Industrial production data anomaly detection system
By detecting production control differences and set drift parameters, combined with multiple window setting strategies and encoder model training, the problem of low anomaly detection efficiency in existing technologies is solved, and more efficient anomaly detection for multivariate time series data is achieved.
Patent Information
- Application Number
- CN202510587370.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-08
- Publication Date
- 2025-10-03
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing anomaly detection models for industrial production data fail to determine targeted data extraction strategies based on the actual production status changes corresponding to the training dataset, resulting in low anomaly detection efficiency.
The production monitoring module is used to detect production control difference parameters and set drift parameters, determine the production data status of the time series training data set, and use the window analysis module to set window extraction parameters according to the forward-looking production change degree, drift trend change parameters or reference cluster distribution index. The sparse autoencoder and variational autoencoder are combined for training to optimize the parameters of the anomaly analysis model.
It improves the anomaly detection efficiency of multivariate time series data, enhances the accuracy and robustness of the anomaly analysis model, and adapts to the data change characteristics under different production conditions.
Smart Images

Figure CN120744732A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of industrial data detection, and in particular to an industrial production data anomaly detection system. Technical Background
[0002] In the industrial production process, the equipment monitoring data obtained by different sensors and at different times are recorded as multivariate time series data. By constructing anomaly detection models to perform anomaly detection on multivariate time series data, abnormal data can be determined in a timely manner. In the process of constructing the anomaly detection model, it is necessary to extract features from the data information to determine the cause of the anomaly. However, the actual production status in the industrial production process changes, and the data features also change. However, the existing anomaly detection model construction process for industrial generated data analysis often determines the training data based on a preset data extraction method, ignoring the connection between the production status of different data. Therefore, how to adaptively adjust the data extraction process based on the changes in the actual production status corresponding to the existing data set to ensure the validity of the data used for anomaly detection model training is an urgent problem to be solved by technical personnel in this field.
[0003] Chinese patent application publication number CN118898045A discloses a method and system for detecting anomalies in industrial internet time series data, comprising the following steps: S1: real-time acquisition of raw time series data; S2: segmenting the time series data according to preset time windows to form multiple time segments; S3: performing multi-level clustering analysis on each time segment to identify different patterns and potential anomalies in the data; S4: constructing a high-dimensional feature space; S5: performing unsupervised learning to train an autoencoder model for anomaly detection; S6: determining whether the current time series data contains anomalies; and S7: scoring the reconstruction error of each time segment and making a judgment. However, the above scheme has the following drawbacks: it fails to determine a targeted data extraction strategy based on the actual production status changes corresponding to the existing training dataset, resulting in low data validity for training the anomaly detection model and, in turn, low anomaly detection efficiency for multivariate time series data. Summary of the Invention
[0004] To this end, the present invention provides an industrial production data anomaly detection system to overcome the problem in the prior art that it fails to determine a targeted data extraction strategy based on the changes in the actual production status corresponding to the existing training data set, resulting in low effectiveness of the data used for anomaly detection model training, and further resulting in low efficiency of anomaly detection for multivariate time series data.
[0005] To achieve the above objectives, the present invention provides an industrial production data anomaly detection system, comprising:
[0006] The production monitoring module is used to detect production control difference parameters and set drift parameters, and determine the production data status of the time series training data set;
[0007] a window analysis module connected to the production monitoring module and configured to respond to window evaluation conditions to determine a window setting strategy for a time series training data set, which is a setting method for determining window extraction parameters for each multivariate time series data set based on a forward-looking production change degree or a drift trend change parameter, or to set window extraction parameters based on a reference cluster distribution index and a set abnormal distribution index;
[0008] an extraction execution module connected to the window analysis module, comprising a first extraction execution unit, a second extraction execution unit, and a third extraction execution unit, configured to perform training execution window extraction based on the window setting strategy determined by the window analysis module;
[0009] a training execution module connected to the extraction execution module, for training the anomaly analysis model based on each acquired training execution window;
[0010] An anomaly assessment module is connected to the training execution module and is used to reconstruct anomaly analysis on each window analysis data of the data to be evaluated to determine the weighted anomaly index of each window analysis data, and respond to the early warning assessment conditions to determine whether the data collected at the target analysis time corresponding to each window analysis data is anomaly detection data.
[0011] Furthermore, the production monitoring module determines the production control difference parameter of the time series training data set based on the operating load parameter of each target monitoring device within the time range corresponding to each multivariate time series data;
[0012] The production monitoring module determines a set drift parameter of a time series training data set based on a period drift index of each multivariate time series data.
[0013] Furthermore, if the window evaluation condition responded by the window analysis module is that the time series training data set is in a state of a type of production data, it is determined that the first extraction execution unit determines a setting method of the window extraction parameters of each multivariate time series data according to the forward-looking production change degree;
[0014] The one type of production data status is that the production control difference parameter of the time series training data set is greater than the preset production control difference parameter.
[0015] Furthermore, if the first execution condition responded by the first extraction execution unit is that the prospective production change degree of the multivariate time series data is greater than a preset prospective production change degree, the window range parameter of the multivariate time series data is determined based on the prospective production change degree and the production dominant coefficient;
[0016] The first execution condition of the response of the first extraction execution unit is that if the prospective production change degree of the multivariate time series data is less than or equal to the preset prospective production change degree, the window range parameter of the multivariate time series data is determined based on the production leading coefficient;
[0017] The first extraction execution unit determines an extraction sliding parameter based on a reference dominant anomaly distribution index, and the extraction sliding parameter is positively correlated with the reference dominant anomaly distribution index.
