Method and device for detecting anomalies and determining the corresponding explanation in temporal data series

DE602023006716T2Active Publication Date: 2025-09-17THALES SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE602023006716
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-07-08
Filing Date
2023-07-06
Publication Date
2025-09-17
Estimated Expiration
2043-07-06

AI Technical Summary

Technical Problem

Existing methods for anomaly detection in time series data, particularly in industrial equipment monitoring and cybersecurity, rely on artificial intelligence algorithms that operate as 'black boxes' and are not understandable by human operators, and current statistical tools fail to account for time series data effectively.

Method used

A method using descriptive vectors and machine learning-based anomaly detection, combined with explainable models like isolation forests and Shapley values, to identify anomalies and provide understandable explanations, enabling predictive maintenance and cybersecurity enhancements.

Benefits of technology

Enables human operators to understand anomaly sources and take appropriate actions by providing clear explanations, facilitating effective predictive maintenance and cybersecurity measures.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present invention relates to a method for detecting anomaly and determining an associated explanation in time series data, an associated device and an associated computer program.

[0002] The invention lies in the field of determining anomalies from data values, and of explaining these anomalies allowing the exploitation of the results by operators.

[0003] The invention finds particular applications in various technical fields, in particular in the detection and explanation of operating anomalies of any type of equipment with a view to the application of efficient maintenance or predictive maintenance.

[0004] In this case, time series of data are provided by sensors that take environmental or operating values ​​from industrial equipment at given time intervals.

[0005] Examples of monitored equipment include industrial machines driven by electric motors, GPU graphics processors in a processor farm, or equipment in a smart grid.

[0006] The invention also applies in the field of cybersecurity, to determine anomalies in requests for access to a computer system from the same IP address, making it possible to detect a cyber-attack.

[0007] In these various fields, very large volumes of data containing values ​​representative of the operation of the system or equipment observed are collected over time. This data, in its raw form, constitutes a very large volume of data, which cannot be used by a human operator to carry out anomaly detection and a preventive or maintenance intervention following such anomaly detection.

[0008] In recent years, various computational methods, particularly those based on the application of artificial intelligence, have been implemented to analyze large volumes of data in order to detect possible anomalies. However, artificial intelligence algorithms operate like a "black box," which is generally not understandable by human operators.

[0009] An additional difficulty arises in the processing of time series, the tools currently known being statistical tools which are not suitable for taking time series into account.

[0010] There is therefore a need to provide anomaly detection and associated explanations on time series of data, to enable adequate support, in particular predictive maintenance in the case of equipment operation monitoring.

[0011] WO 2022 / 093271 A1 describes a method for a system with multiple devices that provide sensor data that is unlabeled. The method includes (1) extracting features from the unlabeled sensor data, using these features to perform failure detection via a machine learning model, generating failure detection labels, and (2) providing both the extracted features and the failure detection labels to a failure prediction model to generate failure predictions and a feature sequence. The document mentions the use of explainable models (“model selection and explainable AI”,

[0034] ).

[0012] US 2021 / 390457 A1 relates to a method for interpreting machine learning models and assigning importance to certain features of the model (those that are prominent). This method can provide global information on the impact of features and local information on the explanations of the prediction. The method uses the calculation of Shapley values. SUMMARY

[0013] To this end, the invention proposes, according to one aspect, a method for detecting anomaly and determining an associated explanation in time series of data according to claim 1.

[0014] Advantageously, the proposed method for detecting an anomaly and determining the associated explanation is based on descriptive vectors of time series of data, and makes it possible to obtain a subset of anomalous time series and for each, one or more data values ​​of the time series having an influence on the score obtained.

[0015] The method for detecting an anomaly and determining the associated explanation according to the invention may also have one or more of the characteristics of dependent claims 2 to 5, taken independently or in any technically conceivable combination.

