Anomaly Detection Method, Device and Computer Readable Medium for a Dynamic Control System

By using neural networks for system identification and Bayesian filtering in dynamic control systems, the detection problems in the prior art under uncertain noise and model errors are solved, and more accurate and reliable abnormality detection is achieved.

CN114815763BActive Publication Date: 2025-06-27SIEMENS AG
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110112274.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-01-27
Publication Date
2025-06-27
Estimated Expiration
2041-01-27

AI Technical Summary

Technical Problem

In dynamic control systems, existing anomaly detection methods are difficult to accurately detect abnormalities when sensor noise and model error are uncertain, especially in highly nonlinear dynamic systems.

Method used

A specially designed neural network is used for system identification, and the system identification process is automatically completed through training, and combined with Bayesian filtering method, the likelihood of the sensor measured values ​​is observed in real time to detect abnormalities.

Benefits of technology

It significantly improves the versatility of system identification, can accurately capture the highly nonlinear dynamic behavior of dynamic control systems, and improves the accuracy and reliability of anomaly detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114815763B_ABST
    Figure CN114815763B_ABST
Patent Text Reader

Abstract

Embodiments of the present invention relate to an anomaly detection method, apparatus, and computer-readable medium for a dynamic control system. The method includes: initializing the hidden state distribution of the dynamic control system using the g-network in the neural network; receiving the measurement value of the sensor and the state value of the trigger at the current time point t obtained by real-time monitoring; inputting at least one first sampling point into the f-network in the neural network to predict at least one second sampling point, where the first sampling point represents the hidden state distribution of the dynamic control system at the neighboring time point t-1 before the current time point t, and the second sampling point represents the prior hidden state distribution of the dynamic control system at the current time point t; using the h-network in the neural network to map the second sampling point to the sensor measurement value space to predict the probability distribution of the sensor measurement value of the dynamic control system at the current time point t; and determining whether there is an anomaly in the system by comparing the measurement value obtained by real-time monitoring with the predicted probability distribution.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the technical field of anomaly detection, and in particular, to an anomaly detection method, device, and computer-readable medium for a dynamic control system. Background Art

[0002] Active state monitoring of dynamic control systems is crucial for ensuring the safety and reliability of various industries (such as discrete manufacturing, power generation, building asset management, and process industries). To pre-detect operating faults in predictive maintenance, an anomaly detection system is usually deployed to monitor the dynamic behavior of the control system, including the dynamic changes of sensor measurements and trigger status values over time. However, in practice, it is still very difficult to establish an effective anomaly detection model with a high true positive rate and a low false positive rate for dynamic control systems because:

[0003] First, the amount of fault data is usually small, and the anomaly detection model must be able to detect unknown faults.

[0004] Second, for control systems with highly nonlinear dynamics, the anomaly detection model must be able to accurately capture the complex dynamic behavior of the system.

[0005] Third, anomaly detection must accurately detect anomalies when the amount of sensor noise and model error are unknown at random time points.

[0006] Currently, the anomaly detection methods for dynamic control systems include: residual-based anomaly detection methods, density-based anomaly detection methods, one-class classification-based anomaly detection methods, and rule-based anomaly detection methods.

[0007] Among them, the residual-based anomaly detection method relies on a prediction model such as a neural network-based regression model (see "Long Short-Term Memory", Hochreiter, Sepp and Jürgen Schmidhuber, published in "Neural Computation" from pages 1735 to 1780 in 1997) or a reconstruction model such as an autoencoder (see "A Fast Learning Algorithm for Deep Belief Networks", Geoffrey E. Hinton, Simon Osindero and Yee-Whye Teh, published in "Neural Computation" from pages 1527 to 1554 in 2006, and "Autoencoding Variational Bayes", Diederik P. Kingma and Max Welling, published on the preprint platform arXiv in 2013) to compress the measurement values of the sensor to obtain low-dimensional features and perform reconstruction. Then, the predicted or reconstructed measurement values are compared with the measurement values obtained from real-time monitoring to generate residuals. If the residual exceeds a preset threshold, an anomaly is considered to be detected. In practice, due to the unknown amount of sensor noise and the prediction error or reconstruction error at each time point, it is difficult to define a strict threshold between the measurement values of normal and abnormal sensors. Therefore, the performance of the residual-based method usually deteriorates when the measurement values of the sensor are subject to large noise interference or the errors of model prediction or reconstruction are unstable.

