Equipment abnormity monitoring method and system based on Internet of Things
By constructing a dynamic adjacency matrix and a GCN model optimized by combining group intelligence algorithms, combining multimodal causal reasoning and fuzzy rules, efficient anomaly labels are generated, and false alarms and underreporting problems in abnormal monitoring in dynamic environments in the existing technology are solved, achieving higher accuracy and reliable anomaly detection.
Patent Information
- Application Number
- CN202510614436.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-13
- Publication Date
- 2025-08-01
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing IoT-based device anomaly monitoring method relies on static adjacency matrix, and is not fully combined with group intelligence algorithms, and cannot cope with the dynamic environment, resulting in the risk of false positives or missed reports from abnormal label generation. Multimodal causal reasoning operates independently, and it is impossible to effectively monitor deep-level exceptions, reducing the credibility of abnormal label generation.
By collecting monitoring data, a high-dimensional original matrix is generated, a dynamic adjacency matrix is constructed, a GCN model is combined with ACO optimization, a low-dimensional topology subset is output through roulette selection, a global optimal search is searched for MLE calculation and K-means clustering, a dynamic causal KG is initialized, and a multi-modal result array is generated through Granger causal testing and fuzzy rule optimization, an alarm mechanism is set and integrated into a JSON report.
It improves the accuracy and response speed of abnormal monitoring, improves the reliability and efficiency of abnormal monitoring, enhances the ability to adapt to dynamic environments, reduces false alarms and missed reports, and improves the credibility of abnormal label generation.
Smart Images

Figure CN120416063A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Internet of Things intelligent operation and maintenance, in particular to a method and system for device anomaly monitoring based on the Internet of Things. Background Art
[0002] With the rapid development of Internet of Things technology, more and more devices are connected to the network through intelligent sensors, forming a huge intelligent device ecosystem. Traditional device monitoring methods mainly rely on statistics-based threshold detection and shallow machine learning models. These methods perform well in low-dimensional data scenarios, but in the high-dimensional, non-linear and dynamically evolving Internet of Things data environment, their generalization ability and feature extraction efficiency are significantly limited. To address this challenge, GCN has been introduced into the anomaly detection field. At the same time, swarm intelligence algorithms such as ACO and PSO have also been used for model parameter tuning, and multi-modal causal reasoning and fuzzy rules have also begun to be applied to improve detection accuracy and robustness.
[0003] Existing Internet of Things-based device anomaly monitoring methods still have deficiencies. The GCN model relies on a static adjacency matrix and does not fully combine swarm intelligence algorithms, making it unable to handle the monitoring of dynamic environments and prone to falling into the global optimum, resulting in the risk of false positives or false negatives in anomaly label generation, affecting the accuracy of anomaly monitoring. Multi-modal causal reasoning often runs independently, is not optimized through fuzzy rules and GWO, and is unable to monitor deep-level anomalies, reducing the credibility of anomaly label generation. Summary of the Invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides a method and system for device anomaly monitoring based on the Internet of Things, which solves the problems that the GCN model relies on a static adjacency matrix, does not fully combine swarm intelligence algorithms, is unable to handle the monitoring of dynamic environments, is prone to falling into the global optimum, resulting in the risk of false positives or false negatives in anomaly label generation, affecting the accuracy of anomaly monitoring, multi-modal causal reasoning often runs independently, is not optimized through fuzzy rules and GWO, and is unable to monitor deep-level anomalies, reducing the credibility of anomaly label generation.
[0006] To solve the above technical problems, the present invention provides the following technical solutions:
[0007] In a first aspect, the present invention provides a method for monitoring device anomalies based on the Internet of Things, which includes collecting monitoring data to generate a high-dimensional raw matrix and constructing a dynamic adjacency matrix, using a GCN model and combining it with ACO for optimization, selecting the output of the final low-dimensional topology subset through roulette selection, calculating enhancement and contrast losses through a contrast learning model, setting the weight of the pseudo-label loss based on the FCM algorithm, generating a combined loss to update the GCN model, using a VAE model and combining it with the PSO algorithm to search for the global optimum, optimizing classification based on K-means clustering and BSO, and performing MLE calculations to generate the final anomaly label, initializing a dynamic causal KG, updating it through Granger causality testing, generating a multi-modal result array through NSM, a scoring formula, a naive Bayes model, a Mahalanobis distance formula, and a logistic regression model, initializing fuzzy rules, generating an optimized anomaly label by combining GWO optimization, integrating it into a JSON report, setting an alarm mechanism based on the JSON report, and storing the collected monitoring data and the JSON report generated by the analysis.
[0008] As a preferred embodiment of the method for monitoring device anomalies based on the Internet of Things according to the present invention, wherein: the steps of collecting monitoring data to generate a high-dimensional raw matrix and constructing a dynamic adjacency matrix, using a GCN model and combining it with ACO for optimization, selecting the output of the final low-dimensional topology subset through roulette selection, calculating enhancement and contrast losses through a contrast learning model, setting the weight of the pseudo-label loss based on the FCM algorithm, and generating a combined loss to update the GCN model include:
[0009] Collect monitoring data, including temperature, vibration, flow, biological signals, CPU usage, process status, data packets, and protocol distribution data, to generate a high-dimensional raw feature matrix and construct a dynamic adjacency matrix;
[0010] Construct a two-layer GCN model, input the high-dimensional raw feature matrix and the dynamic adjacency matrix, generate an initial node embedding matrix through two-layer graph convolution, and generate a topology feature matrix;
[0011] Initialize ACO. Based on the topology feature matrix, each ant selects some features through pheromone and heuristic information and combines them into a low-dimensional topology feature subset;
[0012] If the low-dimensional topology feature subset has an anomaly discrimination degree greater than the threshold of the anomaly discrimination degree, update the pheromone;
[0013] If the low-dimensional topology feature subset has an anomaly discrimination degree less than or equal to the threshold of the anomaly discrimination degree, update the weights of the convolutional layer of the GCN model, output the updated node embedding matrix, normalize the anomaly discrimination degrees of the embedding vectors in the updated node embedding matrix using an exponential function, allocate pheromone weights according to the normalized anomaly discrimination degrees, and update the pheromone concentration through weighted calculation;
[0014] Using roulette wheel selection, adjust the selection path of the ants by combining the updated information concentration and heuristic information, and output the final low-dimensional topological feature subset.
