Abnormality management device and abnormality management method
The abnormality management device addresses signal processing imbalances by generating pseudo-normal data to manage uneven distribution, enhancing resource efficiency in load balancing systems.
Patent Information
- Application Number
- JP2025191755
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-11-12
- Publication Date
- 2026-01-22
- Estimated Expiration
- 2045-11-12
AI Technical Summary
Conventional load balancing systems struggle to manage imbalances in signal processing efficiently, leading to decreased resource usage efficiency due to uneven packet distribution among destination devices.
An abnormality management device that utilizes a generative model to learn and generate pseudo-normal data deviating from true normal data, using a sequence learning model to identify and adjust signal allocation based on dependency relationships, thereby managing signal processing imbalances.
The device effectively manages signal processing imbalances by generating pseudo-normal data to identify and adjust signal allocation, ensuring even distribution and improving resource utilization.
Smart Images

Figure 0007804825000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an abnormality management device and an abnormality management method. [Background technology]
[0002] A round-robin load balancer has been known as a technology for distributing loads by distributing signals to multiple devices. For example, Patent Document 1 discloses a system that instructs an edge router to change the destination server to a backup server group according to the load status of an operational server group, and then uses a load balancer to distribute signals evenly to the backup server group of the changed destination.
[0003] However, depending on the hardware resources of the destination devices, packets may not be distributed evenly to the destination devices due to processing delays or losses on the destination device side. Under such circumstances, there is a risk that the resource usage efficiency of the entire system will decrease, so a technology to detect imbalances in the signal processing volume is desired. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Publication No. 2018-142848 Summary of the Invention [Problem to be solved by the invention]
[0005] According to conventional techniques, it has been difficult to appropriately manage the imbalance in the amount of signal processing.
[0006] The present invention has been made to solve the above-mentioned problems, and has as its object to appropriately manage the imbalance in the amount of signal processing. [Means for solving the problem]
[0007] In order to solve the above-described problems, the abnormality management device according to the present invention includes a first learning unit configured to learn parameters representing a ratio between a probability distribution of normal data indicating a sequence of normal signal counts assigned to a device for each time period and a probability distribution of abnormal data indicating a sequence of signal counts assigned to a device for each time period, including an abnormal signal count deviating from the range of normal signal counts, and to estimate the ratio based on the learned parameters; a first conversion unit configured to convert the normal data into normal data that reflects the dependency relationship between time periods, using a sequence learning model having pre-set model parameters that represent the dependency relationship between time periods inherent in the sequence of normal signal counts assigned to a device for each time period; and a generator that generates pre-conversion pseudo-normal data before the dependency relationship is reflected, which corresponds to pseudo-normal data that is sufficiently deviated from the distribution of the true normal data, using the normal data that reflects the dependency relationship converted by the first conversion unit as true normal data. a second learning unit configured to update classifier parameters of a classifier that distinguishes between the true normal data and the pseudo-normal data in a direction that maximizes an objective function based on the probability distribution of the normal data and the probability distribution of the abnormal data determined from the ratio estimated by the first learning unit, while keeping generator parameters fixed, to train a generative model including the generator and the classifier; a generation unit configured to generate the pre-conversion pseudo-normal data by the generator included in the generative model trained by the second learning unit; a second conversion unit configured to convert the pre-conversion pseudo-normal data generated by the generation unit into the pseudo-normal data reflecting the dependency relationship, using the sequence learning model; and a storage unit configured to store data that has been identified as the pseudo-normal data by the classifier included in the generative model trained by the second learning unit, from the pseudo-normal data converted by the second conversion unit and reflecting the dependency relationship,
[0008] In addition, the abnormality management device of the present invention may further include an adjustment unit configured to adjust the model parameters of the sequence learning model according to the state of learning of the generation model by the second learning unit, wherein the first conversion unit is configured to convert the normal data into normal data reflecting the dependency relationship using the sequence learning model having the model parameters adjusted by the adjustment unit, and the second conversion unit is configured to convert the pre-conversion pseudo-normal data generated by the generation unit into the pseudo-normal data reflecting the dependency relationship using the sequence learning model having the model parameters adjusted by the adjustment unit.
[0009] Furthermore, the abnormality management device according to the present invention may further include a collection unit configured to collect identification information of each source device that allocated each signal along with the sequence of signal counts allocated to the device to be managed; a third conversion unit configured to use the sequence learning model to convert the sequence of signal counts allocated to the device to be managed into a sequence of signal counts allocated to the device to be managed that reflects the dependency; and a determination unit configured to determine that an abnormal number of signals has been allocated to the device to be managed when the sequence of signal counts allocated to the device to be managed that reflects the dependency matches at least a portion of the pseudo-normal data that reflects the dependency and is stored in the memory unit.
[0010] In addition, the abnormality management device of the present invention may be provided with an identification unit configured to identify the source device that has allocated more than a set number of signals to the managed device when the judgment unit determines that an abnormal number of signals has been allocated, and an instruction unit configured to send an instruction to the source device identified by the identification unit to adjust the number of signals to be allocated to the managed device.
[0011] In the abnormality management device according to the present invention, the sequence learning model may be a recurrent neural network model.
[0012] In order to solve the above-mentioned problems, the anomaly management method of the present invention includes a first learning step of learning parameters representing a ratio between a probability distribution of normal data indicating a series of normal signal numbers assigned to a device for each time period and a probability distribution of abnormal data indicating a series of signal numbers assigned to a device for each time period, including an abnormal signal number deviating from the range of the normal signal numbers, and estimating the ratio based on the learned parameters; a first conversion step of converting the normal data into normal data that reflects the dependency relationship between time periods inherent in the series of normal signal numbers assigned to a device for each time period, using a sequence learning model having pre-set model parameters that represent the dependency relationship; and a generator parameter generator of a generator that generates pre-conversion pseudo-normal data before the dependency relationship is reflected, which corresponds to pseudo-normal data that is sufficiently deviated from the distribution of the true normal data, using the normal data that reflects the dependency relationship converted in the first conversion step as true normal data. a second learning step of learning a generative model including the generator and the classifier by updating classifier parameters of a classifier that distinguishes between the true normal data and the pseudo-normal data in a direction that maximizes an objective function based on the probability distribution of the normal data and the probability distribution of the abnormal data determined from the ratio estimated in the first learning step while keeping the parameters fixed; a generation step of generating the pre-conversion pseudo-normal data by the generator included in the generative model trained in the second learning step; a second conversion step of converting the pre-conversion pseudo-normal data generated in the generation step into the pseudo-normal data reflecting the dependency relationship using the sequence learning model; and a storage step of storing, in a storage unit, the data identified as the pseudo-normal data by the classifier included in the generative model trained in the second learning step, from the pseudo-normal data converted in the second conversion step and reflecting the dependency relationship.
[0013] Furthermore, the anomaly management method according to the present invention may further include an adjustment step of adjusting the model parameters of the sequence learning model according to the state of learning of the generative model in the second learning step, wherein the first conversion step uses the sequence learning model having the model parameters adjusted in the adjustment step to convert the normal data into normal data reflecting the dependency, and the second conversion step uses the sequence learning model having the model parameters adjusted in the adjustment step to convert the pre-conversion pseudo-normal data generated in the generation step into the pseudo-normal data reflecting the dependency.
[0014] Furthermore, the abnormality management method according to the present invention may further include a collection step of collecting identification information of each source device that allocated each signal along with the sequence of signal counts allocated to the device to be managed; a third conversion step of using the sequence learning model to convert the sequence of signal counts allocated to the device to be managed into a sequence of signal counts allocated to the device to be managed that reflects the dependency; and a determination step of determining that an abnormal number of signals has been allocated to the device to be managed when the sequence of signal counts allocated to the device to be managed that reflects the dependency matches at least a portion of the pseudo-normal data that reflects the dependency and is stored in the memory unit.
