Abnormal fluctuation detection system and method for real-time data stream
By building a baseline model locally on the home gateway and adaptively updating it, the problems of network latency and 'concept drift' in existing technologies are solved, achieving second-level response and accurate anomaly detection, and reducing false alarm rate and false negative rate.
Patent Information
- Application Number
- CN202511379682.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-25
- Publication Date
- 2025-12-12
AI Technical Summary
Existing technologies for real-time data stream anomaly detection in home gateways rely on cloud platforms, resulting in high network latency, inability to respond to sudden events within seconds, and inability to effectively address 'concept drift' caused by environmental changes, leading to frequent false alarms and missed alarms.
A baseline model is built locally on the home gateway. By collecting conductive and radiative physical characteristics, the model is adaptively updated, the abnormal deviation is calculated, and differential judgment and linkage control are performed in a two-dimensional decision space to achieve second-level response and adaptive detection.
It enables localized anomaly detection for home gateways, reduces network latency, improves response speed, reduces false alarms and missed alarms, and ensures the continuous effectiveness of security capabilities.
Smart Images

Figure CN121125579A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data monitoring, in particular to an abnormal fluctuation detection system and method for real-time data flow. BACKGROUND
[0002] With the rapid development of the Internet of Things and smart home, the number of smart devices and data traffic in home networks is growing explosively. In order to ensure the security, stability and efficient operation of home networks, the existing technology usually deploys an intelligent control system in a home gateway (such as a router) to realize abnormal fluctuation detection and early warning of real-time data flow.
[0003] In the prior art, a publication number CN115203249A, a method for analyzing device time series data based on industrial internet, the cloud platform predicts the monitoring data through an artificial intelligence model, and sends the predicted value to the monitoring terminal. After receiving the predicted value, the monitoring terminal compares and combs the collected monitoring data stream according to the predicted value and the deviation threshold, judges whether there is abnormal fluctuation in the monitoring data stream, marks the segment of the monitoring data stream as abnormal data stream and uploads it completely when there is abnormal data in the monitoring data stream, and uploads the average value when the monitoring data stream is normal. The cloud platform analyzes and stores the abnormal reasons according to the average value and the abnormal data stream. The normal monitoring data stream is uploaded in the form of average value, thereby forming a compression effect on the collected data information, and reducing the data storage cost of the user.
[0004] However, the above technical solution has the following technical defects when applied to the deployment of intelligent control in the home gateway: The data screening module of the monitoring terminal must rely on the prediction module of the cloud platform to issue a predicted value for abnormal judgment; this mode forcibly binds the real-time security capability of the home gateway and the public network connection quality, and each judgment needs to go through the long link of "data collection - upload - cloud analysis - result delivery", which introduces unavoidable network delay and cannot meet the second-level response demand for sudden events such as network attacks. Once the home external network is interrupted or unstable, the entire abnormal detection system will be disabled, forming a security vacuum; Further, the cloud-centralized intelligent model updating mechanism cannot effectively cope with the "concept drift" of the home network environment. The data filtering module of the prior art can only perform rigid comparison of whether the difference between the monitoring data and the predicted value is greater than the deviation threshold, and does not have any learning and adaptive ability. When the user behavior and device state change, causing the data pattern to drift, the fixed predicted value and deviation threshold will quickly become invalid, causing the monitoring terminal to generate a large number of false positives (marking normal changes as abnormal data streams) or false negatives (failing to identify new attacks); to correct this problem, a large number of misjudged abnormal data streams and normal average data must be uploaded to the cloud platform, and new predicted values cannot be issued until the prediction module of the cloud platform completes slow offline retraining, the entire process is slow and inefficient, and greatly wastes network bandwidth and cloud computing resources. The above information disclosed in the background section is only used to enhance the understanding of the background of the present disclosure, and therefore it can include information that does not constitute prior art known to those of ordinary skill in the art. SUMMARY
[0005] The purpose of the present application is to provide an abnormal fluctuation detection system and method for real-time data streams to solve the problems raised in the background art.
[0006] To achieve the above-mentioned purpose, the present application provides the following technical solution: an abnormal fluctuation detection method for real-time data streams, comprising the following steps: S1, determining a target intelligent device in a home gateway, collecting physical layer companion signals generated by the target intelligent device during network communication, including conductive physical characteristics and radiative physical characteristics; S2, constructing a baseline model for representing the normal working state of the target intelligent device for the conductive physical characteristics and the radiative physical characteristics, respectively, wherein: For conductive physical characteristics, a first baseline model is constructed to define the stable association relationship between them and network traffic data; For the radiative physical characteristics, a second baseline model is constructed to define its own stable time sequence pattern; S3, inputting the real-time collected physical layer companion signals into the corresponding baseline model to calculate the abnormal deviation degree, including the first abnormal deviation degree and the second abnormal deviation degree; S4, analyzing and evaluating the first abnormal deviation degree and the second abnormal deviation degree, respectively, and then performing differentiated judgment and linkage control according to the source of the abnormal deviation degree, including selectively triggering the logical layer security alarm for the target intelligent device, the security alarm for the home physical space, and the security alarm for the composite anomaly of the target intelligent device and the home physical space.
[0007] Further, S1 specifically comprises: After determining the target smart device in the home gateway, first, a signal effectiveness index is calculated to represent the data quality of the current synchronization acquisition task; when the signal effectiveness index is higher than a preset quality threshold, the acquisition and storage of the physical layer companion signal are performed, serving as a data source for subsequent baseline model construction.
[0008] Further, S1 specifically includes: The specific acquisition process of the physical layer companion signal is: In a database for baseline model training, a new data record entry is created; the conductive physical feature and the radiative physical feature obtained in the current synchronization acquisition period are stored in the corresponding fields of the new data record entry; For the new data record entry, the calculated value of the signal effectiveness index and the accurate time stamp of the current acquisition period are stored as metadata in the new data record entry, for subsequent data tracing and model iteration; When the signal effectiveness index is lower than the quality threshold, it is determined that the data of the current acquisition period is invalid, and a data discarding operation is performed, i.e., the buffer area for temporarily storing the acquisition data is emptied, and the physical layer companion signal data obtained in the period is not written into the database.
[0009] Further, S2 specifically includes: For the conductive physical feature and the radiative physical feature, baseline models are respectively constructed for adaptive adjustment and fusion of context information; including updating the definition of the normal working state of the target smart device in a confidence weighted manner when the baseline model gradually drifts in the normal operation mode, while effectively suppressing the pollution of abnormal data to the baseline; Specifically, by evaluating the deviation degree of the data to be updated and taking it as part of the model update confidence, the contribution weight of the data to be updated to the baseline model parameter update is dynamically adjusted, and only data conforming to the current normal mode is involved in the baseline iteration.
[0010] Further, S2 specifically includes: The first baseline model is constructed, including: based on the conductive physical feature and the network traffic data, a multi-dimensional association model is constructed, and the model update confidence is calculated according to the data quality, timeliness and consistency with the current model of the newly acquired data, to adaptively update the parameters of the multi-dimensional association model with the model update confidence as the weight; The second baseline model is constructed, including: based on the radiative physical feature, a time series pattern learning model is constructed, and the model update confidence is calculated according to the data quality, timeliness and consistency with the current model of the newly acquired data, to adaptively update the parameters of the time series pattern learning model with the confidence as the weight.