[0015] As a preferred solution of the device anomaly monitoring method based on the Internet of Things according to the present invention, wherein: using the VAE model in combination with the PSO algorithm to search for the global optimum, based on K-means clustering and BSO for classification optimization, and performing MLE calculation to generate the final anomaly label, including:
[0016] Construct a contrastive learning model, input the final low-dimensional topological feature subset, add Gaussian noise and perform clipping to generate an enhanced low-dimensional topological feature subset;
[0017] Calculate the contrastive loss of positive and negative samples through scikit-learn, output the optimized embedding matrix, perform fuzzy clustering, set a fixed number of clusters, calculate the membership degree through the FCM algorithm, and update the cluster center through the weighted centroid method;
[0018] Set the membership degree threshold, screen the samples with membership degree greater than the membership degree threshold as pseudo-labels, calculate the pseudo-label loss value through the cross-entropy loss function, and perform descending sorting to screen the maximum membership degree in the pseudo-labels and set it as the weight of the pseudo-label loss;
[0019] Perform weighted fusion of the comparison loss and the pseudo-label loss to generate a joint loss;
[0020] Perform backpropagation of the joint loss through the Adam optimizer, update the weights of the GCN fully connected layer, output the updated low-dimensional topological feature subset through ACO, and divide it into time series through a time window;
[0021] Construct a VAE model, input the time series, generate an initial latent variable through the encoder, calculate the mean and variance of the initial latent variable through the mean layer and variance layer, generate a reconstructed sequence through the decoder, and output the window length sequence;
[0022] Initialize the PSO algorithm and define the objective function according to the window length sequence;
[0023] Update the particle position and velocity based on the objective function value update rule, and output the global optimal latent variable weight and window length mapping parameter;
[0024] Calculate the product of the optimal latent variable weight and the initial latent variable to obtain the optimized latent variable, and calculate the cumulative timestamp in combination with the window length mapping parameter;
[0025] Interpolate the time series with the cumulative timestamp and the timestamps of the time series using linear interpolation, divide the time series into windows, aggregate all the feature values within each window, generate an optimized dynamic time window sequence, extract temporal features and statistical features, merge them into a multi-scale feature vector, and enhance it through a Transformer model;
[0026] Perform K-means clustering on the enhanced multi-scale feature vector to generate initial anomaly labels and construct an anomaly evolution graph;
[0027] Use BSO to optimize the transition probabilities in the anomaly evolution graph, output the optimal anomaly labels, and perform weighted average fusion in combination with the initial anomaly labels to generate corrected anomaly labels;
[0028] Calculate the likelihood probability of each corrected anomaly label for the multi-modal features and the corrected anomaly labels through MLE, and output the final anomaly labels.
[0029] As a preferred solution of the device anomaly monitoring method based on the Internet of Things described in the present invention, wherein: initialize the dynamic causal KG, update it through Granger causality test, generate a multi-modal result array through NSM, scoring formula, Naive Bayes model, Mahalanobis distance formula, and logistic regression model, initialize fuzzy rules, and generate optimized anomaly labels through GWO optimization, and integrate them into a JSON report, including:
[0030] Initialize the dynamic causal KG, calculate the causal score using Granger causality test, and update the causal edge weights;
[0031] Input the maximum likelihood probability and the multi-scale feature vector, calculate the matching score through the fully connected layer of NSM, generate the normalized likelihood probability through the softmax function, adjust it using Prolog rules, and accumulate it to output the semantic consistency score;
[0032] Based on expert rules and scoring formula, output the anomaly score, obtain the probability based on the Naive Bayes model, output the deviation degree based on the Mahalanobis distance, construct a logistic regression model, and output the classification label;
[0033] Merge the anomaly score, output probability, deviation degree, and classification label into a multi-modal result array;
[0034] Perform weighted fusion on the normalized likelihood probability, output probability, and deviation degree through multi-head attention, and output the fusion label;
[0035] Calculate the cosine similarity between the normalized likelihood probability and the probability, filter out those less than the cosine similarity threshold of the normalized likelihood probability and the probability, and mark them as conflicts;
[0036] Initialize the fuzzy rules. Based on GWO, use the chaotic Tent map to initialize the rule weights and dynamically adjust the rule priority weights.
[0037] Set the initial standard deviation of the fused likelihood probability. Use the Gaussian membership function and dynamically adjust the standard deviation based on the Gaussian distribution change curve, and output the optimized fused likelihood probability.
[0038] Filter out the optimized fused likelihood probability greater than the optimized fused likelihood probability threshold, confirm the anomaly, and output the optimized anomaly label.
[0039] Integrate the optimized anomaly label, semantic consistency score, multimodal result array, and conflict flag, and format them into a JSON report.
[0040] As a preferred solution of the device anomaly monitoring method based on the Internet of Things according to the present invention, wherein: setting an alarm mechanism based on the JSON report, including:
[0041] Set an alarm threshold. If any one or more indicators in the report exceed the alarm threshold, a primary alarm is triggered. If all indicators in the report exceed the alarm threshold, a high-level alarm is triggered.
[0042] As a preferred solution of the device anomaly monitoring method based on the Internet of Things according to the present invention, wherein: generating a high-dimensional original feature matrix for the collected monitoring data first, including:
[0043] Extract time series features using a variance sliding window and a mean sliding window, extract frequency domain features using FFT, and splice them into a high-dimensional original feature matrix.
[0044] As a preferred solution of the device anomaly monitoring method based on the Internet of Things according to the present invention, wherein: storing the collected monitoring data and the generated JSON report from the analysis, including:
[0045] Format the collected monitoring data and the generated JSON report from the analysis into a JSON comprehensive report, convert it into a visual comprehensive report using Grafana, and upload it to the cloud for storage.
[0046] In a second aspect, the present invention provides a device anomaly monitoring system based on the Internet of Things, including
[0047] The collection and analysis module is used to collect monitoring data to generate a high-dimensional original matrix and construct a dynamic adjacency matrix, optimize it using the GCN model combined with ACO, select the output of the final low-dimensional topological subset through roulette wheel selection, calculate the enhancement and contrast loss through the contrast learning model, set the weight of the pseudo-label loss based on the FCM algorithm, generate the combined loss to update the GCN model, use the VAE model combined with the PSO algorithm to search for the global optimum, optimize the classification based on K-means clustering and BSO, and perform MLE calculation to generate the final anomaly label;
[0048] The verification and optimization module is used to initialize the dynamic causal KG, update it through Granger causality test, generate a multi-modal result array through NSM, scoring formula, naive Bayes model, Mahalanobis distance formula, and logistic regression model, initialize the fuzzy rules, and generate the optimized anomaly label by combining with GWO optimization, and integrate it into a JSON report;
[0049] The hierarchical alarm module is used to set the alarm mechanism based on the JSON report;
[0050] The storage and analysis module is used to store the collected monitoring data and the JSON report generated by the analysis.