[0008] Among them, the density-based anomaly detection method models the probability distribution of the measured values of the sensor at each time point, and an anomaly is considered detected when the likelihood value of the measured value during real-time monitoring is lower than a preset threshold. The density-based anomaly detection method includes the Kalman filter algorithm (see "Kalman Filter", C.K. Chui and G.Chen et al. published in "Springer" in 2017; and "Unscented Kalman Filter for Nonlinear Estimation", Eric A. Wan and Rudolph Van Der Merwe published in "IEEE Symposium on Adaptive Systems for Signal Processing, Communications, and Control" (No. 00EX373) in 2000) and the Bayesian estimation algorithm (see "Bayesian Sensor Estimation for Machine Condition Monitoring", Chao Yuan and Claus Neubauer published on pages 517-520 of the proceedings of the IEEE International Conference on Acoustics, Speech, and Signal Processing in 2007; and "Robust Sensor Estimation Using Temporal Information", Chao Yuan and Claus Neubauer published on pages 2077-2080 of the proceedings of the IEEE International Conference on Acoustics, Speech, and Signal Processing in 2008). Although generally the density-based method is more robust to sensor noise than the residual-based method, it still has certain limitations that restrict its practical application. For example: Before applying the Kalman filter method, it is usually necessary to establish a mathematical model of the physical dynamic process through system identification, and system identification is relatively difficult in practice. In addition, many density-based methods usually require high prior knowledge when modeling the physical dynamic process and / or the distribution of sensor measured values. When the physical dynamic process is highly nonlinear, the performance of these methods may deteriorate.

[0009] Anomaly detection methods based on one-class classification, such as one-class support vector machine (SVM) (see "One-Class Support Vector Machines for Document Classification", Larry M. Manevitz and Yousef Malik published on pages 139-154 of the Journal of Machine Learning Research in 2001) and isolation forest (see "Isolation Forest", Fei Tony Liu, Kai Ming Ting, and Zhi-Hua Zhou published in the 8th IEEE International Conference on Data Mining in 2008), can be naturally applied to the anomaly detection of dynamic control systems and have good interpretability. However, due to the curse of dimensionality and the high nonlinearity of system dynamics, these methods are no longer applicable to today's dynamic control systems.

[0010] In the rule-based anomaly detection method, the state conditions that the system must maintain obtained from prior knowledge are acquired. Any physical process value that violates this rule during real-time monitoring is classified as an anomaly. Typically, these rules are defined by domain experts during the system design phase, and manual processing is very time-consuming and laborious. In addition, especially when these rules cross subsystems, there are many potential rules that are difficult for humans to discover. Therefore, the rule-based anomaly detection method is often limited by the inability to discover sufficient rules. Summary of the Invention

[0011] Embodiments of the present invention provide an anomaly detection method, apparatus, and computer-readable medium for a dynamic control system. First, a specially designed neural network structure is used for system identification of the dynamic control system, and the system identification process is automatically completed through the training of the neural network. The use of the neural network can significantly improve the generality of system identification and can obtain the highly nonlinear dynamic behavior of the dynamic control system. Moreover, it also overcomes the common problem of the dimensionality disaster that may be brought by models with general expressive power. Then, considering the uncertainty from sensor noise and model errors, the Bayesian filtering method is used to detect anomalies through the likelihood of sensor measurement values observed in real time.

[0012] In a first aspect, there is provided a method for anomaly detection of a dynamic control system, which can be implemented by a computer program. In this method, a hidden state distribution of a dynamic control system is initialized using a g-network; the measured values of sensors and the status values of triggers in the dynamic control system at the current time point t obtained by real-time monitoring are received; at least one first sampling point is input into an f-network to predict at least one second sampling point, where the at least one first sampling point is used to represent the hidden state distribution of the dynamic control system at a neighboring time point t-1 before the current time point t, and the at least one second sampling point is used to represent the prior hidden state distribution of the dynamic control system at the current time point t; the at least one second sampling point is mapped to the sensor measurement value space using an h-network to predict the probability distribution of the sensor measurement values of the dynamic control system at the current time point t; whether there is an anomaly in the dynamic control system is determined by comparing the measured values obtained by real-time monitoring with the predicted probability distribution; the g-network, f-network, and h-network are sub-networks in a neural network used to represent the dynamic distribution of the dynamic control system, the g-network is a feed-forward network for encoding the measured values of sensors into a low-dimensional hidden state vector; the f-network encodes the measured values of sensors and the status values of triggers within a sliding window into a vector, and uses the hidden state vector at the current time point encoded by the g-network to predict the hidden state vector at the next time point; the h-network is a feed-forward network that decodes the predicted hidden state vector at the next time point into the measured values of sensors and decodes the low-dimensional hidden state vector at the current time point into the measured values of sensors; the neural network is trained using the measured values of sensors obtained under normal operating conditions of the dynamic control system.

