Collaborative Telemetry Engineering for Decentralized Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network monitoring systems rely on centralized controllers for deep anomaly detection (DAD) of telemetry data, which is inefficient and resource-intensive, especially in deployments without a network controller.

Innovation Solution

A decentralized approach where network devices independently generate and share feature vectors based on local telemetry data, performing machine learning to detect deviations and determine predefined actions without a centralized server or controller.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized controllers are used for deep anomaly detection of telemetry data, then comprehensive network monitoring is achieved, but computational overhead and resource consumption increase significantly

Engineering Contradiction:
Improvenetwork monitoring reliabilityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the centralized anomaly detection function into distributed components at each network device. Each device independently performs deep anomaly detection on its own telemetry data using local machine learning models, eliminating the need to aggregate and process all telemetry data through a single centralized controller. This segmentation reduces computational overhead at any single point while maintaining comprehensive monitoring coverage across the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Network devices are empowered to perform self-service anomaly detection by generating and analyzing their own feature vectors locally. Each device uses its own computational resources to run machine learning models and detect anomalies in its telemetry data, rather than relying on external centralized processing. This self-service approach distributes the computational burden and reduces overall system resource consumption.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If centralized controllers process all telemetry data for anomaly detection, then centralized analysis capability is maximized, but system complexity and resource requirements increase

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the anomaly detection functionality into independent modules deployed at each network device. Each device runs its own machine learning model locally, creating multiple simplified detection units rather than one complex centralized system. This segmentation maintains detection precision through specialized local models while reducing overall system complexity by distributing functionality across standard network devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses copying by deploying identical or similar machine learning models across multiple network devices. Each device maintains a local copy of the anomaly detection model, enabling consistent detection precision across the network without requiring a single complex centralized analysis system. This copying approach simplifies the overall architecture by using replicated simple components rather than a single complex component.

Inventive Principle:
Principle #26Copying

3Use of energy by moving object

If decentralized feature vector exchange is implemented, then computational overhead is reduced, but network communication overhead increases

Engineering Contradiction:
Improvecomputational overheadVSAvoidnetwork communication overhead
Core Design Contradiction:
Use of energy by moving objectVSLoss of energy

Solution Approach 1:

The patent extracts only the essential feature vectors from telemetry data for exchange between devices, rather than transmitting complete raw telemetry datasets. Each device processes its local data to extract compressed feature representations that capture the essential information needed for anomaly detection. This extraction minimizes the amount of data that needs to be communicated over the network while preserving the computational benefits of decentralized processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12395439B2Collaborative telemetry engineering
Publication Date: 2025.08.19 CISCO TECHNOLOGY INC
  • US12395439B2 patent drawing
  • US12395439B2 patent drawing
  • US12395439B2 patent drawing

AI summary

Methods are provided for a collaborative, decentralized insight engineering based on exchanging telemetry vectors with peer network devices. Each network device independently detects a deviation in its functioning using machine learning of generated feature vectors. Specifically, the methods involve obtaining, from at least one peer network device, at least a first feature vector that represents at least one insight generated from telemetry data of a respective peer network device. The intermediate network device and the at least one peer network device are configured to forward packets of a traffic flow. The methods further involve determining whether a deviation related to one or more of the network devices, exists based at least on the first feature vector and performing the at least one predefined action based on determining that the deviation exists.