An abnormality detection method for long-time large-capacity recording of a digital oscilloscope

By using high-speed ADC sampling of a digital oscilloscope and FPGA processing, combined with multidimensional feature extraction and online incremental clustering, the problem of false alarms and missed detections caused by the slow evolution of signal features in long-term, large-capacity recordings was solved, achieving stable and reliable anomaly detection and result output.

CN122259922APending Publication Date: 2026-06-23UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
UNIV OF ELECTRONICS SCI & TECH OF CHINA
Filing Date
2026-03-16
Publication Date
2026-06-23

AI Technical Summary

Technical Problem

Existing anomaly detection methods struggle to adapt to the slow evolution of signal characteristics in long-term, high-capacity recording scenarios, leading to increased false alarms and missed detections. Furthermore, they are unable to maintain long-term stability and reliability and cannot effectively output aggregated and statistical information of abnormal events.

Method used

Parallel data streams are acquired through high-speed ADC sampling using a digital oscilloscope. Trigger alignment and multi-dimensional feature extraction are performed using an FPGA. Combined with online incremental clustering and weighted fusion, the detection criteria are dynamically adjusted to identify abnormal signals and output relevant statistical information.

Benefits of technology

It achieves stable output under long-term continuous data input conditions, reduces the risk of judgment results drifting over time, improves the reliability and interpretability of anomaly detection, and supports long-term engineering applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122259922A_ABST
    Figure CN122259922A_ABST
Patent Text Reader

Abstract

The application discloses an abnormality detection method for long-time and large-capacity recording of a digital oscilloscope, and the method comprises the following steps: acquiring a parallel sampling data stream through high-speed ADC sampling of a front end of the digital oscilloscope; performing trigger alignment processing on the parallel sampling data stream through FPGA; performing multi-dimensional feature extraction on waveform data segments after the trigger alignment; obtaining a fusion feature value through normalization and weighted fusion of the features; and further performing classification and statistics on the fusion feature value through an online incremental clustering mode, identifying abnormal waveforms according to probabilities of various features, and outputting an abnormal category and statistical information, so that stable and sustainable operation of the abnormality detection in a long-time and large-capacity recording scene is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of electronic measuring instrument technology, and more specifically, relates to an anomaly detection method for digital oscilloscopes for long-term, high-capacity recording. Background Technology

[0002] With the increasing application of time-domain measurement instruments such as oscilloscopes and waveform recorders in scenarios such as long-term monitoring, reliability assessment, and condition analysis, engineering often requires long-term continuous recording of the measured signal to form large-capacity waveform data for subsequent anomaly detection and analysis. However, in scenarios involving long-term, large-capacity recording, existing anomaly detection methods still face the following problems:

[0003] 1. Under long-term operating conditions, signal characteristics evolve slowly, and the criteria for judgment are prone to becoming invalid over time.

[0004] During long-term continuous recording, the statistical characteristics and morphological features of the measured signal will change slowly and continuously over time. These changes do not necessarily correspond to abnormal events. If the reference standard or judgment criteria for anomaly detection cannot be adjusted accordingly, the detection results are prone to drift over time.

[0005] 2. Existing anomaly detection methods rely on fixed thresholds or static rules, which are difficult to adapt to long-term evolution.

[0006] Methods based on fixed thresholds, fixed feature sets, or static judgment rules can be used in short-term or relatively stable scenarios, but when signal characteristics change slowly over a long period of time, false alarms or missed detections are likely to increase, affecting the stability and reliability of long-term operation.

[0007] 3. Normal evolution and real anomalies are intertwined in observations, making it difficult to balance false alarms and missed detections.

[0008] In long-term recordings, normal evolution manifests as slow, continuous changes, while abnormal events may present as sudden or trend-deviationing changes. Misjudging normal evolution as abnormal can lead to a buildup of false alarms; however, relaxing the criteria to reduce false alarms can increase missed detections, making it difficult to maintain consistent test results over the long term.

