Anomaly detection apparatus, program, and anomaly detection method
The anomaly detection device employs a deep learning model with a sparsely structured graph structure to enhance the accuracy of identifying equipment failure causes, addressing inefficiencies in existing methods by prioritizing sensors with significant edge weights for efficient maintenance.
Patent Information
- Application Number
- JP2024140050
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-05
- Filing Date
- 2024-08-21
- Publication Date
- 2025-08-18
AI Technical Summary
Existing anomaly detection methods struggle with accurately identifying the cause of equipment failure, particularly when the sensor item with a high degree of anomaly is not the direct cause, leading to inefficient maintenance and prolonged identification times.
Anomaly detection device using a deep learning model with a sparsely structured graph structure that utilizes graph attention networks (GAT) and graph deviation networks (GDN) to estimate failure causes by rearranging sensors based on edge weights, enhancing the accuracy of factor estimation.
Improves the accuracy of identifying the cause of equipment failure by prioritizing sensors with significant edge weights, reducing maintenance inefficiencies and time, and facilitating efficient maintenance practices.
Smart Images

Figure 2025120909000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an anomaly detection device, a program, and an anomaly detection method. [Background technology]
[0002] An initiative known as "smart safety" is underway to address industrial safety in response to environmental changes such as digitalization and an aging population with a declining birthrate. One AI technology required for smart safety is predictive maintenance, a method of maintaining equipment. Predictive maintenance aims to reduce downtime and improve maintenance efficiency by detecting signs of failure or changes before a breakdown occurs and carrying out maintenance in advance. Predictive maintenance is a condition-based maintenance method that monitors the condition of equipment using information from sensors attached to the equipment and performs maintenance by identifying signs of equipment failure in advance from that information.
[0003] For example, Patent Document 1 discloses a method for creating a sparse precision matrix, which is an inverse matrix, from a correlation coefficient matrix using a graphical lasso algorithm in order to improve the accuracy of detecting anomalies in time-series data. Furthermore, in recent years, a graph deviation network (GDN) has been proposed, which is an anomaly detection method that uses a graph attention network (GAT). [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2010-078467 Summary of the Invention [Problem to be solved by the invention]
[0005] When detecting a sign of equipment failure, estimating the cause of the failure is useful for efficient maintenance work. To estimate the cause of a failure, a method is known for identifying sensor items with a high degree of anomaly (the difference between the actual measured value and the predicted value). However, the abnormality of the sensor item that is the cause of the failure is not necessarily high. Manual confirmation makes it difficult to perform efficient maintenance work. Furthermore, while the method described in Patent Document 1 can extract important features using sparse structure learning, it has difficulty in dealing with complex models. In contrast, learning a graph structure, such as a GCN (Graph Convolutional Network), using deep learning makes it possible to deal with complex models. However, the complexity of the graph structure can sometimes result in poor accuracy in cause estimation. Learning a graph structure using deep learning here means learning a method for utilizing the graph structure using deep learning.
[0006] Furthermore, while there are conventional techniques for displaying data with a high degree of anomaly, there are cases where the sensor item with a high degree of anomaly is not the direct cause. In such cases, it often takes time to identify the cause. Therefore, there is a need for a data display technique that makes it easier to identify the cause.
[0007] In view of the above, an object of the present disclosure is to provide an anomaly detection device, a program, and an anomaly detection method that can improve the accuracy of factor estimation. [Means for solving the problem]
[0008] (1) An anomaly detection device according to an embodiment of the present disclosure includes: an acquisition unit that acquires detection value data including detection values of sensors installed in the equipment; an anomaly detection unit that determines whether there is a sign of a failure in the equipment by using a learning model generated using normal data from the acquired detection value data; a factor estimation unit that, when it is determined that there is a failure sign, estimates a factor of the failure for which it is determined that there is a failure sign; The learning model is a deep learning model that uses a sparsely structured graph structure, The factor estimation unit also uses the weights of the edges of the graph structure to perform factor estimation by rearranging the sensors so that the sensor estimated to be the cause of the abnormality is placed at the top.
[0009] (2) As one embodiment of the present disclosure, in (1), The factor estimation unit performs the factor estimation by a method in which, where m is an integer equal to or greater than 1 and n is an integer equal to or greater than m, the unit searches for sensors at the start or end points of m sensors connected to each edge with the largest weight in descending order of the degree of abnormality, and then arranges the n sensors found in the order in which they were found.
[0010] (3) As one embodiment of the present disclosure, in (1), The factor estimation unit performs the factor estimation by calculating the sum of values obtained by multiplying the weight of the edge connected to each sensor by the abnormality degree of the sensor at the start or end point of that edge, where n is an integer greater than or equal to 2, sorting all sensors in order of the size of the sum, and extracting the top n sensors.
[0011] (4) As an embodiment of the present disclosure, in (1), The factor estimation unit performs the factor estimation by selecting, for each sensor, the normalized magnitude of the sum of the values obtained by multiplying the weight of the edge connected to each sensor by the abnormality degree of the sensor at the start or end of that edge, or the normalized abnormality degree, whichever is larger, where n is an integer greater than or equal to 2, and sorting all sensors in order of the magnitude of the selected value and extracting the top n sensors.
