IP Library › Granted Patent US 12,744,801
Granted Patent B2
US 12,744,801 · App. 18/159,703 · Granted Sep 22, 2026

Test case-based anomaly detection within a computing environment

Inventors: Zhi Li (Beijing, CN); Xiao Dong Li (Beijing, CN); He Jiang Jia (Beijing, CN); Xing Xing Shen (Beijing, CN); Ye Tian (Dalian, CN); Sheng Jie Han (Beijing, CN)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/1425H04L41/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,744,801
App. No.
18/159,703
Granted
Sep 22, 2026
Kind
B2
Abstract

Processing within a computing environment is facilitated by using a machine learning implicit-anomaly model to determine a possibility of an implicit anomaly within a system based on system metrics data obtained during running of one or more test cases on the system. The process further includes determining, using artificial intelligence, occurrence of an incident within the system associated with running of the one or more test cases. Determining the occurrence of the incident uses the determined possibility of the implicit anomaly within the system based on the system metrics data, and the process further includes initiating an action based on the occurrence of the incident within the system with running of the one or more test cases.

Claims (60)

1 . A computer-implemented method of facilitating processing within a computing environment, the computer-implemented method comprising:

obtaining system metrics data generated during executing one or more test cases configured to test functionality within a system;

using a machine learning implicit-anomaly model to determine a possibility of an implicit anomaly associated with executing the one or more test cases within the system;

determining, using artificial intelligence, an occurrence of an incident within the system based on detecting an anomaly that is not indicated by a result of executing the one or more test cases within the system, wherein detecting the anomaly uses the determined possibility of the implicit anomaly within the system based on the system metrics data; and

initiating an action based on the occurrence of the incident within the system associated with detecting the anomaly not indicated by the result, and despite the one or more test cases completing successfully.

2 . The computer-implemented method of claim 1 , further comprising:

training the machine learning implicit-anomaly model using training system metrics data collected from one or more test systems executing the one or more test cases.

3 . The computer-implemented method of claim 1 , wherein obtaining of the system metrics data comprises:

generating performance-robustness data vectors from collected performance data of the system.

4 . The computer-implemented method of claim 3 , wherein obtaining the system metrics data further comprises:

clustering system text data logs into functional areas; and

classifying the generated performance-robustness data vectors using the functional areas to obtain the system metrics data referenced by the machine learning implicit-anomaly model.

5 . The computer-implemented method of claim 1 , further comprising:

using a machine learning explicit-anomaly model to determine a possibility of an explicit anomaly within the system based on system text data obtained from executing the one or more test cases on the system; and

wherein determining the occurrence of the incident associated with executing the one or more test cases further comprises using the determined possibility of the explicit anomaly within the system based on the system text data in addition to the determined possibility of the implicit anomaly within the system based on the system metrics data, wherein the system metrics data and the system text data are different types of system data collected from executing the one or more test cases on the system.

6 . The computer-implemented method of claim 5 , wherein obtaining of the system metrics data comprises:

generating performance-robustness data vectors from collected performance data of the system;

clustering system text data logs into functional areas; and

classifying the generated performance-robustness data vectors using the functional areas to obtain the system metrics data referenced by the machine learning implicit-anomaly model.

7 . The computer-implemented method of claim 6 , wherein obtaining of the system text data comprises:

collecting and parsing system text output obtained from executing the one or more test cases on the system; and

converting the collected and parsed system text output into text data vectors, the system text data comprising the text data vectors.

8 . The computer-implemented method of claim 5 , wherein the artificial intelligence comprises a multilayer machine learning model, and wherein determining the occurrence of the incident comprises using the multilayer machine learning model in determining the occurrence of the incident within the system based on the determined possibility of implicit anomaly within the system using the system metrics data, and the determined possibility of explicit anomaly within the system using the system text data.

9 . The computer-implemented method of claim 1 , wherein the system is a production system and initiating the action comprises modifying operation of the system based on determining the occurrence of the incident within the system associated with executing the one or more test cases.

10 . A computer system for facilitating processing within a computing environment, the computer system comprising:

a memory; and

at least one processor in communication with the memory, wherein the computer system is configured to perform a method, the method comprising:

obtaining system metrics data generated during executing one or more test cases configured to test functionality within a system;

using a machine learning implicit-anomaly model to determine a possibility of an implicit anomaly associated with executing the one or more test cases within the system;

determining, using artificial intelligence, an occurrence of an incident within the system based on detecting an anomaly that is not indicated by a result of executing the one or more test cases within the system, wherein detecting the anomaly uses the determined possibility of the implicit anomaly within the system based on the system metrics data; and

initiating an action based on the occurrence of the incident within the system associated with detecting the anomaly not indicated by the result, and despite the one or more test cases completing successfully.

11 . The computer system of claim 10 , further comprising:

training the machine learning implicit-anomaly model using training system metrics data collected from one or more test systems executing the one or more test cases.

12 . The computer system of claim 10 , wherein obtaining of the system metrics data comprises:

generating performance-robustness data vectors from collected performance data of the system;

clustering system text data logs into functional areas; and

classifying the generated performance-robustness data vectors using the functional areas to obtain the system metrics data referenced by the machine learning implicit-anomaly model.

