ANOMALY DETECTION AND AUTOMATIC CORRECTION SYSTEM

TR202613650A2Pending Publication Date: 2026-09-21AVEA ILETISIM HIZMETLERI ANONIM SIRKETI (TEKNOLJI MERKEZİ)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
TR202613650
Authority / Receiving Office
TR · TR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-08-12
Publication Date
2026-09-21

Smart Images

  • Figure 00000016_0000
    Figure 00000016_0000
Patent Text Reader

Abstract

This invention relates to a system (1) that enables AI-based early detection of network performance anomalies, root cause analysis, and orchestration of automated remediation actions in 4G / 5G radio access network infrastructure. System (1) provides real-time anomaly detection and self-healing capabilities in scenarios such as cell outage detection, coverage gap identification, interference spike recognition, transmission failure clustering, throughput drop estimation, equipment failure diagnosis, and configuration error detection.
Need to check novelty before this filing date? Find Prior Art

Description

1 TARIFF ANOMALY DETECTION AND AUTOMATIC CORRECTION SYSTEM Technical Area This invention enables the detection of network performance anomalies in 4G / 5G radio access network infrastructure using artificial intelligence. 5 based on early detection, root cause analysis and automated remediation actions It is related to a system that provides the orchestration. State of the Art Current practices have certain shortcomings and inadequacies. These are as follows: Threshold-based alarms: Static threshold values, e.g., PRB usage > 80%, false alarm 10. It leads to positive / negative outcomes. There is no dynamic fundamental tracking in these structures. Silaged KPI monitoring: Each KPI is evaluated independently. RSRP low + transfer. High error rate = detection of multivariate anomaly patterns in the form of coverage holes. It cannot be done. Reactive troubleshooting: Anomalies are discovered following user complaints. These structures have 15 Proactive detection is not present. Manual root cause analysis: Expert engineers manually analyze the records. In this structure... The process takes days. Lack of spatio-temporal correlation: Anomalies that spread to multicellular organisms, e.g., 10 The interruption of the main carrier fiber affecting the cell is distributed as single-cell alarms. 20 Seasonal pattern ignorance: Treating weekly / daily traffic cycles as normal behavior. It cannot be done. Limited automated repair: Manual intervention is required after an alarm. In this configuration... Its self-repair capability is minimal. False alarm fatigue: Operators are constantly monitoring alarms due to the high false positive rate. This is neglected, and critical issues are overlooked. 2 Patent application number TR2025 / 017090, which is included in the prior art. The document details the user's network traffic, file movements, and web interactions in real time. AI-powered threat detection that can monitor and analyze threats in real time. through its mechanisms, it prevents harmful activities both online and locally. capable of preventing, with its modular structure, it is used in personal computers and small-scale systems. The available individual firewall systems are described. The relevant application... The system described in the document uses a different approach for anomaly detection. In conclusion, solutions that address the needs described above are relevant to the subject. Due to its shortcomings, it has become necessary to make improvements in the relevant technical field. Brief Description of the Invention 10 The invention was created by drawing inspiration from existing situations and overcoming the aforementioned drawbacks. It aims to solve the problem. The aim of this invention is to identify network performance anomalies in 4G / 5G radio access network infrastructure. AI-based early detection, root cause analysis, and automated remediation. It is the development of a system that provides orchestration of actions. 15 The system detects cell disruptions, identifies coverage gaps, and tracks sudden surges in interference. recognition, transmission failure clustering, throughput degradation prediction, equipment failure diagnosis and Real-time anomaly detection in configuration error detection scenarios and its own It provides self-healing abilities. The system operates on self-organizing network platforms of telecommunications operators, involving thousands of 20 unsupervised and supervised multidimensional KPI time series collected from base stations It continuously analyzes using machine learning models. The system learns the basics of normal behavior, detects deviations, and correlates with related multicellular processes. It detects anomaly patterns and triggers automated remediation workflows. The system reduces the burden of manual troubleshooting for NOC operators by 80% while MTTR – 25 It reduces the repair time from hours to minutes. A Shape That Will Help Understand the Invention Figure 1 is a schematic representation of the general structure of the system that is the subject of the invention. 