[0012] (5) A program according to an embodiment of the present disclosure includes: Computer, an acquisition unit that acquires detection value data including detection values of sensors installed in the equipment; an anomaly detection unit that determines whether there is a sign of a failure in the equipment by using a learning model generated using normal data from the acquired detection value data; when it is determined that there is a failure sign, the cause estimation unit functions as a cause estimation unit that estimates a cause of the failure for which it is determined that there is a failure sign; The learning model is a deep learning model that uses a sparsely structured graph structure, The factor estimation unit also uses the weights of the edges of the graph structure to perform factor estimation by rearranging the sensors so that the sensor estimated to be the cause of the abnormality is placed at the top.
[0013] (6) An anomaly detection method according to an embodiment of the present disclosure includes: acquiring detection value data including detection values of sensors installed in the equipment; a step of determining whether there is a sign of a failure of the equipment using a learning model generated using normal data from the acquired detection value data; and when it is determined that there is a failure sign, estimating a cause of the failure for which it is determined that there is a failure sign; The learning model is a deep learning model that uses a sparsely structured graph structure, The step of estimating the cause of the abnormality also uses the weights of the edges of the graph structure to perform cause estimation by rearranging the sensors so that the sensor estimated to be the cause of the abnormality is placed at the top.
[0014] (7) As an embodiment of the present disclosure, in any one of (1) to (4), The system further includes a display unit that displays additional information using edge weights of the graph structure superimposed on a graph of time-series data or a graph of statistics. [Effects of the Invention]
[0015] According to the present disclosure, it is possible to provide an anomaly detection device, a program, and an anomaly detection method that can improve the accuracy of factor estimation. [Brief explanation of the drawings]
[0016] [Figure 1] FIG. 1 is a functional block diagram showing a schematic configuration of an anomaly detection device according to an embodiment of the present disclosure. [Figure 2] FIG. 2 is a flowchart of a learning model generation method. [Figure 3] FIG. 3 is a diagram for explaining the weights of edges in a graph. [Figure 4] FIG. 4 is a diagram for explaining the activation function. [Figure 5] FIG. 5 is a flowchart of an anomaly detection method according to an embodiment of the present disclosure. [Figure 6] FIG. 6 is a diagram for explaining the first technique. [Figure 7] FIG. 7 is a diagram for explaining the second technique. [Figure 8] FIG. 8 is a diagram showing an example of evaluation when the facility is a water treatment facility. [Figure 9] FIG. 9 is a diagram for explaining the first data display. [Figure 10] FIG. 10 is a diagram for explaining the second data display. [Figure 11] FIG. 11 is a diagram for explaining the third data display. [Figure 12] FIG. 12 is a diagram for explaining the fourth data display. [Figure 13] FIG. 13 is a diagram for explaining the fifth data display. DETAILED DESCRIPTION OF THE INVENTION
[0017] (Anomaly detection device) FIG. 1 is a functional block diagram illustrating a schematic configuration of an anomaly detection device 10 according to an embodiment of the present disclosure. The anomaly detection device 10 is a device that performs predictive maintenance on equipment 20 and detects signs of failure in the equipment 20. In this embodiment, the anomaly detection device 10 communicates with the equipment 20 to acquire detection value data including detection values of sensors installed in the equipment 20. The anomaly detection device 10, together with the equipment 20, constitutes an anomaly detection system 1. As another example, the anomaly detection device 10 may be incorporated into the equipment 20 and integrated with the equipment 20. The anomaly detection device 10 estimates the detected signs of failure in the equipment 20 and their causes, and presents them to, for example, an administrator of the anomaly detection system 1. The administrator of the anomaly detection system 1 can efficiently perform maintenance work on the equipment 20 using the information presented by the anomaly detection device 10.
[0018] The facility 20 may be, for example, a machine, a device, an electronic device, a meter, etc. In this embodiment, the facility 20 is described as being a water treatment facility or a storage battery, but is not limited thereto.
[0019] The anomaly detection device 10 includes an acquisition unit 11, an anomaly detection unit 12, a cause estimation unit 13, a learning model generation unit 14, a storage unit 15, and a display unit 16. The configuration of the anomaly detection device 10 in FIG. 1 is an example, and some of the components may not be included. The anomaly detection device 10 may also include other components. For example, the anomaly detection device 10 may not include the learning model generation unit 14, but may instead acquire a learning model generated by another device via the acquisition unit 11 and store it in the storage unit 15. For example, the anomaly detection device 10 may not include the display unit 16, but may instead display the detected signs of failure of the equipment 20 and the causes of the failure on a display device external to the anomaly detection device 10.
[0020] In this embodiment, the processing performed by the anomaly detection device 10 can be divided into a "learning phase" and an "estimation phase." In the learning phase, the anomaly detection device 10 acquires past detection values of the sensors of the equipment 20 and generates a learning model through machine learning using training data consisting only of normal data. In the estimation phase, the anomaly detection device 10 acquires detection values of the sensors of the operating equipment 20 and uses the trained learning model to detect signs of failure in the equipment 20 (estimating the occurrence of a failure). In addition, in the estimation phase, the anomaly detection device 10 estimates the cause of the failure.