[0051] In a third aspect, the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and: when the computer program is executed by the processor, any step of the device anomaly monitoring method based on the Internet of Things as described in the first aspect of the present invention is implemented.
[0052] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and: when the computer program is executed by the processor, any step of the device anomaly monitoring method based on the Internet of Things as described in the first aspect of the present invention is implemented.
[0053] The beneficial effects of the present invention are as follows: The present invention generates a high-dimensional original matrix by collecting monitoring data, optimizes it using the GCN model combined with ACO, updates it through the contrast learning model and the FCM algorithm, uses the VAE model combined with the PSO algorithm to search for the global optimum, optimizes the classification based on K-means clustering and BSO, and performs MLE calculation, updates the dynamic causal KG through Granger causality test, generates a multi-modal result array through NSM, scoring formula, naive Bayes model, Mahalanobis distance formula, and logistic regression model, and optimizes it using fuzzy rules and GWO; improves the accuracy and response speed of anomaly monitoring, and enhances the reliability and efficiency of anomaly monitoring. Description of the Drawings
[0054] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0055] Figure 1 It is a flowchart of the device anomaly monitoring method based on the Internet of Things in Embodiment 1.
[0056] Figure 2 It is a schematic diagram of the device anomaly monitoring system based on the Internet of Things in Embodiment 1.
[0057] Figure 3 It is a schematic diagram of the dynamic causal KG update in Embodiment 1.
[0058] Figure 4 It is a schematic diagram of hierarchical alarm in Embodiment 1. Detailed implementation manners
[0059] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following will make a detailed description of the specific implementation manners of the present invention in conjunction with the accompanying drawings of the specification.
[0060] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0061] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that can be included in at least one implementation manner of the present invention. The "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment that excludes other embodiments.
[0062] Embodiment 1, referring to Figures 1 to 4 , which is the first embodiment of the present invention. This embodiment provides a device anomaly monitoring method based on the Internet of Things, including the following steps:
[0063] S1. Collect monitoring data to generate a high-dimensional original matrix and construct a dynamic adjacency matrix. Use the GCN model and combine it with ACO for optimization. Select the output of the final low-dimensional topological subset through roulette wheel selection. Calculate the enhancement and contrast loss through the contrast learning model. Set the weight of the pseudo-label loss based on the FCM algorithm. Generate the combined loss to update the GCN model. Use the VAE model and combine it with the PSO algorithm to search for the global optimum. Optimize the classification based on K-means clustering and BSO, and perform MLE calculation to generate the final anomaly label;
[0064] Specifically, collecting monitoring data to generate a high-dimensional original matrix includes:
[0065] Collect multi-modal data through sensors, including temperature, vibration, flow, and biological signal data;
[0066] The sensors include temperature, vibration, current, and biological signal sensors;
[0067] Collect system performance data through the host log, including CPU usage and process status data;
[0068] Collect traffic metadata through the edge gateway, including packet and protocol distribution data;
[0069] Preprocess the multi-modal data, system performance data, and traffic metadata;
[0070] The preprocessing includes time alignment through timestamps, denoising using wavelet transform, filling missing values through linear interpolation, and normalization processing through the Z-Score normalization method;
[0071] Use the variance sliding window and the mean sliding window to extract time series features, use FFT to extract frequency domain features, and splice them into a high-dimensional original feature matrix.
[0072] Collecting three types of data, namely environmental parameters, system status, and network behavior, through the combination of multi-source sensors and edge computing nodes breaks through the analysis bias problem caused by traditional single data sources, helps the model improve recognition accuracy and robustness. Noise removal and scale normalization processing ensure the stability and comparability of the feature space. Using timestamps for alignment provides a unified reference time benchmark for asynchronously collecting monitoring data. Using multiple sliding windows for trend and fluctuation analysis of different types of data, and combining with FFT to extract periodic change features, fully mines the time series information. Forming a unified high-dimensional space vector through feature splicing provides unified processing for subsequent models and structural guarantee for the input of end-to-end models.
[0073] Furthermore, construct a dynamic adjacency matrix, optimize it using the GCN model in combination with ACO, select the final low-dimensional topological subset through roulette wheel selection, calculate the enhancement and contrast loss through the contrast learning model, set the weight of the pseudo-label loss based on the FCM algorithm, and generate the combined loss to update the GCN model, including:
[0074] Define sensors, gateways, and hosts as the nodes of the dynamic adjacency matrix, define the diagnostic protocol (as the data exchange protocol between two devices, obtained based on the protocol distribution) as the edges of the dynamic adjacency matrix, and define the communication frequency (obtained based on data packets and subjected to min-max normalization) as the edge weights of the dynamic adjacency matrix to construct the dynamic adjacency matrix;
[0075] Construct a two-layer GCN model, including an input layer, two-layer graph convolutional layer, pooling layer, fully connected layer, and output layer;
[0076] Obtain the graph dataset from the Kaggle open platform (construct the training high-dimensional original feature matrix and dynamic adjacency matrix), train the model, and optimize it using the Adam optimizer;
[0077] Input the high-dimensional original feature matrix and the dynamic adjacency matrix, and generate the initial node embedding matrix through two-layer graph convolution;
[0078] Calculate the node degree (obtained by calculating the number of connections of each node in the statistical dynamic adjacency matrix through the degree function) and the neighbor behavior similarity (obtained based on the average of the cosine similarities between node embeddings), and merge them to generate the topological feature matrix;
[0079] Initialize ACO, set the number of ants (set based on the ACO standard parameters), the initial value of pheromone (obtained based on the logistic chaotic map), and the iteration upper limit (set based on a fixed number of iterations);
[0080] Based on the topological feature matrix, each ant selects some features through pheromone and heuristic information and merges them into a low-dimensional topological feature subset. The formula is:
[0081]
[0082] Among them, and θ are the pheromone influence parameter and heuristic information influence parameter (set based on historical research analysis), η j is the anomaly discrimination degree of the next feature j, A and B are the anomaly node set and normal node set (obtained based on the K-means clustering method), f aj and f bj are the values of node a and node b in the topological feature matrix f on the next feature j respectively, is the probability that ant k selects the next feature j from the current feature i, C k is the set of features that ant k can select, l is the index of the next feature j, is the power of the pheromone concentration from the current feature i to feature l is the θ power of the heuristic information from the current feature i to feature l;
[0083] Set the threshold of anomaly discrimination (set based on statistical significance test);
[0084] If the anomaly discrimination is greater than the low-dimensional topological feature subset of the threshold of anomaly discrimination, update the pheromone, and the formula is:
[0085]
[0086] where is the increment of the pheromone concentration on the edge from the current feature i to the next feature j, Q is the pheromone deposition constant (set based on experimental tuning), L k is the path cost of ant k (obtained based on the reciprocal of the F1 score), τ ij is the updated pheromone concentration on the edge from the current feature i to the next feature j, ρ is the pheromone evaporation rate, and k(i,j) is the edge that ant k visits from the current feature i to the next feature j;
[0087] If the anomaly discrimination is less than or equal to the low-dimensional topological feature subset of the threshold of anomaly discrimination, calculate the gradient of the convolutional kernel weights of the GCN model through backpropagation, update the weights of the convolutional layer of the GCN model using the Adam optimizer, generate a new initial node embedding matrix and topological feature matrix, calculate the anomaly discrimination, and stop until the anomaly discrimination is greater than the threshold of anomaly discrimination. Output the updated node embedding matrix, normalize the anomaly discrimination of the embedding vectors in the updated node embedding matrix using the exponential function, allocate the pheromone weights according to the normalized anomaly discrimination, and update the pheromone concentration through weighted calculation;
[0088] Use roulette wheel selection to adjust the selection path of the ant by combining the updated information concentration and heuristic information, and output the final low-dimensional topological feature subset.
