Method and device for monitoring industrial equipment
By introducing automatic encoder and automatic text information labeling technology in industrial equipment monitoring systems, the problem of abnormal behavior detection automation in industrial equipment in the prior art has been solved, and efficient and accurate abnormal behavior recognition and marking are achieved.
Patent Information
- Application Number
- CN202180039302.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-06-02
- Filing Date
- 2021-05-17
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2041-05-17
AI Technical Summary
It is difficult for the prior art to automatically detect abnormal behaviors of industrial equipment, especially when using free text information for data labeling, there are problems such as inconsistency of data, lack of structure and insufficient efficiency.
By introducing an automatic encoder, abnormal behavior recognition is performed based on sensor signal data, and automatically labeled in combination with text information, additional automatic encoder is created or updated to improve detection accuracy.
It realizes automated detection and labeling of abnormal behaviors of industrial equipment, improves the efficiency and accuracy of the monitoring system, and reduces the dependence on field experts.
Smart Images

Figure CN115917464B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the analysis of sensor signal data, and more particularly to the monitoring of industrial equipment, such as in industrial facilities. Background Art
[0002] Embodiments fall within the field of maintenance, startup, and monitoring of large-scale technical systems such as medical and aircraft systems, processing systems, or other systems that include many dynamically configurable components and are subject to continuous revisions. In industrial facilities, maintaining the stability and integrity of industrial equipment is of utmost importance. Industrial equipment includes, for example, motor drives, particularly converters. Industrial equipment can provide sensor signal data that represents a process in the industrial facility or the state of the industrial equipment itself.
[0003] To provide analysis and in particular to identify the (root) cause of abnormal behavior of industrial equipment in these facilities, today's domain experts compare the timestamps of events in log files with abnormal behavior (i.e., anomalies) in sensor signal data and decide whether the events and anomalies are close enough to consider the event description as a label for the anomaly. If an unsupervised learning setting is to be achieved, the identification of abnormal behavior is typically performed only on the sensor signal data itself, without considering other types of data from other sources, for example. Sometimes, rule-based methods attempt to combine unsupervised sensor signal data clustering with explicitly encoded or formally described expert knowledge.
[0004] Patent application CN108805015A proposes a weighted convolutional autoencoder long short-term memory network for anomaly detection in an image stream of moving pedestrians globally and locally in the background and foreground. Labels are learned from the original data channels and the corresponding optical flow channels.
[0005] Patent applications WO2018 / 224670A1 and GB2563280A propose training an autoencoder on clustered time series, establishing a probability model of the reconstruction error of the autoencoder under test, and detecting the reconstruction error as an anomaly in the field of network communication.
[0006] Patent application WO2018 / 224669A1 proposes calculating the derivative of the reconstruction error and training a machine learning model to define a filter for abnormal network communication, rather than using a probability model.
[0007] In US Patent US8209080B2, text cause and symptom data are considered as inputs for teaching an autoencoder.
[0008] Patent application WO2017 / 198909A1 also describes a process of labeling data elements before teaching an autoencoder.
[0009] The patent application US2019 / 036952A1 proposes generating multiple encoders based on network service data and generating image data as a detection target based on network service data. The image data is generated based on a message string using a one-hot vector. Summary of the Invention
[0010] However, none of these solutions have addressed the problem of automatically labeling data using free text information. To automate the detection of abnormal behavior of industrial devices based on sensor signal data, traditionally feature-based analysis algorithms have been used. Autoencoders are introduced to solve the classification task based on the sensor signal data itself, without the need for a custom-defined signal feature extractor.
[0011] Training these autoencoders and customizing the features for traditional analysis require a neatly labeled dataset. So far, this has been done manually by experts in each field. In addition, a great deal of effort is required to label the anomalies detected in industrial facilities so that they can be used for supervised learning of predictive models to optimize maintenance and / or production.
[0012] Efforts to digitize the workshop by introducing a paperless workflow for maintenance and repair tasks have introduced a method of writing reports as free, unstructured text. The text in the reports contains information about repair and / or maintenance tasks, but does not necessarily follow a common wording pattern (dictionary). In addition, this text may contain typos, special technical terms, and language blends. This "free text" information is only loosely coupled to the time point of the work performed, as usually the timestamps do not necessarily align well with the measured sensor signal data and may be retrospective actions performed over a period of time during which domain experts or repair technicians may express assumptions that may be subjective or based on a very small inspection time range compared to the ongoing measurement range that generates the sensor signal data.