[0021] Here, the "past" detection values of the sensors of the equipment 20 acquired in the learning phase specify whether or not a failure has occurred in the equipment 20, and the details and causes of the failure that has occurred.
[0022] The acquiring unit 11 acquires detection value data including detection values of sensors provided in the facility 20. The acquiring unit 11 may acquire the detection value data using at least one of wired communication and wireless communication as a method of communication with the facility 20.
[0023] In the estimation phase, the anomaly detection unit 12 detects an anomaly in the equipment 20 based on the acquired detection value data. An anomaly is an abnormal operation, and in this embodiment, it is a change in the detection value that is mainly related to a failure. In this embodiment, the anomaly detection unit 12 uses a learning model generated using normal data (i.e., past detection values of the sensor of the equipment 20 when it is operating normally) to determine whether the detected value is a sign of a failure based on the degree of deviation from the normal data. Details of the detection method will be described later.
[0024] In the estimation phase, the cause estimation unit 13 estimates the cause of a failure that the anomaly detection unit 12 has determined to have a predictive effect. In the case of general deep learning, the inside of the learning model is a black box and difficult to interpret. In contrast, the anomaly detection device 10 according to this embodiment uses graph deep learning, and is therefore able to handle a graph having nodes (vertices) corresponding to the sensors of the equipment 20. The cause estimation unit 13 can grasp the relationship between the sensors from the graph and estimate the cause of the failure. Details of the method for estimating the cause of the failure will be described later.
[0025] In the learning phase, the learning model generation unit 14 generates a learning model using a deep learning model that utilizes a graph structure. Here, graph convolutional networks (GCN), which are one type of deep learning model that utilizes a graph structure, utilize information between adjacent nodes. Furthermore, a network (GAT) that learns by adding weights to the relationships between nodes has been proposed. The anomaly detection device 10 according to this embodiment employs an anomaly detection method that utilizes a GAT. More specifically, the learning model generation unit 14 employs a method that utilizes a graph deviation network (GDN) and further makes the weights used in the GAT sparse.
[0026] The storage unit 15 may function as a memory that stores various types of information. In this embodiment, the storage unit 15 stores the learning model generated by the learning model generation unit 14. The storage unit 15 may also store, for example, a program executed in the anomaly detection device 10. The storage unit 15 may also store results of processing executed in the anomaly detection device 10. The storage unit 15 may be configured, for example, by a semiconductor memory or the like, but is not limited to this and may be any storage device. For example, the storage unit 15 may be an internal memory of a processor included in the anomaly detection device 10, or may be an external storage device connected to the anomaly detection device 10.
[0027] The display unit 16 displays the results of estimation using the learning model in the estimation phase, i.e., the detected signs of failure in the equipment 20 and their causes, to, for example, an administrator of the anomaly detection system 1. The display unit 16 may be any type of display, such as an LCD (liquid crystal display). In this embodiment, the display unit 16 displays data that facilitates the identification of causes. The administrator can analyze causes, such as signs of failure in the equipment 20, based on this data display. As will be described in detail later, performing an action (e.g., touching, hovering a cursor, clicking, etc.) on a portion of the data display on the display unit 16 displays more detailed information. Therefore, the display unit 16 is configured to allow input by the administrator. The display unit 16 may be, for example, a touch panel display integrated with an input unit. Alternatively, for example, if the anomaly detection device 10 is a computer, the display unit 16 may be a display connected to the computer that displays a cursor that can be operated with an input device (e.g., a mouse, keyboard, etc.) of the computer.
[0028] The anomaly detection method executed by the anomaly detection device 10 configured as described above has an improvement over conventional anomaly detection using GDN in that cause estimation is performed using not only the anomaly degrees of nodes but also the weights of edges (sides). This improvement mainly contributes to an improvement in the cause estimation algorithm.
[0029] (Learning model generation method) 2 is a flowchart illustrating a learning model generation method. As described above, the learning model in this embodiment is a sparsely structured model with a graph structure having edge weights. In the learning phase, the anomaly detection device 10 executes the learning model generation method shown in FIG. 2.
[0030] The acquisition unit 11 acquires past detection value data (step S1). The past detection value data may be, for example, simulated data of a water treatment facility, and may include a time-series data set in which all points are normal over seven days of normal operation, and a time-series data set in which an abnormality occurs over four days. Alternatively, the past detection value data may be, for example, data of a storage battery configured with two storage battery modules and one power conditioner, and may be a time-series data set in which voltage, current, charge / discharge power, temperature, cell balance, and the like are normal and abnormal. The past detection value data specifies whether or not a failure occurred in the facility 20 and the type of failure that occurred at each detection time.
[0031] The learning model generation unit 14 obtains feature vectors from past detection value data and generates a graph based on the similarity of the feature vectors (step S2). In this embodiment, the learning model generation unit 14 maps the detection values of each sensor to a vector space using a known method to obtain feature vectors (embedding vectors). Furthermore, for example, cosine similarity may be used as the similarity of the feature vectors. For example, a graph may be generated by generating edges for sensors with relatively high cosine similarity.
