A time series anomaly detection method for an online monitoring system of a selective metallurgy residue field
By constructing statistical and temporal features, and combining supervised algorithms with unsupervised algorithms, the problem of poor model stability in the online monitoring system of metallurgical slag yards was solved, achieving efficient anomaly detection and improved accuracy.
Patent Information
- Application Number
- CN202211322936.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-27
- Publication Date
- 2025-12-30
- Estimated Expiration
- 2042-10-27
AI Technical Summary
In existing online monitoring systems for slag beneficiation sites, traditional unsupervised learning methods suffer from poor model stability due to a lack of labels and inconsistent expert experience. This makes it difficult to effectively detect anomalies in multiple indicators, and the high randomness of single-base models can easily lead to false alarms or missed alarms.
By constructing statistical features, time features, and time series features, and combining supervised algorithms with unsupervised algorithms to select important features, multiple unsupervised algorithms are used for detection. Pseudo-labels are corrected in accordance with industry standards, and majority voting strategy and weighted fusion method are adopted to improve detection performance.
This system enables efficient anomaly detection in the online monitoring system for metallurgical slag yards, improves the performance of unsupervised algorithms, reduces false alarms and false negatives, and ensures the stability and accuracy of the model.
Smart Images

Figure CN115545115B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of metallurgical slag yard technology, specifically to a time series anomaly detection method for online monitoring systems of metallurgical slag yards. Background Technology
[0002] The online monitoring system for slag heaps (storage) collects data including wetting line, surface displacement, temperature, humidity, rainfall, and conductivity, but does not include accident or anomaly labels. Assessing the stability or degree of anomaly of these online indicators is an unsupervised process. Traditionally, fixed thresholds are configured, triggering alarms when these thresholds are exceeded. However, overly strict threshold settings lead to numerous false alarms, while relatively lenient thresholds result in missed alarms. Therefore, traditional monitoring methods are often ineffective in addressing anomalies hidden within short-term fluctuations in these indicators, making comprehensive and effective monitoring difficult.
[0003] The lack of accurate labels and understanding of specific stable types leads to a chicken-and-egg dilemma. A common approach to address this is to combine unsupervised learning methods with expert experience. This involves first performing detection using various unsupervised algorithms, then comparing the results with expert annotations to continuously optimize the model. However, the varying levels of experience among experts can introduce new noise.
[0004] Therefore, for unsupervised processes involving multiple indicators, the model is initially defined as multi-indicator anomaly detection. Multi-indicator anomaly detection has three characteristics: no labels; far fewer outliers than normal points; and complex patterns. The drawbacks of existing technologies are: high randomness and poor model stability in single-base models. Summary of the Invention
[0005] The purpose of this invention is to provide a time series anomaly detection method for an online monitoring system of metallurgical slag yards. Based on a small number of monitoring items, statistical features, time features, and time series features are constructed to further capture time series characteristics. A supervised algorithm is used to assist an unsupervised algorithm in selecting important features, thereby improving the performance of the unsupervised anomaly detection algorithm and solving the problems mentioned in the background art.
[0006] To achieve the above objectives, the present invention provides the following technical solution:
[0007] A method for detecting time-series anomalies in an online monitoring system for metallurgical slag yards includes the following steps:
[0008] S1: Extract dataset D from the online monitoring system of slag beneficiation sites. The data collection frequency for all monitoring items is 1 hour. The dataset contains timestamp indicators, slag beneficiation site names and monitoring items. Construct a dataset applicable to all slag beneficiation site databases.
[0009] S2: Determine the data processing plan based on the characteristics of time series data: delete features with poor data quality, fill in missing values, and delete features with a correlation coefficient greater than 0.7;
[0010] S3: For the retained features, transform them into new features that better represent the potential problems of the model, run multiple unsupervised algorithms, train data and identify anomalies for each base model, and finally obtain the anomaly label results for each base model. Implement a majority voting strategy to determine the anomaly label; normalize all features, and select features through filtering, wrapping and embedding methods; then use unsupervised algorithms for training to obtain anomaly scores.
[0011] S4: Set thresholds for specific features based on industry standards. If the threshold is exceeded, the record is set as abnormal, thereby correcting the above model results.
[0012] S5: Weighted fusion of detection results from multiple unsupervised algorithms to obtain anomaly scores;
[0013] S6: After the model has been online for a period of time, monitor the model's stability to determine whether the model needs to be rebuilt.