[0015] In addition, the abnormality management method of the present invention may include a step of identifying a source device that has allocated more than a set number of signals to the managed device when it is determined in the determination step that an abnormal number of signals has been allocated, and an instruction step of sending an instruction to the source device identified in the identification step to adjust the number of signals allocated to the managed device. [Effects of the Invention]
[0016] According to the present invention, normal data that has been converted by a first conversion unit and reflects the dependency relationship is regarded as true normal data, and pre-conversion pseudo-normal data that corresponds to pseudo-normal data that is sufficiently deviated from the distribution of true normal data is generated. While fixing generator parameters of the generator, which generates pre-conversion pseudo-normal data before reflecting the dependency relationship corresponding to the pseudo-normal data that is sufficiently deviated from the distribution of true normal data, the classifier parameters of the classifier that distinguishes true normal data from pseudo-normal data are updated in a direction that maximizes an objective function based on the probability distribution of normal data and the probability distribution of abnormal data determined from the ratios estimated by the first learning unit, thereby training a generative model including the generator and the classifier. Therefore, bias in the amount of signal processing can be appropriately managed. [Brief explanation of the drawings]
[0017] [Figure 1] FIG. 1 is a block diagram showing the configuration of an abnormality management system including an abnormality management device according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram showing an outline of an abnormality management system including an abnormality management device according to this embodiment. [Figure 3] FIG. 3 is a diagram for explaining an outline of the number of packets distributed by the traffic control device managed by the abnormality management device. [Figure 4] FIG. 4 is a diagram for explaining the number of packets collected by the abnormality management device according to the present embodiment. [Figure 5] FIG. 5 is a schematic diagram showing an example of the configuration of a sequence learning model used by the abnormality management device according to this embodiment. [Figure 6] FIG. 6 is a diagram for explaining the second learning unit and the conversion unit included in the abnormality management device according to this embodiment. [Figure 7] FIG. 7 is a diagram for explaining the second learning unit included in the abnormality management device according to this embodiment. [Figure 8] FIG. 8 is a diagram for explaining the second learning unit included in the abnormality management device according to this embodiment. [Figure 9] FIG. 9 is a diagram for explaining the generating unit included in the abnormality management device according to this embodiment. [Figure 10]FIG. 10 is a block diagram showing the hardware configuration of the abnormality management device according to this embodiment. [Figure 11] FIG. 11 is a sequence diagram showing the operation of the abnormality management system according to this embodiment. [Figure 12] FIG. 12 is a flowchart showing the operation of the abnormality management device according to this embodiment. [Figure 13A] FIG. 13A is a flowchart showing the operation of the abnormality management device according to this embodiment. [Figure 13B] FIG. 13B is a flowchart showing the operation of the abnormality management device according to this embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0018] Preferred embodiments of the present invention will now be described in detail with reference to FIGS. 1 to 13B.
[0019] [Configuration of anomaly management system] First, an overview of an anomaly management system equipped with an anomaly management device 1 according to an embodiment of the present invention will be described with reference to Fig. 1. In the anomaly management system, in a generative model that handles a series of signal numbers that reflects the inter-time zone dependency inherent in the series of signal numbers allocated from a traffic control device 2 to an opposing device 3 in each time zone, a ratio based on the probability distribution of normality and abnormality is reflected in the objective function of the generative model, and pseudo-normal data that deviates from the normal distribution is generated to build a database for determining the number of abnormal signals.
[0020] The fault management system according to this embodiment is installed in a mobile communication network conforming to 3G, 4G / LTE, 5G, 6G, etc. or a network using a fixed line. As shown in Fig. 1, the fault management device 1 is connected to a traffic control device 2 via a network NW such as a LAN, a WAN, or the Internet.
[0021] As shown in Fig. 2, the traffic control device 2 is communicatively connected to a plurality of opposite devices 3, and distributes received packets to the plurality of opposite devices 3 based on preset distribution criteria. In the following, a case where the "signal" is a "packet" will be explained. As an example, the traffic control device 2 distributes packets in an equal order to the plurality of opposite devices 3 using a round robin method. However, if a packet processing delay occurs on the opposite device 3 side, the traffic control device 2 may have to wait for packets to be sent or retransmit them, resulting in uneven distribution of packets.
[0022] L traffic control devices 2 (L is an integer equal to or greater than 2) are provided, and each traffic control device 2 is uniquely identified by a control device ID (i=1, 2, . . . , L) such as an IP address or a MAC address. The traffic control device 2 can be realized by a computer equipped with a processor, a main memory device, a communication interface, an auxiliary memory device, and an input / output (I / O), and a program that controls these hardware resources. In this embodiment, the traffic control device 2 is configured to be able to increase or decrease the amount of signals distributed to the opposing device 3 under management by changing scheduling parameters of the transmission queue, such as TPS, in response to instructions from the abnormality management device 1.
[0023] The traffic control device 2 can be realized by, for example, an Access and Mobility Management Function (AMF) provided in the core network or a load balancer. The AMF is a function node of the control plane that manages the registration of user terminals and wireless connections. The load balancer is a device provided in the user plane that distributes traffic. When the fault management system is provided in the fixed line network, the traffic control device 2 can be realized by an edge router, a load balancer, etc.
[0024] The opposite device 3 receives the packets distributed by the traffic control device 2. In this embodiment, N opposite devices 3 (N is an integer equal to or greater than 2) are provided. When the traffic control device 2 is configured with an AMF, the opposite device 3 is realized by a UDM (Unified Data Management) provided in the core network. The UDM is a functional node that manages subscriber information in the core network and manages the mobility of user terminals. Specifically, the AMF distributes packets transmitted from user terminals via base stations and transmits them to multiple UDMs. When an anomaly management system is provided in the fixed line network, the opposite device 3 is realized by a CDN (Content Delivery Network) node, a group of Web servers, or the like.
[0025] The opposite device 3 can be realized by a computer equipped with a processor, a main memory device, a communication interface, an auxiliary memory device, and an input / output (I / O), and a program that controls these hardware resources. Each opposite device 3 is identified by an opposite device ID (i=1, 2, . . . , N) such as an IP address or a MAC address. In this embodiment, at least one of the opposite devices 3 has hardware resources with a capacity different from that of the other devices. Therefore, an opposite device 3 with fewer resources than the other opposite devices 3 may experience delays in processing received packets, causing buffer congestion. In such a situation, the traffic control device 2 may take measures such as temporarily restricting transmission to that opposite device 3, resulting in uneven packet distribution overall.
[0026] The opposite device 3 is configured to count and record the number of packets distributed to the traffic control device 2. Fig. 4 is a diagram showing the number of packets distributed to each of the multiple traffic control devices 2 and received and recorded by the opposite device 3. In Fig. 4, the number of packets received and recorded by the opposite device 3 (for example, opposite device ID: 1) is recorded for each identification information of the source traffic control device 2. Fig. 4 shows, for example, the number of packets received in a certain time period (for example, 10 minutes). Also, the total number of packets received from the multiple traffic control devices 2 in that time period is recorded. The opposite device 3 records the number of packets received for each time period as time-series data.
[0027] FIG. 3 is a diagram illustrating normal data and abnormal data of the number of packets allocated to a certain opposite device 3 by each of multiple traffic control devices 2. The horizontal axis of FIG. 3 represents time, and the vertical axis represents the number of packets received by a certain opposite device 3 for each time period. FIG. 3 shows the number of packets allocated to and received by one opposite device 3 (for example, opposite device ID: 1) among the multiple opposite devices 3. The dotted line value in FIG. 3 indicates normal data a1, which is the number of normal packets allocated to the opposite device 3. The normal number of packets means the number of packets allocated by the multiple traffic control devices 2 to the opposite device 3 with opposite device ID: 1 in a set time period (for example, in 10-minute increments) according to the set allocation criteria, and which falls within the range of the allocation criteria.
[0028] On the other hand, the number of packets indicated by the solid line in Figure 3 indicates that, depending on the time period, a larger number of packets than would normally be allocated to the opposite device 3 is allocated. For example, the number of packets indicated by the solid line in section c1 indicates that a larger number of packets than would normally be allocated to the opposite device 3 with opposite device ID: 1 is allocated. In this way, the number of packets indicated by the solid line indicates abnormal data b1, in which the number of packets allocated to the opposite device 3 is abnormal.
[0029] Abnormal data is the number of packets that deviate from the range of packet numbers that are considered normal when distributed according to the set distribution criteria. For example, in the round robin method, packets are theoretically distributed evenly from each traffic control device 2 to each opposite device 3. In this case, normal data is packets that each traffic control device 2 distributes evenly or within a range that can be considered equal. Note that the number of distributed packets and the number of packets received by the opposite device 3 are assumed to be the same. On the other hand, abnormal data is the number of packets that are distributed from the traffic control device 2 to the opposite device 3 when the number of packets that deviates from the range that can be considered equal, due to factors such as differences in the hardware resources of each opposite device 3, is equal.