[0032] The learning model generation unit 14 calculates the weights (attention weights) of the edges of the generated graph (step S3). FIG. 3 is a diagram for explaining the weights of edges of a graph. In FIG. 3, circles surrounding numbers indicate nodes. Arrows connecting nodes indicate edges. The learning model generation unit 14 can determine the weights of edges by inputting detection value data into the generated graph (left diagram of FIG. 3). In the right diagram of FIG. 3, edges indicated by thick lines have a greater weight than edges indicated by thin lines. In this way, the strength of the relationship between nodes (i.e., the strength of the relationship between sensors) is indicated by the weight of the edges in the graph.
[0033] Here, the following equation (1) represents the activation function used by the learning model generation unit 14 in this embodiment.
[0034]
number
[0035] "att i,j " is the weight of the edge from node (i) to node (j). Also, "x i " is the input data to node (i). "x j " is the input data to node (j). "x i " and "x j " is w-dimensional, where w is the window size. If the above feature vector (embedding vector) is v and its number of dimensions is d, then for the coefficients a and W to be learned, W∈R d×w and a∈R 2d holds. R is the set of all real numbers. A circled "+" symbol represents the concatenation of vectors (arrays). LeakyReLU is a function in which the output value is the same as the input value when the input value is 0 or greater, and the output value is the input value multiplied by a predetermined value when the input value is less than 0. The predetermined value is, for example, 0.01. Figure 4 is a diagram illustrating softmax, which is an activation function. "t" on the horizontal axis of Figure 4 is a parameter. The vertical axis is the output value of the function according to the value of "t". The activation function is a function that normalizes edge weights and is used when the learning model generation unit 14 calculates edge weights.
[0036] (Anomaly detection method) 5 is a flowchart illustrating the anomaly detection method according to this embodiment. The anomaly detection device 10 executes the anomaly detection method shown in FIG. 5 in the estimation phase.
[0037] The acquisition unit 11 acquires detection value data (step S11). Step S11 is similar to step S1 in Fig. 2 except that the detection value data does not include past detection value data but includes detection values of sensors of the operating equipment 20. Here, the anomaly detection unit 12 and the factor estimation unit 13 may read a trained learning model stored in the storage unit 15 before step S11.
[0038] The anomaly detection unit 12 predicts the sensor values of the equipment 20 using the learning model (step S12). The anomaly detection unit 12 aggregates the edge weights of the learning model for each node (each sensor) and calculates the detection value at the next time (for example, 10 minutes later if the cycle is 10 minutes) using the detection values of the related sensors. Here, the value predicted by the anomaly detection unit 12 is not limited to the sensor value itself. For example, a method may be adopted in which the sensor value is reconstructed and the difference from the actual measured value is calculated. In such a case, the anomaly detection unit 12 may predict the reconstructed sensor value.
[0039] The anomaly detection unit 12 calculates the degree of anomaly, which is the difference between the actual measurement value and the predicted value (step S13). For example, in the case of a 10-minute cycle, the anomaly detection unit 12 compares the predicted value predicted 10 minutes ago with the actual measurement value obtained from the detection value data to calculate the degree of anomaly for each node (each sensor).
[0040] The anomaly detection unit 12 determines whether there is a sign of a malfunction in the equipment 20 (step S14). For example, the anomaly detection unit 12 may use, as a determination criterion, that the magnitude of any of the degrees of malfunction exceeds a preset threshold, or that the magnitude of any of the degrees of malfunction increases over time. If the anomaly detection unit 12 determines that there is no sign of a malfunction (No in step S14), the process returns to step S11. If the anomaly detection unit 12 determines that there is a sign of a malfunction (Yes in step S14), the process proceeds to step S15.
[0041] The factor estimation unit 13 may identify a node that is highly related to the node (sensor) that showed the abnormality level that was the basis for determining that there is a failure sign, based on the edge weight of the learning model, and may perform factor estimation that the identified node is the cause of the failure. In this embodiment, the factor estimation unit 13 performs factor estimation using any of the first to third methods described below (step S15).
[0042] The cause estimation unit 13 outputs the determination result that there is a sign of failure, the node indicating the degree of anomaly that is the basis of the determination, and the identified cause as an anomaly detection result to the display unit 16 (step S16). Here, the anomaly detection device 10 may be configured to further include an output unit that outputs the anomaly detection result to the display unit 16, instead of the cause estimation unit 13.
[0043] (Factor estimation) Conventionally, a sensor item that is a factor has been identified according to the magnitude of the abnormality level of the sensor item. However, the abnormality level of the sensor item that is a factor does not necessarily increase. In this embodiment, the factor estimation unit 13 identifies the sensor that is a factor based on the edge weight of the learning model as described above. Therefore, factor estimation can be performed with higher accuracy than conventional methods. Below, several methods (first to third methods) of factor estimation based on edge weights executed by the factor estimation unit 13 will be described. The factor estimation unit 13 can perform factor estimation by adopting any of the first to third methods.
