step (A6) is as follows: First, the node structure feature matrix is ​​input into the multi-head graph attention module in the ghost asset detection model to obtain the enhanced feature matrix. Then, the enhanced feature matrix is ​​input into two fully connected layers and a softmax classifier to obtain the ghost asset profile label probability matrix corresponding to each node. Subsequently, the cross-entropy loss function is calculated based on the ghost asset profile label probability matrix and the pre-labeled real label matrix in the training set. Then, based on the cross-entropy loss function, the gradient of all trainable network parameters of the graph structure encoding module and the ghost asset detection module is calculated using the backpropagation algorithm to obtain the gradient values ​​of each parameter. Subsequently, the Adam optimizer is used to update the network parameters based on the calculated gradient values. Finally, the above process is repeated until the cross-entropy loss function converges or reaches the preset maximum number of training rounds to obtain the trained ghost asset detection model. Step (A7) specifically involves the following steps: First, the test set is processed sequentially using the preprocessing steps (A2), the causal structure learning steps (A3), the causal edge saliency testing steps (A4), and the graph convolutional network encoding steps (A5) to obtain the node structure feature matrix corresponding to the test set. Then, this node structure feature matrix is ​​input into the pre-trained ghost asset detection model to obtain the ghost asset profile label probability matrix corresponding to each node in the test set. The ghost asset detection result is then generated through the result generation and output module. This ghost asset detection result includes a list of ghost asset nodes, profile categories, behavioral feature descriptions, and the scope of suspected influence. Finally, based on the ghost asset detection result and the pre-labeled real labels in the test set, the accuracy, precision, recall, and F1 score are calculated to obtain the final trained ghost asset detection model.

10. A ghost asset detection system based on causal inference and perturbation propagation, characterized in that, Includes the following modules: The first module is used to acquire multiple raw operation and maintenance monitoring data generated during the operation of the power monitoring system, and to preprocess all raw operation and maintenance monitoring data to obtain a standardized multidimensional time series matrix. The rows in the standardized multidimensional time series matrix are the time steps corresponding to the raw operation and maintenance monitoring data, and the columns are the monitoring indicators corresponding to the raw operation and maintenance monitoring data. The second module is used to perform causal structure learning on the standardized multidimensional time series matrix obtained by the first module in order to obtain the initial causal adjacency moments. The third module is used to extract all elements with non-zero weight values ​​from the initial causal adjacency matrix obtained by the second module, set the node pair corresponding to each element as a candidate causal edge, perform a significance test on each candidate causal edge, and obtain the processed causal adjacency matrix based on the significance test results of all candidate causal edges. The fourth module is used to input the processed causal adjacency matrix obtained in the third module into the graph convolutional network for encoding in order to obtain the node structure feature matrix. The fifth module is used to input the node structure feature matrix obtained from the fourth module into the pre-trained ghost asset detection model to obtain ghost asset detection results.