[0013] An object of the present invention is to provide a sophisticated general-purpose sensor signal data analysis method suitable for evaluating and interpreting sensor signal data of one or more industrial devices.
[0014] This object is achieved by the following aspects.
[0015] According to a first aspect, this object is achieved by a method for monitoring industrial equipment. The method includes receiving sensor signal data of one or more industrial equipment and one or more events associated with the operation of one or more industrial equipment. The method preferably includes using a first autoencoder to identify abnormal behavior of one or more industrial equipment based on the sensor signal data. The method includes creating or updating an additional autoencoder based on operation data associated with a time window involving abnormal behavior, and associating events located within the time window with the additional autoencoder.
[0016] According to a second aspect, this object is achieved by a device operable to perform the method steps according to the first aspect.
[0017] According to a third aspect, this object is achieved by a computer program product including program code which, when executed, performs the method steps according to the first aspect.
[0018] The computer program product may include a computer program which, when loaded into the working memory of a computer or the device according to the second aspect and executed by the computer or the device respectively, is used to perform the method according to the first aspect. Description of the Drawings
[0019] Figure 1 A schematic diagram of an industrial facility is shown.
[0020] Figure 2 A schematic diagram of sensor signal data is shown.
[0021] Figure 3 A schematic diagram of events is shown,
[0022] Figure 4 An exemplary method step for monitoring industrial equipment is shown.
[0023] Figure 5 Another exemplary method step for monitoring industrial equipment is shown.
[0024] Figure 6 A diagram showing the reconstruction error of the autoencoder Ai, the fault indicator Fj, and the application of the uncertainty indicator to the fault indicator is shown.
[0025] Figure 7 The generation of the vocabulary space and the definition of clusters in the vocabulary space are shown.
[0026] Figure 8 The determination of the tightness of the events and the event clusters is shown.
[0027] Figure 9a and Figure 9bShows the correlation of autoencoders i and i + 1 with the same fault j and the corresponding weights Wij and Wi+1j.
[0028] Figure 10a and Figure 10b Shows the correlation of autoencoders i and i + 1 with faults j and j + 1 and the corresponding weights Wij, Wij+l, and Wi+1j+1. Detailed implementation
[0029] Figure 1 Shows an industrial facility that includes a plurality of industrial devices, such as control devices, operating devices, sensors, and / or actuators. The industrial facility 30 has an industrial Ethernet bus 9 that provides a data connection between two control devices 5 and 6 of the same or different configurations, an operating computer 4, and a communication computer 1. The industrial Ethernet bus 9 is connected to a standard Ethernet bus 8 through a computer 7. The operating computers 2 and 3 are connected to the standard Ethernet bus 8. Through a bus system designed as Profibus, various actuators or sensors 12, 13, 14, 15 are data-connected to the control device 5. The industrial devices can also be connected through Profinet or industrial Ethernet. The monitored industrial devices can also be assets, machines that are not themselves connected to the bus system of the automation system. For example, the industrial device can be a pipeline. In addition, the decentralized peripheral control device 10 is connected to the control device 6 through a bus system. Through a bus system designed as Profibus, various actuators or sensors 16, 17, 18, 19 are data-connected to the control device 6. In addition, the decentralized peripheral control device 11 is connected to the control device 6 through a bus system. Through the decentralized peripheral control device 11, various actuators and sensors 20, 21, 22 can be driven or evaluated through the control device 6. The operating computers 2, 3, 4, the control devices 5, 6, the decentralized peripherals 10, 11, the actuators or sensors 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, and the bus systems 8, 9 serve the operation of the industrial facility.
[0030] The monitoring of industrial devices can be used to maintain the stability and integrity of industrial devices. The anomalies and / or patterns indicating faults of industrial devices can be monitored locally or remotely. Traditionally, local monitoring of industrial devices has been implemented. However, industrial devices are not always easily accessible. In addition, maintenance technicians may need to arrive on-site to access the data retrieved from one or more industrial devices in order to identify the abnormal behavior (i.e., anomalies and / or patterns indicating faults) of one or more industrial devices. In addition, transporting maintenance and / or repair personnel to the on-site facilities of one or more industrial devices is costly. Therefore, remote monitoring and / or diagnosis provides solutions to these challenges.
