Anomaly Detection via Scenario Cluster Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack the capability to accurately detect targeted behaviors by considering complex scenarios where the combined effect of multiple scenario violations is non-additive, indicating a need for a method to group scenario violations and assess their predictive ability.
Innovation Solution
The system clusters scenario violations based on similarity metrics, feeds these clusters into a statistical model to rank their predictive ability, and iteratively computes the effectiveness of combinations of clusters to create super scenario clusters, which are then used to score entities for targeted behavior detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If multiple scenario violations are analyzed individually, then the detection process is simple, but the accuracy of targeted behavior detection is insufficient
Solution Approach 1:
The patent combines multiple scenario violations into cluster scenarios by grouping violations that are temporally or conceptually related. This merging process allows the system to analyze combinations of violations together, capturing the non-additive effects that individual violation analysis misses, thereby improving behavior detection accuracy while managing complexity through structured clustering.
Solution Approach 2:
The patent creates composite scenario clusters by combining multiple individual scenario violations into unified cluster scenarios. These composite structures represent complex behavioral patterns that cannot be captured by single violations alone, enabling more accurate detection of targeted behaviors through the aggregated predictive power of multiple related violations.
2Reliability
If all scenario violations are considered equally, then the processing is straightforward, but the predictive ability of individual violations is underestimated
Solution Approach 1:
The patent transforms the parameter representation of scenario violations by organizing them into clusters with aggregated predictive metrics. This parameter transformation allows the system to evaluate combinations of violations as unified entities with combined predictive power, rather than treating each violation in isolation, thereby improving reliability while structuring the complexity through defined clustering parameters.
3Measurement precision
If individual scenario violations are detected separately, then the detection speed is fast, but false positives increase
Solution Approach 1:
The patent merges multiple individual violation detections into cluster scenario evaluations. By grouping related violations and assessing them together, the system reduces false positives that occur when isolated violations are misinterpreted, while maintaining detection efficiency through structured cluster processing rather than exhaustive individual analysis.
Data Source
AI summary
One or more embodiments may include techniques to identify anomalies based on computer-generated results. Moreover, embodiments may include applying scenario rules to data to detect scenario violations and grouping the scenario violations into scenario clusters based on similar behavior performed by entities indicated by similarity metrics. embodiments include determining predictive ability values for each of the scenario clusters, ranking the scenario clusters based on the predictive ability values, and removing scenario clusters having predictive ability values below a threshold. In embodiments combinations of scenario clusters may be generated from the set of scenario clusters and the combinations of scenario clusters may be evaluated for effectiveness. Embodiments include generating scores for entities of the combinations of scenario clusters deemed effective, and provide results indicating whether one or more of the entities committed an anomaly based on the scores for each of the entities.


