US2023316112A1PendingUtilityA1

Computer-based systems configured for detecting, classifying, and visualizing events in large-scale, multivariate and multidimensional datasets and methods of use thereof

Assignee: CAPITAL ONE SERVICES LLCPriority: Aug 2, 2019Filed: Apr 17, 2023Published: Oct 5, 2023
Est. expiryAug 2, 2039(~13 yrs left)· nominal 20-yr term from priority
G06N 5/04G06F 16/283G06N 20/00G06F 16/285G06N 3/084G06N 3/105
59
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods of the present disclosure include at least one processor that receives a data set of a data stream from a data source, where the data set includes a time-varying data points. The processor determines event observations associated with data points of the time-varying data points based on a detection model to identify types of the event observations, including: i) anomalies, ii) change-points, iii) patterns, or iv) outliers. The processor generates anomaly records in an event data store based on the event observations and automatically generates event records for at least one of the anomaly records based on variables of at least one dimension of the time-varying data points, where the event record links one or more event observations. The processor automatically applies changes in the event record to each event observation of the one or more event observations based on the linking by the event record.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 receiving, by at least one processor, from at least one detection machine learning model, a plurality of event observations associated with at least one data point of a plurality of time-varying data points;
 wherein each time-varying data point of the plurality of time-varying data points comprises at least one variable of at least one dimension; 
   generating, by the at least one processor, a plurality of anomaly records in at least one event data store based at least in part on the plurality of event observations;   inputting, by the at least one processor, the plurality of anomaly records into a root cause machine learning model to determine at least one root cause event associated with each anomaly record of the plurality of anomaly records;
 wherein the root cause machine learning model comprises a plurality of trained association parameters that are trained according to a respective plurality of independent event training data sets to classify the at least one root cause event; 
   automatically generating, by the at least one processor, at least one event record for the at least one root cause event, the at least one event record linking each anomaly record of the at least one root cause event; and   automatically applying, by the at least one processor, at least one change in the at least one event record of the at least one anomaly event to each event observation of the plurality of event observations based on the linking of the plurality of event observations to the event record.   
     
     
         2 . The method of  claim 1 , further comprising receiving, by the at least one processor, a visualization request from at least one computing device via an associated application programming interface (API) target set. 
     
     
         3 . The method of  claim 1 , further comprising receiving, by the at least one processor, an annotation to the event record by a user of the at least one user from a computing device of the at least one computing device;
 wherein the annotation comprises a modification to root cause type.   
     
     
         4 . The method of  claim 3 , further comprising causing to display, by the at least one processor, an indication of the respective annotation in the visualization of the set of events on a screen of the at least one computing device associated with the at least one user. 
     
     
         5 . The method of  claim 1 , wherein the at least one detection machine learning model comprises:
 i) a plurality of anomaly detection models, and   ii) a plurality of change-point detection models.   
     
     
         6 . The method of  claim 1 , further comprising:
 identifying, by the at least one processor, a set of related event observations associated with a common event based on an association model trained to identify the common event using the at least one variable and the at least one dimension of each time-varying data point associated with each event observation.   
     
     
         7 . The method of  claim 1 , further comprising:
 determining, by the at least one processor, an anomaly classification for the set of related event observations when the set of related event observations is identified based at least in part on a classification model trained to recognize the anomaly classification using the at least one variable and the at least one dimension of each time-varying data point associated with each event observation.   
     
     
         8 . The method of  claim 7 , further comprising:
 determining, by the at least one processor, a root cause type of an event associated with the set of related event observations when the anomaly classification for the set of related event observations is determined based at least in part on a root cause model trained to recognize the root cause type using the anomaly classification of the set of related event observations and the at least one variable and the at least one dimension of each time-varying data point associated with each event observation in the set of related event observations.   
     
     
         9 . The method of  claim 1 , wherein the at least one data set comprise financial transaction data. 
     