[0030] In this way, the abnormal data appears as a difference in the number of packets received on the opposing device 3 side due to the presence of one or more traffic control devices 2 that distribute more or fewer packets than other traffic control devices 2 among multiple traffic control devices 2. In other words, the abnormal data represents the number of packets that reflects the imbalance of the round robin.
[0031] [Function block of the abnormality management device] Next, functional blocks of the abnormality management device 1 according to this embodiment will be described with reference to the block diagram of Fig. 1. As shown in Fig. 1, the abnormality management device 1 includes a collection unit 10, a first learning unit 11, a conversion unit (first conversion unit, second conversion unit, third conversion unit) 12, a second learning unit 13, an adjustment unit 14, a generation unit 15, an abnormal signal count database (storage unit) 16, a determination unit 17, an identification unit 18, an instruction unit 19, and a storage unit 20.
[0032] The collection unit 10 collects normal data indicating the sequence of the number of normal packets distributed to the opposite device 3 for each time period, and abnormal data indicating the number of packets distributed to the opposite device 3 for each time period, including the number of abnormal packets. The collection unit 10 collects the number of received packets per unit time (e.g., 10 minutes) (FIG. 4) distributed by multiple traffic control devices 2 and received and recorded by the opposite device 3 for a certain period (e.g., one month). The collection unit 10 can classify the collected distributed packets into normal data and abnormal data by labeling them based on a rule base or statistical threshold, and collect these data. While it is possible to collect a large amount of normal data, abnormal data occurs very rarely, making it difficult to collect a sufficient amount. Therefore, the amount of abnormal data collected by the collection unit 10 is significantly smaller than the amount of normal data (normal data >> abnormal data).
[0033] The collection unit 10 collects, as training data for the first learning unit 11, sequence data that can be considered to be composed only of the number of normally distributed packets, and sequence data that includes the number of normally distributed packets but also a certain number of abnormally distributed packets. The collection unit 10 also collects normal data related to the sequence of the number of normally distributed packets for each time period as data to be converted by the conversion unit 12. The collection unit 10 also collects the sequence of the number of packets distributed to the managed opposing device 3, which is the target of abnormality judgment by the judgment unit 17, as well as identification information of the traffic control device 2 of each source that distributed each packet.
[0034] The first learning unit 11 learns parameters that represent the ratio between a probability distribution of normal data that indicates a series of the number of normal packets distributed to the opposite device 3 in each time period and a probability distribution of abnormal data that indicates a series of the number of packets distributed to the opposite device 3 in each time period, including the number of abnormal packets that deviate from the range of normal packet numbers, and estimates the ratio based on the learned parameters. The first learning unit 11 learns parameters that represent the density ratio of a probability density function that is the probability distribution of normal data and abnormal data, using the series of the number of normal distributed packets for each time period that can be obtained in large quantities and the series of the number of abnormal distributed packets for each time period that can be obtained only in small quantities compared to the number of normal distributed packets. The first learning unit 11 also estimates the density ratio from the learned parameters.
[0035] Here, let D={x (1) ,x (2) ,…,x (N)}, the set of training data including abnormal data is D'={x' (1) ,x' (2) ,…,x' (N’)} where x indicates the number of packets distributed for each time period. (n) is M-dimensional and x (n) =(x1 (n) ,x2 (n) ,…,x M (n) For example, if there are 1000 time periods (=M), the dimension is 1000. Each component x i (n) indicates the number of packets distributed in time slot i.
[0036] In the following, D is called normal data and D' is called abnormal data, and the probability density function of normal data D is called p(x) and the probability density function of abnormal data D' is called p'(x). The probability density function p(x) of normal data D indicates the distribution of the probability that the number of normally distributed packets x will be observed in a certain time period. Furthermore, the probability density function of abnormal data D' indicates the distribution of the probability that the number of abnormally distributed packets x will be observed in a certain time period. The density ratio r(x) between the probability density function p(x) of normal data D and the probability density function p'(x) of abnormal data D' is expressed by the following equation (1).
number
[0037]
number
[0038] The basis function ψ(x) is defined by the RBF (Radial Basis Function) kernel and expressed by the following equation (3).
number
[0039] Here, based on the above formula (1), the specific form of the above formula (3) in which the number of bases b is the number of training data N (b=N) is given by the following formula (4).
number
[0040] The above equation (4) expresses the density ratio as a linear sum of RBFs centered on all training points. Here, we introduce the generalized Kullback-Leibler divergence (KL divergence), which measures the information-theoretic distance between non-negative functions f and g, as shown in the following equation (5).
number
[0041] In density ratio estimation, f=p(x) and g=r θ Substituting p'(x) into the above equation (5), the following equation (6) is used as the objective function.
number
[0042] In the above equation (6), each x n , x' n’ The optimization objective function obtained by approximating the integral with an empirical distribution that sets values other than θ to 0, ignoring terms that do not depend on the parameter θ, and dropping constants is expressed as the following equation (7).
number
[0043] By minimizing J(θ) in equation (7), the density ratio r θ Since J(θ) is a convex function, the first learning unit 11 updates the parameter θ from the initial value until convergence using the parameter θ update formula by the gradient descent method of the following formula (8).
number
[0044] The result of specifically calculating the gradient of the above formula (7) is expressed by the following formula (9).
number
[0045] The first term in the above equation (9) represents the contribution from abnormal data, and the second term represents the contribution from normal data. Since the second term is dominant in the above equation (9), stable estimation is possible when the number of normal data N is large. In other words, even when the amount of abnormal data N' is small, the parameter θ can be stably calculated.
[0046] Before calculating the optimal solution of the parameter θ using the above equations (7) to (9), the first learning unit 11 calculates an appropriate value for the bandwidth h in the above equation (4) by cross-validation, information criterion (KL divergence minimization criterion), etc. Based on the optimal solution of the parameter θ calculated by the KL density ratio estimation method, the first learning unit 11 calculates the density ratio r for an arbitrary input x using the above equation (2). θ The density ratio estimated by the first learning unit 11 is passed to the second learning unit 13, which will be described later.
[0047] The conversion unit 12 is used as a feature conversion model for converting the sequence data of the number of packets allocated for each time period handled by the generative model in the second learning unit 13 described below into data reflecting features that represent the dependency between previous and subsequent time periods in the sequence data. The conversion unit 12 converts normal data into normal data that reflects the dependency, using a sequence learning model that has pre-set model parameters that represent the dependency between time periods inherent in the sequence of the number of packets allocated for each observed time period.
[0048] Furthermore, the converter 12 uses a sequence learning model to convert pre-conversion pseudo-normal data generated by the generator 15 (described later) into pseudo-normal data that reflects the inter-time zone dependency relationship inherent in the sequence of the number of packets distributed for each time zone. Furthermore, the converter 12 uses a sequence learning model having model parameters adjusted by the adjuster 14 (described later) to convert normal data into normal data that reflects the inter-time zone dependency relationship inherent in the sequence of the number of packets distributed for each time zone. Similarly, the converter 12 uses a sequence learning model having model parameters adjusted by the adjuster 14 to convert pre-conversion pseudo-normal data generated by the generator 15 into pseudo-normal data that reflects the inter-time zone dependency relationship inherent in the sequence of the number of packets distributed for each time zone. Furthermore, the converter 12 converts the sequence of the number of packets distributed for each time zone, collected by the collector 10, into a sequence of the number of packets distributed for each time zone that reflects the inter-time zone dependency relationship inherent in the sequence of the number of packets distributed for each time zone, and passes the converted data to the determiner 17.
[0049] The sequence learning model is a model that sequentially inputs the number of packets allocated in each time period that constitutes the input sequence, and generates feature representations that take into account the relationship between previous and next time periods while sequentially updating its internal state. The sequence learning model is a model equipped with a recurrent neural network (RNN), a long short-term memory (LSTM), or a self-attention mechanism, but is not limited to these.