[0011] Further, S3 specifically includes: For the first and second abnormal deviation degrees, not only the static amplitude of the deviation is calculated, but also the time dynamic characteristics of the deviation are further calculated; Then, the static amplitude and time dynamic characteristics are fused by a preset contribution weight to generate a first comprehensive abnormal score and a second comprehensive abnormal score for representing the properties of abnormal events.
[0012] Further, S3 specifically includes: The static amplitude and time dynamic characteristics are fused by a preset contribution weight as follows: According to the real-time collected network traffic data mode, a pre-defined business state currently taken by the target intelligent device is identified; From a pre-constructed weight strategy library, a contribution weight set matched with the pre-defined business state is called, wherein the weight strategy library contains multiple contribution weight sets corresponding to different pre-defined business states one by one; and the called contribution weight set is applied to weight calculation of the static amplitude and the time dynamic characteristics, so as to generate the first comprehensive abnormal score and the second comprehensive abnormal score.
[0013] Further, S4 specifically includes: A two-dimensional decision space with the first comprehensive abnormal score and the second comprehensive abnormal score as orthogonal coordinate axes is constructed; meanwhile, based on the first comprehensive abnormal score and the second comprehensive abnormal score, a real-time abnormal deviation degree coordinate point for positioning in the two-dimensional decision space is defined, and a first abnormal deviation threshold and a second abnormal deviation threshold are preset; In the two-dimensional decision space, the first abnormal deviation threshold and the second abnormal deviation threshold respectively define two mutually orthogonal decision boundary lines, which accurately divide the two-dimensional decision space into four decision regions, including a first decision region, a second decision region, a third decision region, and a fourth decision region; The first decision region, the second decision region, the third decision region, and the fourth decision region correspond to normal state, internal device abnormality, physical space abnormality, and composite abnormality respectively; By determining the unique decision region where the real-time abnormal deviation degree coordinate point falls, differential determination and linkage control are directly mapped and executed.
[0014] Further, S4 specifically includes: The execution of differential determination and linkage control specifically includes the following process: Determination and maintenance of normal state: when the real-time abnormal deviation degree coordinate point is located in the first decision region, it is determined that the system is in a normal state, and continuous monitoring is maintained without triggering any alarm or control; Device internal abnormality determination and response: when the real-time abnormality deviation coordinate point is located in the second decision area, it is determined that the abnormality is derived from the internal of the target smart device, and a logical layer or hardware layer security alarm for the target smart device is triggered accordingly; Physical space abnormality determination and response: when the real-time abnormality deviation coordinate point is located in the third decision area, it is determined that the abnormality is derived from the physical space where the target smart device is located, and a security alarm for the home physical space is triggered accordingly; Composite abnormality determination and response: when the real-time abnormality deviation coordinate point is located in the fourth decision area, it is determined that there is a composite abnormality, and a logical layer or hardware layer security alarm for the target smart device and a security alarm for the home physical space are triggered simultaneously to execute the highest level of security response.
[0015] An abnormal fluctuation detection system for real-time data flow, comprising the following modules: A multi-source signal acquisition module determines a target smart device in a home gateway, and acquires physical layer accompanying signals generated by the target smart device when communicating on a network, including conductive physical characteristics and radiative physical characteristics; A normal behavior modeling module respectively constructs baseline models for representing normal working states of the target smart device for the conductive physical characteristics and the radiative physical characteristics, wherein: For the conductive physical characteristics, a first baseline model is constructed for defining a stable correlation relationship between the conductive physical characteristics and network flow data; For the radiative physical characteristics, a second baseline model is constructed for defining a stable time sequence mode of the radiative physical characteristics; An abnormality deviation calculation module inputs the real-time acquired physical layer accompanying signals into the corresponding baseline models to calculate abnormality deviations, including a first abnormality deviation and a second abnormality deviation; A decision and linkage control module analyzes and evaluates the first abnormality deviation and the second abnormality deviation respectively, and then performs differentiated determination and linkage control according to the sources of the abnormality deviations, including selectively triggering a logical layer security alarm for the target smart device, a security alarm for the home physical space, and simultaneously triggering the security alarm in the composite abnormality of the target smart device and the home physical space.
[0016] Compared with the prior art, the present application has the following advantages: The application solves the dependence on the cloud platform and the network delay and connection interruption problems caused by the dependence by performing all detection steps locally in the home gateway; specifically, by constructing a two-dimensional decision space with the first abnormal deviation degree and the second abnormal deviation degree as the coordinate axes, and using the first abnormal deviation threshold and the second abnormal deviation threshold to define four decision regions, the localization, low-cost determination and second-level response of the abnormal event are realized, the continuous effectiveness of the security capability when the home external network is interrupted is ensured, and the long link constraint of "data acquisition-upload-cloud analysis-result delivery" is fundamentally broken; The application solves the "concept drift" problem caused by environmental changes by constructing a baseline model that can be updated adaptively; specifically, the first baseline model and the second baseline model are updated with confidence by calculating the model update confidence, so that the model can smoothly adapt to the gradual drift of user behavior or device state; further, by identifying the pre-defined business state and calling the matching contribution weight set from the weight strategy library, the deviated static amplitude and the deviated time dynamic characteristics are dynamically weighted to generate the first comprehensive abnormal score and the second comprehensive abnormal score, the context-aware accurate evaluation is realized, the false positives and false negatives caused by the fixed model are significantly reduced, and the inefficient and high-cost offline retraining of the cloud is avoided. BRIEF DESCRIPTION OF DRAWINGS
[0017] Figure 1 It is a whole method flowchart of the application; Figure 2 It is a whole system structure schematic diagram of the application; Figure 3 It is a flowchart frame schematic diagram of S3 in the application. DETAILED DESCRIPTION
[0018] In order to make the above-mentioned purposes, features and advantages of the application more obvious and easy to understand, the specific embodiments of the application will be described in detail below with reference to the accompanying drawings.
[0019] In the following description, many specific details are set forth in order to provide a thorough understanding of the application, but the application can also be implemented in other ways different from those described herein, and those skilled in the art can make similar generalizations without departing from the connotation of the application, therefore the application is not limited to the specific embodiments disclosed below.
[0020] Embodiment one: Please refer to Figure 1 The application provides an abnormal fluctuation detection method for real-time data stream, comprising the following steps: S1, determining a target intelligent device in the home gateway, collecting physical layer associated signals generated by the target intelligent device when communicating in the network, including conductive physical characteristics and radiative physical characteristics; S2, respectively for the conductive physical feature and the radiative physical feature, constructing a baseline model for characterizing the normal working state of the target intelligent device, wherein: For the conductive physical feature, a first baseline model is constructed for defining the stable correlation between it and the network traffic data; For the radiative physical feature, a second baseline model is constructed for defining its own stable timing pattern; S3, input the real-time collected physical layer companion signal into the corresponding baseline model to calculate the abnormal deviation degree, including the first abnormal deviation degree and the second abnormal deviation degree; S4, analyzing and evaluating the first abnormal deviation degree and the second abnormal deviation degree respectively, and then performing differentiated judgment and linkage control according to the source of the abnormal deviation degree, including selectively triggering the logical layer security alarm for the target intelligent device, the security alarm for the home physical space, and the security alarm for the composite anomaly of the target intelligent device and the home physical space.
[0021] S1 specifically includes: After determining the target intelligent device in the home gateway, first calculate a signal effectiveness index for representing the data quality of this synchronization collection task; when the signal effectiveness index is higher than the preset quality threshold, then execute the collection and storage of the physical layer companion signal as the data source for subsequent baseline model construction.
