Anomaly detection method and apparatus for temporal actions, electronic device, and storage medium

By using preset prediction models of attention modules and multiple preset predictors in timing behavior abnormality detection, the timing behavior characteristic values ​​are processed to generate predicted state representation vectors and calculate the abnormal scores, the problem of low accuracy in timing behavior abnormality detection in the prior art is solved, and more efficient and accurate abnormality detection is achieved.

WO2025124164A1PCT designated stage expired Publication Date: 2025-06-19CHINA TELECOM BESTPAY CO LTD

Patent Information

Application Number
PCT/CN2024/135561
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-11
Filing Date
2024-11-29
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

The accuracy of abnormal detection of timing behavior in the prior art is low, mainly due to the problem of the imbalance of abnormal samples and normal sample data based on supervised learning.

Method used

A timing behavior abnormality detection method is adopted, by collecting the current behavior data and state data of the target system, determining the true state representation vector of each timing behavior in the timing behavior set under each preset indicator, and input the behavior characteristic value into the preset prediction model, and outputting the prediction state representation vector. The preset prediction model includes an attention module and a plurality of preset predictors. The attention module processes the behavior feature value, obtains the timing behavior feature representation, and processes the timing behavior feature representation through the preset predictor corresponding to each preset indicator, and obtains the prediction state representation vector under each preset indicator. Based on these representation vectors, the abnormal score of the target system is calculated and the abnormal state is determined when the abnormal score is greater than the preset threshold.

Benefits of technology

It improves the efficiency and accuracy of abnormal detection of timing behavior, and solves the problem of low detection accuracy in related technologies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024135561_19062025_PF_FP_ABST
    Figure CN2024135561_19062025_PF_FP_ABST
Patent Text Reader

Abstract

The present application discloses an anomaly detection method and apparatus for temporal actions, an electronic device, and a storage medium. The anomaly detection method comprises: on the basis of acquired current action data and current state data of a target system, determining a real state representation vector of each temporal action in a temporal action set under each preset index; determining an action feature value of each temporal action on the basis of the current action data; inputting the action feature value into a preset prediction model, and outputting a predicted state representation vector of each temporal action under each preset index; and on the basis of weight values and alarm values of all the preset indexes, and the real state representation vectors and the predicted state representation vectors of all the temporal actions under each preset index, determining an anomaly score of the target system, and when the anomaly score is greater than a preset anomaly threshold, determining that the target system is in an anomalous state.
Need to check novelty before this filing date? Find Prior Art

Description

Abnormal detection method and device for time series behavior, electronic device and storage medium

[0001] Related applications

[0002] This application claims priority to Chinese patent application number 2023116970628, filed on December 11, 2023, entitled “Abnormality detection method for temporal behavior, device therefor, electronic device and storage medium”, the entire text of which is hereby incorporated by reference. Technical Field

[0003] The present application relates to the field of artificial intelligence, and more specifically, to a method for detecting anomalies in temporal behavior, a device thereof, an electronic device, and a storage medium. Background Art

[0004] Time series anomaly detection has always been a challenging problem. With the rapid development of information technology and the internet, network systems are becoming increasingly complex, and system-based time series anomaly detection is becoming increasingly important. In system monitoring scenarios, determining whether a system anomaly has occurred based on behavior and system response is often a manual process. Due to the diverse nature of different scenarios and behaviors, rule-based time series anomaly detection methods have limitations. Consequently, an increasing number of artificial intelligence (AI) models are being used for time series anomaly detection. However, supervised learning-based machine learning models often suffer from a significant imbalance between abnormal and normal data samples, resulting in low detection accuracy for current AI models in time series anomaly detection systems.

[0005] In related technologies, one method for detecting system time series anomalies is to detect whether a system anomaly has occurred by setting rules based on manual experience. However, rules set based on manual experience often need to rely on expert experience, and the set rules are often limited by expert experience, making it difficult to update the rules in a timely manner, and difficult to effectively detect in different scenarios and different behaviors. Therefore, related technologies have also proposed training time series anomaly detection models based on manually labeled behavior samples to determine whether a system anomaly has occurred. However, due to the difficulty in obtaining a balanced number of high-quality labeled samples in actual production environments, the trained artificial intelligence models often have unsatisfactory detection effects in actual production environments. Summary of the Invention

[0006] The embodiments of the present application provide a method for detecting anomalies in time series behavior, an apparatus thereof, an electronic device, and a storage medium thereof, to at least solve the technical problem of low accuracy in detecting anomalies in time series behavior in related technologies.

[0007] According to one aspect of an embodiment of the present application, a method for detecting anomalies in time series behavior is provided, comprising: collecting current behavior data and current state data of a target system, and determining, based on the current behavior data and the current state data, a true state representation vector of each time series behavior in a time series behavior set under each preset indicator; determining, based on the current behavior data, a behavior feature value of each time series behavior; for each time series behavior, inputting the behavior feature value into a preset prediction model, and outputting a predicted state representation vector of the time series behavior under each preset indicator, wherein the preset prediction model comprises: an attention module and a plurality of preset predictors, processing the behavior feature value by the attention module to obtain a time series behavior feature representation, processing the time series behavior feature representation by the preset predictor corresponding to each preset indicator to obtain the predicted state representation vector under each preset indicator; determining an anomaly score of the target system based on weight values ​​and alarm values ​​of all the preset indicators, the true state representation vectors of all the time series behaviors under each preset indicator, and the predicted state representation vectors, and determining that the target system is in an abnormal state if the anomaly score is greater than a preset anomaly threshold.

[0008] Furthermore, the step of determining the true state representation vector of each time series behavior in the time series behavior set under each preset indicator based on the current behavior data and the current state data includes: determining the time series behavior set based on the business requirements of the business performed by the target system, wherein each time series behavior in the time series behavior set corresponds to a time sequence; determining the preset indicator set based on the business requirements, wherein the preset indicator set includes: multiple preset indicators; determining the current behavior sub-data and current state sub-data involved in each time series behavior based on the current behavior data and the current state data; for each time series behavior, determining the true state representation vector of the time series behavior under each preset indicator based on the current behavior sub-data and the current state sub-data involved in the time series behavior.

[0009] Furthermore, after determining the behavioral characteristic value of each of the time series behaviors based on the current behavior data, it also includes: judging whether each of the behavioral characteristic values ​​is a continuous value; if the behavioral characteristic value is a continuous value, performing discrete processing on the continuous value to obtain the behavioral characteristic value after discrete processing.

[0010] Furthermore, before inputting the behavior feature value into the preset prediction model and outputting the predicted state representation vector of the time series behavior under each of the preset indicators, it also includes: constructing an initial prediction model, wherein the initial prediction model includes: an initial attention module and multiple initial preset predictors, each of the initial preset predictors corresponds to one of the preset indicators; collecting historical behavior data and historical state data of the target system within a historical time period; based on the historical behavior data, determining a set of historical behavior feature values ​​for each of the time series behaviors, and based on the historical behavior data and the historical state data, determining a historical state representation vector for each of the time series behaviors under each of the preset indicators; representing the set of historical behavior feature values ​​and all the historical state representation vectors as training data; using the training data to train the initial prediction model until the cross entropy loss is The loss value is less than a preset loss threshold, and the parameter value of each preset parameter in the preset parameter set is obtained, wherein the cross entropy loss value is calculated based on the initial state representation vector and the historical state representation vector using a preset loss function, and the initial state representation vector is a state representation vector output by the initial prediction model, and the preset parameter set includes at least: a first parameter set in the initial attention module, a prompt parameter, and a second parameter set in each of the initial preset predictors, the first parameter set includes at least: feature embedding weight parameters, feature embedding bias parameters, position embedding weight parameters, position embedding bias parameters, and each decoder layer parameter, the second parameter set includes at least: prediction weight parameters, prediction bias parameters; based on the parameter values ​​of all the preset parameters, the initial prediction model is adjusted to obtain the trained preset prediction model.