3 Explanation of Part References 1. System 2. Radio access network element 3. Data collector 4. Time series database 5 5. Unsupervised anomaly detector 6. Multivariate pattern recognizer 7. Spatial-temporal clustering analyzer 8. Root cause analyzer 9. Predictive maintenance engine 10 10. Improvement action is selective. 11. Self-repairing regulator 12. Explainability engine 13. Control panel Detailed Description of the Invention 15 In this detailed description, the preferred configurations of the system (1) that is the subject of the invention are only This is explained to facilitate a better understanding of the subject. This invention enables the detection of network performance anomalies in 4G / 5G radio access network infrastructure using artificial intelligence. early detection based on root cause analysis and automated remediation actions It is related to a system (1) that provides its orchestration. 20 System (1), cell interruption detection, coverage gap identification, interference surge recognition, transmission failure clustering, throughput degradation prediction, equipment failure diagnosis and Real-time anomaly detection in configuration error detection scenarios and its own It provides self-healing abilities. 4 The system (1) is used by telecommunication operators on their self-organizing network platforms. unsupervised and multidimensional KPI time series collected from thousands of base stations It continuously analyzes with supervised machine learning models. The system includes (1) KPIs - Key Performance Indicators, RSRP, RSRQ, SINR, PRB usage, RACH 5 indicators such as success rate, handover success rate, call drop rate, and efficiency distribution. It consists of metrics. RSRP is the metrics the device receives from the base station in the radio access network. RSRQ is a fundamental value that measures the average strength of a signal. In a radio access network, RSRQ is the value of a device's signal strength. SINR stands for Reference Signal Reception Quality. It represents Signal, Interference, and Noise Reception Quality. The PRB (Proximal Reliability Ratio) is a value that measures the quality of connection in a radio access network. RACH, 10 refers to the smallest block of radio resources allocated for data transmission on a network. In telecommunications, it stands for Random Access Channel. System (1) learns the basics of normal behavior, detects deviations, and related multicellular It detects anomaly patterns and triggers automated remediation workflows. The system (1) relieves the burden of manual troubleshooting of NOC – Network Operations Center operators. It reduces the MTTR – Time to Repair value by 80%, from hours to minutes. 15 The system that is the subject of the invention, the schematic representation of which is given in Figure 1 (1);  Augmented reality / virtual reality, cloud gaming, autonomous vehicles, industrial IoT – Edge computing services such as the Internet of Things, consumed end-user devices, and 4G / 5G base station radio access network including application client components. elements (2), 20  4G / 5G radio access network elements (2) and user connections to the end infrastructure a gateway that directs and collects data from multiple sources data collector (3),  Base stations, aggregation sites, and central offices located in the same place Geographically distributed edge computing servers, containerized / virtual machines 25 Time series database offering workload execution infrastructure based on (4),  Real-time, operating as agents running at each end node CPU / memory / storage / network usage, available capacity, working containers / virtual machines, unsupervised collection of node health metrics anomaly detectors (5), 30  each person's GPS - Global Positioning System trajectory, cell transmission history, By collecting velocity vector information, future cell / edge node transitions can be predicted. LSTM - Long Short-Term Memory / GRU - Long Short-Term Memory models a multi-faceted AI engine that predicts and generates the transfer probability matrix Variable pattern recognizer (6),  The application's resources include CPU cores, RAM, storage, and GPU. requirements, delay sensitivity in the form of P95 delay < X