IP Library Granted Patent US 12,373,683
Granted Patent B2
US 12,373,683 · App. 16/881,770 · Granted Jul 29, 2025

Anomaly detection according to a multi-model analysis

Inventor: Faris Muhammad (Edgware, GB)
Assignee: VIAVI Solutions Inc.
G06N3/08G06N3/045
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,373,683
App. No.
16/881,770
Granted
Jul 29, 2025
Kind
B2
Abstract

An anomaly detection system may train a first model associated with detecting anomalies involving a log source based on first historical logs associated with the log source and may train a second model associated with the log source based on second historical logs associated with the log source and target data that are associated with the second historical logs. The anomaly detection system may cause the first model to process the second historical logs to generate training anomaly data of the log source. The anomaly detection system may train a third model associated with the log source based on the training anomaly data and the target data. The anomaly detection system may configure, based on outputs from the second model and the third model, an anomaly detection model to detect the anomalies in input data that are provided to the first model and the second model.

Claims (111)

1. A method, comprising:

training, by a device, a first model of a plurality of first models of a first layer of a model matrix,

wherein the first model is associated with detecting anomalies involving a log source,

wherein the first model is a first neural network,

wherein the first model is trained using historical true logs, and

wherein the historical true logs do not include anomalies;

causing, by the device and after training the first model using the historical true logs, the first model to process historical false logs to generate training anomaly data of the log source,

wherein the historical false logs include anomalies:

training, by the device, a second model of a plurality of second models of a second layer of the model matrix,

wherein the second model is associated with the log source,

wherein the second model is a second neural network,

wherein the second model is trained based on the historical false logs and based on target data associated with the historical false logs, and

wherein the target data identifies one or more detected anomalies within the historical false logs;

training, by the device, a third model of a plurality of third models of the model matrix,

wherein the third model is associated with the log source, and

wherein the third model is trained based on the training anomaly data and based on the target data;

configuring, by the device and based on outputs from the second model and the third model, an anomaly detection model, of the model matrix, to detect anomalies in input data provided to the first model and the second model; and

retraining, by the device and based on feedback regarding accuracy, the anomaly detection model and one or more of the plurality of first models, the plurality of second models, or the plurality of third models.

2. The method of claim 1 , wherein, at least one of:

the third model is a different type of model from the first model, or

the third model is a different type of model from the second model.

3. The method of claim 1 , wherein the third model is an association matrix.

4. The method of claim 1 , wherein the log source comprises a data structure configured to maintain logs associated with events involving at least one of:

a particular device,

a particular application, or

a particular network.

5. The method of claim 1 , further comprising:

expanding the model matrix to include one or more additional layers.

6. The method of claim 1 , wherein the model matrix is scalable horizontally or vertically.

7. The method of claim 1 , wherein retraining the anomaly detection model and one or more of the plurality of first models, the plurality of second models, or the plurality of third models comprises:

retraining, based on the feedback regarding accuracy, the plurality of first models, the plurality of second models, the plurality of third models, and the anomaly detection model.

8. The method of claim 1 , further comprising:

tuning, using one or more hyperparameters, one or more of the first model, the second model, or the third model.

9. A device, comprising:

one or more memories; and

one or more processors, communicatively coupled to the one or more memories, configured to:

train, using historical true logs that do not include anomalies, a first model of a plurality of first models,

wherein the first model is associated with a first log source, and

wherein the first model is a first neural network;

cause, after the first model is trained using the historical true logs, the first model to process historical false logs to generate first training anomaly data of the first log source,

wherein the historical false logs include anomalies:

train, based on the historical false logs, a second model of a plurality of second models,

wherein the second model is associated with the first log source or a second log source, and

wherein the second model is a second neural network;

train, based on the first training anomaly data, a third model of a plurality of third models;

configure, based on outputs from the second model and the third model, an anomaly detection model to detect anomalies in input data provided to the first model and the second model; and

retrain, based on feedback regarding accuracy, the anomaly detection model and one or more of the plurality of first models, the plurality of second models, or the plurality of third models.

10. The device of claim 9 , wherein the second model is associated with the first log source,

wherein the one or more processors are further configured to:

train, based on first historical logs associated with the second log source, a fourth model associated with the second log source; and

train, based on second historical logs associated with the second log source, a fifth model associated with the second log source,

wherein the first historical logs do not include anomalies, and

wherein the second historical logs include anomalies.

11. The device of claim 9 , wherein, to train the second model, the one or more processors are configured to train the second model based on the historical false logs and based on target data, and

wherein the target data identifies one or more previously detected anomalies within the historical false logs.

