Abnormal management device and abnormal management method

The abnormality management device uses normal data to learn a probability model and generate pseudo-abnormal data for detecting signal abnormalities, addressing the challenge of limited data availability and enabling remote failure detection.

JP7710633B1Active Publication Date: 2025-07-18INTERNET INITIATIVE JAPAN INC

Patent Information

Application Number
JP2025075146
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-07-18
Estimated Expiration
2045-04-30

AI Technical Summary

Technical Problem

Conventional techniques for detecting signal abnormalities require a sufficient amount of abnormal signal data, making it difficult to manage abnormalities when little measurement data is available.

Method used

An abnormality management device uses normal data to learn a probability model via maximum likelihood estimation, derives the probability distribution of abnormal data, generates pseudo-abnormal data through adversarial learning, and determines signal abnormalities by comparing collected spectra with stored pseudo-abnormal data.

Benefits of technology

Enables effective management of signal abnormalities even with limited abnormal data, allowing remote detection of communication terminal failures by generating and recognizing pseudo-abnormal patterns.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007710633000001_ABST
    Figure 0007710633000001_ABST
Patent Text Reader

Abstract

Even when there is little measurement data of abnormal signals, it is an object to manage the abnormality of the signals. 【Means for solving the problem】 The abnormality management device 1 uses, as teacher data, normal data indicating a normal frequency spectrum among the frequency spectra of a plurality of signals, for each frequency component intensity, and the parameter of a probability model that outputs the posterior probability that each frequency component intensity is normal is learned by maximum likelihood estimation. And a derivation unit 12 configured to derive a probability distribution of abnormal data indicating a frequency spectrum including a frequency component with an abnormal intensity, based on the posterior probability estimated by the learned probability model, the probability distribution of the normal data, and the prior probability of being normal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an abnormality management device and an abnormality management method.

Background Art

[0002] Conventionally, a technique for analyzing the characteristics of a time-series signal in the frequency domain and detecting an abnormality included in the signal has been known. For example, Patent Document 1 discloses a technique for estimating an abnormality in a signal measured by a sensor using a machine learning model constructed using the frequency spectra of both a normal signal and an abnormal signal as learning data.

[0003] However, in the technique disclosed in Patent Document 1, in order to construct a model having sufficient accuracy for detecting an abnormality, it is necessary to obtain a sufficient number of abnormal signals, and the abnormal signals have to be accumulated over a long period of time. Also, even when detecting an abnormality in a signal in the frequency spectrum by a statistical method, a large amount of measurement data of abnormal signals may be required.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] As described above, according to the conventional technique, it may be difficult to manage an abnormality in a signal when there is little measurement data of the abnormal signal.

[0006] The present invention has been made to solve the above-described problems, and an object thereof is to manage an abnormality in a signal even when there is little measurement data of the abnormal signal.

Means for Solving the Problems

[0007] In order to solve the above problems, the abnormality management device according to the present invention uses, as teacher data, normal data indicating a frequency spectrum in which the intensity of each frequency component is normal among the frequency spectra of a plurality of signals, and learns, by maximum likelihood estimation, the parameters of a probability model that outputs the posterior probability that the intensity of each frequency component is normal. A first learning unit configured to perform the learning; a derived unit configured to derive a probability distribution of abnormal data indicating a frequency spectrum including a frequency component with an abnormal intensity based on the posterior probability estimated by the learned probability model, the probability distribution of the normal data, and the prior probability of being normal; a data processing unit configured to obtain the frequency spectrum of the abnormal data based on the derived probability distribution of the abnormal data; a second learning unit configured to learn a generator that generates pseudo-abnormal data statistically similar to the true abnormal data, using the frequency spectrum of the abnormal data obtained by the data processing unit as the true abnormal data; and a storage unit configured to store the pseudo-abnormal data generated using the learned generator constructed by the second learning unit.

[0008] Further, in the abnormality management device according to the present invention, a collection unit configured to collect the frequency spectrum of the signal to be managed, and a determination unit configured to determine that the signal to be managed is an abnormal signal when the frequency spectrum of the signal to be managed collected is the same as the pseudo-abnormal data stored in the storage unit may be further provided.

[0009] Further, in the abnormality management device according to the present invention, a notification unit configured to externally notify that an abnormality has occurred in the communication terminal that measured the abnormal signal may be further provided when the determination unit determines that the signal is an abnormal signal.

[0010] Further, in the abnormality management device according to the present invention, the second learning unit may perform adversarial learning of a generative model having the generator and a discriminator that discriminates between the pseudo-abnormal data generated by the generator and the true abnormal data.

[0011] In order to solve the above problems, the anomaly management method according to the present invention includes, among the frequency spectra of a plurality of signals, normal data indicating a frequency spectrum in which the intensity of each frequency component is normal as teacher data, and a first learning step of learning the parameters of a probability model that outputs the posterior probability that the intensity of each frequency component is normal by maximum likelihood estimation; a derivation step of deriving the probability distribution of anomaly data indicating a frequency spectrum including frequency components with abnormal intensities based on the posterior probability estimated by the learned probability model, the probability distribution of the normal data, and the prior probability of being normal; a data processing step of obtaining the frequency spectrum of the anomaly data based on the derived probability distribution of the anomaly data; a second learning step of learning a generator that generates pseudo-anomaly data statistically similar to the true anomaly data with the frequency spectrum of the anomaly data obtained in the data processing step as the true anomaly data; and a storage step of storing the pseudo-anomaly data generated using the learned generator constructed in the second learning step in a storage unit.

