Online Anomaly Detection in Time Series Using Moving Subsequences
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing algorithms for anomaly detection in time series are limited to offline detection of fixed-length anomalies and typically only detect the top anomaly, failing to efficiently detect anomalies of various lengths in real-time, especially when new data points are added to the series.
Innovation Solution
A computer-implemented method that updates moving subsequences of varying lengths and determines metric distances with benchmark subsequences, normalizes these distances, and adjusts a threshold value to detect anomalies of different lengths, ensuring the detection of significant anomalies without requiring the entire time series to be stored in memory.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If online anomaly detection is implemented while new data points are added to the time series, then real-time detection capability is improved, but memory requirements increase as the entire time series must be stored
Solution Approach 1:
The patent extracts only the necessary portion of the time series data by maintaining a sliding window of recent values rather than storing the entire time series. The algorithm keeps track of a limited number of most recent values and their subsequences, extracting only what is needed for online anomaly detection while discarding or not storing older data that is no longer relevant for current anomaly detection.
Solution Approach 2:
The patent applies local quality by focusing computational resources and memory storage on the most recent portion of the time series where anomalies are most likely to occur. Instead of uniformly processing or storing the entire time series, the algorithm concentrates on local subsequences within a sliding window, allocating memory and computation locally to where they are most needed for real-time detection.
2Device complexity
If algorithms detect only the top anomaly, then computational complexity is reduced, but detection accuracy decreases as significant anomalous subsequences remain undetected
Solution Approach 1:
The patent segments the anomaly detection task by dividing the time series into multiple subsequences of different lengths (e.g., length L, 2L, 3L, etc.). Instead of treating the entire series as one unit or finding a single top anomaly, the algorithm segments the detection into multiple categories based on subsequence length, allowing it to identify multiple distinct anomalies across different temporal scales without overwhelming computational complexity.
Solution Approach 2:
The patent applies partial action by detecting anomalies at multiple levels of granularity (different subsequence lengths) rather than performing a complete exhaustive search of all possible anomalies. The algorithm performs partial comparisons against benchmark subsequences for each length category, sufficient to detect significant anomalies without the excessive computational cost of analyzing every possible subsequence combination.
3Device complexity
If fixed-length anomalies are detected, then algorithm simplicity is maintained, but versatility decreases as anomalies of various lengths cannot be detected
Solution Approach 1:
The patent implements universality by designing the algorithm to handle multiple subsequence lengths using the same core detection mechanism. The same benchmark comparison logic is applied universally across different length categories (L, 2L, 3L, etc.), allowing a single algorithm structure to detect anomalies of various lengths without requiring separate specialized algorithms for each length, thus maintaining simplicity while achieving versatility.
Data Source
Figure 1
Figure 2
Figure 3A~3B
AI summary
Example embodiments relate to a method for detecting an anomaly in a time series (220). The method comprises obtaining (201) a next value (260) of the time series, updating (202) a moving sequence (221) with the next value, and updating (203) moving subsequences (223, 224, 225) of distinct lengths from the moving sequence. The method further comprises, for each respective one of the distinct lengths, determining (204, 205) normalized metric distances between the moving subsequence and a set of benchmark subsequences, thereby obtaining sets of normalized metric distances (264) respectively associated with the distinct lengths. The method further comprises, if all normalized metric distances in at least one set (264) exceed a predetermined threshold value, retrieving previous values of the time series; and updating the sets of normalized metric distances with updated normalized metric distances. If all normalized metric distances in an updated set (266) of normalized metric distances exceed the predetermined threshold value, an anomaly is detected in the time series.