[0011] Furthermore, the step of processing the behavior feature value through the attention module to obtain the temporal behavior feature representation includes: for each of the temporal behaviors, determining the feature code of the temporal behavior based on the behavior feature value, and determining the position code of the temporal behavior based on the time sequence of the temporal behavior; determining a first vector representation based on the feature code, the feature embedding weight parameter value of the feature embedding layer in the attention module, and the feature embedding bias parameter value, and determining a second vector representation based on the position code, the position embedding weight parameter value of the position embedding layer in the attention module, and the position embedding bias parameter value; splicing the first vector representation and the second vector representation to obtain a feature vector representation; splicing the feature vector representation and the prompt vector representation of the prompt parameter to obtain a preset vector representation; the preset vector representation is processed by each decoder layer in the attention module to obtain the temporal behavior feature representation.

[0012] Furthermore, the step of processing the temporal behavior feature representation by the preset predictor corresponding to each of the preset indicators to obtain the predicted state representation vector under each of the preset indicators includes: for each of the preset indicators, based on the temporal behavior feature representation and the prediction weight parameter value and the prediction bias parameter value of the preset predictor corresponding to the preset indicator, using the preset predictor to determine the probability distribution under the preset indicator; and representing the probability distribution as the predicted state representation vector under the preset indicator.

[0013] Furthermore, the step of determining the anomaly score of the target system based on the weight values ​​and alarm values ​​of all the preset indicators, the real state representation vectors and the predicted state representation vectors of all the time series behaviors under each of the preset indicators includes: determining the weight value and the alarm value of each of the preset indicators, and determining a preset temperature parameter value; based on the preset temperature parameter value, all the weight values, all the alarm values, all the real state representation vectors and all the predicted state representation vectors, using a preset scoring formula to determine the anomaly score of the target system.

[0014] According to another aspect of an embodiment of the present application, a device for detecting anomalies of time series behaviors is also provided, comprising: a first determining unit for collecting current behavior data and current state data of a target system, and determining a true state representation vector of each time series behavior in a time series behavior set under each preset indicator based on the current behavior data and the current state data; a second determining unit for determining a behavior feature value of each of the time series behaviors based on the current behavior data; an input unit for inputting the behavior feature value into a preset prediction model for each of the time series behaviors, and outputting a predicted state representation vector of the time series behavior under each of the preset indicators, wherein the predicted Assume that the prediction model includes: an attention module and multiple preset predictors, the behavior feature value is processed by the attention module to obtain a temporal behavior feature representation, and the temporal behavior feature representation is processed by the preset predictor corresponding to each of the preset indicators to obtain the predicted state representation vector under each of the preset indicators; a third determination unit is used to determine the anomaly score of the target system based on the weight values ​​and alarm values ​​of all the preset indicators, the real state representation vector of all the temporal behaviors under each of the preset indicators, and the predicted state representation vector, and determine that the target system is in an abnormal state when the anomaly score is greater than a preset anomaly threshold.

[0015] Furthermore, the first determination unit includes: a first determination module, used to determine the time series behavior set based on the business requirements of the business executed by the target system, wherein each time series behavior in the time series behavior set corresponds to a time sequence; a second determination module, used to determine the preset indicator set based on the business requirements, wherein the preset indicator set includes: multiple preset indicators; a third determination module, used to determine the current behavior sub-data and current state sub-data involved in each time series behavior based on the current behavior data and the current state data; a fourth determination module, used to determine, for each time series behavior, the real state representation vector of the time series behavior under each preset indicator based on the current behavior sub-data and the current state sub-data involved in the time series behavior.

[0016] Furthermore, the anomaly detection device also includes: a first judgment module, which is used to determine whether each behavior characteristic value is a continuous value after determining the behavior characteristic value of each time series behavior based on the current behavior data; a first processing module, which is used to perform discrete processing on the continuous value when the behavior characteristic value is a continuous value to obtain the behavior characteristic value after discrete processing.

[0017] Furthermore, the anomaly detection device also includes: a first construction module, which is used to construct an initial prediction model before inputting the behavior feature value into the preset prediction model and outputting the predicted state representation vector of the time series behavior under each of the preset indicators, wherein the initial prediction model includes: an initial attention module and multiple initial preset predictors, each of the initial preset predictors corresponds to one of the preset indicators; a first acquisition module, which is used to collect historical behavior data and historical state data of the target system within a historical time period; a fifth determination module, which is used to determine the historical behavior feature value set of each of the time series behaviors based on the historical behavior data, and determine the historical state representation vector of each of the time series behaviors under each of the preset indicators based on the historical behavior data and the historical state data; a first characterization module, which is used to characterize the historical behavior feature value set and all the historical state representation vectors as training data; a first training module, which is used to adopt the The initial prediction model is trained using the training data until the cross-entropy loss value is less than a preset loss threshold, and the parameter value of each preset parameter in the preset parameter set is obtained, wherein the cross-entropy loss value is calculated based on the initial state representation vector and the historical state representation vector using a preset loss function, the initial state representation vector is a state representation vector output by the initial prediction model, and the preset parameter set includes at least: a first parameter set in the initial attention module, a prompt parameter, and a second parameter set in each of the initial preset predictors, the first parameter set includes at least: a feature embedding weight parameter, a feature embedding bias parameter, a position embedding weight parameter, a position embedding bias parameter, and each decoder layer parameter, the second parameter set includes at least: a prediction weight parameter, a prediction bias parameter; a first adjustment module is used to adjust the initial prediction model based on the parameter values ​​of all the preset parameters to obtain the trained preset prediction model.

[0018] Furthermore, the input unit includes: a sixth determination module, for determining, for each of the temporal behaviors, the feature coding of the temporal behavior based on the behavior feature value, and determining the position coding of the temporal behavior based on the time sequence of the temporal behavior; a seventh determination module, for determining a first vector representation based on the feature coding, the feature embedding weight parameter value of the feature embedding layer in the attention module, and the feature embedding bias parameter value, and determining a second vector representation based on the position coding, the position embedding weight parameter value of the position embedding layer in the attention module, and the position embedding bias parameter value; a first splicing module, for splicing the first vector representation and the second vector representation to obtain a feature vector representation; a second splicing module, for splicing the feature vector representation and the prompt vector representation of the prompt parameter to obtain a preset vector representation; a second processing module, for processing the preset vector representation through each decoder layer in the attention module to obtain the feature representation of the temporal behavior.

[0019] Furthermore, the input unit also includes: an eighth determination module, which is used to determine the probability distribution under the preset indicator using the preset predictor based on the temporal behavior feature representation and the prediction weight parameter value and prediction bias parameter value of the preset predictor corresponding to the preset indicator for each of the preset indicators; and a second characterization module, which is used to characterize the probability distribution as the prediction state representation vector under the preset indicator.

[0020] Furthermore, the third determination unit includes: a ninth determination module, used to determine the weight value and the alarm value of each of the preset indicators, and determine a preset temperature parameter value; a tenth determination module, used to determine the abnormality score of the target system based on the preset temperature parameter value, all the weight values, all the alarm values, all the real state representation vectors, and all the predicted state representation vectors using a preset scoring formula.

[0021] According to another aspect of an embodiment of the present application, a computer-readable storage medium is also provided, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute any of the above-mentioned methods for detecting anomalies in timing behaviors.

