Intelligent abnormity early warning system and method for edge node of industrial Internet of Things
By deploying multimodal sensors and quantum encryption at the edge nodes of the Industrial Internet of Things (IIoT), and combining dynamic spatiotemporal graph neural networks and digital twin threshold engines, the latency and security issues of existing systems are solved, achieving real-time, adaptive anomaly warning and quantum anti-attack capabilities.
Patent Information
- Application Number
- CN202511085530.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-04
- Publication Date
- 2025-11-14
AI Technical Summary
Existing industrial IoT edge node anomaly early warning systems rely on centralized cloud processing, resulting in delayed anomaly detection and difficulty in real-time response. They also lack dynamic adaptability and quantum-level encryption protection, making them vulnerable to attacks.
By employing a multimodal sensor array and quantum encryption preprocessing in the edge perception layer, a dynamic spatiotemporal graph neural network and a digital twin threshold engine in the edge intelligence layer, and cross-level federated learning in the cloud-edge collaboration layer, lightweight real-time analysis and quantum-resistant attack protection are achieved.
It enables real-time anomaly detection and adaptive early warning for edge nodes, dynamically adapts to changes in equipment operating conditions, resists quantum computing attacks, and improves system security and response speed.
Smart Images

Figure CN120949648A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial Internet of Things (IoT) technology, and specifically to an intelligent anomaly early warning system and method for industrial IoT edge nodes. Background Technology
[0002] Current industrial IoT edge node anomaly early warning systems generally suffer from the following shortcomings: Traditional systems rely on centralized cloud data processing, resulting in weak intelligent analysis capabilities at the edge, leading to significant anomaly detection delays (often reaching minutes), making it difficult to meet real-time control requirements. Most systems use fixed thresholds or simple statistical models, failing to dynamically adapt to changes in equipment operating conditions (such as load fluctuations and environmental interference). Data lacks quantum-level encryption protection during transmission and edge computing, making it vulnerable to future quantum computing attacks, and model parameters and intermediate data are susceptible to leakage. Summary of the Invention
[0003] To address these issues, the present invention provides an intelligent anomaly early warning system and method for industrial Internet of Things (IoT) edge nodes, thereby resolving the problems in the prior art.
[0004] To achieve the above objectives, the present invention provides the following technical solution:
[0005] An intelligent anomaly early warning system for industrial IoT edge nodes includes an edge sensing layer, an edge intelligence layer, and a cloud-edge collaboration layer.
[0006] The edge sensing layer is used for data acquisition and secure preprocessing; data is acquired through a multimodal sensor array installed on factory production lines or equipment; and the data is encrypted and preprocessed through a quantum encryption preprocessing module.
[0007] The edge intelligence layer is used to intelligently analyze the data transmitted by the edge perception layer, construct a dynamic spatiotemporal graph neural network model and a dynamic edge knowledge graph; and set up a digital twin threshold engine. When the digital twin threshold engine detects an anomaly, it performs reverse reasoning along the knowledge graph and provides adaptive early warning.
[0008] The cloud-edge collaboration layer is used to collaboratively process the early warnings triggered by the digital twin threshold engine. The edge performs initial processing, while the cloud performs global optimization, generates optimization decisions, and simultaneously completes the iterative update of the dynamic spatiotemporal graph neural network model.
[0009] Furthermore, the quantum encryption preprocessing module performs real-time chaotic encryption on the raw data stream at the data acquisition end and supports the national cryptographic algorithm SM4.
[0010] Furthermore, the edge intelligence layer deploys a lightweight graph neural network on the edge nodes. In this embodiment, a dynamic spatiotemporal graph neural network model is adopted to capture the spatial topological relationship and temporal dynamic features of the device group, supporting joint learning of temporal-spatial features.
[0011] Furthermore: In the aforementioned dynamic spatiotemporal graph neural network model, it is necessary to calculate the spatial adjacency matrix Aij. First, the Euclidean distance between nodes is calculated. For any two nodes i and j, their spatial coordinate vector x is calculated. i and x j Euclidean distance: d ij =||x i -x j ||;
[0012] The formula for calculating the spatial association weight between node i and node j is:
[0013]
[0014] Where σ is the kernel width hyperparameter, which controls the decay rate of spatial correlation;
[0015] The spatial adjacency matrix A is obtained by calculating all node pairs (i, j) using formula (1). 空间 .
