IP Library Granted Patent US 12,608,617
Granted Patent B2
US 12,608,617 · App. 16/960,448 · Granted Apr 21, 2026

Model training apparatus, model training method, and program for retraining anomaly detection model

Inventors: Yasuhiro Ikeda (Musashino, JP); Keisuke Ishibashi (Musashino, JP); Yusuke Nakano (Musashino, JP); Keishiro Watanabe (Musashino, JP); Ryoichi Kawahara (Musashino, JP)
Assignee: NTT, Inc.
G06N3/088G06F18/214G06F18/217G06F18/22G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,608,617
App. No.
16/960,448
Granted
Apr 21, 2026
Kind
B2
Abstract

An apparatus for training a model includes a storage unit configured to store a parameter of the model trained by using a training data set, and the training data set, a detector configured to use the model to determine whether an anomaly is present in a test data set and store a determined result and the test data set in the storage unit, and a retraining unit configured to retrain the model by using the determined result, the test data set, and the training data set.

Claims (27)

1 . An apparatus for training a model comprising:

a processor; and

a memory storing program instructions that cause the processor to:

store a parameter of the model trained by using a training data set, and the training data set;

receive data from a network;

obtain an output from the model to determine whether an anomaly in the network is present in a test data set based on the obtained output and store a determined result and the test data set;

retrain the model by using the determined result, the test data set, and the training data set; and

subsequently receive data from the network, and obtain an output from the retrained model to determine whether an anomaly in the network is present in the subsequently received data in real-time,

wherein the processor retrains the model by using an element of the test data set in response to determining that the element of the test data set is incorrectly determined as the anomaly and determining that a distance of the element of the test data set with respect to the training data set is less than a threshold to prevent overlearning.

2 . The apparatus for training the model as claimed in claim 1 , wherein the processor uses the model to determine a class of each element of the test data set, and the processor determines whether the anomaly is present in the test data set based on the determined class.

3 . The apparatus for training the model as claimed in claim 1 , wherein the processor retrains the model by using a correct answer related to whether the anomaly is present in the test data set so that an element of the test data set that has been incorrectly determined is correctly determined.

4 . The apparatus for training the model as claimed in claim 1 , wherein the processor is configured to determine whether to adopt a new parameter of the model to be used by the processor based on accuracy of anomaly detection performed with respect to validation data by using the new parameter after the processor has obtained the new parameter.

5 . The apparatus for training the model as claimed in claim 1 , wherein the data received from the network includes network traffic data.

6 . The apparatus for training the model as claimed in claim 1 , wherein the output from the model is obtained to determine whether the anomaly in a temporal trend of an increase or decrease in a particular type of data in the network is present in the test data set.

7 . The apparatus for training the model as claimed in claim 1 , wherein the distance is a Euclidean distance on a low-dimensional space to which the test data set and the training data set are mapped.

8 . A model training method comprising:

receiving data from a network;

obtaining an output from a model to determine whether an anomaly in the network is present in a test data set based on the obtained output and storing a determined result and the test data set, the model being trained by using a training data set;

retraining the model by using the determined result, the test data set, and the training data set;

f subsequently receiving data from the network, and obtain an output from the retrained model to determine whether an anomaly in the network is present in the subsequently received data in real-time,

wherein the retraining of the model includes retraining the model by using an element of the test data set in response to determining that the element of the test data set is incorrectly determined as the anomaly and determining that a distance of the element of the test data set with respect to the training data set is less than a threshold to prevent overlearning.

9 . A non-transitory computer-readable recording medium having a program for causing a computer to perform a process comprising:

receiving data from a network;

obtaining an output from a model to determine whether an anomaly in the network is present in a test data set based on the obtained output and storing a determined result and the test data set, the model being trained by using a training data set;

retraining the model by using the determined result, the test data set, and the training data set;

f subsequently receiving data from the network, and obtain an output from the retrained model to determine whether an anomaly in the network is present in the subsequently received data in real-time,

wherein the retraining of the model includes retraining the model by using an element of the test data set in response to determining that the element of the test data set is incorrectly determined as the anomaly and determining that a distance of the element of the test data set with respect to the training data set is less than a threshold to prevent overlearning.

