IP Library › Granted Patent US 12,602,368
Granted Patent B2
US 12,602,368 · App. 18/608,327 · Granted Apr 14, 2026

Anomaly detection data workflow for time series data

Inventors: Vannia Gonzalez Macias (Glen Allen, VA); Scott Garcia (Washington, DC); Peter Terrana (Mechanicsville, VA)
Assignee: Capital One Services, LLC
G06F16/2365G06F7/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,602,368
App. No.
18/608,327
Filed
Mar 18, 2024
Granted
Apr 14, 2026
Kind
B2
Art Unit
2152
USPC
707/690
Abstract

Methods and systems are described herein for improving anomaly detection in timeseries datasets. Different machine learning models may be trained to process specific types of timeseries data efficiently and accurately. Thus, selecting a proper machine learning model for identifying anomalies in a specific set of timeseries data may greatly improve accuracy and efficiency of anomaly detection. Another way to improve anomaly detection is to process a multitude of timeseries datasets for a time period (e.g., 90 days) to detect anomalies from those timeseries datasets and then correlate those detected anomalies by generating an anomaly timeseries dataset and identifying anomalies within the anomaly timeseries dataset. Yet another way to improve anomaly detection is to divide a dataset into multiple datasets based on a type of anomaly detection requested.

Claims (90)

1 . A system for correlating events based on multiple anomalies occurring within a given time interval across multiple timeseries datasets, the system comprising:

one or more processors; and

a non-transitory computer-readable storage medium storing instructions, which when executed by the one or more processors cause the one or more processors to:

determine a temporal trait associated with a timeseries dataset of a plurality of timeseries datasets, the temporal trait identifying a pattern within the timeseries dataset;

select, from a first plurality of anomaly detection models and based on determining the temporal trait, a first anomaly detection model, wherein the first plurality of anomaly detection models are trained to detect anomalies in datasets classified under temporal traits;

determine a model execution parameter of a plurality of model execution parameters for the first anomaly detection model based on a timeseries signal associated with the timeseries dataset;

obtain, based on selecting the first anomaly detection model and determining the model execution parameter, a plurality of sets of timestamps by inputting the timeseries dataset into the first anomaly detection model, wherein each set of the plurality of sets of the timestamps includes a corresponding plurality of timestamps, each timestamp representing an anomaly detected within the timeseries dataset;

generate, based on the plurality of sets of the timestamps, an anomaly timeseries dataset having a corresponding aggregated value representing the timestamps for a plurality of time intervals;

input the anomaly timeseries dataset into a second anomaly detection model trained to detect anomalies in aggregated datasets to obtain one or more anomalies, wherein the anomaly timeseries dataset stores aggregated values generated from the plurality of sets of the timestamps that represent the anomalies within the plurality of sets of the timestamps, and wherein the second anomaly detection model is not one of the first plurality of anomaly detection models; and

generate a message based on the one or more anomalies.

2 . The system of claim 1 , wherein the instructions further cause the one or more processors to:

receive the plurality of timeseries datasets,

wherein each timeseries dataset of the plurality of timeseries datasets comprises a plurality of values for a plurality of timestamps,

wherein the plurality of timeseries datasets includes a first dataset comprising a first type of data and a second dataset comprising a second type of data,

wherein the timeseries dataset is the first dataset,

wherein, the plurality of sets of timestamps are obtained by inputting each of the plurality of timeseries datasets into at least one anomaly detection model of the first plurality of anomaly detection models, and

wherein each set of the plurality of sets of timestamps comprises one or more timestamps representing the one or more anomalies detected within the timeseries dataset.

3 . The system of claim 2 , wherein the instructions that cause the one or more processors to select the first anomaly detection model cause the one or more processors to:

select, based on the first type of data, the first anomaly detection model for the first dataset; and

select, based on the second type of data, a third anomaly detection model for the second dataset,

wherein the first anomaly detection model and the third anomaly detection model are of the first plurality of anomaly detection models,

wherein the first dataset is inputted into the first anomaly detection model, and

wherein the second dataset is inputted into the third anomaly detection model.

