IP Library › Granted Patent US 12,518,103
Granted Patent B2
US 12,518,103 · App. 18/188,677 · Granted Jan 6, 2026

Method and apparatus for anomaly detection

Inventors: Péter Szilágyi (Budapest, HU); Gabor Horvath (Budapest, HU); Attila Kadar (Budapest, HU)
Assignee: Nokia Solutions and Networks Oy
G06F40/30G06F11/0766G06F11/0793G06F11/3476G06F16/35G06F40/284
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,518,103
App. No.
18/188,677
Granted
Jan 6, 2026
Kind
B2
Abstract

An apparatus for anomaly detection, the apparatus comprising means for: Collecting a plurality of log messages from a data processing system, log messages comprising textual content and numeric attributes, Classifying the plurality of log messages into a plurality of clusters as a function of a number of the numeric attributes in the log messages, such that the log messages within a cluster have a given number of the numeric attributes, For at least one of the clusters, computing at least one encoding vector associated to a numeric attribute, Computing a combined semantic embedding vector from the textual contents of the plurality of log messages, Combining the at least one encoding vector with the combined semantic embedding vector into a final encoding vector, and Feeding the final encoding vector to an anomaly detection module intended to detect an anomaly in the data processing system.

Claims (50)

1 . An apparatus to detect anomalies, the apparatus comprising:

an anomaly detection module;

at least one processor; and

at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform,

collecting a plurality of log messages from a data processing system, the plurality of log messages reporting events that occur as the data processing system operates, the plurality of log messages comprising textual content and numeric attributes;

classifying the plurality of log messages into a plurality of clusters as a first function of a number of the numeric attributes in the plurality of log messages, such that the plurality of log messages within a cluster have a given number of the numeric attributes;

for at least one of the clusters, computing at least one encoding vector associated to a numeric attribute, wherein the at least one encoding vector is computed as a second function of a representative value of the numeric attribute across the plurality of log messages within the cluster and of a rank of the numeric attribute, wherein the rank is representative of an order of the numeric attribute within the given number of the numeric attributes of the plurality of log messages within the cluster;

computing a combined semantic embedding vector from textual contents of the plurality of log messages;

combining the at least one encoding vector with the combined semantic embedding vector into a final encoding vector; and

feeding the final encoding vector to the anomaly detection module configured to detect an anomaly in the data processing system.

2 . The apparatus according to claim 1 , wherein the apparatus is further caused to perform:

computing the at least one encoding vector associated to the numeric attribute for the plurality of clusters.

3 . The apparatus according to claim 1 , wherein the apparatus is further caused to perform:

computing a plurality of encoding vectors associated to a plurality of the numeric attributes for the at least one of the clusters.

4 . The apparatus according to claim 3 , wherein the apparatus is further caused to perform:

combining the plurality of encoding vectors with the combined semantic embedding vector into the final encoding vector.

5 . The apparatus according to claim 1 , wherein the apparatus is further caused to perform:

computing at least one additional numeric attribute from the plurality of log messages of the at least one of the clusters;

appending the at least one additional numeric attribute to the numeric attributes within the at least one of the clusters; and

increasing the given number of the numeric attributes of the plurality of log messages within the cluster.

6 . The apparatus according to claim 1 , wherein the apparatus is further caused to compute the plurality of clusters as a third function of the textual contents in the plurality of log messages.

7 . The apparatus according to claim 1 , wherein the apparatus is further caused to perform:

computing a plurality of semantic embedding vectors from the textual contents; and

combining the plurality of semantic embedding vectors into the combined semantic embedding vector.

8 . The apparatus according to claim 1 , wherein the apparatus is further caused to convert a plurality of average values into high dimensional polar coordinates.

9 . The apparatus according to claim 1 , wherein the apparatus is further caused to,

compute an intermediate encoding vector from the representative value of the numeric attribute;

select a projection vector within a basis of orthogonal vectors as a third function of the rank of the numeric attribute; and

compute the at least one encoding vector by projecting the intermediate encoding vector on the projection vector.

10 . The apparatus according to claim 1 , wherein the apparatus is further caused to,

compute a transitional encoding vector from the representative value of the numeric attribute; and

multiply at least one coordinate of the transitional encoding vector by a factor depending on an index of the at least one coordinate and the rank of the numeric attribute.

11 . The apparatus according to claim 1 , wherein the apparatus is further caused to perform:

returning an anomaly detection signal to the data processing system in order to cause a corrective action in the data processing system, the anomaly detection signal being computed by the anomaly detection module.

12 . The apparatus according to claim 1 , wherein the anomaly detection module is an autoencoder.

