Industrial time series data learning fusion and anomaly detection method

By analyzing industrial communication protocols, building IP-PLC mapping relationship tables, and collecting multimodal data, combining spatiotemporal feature fusion and physical constraint parameters to optimize detection thresholds, the problems of weak multi-source data fusion capabilities, lack of spatial context modeling and lack of closed-loop optimization mechanisms in the existing technology are solved, and accurate anomaly detection and root cause traceability of industrial timing data are achieved.

CN120179654AActive Publication Date: 2025-06-20南京迅集科技有限公司

Patent Information

Application Number
CN202510626277.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-06-20
Estimated Expiration
2045-05-15

AI Technical Summary

Technical Problem

The existing industrial timing data anomaly detection technology has multi-dimensional technical bottlenecks, including weak multi-source data fusion capabilities, lack of spatial context modeling and lack of closed-loop optimization mechanisms, resulting in limited robustness and intelligence levels of the system under dynamic operating conditions.

Method used

By analyzing the industrial communication protocol, extracting the PLC device ID and IP address, building an IP-PLC mapping relationship table, collecting multimodal data, and building a physical constraint parameter list based on the physical characteristics of the sensor. Based on structured data, a spatial topology map is constructed and spatially associated feature vectors are generated. Combining the physical constraint parameter list, physical rules and topological rules are encoded to form an enhanced feature set. Through spatial and temporal feature fusion and physical constraint parameters optimization detection thresholds, a global benchmark parameter table is generated, and an alarm response mechanism is built to reverse update physical constraint parameters.

Benefits of technology

It realizes accurate detection and root cause traceability of equipment-level and working condition-level abnormalities, improves the safety, reliability and operation and maintenance efficiency of equipment operation, and solves the technical bottlenecks of multi-source data fusion, spatial context modeling and closed-loop optimization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120179654A_ABST
    Figure CN120179654A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of equipment health monitoring and anomaly detection, and discloses an industrial time series data learning fusion and anomaly detection method, which comprises the steps of constructing an IP-PLC mapping relation table, collecting multi-modal data, constructing a physical constraint parameter list, and generating structured data and a storage index. Time domain features and frequency domain features are extracted, a spatial topological graph is constructed, node spatial feature vectors and edge association strength are extracted, spatial association feature vectors are generated, a constraint rule base is constructed, and an enhanced feature set is formed; aggregating the enhanced feature set and the constraint rule base, generating a multi-dimensional feature matrix and a global reference parameter table, further constructing a global reference system, obtaining an equipment-level anomaly probability matrix, and generating a working condition-level anomaly probability matrix; hierarchical optimization is carried out through hierarchical modeling, and an optimization parameter set is generated; constructing an alarm response mechanism, and performing reverse updating to form closed-loop iteration; and an interpretable and extensible solution is provided for equipment health management in a complex industrial scene.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of equipment health monitoring and anomaly detection, and more specifically, to a method for learning fusion and anomaly detection of industrial time-series data. Background Art

[0002] With the rapid development of industrial automation and intelligent operation and maintenance technologies, equipment health monitoring in complex production lines poses higher requirements for anomaly detection. Enterprises urgently need to integrate multi-source heterogeneous data (such as vibration, temperature, image signals, process parameters, etc.), combine physical constraint rules and spatial topological relationships, and build an intelligent diagnostic system with strong dynamic adaptability to address the impacts of non-steady-state noise, collaborative failure risks, and process fluctuations during equipment operation on production safety and efficiency. However, existing systems mostly rely on single data sources or static threshold strategies, lacking the ability to deeply mine the fusion of spatio-temporal features, modeling of the correlation between devices, and dynamic tolerance adjustment, and it is difficult to achieve global collaborative optimization of anomaly detection and root cause tracing.

[0003] Current industrial time-series data anomaly detection technologies have multi-dimensional technical bottlenecks, resulting in limited robustness and intelligence level of the system under dynamic working conditions. First, the multi-source data fusion ability is weak. The system can only process single-type sensor data in isolation (such as only focusing on vibration spectra or temperature trends), and does not effectively integrate time-domain, frequency-domain, spatial features, and physical constraint rule bases, resulting in the omission of key patterns (such as the chain temperature rise caused by the failure of the cooling system). Second, the spatial context modeling is missing. Existing methods ignore the influence propagation paths of equipment layout and adjacent nodes (such as the heat conduction chain reaction), and cannot identify the collaborative failure risks across devices. Finally, the closed-loop optimization mechanism is lacking. Most solutions are "open-loop detection" and lack a feedback loop based on execution records (such as shutdown instructions, maintenance logs), resulting in a high false alarm rate. The above defects jointly restrict the accurate detection ability and self-evolution level of the system in complex dynamic environments. Summary of the Invention

[0004] To overcome the above defects of the prior art and to achieve the above object, the present invention provides the following technical solution: A method for learning fusion and anomaly detection of industrial time-series data, including: S1: Analyze the industrial communication protocol, extract the PLC device ID and IP address, and establish an initial device list; combine the IP address and device ID to construct an IP-PLC mapping relationship table; collect multi-modal data, align it according to the time stamp, and then construct a physical constraint parameter list according to the physical characteristics of the sensors; manage the data through a hierarchical storage strategy to generate structured data and storage indexes; S2: Extract time-domain feature vectors and frequency-domain feature vectors based on structured data; construct a spatial topology graph based on the IP-PLC mapping relation table, extract node spatial feature vectors and edge association strengths, and generate spatial association feature vectors; combine the physical constraint parameter list, encode physical rules and topology rules, construct a constraint rule library, and form an enhanced feature set; S3: Aggregate the enhanced feature sets and constraint rule libraries of industrial equipment in the factory to generate a multi-dimensional feature matrix. Optimize the detection threshold through spatio-temporal feature fusion and physical constraint parameters to generate a global benchmark parameter table, and then construct a global benchmark system; generate a device-level anomaly probability matrix and a working condition-level anomaly probability matrix based on the global benchmark system; S4: Based on the device-level anomaly probability matrix and the generated working condition-level anomaly probability matrix, generate a device-level feature model and a working condition-level feature model through hierarchical modeling, and perform hierarchical optimization to generate an optimized parameter set; S5: Based on the output results of the device-level feature model and the working condition-level feature model and the optimized parameter set, construct an alarm response mechanism, and reversely update the physical constraint parameters associated with the sensors to form a closed-loop iteration.

[0005] Further, the methods of storing the structured data and its indexes include: Parse the communication protocol data of PLC devices through an industrial protocol parsing mechanism, and extract device identifiers, including IP addresses and device IDs; Integrate the IP addresses and device IDs of all PLC devices to establish an initial device list; Based on the initial device list, identify PLC devices with the same IP address. Combine the physical interface information to assign a unique physical interface to each PLC device, assign PLC devices with the same IP address to different physical interfaces, and set interface bindings through a network configuration tool; Integrate the device ID, IP address, and physical interface information into a structured table to obtain an IP-PLC mapping relation table; Real-time collect various types of data from devices through various types of sensor interfaces as the multi-modal data of the devices, align them according to timestamps to form an original data stream, and then perform data cleaning and standardization processing to integrate them into a preprocessed data stream; Define the physical constraint parameters of various types of sensors according to the physical characteristics of the devices, and integrate and construct them to obtain a physical constraint parameter list; Based on the physical constraint parameter list, embed the physical constraint parameters through the hardware layer, algorithm layer, and data layer; The embedding of the hardware layer is to define the sampling parameters of the sensors according to the physical constraint parameters; the embedding of the algorithm layer is to embed different physical equations for different data types; The data layer is embedded to define real-time constraints and security constraints. The real-time constraints are timestamp synchronization and data range check, and the security constraints are adding hardware-level threshold triggers; All types of data are divided into high-timeliness data and low-timeliness data according to the expert experience method. The high-timeliness data is divided into hot data, and the low-timeliness data is divided into cold data. Then, the data storage levels are divided according to the hot data / cold data strategy; The data is standardized into a structured format through data standardization technology to obtain structured data; a storage list is synchronously generated to record the physical location and access priority of data blocks, and a storage index is obtained.

[0006] Furthermore, the way to construct the constraint rule library and form the enhanced feature set includes: Extract the time-domain features of each type of data from the structured data, and then horizontally splice the time-domain features of each type of data into a multi-modal time-domain feature vector; Decompose each type of data through frequency-domain analysis method, and then extract the frequency-domain features of each type of data; Set a fixed time window, and horizontally splice the frequency-domain feature vectors of each type of data within each time window in chronological order to form a single time-series feature item; Arrange the single time-series feature items of all time windows in chronological order to generate a multi-modal frequency-domain feature sequence; Based on the IP-PLC mapping relationship table, construct the spatial topology map of the sensor, extract the node spatial feature vector and edge association strength in the spatial topology map, obtain the spatial association feature vector of each node as the spatial feature of the sensor, and encode the physical constraint parameter list into the physical constraint rule library in combination with the spatial topology map; Horizontally splice the time-domain features, frequency-domain features and spatial features, and convert the rule thresholds in the physical constraint rule library into numerical features, and merge all features to form a multi-modal enhanced feature set; At the same time, in combination with the spatial features, add topological constraints to the physical constraint rule library to form a constraint rule library.