[0022] S1 specifically includes: The specific collection process of the physical layer companion signal is: In a database for baseline model training, a new data record entry is created; the conductive physical feature and the radiative physical feature obtained in this synchronization collection period are stored in the corresponding fields of the new data record entry; For the new data record entry, the calculated value of the signal effectiveness index and the accurate time stamp of the current collection period are stored as metadata in the new data record entry for subsequent data tracing and model iteration use; When the signal effectiveness index is lower than the quality threshold, it is determined that the data of the current collection period is invalid, and the data discard operation is performed, that is, the cache area for temporarily storing the collection data is emptied, and the physical layer companion signal data obtained in this period is not written into the database.
[0023] Further, the implementation process of S1 is as follows: S1.1, data preprocessing and feature extraction: in a synchronous acquisition cycle, the acquired conductive physical characteristics and radiative physical characteristics, i.e. high-frequency power consumption waveform and channel state information CSI, are normalized, and three core parameters that can be quantified by numerical values are extracted, namely conductive signal-to-noise ratio, radiative stability coefficient and synchronous time deviation; Among them, the conductive signal-to-noise ratio refers to the ratio of the effective signal power to the noise power in the power waveform data; the radiative stability coefficient refers to the inverse of the dispersion degree of the CSI amplitude matrix in the acquisition cycle; the synchronous time deviation refers to the absolute difference of the time stamps of the conductive and radiative physical characteristic data packets. All parameters are mapped to the dimensionless numerical value interval of 0 to 1.
[0024] S1.2, in the offline calibration stage, the principal component analysis method including power consumption feature principal component PCA is used to analyze the above three core parameters in a large number of historical acquisition samples, to determine the optimal weight of the respective contribution to the comprehensive data quality, and to obtain three numerically quantified Chinese names: conductive feature weight, radiative feature weight and synchronous deviation weight.
[0025] S1.3, the calculation formula of the signal effectiveness index is: the signal effectiveness index is equal to the product of a basic quality score and a synchronous penalty factor; Among them, the calculation formula of the basic quality score is: multiply the conductive signal-to-noise ratio by the conductive feature weight, add the product of the radiative stability coefficient and the radiative feature weight, and normalize the result; The calculation formula of the synchronous penalty factor is: take the natural constant e as the base, take the product of the negative synchronous time deviation and a preset penalty coefficient as the exponent, and perform exponential operation.
[0026] Further, the technical effects and logical rationality of S1 are explained as follows: For clarity, the numerically quantified Chinese names and letter symbols used in this embodiment are identified, including conductive signal-to-noise ratio Sc, radiative stability coefficient Sr, synchronous time deviation Δt, conductive feature weight Wc, radiative feature weight Wr and signal effectiveness index Iv; By constructing the signal effectiveness index Iv, a quality control mechanism is introduced at the data acquisition source, avoiding the pollution of low-quality data to the subsequent model training, and the logical rationality and technical effects of S1 are embodied through the following algorithm deduction process: The concept of signal-to-noise ratio from the field of "signal processing", the inverse of the coefficient of variation from "statistics", and the weighted average and exponential decay idea from "applied mathematics" are combined; The embodiment sets that in one collection, the normalized conductive signal-to-noise ratio Sc is 0.9, the radiation stability coefficient Sr is 0.8, the synchronization time deviation Δt is 0.05, the offline determined weight conductive feature weight Wc is 0.6, the radiation feature weight Wr is 0.4, and the preset synchronization penalty coefficient is 10; After substituting the numerical value into the basic quality score, the following is obtained ; After substituting the numerical value into the synchronization penalty factor, the following is obtained ; Finally, the signal effectiveness index Iv is obtained ; At this time, the signal effectiveness index Iv is compared with the quality threshold, and if it is higher than the quality threshold, the original data of the conductive signal-to-noise ratio Sc and the radiation stability coefficient Sr collected this time are accepted.
[0027] All input parameters, the conductive signal-to-noise ratio Sc, the radiation stability coefficient Sr, and the synchronization time deviation Δt, are dimensionless values, and the value range is (0, 1); through the above calculation formula, the value range of the output value signal effectiveness index Iv is limited to the range of (0, 1), which ensures the stability and comparability of the output; When the signal effectiveness index Iv output tends to be closer to 1: at least one of the basic quality score and the synchronization penalty factor tends to be closer to 1, which is specifically manifested in that the conductive signal-to-noise ratio Sc and the radiation stability coefficient Sr tend to be closer to 1, and the synchronization time deviation Δt tends to be closer to 0; this indicates that the current collected conductive physical feature signal-to-noise ratio is higher, the radiation physical feature stability is stronger, and the synchronization is higher; When the signal effectiveness index Iv output tends to be closer to 0, it is caused by two situations: One is that the conductive signal-to-noise ratio Sc or the radiation stability coefficient Sr tends to be closer to 0, resulting in a lower basic quality score; Two is that the synchronization time deviation Δt tends to be closer to 1, resulting in a synchronization penalty factor that tends to be closer to 0, which indicates that the current collected signal quality problem is getting more and more serious.
[0028] S2 specifically includes: For the conductive physical feature and the radiation physical feature, a baseline model for adaptively adjusting and fusing context information is constructed; when the baseline model gradually drifts in the normal operation mode, the definition of the target intelligent device normal working state is updated in a confidence weighted manner, while effectively suppressing the pollution of abnormal data to the baseline; Specifically, by evaluating the deviation degree of the data to be updated and taking it as part of the model update confidence, the contribution weight of the data to be updated to the baseline model parameter update is dynamically adjusted, and only the data conforming to the current normal mode participates in the baseline iteration.
[0029] S2 specifically comprises: constructing the first baseline model, comprising: constructing a multi-dimensional correlation model based on the conductive physical features and network traffic data, and calculating a model update confidence according to the data quality, timeliness and consistency with the current model of the newly collected data, to adaptively update the parameters of the multi-dimensional correlation model with the model update confidence as a weight; constructing the second baseline model, comprising: constructing a time series pattern learning model based on the radiative physical features, and calculating a model update confidence according to the data quality, timeliness and consistency with the current model of the newly collected data, to adaptively update the parameters of the time series pattern learning model with the confidence as a weight.