[0031] Previous remote monitoring implementations involved custom software and infrastructure configurations that were cumbersome to maintain and update. Additionally, local data collection required by such remote monitoring systems consumed significant data storage. Further, a secure data transfer channel was needed as potentially sensitive plant data was to be transmitted to a remote viewer.
[0032] In an industrial facility, there may be a device 2 for monitoring one or more industrial devices. The device 2 may be included in either a sensor or an actuator or in a control unit. The device 2 may be part of a device (such as an industrial PC) that is only temporarily connected to the industrial facility. Additionally, the device 2 may be remote from the industrial facility.
[0033] Sensor signal data is typically converted from analog data to digital data and digitally analyzed through different signal processing techniques to extract features relevant to the context of a particular application from the digitized signal data. Examples of signal processing techniques well known to those skilled in the art include, but are not limited to, (Fourier, wavelet) transforms, integration, differentiation and derivation, thresholding, fitting mathematical functions, etc. Now, sensor signal data can be obtained by the device 2, and one or more sensors are operably connected to the device 2. In Figure 2 an exemplary sensor signal data curve is shown. Generally, the device 2 obtains sensor signal data from various sensors. For example, the sensor may be part of an industrial device. The data acquisition of the sensor signal data itself is well known in the prior art and, for the purposes of the present invention, no further explanation and discussion thereof is required. For example, the sensor signal data may include and / or represent information of a current sensor or a vibration sensor of a transducer.
[0034] As is known, problems often occur in industrial facilities, especially those with a large number of industrial devices and support equipment. These problems can manifest as industrial device damage or failure, logic elements (such as software routines) being in an incorrect mode, process control loop misadjustment, one or more communication failures between industrial devices within the plant, etc. These and other problems, although substantial in number, typically result in the process operating with abnormal behavior (i.e., the plant is in an abnormal situation), which is usually associated with suboptimal performance of the plant.
[0035] Before the abnormal behavior is detected, identified, and corrected, the abnormal behavior may have existed for some time, resulting in suboptimal performance of the industrial facility during the period when the problem is detected, identified, and corrected. Therefore, it is necessary to monitor one or more industrial devices. For example, the abnormal behavior can lead to severe damage to equipment, loss of raw materials, or even a major unexpected shutdown within the industrial facility, even if the abnormal behavior exists for a short time. Thus, detecting a problem within the industrial facility only after the abnormal behavior has occurred, regardless of how long the problem is corrected, may still result in significant losses or damage within the industrial facility.
[0036] An autoencoder is an artificial neural network that learns data by encoding input data to generate a hidden layer, decoding the hidden layer to generate output data, comparing the input data to the output data, and adjusting parameters or weight values when performing encoding and / or decoding to approximate the output data to the input data. The autoencoder is characterized in that when learning is completed, the part that performs decoding is removed and only the part that performs encoding is used. The part that performs encoding can be represented as an encoder, and the part that performs decoding can be represented as a decoder. In this disclosure, only the term autoencoder will be used. An autoencoder according to one embodiment of the present invention can be based on inception-residual network v2.
[0037] Hereinafter, the term "event" refers to a time-based fact, observation, action, process, or change in system state. For example, an event, or more precisely, text information associated with an event, may be associated with one or more autoencoders (e.g., a first autoencoder or an additional autoencoder, as described in more detail below). The event may be received by the device via a communication link between the device and the industrial equipment. In addition, the event may be accessed via one or more log files. A log file may include multiple events for one or more industrial equipment. Events may help understand activities in an industrial facility. As described above, other events may be included in one or more repair reports or in general reports. Figure 3 An exemplary excerpt of a repair report file including a plurality of events and annotation comments made by a service technician is shown in FIG.
[0038] However, text log data has not been considered. Furthermore, semantic relations between messages and temporal coupling of dynamic free text messages with respect to generated sensor signal data have not been considered. Furthermore, sensor signal data generated by autoencoders and (continuous) retraining of autoencoders have not been considered.
