System, device and method for detecting abnormal data points
By iteratively applying and updating the anomaly detection model, using data points marked as normal training, and retraining the model after threshold time, the problem of abnormal data points detection in a large number of unlabeled data sets in industrial environments is solved, and efficient and automated anomaly detection is achieved.
Patent Information
- Application Number
- CN202180056612.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-08-10
- Filing Date
- 2021-07-29
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-07-29
AI Technical Summary
The prior art is difficult to effectively detect abnormal data points in large numbers of unlabeled data sets in industrial environments, and relying on expert verification increases the workload.
By iteratively applying and updating the anomaly detection model, the model is trained with data points marked as normal, and the model is retrained after threshold time to detect anomaly data points in an industrial environment.
It realizes effective detection of abnormal data points in a large number of unlabeled data sets, reduces dependence on expert verification, and improves the robustness and automation of the detection model.
Smart Images

Figure CN116034325B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to detecting anomalous data points in operational data associated with an industrial environment. Background Art
[0002] Anomaly detection typically requires an anomaly detection model that is trained to detect anomalies in the use or operation of industrial assets. For example, motor fault detection relies on a model trained with fault-specific features that are generated based on the knowledge of domain experts about the measured operational data from a motor frequency converter. The operational data can be measured as a time series, where data from a particular sensor is obtained, for example, by sampling the motor frequency converter at a particular frequency. In some cases, the operational data can be time series data that is stored and analyzed in batches. The model and thresholds may need to be trained on motor data under normal and faulty conditions for each operating condition. To reduce the training effort, artificial intelligence techniques can be used.
[0003] Existing anomaly detection models may focus on detecting anomalous data points for which there will be a large amount of normal data (only one class) available for training in the future. Additionally, existing artificial intelligence techniques may focus on classifying data in the future, where only a small number of multi-class training data are available. Therefore, artificial intelligence techniques may require a training data set with a large amount of pre-labeled data. However, learning techniques with a large number of unlabeled data points and only a small number of data points labeled as normal or anomalous cannot effectively detect anomalies or anomalous data points. Additionally, the reliance on experts to validate anomaly data point detection may increase. Summary of the Invention
[0004] Accordingly, systems, devices, and methods for detecting anomalous data points can benefit from improvement. The object of the present invention is to effectively detect anomalous data points in operational data associated with an industrial environment. In particular, the object of the present invention is to be able to detect anomalous data points in a large unlabeled data set.
[0005] This object is achieved by a predictive maintenance system, a computing device, and a method for detecting at least one anomalous data point in operational data associated with an industrial environment.
[0006] For example, a method for detecting at least one abnormal data point in operation data associated with an industrial environment, where the operation data includes historical data and streaming data corresponding to the operation of an industrial asset in the industrial environment, the method includes applying one or more anomaly detection models to at least one subset of the operation data, where the anomaly detection models are trained based on a training data set composed of data points marked as normal; using the anomaly detection models to classify the subset-data points in the subset as either normal data points or abnormal data points; updating the training data set at least using the normal data points; retraining the anomaly detection models with the updated training data set after a threshold time has elapsed, where the threshold time is based on the number of updates to the training data set; and using the anomaly detection models to detect the at least one abnormal data point in the industrial environment.
[0007] In one embodiment, a method for detecting at least one abnormal data point in operation data associated with an industrial environment may include iteratively applying one or more anomaly detection models to at least one subset of the operation data, where the anomaly detection models are trained based on a training data set composed of data points marked as normal; iteratively using the anomaly detection models to classify the subset-data points in the subset as either normal data points or abnormal data points; iteratively updating the training data set at least using the data points classified as normal; iteratively applying the anomaly models, classification, and data set updates for the complete operation data or until a threshold time is reached; retraining the anomaly detection models with the updated training data set after the threshold time has elapsed, where the threshold time is based on the number of updates to the training data set; and detecting the at least one abnormal data point in the industrial environment by starting a new iteration. Thus, the present invention includes an iterative continuation of the classification, update, and retraining of the anomaly detection models.
[0008] In another example, a computing device for detecting at least one abnormal data point in operation data associated with an industrial environment, where the operation data includes historical data and streaming data corresponding to the operation of an industrial asset in the industrial environment, the device includes a processing unit; and an anomaly module executable by the processing unit, the anomaly module including computer-readable instructions that, when executed by the processing unit, are configured to perform the steps in one of the methods disclosed herein.
[0009] In yet another example, a predictive maintenance system for an industrial environment includes the computing device disclosed herein.
[0010] Another example includes a computer program product that includes computer-readable code that, when executed on a processor, executes any of the method steps of one or more of the methods herein.