[0044] The first to third methods also use the edge weights of the graph structure to rearrange the sensors so that the sensor estimated to be the cause of the anomaly is at the top. The first to third methods use abnormality data for verification in which the sensor that is the cause of the anomaly (hereinafter referred to as the anomaly factor sensor) is identified, and if the anomaly factor sensor is within the top n estimated sensors, it can be evaluated that the anomaly factor sensor has been correctly identified. n is an integer of 2 or more and may be set in advance depending on the accuracy required for the factor estimation. n is, for example, 5, but is not limited to a specific number. Similarly, for m sensors described below, m is an integer of 1 or more and may be set in advance depending on the accuracy required for the factor estimation. m is, for example, 2, but is not limited to a specific number. Here, n is set to be a number equal to or greater than m.
[0045] (First method) The first method is to search for the nodes (sensors) that are the starting or ending points (connected to the opposite side) of the edges for the m nodes with the largest weights of the edges connected to each node (sensor) in descending order of the degree of anomaly, and then sort the n searched nodes in the order of their search. Figure 6 is a diagram for explaining the first method. In the left diagram of Figure 6, nodes (i) and (j) are arranged in descending order of the degree of anomaly. As in Figure 3, the arrows connecting the nodes represent edges, and edges indicated by thick lines have a larger weight than edges indicated by thin lines. For example, nodes (i1), (i2), and (i3) connected to node (i) have the largest edge weights in this order. In the example of Figure 6, m is 2. Also, in the right diagram of Figure 6, as in the example of Figure 3, circles surrounding numbers represent nodes, and the node from which the arrow points is the edge is the starting point, and the node at the end of the arrow is the end point. i,j " is the weight of the edge from node (i) to node (j), as above. "F i " is the anomaly level of node (i). However, for ease of viewing, in the right diagram of Figure 6, some att i,j and some F i It only specifies.
[0046] When the first method is adopted, the factor estimation unit 13 first searches for the top m (two) nodes (i1) and (i2) with the largest edge weights connected to the node (i) with the highest degree of abnormality.The factor estimation unit 13 then searches for the top m (two) nodes (j1) and (j2) with the largest edge weights connected to the node (j) with the next highest degree of abnormality.In this way, the sensor items that are the factors are identified based on not only the degree of abnormality but also the edge weights.
[0047] In the above example, the node (sensor) that indicated the anomaly level that was the basis for determining that there is a fault sign in the cause estimation was assigned to the end node. However, it can also be assigned to the start node. In other words, either the start node or the end node can be selected as the node connected to the opposite side of the edge (the node to be searched). Specifically, with reference to the right diagram in Figure 6, when node "1," which has the highest anomaly level, is assigned to the end node, the start nodes with the largest edge weights (which can be estimated as the cause) are "1," "2," and "4." On the other hand, when node "1" is assigned to the start point, the end nodes with the largest edge weights are "1," "2," and "5." Furthermore, when node "5," which has the second largest anomaly level, is assigned to the end point, the start nodes with the largest edge weights are "1," "3," and "5." On the other hand, when node "5" is assigned to the start point, the end nodes with the largest edge weights are "2," "4," and "5." The factor estimation unit 13 may associate a node with a high degree of anomaly with either the end point or the start point. Here, the factor estimation unit 13 skips the search if the edge weight is 0. Also, nodes that have already been searched may be skipped. In this way, the factor estimation unit 13 may search for nodes connected to the opposite side of the edges for m nodes (sensors) with the highest weights of edges connected to each node in descending order of the degree of anomaly, and arrange the n searched nodes in the order in which they were searched.
[0048] When the first method is adopted, the factor estimation unit 13 may first perform a process of arranging nodes (sensors) in descending order of the degree of anomaly. Thereafter, the factor estimation unit 13 may perform a process of extracting edges for each end node or start node from the learning model and arranging the edges in descending order of edge weight. Then, as described above, the factor estimation unit 13 may perform a process of searching for nodes connected to the opposite side of each of m edges with the largest weights connected to each of the nodes (sensors) in descending order of the degree of anomaly. The process of searching for nodes may be performed until the number of searched nodes reaches n.
[0049] (Second method) The second method is a method in which, for each node (sensor), the weight of the edge connected to each node is multiplied by the anomaly level of the node at the start or end of that edge (connected to the opposite side), and the sum of the values is calculated, all nodes are sorted in order of the magnitude of the sum, and the top n nodes are extracted. Figure 7 is a diagram for explaining the second method. The symbols shown in Figure 7 have the same meanings as in Figure 6. The left diagram in Figure 7 shows the weight of the edge between node (i) and node (j) and the anomaly level of each node. The right diagram in Figure 7 is the same as the right diagram in Figure 6. In the second method, for node (j), the weight of the edge (att i,j ) and the abnormality degree (F i ) and the sum of the values multiplied by (G j ) is calculated using the following formula:
[0050]
number
[0051] When the second method is adopted, the factor estimation unit 13 calculates the sum (G j ) and calculate the sum (G j ) in order of magnitude. Then, the factor estimation unit 13 extracts the top n nodes. In this way, the sensor items that are factors are identified based on not only the anomaly degree but also the edge weights.