[0089] By modeling sensors, gateways, and hosts as nodes, the diagnostic protocol as the edges between nodes, and the communication frequency as the edge weights, different device roles can be unified, providing a standard input for graph convolution operations. The edges defined based on the protocol ensure the semantic accuracy of the connections, avoiding the defect of traditional edge construction based on physical links being vulnerable to dynamic changes. The normalization process of the communication frequency eliminates the problem of inconsistent dimensions, enabling the GCN to converge better during the training process and avoiding gradient explosion or vanishing. Introducing a two-layer GCN structure and using two-layer graph convolution operations can prevent the occurrence of over-smoothing problems while retaining local neighborhood features, balancing the feature extraction ability and model complexity, and enhancing the generalization ability of the model on small datasets. The ACO optimization feature selection based on topological features generates a topological feature matrix through node degree and neighbor behavior similarity, capturing the consistency features of the local connection density and embedded behavior of nodes, greatly reducing the search space, improving the convergence speed, and retaining the features closely related to structural anomalies. Initializing the pheromone value using Logistic chaotic mapping can effectively break the high consistency of the search path at the initial stage of the search, prompting ants to explore more potential high-quality subsets and improving the final search quality. The anomaly discrimination as the feature selection criterion can more accurately reflect the discriminative ability of features in the anomaly detection task, effectively shortening the indirect path between feature selection and model performance and improving the overall performance index. The roulette wheel selection combined with pheromone weight adjustment introduces the roulette wheel mechanism on the basis of ant colony search, making the selection of feature subsets not only depend on the cumulative effect of pheromone but also incorporate the random perturbation of heuristic information, effectively avoiding the premature convergence of early high-quality paths to the overall search space, thus exploring more possible global optimal solutions and enhancing the representativeness of low-dimensional topological feature subsets and anomaly recognition performance.
[0090] Furthermore, use the VAE model combined with the PSO algorithm to search for the global optimum, optimize the classification based on K-means clustering and BSO, and perform MLE calculations to generate the final anomaly labels, including:
[0091] Construct a contrastive learning model, including an input layer, a basic encoder, a projection head, a contrastive loss layer, and an output layer;
[0092] Input the final low-dimensional topological feature subset, add Gaussian noise and perform clipping to generate an enhanced low-dimensional topological feature subset;
[0093] Calculate the contrastive loss of positive samples (original features and enhanced features of the same device) and negative samples (features of different devices at the same time) through scikit-learn, and output the optimized embedding matrix;
[0094] Perform fuzzy clustering based on the optimized embedding matrix, set a fixed number of clusters (set based on the anomaly type), calculate the membership degree through the FCM algorithm, and update the cluster centers through the weighted centroid method. Stop when the maximum number of updates is reached (set based on the data dimension).
[0095] Set the membership degree threshold (set based on the membership degree distribution statistics), select the samples with membership degrees greater than the membership degree threshold as pseudo-labels, calculate the pseudo-label loss value through the cross-entropy loss function, perform a descending sort, and select the maximum membership degree among the pseudo-labels as the weight of the pseudo-label loss.
[0096] Fusion the alignment loss and the pseudo-label loss with weights to generate a combined loss.
[0097] Backpropagate the combined loss through the Adam optimizer to update the weights of the GCN fully connected layer, and output the updated low-dimensional topological feature subset through ACO.
[0098] Divide the low-dimensional topological subset into time series through a time window.
[0099] Construct a VAE model, including an input layer, a hidden layer, a mean layer, a variance layer, a reparameterization layer, and an output layer.
[0100] Train the model using time series data obtained from the UCR Time Series Archive.
[0101] Input the time series into the trained VAE model, generate an initial latent variable through the encoder, calculate the mean and variance of the initial latent variable through the mean layer and the variance layer, generate a reconstructed sequence through the decoder, and output the window length sequence.
[0102] Initialize the PSO algorithm, define the objective function according to the window length sequence, and the formula is:
[0103]
[0104] where J is the objective function value, MSE is the mean square error of each window (obtained based on the time series and the reconstructed sequence), KL is the divergence (obtained based on the mean and variance of the initial latent variable), and Var is the variance of the window length (obtained based on the window length sequence and the window length mean (calculated based on the window length mean)).
[0105] Based on the objective function value, update the particle position and velocity through the velocity and position update rules, search for the global optimal latent variable weight and window length mapping parameters, and stop until the objective function value is less than the threshold of the objective function value (set based on the bootstrap method), and output the global optimal latent variable weight and window length mapping parameters.