[0011] The present invention advantageously combines semi - supervised learning and anomaly detection. Thus, even in the presence of a small number of normal data points and a large number of unknown data points, anomaly data points can be detected. In addition, the present invention provides a workflow that can be executed in an online learning pipeline. This workflow enables continuous learning from unlabeled and labeled data points and automatically upgrades the anomaly detection model. Therefore, the present invention has the technical effect of generating and maintaining a robust anomaly detection model and learning pipeline for industrial environments.
[0012] Before describing the proposed convention in more detail, it should be understood that various definitions of certain words and phrases are provided in this patent document, and those of ordinary skill in the art will understand that these definitions apply to the prior and future use of these defined words and phrases in many (if not most) examples. Although some terms may include multiple embodiments, the appended claims may specifically limit these terms to a particular embodiment. It should also be understood that features explained in the context of the proposed method may also be included in the proposed system by appropriately configuring and adjusting the system, and vice versa.
[0013] As used herein, an "industrial environment" refers to a facility that can be manufactured semi - automatically or fully automatically. An industrial environment can be part of an automated environment. For example, an industrial automation environment, a laboratory automation environment, a building automation environment, etc. In addition, according to the present invention, an automated environment can include a combination of one or more industrial automation environments, laboratory automation environments, and building automation environments.
[0014] Industrial assets can be control devices, sensors, actuators that include physical devices and digital models that can be used to configure and control the physical devices. For example, computer numerical control (CNC) machines, automated systems in industrial production facilities, motors, generators, etc. Industrial assets can also be referred to as cyber - physical systems because they include cyber - physical devices.
[0015] "Operational data" as used herein is data associated with the operation and operating conditions of industrial assets. Operational data can be received from different sources (e.g., sensors, user devices, etc.). Sensors measure operating parameters associated with the asset. For example, sensors can include thermal imaging devices, vibration sensors, current and voltage sensors, etc. The term "operating parameter" refers to one or more characteristics of the asset. Thus, operational data is a measure of the operating parameters associated with the operation of the asset. For example, operational data can include data points representing vibration, temperature, current, magnetic flux, speed, power associated with an industrial asset (e.g., a motor or rotor in an industrial environment).
[0016] It can receive and analyze operation data in real time. Such operation data can be referred to as streaming data. The "streaming data" used in this article refers to data points received in a time series. For example, streaming data includes time series sensor values of a vibration sensor of a motor. In another example, operation data can be received and stored in batches. Operation data can be referred to as "historical data". For example, historical data includes vibration sensor values from a motor within a month. As used in this article, an "anomaly detection model" refers to one or more models generated from physics-based models and / or data-driven models for industrial assets and / or industrial environments. For example, an anomaly detection model can include an ontology-based model with ontology data of industrial assets, and a prediction model with probability data associated with condition-based probabilities. In one embodiment, the ontology data of industrial assets is used to detect anomalies based on asset attributes and their interdependencies in the ontology model. In another embodiment, the anomaly detection model includes sliding window calculations, Fourier transforms, application of low / high pass filters, neural networks, decision tree analysis, and other techniques well-known in the fields of digital signal processing, machine learning, and automation engineering.
[0017] Based on this training dataset, the anomaly detection model is trained. The training dataset initially includes data points labeled as normal. Thus, when the anomaly detection model is applied to a subset of operation data, the data points in the subset can be classified. In addition, the data points in the subset (subset-data points) are classified as normal data points or anomaly data points. The classification of the subset data points enables the labeling of unlabeled data points in the operation data. This labeling is used to update the training dataset. For example, the training dataset is updated only with normal data points. In another example, the training dataset is updated with both anomaly data points and normal data points. The update of the training dataset can be performed iteratively. When an iteration threshold (i.e., threshold time) is met, the anomaly detection model is retrained based on the updated training dataset. The retraining of the anomaly detection model strengthens the classification performed on the subset-data points. Thus, the present invention advantageously automates the retraining of the anomaly detection model to detect at least one anomaly data point in the operation data.
[0018] In one embodiment, the method can include removing the subset from the operation data and using the retrained anomaly detection model to detect at least one anomaly data point in the remaining operation data without the subset. The method can also include applying the anomaly detection model to a new subset of the operation data and classifying the new data points in the new subset as either normal data points or anomaly data points. Additionally, the method can include updating the training dataset and retraining the trained anomaly detection model as described above.