4 . The system of claim 1 , wherein the instructions further cause the one or more processors to:

combine the timestamps within the plurality of sets of the timestamps into a chronologically ordered dataset of the anomalies by:

retrieving a time interval;

retrieving, from the chronologically ordered dataset, a time associated with a first timestamp stored in a first position within the chronologically ordered dataset;

traversing the chronologically ordered dataset until a second timestamp is reached, wherein the second timestamp is a last timestamp within a time slot associated with the first timestamp; and

generating a first aggregated value based on all the timestamps starting from the first timestamp and ending with the second timestamp, wherein the first aggregated value represents a count of the anomalies detected starting with the first timestamp and ending with the second timestamp.

5 . The system of claim 1 , wherein the instructions further cause the one or more processors to:

receive, from the first anomaly detection model and based on the anomaly timeseries dataset, one or more probabilities corresponding to the one or more anomalies detected by the first anomaly detection model;

retrieve an anomaly confidence threshold; and

remove from the one or more anomalies those anomalies that do not meet the anomaly confidence threshold.

6 . A method comprising:

determining a temporal trait associated with a timeseries dataset of a plurality of timeseries datasets, the temporal trait identifying a pattern within the timeseries dataset;

selecting, from a first plurality of anomaly detection models and based on determining the temporal trait, a first anomaly detection model trained to detect anomalies in datasets classified under the temporal trait;

determining a model execution parameter of a plurality of model execution parameters for the first anomaly detection model based on a timeseries signal associated with the timeseries dataset;

receiving, based on selecting the first anomaly detection model and determining the model execution parameter, a plurality of sets of timestamps by inputting the timeseries dataset into the first anomaly detection model, wherein each set of the plurality of sets of timestamps includes a corresponding plurality of timestamps, each timestamp representing an anomaly detected within the timeseries dataset;

generating, based on the plurality of sets of the timestamps, an anomaly timeseries dataset having a corresponding aggregated value representing timestamps for a plurality of time intervals;

inputting the anomaly timeseries dataset into a second anomaly detection model to obtain one or more anomalies, wherein the anomaly timeseries dataset stores aggregated values generated from the plurality of sets of timestamps that represent anomalies within the plurality of sets of timestamps, and wherein the second anomaly detection model is not one of the first plurality of anomaly detection models; and

generating a message based on the one or more anomalies.

7 . The method of claim 6 , further comprising:

receiving the plurality of timeseries datasets, wherein each timeseries dataset comprises a plurality of values.

8 . The method of claim 7 , wherein the plurality of timeseries datasets includes a first dataset comprising a first type of data and a second dataset comprising a second type of data,

wherein the timeseries dataset is the first dataset.

9 . The method of claim 8 , comprising:

selecting, based on the first type of data, the first anomaly detection model of the first plurality of anomaly detection models; and

selecting, based on the second type of data, a third anomaly detection model of the first plurality of anomaly detection models.

10 . The method of claim 6 , further comprising combining the timestamps within the plurality of sets of timestamps into a chronologically ordered dataset of anomalies by:

storing, in a data structure, a first set of the plurality of sets of timestamps in a chronological order;

selecting each set of the plurality of sets of timestamps; and

placing each timestamp from each selected set into the data structure in the chronological order.

11 . The method of claim 10 , wherein transforming the plurality of sets of timestamps into the anomaly timeseries dataset comprises:

retrieving a time interval;

retrieving, from the data structure, a time associated with a first timestamp stored in a first position within the data structure;

traversing the data structure until a second timestamp is reached, wherein the second timestamp is a last timestamp within a time slot associated with the first timestamp; and

generating a first aggregated value based on all the timestamps between the first timestamp and the second timestamp, wherein the first aggregated value represents a count of the anomalies detected between the first timestamp and the second timestamp.

12 . The method of claim 6 , further comprising:

receiving, from the first anomaly detection model and based on the anomaly timeseries dataset, one or more probabilities corresponding to the one or more anomalies detected by the first anomaly detection model;

retrieving an anomaly confidence threshold; and

removing from the one or more anomalies those anomalies that do not meet the anomaly confidence threshold.