[0016] According to another aspect, the invention relates to a device for detecting anomaly and determining an associated explanation in time series of data according to claim 7, each time series having an associated duration and comprising a number N of operating values ​​of equipment or a system, recorded at regular intervals during said duration, the device comprising a calculation processor configured to implement: a module for projecting, for each time series, the values ​​of said time series onto a number M of basic functions and obtaining a descriptive vector of said time series of size M, a module for training a parameterized anomaly determination model, by machine learning on at least a portion of the calculated descriptive vectors, said anomaly determination model making it possible to calculate an anomaly score per descriptive vector, a module for applying the anomaly determination model to the descriptive vectors of the time series and obtaining an anomaly score per time series, a module for determining a subset of time series comprising an anomaly by comparing the anomaly score of each time series to a predetermined anomaly threshold;a module for determining, for each time series of said subset, from the descriptive vector of said time series, at least part of the values ​​of said descriptive vector having an influence in obtaining the anomaly score of said time series.;

[0017] According to another aspect, the invention relates to an information recording medium, on which are stored software instructions for the execution of a method of detecting an anomaly and determining an associated explanation as briefly described above, when these instructions are executed by a programmable electronic device.

[0018] According to another aspect, the invention relates to a computer program comprising software instructions which, when implemented by a programmable electronic device, implement a method of determining an anomaly and providing an associated explanation as briefly described above.

[0019] Other characteristics and advantages of the invention will emerge from the description given below, for information purposes only and in no way limiting, with reference to the appended figures, among which: there figure 1 illustrates a system for monitoring the operation of equipment implementing the invention according to a first embodiment; the figure 2 is a synopsis of the main steps of a first embodiment of a method for determining an anomaly and providing associated explanation; figure 3 is a synopsis of the main steps of a second embodiment of a method for determining an anomaly and providing associated explanation.

[0020] The invention will be described below in its application in the field of detecting operating anomalies of equipment from series of data which include values ​​taken by sensors.

[0021] It is understood that the invention is not limited to this application, and can also be applied, in a similar manner, for the detection of anomalies and the determination of associated explanations in time series representative of the operation of a system, for example network accesses or accesses to disks in a computer system.

[0022] There figure 1 schematically illustrates a system 2 for monitoring the operation of equipment 4 1 to 4 P, this equipment being, in an example application, electric motors of the same type and operating in parallel under similar conditions.

[0023] The number P is any integer, for example P=100.

[0024] The operating monitoring system 2 performs detection of operating anomalies, for example for predictive maintenance of equipment.

[0025] Each equipment 4 i is associated with sensors 6 i , 8 i , configured to measure operating data of the equipment 4 i at regular time intervals.

[0026] By way of non-limiting example, the sensors 6 i are temperature sensors, adapted to measure the temperature in or near each engine 4 i , and the sensors 8 i are piston speed sensors of each engine 4 i .

[0027] For example, each sensor provides a measurement value every minute, and values ​​are grouped into respective time series of temperature and piston speed, each time series being associated with a given time duration D, for example equal to 24 hours (24h), or in other words, one day.

[0028] In this example, each time series has N=1440 values, which are operating values ​​of the associated equipment.

[0029] Of course, the time duration D is chosen, and can be any, e.g. a few minutes, an hour, a few hours, several days etc.

[0030] Thus, for a piece of equipment 4 i of index i we obtain for time series: Temp k i = t k , 1 i , … , t k , N i Piston k i = p k , 1 i , … , p k , N i

[0031] Where k represents the 24-hour period considered.

[0032] For example, we obtain, for each device, several time series which follow one another in time, for example k=1 for a first period of 24 hours, k=2 for the following period of 24 hours and so on.

[0033] Of course, the number of sensors used is variable, for example between 1 and any number of sensors.

[0034] In the case where only one sensor is used per piece of equipment, only one time series is obtained per piece of equipment and per measurement period. In this case, the time series are said to be monovariate.

[0035] In the case where several sensors are used, several time series are obtained per device and per period. In this case, the time series are said to be multivariate.

[0036] The system 2 further comprises a device 14 for detecting an anomaly and determining an associated explanation, which is a programmable electronic device, for example a computer.

[0037] The device 14 comprises an electronic memory unit 16, at least one calculation processor 18 and an interface 20 for communication with remote devices, by a chosen communication protocol, for example a wired protocol and / or a radio communication protocol. The elements of the device 14 are adapted to communicate via a communication bus 15.

[0038] The sensors 6i, 8i are adapted to transmit the measurement data to the device 14, for example via a radio or wired communication link.