[0050] When a sequence of correctly sorted packet counts for each time period (normal data) is input to the sequence learning model, the sequence learning model performs calculations on the input sequence based on the model parameters, and outputs as an output sequence normal data represented as data in which inter-sequence dependency relationships have been extracted or emphasized, while retaining the sequence features contained in the number of sorted packets for each time period of the input sequence. As shown in Figure 6, by providing the sequence learning model on the output side of generator 131 and on the input side of classifier 132 included in the generative model described below, it becomes possible for the generative model to generate data while retaining the inter-time period features of the sequence data.
[0051] Here, an example will be explained in which an RNN is used as a sequence learning model. Figure 5 is a schematic diagram showing the network structure of an RNN. As shown in Figure 5, the RNN is composed of a neural network consisting of an input layer X, a hidden layer H which is a memory cell, and an output layer Y. Each node in Figure 5 is a node that receives an input x in each time period t. (t) , hidden state (internal state) h (t) , and output y (t) First, input x (t) and the hidden state h of the previous time period (t-1) are multiplied by the corresponding weight matrices U and W, respectively, and a bias term b is added, thereby performing the linear operation shown in the following equation (10).
[0052]
number
[0053] In the above equation (10), a (t) is the intermediate value for updating the hidden state at time t, and represents the weighted sum of the input and past state information. (t) By applying the nonlinear activation function σ(·) to the new hidden state h, as shown in the following equation (11), (t) is obtained.
[0054]
number
[0055] The hidden state h in the above equation (11) (t) is an internal representation that retains past sequence information while reflecting features based on the current input, and is carried over to the processing of the next time period t+1. Furthermore, this hidden state h (t) Based on this, the output y (t) is calculated.
[0056]
number
[0057] In the above equation (12), V is the weight matrix from the hidden state to the output, and c is the bias term for the output layer. In this way, the RNN recursively uses the hidden state of the previous time slot in the input processing of the next time slot, and transmits information from the hidden state of the previous time slot to the hidden state of the next time slot, so it is structured to generate an output that reflects the sequential dependency inherent in the time series of the number of distributed packets.
[0058] Pre-set values are used for the model parameters of the sequence learning model. In the RNN of Fig. 5, values set in advance based on empirical rules or the like are used for the model parameters U, W, V, b, and c. Furthermore, when the values of the model parameters are adjusted by the adjustment unit 14 (described later), the conversion unit 12 performs conversion processing based on the sequence learning model in which the adjusted model parameters (U', W', V', b', c') are set.
[0059] The second learning unit 13 regards normal data, in which the dependency between time periods converted by the conversion unit 12 (first conversion unit) is reflected, as true normal data, and generates pre-conversion pseudo-normal data before the dependency between time periods is reflected, corresponding to pseudo-normal data that is sufficiently deviated from the distribution of true normal data, while keeping fixed generator parameters of the generator 131 that generates pre-conversion pseudo-normal data before the dependency between time periods is reflected, in a direction that maximizes an objective function based on the probability density function (probability distribution) of normal data and the probability density function (probability distribution) of abnormal data determined from the density ratio (ratio) estimated by the first learning unit 11, thereby learning a generative model. The pre-conversion pseudo-normal data before the dependency between time periods corresponding to pseudo-normal data is reflected is data before being converted by the conversion unit 12 (second conversion unit).
[0060] As shown in FIG. 6, the second learning unit 13 executes a Max learning phase of a GAN (Generative Adversarial Network) as a generative model having a generator 131 and a classifier 132, in which only the parameters of the classifier 132 are updated while the generator 131 is fixed. When the sequence of the number of normal packets distributed for each time period converted by the conversion unit 12 is regarded as true normal data, the second learning unit 13 aims to generate pseudo-normal data (pseudo-normal data before being converted by the conversion unit 12) that deviates sufficiently from the distribution of normal data, that is, a sequence of the number of distributed packets that can be treated as abnormal data. For this reason, the Min learning phase in the normal GAN adversarial learning procedure, in which the generator 131 is updated in the minimization direction, is not performed.
[0061] As shown in FIG. 6, the generation model according to this embodiment, which includes the generator 131 and the discriminator 132, is a function of the number of normally distributed packets x=(x1, x2, ..., x) observed in each time period converted by the conversion unit 12. M) is used as training data for learning. Here, pseudo-normal data that deviates sufficiently from the distribution of normal data is a generated sequence that, in terms of statistical properties, is located in a region that significantly deviates from the normal range of normal data, relative to normal data that indicates a sequence of the normal number of packets distributed. When the index of distance or deviation from normal data is log-likelihood, a sequence with a smaller likelihood corresponds to the pseudo-normal data, and when the index is cross-entropy, the larger the entropy value, the greater the deviation. Furthermore, when the KL distance is used as the index, a sequence with a large deviation in the overall distribution is treated as a sequence that deviates sufficiently.
[0062] 6, a conversion unit 12 equipped with a sequence learning model is provided on the input side of the classifier 132 of the generative model and on the output side of the generator 131. An adjustment unit 14 that adjusts the model parameters of the sequence learning model is provided between the objective function 135 of the generative model and the conversion unit 12.
[0063] 7 and 8 are diagrams schematically illustrating the neural network configuration of the generator 131 and the classifier 132 of the generative model used by the second learning unit 13. As shown in FIG. 7, the generator 131 is configured as a neural network having an input layer, a hidden layer, and an output layer. The generator 131 is a model that generates pseudo-normal data from random noise. For example, m randomly sampled Gaussian noise vectors (z1 to z m ).
[0064] The generator 131 outputs the output G(z) after performing a product-sum operation on the input and weight parameters and threshold processing using an activation function. The output G(z) from the generator 131 is pseudo-normal data before conversion that corresponds to pseudo-normal data that deviates from the distribution of true normal data. CNN or ResNet can be used as the neural network that constitutes the generator 131.
[0065] The classifier 132 shown in Fig. 8 is configured with a neural network having an input layer, a hidden layer, and an output layer. In the example of Fig. 8, a series of the number of packets normally distributed, which has been converted by the conversion unit 12 and reflects the dependency between time periods, is given as true normal data as training data input. Each input node shown in Fig. 8 is provided with a series of packets normally distributed, which has been converted by the conversion unit 12 and reflects the dependency between time periods. M The output values x1 to x of the sequence learning model for the number of packets distributed up to M are input respectively.
[0066] The classifier 132 outputs a probability value between 0 and 1 after performing a product-sum operation on the input and weight parameters and threshold processing using an activation function. When the classifier 132 correctly identifies the training data related to the input true normal data as true normal data, it outputs a value close to the output y=1. On the other hand, when the classifier 132 correctly identifies the training data related to the input pseudo normal data as pseudo normal data, it outputs a value close to the output y=0. In this way, the classifier 132 is a model that distinguishes the model distribution generated by the generator 131 from the data distribution of the training data, which is the true distribution. A CNN can be used as the neural network that constitutes the classifier 132.
[0067] As shown in the block diagram of FIG. 6, the generator 131 of the generative model adopted by the second learning unit 13 is represented as a function G, and the discriminator 132 is represented as a function D. Furthermore, true normal data is represented as x, the predicted value output by the discriminator 132 is represented as y, and the correct label is represented as t. The correct label t is set to 1 for true normal data and 0 for pseudo-normal data generated by the generator 131 and converted by the conversion unit 12. In this case, the discriminator 132 calculates the cross entropy E CE It can be expressed as:
[0068]
number
[0069] The first term in the brace of the above equation (13) represents t n lny n In this case, the predicted value yn is the correct label of the true normal data, t n = 1. On the other hand, the second term in the braces represents (1-t n )ln(1-y n ), the predicted value y n is the correct label value (1-t n ) = 0. In this way, the cross entropy E CE is the maximum value when the predicted value matches the correct label value.
[0070] Here, the generator 131 that configures the generative model uses parameters w G ,θ G and the function G(w G ,θ G ) The classifier 132 uses the parameter w D ,θ D and function D(w D ,θ D ) The cross entropy E in the above equation (13) CE The loss function (objective function E) of the generative model including the generator 131 and the discriminator 132 based on the above can be expressed by the following equation (14).
number
[0071] The first term of the above equation (14) represents E D(x)=1 lnD(w D ,θ D ) is the expected value at which the classifier 132 classifies true normal data as true normal data. D(x)=0 ln(1-D(G(w G ,θ G ),w D ,θ D )) is the expected value at which the classifier 132 classifies the pseudo-normal data generated by the generator 131 and converted by the converter 12 as pseudo-normal data. Here, the expected value of the above formula (14) can be expressed as the following formula (15) using a probability distribution.