[0019] The present invention advantageously divides operation data into subsets for efficient and robust application of an anomaly detection model. Thus, the present invention can be implemented on a computing device with resource constraints. For example, an industrial computing device such as an edge device can be used to detect anomaly data points in streaming data received from industrial assets in an industrial environment. In one embodiment, a threshold time can be selected for computational efficiency implemented in a real-time production setting and allows automation engineers to provide input to the anomaly detection model. For example, the automation engineer can provide input regarding the number of data points in a subset or a confidence index in subset-data point classification. Additionally, dividing operation data into subsets enables continuous unsupervised / semi-supervised learning of anomaly data points. Thus, starting from a small set of known normal data points, the present invention provides a method for classifying and labeling unknown data points in operation data.
[0020] The method can further include populating an anomaly data set containing anomaly data points in the subset and the new subset. The anomaly data set can be populated after classifying the data points in the subset of the new subset. The iterative population of the anomaly data set enables continuous learning and re-training of the anomaly detection model. The method can further include updating the training data set with the anomaly data set. Thus, the present invention advantageously provides a method for training an anomaly detection model not only using normal data points (i.e., one class). But also providing normal and anomaly data points (i.e., multiple classes) for training the anomaly detection model. With increasing use of the present invention, the anomaly detection model can be further robust considering enhanced learning from the updated training data set.
[0021] To ensure that the anomaly detection model does not require substantial re-training, normal data points based on actions performed by an expert can be provided to the training data set. Thus, the method can include receiving a training data set including at least normal data points, wherein the normal data points are classified based on at least one of engineering software input and operations in a similar industrial environment. The engineering software input can be provided by monitoring the actions of an automation engineer when configuring an industrial asset. For example, the automation engineer can set boundary conditions for vibration sensor data of a motor in an industrial environment. Data points falling within the boundary conditions are automatically classified as normal data points. Thus, the present invention advantageously seamlessly incorporates expert input without explicit prompting. Additionally, expert input may have been provided earlier in the life cycle of the industrial asset. In another example, a similar industrial environment can include similar motors with similar operating conditions. Normal data points in the operation data of the similar motors are used as the training data set. Thus, the present invention advantageously uses existing labeled data to train the anomaly detection model.
[0022] In one embodiment, a similar industrial environment may be a simulated industrial environment that includes industrial assets and a simulation model of the industrial environment. The simulated industrial environment may be configured to simulate various operating conditions of the industrial assets to generate a training data set that includes at least normal data points.
[0023] The method may include training an anomaly detection model based on the training data set that includes normal data points. Thus, the present invention avoids the time-consuming retraining of the anomaly detection model. In addition, the present invention contemplates a situation where only a limited number of normal data points are available for detecting anomaly data points in the operational data. The method steps disclosed herein provide a mechanism for detecting anomaly data points even when only a limited number of normal data points are known.
[0024] In one embodiment, the method may include determining a confidence index in the subset-data point classification based on at least one of an engineering software input and the operation of a similar industrial environment. The method may further include: when the confidence threshold is not met, reclassifying the subset-data points; and updating the training data set using the confidence index and the reclassified data points. The present invention provides a mechanism for verifying the classification of subset-data points or new data points by determining a confidence index. For example, the difference between a data point classified as normal and a data point within the boundary conditions set by an automation engineer can be used to determine the confidence index. Thus, the present invention does not overfit the classification to the training data set. At the same time, the confidence threshold is used to ensure that the classification is based on the training data set. In addition, the present invention limits the manual intervention of experts. For example, expert input may be provided for data points that need to be reclassified.
[0025] In one embodiment, the anomaly detection model may be included in an anomaly detection pipeline. As used herein, "anomaly detection pipeline" refers to the iterative selection and implementation of an anomaly detection model within a pipeline. The anomaly detection pipeline is thus implemented as an iterative workflow of training, classification, and retraining, where the anomaly detection model is trained using the training data set, where the anomaly detection model is verified based on the classification of normal data points and anomaly data points, and where the anomaly detection model is retrained based on the updated training data set. The present invention presents a simplified method for continuously detecting anomaly data points in the operational data of industrial assets. In addition, the selection of the anomaly detection model ensures that the most appropriate model is selected to detect anomaly data points.
[0026] The method may include generating an anomaly detection pipeline that includes an anomaly detection model associated with an industrial environment, where the anomaly detection model includes a physics-based model, a data-driven model, and combinations thereof. The anomaly detection pipeline may be generated by selecting an anomaly detection model based on a deviation score or an anomaly score or an accuracy score. The method may include determining a deviation score of the anomaly detection model based on an attribute of the anomaly detection model. In one embodiment, the deviation score is also determined based on a training data set. The method may further include selecting at least one anomaly detection model of the anomaly detection pipeline based on the deviation score. In one embodiment, the outputs of the anomaly detection models are compared to select one model or to determine whether a combination of the anomaly detection models results in a robust ensemble. The anomaly detection pipeline advantageously includes a set of robust anomaly detection models and a training data set that is subsequently updated and retrained.