[0013] In a second aspect, there is provided an anomaly detection device for a dynamic control system, including:

[0014] - An initialization module configured to initialize a hidden state distribution of a dynamic control system using a g-network;

[0015] - A data acquisition module configured to receive the measured values of sensors and the status values of triggers in the dynamic control system at the current time point t obtained by real-time monitoring;

[0016] - A prediction module, configured to: input at least one first sampling point into the f network to predict at least one second sampling point, where the at least one first sampling point is used to represent the hidden state distribution of the dynamic control system at the neighboring time point t-1 before the current time point t, and the at least one second sampling point is used to represent the prior hidden state distribution of the dynamic control system at the current time point t; and use the h network to map the at least one second sampling point to the sensor measurement value space to predict the probability distribution of the sensor measurement value of the dynamic control system at the current time point t;

[0017] - An anomaly judgment module, configured to judge whether there is an anomaly in the dynamic control system by comparing the measured value obtained by real-time monitoring with the predicted probability distribution;

[0018] Wherein, the g network, f network and h network are sub-networks in a neural network used to represent the dynamic distribution of the dynamic control system. The g network is a feed-forward network, used to encode the measured value of the sensor into a low-dimensional hidden state vector; the f network encodes the measured value of the sensor and the state value of the trigger within a sliding window into a vector, and uses the hidden state vector at the current time point encoded by the g network to predict the hidden state vector at the next time point; the h network is a feed-forward network, which decodes the predicted hidden state vector at the next time point into the measured value of the sensor, and decodes the low-dimensional hidden state vector at the current time point into the measured value of the sensor; the neural network is trained using the measured values of the sensors obtained under the normal working conditions of the dynamic control system.

[0019] In a third aspect, there is provided an anomaly detection device for a dynamic control system, including: at least one memory, configured to store computer-readable code; at least one processor, configured to call the computer-readable code and execute the steps provided in the first aspect.

[0020] In a fourth aspect, a computer-readable medium has computer-readable instructions stored thereon, and when the computer-readable instructions are executed by a processor, the processor is caused to execute the steps provided in the first aspect.

[0021] For any of the above aspects, optionally, the posterior hidden state distribution of the dynamic control system at the current time point t can also be updated to obtain the first sampling point at the neighboring time point t+1 after the current time point t. Thereby enabling real-time tracking of the uncertainty of the system hidden state and increasing the reliability of anomaly monitoring.

[0022] For any of the above aspects, optionally, the loss function used during the training of the neural network minimizes the sum of the reconstruction error and the prediction error of the measurement values of the sensors at each time point for training. This end-to-end training method makes our neural network very easy to implement in practical applications.

[0023] For any of the above aspects, optionally, the at least one first sampling point and the at least one second sampling point are both sigma sampling points. This enables the efficient expression of the probability distribution with the fewest sampling points, greatly improving the operating efficiency of the method. Description of the Drawings

[0024] Figure 1 It is a schematic structural diagram of the neural network for system identification in the embodiments of the present invention.

[0025] Figure 2 It is a comparison diagram of the effects of anomaly detection using the embodiments of the present invention and the existing methods.

[0026] Figure 3 It is a schematic structural diagram of the anomaly detection device provided by the embodiments of the present invention.

[0027] Figure 4 It is a flowchart of the anomaly detection method provided by the embodiments of the present invention.

[0028] List of Reference Numerals:

[0029]

[0030] Detailed Embodiments

[0031] Now, the subject matter described herein will be discussed with reference to exemplary embodiments. It should be understood that discussing these embodiments is only to enable those skilled in the art to better understand and thus implement the subject matter described herein, and is not a limitation on the scope of protection, applicability, or examples set forth in the claims. The functions and arrangements of the elements discussed can be changed without departing from the scope of protection of the content of the embodiments of the present invention. Each example can omit, substitute, or add various processes or components as needed. For example, the described method can be executed in an order different from the described order, and each step can be added, omitted, or combined. Additionally, the features described relative to some examples can also be combined in other examples.

