Systems and methods relating to anomaly detection and contact center computing environments - Patents.com

The INS model addresses the challenge of anomaly detection in contact centers by generating dynamic radius spheres around high-density regions, effectively identifying anomalies in metric data, improving data quality and cleaning in contact center environments.

JP7798893B2Active Publication Date: 2026-01-14GENESIS CLOUD SERVICES CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2023537323
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-12-21
Filing Date
2021-12-21
Publication Date
2026-01-14
Estimated Expiration
2041-12-21

AI Technical Summary

Technical Problem

Existing anomaly detection systems face challenges in effectively identifying anomalies in metric data, particularly in contact center environments, where traditional methods struggle to distinguish between inliers and outliers, especially when novel observations are present.

Method used

The INS model employs a dynamic radius sphere generation approach, using machine learning algorithms to create spheres around high-density regions in time-series-based observations, allowing for unsupervised anomaly detection by capturing data points and identifying anomalies based on coverage and concentration.

Benefits of technology

This method enhances the ability to detect anomalies by dynamically adapting to the data distribution, improving the detection of both outliers and novel observations, thereby enhancing data cleaning and quality in contact centers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007798893000001
    Figure 0007798893000001
  • Figure 0007798893000002
    Figure 0007798893000002
  • Figure 0007798893000003
    Figure 0007798893000003
Patent Text Reader

Abstract

A system for detecting anomalies in metric data provided by one or more customers, according to one embodiment, comprising: at least one processor; and at least one memory containing a plurality of instructions stored therein, which, upon execution by the at least one processor, cause the system to receive metric data indicative of a plurality of time-series-based observations for a particular customer metric; define a plurality of parameters for characterizing one or more spheres based on the metric data, each sphere being configured to capture a number of time-series-based observations for the particular customer metric; generate the one or more spheres based on the plurality of parameters; determine coverage of the metric data within the one or more spheres; and detect one or more anomalies in the metric data.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application claims priority to U.S. Provisional Patent Application No. 63 / 128,277, filed December 21, 2020, the contents of which are incorporated herein by reference in their entirety. [Background technology]

[0002] Data analysis can involve detecting anomalies in various data sets. In some cases, anomaly detection can involve assessing whether a new observation belongs to the same distribution as previous observations or should be classified as an outlier. Various systems and methods for anomaly detection have several drawbacks. Therefore, the development of alternative systems and methods for anomaly detection remains an area of ​​interest. Summary of the Invention

[0003] One embodiment is directed to unique systems, components, and methods for detecting anomalies in metric data provided by one or more customers. Other embodiments are directed to apparatus, systems, devices, hardware, methods, and combinations thereof for detecting anomalies in data provided by one or more customers.

[0004] According to one embodiment, a system for detecting anomalies in metric data provided by one or more customers may include at least one processor and at least one memory containing a plurality of instructions stored thereon, the instructions, upon execution by the at least one processor, causing the system to receive metric data indicating a plurality of time-series-based observations for a particular customer metric, define a plurality of parameters for characterizing one or more spheres based on the metric data, each sphere being configured to capture several time-series-based observations for the particular customer metric, generate the one or more spheres based on the plurality of parameters, determine coverage of the metric data within the one or more spheres, and detect one or more anomalies in the metric data. Generating the one or more spheres based on the plurality of parameters may include dynamically generating a plurality of spheres, each sphere having a radius that varies based on the plurality of time-series-based observations for the particular customer metric.

[0005] In some embodiments, defining a plurality of parameters based on metric data may include defining a minimum radius for generating at least one sphere, defining radius increments for generating one or more new spheres each having varying radii, and defining a coverage limit indicating a maximum number of metric data points to be covered by the generated sphere.

[0006] In some embodiments, generating one or more spheres based on a plurality of parameters may include determining a location corresponding to a maximum concentration of metric data based on a minimum radius.

[0007] In some embodiments, generating one or more spheres based on the plurality of parameters may include determining whether a coverage limit has been reached, and in response to determining that the coverage limit has not been reached, incrementing a radius to generate at least one new sphere based on the radius increment.

[0008] In some embodiments, generating one or more spheres based on a plurality of parameters may include determining whether the at least one new sphere provides coverage of metric data not previously provided, and, in response to determining that the at least one new sphere does not provide coverage of metric data not previously provided, filtering out metric data already covered by the previous sphere.

[0009] In some embodiments, generating one or more spheres based on a plurality of parameters may include updating a minimum radius in response to a determination that at least one new sphere provides coverage of metric data not previously provided, and updating a position in response to a determination that at least one new sphere provides coverage of metric data not previously provided.

[0010] In some embodiments, generating one or more spheres based on a plurality of parameters may include determining another location corresponding to a maximum concentration of metric data based on a minimum radius of at least one sphere and a distance between the at least one sphere and at least one nearest sphere, and generating at least one new sphere such that a center of the at least one new sphere is positioned at the another location.

[0011] In some embodiments, generating one or more spheres based on a plurality of parameters may include comparing the coverage of the metric data provided by at least one sphere with the coverage of the metric data provided by at least one nearest sphere or at least one new sphere, and selecting a sphere that provides the greatest coverage of the metric data based on the comparison for generation of another new sphere.

[0012] In some embodiments, defining the plurality of parameters based on the metric data may include filtering outliers from the metric data and defining coverage limits based at least in part on the filtered metric data.

[0013] According to another embodiment, a system may include one or more non-transitory machine-readable storage media including a plurality of instructions stored thereon, the instructions, upon execution by at least one processor, causing a system to receive metric data indicating a plurality of time-series-based observations for a particular customer metric, define a plurality of parameters for characterizing one or more spheres based on the metric data, each sphere being configured to capture several time-series-based observations for the particular customer metric, generate the one or more spheres based on the plurality of parameters, determine coverage of the metric data within the one or more spheres, and detect one or more anomalies in the metric data. Generating the one or more spheres based on the plurality of parameters may include dynamically generating a plurality of spheres, each sphere having a radius that varies based on the plurality of time-series-based observations for the particular customer metric.

[0014] In some embodiments, defining a plurality of parameters based on metric data may include defining a minimum radius for generating at least one sphere, defining radius increments for generating one or more new spheres each having varying radii, and defining a coverage limit indicating a maximum number of metric data points to be covered by the generated sphere.

[0015] In some embodiments, generating one or more spheres based on a plurality of parameters may include determining a location corresponding to a maximum concentration of metric data based on a minimum radius.

[0016] In some embodiments, generating one or more spheres based on the plurality of parameters may include determining whether a coverage limit has been reached, and in response to determining that the coverage limit has not been reached, incrementing a radius to generate at least one new sphere based on the radius increment.

[0017] In some embodiments, generating one or more spheres based on a plurality of parameters may include determining whether the at least one new sphere provides coverage of metric data not previously provided, and, in response to determining that the at least one new sphere does not provide coverage of metric data not previously provided, filtering out metric data already covered by the previous sphere.

[0018] In some embodiments, generating one or more spheres based on a plurality of parameters may include updating a minimum radius in response to a determination that at least one new sphere provides coverage of metric data not previously provided, and updating a position in response to a determination that at least one new sphere provides coverage of metric data not previously provided.

[0019] In some embodiments, defining the plurality of parameters based on the metric data may include filtering outliers from the metric data and defining coverage limits based at least in part on the filtered metric data.

[0020] According to yet another embodiment, a method for detecting anomalies in metric data provided by one or more customers may include receiving, by a contact center system or computing device, metric data indicating a plurality of time-series-based observations for a particular customer metric; defining, by the contact center system or computing device, a plurality of parameters for characterizing one or more spheres, each configured to capture several time-series-based observations for the particular customer metric, based on the metric data; generating, by the contact center system or computing device, the one or more spheres based on the plurality of parameters to determine coverage of the metric data within the one or more spheres and detect one or more anomalies in the metric data. Generating, by the contact center system or computing device, a plurality of spheres each having a radius that varies based on the plurality of time-series-based observations for the particular customer metric.

[0021] In some embodiments, defining a plurality of parameters based on the metric data may include: defining, by the contact center system or computer device, a minimum radius for generation of at least one sphere; defining, by the contact center system or computer device, radius increments for generating one or more new spheres each having a varying radius; and defining, by the contact center system or computer device, a coverage limit indicating a maximum number of metric data points to be covered by the generated sphere.

[0022] In some embodiments, generating one or more spheres based on a plurality of parameters may include determining, by the contact center system or computing device, a location corresponding to a maximum concentration of metric data based on a minimum radius.

[0023] In some embodiments, generating one or more spheres based on a plurality of parameters may include determining, by the contact center system or computer device, whether a coverage limit has been reached, and in response to determining that the coverage limit has not been reached, incrementing, by the contact center system or computer device, a radius for generation of at least one new sphere based on the radius increment.

