IP Library › Granted Patent US 12,641,101
Granted Patent B2
US 12,641,101 · App. 18/496,333 · Granted May 26, 2026

Exploring association rules to aid in the trackability of root causes of abnormal events and in the generation of more precise and concise explanations for anomaly detection techniques

Inventors: Adriana Bechara Prado (Niterói, BR); Alexander Eulalio Robles Robles (Valinhos, BR); Eduarda Tatiane Caetano Chagas (Belo Horizonte, BR); Helen Cristina de Mattos Senefonte (Londrina, BR); Jonathan Mendes De Almeida (Brasília, BR); Karen Stéfany Martins (Belo Horizonte, BR)
Assignee: Dell Products L.P.
H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,641,101
App. No.
18/496,333
Granted
May 26, 2026
Kind
B2
Abstract

One example method includes evaluating a set of itemsets, based on the evaluating, computing association rules corresponding to the itemsets, filtering the association rules to identify relevant association rules, sorting the relevant association rules according to their respective metrics of support, confidence, lift, and conviction, and the relevant association rules are sorted from best metrics to worst metrics, storing (1) best itemsets of the set of itemsets, and (2) the association rules with the best metrics, as thresholds, mapping the thresholds to the stored association rules and to feature-value ranges, and identifying the stored association rules and the feature-value ranges as root causes of an anomaly, and explanations of the anomaly, respectively.

Claims (38)

1 . A method, comprising:

generating, by one or more hardware processors, a set of itemsets from boolean transactions generated from discretized outlier-score ranges computed for features of a time-series dataset by an anomaly detection model

evaluating, by the one or more hardware processors, the set of itemsets;

based on the evaluating, computing association rules corresponding to the itemsets, wherein the itemsets are filtered to include itemsets having at least a predefined risk ratio, support, and cardinality indicative of abnormal events;

filtering the association rules to identify relevant association rules whose consequents include at least one itemset associated with an abnormal event;

sorting the relevant association rules according to their respective metrics including support, confidence, lift, and conviction to identify one or more association rules satisfying anomaly explanation criteria;

storing (1) best itemsets selected based on risk ratio, support, and cardinality, and (2) the association rules satisfying the anomaly explanation criteria, as multi-feature anomaly detection thresholds;

mapping the multi-feature anomaly detection thresholds to the stored association rules and to feature-value ranges by identifying, for each feature, subsequences of the time-series dataset having outlier scores within threshold ranges and determining corresponding feature-value ranges;

identifying the stored association rules as root causes of an anomaly and the corresponding feature-value ranges as explanations of the anomaly; and

detecting the anomaly by evaluating antecedent and consequent conditions of at least one stored association rule and determining that the anomaly is present based on satisfaction of both the antecedent and consequent conditions.

2 . The method as recited in claim 1 , wherein each of the itemsets in the set is associated with a respective value of risk ratio, support, and cardinality.

3 . The method as recited in claim 1 , wherein each of the association rules comprises a respective antecedent, and a respective consequent that is associated with the antecedent.

4 . The method as recited in claim 1 , wherein each of the association rules has a respective support ‘s’ and confidence ‘c’.

5 . The method as recited in claim 1 , wherein the root causes of the anomaly and the explanations of the anomaly are used to identify, and implement, a remedial action to resolve the anomaly.

6 . The method as recited in claim 1 , wherein the anomaly is identified by an anomaly detection machine learning model as a result of analysis, by the anomaly detection machine learning model, of time-series data that comprises a set of features (‘F’) and a set of timestamps (‘T’).

7 . The method as recited in claim 1 , wherein the explanations of the anomaly indicate how and/or why the anomaly was identified as such by an anomaly detection machine learning model.

8 . The method as recited in claim 1 , wherein the itemsets in the set were obtained using a frequent pattern mining process.

9 . The method as recited in claim 1 , wherein the association rules are related to combinations of feature-outlier scores.

10 . The method as recited in claim 1 , wherein the support metric indicates a relative frequency of conjunctions of outlier-score ranges.

11 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

generating, by one or more hardware processors, a set of itemsets from boolean transactions generated from discretized outlier-score ranges computed for features of a time-series dataset by an anomaly detection model

evaluating, by the one or more hardware processors, the set of itemsets;

based on the evaluating, computing association rules corresponding to the itemsets, wherein the itemsets are filtered to include itemsets having at least a predefined risk ratio, support, and cardinality indicative of abnormal events;

filtering the association rules to identify relevant association rules whose consequents include at least one itemset associated with an abnormal event;

sorting the relevant association rules according to their respective metrics including support, confidence, lift, and conviction to identify one or more association rules satisfying anomaly explanation criteria;

storing (1) best itemsets selected based on risk ratio, support, and cardinality, and (2) the association rules satisfying the anomaly explanation criteria, as multi-feature anomaly detection thresholds;

mapping the multi-feature anomaly detection thresholds to the stored association rules and to feature-value ranges by identifying, for each feature, subsequences of the time-series dataset having outlier scores within threshold ranges and determining corresponding feature-value ranges;

identifying the stored association rules as root causes of an anomaly and the corresponding feature-value ranges as explanations of the anomaly; and

detecting the anomaly by evaluating antecedent and consequent conditions of at least one stored association rule and determining that the anomaly is present based on satisfaction of both the antecedent and consequent conditions.