[0039] Specifically, in the field of predictive maintenance, a reference signal or so-called fingerprint is needed for comparison. In order to obtain this reference, the system needs to be calibrated during the commissioning phase (called marking). Usually, this calibration is performed through a series of measurements to obtain a mapping function between the sensor signal data from the industrial equipment and the specific operating state or fault to be detected. This process can require a lot of time and effort.
[0040] A solution is proposed that can automatically perform this calibration.
[0041] In the first step, "train one or more autoencoders", for example, during the debugging of industrial equipment, sensor signal data can be obtained from a system with well-known normal behavior. Based on this sensor signal data, a first encoder (a function that repeats the signal of a very close function training) can be trained. This first autoencoder is capable of reproducing each part of the reference signal within a specific time period. Based on the first autoencoder, one can always cross-check between the signal given by the first autoencoder and the signal measured from the industrial equipment. Optionally, known anomalies such as noise, interruptions, outliers, constant values can be added to the training data, and dedicated additional autoencoders can be trained based on this data for noise, interruption, outlier, and constant value detection respectively.
[0042] In the second step, "identify abnormal behavior", during operation, for example, within the duration of a monitoring period T, one or more (trained) autoencoders are applied to one or more sensor signals and / or corresponding sensor signal data of the system, for example. If at a certain point in time, the (measured) sensor signal data is different from the sensor signal data generated by the first autoencoder, then the abnormal behavior of (one or more industrial equipment) is determined. This point in time t as can be recorded as the start of the abnormal behavior or anomaly. The time period between the start (t as ) of the abnormal behavior and the end (tae) of the abnormal behavior characterizes the data representing a specific problem or fault in the industrial equipment or system. Then, this sensor signal data, that is, the data obtained within the time period t ae - t as can be collected and preferably stored for further evaluation and / or processing.
[0043] If at a specific point in time or during a period of time, one or more measured signals or signal data are, for example, between predetermined boundaries or above or below a predetermined threshold respectively similar to the signal data generated by the corresponding autoencoders (for example, the autoencoder for noise, the autoencoder for interruption, the autoencoder for outliers, and / or the autoencoder for constant offset), as the case may be, the indicators for noise, interruption, outliers, constant values can be increased. Such indicators can correspond to alarms. For visualization in an alarm system, the relative importance of the alarms can be used to distinguish the priorities of the detected anomalies. The indicators or alarms can be visualized to notify the user of the detected abnormal behavior.
[0044] In the third step, "Create or update additional autoencoders", sensor signal data from the time period in which the first autoencoder detected abnormal behavior can be used for training, for example, by creating or updating additional autoencoders, e.g., updating one of the existing additional autoencoders. At this time, the additional autoencoders may have no labels or insufficient labels. The proposed solution allows for the assignment of labels to newly trained additional autoencoders.
[0045] To provide labels for the additional autoencoders, one or more of the following steps can be performed. The maintenance technician can create an electronic (repair) report including text information, where, preferably, there is one or more timestamps associated with the text information in the report. For example, the one or more timestamps can also be in text form and included within the (repair) report. Alternatively, the report can be a log file, etc., which includes some text information related to the operation of one or more industrial devices, e.g., during the monitoring period T. The text information can include the reason for the abnormal behavior described in natural language. This text information can be used to assign the reason for the abnormal behavior in text form to the additional autoencoders. For example, the reason for the abnormal behavior in a mechanical press may be that the bearing of the industrial device is damaged. Now, one or more events can be created, where the one or more events include at least a part of the descriptive text of the report and preferably include one or more associated timestamps. Alternatively, the events are sorted according to the associated timestamps. For example, each event can include a timestamp. Then, for example, according to the grammar rules, the importance of the words from the text is identified. In addition, filler words and stop words such as "and", "or", "then", "so" etc. can be removed. In addition, the words can be changed to lowercase and symbols that do not contain technical information such as ".", ",", ".", and the special character "ü" can be removed. To generate a bag-of-words model, the pre-filtered text in the events extracted from the (repair) report can thus be compressed into nouns, and semantic networks can be used to identify the relationships between these nouns. Then, the bag-of-words model can be clustered with one or more in a mixture of the following algorithms (such as t-SNE, K-Means, Bayesian networks, or Word2vec) to be used as a label to describe the fault or corresponding (root) cause. For example, t-SNE is used for dimensionality reduction (in addition, K-Means is used for clustering) and support vector machines are used for dividing clusters. Subsequently, each event can be associated with a fault cluster. A K-Means method using anagrams such as cosine similarity or vector distance can be used, or a method using an event-word matrix to associate event messages with words and a word-cluster matrix to associate words with fault clusters can be used. Then, one or more clusters are associated with one or more (additional) autoencoders such that the text information of the clusters is used to describe the meaning of the faults detected by the autoencoders using the so-called labels.