[0016] Furthermore: the spatiotemporal diagram is extended by calculating the spatiotemporal correlation matrix, the formula of which is:
[0017]
[0018] Among them, A 时空 (t) is the spatiotemporal correlation matrix at time t; A 空间 A is a spatial adjacency matrix; 时 The order is the temporal correlation matrix; The Kronecker product is used to fuse spatial and temporal dependencies; I(t) is the identity matrix, representing the autocorrelation at the current time step.
[0019] Then the graph convolutional layer (GCN) is calculated, and its calculation formula is as follows:
[0020]
[0021] Among them, H (l) Let N be the input feature matrix of the l-th layer, with dimensions N×d, where N is the number of nodes and d is the feature dimension. Let I be the spatiotemporal correlation matrix of the self-loop, and let I be the identity matrix; Let be a degree matrix, satisfying W (l)Let be the trainable weight matrix of the l-th layer, with dimension d×F, where F is the output feature dimension; σ is the non-linear activation function.
[0022] After capturing temporal features, the formula for calculating dynamic temporal convolution is:
[0023]
[0024] Among them, T (l) (t) represents the l-th layer temporal feature at time t; Conv1D represents a one-dimensional convolution operation with a kernel size of k; ω(t): time decay factor;
[0025] The formula for calculating feature aggregation after cross-layer fusion is:
[0026]
[0027] Where Z(t) is the aggregated spatiotemporal feature vector with dimension N×C, where C is the number of channels; Aggregate is the feature fusion function such as attention weighting or pooling operation.
[0028] Furthermore: The formula for calculating the anomaly score is as follows:
[0029] S(t) = f score (Z(t); θ) = Softmax(W) s Z(t)+b s (6);
[0030] Where S(t) represents the abnormal rating vector; W s b s These represent the weights and biases of the scoring layer; fscore is the scoring function.
[0031] The formula for calculating the adaptive threshold is:
[0032] δ(t)=μ h +k·σ h (7);
[0033] Where δ(t) is the dynamic threshold for time t; μh is the historical mean score; σh is the historical standard deviation score; and k is the confidence coefficient.
[0034] The abnormality determination criteria are:
[0035]
[0036] Anomaly(t) is the anomaly label, where 1 indicates an anomaly and 0 indicates normal.
[0037] Furthermore, a dynamic edge knowledge graph is constructed at the edge nodes. The dynamic edge knowledge graph consists of a three-layer knowledge representation structure: a physical layer representing the relationships between device entities, a fault layer representing the historical fault propagation path, and an environmental layer representing external influencing factors such as temperature and humidity. The dynamic edge knowledge graph can be updated autonomously at the edge through an incremental graph learning algorithm without the need for cloud transmission.
[0038] Furthermore: A 3D digital twin model of the device is established by setting up a digital twin threshold engine at the edge nodes; the digital twin threshold engine generates dynamic thresholds based on physical simulation;
[0039] In addition, lightweight quantum encryption is applied to edge nodes to prevent quantum attack and to protect the parameters and intermediate data of the dynamic spatiotemporal graph neural network model.
[0040] Furthermore: The cloud-edge collaboration layer adopts cross-level federated learning, that is, at the edge layer, edge nodes exchange gradients of dynamic spatiotemporal graph neural network models and update the local dynamic spatiotemporal graph neural network model every 5-20 minutes; in the cloud, multi-domain knowledge graphs are aggregated to generate a global supernet model; the cloud uses GPUs to accelerate the training of dynamic spatiotemporal graph neural network models to improve the accuracy of dynamic spatiotemporal graph neural network models; at the same time, the cloud and edge layers collaboratively maintain decision-making.