[0018] Furthermore, if the window evaluation condition responded by the window analysis module is that the time series training data set is in the second-class production data state, it is determined that the second extraction execution unit determines the setting mode of the window extraction parameters of each multivariate time series data according to the drift trend parameter;
[0019] The second type of production data status is that the production control difference parameter of the time series training data set is less than or equal to the preset production control difference parameter and the set drift parameter is greater than the preset set drift parameter.
[0020] Furthermore, the second execution condition responded by the second extraction execution unit is that a drift trend parameter of the multivariate time series data is greater than a preset drift trend parameter, and the window range parameter of the multivariate time series data is determined based on the periodic drift index and the drift trend parameter;
[0021] The second execution condition responded by the second extraction execution unit is that the drift trend parameter of the multivariate time series data is less than or equal to the preset drift trend parameter, and the window range parameter of the multivariate time series data is determined based on the drift trend parameter;
[0022] The second extraction execution unit determines an extraction sliding parameter based on the set drift parameter, and the extraction sliding parameter is negatively correlated with the set drift parameter.
[0023] Furthermore, if the window evaluation condition responded by the window analysis module is that the time series data training set is in the third-category production data state, it is determined that the third extraction execution unit sets the window extraction parameters according to the reference cluster distribution index and the set anomaly distribution index;
[0024] The window range parameter is positively correlated with the reference cluster distribution index of the time series data training set;
[0025] The extracted sliding parameter is positively correlated with the set anomaly distribution index of the time series data training set;
[0026] The three types of production data states are that the production control difference parameter of the time series training data set is less than or equal to the preset production control difference parameter and the set drift parameter is less than or equal to the preset set drift parameter.
[0027] Furthermore, the training execution module responds to the window collection conditions and performs training on the anomaly analysis model based on each training execution window, including:
[0028] For a single training execution window, compress and encode the data corresponding to the training execution window to obtain a representation vector for each training execution window;
[0029] Reconstruct the representation vector through each reconstruction branch to obtain the reconstructed multivariate time series corresponding to each reconstruction branch, determine the training loss parameter based on the joint loss function, and optimize the model parameters according to the training loss parameter;
[0030] The window acquisition condition is that the time series training data set completes the extraction of the training execution window.
[0031] Furthermore, the anomaly assessment module responds to the data assessment conditions, obtains window analysis data at each target analysis moment of the data to be assessed, and performs reconstruction anomaly analysis on each window analysis data, including:
[0032] Perform multivariate time series reconstruction on each window analysis data based on the trained anomaly analysis model to obtain a reconstructed multivariate time series, and determine the weighted anomaly index of the window analysis data corresponding to the reconstructed multivariate time series based on the anomaly difference score of each reconstructed multivariate time series;
[0033] The data evaluation condition is that there is data to be evaluated that requires abnormal weighted analysis.
[0034] Furthermore, if the warning evaluation condition responded by the anomaly evaluation module is that the weighted anomaly index of the window analysis data is greater than the preset weighted anomaly index, the data collected at the target analysis time corresponding to the window analysis data is determined to be anomaly detection data, and a data anomaly warning is issued;
[0035] The warning assessment condition responded by the abnormality assessment module is that the weighted abnormality index at the target analysis moment is less than or equal to the preset weighted abnormality index, then the data collected at the target analysis moment corresponding to the window analysis data is determined to be regular detection data.
[0036] Compared with the prior art, the beneficial effect of the present invention lies in that the technical solution of the present invention determines the production data status according to the production control difference parameters and the set drift parameters, and determines the window setting strategy according to the production data status of the time series training data set, thereby ensuring that the window extraction process for the time series training data set is more in line with the abnormal distribution characteristics in the actual data set, so that the data obtained for training the abnormal analysis model is effective, thereby ensuring the training effect of the abnormal analysis model. The present invention ensures the efficiency of anomaly detection for multivariate time series data.
[0037] Furthermore, the present invention determines the production data status based on the production control difference parameters and the set drift parameters, and characterizes the stability of the production process and the data drift degree corresponding to the time series training data set through the production control difference parameters and the set drift parameters. Targeted window setting strategies are selected for time series training data sets in different production data states to adapt to the dynamic characteristics of abnormal moments in the time series training data set, thereby improving the effectiveness of the data obtained for training the anomaly analysis model.
[0038] Furthermore, in the present invention, for a time series training data set in a type of production data state, the setting method of the window extraction parameters of each multivariate time series data is determined according to the forward-looking production change degree. There are changes in the production conditions corresponding to each multivariate time series data in this type of time series training data set. The degree of change in the production conditions of each multivariate time series data is determined by the forward-looking change degree. In the case of large changes in the production conditions, selecting a smaller window range parameter can better capture the change characteristics, avoiding the poor adaptability of the trained abnormal analysis model obtained by using a single window extraction parameter to turbulent working conditions.
[0039] Furthermore, in the present invention, for the time series training data set in the second-category production data state, the setting method of the window extraction parameters of each multivariate time series data is determined according to the drift trend change parameter, and whether it is in a more intense data drift stage is determined according to the difference in the periodic drift index between the forward-looking time series data, and the window range parameters are set according to the drift degree of the data within the time range, so that the extracted training execution window can better adapt to the changes in data distribution, thereby improving the effectiveness of the data obtained for training the anomaly analysis model.