[0007] Furthermore, the way to obtain the node spatial feature vector and edge association strength includes: Take each sensor as a node, and assign attributes to each node, including sensor type, range and installation coordinates; Based on the IP-PLC mapping relationship table, establish edges for the nodes, and assign attributes to each edge, including the physical distance, directionality and communication protocol between sensors as edge attributes, and construct the spatial topology map; Based on the edges between all nodes in the spatial topology graph, define the nodes with edges as connected by the connection relationship, and the nodes without edges as not connected by the connection relationship. Extract the connection relationships between all nodes and construct an adjacency matrix; Encode the node attributes into numerical feature vectors as node features, and extract all node features to construct a node feature matrix; Perform normalization processing on the adjacency matrix. Based on the node attribute matrix and the normalized adjacency matrix, for each node, aggregate the node features of all adjacent nodes to generate the node spatial feature vector of each node, including type correlation, spatial proximity, and range consistency; At the same time, based on any pair of nodes with edges, extract the physical distance, communication protocol, and sensor type between the two nodes; Set the attenuation coefficient of the physical distance, multiply the physical distance by the attenuation coefficient, add 1, and then take the reciprocal to obtain the physical distance intensity value; For the communication protocol between two nodes, if the communication protocols are exactly the same, assign a communication protocol consistency intensity value of 1, and if the communication protocols are different, the communication protocol consistency intensity value is 0; According to the predefined type complementary rule table, determine the adjustment coefficient of the sensor type combination, and multiply the adjustment coefficient by the default basic sensor type complementary intensity value to obtain the final sensor type complementary intensity value; Perform weighted summation on the physical distance intensity value, communication protocol consistency intensity value, and sensor type complementary intensity value between nodes to calculate the edge association intensity.

[0008] Furthermore, the obtaining method of the physical constraint rule library includes: Horizontally splice the node spatial feature vector of the node and the edge association intensity to obtain the spatial association feature vector of each node; Based on the physical constraint parameter list, combine the spatial topology graph to convert the physical constraint parameter list into structured rules, including physical rules and topological rules, and merge the physical rules and topological rules into a structured physical constraint rule library.

[0009] Furthermore, the generation method of the multi-dimensional feature matrix includes: Extract the time-domain feature vector, frequency-domain feature vector, and spatial association feature vector across devices from the enhanced feature set as heterogeneous data; Based on the device ID and physical interface information, perform timestamp alignment processing on all timestamped heterogeneous data across devices; And perform normalization processing on the processed heterogeneous data according to the range in the physical constraint parameter list, and integrate to obtain a standardized data set; Extract the physical constraints of each device from the physical constraint rule base as the single-device benchmark; then, based on the edge association strength in the spatial topology graph, derive the joint constraints of each device under the collaborative working conditions as the cross-device benchmark; Assign weights to each device according to the criticality of the device in the factory production chain through the expert experience method, and then perform weighted averaging on the single-device benchmark to generate a single-type benchmark range that is common to the whole factory; Integrate the single-type benchmark ranges of all types to generate a global benchmark parameter table; Then, based on the physical constraints in the global parameter table and the expert experience method, preset a static allowable deviation range for each type of device as the original tolerance of each device; Define the ratio of the actual value of the device collected by the sensor to the corresponding global benchmark parameter as the benchmark verification function; Extract time-series statistical features by splitting the standardized data set with a fixed time window, and use a filtering algorithm to separate the long-term trend and short-term fluctuations; Based on the adjacency matrix of the spatial topology graph, aggregate the spatial context features of the nodes to generate a spatial context vector; Convert the physical constraints in the physical constraint rule base into feature screening conditions to eliminate the data that does not conform to the physical constraints; Then, horizontally concatenate the time-domain feature vector, frequency-domain feature vector, and spatial context vector in sequence into a feature sequence with a unified length, and compress the redundant dimensions of the feature sequence through the principal component analysis method to generate a multi-dimensional feature matrix in a unified format.

[0010] Furthermore, the construction method of the global benchmark system includes: Define high-risk devices and low-risk devices based on industry standards, and perform detection parameter binding and detection priority allocation for high-risk devices and low-risk devices; The detection parameter binding is as follows: assign initial sensitivity coefficients to high-risk devices and low-risk devices, and assign an initial fault tolerance coefficient to low-risk devices; and define the sensitivity allocation rule as that the sensitivity coefficient of high-risk devices is greater than that of low-risk devices; The detection priority allocation is as follows: according to the expert experience method, divide the various types of data collected from the device into two types: safety type and efficiency type, and allocate the contribution degree coefficient of the benchmark verification function for each type of data according to the priority that the safety type is greater than the efficiency type; Modify the benchmark verification function through the sensitivity coefficient to obtain a modified benchmark verification function; Modify the original tolerance through the fault tolerance coefficient to obtain a modified dynamic tolerance; take the sum of the actual value of the device collected by each type of sensor and the dynamic tolerance to obtain a dynamic tolerance range; If the actual value of any type of device is greater than the maximum value of the corresponding dynamic tolerance range, the device is determined to be abnormal and an alarm is issued; If the actual values of all types of devices are less than or equal to the maximum value of the corresponding dynamic tolerance range, the correction reference check function is calculated separately for the actual values of each type of device to obtain the sensitivity of the actual values of each type of device; According to the classification of security and efficiency for each type of data, the contribution coefficient is used as the weight of the sensitivity of the actual device value, and then the sensitivities of the actual values of all types of devices are weighted and fused to generate a comprehensive check value; If the comprehensive check value is greater than the preset check value threshold, it is determined that the device is abnormal and an alarm is issued; if the comprehensive check value is less than or equal to the check value threshold, it is determined that the device is not abnormal; Combined with the standardized data set and the global reference parameter table, a dynamic correction strategy is defined, including the real-time synchronization mechanism of dynamic tolerance and the feedback loop optimization of the sensitivity coefficient; The real-time synchronization mechanism of dynamic tolerance is to calculate the standard deviation of the dynamic tolerance within a fixed time window. If the standard deviation of the dynamic tolerance is greater than the preset standard deviation threshold, the dynamic tolerance is updated. The feedback loop optimization of the sensitivity coefficient is to calculate the ratio of the number of false alarms to the total number of alarms as the false alarm rate, and automatically adjust the sensitivity coefficient according to the false alarm rate; Integrate the multi-dimensional feature matrix, the reference check function, and the global reference parameter table to form a global reference system; and it includes static thresholds, dynamic tolerances, and feedback optimization logic.

[0011] Furthermore, the generation methods of the device-level abnormal probability matrix and the generation of the working condition-level abnormal probability matrix include: Based on the global reference system, calculate the ratio of the difference between the actual device value and the maximum value of the dynamic tolerance range to the dynamic tolerance to obtain the standardized deviation; If the standardized deviation is negative, it is assigned a value of 0; Furthermore, map the standardized deviation to a probability value as the preliminary abnormal probability; The mapping method can normalize the standardized deviation to the [0,1] interval through linear normalization; Combined with the multi-dimensional feature matrix and the physical constraint rule base, the multi-dimensional feature matrix is processed for reconstruction error through the principal component analysis method to obtain the PCA reconstruction error probability; Perform probability density estimation on the multi-dimensional feature matrix through the Gaussian mixture model to obtain the GMM probability; Weight and fuse the preliminary abnormal probability, the PCA reconstruction error probability, and the GMM probability to obtain the comprehensive abnormal probability; Use the edge association strength in the spatial topology graph to correct the comprehensive abnormal probability to obtain the corrected comprehensive abnormal probability; Organize the comprehensive anomaly probabilities of all devices into a matrix structure according to the time series by device ID and timestamp, obtaining a device-level anomaly probability matrix, which includes the number of devices, the number of time windows, and the comprehensive anomaly probability of each device in each time window. Aggregate the comprehensive anomaly probabilities of associated devices based on the spatial topology graph according to the process stage and production line module. Combine the joint constraints in the physical constraint rule base and introduce the operating condition characteristics to obtain the operating condition-level anomaly probability matrix.

[0012] Furthermore, the generation method of the optimization parameter set includes: Extract the time series features from the device-level anomaly probability matrix, perform PCA dimensionality reduction on the extracted time series features to obtain the low-dimensional feature vectors of the time series features, and perform physical constraint verification through the physical constraint rule base to filter out the data values that do not conform to the physical rules, obtaining the device-level feature model. Based on the spatial topology graph, aggregate the comprehensive anomaly probabilities of associated devices to generate the preliminary operating condition-level probability, and establish a causal relationship model by combining the joint rules in the physical constraint rule base. Integrate the operating condition-level features as supplementary inputs, use the spatial topology graph as the graph structure, and train the GNN model to capture the dependency relationships between devices to obtain the operating condition-level feature model. According to the classification of high-risk and low-risk types of devices, perform device-level optimization, quantify the influence intensity of adjacent nodes, jointly optimize the false alarm rate, perform operating condition-level optimization, and generate the optimization parameter set.

[0013] Furthermore, the construction method of the alarm response mechanism includes: Set the comprehensive risk level according to the values in the device-level anomaly probability matrix and the operating condition-level anomaly probability matrix. Divide the alarm levels based on the comprehensive risk level. Automatically generate an operation and maintenance work order after the alarm is triggered; automatically allocate the operation and maintenance work order according to the matching of the alarm level and the skills of the maintenance personnel, and optimize the response path in combination with traffic information. Locate the root cause of the anomaly by combining the multi-dimensional feature matrix, the physical constraint rule base, and the historical maintenance records. Dynamically adjust the sensitivity coefficient and tolerance range according to the false alarm rate; store each maintenance process in the preset operation and maintenance database, and then regularly update the physical constraint rule base.

[0014] The technical effects and advantages of the industrial time series data learning fusion and anomaly detection method of the present invention: The present invention takes the time-series data of industrial equipment (such as vibration, temperature, images, etc.) as input, and through IP-PLC mapping, multi-modal feature fusion, dynamic tolerance mechanism and closed-loop optimization, realizes the accurate detection and root cause tracing of equipment-level and working condition-level abnormalities; the core goal is to improve the safety, reliability and operation and maintenance efficiency of equipment operation in industrial scenarios, and directly serve the equipment health management needs in intelligent manufacturing.