[0032] As used herein, the term "comprising" and its variants denote open terms meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" and "an embodiment" mean "at least one embodiment". The term "another embodiment" means "at least one other embodiment". The terms "first", "second", etc. may refer to different or the same objects. There may be other definitions below, whether explicit or implicit. Unless explicitly specified in the context, the definition of a term is consistent throughout the specification.

[0033] To make the solutions provided by the embodiments of the present invention easier to understand, some concepts involved are explained here. It should be noted that these explanations should not be regarded as limiting the protection scope of the claims of the present invention.

[0034] 1. Dynamic control system

[0035] The control system is divided into a static control system and a dynamic control system. The differences between the two are as follows:

[0036] 1) Differences in changes

[0037] The state variables of the dynamic control system change significantly with time and are functions of time. The state variables of the static control system change little with time and are difficult to observe and measure.

[0038] 2) Differences in parameter correlation

[0039] The dynamic control system is composed of multiple variables or parameters, and these variables are interconnected and in constant motion. The output of the static control system at any moment is only related to the input at that moment and has nothing to do with the input before or after that moment.

[0040] 3) Differences in final states

[0041] The final state of the dynamic control system may be either an equilibrium state or a non-equilibrium state. The final state of the static system is an equilibrium state.

[0042] In addition, the dynamic control system may also have characteristics such as highly nonlinear dynamics and unknown sensor noise levels and model errors, which is also the reason why the aforementioned current anomaly detection methods are difficult to apply to dynamic control systems.

[0043] 2. System identification

[0044] System identification is to determine the mathematical model describing the behavior of the system according to the input-output time function of the system. The purpose of establishing a mathematical model through system identification is to estimate the important parameters characterizing the behavior of the system and establish a model that can imitate the behavior of the real system.

[0045] 3. Time series

[0046] A time series is a series of ordered data. Usually, it is data sampled at equal time intervals. If the intervals are not equal, the time scale of each data point is generally marked.

[0047] Next, the embodiments of the present invention will be described in detail with reference to the accompanying drawings.

[0048] First, in combination with Figure 1 and Figure 2 the neural network used for system identification of the dynamic control system and the process of anomaly detection using Bayesian filtering in the embodiments of the present invention are described.

[0049] I. System identification

[0050] Figure 1 The structure of the neural network 10 used for system identification in the embodiments of the present invention is shown.

[0051] Without loss of generality, assume that the dynamic control system includes some sensors and some triggers. Let x t represent the measurement values of these sensors at time point t, and u t represent the state values of these triggers at time point t. Here, the following neural network structure is proposed to obtain the dynamic changes of the time series of the dynamic control system.

[0052] Here, the neural network 10 may include three sub-networks, respectively called the g-network, the f-network, and the h-network.

[0053] Among them, the g-network, with ω as a parameter, is a feed-forward network. Among them, the measurement values x t-1 of the sensors at time point t - 1 are used as inputs, and the measurement values of these sensors are encoded into a low-dimensional hidden state vector z t -1 .

[0054] The f-network, with θ as a parameter, takes the measurement values of the sensors and the state values of the triggers within a sliding window of length l as inputs, and can encode them into a hidden vector h t-1 using a Long Short-Term Memory (LSTM) neural network. Further, using h t-1 as the context of the learned time series, the f-network also takes the hidden state vector z t-1 as an input, and then uses a feed-forward network to predict the hidden state vector z t at the next time point.

[0055] The h-network takes is a parameter, and is a feed - forward network that takes the hidden state vector as input and decodes the hidden state vector into the corresponding sensor measurement value. It should be noted that Figure 1 the two h networks in

[0056] can share the same set of weights. In summary, the entire neural network 10 can be expressed as t-1 to take the sensor measurement value x at time point t - 1 t-l:t-1 , the sensor measurement values x within the sliding window t-l:t-1 and the state value u of the trigger and as inputs, and take the sensor measurement value

[0057] after decoding the hidden state vector

[0058]

[0059] as outputs. In the above loss function, the first two terms are respectively the reconstruction error and prediction error of the sensor measurement value, and the third term is a smoothing factor, so that two temporally consecutive hidden state vectors can be closer. α, β, and γ are hyperparameters representing the weights of the three terms.

