IP Library Granted Patent US 12,386,717
Granted Patent B2
US 12,386,717 · App. 18/232,303 · Granted Aug 12, 2025

Ensemble models for anomaly detection

Inventors: Danny Portman (Johns Creek, GA); Zachary Jones (Decatur, GA)
Assignee: Zeta Global Corp.
G06F11/2263G06F11/1476
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,386,717
App. No.
18/232,303
Granted
Aug 12, 2025
Kind
B2
Abstract

The subject technology detects anomalies in media campaign configuration settings. The anomaly detection system may leverage one or more deep learning models to detect anomalies and identify particular configuration settings that contribute to the detected anomalies. In various embodiments, two or more of the deep learning models may be combined into an ensemble model that boosts the accuracy of anomaly predictions made by the anomaly detection system. The anomaly detection system may review the configuration settings of media campaigns during the configuration process and before the media campaigns run on a publication system in order to reduce the amount of unsuccessful campaigns and minimize the amount of wasted resources spent on running campaigns that have a low likelihood of achieving user defined goals.

Claims (38)

1. An anomaly detection system comprising:

one or more processors; and

a memory storing instructions that, when executed by at least one processor in the one or more processors, cause the at least one processor to perform at least the following operations:

encode one or more configuration settings for a campaign in a composite vector using an encoder, the composite vector being representative of at least a portion of the configuration settings;

generate a composite vector for multiple campaigns to create a set of composite vectors;

aggregate the set of composite vectors to generate an output of the encoder, the output including a training sample for modeling;

transmit the output of the encoder to a training model for training multiple anomaly detection machine learning models;

select two or more of the trained anomaly detection machine learning models to include in an ensemble model; and

use the ensemble model to determine an anomaly occurrence probability for one or more configuration settings of a target campaign.

2. The system of claim 1 , wherein the multiple anomaly detection machine learning models include a least one deep learning model.

3. The system of claim 1 , wherein the one or more processors are further configured to determine a composite vector for the target campaign, the composite vector being representative of at least a portion of the configuration settings of the target campaign.

4. The system of claim 1 , wherein the at least one processor is further configured to use each of the two or more trained models to determine an anomaly occurrence probability for one or more of the configuration settings of the target campaign; and

use a weighted voting process to aggregate the anomaly occurrence probabilities determined by the two or more trained models to generate a composite anomaly occurrence probability for the one or more configuration settings of the target campaign.

5. The system of claim 3 , wherein the composite vector for the target campaign includes normalized features determined for one or more numeric configuration settings and encoded features determined from one or more categorical configuration settings.

6. The system of claim 1 , wherein the two or more trained models determine the anomaly occurrence probability by determining a numerical probability that the target campaign includes an anomaly and comparing the numerical probability to an anomaly threshold.

7. The system of claim 4 , wherein the weighted voting process multiples the anomaly occurrence probability determined by each of the trained models by a voting weight determined based on an anomaly detection accuracy of each of the trained models measured for a test sample of completed campaigns.

8. The system of claim 1 , wherein the at least one processor is further configured to identity an anomaly based on the anomaly occurrence probability for one or more configuration settings of the target campaign; and

identity the one or more configuration settings that contribute to the anomaly using an output of one or more of the trained models.

9. The system of claim 8 , wherein the output used to identify the one or more configuration settings that contribute to the anomaly includes a joint probability distribution determined from the output by one or more layers of at least one of the trained models.

10. The system of claim 8 , wherein the at least one processor is further configured to display an error message that includes the identified one or more configuration settings that contribute to the anomaly.

11. A method of anomaly detection in media campaign configuration settings, the method comprising:

encoding one or more configuration settings for a campaign in a composite vector using an encoder, the composite vector being representative of at least a portion of the configuration settings;

generating a composite vector for multiple campaigns to create a set of composite vectors;

aggregating the set of composite vectors to generate an output of the encoder, the output including a training sample for modeling;

transmitting the output of the encoder to a training model for training multiple anomaly detection machine learning models;

selecting two or more of the trained anomaly detection machine learning models to include in an ensemble model; and

using the ensemble model to determine an anomaly occurrence probability for one or more configuration settings of a target campaign.

12. The method of claim 11 , wherein the multiple anomaly detection machine learning models include a least one deep learning model.

13. The method of claim 11 , further comprising determining a composite vector for the target campaign, the composite vector being representative of at least a portion of the configuration settings of the target campaign.

14. The method of claim 11 , further comprising using each of the two or more trained models to determine an anomaly occurrence probability for one or more of the configuration settings of the target campaign; and

using a weighted voting process to aggregate the anomaly occurrence probabilities determined by the two or more trained models to generate a composite anomaly occurrence probability for the one or more configuration settings of the target campaign.

15. The method of claim 11 , wherein the composite vector for the target campaign includes normalized features determined for one or more numeric configuration settings and encoded features determined from one or more categorical configuration settings.

16. The method of claim 11 , further comprising determining the anomaly occurrence probability by determining a numerical probability that the target campaign includes an anomaly and comparing the numerical probability to an anomaly threshold.

17. The method of claim 14 , further comprising performing the weighted voting process by multiplying the anomaly occurrence probability determined by each of the trained models by a voting weight determined based on an anomaly detection accuracy of each of the trained models measured for a test sample of completed campaigns.

18. The method of claim 11 , further comprising identifying an anomaly based on the anomaly occurrence probability for one or more configuration settings of the target campaign; and

identifying the one or more configuration settings that contribute to the anomaly using an output of one or more of the trained models.

19. The method of claim 18 , wherein the output used to identify the one or more configuration settings that contribute to the anomaly includes a joint probability distribution determined from the output by one or more layers of at least one of the trained models.

20. The method of claim 18 , further comprising displaying an error message that includes the identified one or more configuration settings that contribute to the anomaly.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2025
From: PORTMAN, DANNY; JONES, ZACHARY D
To: ZETA GLOBAL CORP.
Reel/Frame 071035/0833 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Aug 30, 2024
From: ZETA GLOBAL CORP.; ZSTREAM ACQUISITION LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 068822/0154 →
Continuity (2)
Provisional Application 63396397 · Aug 9, 2022
Related Publication 20240054058A1 · Feb 15, 2024
References Cited (6)
US 20200311603A1 · Qiu · 2020 [cited by examiner]
US 20220253699A1 · Hoshen · 2022 [cited by examiner]
US 20230325292A1 · Ardel · 2023 [cited by examiner]
US 20230410143A1 · Retinraj · 2023 [cited by examiner]
US 20240046314A1 · Zhu · 2024 [cited by examiner]
Liu, Shigang et al. “Addressing the class imbalance problem in Twitter spam detection using ensemble learning”, Dec. 13, 2016, Computers & Security, vol. 69, pp. 35-49 (Year: 2016). [cited by examiner]