IP Library › Granted Patent US 12,541,587
Granted Patent B2
US 12,541,587 · App. 18/112,225 · Granted Feb 3, 2026

Addressing structured false positives during asset anomaly detection

Inventors: Bo-Yu Kuo (Kaohsiung, TW); Yu-Jin Chen (New Taipei, TW); Yu-Chi Tang (New Taipei, TW); Shih Hsuan Lee (Zhuangwei, TW)
Assignee: International Business Machines Corporation
G06F21/552G06N3/0442G06N3/08G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,541,587
App. No.
18/112,225
Granted
Feb 3, 2026
Kind
B2
Abstract

Techniques are described with regard to addressing structured false positives in the context of detecting asset anomalies in a computing environment. An associated computer-implemented method includes applying an anomaly detection machine learning model to each of a plurality of assets in order to determine a plurality of anomaly assets among the plurality of assets. The plurality of anomaly assets are determined based upon a model anomaly risk score calculated for each of the plurality of assets consequent to asset event data analysis. The method further includes calculating a structured false positive score for each of the plurality of anomaly assets during a current structured false positive time window. The method further includes retraining the anomaly detection machine learning model responsive to determining that a threshold value of anomaly assets among the plurality of anomaly assets have a structured false positive score exceeding a structured false positive threshold value.

Claims (51)

1 . A computer-implemented method comprising:

applying an anomaly detection machine learning model to each of a plurality of assets in a computing environment in order to determine a plurality of anomaly assets among the plurality of assets based upon a model anomaly risk score calculated for each of the plurality of assets consequent to asset event data analysis;

calculating a structured false positive score for each of the plurality of anomaly assets during a current structured false positive time window;

calculating a total anomaly risk score for each of the plurality of anomaly assets by deducting the structured false positive score calculated for each of the plurality of anomaly assets from the model anomaly risk score calculated for each of the plurality of anomaly assets; and

retraining the anomaly detection machine learning model responsive to determining that a threshold value of anomaly assets among the plurality of anomaly assets have a structured false positive score exceeding a structured false positive threshold value.

2 . The computer-implemented method of claim 1 , further comprising:

responsive to user input, providing a model retraining summary via at least one user application interface, wherein the model retraining summary includes structured false positive data and a listing of anomaly assets among the plurality of anomaly assets having a structured false positive score calculated during the current structured false positive time window that exceeds the structured false positive threshold value.

3 . The computer-implemented method of claim 1 , wherein configuring the anomaly detection machine learning model comprises:

parsing respective behavioral attributes from event data associated with one or more of the plurality of assets; and

training the anomaly detection machine learning model by applying at least one classification algorithm to derive associations between the respective behavioral attributes and each of a plurality of asset types.

4 . The computer-implemented method of claim 3 , wherein configuring the anomaly detection machine learning model further comprises:

training the anomaly detection machine learning model in conjunction with a long short-term memory recurrent neural network (LSTM-RNN) architecture configured to store time series pattern data with respect to one or more of the plurality of assets.

5 . The computer-implemented method of claim 1 , wherein applying the anomaly detection machine learning model to each of the plurality of assets comprises:

predicting for the asset an asset type among a plurality of asset types based upon analyzing event data associated with the asset in view of model-derived associations between respective behavioral attributes and each of the plurality of asset types;

calculating, via the anomaly detection machine learning model, the model anomaly risk score for the asset based upon a normalized probability ratio value associated with a correct model prediction of the asset type for the asset; and

identifying the asset as an anomaly asset responsive to determining that the model anomaly risk score calculated for the asset exceeds a model anomaly risk threshold value.

6 . The computer-implemented method of claim 5 , wherein the normalized probability ratio value is a normalized ratio of a probability value associated with a correct model prediction of the asset type for the asset to a maximum probability value among a set of probability values associated with correct asset type model prediction.

7 . The computer-implemented method of claim 1 , wherein calculating the structured false positive score for each of the plurality of anomaly assets during the current structured false positive time window comprises:

averaging a structured false positive score for the anomaly asset during a time window immediately preceding the current structured false positive time window with a calculated difference between an asset type abnormal ratio value and a curve deviation value.

8 . The computer-implemented method of claim 7 , wherein the asset type abnormal ratio value is a ratio of a number of anomaly assets among the plurality of anomaly assets associated with an asset type of the anomaly asset to a total number of assets of the asset type among the plurality of assets.

9 . The computer-implemented method of claim 1 , wherein retraining the anomaly detection machine learning model comprises:

analyzing event data respectively related to each anomaly asset among the plurality of anomaly assets having a structured false positive score calculated during the current structured false positive time window that exceeds the structured false positive threshold value; and

refining model-derived associations between respective behavioral attributes and each of a plurality of asset types by expanding a behavioral attribute range associated with one or more of the plurality of asset types.