[0024] This Summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used as an aid in limiting the scope of the claimed subject matter. Further embodiments, forms, features, and aspects of the present application will become apparent from the description and figures provided herewith. [Brief explanation of the drawings]

[0025] The concepts described herein are illustrated by way of example, and not by way of limitation, in the accompanying drawings. For simplicity and clarity of illustration, elements illustrated in the figures have not necessarily been drawn to scale. Where considered appropriate, reference labels have been repeated among the figures to indicate corresponding or analogous elements. [Figure 1] FIG. 1 is a simplified block diagram of at least one embodiment of a contact center system. [Figure 2] FIG. 1 is a simplified block diagram of at least one embodiment of a computing device. [Figure 3] 1 is a simplified flowchart of at least one embodiment of a method for detecting anomalies in data provided by one or more customers. [Figure 4] 1 is a simplified flowchart of another embodiment of a method for detecting anomalies in data provided by one or more customers. [Figure 5] 5 is a simplified flowchart of at least one embodiment of a method for generating one or more spheres that may be performed during the generation of the spheres of the method of FIG. 4. [Figure 6] A visual representation of a set of metric data points / observations. [Figure 7] FIG. 6 is a visual representation of a set of metric data points / observations with a sphere generated according to the method of FIG. 5. [Figure 8] FIG. 6 is a visual representation of a set of metric data points / observations with two spheres generated according to the method of FIG. 5. [Figure 9] FIG. 6 is a visual representation of a set of metric data points / observations with three spheres generated according to the method of FIG. 5. [Figure 10] 10 is a visual representation of a collection of metric data points / observations with multiple spheres generated according to the comparison method. [Figure 11] 6 is a visual representation of a collection of metric data points / observations with multiple spheres generated according to the method of FIG. 5. [Figure 12] A visual representation of the performance evaluation for different algorithms / models for detecting anomalies in different datasets. [Figure 13] 10 is a visual representation of a collection of metric data with spheres generated according to a comparison method. [Figure 14] 14 is a visual representation of the metric data set of FIG. 13 with a sphere generated according to the method of FIG. 5. [Figure 15] 10 is a visual representation of a collection of metric data with spheres generated according to a comparison method. [Figure 16] 16 is a visual representation of the metric data set of FIG. 15 with a sphere generated according to the method of FIG. 5. [Figure 17] FIG. 10 is a graphical representation of anomaly detection information versus metrics obtained according to a comparison method. [Figure 18] FIG. 6 is a graphical representation of anomaly detection information versus metrics obtained according to the method of FIG. 5. DETAILED DESCRIPTION OF THE INVENTION

[0026] While the concepts of the present disclosure are susceptible to various modifications and alternative forms, specific embodiments have been shown by way of example in the drawings and are herein described in detail. It should be understood, however, that there is no intention to limit the concepts of the present disclosure to the particular forms disclosed, but on the contrary, the intention is to cover all modifications, equivalents, and alternatives consistent with the scope of the present disclosure and the appended claims.

[0027] References herein to "one embodiment," "an embodiment," "exemplary embodiment," and the like indicate that the described embodiment may include a particular feature, structure, or characteristic, but that all embodiments may or may not necessarily include the particular feature, structure, or characteristic. Moreover, such phrases do not necessarily refer to the same embodiment. It should be further understood that while reference to a "preferred" component or feature may indicate the desirability of a particular component or feature with respect to one embodiment, the present disclosure is not so limited with respect to other embodiments that may omit such component or feature. Furthermore, when a particular feature, structure, or characteristic is described in connection with an embodiment, the implementation of such feature, structure, or characteristic with other embodiments, whether or not explicitly described, is within the knowledge of one of ordinary skill in the art. Furthermore, particular features, structures, or characteristics may be combined in any suitable combinations and / or subcombinations in various embodiments.

[0028] Furthermore, it should be understood that items included in a list of the form "at least one of A, B, and C" can mean (A), (B), (C), (A and B), (B and C), (A and C), or (A, B, and C). Similarly, it should be understood that items listed in the form "at least one of A, B, or C" can mean (A), (B), (C), (A and B), (B and C), (A and C), or (A, B, and C). Further, with respect to the claims, the use of words and phrases such as "a," "an," "at least one," and / or "at least one portion" should not be construed as limiting to only one of such elements unless specifically stated to the contrary, and the use of phrases such as "at least a portion" and / or "a portion" should be construed to encompass both embodiments including only a portion of such an element and embodiments including the whole of such an element unless specifically stated to the contrary.

[0029] The disclosed embodiments may, in some cases, be implemented in hardware, firmware, software, or a combination thereof. The disclosed embodiments may also be implemented as instructions stored on or executed by one or more transitory or non-transitory machine-readable (e.g., computer-readable) storage media, which may be read and executed by one or more processors. A machine-readable storage medium may be embodied as any storage device, mechanism, or other physical structure for storing or transmitting information in a form readable by a machine (e.g., volatile or non-volatile memory, a media disk, or other media device).

[0030] In the drawings, some structural or method features may be shown in a specific arrangement and / or ordering. However, it should be understood that such specific arrangement and / or ordering may not be required. Rather, in some embodiments, such features may be arranged in a different manner and / or order than that shown in the illustrative drawings, unless indicated to the contrary. Furthermore, the inclusion of a structural or method feature in a particular figure does not imply that such feature is required in all embodiments, and in some embodiments, it may not be included or may be combined with other features.

[0031] For data collection and / or data analysis purposes, in some applications it may be useful to check whether a new observation / data point belongs to the same data distribution as existing observations / data points. An observation(s) that belongs to the same data distribution as existing observations may be referred to herein as an inlier, and an observation(s) that does not belong to the same distribution as existing observations may be referred to herein as an outlier. The ability to distinguish between inliers and outliers may be particularly useful in cleaning real-world datasets.

[0032] It should be appreciated that outliers in data (e.g., training data) can often be defined as observations that are far away from others based on one or more visual representations of the data. Thus, in some cases, an outlier detection estimator may attempt to fit and / or capture areas where the data is most concentrated, while typically ignoring deviant observations or outliers.

[0033] However, in some cases, outliers may not yet exist in the data of interest. In those cases, it may be beneficial to detect whether a new observation is an outlier. A new observation that is detected to be an outlier may, at least in some embodiments, be novel. Furthermore, the detection of such outliers may be referred to herein as novelty detection.

[0034] Outlier detection and novelty detection can be performed to detect anomalies in data, especially when detecting unusual observations is desirable. Sometimes, outlier detection is referred to as "unsupervised anomaly detection," and novelty detection is referred to as "semi-supervised anomaly detection." In the context of outlier detection, estimators often assume that outliers / anomalies are located in low-density / concentrated regions, so outliers / anomalies typically cannot form high-density clusters. However, in the context of novelty detection, novelties / anomalies can form high-density clusters as long as they are located in low-density / concentrated regions of data that may be considered normal.

[0035] The systems and methods of the present disclosure are configured to implement a model hereinafter referred to as the INS (Isolation Nearest Spheres) model. It should be understood that the INS model is derived from and inspired by the need to visualize how systems, methods, and / or tools used to implement the model learn different behaviors for different metrics. Furthermore, the INS model relies on visual representations and / or graphical depictions that can be used to detect and assess the severity of anomalies. As a result, anomaly detection for time series observations can be considered similar to, or otherwise informed by, outlier detection in multivariate systems. To relate anomaly detection for time series observations to outlier detection in multivariate systems, the present disclosure contemplates the extraction of useful features from time series data that are useful for describing the continuous behavior of various metrics and are sensitive to outliers.

[0036] In some embodiments, the present disclosure provides machine learning algorithms for detecting anomalies in any time-series metric data that generate models. In some cases, the anomaly detection models contemplated herein are unsupervised and do not require any parameter definition to learn normal behavior from the metric data. Additionally, in some cases, the behavior learned from the metric data is based on knowledge spheres, each with a dynamic radius within one or more high-density regions.

[0037] In some embodiments, the present disclosure contemplates a feature selection process or mechanism for time-series-based observations for various metrics. The process may include considerations of (visual) representation of the time-series-based metric data, sensitivity to outliers in the data, and data standardization (e.g., ensuring the dimensionality of the dataset). Taking these considerations into account, the number of features (e.g., n) selected and / or determined according to the techniques of the present disclosure is based on the current value / observation for a particular metric and historical values / observations for that metric (e.g., observations received within the previous hour or day). In some embodiments, the n features contemplated by the present disclosure may include, but are not limited to, metric values, derivatives, and moving averages.

[0038] For purposes of this disclosure, the definitions provided below are applicable to the subsequent discussion of defined terms. Separation - reduction of data to specific knowledge units (i.e., performed by an INS model). Such reduction is performed to reach knowledge limits. Nearest Neighbor - INS models rely on nearest neighbor distances to determine proximity between data points. These distances are refined and / or improved using data associated only with uncovered behaviors. Spheres - Knowledge units visually represented as clusters of data points / observations. Each knowledge unit is defined by a dynamic radius and center. Behavior - The number of each feature for a particular metric (e.g., n). Coverage - the percentage of observations / data points that are located inside / captured by all spheres.

[0039] Further explanation of the INS model and the terms defined above is provided below with reference to FIGS.

[0040] 1, a simplified block diagram of at least one embodiment of a communications infrastructure and / or contact center system that may be used in conjunction with one or more of the embodiments described herein is shown. In an illustrative embodiment, contact center system 100 is embodied as or otherwise includes a system configured to implement an INS model to detect anomalies in data provided by one or more customers. Contact center system 100 may be embodied as any system capable of providing contact center services (e.g., call center services, chat center services, SMS center services, etc.) to end users and otherwise performing the functions described herein. The illustrative contact center system 100 includes a customer device 102, a network 104, a switch / media gateway 106, a call controller 108, an interactive media response (IMR) server 110, a routing server 112, a storage device 114, a statistics server 116, agent devices 118A, 118B, 118C, a media server 120, a knowledge management server 122, a knowledge system 124, a chat server 126, a web server 128, an interaction (iXn) server 130, a universal contact server 132, a reporting server 134, a media services server 136, and an analytics module 138.The illustrative embodiment of FIG. 1 includes one customer device 102, one network 104, one switch / media gateway 106, one call controller 108, one IMR server 110, one routing server 112, one storage device 114, one statistics server 116, one media server 120, one knowledge management server 122, one knowledge system 124, one chat server 126, one iXn server 130, one universal contact server 132, one reporting server 134, one media services server 136, and one analytics module. Although only one customer device 102, one network 104, one switch / media gateway 106, one call controller 108, one IMR server 110, one routing server 112, one storage device 114, one statistics server 116, one media server 120, one knowledge management server 122, one knowledge system 124, one chat server 126, one iXn server 130, one universal contact server 132, one reporting server 134, one media services server 136, and / or one analytics module 138 are shown, the contact center system 100 may, in other embodiments, include multiple customer devices 102, networks 104, switch / media gateway 106, call controller 108, IMR server 110, routing server 112, storage device 114, statistics server 116, media server 120, knowledge management server 122, knowledge system 124, chat server 126, iXn server 130, universal contact server 132, reporting server 134, media services server 136, and / or analytics module 138. Additionally, in some embodiments, one or more of the components described herein may be excluded from system 100, one or more of the components described as being independent may form part of another component, and / or one or more of the components described as forming part of another component may be independent.