[0039] The respective time series Temp k i And Piston k i received are stored, in appropriate form 10 i,k , 12 i,k , in an electronic memory 16 of the device 14.

[0040] Each stored time series of index i comprises N values ​​representative of the operation of the equipment 4 i during a period of duration D.

[0041] The calculation processor 18 is configured to implement a projection module 22, configured to apply a projection of the values ​​of a time series onto a number M of basic functions in order to obtain a descriptive vector, of size M, of the time series. The number M is configurable, and is less than or equal to the number N of values ​​of a time series.

[0042] The processor 18 is further configured to implement a module 24 for training an algorithm, implementing a parameterized model, for determining anomaly by machine learning on at least a portion of the calculated descriptive vectors. The anomaly determination algorithm makes it possible to calculate an anomaly score per descriptive vector.

[0043] For example, module 24 implements the training of the parameters of an anomaly determination model called an isolation forest, known in the field of machine learning algorithms.

[0044] The training implemented is unsupervised, in other words it is carried out solely from the data collected without using examples previously labeled by experts.

[0045] Furthermore, the processor 18 implements a module 26 for applying the anomaly determination model, with the parameters determined by learning, to the descriptive vectors of the time series to calculate an anomaly score per time series. The anomaly score is a value representative of a presence of an anomaly in the processed data. In one embodiment, the higher the anomaly score for a given piece of equipment, the more the observed operation is considered to be abnormal.

[0046] The processor 18 also implements a module 28 for determining a subset of time series comprising an anomaly, implementing a comparison of the anomaly score of each time series with a predetermined anomaly threshold to determine a subset of time series comprising an anomaly, and a module 30 for determining, for each anomaly time series, from its descriptive vector, at least a portion of the values ​​of the descriptive vector having an influence in obtaining the anomaly score of said time series.

[0047] In particular, module 30 makes it possible to provide an explanation, more easily understood and usable by a human operator, of the source of the observed anomaly. This makes it possible in particular to carry out predictive maintenance, for example by determining a cause of malfunction of equipment which results in an observation of an anomaly in the data of the observed time series.

[0048] The module 30 implements, in one embodiment, an algorithm for calculating, for a given time series, a level of influence of each component of the descriptive vector and / or for calculating one or more alternative time series(s), the or each alternative time series being calculated from said given time series and respecting predetermined rules, the or each alternative time series having an anomaly score in the “normal” operating domain, in particular an anomaly score lower than the predetermined anomaly threshold. Such an alternative time series is also called a counterexample or counterfactual time series.

[0049] Several embodiments of the modules 22, 24, 26, 28 and 30 will be described below.

[0050] In one embodiment, the modules 22, 24, 26, 28 and 30 are implemented in the form of software instructions forming a computer program, which, when executed by a programmable electronic device, implements a method for detecting an anomaly and determining an associated explanation according to the invention.

[0051] In a variant not shown, the modules 22, 24, 26, 28 and 30 are each produced in the form of programmable logic components, such as FPGAs (from the English Field Programmable Gate Array), microprocessors, GPGPU components (from English General-purpose processing on graphics processing ), or even dedicated integrated circuits, such as ASICs (from the English Application Specific Integrated Circuit ).

[0052] The computer program comprising software instructions is further capable of being recorded on a non-transitory, computer-readable information recording medium. This computer-readable medium is, for example, a medium capable of storing electronic instructions and of being coupled to a bus of a computer system. For example, this medium is an optical disk, a magneto-optical disk, a ROM memory, a RAM memory, any type of non-volatile memory (for example EPROM, EEPROM, FLASH, NVRAM), a magnetic card or an optical card.

[0053] More detailed embodiments of modules 22, 24, 26, 28 and 30 will be described below.

[0054] The device 14 for detecting an anomaly and determining the associated explanation is further connected to a human-machine interface 32, making it possible to display data in a form that can be interpreted by an operator. For example, the human-machine interface 32 comprises a display screen.

[0055] The human-machine interface 32 is part of the device 14.

[0056] According to one variant, the human-machine interface is remote from the device 14.