[0046] Now discuss the case of multiple faults and multiple autoencoders. To assign the label of the j-th fault to the i-th autoencoder, within the monitoring time period T, the weight matrix Wij is calculated based on the autoencoder output vector Ai(t) and the fault indicator vector Fj(t). The weight matrix with the weight Wij = 2AiFj / (AiAi + FjFj) represents the degree of association between the i-th autoencoder and the j-th fault. A value greater than a preset threshold (e.g., 0.8) indicates a strong relationship between the autoencoder and the fault. Additionally, appropriate warning and alarm thresholds can be defined to notify the user that the autoencoder needs to be reassigned to the fault. Furthermore, an uncertainty indicator can be introduced. The uncertainty indicator is a parametric function determined for each (type of) event, for example, by introducing a time Δt between the occurrence of the fault and the entry in the corresponding log file. The uncertainty indicator is thus used to set thresholds with uncertainty bounds. Thus, one or more labeled autoencoders can be obtained. One or more autoencoders can then be fed sensor signal data of one or more industrial devices, for example, during the operation of one or more industrial devices and / or during the operation of one or more autoencoders for monitoring one or more industrial devices.
[0047] In a further step, the existing autoencoders can be updated. For example, if the weight matrix Wij has similar values for different i or j, the existing autoencoders can be combined. Then the process (i.e., the autoencoder creation and / or update cycle) can return to the first step "Train one or more autoencoders". If multiple autoencoders (e.g., i and i + 1) are associated with the same fault j, then, as Figure 9a and 9b shown, an autoencoder combined for the fault j is trained. Among them, in Figure 9a , the outputs (e.g., reconstruction errors) of autoencoder i and autoencoder i + 1 and the fault (indicator) j are shown, while Figure 9b shows the changes in the weight matrices Wij and Wi + 1j of the weight matrices. If autoencoder i has similar weights for fault j and fault j + 1, then autoencoder i and autoencoder i + 1 are combined to detect the fault j + 1 in FIGS. 10 and Figure 10a . As the starting point for training the combined autoencoder i + 2 using the datasets of fault j and fault j + 1, regions with the same structure and weights are identified in autoencoder i and autoencoder i + 1 respectively, as Figure 10a and Figure 10b shown. The number of faults and autoencoders to which the update process converges depends on the level of detail of the log file entries. The detail of the log file entries can be controlled by the maintenance technician.
[0048] Further operations and continuous monitoring enable the detection of any new previously undetected abnormal behavior, (re)training (additional) autoencoders, and providing a tagging process. Thus, one or more autoencoders can be tagged, for example, based on one or more log files and / or one or more report texts. Through the log files and / or report texts, assuming structured or unstructured text information, which can be generated when or after an abnormal behavior is detected and / or when or after a fix is executed. These can be maintenance reports or industrial PC logs. In addition, a feedback loop for the training and detection processes is proposed. Whenever an abnormal behavior is detected, a time period is determined for collecting additional data and (re)training one or more autoencoders with new and up-to-date sensor signal data and text information.
[0049] Thus, automatic tagging of one or more autoencoders is provided, which reduces the workload for establishing a monitoring and / or diagnostic system for one or more industrial devices (e.g., in an industrial facility). This solution allows converting an unsupervised machine learning setting into a supervised machine learning setting. Thereby, the robustness of anomaly detection, i.e., the detection of abnormal behavior, is improved. By using a feedback loop, the detection of abnormal behavior can be improved and related events can be classified. The creation of an event vocabulary space for describing event clusters is also improved. A computer program, also referred to as a (software) application, can be provided that performs the tagging of autoencoders in an efficient manner. For example, the computer program can be deployed on-site (using industrial devices), thus also enabling the self-learning of machine learning algorithms. Therefore, the applicant can propose an autoencoder application for industrial anomaly detection. In addition, the application can include a proximity score (also referred to as an uncertainty indicator above) to identify the temporal proximity between anomaly detection and the timestamp of a log file entry. In addition, a vocabulary clustering from log file data (i.e., text information) for industrial fault label definition is proposed.