[0022] According to another aspect of an embodiment of the present application, an electronic device is also provided, comprising one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement any of the above-mentioned methods for detecting anomalies in timing behaviors.

[0023] In the present application, the current behavior data and current state data of the target system are collected, and based on the current behavior data and current state data, the real state representation vector of each time series behavior in the time series behavior set under each preset indicator is determined, and based on the current behavior data, the behavior feature value of each time series behavior is determined. For each time series behavior, the behavior feature value is input into a preset prediction model, and the predicted state representation vector of the time series behavior under each preset indicator is output. Based on the weight values ​​and alarm values ​​of all preset indicators, the real state representation vectors and predicted state representation vectors of all time series behaviors under each preset indicator, the anomaly score of the target system is determined, and when the anomaly score is greater than the preset anomaly threshold, it is determined that the target system is in an abnormal state. In the present application, the real state representation vector of each time series behavior under each preset indicator can be determined based on the collected current behavior data and current state data of the target system, and the behavior feature value of each time series behavior can be determined based on the current behavior data. The behavior feature value is then input into the preset prediction model to obtain the predicted state representation vector of the corresponding time series behavior under each preset indicator. Thereafter, the anomaly score of the target system is calculated based on the weight values ​​and alarm values ​​of all preset indicators, the real state representation vectors and the predicted state representation vectors of all time series behaviors under each preset indicator. If the anomaly score is greater than the preset anomaly threshold, it is determined that the target system is in an abnormal state, which can improve the efficiency and accuracy of anomaly detection of time series behaviors, thereby solving the technical problem of low accuracy of anomaly detection of time series behaviors in related technologies. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0025] FIG1 is a flow chart of an optional method for detecting anomalies in time series behavior according to an embodiment of the present application;

[0026] FIG2 is a schematic diagram of an optional model training process according to an embodiment of the present application;

[0027] FIG3 is a schematic diagram of an optional loss calculation process according to an embodiment of the present application;

[0028] FIG4 is a schematic diagram of an optional unsupervised multi-objective system time series anomaly detection process according to an embodiment of the present application;

[0029] FIG5 is a schematic diagram of an optional device for detecting abnormalities in time sequence behavior according to an embodiment of the present application;

[0030] FIG6 is a hardware structure block diagram of an electronic device (or mobile device) for a method for detecting anomalies in time sequence behavior according to an embodiment of the present application. DETAILED DESCRIPTION

[0031] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.

[0032] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0033] To facilitate those skilled in the art to understand the present application, some of the terms or nouns involved in the embodiments of the present application are explained below:

[0034] Transformer (self-attention model): A model that uses the self-attention mechanism and can be divided into an encoder and a decoder.

[0035] Prompt: In natural language processing, aligning the downstream task's objectives with pre-training objectives improves model accuracy. Therefore, downstream tasks introduce textual prompts to restructure the original task objectives and align them with pre-training tasks.

[0036] Prompt tuning: A prompt-based tuning strategy that adds a small number of parameters to a pre-trained model to improve the model's accuracy on downstream tasks.

[0037] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant regions, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0038] This application proposes a method and automated device for detecting time series anomalies in a multi-target system based on unsupervised learning. The device is divided into a multi-target model module and an anomaly assessment module. The multi-target model module uses a unidirectional self-attention model as the main model. Compared with the LSTM (Long Short-Term Memory) model in the related art, it can more effectively model time series features. In terms of model architecture, in order to avoid the deviation of manually describing the initial state of the system, an additional prompt vector is introduced, which can be implicitly used for the feature representation of the system state. In addition, a multi-target predictor is applied to the prediction of multiple key indicators of the system state, and multiple indicators are used together for system anomaly detection. In order to solve the problem of unbalanced distribution of abnormal data and normal data, the model adopts an unsupervised training method, uses large-scale normal data to pre-train the model, and predicts the system state generated by behavior. In the anomaly assessment module, a multi-target weighted scoring formula is proposed, which can take into account the importance of different targets and target warning line information. The anomaly score is calculated based on the target state output by the multi-target predictor and the actual target state through the scoring formula, and then the system anomaly is evaluated based on the set threshold.

[0039] The present application will be described in detail below with reference to various embodiments.

[0040] Example 1

[0041] According to an embodiment of the present application, an embodiment of a method for detecting anomalies in timing behavior is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0042] FIG1 is a flow chart of an optional method for detecting anomalies in time series behavior according to an embodiment of the present application. As shown in FIG1 , the method includes the following steps:

[0043] Step S101 : collecting current behavior data and current state data of the target system, and determining the real state representation vector of each temporal behavior in the temporal behavior set under each preset indicator based on the current behavior data and current state data.

[0044] Step S102: determining a behavior feature value of each time series behavior based on the current behavior data.

[0045] Step S103: For each temporal behavior, the behavior feature value is input into the preset prediction model, and the prediction state representation vector of the temporal behavior under each preset indicator is output, wherein the preset prediction model includes: an attention module and multiple preset predictors, the behavior feature value is processed by the attention module to obtain the temporal behavior feature representation, and the temporal behavior feature representation is processed by the preset predictor corresponding to each preset indicator to obtain the prediction state representation vector under each preset indicator.

[0046] Step S104, based on the weight values ​​and alarm values ​​of all preset indicators, the real state representation vectors and predicted state representation vectors of all time series behaviors under each preset indicator, determine the anomaly score of the target system, and if the anomaly score is greater than the preset anomaly threshold, determine that the target system is in an abnormal state.

[0047] Through the above steps, the current behavior data and current state data of the target system can be collected, and based on the current behavior data and current state data, the true state representation vector of each time series behavior in the time series behavior set under each preset indicator can be determined. Based on the current behavior data, the behavior feature value of each time series behavior can be determined. For each time series behavior, the behavior feature value is input into the preset prediction model, and the predicted state representation vector of the time series behavior under each preset indicator is output. Based on the weight values ​​and alarm values ​​of all preset indicators, the true state representation vectors and predicted state representation vectors of all time series behaviors under each preset indicator, the anomaly score of the target system can be determined, and when the anomaly score is greater than the preset anomaly threshold, it is determined that the target system is in an abnormal state. In an embodiment of the present application, the real state representation vector of each time series behavior under each preset indicator can be determined based on the collected current behavior data and current state data of the target system, and the behavior feature value of each time series behavior can be determined based on the current behavior data. Then, the behavior feature value is input into the preset prediction model to obtain the predicted state representation vector of the corresponding time series behavior under each preset indicator. Thereafter, the anomaly score of the target system is calculated based on the weight values ​​and alarm values ​​of all preset indicators, the real state representation vectors of all time series behaviors under each preset indicator, and the predicted state representation vectors. If the anomaly score is greater than the preset anomaly threshold, it is determined that the target system is in an abnormal state, which can improve the efficiency and accuracy of anomaly detection of time series behaviors, thereby solving the technical problem of low accuracy of anomaly detection of time series behaviors in the related art.

[0048] The embodiments of the present application are described in detail below in combination with the above steps.

[0049] Step S101 : collecting current behavior data and current state data of the target system, and determining the real state representation vector of each temporal behavior in the temporal behavior set under each preset indicator based on the current behavior data and current state data.

[0050] Optionally, the step of determining the true state representation vector of each time series behavior in the time series behavior set under each preset indicator based on the current behavior data and the current state data includes: determining the time series behavior set based on the business requirements of the business executed by the target system, wherein each time series behavior in the time series behavior set corresponds to a time sequence; determining the preset indicator set based on the business requirements, wherein the preset indicator set includes: multiple preset indicators; determining the current behavior sub-data and current state sub-data involved in each time series behavior based on the current behavior data and the current state data; for each time series behavior, determining the true state representation vector of the time series behavior under each preset indicator based on the current behavior sub-data and current state sub-data involved in the time series behavior.

