System
The system addresses slow response times in communication systems by automating fault detection and countermeasure generation through log data preprocessing and machine learning, facilitating rapid anomaly identification and response.
Patent Information
- Application Number
- JP2024126329
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-08-01
- Publication Date
- 2026-02-13
AI Technical Summary
Current communication systems face challenges in quickly detecting and responding to equipment failures due to high human intervention and complex log data management, which prolongs the time required to identify and address malfunctions.
A system that preprocesses log data, detects anomalies using machine learning, proposes countermeasures, automatically generates reports, and sends notifications, reducing human burden and speeding up responses.
Automates fault detection and countermeasure generation, enabling fast and efficient troubleshooting by collecting, preprocessing, and analyzing log data to identify anomalies and suggest corrective actions.
Smart Images

Figure 2026024008000001_ABST
Abstract
Description
[Technical Field]
[0001] The technology of the present disclosure relates to a system. [Background technology]
[0002] Patent document 1 discloses a persona chatbot control method performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to a description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180282 Summary of the Invention [Problem to be solved by the invention]
[0004] In modern communications infrastructure, it is extremely important to quickly detect and respond appropriately to failures and malfunctions in communications equipment (e.g., base stations). However, current systems impose a heavy human burden when a malfunction occurs, making it difficult to respond quickly. In addition, the accumulation and monitoring of log data has become increasingly complex, significantly increasing the time and effort required to identify the cause of a malfunction. In these circumstances, there is a need for efficient fault detection and automatic countermeasure generation. [Means for solving the problem]
[0005] The present invention provides a system that preprocesses log data collected from communication devices, detects abnormalities based on the preprocessed log data, proposes optimal countermeasures for the detected abnormalities, automatically generates a report based on the proposed countermeasures, transmits the generated report, and sends a notification. This automates the entire process from fault detection to countermeasure proposal, and report generation and distribution, thereby reducing the human burden and speeding up responses.
[0006] Specifically, the system preprocesses log data collected from communications devices by cleaning and formatting it, then uses a machine learning model to detect anomalies based on the preprocessed log data. If an anomaly is detected, the system proposes optimal countermeasures and automatically generates a formatted report containing details of the anomaly and the countermeasures based on the proposed countermeasures. The generated report is then sent by email, and notifications are sent to devices in real time, enabling fast and efficient troubleshooting.
[0007] A "communication device" is a device for transmitting and receiving data within a communication network.
[0008] "Log data" refers to data that is generated and stored by a communication device and includes information on operational status, errors, and other events.
[0009] "Preprocessing" refers to a series of steps taken to convert raw data into a form that can be analyzed and applied to models.
[0010] An "abnormality" refers to an operation or state that deviates from the normal operation of a communication device, and is an event that may cause a malfunction or failure.
[0011] "Detection" is the process of discovering specific patterns or anomalies in collected and analyzed data.
[0012] "Countermeasures" are specific methods or procedures for eliminating or mitigating a detected abnormality.
[0013] A "report" is a formal document containing details of any detected anomalies and proposed remedial actions.
[0014] "Automatic generation" is the process by which a system automatically creates documents and data without human intervention.
[0015] "Send" is the act of delivering a generated report or notification to a designated recipient.
[0016] "Notification" is the act of informing a recipient of specific information from the system in real time. [Brief explanation of the drawings]
[0017] [Figure 1] 1 is a conceptual diagram showing an example of the configuration of a data processing system according to a first embodiment. [Figure 2] 1 is a conceptual diagram showing an example of main functions of a data processing device and a smart device according to a first embodiment. [Figure 3] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and smart glasses according to a second embodiment. [Figure 5] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a third embodiment. [Figure 6] FIG. 11 is a conceptual diagram showing an example of main functions of a data processing device and a headset-type terminal according to a third embodiment. [Figure 7] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a fourth embodiment. [Figure 8] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and a robot according to a fourth embodiment. [Figure 9] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 10] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 11] FIG. 3 is a sequence diagram showing a processing flow of the data processing system according to the first embodiment. [Figure 12] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 1. [Figure 13] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system according to the second embodiment when an emotion engine is combined. [Figure 14] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 2 when an emotion engine is combined. DETAILED DESCRIPTION OF THE INVENTION
[0018] An example of an embodiment of a system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.
[0019] First, the terms used in the following description will be explained.
[0020] In the following embodiments, a coded processor (hereinafter simply referred to as a "processor") may be a single arithmetic device or a combination of multiple arithmetic devices. Furthermore, a processor may be a single type of arithmetic device or a combination of multiple types of arithmetic devices. Examples of arithmetic devices include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), and an APU (Accelerated Processing Unit).
[0021] In the following embodiments, a coded RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a working memory by a processor.
[0022] In the following embodiments, the coded storage is one or more non-volatile storage devices that store various programs, various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), and magnetic tapes.
[0023] In the following embodiments, a communication I / F (Interface) with a symbol is an interface including a communication processor, an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), Bluetooth (registered trademark), etc.
[0024] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."
[0025] [First embodiment]
[0026] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.
[0027] 1, a data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0028] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0029] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The reception device 38, the output device 40, and the camera 42 are also connected to the bus 52.
[0030] The reception device 38 includes a touch panel 38A, a microphone 38B, and the like, and receives user input. The touch panel 38A detects contact with an indicator (for example, a pen or a finger) to receive user input by the touch of the indicator. The microphone 38B detects the user's voice to receive user input by voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.
[0031] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form of expression that the user 20 can perceive (for example, audio and / or text). The display 40A displays visible information such as text and images in accordance with instructions from the processor 46. The speaker 40B outputs audio in accordance with instructions from the processor 46. The camera 42 is a compact digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0032] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54.
[0033] FIG. 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0034] 2, in the data processing device 12, a specific process is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific process is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0035] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0036] In the smart device 14, the processor 46 performs the reception output process. The storage 50 stores a reception output program 60. The reception output program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[0037] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0038] The present invention provides a system that preprocesses log data collected from communication devices, detects abnormalities based on the preprocessed log data, proposes optimal countermeasures for the detected abnormalities, automatically generates a report based on the proposed countermeasures, transmits the generated report, and sends a notification. In this embodiment, the main functions of the system and its processing flow will be described.
[0039] 1. Collect and preprocess log data:
[0040] The server collects log data from communication devices in real time, via APIs and data streams.
[0041] The collected log data is first preprocessed. Preprocessing involves cleaning the data and converting its format to make it analyzable. For example, this involves removing incomplete data, standardizing timestamps, and extracting necessary information.
[0042] 2. Anomaly detection:
[0043] The server inputs the preprocessed log data into an anomaly detection model, which includes machine learning algorithms to accurately detect anomalies that deviate from historical normal behavior patterns.
[0044] If the anomaly detection model finds an anomaly, details of the anomaly are recorded.
[0045] 3. Proposed solutions:
[0046] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which includes referencing a database of past countermeasure patterns.
[0047] The appropriate countermeasures proposed are selected based on the type of abnormality and its cause.
[0048] 4. Generate report:
[0049] The server automatically generates a formal report based on the detected anomalies and proposed remediation measures, including details of the anomaly, the date and time of detection, and proposed remediation measures.
[0050] Reports are prepared according to a standard format and may be converted into formats such as PDF.
[0051] 5. Report Distribution and Notification:
[0052] The server automatically sends generated reports to interested parties, including using an email sending function to deliver the reports to designated recipients.
[0053] It also sends notifications to the device, allowing relevant parties to be aware of any abnormalities and countermeasures in real time.
[0054] Specific examples
[0055] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[0056] Type of anomaly: Sudden drop in signal strength
[0057] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[0058] In this case, the system behaves as follows:
[0059] 1. The server collects log data from base station A and performs preprocessing.
[0060] 2. Using the preprocessed log data, an anomaly detection model detects sudden drops in signal strength.
[0061] 3. The server will suggest the best course of action for this anomaly: "Physical check of antenna" and "Restart signal repeater."
[0062] 4. A detailed report is automatically generated based on the proposed action, including data on signal strength degradation and suggested steps to take.
[0063] 5. Finally, the generated report is sent to the relevant parties via email, and notifications of abnormalities and countermeasures are sent to the terminal in real time.
[0064] This automates the entire process, from detecting a communication device fault to proposing a countermeasure, generating a report, and notifying relevant parties, reducing the human burden and enabling a quick response.
[0065] The processing flow will be explained below.
[0066] Step 1:
[0067] The server collects log data from communication devices. It automatically retrieves the latest log data at regular intervals via an API endpoint or data stream. For example, it retrieves the log data using an HTTP request and stores it in memory or a database.
[0068] Step 2:
[0069] The server preprocesses the collected log data. Specifically, it cleans the data by removing incomplete data, standardizing the timestamp format, and extracting necessary information. This preprocessing prepares the data in a format suitable for analysis.
[0070] Step 3:
[0071] The server inputs the preprocessed log data into an anomaly detection model, which uses a machine learning algorithm to detect anomalies that deviate from normal data patterns. At this time, information such as the type of anomaly, the date and time of occurrence, and the extent of the impact is output.
[0072] Step 4:
[0073] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which involves a process of selecting the optimal countermeasure for each type of anomaly by referencing a past database and a pattern library of countermeasures.
[0074] Step 5:
[0075] The server automatically generates a report based on the details of the detected anomalies and the proposed remediation measures. The report includes details of the anomaly, the date and time of detection, the proposed remediation measures, and recommended action steps. The report is generated in a format such as PDF.
[0076] Step 6:
[0077] The server then emails the generated report to the designated recipient (e.g., administrator or technician). Real-time notifications are also sent to the device, promptly informing the relevant parties of any abnormalities and countermeasures. The notifications include a summary of the report and a link.
[0078] Example 1
[0079] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0080] Modern communications equipment is required to detect anomalies in real time, quickly propose countermeasures, and quickly share information with relevant parties. However, with conventional systems, it is difficult to automate these processes, requiring a great deal of manpower and time. Furthermore, the accuracy of anomaly detection and the appropriateness of countermeasures can be low, making efficient fault management difficult.
[0081] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[0082] In this invention, the server includes means for collecting log data from communication devices in real time, means for preprocessing the collected log data, means for inputting the preprocessed log data into an anomaly detection model to detect anomalies, means for proposing optimal countermeasures for the anomalies, means for automatically generating a report based on the proposed countermeasures, means for sending the generated report by email, and means for sending notifications to relevant parties in real time, thereby enabling real-time anomaly detection and countermeasure proposals, automated report generation, and rapid information sharing.
[0083] A "communications device" is a device that includes hardware and software for transmitting and receiving data.
[0084] "Log data" refers to recorded data relating to the operating status and events of a communication device.
[0085] "Real-time" is a concept that refers to a state in which data is collected and processed almost simultaneously as it occurs.
[0086] "Preprocessing" refers to a series of processes such as data cleaning, format standardization, and extraction of necessary information to prepare collected log data in an analyzable form.
[0087] An "anomaly detection model" is a model that uses a machine learning algorithm to detect anomalies that deviate from normal operating patterns.
[0088] "Countermeasures" refers to appropriate methods and procedures for dealing with detected abnormalities.
[0089] A "report" is a document that compiles detailed information about detected anomalies and proposed remedial actions.
[0090] "Email" is a means of sending messages and files electronically over the Internet.
[0091] "Notification" is a means of informing interested parties in real time about specific events or conditions.
[0092] The present invention is a system that preprocesses log data collected from communication devices, detects anomalies based on that data, and proposes optimal countermeasures. Furthermore, this system has the function of automatically generating reports based on the proposed countermeasures, sending the generated reports to relevant parties, and sending notifications in real time.
[0093] Hardware and software configuration:
[0094] server:
[0095] The server collects log data from communication devices in real time. This collection is done via HTTP API or WebSocket. The collected data is preprocessed on the server and input into an anomaly detection model. Machine learning algorithms such as TensorFlow and PyTorch are used for anomaly detection.
[0096] Communication equipment:
[0097] These are devices that send and receive data, including base stations and modems. These devices generate log data and send it to a server.
[0098] Device:
[0099] A device that receives notifications in real time, including PCs, tablets, smartphones, etc. Notifications are sent as push notifications from the server or emails.
[0100] Data processing and calculation:
[0101] Pretreatment:
[0102] When the server receives the log data, it cleans it, removes incomplete data, standardizes timestamps, and extracts necessary information to make the data analyzable.
[0103] Anomaly detection:
[0104] The preprocessed data is then input into an anomaly detection model, which is trained using machine learning algorithms to detect anomalies by comparing them with past normal patterns. Detailed information about detected anomalies (type of anomaly, time of occurrence, and scope of impact) is then recorded.
[0105] Suggested workaround:
[0106] The server then suggests the best course of action for any detected anomalies. It consults a database of past cases and searches for solutions based on similar cases. For example, if the signal strength drops, it suggests physically checking the antenna or restarting the repeater.
[0107] Generate a report:
[0108] A report is automatically generated based on the details of the anomaly and the proposed remedial action, and is saved in a standard format (e.g. PDF) for future reference.
[0109] Report distribution and notification:
[0110] The server will send the generated report to the relevant parties via email, and at the same time, send real-time notifications to the terminals about any abnormalities and suggested countermeasures, allowing the relevant parties to take immediate action.
[0111] Examples:
[0112] For example, it is assumed that the following abnormality is detected based on log data collected from a certain communication device (base station).
[0113] Type of anomaly: Sudden drop in signal strength
[0114] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[0115] In this case, the system operates as follows.
[0116] 1. The server collects log data from the communication devices and performs preprocessing.
[0117] 2. The preprocessed log data is input into an anomaly detection model using a machine learning algorithm to detect sudden drops in signal strength.
[0118] 3. The server will suggest the following countermeasures for the anomaly: "Physical check of the antenna" and "Restart of the signal repeater."
[0119] 4. Based on the proposed countermeasures, a report is automatically generated detailing the anomaly and the countermeasures.
[0120] 5. The server sends a report to the relevant parties via email, and simultaneously sends real-time notifications to the terminals regarding the occurrence of abnormalities and countermeasures.
[0121] Example prompt sentence:
[0122] "Please check what anomalies were detected and what countermeasures were proposed based on the log data collected from this communication device."
[0123] This automates the process from detecting a communication device fault to proposing a countermeasure, generating a report, and notifying relevant parties, enabling a fast and efficient response to anomalies.
[0124] The flow of the identification process in the first embodiment will be described with reference to FIG.
[0125] Program processing flow
[0126] Step 1: Collect log data
[0127] The server collects log data from the communication devices in real time by sending requests to the communication devices at regular intervals using HTTP API or WebSocket to obtain the latest log data.
[0128] Input: Raw log data obtained from communication devices
[0129] Output: Collected raw log data stored on the server
[0130] Specific operation: The server periodically accesses the communication device, receives log data, and stores it in a database.
[0131] Step 2: Preprocessing the log data
[0132] The server preprocesses the collected log data, cleaning the data to remove incomplete data and filter unnecessary data, standardizing the timestamp format, and extracting necessary information.
[0133] Input: Raw log data stored on the server
[0134] Output: Preprocessed log data
[0135] What happens: The server performs data cleaning, unifies timestamps, and applies algorithms to extract the required information.
[0136] Step 3: Detect anomalies
[0137] The server inputs the preprocessed log data into an anomaly detection model, which uses machine learning algorithms to detect deviations from normal behavior patterns.
[0138] Input: Preprocessed log data
[0139] Output: Log data in which an anomaly was detected and its detailed information
[0140] Specific operation: The server inputs preprocessed log data into an anomaly detection model built using TensorFlow and PyTorch, and determines whether or not there are any anomalies.
[0141] Step 4: Propose a solution
[0142] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, and searches for countermeasures based on similar cases by referencing a past database.
[0143] Input: Log data in which an anomaly was detected and detailed information
[0144] Output: Proposed action
[0145] Specific operation: Based on the type of abnormality and its cause, the server selects the most appropriate countermeasure from a pre-prepared database.
[0146] Step 5: Generate the report
[0147] The server automatically generates a report based on the details of the anomaly and the proposed countermeasures, including details of the anomaly, the date and time of detection, and the proposed countermeasures.
[0148] Input: Anomaly details and suggested remediation
[0149] Output: Automatically generated report (e.g. PDF format)
[0150] Specific operation: The server combines the details of the anomaly and the countermeasures, generates a report based on a template, and converts it into PDF format.
[0151] Step 6: Report distribution and notification
[0152] The server sends the generated report to the relevant parties via email, and simultaneously sends real-time notifications of abnormal occurrences and countermeasures to the relevant parties' terminals.
[0153] Input: Automatically generated report and notification information
[0154] Output: Reports sent by email and notifications sent to terminal
[0155] Specific operation: The server uses the SMTP protocol to send the report by email, and sends notifications to the relevant parties' terminals via the Push notification service.
[0156] These steps automate a series of processes, from collecting log data from communication devices to detecting anomalies, proposing countermeasures, generating reports, and distributing and notifying them.
[0157] (Application example 1)
[0158] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0159] There is a need for a method to manage the operation logs of robots in factories and respond quickly and accurately when an abnormality occurs. Currently, the detection of abnormalities and the proposal of countermeasures are often done manually, which takes time and effort. In addition, the creation of reports is a significant burden, so an automated system is needed to improve efficiency.
[0160] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[0161] In this invention, the server includes means for preprocessing log data collected from the communication devices, means for detecting anomalies based on the preprocessed log data, means for proposing optimal countermeasures for the detected anomalies, means for automatically generating a report based on the proposed countermeasures, means for transmitting the generated report and sending a notification, means for monitoring operation logs of robots in the factory in real time, means for using a machine learning algorithm to detect anomalies with high accuracy using the preprocessed log data, and means for proposing optimal countermeasures after detecting an anomaly, automatically generating a report, and notifying relevant parties. This automates the entire process from detecting anomalies in robots in the factory to proposing countermeasures, generating a report, and notifying relevant parties, thereby reducing the human burden and enabling rapid responses.
[0162] A "communication device" is a device for data communication, and is used to collect log data from factory robots and sensors.
[0163] "Log data" refers to data including operation history and event information recorded by factory robots and communication devices.
[0164] "Preprocessing" refers to the process of cleaning and formatting the collected log data to make it analyzable.
[0165] "Abnormal" refers to behavior or errors that deviate from normal operating patterns, and in the case of factory robots, this includes unexpected behavior or malfunctions.
[0166] An "anomaly detection model" is an algorithm or system that uses machine learning and statistical models to detect anomalies in collected log data.
[0167] "Countermeasures" are specific measures or solutions implemented in response to detected abnormalities, and in the case of factory robots, these include restarting the robot or replacing parts.
[0168] A "report" is an official document summarizing detected anomalies and proposed countermeasures, and is used to share information with relevant parties.
[0169] The "server" is a central device that stores data, pre-processes it, detects anomalies, proposes countermeasures, generates reports, and sends notifications.
[0170] A "machine learning algorithm" is a computational method for learning patterns from large amounts of data and detecting and predicting anomalies.
[0171] "Notifications" are messages or alerts that inform relevant parties in real time about abnormalities and countermeasures.
[0172] "Real-time" refers to reacting and processing events and data immediately at the moment they occur.
[0173] This invention provides a system that monitors the operation logs of factory robots in real time, proposes optimal countermeasures when an abnormality is detected, automatically generates a report, and notifies relevant parties. A specific method for realizing this system is described below.
[0174] Hardware and software used
[0175] Hardware
[0176] Factory robot: an automated device placed on a production line
[0177] Sensing device: Collects robot movement data
[0178] Server: Performs data preprocessing, anomaly detection, countermeasure proposals, report generation and notifications
[0179] software
[0180] Log collection API: Collect operation logs from factory robots in real time
[0181] Data preprocessing tools: cleaning and formatting data (e.g., Python's Pandas library)
[0182] Anomaly detection algorithm: Machine learning model (e.g., PyCaret)
[0183] Countermeasure proposal system: Refer to past database
[0184] Report generation tools: PDF generation (e.g. reportlab)
[0185] Notification system: Email or push notification (e.g. SMTP server)
[0186] System Operation Overview
[0187] 1. Collecting and Preprocessing Log Data
[0188] The server uses a log collection API to collect operation logs from the factory robots in real time, and then uses a data preprocessing tool to clean and convert the collected data into an analyzable format.
[0189] 2. Anomaly detection
[0190] The server inputs the preprocessed log data into a machine learning model to detect anomalies with high accuracy, and when an anomaly is detected, detailed information about it is recorded.
[0191] 3. Proposal of countermeasures
[0192] The server proposes optimal countermeasures for detected anomalies by referencing a past database and existing countermeasure patterns.
[0193] 4. Generate reports
[0194] Based on the proposed countermeasures, the server automatically generates an official report in PDF format, including details of the anomaly, the date and time of detection, and the proposed countermeasures.
[0195] 5. Notification sending
[0196] The generated reports are automatically sent to the relevant parties by the server, and notifications are also sent in real time to smartphones and monitoring devices within the factory.
[0197] Specific examples
[0198] For example, consider a situation where factory robot A suddenly stops performing its designated operation. The server receives the operation logs collected from robot A in real time, and a pre-processing tool cleans and converts the data. The machine learning algorithm then detects the anomaly and suggests countermeasures: "restart robot A" and "physical inspection of the sensor." Based on this, a detailed report is automatically generated and distributed to relevant parties via email, and a notification of the anomaly is sent to the device in real time.
[0199] Prompt Sentence Examples
[0200] "Please apply an application to factory robots that preprocesses log data collected from communication devices, detects abnormalities, proposes optimal countermeasures, generates reports and sends notifications. This application will monitor the robot's operation logs in real time, detect abnormalities, propose countermeasures, automatically generate reports, and send notifications."
[0201] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[0202] Step 1:
[0203] The server uses a log collection API to collect operation logs from the factory robots in real time. It receives the factory robot log data as input and stores it in the server's storage. The output is raw log data for preprocessing.