[0050] Thus, text information with a given timestamp can be input and automatically associated with the abnormal behavior that has been automatically detected by the unsupervised training of one or more autoencoders. Thus, tags can be input manually either by file or via a graphical user interface. In addition, the output of the application includes the tagging of sensor signal data. The feature input from the data file is event logs and time series data, resulting in tagged data output. The disclosure as described herein proposes machine learning based on autoencoders and deals with uncertain temporal relationships. The present disclosure also deals with defining a vocabulary space based on text event descriptions and their relationship to time series anomalies detected by autoencoders.
[0051] Now turning to Figure 4, another embodiment including exemplary method steps is described. In a first step S1, a first autoencoder is trained: "Train a general time series autoencoder". The training of the autoencoder can be based on sensor signal data representing the normal (i.e., desired and expected) behavior of industrial equipment and / or industrial facilities. Subsequently, the autoencoder is applied to the sensor signal data in a second step S2: "Apply the autoencoder to anomaly detection" to identify abnormal system behavior. This can be done "online", i.e., during the operation of industrial equipment and / or industrial facilities, or it can be done "offline", i.e., based on stored sensor signal data. Subsequently, in step S3, events can be associated with the detected anomalies: "Associate facility log events". Then one or more autoencoders can be retrained and / or the corresponding tags of one or more autoencoders can be updated in step S4: "Update and combine autoencoders". Finally, a notification can be initiated or sent, for example, to signal a user or to trigger an alarm. The notification can be sent from the device performing any of the method steps to a control unit. For example, the notification can be displayed to the user on a display, such as on the device itself or on a handheld device.
[0052] Now turning to Figure 5 , further exemplary method steps are shown. Figure 5 The steps shown can be combined with Figure 4 the method steps shown. Of course, some of the steps shown in Figure 4 and Figure 5 can be omitted or other steps can be included.
[0053] To associate facility log events with the detected anomalies, text information can be obtained in step S5: "Obtain text from monitored events". As described above, the text information can be obtained from one or more log files, which are created automatically, for example, by one or more industrial devices, or manually, for example, by a maintenance technician, etc. Subsequently, a vocabulary space can be created from the event text in step S6: "Create a vocabulary space from event text". Finally, the vocabulary spaces can be combined into one or more clusters for tagging abnormal behavior, i.e., anomalies and / or the corresponding autoencoders in step S7.
[0054] Turning to Figure 6, the reconstruction error of the autoencoder Ai, the fault indicator of the fault Fj, and the fault Fj with increased uncertainty Δt are shown over time. For this purpose, a fault indicator Fi can be introduced. The fault indicator Fj can be introduced based on, for example, the timestamps of events in the log file. The height of the fault indicator Fj can represent the number of (relevant) words used to describe the fault in the log file or the number of words used to identify the fault in the cluster, as described below. The fault indicator can be normalized based on the total number of words in the log file or based on the total number of words representing the corresponding fault in the cluster. The reconstruction error of the autoencoder Aj can indicate abnormal behavior of the sensor signal data, i.e., anomalies. To immediately handle multiple faults, a vector representation of the faults and an autoencoder can be used.
[0055] The correlation between the fault indicator Fj and the reconstruction error Ai of the i-th autoencoder can indicate the degree to which the autoencoder is associated with the fault Fj. The correlation between the autoencoder Ai and the fault Fj can be determined based on a weight matrix:
[0056]
[0057] Due to the inconsistency between the timestamps in one or more log files and the timestamps of the sensor signal data, a proximity score or an uncertainty indicator can be introduced. Thus, the uncertainty of each event can be defined, for example, depending on the event-specific detection probability. The uncertainty indicator can be a parametric function, and the parametric function for each type of event can be determined by observing the time Δt between the occurrence of the fault and the input in the log file. Therefore, a weak coupling between the event and the autoencoder is introduced, for example, by allowing values between 0 and 1 and introducing static uncertainty bounds.