[0051] In an embodiment of the present application, the current behavior data (i.e., the behavior data of the current operation on the target system, such as query data, etc.) and the current state data (i.e., the state data of the target system after a certain behavior is executed, such as CPU (Central Processing Unit) data, GPU (Graphics Processing Unit) data, memory data, etc.) of the target system (i.e., the system to be detected) can be collected. Then, based on the current behavior data and the current state data, the real state representation vector of each time series behavior in the time series behavior set (i.e., the time series behavior (i.e., the behavior characteristics) pre-set according to the business needs of the target system (i.e., whether there is a database insert operation, whether there is a GPU usage operation, whether the service is turned on, etc.) under each preset indicator (i.e., the pre-set target indicator, such as GPU usage, GPU load, CPU usage, memory usage, disk remaining space ratio, etc.) can be determined in real time. Specifically, the time series behavior set (each time series behavior in the time series behavior set is for the time series behavior set) can be determined based on the business needs of the business executed by the target system (e.g., real-time query needs for the database, etc.). There should be a time sequence), and then according to business needs, determine the preset indicator set (the preset indicator set includes: multiple preset indicators), and then determine the current behavior sub-data and current state sub-data involved in each time series behavior based on the current behavior data and the current state data (that is, determine the behavior data generated after the time series behavior occurs and the state data that affects the system), and then determine the current behavior sub-data and current state sub-data involved in the time series behavior, and determine the real state representation vector of each time series behavior under each preset indicator (that is, according to the current state sub-data associated with the current behavior sub-data, determine the real state value of the system under each preset indicator after the time series behavior occurs, and then construct the real state value into a real state representation vector).

[0052] Step S102: determining a behavior feature value of each time series behavior based on the current behavior data.

[0053] In an embodiment of the present application, the behavioral data involved in each timing behavior can be analyzed to determine the behavioral characteristic value of each timing behavior (that is, based on the current behavioral data, the behavioral characteristic value of each timing behavior is determined), for example, there are database insertion operations, GPU usage operations, and the queried database tables are numbered from 1 to 100, etc.

[0054] Optionally, after determining the behavior characteristic value of each time series behavior based on the current behavior data, it also includes: judging whether each behavior characteristic value is a continuous value; if the behavior characteristic value is a continuous value, performing discrete processing on the continuous value to obtain the behavior characteristic value after discrete processing.

[0055] In an embodiment of the present application, for behavioral features whose characteristic values ​​are continuous values, directly using continuous values ​​may cause samples with similar characteristics to become unstable in model training due to small differences. Therefore, it is necessary to discretize the continuous values, that is, first determine whether each behavioral characteristic value is a continuous value. If the behavioral characteristic value is a continuous value, then the continuous value is discretized to obtain the behavioral characteristic value after discrete processing.

[0056] Optionally, before inputting the behavior feature value into the preset prediction model and outputting the predicted state representation vector of the time series behavior under each preset indicator, it also includes: constructing an initial prediction model, wherein the initial prediction model includes: an initial attention module and multiple initial preset predictors, each initial preset predictor corresponds to a preset indicator; collecting historical behavior data and historical state data of the target system in a historical time period; based on the historical behavior data, determining the historical behavior feature value set of each time series behavior, and based on the historical behavior data and the historical state data, determining the historical state representation vector of each time series behavior under each preset indicator; representing the historical behavior feature value set and all historical state representation vectors as training data; using the training data to train the initial prediction model until the cross entropy loss value is less than A preset loss threshold is set to obtain the parameter value of each preset parameter in the preset parameter set, wherein the cross entropy loss value is calculated based on the initial state representation vector and the historical state representation vector using a preset loss function, the initial state representation vector is the state representation vector output by the initial prediction model, the preset parameter set includes at least: a first parameter set in the initial attention module, a prompt parameter, and a second parameter set in each initial preset predictor, the first parameter set includes at least: feature embedding weight parameters, feature embedding bias parameters, position embedding weight parameters, position embedding bias parameters, and each decoder layer parameter, the second parameter set includes at least: prediction weight parameters, prediction bias parameters; based on the parameter values ​​of all preset parameters, the initial prediction model is adjusted to obtain the trained preset prediction model.

[0057] In an embodiment of the present application, a self-attention model architecture for multi-target prediction can be constructed (i.e., an initial prediction model is constructed), including: an encoding layer (e.g., a feature embedding layer, a position embedding layer, etc.), several Transformer decoder layers (the encoding layer and the decoder layer constitute an attention module), a multi-target predictor (i.e., an initial preset predictor) (i.e., an initial prediction model is constructed, the initial prediction model includes: an initial attention module and multiple initial preset predictors, and each initial preset predictor corresponds to a preset indicator (i.e., each initial preset predictor is used to predict the target state of the corresponding preset indicator)).

[0058] In an embodiment of the present application, since the initial state of the system is different when each behavior is executed, there is a deviation in describing the system state in the form of manual features. Therefore, a parameterized prompt vector (i.e., prompt parameter) can be used to implicitly represent the initial state of the system, so that it can be jointly trained during model pre-training to obtain a universal vector representation of the initial state of the system (i.e., prompt vector representation).

[0059] In an embodiment of the present application, it is necessary to train the initial prediction model to obtain the optimal parameter values ​​of the model parameters (i.e., preset parameters), thereby obtaining the preset prediction model. Specifically, the historical behavior data and historical state data of the target system in the historical time period can be first collected, and then the historical behavior feature value set of each time series behavior is determined based on the historical behavior data, and the historical state representation vector of each time series behavior under each preset indicator is determined based on the historical behavior data and the historical state data. Then, the historical behavior feature value set and all historical state representation vectors are represented as training data, and the initial prediction model is trained using the training data until the cross entropy loss value is less than the preset loss threshold, thereby obtaining the parameter value of each preset parameter in the preset parameter set, and then adjusting the initial prediction model based on the parameter values ​​of all preset parameters to obtain the trained preset prediction model, wherein the preset parameter set includes: the first parameter set in the initial attention module (the first parameter set includes: feature embedding weight parameter W f , feature embedding bias parameter b f , position embedding weight parameter W p , position embedding bias parameter b p and each decoder layer parameter θ l ), prompt parameter r l And the second parameter set in each initial preset predictor (the second parameter set includes: prediction weight parameter W f , prediction bias parameter b f ).

[0060] In the embodiment of the present application, the cross entropy loss value is calculated based on the initial state representation vector (the initial state representation vector is the state representation vector output by the initial prediction model) and the historical state representation vector using a preset loss function, that is, it is necessary to calculate the cross entropy loss between the state predicted by the model and the state of the actual system. Since it is a multi-target state prediction, the losses of multiple targets are summed together to calculate the loss. The specific formula is as follows:

[0061] Where T is the total number of predicted states (i.e., the total number of time-series behaviors), F is the number of predicted targets (i.e., the number of preset indicators), is the category of the fth predicted target in the system state generated by the actual tth behavior (i.e., the historical state representation vector), It is the probability distribution of the f-th predicted target in the system state generated by the predicted t-th behavior (i.e., the initial state representation vector). Finally, it is trained through the optimizer. During the gradient backpropagation process, the model parameters and prompt parameters are jointly trained.

[0062] In an embodiment of the present application, a portion of the training data can be separated as validation set data, and then it is determined whether the effect of the model on the validation set data reaches the set expected result. If so, the training is terminated and the optimal model is saved.