[0040] Furthermore, in the present invention, for the time series training data set in the three types of production data states, the window range parameters and the extraction sliding parameters are set according to the reference cluster distribution index and the set anomaly distribution index. The degree of working condition change and data drift of such time series training data set are relatively weak. The window extraction parameters are set in a targeted manner according to the actual situation of the time series training data set, ensuring the coverage effect of the extracted training data while reducing the coverage of the training data to improve the training efficiency of the anomaly analysis model.
[0041] Furthermore, the present invention optimizes the parameters of the anomaly analysis model through a joint loss function, integrates the advantages of the prediction model and the reconstruction model, avoids the loss of meaningful information in the hidden layer due to focusing only on the top-level representation, and adds the representation vectors to the generation model and the prediction model respectively to participate in the reconstruction task and the prediction task, taking into account the potential features and time dependencies in the multivariate time series, so that the constructed anomaly analysis model has good accuracy and robustness, thereby improving the efficiency of anomaly detection for multivariate time series data. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 This is a module connection diagram of the industrial production data anomaly detection system of the present invention;
[0043] Figure 2 Extract the module structure diagram of the execution module of the present invention;
[0044] Figure 3 This is a flow chart of the production monitoring module of the present invention determining the production data status according to the production control difference parameter and the set drift parameter;
[0045] Figure 4 A flowchart of the window analysis module of the present invention responding to window evaluation conditions to determine a window setting strategy. DETAILED DESCRIPTION
[0046] In order to make the objects and advantages of the present invention more clearly understood, the present invention is further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0047] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.
[0048] It should be noted that, in the description of the present invention, terms such as "up", "down", "left", "right", "inside", and "outside" indicating directions or positional relationships are based on the directions or positional relationships shown in the accompanying drawings. This is only for the convenience of description and does not indicate or imply that the device or element must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it cannot be understood as a limitation on the present invention.
[0049] Furthermore, it should be noted that, in the description of the present invention, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood in a broad sense. For example, they may refer to fixed connections, detachable connections, or integral connections; mechanical connections or electrical connections; direct connections or indirect connections through an intermediate medium; and internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.
[0050] See also Figures 1 to 4 As shown, the present invention provides an industrial production data anomaly detection system, comprising:
[0051] The production monitoring module is used to detect production control difference parameters and set drift parameters, and determine the production data status of the time series training data set;
[0052] a window analysis module connected to the production monitoring module and configured to respond to window evaluation conditions to determine a window setting strategy for a time series training data set, which is a setting method for determining window extraction parameters for each multivariate time series data set based on a forward-looking production change degree or a drift trend change parameter, or to set window extraction parameters based on a reference cluster distribution index and a set abnormal distribution index;
[0053] an extraction execution module connected to the window analysis module, comprising a first extraction execution unit, a second extraction execution unit, and a third extraction execution unit, configured to set window extraction parameters based on the window setting strategy determined by the window analysis module to extract a training execution window, wherein the window extraction parameters include a window range parameter and an extraction sliding parameter;
[0054] a training execution module connected to the extraction execution module, for training the anomaly analysis model based on each acquired training execution window;
[0055] An anomaly assessment module is connected to the training execution module and is used to reconstruct anomaly analysis on each window analysis data of the data to be evaluated to determine the weighted anomaly index of each window analysis data, and respond to the early warning assessment conditions to determine whether the data collected at the target analysis time corresponding to each window analysis data is anomaly detection data.
[0056] The present invention is applied to anomaly detection of multivariate time series data acquired in a target monitoring area during an industrial production process. During the anomaly detection process, anomaly analysis is reconstructed on the data to be evaluated based on a trained anomaly analysis model. The target monitoring area is the industrial production area where anomaly detection is required for the multivariate time series data acquired during the production process. The multivariate time series data is sequence data composed of data acquired at different times by various sensors that monitor the operating conditions of production equipment within the target monitoring area. The production equipment whose operating conditions need to be detected is recorded as the target monitoring equipment. The present invention further improves the training effect of the anomaly analysis model by improving the effectiveness of the acquired training execution window, thereby improving the execution efficiency of the anomaly detection process for the multivariate time series data. The time series training data set of the present invention is the set of multivariate time series data for which the abnormality labels corresponding to each time in the target monitoring area have been determined in the anomaly detection record. The time with the abnormality label is the abnormal time. The abnormality label corresponding to each abnormal time contains the target monitoring equipment with the abnormality and the target monitoring equipment that caused the abnormality. The target monitoring equipment involved in the abnormality label is recorded as the associated equipment of the corresponding abnormal time. The present invention does not set the category of the operating data monitored by each target monitoring equipment and the sensor category.
[0057] The present invention uses several anomaly detection records, and any anomaly detection record records the production control difference parameters, collective drift parameters, forward-looking production change degree, production change degree, drift trend parameters and weighted anomaly index in the process of performing anomaly detection on the multivariate time series data obtained in the target monitoring area at least once, and each anomaly detection record corresponds to a qualified mark, which records whether the processing efficiency of the anomaly detection process for the multivariate time series data of the target monitoring area meets the user's requirements. It can be understood that the user can determine whether the processing efficiency of the anomaly detection process for the multivariate time series data of the target monitoring area meets the requirements based on self-set indicators. For example, the self-set indicators can be but are not limited to the anomaly warning quality index, and the anomaly warning quality index = 1 / the average value of the interval between the warning moment of each completed abnormal monitoring data and its corresponding collection moment.
[0058] Specifically, the production monitoring module determines the production control difference parameter of the time series training data set based on the operating load parameter of each target monitoring device within the time range corresponding to each multivariate time series data;
[0059] The production monitoring module determines a set drift parameter of a time series training data set based on a period drift index of each multivariate time series data.