13 . One or more non-transitory, computer-readable media for correlating events based on anomalies occurring within a given time interval across multiple timeseries datasets, storing instructions that, when executed by one or more processors, cause operations comprising:

determining a temporal trait associated with a timeseries dataset of a plurality of timeseries datasets, the temporal trait identifying a pattern within the timeseries dataset;

selecting, from a first plurality of anomaly detection models and based on determining the temporal trait, a first anomaly detection model trained to detect anomalies in datasets classified under the temporal trait;

determining a model execution parameter of a plurality of model execution parameters for the first anomaly detection model based on a timeseries signal associated with the timeseries dataset;

receiving, based on selecting the first anomaly detection model and determining the model execution parameter, a plurality of sets of timestamps by inputting the timeseries dataset into the first anomaly detection model, wherein each set of the plurality of sets of timestamps includes a plurality of timestamps, each timestamp representing an anomaly detected within the timeseries dataset;

generating, based on the plurality of sets of the timestamps, an anomaly timeseries dataset having a corresponding aggregated value representing timestamps for a plurality of time intervals;

inputting the anomaly timeseries dataset into a second anomaly detection model to obtain one or more anomalies, wherein the anomaly timeseries dataset stores aggregated values generated from the plurality of sets of timestamps that represent anomalies within the plurality of sets of timestamps, and wherein the second anomaly detection model is not one of the first plurality of anomaly detection models; and

generating a message based on the one or more anomalies.

14 . The one or more non-transitory, computer-readable media of claim 13 , wherein the instructions further cause the one or more processors to:

receive the plurality of timeseries datasets, wherein each timeseries dataset comprises a plurality of values for the plurality of timestamps.

15 . The one or more non-transitory, computer-readable media of claim 14 , wherein the plurality of timeseries datasets includes a first dataset comprising a first type of data and a second dataset comprising a second type of data,

wherein the timeseries dataset is the first dataset.

16 . The one or more non-transitory, computer-readable media of claim 15 , wherein the instructions further cause the one or more processors to:

inputting the first dataset into the first anomaly detection model of the first plurality of anomaly detection models; and

inputting the second dataset into a third anomaly detection model of the first plurality of anomaly detection models.

17 . The one or more non-transitory, computer-readable media of claim 13 , further comprising instructions that cause the one or more processors to combine the timestamps within the plurality of sets of timestamps into a chronologically ordered dataset of the anomalies by:

storing, in a data structure, a first set of the plurality of sets of timestamps in a chronological order;

selecting each set of the plurality of sets of timestamps; and

placing each timestamp from each selected set into the data structure in the chronological order.

18 . The one or more non-transitory, computer-readable media of claim 17 , wherein the instructions that cause the one or more processors to transform the plurality of sets of timestamps into the anomaly timeseries dataset further cause the one or more processors to:

retrieve a time interval;

retrieve, from the data structure, a time associated with a first timestamp stored in a first position within the data structure;

traverse the data structure until a second timestamp is reached, wherein the second timestamp is a last timestamp within a time slot associated with the first timestamp; and

generate a first aggregated value based on all the timestamps between the first timestamp and the second timestamp, wherein the first aggregated value represents a count of the anomalies detected between the first timestamp and the second timestamp.

19 . The one or more non-transitory, computer-readable media of claim 13 , wherein the instructions further cause the one or more processors to:

receive, from the first anomaly detection model and based on the anomaly timeseries dataset, one or more probabilities corresponding to the one or more anomalies detected by the first anomaly detection model;

retrieve an anomaly confidence threshold; and

remove from the one or more anomalies those anomalies that do not meet the anomaly confidence threshold.