[0204] Step 2:
[0205] The server uses a data preprocessing tool to clean the collected log data and convert its format. Specifically, it removes incomplete data, standardizes timestamps, and extracts necessary information. The input is the raw log data obtained in step 1, and the output is the preprocessed, clean data.
[0206] Step 3:
[0207] The server inputs the preprocessed log data into an anomaly detection algorithm (machine learning model). The server compares it with past normal behavior patterns to detect whether there are any anomalies with high accuracy. The input is preprocessed clean data, and the output is the anomaly detection results and detailed information about the anomaly.
[0208] Step 4:
[0209] The server proposes optimal countermeasures for detected anomalies. Here, it refers to a past database and existing countermeasure patterns to select an appropriate method based on the type and cause of the anomaly. The input is the anomaly detection result, and the output is a proposal of specific countermeasures.
[0210] Step 5:
[0211] The server automatically generates a report based on the proposed countermeasures. The report includes details of the anomaly, the date and time of detection, the proposed countermeasures, and procedures. A report generation tool (PDF generation tool) is used for generation. The input is the proposed countermeasures, and the output is an official report.
[0212] Step 6:
[0213] The server automatically sends the generated report to the relevant parties. The relevant parties are notified by email and also by sending a notification to their terminal. Email and push notifications are sent using a notification system. The input is the official report, and the output is a notification of completion of transmission and a notification to the relevant parties.
[0214] Step 7:
[0215] The user checks the received notifications and reports and takes necessary actions. The input is the received notifications and reports, and the output is the specific action taken by the user.
[0216] Furthermore, an emotion engine that estimates the user's emotion may be combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.
[0217] The present invention combines a system that preprocesses log data collected from communication devices, detects anomalies based on the preprocessed log data, proposes optimal countermeasures for the detected anomalies, automatically generates a report based on the proposed countermeasures, transmits the generated report, and sends notifications, with an emotion engine that recognizes user emotions. In this embodiment, the main functions of the system and its processing flow will be described.
[0218] 1. Collecting and pre-processing log data:
[0219] The server collects log data from communication devices in real time, automatically obtaining the latest log data at regular intervals via API endpoints or data streams.
[0220] The collected log data is first preprocessed. Preprocessing involves cleaning the data and converting its format to make it analyzable. For example, this involves removing incomplete data, standardizing timestamps, and extracting necessary information.
[0221] 2. Anomaly detection:
[0222] The server inputs the preprocessed log data into an anomaly detection model, which uses machine learning algorithms to accurately detect anomalies that deviate from normal data patterns. Detailed information such as the type of anomaly, the date and time of occurrence, and the scope of impact is recorded.
[0223] 3. Proposed solutions:
[0224] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which involves a process of selecting the optimal countermeasure for each type of anomaly by referencing a past database and a pattern library of countermeasures.
[0225] 4. Generate report:
[0226] The server automatically generates a report based on the detected anomalies and proposed remediation measures. The report includes details of the anomaly, the date and time of detection, the proposed remediation measures, and recommended action steps. The report is created according to a standard format and may be converted to a format such as PDF.
[0227] 5. Report Distribution and Notification:
[0228] The server sends the generated report to the designated recipient (administrator or technician) via email. Real-time notifications are also sent to the device, allowing relevant parties to quickly understand the occurrence of an abnormality and take appropriate action. Notifications include a summary of the report and a link.
[0229] 6. Emotion Engine in Action:
[0230] The emotion engine is a function for recognizing the user's emotions. It analyzes text and voice data when the user uses the system and recognizes the user's emotions.
[0231] The server adjusts the report content and notification format based on the user's emotions recognized by the emotion engine. For example, if the user is experiencing high stress, the report will include detailed explanations and prioritized solutions.
[0232] The emotion engine also further optimizes the suggested response based on the user's emotions. For example, if the user is calm, it can suggest a response that prioritizes speed.
[0233] Specific examples
[0234] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[0235] Type of anomaly: Sudden drop in signal strength
[0236] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[0237] In this case, the system behaves as follows:
[0238] 1. The server collects log data from base station A and performs preprocessing.
[0239] 2. Using the preprocessed log data, an anomaly detection model detects sudden drops in signal strength.
[0240] 3. The server will suggest the best course of action for this anomaly: "Physical check of antenna" and "Restart signal repeater."
[0241] 4. A detailed report is automatically generated based on the proposed action, including data on signal strength degradation and suggested steps to take.
[0242] 5. If the emotion engine identifies the user's emotions as high stress, a detailed explanation and prioritized actions will be added to the report.
[0243] 6. Finally, the generated report is sent to the relevant parties via email, and notifications of abnormalities and countermeasures are sent to the terminal in real time.
[0244] This enables the system to operate in a way that takes the user's emotions into account, further optimizing the entire process from fault detection to proposing countermeasures, generating reports, and notifying relevant parties.
[0245] The processing flow will be explained below.
[0246] Step 1:
[0247] The server collects log data from communication devices and automatically retrieves the latest log data at regular intervals via API endpoints or data streams.
[0248] Step 2:
[0249] The server preprocesses the collected log data by cleaning and formatting the data, removing incomplete data, standardizing the timestamp format, extracting necessary information, and preparing the data in a format suitable for analysis.
[0250] Step 3:
[0251] The server inputs the preprocessed log data into an anomaly detection model, which uses machine learning algorithms to accurately detect anomalies that deviate from normal data patterns. It then records detailed information about the detected anomalies (such as the type of anomaly, the date and time of occurrence, and the scope of impact).
[0252] Step 4:
[0253] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which involves a process of selecting the optimal countermeasure for each type of anomaly by referencing a past database and a pattern library of countermeasures.
[0254] Step 5:
[0255] The server automatically generates a report based on details of detected anomalies and proposed remediation actions. The report includes details of the anomaly, the date and time of detection, proposed remediation actions, and recommended action steps. The report is created according to a standard format and may be converted to formats such as PDF.
[0256] Step 6:
[0257] The emotion engine analyzes text and voice data to recognize user emotions, identifying emotions from user input and conversations and optimizing the system's response accordingly.
[0258] Step 7:
[0259] The server adjusts the report content and notification format based on the user's emotions recognized by the emotion engine. For example, if the user is experiencing high stress, the report will include detailed explanations and prioritized solutions.
[0260] Step 8:
[0261] The server sends the generated report to the designated recipient (administrator or technician) via email. It also sends real-time notifications to the devices so that the relevant parties can quickly understand the occurrence of an abnormality and take countermeasures. The notifications include a summary of the report and a link.
[0262] Specific examples
[0263] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[0264] Type of anomaly: Sudden drop in signal strength
[0265] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[0266] In this case, the system behaves as follows:
[0267] Step 1:
[0268] The server collects log data from base station A.
[0269] Step 2:
[0270] The server preprocesses the collected log data, for example, removing incomplete data and extracting necessary information.
[0271] Step 3:
[0272] The server inputs the preprocessed log data into an anomaly detection model to detect sudden drops in signal strength.
[0273] Step 4:
[0274] The server will suggest the best course of action to address any abnormalities, namely "physical check of the antenna" and "restarting the signal repeater."
[0275] Step 5:
[0276] The server automatically generates a detailed report based on the proposed action, including data on the signal strength degradation and the steps to take.
[0277] Step 6:
[0278] The emotion engine recognizes the user's emotions, for example, recognizing that the user is in a high stress state.
[0279] Step 7:
[0280] The server adjusts the report content based on the emotions recognized by the emotion engine, adding detailed explanations and prioritized actions.
[0281] Step 8:
[0282] The server sends the generated report to the relevant parties via email, and sends real-time notifications to the terminal regarding any abnormalities and countermeasures.
[0283] This process allows for quick and accurate troubleshooting while taking into consideration the user's feelings.
[0284] Example 2
[0285] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0286] Conventional anomaly detection systems were capable of automating anomaly detection, countermeasure proposals, and report generation, but they were insufficient in taking the user's emotions into consideration. As a result, when a user is in a high-stress state or a specific psychological state, the proposed countermeasures and the report content may be inappropriate or may increase the user's stress. Therefore, an objective of the present invention is to provide a system that takes the user's emotions into consideration and optimizes the entire process from anomaly detection to countermeasure proposals, report generation, and notification.
[0287] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes means for preprocessing log data collected from the communication devices, means for detecting anomalies based on the preprocessed log data, means for proposing optimal countermeasures for the detected anomalies, means for automatically generating a report based on the proposed countermeasures, means for transmitting the generated report and a notification, and means for recognizing the user's emotions and adjusting the content of the report and the format of the notification based on the recognized emotions. This enables an anomaly detection and countermeasure proposal process that takes the user's emotions into consideration.
[0288] A "communication device" is a device that sends and receives data over a network.
[0289] "Log data" refers to data that records the operations and events of a system or communication device.
[0290] "Preprocessing" refers to processes such as data cleaning and format conversion to prepare collected log data in an analyzable form.
[0291] An "anomaly detection model" is a machine learning algorithm or other analytical method used to detect anomalies in collected data.
[0292] "Countermeasures" are proposals for appropriate actions or solutions to detected anomalies.
[0293] A "report" is a document detailing detected anomalies and their corresponding actions.
[0294] "Notification" refers to a message or alert that notifies a user or administrator of an abnormality and the appropriate countermeasure.
[0295] An "emotion engine" is a system that recognizes emotions by analyzing a user's text and voice data.
[0296] "User emotion" refers to the psychological state that the user expresses to the system, and serves as the basis for the system to make adjustments.
[0297] The present invention combines a system that preprocesses log data collected from communication devices, detects anomalies based on the preprocessed log data, proposes optimal countermeasures for the detected anomalies, automatically generates a report based on the proposed countermeasures, transmits the generated report, and sends notifications, with an emotion engine that recognizes user emotions. In this embodiment, the main functions of the system and its processing flow will be described.
[0298] Key components of the system
[0299] 1. Server
[0300] The server is the central processing device of the present invention, and collects log data from communication devices, pre-processes it, analyzes it, detects abnormalities, proposes countermeasures, and generates and notifies reports.
[0301] Machine learning algorithms (e.g., LSTM model for anomaly detection) are used for anomaly detection.
[0302] 2. Communications Equipment
[0303] The communication device is a device that transmits and receives data and provides log data to the system.
[0304] Base station A is an example.
[0305] 3. Emotion Engine
[0306] It is an engine that analyzes the user's text and voice data and recognizes emotions.
[0307] The server uses information from the emotion engine to tailor reports and notifications.
[0308] 4. Terminal
[0309] A device that allows users and administrators to access the system and receive notifications and check reports.
[0310] Hardware and software used
[0311] Data Stream: Used to obtain log data from communication devices in real time.
[0312] API endpoint: An interface for collecting data from a communication device.
[0313] Database: A storage system for temporarily storing collected data.
[0314] Anomaly detection model: A machine learning algorithm (e.g., LSTM model) to analyze the preprocessed data and detect anomalies.
[0315] Emotion engine: Software that analyzes a user's text and voice to recognize emotions.
[0316] Specific examples
[0317] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[0318] Type of anomaly: Sudden drop in signal strength
[0319] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[0320] In this case, the system operates as follows.
[0321] 1. The server collects and preprocesses log data from base station A. Preprocessing includes cleaning the data, removing incomplete data, unifying timestamps, and extracting necessary information.
[0322] 2. The preprocessed log data is fed into an anomaly detection model (e.g., LSTM model) to detect sudden drops in signal strength.
[0323] 3. The server will suggest the best course of action for this anomaly: "Physical check of antenna" and "Restart signal repeater."
[0324] 4. A detailed report is automatically generated based on the proposed action, including data on signal strength degradation and suggested steps to take.
[0325] 5. The emotion engine analyzes the user's text and voice data and, if it recognizes that the user is in a high stress state, adds detailed explanations and prioritized countermeasures to the report.
[0326] 6. Finally, the generated report is sent to the relevant parties via email, and notifications of abnormalities and countermeasures are sent to the terminal in real time.
[0327] Prompt Sentence Examples
[0328] "Based on the log data from base station A, detect anomalies (sudden drop in signal strength), suggest optimal countermeasures, and generate a report. If the user is in a high stress state, add a detailed explanation to the report."
[0329] As described above, the system of the present invention uses data collected from communication devices to effectively and quickly detect anomalies and propose countermeasures, enabling flexible responses that take user emotions into consideration.
[0330] The flow of the identification process in the second embodiment will be described with reference to FIG.
[0331] Step 1:
[0332] Collecting log data
[0333] The server collects log data from a communication device (for example, base station A).
[0334] Input: Real-time log data from communication devices
[0335] How it works: The server automatically retrieves log data at regular intervals using an API endpoint.
[0336] Output: The collected raw log data is stored in a database.
[0337] Step 2:
[0338] Preprocessing of collected log data
[0339] The server pre-processes the collected log data.
[0340] Input: Collected raw log data
[0341] How it works: The server performs data cleaning to remove incomplete data and outliers, as well as standardizing timestamps and converting them into a parsable format.
[0342] Output: Preprocessed and clean log data is generated.
[0343] Step 3:
[0344] Input to the anomaly detection model
[0345] The server inputs the preprocessed log data into the anomaly detection model.
[0346] Input: Preprocessed and clean log data
[0347] How it works: The server applies a machine learning algorithm for anomaly detection (e.g., an LSTM model) to detect anomalies in the data.
[0348] Output: Anomaly detection results (detailed information such as the type of anomaly, the date and time of occurrence, and the scope of impact) are generated.
[0349] Step 4:
[0350] Proposal of countermeasures
[0351] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model.
[0352] Input: Detailed information about the detected anomaly
[0353] How it works: The server searches through a database of past cases and a pattern library of countermeasures to find similar cases and selects the most appropriate response to the detected anomaly (e.g., "physical check of antenna" or "restart of signal repeater").
[0354] Output: A proposed solution is generated.
[0355] Step 5:
[0356] Automatic report generation
[0357] The server automatically generates a report based on detected anomalies and suggested remedial actions.
[0358] Input: Anomaly details and proposed remediation
[0359] How it works: The server creates reports using a standard format and converts them to formats such as PDF if necessary.
[0360] Output: The generated report is saved as a digital file.
[0361] Step 6:
[0362] Emotion recognition by emotion engine
[0363] The emotion engine analyzes the user's text and voice data to recognize emotions.
[0364] Input: Text or voice data entered by a user into the system.
[0365] How it works: The emotion engine performs analysis and recognizes the user's emotional state (e.g., high stress).
[0366] Output: The recognized emotional state of the user is generated as data.
[0367] Step 7:
[0368] Adjusting reports based on sentiment
[0369] The server adjusts the content of the report based on the user's emotions recognized by the emotion engine.
[0370] Input: The perceived emotional state of the user and the generated report
[0371] Action: The server adds detailed explanations and priority actions to the report (e.g. if the user is in a high stress state).
[0372] Output: A reconciled report is generated.
[0373] Step 8:
[0374] Report submission and notification
[0375] The server emails the generated reports to designated recipients and sends real-time notifications to the device.
[0376] Input: Coordinated Report and Notification Information
[0377] What it does: The server emails the report and sends a notification to the device, which includes a summary of the report and a link.
[0378] Output: The recipient receives the report and a notification appears on their device.
[0379] Through the above processing steps, the system collects and analyzes log data from communication devices, and generates and notifies optimal countermeasures and reports that take the user's emotions into consideration.
[0380] (Application example 2)
[0381] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0382] Conventional anomaly detection systems can detect anomalies and propose countermeasures, but there is a need for systems that can operate flexibly and take user emotions into account. In particular, in security services, it is essential to respond according to the user's stress level and urgency, and the challenge is to provide optimal reports and notifications based on the user's emotions.
[0383] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for preprocessing log data collected from the communication devices, means for detecting anomalies based on the preprocessed log data, means for proposing optimal countermeasures for the detected anomalies, means for automatically generating a report based on the proposed countermeasures, means for transmitting the generated report and a notification, means for recognizing the user's emotions, and means for adjusting the content of the report and the format of the notification based on the user's emotions. This enables flexible and prompt response according to the user's emotions.
[0384] A "communications device" is a device used to send and receive data over a network. Examples include routers, switches, and modems.
[0385] "Log data" refers to data that records the operation history of communication devices and systems. This data is used for anomaly detection and analysis.
[0386] "Preprocessing" refers to the process of making raw data into an analyzable form through processes such as cleaning and format conversion.
[0387] "Means for detecting anomalies" refers to algorithms or models for detecting anomalies in preprocessed log data. Machine learning models are often used.
[0388] "Means for proposing countermeasures" refers to a function that suggests appropriate solutions for detected anomalies. This generally involves referencing past data or specialized knowledge databases.
[0389] "Means for automatically generating reports" refers to a system function that automatically creates a report summarizing the details of the abnormality and countermeasures.
[0390] "Means for sending notifications" refers to the functionality for notifying users in real time of generated reports and important information. Notifications are primarily sent via email or push notifications.
[0391] "Means for recognizing emotions" refers to engines or algorithms for analyzing emotions from a user's voice or text data.
[0392] "Means for adjusting notification format" refers to the ability to dynamically change the content of notifications and reports based on the user's emotions. By taking emotions into consideration, we can provide users with an appropriate sharing method.
[0393] This invention is a system that monitors log data collected from communication devices in real time, proposes appropriate countermeasures when an abnormality is detected, automatically generates reports, and sends notifications. It also has a function to optimize the content of reports and notifications by recognizing the user's emotions.
[0394] System Configuration
[0395] The system consists of the following main components:
[0396] 1. Log data collection method
[0397] 2. Data preprocessing methods
[0398] 3. Anomaly detection methods
[0399] 4. Means of proposing countermeasures
[0400] 5. Automatic report generation means
[0401] 6. Notification Method
[0402] 7. Emotion recognition means
[0403] 8. Notification format adjustment means
[0404] Hardware and software used
[0405] Hardware: Servers, users' smartphones, communication devices (e.g., routers, switches)
[0406] Software: Python, Django, machine learning libraries (e.g., scikit-learn, TensorFlow), emotion recognition libraries, real-time notification services
[0407] Data Processing and Computation
[0408] 1. Log data collection and preprocessing:
[0409] The server collects log data from communication devices in real time via API endpoints and data streams, and preprocesses the collected log data by cleaning and formatting it so that it can be analyzed.
[0410] 2. Anomaly detection:
[0411] The pre-processed log data is then subjected to a machine learning model for anomaly detection, which monitors the log data in real time and detects deviations from normal data patterns with high accuracy.
[0412] 3. Proposed solutions:
[0413] When an anomaly is detected, the server refers to a database of past incidents and a pattern library of countermeasures to suggest the optimal countermeasure, which is dynamically adjusted based on the type of anomaly and the user's sentiment.
[0414] 4. Automatic report generation:
[0415] The server automatically generates a report based on the anomaly and the proposed remediation. The report includes details of the anomaly, the date and time it was detected, the proposed remediation, and recommended steps to take. The report is generated in a standard format and can be converted to PDF or other formats.
[0416] 5. Sending notifications:
[0417] Once generated, the report is emailed to the relevant parties and a real-time notification is sent to the device, including a summary of the report and a link to it.
[0418] 6. Emotion recognition:
[0419] The server analyzes text and voice data when a user uses the system and recognizes the user's emotions. This analysis is performed using an emotion recognition library.
[0420] 7. Notification Formatting:
[0421] Tailor the content of reports and notification format based on the perceived emotion, for example, if the user is experiencing high stress, provide a detailed explanation and immediate action plan in the report.
[0422] Specific examples
[0423] When an abnormality is detected in the log data collected from a certain communication device (base station A), for example, a sudden drop in signal strength, the procedure for reporting the abnormality is as follows.
[0424] 1. Data collection and pre-processing: The server collects log data from base station A and performs cleaning and format conversion.
[0425] 2. Anomaly detection: Based on the pre-processed data, the machine learning model detects drops in signal strength.
[0426] 3. Suggested solutions: Suggested solutions for this anomaly include "Physical check of antenna" and "Restart signal repeater".
[0427] 4. Emotion recognition: The emotion recognition engine analyzes the emotion the user feels when receiving this notification. For example, if the user feels high stress, a report will be generated with a detailed explanation and prompt action.
[0428] 5. Notification: The generated report and rapid response procedures are sent to the relevant parties.
[0429] Prompt Sentence Examples
[0430] "A suspicious individual has been detected on the live security camera feed. Due to the user's high stress level, please generate a detailed report with the following immediate steps: Recommendation: Immediate police notification steps."
[0431] The flow of the specific processing in the application example 2 will be described with reference to FIG.
[0432] Step 1:
[0433] The server collects log data from communication devices in real time. The input is the log data obtained from the communication devices. The server receives the log data from API endpoints or data streams and stores this data in local storage. The output is the collected log data.
[0434] Step 2:
[0435] The server preprocesses the collected log data. At this stage, data cleaning and format conversion are performed. The input is the collected raw log data, and specific processes are performed to remove incomplete data, unify timestamps, and extract necessary information. The output is preprocessed, clean log data.
[0436] Step 3:
[0437] The server detects anomalies using preprocessed log data. The input is the preprocessed log data and a machine learning model (e.g., scikit-learn, TensorFlow) is used. Specifically, an algorithm is run to identify data points that deviate from normal data patterns. The output is anomaly detection results that include information such as the type of anomaly, the date and time of occurrence, and the scope of impact.
[0438] Step 4:
[0439] The server proposes optimal countermeasures for detected anomalies. The input is the anomaly detection results, and it uses a database of past responses and a pattern library of countermeasures. The server extracts the most effective countermeasure according to the type of anomaly and proposes specific steps to take. The output is a list of recommended countermeasures.
[0440] Step 5:
[0441] The server automatically generates a report based on the proposed countermeasures. The input is the anomaly detection result and a list of countermeasures. Specifically, a report is generated in text format that includes details of the anomaly, the date and time of detection, the proposed countermeasures, and the recommended procedure. The output is the generated report, which is converted to PDF format or similar and saved.
