Kaspersky Machine Learning for Anomaly Detection

Selecting elements of the ML model in the History section

History provides the history of incoming data, the results of its processing by Kaspersky MLAD, artifacts generated by selected ML model elements, and registered incidents.

When multiple ML models are applied to processing data for a monitored object, Kaspersky MLAD gives you the option to select several components of these models to visualize their inference results: An ML model element is not created for the Limit Detector. The dot indicators of incidents registered using this detector are displayed if use of the Limit Detector is enabled and the display of indicators for all incidents is enabled.

The functionality is available after a license key is added.

To view the inference results of an ML model element:

  1. In the main menu, select the History section.
  2. On the opened page, select one or several elements of the ML model from the Model element drop-down list.

    Element names are displayed as <ML model name> A mirrored mathematical inclusion sign icon. <element name>.

    Graphic areas for the selected preset will display the values of tags received by Kaspersky MLAD for the selected time interval. When you customize graph display, graphs for individual graphic areas will show artifacts linked to the tags associated with those areas and generated by the ML model elements that use these tags.

    The central part of the section will display graphs for artifacts from the selected ML model elements. The values shown on the graphs depend on the analytical algorithms used by the elements to identify anomalies.

    To hide the artifacts for a selected ML model element, click A cross-shaped icon. next to the element.

  3. To display a graph of a specific ML model element's artifact at the bottom of the section, do the following:
    1. Click the A gear icon. button below the tag graphs on the left side of the page.

      The ML model element artifact graph display settings pane appears on the right.

    2. From the Model element drop-down list, select the ML model element. You can select only one ML model element from the list.
    3. Click the Close button.

    The graph will show the value of the selected ML model element's artifact as a red line. The graph area above the orange threshold line is highlighted in red to indicate above-threshold artifact values.

The lower part of the graph displays the dot indicators of incidents that were registered by the selected ML model elements. If the display of indicators for all incidents is enabled, dot indicators for incidents that were registered by all ML models and Limit Detector will be displayed.