ms, bandwidth The request, microservice DAG – Dependency 5 in the form of a Directed Non-Cyclic Graph. Profiling for topology and service quality service level agreements and classification spatial temporal clustering analyzer (7),  RTT – Round Trip Time, jitter, packet loss for each user end node pair, active / passive measurement of end-to-end network path quality in the form of available bandwidth. The main reason for measuring with techniques and storing in time series database (4) is 10 analyzer (8),  Resource demand and user traffic for each edge node and application Analytics that predict time series models using LSTM, Prophet, and ARIMA models. predictive maintenance engine (9),  Delay during the process of assigning application workloads to end nodes: 15 minimizing, improving resource efficiency, energy consumption, cost, and reliability. simultaneous optimization using genetic algorithms, simulated annealing, or NSGA- II performs multi-objective optimization operations based on genetic algorithms. Improvement action is selective (10),  By analyzing the microservice dependency graph, 20 interdependent services at optimum proximity, i.e., on the same node or with minimum hop distance, a self-healing regulator that distributes and optimizes service network routing. (11),  A separate DQN, A3C, PPO designation for each edge coverage area Including a reinforcement learning agent, the situation involves user locations, application 25 using requirements, end resources and network quality, as action. Deploying the application to node X, user experience quality – resource cost optimal with its distributed reinforcement learning feature and reward system. The explainability engine (12) that offers placement policy and  Application 30 based on user mobility forecasting and resource estimation live passage of instances, i.e. state information with checkpoint restoration. the transition, managing and optimizing the transition timing before interrupting module. NOC – Network Operations Center control panel (13) It includes. 6 The characteristics of the elements in the System (1) are as follows: Data collector (3) periodically collects data from radio access network elements (2) at 15 min / 1 hour intervals. maintenance counters, real-time event alarms, corrective maintenance configurations and sums the user plane traces. This data results in a time series database. (4) Multidimensional KPI - Key Performance Indicator vectors per cell are created. 5 These vectors are generated; RSRP_mean, RSRP_standard deviation, RSRQ_P5, SINR_P50, PRB_usage, RACH_success_rate, HO_success_rate, Call drop rate, throughput average, active users, and more than fifty other metrics like these. It includes this feature. The unsupervised anomaly detector (5) performs autoencoder training. In this training, input 10 KPI vectors consisting of data from the first 30 days are used, with an encoder in the form of 50D → 10D. It compresses the hidden field, and the decoder reconstructs the input. In case of a reconstruction error, An anomaly score is calculated. The Isolation Forest program works in parallel with the educational program. This... In this study, random tree partitions are used, with an anomaly equal to the isolation depth. In community logic, any of the methods – OR both – can be configured. 15 If marked with an "AND" symbol, an anomaly is detected. Multivariate pattern recognizer (6), GNN - Graphical Neural Networks graph different structures It forms. In these structures, nodes = cells (2) from radio access network elements, edges = neighbor relationships + frequency of rotation from data collector (3), node properties = time The series database contains (4) KPI vectors. The graphic convolution spreads the information and 20 Each cell collects neighboring KPI information. The learned embedded vectors are fed into the classifier. It is nourished. In these vectors, normal, cell interruption, coverage gap, interference, occlusion The data are compared with each other. A cell may have more than one type of anomaly. Multi-label classification, which it can display, is supported. In the spatial temporal clustering analyzer (7), time series data for 1 hour 25 DBSCAN is run on the sliding time windows (4) from the base. In this run ε = 1 km geographical distance threshold, minimum_samples = 3 cells. Also... Labeled clusters: isolated_event (1-2 cells), regional_issue (3-10 cells), cluster (10+ cells) It consists of large_interrupt data. In temporal tracking, the cluster's time range is examined. In its evolution, expanding / contracting patterns are detected. 