[0041] This invention also provides a method for intelligent anomaly early warning of industrial IoT edge nodes, comprising the following steps:
[0042] Step 1: Multimodal data acquisition and quantum encryption preprocessing; Deploy multimodal sensor arrays on factory production lines and key equipment to acquire multi-dimensional industrial data in real time; Use the quantum encryption preprocessing module at the edge node to encrypt the raw data stream in real time using a chaotic encryption algorithm; Generate encrypted data packets;
[0043] Step 2: Dynamic modeling and knowledge graph construction of the edge intelligence layer; deploy a lightweight dynamic spatiotemporal graph neural network model on the edge nodes to receive and analyze the data in the encrypted data packets; capture the spatial topological relationship and time series dynamic features of the device group through spatiotemporal feature joint learning; and simultaneously construct a three-layer dynamic edge knowledge graph.
[0044] Step 3: Digital Twin Threshold Engine Anomaly Detection and Inference; Establish a 3D digital twin model of the device and generate a dynamic threshold benchmark through physical simulation; When real-time monitoring data exceeds the threshold, trigger the knowledge graph reverse inference mechanism; Locate potential fault sources along the fault layer propagation path and correct the inference results by combining environmental layer variables; Generate early warning information including device ID, anomaly type, and confidence level; Simultaneously start lightweight quantum encryption at the edge to protect model parameters and intermediate calculation data;
[0045] Step 4: Cloud-edge collaborative early warning and model optimization; edge nodes activate preset emergency strategies; generate local handling logs; the cloud receives the early warning and performs global optimization;
[0046] Step 5: System Iteration and Adaptive Learning; The cloud distributes the optimized global model parameters to the edge nodes, and synchronously updates the simulation parameters of the digital twin threshold engine; The edge nodes continuously optimize the knowledge graph reasoning rules based on the newly added running data, forming a closed-loop adaptive learning system of "perception-analysis-decision-optimization";
[0047] Step 6: Enhance quantum security; implement quantum-resistant protection throughout the entire data lifecycle.
[0048] This invention has the following advantages: It employs a dynamic spatiotemporal graph neural network to jointly learn the spatiotemporal features of a device cluster; the digital twin threshold engine generates dynamic thresholds based on physical simulation, adapting to environmental and load changes; lightweight real-time analysis is achieved at the edge layer; and the embedded chaotic encryption + national standard SM4 algorithm, combined with quantum random number generation and lattice-based encryption, effectively resists quantum attacks.
[0049] Other features and advantages of the invention will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. Attached Figure Description
[0050] To more intuitively illustrate the prior art and this application, exemplary drawings are provided below. It should be understood that the specific shapes and structures shown in the drawings should not generally be regarded as limiting conditions for implementing this application; for example, based on the technical concept disclosed in this application and the exemplary drawings, those skilled in the art are able to easily make conventional adjustments or further optimizations to the addition / reduction / classification, specific shapes, positional relationships, connection methods, size ratios, etc. of certain units (components).
[0051] Figure 1 This is a system block diagram of an intelligent anomaly early warning system for an industrial Internet of Things (IoT) edge node, provided as an embodiment of this application. Detailed Implementation
[0052] The following specific embodiments illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. It should be understood that these embodiments are merely for further explanation of the present invention and should not be construed as limiting the scope of protection of the present invention. Technical engineers in the field can make some non-essential improvements and adjustments to the present invention based on the above-described content. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0053] Please see Figure 1 An intelligent anomaly early warning system for industrial IoT edge nodes includes an edge perception layer, an edge intelligence layer, and a cloud-edge collaboration layer.
[0054] The edge sensing layer is used for data acquisition and security preprocessing; data is acquired through a multimodal sensor array set on the factory production line; and the data is encrypted and preprocessed through a quantum encryption preprocessing module.
[0055] The multimodal sensor array integrates various industrial sensors such as temperature, pressure, vibration, and sound waves, and can support industrial protocol adaptation such as Modbus and OPC UA; in addition, the sampling frequency is configurable, and its configuration range can be 1ms-1s.
[0056] The quantum encryption preprocessing module embeds a quantum random number generator (QRNG) chip at the data acquisition end to perform real-time chaotic encryption on the raw data stream, ensuring that data transmission between edge nodes meets quantum security standards. The quantum encryption preprocessing module supports the Chinese national standard SM4 algorithm and quantum random number generation.