[0030] Further, the construction of the baseline model in S2 and the calculation process of adaptive adjustment are specifically as follows: S2.1, construction and adaptive update of the first baseline model: S2.11, after the device is first deployed, the system collects a large amount of conductive physical feature data verified as high quality by S1 and synchronous network traffic data in a preset stable observation period; wherein the conductive physical feature data includes key features of high-frequency power consumption waveform, i.e. harmonic content and transient power peak, and the network traffic data includes data packet sending rate and receiving bandwidth; S2.12, feature engineering is performed on the collected conductive physical feature data and network traffic data to extract power consumption feature vector dimension and network traffic feature vector dimension; subsequently, principal component analysis methods including power consumption feature principal component PCA are used to reduce the dimension of these high-dimensional features to obtain conductive feature principal components and network traffic feature principal components; S2.13, a power flow correlation degree model is constructed for the reduced conductive feature principal components and network traffic feature principal components; the power flow correlation degree model learns the statistical regression relationship between the two under normal state, defines a correlation matching degree index, and reflects the degree of conformity to the preset correlation pattern between real-time power consumption features and network traffic features; S2.14, whenever new data verified as high quality and preliminarily determined as normal by S1 step flows in, the correlation matching degree index of the new data with the current power flow correlation degree model is calculated; at the same time, the time freshness and deviation degree of the new data from the current baseline, i.e. data timeliness weight and data consistency weight, are combined to obtain the model update confidence through calculation; Finally, the parameters of the power flow correlation degree model will be updated through a weighted average formula, which will weight and fuse the contribution of new data with the current model parameters, and the weight is determined by the model update confidence, ensuring that abnormal data will not pollute the baseline; S2.2, Construction and adaptive update of the second baseline model: S2.21, During the stable observation period, a large amount of high-quality radiation physical characteristic data verified by S1 step, including amplitude and phase sequence of channel state information CSI, are collected; S2.22, A long short-term memory network LSTM deep learning model is used to learn the time sequence evolution rule and internal statistical distribution of channel state information CSI data in the normal state, and a CSI time sequence pattern model is formed; the CSI time sequence pattern model is used to predict the CSI at the next moment according to the input CSI sequence, or to reconstruct the input CSI sequence, and output the pattern reconstruction error, which reflects the deviation degree of the real-time CSI sequence from the learned normal time sequence pattern; S2.23, Whenever there is a new data flow verified by S1 step as high quality and preliminarily determined as normal, calculate its pattern reconstruction error; take the pattern reconstruction error as input, combine the data timeliness weight and the data consistency weight, and calculate the model update confidence; the internal parameters of the CSI time sequence pattern model will be fine-tuned through a gradient optimization algorithm, wherein the learning rate is dynamically adjusted by the model update confidence, so that the CSI time sequence pattern model slowly adapts to the normal changes of the environment, while avoiding model drift caused by abnormal data; Further, the technical effects and logical rationality of S2 are explained as follows: For clarity, the numerical quantified Chinese names and letter symbols used in this embodiment are identified, including power consumption characteristic principal component PCA, network traffic characteristic principal component Nc, correlation matching degree index Mc, pattern reconstruction error Er, data timeliness weight Wt, data consistency weight Wo, and model update confidence Cu; Further, the logical rationality and technical effects of S3 are embodied through the following algorithm derivation process: First baseline model update example: Based on the difference between the data collection time and the current time, the data timeliness weight Wt is calculated by an exponential decay function, and based on the deviation degree of the new correlation matching degree index Mc' and the current correlation matching degree index Mc, the model update confidence Cu is calculated by a Gaussian function; In this embodiment, the correlation matching degree index Mc of the current first baseline model is set to 0.95, and the correlation matching degree index Mc of a newly collected set of high-quality normal data is 0.92; Set the data timeliness weight Wt to 0.8 and the data consistency weight Wo to 0.9; use weighted average, and the weight is determined by the power consumption characteristic principal component PCA, then the calculation formula of the model update confidence Cu is:
[0031] After substituting the numerical calculation, we get ; The update formula of the current correlation matching degree index Mc is as follows:
[0032] wherein, Mc' represents the new correlation matching degree index, represents the historical baseline value, representing the long-term cognition and memory of the first baseline model learned in the past to the "normal state"; and a is the fixed learning rate of the model itself, which is set to 0.01 in the embodiment; The new correlation matching degree index Mc' is the result of the trade-off between the historical baseline value and the current correlation matching degree index Mc, and this result is not simply the average result, but is achieved through a dynamic weight, i.e. ; After substituting the new correlation matching degree index into the numerical calculation, we get
[0033] This indicates that the model is fine-tuned to new normal data. The second baseline update example is as follows: The update process of the second baseline model is the same as that of the first baseline model, but the internal parameters are optimized by gradient descent, and the learning rate is dynamically adjusted according to the calculated model update confidence Cu, i.e. learning rate = Cu x initial learning rate; the higher the model update confidence Cu, the more aggressive the model learns new data.
[0034] The power consumption feature principal component PCA, the network traffic feature principal component Nc, the correlation matching degree index Mc, the pattern reconstruction error Er, the data timeliness weight Wt, and the intermediate calculation result model update confidence Cu are all dimensionless and the value range is limited to (0, 1); When the model update confidence Cu output tends to 1, it indicates that the newly collected data is not only of higher quality, but also highly consistent with the current baseline model, and this situation is reflected by the data consistency weight Wo tending to 1; at the same time, the data is fresher, and this situation is reflected by the data timeliness weight Wt tending to 1; This indicates that the device is in a highly stable and typical normal operating state, or its normal state has a small and persistent drift, and the drift trend is consistent with the historical normal data; at this time, the baseline model will fine-tune at the maximum allowed rate to capture the current "normal" definition more accurately, so that the model has high adaptability to the subtle changes of the device normal operation, thereby avoiding misjudgment of the normal progressive changes as abnormal; When the model update confidence Cu output is closer to 0, it indicates that the quality of the newly collected data is lower, or the difference between the device behavior pattern reflected by the newly collected data and the device behavior pattern defined by the baseline model is getting larger, which is embodied by the data consistency weight Wo tending to 0; or the newly collected data has expired, which is embodied by the data timeliness weight Wt tending to 0; At this time, the baseline model is not updated, which ensures that when the device has real anomalies, including malicious attacks and hardware failures, these abnormal data will not be learned into the "normal" baseline, thereby effectively preventing the baseline from being polluted and ensuring the accuracy and sensitivity of subsequent anomaly detection. This mechanism is the core embodiment of the robustness of the present scheme.
[0035] Please refer to Figure 3 , S3 specifically includes: For the first abnormal deviation degree and the second abnormal deviation degree, not only the static amplitude of the deviation is calculated, but also the time dynamic characteristics of the deviation are further calculated; Then, the static amplitude and the time dynamic characteristics are fused through a preset contribution weight to generate a first comprehensive abnormal score and a second comprehensive abnormal score for representing the properties of the abnormal event.
[0036] S3 specifically includes: The static amplitude and the time dynamic characteristics are fused through a preset contribution weight as follows: According to the real-time collected network traffic data pattern, the pre-defined business state currently occupied by the target intelligent device is identified; From a pre-constructed weight strategy library, a contribution weight set matched with the pre-defined business state is called, wherein the weight strategy library contains a plurality of contribution weight sets corresponding to different pre-defined business states one by one; and the called contribution weight set is applied to perform weighted calculation on the static amplitude and the time dynamic characteristics, so as to generate the first comprehensive abnormal score and the second comprehensive abnormal score.