[0060] After the model training is completed, the dynamic behavior of the dynamic control system can be represented as follows:

[0061] z t = f θ (z t-1 ; x t-l:t-1 , u t-l:t-1 ) + Q

[0062]

[0063] where Q is the covariance matrix of the prediction error, which is evaluated based on the empirical value of the prediction error on the validation dataset obtained from the following formula:

[0064] g ω (x t ) - f θ (g ω (x t-1 ) ; x t-l:t-1 , u t-l:t-1 ) for all t > l

[0065] Wherein, R is the covariance matrix of the reconstruction error, which is evaluated based on the reconstruction error on the same validation data set obtained from the following formula:

[0066] For all

[0067] II. Bayesian Filter for Anomaly Detection

[0068] Here, Bayesian filtering can be used for anomaly detection to iteratively estimate the probability distribution of the hidden state of the dynamic control system changing over time.

[0069] Specifically, z t and P t can be used to track the probability distribution of the hidden state of the dynamic control system (hereinafter referred to as the "hidden state distribution"). Among them, z t represents the mean vector, and P t represents the covariance matrix of the hidden state at time point t.

[0070] The whole process is divided into an initial step, a prediction step, an update step, and an anomaly detection step.

[0071] 1. Initial Step

[0072] Let t = 0, initialize z 0 = g ω (x 0 ), P 0 = 0 (all elements are 0).

[0073] Then, the following three steps (prediction, update, and anomaly detection) are used to iteratively estimate z t and P t and detect anomalies:

[0074] 2. Prediction Step

[0075] In this step, the mean and covariance of the prior of the hidden state distribution at time point t are calculated. First, a set of sampling points Z (hereinafter referred to as the "first sampling points") are generated for the hidden state distribution at time point t - 1 through a sampling function (such as the sigma function). If the sampling function is the sigma function, the sampling points are sigma points. Hereinafter, the example of sampling with the sigma function will be used for illustration. The weights corresponding to these sigma points are W m and W c . Among them, an example of the sigma function is to use Van der Merwe's Scaled sigma point algorithm (see "Sigma Point Kalman Filter for Probabilistic Inference in Dynamic State Space Models", published by Vander Merwe in 2004).

[0076] Z, W m , W c = sigmafunction(z t-1 , P t-1 ) (1)

[0077] Select sigma points such that the hidden state distribution of the dynamic control system at time point t-1 can be represented by only a small number of sigma points. These selected sigma points can be passed through the f network to predict at least one second sampling point (an example here is the sigma point) such that:

[0078] Y = f θ (Z, x t-l:t-1 , u t-l:t-1 ) (2)

[0079] Among them, the mean and covariance of the prior hidden state distribution at time point t can be calculated through a lossless transformation function:

[0080]

[0081]

[0082] 3. Update step

[0083] In this step, calculate the mean and covariance of the posterior of the hidden state distribution of the dynamic control system at time point t (referred to as z t and P t ). First, use the h network to map the sigma points Y of the prior of the hidden state distribution of the dynamic control system to the sensor measurement value space.

[0084] L = h(Y) (5)

[0085] Use the lossless transformation function to calculate the mean and covariance of these measurement sigma points.

[0086]

[0087]

[0088] The Kalman gain can be obtained through the following formula:

[0089]

[0090] Then, the following update can be performed:

[0091]

[0092]

[0093] 4. Abnormal Detection Steps

[0094] In this step, anomalies can be detected by calculating the Mahalanobis distance between the measured values obtained from real-time monitoring and the predicted probability distribution:

[0095]

[0096] When the Mahalanobis distance exceeds the preset threshold τ, it indicates that even considering the sensor and predicted noise, these measured values obtained from real-time monitoring are impossible, that is, an anomaly is detected.

[0097] III. Experiments

[0098] The method provided by the embodiment of the present invention is used to detect anomalies in the pump control system dataset. The system data consists of the measured values of 52 sensors sampled every minute within 5 months. There are 7 faults in the dataset that last for several hours to several days. Here, the dataset is divided into a training set, a validation set, and a test set according to a ratio of 3:1:1. All 7 faults occur within the test set period, which means that the training set and the validation set only contain data under normal operating conditions. We use the training set to train the above neural network and use the validation set to adjust the hyperparameters to obtain the best validation performance. The anomaly detection performance is evaluated on the test set.