20 . The one or more non-transitory, computer-readable media of claim 13 , wherein the instructions that cause the one or more processors to transform the plurality of sets of timestamps into the anomaly timeseries dataset further cause the one or more processors to generate the anomaly timeseries dataset with a plurality of time windows and a corresponding number of anomalies detected during a corresponding time window.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2024
From: GONZALEZ MACIAS, VANNIA; GARCIA, SCOTT; TERRANA, PETER
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 066941/0507 →
Continuity (3)
Continuation 18189174 · Mar 23, 2023
Continuation 17238536 · Apr 23, 2021
Related Publication 20240220480A1 · Jul 4, 2024
References Cited (107)
US 5646864A · Whitney · 1997 [cited by applicant]
US 5661668A · Yemini et al. · 1997 [cited by applicant]
US 5748098A · Grace · 1998 [cited by applicant]
US 6023571A · Matsumoto et al. · 2000 [cited by applicant]
US 6049792A · Hart et al. · 2000 [cited by applicant]
US 6295525B1 · Hart et al. · 2001 [cited by applicant]
US 6920468B1 · Cousins et al. · 2005 [cited by applicant]
US 7383191B1 · Herring et al. · 2008 [cited by applicant]
US 8578490B2 · Moran · 2013 [cited by applicant]
US 9917853B2 · Seigel · 2018 [cited by applicant]
US 10122747B2 · Mahaffey et al. · 2018 [cited by applicant]
US 10362055B2 · Kumar et al. · 2019 [cited by applicant]
US 10389738B2 · Muddu et al. · 2019 [cited by applicant]
US 10419450B2 · Muddu et al. · 2019 [cited by applicant]
US 10437831B2 · De-Levie et al. · 2019 [cited by applicant]
US 10579932B1 · Cantrell · 2020 [cited by examiner]
US 10621346B1 · Singh et al. · 2020 [cited by applicant]
US 10776196B2 · Ohana et al. · 2020 [cited by applicant]
US 10855548B2 · Garvey et al. · 2020 [cited by applicant]
US 10965700B2 · Xie et al. · 2021 [cited by applicant]
US 11003421B2 · Bodin et al. · 2021 [cited by applicant]
US 11100064B2 · Dwarampudi et al. · 2021 [cited by applicant]
US 11106789B2 · Kraus et al. · 2021 [cited by applicant]
US 11166075B1 · Decrop et al. · 2021 [cited by applicant]
US 11258807B2 · Muddu et al. · 2022 [cited by applicant]
US 11281643B2 · Hsiao et al. · 2022 [cited by applicant]
US 11354684B2 · Ravichandran · 2022 [cited by applicant]
US 11409961B2 · Freeman et al. · 2022 [cited by applicant]
US 11416622B2 · Sharma et al. · 2022 [cited by applicant]
US 11436647B1 · Null et al. · 2022 [cited by applicant]
US 11449786B2 · Gottschlich et al. · 2022 [cited by applicant]
US 11461441B2 · Shapiro et al. · 2022 [cited by applicant]
US 11475024B2 · Sriharsha · 2022 [cited by applicant]
US 11561959B2 · Marathe · 2023 [cited by applicant]
US 11588834B2 · Bowditch et al. · 2023 [cited by applicant]
US 11599549B2 · Sriharsha · 2023 [cited by applicant]
US 11599815B1 · Mani · 2023 [cited by examiner]
US 11615102B2 · Sriharsha · 2023 [cited by applicant]
US 11620296B2 · Sriharsha · 2023 [cited by applicant]
US 11625602B2 · Sarferaz · 2023 [cited by applicant]
US 11727286B2 · Hazard et al. · 2023 [cited by applicant]
US 11748416B2 · Hicklin et al. · 2023 [cited by applicant]
US 11809492B2 · Sriharsha · 2023 [cited by applicant]
US 11838309B1 · Martin et al. · 2023 [cited by applicant]
US 12032629B2 · Sriharsha · 2024 [cited by applicant]
US 12045316B2 · Côté et al. · 2024 [cited by applicant]
US 12159237B1 · Calmon · 2024 [cited by examiner]
US 20070157315A1 · Moran · 2007 [cited by applicant]
US 20080189225A1 · Herring et al. · 2008 [cited by applicant]
US 20080215355A1 · Herring et al. · 2008 [cited by applicant]
US 20100036643A1 · Marvasti et al. · 2010 [cited by applicant]
US 20130262320A1 · Makanawala et al. · 2013 [cited by applicant]