[0063] Figure 2 is a schematic diagram of an optional model training process according to an embodiment of the present application. As shown in Figure 2, behavior data and actual status can be obtained from the system, and then the behavior data can be input into the prediction model. The prediction model processes the behavior data through the embedding layer (i.e., the embedding layer, including: feature embedding layer (i.e., feature embedding layer) and position embedding layer (i.e., position embedding layer)) to obtain a feature vector representation, and then the feature vector representation is spliced ​​with the prompt vector representation (i.e., Prompt) to obtain a preset vector representation. The preset vector representation is then processed by multiple layers of Transformer Lay (i.e., decoder layer, for example, Transformer Lay1, Transformer Lay2, ..., Transformer LayN) to obtain a temporal behavior feature representation, and then the temporal behavior feature representation is input into the multi-target predictor for prediction to obtain a predicted state. Then, the cross-entropy loss value is calculated based on the predicted state and the actual state. After the cross-entropy loss value is less than the preset loss threshold, the training is determined to be completed.

[0064] FIG3 is a schematic diagram of an optional loss calculation process according to an embodiment of the present application. As shown in FIG3 , the temporal behavior feature of the t-th behavior output by the last decoder layer is represented as Input to the multi-objective predictor (e.g., GPU usage predictor, CPU usage predictor, memory usage predictor) for prediction to obtain the predicted status under multiple preset indicators (e.g., GPU usage, CPU usage, memory usage) (e.g., GPU usage corresponding to CPU usage corresponds to Memory usage corresponding to ), and then based on the predicted state and the corresponding actual state (for example, )Calculate the loss.

[0065] Step S103: For each temporal behavior, the behavior feature value is input into the preset prediction model, and the prediction state representation vector of the temporal behavior under each preset indicator is output, wherein the preset prediction model includes: an attention module and multiple preset predictors, the behavior feature value is processed by the attention module to obtain the temporal behavior feature representation, and the temporal behavior feature representation is processed by the preset predictor corresponding to each preset indicator to obtain the prediction state representation vector under each preset indicator.

[0066] In an embodiment of the present application, the behavioral feature value of each temporal behavior can be input into a multi-objective prediction model (i.e., a preset prediction model) in a temporal order (i.e., time order) to obtain a prediction state representation vector of the temporal behavior under each preset indicator (i.e., for each temporal behavior, the behavioral feature value is input into the preset prediction model, and the prediction state representation vector of the temporal behavior under each preset indicator is output). The preset prediction model includes: an attention module and multiple preset predictors, the attention module is used to process the behavioral feature value to obtain a temporal behavior feature representation, and the preset predictor corresponding to each preset indicator is used to process the temporal behavior feature representation to obtain a prediction state representation vector under each preset indicator.

[0067] Optionally, the step of processing the behavior feature value through the attention module to obtain the temporal behavior feature representation includes: for each temporal behavior, determining the feature coding of the temporal behavior based on the behavior feature value, and determining the position coding of the temporal behavior based on the time order of the temporal behavior; determining a first vector representation based on the feature coding, the feature embedding weight parameter value of the feature embedding layer in the attention module, and the feature embedding bias parameter value, and determining a second vector representation based on the position coding, the position embedding weight parameter value of the position embedding layer in the attention module, and the position embedding bias parameter value; concatenating the first vector representation and the second vector representation to obtain a feature vector representation; concatenating the feature vector representation and the prompt vector representation of the prompt parameter to obtain a preset vector representation; the preset vector representation is processed by each decoder layer in the attention module to obtain the temporal behavior feature representation.

[0068] In an embodiment of the present application, the original behavior data (i.e., the current behavior data collected) is subjected to feature engineering based on expert experience to obtain behavior feature values ​​corresponding to the behavior features (for example, whether there is a database insert operation, whether there is a GPU usage operation, whether the service is turned on, and other behavioral features). These behavior feature values ​​can be divided into category feature values ​​and continuous values. However, the representation of category feature values ​​is usually in the form of one-hot encoding. Direct input into the model will not only cause the feature vector to be too sparse, but also ignore the differences and correlations between feature values. For continuous values, if used directly, samples with similar features may cause model training to be unstable due to small differences. Therefore, it is necessary to discretize the continuous value features, and then apply a layer of feature embedding layer (i.e., feature embedding layer) and position embedding layer (i.e., position embedding layer) to process the behavior feature values ​​(including category feature values ​​and discretized continuous values). Specifically, according to the behavior feature values, first determine the feature encoding x of each time series behavior. f , and according to the time sequence of the temporal behavior, determine the position code x of the temporal behavior p , and then according to the feature encoding, the feature embedding weight parameter value W of the feature embedding layer in the attention module f And the feature embedding bias parameter value b f , determine the first vector representation h f , and according to the position encoding, the position embedding layer in the attention module position embedding weight parameter value W p And the position embedding bias parameter value b p , determine the second vector representation h p , then concatenate the first vector representation and the second vector representation to obtain the feature vector representation h. The specific formula is as follows: h f =W f *x f +b f ; h p =W p *x p +b p ; h=concat(h p ;h f );

[0069] Among them, x f is the feature encoding of the behavior after feature engineering, x p is the position code of the behavior in the behavior sequence, W f 、b f 、W p 、b p are the training parameters of the embedding layer (i.e., feature embedding weight parameter, feature embedding bias parameter, position embedding weight parameter, position embedding bias parameter), hf and h p They are the feature vector representations after the feature embedding layer and the position embedding layer (i.e., the first vector representation and the second vector representation), and finally h f and h p The feature vector representation h of the splicing composition behavior.

[0070] In the embodiment of the present application, considering that the model lacks any information about the initial state of the system, in order to avoid the errors caused by manually describing the initial state of the system, a prompt vector (i.e., prompt vector representation) is introduced to implicitly provide contextual information for the model. Before the behavioral feature representation is input into the model, a prompt vector representing the system state is spliced ​​(i.e., the feature vector representation and the prompt vector representation of the prompt parameter are spliced ​​to obtain a preset vector representation), and then input into the next layer of the model (i.e., the decoder layer). Therefore, the output of each layer of transformer (i.e., the decoder layer) can be simplified to the following formula (i.e., the preset vector representation is processed by each decoder layer in the attention module to obtain a temporal behavioral feature representation):

[0071] in, is the output of the t-th behavior in the sequence at layer l, r l is the prompt vector of the lth layer, θ l are the parameters of the lth layer (i.e., the decoder layer parameters). Due to the unidirectional self-attention model architecture, the output of the tth behavior can only depend on the output results of the previous t-1 behaviors.

[0072] Optionally, the step of processing the temporal behavior feature representation by the preset predictor corresponding to each preset indicator to obtain the prediction state representation vector under each preset indicator includes: for each preset indicator, based on the temporal behavior feature representation and the prediction weight parameter value and the prediction bias parameter value of the preset predictor corresponding to the preset indicator, using the preset predictor to determine the probability distribution under the preset indicator; and representing the probability distribution as the prediction state representation vector under the preset indicator.