[0057] In this embodiment, the BB84 protocol is used to generate the quantum key, and the key generation rate formula is:
[0058] R key = n·(log2N)·Q; where n is the number of photon pulses, N is the number of quantum state basis, and Q is the quantum channel efficiency.
[0059] The encryption formula for the SM4 encryption algorithm is: C = SM4 K (P); where P is the plaintext, K is the key (128), and C is the ciphertext.
[0060] The edge intelligence layer is used to intelligently analyze the data transmitted by the edge perception layer, construct a dynamic spatiotemporal graph neural network model and a dynamic edge knowledge graph; and set up a digital twin threshold engine. When the digital twin threshold engine detects an anomaly, it performs reverse reasoning along the knowledge graph and provides adaptive early warning.
[0061] The edge intelligence layer deploys lightweight graph neural networks at edge nodes. In this embodiment, a dynamic spatiotemporal graph neural network (DSTGNN) model is used to capture the spatial topological relationships and temporal dynamic features of the device group, supporting joint learning of temporal and spatial features.
[0062] In this embodiment, the Dynamic Spatiotemporal Graph Neural Network (DSTGNN) needs to calculate the spatial adjacency matrix Aij. First, it is necessary to calculate the Euclidean distance between nodes. For any two nodes i and j, their spatial coordinate vector x is calculated. i and x j Euclidean distance: d ij =||x i -x j ||.
[0063] The formula for calculating the spatial association weight between node i and node j is:
[0064]
[0065] Wherein, σ is the kernel width hyperparameter, which can control the decay rate of spatial correlation.
[0066] In this embodiment, the spatial adjacency matrix A is obtained by calculating all node pairs (i, j) using formula (1). 空间 .
[0067] The spatiotemporal diagram is extended, and the spatiotemporal correlation matrix is calculated using the following formula:
[0068]
[0069] Among them, A 时空( Let t) be the spatiotemporal correlation matrix at time t; A 空间 The spatial adjacency matrix is calculated using formula (1); A 时序 This is a temporal correlation matrix (such as historical state transition probabilities); is the Kronecker product, used to fuse spatial and temporal dependencies; I(t) is the identity matrix, representing the autocorrelation at the current time step.
[0070] Then the graph convolutional layer (GCN) is calculated, and its calculation formula is as follows:
[0071]
[0072] Among them, H (l) Let N be the input feature matrix of the l-th layer, with dimensions N×d, where N is the number of nodes and d is the feature dimension. Let I be the spatiotemporal correlation matrix of the self-loop, and let I be the identity matrix; Let be a degree matrix, satisfying W(l) Let be the trainable weight matrix of the l-th layer, with dimension d×F, where F is the output feature dimension; σ is the non-linear activation function.
[0073] After capturing temporal features, the formula for calculating dynamic temporal convolution is:
[0074]
[0075] Among them, T (l) (t) represents the l-th layer temporal feature at time t; Conv1D represents a one-dimensional convolution operation with a kernel size of k; ω(t): time decay factor.
[0076] The formula for calculating feature aggregation after cross-layer fusion is:
[0077]
[0078] Where Z(t) is the aggregated spatiotemporal feature vector with dimension N×C, where C is the number of channels; Aggregate is the feature fusion function such as attention weighting or pooling operation.
[0079] The formula for calculating the anomaly score is:
[0080] S(t) = f score (Z(t); θ) = Softmax(W) s Z(t)+b s (6);
[0081] Where S(t) represents the abnormal rating vector (value range [0,1]); W s b s These represent the weights and biases of the scoring layer, respectively; fscore is the scoring function (e.g., a fully connected layer + Softmax).
[0082] The formula for calculating the adaptive threshold is:
[0083] δ(t)=μ h +k·σ h (7);
[0084] Where δ(t) is the dynamic threshold of time t; μh is the historical score mean (e.g., sliding window average); σh is the historical score standard deviation; and k is the confidence coefficient.
[0085] The abnormality determination criteria are:
[0086]
[0087] Anomaly(t) is the anomaly label, where 1 indicates an anomaly and 0 indicates normal.