[0012] Further, in the anomaly management method according to the present invention, it may further include a collection step of collecting the frequency spectrum of the signal to be managed, and a determination step of determining that the signal to be managed is an abnormal signal when the frequency spectrum of the signal to be managed collected is the same as the pseudo-anomaly data stored in the storage unit.

[0013] Further, in the anomaly management method according to the present invention, it may further include a notification step of notifying externally that an anomaly has occurred in the communication terminal that measured the abnormal signal when it is determined in the determination step that the signal is an abnormal signal.

[0014] Further, in the anomaly management method according to the present invention, the second learning step may perform adversarial learning of a generative model having the generator and a discriminator that discriminates between the pseudo-anomaly data generated by the generator and the true anomaly data.

Advantages of the Invention

[0015] According to the present invention, using normal data showing a normal frequency spectrum with the intensity of each frequency component as teacher data, the parameters of a probability model that outputs the posterior probability that the intensity of each frequency component is normal are learned by maximum likelihood estimation, and based on the posterior probability estimated by the learned probability model, the probability distribution of the normal data, and the probability of being normal, the probability distribution of abnormal data showing a frequency spectrum including frequency components with abnormal intensities is derived. Therefore, even when there is little measurement data of abnormal signals, the abnormality of the signals can be managed.

Brief Description of the Drawings

[0016]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Embodiments for Carrying Out the Invention

[0017] Hereinafter, preferred embodiments of the present invention will be described in detail with reference to FIGS. 1 to 9.

[0018] [Configuration of Communication Control System] First, with reference to FIG. 1, an overview of an anomaly management system including an anomaly management device 1 according to an embodiment of the present invention will be described.

[0019] The anomaly management system includes an anomaly management device 1 and a communication terminal 2. The anomaly management device 1 and the communication terminal 2 are connected via a network NW. The anomaly management system according to the present embodiment constructs a database of anomaly data for detecting signal anomalies based on the frequency spectrum of the signals measured by the communication terminal 2.

[0020] The network NW includes, for example, wired networks such as LAN, WAN, Internet, ISDN, mobile communication networks using wireless LAN, LTE / 4G, 5G, 6G wireless communication systems, and wireless networks such as Bluetooth (registered trademark), but the scope of the present invention is not limited thereto.

[0021] The communication terminal 2 can be realized as a mobile communication terminal such as a smartphone, a tablet computer, a laptop computer, a wearable device, etc. In the present embodiment, there are n communication terminals 2 (n is a positive integer of 2 or more). The communication terminal 2 includes a terminal corresponding to a mobile communication network that has a SIM (Subscriber Identity Module), and the SIM contract profile includes identifier information such as an international mobile subscriber identity (IMSI).

[0022] In addition, the communication terminal 2 has an IP address and includes those configured as IoT terminals. The communication terminal 2 is equipped with a mobile communication module and various sensors, can detect various physical quantities, and can measure them as electrical signals. The communication terminal 2 transmits the measured signals to a gateway or the like (not shown) via the network NW or to the abnormality management device 1. In the present embodiment, as an example, the reception level and signal strength of the signals received from the base station, which are periodically measured and recorded by the communication terminal 2 using the mobile communication module, are taken as the signals to be subject to abnormality management.

[0023] As shown in the area 2a of FIG. 1, the communication terminal 2 measures and records the time-series data of the signal strength (\"power [dB]\"). It is difficult to directly detect the occurrence of an abnormality in the signal strength from the waveform data of the signal strength shown in the area 2a. Therefore, the abnormality management device 1 described later converts the time-series data of the signal strength into a spectrum in the frequency domain and analyzes the frequency components to detect signal abnormalities.

[0024] FIG. 2 is a diagram for explaining abnormal data showing a frequency spectrum including frequency components of abnormal intensity. In FIG. 2(a), the horizontal axis represents frequency and the vertical axis represents intensity. The curve a1 is the normal frequency spectrum of the intensity of each frequency component of the signal measured by a certain communication terminal 2, and the curve b1 shows the frequency spectrum including the frequency components of abnormal intensity in the signal measured by another communication terminal 2. In the frequency range c, there is a peak of abnormal frequency components that do not exist in the normal frequency spectrum, indicating that an abnormality has occurred in the intensity of the frequency components. It is considered that a problem has occurred in the communication terminal 2 that measures the signal related to the frequency spectrum including such abnormal intensity frequency components, such as a hardware or setting problem, or a problem on the reception environment side. For example, there may be a failure of the communication module of the communication terminal 2, a bug or incorrect setting of the measurement software, or an influence caused by an internal noise source. Therefore, it is considered that a failure has occurred in the communication terminal 2 that measures the signal related to the frequency spectrum including the frequency components of abnormal intensity.