[0014] S7: The model results are provided to the outside world in the form of a RESTful API.
[0015] Furthermore, it also includes an offline learning phase and an online testing phase, with the data processing and feature engineering methods being consistent in both offline and online phases.
[0016] Furthermore, the steps in the offline learning phase are as follows:
[0017] S1: Data Exploration: Different slag beneficiation sites have different monitoring projects. The maximum set is used to construct model features to adapt to all slag beneficiation site monitoring projects. Check the data quality, including data type, null records, missing rate, number of null records, minimum value, 1st percentile, 5th percentile, 25th percentile, 50th percentile, 75th percentile, 95th percentile, 99th percentile, maximum value, mean, and variance statistics.
[0018] S2: Data processing: Fill in the blanks with the previous non-null value, delete records that are still empty after filling; delete features with a correlation coefficient greater than 0.7;
[0019] S3: Feature Construction: Construct features from the retained features, including statistical feature sets, time feature sets, and time series feature sets;
[0020] S4: Label generation: The abnormal labels of each of the five unsupervised algorithms are calculated and the majority voting strategy is used to obtain the abnormal labels.
[0021] S5: Feature processing: In order to eliminate the influence of units between indicators, data standardization is required to solve the comparability between data indicators;
[0022] S6: Feature selection: To improve the detection performance of unsupervised algorithms, feature selection methods such as wrapping, embedding, and filtering are adopted.
[0023] S7: Label Correction: Correct false labels in accordance with the national standard requirements for warning of displacement, seepage line, rainfall, and dry beach length;
[0024] S8: Model Training: The abnormal scores obtained by the five algorithms are weighted and fused according to the coefficients of 0.2:0.3:0.2:0.1:0.2, and the abnormal scores are divided into the interval [0,100] using the minimum maximum normalization method.
[0025] Furthermore, the early warning monitoring items in S7 during the offline learning phase are as follows:
[0026] 1) The normal operating values for displacement and displacement change rate of the slag beneficiation yard are determined based on the characteristics of the slag yard, engineering comparisons, statistical analysis of existing monitoring results, and experimental research. The early warning thresholds for displacement are shown in the table below:
[0027]
[0028] 2) The red warning value for the burial depth of the seepage line on the outer slope of the slag heap dam is determined according to the design documents and current standards, and the orange warning threshold is taken as 1.1 times the red warning threshold.
[0029] Minimum burial depth of the wetting line (m)
[0030]
[0031] 3) The determination of the warning values for the minimum safe freeboard and minimum dry beach length of the slag heap should comply with the following provisions:
[0032] The red warning thresholds for the minimum safe freeboard and minimum dry beach length of the slag heap are determined based on the design documents and current standards.
[0033] Dam level 1 2 3 4 5 Minimum safety over-height 1.5 1.0 0.7 0.5 0.4 Minimum dry beach length 150 100 70 50 40
[0034] The minimum safe height orange warning threshold is taken as 1.2 to 1.5 times the red warning threshold, and the minimum dry beach length orange warning threshold is taken as 1.1 to 1.4 times the red warning threshold.
[0035] An early warning should be issued if either the minimum safe superelevation or the minimum dry beach length reaches the warning threshold.
[0036] 4) The precipitation warning threshold is determined according to the following table:
[0037]
[0038] Furthermore, the steps for the anomaly detection phase are as follows:
[0039] S1: Save data processing, feature engineering, and model training results: Use pickle to save the results of offline data processing, feature engineering, and model training for online anomaly detection after deployment;
[0040] S2: Monitor model stability: Use the stability index PSI to quantitatively evaluate the distribution difference between offline and online samples, and statistically analyze the degree of change in the distribution of each risk category across the time window. If it is less than 10%, no model update is needed; if it is 10%-20%, the cause of the change needs to be checked and the monitoring frequency increased; if it is greater than 20%, the model needs to be iterated.