13 . The computer system of claim 10 , further comprising:

using a machine learning explicit-anomaly model to determine a possibility of an explicit anomaly within the system based on system text data obtained from executing the one or more test cases on the system; and

wherein determining the occurrence of the incident associated with executing the one or more test cases further comprises using the determined possibility of the explicit anomaly within the system based on the system text data in addition to the determined possibility of the implicit anomaly within the system based on the system metrics data, wherein the system metrics data and the system text data are different types of system data collected from executing the one or more test cases on the system.

14 . The computer system of claim 13 , wherein obtaining of the system metrics data comprises:

generating performance-robustness data vectors from collected performance data of the system;

clustering system text data logs into functional areas; and

classifying the generated performance-robustness data vectors using the functional areas to obtain the system metrics data referenced by the machine learning implicit-anomaly model.

15 . The computer system of claim 14 , wherein obtaining of the system text data comprises:

collecting and parsing system text output obtained from executing the one or more test cases on the system; and

converting the collected and parsed system text output into text data vectors, the system text data comprising the text data vectors.

16 . The computer system of claim 13 , wherein the artificial intelligence comprises a multilayer machine learning model, and wherein determining the occurrence of the incident comprises using the multilayer machine learning model in determining the occurrence of the incident within the system based on the determined possibility of implicit anomaly within the system using the system metrics data, and the determined possibility of explicit anomaly within the system using the system text data.

17 . A computer program product for facilitating processing within a computing environment, the computer program product comprising:

one or more computer-readable storage media and program instructions collectively stored on the one or more computer-readable storage media readable by at least one processing circuit to cause the processing circuit to perform a method comprising:

obtaining system metrics data generated during executing one or more test cases configured to test functionality within a system;

using a machine learning implicit-anomaly model to determine a possibility of an implicit anomaly associated with executing the one or more test cases within the system;

determining, using artificial intelligence, an occurrence of an incident within the system based on detecting an anomaly that is not indicated by a result of executing the one or more test cases within the system, wherein detecting the anomaly uses the determined possibility of the implicit anomaly within the system based on the system metrics data; and

initiating an action based on the occurrence of the incident within the system associated with detecting the anomaly not indicated by the result, and despite the one or more test cases completing successfully.

18 . The computer program product of claim 17 , further comprising:

training the machine learning implicit-anomaly model using training system metrics data collected from one or more test systems executing the one or more test cases.

19 . The computer program product of claim 17 , further comprising:

using a machine learning explicit-anomaly model to determine a possibility of an explicit anomaly within the system based on system text data obtained from executing the one or more test cases on the system; and

wherein determining the occurrence of the incident associated with executing the one or more test cases further comprises using the determined possibility of the explicit anomaly within the system based on the system text data in addition to the determined possibility of the implicit anomaly within the system based on the system metrics data, wherein the system metrics data and the system text data are different types of system data collected from executing the one or more test cases on the system.

20 . The computer program product of claim 19 , wherein the artificial intelligence comprises a multilayer machine learning model, and wherein determining the occurrence of the incident comprises using the multilayer machine learning model in determining the occurrence of the incident within the system based on the determined possibility of implicit anomaly within the system using the system metrics data, and the determined possibility of explicit anomaly within the system using the system text data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2023
From: LI, ZHI; LI, XIAO DONG; JIA, HE JIANG; SHEN, XING XING; TIAN, YE; HAN, SHENG JIE
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 062492/0652 →
Continuity (1)
Related Publication 20240259408A1 · Aug 1, 2024
References Cited (18)
US 9558464B2 · Bassin et al. · 2017 [cited by applicant]
US 9740478B2 · Doganata et al. · 2017 [cited by applicant]
US 9921952B2 · Dean et al. · 2018 [cited by applicant]
US 10116521B2 · Kokkula · 2018 [cited by examiner]
US 10754640B2 · Woulfe et al. · 2020 [cited by applicant]
US 10769009B2 · Luo et al. · 2020 [cited by applicant]
US 11151024B2 · Hwang et al. · 2021 [cited by applicant]
US 20170104774A1 · Vasseur · 2017 [cited by examiner]
US 20200028862A1 · Lin · 2020 [cited by examiner]
US 20200322367A1 · Salvat Lozano · 2020 [cited by examiner]
US 20210058424A1 · Chang · 2021 [cited by examiner]
US 20210089649A1 · Subramanyam · 2021 [cited by examiner]
US 20210211447A1 · Albero · 2021 [cited by examiner]
US 20220303291A1 · Baldini Das Neves · 2022 [cited by examiner]
US 20250363367A1 · Galvin · 2025 [cited by examiner]
US 20260003746A1 · Jiang · 2026 [cited by examiner]
Ali et al., “Classification and Prediction of Software Incidents Using Machine Learning Techniques”, Security and Communication Networks, https://www.hindawi.com/journals/scn/2021/9609823/, published Jan. 1, 2021 (16 pa… [cited by applicant]
Anonymous, “A Method to Adaptively Predict Upcoming Bugs and Automatically Trace Root Cause of a Bug”, ip.com, IPCOM000267759D, https://priorart.ip.com/IPCOM/000267759, published Nov. 20, 2021 (6 pages) (Year: 2021). [cited by applicant]