[0009] 4. Long-term, high-volume recording requires a low-intervention, sustainable detection and result organization and output mechanism.

[0010] Under conditions of continuous accumulation of large volumes of data, anomaly detection needs to operate long-term while maintaining consistent and traceable output. In addition to anomaly alerts, detected anomalies need to be merged and organized, and information such as anomaly category, hit count, occurrence rate, or recent occurrence status should be output for users to review, locate, and further analyze. Existing methods still have shortcomings in terms of adaptive judgment criteria, consistency of anomaly event merging, and long-term output stability.

[0011] In summary, there is an urgent need for an anomaly detection method for long-term, high-capacity recording scenarios, which can adaptively adjust with the evolution of signal characteristics and stably output anomaly prompts and information on the occurrence of anomaly events during long-term operation, thereby improving the reliability and applicability in long-term operating environments. Summary of the Invention

[0012] The purpose of this invention is to overcome the shortcomings of the prior art and provide an anomaly detection method for digital oscilloscopes for long-term, high-capacity recording. When the characteristics of the measured signal evolve slowly over time, the method achieves waveform anomaly detection through adaptive evolution of signal characteristics and outputs statistical information such as the number of hits and frequency of occurrence of various types as the basis for anomaly detection. This maintains the stability, traceability and engineering applicability of long-term operation output.

[0013] To achieve the above-mentioned objectives, the present invention provides an anomaly detection method for digital oscilloscopes used for long-term, high-capacity recording, characterized by comprising the following steps:

[0014] (1) The signal under test is input to the digital oscilloscope and sampled by the high-speed ADC at the front end to obtain the parallel sampling data stream; the parallel sampling data stream is divided into two paths. The first parallel sampling data stream is written to a large-capacity solid-state storage medium SSD for storage, and the other parallel sampling data stream is input to the FPGA.

[0015] (2) Trigger alignment processing is performed on the parallel sampling data stream through FPGA to obtain multiple frames of data segments after trigger alignment and timestamps aligned with the first parallel sampling data stream;

[0016] (3) Extract multi-dimensional features from the multi-frame data segments that trigger alignment, and then normalize and weighted fuse the extracted multi-dimensional features to form fused feature values;

[0017] (4) Perform online incremental clustering on a single feature value to obtain classification information, and then obtain the probability of different feature values ​​appearing based on the classification information to determine the abnormal signal; finally, based on the timestamp of the obtained abnormal signal, read the original fragment abnormal waveform from the large-capacity solid-state storage medium SSD to achieve accurate review of the complete context waveform of the original fragment.

[0018] The objective of this invention is achieved as follows:

[0019] This invention provides an anomaly detection method for long-term, high-capacity recording using a digital oscilloscope. First, a parallel sampling data stream is acquired through high-speed ADC sampling at the front end of the digital oscilloscope. Then, the parallel sampling data stream is triggered and aligned using an FPGA. Next, multi-dimensional features are extracted from the aligned waveform data segments, and the features are normalized and weighted to obtain fused feature values. Finally, online incremental clustering is used to classify and statistically analyze the fused feature values. Abnormal waveforms are identified based on the probability of occurrence of each feature, and the anomaly category and its statistical information are output, thereby achieving stable and sustainable anomaly detection in long-term, high-capacity recording scenarios.

[0020] Meanwhile, the anomaly detection method for long-term, high-capacity recording using a digital oscilloscope according to the present invention also has the following beneficial effects:

[0021] (1) The present invention can run continuously and output stable detection results associated with waveform segments under long-term continuous data input conditions, meeting the engineering application requirements of long-term operation.

[0022] (2) This invention achieves dynamic adjustment of the anomaly detection reference benchmark and judgment criteria over time by performing online statistics and adaptive updates on signal features, so as to adapt to the slow evolution of signal features and reduce the risk of judgment results drifting over time during long-term operation.