[0058] Go to Figure 7 , the generation of the vocabulary space and the definition of clusters in the vocabulary space are shown. The available text information of events can be clustered based on the number of common words, for example, using K-Means, Bayesian networks, etc. Alternatively, the number of events with a single word or common words can be counted. In Figure 7 , the clustering of words based on a Bayesian network is shown, where the clustering is performed based on whether at least 2 events with common words occur.
[0059] In Figure 8 , K-Means is used to determine the tightness of the event and the event cluster to define the tightness of the event description and the event cluster. The word cluster matrix Wdkj and the event word matrix can be used to link the event to the event cluster.
[0060] Additionally or alternatively, a graphical user interface (GUI) can be developed that guides domain export by visualizing process data around the timestamp of an event, e.g., entries in a (facility) log file, and by marking the process. The GUI can also display text information so that domain experts can decide whether the text information can be regarded as an appropriate label for an anomaly. However, this process is time-consuming and requires more effort.
[0061] Other embodiments include:
[0062] In a first embodiment:
[0063] A method for monitoring industrial devices (12 - 22), the method comprising:
[0064] Receiving sensor signal data (ssd) of one or more industrial devices (12 - 22) and one or more events (e) associated with the operation of one or more industrial devices (12 - 22), preferably using a first autoencoder, identifying abnormal behavior (ab) of one or more industrial devices (12 - 22) based on the sensor signal data (ssd),
[0065] Based on the sensor signal data (ssd) associated with a time window (tas, tae) involving the abnormal behavior (ab), creating or updating an additional autoencoder and associating the events (e) located within the time window (tas, tae) with the additional autoencoder.
[0066] In a second embodiment:
[0067] The method according to the embodiment, comprising: associating text information (i) of one or more events (e) located within a time window (tas, tae) with an additional autoencoder for transmitting a notification, the notification including the text information associated with the additional autoencoder.
[0068] In a third embodiment:
[0069] The method according to any of the foregoing embodiments, comprising:
[0070] Wherein, the time window (tas, tae) covers the time period between the start time (tas) and the end time (tae) of the identified abnormal behavior (ab).
[0071] In a fourth embodiment:
[0072] The method according to any of the foregoing embodiments, comprising:
[0073] Training a first autoencoder based on sensor signal data (ssd) representing the normal behavior (ab) of one or more industrial devices (12 - 22).
[0074] In the fifth embodiment:
[0075] The method according to any one of the foregoing embodiments, comprising:
[0076] wherein, an abnormal behavior (ab) of one or more industrial devices (12 - 22) is identified based on a reconstruction error of a first autoencoder.
[0077] In the sixth embodiment:
[0078] The method according to any one of the foregoing embodiments 2 to 5, comprising:
[0079] Transmitting a notification after identifying an abnormal behavior (ab) by an additional autoencoder, for example, based on a reconstruction error of the additional autoencoder.
[0080] In the seventh embodiment:
[0081] The method according to any one of the foregoing embodiments, comprising:
[0082] Assigning a timestamp (t) to the text information of one or more reports (e.g., log files or repair reports in electronic form), thereby creating one or more events (e).
[0083] In the eighth embodiment:
[0084] The method according to any one of the foregoing embodiments, comprising:
[0085] Processing the text information (i) using one or more semantic networks to obtain a description of an abnormal behavior (ab) of one or more industrial devices (12 - 22).
[0086] In the ninth embodiment:
[0087] The method according to any one of the foregoing embodiments, comprising:
[0088] Clustering one or more events (e) and / or text information (i) into a plurality of clusters, wherein each cluster represents a different abnormal behavior (ab) of one or more industrial devices (12 - 22).
[0089] In the tenth embodiment:
[0090] The method according to any one of the foregoing embodiments, comprising:
[0091] Associating each cluster with an autoencoder, wherein each autoencoder represents a normal behavior or an abnormal behavior of one or more industrial devices (12 - 22), and wherein the text information (i) of the cluster is used to describe the identified normal behavior (nb) or abnormal behavior (ab).
[0092] In the eleventh embodiment:
[0093] A method according to any of the foregoing embodiments, comprising:
[0094] Associating a cluster in a plurality of clusters with an autoencoder based on comparing the output of one or more autoencoders with a time window of the abnormal behavior (e.g., using a weight matrix).