[0041] It should be understood that, as used herein, the term "contact center system" is used to refer to the system and / or components thereof depicted in Figure 1, while the term "contact center" is used more generally to refer to contact center systems, the customer service providers that operate these systems, and / or the organizations or companies associated therewith. Thus, unless specifically limited otherwise, the term "contact center" generally refers to a contact center system (e.g., contact center system 100), associated customer service providers (e.g., a particular customer service provider that provides customer service through contact center system 100), and the organization or company on behalf of which customer service is provided.

[0042] By way of background, customer service providers may offer many types of services through contact centers. Such contact centers may be staffed with employees or customer service agents (or simply “agents”) who serve as an interface between a company, enterprise, government agency, or organization (hereinafter interchangeably referred to as an “organization” or “enterprise”) and people, such as users, individuals, or customers (hereinafter interchangeably referred to as “individuals” or “customers”). For example, contact center agents may assist customers in making purchasing decisions, placing orders, or resolving issues with products or services they have already received. Within a contact center, such interactions between contact center agents and external entities or customers may occur via various communication channels, such as, for example, voice (e.g., telephone calls or voice over IP, i.e., VoIP calls), video (e.g., video conferencing), text (e.g., email and text chat), screen sharing, co-browsing, and / or other communication channels.

[0043] Operationally, contact centers generally strive to provide quality service to customers while minimizing costs. For example, one way contact centers operate is to handle all customer interactions with live agents. While this approach may be entirely successful from a service quality perspective, it would likely be prohibitively expensive due to the high cost of agent labor. For this reason, most contact centers utilize some level of automated processes, such as interactive voice response (IVR) systems, interactive media response (IMR) systems, Internet robots (i.e., "bots"), automated chat modules (i.e., "chatbots"), and / or other automated processes, in place of live agents. In many cases, this has proven to be a successful strategy, as automated processes can be highly efficient at handling certain types of interactions and effective in reducing the need for live agents. Such automation allows contact centers to target the use of human agents to more difficult customer interactions, while the automated processes handle more repetitive or routine tasks. Furthermore, automated processes can be structured in a way that optimizes efficiency and promotes repeatability. Although human agents, i.e., live agents, may forget to answer certain questions or follow up on certain details, such errors are typically avoided through the use of automated processes. While customer service providers increasingly rely on automated processes to interact with customers, the use of such technologies by customers remains far less developed. Thus, on the contact center side of the interaction, IVR systems, IMR systems, and / or bots are used to automate parts of the interaction, while actions on the customer side remain manually performed by the customer.

[0044] It should be understood that the contact center system 100 can be used by customer service providers to provide various types of services to customers. For example, the contact center system 100 can be used to engage in and manage interactions in which automated processes (or bots) or human agents communicate with customers. As should be understood, the contact center system 100 can be an in-house facility of a business or enterprise for performing sales and customer service functions related to products and services available through the enterprise. In another embodiment, the contact center system 100 can be operated by a third-party service provider contracted to provide services on behalf of another organization. Furthermore, the contact center system 100 can be deployed on equipment dedicated to the enterprise or third-party service provider and / or in a remote computing environment, such as, for example, a private or public cloud environment with infrastructure to support multiple contact centers for multiple enterprises. The contact center system 100 can include software applications or programs that can be executed on-premise, remotely, or some combination thereof. Furthermore, it should be understood that various components of the contact center system 100 can be distributed across various geographic locations and are not necessarily contained in a single location or computing environment.

[0045] Furthermore, unless specifically limited otherwise, it should be understood that any of the computing elements described herein may be implemented within a cloud-based or cloud computing environment. As used herein, and further described below with reference to computing device 200, "cloud computing" or simply "cloud" is defined as a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services), which can be rapidly provisioned via virtualization, released with minimal management effort or service provider interaction, and then scaled accordingly. Cloud computing can consist of a variety of characteristics (e.g., on-demand self-service, wide area network access, resource pooling, rapid elasticity, scalable service, etc.), service models (e.g., Software as a Service ("SaaS"), Platform as a Service ("PaaS"), Infrastructure as a Service ("IaaS")), and deployment models (e.g., private cloud, community cloud, public cloud, etc.). Cloud execution models, often referred to as "serverless architectures," generally involve a service provider dynamically managing the allocation and provisioning of remote servers to achieve desired functions.

[0046] It should be understood that any of the computer-implemented components, modules, or servers described in connection with Figure 1 may be implemented via one or more types of computing devices, such as, for example, computing device 200 of Figure 2. As will be appreciated, contact center system 100 generally manages resources (e.g., personnel, computers, telecommunications equipment, etc.) to enable delivery of services via telephone, email, chat, or other communication mechanisms. Such services may vary depending on the type of contact center and may include, for example, customer service, help desk functions, emergency response, telemarketing, order taking, and / or other features.

[0047] A customer desiring to receive service from the contact center system 100 may initiate inbound communications (e.g., telephone calls, emails, chats, etc.) to the contact center system 100 via a customer device 102. While FIG. 1 shows one such customer device, namely, the customer device 102, it should be understood that any number of customer devices 102 may be present. The customer device 102 may be, for example, a communication device such as a telephone, smartphone, computer, tablet, or laptop. According to the functionality described herein, a customer may generally use the customer device 102 to initiate, manage, and conduct communications with the contact center system 100, such as telephone calls, emails, chats, text messages, web browsing sessions, and other multimedia transactions.

[0048] Inbound and outbound communications from and to the customer device 102 may typically traverse a network 104, with the nature of the network depending on the type of customer device and mode of communication being used. By way of example, the network 104 may include a telephone, cellular, and / or data service communication network. The network 104 may be a private or public switched telephone network (PSTN), a local area network (LAN), a private wide area network (WAN), and / or a public WAN such as the Internet. Additionally, the network 104 may include a wireless carrier network, including a code division multiple access (CDMA) network, a global system for mobile communications (GSM) network, or any wireless network / technology conventional in the art, including, but not limited to, 3G, 4G, LTE, 5G, etc.

[0049] The switch / media gateway 106 may be coupled to the network 104 to receive and transmit telephone calls between customers and the contact center system 100. The switch / media gateway 106 may include a telephone switch or a communication switch configured to function as a central switch for agent-level routing within the center. The switch may be a hardware switching system or may be implemented via software. For example, the switch 106 may include an automatic call distributor, a private branch exchange (PBX), an IP-based software switch, and / or any other switch having dedicated hardware and software configured to receive Internet-sourced and / or telephone network-sourced interactions from a customer and route these interactions to, for example, one of the agent devices 118. Thus, in general, the switch / media gateway 106 establishes a connection between the customer device 102 and the agent device 118, thereby establishing a voice connection between the customer and the agent.

[0050] As further shown, the switch / media gateway 106 may be coupled to a call controller 108, which, for example, serves as an adapter or interface connection between the switch and other routing, monitoring, and communication processing components of the contact center system 100. The call controller 108 may be configured to process PSTN calls, VoIP calls, and / or other types of calls. For example, the call controller 108 may include computer-telephone integration (CTI) software for interfacing with the switch / media gateway and other components. The call controller 108 may include a session initiation protocol (SIP) server for processing SIP calls. The call controller 108 may also extract data about incoming interactions, such as a customer's phone number, IP address, or email address, and then communicate this with other contact center components when processing the interaction.

[0051] The interactive media response (IMR) server 110 can be configured to enable self-help or virtual assistant functions. Specifically, the IMR server 110 can be similar to an interactive voice response (IVR) server, except that the IMR server 110 is not limited to voice and can also cover various media channels. In an example illustrating voice, the IMR server 110 can be configured with IMR scripts to query customers about their needs. For example, a bank contact center may instruct customers via an IMR script to "press 1" if they want to look up their account balance. Through ongoing interaction with the IMR server 110, customers can receive service without needing to speak with an agent. The IMR server 110 can also be configured to verify the reason a customer is contacting the contact center so that communications can be routed to the appropriate resource. IMR configuration can be implemented through the use of self-service and / or assisted-service tools, including web-based tools for developing IVR and routing applications that run within a contact center environment (e.g., Genesys® Designer).

[0052] The routing server 112 may function to route incoming interactions. For example, when it is determined that an inbound communication should be handled by a human agent, functionality within the routing server 112 may select the most appropriate agent and route the communication to that agent. This agent selection may be based on which available agent is best suited to handle the communication. More specifically, the selection of the appropriate agent may be based on a routing strategy or algorithm implemented by the routing server 112. In doing so, the routing server 112 may query data related to the incoming interaction, such as data related to the particular customer, available agents, and type of interaction, which may be stored in a particular database as described herein. Once an agent is selected, the routing server 112 may interact with the call controller 108 to route (i.e., connect) the incoming interaction to a corresponding agent device 118. As part of this connection, information about the customer may be provided to the selected agent via their agent device 118. This information is intended to enhance the service the agent can provide to the customer.

[0053] It should be appreciated that the contact center system 100 may include one or more mass storage devices (generally represented by the storage device(s) 114) for storing data in one or more databases related to the contact center's functions. For example, the storage device 114 may store customer data maintained in a customer database. Such customer data may include, for example, customer profiles, contact information, service level agreements (SLAs), and interaction history (e.g., details of previous interactions with particular customers, including the nature of the previous interactions, disposition data, wait times, handling times, and actions taken by the contact center to resolve the customer's issues). As another example, the storage device 114 may store agent data in an agent database. The agent data maintained by the contact center system 100 may include, for example, agent availability and agent profiles, schedules, skills, handling times, and / or other related data. As another example, the storage device 114 may store interaction data in an interaction database. The interaction data may include, for example, data related to numerous past interactions between customers and the contact center. More generally, unless otherwise specifically specified, it should be understood that storage device 114 may include databases and / or be configured to store data related to any of the types of information described herein, and that these databases and / or data may be accessible to other modules or servers of contact center system 100 in a manner that facilitates the functions described herein. For example, a server or module of contact center system 100 may query such databases to retrieve data stored therein or transmit data to a database for storage. Storage device 114 may take the form of, for example, any conventional storage medium and may be housed locally or operated from a remote location.By way of example, the database may be a Cassandra database, a NoSQL database, or a SQL database, and may be managed by a database management system such as Oracle, IBM DB2, Microsoft SQL Server, Microsoft Access, PostgreSQL, or the like.