[0015] First, based on communication protocol parsing and physical interface binding, an IP-PLC mapping relationship table is generated. Combining the standardized processing of multi-source sensor (such as vibration, temperature, image) data and the embedding of physical constraint parameters (sampling rules, hardware thresholds), it breaks through the dependence of traditional systems on single data sources or static thresholds, solves the problems of difficult fusion of multi-source heterogeneous data and lack of physical association, and makes the equipment feature representation more comprehensive and in line with engineering logic. Secondly, by quantifying the edge association strength (physical distance attenuation coefficient, communication protocol consistency strength) between adjacent nodes through a spatial topology graph, and introducing algorithms such as principal component analysis (PCA) and Gaussian mixture model (GMM) to generate a comprehensive anomaly probability. Compared with the prior art that only focuses on single-point features or ignores the spatial context, the present invention significantly improves the collaborative fault identification ability. For example, the chain temperature rise risk caused by the failure of the cooling system can be accurately located. Then, a dual-regulation mechanism of dynamic tolerance and sensitivity coefficient is constructed. The threshold is updated in real time according to the content difference standard deviation within the time window, and the sensitivity coefficient is automatically optimized through the false alarm rate feedback loop, enabling the system to adapt to dynamic factors such as production line capacity fluctuations and seasonal changes. At the same time, it supports differential management of high / low-risk equipment (such as sensitivity coefficient of high-risk equipment > sensitivity coefficient of low-risk equipment), taking into account both safety and operation efficiency. Finally, by reverse-updating the physical constraint rule base and historical compensation template through execution records, a closed-loop iterative link of virtual-real interaction is formed. Compared with the existing "open-loop detection" scheme that relies on manual experience to adjust strategies, the present invention realizes the automatic optimization of anomaly detection weights and the continuous evolution of the rule base. The present invention solves the data correlation problem through IP-PLC mapping and physical constraint embedding, improves the collaborative detection ability through spatial topology modeling and dynamic tolerance mechanism, and enhances the system self-adaptability through the closed-loop optimization link. Finally, it realizes the full-process intelligence from data acquisition to root cause tracing, and has significant advantages over traditional methods in terms of false alarm rate control, collaborative fault identification accuracy and strategy iteration efficiency, providing an interpretable and extensible solution for equipment health management in complex industrial scenarios. Description of the Drawings

[0016] Figure 1 Schematic diagram of the learning fusion and anomaly detection method for the industrial time-series data of the present invention; Figure 2Schematic diagram for constructing an enhanced feature set and a constraint rule base in the learning fusion and anomaly detection method for industrial time-series data of the present invention; Figure 3 Schematic flow diagram of the learning fusion and anomaly detection method for industrial time-series data of the present invention; Figure 4 Schematic diagram of the learning fusion and anomaly detection system for industrial time-series data of the present invention. Detailed implementation manners