[0027] In an embodiment of the present invention, the method may include using the anomaly detection pipeline to detect a batch of anomaly data points in the operational data, where detecting the batch of anomaly data points includes applying the anomaly detection pipeline to at least one subset of the batch and iteratively applying to all subsets of the batch, where the anomaly detection pipeline is trained based on a training data set composed of normal data points; using the anomaly detection pipeline to classify the subset-data points in the subset as either normal data points or anomaly data points; at least expanding the training data set with normal data points; and retraining the anomaly detection pipeline with the updated training data set after the threshold time has expired, where the threshold time is based on the number of updates to the training data set.
[0028] The present invention can be advantageously used to detect a batch of anomaly data points. By detecting this batch, the context of the anomaly data points can be determined. Then, the context can be updated to the anomaly data set to make the retraining of the models in the anomaly detection pipeline more robust.
[0029] The systems, devices, and methods of the present invention have the technical effect of reducing engineering work and anomaly detection time. The technical effect is achieved because the work of labeling operational data is reduced. In addition to reducing the labeling work, the detection of anomaly data points can be performed in less time to wait for anomalies to be detected in production. The training data set with normal data points is used to detect anomaly data points in the subset. Therefore, the present invention is suitable for implementation in real-time and newly debugged industrial environments.
[0030] The technical effects are achieved by applying an anomaly detection model to operational data that may be time - series. For example, the anomaly detection model can be formed by frequency transformation, time - series statistics such as mean, median, standard deviation, and windowing. Additionally, the threshold time for retraining the anomaly detection model ensures computational efficiency achieved in an actual production setting and allows input from automation engineers. For example, automation engineers may need to distinguish normal operating states from abnormal operating states based on their experience. For multiple industrial assets in an industrial environment, the effectiveness of automation engineers may be limited. Also, detecting abnormal data points can be time - consuming and require a large amount of human effort. With the help of a general anomaly detection pipeline, majority voting of classification models is automatically performed. In a semi - automated method, automation engineers optionally give feedback after a defined number of iterations of classified data points, while classification can still continue to run in the background. Additionally, updating the training dataset and the anomaly dataset with normal data points and abnormal data points avoids the requirement for a pre - classified dataset or a description of specific classes. Furthermore, generating an anomaly detection pipeline by selecting an anomaly detection model based on model attributes and deviation scores enables a streamlined iterative workflow for training, validation, and retraining.
[0031] The technical features of the present disclosure have been outlined rather extensively above so that those skilled in the art can better understand the subsequent detailed description. The following will describe additional features and advantages of the present disclosure that form the subject matter of the claims. Those skilled in the art will understand that they can readily use the disclosed concepts and specific embodiments as a basis for modifying or designing other structures for achieving the same purposes of the present disclosure. Those skilled in the art will also recognize that such equivalent constructs do not depart from the broadest scope of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Hereinafter, the present invention will be described using the embodiments shown in the drawings.
[0033] Figure 1 The method steps of a method for detecting abnormal data points in unlabeled operational data according to an embodiment of the present invention are illustrated;
[0034] Figure 2 The flowchart of a method for detecting abnormal data points in time - series operational data according to an embodiment of the present invention is illustrated;
[0035] Figure 3 The flowchart of a method for iteratively detecting abnormal data points according to an embodiment of the present invention is illustrated;
[0036] Figure 4 The majority voting of several anomaly detection models according to an embodiment of the present invention is illustrated;
[0037] Figure 5Illustrates the method steps of a method for detecting abnormal data points in operation data associated with an industrial environment; and
[0038] Figure 6 Illustrates a predictive maintenance system and a computing device for detecting abnormal data points in operation data associated with an industrial environment according to an embodiment of the present invention. Detailed Description of the Invention
[0039] Hereinafter, embodiments for implementing the present invention will be described in detail. Various embodiments are described with reference to the accompanying drawings, in which the same reference numerals are always used to denote the same elements. In the following description, for the purpose of explanation, many specific details are set forth in order to provide a thorough understanding of one or more embodiments. Obviously, such embodiments can be practiced without these specific details.
[0040] Figure 1 Illustrates the method steps of a method for detecting abnormal data points in unlabeled operation data U. The operation data U is associated with an industrial environment and can be generated based on the operation of industrial assets in the industrial environment.
[0041] The method starts at step 102 with a first iteration i = 1, receiving / determining a reference normal data set L. For example, the reference normal data set L can be received as the measurement results of similar industrial assets in a similar industrial environment. In another example, the reference normal data set L can be generated based on the simulation of the industrial environment. The reference normal data set L is used as the training data set for the anomaly detection model. Hereinafter, the training data set will be referred to as the training data set L.