[0025] [Functional Blocks of Abnormality Management Device] Next, the functional blocks of the abnormality management device 1 according to the present embodiment will be described with reference to the block diagram of FIG. 1. As shown in FIG. 1, the abnormality management device 1 includes a collection unit 10, a first learning unit 11, a derivation unit 12, a data processing unit 13, a second learning unit 14, a generation unit 15, a storage unit 16, a determination unit 17, and a notification unit 18.

[0026] The collection unit 10 collects the frequency spectra of signals measured by each of the plurality of communication terminals 2 via the network NW. Alternatively, the collection unit 10 can collect the time-series data of the signals measured by each of the plurality of communication terminals 2, and perform Fourier transform on the collected signals to obtain the frequency spectrum. The time-series data of the signal and its frequency spectrum are associated with the identification information of the communication terminal 2 that measured the signal. The collection unit 10 collects the frequency spectra of signals that include a certain number or more of normal frequency spectra in which the intensity of each frequency component used by the first learning unit 11 for learning is normal. Further, the collection unit 10 collects the frequency spectra of the signals to be managed, which are the targets of abnormality determination by the determination unit 17.

[0027] The first learning unit 11 learns, by maximum likelihood estimation, the parameters of a probability model that outputs the posterior probability that the intensity of each frequency component is normal, using, as teacher data, the normal data indicating the frequency spectra in which the intensity of each frequency component among the frequency spectra of a plurality of signals is normal. The first learning unit 11 learns the probability model by maximum likelihood estimation using normal data in a situation where there is little abnormal data. The first learning unit 11 can use a plurality of frequency spectra that include a certain amount or more of normal data as teacher data. The "intensity" is a concept that includes the amplitude, power, or physical quantity corresponding thereto of each frequency component, and includes an aspect in which the value of voltage is used as the intensity.

[0028] Here, let x be the intensity x of a frequency component at a certain observation point. Further, as shown in the following formula (1), the probability density function of normal data is defined as ρ d (x), and the probability density function of abnormal data is defined as ρ g (x), respectively.

Equation

[0029] In the above formula (1), y = 1 indicates the normal class, and y = 0 indicates the abnormal class. Therefore, ρ d (x) indicates the occurrence tendency of the intensity x when belonging to the normal class y = 1, and ρ g (x) indicates the occurrence tendency of the intensity x when belonging to the abnormal class y = 0. Here, (b) in FIG. 2 shows that the horizontal axis is the intensity and the vertical axis is the probability distribution, and the density functions (probability distributions) a2 of the normal data and b2 of the abnormal data at the black circle data points of the normal data a1 and the abnormal data b1 in (a) of FIG. 2 are shown. In the example of (b) in FIG. 2, the probability distributions of both the normal data and the abnormal data follow a normal distribution.

[0030] The density ratio γ(x) of the density function in the above formula (1) is represented by the following formula (2).

Equation

[0031]

Equation

[0032] Here, if π = ρ(y = 1), the above formula (3) can be further represented by the following formula (4).

Number

[0033] Therefore, first, we will obtain the posterior probability ρ(y = 1|x) of being normal (y = 1) with a large number of observed values x. Assuming that the posterior probability ρ(y = 1|x) of normal data follows a normal distribution, it is defined as shown in the following formula (5).

Number

[0034] Furthermore, if the output f(x n ) of the probability model is represented by a linear combination, it can be expressed as shown in the following formula (6).

Number

[0035]

Number

[0036] [Number] That is, Φ is an N×M matrix in which, for N observation points x n , the feature vectors Φ(x n ) obtained from each observation point are arranged as rows.

[0037] Furthermore, the average of the error between the intensity f(x n ) estimated based on the learned parameter w and the actual normal intensity t n (teacher signal) is the variance σ 2 of the normal distribution shown by the following formula (9). [Number]

[0038] Thus, when a probability model represented by a linear combination estimates the posterior probability that the intensity is normal for the input x, each observed value t is assumed to follow a normal distribution with the estimated value f(x n ) of the probability model as the mean. By performing maximum likelihood estimation for all data (x n , t n ), the parameter w of the probability model and the variance σ 2 of the error are estimated. Also, from the definition formula of the normal distribution in the above formula (5), the density function ρ d (x) of the normal data is obtained.

[0039] Here, when approximately estimating the posterior probability ρ(y = 1|x) of the normal data, the relationship ρ(y = 1|x) ≒ q w (y = 1|x) holds. Based on the estimated value q w (y = 1|x) of the posterior probability that the input intensity x is normal, cross-entropy is defined as the loss function U as shown in the following formula (10). [Number]

[0040] The convergence value (minimum value) of the loss function U in the above formula (10) is represented by the following formula (11). [Number]

[0041] The derivation unit 12 transforms the above formula (11) into the following formula (12) to derive the probability density function ρ g (x) of the abnormal data. [Number]

[0042] In the above formula (12), the probability distribution of the normal data, that is, the probability density function ρ d (x) of the normal data is calculated from the normal data collected by the collection unit 10. Also, since the prior probability π of the normal data is much larger than the prior probability (1 - π) of the abnormal data, it can be set to, for example, 0.99. Furthermore, for the observed value x, when y = 1, the log-likelihood lnq w (y = 1|x) is obtained by maximum likelihood estimation based on a large amount of normal data (teacher signals) as shown in the above formulas (6) to (9). Thus, even when there is little abnormal data, the probability distribution of the abnormal data can be obtained from the normal data.