[0017] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0018] Embodiment 1 Please refer to Figures 1 to 3 As shown, the learning fusion and anomaly detection method for industrial time-series data in this embodiment includes: S1: Analyze the industrial communication protocol, extract the PLC device ID and IP address, and establish an initial device list; combine the IP address and device ID to construct an IP-PLC mapping relationship table; collect multi-modal data, align it according to the time stamp, and then construct a physical constraint parameter list according to the physical characteristics of the sensor; manage the data through a hierarchical storage strategy to generate structured data and storage indexes; S2: Based on the structured data, extract time-domain feature vectors and frequency-domain feature vectors; construct a spatial topology graph based on the IP-PLC mapping relationship table, extract node spatial feature vectors and edge association strengths, and generate spatial association feature vectors; combine the physical constraint parameter list, encode the physical rules and topology rules, construct a constraint rule base, and form an enhanced feature set; S3: Aggregate the enhanced feature set and the constraint rule base of industrial devices in the factory to generate a multi-dimensional feature matrix, optimize the detection threshold through spatio-temporal feature fusion and physical constraint parameters, generate a global benchmark parameter table, and then construct a global benchmark system; generate a device-level anomaly probability matrix and a working condition-level anomaly probability matrix based on the global benchmark system; S4: Based on the device-level anomaly probability matrix and the generated working condition-level anomaly probability matrix, generate a device-level feature model and a working condition-level feature model through hierarchical modeling, and perform hierarchical optimization to form an optimized parameter set; S5: Based on the output results of the device-level feature model and the working condition-level feature model and the optimized parameter set, construct an alarm response mechanism, and reversely update the physical constraint parameters associated with the sensor to form a closed-loop iteration; Parse the communication protocol data of PLC devices through industrial protocol parsing mechanisms (such as Modbus and OPC UA parsers), and extract device identifiers, including IP addresses and device IDs; Integrate the IP addresses and device IDs of all PLC devices to establish an initial device list; Based on the initial device list, identify PLC devices with the same IP address. Combine physical interface information (such as eth0 and eth1) to assign a unique physical interface to each PLC device, assign PLC devices with the same IP address to different physical interfaces, and set interface bindings through network configuration tools (such as iproute2); For example, if it is found that two PLC devices (PLC_A and PLC_B) have the same IP address 192.168.1.1, they need to be bound to different physical interfaces; Example: Configure IP binding in the Linux system; 192.168.1.1 PLC_A_eth0 is bound to the eth0 interface; 192.168.1.1 PLC_B_eth1 is bound to the eth1 interface; Integrate the device ID, IP address, and physical interface information into a structured table to obtain an IP-PLC mapping relationship table; used to record the correspondence between the IP address, physical interface, and device ID of each PLC device; It should be noted that PLC devices, as the core of data acquisition and control, are responsible for protocol parsing, data integration, and transmission. They are the intermediate hubs of data acquisition, used to read data from devices such as sensor controllers and parse it through industrial protocols; Real-time collect various types of data from devices through various types of sensor interfaces as the multimodal data of the devices (including but not limited to vibration data (collected by accelerometer sensors), temperature data (collected by thermocouple sensors), and image data (collected by cameras)). Align them according to timestamps (such as synchronize all sensor clocks through NTP, and uniformly access vibration, temperature, and image data through ECC800-Pro devices) to form a raw data stream, and then perform data cleaning and standardization processing to integrate it into a preprocessed data stream; According to the physical characteristics of the devices, define the physical constraint parameters of various types of sensors (such as range, accuracy, response time), and integrate and construct them to obtain a physical constraint parameter list; Examples of physical constraint parameters: Vibration type: sampling frequency (such as 0~10kHz), acceleration limit (such as ±20g), noise threshold (such as ISO 10816 standard); Temperature category: Range (maximum and minimum temperature, e.g., -40°C to 150°C), safety threshold (e.g., material melting point 1500°C), response time (e.g., ≤ 1 second); Image category: Resolution (e.g., 4096×2160), minimum defect size (e.g., 0.1mm), lighting condition (e.g., Lux≥500); Embed physical constraint parameters through the hardware layer, algorithm layer, and data layer based on the physical constraint parameter list. The embedding in the hardware layer is to define the sampling parameters of the sensor according to the physical constraint parameters. Exemplarily, define the sampling frequency, range, and filtering parameters of the vibration sensor, and configure the FPGA pins (such as Package Pin U18), I / O standard (LVCMOS33); define the range, accuracy (±0.5°C), and communication protocol (1-Wire / Modbus) of the temperature sensor, and define the resolution, frame rate, exposure time, and trigger mode (hardware synchronization) of the image sensor; The embedding in the algorithm layer is to embed different physical equations for different data types. For example, the Fourier transform and Newton's law for vibration data, the constrained heat conduction equation (Q = KAΔT) for temperature data, and the geometric constraint (constrained size range) for image data; The embedding in the data layer is to define real-time constraints and safety constraints. The real-time constraints are timestamp synchronization (NTP / GPIO) and data range check (removing outliers), and the safety constraint is to add a hardware-level threshold trigger (e.g., when the vibration intensity > 4mm / s, the relay stops); It should be noted that physical constraint parameters are usually defined by equipment manufacturers or physical models (such as the upper limit of motor speed), including mechanical and dynamic constraints (such as the upper limit of motor speed (e.g., motor speed ≤ 1500 rpm), vibration threshold (e.g., vibration amplitude ≤ 4 mm / s), structural stiffness and strength limits (such as the maximum allowable deformation of a robotic arm), inertia and damping parameters (such as the moment of inertia and damping coefficient of a robotic arm)), thermodynamic constraints (such as the temperature safety range (e.g., equipment surface temperature ≤ 80 °C), heat conduction equation (e.g., Q = KAΔT (relationship between heat flux density and temperature gradient)), cooling rate limit (e.g., temperature drop rate ≤ 5 °C / minute)), energy and fluid dynamics constraints (such as the energy conservation equation (e.g., energy conservation equation for the wellbore flow system of an electric pump well), liquid pressure constraint (such as the pressure range of a hydraulic system 20 - 40 MPa), relationship between flow rate and pressure (such as the coupling relationship between flow rate and pumping pressure)), material and structure constraints (such as the fatigue limit of materials (e.g., stress-life curve of steel), natural frequency of the structure (e.g., the first natural frequency of a robotic arm is 1.2 Hz), deformation threshold (such as the maximum allowable bending deformation of a machining robotic arm)), and control and safety constraints (such as control instruction constraints (e.g., speed adjustment range 80% - 100% of the rated value), safety interlock conditions (such as automatic shutdown when the temperature exceeds the threshold)); All types of data are divided into high-timeliness data and low-timeliness data according to the expert experience method. The high-timeliness data is further divided into hot data, and the low-timeliness data is divided into cold data. Then, the data storage levels are divided according to the hot data / cold data strategy (e.g., vibration and temperature data with high-frequency access are stored in SSD, and historical image data is stored in HDD); The data is standardized into a structured format (such as a TSDB time series database) through data standardization techniques (such as ETL) to obtain structured data; a storage list is synchronously generated to record the physical location and access priority of data blocks, obtaining a storage index; It should be noted that the implementation of dynamic IP binding can be achieved through IP configuration methods (such as etc / hosts), combined with Linux network namespace technology, to ensure that PLC devices with the same IP communicate through different physical interfaces; then, the iptables or iproute2 tools are used to implement route table separation to avoid IP conflicts; In the embedding of physical constraint parameters, physical constraints (such as the heat conduction equation) need to be attached to the data metadata in a standardized format (such as JSON) for subsequent anomaly detection; For the hierarchical storage strategy, according to the hot data strategy, the LSM-Tree structure can be used to manage write and merge operations to optimize storage efficiency; The design of the storage index table refers to the database index principle, and the data block can be quickly located through ROWID; Through the above steps, a complete process from device network configuration to data acquisition, constraint embedding, and storage management is achieved, providing reliable input for subsequent steps; Extract the time-domain features of various types of data from the structured data, and then horizontally splice the time-domain features of various types of data into a multi-modal time-domain feature vector; Decompose various types of data through frequency-domain analysis methods (such as wavelet transform, Fourier transform), and then extract the frequency-domain features of various types of data (such as the proportion of fundamental frequency energy, high-frequency impact energy); Set a fixed time window (such as every 10 minutes, every 1 hour, every 1 day), and horizontally splice the frequency-domain feature vectors of various types of data within each time window in chronological order to form a single time-series feature item; Arrange the single time-series feature items of all time windows in chronological order to generate a multi-modal frequency-domain feature sequence; Exemplarily, based on the structured data, extract the vibration amplitude in the vibration data (such as peak vibration intensity, root mean square RMS) and the temperature fluctuation rate in the temperature data (the temperature change rate per unit time, that is, the ratio of temperature to time), and then horizontally splice them into a time-domain feature vector; Perform multi-scale decomposition on the vibration data through wavelet transform (such as Daubechies wavelet) to obtain wavelet coefficients in different frequency bands; Extract the proportion of fundamental frequency energy in the wavelet coefficients of different frequency bands (such as the energy of the wavelet coefficients in the first 3 scales, used to reflect the fundamental frequency vibration of the device) as the low-frequency trend term, and extract the energy of the wavelet coefficients in the high-frequency scale (such as the last 2 scales, reflecting the local fault impact energy) as the high-frequency impact energy; Horizontally splice the low-frequency trend term and the high-frequency impact energy to form a vibration frequency-domain feature vector (such as {proportion of low-frequency energy, proportion of high-frequency energy}); Decompose the temperature data into a combination of sine waves in different frequency bands through Fourier transform, and extract the low-frequency component with the largest amplitude in the sine wave combination (such as the periodic fluctuation frequency of the device, for example, a 24-hour period corresponds to 0.04 Hz) as the main frequency energy (the frequency component with the largest amplitude in the temperature data, the energy is concentrated and the low-frequency frequency component with physical significance, usually reflecting the periodic temperature change of the device, corresponding to the dominant period of temperature change, such as the temperature rise process after the device motor starts (slow change, dominated by low-frequency components)); Extract the total energy of the frequency band higher than the preset frequency threshold (such as 1 Hz, 10 Hz) in the sine wave combination (such as the total energy > 10 Hz, corresponding to short-period fluctuations, such as high-frequency impact energy caused by faults) as the high-frequency noise energy (the frequency components in the high-frequency band, whose amplitude is usually small and has no actual physical meaning, such as sensor noise (such as Johnson noise of thermistor), environmental interference (such as instantaneous airflow, electromagnetic interference) or sampling error (ADC quantization error or noise in signal transmission)), and splice the main frequency energy and the high-frequency noise energy level to form a temperature frequency domain feature vector (such as {main frequency energy ratio, high-frequency noise energy ratio}); Set a fixed time window (such as every 10 minutes, every 1 hour, every 1 day), and horizontally splice the vibration frequency domain feature vector and the temperature frequency domain feature vector within each time window in chronological order to form a single time series feature item; Arrange all the single time series feature items of the time windows in chronological order to generate a multi-modal frequency domain feature sequence; Exemplarily, the method of converting temperature data into the frequency domain is as follows: Assume that there is a temperature value for each timestamp, and combine the temperature values of all timestamps into a set of temperature data; Obtain a set of frequency components according to this set of temperature data through the Fourier transform formula, and each frequency component corresponds to an amplitude and a phase; The Fourier transform formula is: ; where, represents the nth temperature value, is the frequency component, and the value range is 0 ≤ f ≤ N / 2 (due to symmetry), = 1 corresponds to the frequency with a period of N / f = 10 sampling points (such as when the temperature data is sampled hourly, the period is 10 hours), = 0.1 corresponds to the low-frequency component with a period of 10 / 0.1 = 100 sampling points, represents the natural constant, represents the imaginary unit, represents the pi, is the total number of data points, represents the frequency domain result after Fourier transform, indicating the complex amplitude (including amplitude and phase information) of the temperature data at the frequency The amplitude represents the energy magnitude of the signal at the frequency The phase represents the phase shift of this frequency component relative to the time origin. For example, CX(0.1) represents the energy of the low-frequency component in a set of temperature data; This formula decomposes the temperature data into the superposition of different frequency components by accumulating the product of the time domain data and the sub-exponential function ; Based on the IP-PLC mapping relation table, construct the spatial topology graph of the sensors, extract the node spatial feature vectors and edge association strengths in the spatial topology graph, obtain the spatial association feature vectors of each node, which are used as the spatial features of the sensors, and encode the physical constraint parameter list into a physical constraint rule base in combination with the spatial topology graph; Horizontally splice the time-domain features, frequency-domain features and spatial features, and convert the rule thresholds in the physical constraint rule base (such as temperature value > 125°C, temperature difference between sensor 1 and 2 > 5°C) into numerical features, and merge all features to form a multi-modal enhanced feature set; At the same time, in combination with the spatial features, add topological constraints (such as when the temperature difference between adjacent sensors exceeds the threshold, trigger a linkage alarm) to the physical constraint rule base to form a constraint rule base; the constraint rule base includes the rule name (the unique identifier of the rule (such as vibration shock energy exceeding the standard)), the trigger condition (feature threshold or logical expression (such as high-frequency energy ratio > 0.3)), and the execution action (pre-defined operations (such as generating a warning, triggering a shutdown)); Take each sensor (vibration, temperature, image sensor) as a node, and assign attributes to each node, including sensor type, range, and installation coordinates (three-dimensional space coordinates); Based on the IP-PLC mapping relation table, establish edges for the nodes, and assign attributes to each edge, including the physical distance between sensors (such as distance ≤ 1m), directionality (such as sensor 1 is on the left of 2, and sensor 1 and 2 are connected through a directed PLC port), and communication protocol (such as Modbus TCP or Profibus) as edge attributes, and construct the spatial topology graph; Exemplary spatial topology graph: Sensor A (vibration) —— physical distance ≤ 1m → Sensor B (temperature); Sensor C (image) —— PLC port X2 → Controller; Exemplary edge attributes: Sensor 1 and 2 are located on both sides of the bearing of the same device, the physical distance ≤ 1m, and connect port 0 and port 1 of the PLC port; Based on the edges between all nodes in the spatial topology graph, define the nodes with edges as connected by the connection relationship, and define the nodes without edges as not connected by the connection relationship, extract the connection relationships between all nodes, and construct an adjacency matrix (each element in the adjacency matrix is 1 or 0, 1 means there is an edge between the corresponding two nodes, which is connected, and 0 means there is no edge between the corresponding two nodes, which is not connected); Encode the node attributes into numerical feature vectors, which are used as node features, and extract all node features to construct a node feature matrix; Exemplary node attribute encoding method: Sensor type: One-Hot encoding (such as vibration sensor = [1,0], temperature sensor = [0,1], image sensor = [0,0]); Range: Normalized value (e.g., 0 - 150 °C → 0.8 represents 120 °C); Installation coordinates: Directly use three - dimensional coordinate values; Normalize the adjacency matrix. Based on the node attribute matrix and the normalized adjacency matrix, for each node, aggregate the node features of all adjacent nodes to generate the node spatial feature vector of each node, including type correlation (similarity to the sensor types of adjacent nodes), spatial proximity (average distance weight to adjacent sensors), and range consistency (similarity of the range of adjacent sensors); Meanwhile, based on any pair of nodes with an edge, extract the physical distance, communication protocol, and sensor type between the two nodes; Set the attenuation coefficient of the physical distance (e.g., 0.5, set by expert experience). Multiply the physical distance by the attenuation coefficient, add 1, and then take the reciprocal to obtain the physical distance intensity value; that is, physical distance intensity value = 1 / (1 + physical distance × attenuation coefficient). The attenuation coefficient is used to control the influence degree of the physical distance on the physical distance intensity; For the communication protocol between two nodes, if the communication protocols are exactly the same, assign a communication protocol consistency intensity value of 1. If the communication protocols are different, the communication protocol consistency intensity value is 0; that is, when sensors use the same communication protocol, the association intensity increases; when the protocols are different, the intensity decreases; According to the predefined type complementarity rule table, determine the adjustment coefficient of the sensor type combination. Multiply the adjustment coefficient by the default base sensor type complementarity intensity value (usually 1) to obtain the final sensor type complementarity intensity value; that is, when the sensor types are complementary (such as vibration and temperature), the association intensity needs to be adjusted to reflect their synergistic effect; Exemplary type complementarity rule table: [Sensor type combination: Vibration and temperature], [Adjustment coefficient: 1.5], [Description: High - coupling relationship (such as bearing failure)]; [Sensor type combination: Homogeneous sensors], [Adjustment coefficient: 0.8], [Description: Redundant backup or redundant monitoring]; Perform a weighted sum of the physical distance intensity value, communication protocol consistency intensity value, and sensor type complementarity intensity value between nodes to calculate the edge association intensity; Exemplary weighted sum: Assign different importance weights to the three parts of intensity values (e.g., α = 0.4, β = 0.3, γ = 0.3). Assume that the physical distance intensity between sensor 1 and 2 is 0.5, the communication protocol consistency intensity is 1.0, and the type complementarity intensity is 1.5. Then the edge association intensity = (0.4 × 0.5)+(0.3 × 1.0)+(0.3 × 1.5)=0.2 + 0.3+0.45 = 0.95; Horizontally concatenate the node space feature vector of the node with the edge association strength to obtain the spatial association feature vector of each node; The specific processing flow for generating the node space feature vector is as follows: Step 1: Add self-connections to the adjacency matrix and perform normalization to eliminate the influence of node degree differences, obtaining a normalized adjacency matrix; Step 2: For each node, aggregate the node features of all its adjacent nodes, The relational expression is: ; where, represents the node space feature vector of node v after the (l + 1)-th processing, represents the activation function, such as ReLU, Sigmoid, which is used to introduce non-linear factors to help identify more complex patterns, u represents the adjacent node, and U represents the set of all adjacent nodes, represents the normalization term, which is used to balance the contributions between nodes with different degrees, where is the degree matrix based on the adjacency matrix plus self-connections (i.e., the normalized adjacency matrix), and are the degrees of nodes v and u respectively (i.e., the number of edges connected to them plus self-connections), represents the feature vector of node u at the l-th time, which is the data input to the current layer, represents the current weight matrix, which is a learnable parameter that determines how to transform the node features into the node space feature vector; After aggregating the node features of all adjacent nodes, each node will obtain a feature vector, which is the node space feature vector and contains the aggregated spatial association information, namely type correlation, spatial proximity, and range consistency; Based on the physical constraint parameter list, combine the spatial topology graph to transform the physical constraint parameter list into structured rules, including physical rules and topological rules, and merge the physical rules and topological rules into a structured physical constraint rule library (such as JSON format); Exemplarily transform the parameter list into structured rules: Physical rules: Rule name: Temperature upper limit constraint; Trigger condition: Temperature value > 125°C; Execution action: Trigger an alarm and record; Topological rules: Rule name: Adjacent sensor temperature difference constraint; Trigger condition: Temperature difference between sensor 1 and 2 > 5°C; Execution action: Mark the abnormal area; Extract cross-device time-domain feature vectors, frequency-domain feature vectors, and spatial correlation feature vectors from the enhanced feature sets of all devices in the factory. As heterogeneous data, combine the physical locations and access priorities in the storage index, and preferentially load data blocks with high access priorities (such as real-time vibration data); Based on the device ID and physical interface information, perform timestamp alignment processing (such as interpolation and downsampling) on all timestamped heterogeneous data across devices (referring to data with timestamps) to eliminate time offsets caused by network delays; And according to the range in the physical constraint parameter list, perform normalization processing on the processed heterogeneous data, integrate to obtain a standardized data set, and synchronously record the corresponding relationship between the device ID and the physical constraint parameters to construct a metadata mapping table; To ensure data comparability between different devices and eliminate biases caused by differences in sensor types or sampling frequencies; Extract the physical constraints of each device from the physical constraint rule library as a single-device benchmark, such as the upper limit of vibration amplitude and the threshold of temperature rate; furthermore, based on the edge association strength in the spatial topology graph, derive the joint constraints of each device under the collaborative working conditions as a cross-device benchmark; Assign weights to each device according to the criticality of the device in the factory production chain through the expert experience method, and then perform weighted averaging on the single-device benchmark to generate a single-type benchmark range common to the whole factory; Integrate all types of single-type benchmark ranges to generate a global benchmark parameter table; Furthermore, in the global parameter table, based on physical constraints (such as safety specification requirements) and combined with the expert experience method, preset a static tolerance range for each type of device (such as temperature ±3%, vibration value ±0.5mm / s 2 ) as the original tolerance of each device; And define the ratio of the actual value of the device collected by the sensor to the corresponding global benchmark parameter as the benchmark verification function (for example, the temperature value collected by the temperature sensor is compared with the temperature benchmark in the global benchmark parameter to obtain the result of the benchmark verification function of the device regarding temperature); Exemplary original tolerance settings: For example, if the physical constraint rule library stipulates that the upper temperature limit of a high-temperature device is 80°C, it can be directly mapped to the original tolerance range of 80°C ± 3%; at the same time, combined with the association strength of the spatial topology graph (such as the temperature-vibration complementarity of adjacent devices), derive the tolerance correction coefficient under the joint constraint; Extract time-series statistical features (such as the mean change rate) by dividing the standardized data set with a fixed time window, and use a filtering algorithm to separate the long-term trend and short-term fluctuations; Based on the adjacency matrix of the spatial topology graph, aggregate the spatial context features of the nodes (such as the reciprocal of the installation distance, type complementarity strength) to generate a spatial context vector; Convert the physical constraints in the physical constraint rule library into feature screening conditions, and eliminate the data that does not conform to the physical constraints; Furthermore, horizontally splice the time-domain feature vector, frequency-domain feature vector, and spatial context vector in sequence into a feature sequence of unified length, and compress the redundant dimensions of the feature sequence through the principal component analysis method (such as retaining the core features with 90% variance), generate a multi-dimensional feature matrix in a unified format, and label the physical attributes strongly related to the fault mode (such as high-frequency impact energy), generate a list of retained key physical attributes; Define high-risk devices and low-risk devices based on industry standards, and perform detection parameter binding and detection priority allocation for high-risk devices and low-risk devices; The detection parameter binding is as follows: allocate initial sensitivity coefficients for high-risk devices and low-risk devices, and allocate initial fault tolerance coefficients for low-risk devices (such as ≤2 false alarms per thousand detections); And define the sensitivity allocation rule as that the sensitivity coefficient of high-risk devices is greater than that of low-risk devices (such as high-temperature device = 1.5); It should be noted that the definition of high-risk devices and low-risk devices is only exemplary, and more refined settings can be made according to the actual situation, such as introducing a three-level risk classification: P0 level (severe risk): Key devices that directly affect production safety or product quality (such as high-temperature and high-pressure vessels); P1 level (medium risk): Core devices that affect efficiency or cost (such as the main motor of the production line); P2 level (low risk): Auxiliary devices (such as lighting systems); Refine the parameter binding: Such as the sensitivity coefficient: decreasing according to the risk level (P0 > P1 > P2); The fault tolerance coefficient: increasing according to the risk level (P0 < P1 < P2), allowing a higher tolerance for low-risk devices; The detection priority allocation is as follows: According to the expert experience method, divide the various types of data collected from the device into two types: safety type and efficiency type, and allocate the contribution degree coefficients of the benchmark verification functions for each type of data according to the priority that the safety type is greater than the efficiency type (such as safety type = 0.7, efficiency type = 0.3); Modify the benchmark verification function according to the sensitivity coefficient to obtain the modified benchmark verification function; Take the product of the benchmark verification function value and the sensitivity coefficient as the modified benchmark verification function; (Example, the sensitivity of a high-temperature device = 1.5 × the benchmark value, that is, the actual value only needs to reach 67% of the benchmark value to trigger an alarm); Multiply the sum of the fault tolerance coefficient and 1 by the original tolerance to obtain the corrected dynamic tolerance; (Example: If the fault tolerance coefficient is 2 times per thousand times, the original tolerance of ±3% is extended to ±3.3%); Add the actual device value collected by each type of sensor to the dynamic tolerance to obtain the dynamic tolerance range (For example, if the actual temperature collected from a certain high-temperature fan is 80°C and the dynamic tolerance is ±3.3%, the threshold judgment interval of the reference calibration function is 80°C ± 3.3%, that is, 76°C to 84°C); If the actual value of any type of device is greater than the maximum value of the corresponding dynamic tolerance range, it is determined that the device is abnormal and an alarm is issued; If the actual values of all types of devices are less than or equal to the maximum value of the corresponding dynamic tolerance range, calculate the corrected reference calibration function for the actual value of each type of device separately to obtain the sensitivity of the actual value of each type of device; According to the classification of safety and efficiency types of each type of data, use the contribution coefficient as the weight of the actual device value sensitivity, and then perform weighted fusion on the actual device value sensitivities of all types to generate a comprehensive calibration value; If the comprehensive calibration value is greater than the preset calibration value threshold, it is determined that the device is abnormal and an alarm is issued; If the comprehensive calibration value is less than or equal to the calibration value threshold, it is determined that the device is not abnormal; Combined with the standardized data set and the global reference parameter table, define the dynamic correction strategy, including the real-time synchronization mechanism of dynamic tolerance and the feedback loop optimization of the sensitivity coefficient; The real-time synchronization mechanism of dynamic tolerance is to calculate the standard deviation of dynamic tolerance within a fixed time window. If the standard deviation of dynamic tolerance is greater than the preset standard deviation threshold, update the dynamic tolerance. Calculate the difference between 1 and the standard deviation threshold, and then multiply it by the dynamic tolerance to obtain the updated dynamic tolerance; that is, dynamic tolerance × (1 - standard deviation threshold) = new dynamic tolerance; The feedback loop optimization of the sensitivity coefficient is to calculate the ratio of the number of false alarms to the total number of alarms as the false alarm rate, and automatically adjust the sensitivity coefficient according to the false alarm rate; That is, the original sensitivity coefficient × (1 - false alarm rate) = new sensitivity coefficient; Integrate the multi-dimensional feature matrix, reference calibration function, and global reference parameter table to form a global reference system; and it includes static thresholds, dynamic tolerances, and feedback optimization logic; Decouple the physical constraint rule library, statistical model library, and spatial topology rule library of the global reference system to support independent updates and hot pluggability (For example, replacing the new vibration spectrum analysis algorithm does not affect temperature detection); Define a standardized defect scoring interface for image data (e.g., the defect feature map extracted by CNN is mapped to a numerical defect intensity), and unify the format with other sensor data; For two high-temperature fans (Equipment A / B): Global benchmark system: Single-device benchmark: The upper temperature limit of Equipment A = 80°C ± 3%, and the vibration amplitude of Equipment B ≤ 5mm / s²; Joint constraint: If the temperature-vibration gradient ΔT + ΔV of A + B > 0.5MPa / km, then upgrade the detection priority; Detection parameter binding: The sensitivity of Equipment A = 1.5, and the tolerance = 80°C ± 2%; Contribution degree of safety category = 0.7, and efficiency category = 0.3; Dynamic correction: When the standard deviation of Equipment A for 3 consecutive windows > 0.1, automatically shrink its temperature tolerance to 80°C ± 2%.