[0442] Step 6:
[0443] The server runs an emotion engine to recognize the user's emotions. The input is the user's text or voice data, which is analyzed using an emotion recognition library. The output is the user's emotional state, including emotion categories such as high stress or low stress.
[0444] Step 7:
[0445] The server adjusts the report content and notification format based on the results of the emotion engine. The input is the generated report and emotion recognition results. Specifically, it adjusts the detail level and linguistic tone of the report according to the user's emotion and saves it in an appropriate format. The output is the adjusted report.
[0446] Step 8:
[0447] The server sends the final report and notifies the relevant parties. The input is the adjusted report. Specifically, the report is sent as an email and a real-time notification is sent to the terminal. The output is a notification to the relevant parties and a confirmation of receipt.
[0448] Prompt Sentence Examples
[0449] A suspicious individual has been detected during a live security camera feed. Due to the user's high stress state, please generate a detailed report with the following immediate steps: Recommendation: Immediate police reporting steps
[0450] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0451] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0452] In the above embodiment, an example in which the specific process is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific process may be performed by the smart device 14.
[0453] [Second embodiment]
[0454] FIG. 3 shows an example of the configuration of a data processing system 210 according to the second embodiment.
[0455] 3, the data processing system 210 includes the data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0456] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0457] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, and the camera 42 are also connected to the bus 52.
[0458] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.
[0459] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).
[0460] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.
[0461] Fig. 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Fig. 4, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.
[0462] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0463] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0464] In the smart glasses 214, the reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[0465] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal."
[0466] The present invention provides a system that preprocesses log data collected from communication devices, detects abnormalities based on the preprocessed log data, proposes optimal countermeasures for the detected abnormalities, automatically generates a report based on the proposed countermeasures, transmits the generated report, and sends a notification. In this embodiment, the main functions of the system and its processing flow will be described.
[0467] 1. Collect and preprocess log data:
[0468] The server collects log data from communication devices in real time, via APIs and data streams.
[0469] The collected log data is first preprocessed. Preprocessing involves cleaning the data and converting its format to make it analyzable. For example, this involves removing incomplete data, standardizing timestamps, and extracting necessary information.
[0470] 2. Anomaly detection:
[0471] The server inputs the preprocessed log data into an anomaly detection model, which includes machine learning algorithms to accurately detect anomalies that deviate from historical normal behavior patterns.
[0472] If the anomaly detection model finds an anomaly, details of the anomaly are recorded.
[0473] 3. Proposed solutions:
[0474] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which includes referencing a database of past countermeasure patterns.
[0475] The appropriate countermeasures proposed are selected based on the type of abnormality and its cause.
[0476] 4. Generate report:
[0477] The server automatically generates a formal report based on the detected anomalies and proposed remediation measures, including details of the anomaly, the date and time of detection, and proposed remediation measures.
[0478] Reports are prepared according to a standard format and may be converted into formats such as PDF.
[0479] 5. Report Distribution and Notification:
[0480] The server automatically sends generated reports to interested parties, including using an email sending function to deliver the reports to designated recipients.
[0481] It also sends notifications to the device, allowing relevant parties to be aware of any abnormalities and countermeasures in real time.
[0482] Specific examples
[0483] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[0484] Type of anomaly: Sudden drop in signal strength
[0485] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[0486] In this case, the system behaves as follows:
[0487] 1. The server collects log data from base station A and performs preprocessing.
[0488] 2. Using the preprocessed log data, an anomaly detection model detects sudden drops in signal strength.
[0489] 3. The server will suggest the best course of action for this anomaly: "Physical check of antenna" and "Restart signal repeater."
[0490] 4. A detailed report is automatically generated based on the proposed action, including data on signal strength degradation and suggested steps to take.
[0491] 5. Finally, the generated report is sent to the relevant parties via email, and notifications of abnormalities and countermeasures are sent to the terminal in real time.
[0492] This automates the entire process, from detecting a communication device fault to proposing a countermeasure, generating a report, and notifying relevant parties, reducing the human burden and enabling a quick response.
[0493] The processing flow will be explained below.
[0494] Step 1:
[0495] The server collects log data from communication devices. It automatically retrieves the latest log data at regular intervals via an API endpoint or data stream. For example, it retrieves the log data using an HTTP request and stores it in memory or a database.
[0496] Step 2:
[0497] The server preprocesses the collected log data. Specifically, it cleans the data by removing incomplete data, standardizing the timestamp format, and extracting necessary information. This preprocessing prepares the data in a format suitable for analysis.
[0498] Step 3:
[0499] The server inputs the preprocessed log data into an anomaly detection model, which uses a machine learning algorithm to detect anomalies that deviate from normal data patterns. At this time, information such as the type of anomaly, the date and time of occurrence, and the extent of the impact is output.
[0500] Step 4:
[0501] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which involves a process of selecting the optimal countermeasure for each type of anomaly by referencing a past database and a pattern library of countermeasures.
[0502] Step 5:
[0503] The server automatically generates a report based on the details of the detected anomalies and the proposed remediation measures. The report includes details of the anomaly, the date and time of detection, the proposed remediation measures, and recommended action steps. The report is generated in a format such as PDF.
[0504] Step 6:
[0505] The server then emails the generated report to the designated recipient (e.g., administrator or technician). Real-time notifications are also sent to the device, promptly informing the relevant parties of any abnormalities and countermeasures. The notifications include a summary of the report and a link.
[0506] Example 1
[0507] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[0508] Modern communications equipment is required to detect anomalies in real time, quickly propose countermeasures, and quickly share information with relevant parties. However, with conventional systems, it is difficult to automate these processes, requiring a great deal of manpower and time. Furthermore, the accuracy of anomaly detection and the appropriateness of countermeasures can be low, making efficient fault management difficult.
[0509] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[0510] In this invention, the server includes means for collecting log data from communication devices in real time, means for preprocessing the collected log data, means for inputting the preprocessed log data into an anomaly detection model to detect anomalies, means for proposing optimal countermeasures for the anomalies, means for automatically generating a report based on the proposed countermeasures, means for sending the generated report by email, and means for sending notifications to relevant parties in real time, thereby enabling real-time anomaly detection and countermeasure proposals, automated report generation, and rapid information sharing.
[0511] A "communications device" is a device that includes hardware and software for transmitting and receiving data.
[0512] "Log data" refers to recorded data relating to the operating status and events of a communication device.
[0513] "Real-time" is a concept that refers to a state in which data is collected and processed almost simultaneously as it occurs.
[0514] "Preprocessing" refers to a series of processes such as data cleaning, format standardization, and extraction of necessary information to prepare collected log data in an analyzable form.
[0515] An "anomaly detection model" is a model that uses a machine learning algorithm to detect anomalies that deviate from normal operating patterns.
[0516] "Countermeasures" refers to appropriate methods and procedures for dealing with detected abnormalities.
[0517] A "report" is a document that compiles detailed information about detected anomalies and proposed remedial actions.
[0518] "Email" is a means of sending messages and files electronically over the Internet.
[0519] "Notification" is a means of informing interested parties in real time about specific events or conditions.
[0520] The present invention is a system that preprocesses log data collected from communication devices, detects anomalies based on that data, and proposes optimal countermeasures. Furthermore, this system has the function of automatically generating reports based on the proposed countermeasures, sending the generated reports to relevant parties, and sending notifications in real time.
[0521] Hardware and software configuration:
[0522] server:
[0523] The server collects log data from communication devices in real time. This collection is done via HTTP API or WebSocket. The collected data is preprocessed on the server and input into an anomaly detection model. Machine learning algorithms such as TensorFlow and PyTorch are used for anomaly detection.
[0524] Communication equipment:
[0525] These are devices that send and receive data, including base stations and modems. These devices generate log data and send it to a server.
[0526] Device:
[0527] A device that receives notifications in real time, including PCs, tablets, smartphones, etc. Notifications are sent as push notifications from the server or emails.
[0528] Data processing and calculation:
[0529] Pretreatment:
[0530] When the server receives the log data, it cleans it, removes incomplete data, standardizes timestamps, and extracts necessary information to make the data analyzable.
[0531] Anomaly detection:
[0532] The preprocessed data is then input into an anomaly detection model, which is trained using machine learning algorithms to detect anomalies by comparing them with past normal patterns. Detailed information about detected anomalies (type of anomaly, time of occurrence, and scope of impact) is then recorded.
[0533] Suggested workaround:
[0534] The server then suggests the best course of action for any detected anomalies. It consults a database of past cases and searches for solutions based on similar cases. For example, if the signal strength drops, it suggests physically checking the antenna or restarting the repeater.
[0535] Generate a report:
[0536] A report is automatically generated based on the details of the anomaly and the proposed remedial action, and is saved in a standard format (e.g. PDF) for future reference.
[0537] Report distribution and notification:
[0538] The server will send the generated report to the relevant parties via email, and at the same time, send real-time notifications to the terminals about any abnormalities and suggested countermeasures, allowing the relevant parties to take immediate action.
[0539] Examples:
[0540] For example, it is assumed that the following abnormality is detected based on log data collected from a certain communication device (base station).
[0541] Type of anomaly: Sudden drop in signal strength
[0542] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[0543] In this case, the system operates as follows.
[0544] 1. The server collects log data from the communication devices and performs preprocessing.
[0545] 2. The preprocessed log data is input into an anomaly detection model using a machine learning algorithm to detect sudden drops in signal strength.
[0546] 3. The server will suggest the following countermeasures for the anomaly: "Physical check of the antenna" and "Restart of the signal repeater."
[0547] 4. Based on the proposed countermeasures, a report is automatically generated detailing the anomaly and the countermeasures.
[0548] 5. The server sends a report to the relevant parties via email, and simultaneously sends real-time notifications to the terminals regarding the occurrence of abnormalities and countermeasures.
[0549] Example prompt sentence:
[0550] "Please check what anomalies were detected and what countermeasures were proposed based on the log data collected from this communication device."
[0551] This automates the process from detecting a communication device fault to proposing a countermeasure, generating a report, and notifying relevant parties, enabling a fast and efficient response to anomalies.
[0552] The flow of the identification process in the first embodiment will be described with reference to FIG.
[0553] Program processing flow
[0554] Step 1: Collect log data
[0555] The server collects log data from the communication devices in real time by sending requests to the communication devices at regular intervals using HTTP API or WebSocket to obtain the latest log data.
[0556] Input: Raw log data obtained from communication devices
[0557] Output: Collected raw log data stored on the server
[0558] Specific operation: The server periodically accesses the communication device, receives log data, and stores it in a database.
[0559] Step 2: Preprocessing the log data
[0560] The server preprocesses the collected log data, cleaning the data to remove incomplete data and filter unnecessary data, standardizing the timestamp format, and extracting necessary information.
[0561] Input: Raw log data stored on the server
[0562] Output: Preprocessed log data
[0563] What happens: The server performs data cleaning, unifies timestamps, and applies algorithms to extract the required information.
[0564] Step 3: Detect anomalies
[0565] The server inputs the preprocessed log data into an anomaly detection model, which uses machine learning algorithms to detect deviations from normal behavior patterns.
[0566] Input: Preprocessed log data
[0567] Output: Log data in which an anomaly was detected and its detailed information
[0568] Specific operation: The server inputs preprocessed log data into an anomaly detection model built using TensorFlow and PyTorch, and determines whether or not there are any anomalies.
[0569] Step 4: Propose a solution
[0570] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, and searches for countermeasures based on similar cases by referencing a past database.
[0571] Input: Log data in which an anomaly was detected and detailed information
[0572] Output: Proposed action
[0573] Specific operation: Based on the type of abnormality and its cause, the server selects the most appropriate countermeasure from a pre-prepared database.
[0574] Step 5: Generate the report
[0575] The server automatically generates a report based on the details of the anomaly and the proposed countermeasures, including details of the anomaly, the date and time of detection, and the proposed countermeasures.
[0576] Input: Anomaly details and suggested remediation
[0577] Output: Automatically generated report (e.g. PDF format)
[0578] Specific operation: The server combines the details of the anomaly and the countermeasures, generates a report based on a template, and converts it into PDF format.
[0579] Step 6: Report distribution and notification
[0580] The server sends the generated report to the relevant parties via email, and simultaneously sends real-time notifications of abnormal occurrences and countermeasures to the relevant parties' terminals.
[0581] Input: Automatically generated report and notification information
[0582] Output: Reports sent by email and notifications sent to terminal
[0583] Specific operation: The server uses the SMTP protocol to send the report by email, and sends notifications to the relevant parties' terminals via the Push notification service.
[0584] These steps automate a series of processes, from collecting log data from communication devices to detecting anomalies, proposing countermeasures, generating reports, and distributing and notifying them.
[0585] (Application example 1)
[0586] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[0587] There is a need for a method to manage the operation logs of robots in factories and respond quickly and accurately when an abnormality occurs. Currently, the detection of abnormalities and the proposal of countermeasures are often done manually, which takes time and effort. In addition, the creation of reports is a significant burden, so an automated system is needed to improve efficiency.
[0588] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[0589] In this invention, the server includes means for preprocessing log data collected from the communication devices, means for detecting anomalies based on the preprocessed log data, means for proposing optimal countermeasures for the detected anomalies, means for automatically generating a report based on the proposed countermeasures, means for transmitting the generated report and sending a notification, means for monitoring operation logs of robots in the factory in real time, means for using a machine learning algorithm to detect anomalies with high accuracy using the preprocessed log data, and means for proposing optimal countermeasures after detecting an anomaly, automatically generating a report, and notifying relevant parties. This automates the entire process from detecting anomalies in robots in the factory to proposing countermeasures, generating a report, and notifying relevant parties, thereby reducing the human burden and enabling rapid responses.
[0590] A "communication device" is a device for data communication, and is used to collect log data from factory robots and sensors.
[0591] "Log data" refers to data including operation history and event information recorded by factory robots and communication devices.
[0592] "Preprocessing" refers to the process of cleaning and formatting the collected log data to make it analyzable.
[0593] "Abnormal" refers to behavior or errors that deviate from normal operating patterns, and in the case of factory robots, this includes unexpected behavior or malfunctions.
[0594] An "anomaly detection model" is an algorithm or system that uses machine learning and statistical models to detect anomalies in collected log data.
[0595] "Countermeasures" are specific measures or solutions implemented in response to detected abnormalities, and in the case of factory robots, these include restarting the robot or replacing parts.
[0596] A "report" is an official document summarizing detected anomalies and proposed countermeasures, and is used to share information with relevant parties.
[0597] The "server" is a central device that stores data, pre-processes it, detects anomalies, proposes countermeasures, generates reports, and sends notifications.
[0598] A "machine learning algorithm" is a computational method for learning patterns from large amounts of data and detecting and predicting anomalies.
[0599] "Notifications" are messages or alerts that inform relevant parties in real time about abnormalities and countermeasures.
[0600] "Real-time" refers to reacting and processing events and data immediately at the moment they occur.
[0601] This invention provides a system that monitors the operation logs of factory robots in real time, proposes optimal countermeasures when an abnormality is detected, automatically generates a report, and notifies relevant parties. A specific method for realizing this system is described below.
[0602] Hardware and software used
[0603] Hardware
[0604] Factory robot: an automated device placed on a production line
[0605] Sensing device: Collects robot movement data
[0606] Server: Performs data preprocessing, anomaly detection, countermeasure proposals, report generation and notifications
[0607] software
[0608] Log collection API: Collect operation logs from factory robots in real time
[0609] Data preprocessing tools: cleaning and formatting data (e.g., Python's Pandas library)
[0610] Anomaly detection algorithm: Machine learning model (e.g., PyCaret)
[0611] Countermeasure proposal system: Refer to past database
[0612] Report generation tools: PDF generation (e.g. reportlab)
[0613] Notification system: Email or push notification (e.g. SMTP server)
[0614] System Operation Overview
[0615] 1. Collecting and Preprocessing Log Data
[0616] The server uses a log collection API to collect operation logs from the factory robots in real time, and then uses a data preprocessing tool to clean and convert the collected data into an analyzable format.
[0617] 2. Anomaly detection
[0618] The server inputs the preprocessed log data into a machine learning model to detect anomalies with high accuracy, and when an anomaly is detected, detailed information about it is recorded.
[0619] 3. Proposal of countermeasures
[0620] The server proposes optimal countermeasures for detected anomalies by referencing a past database and existing countermeasure patterns.
[0621] 4. Generate reports
[0622] Based on the proposed countermeasures, the server automatically generates an official report in PDF format, including details of the anomaly, the date and time of detection, and the proposed countermeasures.
[0623] 5. Notification sending
[0624] The generated reports are automatically sent to the relevant parties by the server, and notifications are also sent in real time to smartphones and monitoring devices within the factory.
[0625] Specific examples
[0626] For example, consider a situation where factory robot A suddenly stops performing its designated operation. The server receives the operation logs collected from robot A in real time, and a pre-processing tool cleans and converts the data. The machine learning algorithm then detects the anomaly and suggests countermeasures: "restart robot A" and "physical inspection of the sensor." Based on this, a detailed report is automatically generated and distributed to relevant parties via email, and a notification of the anomaly is sent to the device in real time.
[0627] Prompt Sentence Examples
[0628] "Please apply an application to factory robots that preprocesses log data collected from communication devices, detects abnormalities, proposes optimal countermeasures, generates reports and sends notifications. This application will monitor the robot's operation logs in real time, detect abnormalities, propose countermeasures, automatically generate reports, and send notifications."
[0629] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[0630] Step 1:
[0631] The server uses a log collection API to collect operation logs from the factory robots in real time. It receives the factory robot log data as input and stores it in the server's storage. The output is raw log data for preprocessing.
[0632] Step 2:
[0633] The server uses a data preprocessing tool to clean the collected log data and convert its format. Specifically, it removes incomplete data, standardizes timestamps, and extracts necessary information. The input is the raw log data obtained in step 1, and the output is the preprocessed, clean data.
[0634] Step 3:
[0635] The server inputs the preprocessed log data into an anomaly detection algorithm (machine learning model). The server compares it with past normal behavior patterns to detect whether there are any anomalies with high accuracy. The input is preprocessed clean data, and the output is the anomaly detection results and detailed information about the anomaly.
[0636] Step 4:
[0637] The server proposes optimal countermeasures for detected anomalies. Here, it refers to a past database and existing countermeasure patterns to select an appropriate method based on the type and cause of the anomaly. The input is the anomaly detection result, and the output is a proposal of specific countermeasures.
[0638] Step 5:
[0639] The server automatically generates a report based on the proposed countermeasures. The report includes details of the anomaly, the date and time of detection, the proposed countermeasures, and procedures. A report generation tool (PDF generation tool) is used for generation. The input is the proposed countermeasures, and the output is an official report.
[0640] Step 6:
[0641] The server automatically sends the generated report to the relevant parties. The relevant parties are notified by email and also by sending a notification to their terminal. Email and push notifications are sent using a notification system. The input is the official report, and the output is a notification of completion of transmission and a notification to the relevant parties.
[0642] Step 7:
[0643] The user checks the received notifications and reports and takes necessary actions. The input is the received notifications and reports, and the output is the specific action taken by the user.
[0644] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.
[0645] The present invention combines a system that preprocesses log data collected from communication devices, detects anomalies based on the preprocessed log data, proposes optimal countermeasures for the detected anomalies, automatically generates a report based on the proposed countermeasures, transmits the generated report, and sends notifications, with an emotion engine that recognizes user emotions. In this embodiment, the main functions of the system and its processing flow will be described.
[0646] 1. Collecting and pre-processing log data:
[0647] The server collects log data from communication devices in real time, automatically obtaining the latest log data at regular intervals via API endpoints or data streams.
[0648] The collected log data is first preprocessed. Preprocessing involves cleaning the data and converting its format to make it analyzable. For example, this involves removing incomplete data, standardizing timestamps, and extracting necessary information.
[0649] 2. Anomaly detection:
[0650] The server inputs the preprocessed log data into an anomaly detection model, which uses machine learning algorithms to accurately detect anomalies that deviate from normal data patterns. Detailed information such as the type of anomaly, the date and time of occurrence, and the scope of impact is recorded.
[0651] 3. Proposed solutions:
[0652] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which involves a process of selecting the optimal countermeasure for each type of anomaly by referencing a past database and a pattern library of countermeasures.
[0653] 4. Generate report:
[0654] The server automatically generates a report based on the detected anomalies and proposed remediation measures. The report includes details of the anomaly, the date and time of detection, the proposed remediation measures, and recommended action steps. The report is created according to a standard format and may be converted to a format such as PDF.
[0655] 5. Report Distribution and Notification:
[0656] The server sends the generated report to the designated recipient (administrator or technician) via email. Real-time notifications are also sent to the device, allowing relevant parties to quickly understand the occurrence of an abnormality and take appropriate action. Notifications include a summary of the report and a link.
[0657] 6. Emotion Engine in Action:
[0658] The emotion engine is a function for recognizing the user's emotions. It analyzes text and voice data when the user uses the system and recognizes the user's emotions.
[0659] The server adjusts the report content and notification format based on the user's emotions recognized by the emotion engine. For example, if the user is experiencing high stress, the report will include detailed explanations and prioritized solutions.
[0660] The emotion engine also further optimizes the suggested response based on the user's emotions. For example, if the user is calm, it can suggest a response that prioritizes speed.
[0661] Specific examples
[0662] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[0663] Type of anomaly: Sudden drop in signal strength
[0664] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[0665] In this case, the system behaves as follows:
[0666] 1. The server collects log data from base station A and performs preprocessing.
[0667] 2. Using the preprocessed log data, an anomaly detection model detects sudden drops in signal strength.
[0668] 3. The server will suggest the best course of action for this anomaly: "Physical check of antenna" and "Restart signal repeater."
[0669] 4. A detailed report is automatically generated based on the proposed action, including data on signal strength degradation and suggested steps to take.