[0072]
number
[0073] Here, for the probability density function p(x) of normal data and the probability density function p'(x) of abnormal data in the above equation (1), in order to form a probabilistic labeled classification problem for Max optimization learning of GAN, let p(x)≡ρ(x|y=1) and p'(x)≡ρ(x|y=0). The density ratio r estimated by the first learning unit 11 is θ (x) is defined by the following equation (16).
number
[0074] The probability density function ρ(x|y=1), which is the conditional probability distribution of normal data in the above equation (16), can be calculated from a large amount of normal data using maximum likelihood estimation, etc. Using the calculated probability density function ρ(x|y=1) of normal data, the probability density function ρ(x|y=0), which is the conditional probability distribution of abnormal data, can be expressed by the following equation (17).
number
[0075] The probability density function ρ(x|y=1) of normal data and the probability density function ρ(x|y=0) of abnormal data in the above formula (17) are substituted into the objective function E in the above formula (15), and set values are used for the prior probability ρ(y=1) of the normal (y=1) class and the prior probability ρ(y=0) of the abnormal (y=0) class. For example, the prior probability values are arbitrarily set as ρ(y=1):ρ(y=0)=0.99:0.01, and these prior probability values can be adjusted as needed. Furthermore, the posterior probability ρ(y=1|x) of normality for the number of packets allocated per observed time period x is calculated as D(w D ,θ D ) and the posterior probability ρ(y=0|x) of abnormality for the number of packets allocated per time slot x is 1-D(G(wG ,θ G ),w D ,θ D ) Each posterior probability corresponds to the density ratio r θ and can be obtained from the prior probability.
[0076] Here, when the generator 131 is fixed, the objective function E becomes a maximization problem of the following equation (18) with respect to the discriminator 132.
number
[0077] In training the generative model of this embodiment, as described above, only Max optimization of the objective function E is performed, and the parameters of the discriminator 132 with the generator 131 fixed are trained. This prevents the output of the generator 131 from converging to the distribution of normal data, and instead maintains a sequence that is sufficiently deviated from the distribution of normal data. When the update of the discriminator 132 has converged, the pseudo-normal data sequence output by the fixed generator 131 and converted by the conversion unit 12 has a low likelihood compared to a sequence of a normal number of packets to be distributed. At this time, the generator 131 can generate pre-conversion pseudo-normal data that has the statistical properties expressed by the following equation (19).
number
[0078] The adjustment unit 14 adjusts the model parameters of the sequence learning model according to the state of learning of the generative model by the second learning unit 13. As described above, the model parameters of the sequence learning model are set as initial values based on predetermined values such as empirical rules. As shown in FIG. 6, the adjustment unit 14 monitors the loss transition and output distribution of the classifier 132 during the optimization learning process of the generative model by the second learning unit 13, and adjusts the values of the model parameters of the sequence learning model based on the evaluation (the arrow between the objective function 135 and the conversion unit 12 in FIG. 6). The adjustment unit 14 performs an evaluation, for example, every time the loss of the classifier 132 is calculated, and adaptively adjusts the values of the model parameters of the sequence learning model based on the evaluation result, independently of the gradient propagation of the generative model. Adjusting the model parameters of the sequence learning model by the adjustment unit 14 can improve the learning accuracy of the generative model.
[0079] The generation unit 15 generates pre-conversion pseudo-normal data using a generator 131' included in the generative model trained by the second learning unit 13. As shown in FIG. 9, the generation unit 15 inputs noise to the trained generator 131', causing the conversion unit 12 to generate a large amount of pre-conversion pseudo-normal data. The pre-conversion pseudo-normal data generated by the generation unit 15 is passed to the conversion unit 12. Furthermore, the conversion unit 12, connected to the output side of the trained generator 131', converts the pre-conversion pseudo-normal data into pseudo-normal data that reflects the dependency between time periods through the calculation of the sequence learning model.
[0080] The abnormal signal number database 16 stores data that has been identified as pseudo-normal data by the classifier 132' included in the generative model trained by the second learning unit 13, out of the pseudo-normal data that has been converted by the conversion unit 12 (second conversion unit) and that reflects the dependency relationships between time periods. Specifically, the abnormal signal number database 16 stores data that has been determined as 0 (abnormal) >> 1 (normal) as the output of the trained classifier 132' in the pseudo-normal data converted by the conversion unit 12. In this way, the abnormal signal number database 16 accumulates pseudo-normal data that can be considered as a series of the number of abnormally distributed packets for each time period, and constructs a database of packet number series used in the abnormality determination process.
[0081] The determination unit 17 determines that an abnormal number of signals has been allocated to the managed opposite device 3 when the series of packet counts converted by the conversion unit 12 and allocated to the managed opposite device 3, which reflects the dependency between time periods, matches at least a part of the pseudo-normal data reflecting the dependency between time periods stored in the abnormal signal count database 16. The determination unit 17 can determine that an abnormal number of packets has been allocated to the managed opposite device 3 when the converted series of packet counts allocated to the managed opposite device 3 for each time period completely matches the pseudo-normal data stored in the abnormal signal count database 16, or when it is within a certain range.
[0082] The determination unit 17 compares the numbers of packets distributed in each time period in the pseudo-normal data, starting from the earliest time period, and when a time period occurs in which the numbers of distributed packets match, it can determine that an abnormal number of packets has been distributed to the managed opposite device 3. The pseudo-normal data (1 to L pieces) (L is a positive integer of 2 or more) consisting of a series of the numbers of packets distributed in each of the time periods 1 to D (D is a positive integer of 2 or more) stored in the abnormal signal number database 16, and the series of the numbers of packets distributed for each time period to a certain managed opposite device 3 are respectively expressed as follows:
number
[0083] The determination unit 17 compares the series of the number of packets allocated to the target countermeasure device 3 in the time period from 1 to D with the series of the number of allocated packets in the time period from 1 to D of the pseudo-normal data. If they match, it determines that the number of packets allocated to the target countermeasure device 3 is abnormal. The determination result can be output by comparing the number of allocated packets in some of the time periods from 1 to n (n < D) out of the time periods from 1 to D.
[0084] Also, the determination unit 17 can determine that the number of allocated packets is abnormal when it exceeds a predetermined threshold TH by using the conditional expression of the following formula (20).
[0085]
Equation
[0086] In the above formula (20), l represents the pseudo-normal data from 1 to L, and the threshold TH determines the allowable range for determining the similarity between the series of the number of packets per time period allocated to the target countermeasure device 3 and converted by the conversion unit 12 and the pseudo-normal data, and can be arbitrarily set based on, for example, the distance distribution of the series of the number of packets per time period allocated to the target countermeasure device 3 that has been converted. In the above formula (20), the threshold determination is performed using the pseudo-normal data from 1 to L in order. Note that even when the above formula (20) is adopted, the determination can be made based on the data of the number of allocated packets in some of the time periods among the data of the number of allocated packets in all the time periods from 1 to D.
[0087] When the determining unit 17 determines that an abnormal number of packets has been distributed, the identifying unit 18 identifies the source traffic control device 2 that distributed a set number or more of packets to the managed opposing device 3. The identifying unit 18 identifies a time period in which an abnormality occurs in the number of distributed packets among multiple traffic control devices 2, and further identifies a traffic control device 2 that distributed more or fewer packets than other traffic control devices 2 during the identified time period. The number of identified traffic control devices 2 is not limited to one, and may be multiple.
[0088] The instruction unit 19 transmits an instruction to the traffic control device 2 identified by the identification unit 18 to adjust the number of packets to be distributed to the opposite device 3 to be managed. For example, the instruction unit 19 transmits an instruction to a traffic control device 2 that distributes a larger number of packets than other traffic control devices 2 to reduce the number of packets to be distributed to the opposite device 3 to be managed, so that the multiple traffic control devices 2 each distribute an equal number of packets to the opposite device 3 to be managed.