[0037] Further, the calculation process of the first comprehensive abnormal score and the second comprehensive abnormal score in S3 is decomposed as follows: S3.1, input the real-time collected conductive physical characteristics and network traffic data into the first baseline model to obtain an internal original deviation degree; input the real-time collected radiative physical characteristics into the second baseline model to obtain an external original deviation degree; S3.2, normalize the internal original deviation degree and the external original deviation degree to obtain an abnormal amplitude in the value range [0, 1], including an internal abnormal amplitude and an external abnormal amplitude; Then, in a preset short sliding window, the dynamic change rate is calculated. Specifically, the standard deviation of the internal original deviation sequence is calculated and normalized to obtain the internal dynamic change rate. Similarly, the external original deviation sequence is processed in the same way to obtain the external dynamic change rate. The internal dynamic change rate and the external dynamic change rate are used to quantify the degree of fluctuation of the abnormal deviation in time; S3.3, in the offline calibration phase, for different types of abnormal events marked in the historical data, including hardware aging and malicious software injection, the principal component analysis method including power consumption feature principal component PCA is used to analyze the contribution of the two features of abnormal amplitude and dynamic change rate in S3.2 to distinguish different event types; Based on the analysis result, the amplitude component weight and the dynamic component weight are obtained, and the sum of the two is 1. The weight is common to the calculation of the first comprehensive abnormal score and the second comprehensive abnormal score, because it reflects the inherent importance of the abnormal feature itself; S3.4, the first comprehensive abnormal score and the second comprehensive abnormal score are calculated respectively, and the specific calculation process is: The comprehensive abnormal score is equal to the product of the abnormal amplitude and the corresponding amplitude component weight, plus the product of the dynamic change rate and the corresponding dynamic component weight; Further, for clarity, the numerical quantification of the Chinese name and the letter symbol used in this embodiment are identified, including internal abnormal amplitude Mint, external abnormal amplitude Mext, internal dynamic change rate Tint, external dynamic change rate Text, amplitude component weight Wm, dynamic component weight Wn, first comprehensive abnormal score Sint and second comprehensive abnormal score Sext; By constructing the first comprehensive abnormal score Sint and the second comprehensive abnormal score Sext, the evaluation of the anomaly is upgraded from a single amplitude scalar to a two-dimensional vector that integrates the time dynamic characteristics, enriching the connotation of abnormal information; Further, the following algorithm derivation process is used to reflect the logical rationality and technical effect of S3: In this embodiment, S3 integrates the standard deviation calculation and weighted average method derived from "statistics", and the power consumption feature principal component PCA principal component analysis derived from machine learning for feature contribution evaluation; Assuming that the offline power consumption feature principal component PCA analysis determines that the dynamic change rate is more important than the abnormal amplitude for identifying high-risk attacks, therefore, the amplitude component weight Wm=0.4 and the dynamic component weight Wn=0.6 are set; Scenario one: a sudden malware attack, real-time calculation gets internal anomaly amplitude Mint=0.8, indicating a large deviation amplitude; and since it is sudden, the deviation degree increases dramatically in a short time, and the internal dynamic change rate Tint=0.9 is calculated, indicating that the dynamic change is severe; the specific calculation formula is as follows:
[0038] After substituting the parameters, we get ; Scenario two: device hardware slowly ages, real-time calculation gets Mint=0.8, also indicating a large deviation amplitude; but since it is a long-term gradual change process, the deviation degree is stable at a high level, and the internal dynamic change rate Tint=0.1 is calculated, indicating that the dynamic change is gentle; after substituting the parameters, we get:
[0039] Result comparison: although the anomaly amplitudes of the two scenarios are the same, the first comprehensive anomaly score Sint is 0.86 and 0.38 respectively, successfully distinguishing two different anomalies in nature, which provides a solid data basis for S4 to take different levels of response, including immediate blocking and maintenance reminders; The internal anomaly amplitude Mint, the external anomaly amplitude Mext, the internal dynamic change rate Tint and the external dynamic change rate Text of all input components are non-dimensional values in the interval [0, 1]; the amplitude component weight Wm and the dynamic component weight Wn have a value range of [0, 1] and a sum of 1; through the design of weighted summation, the value range of the final output first comprehensive anomaly score Sint and the second comprehensive anomaly score Sext is limited to the range [0, 1], which is used to reflect the severity level of the comprehensive anomaly; When the output value of the first comprehensive anomaly score Sint approaches 0 infinitely, the internal anomaly amplitude Mint and the internal dynamic change rate Tint both approach 0 infinitely, indicating that the target intelligent device not only matches the baseline model well, i.e. the deviation amplitude is extremely small, but also shows high stability, i.e. the dynamic change rate is extremely low, which is an ideal working scenario; ensuring that the system remains silent when the device is running normally, fundamentally meeting the technical goal of reducing false positives and improving user experience; Correspondingly, when the output value of the first comprehensive anomaly score Sint approaches 1 infinitely, at least one of the internal anomaly amplitude Mint and the internal dynamic change rate Tint approaches 1 infinitely, or both approach 1 infinitely; specifically, when the dynamic component weight Wn is set to a high value, the increase of the internal dynamic change rate Tint will have a stronger driving effect on the increase of the first comprehensive anomaly score Sint; which represents that the system detects an internal anomaly event with a large deviation amplitude and a severe change process.
[0040] S4 specifically comprises: constructing a two-dimensional decision space with the first comprehensive anomaly score and the second comprehensive anomaly score as orthogonal coordinate axes; simultaneously defining a real-time anomaly deviation degree coordinate point for positioning in the two-dimensional decision space based on the first comprehensive anomaly score and the second comprehensive anomaly score, and presetting a first anomaly deviation threshold and a second anomaly deviation threshold; In the two-dimensional decision space, the first anomaly deviation threshold and the second anomaly deviation threshold define two mutually orthogonal decision boundary lines, which accurately divide the two-dimensional decision space into four decision regions, including a first decision region, a second decision region, a third decision region, and a fourth decision region; The first decision region, the second decision region, the third decision region, and the fourth decision region correspond to normal state, device internal anomaly, physical space anomaly, and composite anomaly, respectively; By determining the unique decision region where the real-time anomaly deviation degree coordinate point falls, the differentiated judgment and linkage control are directly mapped and executed.
[0041] S4 specifically further comprises: The execution of differentiated judgment and linkage control has the following specific process: Normal state judgment and maintenance: when the real-time anomaly deviation degree coordinate point is located in the first decision region, it is determined that the system is in a normal state, and continuous monitoring is maintained without triggering any alarm or control; And the state at this time is jointly defined by the first anomaly deviation degree being less than or equal to the first anomaly deviation threshold, and the second anomaly deviation degree being less than or equal to the second anomaly deviation threshold; Device internal anomaly judgment and response: when the real-time anomaly deviation degree coordinate point is located in the second decision region, it is determined that the anomaly originates from the target intelligent device, and accordingly a logical layer or hardware layer security alarm for the target intelligent device is triggered; And the state at this time is jointly defined by the first anomaly deviation degree exceeding the first anomaly deviation threshold and the second anomaly deviation degree not exceeding the second anomaly deviation threshold; Physical space anomaly judgment and response: when the real-time anomaly deviation degree coordinate point is located in the third decision region, it is determined that the anomaly originates from the physical space where the target intelligent device is located, and accordingly a security alarm for the home physical space is triggered; And the state at this time is jointly defined by the first anomaly deviation degree not exceeding the first anomaly deviation threshold and the second anomaly deviation degree exceeding the second anomaly deviation threshold; The determination and response of the composite anomaly: when the real-time anomaly deviation coordinate point is located in the fourth decision region, it is determined that there is a composite anomaly, and the logical layer or hardware layer security alarm for the target intelligent device and the security alarm for the home physical space are triggered at the same time to perform the highest level of security response.
[0042] The state at this time is jointly defined by the first anomaly deviation and the second anomaly deviation exceeding the respective corresponding first anomaly deviation threshold and second anomaly deviation threshold.