[0670] 5. If the emotion engine identifies the user's emotions as high stress, a detailed explanation and prioritized actions will be added to the report.
[0671] 6. Finally, the generated report is sent to the relevant parties via email, and notifications of abnormalities and countermeasures are sent to the terminal in real time.
[0672] This enables the system to operate in a way that takes the user's emotions into account, further optimizing the entire process from fault detection to proposing countermeasures, generating reports, and notifying relevant parties.
[0673] The processing flow will be explained below.
[0674] Step 1:
[0675] The server collects log data from communication devices and automatically retrieves the latest log data at regular intervals via API endpoints or data streams.
[0676] Step 2:
[0677] The server preprocesses the collected log data by cleaning and formatting the data, removing incomplete data, standardizing the timestamp format, extracting necessary information, and preparing the data in a format suitable for analysis.
[0678] Step 3:
[0679] The server inputs the preprocessed log data into an anomaly detection model, which uses machine learning algorithms to accurately detect anomalies that deviate from normal data patterns. It then records detailed information about the detected anomalies (such as the type of anomaly, the date and time of occurrence, and the scope of impact).
[0680] Step 4:
[0681] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which involves a process of selecting the optimal countermeasure for each type of anomaly by referencing a past database and a pattern library of countermeasures.
[0682] Step 5:
[0683] The server automatically generates a report based on details of detected anomalies and proposed remediation actions. The report includes details of the anomaly, the date and time of detection, proposed remediation actions, and recommended action steps. The report is created according to a standard format and may be converted to formats such as PDF.
[0684] Step 6:
[0685] The emotion engine analyzes text and voice data to recognize user emotions, identifying emotions from user input and conversations and optimizing the system's response accordingly.
[0686] Step 7:
[0687] The server adjusts the report content and notification format based on the user's emotions recognized by the emotion engine. For example, if the user is experiencing high stress, the report will include detailed explanations and prioritized solutions.
[0688] Step 8:
[0689] The server sends the generated report to the designated recipient (administrator or technician) via email. It also sends real-time notifications to the devices so that the relevant parties can quickly understand the occurrence of an abnormality and take countermeasures. The notifications include a summary of the report and a link.
[0690] Specific examples
[0691] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[0692] Type of anomaly: Sudden drop in signal strength
[0693] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[0694] In this case, the system behaves as follows:
[0695] Step 1:
[0696] The server collects log data from base station A.
[0697] Step 2:
[0698] The server preprocesses the collected log data, for example, removing incomplete data and extracting necessary information.
[0699] Step 3:
[0700] The server inputs the preprocessed log data into an anomaly detection model to detect sudden drops in signal strength.
[0701] Step 4:
[0702] The server will suggest the best course of action to address any abnormalities, namely "physical check of the antenna" and "restarting the signal repeater."
[0703] Step 5:
[0704] The server automatically generates a detailed report based on the proposed action, including data on the signal strength degradation and the steps to take.
[0705] Step 6:
[0706] The emotion engine recognizes the user's emotions, for example, recognizing that the user is in a high stress state.
[0707] Step 7:
[0708] The server adjusts the report content based on the emotions recognized by the emotion engine, adding detailed explanations and prioritized actions.
[0709] Step 8:
[0710] The server sends the generated report to the relevant parties via email, and sends real-time notifications to the terminal regarding any abnormalities and countermeasures.
[0711] This process allows for quick and accurate troubleshooting while taking into consideration the user's feelings.
[0712] Example 2
[0713] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[0714] Conventional anomaly detection systems were capable of automating anomaly detection, countermeasure proposals, and report generation, but they were insufficient in taking the user's emotions into consideration. As a result, when a user is in a high-stress state or a specific psychological state, the proposed countermeasures and the report content may be inappropriate or may increase the user's stress. Therefore, an objective of the present invention is to provide a system that takes the user's emotions into consideration and optimizes the entire process from anomaly detection to countermeasure proposals, report generation, and notification.
[0715] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes means for preprocessing log data collected from the communication devices, means for detecting anomalies based on the preprocessed log data, means for proposing optimal countermeasures for the detected anomalies, means for automatically generating a report based on the proposed countermeasures, means for transmitting the generated report and a notification, and means for recognizing the user's emotions and adjusting the content of the report and the format of the notification based on the recognized emotions. This enables an anomaly detection and countermeasure proposal process that takes the user's emotions into consideration.
[0716] A "communication device" is a device that sends and receives data over a network.
[0717] "Log data" refers to data that records the operations and events of a system or communication device.
[0718] "Preprocessing" refers to processes such as data cleaning and format conversion to prepare collected log data in an analyzable form.
[0719] An "anomaly detection model" is a machine learning algorithm or other analytical method used to detect anomalies in collected data.
[0720] "Countermeasures" are proposals for appropriate actions or solutions to detected anomalies.
[0721] A "report" is a document detailing detected anomalies and their corresponding actions.
[0722] "Notification" refers to a message or alert that notifies a user or administrator of an abnormality and the appropriate countermeasure.
[0723] An "emotion engine" is a system that recognizes emotions by analyzing a user's text and voice data.
[0724] "User emotion" refers to the psychological state that the user expresses to the system, and serves as the basis for the system to make adjustments.
[0725] The present invention combines a system that preprocesses log data collected from communication devices, detects anomalies based on the preprocessed log data, proposes optimal countermeasures for the detected anomalies, automatically generates a report based on the proposed countermeasures, transmits the generated report, and sends notifications, with an emotion engine that recognizes user emotions. In this embodiment, the main functions of the system and its processing flow will be described.
[0726] Key components of the system
[0727] 1. Server
[0728] The server is the central processing device of the present invention, and collects log data from communication devices, pre-processes it, analyzes it, detects abnormalities, proposes countermeasures, and generates and notifies reports.
[0729] Machine learning algorithms (e.g., LSTM model for anomaly detection) are used for anomaly detection.
[0730] 2. Communications Equipment
[0731] The communication device is a device that transmits and receives data and provides log data to the system.
[0732] Base station A is an example.
[0733] 3. Emotion Engine
[0734] It is an engine that analyzes the user's text and voice data and recognizes emotions.
[0735] The server uses information from the emotion engine to tailor reports and notifications.
[0736] 4. Terminal
[0737] A device that allows users and administrators to access the system and receive notifications and check reports.
[0738] Hardware and software used
[0739] Data Stream: Used to obtain log data from communication devices in real time.
[0740] API endpoint: An interface for collecting data from a communication device.
[0741] Database: A storage system for temporarily storing collected data.
[0742] Anomaly detection model: A machine learning algorithm (e.g., LSTM model) to analyze the preprocessed data and detect anomalies.
[0743] Emotion engine: Software that analyzes a user's text and voice to recognize emotions.
[0744] Specific examples
[0745] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[0746] Type of anomaly: Sudden drop in signal strength
[0747] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[0748] In this case, the system operates as follows.
[0749] 1. The server collects and preprocesses log data from base station A. Preprocessing includes cleaning the data, removing incomplete data, unifying timestamps, and extracting necessary information.
[0750] 2. The preprocessed log data is fed into an anomaly detection model (e.g., LSTM model) to detect sudden drops in signal strength.
[0751] 3. The server will suggest the best course of action for this anomaly: "Physical check of antenna" and "Restart signal repeater."
[0752] 4. A detailed report is automatically generated based on the proposed action, including data on signal strength degradation and suggested steps to take.
[0753] 5. The emotion engine analyzes the user's text and voice data and, if it recognizes that the user is in a high stress state, adds detailed explanations and prioritized countermeasures to the report.
[0754] 6. Finally, the generated report is sent to the relevant parties via email, and notifications of abnormalities and countermeasures are sent to the terminal in real time.
[0755] Prompt Sentence Examples
[0756] "Based on the log data from base station A, detect anomalies (sudden drop in signal strength), suggest optimal countermeasures, and generate a report. If the user is in a high stress state, add a detailed explanation to the report."
[0757] As described above, the system of the present invention uses data collected from communication devices to effectively and quickly detect anomalies and propose countermeasures, enabling flexible responses that take user emotions into consideration.
[0758] The flow of the identification process in the second embodiment will be described with reference to FIG.
[0759] Step 1:
[0760] Collecting log data
[0761] The server collects log data from a communication device (for example, base station A).
[0762] Input: Real-time log data from communication devices
[0763] How it works: The server automatically retrieves log data at regular intervals using an API endpoint.
[0764] Output: The collected raw log data is stored in a database.
[0765] Step 2:
[0766] Preprocessing of collected log data
[0767] The server pre-processes the collected log data.
[0768] Input: Collected raw log data
[0769] How it works: The server performs data cleaning to remove incomplete data and outliers, as well as standardizing timestamps and converting them into a parsable format.
[0770] Output: Preprocessed and clean log data is generated.
[0771] Step 3:
[0772] Input to the anomaly detection model
[0773] The server inputs the preprocessed log data into the anomaly detection model.
[0774] Input: Preprocessed and clean log data
[0775] How it works: The server applies a machine learning algorithm for anomaly detection (e.g., an LSTM model) to detect anomalies in the data.
[0776] Output: Anomaly detection results (detailed information such as the type of anomaly, the date and time of occurrence, and the scope of impact) are generated.
[0777] Step 4:
[0778] Proposal of countermeasures
[0779] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model.
[0780] Input: Detailed information about the detected anomaly
[0781] How it works: The server searches through a database of past cases and a pattern library of countermeasures to find similar cases and selects the most appropriate response to the detected anomaly (e.g., "physical check of antenna" or "restart of signal repeater").
[0782] Output: A proposed solution is generated.
[0783] Step 5:
[0784] Automatic report generation
[0785] The server automatically generates a report based on detected anomalies and suggested remedial actions.
[0786] Input: Anomaly details and proposed remediation
[0787] How it works: The server creates reports using a standard format and converts them to formats such as PDF if necessary.
[0788] Output: The generated report is saved as a digital file.
[0789] Step 6:
[0790] Emotion recognition by emotion engine
[0791] The emotion engine analyzes the user's text and voice data to recognize emotions.
[0792] Input: Text or voice data entered by a user into the system.
[0793] How it works: The emotion engine performs analysis and recognizes the user's emotional state (e.g., high stress).
[0794] Output: The recognized emotional state of the user is generated as data.
[0795] Step 7:
[0796] Adjusting reports based on sentiment
[0797] The server adjusts the content of the report based on the user's emotions recognized by the emotion engine.
[0798] Input: The perceived emotional state of the user and the generated report
[0799] Action: The server adds detailed explanations and priority actions to the report (e.g. if the user is in a high stress state).
[0800] Output: A reconciled report is generated.
[0801] Step 8:
[0802] Report submission and notification
[0803] The server emails the generated reports to designated recipients and sends real-time notifications to the device.
[0804] Input: Coordinated Report and Notification Information
[0805] What it does: The server emails the report and sends a notification to the device, which includes a summary of the report and a link.
[0806] Output: The recipient receives the report and a notification appears on their device.
[0807] Through the above processing steps, the system collects and analyzes log data from communication devices, and generates and notifies optimal countermeasures and reports that take the user's emotions into consideration.
[0808] (Application example 2)
[0809] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[0810] Conventional anomaly detection systems can detect anomalies and propose countermeasures, but there is a need for systems that can operate flexibly and take user emotions into account. In particular, in security services, it is essential to respond according to the user's stress level and urgency, and the challenge is to provide optimal reports and notifications based on the user's emotions.
[0811] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for preprocessing log data collected from the communication devices, means for detecting anomalies based on the preprocessed log data, means for proposing optimal countermeasures for the detected anomalies, means for automatically generating a report based on the proposed countermeasures, means for transmitting the generated report and a notification, means for recognizing the user's emotions, and means for adjusting the content of the report and the format of the notification based on the user's emotions. This enables flexible and prompt response according to the user's emotions.
[0812] A "communications device" is a device used to send and receive data over a network. Examples include routers, switches, and modems.
[0813] "Log data" refers to data that records the operation history of communication devices and systems. This data is used for anomaly detection and analysis.
[0814] "Preprocessing" refers to the process of making raw data into an analyzable form through processes such as cleaning and format conversion.
[0815] "Means for detecting anomalies" refers to algorithms or models for detecting anomalies in preprocessed log data. Machine learning models are often used.
[0816] "Means for proposing countermeasures" refers to a function that suggests appropriate solutions for detected anomalies. This generally involves referencing past data or specialized knowledge databases.
[0817] "Means for automatically generating reports" refers to a system function that automatically creates a report summarizing the details of the abnormality and countermeasures.
[0818] "Means for sending notifications" refers to the functionality for notifying users in real time of generated reports and important information. Notifications are primarily sent via email or push notifications.
[0819] "Means for recognizing emotions" refers to engines or algorithms for analyzing emotions from a user's voice or text data.
[0820] "Means for adjusting notification format" refers to the ability to dynamically change the content of notifications and reports based on the user's emotions. By taking emotions into consideration, we can provide users with an appropriate sharing method.
[0821] This invention is a system that monitors log data collected from communication devices in real time, proposes appropriate countermeasures when an abnormality is detected, automatically generates reports, and sends notifications. It also has a function to optimize the content of reports and notifications by recognizing the user's emotions.
[0822] System Configuration
[0823] The system consists of the following main components:
[0824] 1. Log data collection method
[0825] 2. Data preprocessing methods
[0826] 3. Anomaly detection methods
[0827] 4. Means of proposing countermeasures
[0828] 5. Automatic report generation means
[0829] 6. Notification Method
[0830] 7. Emotion recognition means
[0831] 8. Notification format adjustment means
[0832] Hardware and software used
[0833] Hardware: Servers, users' smartphones, communication devices (e.g., routers, switches)
[0834] Software: Python, Django, machine learning libraries (e.g., scikit-learn, TensorFlow), emotion recognition libraries, real-time notification services
[0835] Data Processing and Computation
[0836] 1. Log data collection and preprocessing:
[0837] The server collects log data from communication devices in real time via API endpoints and data streams, and preprocesses the collected log data by cleaning and formatting it so that it can be analyzed.
[0838] 2. Anomaly detection:
[0839] The pre-processed log data is then subjected to a machine learning model for anomaly detection, which monitors the log data in real time and detects deviations from normal data patterns with high accuracy.
[0840] 3. Proposed solutions:
[0841] When an anomaly is detected, the server refers to a database of past incidents and a pattern library of countermeasures to suggest the optimal countermeasure, which is dynamically adjusted based on the type of anomaly and the user's sentiment.
[0842] 4. Automatic report generation:
[0843] The server automatically generates a report based on the anomaly and the proposed remediation. The report includes details of the anomaly, the date and time it was detected, the proposed remediation, and recommended steps to take. The report is generated in a standard format and can be converted to PDF or other formats.
[0844] 5. Sending notifications:
[0845] Once generated, the report is emailed to the relevant parties and a real-time notification is sent to the device, including a summary of the report and a link to it.
[0846] 6. Emotion recognition:
[0847] The server analyzes text and voice data when a user uses the system and recognizes the user's emotions. This analysis is performed using an emotion recognition library.
[0848] 7. Notification Formatting:
[0849] Tailor the content of reports and notification format based on the perceived emotion, for example, if the user is experiencing high stress, provide a detailed explanation and immediate action plan in the report.
[0850] Specific examples
[0851] When an abnormality is detected in the log data collected from a certain communication device (base station A), for example, a sudden drop in signal strength, the procedure for reporting the abnormality is as follows.
[0852] 1. Data collection and pre-processing: The server collects log data from base station A and performs cleaning and format conversion.
[0853] 2. Anomaly detection: Based on the pre-processed data, the machine learning model detects drops in signal strength.
[0854] 3. Suggested solutions: Suggested solutions for this anomaly include "Physical check of antenna" and "Restart signal repeater".
[0855] 4. Emotion recognition: The emotion recognition engine analyzes the emotion the user feels when receiving this notification. For example, if the user feels high stress, a report will be generated with a detailed explanation and prompt action.
[0856] 5. Notification: The generated report and rapid response procedures are sent to the relevant parties.
[0857] Prompt Sentence Examples
[0858] "A suspicious individual has been detected on the live security camera feed. Due to the user's high stress level, please generate a detailed report with the following immediate steps: Recommendation: Immediate police notification steps."
[0859] The flow of the specific processing in the application example 2 will be described with reference to FIG.
[0860] Step 1:
[0861] The server collects log data from communication devices in real time. The input is the log data obtained from the communication devices. The server receives the log data from API endpoints or data streams and stores this data in local storage. The output is the collected log data.
[0862] Step 2:
[0863] The server preprocesses the collected log data. At this stage, data cleaning and format conversion are performed. The input is the collected raw log data, and specific processes are performed to remove incomplete data, unify timestamps, and extract necessary information. The output is preprocessed, clean log data.
[0864] Step 3:
[0865] The server detects anomalies using preprocessed log data. The input is the preprocessed log data and a machine learning model (e.g., scikit-learn, TensorFlow) is used. Specifically, an algorithm is run to identify data points that deviate from normal data patterns. The output is anomaly detection results that include information such as the type of anomaly, the date and time of occurrence, and the scope of impact.
[0866] Step 4:
[0867] The server proposes optimal countermeasures for detected anomalies. The input is the anomaly detection results, and it uses a database of past responses and a pattern library of countermeasures. The server extracts the most effective countermeasure according to the type of anomaly and proposes specific steps to take. The output is a list of recommended countermeasures.
[0868] Step 5:
[0869] The server automatically generates a report based on the proposed countermeasures. The input is the anomaly detection result and a list of countermeasures. Specifically, a report is generated in text format that includes details of the anomaly, the date and time of detection, the proposed countermeasures, and the recommended procedure. The output is the generated report, which is converted to PDF format or similar and saved.
[0870] Step 6:
[0871] The server runs an emotion engine to recognize the user's emotions. The input is the user's text or voice data, which is analyzed using an emotion recognition library. The output is the user's emotional state, including emotion categories such as high stress or low stress.
[0872] Step 7:
[0873] The server adjusts the report content and notification format based on the results of the emotion engine. The input is the generated report and emotion recognition results. Specifically, it adjusts the detail level and linguistic tone of the report according to the user's emotion and saves it in an appropriate format. The output is the adjusted report.
[0874] Step 8:
[0875] The server sends the final report and notifies the relevant parties. The input is the adjusted report. Specifically, the report is sent as an email and a real-time notification is sent to the terminal. The output is a notification to the relevant parties and a confirmation of receipt.
[0876] Prompt Sentence Examples
[0877] A suspicious individual has been detected during a live security camera feed. Due to the user's high stress state, please generate a detailed report with the following immediate steps: Recommendation: Immediate police reporting steps
[0878] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0879] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0880] In the above embodiment, an example in which the specific processing is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the smart glasses 214.
[0881] [Third embodiment]
[0882] FIG. 5 shows an example of the configuration of a data processing system 310 according to the third embodiment.
[0883] 5, the data processing system 310 includes the data processing device 12 and a headset type terminal 314. An example of the data processing device 12 is a server.
[0884] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0885] The headset type terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a display 343. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the display 343 are also connected to the bus 52.
[0886] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.
[0887] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).
[0888] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.
[0889] Fig. 6 shows an example of the main functions of the data processing device 12 and the headset type terminal 314. As shown in Fig. 6, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.
[0890] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0891] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0892] In the headset type terminal 314, a reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[0893] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the headset type terminal 314 will be referred to as the "terminal."
[0894] The present invention provides a system that preprocesses log data collected from communication devices, detects abnormalities based on the preprocessed log data, proposes optimal countermeasures for the detected abnormalities, automatically generates a report based on the proposed countermeasures, transmits the generated report, and sends a notification. In this embodiment, the main functions of the system and its processing flow will be described.
[0895] 1. Collect and preprocess log data:
[0896] The server collects log data from communication devices in real time, via APIs and data streams.
[0897] The collected log data is first preprocessed. Preprocessing involves cleaning the data and converting its format to make it analyzable. For example, this involves removing incomplete data, standardizing timestamps, and extracting necessary information.
[0898] 2. Anomaly detection:
[0899] The server inputs the preprocessed log data into an anomaly detection model, which includes machine learning algorithms to accurately detect anomalies that deviate from historical normal behavior patterns.
[0900] If the anomaly detection model finds an anomaly, details of the anomaly are recorded.
[0901] 3. Proposed solutions:
[0902] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which includes referencing a database of past countermeasure patterns.
[0903] The appropriate countermeasures proposed are selected based on the type of abnormality and its cause.
[0904] 4. Generate report:
[0905] The server automatically generates a formal report based on the detected anomalies and proposed remediation measures, including details of the anomaly, the date and time of detection, and proposed remediation measures.
[0906] Reports are prepared according to a standard format and may be converted into formats such as PDF.
[0907] 5. Report Distribution and Notification:
[0908] The server automatically sends generated reports to interested parties, including using an email sending function to deliver the reports to designated recipients.
[0909] It also sends notifications to the device, allowing relevant parties to be aware of any abnormalities and countermeasures in real time.
[0910] Specific examples
[0911] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[0912] Type of anomaly: Sudden drop in signal strength
[0913] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[0914] In this case, the system behaves as follows:
[0915] 1. The server collects log data from base station A and performs preprocessing.
[0916] 2. Using the preprocessed log data, an anomaly detection model detects sudden drops in signal strength.
[0917] 3. The server will suggest the best course of action for this anomaly: "Physical check of antenna" and "Restart signal repeater."
[0918] 4. A detailed report is automatically generated based on the proposed action, including data on signal strength degradation and suggested steps to take.
[0919] 5. Finally, the generated report is sent to the relevant parties via email, and notifications of abnormalities and countermeasures are sent to the terminal in real time.
[0920] This automates the entire process, from detecting a communication device fault to proposing a countermeasure, generating a report, and notifying relevant parties, reducing the human burden and enabling a quick response.
[0921] The processing flow will be explained below.