[0089] The memory unit 20 stores the parameter θ and the density ratio r estimated by the learning by the first learning unit 11. θ The storage unit 20 also stores the generator 131 and the classifier 132 included in the trained generative model, as well as the model parameters of the sequence learning model adjusted by the adjustment unit 14.
[0090] [Hardware configuration of the fault management device] Next, an example of a hardware configuration for realizing the abnormality management device 1 having the above-described functions will be described with reference to FIG.
[0091] 10, the fault management device 1 can be realized by, for example, a computer including a processor 102, a main memory device 103, a communication interface 104, an auxiliary memory device 105, and an input / output (I / O) 106 connected via a bus 101, and a program for controlling these hardware resources. Furthermore, the fault management device 1 includes a display device 107.
[0092] The processor 102 is a circuit or device that performs arithmetic processing, and is realized by, for example, a general-purpose central processing unit (CPU), a graphics processing unit (GPU), a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), etc. Alternatively, the processor 102 may be configured by combining some or all of these.
[0093] The main memory device 103 is configured, for example, with a volatile random access memory (RAM), and pre-stores programs for the processor 102 to perform various controls and calculations. The processor 102 and the main memory device 103 implement the functions of the abnormality management device 1, such as the collection unit 10, first learning unit 11, conversion unit 12, second learning unit 13, adjustment unit 14, determination unit 17, identification unit 18, and instruction unit 19 shown in FIG.
[0094] The communication interface 104 is an interface circuit for connecting the abnormality management device 1 to various external electronic devices via a network.
[0095] The auxiliary storage device 105 is composed of a readable / writable storage medium and a drive for reading and writing various information such as programs and data from and to the storage medium. The auxiliary storage device 105 can use non-volatile storage such as a hard disk or flash memory as the storage medium.
[0096] The auxiliary storage device 105 has a program storage area for storing an abnormality management program. The auxiliary storage device 105 also has a program storage area for storing parameters representing the density ratio of the probability density functions of normal data and abnormal data executed by the abnormality management device 1, and a first learning program for estimating the density ratio. The auxiliary storage device 105 also has a program storage area for storing a program by which the conversion unit 12 performs calculations on the sequence learning model. The auxiliary storage device 105 also has a program storage area for storing a second learning program for learning the generative model executed by the abnormality management device 1.
[0097] The auxiliary storage device 105 realizes the abnormal signal count database 16 and the storage unit 20 described in Fig. 1. Furthermore, for example, it may have a backup area for backing up the above-mentioned data and programs.
[0098] The input / output I / O 106 is an input / output device that inputs signals from external devices and outputs signals to external devices.
[0099] The display device 107 is configured by an organic EL display, a liquid crystal display, etc. The display device 107 can display on a screen time-series data of the number of packets distributed to the counterpart device 3 to be managed.
[0100] [Operation of the abnormality management device] Next, the operation of the abnormality management device 1 having the above-described configuration will be described with reference to the sequence diagram of FIG. 11 and the flowcharts of FIGS. 12 to 13B.
[0101] As shown in FIG. 11, first, the opposing device 3 records the number of packets distributed by the traffic control device 2 (step S1). In step S1, the opposing device 3 records, for example, the number of packets distributed to the opposing device 3 from each of the multiple traffic control devices 2 in 10-minute increments over a one-month period (FIG. 4). Next, the collection unit 10 of the abnormality management device 1 collects, from the opposing device 3, normal data related to a series of normally distributed packet counts and abnormal data including an abnormally distributed packet count (step S2). The collection unit 10 collects, as normal data, data including only a series of normally distributed packet counts or series data that can be considered to include only normally distributed packet counts in the series data of the number of distributed packets for each time period. In addition, the collection unit 10 collects a small amount of abnormal data compared to the normal data. After collecting the series of packet counts for each time period distributed to the opposing device 3, the collection unit 10 can classify the data into normal data and abnormal data.
[0102] Next, the first learning unit 11 performs a first learning process (step S3). FIG. 12 is a flowchart illustrating the first learning process of step S3 in more detail. As shown in step S20 of FIG. 12, the first learning unit 11 calculates a density ratio r θ (Step S20). The first learning unit 11 updates the parameter θ by gradient descent or the like using the above equations (7) to (9) to find an optimal solution for the parameter θ.
[0103] Next, the first learning unit 11 calculates the density ratio r from the learned parameter θ calculated in step S20 based on the above formula (2). θ is estimated (step S21).
[0104] 11, the conversion unit 12 performs a conversion process using the sequence learning model, and the second learning unit 13 performs a second learning process (step S4). In step S4, the second learning unit 13 considers normal data converted by the conversion unit 12 based on the calculation of the sequence learning model and reflecting the dependency between time periods as true normal data, and generates pre-conversion pseudo-normal data before the dependency between time periods is reflected in the conversion unit 12, which corresponds to pseudo-normal data that is sufficiently deviated from the distribution of true normal data, while keeping fixed the generator parameters of the generator 131. θ The classifier parameters of the classifier 132 that distinguishes between true normal data and pseudo normal data are updated in the direction of maximizing the objective function E based on the probability density function ρ(x|y=1) of normal data and the probability density function ρ(x|y=0) of abnormal data (the above equation (17)) determined from the above equation.
[0105] 13A and 13B are flowcharts for explaining the conversion process and the second learning process in step S4. First, the second learning unit 13 converts the density ratio r θ The probability density function ρ(x|y=1) of normal data and the probability density function ρ(x|y=0) of abnormal data (the above formula (17)) determined from the above are set as the objective function E (formula (15)) of the GAN (step S300). More specifically, the second learning unit 13 calculates the probability density function ρ(x|y=1), which is the conditional probability distribution of normal data, from the large amount of normal data collected by the collection unit 10 using a maximum likelihood estimation method or the like. In addition, the second learning unit 13 determines the probability density function ρ(x|y=0), which is the conditional probability distribution of abnormal data expressed by the above formula (17), from the calculated probability density function ρ(x|y=1) of normal data.
[0106] The prior probability ρ(y=1) of normality and the prior probability ρ(y=0) of abnormality are set to values previously set, for example, ρ(y=1):ρ(y=0)=0.99:0.01, in the above equation (12), because the number of normal data is overwhelmingly large. Furthermore, in the optimal solution of the objective function E in the above equation (15), D(w D ,θ D) is the posterior probability ρ(y=1|x) that the number of packets distributed per observed time period is normal for x, and 1-D(G(w G ,θ G ),w D ,θ D ) is the posterior probability ρ(y=0|x) of anomaly for the number of packets allocated per time slot x. These posterior probabilities ρ(y=1|x) and ρ(y=0|x) are calculated based on the estimated density ratio r θ and can be obtained from the prior probabilities ρ(y=1), ρ(y=0).
[0107] Next, the second learning unit 13 acquires the sequence of the number of normally distributed packets for each time period collected in step S1 as normal data (step S301) (training data 134 before conversion in FIG. 6). Next, the conversion unit 12 sets initial values of model parameters of the sequence learning model (step S302). In step S302, pre-set model parameters are set, and for example, values based on empirical rules or randomly set values can be used. Next, the conversion unit 12 inputs the normal data acquired in step S301 into the sequence learning model, converts it into normal data that reflects the inter-time period dependency inherent in the sequence of the number of distributed packets for each time period based on the model parameters, and outputs the converted normal data as truly abnormal data (step S303).
[0108] Next, the second learning unit 13 inputs the true normal data output from the sequence learning model in step S303 to the classifier 132 as training data, and adjusts the parameter w of the classifier 132 so that the true normal data is classified as true normal data (y=1). D ,θ D (Step S304). In Step S304, the second learning unit 13 can cause the classifier 132 to learn true normal data using, for example, an error backpropagation method. In Step S304, the classifier 132 that can distinguish true normal data from true normal data is pre-trained.
[0109] Next, the second learning unit 13 generates Gaussian noise and provides a random vector of the generated Gaussian noise as an input to the generator 131 (step S305). Subsequently, the generator 131 calculates a random vector of the input z and the weight parameter w based on the provided Gaussian noise. G ,θ G and threshold processing using an activation function to generate pseudo-normal data G(z) before conversion (step S306).