[0060] Among them, when the production monitoring module determines the production data state of the time series training data set, it obtains the operating load parameters of each target monitoring device within the time range corresponding to each multivariate time series data in the time series training data set, and detects the production difference index of each target monitoring device. The production control difference parameter is the average value of the production difference index of each target monitoring device. For a single target monitoring device, the production difference value number k is the number of multivariate time series data contained in the time series training data set, si is the operating load parameter of the target monitoring device within the time range corresponding to the i-th multivariate time series data, s0 is the average value of the operating load parameter of the target monitoring device within the time range corresponding to each multivariate time series data, and for the time range corresponding to a single multivariate time series data, the operating load parameter is the maximum value of the operating power of the target monitoring device within the time range corresponding to the multivariate time series data;
[0061] The set drift parameter is the average value of the periodic drift index of each multivariate time series data in the time series training data set. For a single multivariate time series data, if there are two abnormal moments without any abnormal moment between them, the two abnormal moments are recorded as a group of adjacent abnormal moments, and the interval length between the abnormal moments in each group of adjacent abnormal moments is obtained and recorded as the abnormal interval parameter. The abnormal moment is the moment with an abnormal label. The periodic drift index = the maximum value of the serial interval difference reference value / the serial interval difference degree. For a single abnormal interval parameter, the serial interval difference reference value is the absolute value of the difference between the abnormal interval parameter and the average value of each abnormal interval parameter in the multivariate time series data. The serial interval difference degree is the average value of each serial interval difference reference value.
[0062] The production data state includes a first-class production data state, a second-class production data state, and a third-class production data state. If the production control difference parameter of the time series training data set is greater than the preset production control difference parameter, the time series training data set is determined to be in the first-class production data state. If the production control difference parameter of the time series training data set is less than or equal to the preset production control difference parameter and the set drift parameter is greater than the preset set drift parameter, the time series training data set is determined to be in the second-class production data state. If the production control difference parameter of the time series training data set is less than or equal to the preset production control difference parameter and the set drift parameter is less than or equal to the preset set drift parameter, the time series training data set is determined to be in the third-class production data state.
[0063] The values of the preset production control difference parameter and the preset set drift parameter can be determined by the user according to the actual working scenario. For example, the user can set them according to the anomaly detection record. The higher the user's requirements for the processing efficiency of the anomaly detection process of the multivariate time series data of the target monitoring area, the smaller the value of the preset production control difference parameter and the smaller the value of the preset set drift parameter. A method for determining the value of the preset production control difference parameter is provided, and the maximum value of the production control difference parameter of the time series training data set in the three types of production data states in the anomaly detection record that meets the user's requirements for the processing efficiency of the anomaly detection process of the multivariate time series data of the target monitoring area is recorded as the preset production control difference parameter. A method for determining the value of the preset set drift parameter is provided, and the maximum value of the set drift parameter of the time series training data set in the three types of production data states in the anomaly detection record that meets the user's requirements for the processing efficiency of the anomaly detection process of the multivariate time series data of the target monitoring area is recorded as the preset set drift parameter.
[0064] Specifically, if the window evaluation condition responded by the window analysis module is that the time series training data set is in a class of production data state, it is determined that the first extraction execution unit determines the setting method of the window extraction parameters of each multivariate time series data according to the forward-looking production change degree;
[0065] The one type of production data status is that the production control difference parameter of the time series training data set is greater than the preset production control difference parameter.
[0066] Specifically, the first execution condition responded by the first extraction execution unit is that if the prospective production change degree of the multivariate time series data is greater than the preset prospective production change degree, the window range parameter of the multivariate time series data is determined based on the prospective production change degree and the production dominant coefficient;
[0067] The first execution condition of the response of the first extraction execution unit is that if the prospective production change degree of the multivariate time series data is less than or equal to the preset prospective production change degree, the window range parameter of the multivariate time series data is determined based on the production leading coefficient;
[0068] The first extraction execution unit determines an extraction sliding parameter based on a reference dominant anomaly distribution index, and the extraction sliding parameter is positively correlated with the reference dominant anomaly distribution index.
[0069] Wherein, for a single multivariate time series data, the forward-looking production change degree is the average of the forward-looking change degrees of each target monitoring device. For a single target monitoring device, the forward-looking change degree = |the operating load parameter of the target monitoring device within the time range corresponding to the multivariate time series data - the operating load parameter of the target monitoring device within the time range corresponding to the forward-looking time series data of the multivariate time series data | / the operating load parameter of the target monitoring device within the time range corresponding to the forward-looking time series data of the multivariate time series data. The forward-looking time series data is the multivariate time series data with the shortest interval between the earliest moment in the time series training data set and the multivariate time series data;
[0070] The value of the preset forward-looking production change degree can be determined by the user according to the actual working scenario. For example, the user can set it according to the anomaly detection record. The higher the user's requirement for the processing efficiency of the anomaly detection process of the multivariate time series data of the target monitoring area, the smaller the value of the preset forward-looking production change degree. A method for transplanting the value of the preset forward-looking production change degree is provided. The anomaly detection record for determining the window range parameter of the multivariate time series data based on the forward-looking production change degree and the production dominant coefficient is recorded as a forward-looking reference record. The minimum value of the forward-looking production change degree of the multivariate time series data in the forward-looking reference record that meets the user's requirement for the processing efficiency of the anomaly detection process of the multivariate time series data of the target monitoring area is recorded as the preset forward-looking production change degree.
