arXiv:2503.23060cs.LG2025-03被引 5

提出DIVAD模型,提升跨领域时间序列异常检测效果

Unsupervised Anomaly Detection in Multivariate Time Series across Heterogeneous Domains

  • 基于领域泛化思想,构建不变特征表示以应对正常行为变化
  • 在Exathlon基准上最大F1分数提升20%和15%
  • 适用于多领域实际运维场景,对系统稳定性提升有重要意义

数字化服务的普及及其规模与复杂性,使得IT运营中的事件更加频繁、多样且影响深远。这推动了‘人工智能运维’(AIOps)的核心进展,即从海量多变量时间序列数据中检测异常。本文首先提出一个统一的无监督异常检测(AD)方法基准框架,并指出实际AIOps场景中正常行为分布偏移的问题。为应对领域偏移下的异常检测挑战,我们采用领域泛化框架,提出新的无监督异常检测方法——领域不变变分自编码器(DIVAD),以学习领域不变表示。在Exathlon基准上的评估显示,DIVAD的两个主要变体在最大性能上显著优于当前最佳无监督方法,最大峰值F1分数分别提升了20%和15%。在Application Server Dataset上的进一步验证表明,该领域泛化方法具有更广泛的应用潜力。

原文摘要 · Abstract (English)

The widespread adoption of digital services, along with the scale and complexity at which they operate, has made incidents in IT operations increasingly more likely, diverse, and impactful. This has led to the rapid development of a central aspect of "Artificial Intelligence for IT Operations" (AIOps), focusing on detecting anomalies in vast amounts of multivariate time series data generated by service entities. In this paper, we begin by introducing a unifying framework for benchmarking unsupervised anomaly detection (AD) methods, and highlight the problem of shifts in normal behaviors that can occur in practical AIOps scenarios. To tackle anomaly detection under domain shift, we then cast the problem in the framework of domain generalization and propose a novel approach, Domain-Invariant VAE for Anomaly Detection (DIVAD), to learn domain-invariant representations for unsupervised anomaly detection. Our evaluation results using the Exathlon benchmark show that the two main DIVAD variants significantly outperform the best unsupervised AD method in maximum performance, with 20% and 15% improvements in maximum peak F1-scores, respectively. Evaluation using the Application Server Dataset further demonstrates the broader applicability of our domain generalization methods.

异常检测时间序列领域泛化AIOps

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。