[0043] The derivation unit 12 is based on the estimated value q w (y = 1|x) of the posterior probability estimated by the probability model learned by the first learning unit 11, the probability density function ρ d (x) of the normal data, and the prior probability π of being normal, and derives the probability density function ρ g (x) of the abnormal data indicating the abnormal intensity.

[0044] Based on the derived probability distribution of the abnormal data, the data processing unit 13 obtains the frequency spectrum of the abnormal data. The data processing unit 13 is the probability density function ρ of the abnormal data in the above formula (12) gUsing (x), for example, by random sampling, the intensity values in the abnormal state are generated, and by arranging them in order for each frequency component, the frequency spectrum related to the abnormal data can be obtained. Further, the data processing unit 13 can obtain the frequency spectrum of the abnormal data corresponding to any plurality of data points in the frequency range c where the abnormal state shown in FIG. 2(a) occurs.

[0045] The second learning unit 14 learns a generator 141 that generates pseudo-abnormal data statistically similar to the true abnormal data, using the frequency spectrum of the abnormal data obtained by the data processing unit 13 as the true abnormal data. The second learning unit 14 performs, for example, adversarial learning of a generation model having a generator 141 and a discriminator 142 that discriminates between the pseudo-abnormal data generated by the generator 141 and the true abnormal data.

[0046] As shown in FIG. 3, the second learning unit 14 adversarially learns a GAN (Generative Adversarial Network) having a generator 141 and a discriminator 142.

[0047] FIGS. 4 and 5 are diagrams schematically showing the neural network configurations of the generator 141 and the discriminator 142 of the GAN used by the second learning unit 14. As shown in FIG. 4, the generator 141 is composed of a neural network having an input layer, a hidden layer, and an output layer. The generator 141 is a model that generates pseudo-abnormal data from random noise. For example, a vector of Gaussian noise is randomly sampled m times and input to the input nodes of the generator 141 (z1~z m )

[0048] The generator 141 outputs an output G(z) through a product-sum operation of the input and weight parameters and a threshold process by an activation function. The output G(z) from the generator 141 is data similar to the true abnormal data. CNN or ResNet can be used as the neural network constituting the generator 141.

[0049] The discriminator 142 shown in FIG. 5 is composed of a neural network having an input layer, a hidden layer, and an output layer. In the example of FIG. 5, as the input of the training data, the frequency spectrum of the abnormal data obtained by the data processing unit 14 as a result of the learning by the first learning unit 11 is given.

[0050] The discriminator 142 outputs a binary output of 1 or 0 through the product-sum operation of the input and the weight parameter and the threshold processing by the activation function. When the discriminator 142 correctly discriminates the training data related to the input true abnormal data as true abnormal data, it outputs the output y = 1. On the other hand, when the discriminator 142 correctly discriminates the training data related to the input pseudo-abnormal data as pseudo-abnormal data, it outputs the output y = 0. Thus, the discriminator 142 is a model that distinguishes the model distribution generated by the generator 141 from the data distribution of the training data that is the true distribution. A CNN can be used as the neural network constituting the discriminator 142.

[0051] FIG. 3 is a block diagram for explaining the adversarial learning of the GAN by the second learning unit 14. The generator 141 of the GAN adopted by the second learning unit 14 is represented by the function G, and the discriminator 142 is represented by the function D. Also, the true abnormal data is represented by x, the predicted value that is the output by the discriminator 142 is represented by y, and the correct label is represented by t. The correct label t is set to 1 for the true abnormal data and 0 for the pseudo-abnormal data generated by the generator 141. At this time, the discriminator 142 is the cross entropy E of the following formula (13) as a binary classification problem CE which can be represented by.

[0052]

Equation

[0053] In the first term within the braces of the above formula (13), the t represented by n ln y n in which, for the predicted value y of the discriminator 142 n it is desirable that it approaches the value of the correct label t n = 1 of the true abnormal data. On the other hand, for the second term within the braces, (1 - t) represented by n)ln(1 - y n ) In this case, the predicted value y of the discriminator 142 n should approach the value of the correct label (1 - t n ) = 0 that identifies the pseudo-abnormal data. Thus, the cross-entropy E CE becomes the maximum value when the predicted value matches the value of the correct label.

[0054] Here, the generator 141 that constitutes the GAN has parameters w G , θ G and is represented by the function G(w G , θ G ). Also, the discriminator 142 has parameters w D , θ D and is represented by the function D(w D , θ D ). The objective function E of the GAN equipped with the generator 141 and the discriminator 142 based on the cross-entropy E CE in the above equation (13) can be expressed by the following equation (14).