[0106] Calculate the product of the optimal latent variable weights and the initial latent variables to obtain the optimized latent variables;
[0107] Use the window length mapping parameter and the optimized latent variables to generate an optimized window length sequence through the sigmoid function, and perform smoothing processing using the moving average method, and calculate the cumulative timestamp through the summation formula;
[0108] Use linear interpolation to interpolate the time series with respect to the cumulative timestamp and the timestamps of the time series, and perform window partitioning on the time series, and aggregate all the eigenvalue within each window through mean aggregation to generate an optimized dynamic time window sequence;
[0109] Based on the optimized dynamic time window sequence, extract time series features through wavelet transform and moving window mean, extract statistical features through sequence mean and sequence variance, merge them into a multi-scale feature vector, and enhance it through the Transformer model;
[0110] Perform K-means clustering on the enhanced multi-scale feature vector to generate initial anomaly labels, including point anomalies, collective anomalies, and continuous anomalies;
[0111] Based on the initial anomaly labels, set the nodes of the anomaly evolution graph, and based on the initial transition probability between two initial anomaly labels (heuristically set based on domain knowledge), set the edges of the anomaly evolution graph to construct the anomaly evolution graph;
[0112] Use BSO to optimize the transition probabilities in the anomaly evolution graph, stop when the maximum number of optimizations is reached (set based on an empirical formula for the problem size), and output the optimal anomaly labels;
[0113] Perform weighted average fusion on the initial anomaly labels and the optimal anomaly labels to generate corrected anomaly labels;
[0114] Calculate the likelihood probability of each corrected anomaly label for the multi-modal features and the corrected anomaly labels through MLE, and select the corrected anomaly label with the maximum likelihood probability to output the final anomaly label.
[0115] Optimize the latent variables and window length through VAE + PSO. The objective function optimized by PSO considers triple constraints (reconstruction error, divergence, window length variance), constituting a unified evaluation criterion, enhancing the global search ability. The optimized window length sequence is smoothed by sigmoid activation and moving average, solving the problem of strong discrete jump in the original time window, achieving controllable continuity of the dynamic time window, performing excellently under non-equidistant or variable-period anomalies, overcoming the rigid defects of traditional fixed-window strategies. Pseudo-label generation and joint loss design, mapping the membership weight into the pseudo-label loss. Compared with traditional binary pseudo-label processing methods, continuous uncertainty modeling is introduced, significantly improving the reliability and stability of pseudo-labels. The joint loss introduces pseudo-supervised feedback in contrastive learning, effectively enhancing the representational learning's perception ability of "weak cross-device correlations" and improving the discriminative power of the embedding space. Multi-scale feature fusion + K-means clustering. After multi-scale feature fusion, the feature space simultaneously has frequency domain, time domain, and statistical structures, improving the ability to distinguish complex behaviors. K-means clustering in this multi-scale space shows the ability of self-organization of abnormal patterns, providing a reasonable initial node structure for subsequent construction of the abnormal evolution graph. BSO optimizes the transition probability of the abnormal evolution graph. BSO introduces local mutation and combined memory mechanisms on the basis of global search, making it have stronger jumping ability and convergence stability in the optimization of high-dimensional graph structures. The abnormal labels obtained after graph structure optimization are closer to the real evolution path, enhancing the interpretability and traceability of anomaly detection. MLE calculates the final abnormal labels. Selecting abnormal labels based on the maximum likelihood criterion can automatically avoid low-confidence interference from multi-label candidates, improving the determination credibility of anomaly recognition. At the same time, MLE uses multi-modal features to enhance information constraints, making the final output labels have the advantage of multi-source information fusion and improving the overall system robustness.
[0116] S2. Initialize the dynamic causal KG, update it through Granger causality test, generate a multi-modal result array through NSM, scoring formula, Naive Bayes model, Mahalanobis distance formula, and logistic regression model, initialize fuzzy rules, generate optimized abnormal labels by combining with GWO optimization, and integrate them into a JSON report;
[0117] Specifically, initialize the dynamic causal KG, update it through Granger causality test, generate a multi-modal result array through NSM, scoring formula, Naive Bayes model, Mahalanobis distance formula, and logistic regression model, initialize fuzzy rules, generate optimized abnormal labels by combining with GWO optimization, and integrate them into a JSON report, including:
[0118] Define the sensor, gateway, host, and the final anomaly type as nodes of the dynamic causal KG. The semantic relationship (the cooperation relationship between devices) and the causal relationship (if a change in one node causes a change in another node, then there is a causal relationship between the two nodes) are the semantic edges and causal edges of the dynamic causal KG respectively. Based on the heuristic assignment of domain knowledge, set the weights of the semantic edges and causal edges respectively, and initialize the dynamic causal KG;
[0119] Based on the time series, use Granger causality test to calculate the causality score, find the corresponding probability based on the F-distribution table, filter out the corresponding probability less than the probability threshold (set based on the hypothesis test in statistics), update the causal edge weight, and generate the updated dynamic causal KG. The formula is:
[0120]
[0121] where Gra is the causality score, X is the potential causal feature, Y is the final anomaly label, T is the total number of time steps t, and y t is the actual value of the final anomaly label Y at time step t;
[0122] Based on the final anomaly label, maximum likelihood probability, and dynamic causal KG, formulate Prolog rules (if the temporal features of multimodal data, system performance data, and traffic metadata are respectively greater than their corresponding temporal feature thresholds, and the causal edge weights and maximum likelihood probabilities (point anomaly, continuous anomaly, and collective anomaly) of the dynamic causal KG are respectively greater than the corresponding preset thresholds, then adjust the normalized likelihood probabilities of point anomaly, continuous anomaly, and collective anomaly respectively (the thresholds are set based on Top-k sampling), otherwise do not adjust). Input the maximum likelihood probability and multi-scale feature vector, calculate the matching score through the fully connected layer of NSM, and normalize it through the softmax function to generate the normalized likelihood probability;
[0123] Adjust the normalized likelihood probability through Prolog rules, and accumulate the adjusted normalized likelihood probability to output the semantic consistency score;
[0124] Based on the final anomaly label, multi-scale feature vector, maximum likelihood probability, and dynamic causal KG, formulate expert rules (if the anomaly discrimination degrees of the sensor and gateway are respectively greater than their corresponding anomaly degree thresholds, and the semantic edge weights of the dynamic causal KG are respectively greater than their corresponding semantic edge weight thresholds, then increase the initial anomaly score. If the L2 norm of the multi-scale feature vector is greater than the norm threshold, then increase the initial anomaly score to generate an adjustment value (the anomaly degree, weight, and norm thresholds are set based on the fixed threshold method)). Combine with the scoring formula to output the anomaly score. The formula is:
[0125] S = C + W KG·Z,
[0126] where S is the anomaly score, C is the sum of the adjustment values of all rules (each rule is obtained based on the multi-scale feature vector and the semantic edge weight W of the dynamic causal KG), KG and Z is the intensity of the multi-scale feature vector (calculated based on the L2 norm);
[0127] Construct a Naive Bayes model based on the multi-scale feature vector and the final anomaly label, and adjust it by combining the semantic edge weight of the dynamic causal KG to obtain the adjusted probability. The formula is:
[0128] O′(Y u ) = O(Y u )·me(W KG ),
[0129] where O′ is the adjusted probability, O is the prior probability (obtained based on the Naive Bayes model), W KG is the semantic edge weight of the dynamic causal KG, me is the calculation of the average value, and u is the index of the final anomaly label;
[0130] Based on the multi-scale feature vector, use the Mahalanobis distance formula to calculate the Mahalanobis distance between the multi-scale feature vector and the normal sample mean (obtained based on the TON_IoT data statistics), and adjust it by combining the semantic edge weight of the dynamic causal KG to output the deviation degree. The formula is:
[0131] D′ = D·(1 + me(W KG ))
[0132] where D′ is the adjusted Mahalanobis distance (representing the deviation degree), and D is the Mahalanobis distance;
[0133] Construct a logistic regression model, including an input layer and an output layer, and train the model based on the final anomaly label and the multi-scale feature vector. The formula is:
[0134]
[0135] where V is the probability, X is the multi-scale feature vector, and W and b are the weight matrix and the bias term (obtained by training based on the TON_IoT data);
[0136] Adjust it by combining the semantic edge weight of the dynamic causal KG and output the classification label. The formula is:
[0137] V′(Y u ∣X) = P(Y u ∣X)·me(W KG ),
[0138] where V′ is the adjusted probability;
[0139] Merge the anomaly score, output probability, deviation degree, and classification label into a multi-modal result array;
[0140] Perform weighted fusion on the normalized likelihood probability, output probability, and deviation degree through multi-head attention, screen the fusion result greater than the fusion result threshold (set based on the rule of thumb), and output the fusion label;
[0141] Calculate the cosine similarity between the normalized likelihood probability and the probability, screen the value less than the cosine similarity threshold of the normalized likelihood probability and the probability (set based on the domain knowledge of device usage), and mark it as a conflict;
[0142] Initialize the fuzzy rules, based on GWO, use the chaotic Tent map to initialize the rule weights, and dynamically adjust the rule priority weights. The formula is:
[0143] F(t′) = F(0) × (1 + Δh(t′)),
[0144] where F(t′) is the weight value of a certain fuzzy rule at the current moment t′, F(0) is the initial rule weight, and Δh(t′) is the weight increment at the current moment t′ (dynamically calculated based on the frequency change of the anomaly matched by this rule);
[0145] Set the initial standard deviation for the fused likelihood probability (set based on the direct standard deviation estimation method), use the Gaussian membership function, and dynamically adjust the standard deviation based on the Gaussian distribution change curve until the standard deviation converges and then stop. Output the optimized fused likelihood probability. The formula is:
[0146]
[0147] where σ(t′) is the standard deviation at the current moment t′, σ0 is the initial standard deviation, E is the number of inference iterations, E max is the maximum number of inference rounds, e is the base of the natural logarithm, and ε is the normalization factor (set based on standard experiments);
[0148] Screen the optimized fused likelihood probability greater than the optimized fused likelihood probability threshold (set based on the statistical analysis of the fused likelihood probability distribution of normal and abnormal events in historical data), confirm the anomaly, and output the optimized anomaly label;
[0149] Integrate the optimized anomaly label, semantic consistency score, multi-modal result array, and conflict mark, and format them into a JSON report.
[0150] By constructing and updating a dynamic causal KG, the problems of missing context and isolated event analysis in traditional anomaly detection are solved. The causal edges are quantitatively updated through Granger tests, and a knowledge graph that can evolve with the system state changes is constructed, improving the system's dynamic adaptability and anomaly interpretability, significantly reducing the possibility of misjudging causal edges, ensuring the reliability of the causal graph, and thus providing a more accurate prior structure for subsequent anomaly reasoning. Based on the normalization likelihood probability adjustment of Prolog rules and NSM, the "black box" problem existing in deep learning for anomaly detection is solved. By introducing expert experience through regularization adjustment, the system's interpretability and adjustment flexibility are improved, avoiding misjudgment of the model on boundary samples, making anomaly judgment more contextually relevant. The multi-modal fusion and conflict detection mechanism, and the conflict marking mechanism can prompt the existence of multiple solutions or specific structures in anomaly recognition, which is conducive to the triggering of subsequent manual review or active learning mechanisms. The fuzzy rule optimization and GWO scheduling mechanism solve the problem of performance degradation of fixed rules in dynamic scenarios, introduce a dynamic feedback mechanism to enhance the system's response ability, and dynamically adjust the contribution degree of fuzzy rules through a weight increment function, enabling the system to automatically strengthen the corresponding rules when the frequency of anomaly types changes. The Gaussian fuzzy adjustment of the fusion likelihood probability solves the problem of insufficient generalization of traditional fixed Gaussian parameter models to different anomaly patterns, enhances the model's adaptability to non-uniform anomaly features, and improves the judgment stability after the anomaly label converges, reducing the problem of false triggering caused by sample fluctuations.
[0151] S3. Set up an alarm mechanism based on the JSON report;
[0152] Specifically, setting up an alarm mechanism based on the JSON report includes:
[0153] Set an alarm threshold (set based on historical anomaly data analysis). If any one or more indicators in the JSON report exceed the alarm threshold, a primary alarm is triggered. If all indicators in the report exceed the alarm threshold, a high-level alarm is triggered;
[0154] The primary alarm includes notifying by text message or APP and recording logs;
[0155] The high-level alarm includes adjusting device parameters and isolating the abnormal device.
[0156] Setting the alarm threshold through historical anomaly data analysis effectively reduces the false alarm rate, improves the practicality and trust of the system. When the device is initially deployed or the scenario is changed, it has the ability to quickly adapt, supports personalized settings under different devices and environmental conditions. Through the hierarchical alarm mechanism, it combines the dual guarantees of edge response and central instruction, enhancing the robustness and reliability of the system.
[0157] S4. Store the collected monitoring data and the generated JSON reports from the analysis;
[0158] Specifically, first generate a high-dimensional raw feature matrix for the collected monitoring data, including:
[0159] Format the collected monitoring data and the generated JSON reports from the analysis into a JSON comprehensive report, and use Grafana to convert it into a visual comprehensive report, then upload it to the cloud for storage.