[0088] In this embodiment, the spatiotemporal correlation matrix A is established using formulas (1) and (2). 时空( t), describing the spatial and temporal dependencies between devices; extracting spatial and temporal features through formula (3) (graph convolution) and formula (4) (temporal convolution) respectively, and aggregating them into a unified representation Z(t) through formula (5); calculating the anomaly score S(t) based on the aggregated features through formula (6), generating the dynamic threshold δ(t) through formula (7), and finally determining the anomaly through formula (8).
[0089] Assuming three IoT devices (nodes) move on a two-dimensional plane, their spatiotemporal relationship needs to be modeled.
[0090] The spatial coordinates are: Device 1, x1 = [0,0]; Device 2, x2 = [1,0]; Device 3, x3 = [0,1]; Hyperparameter: σ = 1 (controls spatial weight decay); In addition, assuming the current time t = 1, the historical state depends only on its own state at the previous time.
[0091] The spatial adjacency matrix A is calculated according to formula (1).
[0092] First, let's take an example of the Euclidean equations between randomly selected nodes. The calculation process is shown in Table 1 below:
[0093] Table 1
[0094]
[0095] Then construct the spatial adjacency matrix.
[0096]
[0097] Assuming that time-series dependencies only retain their own historical state, then
[0098]
[0099] A diagonal line of 1 indicates that each node depends on its own state at the previous time step; an off-diagonal line of 0 indicates that there is no cross-node temporal dependency.
[0100] Next, the spatiotemporal correlation matrix is constructed according to formula (2). The specific steps are as follows:
[0101] First, define the identity matrix I(t) at the current time, i.e.
[0102]
[0103] Then calculate the Kronen product:
[0104] The space part is
[0105]
[0106] Expanded into a 9x9 matrix, in this embodiment, specific values are omitted, only the structure is shown.
[0107] The timing part is
[0108]
[0109] When expanded, it is also a 9×9 matrix, with non-zero elements only on the diagonal.
[0110] Adding them together yields the final spacetime matrix:
[0111]
[0112] In the matrix block structure, the top left, top middle, and top right are spatial weight blocks, while the bottom left, bottom middle, and bottom right are temporal weight blocks.
[0113] Analysis of the results shows that: off-diagonal blocks (such as the top left 3×3) reflect the spatial relationship between devices, such as the weight of device 1 and device 2 being 0.606; diagonal blocks (such as the bottom left 3×3) retain their own historical state and have a weight of 1; the spatiotemporal matrix captures both spatial proximity and temporal continuity, making it suitable for dynamic graph neural network input.
[0114] In addition, a dynamic edge knowledge graph is constructed at the edge nodes. The dynamic edge knowledge graph consists of a three-layer knowledge representation structure, namely the physical layer representing the relationship between device entities, the fault layer representing the historical fault propagation path, and the environmental layer representing external influencing factors such as temperature and humidity.
[0115] In this embodiment, the physical layer's physical device relationships can be illustrated by examples, such as "motor A - drive - gearbox B"; the historical fault propagation path of the fault layer can be "bearing wear → abnormal vibration → temperature rise".
[0116] Dynamic edge knowledge graphs can be updated autonomously at the edge using incremental graph learning algorithms, without requiring data transmission back to the cloud.
[0117] A 3D digital twin model of the device is established by setting up a digital twin threshold engine at the edge node; the digital twin threshold engine generates dynamic thresholds based on physical simulation.
[0118] For example, taking bearing temperature as an example, the threshold calculation formula based on physical simulation is as follows:
[0119] T threshold =T env +△T·η;
[0120] Where Tenv is the ambient temperature, ΔT is the temperature rise threshold, and η is the load factor.
[0121] Furthermore, to ensure quantum-resistant encryption at the edge, this embodiment employs lattice-based encryption (such as NTRU).
[0122] Furthermore, it protects the parameters and intermediate data of the dynamic spatiotemporal graph neural network model and performs lightweight quantum encryption on edge nodes.
[0123] The cloud-edge collaboration layer is used to collaboratively process the early warnings triggered by the digital twin threshold engine. The edge performs initial processing, while the cloud performs global optimization, generates optimization decisions, and simultaneously completes the iterative update of the DSTGNN model.
