IP Library › Granted Patent US 12,517,981
Granted Patent B2
US 12,517,981 · App. 17/590,489 · Granted Jan 6, 2026

Automatic anomaly thresholding for machine learning

Inventor: Lorne Schell (Montreal, CA)
Assignee: ServiceNow, Inc.
G06F18/2155G06F18/217G06F18/2433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,517,981
App. No.
17/590,489
Granted
Jan 6, 2026
Kind
B2
Abstract

A program is provided to automatically train using a training dataset a machine learning model for detecting anomalies. The machine learning model is automatically applied to a validation dataset to determine anomaly detection results. A histogram of the anomaly detection results of the machine learning model is automatically generated. The histogram is automatically analyzed, and a first peak and a second peak of the histogram is automatically identified. A threshold activation of the machine learning model is automatically determined based at least in part on the automatically identified second peak of the histogram.

Claims (42)

1 . A method, comprising:

training a machine learning model for detecting anomalies using a training dataset, wherein the training dataset includes one or more network operations;

applying the trained machine learning model to a validation dataset to determine anomaly detection results based on a normality score for each of the one or more network operations;

generating a histogram reflective of the normality score for each of the one or more network operations included as part of the anomaly detection results of the machine learning model, wherein each of the normality scores of the one or more network operations reflects predicts occurrence of an anomaly with respect to normal operations;

identifying, using one or more processors to automatically analyze the histogram, a first peak reflecting normal operations and a second peak predicts the occurrence of the anomaly;

determining a threshold activation corresponding to one or more network anomalies for the machine learning model based at least in part on the identified second peak of the histogram;

applying the trained machine learning model for detecting anomalies including the threshold activation to generate a predicted normality score for a network operation identified as an anomaly; and

updating training of the trained machine learning model to reflect feedback associated with the anomaly identified based on the predicted normality score.

2 . The method of claim 1 , wherein a predicted score associated with the identified first peak of the histogram is associated with a valid operating status of a network computer environment.

3 . The method of claim 1 , wherein a predicted score associated with the identified second peak of the histogram is associated with an anomalous operating behavior of a network computer environment.

4 . The method of claim 1 , wherein a predicted score associated with the identified second peak of the histogram is less than a predicted score associated with the identified first peak of the histogram.

5 . The method of claim 1 , wherein the generated histogram is multimodal.

6 . The method of claim 1 , wherein the generated histogram has a first mode and a second mode, and wherein the first mode corresponds to the identified first peak of the histogram and the second mode corresponds to the identified second peak of the histogram.

7 . The method of claim 1 , wherein the training dataset includes unlabeled data.

8 . The method of claim 1 , wherein the training dataset includes operating data gathered for at least a month.

9 . The method of claim 1 , wherein the threshold activation of the machine learning model is set to a value less than a predicted score associated with the identified second peak of the histogram.

10 . The method of claim 9 , wherein the value less than the predicted score associated with the identified second peak of the histogram is based on a configured offset value.

11 . The method of claim 10 , wherein the configured offset value is configured using a percentage value.

12 . A system, comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory is configured to provide the one or more processors with instructions which when executed cause the one or more processors to:

train, using a training dataset, a machine learning model for detecting anomalies, wherein the training dataset includes one or more network operations;

apply the trained machine learning model to a validation dataset to determine anomaly detection results based on a normality score for each of the one or more network operations;

generate a histogram reflective of the normality score for each of the one or more network operations included as part of the anomaly detection results of the machine learning model, wherein each of the normality scores of the one or more network operations reflects predicts occurrence of an anomaly with respect to normal operations;

analyze the histogram and automatically identify a first peak reflecting normal operations and a second peak predicts the occurrence of the anomaly; and

determine a threshold activation corresponding to one or more network anomalies for the machine learning model based at least in part on the identified second peak of the histogram;

apply the trained machine learning model for detecting anomalies including the threshold activation to generate a predicted normality score for a network operation identified as an anomaly; and

update the training of the trained machine learning model to reflect feedback associated with the anomaly identified based on the predicted normality score.

13 . The system of claim 12 , wherein a predicted score associated with the identified first peak of the histogram is associated with a valid operating status of a network computer environment.

14 . The system of claim 12 , wherein a predicted score associated with the identified second peak of the histogram is associated with an anomalous operating behavior of a network computer environment.

15 . The system of claim 12 , wherein a predicted score associated with the identified second peak of the histogram is less than a predicted score associated with the identified first peak of the histogram.

16 . The system of claim 12 , wherein the generated histogram has a first mode and a second mode, and wherein the first mode corresponds to the identified first peak of the histogram and the second mode corresponds to the identified second peak of the histogram.

17 . The system of claim 12 , wherein the training dataset includes operating data gathered for at least a month.

18 . The system of claim 12 , wherein the threshold activation of the machine learning model is set to a value less than a predicted score associated with the identified second peak of the histogram.

19 . A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

training, using a training dataset, a machine learning model for detecting anomalies, wherein the training dataset includes one or more network operations;

applying the trained machine learning model to a validation dataset to determine anomaly detection results based on a normality score for each of the one or more network operations;

generating a histogram reflective of the normality score for each of the one or more network operations included as part of the anomaly detection results of the machine learning model, wherein each of the normality scores of the one or more network operations reflects predicts occurrence of an anomaly with respect to normal operations;

analyzing the histogram and automatically identifying a first peak reflecting normal operations and a second peak predicts the occurrence of the anomaly;

determining a threshold activation corresponding to one or more network anomalies for the machine learning model based at least in part on the identified second peak of the histogram;

apply the trained machine learning model for detecting anomalies including the threshold activation to generate a predicted normality score for a network operation identified as an anomaly; and

update the training of the trained machine learning model to reflect feedback associated with the anomaly identified based on the predicted normality score.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2022
From: SCHELL, LORNE
To: SERVICENOW, INC.
Reel/Frame 060154/0905 →
Continuity (1)
Related Publication 20230244754A1 · Aug 3, 2023
References Cited (4)
US 20190130659A1 · Ide · 2019 [cited by examiner]
US 20210026722A1 · Bhatia · 2021 [cited by examiner]
US 20210342586A1 · Fleisig · 2021 [cited by examiner]
US 20220391724A1 · Yoon · 2022 [cited by examiner]