[0023] (3) The present invention categorizes and organizes the detected abnormal events according to feature similarity to form an abnormal category (or abnormal pattern), and outputs the abnormal category identifier and related information to improve the interpretability and analyzability of abnormal results recorded over a long period of time, and facilitates playback, location and comparison verification.

[0024] (4) This invention outputs information on the occurrence of each anomaly category during long-term operation, including the number of hits, the occurrence ratio, the most recent occurrence time or the occurrence interval, etc., so that users can pay attention to and deal with the anomaly category in combination with specific application rules, thereby reducing the cost of manual sorting and improving the engineering availability under long-term operation conditions. Attached Figure Description

[0025] Figure 1 This is a schematic diagram illustrating the structure of the long-term recording anomaly detection system of the present invention.

[0026] Figure 2 This is a flowchart of an anomaly detection method for long-term, high-capacity recording using a digital oscilloscope, according to the present invention.

[0027] Figure 3 This is an illustrative diagram illustrating the fixed-level segmented waveform based on the present invention;

[0028] Figure 4a This is a schematic diagram of the normal waveform of the present invention.

[0029] Figure 4b This is the abnormal waveform with a sudden increase in amplitude captured by the present invention.

[0030] Figure 4c This is the glitch abnormal waveform captured by the present invention.

[0031] Figure 4d This is the abnormal waveform shape of the present invention. Detailed Implementation

[0032] The specific embodiments of the present invention will now be described with reference to the accompanying drawings to enable those skilled in the art to better understand the invention. It should be particularly noted that in the following description, detailed descriptions of known functions and designs that might obscure the main content of the invention will be omitted here.

[0033] Example

[0034] In this embodiment, taking the long-term monitoring scenario of the output ripple signal of a power module as an example, the present invention describes an anomaly detection method for long-term, large-capacity recording using a digital oscilloscope.

[0035] During power supply reliability testing, it is necessary to continuously record and detect anomalies in the power supply output ripple signal over a long period of time. The test time usually lasts from several hours to several days, during which transient disturbances, abnormal oscillations, or sudden noise increases may occur. Traditional manual inspection or fixed threshold detection methods are difficult to maintain stable anomaly identification capabilities during long-term operation. Therefore, the method of this invention is used for automatic detection.

[0036] This embodiment uses a certain model of digital oscilloscope for data acquisition, and its main parameters are as follows.

[0037] Table 1 Oscilloscope acquisition parameter settings;

[0038] parameter numerical values Sampling rate 2GS / s Sampling resolution 12bit Single frame recording length 4096 points Pre-trigger depth 1024 points Triggering method Rising edge triggered Number of frames captured 10000

[0039] In this embodiment, a schematic diagram of the long-term recording anomaly detection system is shown, as follows: Figure 1 As shown; we combine Figure 1 This paper provides a detailed description of an anomaly detection method for digital oscilloscopes used for long-term, high-capacity recording, such as... Figure 2 As shown, the specific process includes the following steps:

[0040] (1) The signal under test is input to the digital oscilloscope and digitized by the high-speed ADC at a sampling rate of 2GS / s to form a continuous parallel 4-channel sampling data stream; then the parallel sampling data stream is divided into two channels. The first parallel sampling data stream is written to a large-capacity solid-state storage medium SSD for storage through the high-speed data bus, and the other parallel sampling data stream is input to the FPGA for real-time processing.

[0041] (2) Trigger alignment processing is performed on the parallel sampling data stream through FPGA to obtain multiple frames of data segments after trigger alignment and timestamps aligned with the first parallel sampling data stream;

[0042] (2.1) Configure the pre-trigger depth of the FIFO The FIFO has 1024 points, and its programmable full threshold is configured to be the number of points in a single segment. The value is 4096;

[0043] Set the FIFO trigger condition: edge-triggered;

[0044] (2.2) The parallel sampling data stream is input to the FPGA through the high-speed interface. The FPGA writes the sampling data into the buffer FIFO. Before the number of points written to the FIFO reaches the pre-trigger depth of 1024, the FIFO only performs writing and does not perform reading. When the FIFO write reaches the pre-trigger depth of 1024 and the trigger condition is not met, the FIFO enters the circular buffer mode, writing and reading at the same time to maintain the pre-trigger data depth in the FIFO constant. When the trigger condition is met, the FIFO stops reading and continues to write subsequent sampling data until the FIFO reaches the programmable full threshold. Then the FIFO pulls up the frame reset signal and stops the FIFO writing operation, resulting in a frame of 4096-point parallel output data segment.