US 20150088606A1 · Tyagi · 2015 [cited by applicant]
US 20150106927A1 · Ferragut et al. · 2015 [cited by applicant]
US 20160076970A1 · Takahashi · 2016 [cited by applicant]
US 20170063884A1 · Seigel · 2017 [cited by applicant]
US 20170063905A1 · Muddu et al. · 2017 [cited by applicant]
US 20170169325A1 · McCord et al. · 2017 [cited by applicant]
US 20170329660A1 · Salunke et al. · 2017 [cited by applicant]
US 20170339178A1 · Mahaffey et al. · 2017 [cited by applicant]
US 20180219889A1 · Oliner et al. · 2018 [cited by applicant]
US 20180248902A1 · Dãnilã-Dumitrescu et al. · 2018 [cited by applicant]
US 20180330253A1 · Gottschlich et al. · 2018 [cited by applicant]
US 20190028557A1 · Modi et al. · 2019 [cited by applicant]
US 20190052672A1 · Kumar et al. · 2019 [cited by applicant]
US 20190079994A1 · Ma et al. · 2019 [cited by applicant]
US 20190109868A1 · Muddu et al. · 2019 [cited by applicant]
US 20190245876A1 · Faigon et al. · 2019 [cited by applicant]
US 20190280942A1 · Côtéet al. · 2019 [cited by applicant]
US 20190294598A1 · Hsiao et al. · 2019 [cited by applicant]
US 20190294719A1 · Beringer et al. · 2019 [cited by applicant]
US 20190294720A1 · Beringer et al. · 2019 [cited by applicant]
US 20190294734A1 · Beringer et al. · 2019 [cited by applicant]
US 20190303726A1 · Côtéet al. · 2019 [cited by applicant]
US 20190312941A1 · Maccini et al. · 2019 [cited by applicant]
US 20190327251A1 · Muddu et al. · 2019 [cited by applicant]
US 20190379589A1 · Ryan et al. · 2019 [cited by applicant]
US 20200007564A1 · Xie et al. · 2020 [cited by applicant]
US 20200073740A1 · Ohana · 2020 [cited by examiner]
US 20200160458A1 · Bodin et al. · 2020 [cited by applicant]
US 20200202256A1 · Chaudhari et al. · 2020 [cited by applicant]
US 20200267057A1 · Garvey et al. · 2020 [cited by applicant]
US 20200285737A1 · Kraus et al. · 2020 [cited by applicant]
US 20200304364A1 · Tapia et al. · 2020 [cited by applicant]
US 20200349241A1 · Shapiro et al. · 2020 [cited by applicant]
US 20210019300A1 · Marathe · 2021 [cited by applicant]
US 20210056430A1 · Wu et al. · 2021 [cited by applicant]
US 20210117382A1 · Sriharsha · 2021 [cited by applicant]
US 20210117415A1 · Sriharsha · 2021 [cited by applicant]
US 20210117857A1 · Sriharsha · 2021 [cited by applicant]
US 20210117868A1 · Sriharsha · 2021 [cited by applicant]
US 20210241289A1 · Roy et al. · 2021 [cited by applicant]
US 20210286705A1 · Carter · 2021 [cited by applicant]
US 20220035806A1 · Horesh et al. · 2022 [cited by applicant]
US 20220124110A1 · Chhabra · 2022 [cited by examiner]
US 20220237102A1 · Bugdayci · 2022 [cited by examiner]
US 20220239675A1 · Panse et al. · 2022 [cited by applicant]
US 20220239683A1 · Kaliya Perumal et al. · 2022 [cited by applicant]
US 20220358124A1 · Sriharsha · 2022 [cited by applicant]
US 20230078661A1 · Wei et al. · 2023 [cited by applicant]
US 20230177085A1 · Sriharsha · 2023 [cited by applicant]
US 20230205819A1 · Sriharsha · 2023 [cited by applicant]
US 20240320267A1 · Sriharsha · 2024 [cited by applicant]
Mohsin Munir et al., DeepAnT: A Deep Learning Approach for Unsupervised Anomaly Detection in Time Series, vol. 7, 1991-2005, 2019 (15 pages). [cited by applicant]
US Non-Final Office Action on US Appl. U.S. Appl. No. 18/501,733 Dated Mar. 25, 2025 (53 pages). [cited by applicant]
Boulton CA and Lenton TM, “A new method for detecting abrupt shifts in time series” [version 1; peer review: 2 approved with reservations] F1000Research 2019, 8:7 46 https://doi.org/10.12688/f1000reserch.19310.1 (Year: … [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 18/501,733, filed Jul. 21, 2025 (17 pages). [cited by applicant]