[0071] For a single multivariate time series data, if the prospective production change degree is greater than the preset prospective production change degree, the window range parameter of the multivariate time series data is negatively correlated with the sequence dominant coefficient, and the sequence dominant coefficient = prospective production change degree / production dominant coefficient. If the prospective production change degree is greater than the preset prospective production change degree, the window range parameter of the multivariate time series data is positively correlated with the production dominant coefficient, and the production dominant coefficient = the number of associated time series data of the multivariate time series data in the time series training data set / the number of the multivariate time series data in the time series training data set. The associated time series data is the multivariate time series data whose production change degree with the multivariate time series data is less than the preset production change degree. For any two multivariate time series data, the production change degree is the average value of the production change degree of each target monitoring equipment. For a single target monitoring equipment, the production change Degree = absolute value of the difference between the operating load parameters of the target monitoring device within the time range corresponding to the two multivariate time series data / average value of the operating load parameters of the target monitoring device within the time range corresponding to the two multivariate time series data. The set of the multivariate time series data and its associated time series data is recorded as the dominant set of the multivariate time series data. If there are two abnormal moments in the dominant set and there is no abnormal moment in the dominant set, the two abnormal moments are recorded as a group of adjacent dominant analysis moments. The interval length between the two abnormal moments in each group of adjacent dominant analysis moments is detected. The reference dominant abnormal distribution index is the average value of the interval length between the two abnormal moments in each group of adjacent dominant analysis moments in the dominant set. The window range parameter is the duration corresponding to the obtained training execution window. The extracted sliding parameter is the sliding step size when performing the training execution window.
[0072] The value of the preset production change degree can be determined by the user according to the actual working scenario. For example, the user can set it according to the anomaly detection record. The higher the user's requirement for the processing efficiency of the anomaly detection process of the multivariate time series data of the target monitoring area, the larger the value of the preset production change degree. A method for determining the value of the preset production change degree is provided, and the maximum value of the production change degree of each associated time series in the anomaly detection record that meets the user's requirement for the processing efficiency of the anomaly detection process of the multivariate time series data of the target monitoring area is recorded as the preset production change degree.
[0073] Specifically, if the window evaluation condition responded by the window analysis module is that the time series training data set is in the second-class production data state, it is determined that the second extraction execution unit determines the setting mode of the window extraction parameters of each multivariate time series data according to the drift trend parameter;
[0074] The second type of production data status is that the production control difference parameter of the time series training data set is less than or equal to the preset production control difference parameter and the set drift parameter is greater than the preset set drift parameter.
[0075] Specifically, the second execution condition responded by the second extraction execution unit is that the drift trend parameter of the multivariate time series data is greater than the preset drift trend parameter, and the window range parameter of the multivariate time series data is determined based on the periodic drift index and the drift trend parameter;
[0076] The second execution condition responded by the second extraction execution unit is that the drift trend parameter of the multivariate time series data is less than or equal to the preset drift trend parameter, and the window range parameter of the multivariate time series data is determined based on the drift trend parameter;
[0077] The second extraction execution unit determines an extraction sliding parameter based on the set drift parameter, and the extraction sliding parameter is negatively correlated with the set drift parameter.
[0078] Among them, for a single multivariate time series data, the drift trend parameter = |the periodic drift index of the multivariate time series data-the periodic drift index of the prospective time series data of the multivariate time series data| / the periodic drift index of the prospective time series data of the multivariate time series data. The value of the preset drift trend parameter can be determined by the user according to the actual working scenario. For example, the user can set it according to the anomaly detection record. The higher the user's requirement for the processing efficiency of the anomaly detection process of the multivariate time series data of the target monitoring area, the smaller the value of the preset drift trend parameter. A method for determining the value of the preset drift trend parameter is provided. The anomaly detection record for determining the window range parameter of the multivariate time series data based on the periodic drift index and the drift trend parameter is recorded as a drift reference record. The minimum value of the drift trend parameter in the drift reference record that meets the user's requirement for the processing efficiency of the anomaly detection process of the multivariate time series data of the target monitoring area is recorded as the preset drift trend parameter.
[0079] For a single multivariate time series data, when the drift trend parameter is greater than the preset drift trend parameter, the window range parameter of the multivariate time series data is negatively correlated with the drift evaluation coefficient, and the drift evaluation coefficient is the sum of the multivariate time series data and the drift trend parameter. When the drift trend parameter is less than or equal to the preset drift trend parameter, the window range parameter of the multivariate time series data is positively correlated with the drift trend parameter.
[0080] Specifically, if the window evaluation condition responded by the window analysis module is that the time series data training set is in the three-category production data state, it is determined that the third extraction execution unit sets the window extraction parameters according to the reference cluster distribution index and the set anomaly distribution index;
[0081] The window range parameter is positively correlated with the reference cluster distribution index of the time series data training set;
[0082] The extracted sliding parameter is positively correlated with the set anomaly distribution index of the time series data training set;
[0083] The three types of production data states are that the production control difference parameter of the time series training data set is less than or equal to the preset production control difference parameter and the set drift parameter is less than or equal to the preset set drift parameter.
