IP Library Granted Patent US 12,574,397
Granted Patent B2
US 12,574,397 · App. 18/192,812 · Granted Mar 10, 2026

Detecting and mitigating system anomalies using knowledge graphs

Inventors: Bhavna Agrawal (Armonk, NY); Robert Jeffrey Baseman (Brewster, NY); Jeffrey Owen Kephart (Cortlandt Manor, NY); Anuradha Bhamidipaty (Yorktown Heights, NY); Elham Khabiri (Briarcliff Manor, NY); Yingjie Li (Chappaqua, NY); Srideepika Jayaraman (White Plains, NY)
Assignee: International Business Machines Corporation
H04L63/1425H04L41/0631H04L41/065H04L41/16H04L43/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,574,397
App. No.
18/192,812
Granted
Mar 10, 2026
Kind
B2
Abstract

Detecting and mitigating anomalous system behavior by providing a machine learning model comprising a knowledge graph depicting system entity relationships, and modeling behavioral correlations among system entities according to historical time-series data, receiving real-time time-series data for the system, detecting an anomalous system behavior in a system locale, according to the real-time time-series data, according to the machine learning model and multivariate sensor metrics, diagnosing the anomalous system behavior according to an upstream portion of the knowledge graph and a statistical behavior model for the system locale, and mitigating the anomalous behavior by deriving a recommended action according to the anomalous behavior and generating a work order to implement the recommended action.

Claims (62)

1 . A computer implemented method comprising:

providing a machine learning model comprising a knowledge graph depicting system entity relationships, and modeling behavioral correlations among system entities according to historical time-series data;

receiving real-time time-series data for the system according to monitoring frequencies;

detecting an anomalous system behavior in a system locale, according to the real-time time-series data, the machine learning model, monitoring thresholds and multivariate sensor metrics;

adjusting the monitoring thresholds, and the monitoring frequencies, according to the system locale, the knowledge graph and the anomalous system behavior;

diagnosing the anomalous system behavior according to an upstream portion of the knowledge graph and a statistical behavior model for the system locale;

deriving a recommended action according to the anomalous system behavior; and

generating a work order to implement the recommended action.

2 . The computer implemented method according to claim 1 , wherein providing a machine learning model comprising a knowledge graph depicting system entity relationships, and modeling behavioral correlations among system entities according to historical time-series data comprises:

receiving a representation of physical or logical connectivity of the system and historical time series data recorded by sensors of the system;

deriving from at least one of the knowledge graph and historical time series data, a multi-variate statistical model of system-level behavior anomalies; and

deriving from the multi-variate statistical model an indicative set of conditions on multi-variate aggregations of sensors that indicate anomalous behavior.

3 . The computer implemented method according to claim 2 , further comprising:

receiving a prescription for or computing salient sub-graphs and applying it to the knowledge graph to produce a set of one or more salient sub-graphs;

deriving from at least one of the salient sub-graphs and historical time series data, a second multi-variate statistical model of system-level behavior anomalies; and

deriving from the second multi-variate statistical model an indicative set of conditions on multi-variate aggregations of sensors that indicate anomalous behavior.

4 . The computer implemented method according to claim 2 , wherein deriving from at least one of the knowledge graph and historical time series data, a multi-variate statistical model of system-level behavior anomalies comprises limiting the knowledge graph to a set of nodes defined by a maximum inter-node distance from each other.

5 . The computer implemented method according to claim 2 , wherein deriving a multi-variate statistical model comprises inferring causation from directed edges of the knowledge graph.

6 . The computer implemented method according to claim 2 , wherein deriving a multi-variate statistical model comprises encoding a portion of nodes of the knowledge graph as an intermediate representation.

7 . The computer implemented method according to claim 2 , wherein deriving a multi-variate statistical model comprises inferring a Bayes net from the knowledge graph.

8 . The computer implemented method according to claim 1 , further comprising altering an anomalous behavior threshold for a system node selected from a group consisting of nodes upstream of the system locale, nodes downstream of the system locale, and combinations thereof.

9 . A computer program product comprising one or more computer readable storage media and collectively stored program instructions on the one or more computer readable storage media, the stored program instructions which, when executed, cause one or more processors to:

provide a machine learning model comprising a knowledge graph depicting system entity relationships, and modeling behavioral correlations among system entities according to historical time-series data;

receive real-time time-series data for the system according to monitoring frequencies;

detect an anomalous system behavior in a system locale, according to the real-time time-series data, the machine learning model, monitoring thresholds, and multivariate sensor metrics;

adjusting the monitoring thresholds, and the monitoring frequencies, according to the system locale, knowledge graph and the anomalous system behavior;

diagnose the anomalous system behavior according to an upstream portion of the knowledge graph and a statistical behavior model for the system locale;

derive a recommended action according to the anomalous system behavior; and

generate a work order to implement the recommended action.