12 . The non-transitory storage medium as recited in claim 11 , wherein each of the itemsets in the set is associated with a respective value of risk ratio, support, and cardinality.

13 . The non-transitory storage medium as recited in claim 11 , wherein each of the association rules comprises a respective antecedent, and a respective consequent that is associated with the antecedent.

14 . The non-transitory storage medium as recited in claim 11 , wherein each of the association rules has a respective support ‘s’ and confidence ‘c’.

15 . The non-transitory storage medium as recited in claim 11 , wherein the root causes of the anomaly and the explanations of the anomaly are used to identify, and implement, a remedial action to resolve the anomaly.

16 . The non-transitory storage medium as recited in claim 11 , wherein the anomaly is identified by an anomaly detection machine learning model as a result of analysis, by the anomaly detection machine learning model, of time-series data that comprises a set of features (‘F’) and a set of timestamps (‘T’).

17 . The non-transitory storage medium as recited in claim 11 , wherein the explanations of the anomaly indicate how and/or why the anomaly was identified as such by an anomaly detection machine learning model.

18 . The non-transitory storage medium as recited in claim 11 , wherein the itemsets in the set were obtained using a frequent pattern mining process.

19 . The non-transitory storage medium as recited in claim 11 , wherein the association rules are related to combinations of feature-outlier scores.

20 . The non-transitory storage medium as recited in claim 11 , wherein the support metric indicates a relative frequency of conjunctions of outlier-score ranges.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2023
From: BECHARA PRADO, ADRIANA; ROBLES ROBLES, ALEXANDER EULALIO; CAETANO CHAGAS, EDUARDA TATIANE; DE MATTOS SENEFONTE, HELEN CRISTINA; MENDES DE ALMEIDA, JONATHAN; MARTINS, KAREN STÉFANY
To: DELL PRODUCTS L.P.
Reel/Frame 065374/0236 →
Continuity (1)
Related Publication 20250141897A1 · May 1, 2025
References Cited (14)
US 10958689B1 · Ganesan · 2021 [cited by examiner]
US 11206277B1 · Oh · 2021 [cited by examiner]
US 20220113888A1 · Cady · 2022 [cited by examiner]
US 20220413907A1 · Sekiya · 2022 [cited by examiner]
US 20240259409A1 · Allouche · 2024 [cited by examiner]
C. C. M. Yeh et al., “Matrix Profile I: All pairs similarity joins for time series: a unifying view that includes motifs, discords and shapelets”, Proc' of 16th IEEE ICDM, 2016, pp. 1317-1322. [cited by applicant]
Dell Invention Disclosure. 133149. “A framework to aid in the selection of thresholds for anomaly detection models, along with the generation of quantitative explanations”. 2023. [cited by applicant]
P. Bailis, E. Gan, S. Madden, D. Narayanan, K. Rong, and S. Suri, “MacroBase: Prioritizing Attention in Fast Data.” arXiv, Mar. 24, 2017. doi: 10.48550/arXiv.1603.00567. [cited by applicant]
J. Han, J. Pei, and Y. Yin. Mining frequent patterns without candidate generation. In SIGMOD, 2000. [cited by applicant]
Ribeiro, Marco Tulio, Sameer Singh, and Carlos Guestrin. “Why should i trust you?” Explaining the predictions of any classifier. Proceedings of the 22nd ACM SIGKDD international conference on knowledge discovery and dat… [cited by applicant]
Lundberg, Scott M., and Su-In Lee. “A unified approach to interpreting model predictions.” Advances in neural information processing systems 30 (2017). [cited by applicant]
V. Jacob, F. Song, A. Stiegler, B. Rad, Y. Diao, and N. Tatbul, “Exathlon: A Benchmark for Explainable Anomaly Detection over Time Series.” arXiv, Sep. 5, 2021. doi: 10.48550/arXiv.2010.05073. [cited by applicant]
J. M. DeAlmeida et al., “Abnormal Behavior Detection Based on Traffic Pattern Categorization in Mobile Networks,” IEEE Transactions on Network and Service Management, vol. 18, No. 4, pp. 4213-4224, Dec. 2021, doi: 10.11… [cited by applicant]
A. Maske and B. Joglekar, “Survey on Frequent Item-Set Mining Approaches in Market Basket Analysis,” in 2018 Fourth International Conference on Computing Communication Control and Automation (ICCUBEA), Aug. 2018, pp. 1-… [cited by applicant]