[0922] Step 1:
[0923] The server collects log data from communication devices. It automatically retrieves the latest log data at regular intervals via an API endpoint or data stream. For example, it retrieves the log data using an HTTP request and stores it in memory or a database.
[0924] Step 2:
[0925] The server preprocesses the collected log data. Specifically, it cleans the data by removing incomplete data, standardizing the timestamp format, and extracting necessary information. This preprocessing prepares the data in a format suitable for analysis.
[0926] Step 3:
[0927] The server inputs the preprocessed log data into an anomaly detection model, which uses a machine learning algorithm to detect anomalies that deviate from normal data patterns. At this time, information such as the type of anomaly, the date and time of occurrence, and the extent of the impact is output.
[0928] Step 4:
[0929] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which involves a process of selecting the optimal countermeasure for each type of anomaly by referencing a past database and a pattern library of countermeasures.
[0930] Step 5:
[0931] The server automatically generates a report based on the details of the detected anomalies and the proposed remediation measures. The report includes details of the anomaly, the date and time of detection, the proposed remediation measures, and recommended action steps. The report is generated in a format such as PDF.
[0932] Step 6:
[0933] The server then emails the generated report to the designated recipient (e.g., administrator or technician). Real-time notifications are also sent to the device, promptly informing the relevant parties of any abnormalities and countermeasures. The notifications include a summary of the report and a link.
[0934] Example 1
[0935] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[0936] Modern communications equipment is required to detect anomalies in real time, quickly propose countermeasures, and quickly share information with relevant parties. However, with conventional systems, it is difficult to automate these processes, requiring a great deal of manpower and time. Furthermore, the accuracy of anomaly detection and the appropriateness of countermeasures can be low, making efficient fault management difficult.
[0937] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[0938] In this invention, the server includes means for collecting log data from communication devices in real time, means for preprocessing the collected log data, means for inputting the preprocessed log data into an anomaly detection model to detect anomalies, means for proposing optimal countermeasures for the anomalies, means for automatically generating a report based on the proposed countermeasures, means for sending the generated report by email, and means for sending notifications to relevant parties in real time, thereby enabling real-time anomaly detection and countermeasure proposals, automated report generation, and rapid information sharing.
[0939] A "communications device" is a device that includes hardware and software for transmitting and receiving data.
[0940] "Log data" refers to recorded data relating to the operating status and events of a communication device.
[0941] "Real-time" is a concept that refers to a state in which data is collected and processed almost simultaneously as it occurs.
[0942] "Preprocessing" refers to a series of processes such as data cleaning, format standardization, and extraction of necessary information to prepare collected log data in an analyzable form.
[0943] An "anomaly detection model" is a model that uses a machine learning algorithm to detect anomalies that deviate from normal operating patterns.
[0944] "Countermeasures" refers to appropriate methods and procedures for dealing with detected abnormalities.
[0945] A "report" is a document that compiles detailed information about detected anomalies and proposed remedial actions.
[0946] "Email" is a means of sending messages and files electronically over the Internet.
[0947] "Notification" is a means of informing interested parties in real time about specific events or conditions.
[0948] The present invention is a system that preprocesses log data collected from communication devices, detects anomalies based on that data, and proposes optimal countermeasures. Furthermore, this system has the function of automatically generating reports based on the proposed countermeasures, sending the generated reports to relevant parties, and sending notifications in real time.
[0949] Hardware and software configuration:
[0950] server:
[0951] The server collects log data from communication devices in real time. This collection is done via HTTP API or WebSocket. The collected data is preprocessed on the server and input into an anomaly detection model. Machine learning algorithms such as TensorFlow and PyTorch are used for anomaly detection.
[0952] Communication equipment:
[0953] These are devices that send and receive data, including base stations and modems. These devices generate log data and send it to a server.
[0954] Device:
[0955] A device that receives notifications in real time, including PCs, tablets, smartphones, etc. Notifications are sent as push notifications from the server or emails.
[0956] Data processing and calculation:
[0957] Pretreatment:
[0958] When the server receives the log data, it cleans it, removes incomplete data, standardizes timestamps, and extracts necessary information to make the data analyzable.
[0959] Anomaly detection:
[0960] The preprocessed data is then input into an anomaly detection model, which is trained using machine learning algorithms to detect anomalies by comparing them with past normal patterns. Detailed information about detected anomalies (type of anomaly, time of occurrence, and scope of impact) is then recorded.
[0961] Suggested workaround:
[0962] The server then suggests the best course of action for any detected anomalies. It consults a database of past cases and searches for solutions based on similar cases. For example, if the signal strength drops, it suggests physically checking the antenna or restarting the repeater.
[0963] Generate a report:
[0964] A report is automatically generated based on the details of the anomaly and the proposed remedial action, and is saved in a standard format (e.g. PDF) for future reference.
[0965] Report distribution and notification:
[0966] The server will send the generated report to the relevant parties via email, and at the same time, send real-time notifications to the terminals about any abnormalities and suggested countermeasures, allowing the relevant parties to take immediate action.
[0967] Examples:
[0968] For example, it is assumed that the following abnormality is detected based on log data collected from a certain communication device (base station).
[0969] Type of anomaly: Sudden drop in signal strength
[0970] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[0971] In this case, the system operates as follows.
[0972] 1. The server collects log data from the communication devices and performs preprocessing.
[0973] 2. The preprocessed log data is input into an anomaly detection model using a machine learning algorithm to detect sudden drops in signal strength.
[0974] 3. The server will suggest the following countermeasures for the anomaly: "Physical check of the antenna" and "Restart of the signal repeater."
[0975] 4. Based on the proposed countermeasures, a report is automatically generated detailing the anomaly and the countermeasures.
[0976] 5. The server sends a report to the relevant parties via email, and simultaneously sends real-time notifications to the terminals regarding the occurrence of abnormalities and countermeasures.
[0977] Example prompt sentence:
[0978] "Please check what anomalies were detected and what countermeasures were proposed based on the log data collected from this communication device."
[0979] This automates the process from detecting a communication device fault to proposing a countermeasure, generating a report, and notifying relevant parties, enabling a fast and efficient response to anomalies.
[0980] The flow of the identification process in the first embodiment will be described with reference to FIG.
[0981] Program processing flow
[0982] Step 1: Collect log data
[0983] The server collects log data from the communication devices in real time by sending requests to the communication devices at regular intervals using HTTP API or WebSocket to obtain the latest log data.
[0984] Input: Raw log data obtained from communication devices
[0985] Output: Collected raw log data stored on the server
[0986] Specific operation: The server periodically accesses the communication device, receives log data, and stores it in a database.
[0987] Step 2: Preprocessing the log data
[0988] The server preprocesses the collected log data, cleaning the data to remove incomplete data and filter unnecessary data, standardizing the timestamp format, and extracting necessary information.
[0989] Input: Raw log data stored on the server
[0990] Output: Preprocessed log data
[0991] What happens: The server performs data cleaning, unifies timestamps, and applies algorithms to extract the required information.
[0992] Step 3: Detect anomalies
[0993] The server inputs the preprocessed log data into an anomaly detection model, which uses machine learning algorithms to detect deviations from normal behavior patterns.
[0994] Input: Preprocessed log data
[0995] Output: Log data in which an anomaly was detected and its detailed information
[0996] Specific operation: The server inputs preprocessed log data into an anomaly detection model built using TensorFlow and PyTorch, and determines whether or not there are any anomalies.
[0997] Step 4: Propose a solution
[0998] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, and searches for countermeasures based on similar cases by referencing a past database.
[0999] Input: Log data in which an anomaly was detected and detailed information
[1000] Output: Proposed action
[1001] Specific operation: Based on the type of abnormality and its cause, the server selects the most appropriate countermeasure from a pre-prepared database.
[1002] Step 5: Generate the report
[1003] The server automatically generates a report based on the details of the anomaly and the proposed countermeasures, including details of the anomaly, the date and time of detection, and the proposed countermeasures.
[1004] Input: Anomaly details and suggested remediation
[1005] Output: Automatically generated report (e.g. PDF format)
[1006] Specific operation: The server combines the details of the anomaly and the countermeasures, generates a report based on a template, and converts it into PDF format.
[1007] Step 6: Report distribution and notification
[1008] The server sends the generated report to the relevant parties via email, and simultaneously sends real-time notifications of abnormal occurrences and countermeasures to the relevant parties' terminals.
[1009] Input: Automatically generated report and notification information
[1010] Output: Reports sent by email and notifications sent to terminal
[1011] Specific operation: The server uses the SMTP protocol to send the report by email, and sends notifications to the relevant parties' terminals via the Push notification service.
[1012] These steps automate a series of processes, from collecting log data from communication devices to detecting anomalies, proposing countermeasures, generating reports, and distributing and notifying them.
[1013] (Application example 1)
[1014] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[1015] There is a need for a method to manage the operation logs of robots in factories and respond quickly and accurately when an abnormality occurs. Currently, the detection of abnormalities and the proposal of countermeasures are often done manually, which takes time and effort. In addition, the creation of reports is a significant burden, so an automated system is needed to improve efficiency.
[1016] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[1017] In this invention, the server includes means for preprocessing log data collected from the communication devices, means for detecting anomalies based on the preprocessed log data, means for proposing optimal countermeasures for the detected anomalies, means for automatically generating a report based on the proposed countermeasures, means for transmitting the generated report and sending a notification, means for monitoring operation logs of robots in the factory in real time, means for using a machine learning algorithm to detect anomalies with high accuracy using the preprocessed log data, and means for proposing optimal countermeasures after detecting an anomaly, automatically generating a report, and notifying relevant parties. This automates the entire process from detecting anomalies in robots in the factory to proposing countermeasures, generating a report, and notifying relevant parties, thereby reducing the human burden and enabling rapid responses.
[1018] A "communication device" is a device for data communication, and is used to collect log data from factory robots and sensors.
[1019] "Log data" refers to data including operation history and event information recorded by factory robots and communication devices.
[1020] "Preprocessing" refers to the process of cleaning and formatting the collected log data to make it analyzable.
[1021] "Abnormal" refers to behavior or errors that deviate from normal operating patterns, and in the case of factory robots, this includes unexpected behavior or malfunctions.
[1022] An "anomaly detection model" is an algorithm or system that uses machine learning and statistical models to detect anomalies in collected log data.
[1023] "Countermeasures" are specific measures or solutions implemented in response to detected abnormalities, and in the case of factory robots, these include restarting the robot or replacing parts.
[1024] A "report" is an official document summarizing detected anomalies and proposed countermeasures, and is used to share information with relevant parties.
[1025] The "server" is a central device that stores data, pre-processes it, detects anomalies, proposes countermeasures, generates reports, and sends notifications.
[1026] A "machine learning algorithm" is a computational method for learning patterns from large amounts of data and detecting and predicting anomalies.
[1027] "Notifications" are messages or alerts that inform relevant parties in real time about abnormalities and countermeasures.
[1028] "Real-time" refers to reacting and processing events and data immediately at the moment they occur.
[1029] This invention provides a system that monitors the operation logs of factory robots in real time, proposes optimal countermeasures when an abnormality is detected, automatically generates a report, and notifies relevant parties. A specific method for realizing this system is described below.
[1030] Hardware and software used
[1031] Hardware
[1032] Factory robot: an automated device placed on a production line
[1033] Sensing device: Collects robot movement data
[1034] Server: Performs data preprocessing, anomaly detection, countermeasure proposals, report generation and notifications
[1035] software
[1036] Log collection API: Collect operation logs from factory robots in real time
[1037] Data preprocessing tools: cleaning and formatting data (e.g., Python's Pandas library)
[1038] Anomaly detection algorithm: Machine learning model (e.g., PyCaret)
[1039] Countermeasure proposal system: Refer to past database
[1040] Report generation tools: PDF generation (e.g. reportlab)
[1041] Notification system: Email or push notification (e.g. SMTP server)
[1042] System Operation Overview
[1043] 1. Collecting and Preprocessing Log Data
[1044] The server uses a log collection API to collect operation logs from the factory robots in real time, and then uses a data preprocessing tool to clean and convert the collected data into an analyzable format.
[1045] 2. Anomaly detection
[1046] The server inputs the preprocessed log data into a machine learning model to detect anomalies with high accuracy, and when an anomaly is detected, detailed information about it is recorded.
[1047] 3. Proposal of countermeasures
[1048] The server proposes optimal countermeasures for detected anomalies by referencing a past database and existing countermeasure patterns.
[1049] 4. Generate reports
[1050] Based on the proposed countermeasures, the server automatically generates an official report in PDF format, including details of the anomaly, the date and time of detection, and the proposed countermeasures.
[1051] 5. Notification sending
[1052] The generated reports are automatically sent to the relevant parties by the server, and notifications are also sent in real time to smartphones and monitoring devices within the factory.
[1053] Specific examples
[1054] For example, consider a situation where factory robot A suddenly stops performing its designated operation. The server receives the operation logs collected from robot A in real time, and a pre-processing tool cleans and converts the data. The machine learning algorithm then detects the anomaly and suggests countermeasures: "restart robot A" and "physical inspection of the sensor." Based on this, a detailed report is automatically generated and distributed to relevant parties via email, and a notification of the anomaly is sent to the device in real time.
[1055] Prompt Sentence Examples
[1056] "Please apply an application to factory robots that preprocesses log data collected from communication devices, detects abnormalities, proposes optimal countermeasures, generates reports and sends notifications. This application will monitor the robot's operation logs in real time, detect abnormalities, propose countermeasures, automatically generate reports, and send notifications."
[1057] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[1058] Step 1:
[1059] The server uses a log collection API to collect operation logs from the factory robots in real time. It receives the factory robot log data as input and stores it in the server's storage. The output is raw log data for preprocessing.
[1060] Step 2:
[1061] The server uses a data preprocessing tool to clean the collected log data and convert its format. Specifically, it removes incomplete data, standardizes timestamps, and extracts necessary information. The input is the raw log data obtained in step 1, and the output is the preprocessed, clean data.
[1062] Step 3:
[1063] The server inputs the preprocessed log data into an anomaly detection algorithm (machine learning model). The server compares it with past normal behavior patterns to detect whether there are any anomalies with high accuracy. The input is preprocessed clean data, and the output is the anomaly detection results and detailed information about the anomaly.
[1064] Step 4:
[1065] The server proposes optimal countermeasures for detected anomalies. Here, it refers to a past database and existing countermeasure patterns to select an appropriate method based on the type and cause of the anomaly. The input is the anomaly detection result, and the output is a proposal of specific countermeasures.
[1066] Step 5:
[1067] The server automatically generates a report based on the proposed countermeasures. The report includes details of the anomaly, the date and time of detection, the proposed countermeasures, and procedures. A report generation tool (PDF generation tool) is used for generation. The input is the proposed countermeasures, and the output is an official report.
[1068] Step 6:
[1069] The server automatically sends the generated report to the relevant parties. The relevant parties are notified by email and also by sending a notification to their terminal. Email and push notifications are sent using a notification system. The input is the official report, and the output is a notification of completion of transmission and a notification to the relevant parties.
[1070] Step 7:
[1071] The user checks the received notifications and reports and takes necessary actions. The input is the received notifications and reports, and the output is the specific action taken by the user.
[1072] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.
[1073] The present invention combines a system that preprocesses log data collected from communication devices, detects anomalies based on the preprocessed log data, proposes optimal countermeasures for the detected anomalies, automatically generates a report based on the proposed countermeasures, transmits the generated report, and sends notifications, with an emotion engine that recognizes user emotions. In this embodiment, the main functions of the system and its processing flow will be described.
[1074] 1. Collecting and pre-processing log data:
[1075] The server collects log data from communication devices in real time, automatically obtaining the latest log data at regular intervals via API endpoints or data streams.
[1076] The collected log data is first preprocessed. Preprocessing involves cleaning the data and converting its format to make it analyzable. For example, this involves removing incomplete data, standardizing timestamps, and extracting necessary information.
[1077] 2. Anomaly detection:
[1078] The server inputs the preprocessed log data into an anomaly detection model, which uses machine learning algorithms to accurately detect anomalies that deviate from normal data patterns. Detailed information such as the type of anomaly, the date and time of occurrence, and the scope of impact is recorded.
[1079] 3. Proposed solutions:
[1080] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which involves a process of selecting the optimal countermeasure for each type of anomaly by referencing a past database and a pattern library of countermeasures.
[1081] 4. Generate report:
[1082] The server automatically generates a report based on the detected anomalies and proposed remediation measures. The report includes details of the anomaly, the date and time of detection, the proposed remediation measures, and recommended action steps. The report is created according to a standard format and may be converted to a format such as PDF.
[1083] 5. Report Distribution and Notification:
[1084] The server sends the generated report to the designated recipient (administrator or technician) via email. Real-time notifications are also sent to the device, allowing relevant parties to quickly understand the occurrence of an abnormality and take appropriate action. Notifications include a summary of the report and a link.
[1085] 6. Emotion Engine in Action:
[1086] The emotion engine is a function for recognizing the user's emotions. It analyzes text and voice data when the user uses the system and recognizes the user's emotions.
[1087] The server adjusts the report content and notification format based on the user's emotions recognized by the emotion engine. For example, if the user is experiencing high stress, the report will include detailed explanations and prioritized solutions.
[1088] The emotion engine also further optimizes the suggested response based on the user's emotions. For example, if the user is calm, it can suggest a response that prioritizes speed.
[1089] Specific examples
[1090] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[1091] Type of anomaly: Sudden drop in signal strength
[1092] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[1093] In this case, the system behaves as follows:
[1094] 1. The server collects log data from base station A and performs preprocessing.
[1095] 2. Using the preprocessed log data, an anomaly detection model detects sudden drops in signal strength.
[1096] 3. The server will suggest the best course of action for this anomaly: "Physical check of antenna" and "Restart signal repeater."
[1097] 4. A detailed report is automatically generated based on the proposed action, including data on signal strength degradation and suggested steps to take.
[1098] 5. If the emotion engine identifies the user's emotions as high stress, a detailed explanation and prioritized actions will be added to the report.
[1099] 6. Finally, the generated report is sent to the relevant parties via email, and notifications of abnormalities and countermeasures are sent to the terminal in real time.
[1100] This enables the system to operate in a way that takes the user's emotions into account, further optimizing the entire process from fault detection to proposing countermeasures, generating reports, and notifying relevant parties.
[1101] The processing flow will be explained below.
[1102] Step 1:
[1103] The server collects log data from communication devices and automatically retrieves the latest log data at regular intervals via API endpoints or data streams.
[1104] Step 2:
[1105] The server preprocesses the collected log data by cleaning and formatting the data, removing incomplete data, standardizing the timestamp format, extracting necessary information, and preparing the data in a format suitable for analysis.
[1106] Step 3:
[1107] The server inputs the preprocessed log data into an anomaly detection model, which uses machine learning algorithms to accurately detect anomalies that deviate from normal data patterns. It then records detailed information about the detected anomalies (such as the type of anomaly, the date and time of occurrence, and the scope of impact).
[1108] Step 4:
[1109] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which involves a process of selecting the optimal countermeasure for each type of anomaly by referencing a past database and a pattern library of countermeasures.
[1110] Step 5:
[1111] The server automatically generates a report based on details of detected anomalies and proposed remediation actions. The report includes details of the anomaly, the date and time of detection, proposed remediation actions, and recommended action steps. The report is created according to a standard format and may be converted to formats such as PDF.
[1112] Step 6:
[1113] The emotion engine analyzes text and voice data to recognize user emotions, identifying emotions from user input and conversations and optimizing the system's response accordingly.
[1114] Step 7:
[1115] The server adjusts the report content and notification format based on the user's emotions recognized by the emotion engine. For example, if the user is experiencing high stress, the report will include detailed explanations and prioritized solutions.
[1116] Step 8:
[1117] The server sends the generated report to the designated recipient (administrator or technician) via email. It also sends real-time notifications to the devices so that the relevant parties can quickly understand the occurrence of an abnormality and take countermeasures. The notifications include a summary of the report and a link.
[1118] Specific examples
[1119] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[1120] Type of anomaly: Sudden drop in signal strength
[1121] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[1122] In this case, the system behaves as follows:
[1123] Step 1:
[1124] The server collects log data from base station A.
[1125] Step 2:
[1126] The server preprocesses the collected log data, for example, removing incomplete data and extracting necessary information.
[1127] Step 3:
[1128] The server inputs the preprocessed log data into an anomaly detection model to detect sudden drops in signal strength.
[1129] Step 4:
[1130] The server will suggest the best course of action to address any abnormalities, namely "physical check of the antenna" and "restarting the signal repeater."
[1131] Step 5:
[1132] The server automatically generates a detailed report based on the proposed action, including data on the signal strength degradation and the steps to take.
[1133] Step 6:
[1134] The emotion engine recognizes the user's emotions, for example, recognizing that the user is in a high stress state.
[1135] Step 7:
[1136] The server adjusts the report content based on the emotions recognized by the emotion engine, adding detailed explanations and prioritized actions.
[1137] Step 8:
[1138] The server sends the generated report to the relevant parties via email, and sends real-time notifications to the terminal regarding any abnormalities and countermeasures.
[1139] This process allows for quick and accurate troubleshooting while taking into consideration the user's feelings.
[1140] Example 2
[1141] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[1142] Conventional anomaly detection systems were capable of automating anomaly detection, countermeasure proposals, and report generation, but they were insufficient in taking the user's emotions into consideration. As a result, when a user is in a high-stress state or a specific psychological state, the proposed countermeasures and the report content may be inappropriate or may increase the user's stress. Therefore, an objective of the present invention is to provide a system that takes the user's emotions into consideration and optimizes the entire process from anomaly detection to countermeasure proposals, report generation, and notification.