[0124] The cloud-edge collaboration layer adopts cross-level federated learning. At the edge layer, edge nodes exchange DSTGNN model gradients and update the local DSTGNN model every 5-20 minutes. In the cloud, multi-domain knowledge graphs are aggregated to generate a global supernet model. In addition, the cloud uses GPUs to accelerate the training of the DSTGNN model to improve model accuracy. At the same time, the cloud and edge layers work together to maintain decision-making.
[0125] The edge sensing layer uses a sensor array to collect multidimensional data in real time, and a quantum encryption module provides initial protection for the collected multidimensional data.
[0126] In the edge intelligence layer, edge nodes first analyze the data from the edge perception layer. Specifically, this involves the DSTGNN model extracting spatiotemporal features, using a dynamic edge knowledge graph to associate historical states, and using the digital twin model in the digital twin threshold engine to predict device trends.
[0127] When the threshold engine of the digital twin triggers an alert, the edge performs initial processing, and then the cloud generates an optimization strategy.
[0128] Meanwhile, based on a cross-level federated learning framework, edge experience is aggregated, the DSTGNN model is optimized in the cloud, and the update packet differential is pushed to the edge to complete the iterative update of the DSTGNN model.
[0129] A method for intelligent anomaly early warning of industrial IoT edge nodes includes the following steps:
[0130] Step 1: Multimodal data acquisition and quantum encryption preprocessing;
[0131] Multimodal sensor arrays are deployed on factory production lines and key equipment to collect multi-dimensional industrial data such as vibration, temperature, and pressure in real time. The quantum encryption preprocessing module at the edge node is used to encrypt the raw data stream in real time using a chaotic encryption algorithm, and the national cryptographic SM4 algorithm is applied simultaneously to complete compliance encryption processing and generate encrypted data packets.
[0132] Step 2: Dynamic modeling and knowledge graph construction of the edge intelligence layer;
[0133] A lightweight dynamic spatiotemporal graph neural network model is deployed at the edge nodes to capture the spatial topological relationships and time-series dynamic features of the device group through joint learning of spatiotemporal features; at the same time, a three-layer dynamic edge knowledge graph is constructed.
[0134] Step 3: Anomaly detection and inference using the digital twin threshold engine;
[0135] Establish a 3D digital twin model of the equipment and generate a dynamic threshold benchmark through physical simulation; when the real-time monitoring data exceeds the threshold, trigger the knowledge graph reverse reasoning mechanism; locate potential fault sources along the fault layer propagation path and correct the reasoning results in combination with environmental layer variables; generate early warning information containing equipment ID, anomaly type, and confidence level; and simultaneously start lightweight quantum encryption at the edge to protect model parameters and intermediate calculation data.
[0136] Step 4: Cloud-edge collaborative early warning and response and model optimization;
[0137] Edge nodes perform initial handling: activate preset emergency strategies (such as device frequency reduction); generate local handling logs;
[0138] After receiving early warnings in the cloud, global optimization is performed: multi-domain knowledge graphs are aggregated to build a global supernet model; GPU acceleration training is used to improve the accuracy of graph neural networks; cross-device linkage decision-making schemes are generated; and through a cross-level federated learning mechanism, edge nodes exchange model gradients every 5-20 minutes to achieve dynamic updates of the local model.
[0139] Step 5: System Iteration and Adaptive Learning;
[0140] The cloud distributes the optimized global model parameters to the edge nodes, and updates the simulation parameters of the digital twin threshold engine in sync. The edge nodes continuously optimize the knowledge graph reasoning rules based on the newly added running data, forming a closed-loop adaptive learning system of "perception-analysis-decision-optimization".
[0141] Step 6: Enhance quantum security; implement quantum anti-attack protection throughout the entire data lifecycle: dual protection of chaotic encryption and national cryptographic algorithm at the acquisition end; quantum key distribution (QKD) technology is used in the transmission channel; quantum random number generators (QRNG) are deployed on edge computing nodes; ensure the confidentiality of data and the integrity of the model in the quantum computing environment.