[0045] (2.3) After a data segment is output, the FIFO pulls the frame reset signal low again to unlock the FIFO write operation, and then returns to step (2.2) to start the acquisition of the next frame of data until the M-frame data segment is acquired.

[0046] (3) Extract multi-dimensional features from the multi-frame data segments that trigger alignment, and then normalize and weighted fuse the extracted multi-dimensional features to form fused feature values;

[0047] (3.1) Extract the temporal and energy features of each data segment using the feature extraction module inside the FPGA;

[0048] Among them, the Frame data fragment The time-domain characteristics include: mean ,variance and peak value ;

[0049] ;

[0050] ;

[0051] ;

[0052] No. Frame data fragment Energy characteristics for:

[0053] ;

[0054] in, Representing data fragments The Middle The sampled values ​​of each sampling point;

[0055] Table 2 shows examples of feature extraction results for some frame data.

[0056] Table 2. Example of feature extraction;

[0057] Frame number mean variance Peak-to-peak value energy 1 0.021 0.013 0.48 36.5 2 0.020 0.014 0.46 35.9 3 0.022 0.012 0.47 36.1 4 0.051 0.016 0.89 56.1

[0058] (3.2) Regarding the mean ,variance Peak-to-peak value and energy Find the maximum value for each;

[0059] ;

[0060] ;

[0061] ;

[0062] ;

[0063] (3.3) Eigenvalue normalization:

[0064] ;

[0065] ;

[0066] ;

[0067] ;

[0068] (3.4) Based on the weights issued by the host computer, the normalized feature values ​​are weighted and fused to obtain the fused feature values. ;

[0069]

[0070] in, They are respectively The corresponding weights, and satisfying: .

[0071] (4) Perform online incremental clustering on a single feature value to obtain classification information, and then obtain the probability of different feature values ​​appearing based on the classification information to determine anomalies. The specific process is as follows:

[0072] (4.1) Set the number of cluster centers to K=16 and initialize the hit count of each cluster center to 0;

[0073] Initialize the set of abnormal cluster centers The empty flag is 1.

[0074] Each cluster center is assigned a corresponding data segment waveform storage RAM to store the data segments;

[0075] (4.2) Store each cluster center in the FPGA register, with one cluster center stored in one register;

[0076] (4.3) The FPGA fuses the feature values ​​of the first frame data segment. Directly used as the set of cluster centers The first central value, namely: ,Will Increase the number of hits by 1: Set the cluster centers The null flag is changed to 0, and the first frame data segment is stored in RAM1;

[0077] then, At that time, the FPGA calculates the first Fusion feature values ​​of frame data segments With cluster center set All cluster centers Distance: ;

[0078] Take the cluster center value corresponding to the minimum distance: ,like Then Classified as an existing cluster center Then update the corresponding cluster center values. And increment the corresponding cluster center hit count by 1, that is: Then the first Frame data fragments overwritten in the corresponding In the middle; if Then first determine the cluster center set. Are there any unclassified cluster centers? If so, then the first cluster center will be... A frame data fragment is stored in the cluster center, the hit count of the cluster center is incremented by 1, and the th... The frame data fragment is stored in the RAM corresponding to the cluster center; if there are no more unclassified cluster centers, i.e., the cluster center set... If all cluster centers in the first cluster have already been classified, then the first cluster is considered to be in the first cluster. Frame data fragments are not included in the cluster center set If all cluster centers are absorbed, then only one independent register is used to count the number of anomalies;

[0079] (4.4) After the M-frame data segment is processed, the host computer reads the hit count of each cluster center from the FPGA through the high-speed communication interface. Then calculate the hit probability corresponding to each cluster center. :

[0080] ;

[0081] Examples of clustering statistics are shown in Table 3.