[0057] In particular, this makes it possible to display data relating to anomalies in the monitored equipment, and explanations relating to the detected anomalies, in particular information obtained by the module 30. For example, the display of alternative time series makes it easier for an operator to understand which values ​​of the observed time series induce an anomaly score higher than the anomaly threshold, and consequently which maintenance actions are to be taken.

[0058] There figure 2 is a synopsis of the main steps of a first embodiment of the method for detecting an anomaly and determining the associated explanation.

[0059] In this first embodiment, the detection is applied to time series of stored data, in other words it is a detection of anomalies and a determination of associated explanation which is carried out a posteriori.

[0060] The results obtained relating to the detection of anomalies and their explanations are, for example, applicable for the calibration of equipment.

[0061] The method is applied in this embodiment to previously stored time series, for example on P observed equipment, over K successive observation time periods, each time series comprising N operating values ​​of one of the equipment over an observation time period.

[0062] As a non-limiting example, P=100, K=1 and the duration of a time period is 24 hours, a time series comprising values ​​taken every minute, N=1440.

[0063] Alternatively, the method also applies with time series comprising measured values ​​for a piece of equipment, over a number K, for example K=100, of successive time series.

[0064] As a non-limiting example, we consider that each piece of equipment is equipped with a temperature sensor, and the operating values ​​taken are temperature values.

[0065] In this first embodiment, the method comprises a step 40 of applying, for each of the stored time series, a projection onto a base of M chosen functions.

[0066] The number M is a parameter whose value indicates a projection depth.

[0067] Preferably, M is strictly less than N.

[0068] For example M is smaller than half of N.

[0069] For example, M is set to a predetermined value, for example between 5 and 10, and for example equal to 8, for any N greater than this predetermined value.

[0070] In one embodiment, the chosen function basis is a wavelet transform basis, for example the Haar wavelet basis, well known in the field of signal processing.

[0071] A subset of M functions of the Haar wavelet basis of size N is chosen to apply the projection, for example the first M functions of the basis. For example M=8.

[0072] Alternatively, the function basis used is a B-Splines function basis.

[0073] Let X be a time series of N values: ( x 1 , .... , x N ) and let H be a matrix formed of M basis functions forming a projection basis. The matrix H is of size MxN, M being the number of rows, N the number of columns.

[0074] The projection of X onto H is carried out by calculating the scalar product between H and X, and the result is a vector d, called the descriptive vector of the time series X, of size M.

[0075] In general: d = H ⋅ X

[0076] With d = [ d 1 , ... ,d M ], where each component di of the descriptive vector d is a descriptive variable of the associated time series X.

[0077] As a simplified numerical example, the matrix H is as follows, for example dimensions N=8 and M=5: H = 1 1 1 1 1 1 1 1 1 1 1 1 0 0 0 0 0 0 0 0 1 1 1 1 1 1 0 0 0 0 0 0 0 0 1 1 0 0 0 0

[0078] Projection step 40 is applied for each time series to obtain a descriptive vector of the time series.

[0079] The descriptive vectors obtained are temporarily stored in an electronic memory of the programmable electronic device implementing the method.

[0080] The method also comprises a step 42 of unsupervised learning of the parameters of an anomaly determination model, for the implementation of an anomaly determination algorithm, on at least part of the calculated descriptive vectors.

[0081] Preferably, all the descriptive vectors calculated in the projection step 40 are used.

[0082] Preferably, an isolation forest type machine learning algorithm is implemented.

[0083] Alternatively, another unsupervised anomaly detection method, producing an anomaly score, is used, for example the method known as "local factor outlier".

[0084] The anomaly determination algorithm takes as input a descriptive vector of size M and provides as output an anomaly score, allowing to infer the potential presence of anomaly in the time series data associated with the descriptive vector.

[0085] For example, the anomaly scores obtained at the output are, for example, normalized between a minimum and a maximum value. The closer the anomaly score is to the maximum value, the more likely the presence of an anomaly is, and conversely, the closer the anomaly score is to the minimum value, the more it is considered to be "normal" operation.

[0086] The learning step 42 is followed by a step 44 of applying the algorithm implementing the parameterized anomaly determination model to each descriptive vector to calculate the associated anomaly score.