[0042] At step 104, unlabeled operation data U is received. The unlabeled operation data U can be received in a time series or as a batch file that may not be in a continuous time series. The operation data U is the data set / data stream in which abnormal data points are detected.
[0043] At step 106, an anomaly detection model f is trained based on the training data set L i . Based on the training, the anomaly detection model is configured to classify data points as normal data points. At step 108, the anomaly detection model f i is applied to the training data set to verify the classification as normal data points.
[0044] At step 110, a subset S is selected from the operation data U. At step 112, the anomaly detection model f i is applied to the subset S to generate classified data points (labels) labeled as either normal data points N or abnormal data points A i . In one embodiment, the classified data point labels iShown as trends 1 and 0, where 1 represents normal data points and 0 represents abnormal data points.
[0045] In step 116, the normal data points classified in step 112 are used to expand the training data set. Additionally, in step 118, an abnormal data set with the abnormal data points identified in step 112 is generated. In one embodiment, steps 116 and 118 can be collectively referred to as expanding the training data set and are represented by step 114. In addition to expanding the training data set, in step 118, the anomaly detection model f is constrained based on the expanded training data set. i . The retrained anomaly detection model for the next iteration i + 1 is referred to as f i+i . In one embodiment, according to the anomaly detection models f i and f i+i in iterations i and i + 1, the optimization function f i ' = opt{f i, f i+1} is applied to generate the constrained anomaly detection model f' i . In step 120, the subset S is removed from the operational data U, and steps 110 - 118 are repeated with the retrained anomaly detection model f' i .
[0046] Figure 2 FIG. illustrates a flowchart of a method 200 for detecting abnormal data points in time series operational data U according to an embodiment of the present invention. For Figure 2 purposes, the time series operational data U and the operational data U can be used interchangeably. The method 200 is divided into three phases 210, 220, and 230. In phase 210, supervised learning is performed. In phase 220, industrial verification can be performed. In step 230, unsupervised learning and reinforcement learning are performed. Phases 210 - 230 are described below according to the flowchart.
[0047] In the supervised learning phase 210, an anomaly detection model is selected as part of the anomaly detection pipeline and its parameters are initialized. For example, the anomaly detection model is an isolation forest model. In step 212, the selection of the isolation forest model is indicated by model type = 1. Additionally, in step 212, the counter is initialized to cnt = 0. In step 214, the training data set L is received and the isolation forest model is trained based on the training data set L. The training data set L includes normal data points N and abnormal data points A. In step 216, the normal data points N are merged into the training data set L. In one embodiment, the abnormal data points A are incorporated into the training data set in step 218.
[0048] In the validation phase 220, domain experts can provide input to validate the classification of normal data points N and abnormal data points A. For example, in step 222, an automation engineer can provide ground truth to validate the classification. In step 224, the anomaly detection pipeline is iteratively applied to the operational data U. In step 226, a subset S is selected from the operational data U and the anomaly detection pipeline is applied. The subset S is selected according to the chronological order. Therefore, the leftmost block of the time series operational data U is selected. Thus, the earliest time block is the subset S and is input for classification in the first round.
[0049] In the unsupervised learning phase 230, the anomaly detection pipeline is applied to a series of subsets of the operational data U. At predetermined time steps, the anomaly detection pipeline is enhanced with an enlarged normal data set. In step 232, when the application of the anomaly detection pipeline finishes classification, the subset S is removed from the operational data U. In step 234, time series operational data from industrial assets is received in real time. In step 236, a counter cnt is incremented. In step 238, the counter cnt is checked to confirm whether the counter cnt value is less than a threshold time. Additionally, it is checked whether the time series operational data U is not empty. If any of the checks is affirmative, a new subset is selected from the operational data U and the method continues from step 224.
[0050] Phase 230 is also an enhancement phase. Enhancement is performed by enlarging the training data set L and retraining the anomaly detection pipeline. Enhancement makes the anomaly detection pipeline robust and extends its generality by retraining.
[0051] Method 200 can be encoded as follows.
[0052] Input: Data: L reference normal data set as the training data set; Data: M empty data set to be filled as the abnormal data set; Data: U time series operational data; Threshold time: t constraint for enhancing the trained model; Model: f model selected as part of the anomaly detection pipeline.
[0053] Output: A set of normal data points and abnormal data points. Each set contains: M detected anomalies, L enlarged normal data set, and f robust anomaly detection model.