13 . The apparatus according to claim 12 , wherein the apparatus is further caused to perform:

receiving a reconstruction loss computed by the autoencoder; and

classifying a value of the reconstruction loss higher than an anomaly threshold as an anomaly.

14 . The apparatus according to claim 1 , wherein the apparatus is further caused to perform:

training the anomaly detection module using a plurality of training encoding vectors, the plurality of training encoding vectors being computed from a training dataset of log messages.

15 . A method of operating an apparatus for anomaly detection, the method comprising:

collecting a plurality of log messages from a data processing system, the plurality of log messages reporting events that occur as the data processing system operates, the plurality of log messages comprising textual content and numeric attributes;

classifying the plurality of log messages into a plurality of clusters as a first function of a number of the numeric attributes in the plurality of log messages, such that the plurality of log messages within a cluster have a given number of the numeric attributes;

for at least one of the clusters, computing at least one encoding vector associated to a numeric attribute, wherein the at least one encoding vector is computed as a second function of a representative value of the numeric attribute across the plurality of log messages within the cluster and of a rank of the numeric attribute, wherein the rank is representative of an order of the numeric attribute within the given number of the numeric attributes of the plurality of log messages within the cluster;

computing a combined semantic embedding vector from textual contents of the plurality of log messages;

combining the at least one encoding vector with the combined semantic embedding vector into a final encoding vector; and

feeding the final encoding vector to an anomaly detection module of the apparatus, the anomaly detection module configured to detect an anomaly in the data processing system.

16 . The method according to claim 15 , further comprising returning an anomaly detection signal representing the anomaly.

17 . The method according to claim 16 , further comprising performing corrective action as a third function of the anomaly detection signal.

18 . The method according to claim 17 , wherein the corrective action is performed in the data processing system.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2023
From: SZILÁGYI, PÉTER
To: NOKIA SOLUTIONS AND NETWORKS KFT.
Reel/Frame 063251/0743 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2023
From: NOKIA SOLUTIONS AND NETWORKS KFT.
To: NOKIA SOLUTIONS AND NETWORKS OY
Reel/Frame 063251/0770 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2023
From: BUDAPEST UNIVERSITY OF TECHNOLOGY AND ECONOMICS
To: NOKIA SOLUTIONS AND NETWORKS OY
Reel/Frame 063251/0822 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2023
From: HORVATH, GABOR; KADAR, ATTILA
To: BUDAPEST UNIVERSITY OF TECHNOLOGY AND ECONOMICS
Reel/Frame 063251/0832 →
Priority Claims (1)
EP 22178500 · Jun 10, 2022 · regional
Continuity (1)
Related Publication 20230412627A1 · Dec 21, 2023
References Cited (19)
US 11860756B2 · Yeddu · 2024 [cited by examiner]
US 12026046B2 · Friedrich · 2024 [cited by examiner]
US 20190050747A1 · Nakamura et al. · 2019 [cited by applicant]
US 20190149565A1 · Hagi et al. · 2019 [cited by applicant]
US 20190303727A1 · Foroughi · 2019 [cited by examiner]
US 20200159826A1 · Lev Tov · 2020 [cited by examiner]
US 20200382536A1 · Dherange et al. · 2020 [cited by applicant]
US 20210174253A1 · Moore et al. · 2021 [cited by applicant]
US 20220019914A1 · James et al. · 2022 [cited by applicant]
US 20230137235A1 · Chen · 2023 [cited by examiner]
US 20230177380A1 · Bansal · 2023 [cited by examiner]
US 20250028752A1 · Lauber · 2025 [cited by examiner]
CN 114118295A · 2022 [cited by applicant]
“Zero-touch network and Service Management (ZSM); Reference Architecture”, ETSI GS ZSM 002, V1.1.1, Aug. 2019, pp. 1-80. [cited by applicant]
Sundararaman et al., “Methods for Numeracy-Preserving Word Embeddings”, Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP), Nov. 16-20, 2020, pp. 4742-4753. [cited by applicant]
“BERT language model”, Tech Target, Mar. 7, 2022, Webpage archive available at :http://web.archive.org/web/20220307180514/https://www.techtarget.com/searchenterpriseal/definition/BERT-language-model. [cited by applicant]
Kim et al., “Intrusion Detection Based on Sequential Information Preserving Log Embedding Methods and Anomaly Detection Algorithms”, IEEE Access, vol. 9, Apr. 8, 2021, pp. 58088-58101. [cited by applicant]
Extended European Search Report received for corresponding European Patent Application No. 22178500.9, dated Jan. 10, 2023, 8 pages. [cited by applicant]
Kim et al., “seq2vec: Analyzing sequential data using multi-rank embedding vectors”, Electronic Commerce Research and Applications, vol. 43, Sep.-Oct. 2020, pp. 1-15. [cited by applicant]