IP Library › Granted Patent US 12,267,349
Granted Patent B1
US 12,267,349 · App. 18/763,469 · Granted Apr 1, 2025

Multi-dimensional anomaly source detection

Inventors: Jason Black (Columbus, OH); Bradley Glenn (Columbus, OH); Cameron Conte (Columbus, OH)
Assignee: THE HUNTINGTON NATIONAL BANK
H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,349
App. No.
18/763,469
Granted
Apr 1, 2025
Kind
B1
Abstract

Techniques are described herein for validating the occurrence of an anomaly and/or identifying a source and/or impact of an anomaly initially detected in time series data. A plurality of time series data instances individually corresponding to a respective entity of a plurality of entities may be obtained. An anomalous value may be detected in a first time series data instance of the plurality of time series data instances, the first time series data instance being associated with an entity. One or more correlated entity peers for the entity may be identified based at least in part on a predefined hierarchy and/or segmentation scheme. The occurrence of the anomaly and/or the source and/or impact of the anomaly may be determined based on comparing the anomaly to time series data of the time series data of the correlated entity peers.

Claims (52)

1. A computer-implemented method, comprising:

obtaining, by a computing device, a plurality of time series data instances individually corresponding to a respective entity of a plurality of entities;

detecting, by the computing device, an anomalous value in a first time series data instance of the plurality of time series data instances, the first time series data instance being associated with an entity of the plurality of entities;

identifying, from a predefined geographical hierarchy, a first level to which the entity is associated, the predefined geographical hierarchy comprising a plurality of levels corresponding to different geographical areas with which respective subsets of the plurality of entities are individually associated;

identifying, by the computing device, a first correlated entity peer from the plurality of entities based at least in part on executing a correlation analysis algorithm on the first time series data instance corresponding to the entity and a second time series data instance corresponding to a second entity of the plurality of entities, the second entity being associated with a second level of the predefined geographical hierarchy that is different from the first level with which the entity is associated;

identifying, by the computing device, a second correlated entity peer from the plurality of entities based at least in part on executing the correlation analysis algorithm on the first time series data instance corresponding to the entity and a third time series data instance corresponding to a third entity of the plurality of entities, the third entity being associated with a common attribute with which the entity is associated;

determining that an anomaly has occurred based at least in part on determining whether the anomalous value detected within the first time series data instance conforms to at least one of a first value of the second time series data instance corresponding to the first correlated entity peer or a second value of the third time series data instance corresponding to the second correlated entity peer; and

identifying a source of the anomaly as being associated with at least one of: 1) the first level or the second level of the predefined geographical hierarchy or 2) the common attribute with which the entity and the third entity are both associated.

2. The computer-implemented method of claim 1 , further comprising performing one or more operations in response to determining that the anomalous value indicates that the anomaly has occurred, wherein the one or more operations comprising transmitting a notification, transmitting an electronic message, or presenting data indicating the anomaly has occurred.

3. The computer-implemented method of claim 1 , wherein determining that the anomaly has occurred is based at least in part on determining that the first value of the second time series data instance is anomalous.

4. The computer-implemented method of claim 1 , wherein identifying the first correlated entity peer further comprises:

obtaining the predefined geographical hierarchy;

identifying a lowest level of the predefined geographical hierarchy with which the entity is associated, the lowest level being the first level; and

identifying the second level based at least in part on identifying a next-lowest level of the predefined geographical hierarchy that is higher than the first level with which the entity is associated.

5. The computer-implemented method of claim 1 , wherein identifying the second correlated entity peer further comprises obtaining a first attribute value associated with the entity, wherein the second correlated entity peer is identified based at least in part on being associated with a second attribute value that matches the first attribute value.

6. The computer-implemented method of claim 1 , wherein the anomaly is identified as relating to the entity and the first correlated entity peer or the second correlated entity peer.

7. The computer-implemented method of claim 1 , wherein the source of the anomaly is identified being associated with the first level of the predefined geographical hierarchy based at least in part on determining that the anomalous value detected within the first time series data instance fails to conform to the second value of the third time series data instance corresponding to the second correlated entity peer.

8. The computer-implemented method of claim 1 , wherein the source of the anomaly is identified being associated with the common attribute based at least in part on determining that the anomalous value detected within the first time series data instance conforms to conform to the second value of the third time series data instance corresponding to the second correlated entity peer.

9. A system, comprising:

one or more processors; and

one or more memories storing computer-executable instructions that, when executed by the one or more processors, causes the one or more processors to:

obtain a plurality of time series data instances individually corresponding to a respective entity of a plurality of entities;

detect an anomalous value in a first time series data instance of the plurality of time series data instances, the first time series data instance being associated with an entity of the plurality of entities;

identify, from a predefined geographical hierarchy, a first level to which the entity is associated, the predefined geographical hierarchy comprising a plurality of levels corresponding to different geographical areas with which respective subsets of the plurality of entities are individually associated;

identify a first correlated entity peer from the plurality of entities based at least in part on executing a correlation analysis algorithm on the first time series data instance corresponding to the entity and a second time series data instance corresponding to a second entity of the plurality of entities, the second entity being associated with a second level of the predefined geographical hierarchy that is different from the first level with which the entity is associated;

identify a second correlated entity peer from the plurality of entities based at least in part on executing the correlation analysis algorithm on the first time series data instance corresponding to the entity and a third time series data instance corresponding to a third entity of the plurality of entities, the third entity being associated with a common attribute with which the entity is associated;

determine that an anomaly has occurred based at least in part on determining whether the anomalous value detected within the first time series data instance conforms to at least one of a first value of the second time series data instance corresponding to the first correlated entity peer or a second value of the third time series data instance corresponding to the second correlated entity peer; and

identify a source of the anomaly as being associated with at least one of 1) the first level or the second level of the predefined geographical hierarchy or 2) the common attribute with which the entity and the third entity are both associated.