[0054]
[0055]
[0056] Figure 3The flowchart of method 300 for iteratively detecting abnormal data points according to an embodiment of the present invention is illustrated, where t = 1. Method 300 illustrates the operation of the present invention when receiving time series operation data U. Method 300 begins at step 302, where a type of support vector machine (SVM) is selected as part of the anomaly detection pipeline. Additionally, at step 302, a counter cnt is initialized.
[0057] At step 304, a training data set L is used to train the one-class SVM model. At step 306, the anomaly detection pipeline is applied to the operation data U, and the data points in subset S are classified into normal data points N and abnormal data points A. At step 308, a domain expert can verify the classification. At step 310, the normal data points N are merged into the training data set to generate an enlarged training data L 1 . At step 312, the abnormal data points A are updated to the abnormal data set M.
[0058] The above steps are repeated in round 320 as the flow of operation data U. Thus, at step 322, the operation data U is streamed, and at step 324, a new subset is selected. The enlarged training data set L 1 is used to constrain / enhance the anomaly detection pipeline. Steps 330 and 332 are repetitions of steps 310 and 312. Other rounds 330 are carried out as described above.
[0059] The steps of method 300 can be repeated until the operation data U is no longer streamed or the industrial asset operation is interrupted. For example, if the motor stops. When the steps are completed, the result will be an enlarged training data set L 2 and an enlarged abnormal data set M. Additionally, the anomaly detection pipeline will include a robust model for the industrial asset. The enlarged data sets L 2 and M can be additionally used to cluster operation data from similar industrial assets.
[0060] Figure 4 Illustrated is a majority vote for labeling unlabeled subsets S in normal N and abnormal A data sets when multiple anomaly detection models i = l,...N are available at the i-th step. The data is labeled as a robust anomaly only when most models indicate that the unlabeled data is abnormal in time region 440. In other cases, when only one of the three anomaly detection models indicates abnormal behavior, the data S is considered normal in these time regions 410 - 430. As shown in the above description, the method of the present invention produces an enlarged training data set L 2 and an enlarged abnormal data set M. Additionally, the anomaly detection pipeline will include a robust model for the industrial asset.
[0061] At Figure 4In the figure, the abnormal data points output by different anomaly detection models are illustrated on the curve graph. 410 illustrates the abnormal data point AD1 detected by the anomaly detection model 1. 420 illustrates the abnormal data point AD2 detected by the anomaly detection model 2. 430 illustrates the abnormal data point AD3 detected by the anomaly detection model 3. The abnormal data points AD1 and AD2 overlap with each other. However, AD3 does not overlap with AD1 and AD2. The abnormal data points AD1 and AD2 are identified as a robust abnormal data set, and the corresponding anomaly detection models 1 and 2 are identified as robust models that can be used in the set in the anomaly detection pipeline.
[0062] Figure 5 Illustrated are the steps of a method for detecting abnormal data points in operational data associated with an industrial environment according to an embodiment of the present invention.
[0063] The method begins at step 510 of applying one or more anomaly detection models to at least one subset of the operational data. The anomaly detection models are trained based on a training data set. The training data set initially includes data points labeled as normal. Thus, step 510 includes training the anomaly detection models based on the training data set. The training data set may be provided with normal data points based on actions performed by an expert. Thus, step 510 may include receiving a training data set including at least normal data points, wherein the normal data points are classified based on at least one of engineering software inputs and operations in a similar industrial environment.
[0064] When an anomaly detection model is applied to a subset of the operational data, classification of the data points in the subset is possible. Step 520 includes classifying the subset-data points as subset normal data points or abnormal data points. The classification of the subset data points enables labeling of the unlabeled data points in the operational data.
[0065] In one embodiment, step 520 may include determining a confidence index in the subset-data point classification based on at least one of engineering software inputs and operations in a similar industrial environment. The method may further include: reclassifying the subset data points when a confidence threshold is not met; and updating the training data set using the confidence index and the reclassified data points. The present invention provides a mechanism for verifying the classification of subset data points or new data points by determining a confidence index. For example, the difference between a data point classified as normal and the boundary conditions set by an automation engineer can be used to determine the confidence index. Additionally, expert input may be provided for data points that require reclassification.
[0066] The tags provide new training data for the anomaly detection model. Thus, step 530 includes updating the training data set with at least normal data points. Step 530 may also include populating an anomaly data set that contains anomaly data points in the subset and the new subset. The anomaly data set can be populated after classifying the data points in the subset of the new subset. The update of the training data set can be performed iteratively. The iterative population of the anomaly data set enables continuous learning and retraining of the anomaly detection model.
[0067] When the iteration threshold (i.e., the threshold time) is met, the anomaly detection model is retrained based on the updated training data set. Step 540 includes retraining the anomaly detection model with the updated training data set after the expiration of the threshold time. The retraining of the anomaly detection model strengthens the classification performed on the subset data points. Step 550 includes detecting anomaly data points in the operational data based on the application of the constrained anomaly detection model.