[0019] It should be noted that through the construction of the global benchmark, a complete chain from data standardization to rule mapping and then to multi-dimensional modeling is realized, ensuring the accuracy and interpretability of subsequent anomaly detection; Based on the global benchmark system, calculate the ratio of the difference between the actual value of the equipment and the maximum value of the dynamic tolerance range to the dynamic tolerance to obtain the standardized deviation; If the standardized deviation is negative, assign it a value of 0. If it is positive, it means exceeding the tolerance range; Furthermore, map the standardized deviation to a probability value as the preliminary anomaly probability; The mapping method can normalize the standardized deviation to the [0,1] interval through linear normalization; Example: A certain temperature value is 85°C, the reference value is 80°C, and the dynamic tolerance is ±3.3% → the upper tolerance limit = 84.24°C, the standardized deviation = (85 - 84.24) / 3.3 ≈ 0.23 → the preliminary anomaly probability ≈ 23%; Combined with the multi-dimensional feature matrix and the physical constraint rule library, perform reconstruction error processing on the multi-dimensional feature matrix through the principal component analysis method (PCA) to obtain the PCA reconstruction error probability; Specifically, combined with the multi-dimensional feature matrix and the physical constraint rule library, perform PCA dimensionality reduction on the multi-dimensional feature matrix through the principal component analysis method, calculate the reconstruction error (Euclidean norm) of each sample in the low-dimensional space as the structured anomaly score, and standardize the reconstruction error to the anomaly probability of [0,1]; Perform probability density estimation on the multi-dimensional feature matrix through the Gaussian mixture model (GMM) to obtain the GMM probability; Specifically, assume that the normal data follows a multi-dimensional Gaussian distribution and use GMM to fit the feature distribution; Calculate the probability density value of each sample, convert it into the statistical anomaly probability; and filter out the data points that do not conform to the rules (such as noise interference) in combination with the physical constraint rule base; Perform weighted fusion on the preliminary anomaly probability, PCA reconstruction error probability, and GMM probability to obtain the comprehensive anomaly probability; Use the edge association strength in the spatial topology graph to correct the comprehensive anomaly probability to obtain the corrected comprehensive anomaly probability; Specifically, if multiple adjacent nodes (with consistent communication protocols and short physical distances) of a certain node simultaneously show high anomaly probabilities, it is determined that the anomaly probability of this node needs to be multiplied by an association amplification factor to reflect the possibility of collaborative failures; ; is the association weight decay factor (usually set to 0.1) to prevent over-amplification of isolated events; Organize the comprehensive anomaly probabilities of all devices into a matrix structure according to the time series by device ID and timestamp to obtain the device-level anomaly probability matrix; including the number of devices, the number of time windows, and the comprehensive anomaly probability of each device in each time window (range [0,1]); Example matrix: {device ID, timestamp 1, timestamp 2,..., threshold trigger}; {ID1, 0.12, 0.35,..., 0.3}; {ID2, 0.05, 0.28,..., 0.3}; Dynamically set the threshold (such as 0.3) according to business requirements (such as higher priority for security devices), and the cells exceeding the threshold are marked as potential anomalies; Aggregate the comprehensive anomaly probabilities of associated devices based on the spatial topology graph according to the process stage and production line modules (such as injection molding, assembly, testing) (such as by methods of weighted average or max pooling to aggregate); Combine the joint constraints in the physical constraint rule base and introduce the working condition characteristics to obtain the working condition-level anomaly probability matrix; The relational expression for generating the working condition-level probability is: ; Among them, represents the set of devices in the mth working condition group, represents the weight of device c in this working condition group, represents the comprehensive anomaly probability of device c at time t, represents the working condition-level characteristic at time t (such as energy consumption deviation), represents the fusion coefficient of the preset working condition characteristics; The working condition-level anomaly probability matrix Each cell P(m,t) in it represents the joint anomaly probability of the mth process stage or production line module in the time window t; It should be noted that the device-level anomaly probability matrix shows the independent anomaly probabilities of individual devices for locating specific fault sources (such as abnormal vibration of a certain motor), and typical application scenarios include equipment inspection and single-machine maintenance. The working-condition-level anomaly probability matrix shows the joint anomaly probabilities under the collaborative state of multiple devices for discovering systematic risks (such as abnormal overall energy consumption of a production line), and typical application scenarios are process optimization and energy efficiency management; Extract time-series features (such as amplitude volatility and fundamental frequency energy ratio) from the device-level anomaly probability matrix; Example: According to the device-level anomaly probability matrix, convert the anomaly probability of the device into a curve form, analyze the anomaly probability curve, identify periodic fluctuations, and extract the fluctuation frequency as a time-series feature; Perform PCA dimensionality reduction on the extracted time-series features to obtain low-dimensional feature vectors of the time-series features; and perform physical constraint verification through the physical constraint rule library to filter out data values that do not conform to physical rules (such as local anomalies caused by sensor noise) to obtain a device-level feature model, including the dimensionality-reduced feature set and the physical constraint verification results; Example: If the abnormal vibration probability of a certain device suddenly increases but the temperature is normal, it is marked as a suspected false alarm; Based on the spatial topology graph, aggregate the comprehensive anomaly probabilities of associated devices (weighted average or max pooling processing) to generate a preliminary working-condition-level probability; Example: Slight anomalies occur in all 3 motors in the injection molding section → Generate a working-condition-level probability after aggregation; Establish a causal relationship model in combination with the joint rules in the physical constraint rule library (such as heat conduction chain reaction and energy consumption coupling); Example: The failure of the cooling system may cause the temperature deviation of multiple devices → Establish a causal relationship model; Integrate working-condition-level features (such as production capacity volatility and energy consumption trend) as supplementary inputs; Example: The overall energy consumption of the production line decreases by 10% → Integrate it as a working-condition-level feature; Using the spatial topology graph as the graph structure, train a GNN model to capture the dependencies between devices (such as heat conduction chain reaction and energy consumption coupling) to obtain a working-condition-level feature model, covering cross-device association features, joint constraints, and GNN modeling results; Example: The abnormal probability propagation path of adjacent nodes → Quantify the collaborative fault risk; It should be noted that the purpose of the device-level feature model is to locate the root cause of single-device faults and output the dimensionality reduction results of features and the physical rule filtering results; The purpose of the working-condition-level feature model is to identify systematic risks and output cross-device association features and GNN model outputs; Example: Device level: The anomaly probability matrix of Device D1 shows that the high temperature continues to rise → Feature modeling discovers abnormal temperature gradient → Trigger bearing wear warning; Operating condition level: The operating condition level matrix in the injection molding section shows energy consumption deviation → The GNN detects a collaborative failure in the cooling system → It is recommended to check the status of the water pump; According to the classification of high-risk and low-risk types of equipment, perform equipment-level optimization, quantify the influence intensity of adjacent nodes, jointly optimize the false alarm rate, perform operating condition-level optimization, and form an optimization parameter set; Specifically, the equipment-level optimization is to automatically adjust the feature weights according to the classification of high-risk and low-risk types of equipment, Example: The weight of the safety class index of P0-level equipment is set to 80%, and the efficiency class is set to 20%; And update the equipment-level feature model through the incremental learning mechanism to adapt to process changes; The operating condition-level optimization is to calculate the influence weight of adjacent nodes (such as the closer the distance, the higher the weight) based on the spatial topology graph to quantify the association strength; and jointly optimize the false alarm rate and missed alarm rate, and set a lower threshold for key operating conditions; According to the values in the equipment-level anomaly probability matrix and the operating condition-level anomaly probability matrix, set the comprehensive risk level (such as P0 level, P1 level, P2 level, equipment-level anomaly probability matrix, P0 level: P>0.5, P1 level: 0.3<P≤0.5, P2 level: P≤0.3, operating condition-level anomaly probability matrix, P0 level: P>0.4, P1 level: 0.2<P≤0.4, P2 level: P≤0.2); Based on the comprehensive risk level, divide the alarm levels; for example, P0 level triggers a red alarm + automatic shutdown (such as power off of key equipment), P1 level pushes a yellow warning (such as power off of key equipment), P2 level records a green prompt (such as slight fluctuations in auxiliary equipment); After the alarm is triggered, an operation and maintenance work order (including equipment ID, timestamp, priority) is automatically generated, and manual remarks can be supplemented (such as the need to carry an infrared thermal imager for troubleshooting); According to the matching of the alarm level and the skills of maintenance personnel, automatically assign work orders, and optimize the response path in combination with traffic information; Combined with the multi-dimensional feature matrix, the physical constraint rule library and the historical maintenance records, locate the root cause of the anomaly, for example: abnormal motor temperature → frequency domain analysis finds bearing wear → recommend replacement model; Dynamically adjust the sensitivity coefficient and tolerance range according to the false alarm rate, and use Bayesian optimization to balance sensitivity and specificity; store each maintenance process in the preset operation and maintenance database, and then regularly update the physical constraint rule library.