[0084] Among them, when the time series data training set is in the three-category production data state, the window extraction parameters are set according to the cluster distribution index and the set abnormal distribution index to obtain the abnormal moments contained in each multivariate time series data in the time series data training set, and the cluster abnormality set is determined according to the abnormal label corresponding to each abnormal moment. The cluster abnormality set is a set of several abnormal moments. The associated devices corresponding to each abnormal moment in any cluster abnormality set are the same. For a single cluster abnormality set, if there are two abnormal moments in the cluster abnormality set and there is no abnormal moment in the cluster abnormality set, the above two abnormal moments are recorded as a group of adjacent cluster abnormalities. Class moment, the interval length between two abnormal moments in each group of adjacent cluster moments is detected, the cluster distribution index is the average value of the interval length between two abnormal moments in each group of adjacent cluster moments in the cluster abnormal set, the reference cluster distribution index is the average value of the cluster distribution index of each cluster abnormal set in the time series data training set, if there is no abnormal moment between two abnormal moments in the time series data training set, then the above two abnormal moments are recorded as a group of adjacent abnormal moments, and the set abnormal distribution index is the average value of the interval length between two abnormal moments in each group of adjacent abnormal moments in the time series data training set.
[0085] Specifically, the training execution module responds to the window collection conditions and trains the anomaly analysis model based on each training execution window, including:
[0086] For a single training execution window, compress and encode the data corresponding to the training execution window to obtain a representation vector for each training execution window;
[0087] Reconstruct the representation vector through each reconstruction branch to obtain the reconstructed multivariate time series corresponding to each reconstruction branch, determine the training loss parameter based on the joint loss function, and optimize the model parameters according to the training loss parameter;
[0088] The window acquisition condition is that the time series training data set completes the extraction of the training execution window.
[0089] Among them, the present invention uses the sparse encoder in the sparse autoencoder to compress and encode the data corresponding to each training execution window, and records the output result after compression encoding as the representation vector of the corresponding training execution window. The reconstruction branch in the present invention includes the first reconstruction branch, the second reconstruction branch and the third reconstruction branch. For a single training execution window W t , the data vector at the last moment it contains is recorded as x t , the representation vector is recorded as z t , the representation vector z t As the input of the first reconstruction branch, the second reconstruction branch and the third reconstruction branch respectively, to perform the reconstruction operation, the output of the first reconstruction branch, the second reconstruction branch and the third reconstruction branch are respectively recorded as the first training reconstruction multivariate time series The second training reconstructs the multivariate time series And the third training reconstructs the multivariate time series
[0090] The structure of the sparse encoder in the sparse autoencoder includes Layer0 and Layer1. Layer0 and Layer1 are composed of linear layers, BN layers and Sigmoid nonlinear activation layers. The input dimensions and output dimensions of all linear layers are set equal. The sparse encoder is used for the time window W. t The data in the output time window W is compressed and encoded. t The representation vector z of the m variables (i.e., the data obtained by each sensor) changing over time t The specific process is expressed as L0 = Sigmoid (BN (Linear (x t ))), z t =L1=Sigmoid(BN(Linear(L0))), where Linear represents a linear layer with equal input and output dimensions, BN represents batch normalization, Sigmoid represents the Sigmoid nonlinear activation function, and L0 and L1 represent potential vectors;
[0091] The first reconstruction branch uses the sparse decoder of the sparse autoencoder to represent the vector z t Reconstruct and obtain the first training reconstructed multivariate time series The specific structure of the sparse decoder includes Layer2 and Layer3. Layer2 and Layer3 are composed of linear layers, BN layers, and Sigmoid nonlinear activation layers. The input dimensions and output dimensions of all linear layers in Layer2 and Layer3 are set to the same. The first reconstruction branch obtains the first training reconstructed multivariate time series. The specific processing process is expressed as L2=Sigmoid(BN(Linear(z t))), L2 and L3 represent latent vectors;
[0092] The second reconstruction branch is a variational autoencoder, which transforms the representation vector z into t Compressed into a low-dimensional normal representation Then, the second training reconstructed multivariate time series is obtained by reconstruction It includes a variational encoder and a variational decoder, wherein the structure of the variational encoder includes Layer 4 and Layer 5; Layer 4 and Layer 5 are composed of a linear layer (Linear), a BN layer and a Sigmoid nonlinear activation layer, and the output dimension of the linear layer in Layer 5 is smaller than that of Layer 4; the structure of the variational decoder includes Layer 6 and Layer 7, and Layer 6 and Layer 7 are composed of a linear layer (Linear), a BN layer and a Sigmoid nonlinear activation layer, and the output dimension of the linear layer in Layer 7 is larger than that of Layer 6, and the second reconstruction branch obtains a second training reconstructed multivariate time series The specific process is expressed by the formula L4 = Sigmoid (BN (Linear (z t ))),
[0093] The third reconstruction branch is a prediction model that converts the representation vector z output by the sparse encoder into t Input to the prediction model to predict the next moment x at the right boundary of the time window t+1 , obtain the third training reconstruction multivariate time series The prediction model consists of a multi-layer perceptron, a BN layer, and a ReLU nonlinear activation layer. The third reconstruction branch obtains the third training reconstructed multivariate time series. The specific process is expressed by the formula ReLU represents a nonlinear activation function;
[0094] The joint loss function Loss = λ1L a +λ2L b +(1-λ1-λ2)L c, by minimizing the joint loss function, the model parameters of the anomaly analysis model are optimized. How to optimize the model parameters is a content that those skilled in the art have already mastered and will not be elaborated on here. λ1 and λ2 are the weight coefficients of the first reconstruction branch and the weight coefficient of the second reconstruction branch, respectively, which are used to balance the importance of the first reconstruction branch, the second reconstruction branch, and the third reconstruction branch. The user can set the weight coefficients of the first reconstruction branch and the second reconstruction branch according to actual needs. How to set the weight coefficients of each reconstruction branch is a content that those skilled in the art have already mastered and will not be elaborated on here. A value of the weight coefficient of the first reconstruction branch and the weight coefficient of the second reconstruction branch is provided. The weight coefficient of the first reconstruction branch is 0.3, and the weight coefficient of the second reconstruction branch is 0.4.