Equation

[0055] The E represented by the first term in the above equation (14) D(x)=1 lnD(w D , θ D ) is the expected value that the discriminator 142 identifies the true abnormal data as true abnormal data. The E represented by the second term in the above equation (14) D(x)=0 ln(1 - D(G(w G , θ G ), w D , θ D )) is the expected value that the discriminator 142 identifies the pseudo-abnormal data generated by the generator 141 as pseudo-abnormal data. In the learning of the GAN, the generator 141 and the discriminator 142 are adversarially learned by the min-max optimization of the objective function E. Therefore, the generator 141 is learned so that it can generate pseudo-abnormal data that deceives the discriminator 142, and the discriminator 142 is learned so that it can identify the pseudo-abnormal data generated by the generator 141 as pseudo-abnormal data.

[0056] In the learning of the discriminator 142, when true abnormal data is given, the discriminator 142 outputs an output close to y = 1 to maximize the first term of the objective function E in the above formula (14). On the other hand, when pseudo-abnormal data is given, the learning is performed so that the discriminator 142 outputs an output close to y = 0 to maximize the second term of the objective function E.

[0057] In the learning of the generator 141, D(G(w G , θ G ), w D , θ D )(D(G(z)) in FIG. 3) approaches 1, so that G(w G , θ G )(G(z) in FIG. 3) is output to minimize the objective function E. The second learning unit 14 uses a learning procedure that alternately updates the parameters of the generator 141 and the parameters of the discriminator 142. The details of the learning procedures of the generator 141 and the discriminator 142 by the second learning unit 14 will be described later.

[0058] The generation unit 15 generates pseudo-abnormal data using the learned generator 141' whose GAN objective function E has been optimized by the second learning unit 14.

[0059] The storage unit 16 stores the generated pseudo-abnormal data. The storage unit 16 also stores the true abnormal data obtained by the data processing unit 13.

[0060] When the frequency spectrum of the signal collected by the collection unit 10 matches the pseudo-abnormal data stored in the storage unit 16, the determination unit 17 determines that the signal is an abnormal signal. More specifically, when the frequency spectrum of the signal matches the pseudo-abnormal data and the true abnormal data stored in the storage unit 16, the determination unit 17 identifies the communication terminal 2 associated with the signal of the frequency spectrum.

[0061] When the determination unit 17 determines that the signal is an abnormal signal, the notification unit 18 notifies the outside that an abnormality has occurred in the communication terminal 2 that has measured the signal of the frequency spectrum to be determined. The notification unit 18 can send an alarm to a management server provided outside. The notification unit 18 may send a notification to the communication device 2 in which the occurrence of an abnormality is detected via the network NW.

[0062] [Hardware Configuration of Abnormality Management Device] Next, an example of the hardware configuration for realizing the abnormality management device 1 having the above-described functions will be described with reference to FIG. 6.

[0063] As shown in FIG. 6, the abnormality management device 1 can be realized by, for example, a computer including a processor 102, a main storage device 103, a communication interface 104, an auxiliary storage device 105, and an input / output I / O 106 connected via a bus 101, and a program for controlling these hardware resources. Further, the abnormality management device 1 includes a display device 107.

[0064] The processor 102 is realized by a CPU, a GPU, an FPGA, an ASIC, or the like.

[0065] In the main storage device 103, programs for the processor 102 to perform various controls and operations are stored in advance. The functions of the abnormality management device 1 such as the collection unit 10, the first learning unit 11, the derivation unit 12, the data processing unit 13, the second learning unit 14, the generation unit 15, the determination unit 17, and the notification unit 18 shown in FIG. 1 are realized by the processor 102 and the main storage device 103.

[0066] The communication interface 104 is an interface circuit for network-connecting the abnormality management device 1 and various external electronic devices.

[0067] The auxiliary storage device 105 is composed of a readable and writable storage medium and a driving device for reading and writing various information such as programs and data to and from the storage medium. As the storage medium of the auxiliary storage device 105, a semiconductor memory such as a hard disk or a flash memory can be used.

[0068] The auxiliary storage device 105 has a program storage area for storing an abnormality management program. The auxiliary storage device 105 also has a program storage area for storing a learning program for adversarial learning of the GAN executed by the abnormality management device 1. The auxiliary storage device 105 also has a program storage area for storing a first learning program executed by the abnormality management device 1. The storage unit 16 described in FIG. 1 is realized by the auxiliary storage device 105. Furthermore, for example, it may have a backup area for backing up the above-described data, programs, etc.

[0069] The input / output I / O 106 is an input / output device that inputs signals from external devices and outputs signals to external devices.

[0070] The display device 107 is composed of an organic EL display, a liquid crystal display, or the like. The display device 107 can display true abnormal data on the screen.

[0071] [Operation of the Abnormality Management Device] Next, the operation of the abnormality management device 1 having the above-described configuration will be described with reference to the flowcharts of FIGS. 7 and 8.

[0072] As shown in FIG. 7, first, the collection unit 10 collects a frequency spectrum containing a certain number or more of normal data (step S1). The collection unit 10 collects a frequency spectrum in which, for example, 99% or more of the frequency spectra of a plurality of signals are normal data. The collection unit 10 can collect the time-series data of the signals measured by each communication terminal 2 from the gateway or each communication terminal 2 via the network NW and convert it into a frequency spectrum.