12. The device of claim 9 , wherein the second model is associated with the first log source,

wherein the one or more processors are further configured to:

train, based on first historical logs associated with the second log source, a fourth model;

train, based on second historical logs associated with the second log source, a fifth model;

cause the fourth model to process the second historical logs to generate second training anomaly data of the second log source; and

train, based on the second training anomaly data, a sixth model associated with the second log source,

wherein the anomaly detection model is configured to detect the anomalies in the input data based on outputs from the second model, the third model, the fifth model, and the sixth model, and

wherein the first model is a same type of model as the fourth model, the second model is a same type of model as the fifth model, and the third model is a same type of model as the sixth model.

13. The device of claim 9 , wherein the second model is associated with the first log source,

wherein the one or more processors are further configured to:

train, based on first historical logs associated with the second log source, a fourth model;

train, based on second historical logs associated with the second log source, a fifth model;

cause the fourth model to process the second historical logs to generate second training anomaly data of the second log source; and

train, based on the second training anomaly data, a sixth model associated with the second log source,

wherein the anomaly detection model is configured to detect the anomalies in the input data based on outputs from the second model, the third model, the fifth model, and the sixth model, and

wherein the fourth model and the fifth model are individual neural networks.

14. The device of claim 9 , wherein the second model is associated with the first log source,

wherein the one or more processors are further configured to:

train, based on first historical logs associated with the second log source, a fourth model;

train, based on second historical logs associated with the second log source, a fifth model;

cause the fourth model to process the second historical logs to generate second training anomaly data of the second log source; and

train, based on the second training anomaly data, a sixth model associated with the second log source,

wherein the anomaly detection model is configured to detect the anomalies in the input data based on outputs from the second model, the third model, the fifth model, and the sixth model, and

wherein the third model and sixth model are association matrices.

15. The device of claim 9 , wherein the first log source and the second log source are configured to maintain individual logs associated with an event involving at least one of:

a particular device,

a particular application, or

a particular network.

16. A non-transitory computer-readable medium storing instructions, the instructions comprising:

one or more instructions that, when executed by one or more processors, cause the one or more processors to:

train, using historical true logs that do not include anomalies, a first model of a plurality of first models,

wherein the first model is a first neural network;

cause, after the first model is trained using the historical true logs, the first model to process historical false logs to generate training anomaly data,

wherein the historical false logs include anomalies:

train, based on the historical false logs, a second model of a plurality of second models,

wherein the second model is a second neural network;

train, based on the training anomaly data, a third model of a plurality of third models;

configure an anomaly detection model based on one or more of the first model, the second model, or the third model; and

retrain, based on feedback regarding accuracy, the anomaly detection model and one or more of the plurality of first models, the plurality of second models, or the plurality of third models.

17. The non-transitory computer-readable medium of claim 16 , wherein the one or more instructions, that cause the one or more processors to train the second model, cause the one or more processors to:

train the second model based on the historical false logs and based on target data that identifies one or more previously detected anomalies within the historical false logs.

18. The non-transitory computer-readable medium of claim 16 , wherein the first neural network and the second neural network are individually trained recurrent neural networks.

19. The non-transitory computer-readable medium of claim 16 , wherein the one or more instructions further cause the one or more processors to:

receive log data associated with a log source;

identify a log of the log data;

process, via the first model, the log data to determine first anomaly data in the log data;

process, via the second model, the log data to determine a first probability that the log data include an anomaly;

process, via the third model, the first anomaly data to determine a second probability that the log data include an anomaly; and

determine, based on the first probability satisfying a threshold and the second probability satisfying the threshold, that the log is associated with an anomaly.

20. The non-transitory computer-readable medium of claim 16 , wherein the one or more instructions further cause the one or more processors to:

process, via the first model, log data to determine first anomaly data in the log data;

process, via the second model, the log data to determine a first probability that the log data include an anomaly;

process, via the third model, the first anomaly data to determine a second probability that the log data include an anomaly;

indicate, via a user interface and based on the first probability satisfying a threshold and the second probability satisfying the threshold, that a log of the log data is likely associated with an anomaly;

receive, from the user interface, a training response associated with the log including an anomaly; and

retrain, based on the training response, at least one of the first model, the second model, or the third model.