10 . The computer program product according to claim 9 , wherein providing a machine learning model comprises program instructions, which, when executed cause the one or more processors to:

receive a representation of physical or logical connectivity of the system and historical time series data recorded by sensors of the system;

derive from at least one of the knowledge graph and historical time series data, a multi-variate statistical model of system-level behavior anomalies; and

derive from the multi-variate statistical model an indicative set of conditions on multi-variate aggregations of sensors that indicate anomalous behavior.

11 . The computer program product according to claim 10 , the stored program instructions further causing the one or more processors to:

receive a prescription for or computing salient sub-graphs and applying it to the knowledge graph to produce a set of one or more salient sub-graphs;

derive from at least one of the salient sub-graphs and historical time series data, a second multi-variate statistical model of system-level behavior anomalies; and

derive from the second multi-variate statistical model an indicative set of conditions on multi-variate aggregations of sensors that indicate anomalous behavior.

12 . The computer program product according to claim 10 , wherein deriving from at least one of the knowledge graph and historical time series data, a multi-variate statistical model of system-level behavior anomalies comprises limiting the knowledge graph to a set of nodes defined by a maximum inter-node distance from each other.

13 . The computer program product according to claim 10 , wherein deriving a multi-variate statistical model comprises inferring causation from directed edges of the knowledge graph.

14 . The computer program product according to claim 10 , wherein deriving a multi-variate statistical model comprises encoding a portion of nodes of the knowledge graph as an intermediate representation.

15 . The computer program product according to claim 10 , wherein deriving a multi-variate statistical model comprises inferring a Bayes net from the knowledge graph.

16 . The computer program product according to claim 9 , the stored program instructions further causing the one or more processors to alter an anomalous behavior threshold for a system node selected from a group consisting of nodes upstream of the system locale, nodes downstream of the system locale, and combinations thereof.

17 . A computer system comprising:

one or more computer processors;

one or more computer readable storage media; and

stored program instructions on the one or more computer readable storage media for execution by the one or more computer processors, the stored program instructions which, when executed, cause the one or more computer processors to:

provide a machine learning model comprising a knowledge graph depicting system entity relationships, and modeling behavioral correlations among system entities according to historical time-series data;

receive real-time time-series data for the system according to monitoring frequencies;

detect an anomalous system behavior in a system locale, according to the real-time time-series data, the machine learning model, monitoring thresholds, and multivariate sensor metrics;

adjusting the monitoring thresholds, and the monitoring frequencies, according to the system locale, knowledge graph and the anomalous system behavior;

diagnose the anomalous system behavior according to an upstream portion of the knowledge graph and a statistical behavior model for the system locale;

derive a recommended action according to the anomalous system behavior; and

generate a work order to implement the recommended action.

18 . The computer system according to claim 17 , wherein providing a machine learning model comprises program instructions, which, when executed cause the one or more processors to:

receive a representation of physical or logical connectivity of the system and historical time series data recorded by sensors of the system;

derive from at least one of the knowledge graph and historical time series data, a multi-variate statistical model of system-level behavior anomalies; and

derive from the multi-variate statistical model an indicative set of conditions on multi-variate aggregations of sensors that indicate anomalous behavior.

19 . The computer system according to claim 18 , the stored program instructions further causing the one or more processors to:

receive a prescription for or computing salient sub-graphs and applying it to the knowledge graph to produce a set of one or more salient sub-graphs;

derive from at least one of the salient sub-graphs and historical time series data, a second multi-variate statistical model of system-level behavior anomalies; and

derive from the second multi-variate statistical model an indicative set of conditions on multi-variate aggregations of sensors that indicate anomalous behavior.