[0073] Next, the first learning unit 11 performs the first learning process (step S2). After that, the derivation unit 12 derives the density function of the abnormal data (step S3). FIG. 8 is a flowchart for explaining steps S2 and S3 in more detail. As shown in step S30 of FIG. 8, based on the frequency spectrum collected in step S1 and containing normal data at a certain ratio, the first learning unit 11 uses the normal data as teacher data and estimates the posterior probability q w (y = 1|x) of the probability model with parameters w, σ 2 by maximum likelihood estimation (step S30).

[0074] In step S30, the first learning unit 11 performs learning by maximum likelihood estimation according to the above equations (6) to (9). Also, in step S30, the first learning unit 11 obtains the estimated values q of the posterior probability that the intensity x is normal from the probability model with parameters w, σ 2 (y = 1|x). w (y = 1|x) is obtained.

[0075] Furthermore, the first learning unit 11 estimates the density function ρ of the normal data d (x) (normal distribution) based on the normal intensity x of each frequency component (step S31).

[0076] Next, the derivation unit 12 substitutes the log-likelihood lnq of the posterior probability obtained in step S30 w (y = 1|x), the density function ρ of the normal data obtained in step S31 d (x), and the prior probability π of the normal data (e.g., 0.99) into the above equation (12) to derive the density function ρ of the abnormal data g (x) (step S33).

[0077] After that, the process proceeds to step S4 in FIG. 7. Subsequently, the data processing unit 13 uses the density function ρ of the abnormal data derived in step S3 gBased on (x), the intensities for each frequency component of the abnormal data are arranged in order to obtain a frequency spectrum (step S4). For example, in step S4, a density function ρ g which is a normal distribution for each frequency component, creates 10,000 data centered around the median from (x). When the number of frequency components is 1,000, (10,000 to the power of 1,000) frequency spectra are created.

[0078] Subsequently, the second learning unit 14 learns a generator 141 that generates pseudo-abnormal data statistically similar to the true abnormal data, using the frequency spectrum of the abnormal data obtained in step S4 as the true abnormal data (step S5) (second learning process).

[0079] Specifically, the second learning unit 14 performs adversarial learning of a GAN having a generator 141 that generates pseudo-abnormal data similar to the true abnormal data, using the frequency spectrum of the abnormal data obtained in step S4 as the true abnormal data, and a discriminator 142 that discriminates between the pseudo-abnormal data generated by the generator 141 and the true abnormal data. Note that the details of the learning process in step S5 will be described later.

[0080] Next, the generation unit 15 generates pseudo-abnormal data using the learned generator 141' (step S6). The generated pseudo-abnormal data is stored in the storage unit 16 (step S7). In step S7, the true abnormal data used as the training data of the GAN is also stored in the storage unit 16.

[0081] After that, the collection unit 10 collects the frequency spectrum of the signal to be managed (step S8). Next, when the frequency spectrum of the signal collected in step S8 matches the pseudo-abnormal data or the true abnormal data stored in the storage unit 16, the determination unit 17 determines that it is an abnormal signal (step S9). In step S9, when the frequency spectrum of the signal to be managed not only completely matches the pseudo-abnormal data or the true abnormal data, but also matches within a certain allowable range, it can be determined that it is an abnormal signal. In addition, by collating the frequency spectrum in order for each frequency component, for example, when it matches within the range c of the frequency components in the curve b1 of the abnormal data in (a) of FIG. 2 or the frequency components before that, it can be determined that it is an abnormal signal. The determination unit 17 identifies the communication terminal 2 that has measured the abnormal signal.

[0082] Next, the notification unit 18 gives a notification indicating that an abnormality has occurred in the communication terminal 2 that has measured the signal determined to be an abnormal signal to an external management server or the like (step S10).

[0083] Next, referring to FIG. 9, the second learning process (step S5) of the abnormality management device 1 described in FIG. 7 will be described. First, the second learning unit 14 inputs the true abnormal data as the training data 144 to the discriminator 142, and the parameters w D , θ D of the discriminator 142 are learned and updated so as to identify the true abnormal data as the true abnormal data (y = 1) (step S20).

[0084] In step S20, the second learning unit 14 can cause the discriminator 142 to learn the true abnormal data using, for example, the error backpropagation method. By step S20, a discriminator 142 that can identify the true abnormal data as the true abnormal data is constructed in advance.

[0085] Next, the second learning unit 14 generates Gaussian noise and provides a random vector of the generated Gaussian noise as an input to the generator 141 (step S21). Subsequently, based on the provided Gaussian noise, the generator 141 performs a sum-of-products operation of the input z and the weight parameters w G , θ G and threshold processing using an activation function to generate pseudo-abnormal data G(z) (step S22).

[0086] Next, the second learning unit 14 performs learning of the discriminator 142. The learning of the discriminator 142 is performed with the parameters w D , θ D of the generator 141 fixed. First, the second learning unit 14 provides true abnormal data as training data 144 to the discriminator 142 as an input. Then, the second learning unit 14 updates the parameters w D , θ D by the error backpropagation method or the like so that the objective function E in the above equation (14) becomes maximum (step S23). Note that the label of the training data 144 is set to 1 (true abnormal data).