Assignments (5)
RELEASE OF SECURITY INTEREST AT REEL/FRAME 73189/0873 Recorded May 28, 2026
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: INERTIAL LABS, INC.; VIAVI SOLUTIONS INC.; VIAVI SOLUTIONS LICENSING LLC
Reel/Frame 075642/0381 →
SECURITY INTEREST Recorded Nov 14, 2025
From: VIAVI SOLUTIONS INC.; VIAVI SOLUTIONS LICENSING LLC; INERTIAL LABS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS AGENT
Reel/Frame 073571/0137 →
SECURITY AGREEMENT Recorded Oct 21, 2025
From: INERTIAL LABS, INC.; VIAVI SOLUTIONS INC.; VIAVI SOLUTIONS LICENSING LLC
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 073189/0873 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2022
From: VIAVI SOLUTIONS UK LTD.
To: VIAVI SOLUTIONS LICENSING LLC
Reel/Frame 060720/0093 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2020
From: MUHAMMAD, FARIS
To: VIAVI SOLUTIONS INC.
Reel/Frame 052743/0593 →
Continuity (1)
Related Publication 20210365774A1 · Nov 25, 2021
References Cited (23)
US 11038775B2 · Pandey · 2021 [cited by examiner]
US 12056579B1 · Mattar · 2024 [cited by examiner]
US 20150100524A1 · Pantel · 2015 [cited by examiner]
US 20180219889A1 · Oliner et al. · 2018 [cited by applicant]
US 20210281592A1 · Givental · 2021 [cited by examiner]
WO WO2021118526A1 · 2021 [cited by examiner]
Gadal, S. M. A. M., & Mokhtar, R. A. (Jan. 2017). Anomaly detection approach using hybrid algorithm of data mining technique. In 2017 International Conference on Communication, Control, Computing and Electronics Enginee… [cited by examiner]
Hill, D. J., & Minsker, B. S. (2010). Anomaly detection in streaming environmental sensor data: A data-driven modeling approach. Environmental Modelling & Software, 25(9), 1014-1022. (Year: 2010). [cited by examiner]
Extended European Search Report for Application No. EP21174339.8, mailed on Mar. 30, 2022, 11 pages. [cited by applicant]
Kruegel et al., “A Multi-model Approach to the Detection of Web-based Attacks,” Computer Networks, Elsevier, Aug. 5, 2005, vol. 48 (5), pp. 717-738. [cited by applicant]
Xia et al., “Ensemble Methods for Anomaly Detection Based on System Log,” IEEE 2019 24th Pacific Rim International Symposium on Dependable Computing (PRDC), Dec. 1, 2019, pp. 930-931. [cited by applicant]
M. Du, F. Li, G. Zheng and V. Srikumar, “DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep Learning,” the 2017 ACM SIGSAC Conference, 2017. [cited by applicant]
Q. Fu, J.-G. Lou, Y. Wang and J. Li, “Execution Anomaly Detection in Distributed Systems through Unstructured Log Analysis,” International Conference on Data Mining (ICDM), No. IEEE, pp. 149-158, 2009. [cited by applicant]
S. He, . J. Zhu, P. He and M. R. Lyu, “Experience Report: System Log Analysis for Anomaly Detection,” No. IEEE, 2016. [cited by applicant]
P. Kostjens, “Anomaly Detection in Application Log Data,” 2018. [cited by applicant]
J.-G. Lou, Q. Fu, S. Yang, Y. Xu and J. Li, “Mining Invariants from Console Logs for System Problem Detection,” 2010. [cited by applicant]
S. Lu, X. Wei, Y. Li and L. Wang, “Detecting Anomaly in Big Data System Logs Using Convolutional Neural Network,” 2018 IEEE 16th Intl Conf on Dependable, Autonomic and Secure Computing, 16th Intl Conf on Pervasive Intel… [cited by applicant]
J. Shi, G. He and X. Liu, “Anomaly Detection for Key Performance Indicators Through Machine Learning,” 2018 International Conference on Network Infrastructure and Digital Content (IC-NIDC), 2018. [cited by applicant]
M. Wang, L. Xu and L. Guo, “Anomaly Detection of System Logs Based on Natural Language Processing and Deep Learning,” 2018 4th International Conference on Frontiers of Signal Processing (ICFSP), No. IEEE, 2018. [cited by applicant]
W. Xu, L. Huang, A. Fox, D. Patterson and M. Jordan, “Online system problem detection by mining patterns of console logs,” 2009 Ninth IEEE International Conference on Data Mining, No. IEEE, 2009. [cited by applicant]
K. Zhang, J. Xu, M. R. Min, G. Jiang, K. Pelechrinis and H. Zhang, “Automated IT system failure prediction: A deep learning approach,” 2016 IEEE International Conference on Big Data (Big Data), No. IEEE, 2016. [cited by applicant]
J. Ngiam, A. Khosla, M. Kim, J. Nam, H. Lee and A. Y. Ng, “Multimodal Deep Learning”, 2011. [cited by applicant]
“Anomaly Detection from System Tracing Data using Multimodel Deep Learning,” 12th International Conference on Cloud Computing (CLOUD), No. IEEE, pp. 179-186, 2019. [cited by applicant]
Cited By (2)
US 12,613,761 US 12,682,222