20 . The computer system according to claim 17 , the stored program instructions further causing the one or more processors to alter an anomalous behavior threshold for a system node selected from a group consisting of nodes upstream of the system locale, nodes downstream of the system locale, and combinations thereof.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2023
From: AGRAWAL, BHAVNA; BASEMAN, ROBERT JEFFREY; KEPHART, JEFFREY OWEN; BHAMIDIPATY, ANURADHA; KHABIRI, ELHAM; LI, YINGJIE; JAYARAMAN, SRIDEEPIKA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 063200/0038 →
Continuity (1)
Related Publication 20240333739A1 · Oct 3, 2024
References Cited (41)
US 9366451B2 · Guo · 2016 [cited by applicant]
US 10127453B2 · Verdejo · 2018 [cited by applicant]
US 10628253B2 · Sharma · 2020 [cited by applicant]
US 10635094B2 · Rosca · 2020 [cited by applicant]
US 11182748B1 · Neckermann · 2021 [cited by examiner]
US 11228505B1 · Wang · 2022 [cited by examiner]
US 11314242B2 · Sun · 2022 [cited by applicant]
US 20100318641A1 · Bullard · 2010 [cited by examiner]
US 20130198119A1 · Eberhardt, III · 2013 [cited by examiner]
US 20140172371A1 · Zhu · 2014 [cited by examiner]
US 20160282821A1 · Chen · 2016 [cited by examiner]
US 20180219888A1 · Apostolopoulos · 2018 [cited by examiner]
US 20200019893A1 · Lu · 2020 [cited by applicant]
US 20200250062A1 · Arora · 2020 [cited by examiner]
US 20200252261A1 · Arora · 2020 [cited by examiner]
US 20200364128A1 · Vittal · 2020 [cited by examiner]
US 20200409339A1 · Arashanipalai · 2020 [cited by examiner]
US 20220303291A1 · Baldini Das Neves · 2022 [cited by examiner]
US 20230016199A1 · Jividen · 2023 [cited by examiner]
US 20230069074A1 · Chen · 2023 [cited by examiner]
US 20230102786A1 · Garapati · 2023 [cited by examiner]
US 20230142028A1 · Cheng · 2023 [cited by examiner]
US 20230153680A1 · Rohrkemper · 2023 [cited by examiner]
US 20240305549A1 · Staszel · 2024 [cited by examiner]
US 20250301328A1 · Abbaszadeh · 2025 [cited by examiner]
CN 112085202A · 2020 [cited by applicant]
Chhetri et al., “Knowledge Graph Based Hard Drive Failure Prediction”, Sensors 2022, 22, 985, Jan. 27, 2022, 21 Pgs, <https://doi.org/10.3390/s22030985>. [cited by applicant]
Choudhary et al., “A Survey of Knowledge Graph Embedding and Their Applications”, Indian Institute of Technology Delhi, 11 Pgs, arXiv:2107.07842v1 [cs.IR] Jul. 16, 2021, <https://arxiv.org/pdf/2107.07842.pdf>. [cited by applicant]
Jia et al., “Pattern Discovery and Anomaly Detection via Knowledge Graph”, IEEE Xplore, 2018 21st International Conference on Information Fusion (Fusion), 8 Pgs, 978-0-9964527-7-9 © 2018 ISIF, Downloaded on Jan. 10, 202… [cited by applicant]
Li et al., “A semantic model-based fault detection approach for building energy systems”, ScienceDirect, Elsevier, Building and Environment 207 (2022) 108548, 16 Pgs, Nov. 11, 2021, <https://doi.org/10.1016/j.buildenv.2… [cited by applicant]
Nesen et al, “Knowledge Graphs for Semantic-Aware Anomaly Detection in Video”, 2020 IEEE Third International Conference on Artificial Intelligence and Knowledge Engineering (AIKE), 978-1-7281-8708-2/20 © 2020 IEEE DOI 1… [cited by applicant]
Schoenfisch et al., “Root cause analysis in IT infrastructures using ontologies and abduction in Markov Logic Networks”, Science Direct, Elsevier Ltd, Information Systems , Nov. 12, 2017, 3 Pgs, <https://doi.org/10.1016… [cited by applicant]
Senarantne et al., “Unsupervised Anomaly Detection in Knowledge Graphs ”, ACM ISBN 978-1-4503-9565-Jun. 21, 12, 5 Pgs, Dec. 6-8, 2021, <https://doi.org/10.1145/3502223.3502246>. [cited by applicant]
Setiawan et al., “GWAD: Greedy Workflow Graph Anomaly Detection Framework for System Traces”, 2020 IEEE International Conference on Systems, Man, and Cybernetics (SMC), 7 Pgs, Oct. 11-14, 2020, 978-1-7281-8526-2/20 © 20… [cited by applicant]
Su et al., “A survey based on knowledge graph in fault diagnosis, analysis and prediction: key technologies and challenges”, 2020 International Conference on Artificial Intelligence and Computer Engineering (ICAICE'20),… [cited by applicant]
Su et al., “Robust Anomaly Detection for Multivariate Time Series through Stochastic Recurrent Neural Network”, Aug. 4-8, 2019, Anchorage, AK, USA © 2019 Association for Computing Machinery, 10 Pgs, ACM ISBN 978-1-4503-… [cited by applicant]
Vaska et al., “Context-Dependent Anomaly Detection with Knowledge Graph Embedding Models”, arXiv:2203.09354v2 [cs.LG] Mar. 19, 2022, 9 Pgs, <https://arxiv.org/pdf/2203.09354.pdf>. [cited by applicant]
Xiao et al., “SSP: Semantic Space Projection for Knowledge Graph Embedding with Text Descriptions”, arXiv:1604.04835v3, [cs.CL] Jun. 17, 2017, 7 Pgs, <https://arxiv.org/pdf/1604.04835.pdf>. [cited by applicant]
Zhao et al., “Anomaly detection of unstructured big data via semantic analysis and dynamic knowledge graph construction”, Apr. 12, 2021, 18 Pgs, https://www.spiedigitallibrary.org/terms-of-use>. [cited by applicant]
Zhong et al., “Aligning Knowledge and Text Embeddings by Entity Descriptions”, Proceedings of the 2015 Conference on Empirical Methods in Natural Language Processing, 6 Pgs, Lisbon, Portugal, Sep. 17-21, 2015, c 2015 As… [cited by applicant]
Zhou et al., “Commonsense Knowledge Aware Conversation Generation with Graph Attention”, Proceedings of the Twenty-Seventh International Joint Conference on Artificial Intelligence, 7 Pgs, Downloaded Jan. 25, 2023. [cited by applicant]