Anomaly Detection Model Segmentation for Immediate System Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anomaly detection systems require a system to be in a normal state when preparing a model, making it impossible to monitor systems that may not be operating normally initially.
Innovation Solution
An information processing apparatus that acquires and classifies events from both standard and target systems, using two models to determine if events are normal or anomalous, allowing monitoring to start even if the target system is not initially in a normal state.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a model is prepared by learning normal operation data, then anomaly detection accuracy is improved, but the system cannot start monitoring until it is confirmed to be in a normal state
Solution Approach 1:
The patent segments the learning process into two distinct phases: a first learning process that creates an initial model using only standard apparatus data, and a second learning process that refines the model using target apparatus data. This segmentation allows the system to start monitoring immediately with the first model while progressively improving accuracy through the second learning process, thereby resolving the contradiction between starting time and detection accuracy.
Solution Approach 2:
The patent performs preliminary action by pre-learning the normal operation patterns of the standard apparatus before deploying monitoring to the target apparatus. This preliminary learning creates a baseline model that enables immediate monitoring startup, and subsequent learning continuously improves the model using actual target apparatus data, thus eliminating the waiting period while maintaining accuracy improvement.
2Productivity
If monitoring starts without knowing the normal operation state, then monitoring can begin immediately, but anomaly detection accuracy deteriorates
Solution Approach 1:
The patent implements a dynamic learning approach where the model evolves from a static pre-learned state to an adaptive state that continuously improves. The first learning process establishes initial dynamics based on standard apparatus, while the second learning process adapts the model to target apparatus characteristics over time, enabling both immediate startup and progressive accuracy improvement.
Solution Approach 2:
The patent incorporates feedback mechanisms where the monitoring system continuously collects data from the target apparatus and uses it to refine the model through the second learning process. This feedback loop allows the system to start with preliminary knowledge and progressively improve detection accuracy based on actual operational data, resolving the contradiction between immediate startup and accuracy.
3Force
If only standard apparatus data is used for learning, then the model can be prepared in advance, but it cannot adapt to the specific characteristics of the target apparatus
Solution Approach 1:
The patent segments the learning data sources into two categories: standard apparatus data for foundational model construction, and target apparatus data for adaptation. This segmentation allows the model to benefit from both pre-prepared knowledge and device-specific characteristics, resolving the contradiction between preparation capability and adaptability.
Solution Approach 2:
The patent merges two learning processes into a unified model development framework. The first learning process combines standard apparatus data to create a baseline model, while the second learning process combines target apparatus data to adapt the model. The merging of these two learning stages produces a model that possesses both preparation capability and target-specific adaptability.
Data Source
AI summary
An information processing apparatus (2000) classifies each event that occurred in a target apparatus to be determined (10) either as an event (event of a first class) that also occurs in a standard apparatus (20) or as an event (event of a second class) that does not occur in the standard apparatus (20). Herein, a first model used for a determination with respect to an event that also occurs in the standard apparatus (20) and a second model used for a determination with respect to an event that does not occur in the standard apparatus (20) are used as models for determining whether an event that occurs in a target apparatus to be determined (10) is a target for warning. The information processing apparatus (2000) performs learning of the first model using an event of the first class. Further, the information processing apparatus (2000) performs learning of the second model using an event of the second class.