[0073] In the embodiment of the present application, the feature representation of the last layer of transformer (i.e., the time series behavior feature representation) ) is output to the multi-target state predictor (i.e., preset predictor). Since it is difficult to judge whether a system has an abnormality by a single indicator, for example, when the power usage of the system GPU is very high, it may not be an abnormality, but if the GPU usage is found to be very low at the same time, then it is very likely that the system has an abnormality. Therefore, a multi-target state prediction is proposed, and multiple indicators are used to evaluate whether the system has an abnormality. In the system monitoring scenario, some target indicators that need to be predicted (i.e., preset indicators) include: GPU usage at the next moment, GPU load, CPU usage, memory usage, disk remaining space ratio, etc. For any one of the prediction targets, it can be formulated as (i.e., for each preset indicator, the prediction weight parameter value W of the preset predictor based on the temporal behavior feature representation and the preset indicator corresponding to the preset indicator f , predict the bias parameter value b f , use the preset predictor to determine the probability distribution under the preset indicator And the probability distribution is represented as a prediction state representation vector under the preset indicators):

[0074] in, It is the feature representation of the t-th behavior output by the last layer of transformer. is the probability distribution of the fth predicted target of the predicted tth state, W f and b f Represents the parameters of the predictor (i.e., prediction weight parameters, prediction bias parameters).

[0075] Step S104: Based on the weight values ​​and alarm values ​​of all preset indicators, the real state representation vectors and predicted state representation vectors of all time series behaviors under each preset indicator, determine the anomaly score of the target system, and if the anomaly score is greater than the preset anomaly threshold, determine that the target system is in an abnormal state.

[0076] Optionally, the step of determining the anomaly score of the target system based on the weight values ​​and alarm values ​​of all preset indicators, the real state representation vectors and predicted state representation vectors of all time series behaviors under each preset indicator includes: determining the weight value and alarm value of each preset indicator, and determining a preset temperature parameter value; based on the preset temperature parameter value, all weight values, all alarm values, all real state representation vectors and all predicted state representation vectors, using a preset scoring formula to determine the anomaly score of the target system.

[0077] In an embodiment of the present application, an anomaly score of the target system can be calculated by an anomaly assessment module. If the anomaly score is greater than a preset anomaly threshold (which can be set according to actual conditions), it is determined that the target system is in an abnormal state.

[0078] In the embodiment of the present application, a multi-objective weighted scoring formula (i.e., a preset scoring formula) is proposed for calculating the anomaly score. Since after an anomaly occurs in the system, the anomalies of the various targets of the system are different, and the importance of each target is also different, in order to better measure the gap between the model prediction state and the actual state and to determine whether an anomaly has occurred, the floating ratio of the difference value generated by the reconstruction of different features in the system can be pre-evaluated, and combined with the alarm lines set for different targets, a multi-objective weighted scoring formula is constructed to calculate the anomaly score to determine whether an anomaly has occurred in the system. The multi-objective weighted scoring formula is as follows (i.e., determining the weight value β of each preset indicator f And the alarm value is up f , and determine the preset temperature parameter value τ, and then use the preset scoring formula to determine the abnormality score of the target system based on the preset temperature parameter value, all weight values, all alarm values, all true state representation vectors, and all predicted state representation vectors):

[0079] in, Used to judge the gap between the model prediction state and the actual state. If the system is abnormal, there will be a deviation between the target state predicted by the model and the actual target state; β f It is used to adjust the weight of the importance of different indicators and to measure the differences between different indicators; the coefficient It is used to measure whether the actual target state exceeds the manually set alarm line, where up f Indicates the warning line of the fth indicator, τ is the temperature parameter used to scale the coefficient. If the actual state is lower than the warning line, it means that the anomaly score should not be high. If it is higher than the warning line, it means that the model needs to improve the anomaly score. Since the model parameters are trained based on a large amount of normal behavior data, if an anomaly occurs in the system, the calculated score (i.e., anomaly score) is often large. Therefore, you can set the threshold (i.e. preset abnormal threshold) to divide normal data and abnormal data. If This means that an abnormality has occurred in the behavioral system, otherwise the system has not.

[0080] The following describes in detail another optional specific implementation.

[0081] FIG4 is a schematic diagram of an optional unsupervised multi-objective system time series anomaly detection process according to an embodiment of the present application. As shown in FIG4 , the process includes the following steps:

[0082] (1) Collect a large amount of behavioral data within the system and the corresponding status data of the system.

[0083] (2) Construct features of behavioral data and construct features that describe system states.

[0084] (3) Construct a multi-target prediction model, which is mainly composed of a coding layer, several decoder layers, and a stack of multi-target predictors.

[0085] (4) A parameterized prompt vector is used to implicitly represent the initial state of the system.

[0086] (5) Train multi-objective prediction model.

[0087] (6) The model performance on the validation set to obtain the optimal model.

[0088] (7) Calculate the anomaly score through the anomaly assessment module.

[0089] (8) Deploy multi-objective prediction models and anomaly assessment modules for inference.

[0090] In the embodiment of the present application, in view of the fact that the time series anomaly detection method based on rule matching in the related art is highly dependent on expert experience in system monitoring scenarios and the time series anomaly detection method in the machine learning algorithm is generally unable to effectively solve the problems of difficulty in obtaining labeled data and data imbalance in system time series anomaly detection scenarios, an unsupervised multi-target system time series anomaly detection method is proposed. A self-attention model for multi-target prediction is introduced into the multi-target prediction model, and a prompt vector is introduced to implicitly represent the initial state of the system, which is spliced ​​with the vector representation of the input data. The mapping relationship between behavior data and system response state is learned through the model. Since only normal samples are required for training during the training process, the problem of extremely unbalanced distribution of abnormal data and normal data in the anomaly detection field is avoided, thereby improving the efficiency of system time series anomaly detection. In addition, a multi-target weighted scoring formula is proposed in the anomaly evaluation module, which can consider the importance of different target indicators and the warning line information of the target indicators. The anomaly score is calculated based on the target state output by the multi-target predictor and the actual target state through the scoring formula, and whether an anomaly has occurred is determined by a set threshold.

[0091] The following describes it in detail with reference to another embodiment.

[0092] Example 2

[0093] The device for detecting anomalies in time series behavior provided in this embodiment includes a plurality of implementation units, each of which corresponds to an implementation step in the first embodiment.

[0094] FIG5 is a schematic diagram of an optional device for detecting anomalies of time series behavior according to an embodiment of the present application. As shown in FIG5 , the device may include: a first determining unit 50, a second determining unit 51, an input unit 52, and a third determining unit 53, wherein:

[0095] A first determining unit 50 is configured to collect current behavior data and current state data of the target system, and determine a true state representation vector of each time series behavior in the time series behavior set under each preset indicator based on the current behavior data and current state data;

[0096] A second determining unit 51 is configured to determine a behavior feature value of each time series behavior based on current behavior data;

[0097] An input unit 52 is configured to input the behavior feature value of each time series behavior into a preset prediction model, and output a predicted state representation vector of the time series behavior under each preset indicator, wherein the preset prediction model includes an attention module and multiple preset predictors, the behavior feature value is processed by the attention module to obtain a time series behavior feature representation, and the time series behavior feature representation is processed by the preset predictor corresponding to each preset indicator to obtain a predicted state representation vector under each preset indicator;

[0098] The third determination unit 53 is used to determine the anomaly score of the target system based on the weight values ​​and alarm values ​​of all preset indicators, the real state representation vectors of all time series behaviors under each preset indicator, and the predicted state representation vectors, and determine that the target system is in an abnormal state when the anomaly score is greater than the preset anomaly threshold.