[0099] Figure 2 shows the performance when using the method of the embodiment of the present invention and several other methods (Isolation Forest, Bayesian Estimation Algorithm, Autoencoders including Sparse Autoencoder, Variational Autoencoder, LSTM Autoencoder) for anomaly detection. All baseline models are trained using the same dataset.

[0100] Assuming that the maximum acceptable false positive rate (FPR) is 0.01 (1 false alarm per 100 minutes), compare the values of the area under the partial ROC curve (Area Under ROC curve, AUC) when the maximum FPR is 0.01. The higher the AUC value, the more anomalies the model can detect under the same FPR. Figure 2 shows that the method of the embodiment of the present invention is significantly better than other methods. Among them, No. 1 corresponds to the embodiment of the present invention, No. 2 corresponds to Isolation Forest, No. 3 corresponds to Seq2SeqLSTM, No. 4 corresponds to Dilated Convolutional Neural Network (DilatedCNN), No. 5 corresponds to Sparse Autoencoder, No. 6 corresponds to Variational Autoencoder, No. 7 corresponds to LSTM Autoencoder, and No. 8 corresponds to Bayesian Estimation Algorithm.

[0101] Above, the principles of system identification for the dynamic control system and anomaly detection using Bayesian filtering in the embodiments of the present invention are introduced. Next, the apparatus 30 capable of implementing anomaly detection provided by the embodiments of the present invention will be introduced.

[0102] The anomaly detection apparatus 30 provided by the embodiments of the present invention can be implemented as a network of computer processors to execute the anomaly detection method 400 for the dynamic control system in the embodiments of the present invention. The anomaly detection apparatus 30 can also be a single computer as shown in Figure 3 which includes at least one memory 301, which includes a computer-readable medium, such as a random access memory (RAM). The apparatus 30 also includes at least one processor 302 coupled to the at least one memory 301. Computer-executable instructions are stored in the at least one memory 301, and when executed by the at least one processor 302, can cause the at least one processor 302 to execute the steps described herein. The at least one processor 302 can include a microprocessor, an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a central processing unit (CPU), a graphics processing unit (GPU), a state machine, etc. Embodiments of computer-readable media include, but are not limited to, floppy disks, CD-ROMs, magnetic disks, memory chips, ROMs, RAMs, ASICs, configured processors, all-optical media, all magnetic tapes or other magnetic media, or any other medium from which a computer processor can read instructions. In addition, various other forms of computer-readable media can send or carry instructions to a computer, including routers, private or public networks, or other wired and wireless transmission devices or channels. The instructions can include code in any computer programming language, including C, C++, C#, Visual Basic, Java, and JavaScript.

[0103] When executed by the at least one processor 302, Figure 3 the at least one memory 301 shown in

[0104] - An initialization module 311, configured to initialize a hidden state distribution of a dynamic control system using the g network in the neural network 10 shown in Figure 1 ;

[0105] - A data acquisition module 312, configured to receive the measured values of the sensors and the status values of the triggers in the dynamic control system at the current time point t obtained by real-time monitoring;

[0106] - A prediction module 313, configured to: input at least one first sampling point intoFigure 1 The f-network in the neural network 10 shown is configured to predict at least one second sampling point, where at least one first sampling point is used to represent the hidden state distribution of the dynamic control system at the neighboring time point t-1 before the current time point t, and at least one second sampling point is used to represent the prior hidden state distribution of the dynamic control system at the current time point t; and use the h-network in the neural network 10 to map at least one second sampling point to the sensor measurement value space to predict the probability distribution of the sensor measurement values of the dynamic control system at the current time point t;

[0107] - An anomaly judgment module 314, configured to judge whether there is an anomaly in the dynamic control system by comparing the measured value obtained by real-time monitoring with the predicted probability distribution;

[0108] Optionally, the anomaly detection program 31 may further include an update module 315, configured to update the posterior hidden state distribution of the dynamic control system at the current time point t for obtaining the first sampling point at the neighboring time point t+1 after the current time point t.

[0109] Optionally, the loss function adopted during the training of the neural network minimizes the sum of the reconstruction error and the prediction error of the measured values of the sensors at each time point used for training.

[0110] Optionally, both the at least one first sampling point and the at least one second sampling point are sigma sampling points.

[0111] Optionally, the anomaly detection device 30 may further include a communication module 303, connected to at least one processor 302 and at least one memory 301 through a bus, for the anomaly detection device 30 to communicate with external devices.

