Learning apparatus, anomaly detection apparatus, learning method, anomaly detection method, and program
A learning apparatus according to one embodiment includes an input unit configured to input a normal data collection for a first system that is a target domain and to input a normal data collection for a second system that is a source domain. The learning apparatus includes a learning unit configured to train a model that includes a first autoencoder configured to input normal data for the target domain, based on the normal data collection for the first system and the normal data collection for the second system. The model includes a second autoencoder configured to input normal data for the source domain, and includes a discriminator configured to output a probability that output data is data representing a feature for any one of the target domain and the source domain, while using, as an input, output data, output data of a first encoder included in the first autoencoder or a second encoder included in the second autoencoder.
1 . An anomaly detection apparatus comprising:
circuitry configured to:
input (i) a normal data collection for a first system that is a target domain and (ii) a normal data collection for a second system that is a source domain;
train a model, the model including:
a first autoencoder configured to input normal data for the target domain, based on the normal data collection for the first system,
a second autoencoder configured to input normal data for the source domain, based on the normal data collection for the second system, and
a discriminator configured to use, as an input, output data, of a first encoder included in the first autoencoder, or a second encoder included in the second autoencoder, to output a probability that the output data is output data representing a feature for any one of the target domain and the source domain;
obtain target data for the first system on which anomaly detection is performed; and
determine whether an anomaly has occurred in the first system based on whether a difference between the target data and output data from the first autoencoder exceeds a threshold, by using only the first autoencoder included in the trained model,
wherein a first encoder included in the first autoencoder compresses the normal data collection for the first system and outputs a first feature quantity,
wherein a second encoder included in the second autoencoder compresses the normal data collection for the second system and outputs a second feature quantity,
wherein the discriminator is configured to use, as the input, the first feature quantity or the second feature quantity, to output a probability that the input is data representing a feature for any one of the target domain and the source domain, and
wherein the circuitry is configured to learn parameters of the model such that a difference between an input and an output of the first autoencoder and a difference between an input and an output of the second autoencoder are minimized, and the probability that the discriminator outputs is maximized.
2 . The anomaly detection apparatus according to claim 1 , wherein the circuitry is configured to learn parameters of the model such that,
a difference between an input and an output of the first autoencoder and a difference between an input and an output of the second autoencoder are minimized, and
the probability that the discriminator output is maximized.
3 . The anomaly detection apparatus according to claim 1 , wherein the number of pieces of data included in the normal data collection for the target domain is smaller than the number of pieces of data included in the normal data collection for the source domain.
4 . An anomaly detection method executed by a computer, the anomaly detection method comprising:
determining whether an anomaly has occurred in a system that is a target on which anomaly detection is performed, by using (i) the first autoencoder included in the model trained by the anomaly detection apparatus according to claim 1 and (ii) data for the system.
5 . The anomaly detection according to claim 1 , wherein the circuitry is configured to learn parameters of the model such that a difference between an input and an output of the first autoencoder and a difference between an input and an output of the second autoencoder are minimized, and the probability that the discriminator outputs is maximized.
6 . The anomaly detection according to claim 1 , wherein the first encoder is configured to compress the normal data collection for the first system to output a first feature quantity, the second encoder is configured to compress the normal data collection for the second system to output a second feature quantity, and the discriminator is configured to use the first feature quantity or the second feature quantity as the input.
7 . An anomaly detection method executed by a computer, the learning method comprising:
inputting (i) a normal data collection for a first system that is a target domain and (ii) a normal data collection for a second system that is a source domain; and
training a model, the model including:
a first autoencoder configured to input normal data for the target domain, based on the normal data collection for the first system,
a second autoencoder configured to input normal data for the source domain, based on the normal data collection for the second system, and
a discriminator configured to use, as an input, output data, of a first encoder included in the first autoencoder, or a second encoder included in the second autoencoder, to output a probability that the output data is data representing a feature for any one of the target domain and the source domain, and
obtaining target data for the first system on which anomaly detection is performed; and
determining whether an anomaly has occurred in the first system based on whether a difference between the target data and output data from the first autoencoder exceeds a threshold, by using only the first autoencoder included in the trained model,
wherein a first encoder included in the first autoencoder compresses the normal data collection for the first system and outputs a first feature quantity,
wherein a second encoder included in the second autoencoder compresses the normal data collection for the second system and outputs a second feature quantity,
wherein the discriminator is configured to use, as the input, the first feature quantity or the second feature quantity, to output a probability that the input is data representing a feature for any one of the target domain and the source domain, and
wherein the learning method further comprises learning parameters of the model such that a difference between an input and an output of the first autoencoder and a difference between an input and an output of the second autoencoder are minimized, and the probability that the discriminator outputs is maximized.
8 . A non-transitory computer readable medium storing a program that causes a computer to execute the anomaly detection method according to claim 7 .