[0054] Statistics server 116 may be configured to record and aggregate data related to the performance and operational aspects of contact center system 100. Such information may be compiled by statistics server 116 and made available to other servers and modules, such as reporting server 134, which may then use the data to generate reports used to manage operational aspects of the contact center and to take automated actions in accordance with the functionality described herein. Such data may relate to the status of contact center resources, such as average wait times, abandon rates, agent occupancy, and others as may be required by the functionality described herein.

[0055] The agent devices 118 of the contact center system 100 may be communication devices configured to interact with the various components and modules of the contact center system 100 in a manner that facilitates the functionality described herein. For example, the agent devices 118 may include telephones adapted for regular telephone calls or VoIP calls. The agent devices 118 may further include computing devices configured to communicate with servers of the contact center system 100, perform data processing associated with operations, and interface with customers via voice, chat, email, and other multimedia communication mechanisms in accordance with the functionality described herein. While FIG. 1 shows three such agent devices 118, namely, agent devices 118A, 118B, and 118C, it should be understood that any number of agent devices 118 may be present in a particular embodiment.

[0056] The multimedia / social media server 120 may be configured to facilitate media (non-voice) interactions with the customer device 102 and / or server 128. Such media interactions may relate to, for example, email, voicemail, chat, video, text messaging, web, social media, co-browsing, etc. The multimedia / social media server 120 may take the form of any IP router conventional in the art having dedicated hardware and software for receiving, processing, and forwarding multimedia events and communications.

[0057] The knowledge management server 122 may be configured to facilitate interactions between customers and the knowledge system 124. Generally, the knowledge system 124 may be a computer system capable of receiving questions or queries and providing answers in response. The knowledge system 124 may be included as part of the contact center system 100 or may be operated remotely by a third party. The knowledge system 124 may include an artificial intelligence computer system capable of answering questions posed in natural language by retrieving information from sources such as encyclopedias, dictionaries, newswire articles, literary works, or other documents submitted to the knowledge system 124 as reference material. As an example, the knowledge system 124 may be embodied as an IBM Watson or similar system.

[0058] The chat server 126 may be configured to conduct, orchestrate, and manage electronic chat communications with customers. Generally, the chat server 126 is configured to implement and maintain chat conversations and generate chat transcripts. Such chat communications may be conducted by the chat server 126 in a manner such that customers communicate with automated chatbots, human agents, or both. In an illustrative embodiment, the chat server 126 may function as a chat orchestration server that dispatches chat conversations between chatbots and available human agents. In such cases, the processing logic of the chat server 126 may be rule-driven to leverage intelligent workload distribution among available chat resources. The chat server 126 may also implement, manage, and facilitate user interfaces (UIs) associated with the chat feature, including UIs generated on either the customer device 102 or the agent device 118. The chat server 126 may be configured to transfer chats between automated and human sources within a single chat session with a particular customer, for example, so that the chat session transfers from a chatbot to a human agent or from a human agent to a chatbot. The chat server 126 may also be coupled to the knowledge management server 122 and the knowledge system 124 to receive suggestions and answers to inquiries posed by the customer during the chat, for example, so that links to related articles may be provided.

[0059] Web server 128 may be included to provide site hosts for various social interaction sites to which customers subscribe, such as Facebook, Twitter, and Instagram. While depicted as part of contact center system 100, it should be understood that web server 128 may be provided by a third party and / or maintained remotely. Web server 128 may also host web pages for businesses or organizations supported by contact center system 100. For example, customers may browse web pages to receive information about a particular business's products and services. Within such business web pages, mechanisms may be provided for initiating interactions with contact center system 100, for example, via web chat, voice, or email. One example of such a mechanism is a widget that may be deployed on a web page or website hosted on web server 128. As used herein, a widget refers to a user interface component that performs a specific function. In some implementations, a widget may include a graphical user interface control that may be overlaid on a web page displayed to customers over the Internet. A widget may display information in a window or text box, or include buttons or other controls that allow a user to access a particular function, such as sharing or opening a file or initiating a communication. In some implementations, a widget includes a user interface component with a portable portion of code that can be installed and executed within a separate web page without compilation. Some widgets may include corresponding or additional user interfaces and may be configured to access various local resources (e.g., calendar or contact information on the customer device) or remote resources over a network (e.g., instant messaging, email, or social networking updates).

[0060] The interaction (iXn) server 130 may be configured to manage contact center deferrable activities and their routing to human agents for completion. As used herein, deferrable activities include back-office work that can be performed offline, such as responding to email, attending training, and other activities that do not require real-time communication with customers. As an example, the interaction (iXn) server 130 may be configured to interact with the routing server 112 to select an appropriate agent to handle each deferrable activity. Once assigned to a particular agent, the deferrable activity is pushed to that agent, such that the deferrable activity is displayed on the selected agent's agent device 118. The deferrable activity may be displayed in a work bin as a task for the selected agent to complete. The work bin functionality may be implemented via any conventional data structure, such as a linked list, an array, and / or other suitable data structure. Each agent device 118 may include a work bin. As an example, the work bin may be maintained in a buffer memory of the corresponding agent device 118.

[0061] A universal contact server (UCS) 132 may be configured to retrieve information stored in a customer database and / or transmit information to the customer database for storage in the customer database. For example, UCS 132 may be utilized as part of a chat function to facilitate maintaining a history of how chats with particular customers were handled, which may then be used as a reference for how future chat communications should be handled. More generally, UCS 132 may be configured to facilitate maintaining a history of customer preferences, such as preferred media channels and best times to contact. To do this, UCS 132 may be configured to identify data related to each customer's interaction history, such as data regarding comments from agents, customer communication history, etc. Each of these data types may then be stored in a customer database or other module and retrieved as needed by the functions described herein.

[0062] The reporting server 134 may be configured to generate reports from data compiled and aggregated by the statistics server 116 or other sources. Such reports may include near-real-time or historical reports and may relate to the status of contact center resources and performance characteristics, such as average wait times, abandon rates, and / or agent occupancy. Reports may be generated automatically or in response to specific requests from requestors (e.g., agents, administrators, contact center applications, etc.). The reports may then be used to manage the operation of the contact center in accordance with the functionality described herein.

[0063] Media services server 136 may be configured to provide audio and / or video services to support contact center functions, such as IVR or IMR system prompts (e.g., playing audio files), music on hold, voicemail / single-party recording, multi-party recording (e.g., of audio and / or video calls), speech recognition, dual tone multi-frequency (DTMF) recognition, fax, audio and video transcoding, secure real-time transport protocol (SRTP), audio conferencing, video conferencing, coaching (e.g., support for a coach to eavesdrop on an interaction between a customer and an agent and for the coach to provide comments to an agent without the customer hearing the comments), call analytics, keyword spotting, and / or other related functions, according to functionality described herein.

[0064] The analytics module 138 may be configured to provide systems and methods for performing analytics on data received from multiple different data sources, as may be required by the functionality described herein. According to illustrative embodiments, the analytics module 138 may also generate, update, train, and modify predictors or models based on collected data, such as, for example, customer data, agent data, and interaction data. The models may include customer or agent behavior models. The behavior models may be used to predict, for example, customer or agent behavior in various situations, thereby enabling embodiments of the technology described herein to adjust interactions based on such predictions or allocate resources in preparation for predicted characteristics of future interactions, thereby improving overall contact center performance and customer experience. While the analytics module is described as being part of the contact center, it will be understood that such behavior models may also be implemented in customer systems (or, as used herein, the “customer side” of the interaction) and used to the benefit of the customer.

[0065] According to an illustrative embodiment, the analytics module 138 may have access to data stored in the storage device 114, including a customer database and an agent database. The analytics module 138 may also have access to an interaction database that stores data related to interactions and interaction content (e.g., transcripts of interactions and events detected therein), interaction metadata (e.g., customer identifier, agent identifier, interaction medium, interaction length, interaction start and end times, department, tagged categories), and application settings (e.g., interaction paths through the contact center). Additionally, the analytics module 138 may be configured to search the data stored in the storage device 114 for use in developing and training algorithms and models, for example, by applying machine learning techniques.

[0066] One or more of the included models may be configured to predict customer or agent behavior and / or aspects related to contact center operation and performance. Additionally, one or more of the models may be used for natural language processing, including, for example, intent recognition. The models may be developed based on known first-principles equations describing the system, data resulting in empirical models, or a combination of known first-principles equations and data. When developing models for use in the present embodiments, first-principles equations are often not available or easily derived, so building empirical models based on collected and stored data may generally be preferred. To adequately capture the relationships between manipulated / disturbance variables and controlled variables of a complex system, in some embodiments, it may be preferred that the model be nonlinear. This is because nonlinear models may exhibit curvilinear relationships between manipulated / disturbance variables and controlled variables rather than the linear relationships common in complex systems such as those discussed herein. Given the aforementioned requirements, machine learning or neural network-based approaches may be preferred for implementing the models. For example, neural networks may be developed based on empirical data using advanced regression algorithms.

[0067] The analysis module 138 may further include an optimizer. As will be appreciated, an optimizer may be used to minimize a "cost function" objective subject to a set of constraints, where the cost function is a mathematical expression of a desired objective or system behavior. Because the model may be nonlinear, the optimizer may be a nonlinear programming optimizer. However, it is contemplated that the techniques described herein may be implemented using a variety of different types of optimization approaches, individually or in combination, including, but not limited to, linear programming, quadratic programming, mixed-integer nonlinear programming, stochastic programming, global nonlinear programming, genetic algorithms, particle / swarm techniques, etc.