[0095] In the twelfth embodiment:
[0096] A method according to any of the foregoing embodiments, comprising:
[0097] Updating the association between the cluster and the autoencoder based on the comparison according to the foregoing claims.
[0098] In the thirteenth embodiment:
[0099] A method according to any of the foregoing embodiments, comprising:
[0100] When a plurality of autoencoders are related to sensor signal data (ssd) associated with a time window (tas, tae) of an abnormal behavior (ab), creating a combined autoencoder for identifying the abnormal behavior (ab).
[0101] In the fourteenth embodiment:
[0102] An apparatus (2) operable to perform the method steps of any of the foregoing embodiments.
[0103] In the fifteenth embodiment:
[0104] A computer program product comprising program code which, when executed, performs any of the method steps of embodiments 1 to 13.
Claims
1. A method for monitoring industrial devices (12 - 22), the method comprises: receiving sensor signal data (ssd) of one or more industrial devices (12 - 22) and one or more events (e) associated with the operation of the one or more industrial devices (12 - 22), using a first auto - encoder to identify abnormal behavior (ab) of the one or more industrial devices (12 - 22) based on the sensor signal data (ssd), Based on the sensor signal data (ssd) associated with a time window (t as , t ae ) related to the abnormal behavior (ab), an additional autoencoder is created or updated, and, characterized in that, Associate one or more of the events (e) within the time window (t as , t ae ) with the additional autoencoder, and one or more events are associated with text information, wherein the text information is used to assign the cause of the abnormal behavior to the additional autoencoder for transmitting a notification, transmitting the notification after the abnormal behavior (ab) is identified by the additional auto - encoder, the notification including the text information associated with the additional auto - encoder.
2. The method according to claim 1, wherein, The time window (t as , t ae ) covers the time period between the start time (t as ) and the end time (t ae ) of the identified abnormal behavior (ab).
3. The method according to any one of the preceding claims, comprises: training the first auto - encoder based on sensor signal data (ssd) representing normal behavior of the one or more industrial devices (12 - 22).
4. The method according to claim 1 or 2, wherein, identifying the abnormal behavior (ab) of the one or more industrial devices (12 - 22) is based on the reconstruction error of the first auto - encoder.
5. The method according to claim 1 or 2, comprises: assigning a timestamp (t) to the text information, where the text information is included in one or more reports of a record file or a repair report in electronic form, thereby creating the one or more events (e).
6. The method according to claim 1 or 2, comprises: using one or more semantic networks to process the text information (i) to obtain a description of the abnormal behavior (ab) of the one or more industrial devices (12 - 22).
7. The method according to claim 1 or 2, comprises: clustering the one or more events (e) and / or text information (i) into multiple clusters, where each cluster represents a different abnormal behavior (ab) of the one or more industrial devices (12 - 22).
8. The method according to claim 7, comprises: associating each cluster with an auto - encoder, where each auto - encoder represents normal behavior or abnormal behavior of the one or more industrial devices (12 - 22), and the text information (i) of the cluster is used to describe the identified normal behavior (nb) or abnormal behavior (ab) respectively.
9. The method according to claim 7 of the preceding claims, comprises: associating a first cluster among the multiple clusters with an auto - encoder based on comparing the output of one or more auto - encoders with sensor signal data of a time window of the abnormal behavior using a weight matrix.
10. The method according to claim 9, comprises: updating the association between the first cluster and the auto - encoder based on the comparison.
11. The method according to claim 8, comprises: In the case where a plurality of autoencoders are associated with the sensor signal data (ssd) for a time window (t as , t ae ) associated with the abnormal behavior (ab), a combined autoencoder for identifying the abnormal behavior (ab) is created based on the plurality of autoencoders.
12. An apparatus (2) comprising a computer program for performing the steps of the method according to any one of the preceding claims when the computer program is loaded into the working memory of the apparatus.
Citation Information
Patent Citations
Weighted convolutional autoencoder-long short-term memory network-based crowd anomaly detection method
CN108805015A
Anomaly detection in computer networks
GB2563280A
Method and apparatus for detecting anomaly traffic
US20190036952A1
System for determining most probable cause of a problem in a plant
US8209080B2
Segmentation of data
WO2017198909A1