[0160] By integrating the monitoring data and JSON reports and formatting them into a unified structure, it is convenient for unified analysis and display. The JSON format provides highly structured data support, is suitable for docking with backend systems, and using Grafana can achieve dynamic display of multi-dimensional charts, effectively assisting decision-making, realizing multi-source data fusion, and improving the global visualization management ability of operation and maintenance.
[0161] This embodiment also provides an Internet of Things-based device anomaly monitoring system, including:
[0162] A collection and analysis module, which is used to collect monitoring data to generate a high-dimensional raw matrix and construct a dynamic adjacency matrix, optimize it using the GCN model combined with ACO, select the output of the final low-dimensional topology subset through roulette wheel selection, calculate the enhancement and contrast loss through a contrast learning model, set the weight of the pseudo-label loss based on the FCM algorithm, generate a joint loss to update the GCN model, use the VAE model combined with the PSO algorithm to search for the global optimum, perform classification optimization based on K-means clustering and BSO, and perform MLE calculation to generate the final anomaly label;
[0163] A verification and optimization module, which is used to initialize the dynamic causal KG, update it through Granger causality test, generate a multi-modal result array through NSM, scoring formula, naive Bayes model, Mahalanobis distance formula, and logistic regression model, initialize fuzzy rules, combine with GWO optimization to generate an optimized anomaly label, and integrate it into a JSON report;
[0164] A grading alarm module, which is used to set an alarm mechanism based on the JSON report;
[0165] A storage and analysis module, which is used to store the collected monitoring data and the generated JSON reports from the analysis.
[0166] This embodiment also provides a computer device, which is applicable to the situation of the Internet of Things-based device anomaly monitoring method, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the Internet of Things-based device anomaly monitoring method proposed in the above embodiment.
[0167] The computer device can be a terminal, which includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, carrier networks, NFC (Near Field Communication), or other technologies. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball, or touchpad provided on the outer shell of the computer device, or an external keyboard, touchpad, or mouse, etc.
[0168] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, it implements the method for monitoring device anomalies based on the Internet of Things as proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM for short), Electrically Erasable Programmable Read-Only Memory (EEPROM for short), Erasable Programmable Read Only Memory (EPROM for short), Programmable Red-Only Memory (PROM for short), Read-Only Memory (ROM for short), magnetic memory, flash memory, magnetic disks, or optical discs.
[0169] In summary, the present invention generates a high-dimensional raw matrix by collecting monitoring data, uses a GCN model and combines it with ACO for optimization, updates through a contrast learning model and FCM algorithm, uses a VAE model combined with a PSO algorithm to search for the global optimum, optimizes classification based on K-means clustering and BSO, and performs MLE calculations. Updates the dynamic causal KG through Granger causality tests, generates a multi-modal result array through NSM, scoring formula, naive Bayesian model, Mahalanobis distance formula, and logistic regression model, and uses fuzzy rules and GWO for optimization; improves the accuracy and response speed of anomaly monitoring, and enhances the reliability and efficiency of anomaly monitoring.
[0170] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.
Claims
1. An abnormal device monitoring method based on the Internet of Things, characterized in that: Including, Collect monitoring data to generate a high-dimensional raw matrix and construct a dynamic adjacency matrix, use the GCN model and combine it with ACO for optimization, select the output of the final low-dimensional topological subset through roulette selection, calculate the enhancement and contrast loss through the contrast learning model, set the weight of the pseudo-label loss based on the FCM algorithm, generate the joint loss to update the GCN model, use the VAE model combined with the PSO algorithm to search for the global optimum, optimize the classification based on K-means clustering and BSO, and perform MLE calculation to generate the final anomaly label; Initialize the dynamic causal KG, update it through Granger causality test, generate a multi-modal result array through NSM, scoring formula, naive Bayes model, Mahalanobis distance formula, and logistic regression model, initialize the fuzzy rules, combine with GWO optimization to generate the optimized anomaly label, and integrate it into a JSON report; Set the alarm mechanism based on the JSON report; Store the collected monitoring data and the generated JSON report from the analysis.
2. The method for monitoring device anomalies based on the Internet of Things according to claim 1, characterized in that: The process of collecting monitoring data to generate a high-dimensional raw matrix and construct a dynamic adjacency matrix, using the GCN model and combining it with ACO for optimization, selecting the output of the final low-dimensional topological subset through roulette selection, calculating the enhancement and contrast loss through the contrast learning model, setting the weight of the pseudo-label loss based on the FCM algorithm, and generating the joint loss to update the GCN model includes: Collect monitoring data, including temperature, vibration, flow, biological signals, CPU usage, process status, data packets, and protocol distribution data, to generate a high-dimensional raw feature matrix and construct a dynamic adjacency matrix; Construct a two-layer GCN model, input the high-dimensional raw feature matrix and the dynamic adjacency matrix, generate the initial node embedding matrix through two-layer graph convolution, and generate the topological feature matrix; Initialize ACO. Based on the topological feature matrix, each ant selects some features through pheromone and heuristic information and combines them into a low-dimensional topological feature subset; If the low-dimensional topological feature subset has an anomaly discrimination degree greater than the threshold of the anomaly discrimination degree, update the pheromone; If the low-dimensional topological feature subset has an anomaly discrimination degree less than or equal to the threshold of the anomaly discrimination degree, update the weights of the convolutional layer of the GCN model, output the updated node embedding matrix, normalize the anomaly discrimination degree of the embedding vectors in the updated node embedding matrix, use the exponential function, allocate the pheromone weight according to the normalized anomaly discrimination degree, and update the pheromone concentration through weighted calculation; Use roulette selection to adjust the selection path of the ants in combination with the updated information concentration and heuristic information, and output the final low-dimensional topological feature subset.