[0087] Next, the second learning unit 14 provides the pseudo-abnormal data generated by the generator 141 in step S22 to the discriminator 142 as an input, and updates the parameters w D , θ D by the error backpropagation method or the like so that the objective function E in the above equation (14) becomes maximum (step S24). That is, in steps S23 and S24, in order to maximize the objective function E in the above equation (14), the first term outputs D(w D , θ D ) = 1, and the second term is optimized so that D(G(w G , θ G ), w D , θ D ) = 0. Note that the label of the training data 144 is set to 0 (pseudo-abnormal data).

[0088] The learning of the discriminator 142 in step S23 and step S24 corresponds to the dashed arrow shown in the block diagram of the second learning unit 14 shown in FIG. 3, in which the discriminator error is calculated in the block 145 of the objective function E based on the output 143 from the discriminator 142, and then error backpropagation is performed to the discriminator 142.

[0089] Next, the second learning unit 14 performs learning of the generator 141. In the learning of the generator 141, the parameters of the discriminator 142 are fixed. The second learning unit 14 learns the generator 141 so that pseudo-abnormal data is generated when random Gaussian noise is given to the generator 141. Specifically, the second learning unit 14 updates the parameters w G , θ G by the error backpropagation method or the like in order to minimize the objective function E of the above formula (14) (step S25).

[0090] The learning in step S25 corresponds to the flow of the dashed arrow indicating error backpropagation to the generator 141 in the block diagram of the second learning unit 14 in FIG. 3. That is, step S25 corresponds to the flow of the dashed arrow in which the pseudo-abnormal data generated by the generator 141 in FIG. 3 is input to the discriminator 142, the generator error is calculated in the block 145 of the objective function E from the output 143, and further error backpropagation is performed to the generator 141.

[0091] Thereafter, until the value of the objective function E reaches the Nash equilibrium and converges (step S26: NO), the learning of the discriminator 142 and the generator 141 from step S22 to step S25 is repeatedly performed. On the other hand, when the value of the objective function E converges (step S26: YES), the processing from step S20 to step S26 is repeated until the learning of the generator 141 and the discriminator 142 is performed using the remaining true abnormal data in order (step S27: NO).

[0092] After that, when the generator 141 and the discriminator 142 are trained using all the true abnormal data (step S27: YES), the second training unit 14 stores the trained generator 141' in the storage unit 16 (step S28). The trained generator 141' is constructed by the processing from step S20 to step S28 above. Further thereafter, the process proceeds to step S6 in FIG. 7.

[0093] As described above, according to the abnormality management device 1 according to the present embodiment, by using normal data as teacher data and learning the parameters of the probability model that outputs the posterior probability of normal intensity by maximum likelihood estimation, the posterior probability of normal intensity is estimated. Further, based on the estimated value of the posterior probability, the density function of the normal data, and the prior probability of the normal data, the density function of the abnormal data is derived. Further, the frequency spectrum of the abnormal data obtained from the derived density function of the abnormal data is used as the true abnormal data in the generation model to generate pseudo-abnormal data similar to the true abnormal data. The generated pseudo-abnormal data is stored in the storage unit 16 together with the true abnormal data as a database. Therefore, even when there is little measurement data of the abnormal signal, the abnormality of the signal can be managed.

[0094] Also, according to the abnormality management device 1 according to the present embodiment, the frequency spectrum of the signal measured for each communication terminal 2 is collected, and in order to determine abnormal data, after identifying the communication terminal 2 in which an abnormality has occurred, an alarm is issued. Therefore, it is possible to detect a failure of the communication terminal 2 remotely without performing an abnormality analysis at the location where the communication terminal 2 is arranged.

[0095] Also, according to the abnormality management device 1 according to the present embodiment, in order to compare the intensity of each frequency component of the frequency spectrum indicated by the pseudo-abnormal data generated by the trained generator 141' with the intensity of each frequency component of the frequency spectrum of the actually measured signal, when a part of the spectrum matches, it becomes possible to predict the abnormality of the signal.

[0096] Also, in the described embodiment, an example was given where the signal measured by the communication terminal 2 is time-series data of signal strength. However, the time-series signal to be subjected to anomaly detection is not limited to signal strength as long as it is a signal capable of frequency analysis. For example, the communication terminal 2 may be configured to include a biosensor and measure time-series data of biosignals such as a user's heartbeat, blood pressure, body temperature, etc. Alternatively, the communication terminal 2 may be equipped with various sensors such as a vibration sensor, a sound sensor, a pressure sensor, etc., and be capable of measuring time-series data of physical quantities such as vibration, sound, pressure, etc.

[0097] Also, in the described embodiment, an example was given where the communication terminal 2 is a terminal equipped with a SIM such as a smartphone and an IoT terminal having an IP address. However, the communication terminal 2 may be a conventional device without a communication function as long as it can input the time-series data of the measured signal into the anomaly detection device 1.

[0098] Also, in the described embodiment, the second learning unit 14 was described for the case of performing GAN learning. However, the learning of the generator 141 can be performed not only by adversarial learning but also by VAE (Variational Autoencoder), diffusion models, Energy-Based Models (EBMs), etc.