[0112] It should be noted that the embodiments of the present invention may include devices having architectures different from Figure 3 the architecture shown. The above architecture is merely exemplary and is used to explain the method 400 provided by the embodiments of the present invention.

[0113] In addition, the above-mentioned modules may also be regarded as various functional modules implemented by hardware, used to implement various functions involved when the anomaly detection device 30 executes the anomaly detection method of the dynamic control system. For example, the control logic of each process involved in the method is pre-burned into chips such as Field-Programmable Gate Array (FPGA) chips or Complex Programmable Logic Devices (CPLD), and these chips or devices execute the functions of the above-mentioned modules. The specific implementation manner may depend on engineering practices.

[0114] Optionally, the anomaly detection device 30 may further include a communication module 303, which is connected to at least one processor 302 and at least one memory 301 through a bus and is used for the anomaly detection device 30 to communicate with external devices.

[0115] It should be noted that the embodiments of the present invention may include devices having architectures different from Figure 3 the shown architecture. The above architecture is merely exemplary and is used to explain the method 400 provided by the embodiments of the present invention.

[0116] In addition, the above-mentioned modules can also be regarded as various functional modules implemented by hardware, which are used to implement various functions involved when the anomaly detection device 30 executes the anomaly detection method of the dynamic control system. For example, the control logic of each process involved in the method is pre-burned into chips such as a Field-Programmable Gate Array (FPGA) chip or a Complex Programmable Logic Device (CPLD), and these chips or devices execute the functions of the above-mentioned modules, and the specific implementation manner can depend on engineering practices.

[0117] Next, refer to Figure 4 to describe the anomaly detection method 400 of the dynamic control system provided by the embodiments of the present invention. As Figure 4 shown, the method may include the following steps:

[0118] -S401: Initialize a hidden state distribution of a dynamic control system using the g network in the neural network 10 shown in Figure 1 ;

[0119] -S402: Receive the measurement value of the sensor and the state value of the trigger in the dynamic control system at the current time point t obtained by real-time monitoring;

[0120] -S403: Input at least one first sampling point into the f network in the neural network 10 to predict at least one second sampling point, where at least one first sampling point is used to represent the hidden state distribution of the dynamic control system at the neighboring time point t - 1 before the current time point t, and at least one second sampling point is used to represent the prior hidden state distribution of the dynamic control system at the current time point t;

[0121] -S404: Use the h network in the neural network 10 to map at least one second sampling point to the sensor measurement value space to predict the probability distribution of the sensor measurement value of the dynamic control system at the current time point t;

[0122] -S405: Determine whether there is an anomaly in the dynamic control system by comparing the measurement value obtained by real-time monitoring with the predicted probability distribution.

[0123] Optionally, step S406 may further be included in method 400: updating the posterior hidden state distribution of the dynamic control system at the current time point t for obtaining a first sampling point at a neighboring time point t+1 after the current time point t.

[0124] Optionally, the loss function adopted during the training of neural network 10 minimizes the sum of the reconstruction error and the prediction error of the measurement values of sensors at each time point for training.

[0125] Optionally, at least one first sampling point and at least one second sampling point are both sigma sampling points.

[0126] In addition, an embodiment of the present invention further provides a computer-readable medium, on which computer-readable instructions are stored. When the computer-readable instructions are executed by a processor, the processor is caused to execute the foregoing anomaly detection method for a dynamic control system. Embodiments of the computer-readable medium include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Optionally, the computer-readable instructions may be downloaded from a server computer or a cloud via a communication network.

[0127] It should be noted that not all steps and modules in the above-mentioned various processes and system structure diagrams are necessary, and some steps or modules may be ignored according to actual needs. The execution order of each step is not fixed and can be adjusted according to needs. The system structure described in the above-mentioned various embodiments may be a physical structure or a logical structure. That is, some modules may be implemented by the same physical entity, or some modules may be implemented separately by multiple physical entities, or some components in multiple independent devices may be jointly implemented.