[0082] Cluster Center Number of hits Hit probability C1 9840 98.40% C2 90 0.90% C3 50 0.50% C4 20 0.20% C5 0 0 C6 0 0 C7 0 0 C8 0 0 C9~C16 0 0

[0083] Finally, the host computer extracts the timestamps of the data segments corresponding to the abnormal flag bits, and retrieves the corresponding data locations in the large-capacity solid-state storage medium SSD based on the timestamps, so as to achieve accurate review of the details of the original waveform.

[0084] In this embodiment, after performing online incremental clustering on 10,000 frames of waveform data, only 4 cluster centers were hit, and the remaining cluster centers were not absorbed by the data segments. C1 represents the main waveform pattern under normal system operation; C2, C3, and C4 represent three types of abnormal waveform patterns that appeared during long-term monitoring. Since C2 (0.90%), C3 (0.50%), and C4 (0.20%) are all below the 1% abnormal threshold set by the host computer, C2, C3, and C4 are determined to be abnormal categories. The system reads the data segments stored in the RAM of the corresponding cluster centers and outputs abnormal flag information, while recording the number of hits and the probability of occurrence of each abnormal category. As shown in Figure 4, among the detected abnormal waveform examples, Figure 4(a) is a normal waveform, Figure 4(b) shows a waveform amplitude abrupt increase abnormality, Figure 4(c) shows a waveform with spikes abnormality, and Figure 4(d) shows a waveform morphology abrupt change abnormality.

Claims

1. A digital oscilloscope method for detecting an anomaly in a long-time large-capacity recording, characterized by, Includes the following steps: (1) The signal under test is input to the digital oscilloscope and sampled by the high-speed ADC at the front end to obtain the parallel sampling data stream; the parallel sampling data stream is divided into two paths. The first parallel sampling data stream is written to a large-capacity solid-state storage medium SSD for storage, and the other parallel sampling data stream is input to the FPGA. (2) Trigger alignment processing is performed on the parallel sampling data stream through FPGA to obtain multiple frames of data segments after trigger alignment and timestamps aligned with the first parallel sampling data stream; (3) Extract multi-dimensional features from the multi-frame data segments that trigger alignment, and then normalize and weighted fuse the extracted multi-dimensional features to form fused feature values; (4) Perform online incremental clustering on a single feature value to obtain classification information, and then obtain the probability of different feature values ​​appearing based on the classification information to determine the abnormal signal; finally, based on the timestamp of the obtained abnormal signal, read the original fragment abnormal waveform from the large-capacity solid-state storage medium SSD to achieve accurate review of the complete context waveform of the original fragment.

2. The anomaly detection method for long-duration, high-capacity recording using a digital oscilloscope according to claim 1, characterized in that, The specific processing flow of step (2) is as follows: (2.1) Configure the pre-trigger depth of RAM as follows: Configure the length of a single data frame as ; Set the trigger condition for the acquired waveform to edge triggering; (2.2) The parallel sampling data stream is input to the FPGA through a high-speed interface. The memory controller starts writing waveform data from address 0 of the RAM. When the written data has not reached the specified address... Previously, only data write operations were performed without triggering a check; when the written data reached... Then, a trigger check is performed. Before a trigger signal is detected, data is continuously written to the RAM space. When the maximum address is reached, a cyclic overwrite write operation is performed on the RAM. When the set trigger condition is met, the current write address is recorded as the trigger address. It continues to write subsequent sampled data until the cumulative collected data reaches [a certain value]. point; When the written data reaches the set frame length When the system generates a frame completion signal, it stops the write operation and proceeds according to the trigger address. and and Calculate the starting address of the trigger segment. and end address The waveform data is read from the start and end addresses to obtain a complete data frame, and the data segment of that frame is output. ; (2.3) After a data segment is output, the system re-initializes the write address and control state, releases the RAM write operation lock, and then returns to step (2.2) to start the acquisition of the next data segment until M data segments are acquired.