[1143] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes means for preprocessing log data collected from the communication devices, means for detecting anomalies based on the preprocessed log data, means for proposing optimal countermeasures for the detected anomalies, means for automatically generating a report based on the proposed countermeasures, means for transmitting the generated report and a notification, and means for recognizing the user's emotions and adjusting the content of the report and the format of the notification based on the recognized emotions. This enables an anomaly detection and countermeasure proposal process that takes the user's emotions into consideration.
[1144] A "communication device" is a device that sends and receives data over a network.
[1145] "Log data" refers to data that records the operations and events of a system or communication device.
[1146] "Preprocessing" refers to processes such as data cleaning and format conversion to prepare collected log data in an analyzable form.
[1147] An "anomaly detection model" is a machine learning algorithm or other analytical method used to detect anomalies in collected data.
[1148] "Countermeasures" are proposals for appropriate actions or solutions to detected anomalies.
[1149] A "report" is a document detailing detected anomalies and their corresponding actions.
[1150] "Notification" refers to a message or alert that notifies a user or administrator of an abnormality and the appropriate countermeasure.
[1151] An "emotion engine" is a system that recognizes emotions by analyzing a user's text and voice data.
[1152] "User emotion" refers to the psychological state that the user expresses to the system, and serves as the basis for the system to make adjustments.
[1153] The present invention combines a system that preprocesses log data collected from communication devices, detects anomalies based on the preprocessed log data, proposes optimal countermeasures for the detected anomalies, automatically generates a report based on the proposed countermeasures, transmits the generated report, and sends notifications, with an emotion engine that recognizes user emotions. In this embodiment, the main functions of the system and its processing flow will be described.
[1154] Key components of the system
[1155] 1. Server
[1156] The server is the central processing device of the present invention, and collects log data from communication devices, pre-processes it, analyzes it, detects abnormalities, proposes countermeasures, and generates and notifies reports.
[1157] Machine learning algorithms (e.g., LSTM model for anomaly detection) are used for anomaly detection.
[1158] 2. Communications Equipment
[1159] The communication device is a device that transmits and receives data and provides log data to the system.
[1160] Base station A is an example.
[1161] 3. Emotion Engine
[1162] It is an engine that analyzes the user's text and voice data and recognizes emotions.
[1163] The server uses information from the emotion engine to tailor reports and notifications.
[1164] 4. Terminal
[1165] A device that allows users and administrators to access the system and receive notifications and check reports.
[1166] Hardware and software used
[1167] Data Stream: Used to obtain log data from communication devices in real time.
[1168] API endpoint: An interface for collecting data from a communication device.
[1169] Database: A storage system for temporarily storing collected data.
[1170] Anomaly detection model: A machine learning algorithm (e.g., LSTM model) to analyze the preprocessed data and detect anomalies.
[1171] Emotion engine: Software that analyzes a user's text and voice to recognize emotions.
[1172] Specific examples
[1173] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[1174] Type of anomaly: Sudden drop in signal strength
[1175] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[1176] In this case, the system operates as follows.
[1177] 1. The server collects and preprocesses log data from base station A. Preprocessing includes cleaning the data, removing incomplete data, unifying timestamps, and extracting necessary information.
[1178] 2. The preprocessed log data is fed into an anomaly detection model (e.g., LSTM model) to detect sudden drops in signal strength.
[1179] 3. The server will suggest the best course of action for this anomaly: "Physical check of antenna" and "Restart signal repeater."
[1180] 4. A detailed report is automatically generated based on the proposed action, including data on signal strength degradation and suggested steps to take.
[1181] 5. The emotion engine analyzes the user's text and voice data and, if it recognizes that the user is in a high stress state, adds detailed explanations and prioritized countermeasures to the report.
[1182] 6. Finally, the generated report is sent to the relevant parties via email, and notifications of abnormalities and countermeasures are sent to the terminal in real time.
[1183] Prompt Sentence Examples
[1184] "Based on the log data from base station A, detect anomalies (sudden drop in signal strength), suggest optimal countermeasures, and generate a report. If the user is in a high stress state, add a detailed explanation to the report."
[1185] As described above, the system of the present invention uses data collected from communication devices to effectively and quickly detect anomalies and propose countermeasures, enabling flexible responses that take user emotions into consideration.
[1186] The flow of the identification process in the second embodiment will be described with reference to FIG.
[1187] Step 1:
[1188] Collecting log data
[1189] The server collects log data from a communication device (for example, base station A).
[1190] Input: Real-time log data from communication devices
[1191] How it works: The server automatically retrieves log data at regular intervals using an API endpoint.
[1192] Output: The collected raw log data is stored in a database.
[1193] Step 2:
[1194] Preprocessing of collected log data
[1195] The server pre-processes the collected log data.
[1196] Input: Collected raw log data
[1197] How it works: The server performs data cleaning to remove incomplete data and outliers, as well as standardizing timestamps and converting them into a parsable format.
[1198] Output: Preprocessed and clean log data is generated.
[1199] Step 3:
[1200] Input to the anomaly detection model
[1201] The server inputs the preprocessed log data into the anomaly detection model.
[1202] Input: Preprocessed and clean log data
[1203] How it works: The server applies a machine learning algorithm for anomaly detection (e.g., an LSTM model) to detect anomalies in the data.
[1204] Output: Anomaly detection results (detailed information such as the type of anomaly, the date and time of occurrence, and the scope of impact) are generated.
[1205] Step 4:
[1206] Proposal of countermeasures
[1207] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model.
[1208] Input: Detailed information about the detected anomaly
[1209] How it works: The server searches through a database of past cases and a pattern library of countermeasures to find similar cases and selects the most appropriate response to the detected anomaly (e.g., "physical check of antenna" or "restart of signal repeater").
[1210] Output: A proposed solution is generated.
[1211] Step 5:
[1212] Automatic report generation
[1213] The server automatically generates a report based on detected anomalies and suggested remedial actions.
[1214] Input: Anomaly details and proposed remediation
[1215] How it works: The server creates reports using a standard format and converts them to formats such as PDF if necessary.
[1216] Output: The generated report is saved as a digital file.
[1217] Step 6:
[1218] Emotion recognition by emotion engine
[1219] The emotion engine analyzes the user's text and voice data to recognize emotions.
[1220] Input: Text or voice data entered by a user into the system.
[1221] How it works: The emotion engine performs analysis and recognizes the user's emotional state (e.g., high stress).
[1222] Output: The recognized emotional state of the user is generated as data.
[1223] Step 7:
[1224] Adjusting reports based on sentiment
[1225] The server adjusts the content of the report based on the user's emotions recognized by the emotion engine.
[1226] Input: The perceived emotional state of the user and the generated report
[1227] Action: The server adds detailed explanations and priority actions to the report (e.g. if the user is in a high stress state).
[1228] Output: A reconciled report is generated.
[1229] Step 8:
[1230] Report submission and notification
[1231] The server emails the generated reports to designated recipients and sends real-time notifications to the device.
[1232] Input: Coordinated Report and Notification Information
[1233] What it does: The server emails the report and sends a notification to the device, which includes a summary of the report and a link.
[1234] Output: The recipient receives the report and a notification appears on their device.
[1235] Through the above processing steps, the system collects and analyzes log data from communication devices, and generates and notifies optimal countermeasures and reports that take the user's emotions into consideration.
[1236] (Application example 2)
[1237] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[1238] Conventional anomaly detection systems can detect anomalies and propose countermeasures, but there is a need for systems that can operate flexibly and take user emotions into account. In particular, in security services, it is essential to respond according to the user's stress level and urgency, and the challenge is to provide optimal reports and notifications based on the user's emotions.
[1239] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for preprocessing log data collected from the communication devices, means for detecting anomalies based on the preprocessed log data, means for proposing optimal countermeasures for the detected anomalies, means for automatically generating a report based on the proposed countermeasures, means for transmitting the generated report and a notification, means for recognizing the user's emotions, and means for adjusting the content of the report and the format of the notification based on the user's emotions. This enables flexible and prompt response according to the user's emotions.
[1240] A "communications device" is a device used to send and receive data over a network. Examples include routers, switches, and modems.
[1241] "Log data" refers to data that records the operation history of communication devices and systems. This data is used for anomaly detection and analysis.
[1242] "Preprocessing" refers to the process of making raw data into an analyzable form through processes such as cleaning and format conversion.
[1243] "Means for detecting anomalies" refers to algorithms or models for detecting anomalies in preprocessed log data. Machine learning models are often used.
[1244] "Means for proposing countermeasures" refers to a function that suggests appropriate solutions for detected anomalies. This generally involves referencing past data or specialized knowledge databases.
[1245] "Means for automatically generating reports" refers to a system function that automatically creates a report summarizing the details of the abnormality and countermeasures.
[1246] "Means for sending notifications" refers to the functionality for notifying users in real time of generated reports and important information. Notifications are primarily sent via email or push notifications.
[1247] "Means for recognizing emotions" refers to engines or algorithms for analyzing emotions from a user's voice or text data.
[1248] "Means for adjusting notification format" refers to the ability to dynamically change the content of notifications and reports based on the user's emotions. By taking emotions into consideration, we can provide users with an appropriate sharing method.
[1249] This invention is a system that monitors log data collected from communication devices in real time, proposes appropriate countermeasures when an abnormality is detected, automatically generates reports, and sends notifications. It also has a function to optimize the content of reports and notifications by recognizing the user's emotions.
[1250] System Configuration
[1251] The system consists of the following main components:
[1252] 1. Log data collection method
[1253] 2. Data preprocessing methods
[1254] 3. Anomaly detection methods
[1255] 4. Means of proposing countermeasures
[1256] 5. Automatic report generation means
[1257] 6. Notification Method
[1258] 7. Emotion recognition means
[1259] 8. Notification format adjustment means
[1260] Hardware and software used
[1261] Hardware: Servers, users' smartphones, communication devices (e.g., routers, switches)
[1262] Software: Python, Django, machine learning libraries (e.g., scikit-learn, TensorFlow), emotion recognition libraries, real-time notification services
[1263] Data Processing and Computation
[1264] 1. Log data collection and preprocessing:
[1265] The server collects log data from communication devices in real time via API endpoints and data streams, and preprocesses the collected log data by cleaning and formatting it so that it can be analyzed.
[1266] 2. Anomaly detection:
[1267] The pre-processed log data is then subjected to a machine learning model for anomaly detection, which monitors the log data in real time and detects deviations from normal data patterns with high accuracy.
[1268] 3. Proposed solutions:
[1269] When an anomaly is detected, the server refers to a database of past incidents and a pattern library of countermeasures to suggest the optimal countermeasure, which is dynamically adjusted based on the type of anomaly and the user's sentiment.
[1270] 4. Automatic report generation:
[1271] The server automatically generates a report based on the anomaly and the proposed remediation. The report includes details of the anomaly, the date and time it was detected, the proposed remediation, and recommended steps to take. The report is generated in a standard format and can be converted to PDF or other formats.
[1272] 5. Sending notifications:
[1273] Once generated, the report is emailed to the relevant parties and a real-time notification is sent to the device, including a summary of the report and a link to it.
[1274] 6. Emotion recognition:
[1275] The server analyzes text and voice data when a user uses the system and recognizes the user's emotions. This analysis is performed using an emotion recognition library.
[1276] 7. Notification Formatting:
[1277] Tailor the content of reports and notification format based on the perceived emotion, for example, if the user is experiencing high stress, provide a detailed explanation and immediate action plan in the report.
[1278] Specific examples
[1279] When an abnormality is detected in the log data collected from a certain communication device (base station A), for example, a sudden drop in signal strength, the procedure for reporting the abnormality is as follows.
[1280] 1. Data collection and pre-processing: The server collects log data from base station A and performs cleaning and format conversion.
[1281] 2. Anomaly detection: Based on the pre-processed data, the machine learning model detects drops in signal strength.
[1282] 3. Suggested solutions: Suggested solutions for this anomaly include "Physical check of antenna" and "Restart signal repeater".
[1283] 4. Emotion recognition: The emotion recognition engine analyzes the emotion the user feels when receiving this notification. For example, if the user feels high stress, a report will be generated with a detailed explanation and prompt action.
[1284] 5. Notification: The generated report and rapid response procedures are sent to the relevant parties.
[1285] Prompt Sentence Examples
[1286] "A suspicious individual has been detected on the live security camera feed. Due to the user's high stress level, please generate a detailed report with the following immediate steps: Recommendation: Immediate police notification steps."
[1287] The flow of the specific processing in the application example 2 will be described with reference to FIG.
[1288] Step 1:
[1289] The server collects log data from communication devices in real time. The input is the log data obtained from the communication devices. The server receives the log data from API endpoints or data streams and stores this data in local storage. The output is the collected log data.
[1290] Step 2:
[1291] The server preprocesses the collected log data. At this stage, data cleaning and format conversion are performed. The input is the collected raw log data, and specific processes are performed to remove incomplete data, unify timestamps, and extract necessary information. The output is preprocessed, clean log data.
[1292] Step 3:
[1293] The server detects anomalies using preprocessed log data. The input is the preprocessed log data and a machine learning model (e.g., scikit-learn, TensorFlow) is used. Specifically, an algorithm is run to identify data points that deviate from normal data patterns. The output is anomaly detection results that include information such as the type of anomaly, the date and time of occurrence, and the scope of impact.
[1294] Step 4:
[1295] The server proposes optimal countermeasures for detected anomalies. The input is the anomaly detection results, and it uses a database of past responses and a pattern library of countermeasures. The server extracts the most effective countermeasure according to the type of anomaly and proposes specific steps to take. The output is a list of recommended countermeasures.
[1296] Step 5:
[1297] The server automatically generates a report based on the proposed countermeasures. The input is the anomaly detection result and a list of countermeasures. Specifically, a report is generated in text format that includes details of the anomaly, the date and time of detection, the proposed countermeasures, and the recommended procedure. The output is the generated report, which is converted to PDF format or similar and saved.
[1298] Step 6:
[1299] The server runs an emotion engine to recognize the user's emotions. The input is the user's text or voice data, which is analyzed using an emotion recognition library. The output is the user's emotional state, including emotion categories such as high stress or low stress.
[1300] Step 7:
[1301] The server adjusts the report content and notification format based on the results of the emotion engine. The input is the generated report and emotion recognition results. Specifically, it adjusts the detail level and linguistic tone of the report according to the user's emotion and saves it in an appropriate format. The output is the adjusted report.
[1302] Step 8:
[1303] The server sends the final report and notifies the relevant parties. The input is the adjusted report. Specifically, the report is sent as an email and a real-time notification is sent to the terminal. The output is a notification to the relevant parties and a confirmation of receipt.
[1304] Prompt Sentence Examples
[1305] A suspicious individual has been detected during a live security camera feed. Due to the user's high stress state, please generate a detailed report with the following immediate steps: Recommendation: Immediate police reporting steps
[1306] The specific processing unit 290 transmits the result of the specific processing to the headset type terminal 314. In the headset type terminal 314, the control unit 46A causes the speaker 240 and the display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[1307] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[1308] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the headset type terminal 314.
[1309] [Fourth embodiment]
[1310] FIG. 7 shows an example of the configuration of a data processing system 410 according to the fourth embodiment.
[1311] 7, a data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[1312] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[1313] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a control target 443. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the control target 443 are also connected to the bus 52.
[1314] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.
[1315] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).
[1316] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.
[1317] The control object 443 includes a display device, LEDs in the eyes, and motors for driving the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the emotions of the robot 414 can be expressed by controlling these motors. In addition, the facial expressions of the robot 414 can also be expressed by controlling the light emission state of the LEDs in the eyes of the robot 414.
[1318] Fig. 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Fig. 8, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.
[1319] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[1320] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[1321] In the robot 414, the processor 46 performs the reception output process. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[1322] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1323] The present invention provides a system that preprocesses log data collected from communication devices, detects abnormalities based on the preprocessed log data, proposes optimal countermeasures for the detected abnormalities, automatically generates a report based on the proposed countermeasures, transmits the generated report, and sends a notification. In this embodiment, the main functions of the system and its processing flow will be described.
[1324] 1. Collect and preprocess log data:
[1325] The server collects log data from communication devices in real time, via APIs and data streams.
[1326] The collected log data is first preprocessed. Preprocessing involves cleaning the data and converting its format to make it analyzable. For example, this involves removing incomplete data, standardizing timestamps, and extracting necessary information.
[1327] 2. Anomaly detection:
[1328] The server inputs the preprocessed log data into an anomaly detection model, which includes machine learning algorithms to accurately detect anomalies that deviate from historical normal behavior patterns.
[1329] If the anomaly detection model finds an anomaly, details of the anomaly are recorded.
[1330] 3. Proposed solutions:
[1331] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which includes referencing a database of past countermeasure patterns.
[1332] The appropriate countermeasures proposed are selected based on the type of abnormality and its cause.
[1333] 4. Generate report:
[1334] The server automatically generates a formal report based on the detected anomalies and proposed remediation measures, including details of the anomaly, the date and time of detection, and proposed remediation measures.
[1335] Reports are prepared according to a standard format and may be converted into formats such as PDF.
[1336] 5. Report Distribution and Notification:
[1337] The server automatically sends generated reports to interested parties, including using an email sending function to deliver the reports to designated recipients.
[1338] It also sends notifications to the device, allowing relevant parties to be aware of any abnormalities and countermeasures in real time.
[1339] Specific examples
[1340] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[1341] Type of anomaly: Sudden drop in signal strength
[1342] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[1343] In this case, the system behaves as follows:
[1344] 1. The server collects log data from base station A and performs preprocessing.
[1345] 2. Using the preprocessed log data, an anomaly detection model detects sudden drops in signal strength.
[1346] 3. The server will suggest the best course of action for this anomaly: "Physical check of antenna" and "Restart signal repeater."
[1347] 4. A detailed report is automatically generated based on the proposed action, including data on signal strength degradation and suggested steps to take.
[1348] 5. Finally, the generated report is sent to the relevant parties via email, and notifications of abnormalities and countermeasures are sent to the terminal in real time.
[1349] This automates the entire process, from detecting a communication device fault to proposing a countermeasure, generating a report, and notifying relevant parties, reducing the human burden and enabling a quick response.
[1350] The processing flow will be explained below.
[1351] Step 1:
[1352] The server collects log data from communication devices. It automatically retrieves the latest log data at regular intervals via an API endpoint or data stream. For example, it retrieves the log data using an HTTP request and stores it in memory or a database.
[1353] Step 2:
[1354] The server preprocesses the collected log data. Specifically, it cleans the data by removing incomplete data, standardizing the timestamp format, and extracting necessary information. This preprocessing prepares the data in a format suitable for analysis.
[1355] Step 3:
[1356] The server inputs the preprocessed log data into an anomaly detection model, which uses a machine learning algorithm to detect anomalies that deviate from normal data patterns. At this time, information such as the type of anomaly, the date and time of occurrence, and the extent of the impact is output.
[1357] Step 4:
[1358] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which involves a process of selecting the optimal countermeasure for each type of anomaly by referencing a past database and a pattern library of countermeasures.
[1359] Step 5:
[1360] The server automatically generates a report based on the details of the detected anomalies and the proposed remediation measures. The report includes details of the anomaly, the date and time of detection, the proposed remediation measures, and recommended action steps. The report is generated in a format such as PDF.
[1361] Step 6:
[1362] The server then emails the generated report to the designated recipient (e.g., administrator or technician). Real-time notifications are also sent to the device, promptly informing the relevant parties of any abnormalities and countermeasures. The notifications include a summary of the report and a link.
[1363] Example 1
[1364] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1365] Modern communications equipment is required to detect anomalies in real time, quickly propose countermeasures, and quickly share information with relevant parties. However, with conventional systems, it is difficult to automate these processes, requiring a great deal of manpower and time. Furthermore, the accuracy of anomaly detection and the appropriateness of countermeasures can be low, making efficient fault management difficult.
[1366] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[1367] In this invention, the server includes means for collecting log data from communication devices in real time, means for preprocessing the collected log data, means for inputting the preprocessed log data into an anomaly detection model to detect anomalies, means for proposing optimal countermeasures for the anomalies, means for automatically generating a report based on the proposed countermeasures, means for sending the generated report by email, and means for sending notifications to relevant parties in real time, thereby enabling real-time anomaly detection and countermeasure proposals, automated report generation, and rapid information sharing.
[1368] A "communications device" is a device that includes hardware and software for transmitting and receiving data.
[1369] "Log data" refers to recorded data relating to the operating status and events of a communication device.
[1370] "Real-time" is a concept that refers to a state in which data is collected and processed almost simultaneously as it occurs.
[1371] "Preprocessing" refers to a series of processes such as data cleaning, format standardization, and extraction of necessary information to prepare collected log data in an analyzable form.
[1372] An "anomaly detection model" is a model that uses a machine learning algorithm to detect anomalies that deviate from normal operating patterns.
[1373] "Countermeasures" refers to appropriate methods and procedures for dealing with detected abnormalities.
[1374] A "report" is a document that compiles detailed information about detected anomalies and proposed remedial actions.
[1375] "Email" is a means of sending messages and files electronically over the Internet.
[1376] "Notification" is a means of informing interested parties in real time about specific events or conditions.
[1377] The present invention is a system that preprocesses log data collected from communication devices, detects anomalies based on that data, and proposes optimal countermeasures. Furthermore, this system has the function of automatically generating reports based on the proposed countermeasures, sending the generated reports to relevant parties, and sending notifications in real time.
[1378] Hardware and software configuration:
[1379] server:
[1380] The server collects log data from communication devices in real time. This collection is done via HTTP API or WebSocket. The collected data is preprocessed on the server and input into an anomaly detection model. Machine learning algorithms such as TensorFlow and PyTorch are used for anomaly detection.
[1381] Communication equipment:
[1382] These are devices that send and receive data, including base stations and modems. These devices generate log data and send it to a server.
[1383] Device:
[1384] A device that receives notifications in real time, including PCs, tablets, smartphones, etc. Notifications are sent as push notifications from the server or emails.