30 The root cause analyzer (8) constructs the causal graph. Here, variables = Time KPIs from the series database (4), configuration parameters from the data collector (3) + 7 It includes environmental factors. Granger causality tests: if the past values ​​of A cause B to... If Granger A predicts KPI_B better than Granger B based on its own history, then Granger A predicts KPI_B. It explains. Bayesian network learning: probabilistic dependencies are established. Inference. motor: given anomaly evidence from an unsupervised anomaly detector (5), most likely The root cause is calculated. For example, P(hardware_failure | observed_symptoms) = 0.85 5 It is in this form. The predictive maintenance engine (9) displays the failure event history in the time series database (4). It trains the LSTM using: Input = 7-day KPI sequence before the failure, Output = next. Probability of failure within 24 / 48 / 72 hours. Learned early warning signs: phased RSRP - Reference Signal Received Power degradation, increased CRC - Cyclic Redundancy Check errors, 10 These are temperature anomalies. Maintenance tickets with estimated failure time and confidence score. It is generated automatically and sent to the control panel (13). Improvement action selector (10), rule-based heuristic methods and RL - Reinforcement It runs a combination of learning agents. Rules: if unsupervised anomaly detector (5) Restart the cell if cell interruption is detected; if multivariate 15 If a coverage gap appears from the pattern recognizer (6), adjust the antenna tilt; if If interference comes from the spatial temporal clustering analyzer (7), the frequency is reallocated. et. The RL agent learns the following: status = anomaly type from unsupervised anomaly detector (5), Violence, radio access network elements (2) cell load, time of day, action = correction Options, reward = speed of solution + minimizing user impact. Too many 20 options for action discovery. armed robber. The self-healing regulator (11) executes the action selected from the improvement action selector (10). Parameter adjustment process includes tilt angle, azimuth, power, neighbor list, radio access network. (2) CIQ / NetAct API calls are made to the elements. During cell restart OAM interface commands are sent to radio access network elements (2) to eNB / gNB. Traffic 25 During the unloading process, the rotational speed parameter is adjusted and load balancing is triggered. Impact simulation and approval workflows for high-risk actions are performed during the inspections. KPI monitoring from the data collector (3) for 30 minutes during post-action validation. The procedure is performed, and if no improvement is detected, it is reversed. The explainability engine (12) 30 anomalies marked in the unsupervised anomaly detector (5) It generates reasons for: which KPIs are identified in the SHAP - Shapley Additive Annotations method? The values ​​that contributed most to the anomaly score were used in calculating the importance of the feature. It is used in natural language generation, "The cause of the Cell_123 anomaly is the radio access network." 8 Based on the data received from elements (2), RSRP decreased by 15 dB. Time series Based on the data obtained from the database (4), the handover errors decreased from 30% to 25%. The sudden change, according to the data received from the data collector (3), is that the temperature increased by 10%. An example is its rise to 65°C. Causal from the root cause analyzer (8) Chain visualization is obtained and a fault propagation diagram is created. Reports are saved and 5 It is displayed on the control panel (13). The control panel (13) has real-time anomaly stream displays. On these displays, unsupervised anomaly detector (5) sorted list according to severity, spatial geographic heat map from temporal clustering analyzer (7), time series database (4) trend charts are included. In addition, from the self-healing regulator (11) 10 The action status is tracked as pending, in progress, completed, or failed. These screens display performance metrics in the form of accuracy / recall. Detection accuracy, false positive rate, and MTTR – Time to Repair based on anomaly type. The deviation detection in model tracking is as follows: unsupervised anomaly detector (5), very Retraining of the variable pattern recognizer (6) and the predictive maintenance engine (9) 15 It triggers. The operation of the system (1) is carried out in the following steps: The data collector (3) collects a continuous stream of KPIs in the form of a Kafka pipeline. This stream is only Time series data in high cardinality form optimized for insertion workload. It is written on the base (4). 