[0020] Embodiment 2 Please refer to Figure 4 As shown, for the parts not described in detail in this embodiment, refer to the description content of Embodiment 1. Provide a learning fusion and anomaly detection system for industrial time series data, including: Data Acquisition and Preprocessing Module: Parse industrial communication protocols, extract PLC device IDs and IP addresses, and establish an initial device list; combine the IP addresses and device IDs to construct an IP-PLC mapping relationship table; collect multi-modal data, align it by timestamp, and then construct a physical constraint parameter list based on the physical characteristics of sensors; manage data through a hierarchical storage strategy to generate structured data and storage indexes; Feature Extraction and Enhancement Module: Based on the structured data, extract time-domain feature vectors and frequency-domain feature vectors; construct a spatial topology graph based on the IP-PLC mapping relationship table, extract node spatial feature vectors and edge association strengths, and generate spatial association feature vectors; combine the physical constraint parameter list, encode physical rules and topological rules, construct a constraint rule library, and form an enhanced feature set; Global Benchmark System Construction Module: Aggregate the enhanced feature sets and constraint rule libraries of industrial devices in the factory to generate a multi-dimensional feature matrix, optimize the detection threshold through spatio-temporal feature fusion and physical constraint parameters, generate a global benchmark parameter table, and then construct a global benchmark system; generate a device-level anomaly probability matrix and a working condition-level anomaly probability matrix based on the global benchmark system; Anomaly Detection and Hierarchical Modeling Module: Based on the device-level anomaly probability matrix and the generated working condition-level anomaly probability matrix, generate a device-level feature model and a working condition-level feature model through hierarchical modeling, and perform hierarchical optimization to generate an optimized parameter set; Closed-loop Optimization and Alarm Response Module: Based on the output results of the device-level feature model and the working condition-level feature model and the optimized parameter set, construct an alarm response mechanism, and reversely update the physical constraint parameters associated with the sensors to form a closed-loop iteration.