[0068] According to some embodiments, the model and optimizer may be used together in an optimization system. For example, the analytics module 138 may utilize the optimization system as part of an optimization process in which aspects of contact center performance and operation are optimized or at least enhanced. This may include, for example, features related to customer experience, agent experience, interaction routing, natural language processing, intent recognition, or other functionality related to automated processes.

[0069] The various components, modules, and / or servers in FIG. 1 (as well as other figures contained herein) may each include one or more processors that execute computer program instructions and interact with other system components to perform the various functions described herein. Such computer program instructions may be stored in memory implemented using standard memory devices such as, for example, random-access memory (RAM), or may be stored on other non-transitory computer-readable media such as, for example, a CD-ROM, a flash drive, etc. Although each of the server functions is described as being provided by a particular server, those skilled in the art should understand that the functions of the various servers may be combined or integrated into a single server, or the functions of a particular server may be distributed across one or more other servers without departing from the scope of the technology described herein. Additionally, the terms “interaction” and “communication” are used interchangeably and generally refer to any real-time and non-real-time interaction using any communication channel, including, but not limited to, telephone calls (PSTN or VoIP calls), email, Vmail, video, chat, screen sharing, text messages, social media messages, WebRTC calls, etc. Access to and control of components of contact center system 100 may be affected through user interfaces (UIs), which may be generated on customer devices 102 and / or agent devices 118. As previously mentioned, contact center system 100 may be operated as a hybrid system in which some or all components are hosted remotely, such as in a cloud-based or cloud computing environment. It should be understood that each of the devices of contact center system 100 may be embodied as part of, include, or form part of one or more computing devices similar to computing device 200 described below with reference to FIG. 2 .

[0070] Referring now to FIG. 2 , a simplified block diagram of at least one embodiment of a computing device 200 is shown. In the illustrative embodiment, the computing device 200 is embodied as or otherwise includes a system configured to implement an INS model to detect anomalies in data provided by one or more customers. The illustrative computing device 200 depicts at least one embodiment of each of the computing devices, systems, servicers, controllers, switches, gateways, engines, modules, and / or computing components (e.g., which may be collectively referred to interchangeably as computing devices, servers, or modules for brevity herein) described herein. For example, various computing devices may be processes or threads running on one or more processors of one or more computing devices 200, which may be executing computer program instructions and interacting with other system modules to perform various functions described herein. Unless specifically limited otherwise, functionality described in the context of multiple computing devices may be integrated into a single computing device, or various functionality described in the context of a single computing device may be distributed across several computing devices. Furthermore, with respect to a computing system described herein, such as the contact center system 100 of FIG. 1, the various servers and computer devices of that system may be located on a local computing device 200 (e.g., on-site in the same physical location as the contact center agents), a remote computing device 200 (e.g., off-site, i.e., in a cloud-based environment, or in a cloud computing environment, e.g., in a remote data center connected via a network), or some combination thereof.In some embodiments, functionality provided by a server located on an off-site computing device may be accessed and provided via a virtual private network (VPN) as if such server were on-site, or functionality may be provided using software as a service (SaaS) accessed over the internet using various protocols, e.g., by exchanging data via extensible markup language (XML), JSON, and / or functionality may be otherwise accessed / utilized.

[0071] In some embodiments, computing device 200 may be embodied as a server, a desktop computer, a laptop computer, a tablet computer, a notebook, a netbook, an Ultrabook™, a mobile phone, a mobile computing device, a smartphone, a wearable computing device, a personal digital assistant, an Internet of Things (IoT) device, a processing system, a wireless access point, a router, a gateway, and / or any other computing, processing, and / or communication device capable of performing the functions described herein.

[0072] The computing device 200 includes a processing device 202 that executes algorithms and / or processes data according to operational logic 208, an input / output device 204 that enables communication between the computing device 200 and one or more external devices 210, and a memory 206 that stores data received from the external device 210 via the input / output device 204, for example.

[0073] The input / output devices 204 enable the computing device 200 to communicate with external devices 210. For example, the input / output devices 204 may include a transceiver, a network adapter, a network card, an interface, one or more communication ports (e.g., a USB port, a serial port, a parallel port, an analog port, a digital port, VGA, DVI, HDMI, FireWire, CAT5, or any other type of communication port or interface), and / or other communication circuitry. The communication circuitry of the computing device 200 may be configured to conduct such communication using any one or more communication technologies (e.g., wireless or wired communication) and associated protocols (e.g., Ethernet, Bluetooth, Wi-Fi, WiMAX, etc.) depending on the particular computing device 200. The input / output devices 204 may include hardware, software, and / or firmware suitable for implementing the techniques described herein.

[0074] External device 210 may be any type of device that allows data to be input or output from computing device 200. For example, in various embodiments, external device 210 may be embodied as one or more of the devices / systems described herein and / or portions thereof. Furthermore, in some embodiments, external device 210 may be embodied as another computing device, a switch, a diagnostic tool, a controller, a printer, a display, an alarm, a peripheral device (e.g., a keyboard, a mouse, a touchscreen display, etc.), and / or any other computing, processing, and / or communication device capable of performing the functions described herein. Furthermore, it should be understood that in some embodiments, external device 210 may be integrated into computing device 200.

[0075] Processing device 202 may be embodied as any type of processor capable of performing the functions described herein. In particular, processing device 202 may be embodied as one or more single-core or multi-core processors, microcontrollers, or other processors or processing / control circuitry. For example, in some embodiments, processing device 202 may include or be embodied as an arithmetic logic unit (ALU), a central processing unit (CPU), a digital signal processor (DSP), a graphics processing unit (GPU), a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), and / or another suitable processor. Processing device 202 may be of a programmable type, a dedicated hardwired state machine, or a combination thereof. A processing device 202 having multiple processing units may utilize distributed processing, pipelined processing, and / or parallel processing in various embodiments. Furthermore, processing device 202 may be dedicated to performing only the operations described herein, or may be utilized in one or more additional applications. In an illustrative embodiment, processing device 202 is programmable, executing algorithms and / or processing data according to operating logic 208 defined by programming instructions (e.g., software or firmware) stored in memory 206. Additionally or alternatively, operating logic 208 of processing device 202 may be defined at least in part by hardwired logic or other hardware. Furthermore, processing device 202 may include one or more components of any type suitable for processing signals received from input / output device 204 or from other components or devices and providing a desired output signal. Such components may include digital circuits, analog circuits, or a combination thereof.

[0076] Memory 206 may be one or more types of non-transitory computer-readable media, such as solid-state memory, electromagnetic memory, optical memory, or a combination thereof. Furthermore, memory 206 may be volatile and / or non-volatile, and in some embodiments, some or all of memory 206 may be of a portable type, such as a disk, tape, memory stick, cartridge, and / or other suitable portable memory. During operation, memory 206 may store various data and software used during operation of computing device 200, such as an operating system, applications, programs, libraries, and drivers. It should be understood that memory 206 may store data manipulated by operating logic 208 of processing device 202, such as, for example, data representing signals received from and / or transmitted to input / output devices 204, in addition to or instead of storing programming instructions defining operating logic 208. As shown in FIG. 2, memory 206 may be included in and / or coupled to processing device 202, depending on the particular embodiment. For example, in some embodiments, processing device 202, memory 206, and / or other components of computing device 200 may form part of a system-on-a-chip (SoC) and be integrated into a single integrated circuit chip.

[0077] In some embodiments, various components of computing device 200 (e.g., processing device 202 and memory 206) may be communicatively coupled via an input / output subsystem, which may be embodied as circuits and / or components for facilitating input / output operations with processing device 202, memory 206, and other components of computing device 200. For example, the input / output subsystem may be embodied as or may otherwise include a memory controller hub, an input / output control hub, firmware devices, communication links (i.e., point-to-point links, bus links, wires, cables, light guides, printed circuit board traces, etc.), and / or other components and subsystems for facilitating input / output operations.

[0078] Computing device 200 may, in other embodiments, include other or additional components, such as those commonly found in a typical computing device (e.g., various input / output devices and / or other components). It should be further understood that one or more of the components of computing device 200 described herein may be distributed across multiple computing devices. In other words, the techniques described herein may be employed by a computing system including one or more computing devices. In addition, while only a single processing device 202, I / O device 204, and memory 206 are illustratively shown in FIG. 2 , it should be understood that a particular computing device 200 may, in other embodiments, include multiple processing devices 202, I / O devices 204, and / or memory 206. Furthermore, in some embodiments, two or more external devices 210 may communicate with computing device 200.

[0079] Computing device 200 may be one of multiple devices connected by a network or to other systems / resources via a network. The network may be embodied as any one or more types of communications network capable of facilitating communication between various devices communicatively connected via the network. Thus, the network may include one or more networks, routers, switches, access points, hubs, computers, client devices, endpoints, and / or other intervening network devices. For example, the network may be embodied as or otherwise include one or more cellular networks, telephone networks, local or wide area networks, publicly available global networks (e.g., the Internet), ad hoc networks, short range communications links, or combinations thereof. In some embodiments, the network may include circuit-switched voice or data networks, packet-switched voice or data networks, and / or any other network capable of carrying voice and / or data. In particular, in some embodiments, the network may include an Internet Protocol (IP)-based network and / or an asynchronous transfer mode (ATM)-based network. In some embodiments, the network may handle voice traffic (e.g., via a Voice over IP (VOIP) network), web traffic, and / or other network traffic, depending on the particular embodiment and / or the devices in the system that communicate with each other.In various embodiments, the networks may include analog or digital wired and wireless networks (e.g., IEEE 802.11 networks, Public Switched Telephone Networks (PSTN), Integrated Services Digital Networks (ISDN), and Digital Subscriber Lines (xDSL)), Third Generation (3G) mobile networks, Fourth Generation (4G) mobile networks, Fifth Generation (5G) mobile networks, wired Ethernet networks, private networks (e.g., intranets, etc.), radio, television, cable, satellite, and / or any other distribution or tunneling mechanism for carrying data, or any suitable combination of such networks. It should be understood that various devices / systems may communicate with each other over different networks depending on the source and / or destination device / system.