[0087] Thus, for each time series processed we obtain an associated anomaly score, using the descriptive vector of the time series.

[0088] In one embodiment, an anomaly score is thus obtained for each piece of equipment observed.

[0089] The method then comprises a step 46 of comparing each calculated anomaly score to a predetermined or dynamically calculated anomaly threshold.

[0090] The predetermined anomaly threshold is between the minimum and maximum anomaly score value. For example, if the score is between 0 and 1, the anomaly threshold is set to 0.5.

[0091] Alternatively, a percentage P is set, for example P=10%, and the abnormal scores are considered to be the highest P scores. An anomaly threshold value is derived from this.

[0092] Alternatively, the calculated anomaly scores are ordered from smallest to largest (or vice versa), and deviations between anomaly scores are calculated. For example, abnormal scores are those following the highest deviation. For example, if the scores are respectively {0.1; 0.2; 0.3; 0.7; 0.8} the abnormal scores are 0.7 and 0.8, the highest deviation being between 0.3 and 0.7.

[0093] If the anomaly score is greater than the predetermined or dynamically calculated anomaly threshold, the corresponding time series is labeled as having an anomaly.

[0094] A subset of anomaly time series (i.e. including an anomaly) relative to the predetermined anomaly threshold is thus obtained, if applicable.

[0095] In the case where an anomaly score is obtained per observed equipment, similarly a subset of equipment in anomaly relative to the predetermined anomaly threshold is thus obtained.

[0096] The method then comprises a step 48 of explaining the detected anomalies. For each time series of the subset of anomalous time series, step 48 implements a determination, from the descriptive vector of said time series, of at least part of the values ​​of the time series having an influence in obtaining the anomaly score.

[0097] In the embodiment of the figure 2 , step 48 comprises two sub-steps, a first sub-step 50 of calculating the level of influence of each component of the descriptive vector of the time series considered and a step 52 of calculating one or more alternative time series(s), each alternative time series being a counter-example or counterfactual time series. Each alternative time series is a series that the anomaly determination algorithm would have classified as normal, and each alternative series is close to the original series.

[0098] Substep 50 implements a calculation of the Shapley values ​​for each component of the descriptive vector, each Shapley value providing a level of influence of this component.

[0099] From the level of influence of each component of the descriptive vector it is possible to calculate a level of influence associated with each value of the time series associated with the descriptive vector.

[0100] Shapley values ​​are initially used for payoff distribution in the field of cooperative games in game theory, and their application in the field of machine learning is known.

[0101] The formula for calculating Shapley values ​​for each element in a set of elements is known.

[0102] In its application here, the element set is the set of components of a descriptive vector, and the associated function is the anomaly determination model (i.e. the anomaly score obtained).

[0103] In this case, a gain value is calculated for each component of the descriptive vector in the anomaly determination model.

[0104] This gives a level of influence per component of the descriptive vector.

[0105] Substep 52 implements an alternative time series calculation.

[0106] In one embodiment, sub-step 52 applies to a given descriptive vector, here called initial descriptive vector, a calculation of at least one alternative (or counter-example) descriptive vector.

[0107] The initial descriptive vector has an associated anomaly score greater than the anomaly threshold.

[0108] An alternative descriptive vector has an associated anomaly score lower than the anomaly threshold. Thus, the alternative descriptive vector has at least one component distinct from the component of the same rank in the original descriptive vector.

[0109] Moreover, the initial descriptive vector and the alternative descriptive vector are close in the sense of a distance, for example the Euclidean distance, in other words the distance between the initial descriptive vector and the alternative descriptive vector is less than a predetermined distance threshold.

[0110] Additionally, a likelihood condition of the alternative descriptive vector is applied, for example based on the anomaly score calculated by the anomaly determination algorithm.

[0111] The computation of an alternative (or counterexample) descriptive vector is performed using a known method, for example using the method described in the article “Model-agnostic and Scalable Counterfactual Explanations via Reinforcement Learning” by RF Samoilescu et al, published in June 2021.

[0112] Alternatively, any other alternative descriptive vector calculation method may be applied.