[0052] Here, in the above example, the node (sensor) that showed the degree of anomaly that was the basis for determining that there was a sign of failure in the cause estimation was made to correspond to the end node, but it is also possible to make it correspond to the start node. In other words, either the start node or the end node may be selected as the node connected to the opposite side of the edge (the node used to calculate the above sum). To explain this in more detail with reference to the right diagram of Figure 7, when node "1" is made to correspond to the end node, G1 is set to "F1 x att 1,1 +F2×att 2,1 +F4×att 4,1 On the other hand, when node "1" corresponds to the starting point, G1 is calculated as "F1 × att 1,1 +F2×att 1,2 +F5×att 1,5 " Also, when node "5" corresponds to the end point, G5 is calculated as "F1 × att 1,5 +F3×att 3,5 +F5×att 5,5 On the other hand, when node "5" is associated with the starting point, G5 is calculated as "F2 × att 5,2 +F4×att 5,4 +F5×att 5,5 The factor estimation unit 13 may correspond each node to an end point or a start point. In this way, the factor estimation unit 13 calculates the sum (G j ) and calculate the sum (G j ) and extract the top n nodes.
[0053] When the second method is adopted, the factor estimation unit 13 may perform a process of selecting one node from all nodes and setting the target node for calculation. Then, the factor estimation unit 13 may perform a process of extracting edges connected to the target node from the learning model and searching for the end node or start node of the extracted edge (i.e., the node connected to the opposite side). Then, the factor estimation unit 13 may perform a process of calculating the above sum using the anomaly degree of the searched node and the edge weight, as described above. The factor estimation unit 13 may repeat the process of setting the target node, the search process, and the calculation process so that the above sum is calculated for all nodes. Then, the factor estimation unit 13 may extract the top n nodes sorted in order of the size of the above sum.
[0054] (Third method) The third method is a method in which, for each node (sensor), the normalized magnitude of the sum of the values obtained by multiplying the weight of the edge connected to each node by the anomaly degree of the node at the start or end point of the edge (connected to the opposite side) or the normalized anomaly degree, whichever is larger, is selected, and all nodes are sorted in order of the magnitude of the selected value, and the top n nodes are extracted. In other words, the third method is a method in which, for node (j), the sum (G j ) and the normalized value of the anomaly score (F j ) is normalized, the largest value is selected, and all nodes are sorted in order of the magnitude of the selected value, and the top n nodes are extracted. Here, normalization is performed by j ) and abnormality (F j ) can be compared, and in this embodiment, the process is to divide it by the total value of all nodes. That is, the larger of the two normalized values is set as the selected value, and the selected value (H j ) is calculated using the following formula:
[0055]
number
[0056] When the third method is adopted, the factor estimation unit 13 may perform a process of selecting one of all nodes and setting the target node for calculation. After that, the factor estimation unit 13 may perform a process of extracting an edge connected to the target node from the learning model and searching for the end node or start node of the extracted edge (i.e., the node connected to the opposite side). Then, the factor estimation unit 13 may perform a process of calculating the above sum using the anomaly degree of the searched node and the edge weight, as described above. In addition, the factor estimation unit 13 may also obtain the anomaly degree for the target node and calculate the sum (G j ) and abnormality (F j ) may be normalized. Then, the factor estimation unit 13 may select the larger of the two normalized values (selection value determination process). The factor estimation unit 13 may repeat the processes of setting the target node, searching, calculating, normalizing, and selecting so that selection values are determined for all nodes. Then, the factor estimation unit 13 may extract the top n nodes sorted in order of the magnitude of the selection value. Here, the third method may further incorporate the first method. Then, the largest value of the three results may be selected.
[0057] FIG. 8 illustrates an example of an evaluation of the facility 20, a water treatment facility. The conventional method using a GDN and the method of the present embodiment were evaluated using the same data set. The data set in FIG. 8 is simulated data for a water treatment facility, including a time-series data set in which all points are normal over seven days of normal operation and a time-series data set in which an anomaly occurs over four days. The latter data set includes 36 anomalies, each targeting different sensors and over different time periods, in anticipation of a cyberattack. In the anomaly data, each method was evaluated based on the percentage of sensors included in the top five (corresponding to the case where n is 5) listed as the cause of the anomaly in the conventional method and the method of the present embodiment. "Anomaly level only" is a conventional method that identifies the cause of the anomaly based solely on the magnitude of the anomaly level of the sensor item. The first method was evaluated in two patterns: when m was set to 40 and when m was set to 2. In the present embodiment, the second and third methods were used for cause estimation, demonstrating a high estimation accuracy of over 50%. Furthermore, it was shown that when the first method was adopted, the decrease in the estimation accuracy of the cause of the fault could be suppressed compared to the conventional method using GDN. An evaluation (separate verification) was also conducted in which the facility 20 was a storage battery. The data used was a storage battery consisting of two storage battery modules and one power conditioner, and included time-series data sets of voltage, current, charge / discharge power, temperature, cell balance, and other data under normal and abnormal conditions. As a result, the conventional method was unable to identify the sensor item causing the fault in the cell-related fault data, but the first to third methods correctly identified the cell-related fault (failure due to a broken wire in the cell module). As shown in Figure 8 and another verification, the method of this embodiment can improve the accuracy of the cause of the fault estimation compared to the conventional method using GDN.
