IP Library Granted Patent US 12,730,702
Granted Patent B2
US 12,730,702 · App. 18/977,175 · Granted Sep 8, 2026

Early root cause localization

Inventors: Zhengzhang Chen (Princeton Junction, NJ); Haifeng Chen (West Windsor, NJ); Yanchi Liu (Princeton, NJ); LuAn Tang (Cranbury, NJ); Haoyu Wang (Plainsboro, NJ); Dongjie Wang (Orlando, FL)
Assignee: NEC Corporation
G06F11/079G06F11/0709G06F21/55
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,730,702
App. No.
18/977,175
Granted
Sep 8, 2026
Kind
B2
Abstract

Methods and systems for root cause analysis include combining system logs and system metrics into time-series data. Individual root cause analysis is performed to determine individual causal scores for respective system entities. Topological root cause analysis is performed to capture topological patterns of system anomalies. The individual causal scores and the topological patterns are integrated by a weighted sum. A corrective action is performed on an entity identified based on the weighted sum.

Claims (32)

1 . A computer-implemented method for root cause analysis, comprising:

combining system logs and system metrics from a cyber-physical system into time-series data;

performing individual root cause analysis to determine individual causal scores for respective system entities that are related to system anomalies of the cyber-physical system based on the time-series data;

performing topological root cause analysis that utilizes disentangled causal graph learning with a graph neural network (GNN) based vector autoregressive framework to capture topological patterns of the system anomalies within the cyber-physical system in real-time through learned causal graphs based on the time-series data;

integrating the individual causal scores and topological scores resulting from the topological root cause analysis by a weighted sum to identify system entities as root causes for the system anomalies based on a likelihood of nodes of the learned causal graphs being root causes; and

performing a corrective action on an entity from the system entities identified as the root causes of the system anomalies for the cyber-physical system based on the weighted sum, the corrective action including halting a compromised process based on the root causes identified as an intrusion in the network system of the cyber-physical system.

2 . The method of claim 1 , further comprising performing early root cause localization to determine the entity after a tolerance time has elapsed.

3 . The method of claim 1 , wherein combining system logs and system metrics includes parsing the system logs to convert the system logs into respective time series.

4 . The method of claim 1 , further comprising performing trigger point detection to detect the system anomalies based on a distance measured between two consecutive batches of time-series data.

5 . The method of claim 4 , wherein the distance is measured according to a log-Euclidean distance or a log-Cholesky distance.

6 . The method of claim 4 , wherein performing trigger point detection includes generating respective covariance matrices for the two consecutive batches of time-series data and determining the distance between the covariance matrices.

7 . The method of claim 1 , wherein performing individual root cause analysis uses an extreme value theory approach.

8 . The method of claim 1 , wherein performing topological root cause analysis uses disentangled causal graph learning that separates invariant and variant causal relationships among various system entities of the cyber-physical system through learned causal graphs generated based on the time-series data.

9 . The method of claim 1 , wherein the entity is an entity within a cloud computing environment.

10 . The method of claim 1 , wherein the corrective action includes changing a configuration, environmental condition, or operational status of the entity.

11 . A system for root cause analysis, comprising:

a hardware processor; and

a memory that stores a computer program which, when executed by the hardware processor, causes the hardware processor to:

combine system logs and system metrics from a cyber-physical system into time-series data;

perform individual root cause analysis to determine individual causal scores for respective system entities that are related to system anomalies of the cyber-physical system based on the time-series data;

perform topological root cause analysis that utilizes disentangled causal graph learning with a graph neural network (GNN) based vector autoregressive framework to capture topological patterns of the system anomalies within the cyber-physical system in real-time through learned causal graphs based on the time-series data;

integrate the individual causal scores and the topological scores resulting from the topological root cause analysis by a weighted sum to identify system entities as root causes for the system anomalies based on a likelihood of nodes of the learned causal graphs being root causes; and

perform a corrective action on an entity from the system entities identified as the root causes of the system anomalies for the cyber-physical system based on the weighted sum, the corrective action including halting a compromised process based on the root causes identified as an intrusion in the network system of the cyber-physical system.

12 . The system of claim 11 , wherein the computer program further causes the hardware processor to perform early root cause localization to determine the entity after a tolerance time has elapsed.