20 The autoencoder performs continuous inference. It does this in parallel for all cells every 15 minutes. Collective forecasts are made. The reconstruction error threshold is adaptable. In this adaptation, the moving average + 3x standard deviation is applied. The Isolation Forest consists of 100 trees; pollution factor past It adjusts automatically according to the anomaly rate. This adjustment is typically around 1-5%. 25 GNN is retrained daily. This training includes validated events + NOC feedback. Supervised learning is performed using new anomaly labels in this manner. The graphical structure is updated: This process reflects changes to the transfer topology. Real-time inference is performed. This inference occurs instantly when the cell KPI vector arrives. Classification is done. 30 9 Spatial-temporal clustering analyzer (7) performs batch studies of 7 hours. In the study, anomaly points from the last 24 hours are clustered. Persistent clusters longer than 6 hours. The situation is escalated. Temporary anomalies lasting less than 1 hour are recorded, but these are of low priority. The root cause analyzer is triggered. This trigger detects a high-significance anomaly. When this is done, and the multi-cell cluster is identified, the NOC engineer manually determines root cause 5. The analysis is done when a request is made. A causal graph query is performed. This query includes the 3 most likely causes, their confidence scores, and which ones. Supporting evidence is used to correlate KPI trends. In predictive maintenance, daily batch operations are performed. Failure risk scores are calculated for all cells. Calculated. High-risk cells with a score greater than 0.7 are marked for inspection. 10 A priority work order is created during maintenance scheduler integration. The improvement action is called for selective (10) anomalies. For known patterns, it is called for deterministic. The rule engine is consulted first in the form of actions. According to the exploitation balance of exploration. For ambiguous situations where comparisons are made, the RL agent is used. Large configuration changes, Humans are used in the cycle for critical actions such as multicellular impact. 15 Self-healing regulatory (11) action performs security checks. Traffic Dry run simulation in the form of impact estimation with a simulator, automated for low risk. Approval workflow: management approval for mid-level, change board approval for high risk, Execution with monitoring in the form of real-time KPI tracking during the action, within 15 minutes. If the KPI deteriorates, an automatic rollback is performed. 20 The explainability engine (12) generates post-anomaly reports. The report includes a timeline, Annotated KPI charts with periods of anomaly, SHAP waterfall charts, causal diagrams. It includes a PDF report containing diagrams. This report is for future similarity searches. time series are stored in the database (4). Live updates are made on the control panel (13). These updates are for new anomalies 25 WebSocket offers instant notifications and interactive, detailed breakdowns based on cell, sector, and neighbors. Operators can approve / reject, add notes, and provide clarification. It is in the form of a feedback loop. The rejected alarms model in the feedback loop is incorrect. It retrains positively. The system in question (1) is the SON - Self-Organizing in the OSS / BSS ecosystem. It is deployed as a network module. EM - Collects KPIs from the Element Manager layer, NMS - Network. It works integrated with the Management System. The system (1) is compatible with the O-RAN architecture. It is xApp within Near Real-Time RIC. Anomaly detection, long-term optimization as rApp in Non-Real-Time RIC 5 policies are implemented. System (1) has cloud-native deployment capability. Stateless services: API gateway, web server; stateful: time series VT, model server in Kubernetes pods includes. System (1) has a microservice architecture. In System (1), data collection service, anomaly 10 The detection service, root cause analysis service, and remediation service are independently scalable. The system (1) operates in a message-oriented manner. In the system (1), KPI flow, anomaly events, actions Asynchronous communication for Kafka topics is performed in the form of commands. In the system (1) There is an ML – Machine Learning pipeline. The system has (1) TRAINING workflows. Kubeflow, MLflow for the model registry, and Seldon / KFServing 15 for inference presentation. It is used. System (1) performs continuous integration / continuous deployment. System (1) GitOps - ArgoCD offers automated testing such as pytest and integration tests, model versioning, and A / B optimization. There are tests available.