[0043] Further, the calculation process of the differential determination and linkage control based on the two-dimensional decision space in S4 is decomposed as follows: S4.1, obtain the decision coordinate: Obtain the first comprehensive anomaly score Sint and the second comprehensive anomaly score Sext from S3, and take them as a coordinate point in the two-dimensional decision space; S4.2, in the offline calibration stage, collect a large amount of historical data containing known anomaly events, including pure software attacks, physical interference, composite attacks and hardware failures; each data sample of the historical data contains its corresponding first comprehensive anomaly score Sint, second comprehensive anomaly score Sext and expert-labeled optimal "linkage control category"; Use supervised machine learning classification algorithms, including support vector machines (SVM), to train the historical data to find the optimal hyperplane that divides different "linkage control categories"; the learned hyperplane constitutes a set of "decision boundary functions" in the two-dimensional decision space; Expression of decision boundary: each decision boundary function is defined by a linear or nonlinear expression, which contains the first component coefficient, the second component coefficient and the boundary offset; S4.3, for the coordinate point of the first comprehensive anomaly score Sint and the second comprehensive anomaly score Sext, substitute it into the expression of each decision boundary function for calculation, specifically: Multiply the first comprehensive anomaly score Sint by the first component coefficient of the function, add the second comprehensive anomaly score Sext multiplied by the second component coefficient of the function, and finally subtract the boundary offset of the function to obtain the boundary determination value; Region positioning: according to the positive and negative combination of the boundary determination value calculated by each boundary function, the decision region identification to which the coordinate point belongs is uniquely determined, which can be represented by a numerical value quantified Chinese name; S4.4, the system binds each decision area identifier with a specific set of linkage control instructions through a preset area control mapping table; when the decision area identifier to which the real-time coordinate point belongs is determined, the corresponding linkage control instruction set is executed, including no operation, log recording, sending priority alarm, isolating device network, cutting off device power supply, and triggering home security alarm; Further, the technical effects and logical rationality in S4 are explained as follows: For clarity, the numerical values used in this embodiment are quantified and the Chinese names and letter symbols are identified, including the first comprehensive abnormality score Sint, the second comprehensive abnormality score Sext, the decision boundary function f i , the first component coefficient a i , the second component coefficient b i , the boundary offset c i , the boundary determination value V i , and the decision area identifier Rid, wherein i represents the index of the decision boundary function, the first component coefficient, the second component coefficient, the boundary offset, and the boundary determination value; By constructing a decision mechanism based on a two-dimensional decision space, complex abnormality patterns composed of different combinations of the first comprehensive abnormality score Sint and the second comprehensive abnormality score Sext are identified and responded to; the logical rationality and technical effects are embodied through the following algorithm derivation process: Initial source: the core idea of S4 in this embodiment is derived from the classification algorithm in the field of machine learning, especially the support vector machine SVM or decision tree theory, aiming to find the optimal classification boundary in high-dimensional space; Suppose two linear decision boundary functions f are obtained through training: The first decision boundary function f, i.e. f1: wherein the first component coefficient a1=0.5, the second component coefficient b1=0.5, and the boundary offset c1=0.6; The calculation formula is: V1 equals the first comprehensive abnormality score Sint multiplied by 0.5 plus the second comprehensive abnormality score Sext multiplied by 0.5 minus 0.6; The second decision boundary function f, i.e. f2: wherein the first component coefficient a2=0.8, the second component coefficient b2=0.2, and the boundary offset c2=0.5; The calculation formula is: V2 equals the first comprehensive abnormality score Sint multiplied by 0.8 plus the second comprehensive abnormality score Sext multiplied by 0.2 minus 0.5; The area control mapping table is defined as: When (V1<0, V2<0), Rid=1, which represents normal at this time; When (V1≥0, V2<0), Rid=2, which represents physical space alarm at this time; When (V1<0, V2≥0), Rid=3, which represents a logical alarm of the device; When (V1≥0, V2≥0), Rid=4, which represents the highest level alarm; Set scene one: pure software attack, S3 calculates the first comprehensive abnormal score Sint=0.8 and the second comprehensive abnormal score Sext=0.1.
[0044] At this time, V1<0; At this time, V2≥0; The determination result is (V1<0, V2≥0), which matches the decision area identifier Rid=3, and triggers a logical alarm of the device; Set scene two: physical environment anomaly, S3 calculates the first comprehensive abnormal score Sint=0.2 and the second comprehensive abnormal score Sext=0.9.
[0045] At this time, V1<0; At this time, V2<0; The determination result is (V1<0, V2<0), which matches the decision area identifier Rid=1, and is determined as normal; this shows that the decision boundary design considers this combination risk to be low, which reflects the refinement of the strategy; if an alarm is needed for this scenario, the decision boundary function needs to be adjusted.
[0046] In this embodiment, the first comprehensive abnormal score Sint and the second comprehensive abnormal score Sext are both dimensionless values in the interval [0, 1], and the first component coefficient a, the second component coefficient b, and the boundary offset c are dimensionless parameters obtained by training; The output decision area identifier Rid is a discrete category identifier and does not have a continuous value range, but the decision area it represents is a division on a two-dimensional plane formed by the value range [0, 1]x[0, 1] of the first comprehensive abnormal score Sint and the second comprehensive abnormal score Sext; When the (first comprehensive abnormal score Sint, second comprehensive abnormal score Sext) coordinate point is (0, 0), the boundary determination value V i of all boundary functions is the negative boundary offset c i , as long as the boundary offset c i is positive, the point must fall into the "negative" side space defined by all boundary functions, which is usually defined as the "normal" area, i.e., the output decision area identifier Rid=1; When the (first comprehensive abnormal score Sint, second comprehensive abnormal score Sext) coordinate point is (1, 1), the boundary determination value V ithe value of which is the largest, the point falls into the "positive" side space defined by all the boundary functions, which is usually defined as the highest risk decision region, i.e. the output decision region identification Rid=4; Further, when the (first comprehensive anomaly score Sint, second comprehensive anomaly score Sext) coordinate point is far away from the origin (0, 0) and crosses multiple decision boundaries: this indicates that one or both of the anomaly components are significantly increasing; as the coordinate point moves, it enters different decision regions, triggering different types and levels of linkage control; When the (first comprehensive anomaly score Sint, second comprehensive anomaly score Sext) coordinate point approaches the origin (0, 0): this indicates that both the first comprehensive anomaly score Sint and the second comprehensive anomaly score Sext components approach 0 at the same time, indicating that the system is in a stable and normal state; at this time, the coordinate point must be located in the core normal region surrounded by all decision boundaries, and will not trigger any alarm or control.
[0047] Embodiment two: Please refer to Figure 2 An abnormal fluctuation detection system for real-time data streams, comprising the following modules: A multi-source signal acquisition module determines a target smart device in a home gateway, and acquires physical layer companion signals generated by the target smart device when communicating on the network, including conductive physical characteristics and radiative physical characteristics; A normal behavior modeling module respectively for the conductive physical characteristics and the radiative physical characteristics, constructs baseline models for representing the normal working state of the target smart device, wherein: For conductive physical characteristics, a first baseline model is constructed for defining the stable correlation between them and network traffic data; For the radiative physical characteristics, a second baseline model is constructed for defining their own stable time sequence mode; An abnormal deviation calculation module inputs the real-time acquired physical layer companion signals into the corresponding baseline model to calculate the abnormal deviation degree, including the first abnormal deviation degree and the second abnormal deviation degree; A decision and linkage control module analyzes and evaluates the first abnormal deviation degree and the second abnormal deviation degree respectively, and then performs differentiated judgment and linkage control according to the source of the abnormal deviation degree, including selectively triggering a logical layer security alarm for the target smart device, a security alarm for the home physical space, and simultaneously triggering a security alarm in the case of composite anomaly of the target smart device and the home physical space.