3. The anomaly detection method for long-duration, high-capacity recording using a digital oscilloscope according to claim 1, characterized in that, The specific processing flow of step (3) is as follows: (3.1) Extract the temporal and energy features of each data segment using the feature extraction module inside the FPGA; Among them, the Frame data fragment The time-domain characteristics include: mean ,variance and peak value ; ; ; ; No. Frame data fragment Energy characteristics for: ; in, Representing data fragments The Middle The sampled values ​​of each sampling point; (3.2) Regarding the mean ,variance Peak-to-peak value and energy Find the maximum value for each; ; ; ; ; (3.3) Eigenvalue normalization: ; ; ; ; (3.4) Based on the weights issued by the host computer, the normalized feature values ​​are weighted and fused to obtain the fused feature values. ; ; in, They are respectively The corresponding weights, and satisfying: .

4. The anomaly detection method for long-duration, high-capacity recording using a digital oscilloscope according to claim 1, characterized in that, The specific processing flow of step (4) is as follows: (4.1) Set up the set of abnormal cluster centers , Indicates the first Cluster centers, Indicates the number of cluster centers; Initialize the set of abnormal cluster centers The null flag is set to 1, initialized. Empty, initialize Corresponding number of hits =0; Each cluster center is assigned a data segment waveform storage RAM to store the data segment and its corresponding timestamp. (4.2) will Each cluster center is stored in the FPGA. In each register, one cluster center is stored. (4.3) The FPGA fuses the feature values ​​of the first frame data segment. Directly used as the set of cluster centers The first central value, namely: ,Will Increase the number of hits by 1: Set the cluster centers The null flag is changed to 0, and the first frame data segment is stored in RAM1; then, At that time, the FPGA calculates the first Fusion feature values ​​of frame data segments With cluster center set All cluster centers Distance: ; Take the cluster center value corresponding to the minimum distance: ,like Then Classified as an existing cluster center Then update the corresponding cluster center values. And increment the corresponding cluster center hit count by 1, that is: Then the first Frame data fragments overwritten in the corresponding In the middle; if Then first determine the cluster center set. Are there any unclassified cluster centers? If so, then the first cluster center will be... A frame data fragment is stored in the cluster center, the hit count of the cluster center is incremented by 1, and the th... The frame data fragment is stored in the RAM corresponding to the cluster center; if there are no more unclassified cluster centers, i.e., the cluster center set... If all cluster centers in the first cluster have already been classified, then the first cluster is considered to be in the first cluster. Frame data fragments are not included in the cluster center set If all cluster centers are absorbed, then only one register is used to count the number of anomalies; (4.4) After the M-frame data segment is processed, the host computer reads the hit count of each cluster center from the FPGA through the high-speed communication interface. Then calculate the hit probability corresponding to each cluster center. : ; upper computer for each Sort the samples and select those with a probability lower than a preset probability threshold. The cluster centers are used as anomaly categories, and then the data segments stored in the RAM associated with the corresponding anomaly categories are read, and anomaly flags are added before output. In addition, for data segments that were not absorbed by the cluster centers, the host computer also reads the anomaly count value and records it as... Then calculate the corresponding anomaly probability. : ; If the abnormal probability If the pre-set abnormality ratio threshold is exceeded, an abnormality flag will be output. Meanwhile, the host computer extracts the timestamps of the data segments corresponding to the abnormal flag bits, and retrieves the corresponding data locations in the large-capacity solid-state storage medium SSD based on the timestamps, so as to achieve accurate review of the details of the original waveform.