[0113] From an alternative descriptive vector, one or more alternative time series are calculated, i.e. whose projection on the basis of chosen functions makes it possible to obtain the alternative descriptive vector, by applying an inverse transformation.

[0114] The alternative time series(s) contain different values ​​from the initial time series. These different values ​​are highlighted and reported to the operator.

[0115] This allows us to better understand the anomaly observed and to remedy it.

[0116] There figure 3 is a synopsis of the main steps of a second embodiment of the method for detecting an anomaly and determining the associated explanation.

[0117] In this second embodiment, the detection is applied to time series of data collected as and when, almost in real time, and takes into account the evolution of the anomaly scores calculated for each piece of equipment monitored.

[0118] The results obtained relating to anomaly detection and their explanations are, for example, applicable to predictive maintenance and breakdown avoidance.

[0119] The method is applied to time series collected over successive PER_k time periods, for each monitored equipment.

[0120] For example, in the monovariate case, during each time period, a time series of data collected by a sensor associated with a piece of equipment is processed.

[0121] In this embodiment, each time period has an associated duration, which is for example of the order of one to several hours.

[0122] For example, the time period duration is less than the time period duration selected in the first embodiment.

[0123] The time series of values ​​measured during a first time period Per_1 are obtained.

[0124] In a first processing step 60, these first time series are processed as in the first embodiment. In other words, the first processing step 60 implements steps similar to steps 40 to 48 described previously.

[0125] The parameters of the anomaly determination model, implemented by the anomaly determination algorithm, learned during the learning step 42 are stored.

[0126] Then, an index k of the next time period is set to the value k=2 in step 62.

[0127] Time series with values ​​measured during the period Per_k are processed in a second processing step 64.

[0128] The second processing step 64 implements a projection 66 of the time series onto the M chosen basic functions making it possible to obtain a descriptive vector per time series of the period Per_k.

[0129] Step 66 is followed by a step 68 of application of the anomaly determination model, this model being parameterized by the previously learned parameters. For each descriptive vector, associated with a piece of equipment, an anomaly score is calculated for the period Per_k.

[0130] The method also comprises a step 70 of determining a change in the anomaly score for each observed equipment. For example, for an equipment of index i, step 70 implements a calculation of the difference between the anomaly score calculated for the period Per_k-1 and the anomaly score calculated for the period Per_k.

[0131] This difference calculation makes it possible to detect variations in the anomaly score for the same equipment, and consequently to detect drifts or a speed of degradation of the equipment, even before the anomaly threshold is reached. Advantageously, this makes it possible to anticipate possible degradations, and therefore to optimize predictive maintenance.

[0132] The method further comprises a third processing step 72, implemented on the time series obtained for the period Per_k, which is analogous to the first processing step.

[0133] In other words, the third processing step 72 implements steps analogous to steps 40 to 48 described previously.

[0134] In particular, during the third processing step 72, the parameters of the anomaly determination model are updated by the learning step (analogous to step 42).

[0135] The parameters of the anomaly determination model learned during the training step on the descriptive vectors of the time series of the period Per_k are stored.

[0136] The third processing step is followed by a repetition of steps 64 to 72 for a subsequent time period, with the index k being incremented.

[0137] Thus, advantageously, the method makes it possible to obtain over successive time periods a calculation of anomaly scores and a determination of associated explanation, a detection of anomaly equipment, as well as a detection of the evolution of the anomaly scores, for the same equipment, over several successive time periods.