[0142] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. An intelligent anomaly early warning system for industrial Internet of Things (IoT) edge nodes, characterized in that, This includes the edge perception layer, the edge intelligence layer, and the cloud-edge collaboration layer. The edge sensing layer is used for data acquisition and security preprocessing; data is acquired through a multimodal sensor array installed on factory production lines or equipment. The data is pre-processed using a quantum encryption preprocessing module; The edge intelligence layer is used to intelligently analyze the data transmitted by the edge perception layer and to construct a dynamic spatiotemporal graph neural network model and a dynamic edge knowledge graph. A digital twin threshold engine is set up. When the digital twin threshold engine detects an anomaly, it performs reverse reasoning along the knowledge graph and provides adaptive warnings. The cloud-edge collaboration layer is used to collaboratively process the early warnings triggered by the digital twin threshold engine. The edge performs initial processing, while the cloud performs global optimization, generates optimization decisions, and simultaneously completes the iterative update of the dynamic spatiotemporal graph neural network model.
2. The intelligent anomaly early warning system for industrial IoT edge nodes according to claim 1, characterized in that, The quantum encryption preprocessing module performs real-time chaotic encryption on the raw data stream at the data acquisition end and supports the national cryptographic SM4 algorithm.
3. The intelligent anomaly early warning system for industrial IoT edge nodes according to claim 1, characterized in that, The edge intelligence layer deploys a lightweight graph neural network on the edge nodes. In this embodiment, a dynamic spatiotemporal graph neural network model is adopted to capture the spatial topological relationship and temporal dynamic features of the device group, supporting joint learning of temporal-spatial features.
4. The intelligent anomaly early warning system for industrial IoT edge nodes according to claim 3, characterized in that, In the dynamic spatiotemporal graph neural network model, it is necessary to calculate the spatial adjacency matrix Aij. First, the Euclidean distance between nodes is calculated. For any two nodes i and j, their spatial coordinate vector x is calculated. i and x j Euclidean distance: d ij =||x i -x j ||; The formula for calculating the spatial association weight between node i and node j is: Where σ is the kernel width hyperparameter, which controls the decay rate of spatial correlation; The spatial adjacency matrix A is obtained by calculating all node pairs (i, j) using formula (1). 空间 .
5. The intelligent anomaly early warning system for industrial IoT edge nodes according to claim 4, characterized in that, The spatiotemporal diagram is extended, and the spatiotemporal correlation matrix is calculated using the following formula: in, Let A be the spatiotemporal correlation matrix at time t; 空间 A is a spatial adjacency matrix; 时 The order is the temporal correlation matrix; The Kronecker product is used to fuse spatial and temporal dependencies; I(t) is the identity matrix, representing the autocorrelation at the current time step. Then the graph convolutional layer (GCN) is calculated, and its calculation formula is as follows: Among them, H (l) Let N be the input feature matrix of the l-th layer, with dimensions N×d, where N is the number of nodes and d is the feature dimension. Let I be the spatiotemporal correlation matrix of the self-loop, and let I be the identity matrix; Let be a degree matrix, satisfying W (l) Let be the trainable weight matrix of the l-th layer, with dimension d×F, where F is the output feature dimension; σ is the non-linear activation function. After capturing temporal features, the formula for calculating dynamic temporal convolution is: Among them, T (l) (t) represents the l-th layer temporal feature at time t; Conv1D represents a one-dimensional convolution operation with a kernel size of k; ω(t): time decay factor; The formula for calculating feature aggregation after cross-layer fusion is: Where Z(t) is the aggregated spatiotemporal feature vector with dimension N×C, where C is the number of channels; Aggregate is the feature fusion function such as attention weighting or pooling operation.
6. The intelligent anomaly early warning system for industrial IoT edge nodes according to claim 5, characterized in that, The formula for calculating the score of anomalies is: S(t)=f score (Z(t);θ)=Softmax(W s Z(t)+b s ) (6); Where S(t) represents the abnormal rating vector; W s b s These represent the weights and biases of the scoring layer; fscore is the scoring function. The formula for calculating the adaptive threshold is: δ(t)=μ h +k·s h (7); Where δ(t) is the dynamic threshold for time t; μh is the historical mean score; σh is the historical standard deviation score; and k is the confidence coefficient. The abnormality determination criteria are: Anomaly(t) is the anomaly label, where 1 indicates an anomaly and 0 indicates normal.