     
         10 . The method of  claim 1 , further comprising generating, by the at least one processor, an event management graphical user interface (GUI) to enable a user to manage events linking one or more event observations of the plurality of event observations;
 wherein the event management GUI comprises:
 an event explorer view depicting each event observations of the plurality of event observation in a time-varying representation; 
 an event selection prompt selectable from the explorer view to enable user selection of a previously recorded event linking the one or more event observations of the plurality of event observations; and 
 an event modification prompt selectable from the event selection prompt to modify the event linking the one or more event observations; and
 wherein the event modification prompt comprises user selectable event details comprising:
 i) an event name, 
 ii) an event description, and 
 iii) an event classification. 
 
 
   
     
     
         11 . A system comprising:
 at least one data store configured to store at least one data set;   at least one processor, configured to:
 receive, from at least one detection machine learning model, a plurality of event observations associated with at least one data point of a plurality of time-varying data points;
 wherein each time-varying data point of the plurality of time-varying data points comprises at least one variable of at least one dimension; 
 
 generate a plurality of anomaly records in at least one event data store based at least in part on the plurality of event observations; 
 input the plurality of anomaly records into a root cause machine learning model to determine at least one root cause event associated with each anomaly record of the plurality of anomaly records;
 wherein the root cause machine learning model comprises a plurality of trained association parameters that are trained according to a respective plurality of independent event training data sets to classify the at least one root cause event; 
 
 automatically generate at least one event record for the at least one root cause event, the at least one event record linking each anomaly record of the at least one root cause event; and 
 automatically apply at least one change in the at least one event record of the at least one anomaly event to each event observation of the plurality of event observations based on the linking of the plurality of event observations to the event record. 
   
     
     
         12 . The system of  claim 11 , wherein the at least one processor is further configured to receive an annotation to the event record by a user of the at least one user from a computing device of the at least one computing device;
 wherein the annotation comprises a modification to a root cause type.   
     
     
         13 . The system of  claim 12 , wherein the at least one processor is further configured to cause to display an indication of the respective annotation in a visualization of the set of events on a screen of the at least one computing device associated with the at least one user. 
     
     
         14 . The system of  claim 11 , wherein the detection model comprises:
 i) a plurality of anomaly detection models, and   ii) a plurality of change-point detection models.   
     
     
         15 . The system of  claim 11 , wherein the at least one processor is further configured to:
 identify a set of related event observations associated with a common event based on an association model trained to identify the common event using the at least one variable and the at least one dimension of each time-varying data point associated with each event observation.   
     
     
         16 . The system of  claim 11 , wherein the at least one processor is further configured to:
 determine an anomaly classification for the set of related event observations when the set of related event observations is identified based at least in part on a classification model trained to recognize the anomaly classification using the at least one variable and the at least one dimension of each time-varying data point associated with each event observation.   
     
     
         17 . The system of  claim 16 , wherein the at least one processor is further configured to:
 determine a root cause type of an event associated with the set of related event observations when the anomaly classification for the set of related event observations is determined based at least in part on a root cause model trained to recognize the root cause type using the anomaly classification of the set of related event observations and the at least one variable and the at least one dimension of each time-varying data point associated with each event observation in the set of related event observations.   
     
     
         18 . The system of  claim 11 , wherein the at least one data set comprise transaction data representative of merchant transactions. 
     
     
         19 . The system  claim 11 , wherein the at least one processor is further configured to receive an annotation to the event record by a user of the at least one user from a computing device of the at least one computing device;
 wherein the annotation comprises a removal of a selected event observation from the set of related event observations.   
     
     
         20 . The system of  claim 11 , wherein the at least one processor is further configured to generate an event management graphical user interface (GUI) to enable a user to manage events linking one or more event observations of the plurality of event observations;
 wherein the event management GUI comprises:
 an event explorer view depicting each event observations of the plurality of event observation in a time-varying representation; 
 an event selection prompt selectable from the explorer view to enable user selection of a previously recorded event linking the one or more event observations of the plurality of event observations; and 
 an event modification prompt selectable from the event selection prompt to modify the event linking the one or more event observations; and
 wherein the event modification prompt comprises user selectable event details comprising:
 i) an event name, 
 ii) an event description, and 
 iii) an event classification.

Join the waitlist — get patent alerts

Track US2023316112A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.