Claims

11 REQUESTS 1. Artificial intelligence for network performance anomalies in 4G / 5G radio access network infrastructure. early detection based on root cause analysis and automated remediation actions It is a system (1) that provides orchestration, and its feature is;  Augmented reality / virtual reality, cloud gaming, autonomous vehicles, industrial IoT – 5 Edge computing services such as the Internet of Things, consumed end-user devices, and 4G / 5G base station radio access network including application client components. elements (2),  4G / 5G radio access network elements (2) and user connections to the end infrastructure 10 is the gateway that directs and collects data from multiple sources. data collector (3),  Base stations, aggregation sites, and central offices located in the same place Geographically distributed edge computing servers, containerized / virtual machines. Time series database offering workload execution infrastructure based on (4),  15 real-time agents operating at each end node CPU / memory / storage / network usage, available capacity, working containers / virtual machines, unsupervised collection of node health metrics anomaly detectors (5),  each person's GPS - Global Positioning System trajectory, cell transmission history, By collecting velocity vector information, future cell / edge node transitions can be predicted. LSTM - Long Short-Term Memory / GRU - Long Short-Term Memory models a multi-faceted AI engine that predicts and generates the transfer probability matrix Variable pattern recognizer (6),  The application's resources include CPU cores, RAM, storage, and GPU. requirements, delay sensitivity in the form of P95 delay < X ms, bandwidth 25 the demand, microservice DAG – Directed Non-Cyclic Graph form of dependency Profiling for topology and service quality service level agreements and classification spatial temporal clustering analyzer (7),  RTT – Round Trip Time, jitter, packet loss for each user end node pair, Active / passive measurement of end-to-end network path quality in the form of available bandwidth 30 The main reason is that it measures with techniques and stores in time series database (4). analyzer (8), 12  Resource demand and user traffic for each edge node and application Analytics that predict time series models using LSTM, Prophet, and ARIMA models. predictive maintenance engine (9),  Delay during the process of assigning application workloads to end nodes minimizing, improving resource efficiency, energy consumption, cost, and reliability. simultaneous optimization using genetic algorithms, simulated annealing, or NSGA- II performs multi-objective optimization operations based on genetic algorithms. Improvement action is selective (10),  Analyze the microservice dependency graph to identify interdependent services at optimum proximity, i.e., on the same node or with minimum hop distance, 10 a self-healing regulator that distributes and optimizes service network routing. (11),  A separate DQN, A3C, PPO designation for each edge coverage area including a reinforcement learning agent, user positions as situations, application using requirements, end resources and network quality, action 15 Deploying the application to node X, user experience quality – resource cost optimal with its distributed reinforcement learning feature and reward system. The explainability engine (12) that offers placement policy and  Implementation based on user mobility forecasting and resource estimation live traversal of instances, i.e., checkpoint restoration with status information 20 the transition, managing and optimizing the transition timing before interrupting module. NOC – Network Operations Center control panel (13) It includes.

2. The system mentioned in accordance with claim 1 is (1), and its feature is a radio access network. Periodic maintenance meters from (2) 15 min / 1 hour intervals, actual 25 alarms related to timed events, corrective maintenance configurations, and user-level taking the sum of the traces, as a result of this data, the time series database (4) and cell multidimensional KPI - Key Performance Indicator vectors It includes a data collector (3) that enables its creation.

3. The system mentioned in accordance with claim 1 is (1), and its feature is that the first 30 days are 30 as input. The encoder uses KPI vectors consisting of data in the form of 50D → 10D. autoencoder that compresses the hidden field, the decoder reconstructs the input. conducting the training, calculating the anomaly score in the reconstruction error, 13 Isolation Forest is being used in parallel in education, with randomly selected trees in this study. partitions, using an anomaly equal to the depth of isolation, in community logic Either of the methods – OR or both – can be configured AND checked. It includes an unsupervised anomaly detector (5) that detects anomalies.

4. The system mentioned in accordance with claim 1 is (1), and its feature is; nodes = radio access network 5 (2) cells, edges = neighbor relationships + data collector (3) rollover Frequency, node characteristics = KPI vectors from time series database (4) GNN - Graphical Neural Networks create different structures in a graph and transmit information through graph convolution. embedded vectors that are deployed and collect neighboring KPI information for each cell. feeding into the classifier, these vectors show normal, cell interruption, coverage gap, 10 The initiative compares congestion data, from one cell to another. multi-label classification supports multiple anomaly types that can be shown. It includes a variable pattern recognizer (6).