[0068] Figure 6 FIG. illustrates a predictive maintenance system 600 according to an embodiment of the present invention and computing devices 620 and 620' for detecting anomaly data points in operational data associated with an industrial environment 610. The industrial environment 610 includes a plurality of industrial assets 612-618. The industrial assets may include a motor 612, a rotor 614, a conveyor belt 616, and a gearbox 618. The industrial assets 612 to 618 may be equipped with sensors configured to measure corresponding operating parameters.
[0069] In one embodiment, the computing device 620 is located within the industrial environment 610. For example, the computing device 620 may be an edge computing device. The edge computing device 620 may be a lightweight and low-cost device that collects data from various sensors deployed in the industrial environment 610, stores and buffers the collected data (i.e., the operating data of the industrial assets 612-618), performs analysis on the collected data, and executes actions (e.g., issuing control commands) based on the results of the analysis. In the present invention, the analysis performed by the edge computing device 620 is to detect anomaly data points in the operational data.
[0070] In another embodiment, the computing device 620' may be hosted on an IOT platform 650. The IOT platform 650 may include a cloud computing platform, a fog / edge computing platform, or a combination of both. In one embodiment, the IOT platform 650 serves as a host on which the computing device 620' is implemented. The IOT platform 650 includes distributed computing resources distributed and connected via a communication network.
[0071] As used herein, "cloud computing" refers to a processing environment that includes configurable computing physical and logical resources (e.g., networks, servers, memories, applications, services, etc.) and data distributed over a network (e.g., the Internet). A cloud computing system provides on-demand network access to a shared pool of configurable computing physical and logical resources. The network is, for example, a wired network, a wireless network, a communication network, or a network formed by any combination of these networks.
[0072] As used herein, "fog computing" or edge computing enables an IOT platform to be implemented closer to an automation environment. Fog / edge computing extends cloud computing to the physical locations of devices belonging to an automation network. It can be a combination of multiple edge devices 620 configured to perform the operations of the IOT platform 650.
[0073] The predictive maintenance system 600 includes computing devices 620 and 620', an IOT platform 650, and a database 640. The database 640 is configured to store historical operation data of industrial assets 612 - 618. The historical operation data refers to data collected from sensors in the industrial environment 610 and stored in the database 640 or the computing device 620. In addition, the database 640 may also include a training data set associated with the industrial environment. Further, the database 640 may be configured to store simulation models associated with the industrial environment 610 and the industrial assets 612 - 618.
[0074] The computing devices 620 and 620' may include similar hardware / software modules to implement the present invention. The following description is about the edge device 620. The edge device 620 includes a processing unit 622, a display 624 configured to receive user input and display an output based on commands from the processing unit 622, and a memory 630 communicatively coupled to the processing unit 622. Although not shown in Figure 6 , it can be understood that the edge device 620 may also include a power module, a communication interface, etc. The processing unit 622 is configured to execute modules stored in the memory 630. The display 624 is configured to display a graphical user interface (GUI) 626 to enable an automation engineer / expert to interact with the edge device 620.
[0075] The memory 630 includes an anomaly module 635, which when executed enables the edge device 620 to detect anomaly data points in the operation data. The anomaly module 635 includes a training module 632, a marking module 634, an updating module 636, and a retraining module 638.
[0076] In operation, the edge device 620 receives operational data from sensors associated with industrial assets 612 - 618 via a communication interface. Additionally, the edge device 620 extracts a training data set stored in the database 640. The training module 632 is configured to train one or more anomaly detection models generated from a simulation model in the database 640. The training is based on the training data set extracted from the database 640. The training data set includes normal data points that have been verified based on operations in a similar industrial environment.
[0077] In one embodiment, an anomaly detection model is selected to form an anomaly detection pipeline. The anomaly detection pipeline is implemented as an isolated workflow for training, classification, and retraining. The training module 632 can be configured to generate an anomaly detection pipeline that includes the anomaly detection models based on deviation scores determined for each anomaly detection model. The deviation scores are determined based on the attributes of the anomaly detection models, and the deviation scores indicate the accuracy of each anomaly detection model.
[0078] The tagging module 634 is configured to classify data points in a subset of the operational data. The data points within the subset are referred to as subset - data points. The subset data points are classified as normal data points or anomaly data points using the anomaly detection models. In one embodiment, the tagging module 634 is also configured to determine a confidence index in the subset data point classification based on a simulation model or operations in a similar industrial environment. The tagging module 634 can be configured to classify the subset data points when a confidence threshold is not met. For example, the confidence threshold can be a predetermined value that an automation engineer can set using the GUI 626 to ensure that the quality of the classification does not exceed a predetermined value. In another embodiment, the automation engineer can re - classify data points that do not meet the confidence threshold.