[0021] Embodiment 3 This embodiment publicly provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the running mode of the above-provided method for learning fusion and anomaly detection of industrial time-series data.

[0022] Since the electronic device introduced in this embodiment is the electronic device adopted for implementing the method for learning fusion and anomaly detection of industrial time-series data in the embodiments of the present application, based on the method for learning fusion and anomaly detection of industrial time-series data introduced in the embodiments of the present application, those skilled in the art can understand the specific implementation manners and various variations of the electronic device in this embodiment. Therefore, the specific implementation of how this electronic device implements the method in the embodiments of the present application will not be described in detail here. As long as those skilled in the art implement the electronic device adopted for the method for learning fusion and anomaly detection of industrial time-series data in the embodiments of the present application, it falls within the scope of protection of the present application.

[0023] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the actual situation. The preset parameters and threshold selection in the formulas are set by those skilled in the art according to the actual situation.

[0024] The above is only the preferred embodiment of the present invention, and the protection scope of the present invention is not limited to the above embodiments. All technical solutions within the idea of the present invention belong to the protection scope of the present invention. It should be pointed out that for ordinary users in the technical field, several improvements and refinements made without departing from the principle of the present invention should also be regarded as the protection scope of the present invention.

Claims

1. The learning fusion and anomaly detection method of industrial time series data is characterized by: include: S1: parse the industrial communication protocol, extract the PLC device ID and IP address, and establish the initial device list; Combine IP address and device ID to build IP-PLC mapping relationship table; collect multimodal data, align by timestamp, and then build a list of physical constraint parameters based on the physical characteristics of the sensor; manage data through hierarchical storage strategy to generate structured data and storage index; S2: Based on structured data, extract time domain feature vectors and frequency domain feature vectors; construct a spatial topology graph based on the IP-PLC mapping relationship table, extract node spatial feature vectors and edge association strength, and generate spatial association feature vectors; combine the physical constraint parameter list, encode the physical rules and topology rules, construct a constraint rule library, and form an enhanced feature set; S3: Aggregate the enhanced feature set and constraint rule base of industrial equipment in the factory to generate a multi-dimensional feature matrix, optimize the detection threshold through spatiotemporal feature fusion and physical constraint parameters, generate a global benchmark parameter table, and then build a global benchmark system; Generate equipment-level abnormality probability matrix and operating condition-level abnormality probability matrix based on the global benchmark system; S4: Based on the device-level abnormal probability matrix and the generated working condition-level abnormal probability matrix, the device-level feature model and the working condition-level feature model are generated through hierarchical modeling, and hierarchical optimization is performed to generate an optimized parameter set; S5: Based on the output results of the device-level feature model and the working condition-level feature model and the optimized parameter set, an alarm response mechanism is constructed, and the physical constraint parameters associated with the sensor are reversely updated to form a closed-loop iteration.

2. The learning fusion and anomaly detection method for industrial time series data according to claim 1 is characterized in that: The structured data and storage index methods include: Parse the communication protocol data of PLC devices through industrial protocol parsing mechanism and extract device identifiers, including IP address and device ID; Integrate the IP addresses and device IDs of all PLC devices to create an initial device list; Based on the initial device list, identify PLC devices with the same IP address, combine the physical interface information, assign a unique physical interface to each PLC device, assign PLC devices with the same IP address to different physical interfaces, and set interface binding through the network configuration tool; Integrate the device ID, IP address, and physical interface information into a structured table to obtain an IP-PLC mapping relationship table; Through various types of sensor interfaces, multi-type transmission data of the equipment is collected in real time as multi-modal data of the equipment, and the original data stream is formed by timestamp alignment, and then the data is cleaned and standardized to be integrated into the pre-processed data stream; According to the physical characteristics of the equipment, the physical constraint parameters of each type of sensor are defined, and then integrated and constructed to obtain a list of physical constraint parameters; Based on the physical constraint parameter list, the physical constraint parameters are embedded through the hardware layer, algorithm layer and data layer; The hardware layer embedding is to define the sampling parameters of the sensor according to the physical constraint parameters; the algorithm layer embedding is to embed different physical equations for different data types; Data layer embedding is to define real-time constraints and security constraints. Real-time constraints are timestamp synchronization and data range checks, and security constraints are to add hardware-level threshold triggers. Divide all types of data into high-timeliness data and low-timeliness data based on expert experience, divide high-timeliness data into hot data, and divide low-timeliness data into cold data, and then divide the data storage level according to the hot data / cold data strategy; The data is standardized into a structured format through data standardization technology to obtain structured data; a storage list is generated simultaneously to record the physical location and access priority of the data block to obtain a storage index.

3. The learning fusion and anomaly detection method for industrial time series data according to claim 2 is characterized in that: The method of constructing a constraint rule base and forming an enhanced feature set includes: Extract the time domain features of each type of data from the structured data, and then horizontally splice the time domain features of each type of data into a multi-modal time domain feature vector; Decompose various types of data through frequency domain analysis method, and then extract the frequency domain characteristics of various types of data; Set a fixed time window, and horizontally splice the frequency domain feature vectors of each type of data in each time window in chronological order to form a single time series feature item; Arrange the single time series feature items of all time windows in chronological order to generate a multi-modal frequency domain feature sequence; Based on the IP-PLC mapping relationship table, the spatial topology of the sensor is constructed, and the node spatial feature vectors and edge association strengths in the spatial topology are extracted to obtain the spatial association feature vector of each node as the spatial feature of the sensor. The physical constraint parameter list is encoded into a physical constraint rule library in combination with the spatial topology. The time domain features, frequency domain features and space features are horizontally spliced, and the rule thresholds in the physical constraint rule library are converted into numerical features. All features are merged to form a multi-modal enhanced feature set. At the same time, combined with spatial characteristics, topological constraints are added to the physical constraint rule library to form a constraint rule library.

4. The learning fusion and anomaly detection method for industrial time series data according to claim 3 is characterized in that: The node space feature vector and edge association strength are obtained in the following manner: Treat each sensor as a node and assign attributes to each node, including sensor type, measuring range and installation coordinates; Based on the IP-PLC mapping relationship table, edges are established for nodes, and attributes are assigned to each edge, including the physical distance, directionality and communication protocol between sensors as edge attributes, to construct a spatial topology graph; Based on the edges between all nodes in the spatial topology graph, nodes with edges are defined as connected, and nodes without edges are defined as unconnected. The connection relationships between all nodes are extracted and an adjacency matrix is ​​constructed. Encode node attributes into numerical feature vectors as node features, extract all node features to construct a node feature matrix; The adjacency matrix is ​​standardized. Based on the node attribute matrix and the standardized adjacency matrix, for each node, the node features of all adjacent nodes are aggregated to generate a node spatial feature vector for each node, including type correlation, spatial proximity, and range consistency. At the same time, based on any pair of nodes with an edge, the physical distance, communication protocol and sensor type between the two nodes are extracted; Set the attenuation coefficient of the physical distance, multiply the physical distance by the attenuation coefficient, add 1, and then take the reciprocal to get the physical distance strength value; For the communication protocol between two nodes, if the communication protocols are completely consistent, the communication protocol consistency strength value is assigned to 1; if the communication protocols are inconsistent, the communication protocol consistency strength value is assigned to 0; According to the predefined type complementarity rule table, an adjustment coefficient of the sensor type combination is determined, and the adjustment coefficient is multiplied by a default basic sensor type complementarity strength value to obtain a final sensor type complementarity strength value; The edge association strength is calculated by weighted summing the physical distance strength value, communication protocol consistency strength value and sensor type complementarity strength value between nodes.