[0095] L a is the loss function of the first reconstruction branch, Represents x t and The mean square error, KL represents the KL divergence, β represents the weight of the KL divergence, ρ is the preset sparsity target, which represents the expected average activation probability of neurons. is the actual average activation probability of the l-th layer neurons, L represents the dimension of the hidden layer setting of the sparse encoder, Represents x t and The maximum mean difference error, L b is the loss function of the second reconstruction branch, θ and φ represent the parameters of the variational encoder and variational decoder respectively, Calculate z t and The negative log-likelihood between the two is to reduce the z t The reconstruction error of By minimizing the representation vector z t The KL divergence between the approximate posterior and prior values of the regularized normal representation L c is the loss function of the third reconstruction branch, Represents x t and The root mean square error.
[0096] Specifically, the anomaly assessment module responds to the data assessment conditions, obtains the window analysis data of each target analysis moment of the data to be assessed, and performs reconstruction anomaly analysis on each window analysis data, including:
[0097] Perform multivariate time series reconstruction on each window analysis data based on the trained anomaly analysis model to obtain a reconstructed multivariate time series, and determine the weighted anomaly index of the window analysis data corresponding to the reconstructed multivariate time series based on the anomaly difference score of each reconstructed multivariate time series;
[0098] The data evaluation condition is that there is data to be evaluated that requires abnormal weighted analysis.
[0099] The data to be evaluated are all multivariate time series data obtained by monitoring each target monitoring device in the target monitoring area, and the target analysis time is the time when the operation data of each target monitoring device is collected. The data to be evaluated can be defined as X = {x1, x2, ..., x t ,…x n}, xt is the data vector at the t-th target analysis moment. The data vector corresponding to each target analysis moment is an m-dimensional vector, m is the number of sensors for running data collection. For a single target analysis moment, the window analysis data is a set of vectors containing the preset number of moments. For example, for xt, its window analysis data W t ={x t-a+1 ,x t-a ,…,x t}, a is the number of target analysis moments included in the window analysis data. The value of the preset number of moments can be determined by the user according to the actual working scenario. This is easy to understand for those skilled in the art and will not be elaborated here;
[0100] For the window analysis data corresponding to a single target analysis moment, the process of reconstructing the anomaly analysis includes: taking the window analysis data of the target analysis moment as the input of the trained anomaly detection model, performing multivariate time series reconstruction on the window analysis data according to each reconstruction branch, recording the outputs of the first reconstruction branch, the second reconstruction branch and the third reconstruction branch as the first reconstructed multivariate time series, the second reconstructed multivariate time series and the third reconstructed multivariate time series respectively, subtracting the first reconstructed multivariate time series, the second reconstructed multivariate time series and the third reconstructed multivariate time series from the data vector corresponding to the target analysis moment respectively, recording the obtained differences as the first anomaly difference score, the second anomaly difference score and the third anomaly difference score respectively, and the weighted anomaly index of the window analysis data at the target analysis moment A1, A2 and A3 are respectively the first abnormal difference score, the second abnormal difference score and the third abnormal difference score. How to determine the first abnormal difference score, the second abnormal difference score and the third abnormal difference score is already known to those skilled in the art and will not be elaborated here.
[0101] Specifically, the warning assessment condition responded by the anomaly assessment module is that if the weighted anomaly index of the window analysis data is greater than the preset weighted anomaly index, the data collected at the target analysis time corresponding to the window analysis data is determined to be anomaly detection data, and a data anomaly warning is issued;
[0102] The warning assessment condition responded by the abnormality assessment module is that the weighted abnormality index at the target analysis moment is less than or equal to the preset weighted abnormality index, then the data collected at the target analysis moment corresponding to the window analysis data is determined to be regular detection data.
[0103] Among them, the value of the preset weighted anomaly index can be determined by the user according to the actual working scenario. For example, the user can set it according to the anomaly detection record. The higher the user's requirement for the processing efficiency of the anomaly detection process of the multivariate time series data of the target monitoring area, the smaller the value of the preset weighted anomaly index. A method for determining the value of the preset weighted anomaly index is provided, and the anomaly detection record for data anomaly warning is recorded as a warning reference record. The average value of the weighted anomaly index of each window analysis data in the warning reference record that meets the user's requirement for the processing efficiency of the anomaly detection process of the multivariate time series data of the target monitoring area is recorded as the preset weighted anomaly index.
[0104] Thus far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art may make equivalent changes or substitutions to the relevant technical features, and the technical solutions after such changes or substitutions will fall within the scope of protection of the present invention.
[0105] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that the present invention is susceptible to various modifications and variations. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.
Claims
1. An industrial production data anomaly detection system, characterized in that: include: The production monitoring module is used to detect production control difference parameters and set drift parameters, and determine the production data status of the time series training data set; a window analysis module connected to the production monitoring module and configured to respond to window evaluation conditions to determine a window setting strategy for a time series training data set, which is a setting method for determining window extraction parameters for each multivariate time series data set based on a forward-looking production change degree or a drift trend change parameter, or to set window extraction parameters based on a reference cluster distribution index and a set abnormal distribution index; an extraction execution module connected to the window analysis module, comprising a first extraction execution unit, a second extraction execution unit, and a third extraction execution unit, configured to set window extraction parameters based on the window setting strategy determined by the window analysis module to extract a training execution window, wherein the window extraction parameters include a window range parameter and an extraction sliding parameter; a training execution module connected to the extraction execution module, for training the anomaly analysis model based on each acquired training execution window; An anomaly assessment module is connected to the training execution module and is used to reconstruct anomaly analysis on each window analysis data of the data to be evaluated to determine the weighted anomaly index of each window analysis data, and respond to the early warning assessment conditions to determine whether the data collected at the target analysis time corresponding to each window analysis data is anomaly detection data.
