用可解释的微分方程模型,同时检测异常、定位根源并分类。
Unifying Explainable Anomaly Detection and Root Cause Analysis in Dynamical Systems
- 基于神经微分方程与因果推断,构建统一解释框架。
- 在多个动力系统上实现高精度异常检测与根因定位。
- 适合需要可解释性的工业系统监控场景。
动力系统广泛存在于科学与工程领域,易受异常影响,进而损害性能与可靠性。本文针对由常微分方程(ODE)描述的动力系统中的异常检测、根因定位与异常类型分类问题,提出可解释因果微分方程(ICODE)网络。该模型将异常分为两类:通过变量间耦合传播的网络异常,以及局限于单个变量的测量异常。ICODE利用神经ODE进行异常检测,并通过解释通道实施因果推断,实现根因分析,揭示为何特定时间段被标记为异常。其核心假设是异常会改变系统的底层ODE,表现为变量间因果关系的变化。我们从理论上分析了学习到的模型参数扰动如何用于识别异常及其根因。大量实验验证了ICODE在多种动力系统上的有效性,能准确检测异常、分类异常类型并精确定位根源。
原文摘要 · Abstract (English)
Dynamical systems, prevalent in various scientific and engineering domains, are susceptible to anomalies that can significantly impact their performance and reliability. This paper addresses the critical challenges of anomaly detection, root cause localization, and anomaly type classification in dynamical systems governed by ordinary differential equations (ODEs). We define two categories of anomalies: cyber anomalies, which propagate through interconnected variables, and measurement anomalies, which remain localized to individual variables. To address these challenges, we propose the Interpretable Causality Ordinary Differential Equation (ICODE) Networks, a model-intrinsic explainable learning framework. ICODE leverages Neural ODEs for anomaly detection while employing causality inference through an explanation channel to perform root cause analysis (RCA), elucidating why specific time periods are flagged as anomalous. ICODE is designed to simultaneously perform anomaly detection, RCA, and anomaly type classification within a single, interpretable framework. Our approach is grounded in the hypothesis that anomalies alter the underlying ODEs of the system, manifesting as changes in causal relationships between variables. We provide a theoretical analysis of how perturbations in learned model parameters can be utilized to identify anomalies and their root causes in time series data. Comprehensive experimental evaluations demonstrate the efficacy of ICODE across various dynamical systems, showcasing its ability to accurately detect anomalies, classify their types, and pinpoint their origins.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。