10. The system of claim 9 , wherein executing the computer-executable instructions further causes the one or more processors to perform one or more operations in response to determining that the anomalous value indicates that the anomaly has occurred, wherein the one or more operations comprising transmitting a notification, transmitting an electronic message, or presenting data indicating the anomaly has occurred.

11. The system of claim 9 , wherein determining that the anomaly has occurred is based at least in part on determining that the first value of the second time series data instance is anomalous.

12. The system of claim 9 , wherein executing the computer-executable instructions further causes the one or more processors to identify the first correlated entity peer further causes the one or more processors to:

obtain the predefined geographical hierarchy;

identify a lowest level of the predefined geographical hierarchy with which the entity is associated, the lowest level being the first level; and

identify the second level based at least in part on identifying a next-lowest level of the predefined geographical hierarchy that is higher than the first level with which the entity is associated.

13. The system of claim 9 , wherein executing the computer-executable instructions further causes the one or more processors to identify the second correlated entity peer further causes the one or more processors to obtain a first attribute value associated with the entity, wherein the second correlated entity peer is identified based at least in part on being associated with a second attribute value that matches the first attribute value.

14. The system of claim 9 , wherein the anomaly is identified as relating to the entity and the first correlated entity peer or the second correlated entity peer.

15. A non-transitory computer-readable storage medium storing computer-executable instructions that, when executed with one or more processors of a computing device, causes the computing device to:

obtain a plurality of time series data instances individually corresponding to a respective entity of a plurality of entities;

detect an anomalous value in a first time series data instance of the plurality of time series data instances, the first time series data instance being associated with an entity of the plurality of entities;

identify, from a predefined hierarchy, a first level to which the entity is associated, the predefined hierarchy comprising a plurality of levels with which respective subsets of the plurality of entities are individually associated;

identify a first correlated entity peer from the plurality of entities based at least in part on executing a correlation analysis algorithm on the first time series data instance corresponding to the entity and a second time series data instance corresponding to a second entity of the plurality of entities, the second entity being associated with a second level of the predefined hierarchy that is different from the first level with which the entity is associated;

identify a second correlated entity peer from the plurality of entities based at least in part on executing the correlation analysis algorithm on the first time series data instance corresponding to the entity and a third time series data instance corresponding to a third entity of the plurality of entities, the third entity being associated with a common attribute with which the entity is associated;

determine that an anomaly has occurred based at least in part on determining whether the anomalous value detected within the first time series data instance conforms to at least one of a first value of the second time series data instance corresponding to the first correlated entity peer or a second value of the third time series data instance corresponding to the second correlated entity peer; and

identify a source of the anomaly as being associated with at least one of: 1) the first level or the second level of the predefined hierarchy or 2) the common attribute with which the entity and the third entity are both associated.

16. The non-transitory computer-readable storage medium of claim 15 , wherein executing the computer-executable instructions further causes the computing device to perform one or more operations in response to determining that the anomalous value indicates that the anomaly has occurred, wherein the one or more operations comprising transmitting a notification, transmitting an electronic message, or presenting data indicating the anomaly has occurred.

17. The non-transitory computer-readable storage medium of claim 15 , wherein determining that the anomaly has occurred is based at least in part on determining that the first value of the second time series data instance is anomalous.

18. The non-transitory computer-readable storage medium of claim 15 , wherein executing the computer-executable instructions further causes the one or more processors to identify the first correlated entity peer further causes the one or more processors to:

obtain the predefined hierarchy;

identify a lowest level of the predefined hierarchy with which the entity is associated, the lowest level being the first level; and

identify the second level based at least in part on identifying a next-lowest level of the predefined hierarchy that is higher than the first level with which the entity is associated.

19. The non-transitory computer-readable storage medium of claim 15 , wherein executing the computer-executable instructions further causes the computing device to identify the second correlated entity peer further causes the one or more processors to obtain a first attribute value associated with the entity, wherein the second correlated entity peer is identified based at least in part on being associated with a second attribute value that matches the first attribute value.

20. The non-transitory computer-readable storage medium of claim 15 , wherein the predefined hierarchy is a predefined geographical hierarchy or a predefined managerial hierarchy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 5, 2024
From: BLACK, JASON; GLENN, BRADLEY; CONTE, CAMERON
To: THE HUNTINGTON NATIONAL BANK
Reel/Frame 067915/0851 →
References Cited (12)
US 11294756B1 · Sadrieh · 2022 [cited by examiner]
US 20180082208A1 · Cormier · 2018 [cited by examiner]
US 20220092612A1 · Bharath · 2022 [cited by examiner]
US 20220237620A1 · Saarenvirta · 2022 [cited by examiner]
US 20230033647A1 · Lemberg · 2023 [cited by examiner]
US 20230067842A1 · Yin · 2023 [cited by examiner]
US 20230245234A1 · Sumant · 2023 [cited by examiner]
US 20240095579A1 · Paulraj · 2024 [cited by examiner]
US 20240223434A1 · Cheng · 2024 [cited by examiner]
US 20240356944A1 · Mahajan · 2024 [cited by examiner]
Ang et al., “EADS: An Early Anomaly Detection System for Sensor-Based Multivariate Time Series,” 2024 IEEE 40th International Conference on Data Engineering (ICDE) Year: 2024 | Conference Paper | Publisher: IEEE. [cited by examiner]
Sun et al., “Unraveling the ‘Anomaly’ in Time Series Anomaly Detection: A Self-supervised Tri-domain Solution,” 2024 IEEE 40th International Conference on Data Engineering (ICDE) Year: 2024 | Conference Paper | Publishe… [cited by examiner]
Cited By (1)
US 12,699,623