[0110] Next, the conversion unit 12 provides the pseudo normal data G(z) before conversion generated in step S306 as input to the sequence learning model, and converts it into pseudo normal data G(z) that reflects the dependency between time periods based on the calculations of the sequence learning model (step S307). Subsequently, as shown by the connector A in FIG. 13B, the second learning unit 13 trains the classifier 132. The training of the classifier 132 is performed by using the parameter w G ,θ G First, the second learning unit 13 provides the true normal data obtained in step S303 as training data to the classifier 132 as input. Then, the second learning unit 13 adjusts the parameter w by backpropagation or the like so that the objective function E in the above equation (15) is maximized. D ,θ D (Step S308). The label of the training data is set to 1 (true normal data).
[0111] Next, the second learning unit 13 provides the pseudo-normal data generated by the generator 131 in step S306 and further converted in step S307 as input to the discriminator 132, and calculates the parameter w by backpropagation or the like so that the objective function E in the above equation (15) is maximized. D ,θ D is updated (step S309).
[0112] The learning of the classifier 132 in steps S308 and S309 corresponds to the dashed arrows in the block diagram of the second learning unit 13 shown in FIG. 6 , which indicate that a classifier error is calculated in block 135 of the objective function E based on the output 133 from the classifier 132, and then the error is backpropagated to the classifier 132.
[0113] Thereafter, if the value of objective function E has not converged (step S310: NO), adjustment unit 14 adjusts the model parameters of the sequence learning model (step S311), and second learning unit 13 repeatedly learns classifier 132. Adjustment unit 14 sets the model parameters adjusted in step S311 to the sequence learning model (step S312). Next, conversion unit 12 again inputs the normal data acquired in step S301 to the sequence learning model for which the adjusted model parameters have been set, performs calculations on the sequence learning model, and converts the data into normal data that reflects the inter-time zone dependency inherent in the sequence of the number of packets allocated for each time zone, and outputs the data as true abnormal data (step S313).
[0114] Next, the conversion unit 12 inputs the pseudo-normal data before conversion, which is generated based on noise by the generator 131, to the sequence learning model for which the adjusted model parameters are set, performs calculations on the sequence learning model, and converts the pseudo-normal data into pseudo-normal data that reflects the inter-time-zone dependency inherent in the sequence of the number of packets allocated for each time zone, and outputs the pseudo-normal data (step S314). Thereafter, the second learning unit 13 repeats steps S308 and S309, and when the value of the objective function E converges to the optimal solution of the above equation (15) (step S310: YES), it repeats the processes from step S302 to step S314 using other normal data in turn, as shown by the connector B in the figure, until the generator 131 and the discriminator 132 are trained (step S313: NO).
[0115] Thereafter, when the classifier 132 has been trained using all normal data (step S315: YES), the storage unit 20 stores the trained generative models, the generator 131' and the classifier 132', and the model parameters of the sequence learning model adjusted by the adjustment unit 14 (step S316). Note that steps S302 to S314 can be batch processed. After that, the process proceeds to step S5 in FIG. 11.
[0116] Next, the generation unit 15 causes the generator 131′ included in the trained generative model constructed by the second learning unit 13 to generate pre-conversion pseudo-normal data (step S5). Subsequently, the conversion unit 12 uses the sequence learning model in which the adjusted model parameters are set to convert the pre-conversion pseudo-normal data generated in step S5 into pseudo-normal data that reflects the inter-time period dependency inherent in the sequence of the number of packets distributed for each time period (step S6). Next, the abnormal signal number database 16 stores, among the pseudo-normal data converted in step S6, pseudo-normal data that is identified as pseudo-normal data by the classifier 132′ included in the trained generative model constructed by the second learning unit 13 (step S7). In step S7, the pseudo-normal data converted in step S6 is further passed through the classifier 132′ included in the trained generative model, and pseudo-normal data for which the output of the classifier 132′ is determined to be 0 (abnormal) >> 1 (normal) is stored in the abnormal signal number database 16.
[0117] After that, the target device 3 to be managed records the number of packets allocated by each of the plurality of traffic control devices 2 for each time period (step S8). The target device 3 to be managed is the device with the same target device ID: 1 as the device 3 for which the number of packets was collected and the learning of the generation model was performed in steps S1 to S7. In step S8, for example, the number of allocated packets over one month in 10-minute units is recorded (Fig. 4). Subsequently, the collection unit 10 collects the number of packets allocated to the target device 3 to be managed recorded in step S8 (step S9). Next, the conversion unit 12 performs the calculation of the sequence learning model with the adjusted model parameters set, and converts the sequence of the number of allocated packets for each time period collected in step S9 into a sequence of the number of allocated packets for each time period that reflects the dependency between the time periods inherent in the sequence (step S10).
[0118] Subsequently, when the sequence of the number of packets allocated to the target device 3 to be managed for each time period, which is converted in step S10, matches the pseudo-normal data stored in the abnormal signal number database 16, the determination unit 17 determines that an abnormal number of packets has been allocated to the target device 3 to be managed (step S11). In step S11, when the conditional expression of the above formula (20) is satisfied, the determination unit 17 can determine that the number of packets for each time period allocated to the target device 3 to be managed is abnormal. The determination unit 17 applies the conditional expression of the above formula (20) in order from, for example, the first pseudo-normal data corresponding to the earlier time period among the 1 to L pseudo-normal data stored in the abnormal signal number database 16, and when the conditional expression is satisfied in the pseudo-normal data of the nth (n < D) time period, it can be determined that an abnormal number of packets has been allocated to the target device 3 to be managed.
[0119] Next, when it is determined in step S11 that an abnormal number of packets has been allocated to the counterpart device 3 under management, the identifying unit 18 identifies, among the multiple traffic control devices 2, a traffic control device 2 that is allocating more packets than the other traffic control devices 2 during the time period subject to the determination (step S12). In step S12, one or more traffic control devices 2 can be identified.
[0120] Next, the instruction unit 19 transmits an instruction to the traffic control device 2 identified in step S12 to adjust the number of packets to be distributed (step S13). Specifically, the instruction unit 19 instructs the traffic control device 2 that is distributing more packets to the opposite device 3 to be managed than the other traffic control devices 2 to distribute an equal number of packets to the other traffic control devices 2. Thereafter, the traffic control device 2 that received the instruction changes the number of packets to be distributed to the opposite device 3 to be managed, i.e., the scheduling parameters of the transmission queue such as TPS, in accordance with the instruction (step S14). Thereafter, the processing from step S1 to step S14 is executed for each opposite device 3 other than the opposite device ID: 1 (opposing device IDs: 2 to N).
[0121] As described above, the anomaly management device 1 according to this embodiment learns parameters representing the density ratio between the probability density function of normal data and the probability density function of abnormal data based on normal data indicating the number of normally distributed packets for each time period that can be collected in large quantities and abnormal data indicating the number of abnormally distributed packets for each time period that can be collected even in small quantities, and estimates the density ratio. Furthermore, the probability density function of normal data and the probability density function of abnormal data determined based on the estimated density ratio are set as the objective function of the generative model, and the classifier 132 is updated in the direction of maximizing the objective function. Furthermore, in training the generative model, training data that reflects the inter-time period dependency, transformed by the sequence learning model, is used as input data for the classifier 132. Then, pseudo-normal data that is sufficiently deviated from the distribution of true normal data indicating the number of normally distributed packets, generated in large quantities by the generator 131' of the trained generative model, is further transformed using the sequence learning model to generate pseudo-normal data. The pseudo-normal data identified as pseudo-normal data by the classifier 132' of the trained generative model is used as an abnormal data template to build a database. This allows for appropriate management of bias in signal processing volume.
[0122] Furthermore, according to the abnormality management device 1 of this embodiment, the density ratio is estimated using abnormal data that is available even in small amounts, and the probability density function of normal data and the probability density function of abnormal data determined based on the density ratio are set as coefficients of the objective function of the generative model. Therefore, the generative model is trained by reflecting the patterns of normal data and abnormal data obtained as actual observation data, thereby improving the learning accuracy of the generative model.
[0123] Furthermore, according to the anomaly management device 1 of this embodiment, a sequence learning model that extracts features that represent inter-time zone dependency relationships inherent in the sequence of the number of packets distributed for each time zone is interposed between the input side of the classifier 132 of the generative model and the output side of the generator 131, and the values of the model parameters of the sequence learning model are adjusted according to the progress of learning of the generative model. This makes it possible to further improve the learning accuracy of the generative model.