[0099] The above-mentioned anomaly detection device can collect the current behavior data and current state data of the target system through the first determination unit 50, and determine the real state representation vector of each time series behavior in the time series behavior set under each preset indicator based on the current behavior data and the current state data, determine the behavior feature value of each time series behavior based on the current behavior data through the second determination unit 51, input the behavior feature value into the preset prediction model for each time series behavior through the input unit 52, and output the predicted state representation vector of the time series behavior under each preset indicator, determine the anomaly score of the target system based on the weight values ​​and alarm values ​​of all preset indicators, the real state representation vectors of all time series behaviors under each preset indicator, and the predicted state representation vector, through the third determination unit 53, and determine that the target system is in an abnormal state when the anomaly score is greater than the preset anomaly threshold. In an embodiment of the present application, the real state representation vector of each time series behavior under each preset indicator can be determined based on the collected current behavior data and current state data of the target system, and the behavior feature value of each time series behavior can be determined based on the current behavior data. Then, the behavior feature value is input into the preset prediction model to obtain the predicted state representation vector of the corresponding time series behavior under each preset indicator. Thereafter, the anomaly score of the target system is calculated based on the weight values ​​and alarm values ​​of all preset indicators, the real state representation vectors of all time series behaviors under each preset indicator, and the predicted state representation vectors. If the anomaly score is greater than the preset anomaly threshold, it is determined that the target system is in an abnormal state, which can improve the efficiency and accuracy of anomaly detection of time series behaviors, thereby solving the technical problem of low accuracy of anomaly detection of time series behaviors in related technologies.

[0100] Optionally, the first determination unit includes: a first determination module, used to determine a set of time series behaviors based on the business requirements of the business executed by the target system, wherein each time series behavior in the time series behavior set corresponds to a time sequence; a second determination module, used to determine a set of preset indicators based on business requirements, wherein the preset indicator set includes: multiple preset indicators; a third determination module, used to determine the current behavior sub-data and current state sub-data involved in each time series behavior based on the current behavior data and the current state data; a fourth determination module, used to determine, for each time series behavior, the real state representation vector of the time series behavior under each preset indicator based on the current behavior sub-data and the current state sub-data involved in the time series behavior.

[0101] Optionally, the anomaly detection device also includes: a first judgment module, used to determine whether each behavior characteristic value is a continuous value after determining the behavior characteristic value of each time series behavior based on the current behavior data; a first processing module, used to perform discrete processing on the continuous value when the behavior characteristic value is a continuous value, to obtain the behavior characteristic value after discrete processing.

[0102] Optionally, the anomaly detection device further includes: a first construction module for constructing an initial prediction model before inputting the behavior feature value into the preset prediction model and outputting the predicted state representation vector of the time series behavior under each preset indicator, wherein the initial prediction model includes: an initial attention module and a plurality of initial preset predictors, each initial preset predictor corresponding to a preset indicator; a first acquisition module for collecting historical behavior data and historical state data of the target system within a historical time period; a fifth determination module for determining a set of historical behavior feature values ​​of each time series behavior based on the historical behavior data, and determining a historical state representation vector of each time series behavior under each preset indicator based on the historical behavior data and the historical state data; a first characterization module for representing the set of historical behavior feature values ​​and all historical state representation vectors as training data; a first training module for adopting training The initial prediction model is trained with data until the cross-entropy loss value is less than a preset loss threshold, and the parameter value of each preset parameter in the preset parameter set is obtained, wherein the cross-entropy loss value is calculated based on the initial state representation vector and the historical state representation vector using a preset loss function, the initial state representation vector is a state representation vector output by the initial prediction model, the preset parameter set includes at least: a first parameter set in the initial attention module, a prompt parameter, and a second parameter set in each initial preset predictor, the first parameter set includes at least: a feature embedding weight parameter, a feature embedding bias parameter, a position embedding weight parameter, a position embedding bias parameter, and each decoder layer parameter, the second parameter set includes at least: a prediction weight parameter, a prediction bias parameter; a first adjustment module is used to adjust the initial prediction model based on the parameter values ​​of all preset parameters to obtain a trained preset prediction model.

[0103] Optionally, the input unit includes: a sixth determination module, used to determine the feature coding of the temporal behavior based on the behavior feature value for each temporal behavior, and to determine the position coding of the temporal behavior based on the time sequence of the temporal behavior; a seventh determination module, used to determine the first vector representation based on the feature coding, the feature embedding weight parameter value of the feature embedding layer in the attention module, and the feature embedding bias parameter value, and to determine the second vector representation based on the position coding, the position embedding weight parameter value of the position embedding layer in the attention module, and the position embedding bias parameter value; a first splicing module, used to splice the first vector representation and the second vector representation to obtain a feature vector representation; a second splicing module, used to splice the feature vector representation and the prompt vector representation of the prompt parameter to obtain a preset vector representation; a second processing module, used to process the preset vector representation through each decoder layer in the attention module to obtain a temporal behavior feature representation.

[0104] Optionally, the input unit also includes: an eighth determination module, which is used to determine the probability distribution under the preset indicator using the preset predictor based on the temporal behavior feature representation and the prediction weight parameter value and prediction bias parameter value of the preset predictor corresponding to the preset indicator for each preset indicator; and a second characterization module, which is used to characterize the probability distribution as a prediction state representation vector under the preset indicator.

[0105] Optionally, the third determination unit includes: a ninth determination module, used to determine the weight value and alarm value of each preset indicator, and determine the preset temperature parameter value; a tenth determination module, used to determine the abnormality score of the target system based on the preset temperature parameter value, all weight values, all alarm values, all real state representation vectors and all predicted state representation vectors using a preset scoring formula.

[0106] The above-mentioned abnormality detection device may also include a processor and a memory. The above-mentioned first determination unit 50, second determination unit 51, input unit 52, third determination unit 53, etc. are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to realize the corresponding functions.

[0107] The processor includes a kernel that retrieves corresponding program units from memory. One or more kernels can be configured to determine an anomaly score for the target system based on the weights and alarm values ​​of all preset indicators, the actual state representation vectors for all time series behaviors under each preset indicator, and the predicted state representation vectors by adjusting kernel parameters. If the anomaly score exceeds a preset anomaly threshold, the target system is determined to be in an abnormal state.

[0108] The above-mentioned memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0109] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program initialized with the following method steps: collecting current behavior data and current state data of the target system, and determining the true state representation vector of each time series behavior in the time series behavior set under each preset indicator based on the current behavior data and the current state data, determining the behavior feature value of each time series behavior based on the current behavior data, for each time series behavior, inputting the behavior feature value into a preset prediction model, outputting the predicted state representation vector of the time series behavior under each preset indicator, determining the anomaly score of the target system based on the weight values ​​and alarm values ​​of all preset indicators, the true state representation vectors of all time series behaviors under each preset indicator, and the predicted state representation vectors, and determining that the target system is in an abnormal state when the anomaly score is greater than a preset anomaly threshold.

[0110] According to another aspect of an embodiment of the present application, a computer-readable storage medium is also provided, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the above-mentioned method for detecting anomalies in timing behavior.

[0111] According to another aspect of an embodiment of the present application, an electronic device is also provided, comprising one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by one or more processors, the one or more processors implement the above-mentioned method for detecting anomalies in timing behavior.

[0112] Figure 6 is a hardware structure block diagram of an electronic device (or mobile device) for a method for detecting anomalies in timing behavior according to an embodiment of the present application. As shown in Figure 6, the electronic device may include one or more (602a, 602b, ..., 602n are used in Figure 6 to illustrate) processors 602 (the processor 602 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), and a memory 604 for storing data. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, a keyboard, a power supply and / or a camera. It will be understood by those skilled in the art that the structure shown in Figure 6 is only for illustration and does not limit the structure of the above-mentioned electronic device. For example, the electronic device may also include more or fewer components than those shown in Figure 6, or have a configuration different from that shown in Figure 6.

[0113] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0114] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.