[0041] Compared with the prior art, the beneficial effects of the present invention are:
[0042] This invention provides a time-series anomaly detection method for online monitoring systems of metallurgical slag yards. The method extracts data from a database, fills in missing values, deletes some original indicators with high correlation coefficients, and constructs statistical, temporal, and time-series features from the remaining indicators through feature engineering. All features are normalized, and anomaly labels are determined through majority voting using an unsupervised algorithm. Feature selection is performed on the processed label data, using these importance indicators to improve the detection performance of the unsupervised algorithm. False labels are then corrected using industry standards. Finally, the detection results of the unsupervised algorithm are weighted and fused, dividing the anomaly scores [0, 100] into I (≥75), II (≥50), III (≥25), and IV (≥0). This method achieves the construction of statistical, temporal, and time-series features based on a small number of monitoring items, further capturing time-series characteristics. It uses a supervised algorithm to assist the unsupervised algorithm in selecting important features, thereby improving the performance of the unsupervised anomaly detection algorithm. Attached Figure Description
[0043] Figure 1 This is a model design drawing of the present invention;
[0044] Figure 2 This is a sample diagram of the input data for the present invention;
[0045] Figure 3 This is a flowchart of the model service call process of the present invention. Detailed Implementation
[0046] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0047] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions in the embodiments of the present application will be described clearly and completely in conjunction with the accompanying drawings.
[0048] like Figure 1 As shown, the implementation steps are as follows:
[0049] Step 1: Data Extraction: Prepare dataset D, containing N data points, with d dimensions including timestamps, names of selected slag yards (repositories), and monitoring items.
[0050] According to the "Technical Specification for Safety Monitoring of Tailings Dams" (AQ2030-2010), the safety monitoring of tailings dams should be based on the tailings dam's grade, dam construction method, geological conditions, and geographical features, with corresponding monitoring items and facilities set up. Different tailings slag heaps (dams) have different monitoring items, and the model features should be constructed with maximum integration to adapt to all online monitoring items for tailings slag heaps (dams). Because a data confidentiality agreement has been signed, Figure 2 The dataset has been anonymized and contains 66 features, 1 character field, 1 timestamp field, and 64 numeric fields.
[0051] Step 2: Data Processing: After deleting poor-quality data, handle missing values and correlations:
[0052] a) Delete data: Delete data with poor quality, such as features with a missing rate greater than 80%, blank rows, variance close to 0, constant columns, etc. For input data of a certain slag yard (storage), after deleting the data with poor quality, there are 15 features remaining, including 1 character type, 1 timestamp and 13 numeric fields.
[0053] b) Missing values are filled with the previous non-null value, and records that are still empty after filling are deleted.
[0054] c) Perform Pearson correlation calculations on each pair of retained features, and delete features with a correlation coefficient greater than 0.7.
[0055] After data processing, six features were retained, including one character type, one timestamp, and four numerical types.
[0056] Step 3: Feature Engineering: The process of transforming raw features into features that better represent the potential problems of the model.
[0057] a) Feature Construction: Feature construction was performed on the retained features, resulting in three feature sets: a statistical feature set, a temporal feature set, and a time-series feature set. The statistical feature set calculates the maximum, minimum, mean, standard deviation, median, variance, and skewness of a single feature over a time series. The temporal feature set includes the hour corresponding to the data timestamp, the day of the week, whether it is a weekend, and whether it is a holiday. The time-series feature set includes the maximum, minimum, mean, standard deviation, and median of a single feature at the same hour; the value of a single feature in the previous hour; and the maximum, minimum, mean, median, sum, variance, standard deviation, 0.25 quantile, 0.5 quantile, 0.75 quantile, and 0.9 quantile of a single feature over a day.
[0058] b) Label generation: Anomaly labels are calculated using five unsupervised algorithms. If more than three of the five labels mark anomalies, the data is classified as an anomaly; otherwise, it is classified as a normal point.
[0059] c) Feature processing: In order to eliminate the influence of different dimensions between indicators, data standardization is required to solve the comparability between data indicators.
[0060] d) Feature Selection: This application selects eight feature selection algorithms, including wrapping, embedding, and filtering. Based on the data characteristics of this system, wrapping algorithms include logistic regression and support vector machines; embedding algorithms include GBDT, random forest, extremely random trees, logistic regression with L1 regularization, and support vector machine classification algorithms with L1 regularization; and filtering algorithms include variance. There are still many metrics for feature construction, and directly using them for training or detection requires significant resources and contains a lot of useless data. After feature selection, the dimensionality-reduced metrics are used as new features, which can filter out some useless data and save resources.
[0061] Based on the four original numerical features, 100 new features were constructed, bringing the total to 104 features. After feature selection, 15 key features were chosen for subsequent model training.