[0124] In the embodiment described above, the second learning unit 13 has been described as having a generative model with a GAN configuration. However, the generative model can be configured not only based on a GAN but also based on a VAE (Variational Autoencoder), Energy-Based Models (EBMs), or the like.
[0125] In addition, in the described embodiment, the conversion unit 12 employs a neural network such as an RNN, LSTM, or self-attention as the sequence learning model. However, the sequence learning model may be an autoencoder, a transformer, or the like, as long as it learns the temporal or sequential dependencies inherent in sequence data and extracts features, converts, or reconstructs the input sequence based on the dependencies.
[0126] The above describes embodiments of the abnormality management device and abnormality management method of the present invention, but the present invention is not limited to the described embodiments, and various modifications that a person skilled in the art can conceive are possible within the scope of the invention described in the claims. [Explanation of symbols]
[0127] 1...abnormality management device, 2...traffic control device, 3...opposing device, 10...collection unit, 11...first learning unit, 12...conversion unit, 13...second learning unit, 14...adjustment unit, 15...generation unit, 16...abnormal signal count database, 17...determination unit, 18...identification unit, 19...instruction unit, 20...memory unit, 101...bus, 102...processor, 103...main memory device, 104...communication interface, 105...auxiliary memory device, 106...input / output I / O, 107...display device, 131...generator, 132...identifier, NW...network.
Claims
1. a first learning unit configured to learn a parameter representing a ratio between a probability distribution of normal data indicating a sequence of normal signal numbers assigned to the device for each time period and a probability distribution of abnormal data indicating a sequence of signal numbers assigned to the device for each time period, the sequence including an abnormal signal number that deviates from a range of normal signal numbers, and to estimate the ratio based on the learned parameter; a first conversion unit configured to convert the normal data into normal data that reflects the dependency relationships between time periods, using a sequence learning model having pre-set model parameters that represent the dependency relationships between time periods that exist in the sequence of normal signal numbers allocated to the device for each time period; a second learning unit configured to: consider the normal data, in which the dependency relationship converted by the first conversion unit is reflected, as true normal data, and generate pre-conversion pseudo-normal data before the dependency relationship is reflected, corresponding to pseudo-normal data sufficiently deviating from the distribution of the true normal data, while keeping fixed generator parameters of a generator that distinguishes between the true normal data and the pseudo-normal data, in a direction that maximizes an objective function based on a probability distribution of the normal data and a probability distribution of the abnormal data determined from the ratio estimated by the first learning unit; and to learn a generative model including the generator and the classifier; a generation unit configured to generate the pre-conversion pseudo-normal data using the generator included in the generative model trained by the second learning unit; a second conversion unit configured to convert the pre-conversion pseudo-normal data generated by the generation unit into the pseudo-normal data reflecting the dependency relationship using the sequence learning model; a storage unit configured to store data that has been further identified as the pseudo-normal data by the classifier included in the generative model trained by the second learning unit, from the pseudo-normal data that has been converted by the second conversion unit and in which the dependency relationship has been reflected; An abnormality management device comprising:
2. 2. The abnormality management device according to claim 1, further comprising an adjustment unit configured to adjust the model parameters of the sequence learning model according to a state of learning of the generative model by the second learning unit; the first conversion unit is configured to convert the normal data into normal data in which the dependency is reflected, using the sequence learning model having the model parameters adjusted by the adjustment unit; The second conversion unit is configured to convert the pre-conversion pseudo-normal data generated by the generation unit into the pseudo-normal data reflecting the dependency relationship, using the sequence learning model having the model parameters adjusted by the adjustment unit. An abnormality management device characterized by:
3. 2. The abnormality management device according to claim 1, a collection unit configured to collect identification information of each source device that has allocated each signal together with a sequence of the number of signals allocated to the device to be managed; a third conversion unit configured to convert, using the sequence learning model, the sequence of the number of signals allocated to the managed device into a sequence of the number of signals allocated to the managed device that reflects the dependency; a determination unit configured to determine that an abnormal number of signals has been allocated to the device to be managed when a series of the number of signals allocated to the device to be managed, in which the dependency relationship is reflected, matches at least a part of the pseudo-normal data stored in the storage unit; and An abnormality management device comprising:
4. 4. The abnormality management device according to claim 3, an identification unit configured to identify a source device that has assigned a set number of signals or more to the managed device when the determination unit determines that an abnormal number of signals has been assigned; an instruction unit configured to transmit an instruction to the source device identified by the identification unit to adjust the number of signals to be distributed to the managed device; An abnormality management device comprising:
5. 2. The abnormality management device according to claim 1, The sequence learning model is a recurrent neural network model. An abnormality management device characterized by:
6. A computer-implemented anomaly management method, comprising: a first learning step of learning parameters representing a ratio between a probability distribution of normal data indicating a series of normal signal numbers assigned to the device for each time period and a probability distribution of abnormal data indicating a series of signal numbers assigned to the device for each time period, including an abnormal signal number that deviates from the range of normal signal numbers, and estimating the ratio based on the learned parameters; a first conversion step of converting the normal data into normal data that reflects the dependency relationships between time periods, using a sequence learning model having pre-set model parameters that represent the dependency relationships between time periods that exist in the sequence of normal signal numbers assigned to the device for each time period; a second learning step of learning a generative model including the generator and the classifier by updating a classifier parameter of a classifier that distinguishes between the true normal data and the pseudo-normal data in a direction that maximizes an objective function based on a probability distribution of the normal data and a probability distribution of the abnormal data determined from the ratio estimated in the first learning step, while keeping fixed a generator parameter of a generator that generates pre-conversion pseudo-normal data before the dependency relationship is reflected, where the pre-conversion pseudo-normal data corresponds to pseudo-normal data that is sufficiently deviated from the distribution of the true normal data, with the normal data that has been converted in the first conversion step and in which the dependency relationship is reflected being treated as true normal data; a generating step of generating the pre-conversion pseudo-normal data by the generator included in the generative model trained in the second learning step; a second conversion step of converting the pre-conversion pseudo-normal data generated in the generation step into the pseudo-normal data reflecting the dependency relationship using the sequence learning model; a storage step of storing, in a storage unit, data that has been further identified as the pseudo-normal data by the classifier included in the generative model trained in the second learning step, from the pseudo-normal data that has been converted in the second conversion step and in which the dependency relationship has been reflected; An abnormality management method comprising:
7. 7. The abnormality management method according to claim 6, further comprising an adjustment step of adjusting the model parameters of the sequence learning model according to a learning state of the generative model in the second learning step; the first conversion step converts the normal data into normal data that reflects the dependency relationship using the sequence learning model having the model parameters adjusted in the adjustment step; The second conversion step converts the pre-conversion pseudo-normal data generated in the generation step into the pseudo-normal data reflecting the dependency relationship, using the sequence learning model having the model parameters adjusted in the adjustment step. An abnormality management method characterized by:
8. 7. The abnormality management method according to claim 6, Furthermore, a collection step of collecting the sequence of the number of signals allocated to the devices to be managed and the identification information of each source device that allocated each signal; a third conversion step of converting the sequence of the number of signals allocated to the managed devices into a sequence of the number of signals allocated to the managed devices that reflects the dependency relationship, using the sequence learning model; a determining step of determining that an abnormal number of signals has been allocated to the device to be managed when a series of the number of signals allocated to the device to be managed, in which the dependency relationship is reflected, matches at least a part of the pseudo-normal data stored in the storage unit; An abnormality management method comprising:
9. 9. The abnormality management method according to claim 8, a specifying step of specifying a source device that has assigned a set number of signals or more to the managed device when it is determined in the determining step that an abnormal number of signals has been assigned; an instruction step of transmitting an instruction to the source device identified in the identification step to adjust the number of signals to be distributed to the managed device; An abnormality management method comprising:
Citation Information
Patent Citations
Abnormal management device and abnormal management method
JP7710633B1
Abnormality management device and abnormality management method
JP7731520B1
Abnormality management device and abnormality management method
JP7742001B1
Abnormality detection device, probability distribution learning device, self-encoder learning device, data conversion device, and program
WO2020031570A1
Communication service system and congestion avoidance method
JP2018142848A