[1385] Data processing and calculation:
[1386] Pretreatment:
[1387] When the server receives the log data, it cleans it, removes incomplete data, standardizes timestamps, and extracts necessary information to make the data analyzable.
[1388] Anomaly detection:
[1389] The preprocessed data is then input into an anomaly detection model, which is trained using machine learning algorithms to detect anomalies by comparing them with past normal patterns. Detailed information about detected anomalies (type of anomaly, time of occurrence, and scope of impact) is then recorded.
[1390] Suggested workaround:
[1391] The server then suggests the best course of action for any detected anomalies. It consults a database of past cases and searches for solutions based on similar cases. For example, if the signal strength drops, it suggests physically checking the antenna or restarting the repeater.
[1392] Generate a report:
[1393] A report is automatically generated based on the details of the anomaly and the proposed remedial action, and is saved in a standard format (e.g. PDF) for future reference.
[1394] Report distribution and notification:
[1395] The server will send the generated report to the relevant parties via email, and at the same time, send real-time notifications to the terminals about any abnormalities and suggested countermeasures, allowing the relevant parties to take immediate action.
[1396] Examples:
[1397] For example, it is assumed that the following abnormality is detected based on log data collected from a certain communication device (base station).
[1398] Type of anomaly: Sudden drop in signal strength
[1399] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[1400] In this case, the system operates as follows.
[1401] 1. The server collects log data from the communication devices and performs preprocessing.
[1402] 2. The preprocessed log data is input into an anomaly detection model using a machine learning algorithm to detect sudden drops in signal strength.
[1403] 3. The server will suggest the following countermeasures for the anomaly: "Physical check of the antenna" and "Restart of the signal repeater."
[1404] 4. Based on the proposed countermeasures, a report is automatically generated detailing the anomaly and the countermeasures.
[1405] 5. The server sends a report to the relevant parties via email, and simultaneously sends real-time notifications to the terminals regarding the occurrence of abnormalities and countermeasures.
[1406] Example prompt sentence:
[1407] "Please check what anomalies were detected and what countermeasures were proposed based on the log data collected from this communication device."
[1408] This automates the process from detecting a communication device fault to proposing a countermeasure, generating a report, and notifying relevant parties, enabling a fast and efficient response to anomalies.
[1409] The flow of the identification process in the first embodiment will be described with reference to FIG.
[1410] Program processing flow
[1411] Step 1: Collect log data
[1412] The server collects log data from the communication devices in real time by sending requests to the communication devices at regular intervals using HTTP API or WebSocket to obtain the latest log data.
[1413] Input: Raw log data obtained from communication devices
[1414] Output: Collected raw log data stored on the server
[1415] Specific operation: The server periodically accesses the communication device, receives log data, and stores it in a database.
[1416] Step 2: Preprocessing the log data
[1417] The server preprocesses the collected log data, cleaning the data to remove incomplete data and filter unnecessary data, standardizing the timestamp format, and extracting necessary information.
[1418] Input: Raw log data stored on the server
[1419] Output: Preprocessed log data
[1420] What happens: The server performs data cleaning, unifies timestamps, and applies algorithms to extract the required information.
[1421] Step 3: Detect anomalies
[1422] The server inputs the preprocessed log data into an anomaly detection model, which uses machine learning algorithms to detect deviations from normal behavior patterns.
[1423] Input: Preprocessed log data
[1424] Output: Log data in which an anomaly was detected and its detailed information
[1425] Specific operation: The server inputs preprocessed log data into an anomaly detection model built using TensorFlow and PyTorch, and determines whether or not there are any anomalies.
[1426] Step 4: Propose a solution
[1427] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, and searches for countermeasures based on similar cases by referencing a past database.
[1428] Input: Log data in which an anomaly was detected and detailed information
[1429] Output: Proposed action
[1430] Specific operation: Based on the type of abnormality and its cause, the server selects the most appropriate countermeasure from a pre-prepared database.
[1431] Step 5: Generate the report
[1432] The server automatically generates a report based on the details of the anomaly and the proposed countermeasures, including details of the anomaly, the date and time of detection, and the proposed countermeasures.
[1433] Input: Anomaly details and suggested remediation
[1434] Output: Automatically generated report (e.g. PDF format)
[1435] Specific operation: The server combines the details of the anomaly and the countermeasures, generates a report based on a template, and converts it into PDF format.
[1436] Step 6: Report distribution and notification
[1437] The server sends the generated report to the relevant parties via email, and simultaneously sends real-time notifications of abnormal occurrences and countermeasures to the relevant parties' terminals.
[1438] Input: Automatically generated report and notification information
[1439] Output: Reports sent by email and notifications sent to terminal
[1440] Specific operation: The server uses the SMTP protocol to send the report by email, and sends notifications to the relevant parties' terminals via the Push notification service.
[1441] These steps automate a series of processes, from collecting log data from communication devices to detecting anomalies, proposing countermeasures, generating reports, and distributing and notifying them.
[1442] (Application example 1)
[1443] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1444] There is a need for a method to manage the operation logs of robots in factories and respond quickly and accurately when an abnormality occurs. Currently, the detection of abnormalities and the proposal of countermeasures are often done manually, which takes time and effort. In addition, the creation of reports is a significant burden, so an automated system is needed to improve efficiency.
[1445] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[1446] In this invention, the server includes means for preprocessing log data collected from the communication devices, means for detecting anomalies based on the preprocessed log data, means for proposing optimal countermeasures for the detected anomalies, means for automatically generating a report based on the proposed countermeasures, means for transmitting the generated report and sending a notification, means for monitoring operation logs of robots in the factory in real time, means for using a machine learning algorithm to detect anomalies with high accuracy using the preprocessed log data, and means for proposing optimal countermeasures after detecting an anomaly, automatically generating a report, and notifying relevant parties. This automates the entire process from detecting anomalies in robots in the factory to proposing countermeasures, generating a report, and notifying relevant parties, thereby reducing the human burden and enabling rapid responses.
[1447] A "communication device" is a device for data communication, and is used to collect log data from factory robots and sensors.
[1448] "Log data" refers to data including operation history and event information recorded by factory robots and communication devices.
[1449] "Preprocessing" refers to the process of cleaning and formatting the collected log data to make it analyzable.
[1450] "Abnormal" refers to behavior or errors that deviate from normal operating patterns, and in the case of factory robots, this includes unexpected behavior or malfunctions.
[1451] An "anomaly detection model" is an algorithm or system that uses machine learning and statistical models to detect anomalies in collected log data.
[1452] "Countermeasures" are specific measures or solutions implemented in response to detected abnormalities, and in the case of factory robots, these include restarting the robot or replacing parts.
[1453] A "report" is an official document summarizing detected anomalies and proposed countermeasures, and is used to share information with relevant parties.
[1454] The "server" is a central device that stores data, pre-processes it, detects anomalies, proposes countermeasures, generates reports, and sends notifications.
[1455] A "machine learning algorithm" is a computational method for learning patterns from large amounts of data and detecting and predicting anomalies.
[1456] "Notifications" are messages or alerts that inform relevant parties in real time about abnormalities and countermeasures.
[1457] "Real-time" refers to reacting and processing events and data immediately at the moment they occur.
[1458] This invention provides a system that monitors the operation logs of factory robots in real time, proposes optimal countermeasures when an abnormality is detected, automatically generates a report, and notifies relevant parties. A specific method for realizing this system is described below.
[1459] Hardware and software used
[1460] Hardware
[1461] Factory robot: an automated device placed on a production line
[1462] Sensing device: Collects robot movement data
[1463] Server: Performs data preprocessing, anomaly detection, countermeasure proposals, report generation and notifications
[1464] software
[1465] Log collection API: Collect operation logs from factory robots in real time
[1466] Data preprocessing tools: cleaning and formatting data (e.g., Python's Pandas library)
[1467] Anomaly detection algorithm: Machine learning model (e.g., PyCaret)
[1468] Countermeasure proposal system: Refer to past database
[1469] Report generation tools: PDF generation (e.g. reportlab)
[1470] Notification system: Email or push notification (e.g. SMTP server)
[1471] System Operation Overview
[1472] 1. Collecting and Preprocessing Log Data
[1473] The server uses a log collection API to collect operation logs from the factory robots in real time, and then uses a data preprocessing tool to clean and convert the collected data into an analyzable format.
[1474] 2. Anomaly detection
[1475] The server inputs the preprocessed log data into a machine learning model to detect anomalies with high accuracy, and when an anomaly is detected, detailed information about it is recorded.
[1476] 3. Proposal of countermeasures
[1477] The server proposes optimal countermeasures for detected anomalies by referencing a past database and existing countermeasure patterns.
[1478] 4. Generate reports
[1479] Based on the proposed countermeasures, the server automatically generates an official report in PDF format, including details of the anomaly, the date and time of detection, and the proposed countermeasures.
[1480] 5. Notification sending
[1481] The generated reports are automatically sent to the relevant parties by the server, and notifications are also sent in real time to smartphones and monitoring devices within the factory.
[1482] Specific examples
[1483] For example, consider a situation where factory robot A suddenly stops performing its designated operation. The server receives the operation logs collected from robot A in real time, and a pre-processing tool cleans and converts the data. The machine learning algorithm then detects the anomaly and suggests countermeasures: "restart robot A" and "physical inspection of the sensor." Based on this, a detailed report is automatically generated and distributed to relevant parties via email, and a notification of the anomaly is sent to the device in real time.
[1484] Prompt Sentence Examples
[1485] "Please apply an application to factory robots that preprocesses log data collected from communication devices, detects abnormalities, proposes optimal countermeasures, generates reports and sends notifications. This application will monitor the robot's operation logs in real time, detect abnormalities, propose countermeasures, automatically generate reports, and send notifications."
[1486] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[1487] Step 1:
[1488] The server uses a log collection API to collect operation logs from the factory robots in real time. It receives the factory robot log data as input and stores it in the server's storage. The output is raw log data for preprocessing.
[1489] Step 2:
[1490] The server uses a data preprocessing tool to clean the collected log data and convert its format. Specifically, it removes incomplete data, standardizes timestamps, and extracts necessary information. The input is the raw log data obtained in step 1, and the output is the preprocessed, clean data.
[1491] Step 3:
[1492] The server inputs the preprocessed log data into an anomaly detection algorithm (machine learning model). The server compares it with past normal behavior patterns to detect whether there are any anomalies with high accuracy. The input is preprocessed clean data, and the output is the anomaly detection results and detailed information about the anomaly.
[1493] Step 4:
[1494] The server proposes optimal countermeasures for detected anomalies. Here, it refers to a past database and existing countermeasure patterns to select an appropriate method based on the type and cause of the anomaly. The input is the anomaly detection result, and the output is a proposal of specific countermeasures.
[1495] Step 5:
[1496] The server automatically generates a report based on the proposed countermeasures. The report includes details of the anomaly, the date and time of detection, the proposed countermeasures, and procedures. A report generation tool (PDF generation tool) is used for generation. The input is the proposed countermeasures, and the output is an official report.
[1497] Step 6:
[1498] The server automatically sends the generated report to the relevant parties. The relevant parties are notified by email and also by sending a notification to their terminal. Email and push notifications are sent using a notification system. The input is the official report, and the output is a notification of completion of transmission and a notification to the relevant parties.
[1499] Step 7:
[1500] The user checks the received notifications and reports and takes necessary actions. The input is the received notifications and reports, and the output is the specific action taken by the user.
[1501] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.
[1502] The present invention combines a system that preprocesses log data collected from communication devices, detects anomalies based on the preprocessed log data, proposes optimal countermeasures for the detected anomalies, automatically generates a report based on the proposed countermeasures, transmits the generated report, and sends notifications, with an emotion engine that recognizes user emotions. In this embodiment, the main functions of the system and its processing flow will be described.
[1503] 1. Collecting and pre-processing log data:
[1504] The server collects log data from communication devices in real time, automatically obtaining the latest log data at regular intervals via API endpoints or data streams.
[1505] The collected log data is first preprocessed. Preprocessing involves cleaning the data and converting its format to make it analyzable. For example, this involves removing incomplete data, standardizing timestamps, and extracting necessary information.
[1506] 2. Anomaly detection:
[1507] The server inputs the preprocessed log data into an anomaly detection model, which uses machine learning algorithms to accurately detect anomalies that deviate from normal data patterns. Detailed information such as the type of anomaly, the date and time of occurrence, and the scope of impact is recorded.
[1508] 3. Proposed solutions:
[1509] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which involves a process of selecting the optimal countermeasure for each type of anomaly by referencing a past database and a pattern library of countermeasures.
[1510] 4. Generate report:
[1511] The server automatically generates a report based on the detected anomalies and proposed remediation measures. The report includes details of the anomaly, the date and time of detection, the proposed remediation measures, and recommended action steps. The report is created according to a standard format and may be converted to a format such as PDF.
[1512] 5. Report Distribution and Notification:
[1513] The server sends the generated report to the designated recipient (administrator or technician) via email. Real-time notifications are also sent to the device, allowing relevant parties to quickly understand the occurrence of an abnormality and take appropriate action. Notifications include a summary of the report and a link.
[1514] 6. Emotion Engine in Action:
[1515] The emotion engine is a function for recognizing the user's emotions. It analyzes text and voice data when the user uses the system and recognizes the user's emotions.
[1516] The server adjusts the report content and notification format based on the user's emotions recognized by the emotion engine. For example, if the user is experiencing high stress, the report will include detailed explanations and prioritized solutions.
[1517] The emotion engine also further optimizes the suggested response based on the user's emotions. For example, if the user is calm, it can suggest a response that prioritizes speed.
[1518] Specific examples
[1519] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[1520] Type of anomaly: Sudden drop in signal strength
[1521] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[1522] In this case, the system behaves as follows:
[1523] 1. The server collects log data from base station A and performs preprocessing.
[1524] 2. Using the preprocessed log data, an anomaly detection model detects sudden drops in signal strength.
[1525] 3. The server will suggest the best course of action for this anomaly: "Physical check of antenna" and "Restart signal repeater."
[1526] 4. A detailed report is automatically generated based on the proposed action, including data on signal strength degradation and suggested steps to take.
[1527] 5. If the emotion engine identifies the user's emotions as high stress, a detailed explanation and prioritized actions will be added to the report.
[1528] 6. Finally, the generated report is sent to the relevant parties via email, and notifications of abnormalities and countermeasures are sent to the terminal in real time.
[1529] This enables the system to operate in a way that takes the user's emotions into account, further optimizing the entire process from fault detection to proposing countermeasures, generating reports, and notifying relevant parties.
[1530] The processing flow will be explained below.
[1531] Step 1:
[1532] The server collects log data from communication devices and automatically retrieves the latest log data at regular intervals via API endpoints or data streams.
[1533] Step 2:
[1534] The server preprocesses the collected log data by cleaning and formatting the data, removing incomplete data, standardizing the timestamp format, extracting necessary information, and preparing the data in a format suitable for analysis.
[1535] Step 3:
[1536] The server inputs the preprocessed log data into an anomaly detection model, which uses machine learning algorithms to accurately detect anomalies that deviate from normal data patterns. It then records detailed information about the detected anomalies (such as the type of anomaly, the date and time of occurrence, and the scope of impact).
[1537] Step 4:
[1538] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model, which involves a process of selecting the optimal countermeasure for each type of anomaly by referencing a past database and a pattern library of countermeasures.
[1539] Step 5:
[1540] The server automatically generates a report based on details of detected anomalies and proposed remediation actions. The report includes details of the anomaly, the date and time of detection, proposed remediation actions, and recommended action steps. The report is created according to a standard format and may be converted to formats such as PDF.
[1541] Step 6:
[1542] The emotion engine analyzes text and voice data to recognize user emotions, identifying emotions from user input and conversations and optimizing the system's response accordingly.
[1543] Step 7:
[1544] The server adjusts the report content and notification format based on the user's emotions recognized by the emotion engine. For example, if the user is experiencing high stress, the report will include detailed explanations and prioritized solutions.
[1545] Step 8:
[1546] The server sends the generated report to the designated recipient (administrator or technician) via email. It also sends real-time notifications to the devices so that the relevant parties can quickly understand the occurrence of an abnormality and take countermeasures. The notifications include a summary of the report and a link.
[1547] Specific examples
[1548] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[1549] Type of anomaly: Sudden drop in signal strength
[1550] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[1551] In this case, the system behaves as follows:
[1552] Step 1:
[1553] The server collects log data from base station A.
[1554] Step 2:
[1555] The server preprocesses the collected log data, for example, removing incomplete data and extracting necessary information.
[1556] Step 3:
[1557] The server inputs the preprocessed log data into an anomaly detection model to detect sudden drops in signal strength.
[1558] Step 4:
[1559] The server will suggest the best course of action to address any abnormalities, namely "physical check of the antenna" and "restarting the signal repeater."
[1560] Step 5:
[1561] The server automatically generates a detailed report based on the proposed action, including data on the signal strength degradation and the steps to take.
[1562] Step 6:
[1563] The emotion engine recognizes the user's emotions, for example, recognizing that the user is in a high stress state.
[1564] Step 7:
[1565] The server adjusts the report content based on the emotions recognized by the emotion engine, adding detailed explanations and prioritized actions.
[1566] Step 8:
[1567] The server sends the generated report to the relevant parties via email, and sends real-time notifications to the terminal regarding any abnormalities and countermeasures.
[1568] This process allows for quick and accurate troubleshooting while taking into consideration the user's feelings.
[1569] Example 2
[1570] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1571] Conventional anomaly detection systems were capable of automating anomaly detection, countermeasure proposals, and report generation, but they were insufficient in taking the user's emotions into consideration. As a result, when a user is in a high-stress state or a specific psychological state, the proposed countermeasures and the report content may be inappropriate or may increase the user's stress. Therefore, an objective of the present invention is to provide a system that takes the user's emotions into consideration and optimizes the entire process from anomaly detection to countermeasure proposals, report generation, and notification.
[1572] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes means for preprocessing log data collected from the communication devices, means for detecting anomalies based on the preprocessed log data, means for proposing optimal countermeasures for the detected anomalies, means for automatically generating a report based on the proposed countermeasures, means for transmitting the generated report and a notification, and means for recognizing the user's emotions and adjusting the content of the report and the format of the notification based on the recognized emotions. This enables an anomaly detection and countermeasure proposal process that takes the user's emotions into consideration.
[1573] A "communication device" is a device that sends and receives data over a network.
[1574] "Log data" refers to data that records the operations and events of a system or communication device.
[1575] "Preprocessing" refers to processes such as data cleaning and format conversion to prepare collected log data in an analyzable form.
[1576] An "anomaly detection model" is a machine learning algorithm or other analytical method used to detect anomalies in collected data.
[1577] "Countermeasures" are proposals for appropriate actions or solutions to detected anomalies.
[1578] A "report" is a document detailing detected anomalies and their corresponding actions.
[1579] "Notification" refers to a message or alert that notifies a user or administrator of an abnormality and the appropriate countermeasure.
[1580] An "emotion engine" is a system that recognizes emotions by analyzing a user's text and voice data.
[1581] "User emotion" refers to the psychological state that the user expresses to the system, and serves as the basis for the system to make adjustments.
[1582] The present invention combines a system that preprocesses log data collected from communication devices, detects anomalies based on the preprocessed log data, proposes optimal countermeasures for the detected anomalies, automatically generates a report based on the proposed countermeasures, transmits the generated report, and sends notifications, with an emotion engine that recognizes user emotions. In this embodiment, the main functions of the system and its processing flow will be described.
[1583] Key components of the system
[1584] 1. Server
[1585] The server is the central processing device of the present invention, and collects log data from communication devices, pre-processes it, analyzes it, detects abnormalities, proposes countermeasures, and generates and notifies reports.
[1586] Machine learning algorithms (e.g., LSTM model for anomaly detection) are used for anomaly detection.
[1587] 2. Communications Equipment
[1588] The communication device is a device that transmits and receives data and provides log data to the system.
[1589] Base station A is an example.
[1590] 3. Emotion Engine
[1591] It is an engine that analyzes the user's text and voice data and recognizes emotions.
[1592] The server uses information from the emotion engine to tailor reports and notifications.
[1593] 4. Terminal
[1594] A device that allows users and administrators to access the system and receive notifications and check reports.
[1595] Hardware and software used
[1596] Data Stream: Used to obtain log data from communication devices in real time.
[1597] API endpoint: An interface for collecting data from a communication device.
[1598] Database: A storage system for temporarily storing collected data.
[1599] Anomaly detection model: A machine learning algorithm (e.g., LSTM model) to analyze the preprocessed data and detect anomalies.
[1600] Emotion engine: Software that analyzes a user's text and voice to recognize emotions.
[1601] Specific examples
[1602] For example, let's say the following anomaly is detected based on log data collected from a certain communication device (base station A):
[1603] Type of anomaly: Sudden drop in signal strength
[1604] Anomaly detected: A sudden drop in signal strength was detected from around 3:00 on October 1st.
[1605] In this case, the system operates as follows.
[1606] 1. The server collects and preprocesses log data from base station A. Preprocessing includes cleaning the data, removing incomplete data, unifying timestamps, and extracting necessary information.
[1607] 2. The preprocessed log data is fed into an anomaly detection model (e.g., LSTM model) to detect sudden drops in signal strength.
[1608] 3. The server will suggest the best course of action for this anomaly: "Physical check of antenna" and "Restart signal repeater."
[1609] 4. A detailed report is automatically generated based on the proposed action, including data on signal strength degradation and suggested steps to take.
[1610] 5. The emotion engine analyzes the user's text and voice data and, if it recognizes that the user is in a high stress state, adds detailed explanations and prioritized countermeasures to the report.
[1611] 6. Finally, the generated report is sent to the relevant parties via email, and notifications of abnormalities and countermeasures are sent to the terminal in real time.
[1612] Prompt Sentence Examples
[1613] "Based on the log data from base station A, detect anomalies (sudden drop in signal strength), suggest optimal countermeasures, and generate a report. If the user is in a high stress state, add a detailed explanation to the report."