[0115] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0116] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0117] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0118] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0119] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A method for detecting anomalies of time series behavior, comprising: Collecting current behavior data and current state data of the target system, and determining a real state representation vector of each time series behavior in the time series behavior set under each preset indicator based on the current behavior data and the current state data; Based on the current behavior data, determining a behavior characteristic value of each of the time series behaviors; For each of the temporal behaviors, the behavior feature value is input into a preset prediction model, and a predicted state representation vector of the temporal behavior under each of the preset indicators is output, wherein the preset prediction model includes: an attention module and a plurality of preset predictors, the behavior feature value is processed by the attention module to obtain a temporal behavior feature representation, and the temporal behavior feature representation is processed by the preset predictor corresponding to each of the preset indicators to obtain the predicted state representation vector under each of the preset indicators; Based on the weight values ​​and alarm values ​​of all the preset indicators, the real state representation vector of all the time series behaviors under each of the preset indicators, and the predicted state representation vector, the anomaly score of the target system is determined, and when the anomaly score is greater than a preset anomaly threshold, it is determined that the target system is in an abnormal state.

2. The abnormality detection method according to claim 1, wherein: The step of determining a real state representation vector of each time series behavior in the time series behavior set under each preset indicator based on the current behavior data and the current state data comprises: Determine the set of timing behaviors based on the business requirements of the business executed by the target system, wherein each of the timing behaviors in the set of timing behaviors corresponds to a time sequence; Based on the business requirements, a preset indicator set is determined, wherein the preset indicator set includes: a plurality of the preset indicators; Based on the current behavior data and the current state data, determining the current behavior sub-data and the current state sub-data involved in each of the time series behaviors; For each of the time series behaviors, based on the current behavior sub-data and the current state sub-data involved in the time series behavior, the real state representation vector of the time series behavior under each of the preset indicators is determined.

3. The abnormality detection method according to claim 1, wherein: After determining the behavior feature value of each of the time series behaviors based on the current behavior data, the method further includes: Determining whether each of the behavior characteristic values ​​is a continuous value; In the case where the behavior feature value is a continuous value, the continuous value is discretized to obtain the behavior feature value after discretization.

4. The abnormality detection method according to claim 1, wherein: Before inputting the behavior feature value into a preset prediction model and outputting a prediction state representation vector of the time series behavior under each preset indicator, the method further includes: Constructing an initial prediction model, wherein the initial prediction model includes: an initial attention module and a plurality of initial preset predictors, each of the initial preset predictors corresponding to one of the preset indicators; Collect historical behavior data and historical status data of the target system within a historical time period; Based on the historical behavior data, determine a set of historical behavior feature values ​​of each of the time series behaviors, and based on the historical behavior data and the historical state data, determine a historical state representation vector of each of the time series behaviors under each of the preset indicators; Characterizing the historical behavior feature value set and all the historical state representation vectors as training data; The initial prediction model is trained using the training data until the cross entropy loss value is less than a preset loss threshold, and the parameter value of each preset parameter in the preset parameter set is obtained, wherein the cross entropy loss value is calculated based on the initial state representation vector and the historical state representation vector using a preset loss function, the initial state representation vector is a state representation vector output by the initial prediction model, the preset parameter set includes at least: a first parameter set in the initial attention module, a prompt parameter, and a second parameter set in each of the initial preset predictors, the first parameter set includes at least: a feature embedding weight parameter, a feature embedding bias parameter, a position embedding weight parameter, a position embedding bias parameter, and each decoder layer parameter, the second parameter set includes at least: a prediction weight parameter, a prediction bias parameter; Based on the parameter values ​​of all the preset parameters, the initial prediction model is adjusted to obtain the trained preset prediction model.

5. The abnormality detection method according to claim 1, wherein: The step of processing the behavior feature value by the attention module to obtain a temporal behavior feature representation comprises: For each of the time series behaviors, determining a feature code of the time series behavior based on the behavior feature value, and determining a position code of the time series behavior based on the time sequence of the time series behavior; Determine a first vector representation based on the feature encoding, a feature embedding weight parameter value of a feature embedding layer in the attention module, and a feature embedding bias parameter value, and determine a second vector representation based on the position encoding, a position embedding weight parameter value of a position embedding layer in the attention module, and a position embedding bias parameter value; Concatenating the first vector representation and the second vector representation to obtain a feature vector representation; splicing the feature vector representation and the prompt vector representation of the prompt parameter to obtain a preset vector representation; The preset vector representation is processed by each decoder layer in the attention module to obtain the temporal behavior feature representation.

6. The abnormality detection method according to claim 1, wherein: The step of processing the temporal behavior feature representation by the preset predictor corresponding to each of the preset indicators to obtain the predicted state representation vector under each of the preset indicators comprises: For each of the preset indicators, based on the temporal behavior feature representation and the prediction weight parameter value and the prediction bias parameter value of the preset predictor corresponding to the preset indicator, the preset predictor is used to determine the probability distribution under the preset indicator; The probability distribution is represented as the predicted state representation vector under the preset indicator.

7. The abnormality detection method according to claim 1, wherein: The step of determining the abnormality score of the target system based on the weight values ​​and alarm values ​​of all the preset indicators, the real state representation vector of all the time series behaviors under each of the preset indicators, and the predicted state representation vector comprises: Determine the weight value and the alarm value of each of the preset indicators, and determine a preset temperature parameter value; Based on the preset temperature parameter value, all the weight values, all the alarm values, all the real state representation vectors, and all the predicted state representation vectors, a preset scoring formula is used to determine the abnormality score of the target system.

8. A device for detecting abnormality of a time series behavior, comprising: A first determination unit is used to collect current behavior data and current state data of the target system, and determine a real state representation vector of each time series behavior in the time series behavior set under each preset indicator based on the current behavior data and the current state data; A second determining unit, configured to determine a behavior characteristic value of each of the time series behaviors based on the current behavior data; An input unit is used to input the behavior feature value into a preset prediction model for each of the temporal behaviors, and output a predicted state representation vector of the temporal behavior under each of the preset indicators, wherein the preset prediction model includes: an attention module and a plurality of preset predictors, the behavior feature value is processed by the attention module to obtain a temporal behavior feature representation, and the temporal behavior feature representation is processed by the preset predictor corresponding to each of the preset indicators to obtain the predicted state representation vector under each of the preset indicators; The third determination unit is used to determine the anomaly score of the target system based on the weight values ​​and alarm values ​​of all the preset indicators, the real state representation vector of all the time series behaviors under each of the preset indicators, and the predicted state representation vector, and determine that the target system is in an abnormal state when the anomaly score is greater than a preset anomaly threshold.

9. A computer-readable storage medium, wherein: The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute the method for detecting anomalies in timing behaviors as described in any one of claims 1 to 7.

10. An electronic device comprising one or more processors and a memory, wherein the memory is used to store one or more programs, wherein: When the one or more programs are executed by the one or more processors, the one or more processors implement the method for detecting abnormalities in timing behaviors as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Business index abnormity detection method and device, electronic equipment and storage medium

    CN113822366A

  • Microservice system anomaly detection method and device based on multi-index time sequence prediction

    CN116383096A

  • Time sequence behavior anomaly detection method and device, electronic equipment and storage medium

    CN117688445A

  • Method for incident detection in a time-evolving system

    US20180075362A1

Cited By

  • Bank intelligent authorization method, system and device based on shared operation system and medium

    CN120338937A

  • Industrial computer data processing method and device

    CN120875483A

  • Driver on-duty state early warning system based on deep learning

    CN120986420A

  • Industrial production energy consumption anomaly detection method and device

    CN121093224A

  • Temperature prediction method, state detection method, related equipment and medium

    CN121188378A