IP Library Granted Patent US 10,692,004
Granted Patent B1
US 10,692,004 · App. 16/458,096 · Granted Jun 23, 2020

System and method for anomaly detection in dynamically evolving data using random neural network decomposition

Inventor: David Segev (Lapid, IL)
Assignee: ThetaRay Ltd.
G06N3/08G06F11/0721G06F11/0751
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,692,004
App. No.
16/458,096
Granted
Jun 23, 2020
Kind
B1
Abstract

Detection systems, methods and computer program products comprising a non-transitory tangible storage medium readable by a processing circuit and storing instructions for execution by the processing circuit for performing a method for anomaly detection, a detected anomaly being indicative of an undesirable event. A detection system comprises a computer and an anomaly detection engine executable by the computer, the anomaly detection engine configured to perform a method comprising receiving data comprising a plurality m of multidimensional data points (MDDPs), each data point having n features, constructing a dictionary D based on the received data, embedding dictionary D into a lower dimension embedded space and classifying, based in the lower dimension embedded space, a MDDP as an anomaly or as normal.

Claims (29)

1. A computer program product comprising: a non-transitory tangible storage medium readable by a processing circuit and storing instructions for execution by the processing circuit for performing a method comprising:

a) receiving a plurality m of multidimensional data points (MDDPs), each data point having n≥2 features, wherein n<<m and wherein the data forms a matrix A with size m×n, matrix A having a rank k≤n;

b) applying random projection and neural network (RPNN) processing to matrix A to obtain a dictionary D in the form of a matrix m′×n, wherein m′<m, wherein accordingly dictionary D has fewer MDDPs than matrix A and a lower rank than k,

wherein the applying RPNN processing includes running a plurality of iterations i, each iteration i resulting in a new dictionary D i with a respective reduced rank smaller than a rank of an immediately preceding dictionary, stopping the running of the plurality of iterations i when the respective reduced rank of dictionary D i does not change from the immediately preceding dictionary rank, and concatenating all new dictionaries D i to construct dictionary D;

c) applying a kernel method to dictionary D to obtain an embedded dictionary D with a dimension smaller than n; and

d) based on embedded dictionary D, classifying a MDDP in offline processing or a newly arrived MDDP (NAMDDP) in online processing as an anomaly,

whereby the reduction in the plurality of MDDPs from m to m′ enhances performance of a computer including the computer program product for anomaly detection in both processing and storage terms.

2. The computer program product of claim 1 , wherein the non-transitory tangible storage medium is cloud-based, hardware-server based and/or virtual-server based.

3. The computer program product of claim 1 , wherein the data is received from a plurality of data sources.

4. The computer program product of claim 1 , wherein the anomaly is indicative of an undesirable event selected from the group consisting of a financial risk event, a financial threat event, a financial fraud event and a financial network intrusion event.

5. The computer program product of claim 1 , wherein the anomaly detection is used to detect money laundering.

6. A computer system, comprising:

a) a preparation module configured to receive a plurality m of multidimensional data points (MDDPs), each data point having n≥2 features wherein n<<m and wherein the data forms a matrix A with size m×n, matrix A having a rank k≤n, and to apply random projection and neural network (RPNN) processing to matrix A to obtain a dictionary D in the form of a matrix m′×n, wherein m′<m, wherein accordingly dictionary D has fewer MDDPs than matrix A and a lower rank than k,

wherein the configuration of the preparation module to apply RPNN processing to matrix A to obtain dictionary D includes a configuration to run a plurality of iterations i, each iteration i resulting in a new dictionary Di with a respective reduced rank smaller than a rank of an immediately preceding dictionary, to stop running the iterations when the respective reduced rank of dictionary Di does not change from the immediately preceding dictionary rank, and to concatenate all new dictionaries Di to construct dictionary D; and

b) an anomaly detection system including an anomaly detection engine configured to apply a kernel method to dictionary D to obtain an embedded dictionary D with a dimension smaller than n, and, based on embedded dictionary D, to classify a MDDP in offline processing or a newly arrived MDDP (NAMDDP) in online processing as an anomaly,

whereby the reduction in the plurality of MDDPs from m to m′ enhances performance of the computer system for anomaly detection in both processing and storage terms.

7. The computer system of claim 6 , wherein the data is received from a plurality of data sources.

8. The computer system of claim 6 , wherein the anomaly is indicative of an undesirable event selected from the group consisting of a financial risk event, a financial threat event, a financial fraud event and a financial network intrusion event.

9. The computer system of claim 6 , wherein the anomaly detection is used to detect money laundering.

10. A method, comprising:

a) receiving a plurality m of multidimensional data points (MDDPs), each data point having n≥2 features wherein n<<m and wherein the data forms a matrix A with size m×n, matrix A having a rank k≤n;

b) applying random projection and neural network (RPNN) processing to matrix A to obtain a dictionary D in the form of a matrix m′×n, wherein m′<m, wherein accordingly dictionary D has fewer MDDPs than matrix A and a lower rank than k,

wherein the applying RPNN processing includes running a plurality of iterations i, each iteration i resulting in a new dictionary D i with a respective reduced rank smaller than a rank of an immediately preceding dictionary, stopping the running of the plurality of iterations i when the respective reduced rank of dictionary D i does not change from the immediately preceding dictionary rank, and concatenating all new dictionaries D i to construct dictionary D;

c) applying a kernel method to dictionary D to obtain an embedded dictionary D with a dimension smaller than n; and

d) based on embedded dictionary D, classifying a MDDP in offline processing or a newly arrived MDDP (NAMDDP) in online processing as an anomaly,

whereby the reduction in the plurality of MDDPs from m to m′ enhances performance of a computer system for anomaly detection in both processing and storage terms.

11. The method of claim 10 , wherein the data is received from a plurality of data sources.

12. The method of claim 10 , wherein the anomaly is indicative of an undesirable event selected from the group consisting of a financial risk event, a financial threat event, a financial fraud event and a financial network intrusion event.

13. The method of claim 10 , wherein the anomaly detection is used to detect money laundering.

Assignments (3)
SECURITY INTEREST Recorded Jun 25, 2024
From: THETA RAY LTD
To: HSBC BANK PLC
Reel/Frame 067826/0839 →
SECURITY INTEREST Recorded Dec 27, 2022
From: THETA RAY LTD
To: KREOS CAPITAL VI (EXPERT FUND) L.P.
Reel/Frame 062207/0011 →
SECURITY INTEREST Recorded Jun 30, 2021
From: THETARAY LTD.
To: KREOS CAPITAL VI (EXPERT FUND) L.P.
Reel/Frame 056711/0546 →
Cited By (7)
US 12,218,957 US 12,284,087 US 12,309,039 US 12,323,440 US 12,367,282 US 12,443,714 US 12,675,457