[1614] As described above, the system of the present invention uses data collected from communication devices to effectively and quickly detect anomalies and propose countermeasures, enabling flexible responses that take user emotions into consideration.
[1615] The flow of the identification process in the second embodiment will be described with reference to FIG.
[1616] Step 1:
[1617] Collecting log data
[1618] The server collects log data from a communication device (for example, base station A).
[1619] Input: Real-time log data from communication devices
[1620] How it works: The server automatically retrieves log data at regular intervals using an API endpoint.
[1621] Output: The collected raw log data is stored in a database.
[1622] Step 2:
[1623] Preprocessing of collected log data
[1624] The server pre-processes the collected log data.
[1625] Input: Collected raw log data
[1626] How it works: The server performs data cleaning to remove incomplete data and outliers, as well as standardizing timestamps and converting them into a parsable format.
[1627] Output: Preprocessed and clean log data is generated.
[1628] Step 3:
[1629] Input to the anomaly detection model
[1630] The server inputs the preprocessed log data into the anomaly detection model.
[1631] Input: Preprocessed and clean log data
[1632] How it works: The server applies a machine learning algorithm for anomaly detection (e.g., an LSTM model) to detect anomalies in the data.
[1633] Output: Anomaly detection results (detailed information such as the type of anomaly, the date and time of occurrence, and the scope of impact) are generated.
[1634] Step 4:
[1635] Proposal of countermeasures
[1636] The server proposes optimal countermeasures for anomalies detected by the anomaly detection model.
[1637] Input: Detailed information about the detected anomaly
[1638] How it works: The server searches through a database of past cases and a pattern library of countermeasures to find similar cases and selects the most appropriate response to the detected anomaly (e.g., "physical check of antenna" or "restart of signal repeater").
[1639] Output: A proposed solution is generated.
[1640] Step 5:
[1641] Automatic report generation
[1642] The server automatically generates a report based on detected anomalies and suggested remedial actions.
[1643] Input: Anomaly details and proposed remediation
[1644] How it works: The server creates reports using a standard format and converts them to formats such as PDF if necessary.
[1645] Output: The generated report is saved as a digital file.
[1646] Step 6:
[1647] Emotion recognition by emotion engine
[1648] The emotion engine analyzes the user's text and voice data to recognize emotions.
[1649] Input: Text or voice data entered by a user into the system.
[1650] How it works: The emotion engine performs analysis and recognizes the user's emotional state (e.g., high stress).
[1651] Output: The recognized emotional state of the user is generated as data.
[1652] Step 7:
[1653] Adjusting reports based on sentiment
[1654] The server adjusts the content of the report based on the user's emotions recognized by the emotion engine.
[1655] Input: The perceived emotional state of the user and the generated report
[1656] Action: The server adds detailed explanations and priority actions to the report (e.g. if the user is in a high stress state).
[1657] Output: A reconciled report is generated.
[1658] Step 8:
[1659] Report submission and notification
[1660] The server emails the generated reports to designated recipients and sends real-time notifications to the device.
[1661] Input: Coordinated Report and Notification Information
[1662] What it does: The server emails the report and sends a notification to the device, which includes a summary of the report and a link.
[1663] Output: The recipient receives the report and a notification appears on their device.
[1664] Through the above processing steps, the system collects and analyzes log data from communication devices, and generates and notifies optimal countermeasures and reports that take the user's emotions into consideration.
[1665] (Application example 2)
[1666] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1667] Conventional anomaly detection systems can detect anomalies and propose countermeasures, but there is a need for systems that can operate flexibly and take user emotions into account. In particular, in security services, it is essential to respond according to the user's stress level and urgency, and the challenge is to provide optimal reports and notifications based on the user's emotions.
[1668] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for preprocessing log data collected from the communication devices, means for detecting anomalies based on the preprocessed log data, means for proposing optimal countermeasures for the detected anomalies, means for automatically generating a report based on the proposed countermeasures, means for transmitting the generated report and a notification, means for recognizing the user's emotions, and means for adjusting the content of the report and the format of the notification based on the user's emotions. This enables flexible and prompt response according to the user's emotions.
[1669] A "communications device" is a device used to send and receive data over a network. Examples include routers, switches, and modems.
[1670] "Log data" refers to data that records the operation history of communication devices and systems. This data is used for anomaly detection and analysis.
[1671] "Preprocessing" refers to the process of making raw data into an analyzable form through processes such as cleaning and format conversion.
[1672] "Means for detecting anomalies" refers to algorithms or models for detecting anomalies in preprocessed log data. Machine learning models are often used.
[1673] "Means for proposing countermeasures" refers to a function that suggests appropriate solutions for detected anomalies. This generally involves referencing past data or specialized knowledge databases.
[1674] "Means for automatically generating reports" refers to a system function that automatically creates a report summarizing the details of the abnormality and countermeasures.
[1675] "Means for sending notifications" refers to the functionality for notifying users in real time of generated reports and important information. Notifications are primarily sent via email or push notifications.
[1676] "Means for recognizing emotions" refers to engines or algorithms for analyzing emotions from a user's voice or text data.
[1677] "Means for adjusting notification format" refers to the ability to dynamically change the content of notifications and reports based on the user's emotions. By taking emotions into consideration, we can provide users with an appropriate sharing method.
[1678] This invention is a system that monitors log data collected from communication devices in real time, proposes appropriate countermeasures when an abnormality is detected, automatically generates reports, and sends notifications. It also has a function to optimize the content of reports and notifications by recognizing the user's emotions.
[1679] System Configuration
[1680] The system consists of the following main components:
[1681] 1. Log data collection method
[1682] 2. Data preprocessing methods
[1683] 3. Anomaly detection methods
[1684] 4. Means of proposing countermeasures
[1685] 5. Automatic report generation means
[1686] 6. Notification Method
[1687] 7. Emotion recognition means
[1688] 8. Notification format adjustment means
[1689] Hardware and software used
[1690] Hardware: Servers, users' smartphones, communication devices (e.g., routers, switches)
[1691] Software: Python, Django, machine learning libraries (e.g., scikit-learn, TensorFlow), emotion recognition libraries, real-time notification services
[1692] Data Processing and Computation
[1693] 1. Log data collection and preprocessing:
[1694] The server collects log data from communication devices in real time via API endpoints and data streams, and preprocesses the collected log data by cleaning and formatting it so that it can be analyzed.
[1695] 2. Anomaly detection:
[1696] The pre-processed log data is then subjected to a machine learning model for anomaly detection, which monitors the log data in real time and detects deviations from normal data patterns with high accuracy.
[1697] 3. Proposed solutions:
[1698] When an anomaly is detected, the server refers to a database of past incidents and a pattern library of countermeasures to suggest the optimal countermeasure, which is dynamically adjusted based on the type of anomaly and the user's sentiment.
[1699] 4. Automatic report generation:
[1700] The server automatically generates a report based on the anomaly and the proposed remediation. The report includes details of the anomaly, the date and time it was detected, the proposed remediation, and recommended steps to take. The report is generated in a standard format and can be converted to PDF or other formats.
[1701] 5. Sending notifications:
[1702] Once generated, the report is emailed to the relevant parties and a real-time notification is sent to the device, including a summary of the report and a link to it.
[1703] 6. Emotion recognition:
[1704] The server analyzes text and voice data when a user uses the system and recognizes the user's emotions. This analysis is performed using an emotion recognition library.
[1705] 7. Notification Formatting:
[1706] Tailor the content of reports and notification format based on the perceived emotion, for example, if the user is experiencing high stress, provide a detailed explanation and immediate action plan in the report.
[1707] Specific examples
[1708] When an abnormality is detected in the log data collected from a certain communication device (base station A), for example, a sudden drop in signal strength, the procedure for reporting the abnormality is as follows.
[1709] 1. Data collection and pre-processing: The server collects log data from base station A and performs cleaning and format conversion.
[1710] 2. Anomaly detection: Based on the pre-processed data, the machine learning model detects drops in signal strength.
[1711] 3. Suggested solutions: Suggested solutions for this anomaly include "Physical check of antenna" and "Restart signal repeater".
[1712] 4. Emotion recognition: The emotion recognition engine analyzes the emotion the user feels when receiving this notification. For example, if the user feels high stress, a report will be generated with a detailed explanation and prompt action.
[1713] 5. Notification: The generated report and rapid response procedures are sent to the relevant parties.
[1714] Prompt Sentence Examples
[1715] "A suspicious individual has been detected on the live security camera feed. Due to the user's high stress level, please generate a detailed report with the following immediate steps: Recommendation: Immediate police notification steps."
[1716] The flow of the specific processing in the application example 2 will be described with reference to FIG.
[1717] Step 1:
[1718] The server collects log data from communication devices in real time. The input is the log data obtained from the communication devices. The server receives the log data from API endpoints or data streams and stores this data in local storage. The output is the collected log data.
[1719] Step 2:
[1720] The server preprocesses the collected log data. At this stage, data cleaning and format conversion are performed. The input is the collected raw log data, and specific processes are performed to remove incomplete data, unify timestamps, and extract necessary information. The output is preprocessed, clean log data.
[1721] Step 3:
[1722] The server detects anomalies using preprocessed log data. The input is the preprocessed log data and a machine learning model (e.g., scikit-learn, TensorFlow) is used. Specifically, an algorithm is run to identify data points that deviate from normal data patterns. The output is anomaly detection results that include information such as the type of anomaly, the date and time of occurrence, and the scope of impact.
[1723] Step 4:
[1724] The server proposes optimal countermeasures for detected anomalies. The input is the anomaly detection results, and it uses a database of past responses and a pattern library of countermeasures. The server extracts the most effective countermeasure according to the type of anomaly and proposes specific steps to take. The output is a list of recommended countermeasures.
[1725] Step 5:
[1726] The server automatically generates a report based on the proposed countermeasures. The input is the anomaly detection result and a list of countermeasures. Specifically, a report is generated in text format that includes details of the anomaly, the date and time of detection, the proposed countermeasures, and the recommended procedure. The output is the generated report, which is converted to PDF format or similar and saved.
[1727] Step 6:
[1728] The server runs an emotion engine to recognize the user's emotions. The input is the user's text or voice data, which is analyzed using an emotion recognition library. The output is the user's emotional state, including emotion categories such as high stress or low stress.
[1729] Step 7:
[1730] The server adjusts the report content and notification format based on the results of the emotion engine. The input is the generated report and emotion recognition results. Specifically, it adjusts the detail level and linguistic tone of the report according to the user's emotion and saves it in an appropriate format. The output is the adjusted report.
[1731] Step 8:
[1732] The server sends the final report and notifies the relevant parties. The input is the adjusted report. Specifically, the report is sent as an email and a real-time notification is sent to the terminal. The output is a notification to the relevant parties and a confirmation of receipt.
[1733] Prompt Sentence Examples
[1734] A suspicious individual has been detected during a live security camera feed. Due to the user's high stress state, please generate a detailed report with the following immediate steps: Recommendation: Immediate police reporting steps
[1735] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the control target 443 to output the result of the specific processing. The microphone 238 acquires voice indicating a user input regarding the result of the specific processing. The control unit 46A transmits voice data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the voice data.
[1736] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[1737] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the robot 414.
[1738] The emotion identification model 59 as an emotion engine may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to an emotion map (see FIG. 9), which is a specific mapping. Similarly, the emotion identification model 59 may determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[1739] FIG. 9 is a diagram illustrating an emotion map 400 on which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. Emotions closer to the center of the concentric circles are more primitive. Emotions representing states and actions arising from a state of mind are arranged on the outer edges of the concentric circles. The concept of emotion includes both affect and mental states. Emotions generally generated from reactions occurring in the brain are arranged on the left side of the concentric circles. Emotions generally induced by situational judgment are arranged on the right side of the concentric circles. Emotions generally generated from reactions occurring in the brain and induced by situational judgment are arranged on the upper and lower sides of the concentric circles. Furthermore, the emotion of "pleasure" is arranged on the upper side of the concentric circles, and the emotion of "discomfort" is arranged on the lower side. In this way, in the emotion map 400, multiple emotions are mapped based on the structure by which emotions are generated, and emotions that tend to occur simultaneously are mapped close to each other.
[1740] These emotions are distributed in the 3 o'clock direction on emotion map 400, and typically fluctuate between relief and anxiety. In the right half of emotion map 400, situational awareness dominates over internal sensations, resulting in a sense of calm.
[1741] The inside of emotion map 400 represents what is going on in the mind, and the outside of emotion map 400 represents behavior, so the further you go outside emotion map 400, the more visible the emotions become (the more they are expressed in behavior).
[1742] Human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. Emotions can also be created for robots, automobiles, and motorcycles, based on various balances, such as posture and remaining battery life. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. An emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on Voice Emotion Recognition and Emotional Brain Physiological Signal Analysis Systems, Tokushima University, Doctoral Dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map lists emotions belonging to the "reaction" domain, where sensation is dominant. The right half of the emotion map lists emotions belonging to the "situation" domain, where situational awareness is dominant.
[1743] The emotion map defines two emotions that promote learning. One is a negative emotion on the situation side, around the middle of "repentance" or "reflection." In other words, this occurs when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is a positive emotion on the response side, around "desire." In other words, this occurs when the robot experiences positive feelings such as "I want more" or "I want to know more."
[1744] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values indicating each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple pieces of training data that are combinations of user input and emotion values indicating each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions that are located close to each other have similar values, as in the emotion map 900 shown in FIG. 10. FIG. 10 shows an example in which multiple emotions, "relieved," "calm," and "reassuring," have similar emotion values.
[1745] The system according to the present disclosure has been described above mainly with respect to the functions of the data processing device 12, but the system according to the present disclosure is not necessarily implemented on a server. The system according to the present disclosure may be implemented as a general information processing system. The present disclosure may be implemented, for example, as a software program running on a personal computer or an application running on a smartphone, etc. The method according to the present disclosure may be provided to users in the form of SaaS (Software as a Service).
[1746] In the above embodiment, an example was given in which the specific processing is performed by one computer 22, but the technology of the present disclosure is not limited to this, and the specific processing may be distributed and performed by a plurality of computers including the computer 22. For example, the data generation model 58 may be provided in an external device of the data processing device 12, and data may be generated in the external device in accordance with input data.
[1747] In the above embodiment, an example in which the specific processing program 56 is stored in the storage 32 has been described, but the technology of the present disclosure is not limited to this. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-transitory storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-transitory storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes the specific processing in accordance with the specific processing program 56.
[1748] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.
[1749] It is not necessary to store all of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store all of the specific processing program 56 in the storage 32; only a portion of the specific processing program 56 may be stored.
[1750] The hardware resource for executing a specific process can be any of the following processors: An example of a processor is a CPU, which is a general-purpose processor that functions as a hardware resource for executing a specific process by executing software, i.e., a program. Another example of a processor is a dedicated electrical circuit, such as an FPGA (Field-Programmable Gate Array), a PLD (Programmable Logic Device), or an ASIC (Application Specific Integrated Circuit), which is a processor with a circuit configuration designed specifically for executing a specific process. Each processor has built-in or connected memory, and each processor uses the memory to execute the specific process.
[1751] The hardware resource that executes the specific processing may be configured with one of these various processors, or may be configured with a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Also, the hardware resource that executes the specific processing may be a single processor.
[1752] As an example of a system configured with a single processor, first, one processor is configured by combining one or more CPUs and software, and this processor functions as a hardware resource that executes a specific process. Second, there is a system that uses a processor that realizes the functions of an entire system including multiple hardware resources that execute a specific process on a single IC chip, as typified by SoC (System-on-a-chip). In this way, a specific process is realized using one or more of the above-mentioned various processors as hardware resources.
[1753] Furthermore, the hardware structure of these various processors can be, more specifically, an electric circuit that combines circuit elements such as semiconductor devices. The specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps may be deleted, new steps may be added, or the processing order may be rearranged, without departing from the spirit of the invention.
[1754] The above-described description and illustrations are a detailed explanation of the parts related to the technology of the present disclosure and are merely an example of the technology of the present disclosure. For example, the above description of the configuration, functions, actions, and effects is an explanation of an example of the configuration, functions, actions, and effects of the parts related to the technology of the present disclosure. Therefore, it goes without saying that unnecessary parts may be deleted, new elements may be added, or replacements may be made to the above-described description and illustrations within the scope of the gist of the technology of the present disclosure. Furthermore, to avoid confusion and facilitate understanding of the parts related to the technology of the present disclosure, the above-described description and illustrations omit explanations of common technical knowledge that do not require particular explanation to enable the implementation of the technology of the present disclosure.
[1755] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference.
[1756] The following is further disclosed regarding the above embodiment.
[1757] (Claim 1)
[1758] means for pre-processing log data collected from a communication device;
[1759] means for detecting anomalies based on the preprocessed log data;
[1760] A means for proposing optimal countermeasures for detected anomalies;
[1761] means for automatically generating a report based on the proposed remedial action;
[1762] means for transmitting the generated report and for transmitting notifications;
[1763] A system including:
[1764] (Claim 2)
[1765] 10. The system of claim 1, wherein the preprocessing means performs data cleaning and formatting.
[1766] (Claim 3)
[1767] 10. The system of claim 1, wherein the means for detecting anomalies uses a machine learning model.
[1768] (Claim 4)
[1769] 10. The system of claim 1, wherein the means for automatically generating a report generates a formatted report that includes details of the anomaly and a remedial action.
[1770] (Claim 5)
[1771] 10. The system of claim 1, wherein the sending means sends the generated report by email and sends the notification in real time.
[1772] "Example 1"
[1773] (Claim 1)
[1774] means for collecting log data collected from communication devices in real time;
[1775] means for pre-processing the collected log data;
[1776] a means for inputting the preprocessed log data into an anomaly detection model to detect anomalies;
[1777] A means for proposing optimal countermeasures for abnormalities;
[1778] means for automatically generating a report based on the proposed remedial action;
[1779] means for transmitting the generated report using email;
[1780] a means of sending real-time notifications to interested parties;
[1781] A system including:
[1782] (Claim 2)
[1783] 2. The system according to claim 1, wherein the preprocessing means cleans the data, standardizes the format of the timestamp, and extracts necessary information.
[1784] (Claim 3)
[1785] 2. The system of claim 1, wherein the means for detecting anomalies uses an anomaly detection model that employs a machine learning algorithm.
[1786] "Application Example 1"
[1787] (Claim 1)
[1788] means for pre-processing log data collected from a communication device;
[1789] means for detecting anomalies based on the preprocessed log data;
[1790] A means for proposing optimal countermeasures for detected anomalies;
[1791] means for automatically generating a report based on the proposed remedial action;
[1792] means for transmitting the generated report and for transmitting notifications;
[1793] A means of monitoring the operation logs of robots in factories in real time,
[1794] Using machine learning algorithms to detect anomalies with high accuracy using preprocessed log data;
[1795] After detecting an anomaly, the system proposes optimal countermeasures, automatically generates a report, and notifies the relevant parties.
[1796] A system including:
[1797] (Claim 2)
[1798] 10. The system of claim 1, wherein the preprocessing means performs data cleaning and formatting.
[1799] (Claim 3)
[1800] 10. The system of claim 1, wherein the means for detecting anomalies uses a machine learning model.
[1801] "Example 2: Combining Emotion Engines"
[1802] (Claim 1)
[1803] means for pre-processing log data collected from a communication device;
[1804] means for detecting anomalies based on the preprocessed log data;
[1805] A means for proposing optimal countermeasures for detected anomalies;
[1806] means for automatically generating a report based on the proposed remedial action;
[1807] means for transmitting the generated report and for transmitting notifications;
[1808] means for recognizing a user's emotion and adjusting the content of the report or the format of the notification based on the recognized emotion;
[1809] A system including:
[1810] (Claim 2)
[1811] 10. The system of claim 1, wherein the preprocessing means performs data cleaning and formatting.
[1812] (Claim 3)
[1813] 10. The system of claim 1, wherein the means for detecting anomalies uses a machine learning model.
[1814] (Claim 4)
[1815] 10. The system of claim 1, further comprising an emotion engine that analyzes a user's text and voice data to recognize emotions.
[1816] (Claim 5)
[1817] 5. The system of claim 4, further comprising: adding detailed explanations and prioritized countermeasures to the report content based on the recognized user sentiment.
[1818] "Application example 2 when combining emotion engines"
[1819] (Claim 1)
[1820] means for pre-processing log data collected from a communication device;
[1821] means for detecting anomalies based on the preprocessed log data;
[1822] A means for proposing optimal countermeasures for detected anomalies;
[1823] means for automatically generating a report based on the proposed remedial action;
[1824] means for transmitting the generated report and for transmitting notifications;
[1825] means for recognizing a user's emotion;
[1826] means for adjusting report content and notification format based on user sentiment;
[1827] A system including:
[1828] (Claim 2)
[1829] 10. The system of claim 1, wherein the preprocessing means performs data cleaning and formatting.
[1830] (Claim 3)
[1831] 10. The system of claim 1, wherein the means for detecting anomalies uses a machine learning model. [Explanation of symbols]
[1832] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Device 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robot< / url:> < / url:> < / url:> < / url:>
Claims
1. means for pre-processing log data collected from a communication device; means for detecting anomalies based on the preprocessed log data; A means for proposing optimal countermeasures for detected anomalies; means for automatically generating a report based on the proposed remedial action; means for transmitting the generated report and for transmitting notifications; A system including:
2. 2. The system of claim 1, wherein the preprocessing means performs data cleaning and format conversion.
3. The system of claim 1 , wherein the means for detecting anomalies uses a machine learning model.
4. 10. The system of claim 1, wherein the means for automatically generating a report generates a formatted report that includes details of the anomaly and a remedial action.
5. 2. The system of claim 1, wherein the sending means sends the generated report by email and sends the notification in real time.
Citation Information
Patent Citations
Persona chatbot control method and system
JP2022180282A