[0080] It should be understood that computing device 200 may communicate with other computing devices 200 via any type of gateway or tunneling protocol, such as Secure Sockets Layer or Transport Layer Security. Network interfaces may include built-in network adapters, such as network interface cards, suitable for interfacing a computing device to any type of network capable of performing the operations described herein. Furthermore, the network environment may be a virtual network environment in which various network components are virtualized. For example, the various machines may be virtual machines implemented as software-based computers running on a physical machine. The virtual machines may share the same operating system, or in other embodiments, different operating systems may run on each virtual machine instance. For example, a "hypervisor" type of virtualization is used in which multiple virtual machines run on the same host physical machine, each functioning as if it had its own dedicated box. Other types of virtualization may be employed in other embodiments, such as networks (e.g., via software-defined networking) or functions (e.g., via network function virtualization).

[0081] Accordingly, one or more of the computing devices 200 described herein may be embodied as or form a part of one or more cloud-based systems. In a cloud-based embodiment, the cloud-based system may be embodied, for example, as a server-ambiguous computing solution that executes instructions on demand, executes instructions only when prompted by specific activities / triggers, and does not consume computing resources when not in use. That is, the system may be embodied as a virtual computing environment residing “on” a computing system (e.g., a distributed network of devices) in which various virtual functions (e.g., Lambda functions, Azure functions, Google Cloud Functions, and / or other suitable virtual functions) may be executed corresponding to the functionality of the system described herein. For example, when an event occurs (e.g., data is transferred to the system for processing), the virtual computing environment may be communicated (e.g., via a request to the virtual computing environment's API), which may then route the request to the correct virtual function (e.g., a particular server-ambiguous computing resource) based on a set of rules. Thus, when a request for transmission of data is made by a user (e.g., via an appropriate user interface to the system), an appropriate virtual function may be executed to perform the action before deleting the instance of the virtual function.

[0082] Referring now to FIG. 3 , in use, a system or device may perform method 300 for detecting anomalies in data provided by one or more customers. It should be understood that in some embodiments, the system may be embodied as a contact center system (e.g., contact center system 100 of FIG. 1 ) and / or a computing device (e.g., computing device 200 of FIG. 2 ) or system / device thereof. Furthermore, in some embodiments, the system may be embodied as or otherwise include a set of tools for assisting in operational monitoring, management, and troubleshooting of various platforms. In one example, the system may be embodied as or otherwise include a suite of tools provided by Genesys Workbench (WB) 9.2 or any subsequent release(s) thereof. In particular, the system may incorporate various features of, for example, the Workbench Anomaly Detection (AD) functionality. Finally, it should be understood that certain blocks of method 300 are illustrated by way of example, and that such blocks may be combined or divided, added or removed, and / or reordered, in whole or in part, depending on the particular embodiment, unless stated to the contrary.

[0083] The illustrative method 300 begins at block 312, where the system receives metric data. In some embodiments, the metric data may be provided from a source external and / or remote to the system, and the system may be communicatively coupled to the source to receive the metric data from the source. In either case, in the illustrative embodiment, the metric data represents time-series-based observations of particular customer metrics, and the selection and / or specification of the metrics may be based on and / or tailored to the specific needs of a particular customer. Receiving the metric data by the system at block 312 may include or otherwise be associated with capturing the metric data from a source (e.g., CPU, RAM, disk, network).

[0084] At block 314 of illustrative method 300, the system defines parameters characterizing one or more spheres based on the metric data. Further details regarding the definition of these parameters are described below with reference to FIG. 4 (i.e., block 414). As is evident from the foregoing, each of the one or more spheres is configured to capture a number of time-series-based observations from the metric data related to a particular customer metric such that the observations lie within the sphere.

[0085] At block 316 of illustrative method 300, the system generates one or more spheres based on the parameters defined at block 314. Further details regarding sphere generation are described below with reference to FIG. 5. In an illustrative embodiment, to perform block 316, the system performs blocks 318 and 320. At block 318, the system determines coverage of metric data within one or more spheres. At block 320, the system dynamically generates multiple spheres with varying radii based on time-series-based observations from metric data related to particular customer metrics. In some embodiments, blocks 318 and 320 may be combined into a single block. In one example, the coverage determination at block 318 may be combined with the dynamic generation of spheres at block 320.

[0086] In block 322 of illustrative method 300, the system saves model parameters (e.g., parameters associated with sphere generation in block 316). In some embodiments, execution of block 322 may represent or be otherwise associated with the complete creation of the INS model.

[0087] In block 324 of the example method 300, the system detects one or more anomalies in the metric data based on the sphere generated in block 316 and / or the model parameters saved in block 322. In some embodiments, performance of block 324 may represent or otherwise be associated with anomaly detection activities performed subsequent to the creation of an INS model.

[0088] Although blocks 312-324 are described relatively serially, it should be understood that various blocks of method 300 may be performed in parallel in some embodiments.

[0089] Referring now to FIG. 4 , in use, a system or device may perform method 400 for detecting anomalies in data provided by one or more customers. Method 400 may be similar to method 300, and some blocks of method 400 may provide further details relative to corresponding blocks of method 300, as alluded to above. It should be understood that in some embodiments, the system may be embodied as a contact center system (e.g., contact center system 100 of FIG. 1 ) and / or a computing device (e.g., computing device 200 of FIG. 2 ) or system / device thereof. It should be understood that certain blocks of method 400 are illustrated by way of example, and that such blocks may be combined, divided, added, removed, and / or reordered in whole or in part, depending on the particular embodiment, unless stated to the contrary.

[0090] The illustrative method 400 begins at block 402, where the system receives metric data. It should be understood that, in at least some embodiments, block 402 corresponds to block 302 of method 300. In the illustrative embodiment, to perform block 402, the system performs block 404. In block 404, the system retrieves or retrieves metric data from a source (e.g., a customer platform). However, it should be understood that in some embodiments, block 404 may be omitted.

[0091] In block 406 of illustrative method 400, the system initializes an anomaly detection model (INS model). In some embodiments, block 406 may be embodied as or otherwise include an input block to the INS model, where the metric data received in block 402 is provided to the INS model. Furthermore, in some embodiments, block 406 may be incorporated into block 402.

[0092] At block 408 of illustrative method 400, the system standardizes one or more features of the INS model. To do so, in an illustrative embodiment, the system performs blocks 410 and 412. At block 410, the system identifies one or more features of interest for the metric data received at block 402. These features, in at least some embodiments, may include mathematical parameters for analyzing the metric data (e.g., statistics, derivatives, weighted averages, etc.), mathematical parameters for determining a particular distribution of the metric data, and / or mathematical parameters for identifying one or more outliers in the metric data. At block 412, the system normalizes the features identified at block 410 based on one or more frames of reference. In some embodiments, at block 412, the system establishes one or more frames of reference for evaluating the features identified at block 410.

[0093] At block 414 of illustrative method 400, the system defines parameters characterizing one or more spheres based on the metric data. It should be understood that, in at least some embodiments, block 414 corresponds to block 304 of method 300. It should further be understood that, in at least some embodiments, the system's performance of block 414 serves as a prelude to the subsequent generation of one or more spheres. In an illustrative embodiment, to perform block 414, the system performs blocks 416, 418, 424, 426, 428, 430, and 432. Each of these blocks is described below.

[0094] At block 416 of illustrative method 400, the system obtains or develops a distance matrix for the metric data received at block 402. In some embodiments, block 416 may be incorporated into block 410. In either case, the distance matrix obtained at block 416 enables the system to determine distances between observations / data points included in the metric data.

[0095] At block 418 of illustrative method 400, based on the distance matrix obtained at block 416, the system determines a nearest neighbor distance value for each observation / data point in the metric data. In an illustrative embodiment, to perform block 418, the system performs blocks 420 and 422. At block 420, the system determines the average of the nearest neighbor distances for all observations / data points in the metric data. At block 422, the system determines a maximum bound for the nearest neighbor distance values ​​according to a Tukey test. In some embodiments, the system may perform blocks 420 and 422 in parallel with each other.

[0096] At block 424 of illustrative method 400, the system defines a radius increment for generating one or more spheres. As will be apparent from the description below, in at least some embodiments, the radius increment may be used in combination with a minimum sphere radius, described below, to generate one or more new spheres after generating the first / initial sphere. Furthermore, due at least in part to variations in the radius increment and the minimum sphere radius over the course of performing method 400, the one or more new spheres generated using the radius increment may have varying radii. In some embodiments, the definition of the radius increment at block 424 is based on the average determined by the system at block 420.

[0097] At block 426 of illustrative method 400, the system defines a minimum sphere radius for generation of at least one sphere. The minimum sphere radius, in at least some embodiments, may be used to generate a first / initial sphere. In some embodiments, the definition of the minimum sphere radius at block 426 is based on a maximum limit determined by the system at block 422. Furthermore, in some embodiments, the system may perform blocks 424 and 426 in parallel with each other.

[0098] At block 428 of illustrative method 400, the system determines a density for the generation of at least one sphere. In some embodiments, the density corresponds to or is otherwise embodied as the number of observations / data points of metric data that fall within and are captured by the first / initial sphere. The density of the sphere, in at least some embodiments, may be determined by or embodied as the concentration of observations / data points in a particular region. Additionally, in some embodiments, the determination of the sphere density at block 428 is based on the distance matrix obtained by the system at block 416 and the minimum sphere radius defined by the system at block 426.

[0099] At block 430 of illustrative method 400, the system applies a density filter to the sphere density determination made at block 428. In some embodiments, the density filter applied by the system at block 430 filters out outliers or unusual / unusual observations from the metric data such that they do not affect the definition of coverage limits, as described below.

[0100] At block 432 of the illustrative method 400, the system defines a coverage limit indicating the maximum number of observations / data points that will be covered by the sphere. In the illustrative embodiment, the coverage limit defined by the system at block 432 is based at least in part on the filtered metric data from block 430.