[0058] Furthermore, to enable the administrator to easily identify the cause, it is preferable that at least one of the first to fifth data displays described below be displayed on the display unit 16. The first to fifth data display images may be generated, for example, by the factor estimation unit 13, and the factor estimation unit 13 may display them on the display unit 16. In this embodiment, the factor estimation unit 13 generates the first to fifth data display images by superimposing additional information using edge weights of a graph structure on a time-series data graph or a statistical quantity graph, and displays them on the display unit 16. The time-series data graph may be, for example, a line graph showing changes over time. The statistical quantity graph may be, for example, a pie chart showing the number of sensors classified as faults (errors), fault warnings, or normal over a predetermined period. In this embodiment, the factor estimation unit 13 may acquire the details of an action (e.g., touch, hover, click, etc.) on the data display and change the additional information depending on the details of the action. As described above, the storage unit 15 stores the results of processing executed in the anomaly detection device 10. The factor estimation unit 13 may obtain necessary data (such as the weight of an edge of a graph estimated at a specific time) from the storage unit 15 and generate additional information.
[0059] FIG. 9 is a diagram illustrating the first data display. The horizontal axis in FIG. 9 represents time. The vertical axis in FIG. 9 represents the sensor detection value or the anomaly level value. The values on the vertical axis may use units according to the type of sensor, and may be normalized, for example, with the maximum value set to 1. When the cursor (shown as a triangle in FIG. 9) is placed on a line in the line graph, the first data display displays the "graph edge weight" in a pop-up. The first data display can visualize changes in the graph edge weight. In the example of FIG. 9, three sensors (Sensors 1 to 3) and anomaly levels are displayed as line graphs, and the way the graph edge weight changes over time for the anomaly level is shown.
[0060] FIG. 10 is a diagram illustrating the second data display. The pie chart in FIG. 10 shows the number of sensors classified as faulty (error), fault warning, or normal over a specified period. In the example of FIG. 10, 14 sensors are classified as error, and 155 sensors are classified as warning. When the cursor (represented by a triangle in FIG. 10) is placed on any of the sections of the pie chart, the sensor types (in the example of FIG. 10, types that measure charge / discharge, temperature, current, or voltage) are displayed in darker colors in descending order of number. In other words, a color map for each sensor type is displayed in a pop-up. In the example of FIG. 10, the most common type of sensor classified as warning is temperature. Also, the most common type of sensor classified as error is current. By visually displaying statistical information in this way, it is possible to effectively assist administrators in identifying the cause of an error.
[0061] FIG. 11 is a diagram illustrating the third data display. The horizontal and vertical axes in FIG. 11 are the same as those in FIG. 9. In the third data display, when you place the cursor over a line in the line graph, a pop-up displays the "graph edge weight." Clicking further displays the line graphs of all closely related sensors (nodes connected by edges in the graph). The third data display can display all line graphs of closely related sensors to help identify the cause. In the example in FIG. 11, line graphs of three sensors (Sensors 1 to 3) and their anomaly levels are displayed (left). Clicking the line graph for Sensor 2 also displays the line graph of a closely related sensor (Sensor 4) that was not displayed (right). Here, if a line graph of a sensor that is not closely related is displayed, clicking the line graph may hide the line graph of the sensor that is not closely related.
[0062] Figure 12 is a diagram illustrating the fourth data display. The horizontal and vertical axes in Figure 12 are the same as those in Figure 9. For example, an administrator can display the relationships between multiple sensors by performing an action on the screen (e.g., pressing a specific button in the menu) as shown in the left diagram of Figure 12. In the example of Figure 12, the difference (-Sensor1·Sensor2) between Sensor2 (e.g., corresponding to a current value) and Sensor1 (e.g., corresponding to a voltage value) is shown. The background color may be displayed according to the magnitude of this difference. For example, if the difference exceeds a first threshold, it may be displayed in red, and if it exceeds a second threshold (a value smaller than the first threshold) but is equal to or less than the first threshold, it may be displayed in yellow. By overlaying this color background display with line graphs of sensors and anomaly levels (right diagram), a large amount of information can be displayed in an easy-to-read manner, effectively supporting the identification of the cause.
[0063] Figure 13 is a diagram illustrating the fifth data display. In the fifth data display, each sensor is represented by a circle with an identification number, similar to the nodes in Figure 3. Furthermore, in the fifth data display, the lines connecting sensors correspond to edges. For example, an administrator can specify two times or periods and execute the fifth data display. The fifth data display places related nodes close to each other, allowing for divisions such as Area A and Area B, which allows for a better visual understanding of the relationships between nodes. It also makes it possible to visually grasp the changes in edge weights over time. In the example of Figure 13, the left diagram shows the relationship between sensors during a certain period, and the right diagram shows the relationship between sensors during a subsequent period. Comparing Area A visually reveals that the weight between sensors indicated by 0 and 25 has increased, as has the weight between sensors indicated by 12 and 19. Comparing Area B visually reveals that the weight between sensors indicated by 11 and 28 has decreased.
[0064] In this way, the display unit 16 displays data by superimposing additional information using edge weights of a graph structure onto a time-series data graph or a statistical quantity graph. This allows the administrator of the anomaly detection system 1 to easily identify the cause of a failure and efficiently carry out maintenance work on the equipment 20.