7. The intelligent anomaly early warning system for industrial IoT edge nodes according to claim 1, characterized in that, A dynamic edge knowledge graph is constructed at the edge nodes. The dynamic edge knowledge graph consists of a three-layer knowledge representation structure: a physical layer representing the relationships between device entities, a fault layer representing the historical fault propagation path, and an environmental layer representing external influencing factors. The dynamic edge knowledge graph can be updated autonomously at the edge through an incremental graph learning algorithm without the need for cloud transmission.
8. The intelligent anomaly early warning system for industrial IoT edge nodes according to claim 1, characterized in that, A 3D digital twin model of the device is established by setting up a digital twin threshold engine at the edge node; the digital twin threshold engine generates dynamic thresholds based on physical simulation. In addition, lightweight quantum encryption is applied to edge nodes to prevent quantum attack and to protect the parameters and intermediate data of the dynamic spatiotemporal graph neural network model.
9. The intelligent anomaly early warning system for industrial IoT edge nodes according to claim 1, characterized in that, The cloud-edge collaboration layer adopts cross-level federated learning. At the edge layer, edge nodes exchange gradients of the dynamic spatiotemporal graph neural network model and update the local dynamic spatiotemporal graph neural network model every 5-20 minutes. In the cloud, multi-domain knowledge graphs are aggregated to generate a global supernet model. The cloud uses GPUs to accelerate the training of the dynamic spatiotemporal graph neural network model to improve its accuracy. At the same time, the cloud and edge layers collaboratively maintain decision-making.
10. A method for intelligent anomaly early warning of industrial Internet of Things (IoT) edge nodes, characterized in that, Includes the following steps: Step 1: Multimodal data acquisition and quantum encryption preprocessing; Deploy multimodal sensor arrays on factory production lines and key equipment to acquire multi-dimensional industrial data in real time; Use the quantum encryption preprocessing module at the edge node to encrypt the raw data stream in real time using a chaotic encryption algorithm; Generate encrypted data packets; Step 2: Dynamic modeling and knowledge graph construction of the edge intelligence layer; deploy a lightweight dynamic spatiotemporal graph neural network model on the edge nodes to receive and analyze the data in the encrypted data packets; capture the spatial topological relationship and time series dynamic features of the device group through spatiotemporal feature joint learning; and simultaneously construct a three-layer dynamic edge knowledge graph. Step 3: Digital Twin Threshold Engine Anomaly Detection and Inference; Establish a 3D digital twin model of the device and generate a dynamic threshold benchmark through physical simulation; When real-time monitoring data exceeds the threshold, trigger the knowledge graph reverse inference mechanism; Locate potential fault sources along the fault layer propagation path and correct the inference results in combination with environmental layer variables; Generate early warning information including device ID, anomaly type, and confidence level; Simultaneously initiate lightweight quantum encryption at the edge to protect model parameters and intermediate computation data; Step 4: Cloud-edge collaborative early warning and response and model optimization; edge nodes activate preset emergency strategies; Generate local handling logs; perform global optimization after receiving alerts in the cloud. Step 5: System Iteration and Adaptive Learning; The cloud distributes the optimized global model parameters to the edge nodes and updates the simulation parameters of the digital twin threshold engine in sync. The edge nodes continuously optimize the knowledge graph reasoning rules based on the newly added running data, forming a closed-loop adaptive learning system of "perception-analysis-decision-optimization". Step 6: Enhance quantum security; implement quantum-resistant protection throughout the entire data lifecycle.
Citation Information
Cited By
Park governance-oriented cloud-edge collaborative multi-modal reasoning method and system
CN121146100A
Internet of Things cluster data analysis method based on big data and artificial intelligence
CN121434866A
An internet of things cluster data analysis method based on big data and artificial intelligence
CN121434866B
An industrial internet remote monitoring operation and maintenance management system and method
CN122395059A