Claims

1. A method of detecting an anomaly and determining an associated explanation in time series of data, each time series having an associated duration and comprising a number N of operating values of an item of equipment taken by sensors associated with the item of equipment, or values representative of the operation of a system, taken at regular intervals during said duration, the method being characterized in that it comprises steps implemented by a computational processor of: - for each time series, projecting (40) of the values of said time series onto a number M of basis functions and obtaining a descriptive vector of said time series of size M, said basis functions being functions of a wavelet transform basis or B-Spline functions; - training (42) a parameterised anomaly determination model by machine learning on at least some of the descriptive vectors calculated, said anomaly determination model making it possible to calculate an anomaly score for each descriptive vector; - applying (44) the anomaly determination model to the descriptive vectors of the time series and obtaining an anomaly score for each time series; - determining (46) a subset of time series containing an anomaly by comparing the anomaly score of each time series with a predetermined anomaly threshold; - for each time series of said subset, determining (48), from the descriptive vector of said time series, at least some of the values of said descriptive vector that influence the obtaining of the anomaly score of said time series, which determining (48) comprises, for an initial descriptive vector, ∘ calculating at least one alternative descriptive vector, said alternative descriptive vector comprising at least one component distinct from the component of the same rank in the initial descriptive vector, having an associated anomaly score, obtained by applying said parameterised anomaly determination model, that is lower than the anomaly threshold, and being such that a distance between the initial descriptive vector and the alternative descriptive vector is less than a predetermined distance threshold, ∘ and ∘ determining at least one alternative time series from the alternative descriptive vector, the projection of said alternative time series onto said base of selected functions making it possible to obtain said alternative descriptive vector, the one or more alternative time series comprising values different from the values of the initial time series, these different values being highlighted and signalled to the operator by a human-machine interface.

2. The method according to claim 1, wherein determining (48), from the descriptive vector of said time series, of at least some of the values of said descriptive vector that influence the obtaining of the anomaly score of said time series comprises calculating (50) a level of influence in obtaining the influence score for each component of said descriptive vector.

3. The method according to claim 2, wherein the calculating of a level of influence implements a calculation of Shapley values, said level of influence being equal to the Shapley value calculated for each component of said descriptive vector.

4. The method according to any one of claims 1 to 3, implemented on time series, comprising at least a first time series and at least a second time series of operating values of an item of equipment or system, collected over successive time periods comprising, at least, a first time period and a second time period, succeeding the first time period, the method comprising: - -obtaining a first anomaly score of a descriptive vector determined for a time series over the first time period, by implementing an anomaly determination model parameterised by parameters calculated for said first time period, - obtaining a second anomaly score of a descriptive vector determined for a time series of a time series over the second time period by implementing the anomaly determination model parameterised by parameters calculated for said first time period, and - an anomaly score change determination for said item of equipment or system, consisting of calculating a difference between the second anomaly score calculated and the first anomaly score calculated.

5. The method according to claim 4, further comprising an updating of the parameters of the anomaly determination model parameterised over said second time period.

6. A computer program comprising software instructions which, when executed by a programmable electronic device, implement a method of detecting an anomaly and determining an associated explanation in accordance with claims 1 to 5.

7. A device for detecting an anomaly and determining an associated explanation in time series of data, each time series having an associated duration and comprising a number N of operating values of an item of equipment taken by sensors associated with the item of equipment, or values representative of the operation of a system, taken at regular intervals during said duration, the device comprising or being connected to a human-machine interface, the device being characterised in that it comprises a calculation processor configured to implement: - a module (22) for projecting, for each time series, the values of said time series onto a number M of basis functions and obtaining a descriptive vector of said time series of size M, said basis functions being functions of a wavelet transform basis or B-Spline functions; - a module (24) for training a parameterised anomaly determination model by machine learning on at least some of the descriptive vectors calculated, said anomaly determination model making it possible to calculate an anomaly score for each descriptive vector; - a module (26) for applying the anomaly determination model to the descriptive vectors of the time series and obtaining an anomaly score for each time series; - a module (28) for determining a subset of time series containing an anomaly by comparing the anomaly score of each time series with a predetermined anomaly threshold; - a module (30) for determining, for each time series of said subset, from the descriptive vector of said time series, at least some of the values of said descriptive vector that influence the obtaining of the anomaly score of said time series, which performs for an initial descriptive vector, a calculation of at least one alternative descriptive vector, said alternative descriptive vector comprising at least one component distinct from the component of the same rank in the initial descriptive vector, having an associated anomaly score, obtained by applying said parameterised anomaly determination model, that is lower than the anomaly threshold, and being such that a distance between the initial descriptive vector and the alternative descriptive vector is less than a predetermined distance threshold, and determining at least one alternative time series from the alternative descriptive vector, projecting said alternative time series onto said base of selected functions to obtain said alternative descriptive vector, the alternative time series or series comprising values different from the values of the initial time series, these different values being highlighted and indicated to the operator by said man-machine interface.