[0101] At block 434 of the illustrative method 400, the system generates one or more spheres based on the parameters defined in block 414. It should be appreciated that, in at least some embodiments, block 434 corresponds to block 306 of method 300.

[0102] Although blocks 402-434 are described relatively serially, it should be understood that various blocks of method 400 may be performed in parallel in some embodiments.

[0103] 5 , in use, to perform block 434 of method 400, a system or device may execute method 500. Method 500 may, in at least some embodiments, be similar to block 306 of method 300. It should be understood that in some embodiments, the system may be embodied as a contact center system (e.g., contact center system 100 of FIG. 1 ) and / or a computing device (e.g., computing device 200 of FIG. 2 ) or system / device thereof. It should be understood that certain blocks of method 500 are illustrated by way of example, and that such blocks may be combined, divided, added, removed, and / or rearranged, in whole or in part, depending on the particular embodiment, unless stated to the contrary.

[0104] Illustrative method 500 begins at block 502, where the system detects one or more spheres that have already been generated. It should be understood that in some cases (e.g., during generation of the first / initial spheres), no spheres may be detected at block 502. Thus, in these cases, block 502 may optionally be omitted from the method.

[0105] At block 504 of illustrative method 500, the system determines a density for the generation of at least one sphere. In some embodiments, the density corresponds to or is otherwise embodied as the number of observations / data points of the metric data that fall within and are captured by the first / initial sphere. In other embodiments, the density corresponds to or is otherwise embodied as the number of observations / data points of the metric data that fall within and are captured by the first / initial sphere and one or more spheres closest to the first / initial sphere. In an illustrative embodiment, to implement block 504, the system implements blocks 506, 508, 510, and 512.

[0106] At block 506 of illustrative method 500, the system determines density based on the minimum sphere radius defined at block 426 of method 400. At block 508 of illustrative method 500, the system determines density based on the closest detected sphere (e.g., the sphere detected at block 502). It should be understood that in some cases (e.g., during generation of the first / initial sphere), the closest sphere may not be detected and the system may not perform block 508. Furthermore, it should be understood that in other cases (e.g., when one or more closest spheres are generated subsequent to generation of the first / initial sphere), the determination of density at block 504 may be based on both the minimum sphere radius defined at block 426 of method 400 and the closest detected sphere (e.g., from block 502). Thus, in these cases, blocks 506 and 508 may be combined into a single block.

[0107] At block 510 of illustrative method 500, the system determines a location corresponding to the greatest concentration of metric data based at least in part on the minimum sphere radius defined at block 426. In some cases, the location determined by the system at block 510 may also be based on the nearest detected sphere. At block 512, the system generates at least one sphere such that the center of the sphere is located at the location determined at block 510. The at least one sphere generated by the system at block 512 may, at least in some cases, correspond to the first / initial sphere. In other cases, the at least one sphere generated by the system at block 512 may correspond to a sphere generated after the first / initial sphere. In those cases, the system may (i) determine another location corresponding to the greatest concentration of metric data based on the minimum sphere radius defined at block 426 and the distance between the first / initial sphere and at least one nearest sphere (i.e., at block 510), and (ii) generate at least one new sphere such that the center of the at least one new sphere is located at another location (i.e., at block 512).

[0108] At block 514 of illustrative method 500, the system compares the coverage of the metric data provided by the new or most recently generated sphere with the coverage of the metric data provided by one or more reference spheres. In one example, the reference sphere includes a first / initial sphere. In another example, the reference sphere(s) include the first / initial sphere and at least one nearest sphere subsequently generated to the first sphere. Of course, if the sphere generated by the system at block 512 corresponds to the first / initial sphere, then in at least some embodiments, execution of block 514 may be omitted.

[0109] At block 516 of illustrative method 500, the system selects the sphere (i.e., of the spheres compared at block 514) that provides the greatest coverage of the metric data for generation of another new sphere. It should be understood that, in at least some embodiments, if the sphere generated by the system at block 512 corresponds to the first / initial sphere, execution of block 516 may be omitted.

[0110] At block 518 of the illustrative method 500, the system determines whether the coverage limit defined at block 432 of the method 400 has been reached.

[0111] At block 520 of the illustrative method 500, in response to determining at block 518 that the coverage limit has been reached, the system saves the anomaly detection model (ie, the INS model).

[0112] At block 522 of the illustrative method 500, the system finishes training the model based on the metric data.

[0113] At block 524 of illustrative method 400, in response to a determination at block 518 that the coverage limit has not been reached, the system increments the radius for the generation of at least one new sphere based on the radius increment defined at block 424 of method 500.

[0114] At block 526 of the illustrative method 500, the system determines whether at least one new sphere (whose radius is incremented at block 524) provides coverage of metric data that was not previously provided.

[0115] At block 528 of illustrative method 500, in response to a determination at block 526 that at least one new sphere provides coverage of metric data not previously provided, the system updates the minimum sphere radius (e.g., the minimum sphere radius defined at block 426 of method 400) and location (e.g., the location described above with reference to block 512) corresponding to the center for generating the next sphere.

[0116] At block 530 of illustrative method 500, in response to a determination at block 526 that the at least one new sphere does not provide coverage of metric data that was not previously provided, the system filters out metric data associated with the at least one new sphere.

[0117] Although blocks 502-530 are described relatively serially, it should be understood that various blocks of method 500 may be performed in parallel in some embodiments.

[0118] Several unique features and / or advantages may be associated with the execution and implementation of the illustrative INS model by the system. In one aspect, because the model can be trained without regard to specific customer metrics, the model provides automatic parameter tuning across a wide range of different metrics. In another aspect, because the model does not depend on a predetermined number of spheres to be generated for a specific customer metric, spheres may be generated according to each iteration of the model, which may, at least in some cases, provide greater accuracy and / or precision. In yet another aspect, because the positions of spheres generated by the model are determined based on high-density / high-concentration areas, the model avoids limitations associated with positioning spheres according to random probability distributions. In yet another aspect, by filtering / removing metric data points already covered by previous iterations, the computational complexity of the model is reduced compared to other configurations. In a further aspect, the dynamic radius calculations performed during each model iteration, and the spheres with variable radii generated based on those calculations, enable expanded data coverage using fewer spheres than may be required by other configurations. In yet another aspect, the model can use data points outside of existing spheres to generate new spheres, merge spheres with each other, and / or capture model mutations without requiring historical data for specific customer metrics. In an additional aspect, because the model ignores data points covered by previous iterations, the model may achieve a degree of accuracy and / or precision not achieved by other configurations. Furthermore, it should be appreciated that the model's reduced computational complexity may minimize the storage space (e.g., in memory) required to store model data. Finally, the model can provide improved simplicity for calculating anomaly scores based on distance to nearest spheres.

[0119] 6, a set 600 of metric data points / observations is shown after feature selection and before data analysis and generation of spheres based on the INS model. In an illustrative embodiment, the representation of the metric data points shown in FIG. 6 correlates to or otherwise corresponds to the normalized representation of the model features (e.g., the representation after the system performs block 408). Additionally, in the illustrative example, the set 600 of data points includes approximately 288 points collected over one day. Of course, it should be understood that in other examples, the set 600 can include another suitable number of data points collected over another suitable period of time.

[0120] 7, based on a set 600 of data points / observations, at least one iteration of an INS model by the system (e.g., by methods 300, 400, 500) generates a sphere 700 having a center 702 and a radius 704. In an illustrative example, the center 702 is located at the maximum concentration / density of data points within the sphere 700 with the smallest sphere radius. Further, in an illustrative example, the sphere 700 provides approximately 25% coverage of the data points within the set 600. In some embodiments, a larger sphere may exhibit a dominant behavior with multiple single behaviors.

[0121] 8 , multiple iterations of the INS model by the system (e.g., by methods 300, 400, 500) based on set 600 of data points / observations generates another sphere 800 having a center 802 and a radius 804. In the illustrative embodiment, radius 804 is different from and smaller than radius 704, and spheres 700, 800 are spaced apart from one another. Additionally, in the illustrative embodiment, center 802 is located at the maximum concentration / density of data points within sphere 800. Finally, in the illustrative example, spheres 700, 800 collectively provide approximately 47% coverage of the data points in set 600.

[0122] 9 , multiple iterations of the INS model by the system (e.g., by methods 300, 400, 500) based on set 600 of data points / observations generates another sphere 900 having a center 902 and a radius 904. In the illustrative embodiment, radius 904 is different from and larger than radius 804, and spheres 700, 800, 900 are spaced apart from one another. Additionally, in the illustrative embodiment, center 902 is located at the maximum concentration / density of data points within sphere 900. Finally, in the illustrative example, spheres 700, 800, 900 collectively provide approximately 72% coverage of the data points in set 600.

[0123] Referring now to FIG. 10, based on a set of data points / observations 600: Running a comparison model different from the INS model (e.g., in a manner different from illustrative methods 300, 400, 500) generates a set 1000 of spheres, each having the same radius. In the comparison example, set 1000 includes 21 spheres.

[0124] 11 , multiple iterations of an INS model by a system (e.g., by methods 300, 400, 500) based on a set of data points / observations 600 generates a set of spheres 1100 having varying radii. In the illustrative example, set 1100 includes seven spheres (i.e., spheres 700, 800, 900, 1102, 1104, 1106, 1108). In at least some cases, set 1100 provides equal or better coverage of set 600 than set 1000, using fewer spheres.

[0125] Referring now to FIG. 12 , performance evaluation 1200 illustrates the performance of an INS model compared to other algorithms based on various datasets. The models / algorithms illustrated include (i) one-class SVM 1202, (ii) isolation forest (iForest) 1204, (iii) local outlier factor 1206, (iv) isolation nearest neighbor ensemble (iNNE) 1208, (v) isolation nearest neighbor sphere with constant sphere radius (INSS) 1210, and (vi) isolation nearest neighbor sphere with variable sphere radius 1212 (corresponding to the INS model). The datasets include datasets 1216, 1218, 1220, 1222, 1224, 1226, 1228, and 1230 with introduced anomalies. Evaluation 1200 illustrates the performance of different anomaly detection models / algorithms on two-dimensional datasets. The datasets, in at least some embodiments, may include one or two modes (regions of high density) to demonstrate the model / algorithm's ability to handle multimodal data.