2. The industrial production data anomaly detection system according to claim 1, characterized in that: The production monitoring module determines the production control difference parameter of the time series training data set based on the operating load parameter of each target monitoring device within the time range corresponding to each multivariate time series data; The production monitoring module determines a set drift parameter of a time series training data set based on a period drift index of each multivariate time series data.
3. The industrial production data anomaly detection system according to claim 2, characterized in that: If the window evaluation condition responded by the window analysis module is that the time series training data set is in a first-class production data state, it is determined that the first extraction execution unit determines the setting method of the window extraction parameters of each multivariate time series data according to the forward-looking production change degree; The one type of production data status is that the production control difference parameter of the time series training data set is greater than the preset production control difference parameter.
4. The industrial production data anomaly detection system according to claim 3, characterized in that: The first execution condition responded by the first extraction execution unit is that the prospective production change degree of the multivariate time series data is greater than the preset prospective production change degree, and the window range parameter of the multivariate time series data is determined based on the prospective production change degree and the production leading coefficient; The first execution condition of the response of the first extraction execution unit is that if the prospective production change degree of the multivariate time series data is less than or equal to the preset prospective production change degree, the window range parameter of the multivariate time series data is determined based on the production leading coefficient; The first extraction execution unit determines an extraction sliding parameter based on a reference dominant anomaly distribution index, and the extraction sliding parameter is positively correlated with the reference dominant anomaly distribution index.
5. The industrial production data anomaly detection system according to claim 4, characterized in that: If the window evaluation condition responded by the window analysis module is that the time series training data set is in the second-class production data state, it is determined that the second extraction execution unit determines the setting mode of the window extraction parameters of each multivariate time series data according to the drift trend parameter; The second type of production data status is that the production control difference parameter of the time series training data set is less than or equal to the preset production control difference parameter and the set drift parameter is greater than the preset set drift parameter.
6. The industrial production data anomaly detection system according to claim 5, characterized in that: The second execution condition responded by the second extraction execution unit is that a drift trend parameter of the multivariate time series data is greater than a preset drift trend parameter, and the window range parameter of the multivariate time series data is determined based on the periodic drift index and the drift trend parameter; The second execution condition responded by the second extraction execution unit is that the drift trend parameter of the multivariate time series data is less than or equal to the preset drift trend parameter, and the window range parameter of the multivariate time series data is determined based on the drift trend parameter; The second extraction execution unit determines an extraction sliding parameter based on the set drift parameter, and the extraction sliding parameter is negatively correlated with the set drift parameter.
7. The industrial production data anomaly detection system according to claim 6, characterized in that: If the window evaluation condition responded by the window analysis module is that the time series data training set is in the third-category production data state, it is determined that the third extraction execution unit sets the window extraction parameters according to the reference cluster distribution index and the set anomaly distribution index; The window range parameter is positively correlated with the reference cluster distribution index of the time series data training set; The extracted sliding parameter is positively correlated with the set anomaly distribution index of the time series data training set; The three types of production data states are that the production control difference parameter of the time series training data set is less than or equal to the preset production control difference parameter and the set drift parameter is less than or equal to the preset set drift parameter.
8. The industrial production data anomaly detection system according to claim 7, characterized in that: The training execution module responds to the window collection conditions and trains the anomaly analysis model based on each training execution window, including: For a single training execution window, compress and encode the data corresponding to the training execution window to obtain a representation vector for each training execution window; Reconstruct the representation vector through each reconstruction branch to obtain the reconstructed multivariate time series corresponding to each reconstruction branch, determine the training loss parameter based on the joint loss function, and optimize the model parameters according to the training loss parameter; The window acquisition condition is that the time series training data set completes the extraction of the training execution window.
9. The industrial production data anomaly detection system according to claim 1, characterized in that: The anomaly assessment module responds to the data assessment conditions, obtains the window analysis data of each target analysis time of the data to be assessed, and performs reconstruction anomaly analysis on each window analysis data, including: Perform multivariate time series reconstruction on each window analysis data based on the trained anomaly analysis model to obtain a reconstructed multivariate time series, and determine the weighted anomaly index of the window analysis data corresponding to the reconstructed multivariate time series based on the anomaly difference score of each reconstructed multivariate time series; The data evaluation condition is that there is data to be evaluated that requires abnormal weighted analysis.
10. The industrial production data anomaly detection system according to claim 9, characterized in that: The warning assessment condition responded by the anomaly assessment module is that the weighted anomaly index of the window analysis data is greater than the preset weighted anomaly index, then the data collected at the target analysis time corresponding to the window analysis data is determined to be anomaly detection data, and a data anomaly warning is issued; The warning assessment condition responded by the abnormality assessment module is that the weighted abnormality index at the target analysis moment is less than or equal to the preset weighted abnormality index, then the data collected at the target analysis moment corresponding to the window analysis data is determined to be regular detection data.
Citation Information
Patent Citations
Industrial internet time series data anomaly detection method and system
CN118898045A
Cited By
Process execution anomaly detection method based on data driving
CN121009317A
A data-driven process execution anomaly detection method
CN121009317B
Production anomaly prediction method and system based on large model and MES system
CN121543834A