[0065] As described above, the anomaly detection device 10 and anomaly detection method according to this embodiment can improve the accuracy of cause estimation by using the edge weights of the graph structure to perform cause estimation, which rearranges sensors so that sensors estimated to be the cause of the anomaly are at the top. Furthermore, by displaying data including additional information using the edge weights of the graph structure, it is possible to shorten the time required to identify the cause of a failure.
[0066] Although the embodiments according to the present disclosure have been described based on the drawings and examples, it should be noted that those skilled in the art would easily be able to make various modifications or alterations based on the present disclosure. Therefore, it should be noted that these modifications and alterations are included within the scope of the present disclosure. For example, the functions included in each component or step can be rearranged so as not to be logically inconsistent, and multiple components or steps can be combined or divided into one.
[0067] Although the embodiments of the present disclosure have been described mainly as an apparatus and a method, the embodiments of the present disclosure may also be realized as a program executed by a processor included in the apparatus or a storage medium on which a program is recorded, and it should be understood that these are also included within the scope of the present disclosure.
[0068] For example, the anomaly detection device 10 may be realized by, for example, a computer. That is, a program may cause the computer to function as the acquisition unit 11, the anomaly detection unit 12, the cause estimation unit 13, etc. The computer may include a storage device such as a memory, a control device such as a CPU (central processing unit) and other processors, a communication device for connecting to a network, and a display device. In this case, the acquisition unit 11 may be realized by the communication device of the computer. The storage unit 15 may be realized by the storage device of the computer. The display unit 16 may be realized by the display device of the computer. Furthermore, the anomaly detection unit 12, the cause estimation unit 13, and the learning model generation unit 14 may be implemented by a program executed by the control device of the computer. The program may be stored in a storage device and read by the control device when executed. [Explanation of symbols]
[0069] 1. Anomaly detection system 10. Anomaly detection device 11 Acquisition Department 12 Abnormality detection unit 13 Factor estimation section 14 Learning model generation unit 15 Storage section 16 Display 20 Equipment
Claims
1. an acquisition unit that acquires detection value data including detection values of sensors installed in the equipment; an anomaly detection unit that determines whether there is a sign of a failure in the equipment by using a learning model generated using normal data from the acquired detection value data; a factor estimation unit that, when it is determined that there is a failure sign, estimates a factor of the failure for which it is determined that there is a failure sign; The learning model is a deep learning model that uses a sparsely structured graph structure, The anomaly detection device, wherein the factor estimation unit performs factor estimation by rearranging sensors so that sensors estimated to be the cause of an anomaly are ranked higher, also using edge weights of the graph structure.
2. 2. The anomaly detection device according to claim 1, wherein m is an integer of 1 or more and n is an integer of 2 or more and greater than m, and the cause estimation unit performs the cause estimation by a method of searching for sensors at start points or end points of m sensors connected to each edge with the largest weights in descending order of the degree of anomaly, and arranging the searched n sensors in the order in which they were searched.
3. 2. The anomaly detection device according to claim 1, wherein the factor estimation unit performs the factor estimation by a method of calculating, for each sensor, a sum of values obtained by multiplying a weight of an edge connected to each sensor by the degree of anomaly of the sensor at the start point or end point of the edge, where n is an integer of 2 or greater, sorting all sensors in order of magnitude of the sum, and extracting the top n sensors.
4. 2. The anomaly detection device according to claim 1, wherein the factor estimation unit selects, for each sensor, a normalized magnitude of a sum of values obtained by multiplying a weight of an edge connected to each sensor by an anomaly degree of the sensor at the start point or end point of the edge, where n is an integer of 2 or greater, or a larger value of the normalized anomaly degree, sorts all sensors in order of magnitude of the selected value, and extracts the top n sensors, where n is an integer of 2 or greater, to perform the factor estimation.
5. Computer, an acquisition unit that acquires detection value data including detection values of sensors installed in the equipment; an anomaly detection unit that determines whether there is a sign of a failure in the equipment by using a learning model generated using normal data from the acquired detection value data; when it is determined that there is a failure sign, the cause estimation unit functions as a cause estimation unit that estimates a cause of the failure for which it is determined that there is a failure sign; The learning model is a deep learning model that uses a sparsely structured graph structure, The cause estimation unit performs cause estimation by rearranging sensors so that a sensor estimated to be a cause of an abnormality is placed at the top, also using edge weights of the graph structure.
6. acquiring detection value data including detection values of sensors installed in the equipment; a step of determining whether there is a sign of a failure of the equipment using a learning model generated using normal data from the acquired detection value data; and when it is determined that there is a failure sign, estimating a cause of the failure for which it is determined that there is a failure sign; The learning model is a deep learning model that uses a sparsely structured graph structure, The anomaly detection method, wherein the step of estimating the cause performs cause estimation by rearranging the sensors so that the sensor estimated to be the cause of the anomaly is ranked higher, also using the edge weights of the graph structure.
7. 5. The anomaly detection device according to claim 1, further comprising: a display unit that displays data in which additional information using edge weights of the graph structure is superimposed on a graph of time-series data or a graph of statistics.
Citation Information
Patent Citations
Time-series data analysis system, method, and program
JP2010078467A