[0062] Step Four: Industry Standards
[0063] a) Displacement rate change: A yellow warning is issued if the displacement rate exceeds 1.3 times the normal operating value. The calculation method for the normal operating value of displacement refers to the cloud model mentioned in the paper "Determination Method of 4-level Early Warning Threshold for Tailings Dam Deformation Based on Improved CM". The multi-step reverse cloud model generator transforms the monitoring data into qualitative concepts characterized by sample expectation, entropy, and hyperentropy, and establishes a mutual mapping between the monitoring data and the normal operating status of the slag yard (sump). Then, the forward cloud generator is used to construct cloud droplets to realize the mapping from qualitative concepts to quantitative characteristics. According to the 3E rule, if the value is within the range, it is considered that the slag yard (sump) is operating normally. In this embodiment of the invention, if the value exceeds the normal operating value, the record is marked as abnormal.
[0064] b) Immersion line: Based on the grade of the slag yard (storage), determine whether the real-time data of the minimum burial depth of the immersion line is lower than the minimum value. In this embodiment of the invention, if the burial depth is lower than the minimum immersion depth of the immersion line, the record is marked as abnormal.
[0065] c) Minimum dry beach length: Based on the grade of the slag heap (storage), determine whether the real-time data of the minimum dry beach length is lower than the red warning threshold. In this embodiment of the invention, if the length is lower than the red warning threshold, the record is marked as abnormal.
[0066] d) Rainfall: Statistical analysis of rainfall within 1 hour, 3 hours, 6 hours, 12 hours, and 24 hours. If the rainfall exceeds the yellow warning threshold, the record will be marked as abnormal.
[0067] Step 5: Model Training
[0068] a) The abnormal scores obtained from the five algorithms were weighted and fused according to the coefficients of 0.2:0.3:0.2:0.1:0.2.
[0069] b) Use the min-max normalization method to divide the outlier scores into the [0, 100] interval.
[0070] c) The model results are divided into four categories: IV (low risk), III (moderate risk), II (relatively high risk), and I (major risk);
[0071] After filtering important features, the evaluation metrics of the five unsupervised algorithms were all improved, especially the accuracy and precision metrics, which showed significant improvement.
[0072] Step Six: Model Monitoring: During model training, although a test set is used to verify the model's performance, overfitting cannot be completely ruled out. Furthermore, significant changes in the business context (such as natural disasters like floods and mudslides) during product operation cannot be ruled out. The model's assumptions and sample processing methods can cause a certain degree of deviation between the modeled samples and the actual sample distribution. These factors necessitate verifying the model's stability, and there are still sufficient reasons to doubt whether the model can maintain stable performance when faced with recent new sample data. The best way to examine stability is to extract recent samples across time windows and evaluate its stability by assessing the model's performance on these recent samples. If conditions permit, multiple samples from different time windows can be used for verification. Anomaly scores [0, 100] are divided into I (≥75), II (≥50), III (≥25), and IV (≥0). Based on these four levels, the degree of change in the distribution across time windows for each level is statistically analyzed.
[0073]
[0074] Step 7: Online Deployment: The model results are provided to the public via a RESTful API. The execution flow is as follows: Figure 3 As shown: The caller invokes the Web service API, the Web service invokes the native model, and returns the result. This method of exposing APIs in the form of HTTP is the industry standard for providing related services to the outside world.
[0075] In summary, the present invention provides a time series anomaly detection method for online monitoring systems of metallurgical slag yards. Compared with a single unsupervised anomaly detection algorithm, it realizes the construction of statistical features, time features, and time series features based on a small number of monitoring items, further capturing time series characteristics. It uses a supervised algorithm to assist the unsupervised algorithm in selecting important features, thereby improving the performance of the unsupervised anomaly detection algorithm.
[0076] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. A time series anomaly detection method for an online monitoring system of a selective metallurgy slag yard, characterized in that, Comprising the following steps: S1: Extracting the data set D of the on-line monitoring system of the dressing and smelting slag field, the data acquisition frequency of all monitoring items is 1 hour, the data set contains time stamp index, dressing and smelting slag field name and monitoring item, and the data set suitable for all dressing and smelting slag field libraries is constructed; S2: According to the characteristics of time series data, determine the data processing scheme: delete the features with poor data quality, fill in the missing values, delete the features with correlation coefficient greater than 0.7; S3: For the remaining features, convert them into new features that better represent the potential problems of the model, run multiple unsupervised algorithms, and train and judge the anomaly for each base model to get the final anomaly label result of each base model, and determine the anomaly label by majority voting strategy; Normalize all features, select features by filtering method, wrapping method and embedding method; Then train using unsupervised algorithm to get abnormal score; S4: Set threshold for features according to industry standards, set record as abnormal if exceeding threshold, and correct model result in this way; S5: Weighted fusion of detection results of multiple unsupervised algorithms to obtain abnormal score; S6: After the model is put into operation for a period of time, monitor the stability of the model to determine whether the model needs to be rebuilt; S7: The model result is provided in the form of Restful API interface.