Assignments (2)
CHANGE OF NAME Recorded Aug 11, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072416/0598 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2020
From: IKEDA, YASUHIRO; ISHIBASHI, KEISUKE; NAKANO, YUSUKE; WATANABE, KEISHIRO; KAWAHARA, RYOICHI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 053324/0566 →
Priority Claims (1)
JP 2018-001485 · Jan 9, 2018 · national
Continuity (1)
Related Publication 20200334578A1 · Oct 22, 2020
References Cited (30)
US 7058616B1 · Larder · 2006 [cited by examiner]
US 20140114442A1 · Li · 2014 [cited by examiner]
US 20170353477A1 · Faigon · 2017 [cited by examiner]
US 20190391038A1 · Kitai · 2019 [cited by examiner]
US 20200052981A1 · Pandey · 2020 [cited by examiner]
JP 2001236337A · 2001 [cited by applicant]
O'Reilly et al. (“Anomaly Detection in Wireless Sensor Networks in a Non-Stationary Environment”, IEEE, vol. 16, No. 3, 2014) (Year: 2014). [cited by examiner]
Liu et al. (“An Anomaly Detection Algorithm of Cloud Platform Based on Self-Organizing Maps”, 2016) (Year: 2016). [cited by examiner]
Kirkpatrick et al. (“Overcoming catastrophic forgetting in neural networks”, PNAS, Mar. 28, 2017, vol. 114, No. 13, pp. 3521-3526) (Year: 2017). [cited by examiner]
Tune et al. (“Fisher Information in Flow Size Distribution Estimation”, 2011) (Year: 2011). [cited by examiner]
Rassam et al. (“Adaptive and online data anomaly detection for wireless sensor systems”, Knowledge-Based Systems 60 (2014) 44-57) (Year: 2014). [cited by examiner]
Dongli et al. (“A method of anomaly detection and fault diagnosis with online adaptive learning under small training samples”, Pattern Recognition vol. 64, Apr. 2017, pp. 374-385) (Year: 2017). [cited by examiner]
Neuberg et al. (“Detecting Relative Anomaly”, arXiv May 16, 2016) (Year: 2016). [cited by examiner]
Tian et al. (“A Hierarchical PCA-based Anomaly Detection Model”, 2013 pp. 621-625) (Year: 2013). [cited by examiner]
Burbeck et al. (“ADWICE—Anomaly Detection with Real-Time Incremental Clustering”, ICISC 2004, LNCS 3506, pp. 407-424, 2005) (Year: 2005). [cited by examiner]
International Search Report issued on Jan. 29, 2019 in PCT/JP2018/039953 filed on Oct. 26, 2018, 2 pages. [cited by applicant]
Nakano et al., “Autoencoder based detection method for network anomalies”, Proceedings of The 2017 IEICE General Conference, Communication 2, 2017, ISSN 1349-1369, 6 total pages (with unedited computer-generated English… [cited by applicant]
Sato et al., “Learning Weights of Training Data by Game Results”, Journal of Information Processing Society, 2014, vol. 55, No. 11, ISSN 1882-7764, 17 total pages (with English Abstract and unedited computer-generated E… [cited by applicant]
Ueda et al., “Automated Training Data Selection for Response Time Degradation Diagnosis of Web Service Systems Using Machine Learning Combination”, The Transactions of the Institute of Electronics, Information and Commu… [cited by applicant]
Sakurada et al., “Dimensionality Reduction with the Autoencoder for Anomaly Detection of Spacecrafts”, The 28 [cited by applicant]
Hodge et al., “A Survey of Outlier Detection Methodologies”, Artificial Intelligence Review, 2004, <URL:https://www.researchgate/net/publication/220638052>, pp. 1-43 (44 total pages). [cited by applicant]
Ringberg et al., “Sensitivity of PCA for Traffic Anomaly Detection”, ACM SIGMETRICS Performance Evaluation Review 35.1, 2007, pp. 109-120. [cited by applicant]
Kirkpatrick et al., “Overcoming catastrophic forgetting in neural networks”, Proceedings of the National Academy of Sciences, 2017, pp. 1-13. [cited by applicant]
Bottou, “Large-Scale Machine Learning with Stochastic Gradient Descent”, Proceedings of COMPSTAT 2010, Physica-Verlag HD, 2010, pp. 1-10. [cited by applicant]
Van Der Maaten et al., “Visualizing Data using t-SNE”, Journal of Machine Learning Research, 2008, vol. 9, pp. 2579-2605. [cited by applicant]
Tavallaee et al., “A Detailed Analysis of the KDD CUP 99 Data Set”, Computational Intelligence for Security and Defense Applications, 2009, CISDA 2009, IEEE Symposium on. IEEE, NRC Publications Archive (NPArC), 8 total … [cited by applicant]
Yasuhiro Ikeda, et al., “Inferring causal parameters of anomalies detected by autoencoder using sparse optimization,” The Institute of Electronics, Information and Communication Engineers, Technical Report of IEICE, 201… [cited by applicant]
Constantine Manikopoulos, et al., “Network Intrusion and Fault Detection: A Statistical Anomaly Approach,” IEEE Communications Magazine, Oct. 2002, pp. 76-82. [cited by applicant]
Office Action issued Nov. 24, 2021 in corresponding Japanese Patent Application No. 2019-564307 (with English Translation), 8 pages. [cited by applicant]
“Read a paper developed by DeepMind an algorithm to avoid the flaws “catastrophic oblivion” of neural networks”, 2017, 20 pages (with English Translation) Retrieved from the Internet:<URL:https://qiita.com/yu4u/items/8b… [cited by applicant]