5. The method for learning, fusion and anomaly detection of industrial time series data according to claim 4, characterized in that: The physical constraint rule base is obtained in the following manner: The node spatial feature vector of the node is horizontally concatenated with the edge association strength to obtain the spatial association feature vector of each node; Based on the physical constraint parameter list and combined with the spatial topology graph, the physical constraint parameter list is transformed into structured rules, including physical rules and topological rules, and the physical rules and topological rules are merged into a structured physical constraint rule library.

6. The method for learning, fusion and anomaly detection of industrial time series data according to claim 5, characterized in that: The generation method of the multidimensional feature matrix includes: Extracting time domain feature vectors, frequency domain feature vectors, and spatial correlation feature vectors across devices from the enhanced feature set as heterogeneous data; Based on the device ID and physical interface information, all heterogeneous data with timestamps across devices are timestamped and aligned; And according to the range in the physical constraint parameter list, the processed heterogeneous data are normalized and integrated to obtain a standardized data set; Extract the physical constraints of each device from the physical constraint rule library as a single-device benchmark; then derive the joint constraints of each device under collaborative working conditions based on the edge association strength in the spatial topology graph as a cross-device benchmark; By using the expert experience method to assign weights to each device according to its criticality in the factory production chain, the single-device benchmarks are weighted averaged to generate a single-type benchmark range that is common to the entire factory; Integrate all types of single-type benchmark ranges to generate a global benchmark parameter table; Then, in the global parameter table, a static tolerance range is preset for each type of equipment based on physical constraints combined with expert experience as the original tolerance of each equipment; And define the ratio of the actual value of the device collected by the sensor and the corresponding global benchmark parameter as the benchmark verification function; The standardized data set is segmented into fixed time windows to extract time series statistical features, and the filtering algorithm is used to separate long-term trends from short-term fluctuations; Based on the adjacency matrix of the spatial topology graph, the spatial context features of the nodes are aggregated to generate a spatial context vector; Convert the physical constraints in the physical constraint rule library into feature screening conditions to eliminate data that does not meet the physical constraints; Then, the time domain feature vector, frequency domain feature vector and spatial context vector are horizontally spliced ​​in sequence into a feature sequence of uniform length, and the redundant dimensions of the feature sequence are compressed through principal component analysis to generate a multi-dimensional feature matrix in a unified format.

7. The method for learning, fusion and anomaly detection of industrial time series data according to claim 6, characterized in that: The global benchmark system is constructed in the following ways: Define high-risk devices and low-risk devices based on industry standards, bind detection parameters and assign detection priorities to high-risk devices and low-risk devices; The detection parameter binding is: allocating initial sensitivity coefficients to high-risk devices and low-risk devices, and allocating initial fault tolerance coefficients to low-risk devices; and defining the sensitivity allocation rule that the sensitivity coefficient of the high-risk device is greater than the sensitivity coefficient of the low-risk device; The detection priority is allocated as follows: according to the expert experience method, the various types of data collected from the equipment are divided into two types: safety and efficiency, and the contribution coefficient of the benchmark verification function of each type of data is allocated with the safety type being higher than the efficiency type; The benchmark calibration function is modified by the sensitivity coefficient to obtain a modified benchmark calibration function; The original tolerance is corrected by the fault tolerance coefficient to obtain the corrected dynamic tolerance; the sum of the actual value of the device collected by each type of sensor and the dynamic tolerance is taken to obtain the dynamic tolerance range; If the actual value of any type of equipment is greater than the maximum value of the corresponding dynamic tolerance range, the equipment is judged to be abnormal and an alarm is issued; If the actual values ​​of all types of equipment are less than or equal to the maximum value of the corresponding dynamic tolerance range, then the corrected benchmark calibration function is calculated separately for the actual value of each type of equipment to obtain the sensitivity of the actual value of each type of equipment; According to the security and efficiency classification of each type of data, the contribution coefficient is used as the sensitivity weight of the actual value of the equipment, and then the sensitivity of the actual value of all types of equipment is weighted and integrated to generate a comprehensive verification value; If the comprehensive check value is greater than the preset check value threshold, it is determined that the device is abnormal and an alarm is issued; if the comprehensive check value is less than or equal to the check value threshold, it is determined that the device is not abnormal; Combine the standardized data set with the global benchmark parameter table to define the dynamic correction strategy, including the real-time synchronization mechanism of dynamic tolerance and the feedback loop optimization of sensitivity coefficients; The real-time synchronization mechanism of dynamic tolerance is to calculate the standard deviation of dynamic tolerance within a fixed time window. If the standard deviation of dynamic tolerance is greater than the preset standard deviation threshold, the dynamic tolerance is updated. The feedback loop of the sensitivity coefficient is optimized to calculate the ratio of the number of false alarms to the total number of alarms as the false alarm rate, and automatically adjust the sensitivity coefficient according to the false alarm rate; Integrate multi-dimensional feature matrix, benchmark verification function, and global benchmark parameter table to form a global benchmark system; and it includes static thresholds, dynamic tolerances, and feedback optimization logic.

8. The method for learning, fusion and anomaly detection of industrial time series data according to claim 7, characterized in that: The generation method of the device-level abnormal probability matrix and the generation method of the working condition-level abnormal probability matrix includes: Based on the global benchmark system, the difference between the actual value of the equipment and the maximum value of the dynamic tolerance range is calculated by ratio with the dynamic tolerance to obtain the standardized deviation; If the standardized deviation is negative, it is assigned a value of 0; Then the standardized deviation is mapped to a probability value as the preliminary abnormality probability; The mapping method can normalize the standardized deviation to the [0,1] interval through linear normalization; Combining the multidimensional feature matrix and the physical constraint rule base, the multidimensional feature matrix is ​​reconstructed through principal component analysis to obtain the PCA reconstruction error probability. The probability density of the multi-dimensional feature matrix is ​​estimated through the Gaussian mixture model to obtain the GMM probability; The preliminary anomaly probability, PCA reconstruction error probability and GMM probability are weighted and fused to obtain the comprehensive anomaly probability; The comprehensive anomaly probability is corrected by using the edge correlation strength in the spatial topology graph to obtain the corrected comprehensive anomaly probability; The comprehensive abnormal probability of all devices is organized into a matrix structure according to the time series, device ID and timestamp to obtain the device-level abnormal probability matrix; including the number of devices, the number of time windows, and the comprehensive abnormal probability of each device in each time window; Based on the spatial topology, the comprehensive abnormal probability of the associated equipment is aggregated according to the process stage and production line module; The operating condition level abnormal probability matrix is ​​obtained by combining the joint constraints in the physical constraint rule base and introducing the operating condition characteristics.

9. The method for learning, fusion and anomaly detection of industrial time series data according to claim 8, characterized in that: The generation method of the optimization parameter set includes: Extract the time series features from the device-level abnormal probability matrix, perform PCA dimensionality reduction on the extracted time series features, and obtain the low-dimensional feature vector of the time series features; perform physical constraint verification through the physical constraint rule library, filter the data values ​​that do not conform to the physical rules, and obtain the device-level feature model; Based on the spatial topology graph, the comprehensive abnormal probability of the associated equipment is aggregated to generate the preliminary working condition level probability, and the causal relationship model is established by combining the joint rules in the physical constraint rule library; Integrate the working condition level features as supplementary input, use the spatial topology graph as the graph structure, train the GNN model to capture the dependencies between devices, and obtain the working condition level feature model; According to the high-risk and low-risk types of equipment, equipment-level optimization is carried out, the impact intensity of adjacent nodes is quantified, the false alarm rate is jointly optimized, the working condition level optimization is carried out, and the optimization parameter set is generated.

10. The method for learning, fusion and anomaly detection of industrial time series data according to claim 9, characterized in that: The alarm response mechanism is constructed in the following ways: Set the comprehensive risk level according to the values ​​in the equipment-level abnormal probability matrix and the working condition-level abnormal probability matrix; Classify the alarm levels based on the comprehensive risk level; Automatically generate an operation and maintenance work order after the alarm is triggered; automatically assign an operation and maintenance work order based on the alarm level and the maintenance personnel's skills, and optimize the response path based on traffic information; Locate the root cause of abnormality by combining multi-dimensional feature matrix, physical constraint rule base and historical maintenance records; The sensitivity coefficient and tolerance range are dynamically adjusted according to the false alarm rate; each maintenance process is stored in the preset operation and maintenance database, and the physical constraint rule library is updated regularly.

Citation Information

Patent Citations

  • Industrial control system anomaly detection method based on dual-contour model

    CN106502234A

  • Water conservancy safety detection method based on AI edge calculation

    CN119652942A

  • Equipment intelligent guarantee system based on off-line large model

    CN119919126A

Cited By

  • Intelligent factory monitoring method and system based on multi-sensor fusion

    CN120469321A

  • End-to-end packet loss recovery method of wet copper production process, electronic equipment and medium

    CN120498602A

  • Industrial equipment fault prediction and health management method based on multi-sensor fusion

    CN120509001A

  • Water supply network water quality abnormity tracing method and system based on data fusion

    CN120741805A

  • Intelligent pump performance data analysis processing method and system

    CN120745229A