3. The method for monitoring device anomalies based on the Internet of Things according to claim 2, characterized in that: The process of using the VAE model combined with the PSO algorithm to search for the global optimum, optimizing the classification based on K-means clustering and BSO, and performing MLE calculation to generate the final anomaly label includes: Construct a contrast learning model, input the final low-dimensional topological feature subset, add Gaussian noise and perform clipping to generate an enhanced low-dimensional topological feature subset; Calculate the contrastive loss between positive and negative samples through scikit - learn, output the optimized embedding matrix, perform fuzzy clustering, set a fixed number of clusters, calculate the membership degree through the FCM algorithm, and update the cluster centers through the weighted centroid method; Set the membership degree threshold, select the samples with membership degree greater than the threshold as pseudo - labels, calculate the pseudo - label loss value through the cross - entropy loss function, perform a descending sort, and select the maximum membership degree among the pseudo - labels as the weight of the pseudo - label loss; Fuse the contrastive loss and the pseudo - label loss with weights to generate a joint loss; Perform backpropagation on the joint loss through the Adam optimizer to update the weights of the GCN fully - connected layer, output the updated low - dimensional topological feature subset through ACO, and divide it into time series through a time window; Construct a VAE model, input the time series, generate an initial latent variable through the encoder, calculate the mean and variance of the initial latent variable through the mean layer and variance layer, generate a reconstructed sequence through the decoder, and output the window - length sequence; Initialize the PSO algorithm and define the objective function according to the window - length sequence; Update the particle positions and velocities based on the objective - function value update rule, and output the global - optimal latent - variable weights and window - length mapping parameters; Calculate the product of the optimal latent - variable weights and the initial latent variable to obtain the optimized latent variable, and calculate the cumulative timestamp in combination with the window - length mapping parameters; Interpolate the time series using linear interpolation based on the cumulative timestamp and the time - series timestamps, perform window partitioning on the time series, aggregate all the feature values within each window to generate an optimized dynamic - time - window sequence, extract temporal features and statistical features, merge them into a multi - scale feature vector, and enhance it through the Transformer model; Perform K - means clustering on the enhanced multi - scale feature vector to generate initial anomaly labels, and construct an anomaly evolution graph; Optimize the transition probabilities in the anomaly evolution graph using BSO, output the optimal anomaly labels, and perform weighted - average fusion in combination with the initial anomaly labels to generate corrected anomaly labels; Calculate the likelihood probability of each corrected anomaly label for the multi - modal features and the corrected anomaly labels through MLE, and output the final anomaly labels.
4. The method for monitoring device anomalies based on the Internet of Things according to claim 3, wherein: Initialize the dynamic causal KG, update it through Granger causality test, generate a multi - modal result array through NSM, scoring formula, Naive Bayes model, Mahalanobis distance formula, and logistic regression model, initialize fuzzy rules, and generate optimized anomaly labels through GWO optimization, and integrate them into a JSON report, including: Initialize the dynamic causal KG, calculate the causal score using Granger causality test, and update the causal - edge weights; Input the maximum likelihood probability and the multi - scale feature vector, calculate the matching score through the fully - connected layer of NSM, generate the normalized likelihood probability through the softmax function, adjust it using Prolog rules, and accumulate to output the semantic - consistency score; Output the anomaly score based on expert rules and scoring formula, obtain the probability based on the Naive Bayes model, output the deviation degree based on the Mahalanobis distance, construct a logistic regression model, and output the classification label; Merge the anomaly score, output probability, deviation degree, and classification label into a multi-modal result array; Perform weighted fusion on the normalized likelihood probability, output probability, and deviation degree through multi-head attention, and output a fused label; Calculate the cosine similarity between the normalized likelihood probability and the probability, filter out those less than the cosine similarity threshold of the normalized likelihood probability and the probability, and mark them as conflicts; Initialize the fuzzy rules, initialize the rule weights using the chaotic Tent map based on GWO, and dynamically adjust the rule priority weights; Set an initial standard deviation for the fused likelihood probability, use the Gaussian membership function, and dynamically adjust the standard deviation based on the Gaussian distribution change curve to output the optimized fused likelihood probability; Filter out those where the optimized fused likelihood probability is greater than the optimized fused likelihood probability threshold, confirm the anomaly, and output the optimized anomaly label; Integrate the optimized anomaly label, semantic consistency score, multi-modal result array, and conflict mark, and format them into a JSON report.
5. The method for monitoring device anomalies based on the Internet of Things according to claim 4, characterized in that: The alarm mechanism is set based on the JSON report, including: Set the alarm threshold. If any one or more indicators in the report exceed the alarm threshold, a primary alarm is triggered. If all indicators in the report exceed the alarm threshold, a high-level alarm is triggered.
6. The method for abnormal device monitoring based on the Internet of Things according to claim 2, characterized in that: The high-dimensional raw feature matrix is generated for the collected monitoring data, including: Extract time-series features using a variance sliding window and a mean sliding window, extract frequency-domain features using FFT, and concatenate them into a high-dimensional raw feature matrix.
7. The method for monitoring device anomalies based on the Internet of Things according to claim 6, wherein: The storage of the collected monitoring data and the JSON report generated by the analysis includes: Format the collected monitoring data and the JSON report generated by the analysis into a JSON comprehensive report, convert it into a visual comprehensive report using Grafana, and upload it to the cloud for storage.
8. An equipment anomaly monitoring system based on the Internet of Things, based on the equipment anomaly monitoring method based on the Internet of Things according to any one of claims 1 to 7, characterized in that: Including, The collection and analysis module is used to collect monitoring data to generate a high-dimensional raw matrix and construct a dynamic adjacency matrix, optimize it using the GCN model combined with ACO, select the final low-dimensional topology subset through roulette wheel selection, calculate the enhancement and contrast loss through the contrast learning model, set the weight of the pseudo-label loss based on the FCM algorithm, generate a joint loss to update the GCN model, search for the global optimum using the VAE model combined with the PSO algorithm, perform classification optimization based on K-means clustering and BSO, and perform MLE calculation to generate the final anomaly label; The verification and optimization module is used to initialize the dynamic causal KG, update it through Granger causality test, generate a multi-modal result array through NSM, scoring formula, naive Bayes model, Mahalanobis distance formula, and logistic regression model, initialize the fuzzy rules, combine GWO optimization to generate an optimized anomaly label, and integrate it into a JSON report; The hierarchical alarm module is used to set the alarm mechanism based on the JSON report; The storage and analysis module is used to store the collected monitoring data and the JSON report generated by the analysis.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the device anomaly monitoring method based on the Internet of Things according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, it implements the steps of the method for monitoring device anomalies based on the Internet of Things according to any one of claims 1 to 7.
Citation Information
Cited By
High-rise building fire monitoring system and method based on distributed sensors
CN120412170A
Distribution network line fault analysis method, system and equipment based on edge calculation
CN120632538A
Method and system for tracing abnormal data of equipment operation behavior based on block chain
CN121071753A
AI-based experimental consumable management system and method
CN121148625A
Edge computing node exception recovery method and system, electronic equipment and storage medium
CN121636236A