2. The time series anomaly detection method for an online monitoring system of a selective metallurgy slag yard according to claim 1, wherein: It includes offline learning phase and online detection phase, and the data processing and feature engineering methods of the two phases are consistent.
3. The time series anomaly detection method for an online monitoring system of a selective metallurgy slag yard according to claim 2, wherein: The steps of the offline learning phase are as follows: Data exploration: Different monitoring items in different dressing and smelting slag fields, construct model features with maximum set to adapt to all dressing and smelting slag field monitoring items; Check data quality, including data type, null record, missing rate, null record number, minimum value, 1st percentile, 5th percentile, 25th percentile, 50th percentile, 75th percentile, 95th percentile, 99th percentile, maximum value, mean value, variance; Delete features with poor data quality to provide data quality; Data processing: Use the previous non-null value to fill in, delete the records that are still empty after filling; Delete features with correlation coefficient greater than 0.7; Feature construction: Feature construction is performed on the remaining features, including statistical feature set, time feature set and time series feature set; Label generation: Calculate the abnormal label of each algorithm through 5 kinds of unsupervised algorithms, and obtain the abnormal label by majority voting strategy; Feature processing: In order to eliminate the dimension effect between indexes, data standardization processing is needed to solve the comparability between data indexes; Feature selection: In order to improve the detection performance of unsupervised algorithm, the feature selection methods of wrapping method, embedding method and filtering method are adopted; Label correction: Combine the index early warning requirements of displacement, wetting line, rainfall and dry beach length in national standard to correct false label; Model training: Through 5 kinds of algorithms, the abnormal score value is obtained, and the weighted fusion is carried out according to the coefficient of 0.2:0.3:0.2:0.1:0.2, and the minimum maximum normalization method is used to divide the abnormal score value into [0, 100] interval.
4. The time series anomaly detection method for an online monitoring system of a selective metallurgy slag yard according to claim 3, wherein: The early warning monitoring items in the offline learning phase are as follows: 1) The normal operation values of displacement and displacement rate of the smelting slag field are determined according to the characteristics of the library, engineering analogy, statistical analysis of existing monitoring results and experimental research. The pre-warning threshold of displacement is as follows: 2) The red pre-warning threshold of the saturation line depth of the outer slope of the smelting slag field is determined according to the design documents and the existing standards. The orange pre-warning threshold is 1.1 times of the red pre-warning threshold: Minimum saturation line depth (m) 3) The pre-warning threshold of the minimum safe superhigh and the minimum dry beach length of the smelting slag field should meet the following provisions: The red pre-warning threshold of the minimum safe superhigh and the minimum dry beach length of the smelting slag field is determined according to the design documents and the existing standards: The orange pre-warning threshold of the minimum safe superhigh is 1.2-1.5 times of the red pre-warning threshold, and the orange pre-warning threshold of the minimum dry beach length is 1.1-1.4 times of the red pre-warning threshold; Either the minimum safe superhigh or the minimum dry beach length reaching the pre-warning threshold should be pre-warned; 4) The pre-warning threshold of precipitation is determined as follows:
5. The time series anomaly detection method for an online monitoring system of a selective metallurgical slag yard according to claim 2, wherein, The steps of the online detection stage are as follows: Save data processing, feature engineering, and model training results: use pickle to save the results of offline data processing, feature engineering, and model training to provide online anomaly detection in the form of Restful API interface; Monitor model stability: use the stability index PSI to quantitatively evaluate the distribution difference between offline samples and online samples, and statistically analyze the change degree of the distribution of each risk category across time windows. If the change is less than 10%, the model does not need to be updated; if the change is between 10% and 20%, the reason for the change needs to be checked and the monitoring frequency needs to be increased; if the change is greater than 20%, the model needs to be iterated.
Citation Information
Patent Citations
Unsupervised anomaly detection and robust trend prediction method for operation and maintenance data
CN111913849A
Power grid data anomaly detection method and device based on ensemble learning
CN113626502A