10 . A computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a computing device to cause the computing device to:

apply an anomaly detection machine learning model to each of a plurality of assets in a computing environment in order to determine a plurality of anomaly assets among the plurality of assets based upon a model anomaly risk score calculated for each of the plurality of assets consequent to asset event data analysis;

calculate a structured false positive score for each of the plurality of anomaly assets during a current structured false positive time window;

calculate a total anomaly risk score for each of the plurality of anomaly assets by deducting the structured false positive score calculated for each of the plurality of anomaly assets from the model anomaly risk score calculated for each of the plurality of anomaly assets; and

retrain the anomaly detection machine learning model responsive to determining that a threshold value of anomaly assets among the plurality of anomaly assets have a structured false positive score exceeding a structured false positive threshold value.

11 . The computer program product of claim 10 , wherein the program instructions further cause the computing device to:

responsive to user input, provide a model retraining summary via at least one user application interface, wherein the model retraining summary includes structured false positive data and a listing of anomaly assets among the plurality of anomaly assets having a structured false positive score calculated during the current structured false positive time window that exceeds the structured false positive threshold value.

12 . The computer program product of claim 10 , wherein configuring the anomaly detection machine learning model comprises:

parsing respective behavioral attributes from event data associated with one or more of the plurality of assets; and

training the anomaly detection machine learning model by applying at least one classification algorithm to derive associations between the respective behavioral attributes and each of a plurality of asset types.

13 . The computer program product of claim 10 , wherein retraining the anomaly detection machine learning model comprises:

analyzing event data respectively related to each anomaly asset among the plurality of anomaly assets having a structured false positive score calculated during the current structured false positive time window that exceeds the structured false positive threshold value; and

refining model-derived associations between respective behavioral attributes and each of a plurality of asset types by expanding a behavioral attribute range associated with one or more of the plurality of asset types.

14 . A system comprising:

at least one processor; and

a memory storing an application program, which, when executed on the at least one processor, performs an operation comprising:

applying an anomaly detection machine learning model to each of a plurality of assets in a computing environment in order to determine a plurality of anomaly assets among the plurality of assets based upon a model anomaly risk score calculated for each of the plurality of assets consequent to asset event data analysis;

calculating a structured false positive score for each of the plurality of anomaly assets during a current structured false positive time window;

calculating a total anomaly risk score for each of the plurality of anomaly assets by deducting the structured false positive score calculated for each of the plurality of anomaly assets from the model anomaly risk score calculated for each of the plurality of anomaly assets; and

retraining the anomaly detection machine learning model responsive to determining that a threshold value of anomaly assets among the plurality of anomaly assets have a structured false positive score exceeding a structured false positive threshold value.

15 . The system of claim 14 , wherein the operation further comprises:

responsive to user input, providing a model retraining summary via at least one user application interface, wherein the model retraining summary includes structured false positive data and a listing of anomaly assets among the plurality of anomaly assets having a structured false positive score calculated during the current structured false positive time window that exceeds the structured false positive threshold value.

16 . The system of claim 14 , wherein configuring the anomaly detection machine

parsing respective behavioral attributes from event data associated with one or more of the plurality of assets; and

training the anomaly detection machine learning model by applying at least one classification algorithm to derive associations between the respective behavioral attributes and each of a plurality of asset types.

17 . The system of claim 14 , wherein retraining the anomaly detection machine learning model comprises:

analyzing event data respectively related to each anomaly asset among the plurality of anomaly assets having a structured false positive score calculated during the current structured false positive time window that exceeds the structured false positive threshold value; and

refining model-derived associations between respective behavioral attributes and each of a plurality of asset types by expanding a behavioral attribute range associated with one or more of the plurality of asset types.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2023
From: KUO, BO-YU; CHEN, YU-JIN; TANG, YU-CHI; LEE, SHIH HSUAN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 062756/0353 →
Continuity (1)
Related Publication 20240281522A1 · Aug 22, 2024
References Cited (10)
US 9817884B2 · Greifeneder et al. · 2017 [cited by applicant]
US 10187403B2 · Gopalakrishnan et al. · 2019 [cited by applicant]
US 10931692B1 · Mota et al. · 2021 [cited by applicant]
US 20150128263A1 · Raugas · 2015 [cited by examiner]
US 20180337836A1 · Balabine et al. · 2018 [cited by applicant]
US 20210051165A1 · Sarfraz et al. · 2021 [cited by applicant]
US 20210073060A1 · Grant · 2021 [cited by examiner]
US 20220060491A1 · Achleitner · 2022 [cited by examiner]
Grill, Martin et al. Reducing false positives of network anomaly detection by local adaptive multivariate smoothing. Journal of Computer and System Sciences, vol. 83 Issue 1, Feb. 2017, pp. 43-57, Elsevier Science Direc… [cited by applicant]
Al Jallad, Khloud et al. Anomaly detection optimization using big data and deep learning to reduce false-positive. Journal of Big Data, vol. 7, Article No. 68, Aug. 31, 2020, pp. 1-12, Springer Open. <https://journalofb… [cited by applicant]