[0048] In order to verify the effectiveness of the method in distinguishing different types of abnormal events and executing accurate responses, the following experiments are designed and performed: The experimental environment is built on a standard home network test platform, a commercially available mainstream brand of intelligent security camera is selected as the target intelligent device, and the monitoring gateway is deployed on an edge computing device equipped with a customized Linux system. The device is equipped with a high-precision current sensor to collect the conductive physical characteristics, i.e., device power consumption, and a wideband radio frequency receiver to collect the radiative physical characteristics, i.e., the electromagnetic spectrum around the Wo-Fi signal; Before the experiment, the target device has been stably running for 72 hours in the normal working mode including daytime recording, night infrared recording, and PTZ rotation, to ensure that the first baseline model and the second baseline model have completed sufficient initial training. In the offline calibration stage, by injecting historical attack samples and simulating hardware failure data, the contribution of abnormal features is evaluated by using the power consumption feature principal component analysis (PCA) method; The analysis results show that for sudden and high-risk malware injection events, the dynamic change of abnormal deviation is a more critical discriminant feature than the static deviation amplitude. Based on this, the general contribution weight is determined: The amplitude component weight Wm is 0.4, and the dynamic component weight Wn is 0.6; At the same time, using the (first comprehensive abnormal score Sint, second comprehensive abnormal score Sext) coordinate point data set containing various labeled events, two optimal linear decision boundary functions f1 and f2 are trained and solidified by support vector machine (SVM) algorithm, and their parameters are: f1 (a1=0.5, b1=0.5, c1=0.6) and f2 (a2=0.8, b2=0.2, c2=0.5); The experiment simulates six typical scenarios, collects data in real time and inputs into the deployed detection system, records the comprehensive abnormal score calculation process of the abnormal deviation calculation module and the decision-making results of the decision-making and linkage control module, to verify the technical effect of the invention; Parameter name Normal operating state Simulate hardware aging Simulate malware injection Simulate physical shielding interference Simulate composite attack Simulate slow data theft Internal abnormal amplitude Mint 0.05 0.70 0.80 0.10 0.90 0.60 Internal dynamic change rate Tint 0.02 0.10 0.90 0.15 0.85 0.70 External abnormal amplitude Mext 0.04 0.05 0.10 0.90 0.80 0.10 External dynamic change rate Text 0.03 0.05 0.12 0.80 0.80 0.15 First comprehensive abnormal score Sint 0.03 0.34 0.86 0.13 0.87 0.66 Second comprehensive abnormal score Sext 0.03 0.05 0.11 0.84 0.80 0.13 Boundary determination value V1 -0.57 -0.41 -0.11 -0.12 0.24 -0.21 Boundary determination value V2 -0.49 -0.21 0.18 -0.32 0.36 0.05 Decision area identifier Rid 1 1 3 1 4 3 System linkage control result State normal State normal Trigger device logical alarm State normal Trigger highest level alarm Trigger device logical alarm
[0049] Data analysis and conclusion: The ability to distinguish abnormality with the same amplitude but different properties: comparing simulated hardware aging and simulated malware injection, the internal abnormal amplitude Mint is similar, but due to the huge difference in dynamic change rate Tint, the first comprehensive abnormal score Sint is 0.34 and 0.86 respectively. This makes the system successfully determine the slow and low-risk aging process as normal, while accurately identifying and triggering the device logic alarm for the sudden and high-risk malware injection, demonstrating the advantage of the invention in deeply describing the nature of abnormal events by integrating dynamic features; Precise traceability and differentiated response: In the "simulated physical shielding interference" scenario, the first comprehensive anomaly score Sint is extremely low, while the second comprehensive anomaly score Sext is extremely high; although the abnormality degree of this combination is high, according to the decision boundary function, the coordinate point falls in the normal region, which reflects the strategy of the decision model - that is, the risk level of pure external physical interference is not high, which avoids false positives; in the "simulated malicious software injection", the first comprehensive anomaly score Sint is much higher than the second comprehensive anomaly score Sext, and the system accurately judges that it is an internal problem of the device; In the "simulated composite attack", the first comprehensive anomaly score Sint and the second comprehensive anomaly score Sext are both high, and the system triggers the highest level of composite alarm; this proves that the two-dimensional decision space can effectively distinguish the source of the anomaly and execute precise differentiated response; Sensitivity to new attacks: In the "simulated slow data theft" scenario, the original indicators may not be extreme, but the first comprehensive anomaly score Sint after fusion with dynamic features reaches 0.66, which is enough to make its coordinate point cross the decision boundary f2 and trigger the device logic alarm; This shows that the method of the application also has high detection sensitivity to slow and stealthy attacks that are difficult to detect by traditional single static threshold-based methods.
[0050] It should be noted that: all the calculation formulas in the present application file use regression analysis including but not limited to machine learning algorithms to analyze the collected relevant parameters in depth, identify their natural trends and mutual relationships. Professional software such as Python's Scikit-learn library or R language is used to automatically generate mathematical models that match the data. Then, the performance of the model is objectively evaluated through cross-validation and other methods, and combined with continuous feedback and optimization to ensure that the created formula truly reflects the internal law of the data, thereby ensuring its effectiveness and accuracy. In all the calculation formulas in the present application, the parameters in each formula are processed by consistent range of dimensionless to ensure that different physical quantities are compared on the same scale; the dimensionless technique includes but is not limited to Min-Max-Normalization, Z-Score standardization; The technical solutions of the present application can be embodied in the form of a software product, which can be stored in a computer-readable storage medium such as a computer's floppy disk, read-only memory (ROM), random access memory (RAM), FLASH, hard disk or optical disk, etc., including a number of instructions to make a computer device (which can be a personal computer, server, or network device, etc.) execute the methods of various embodiments of the present application.
[0051] The logic and / or steps represented in flow diagrams or otherwise described herein, for example, can be considered as a sequence of executable instructions, and can be embodied in any computer-readable medium for use by or in connection with an instruction execution system, apparatus, or device, such as a computer-based system, processor-containing system, or other system that can fetch the instructions from the instruction execution system, apparatus, or device and execute the instructions. For purposes of this specification, a "computer-readable medium" can be any apparatus that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus, or device. The computer-readable medium can be, for example but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples (a non-exhaustive list) of the computer-readable medium include an electrical connection, hard-wired
[0052] It should be noted that the above-mentioned embodiments are only used to illustrate but not to limit the technical solutions of the present application, and although the present application has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or equivalent replaced without departing from the spirit and scope of the technical solutions of the present application, and they should be covered in the scope of the claims of the present application.
Claims
1. A method for detecting abnormal fluctuations in real-time data streams, characterized in that: Includes the following steps: S1. Identify the target smart device in the home gateway and collect the physical layer associated signals generated by the target smart device during network communication, including conductive physical characteristics and radiative physical characteristics; S2. Construct baseline models to characterize the normal operating state of the target intelligent device, respectively, for the conductive physical characteristics and the radiative physical characteristics, wherein: For the conductive physical characteristics, a first baseline model is constructed to define the stable correlation between them and network traffic data; For the aforementioned radioactive physical characteristics, a second baseline model is constructed to define its own stable temporal patterns; S3. Input the real-time acquired physical layer associated signals into the corresponding baseline model to calculate the anomaly deviation, including the first anomaly deviation and the second anomaly deviation. S4. Analyze and evaluate the first abnormal deviation and the second abnormal deviation respectively, and then perform differentiated judgment and linkage control according to the source of the abnormal deviation, including selectively triggering logical layer security alarms for target smart devices, security alarms for home physical spaces, and simultaneously triggering security alarms under the combined abnormality of target smart devices and home physical spaces.