[0099] As described above, the embodiments of the anomaly management device and the anomaly management method of the present invention have been described. However, the present invention is not limited to the described embodiments, and various modifications that can be assumed by those skilled in the art can be made within the scope of the invention described in the claims.

Explanation of Reference Numerals

[0100] 1...Abnormality management device, 2...Communication terminal, 3...Base station, 4...Core network, 10...Collection unit, 11...First learning unit, 12...Derivation unit, 13...Data processing unit, 14...Second learning unit, 15...Generation unit, 16...Memory unit, 17...Judgment unit, 18...Notification unit, 101...Bus, 102...Processor, 103...Main memory device, 104...Communication interface, 105...Auxiliary storage device, 106...Input / output I / O, 107...Display device, 141...Generator, 142...Identifier, NW...Network.

Claims

1. Among the frequency spectra of a plurality of signals, using normal data indicating a normal frequency spectrum with the intensity of each frequency component being normal as teacher data, a first learning unit configured to learn the parameters of a probability model that outputs the posterior probability that the intensity of each frequency component is normal by maximum likelihood estimation; A derivation unit configured to derive the probability distribution of abnormal data indicating a frequency spectrum including frequency components with abnormal intensities based on the posterior probability estimated by the learned probability model, the probability distribution of the normal data, and the prior probability of being normal; A data processing unit configured to obtain the frequency spectrum of the abnormal data based on the derived probability distribution of the abnormal data; A second learning unit configured to learn a generator that generates pseudo-abnormal data statistically similar to the true abnormal data, using the frequency spectrum of the abnormal data obtained by the data processing unit as the true abnormal data; A storage unit configured to store the pseudo-abnormal data generated using the learned generator constructed by the second learning unit An abnormality management device comprising the above.

2. In the abnormality management device according to Claim 1, Further comprising a collection unit configured to collect the frequency spectrum of the signal to be managed; A determination unit configured to determine that the signal to be managed is an abnormal signal when the frequency spectrum of the signal to be managed collected matches the pseudo-abnormal data stored in the storage unit An abnormality management device characterized by comprising the above.

3. In the abnormality management device according to Claim 2, Further comprising a notification unit configured to notify externally that an abnormality has occurred in the communication terminal that measured the abnormal signal when it is determined by the determination unit that the signal is an abnormal signal An abnormality management device comprising the above.

4. In the abnormality management device according to Claim 1, The second learning unit performs adversarial learning of a generative model having the generator and a discriminator that discriminates between the pseudo-abnormal data generated by the generator and the true abnormal data An abnormality management device characterized by the above.

5. An abnormality management method executed by a computer, In a first learning step, using, as teacher data, normal data indicating a normal frequency spectrum in which the intensity of each frequency component among the frequency spectra of a plurality of signals is normal, the parameters of a probability model that outputs the posterior probability that the intensity of each frequency component is normal are learned by maximum likelihood estimation. In a derivation step, based on the posterior probability estimated by the learned probability model, the probability distribution of abnormal data indicating a frequency spectrum including frequency components with abnormal intensities, the probability distribution of the normal data, and the prior probability of being normal, the probability distribution of the abnormal data is derived. In a data processing step, based on the derived probability distribution of the abnormal data, the frequency spectrum of the abnormal data is obtained. In a second learning step, using the frequency spectrum of the abnormal data obtained in the data processing step as true abnormal data, a generator that generates pseudo-abnormal data statistically similar to the true abnormal data is learned. In a storage step, the pseudo-abnormal data generated using the learned generator constructed in the second learning step is stored in a storage unit. An anomaly management method comprising the above steps.

6. The anomaly management method according to claim 5, wherein further comprising a collection step of collecting the frequency spectrum of the signal to be managed, and a determination step of determining that the signal to be managed is an abnormal signal when the frequency spectrum of the signal to be managed collected matches the pseudo-abnormal data stored in the storage unit. An anomaly management method characterized by comprising the above steps.

7. The anomaly management method according to claim 6, wherein further comprising a notification step of notifying externally that an anomaly has occurred in the communication terminal that measured the abnormal signal when it is determined in the determination step that the signal is an abnormal signal. An anomaly management method comprising the above steps.

8. The anomaly management method according to claim 5, wherein the second learning step performs adversarial learning of a generative model having the generator and a discriminator that discriminates between the pseudo-abnormal data generated by the generator and the true abnormal data. An anomaly management method characterized by the above.

Citation Information

Patent Citations

  • Method for identifying early failure of rotary machine

    CN115238736A

  • Methods and systems for identifying presence of abnormal heart sounds of a subject

    EP3885974A1

  • Apparatus, system and method for determining abnormality

    JP2020027386A

  • Anomaly detection system, anomaly detection method, anomaly detection program, and trained model generation method

    JP2022037241A

  • Anomaly detection device and anomaly detection method

    JP7549177B1

Cited By

  • Abnormality management device and abnormality management method

    JP7737584B1

  • Abnormality management device and abnormality management method

    JP7752279B1

  • Abnormality management device and abnormality management method

    JP7755771B1

  • Abnormality management device and abnormality management method

    JP7762832B1

  • Abnormality management device and abnormality management method

    JP7804825B1