[0126] For each data set 1216, 1218, 1220, 1222, 1224, 1226, 1228, 1230, one percent of the samples may be generated as random noise and considered as outliers. Data points within these data sets may be designated by (a) a circle (i.e., corresponding to normal samples detected as normal), (b) a start (i.e., corresponding to outliers detected as outliers), (c) an upward triangle (i.e., corresponding to outliers detected as normal samples), and (d) a downward triangle (i.e., corresponding to normal samples detected as outliers).

[0127] Referring now to FIG. 13, based on a set of data points / observations 1300: Running a comparison model different from the INS model (iNNE) (e.g., different from illustrative methods 300, 400, 500) generates a set of spheres 1302. In the comparative example, set 1302 may include 320 spheres. Additionally, in the comparative example, set 1302 may be associated with an F1 score of 59.3%.

[0128] 14, multiple iterations of an INS model by a system (e.g., by methods 300, 400, 500) based on a set of data points / observations 1300 generates a set of spheres 1400. In an illustrative example, set 1400 may include 99 spheres. Additionally, in an illustrative example, set 1400 of spheres may be associated with an F1 score of 92.0%.

[0129] Referring now to FIG. 15, based on a set of data points / observations 1500: Running a comparison model different from the INS model (iNNE) (e.g., different from illustrative methods 300, 400, 500) generates a set of spheres 1502. In the comparative example, set 1502 may include 320 spheres. Additionally, in the comparative example, set 1502 may be associated with an F1 score of 78.9%.

[0130] 16, multiple iterations of an INS model by a system (e.g., by methods 300, 400, 500) based on a set of data points / observations 1500 generates a set of spheres 1600. In an illustrative example, set 1600 may include 83 spheres. Additionally, in an illustrative example, set 1600 of spheres may be associated with an F1 score of 95.5%.

[0131] 17 and 18, a set of comparison graphs 1700 is associated with a run of a comparison model that is different from the INS model, and a set of graphs 1800 is associated with a run of the INS model.

[0132] In some embodiments, a method for automatically detecting anomalies in a continuously monitored component comprises: - continuously monitoring data points from a performance counter while the component is operating includes receiving, by a processor of the computing device, data points included in a time series generated by the component, the data points being data points of the performance counter, and the data points not being labeled as normal or abnormal before being processed; - detecting anomalies in a time series when there is no labeled data defining anomalous data and no labeled data defining normal data; - post-processing of the generated anomalous events to aggregate the anomalous events by combining the generated anomalous events for a single data point in multiple processing paths into a single event carrying identifiers of all the detected processing paths, each processing path identifier corresponding to a respective type of anomaly; - providing information about whether the component is operating properly or malfunctioning, and enabling an owner or operator of the component to be notified of abnormal behavior when the abnormal behavior of the component occurs; - Detecting anomalies in a time series involves detecting the anomaly scores of one sample along with the scores of its neighbors according to the Isolation Nearest Spheres algorithm.

Claims

1. 1. A system for detecting anomalies in metric data provided by one or more customers, the system comprising: at least one processor; at least one memory containing a plurality of instructions stored therein, the instructions, upon execution by the at least one processor, causing the system to: receiving metric data indicating a plurality of time-series-based observations for a particular customer metric; defining, based on the metric data, a plurality of parameters for characterizing the plurality of spheres, each of the plurality of spheres configured to capture a number of time-series-based observations for the particular customer metric; a memory configured to generate the plurality of spheres based on the plurality of parameters, determine coverage of the metric data within the plurality of spheres, and detect one or more anomalies in the metric data based on the plurality of spheres; generating the plurality of spheres based on the plurality of parameters includes dynamically generating a plurality of spheres, each of the plurality of spheres having a radius that varies based on the plurality of time-series-based observations for the particular customer metric.

2. Defining the plurality of parameters based on the metric data includes: defining a minimum radius for generating at least one sphere; defining radius increments for generating one or more new spheres each having a varying radius; and defining a coverage limit indicating a maximum number of metric data points that will be covered by the generated sphere.

3. The system of claim 2 , wherein generating the plurality of spheres based on the plurality of parameters comprises determining a location corresponding to a maximum concentration of metric data based on the minimum radius.

4. generating the plurality of spheres based on the plurality of parameters, determining whether the coverage limit has been reached; and incrementing a radius for generation of at least one new sphere based on the radius increment in response to determining that the coverage limit has not been reached.

5. generating the plurality of spheres based on the plurality of parameters, determining whether the at least one new sphere provides coverage of the metric data not previously provided; and filtering out metric data already covered by a previous sphere in response to determining that the at least one new sphere does not provide coverage of the metric data not previously provided.

6. generating the plurality of spheres based on the plurality of parameters, updating the minimum radius in response to determining that the at least one new sphere provides coverage of the metric data not previously provided; and updating the location in response to the determination that the at least one new sphere provides coverage of the metric data not previously provided.

7. generating the plurality of spheres based on the plurality of parameters, determining another location corresponding to the maximum concentration of metric data based on the minimum radius of the at least one sphere and a distance between the at least one sphere and at least one nearest sphere; and generating at least one new sphere such that a center of the at least one new sphere is positioned at the other location.

8. generating the plurality of spheres based on the plurality of parameters, comparing the coverage of the metric data provided by the at least one sphere with the coverage of the metric data provided by the at least one nearest sphere or the at least one new sphere; and selecting a sphere that provides the greatest coverage of the metric data based on the comparison for generation of another new sphere.

9. Defining the plurality of parameters based on the metric data includes: filtering outliers from the metric data; and defining the coverage limits based at least in part on the filtered metric data.

10. One or more non-transitory machine-readable storage media containing a plurality of instructions stored thereon, The instructions, upon execution by at least one processor, cause the system to: receiving metric data indicating a plurality of time-series-based observations for a particular customer metric; defining, based on the metric data, a plurality of parameters for characterizing the plurality of spheres, each of the plurality of spheres configured to capture a number of time-series-based observations for the particular customer metric; generating the plurality of spheres based on the plurality of parameters, determining coverage of the metric data within the plurality of spheres, and detecting one or more anomalies in the metric data based on the plurality of spheres; one or more non-transitory machine-readable storage media, wherein generating the plurality of spheres based on the plurality of parameters includes dynamically generating a plurality of spheres, each of the plurality of spheres having a radius that varies based on the plurality of time-series-based observations for the particular customer metric.

11. Defining the plurality of parameters based on the metric data includes: defining a minimum radius for generating at least one sphere; defining radius increments for generating one or more new spheres each having a varying radius; and defining a coverage limit indicating a maximum number of metric data points that will be covered by the generated sphere.

12. 12. The one or more non-transitory machine-readable storage media of claim 11, wherein generating the plurality of spheres based on the plurality of parameters comprises determining a position corresponding to a greatest concentration of metric data based on the minimum radius.

13. 13. The one or more non-transitory machine-readable storage media of claim 12, wherein generating the plurality of spheres based on the plurality of parameters comprises: determining whether the coverage limit has been reached; and in response to determining that the coverage limit has not been reached, incrementing a radius for generating at least one new sphere based on the radius increment.

14. generating the plurality of spheres based on the plurality of parameters includes determining whether the at least one new sphere provides coverage of the metric data not previously provided; and filtering out metric data already covered by a previous sphere in response to determining that the at least one new sphere does not provide coverage of the metric data not previously provided.

15. generating the plurality of spheres based on the plurality of parameters includes updating the minimum radius in response to determining that the at least one new sphere provides coverage of the metric data not previously provided; and updating the location in response to the determination that the at least one new sphere provides coverage of the metric data that was not previously provided.

16. Defining the plurality of parameters based on the metric data includes: filtering outliers from the metric data; and defining the coverage limits based at least in part on the filtered metric data.

17. 1. A method for detecting anomalies in metric data provided by one or more customers, the method comprising: receiving, by a contact center system or computing device, metric data indicative of a plurality of time-series-based observations for a particular customer metric; defining, by the contact center system or the computing device based on the metric data, a plurality of parameters for characterizing a plurality of spheres, each of the plurality of spheres configured to capture a number of time-series-based observations for the particular customer metric; generating the plurality of spheres by the contact center system or the computer device based on the plurality of parameters, determining coverage of the metric data within the plurality of spheres, and detecting one or more anomalies in the metric data based on the plurality of spheres; generating the plurality of spheres based on the plurality of parameters includes dynamically generating, by the contact center system or the computing device, the plurality of spheres, each sphere having a radius that varies based on the plurality of time-series-based observations for the particular customer metric.

18. Defining the plurality of parameters based on the metric data includes: defining, by the contact center system or the computer device, a minimum radius for generation of at least one sphere; defining, by the contact center system or the computing device, radius increments for generating one or more new spheres having varying radii; and defining, by the contact center system or the computing device, a coverage limit indicating a maximum number of metric data points that will be covered by the generated sphere.

19. 20. The method of claim 18, wherein generating the plurality of spheres based on the plurality of parameters includes determining, by the contact center system or the computing device, a location corresponding to a greatest concentration of metric data based on the minimum radius.

20. generating the plurality of spheres based on the plurality of parameters, determining, by the contact center system or the computing device, whether the coverage limit has been reached; and incrementing, by the contact center system or the computing device, a radius for generation of at least one new sphere based on the radius increment in response to determining that the coverage limit has not been reached.

Citation Information

Patent Citations

  • Density-based clustering for multidimensional data

    JP2013511783A

  • Data clustering method, information processor, and data clustering program

    JP2016224915A

  • Unusual log detection system and unusual log detection method

    JP2017146832A

  • Image retrieval device, image retrieval system and image retrieval method

    JP2017220085A

  • Method and system for automated intent mining, classification and disposition

    JP2019169148A