Claims

1. An anomaly detection method for a dynamic control system (400), characterized in that, Including: - Initializing (S401) the hidden state distribution of a dynamic control system using a g-network; - Receiving (S402) the measured values of sensors and the state values of triggers in the dynamic control system at the current time point t obtained by real-time monitoring; - Inputting (S403) at least one first sampling point into an f-network to predict at least one second sampling point, where the at least one first sampling point is used to represent the hidden state distribution of the dynamic control system at the neighboring time point t-1 before the current time point t, and the at least one second sampling point is used to represent the prior hidden state distribution of the dynamic control system at the current time point t; - Using an h-network to map (S404) the at least one second sampling point to the sensor measurement value space to predict the probability distribution of the sensor measurement values of the dynamic control system at the current time point t; - Judging (S405) whether there is an abnormality in the dynamic control system by comparing the measured values obtained by real-time monitoring with the predicted probability distribution; Wherein, the g-network, f-network, and h-network are sub-networks in a neural network used to represent the dynamic distribution of the dynamic control system. The g-network is a feedforward network used to encode the measured values of sensors into a low-dimensional hidden state vector; the f-network encodes the measured values of sensors and the state values of triggers within a sliding window into a vector and uses the hidden state vector at the current time point encoded by the g-network to predict the hidden state vector at the next time point; the h-network is a feedforward network that decodes the predicted hidden state vector at the next time point into the measured values of sensors at the next time point and decodes the low-dimensional hidden state vector at the current time point into the measured values of sensors at the current time point; the neural network is trained using the measured values of sensors obtained under normal operating conditions of the dynamic control system.

2. The method according to claim 1, characterized in that, Also including: - Updating (S406) the posterior hidden state distribution of the dynamic control system at the current time point t to obtain the first sampling point at the neighboring time point t+1 after the current time point t.

3. The method according to claim 1, characterized in that The loss function used during the training of the neural network minimizes the sum of the reconstruction error and prediction error of the measured values of sensors at each time point used for training.

4. The method according to claim 1, wherein Both the at least one first sampling point and the at least one second sampling point are sigma sampling points.

5. An abnormality detection device (30) for a dynamic control system, including: - An initialization module (311) configured to initialize the hidden state distribution of a dynamic control system using a g-network; - A data acquisition module (312) configured to receive the measured values of sensors and the state values of triggers in the dynamic control system at the current time point t obtained by real-time monitoring; - A prediction module (313) configured to: - Input at least one first sampling point into the f network to predict at least one second sampling point, where the at least one first sampling point is used to represent the hidden state distribution of the dynamic control system at the neighboring time point t - 1 before the current time point t, and the at least one second sampling point is used to represent the prior hidden state distribution of the dynamic control system at the current time point t; and - Use the h network to map the at least one second sampling point to the sensor measurement value space to predict the probability distribution of the sensor measurement values of the dynamic control system at the current time point t; - An anomaly judgment module (314) configured to judge whether there is an anomaly in the dynamic control system by comparing the measured value obtained by real-time monitoring with the predicted probability distribution; Wherein, the g network, f network, and h network are sub-networks in a neural network used to represent the dynamic distribution of the dynamic control system. The g network is a feed-forward network used to encode the measured values of the sensor into a low-dimensional hidden state vector; the f network encodes the measured values of the sensor and the state values of the trigger within a sliding window into a vector, and uses the hidden state vector at the current time point encoded by the g network to predict the hidden state vector at the next time point; the h network is a feed-forward network that decodes the predicted hidden state vector at the next time point into the measured values of the sensor at the next time point, and decodes the low-dimensional hidden state vector at the current time point into the measured values of the sensor at the current time point; the neural network is trained using the measured values of the sensor obtained under normal operating conditions of the dynamic control system.

6. The device according to claim 5, characterized in that, Further comprising: - An update module (315) configured to update the posterior hidden state distribution of the dynamic control system at the current time point t for obtaining the first sampling point at the neighboring time point t + 1 after the current time point t.

7. The device according to claim 5, characterized in that, The loss function used during the training of the neural network minimizes the sum of the reconstruction error and prediction error of the measured values of the sensor at each time point used for training.

8. The device according to claim 5, characterized in that Both the at least one first sampling point and the at least one second sampling point are sigma sampling points.

9. An abnormality detection device (30) for a dynamic control system, characterized in that, Comprising: - At least one memory (301) configured to store computer-readable code; - At least one processor (302) configured to call the computer-readable code and execute the method according to any one of claims 1 to 4.

10. A computer-readable medium, characterized in that, Computer-readable instructions are stored on the computer-readable medium, and when the computer-readable instructions are executed by the processor, the processor is caused to execute the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Satellite anomaly detection method based on Bayesian neural network

    CN110751199A

  • Electromechanical equipment fault diagnosis method based on deep neural network

    CN111666982A