2. The method for detecting abnormal fluctuations in real-time data streams according to claim 1, characterized in that: S1 specifically includes: After identifying the target smart device in the home gateway, a signal validity index is first calculated to characterize the data quality of this synchronous acquisition task. When the signal validity index is higher than a preset quality threshold, the acquisition and storage of the physical layer accompanying signal are then performed as the data source for subsequent baseline model construction.
3. The method for detecting abnormal fluctuations in real-time data streams according to claim 2, characterized in that: S1 specifically also includes: The specific acquisition process of physical layer associated signals is as follows: In a database used for baseline model training, create a new data record entry; store the conductive and radiometric physical characteristics acquired during this synchronous acquisition period into the corresponding fields of the new data record entry; For new data record entries, the calculated value of the signal effectiveness index and the precise timestamp of the current acquisition period are stored as metadata in the new data record entries for subsequent data tracing and model iteration. When the signal validity index is lower than the quality threshold, the data of the current acquisition cycle is determined to be invalid, and a data discard operation is performed, that is, the buffer area used to temporarily store the data acquired in this cycle is cleared, and the physical layer associated signal data acquired in this cycle is not written into the database.
4. The method for detecting abnormal fluctuations in real-time data streams according to claim 3, characterized in that: S2 specifically includes: For the conductive physical characteristics and the radiative physical characteristics, baseline models are constructed to adaptively adjust and fuse contextual information, respectively. This includes updating the definition of the normal working state of the target intelligent device in a confidence-weighted manner when the baseline model gradually drifts in the normal operating mode, while effectively suppressing the contamination of the baseline by abnormal data. Specifically, by assessing the degree of deviation of the data to be updated and using it as part of the model update confidence, the contribution weight of the data to be updated to the baseline model parameter update is dynamically adjusted, so that only data that conforms to the current normal pattern participates in the baseline iteration.
5. The method for detecting abnormal fluctuations in real-time data streams according to claim 4, characterized in that: S2 specifically includes: Constructing the first baseline model includes: constructing a multidimensional correlation model based on the conductive physical characteristics and network traffic data, and calculating the model update confidence based on the data quality, timeliness and consistency with the current model of the newly collected data, and adaptively updating the parameters of the multidimensional correlation model with weighted model update confidence. Constructing the second baseline model includes: building a time-series pattern learning model based on the radiation physical characteristics, and calculating the model update confidence based on the data quality, timeliness, and consistency with the current model of the newly acquired data, and using the confidence to adaptively update the parameters of the time-series pattern learning model in a weighted manner.
6. The method for detecting abnormal fluctuations in real-time data streams according to claim 5, characterized in that: S3 specifically includes: For the first abnormal deviation and the second abnormal deviation, not only is the static magnitude of the deviation calculated, but also the time dynamic characteristics of the deviation are further calculated. Subsequently, the static amplitude and time dynamic features are fused together using preset contribution weights to generate a first comprehensive anomaly score and a second comprehensive anomaly score for characterizing the nature of the abnormal event.
7. The method for detecting abnormal fluctuations in real-time data streams according to claim 6, characterized in that: S3 specifically includes: The static amplitude and time dynamic characteristics are specifically defined by preset contribution weights as follows: Based on the real-time collected network traffic data patterns, the predefined business state of the target smart device can be identified. From a pre-built weight strategy library, a set of contribution weights matching the predefined business state is called, wherein the weight strategy library contains multiple sets of contribution weights that correspond one-to-one with different predefined business states; and the called set of contribution weights is used to perform weighted calculation on the static amplitude and the time dynamic features to generate the first comprehensive anomaly score and the second comprehensive anomaly score.
8. The method for detecting abnormal fluctuations in real-time data streams according to claim 7, characterized in that: S4 specifically includes: A two-dimensional decision space is constructed with the first comprehensive anomaly score and the second comprehensive anomaly score as orthogonal coordinate axes; at the same time, based on the first comprehensive anomaly score and the second comprehensive anomaly score, a real-time anomaly deviation coordinate point is defined for positioning in the two-dimensional decision space, and a first anomaly deviation threshold and a second anomaly deviation threshold are preset. In the two-dimensional decision space, the first abnormal deviation threshold and the second abnormal deviation threshold define two mutually orthogonal decision boundary lines, which precisely divide the two-dimensional decision space into four decision regions, including the first decision region, the second decision region, the third decision region and the fourth decision region. The first decision area, the second decision area, the third decision area, and the fourth decision area correspond to the normal state, the internal equipment abnormality, the physical space abnormality, and the combined abnormality, respectively. By determining the unique decision region into which the real-time abnormal deviation coordinate point falls, differentiated judgment and linkage control are directly mapped and executed.
9. The method for detecting abnormal fluctuations in real-time data streams according to claim 8, characterized in that: S4 also includes: The specific process for determining and controlling the differentiated execution is as follows: Determination and maintenance of normal state: When the real-time abnormal deviation coordinate point is located in the first decision area, the system is determined to be in a normal state and will maintain continuous monitoring without triggering any alarms or controls. Determination and response to internal device anomalies: When the real-time anomaly deviation coordinate point is located in the second decision area, the anomaly is determined to originate from inside the target intelligent device, and a security alarm for the logic layer or hardware layer of the target intelligent device is triggered accordingly. Physical space anomaly determination and response: When the real-time anomaly deviation coordinate point is located in the third decision area, the anomaly is determined to originate from the physical space where the target smart device is located, and a security alarm for the home physical space is triggered accordingly. Judgment and response to composite anomalies: When the real-time anomaly deviation coordinate point is located in the fourth decision area, it is determined that there is a composite anomaly, and accordingly, a security alarm at the logic layer or hardware layer for the target smart device and a security alarm for the home physical space are triggered simultaneously to execute the highest level of security response.
10. A system for detecting abnormal fluctuations in real-time data streams, comprising a method for detecting abnormal fluctuations in real-time data streams according to any one of claims 1-9, characterized in that, Includes the following modules: The multi-source signal acquisition module identifies the target smart device in the home gateway and acquires the physical layer associated signals generated by the target smart device during network communication, including conductive physical characteristics and radiative physical characteristics. The normal behavior modeling module constructs baseline models to characterize the normal operating state of the target intelligent device, targeting both the conductive and radiative physical characteristics, respectively. For the conductive physical characteristics, a first baseline model is constructed to define the stable correlation between them and network traffic data; For the aforementioned radioactive physical characteristics, a second baseline model is constructed to define its own stable temporal patterns; The abnormal deviation calculation module inputs the real-time acquired physical layer associated signals into the corresponding baseline model to calculate the abnormal deviation degree, including the first abnormal deviation degree and the second abnormal deviation degree. The decision-making and linkage control module analyzes and evaluates the first and second abnormal deviations respectively, and then performs differentiated judgment and linkage control according to the source of the abnormal deviations, including selectively triggering logical layer security alarms for target smart devices, security alarms for home physical spaces, and simultaneously triggering security alarms under combined abnormalities of target smart devices and home physical spaces.
Citation Information
Patent Citations
Analysis method of equipment time series data based on industrial internet
CN115203249A