5. The system mentioned in accordance with claim 1 is (1), and its characteristic is; ε = 1 km geographical distance threshold, minimum_samples = 3 cells, time series data for 1 hour. 15 Running DBSCAN on sliding time windows (4) from the base, 1-2 cell isolated_event, regional_issue of 3-10 cells, large_interruption of 10+ cells from data. creating labeled clusters, temporally tracking the evolution of the cluster over time, Spatial-temporal clustering analyzer that detects expanding / contracting patterns (7) includes. 20 6. The system mentioned in accordance with claim 1 is (1), and its feature is that the variables are time series data. from the base (4) KPIs, configuration parameters from the data collector (3) and environmental In Granger causality tests, if a causal graph is constructed that includes the factors... If A's past data predicts B better than B's own past data, then KPI_A Granger explains KPI_B using probabilistic 25 in Bayesian network learning. creating dependencies. from the unsupervised anomaly detector in the inference engine (5) Given the evidence of the anomaly, the root cause is calculated by determining the most likely root cause. It includes the analyzer (8).

7. The system mentioned in accordance with claim 1 is (1), and its feature is that it is in a time series database. (4) Training LSTM using fault event history, with 30 faults as input in this training. The previous 7-day KPI sequence, as an output, indicates the probability of failure in the next 24 / 48 / 72 hours. using, stepped RSRP - Reference Signal Received Power distortion, increasing CRC - Cyclic Redundancy Control detects errors and temperature anomalies using learned early warning systems. 14 maintenance using indicators, estimated failure time and confidence score. The predictor that automatically generates tickets and sends them to the control panel (13) maintenance engine (9) includes.

8. The system mentioned in accordance with claim 1 is (1), and its feature is rule-based heuristic. methods and combinations of RL - Reinforcement Learning agents, if 5 If a cell interruption is detected by the unsupervised anomaly detector (5), the cell is closed. restart if the coverage gap from the multivariate pattern recognizer (6) If it comes, adjust the antenna tilt, if from the spatial temporal clustering analyzer (7) The situation is that rules are created to reallocate the frequency if an incoming request is received. unsupervised anomaly detector (5) anomaly type, severity, radio access network 10 (2) cell load, time of day, action = correction options, reward = Training the RL agent to improve resolution speed and minimize user impact. Improvement action selector using multi-armed robber for action discovery (10) It includes.

9. The system mentioned in accordance with claim 1 is (1), and its feature is; improvement action selector 15 (10) performs the selected action, setting the parameter angle, azimuth, power, Making CIQ / NetAct API calls to the neighbor list radio access network elements (2), In the cell restart process, radio access network elements to eNB / gNB (2) OAM interface command sender, turnover parameter in traffic offloading process. adjustment, load balancing trigger, impact simulation in pre-checks and 20 Performing approval workflow for high-risk actions, post-action verification. data collector (3) performs KPI monitoring for 30 minutes and detects improvement If it does not, it includes a self-repairing regulator (11) that reverses it.

10. The system mentioned in accordance with claim 1 is (1), and its characteristic is; uncontrolled anomaly SHAP - Shapley 25, which produces reasons for anomalies marked in the detector (5). In the Contributing Explanations method, which KPIs contribute most to the anomaly score? radio access network that uses found values ​​in calculating feature importance from its elements (2), data collector (3) and time series database (4) Generate natural language based on the data received from the root cause analyzer (8) causal chain visualization, field and fault propagation diagram generation, reports 30 storing and displaying these reports on the control panel (13) It includes an explainability engine (12).

11. The system mentioned in accordance with claim 1 is (1), and its characteristic is; uncontrolled anomaly List sorted by severity from detector (5), spatial temporal clustering from the analyzer (7) geographic heat map, time series database (4) trend The graphs are pending from the self-healing regulator (11), Data is available in the form of action status tracking: completed, failed, etc. real-time anomaly stream displays, sensitivity / recall displays on these screens Detection accuracy, false positive rate, and anomaly type according to MTTR – Repair Deviation detection in model monitoring, which has performance metrics such as duration. with unsupervised anomaly detector (5), multivariate pattern recognizer (6) and Control panel (13) 10 which triggers retraining of the predictive maintenance engine (9) It includes.