13 . The system of claim 11 , wherein the combination of system logs and system metrics includes a parsing of the system logs to convert the system logs into respective time series.

14 . The system of claim 11 , wherein the computer program further causes the hardware processor to perform trigger point detection to detect the system anomalies based on a distance measured between two consecutive batches of time series data.

15 . The system of claim 14 , wherein the distance is measured according to a log-Euclidean distance or a log-Cholesky distance.

16 . The system of claim 14 , wherein the performance of trigger point detection includes generation of respective covariance matrices for the two consecutive batches of time-series data and determining the distance between the covariance matrices.

17 . The system of claim 11 , wherein the performance of individual root cause analysis uses an extreme value theory approach.

18 . The system of claim 11 , wherein the performance of topological root cause analysis uses disentangled causal graph learning that separates invariant and variant causal relationships among various system entities of the cyber-physical system through learned causal graphs generated based on the time-series data.

19 . The system of claim 11 , wherein the entity is an entity within a cloud computing environment.

20 . The system of claim 11 , wherein the corrective action includes a change of configuration, environmental condition, or operational status of the entity.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2026
From: NEC LABORATORIES AMERICA, INC.
To: NEC CORPORATION
Reel/Frame 075265/0791 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2024
From: CHEN, ZHENGZHANG; CHEN, HAIFENG; LIU, YANCHI; TANG, LUAN; WANG, HAOYU; WANG, DONGJIE
To: NEC LABORATORIES AMERICA, INC.
Reel/Frame 069554/0835 →
Continuity (2)
Provisional Application 63609628 · Dec 13, 2023
Related Publication 20250199900A1 · Jun 19, 2025
References Cited (18)
US 20190044969A1 · Pilkington · 2019 [cited by examiner]
US 20190266253A1 · Maiti · 2019 [cited by examiner]
US 20200250308A1 · Li · 2020 [cited by examiner]
US 20210111943A1 · Moser · 2021 [cited by examiner]
US 20220358005A1 · Saha · 2022 [cited by examiner]
US 20220382614A1 · Chen et al. · 2022 [cited by applicant]
US 20230069074A1 · Chen et al. · 2023 [cited by applicant]
US 20240054043A1 · Chen et al. · 2024 [cited by applicant]
US 20240061739A1 · Chen et al. · 2024 [cited by applicant]
US 20240061740A1 · Chen et al. · 2024 [cited by applicant]
US 20240202063A1 · Kim · 2024 [cited by examiner]
Meng et al., “Localizing Failure Root Causes in a Microservice through Causality Inference”, 2020, IEEE, pp. 1-10. (Year: 2020). [cited by examiner]
Zheng, L., Chen, Z., He, J., & Chen, H. (May 2024). MULAN: Multi-modal Causal Structure Learning and Root Cause Analysis for Microservice Systems. In Proceedings of the ACM on Web Conference 2024 (pp. 4107-4116). [cited by applicant]
Zheng, L., Chen, Z., He, J., & Chen, H. (Feb. 4, 2024). Multi-modal Causal Structure Learning and Root Cause Analysis. arXiv preprint arXiv:2402.02357. [cited by applicant]
Zheng, L., Chen, Z., Wang, D., Deng, C., Matsuoka, R., & Chen, H. (Sep. 26, 2024). LEMMA-RCA: A Large Multi-modal Multi-domain Dataset for Root Cause Analysis. arXiv preprint arXiv:2406.05375. [cited by applicant]
Deng, C., Chen, Z., Zhao, X., Wang, H., Wang, J., Chen, H., & Gao, J. (Oct. 28, 2024). RIO-CPD: A Riemannian Geometric Method for Correlation-aware Online Change Point Detection. arXiv preprint arXiv:2407.09698. [cited by applicant]
Wang, D., Chen, Z., Fu, Y., Liu, Y., & Chen, H. (Aug. 6, 2023). Incremental causal graph learning for online root cause analysis. In Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining (… [cited by applicant]
Wang, D., Chen, Z., Ni, J., Tong, L., Wang, Z., Fu, Y., & Chen, H. (Aug. 6, 2023). Interdependent causal networks for root cause localization. In Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and … [cited by applicant]