[0079] The update module 636 is configured to update the training data set with the newly classified normal data points in the subset. In one embodiment, the training data set can also be updated with the confidence index and re - classified data points. The update module 636 is configured to populate an anomaly data set that contains the anomaly data points in the subset. In one embodiment, the training data set can be updated with the anomaly data set. The update module 636 is configured to determine a threshold time based on the number of updates performed on the training data set.
[0080] When the threshold time expires, the retraining module 638 is configured to retrain the anomaly detection model with an updated training data set. Additionally, the retraining module 638 extracts a new subset from the operational data and applies the retrained anomaly detection model to the new subset of the operational data. Thereafter, the tagging module 634 is configured to classify the new data points in the new subset as normal data points or anomaly data points. Based on the classification, the anomaly module 635 is configured to iteratively detect the anomaly data points in the operational data. In one embodiment, the anomaly module 635 is configured to detect a batch of anomaly data points in the operational data.
[0081] The present invention may take the form of a computer program product that includes program modules accessible from a computer-usable or computer-readable medium that stores program code for use by or in conjunction with one or more computers, processors, or instruction execution systems. For the purposes of this specification, a computer-usable or computer-readable medium can be any device that can contain, store, communicate, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The medium can be an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system (or apparatus or device) or propagation medium, or they themselves, as a signal carrier is not included in the definition of a physical computer-readable medium, which includes semiconductor or solid state memories, magnetic tape, removable computer disks, random access memory (RAM), read-only memory (ROM), hard disk, and optical disks such as compact disk read-only memory (CD-ROM), compact disk read / write, and DVD. The processors and program code for implementing each aspect of the present technology can be centralized or distributed (or a combination thereof) as would be known to those skilled in the art.
Claims
1. A method for detecting at least one anomalous data point in operational data (U) associated with an industrial environment (610), wherein the operational data (U) includes historical data and streaming data corresponding to the operation of industrial assets (612 - 618) in the industrial environment (610), the method comprises: applying one or more anomaly detection models (fi) to at least one subset (S) of the operational data (U), wherein the anomaly detection models (fi) are trained based on a training data set (L) consisting of data points labeled as normal; using the anomaly detection models (fi) to classify the subset - data points in the subset (S) as either normal data points (N) or anomalous data points (A); determining a confidence index in the classification of the subset - data points based on at least one of engineering software input and operations in a similar industrial environment; when a confidence threshold is not met, re - classifying the subset - data points; updating the training data set with the confidence index and the re - classified data points; updating the training data set at least with the normal data points; re - training the anomaly detection models (fi) with the updated training data set after a threshold time has elapsed, wherein the threshold time is based on the number of updates to the training data set; and using the anomaly detection models to detect the at least one anomalous data point in the operational data (U); removing the subset from the operational data (U); using the re - trained anomaly detection models (fi) to detect the at least one anomalous data point in the remaining operational data (U) without the subset; applying the re - trained anomaly detection models (fi) to a new subset of the operational data (U) and classifying the new data points in the new subset as either the normal data points (N) or the anomalous data points (A); and updating the training data set and re - training the re - trained anomaly detection models.
2. The method according to claim 1, further comprises: populating an anomaly data set containing the anomalous data points in the subset and the new subset.
3. The method according to claim 2, further comprises: updating the training data set with the anomaly data set.
4. The method according to claim 1, further comprises: receiving the training data set (L) including at least the normal data points, wherein the normal data points are classified based on at least one of engineering software input and operations in a similar industrial environment; and training the anomaly detection models (fi) based on the training data set (L) including the normal data points.
5. The method according to any one of the preceding claims, wherein, The one or more anomaly detection models (fi) are included in an anomaly detection pipeline (224, 306, 326), where the anomaly detection pipeline (224, 306, 326) is implemented as an iterative workflow of training, classification, and retraining, where the anomaly detection model (fi) is trained with the training dataset, where the anomaly detection model (fi) is validated based on the classification of the normal data points and the anomaly data points, and where the anomaly detection model (fi) is retrained based on the updated training dataset.
6. The method according to claim 5, further comprising: generating an anomaly detection pipeline (224, 306, 326) that includes an anomaly detection model (fi) associated with an industrial environment (610), where the anomaly detection model (fi) includes physics-based models, data-driven models, and combinations thereof; and determining a deviation score of the anomaly detection model (fi) based on an attribute of the anomaly detection model (fi).
7. The method according to claim 6, wherein generating the anomaly detection pipeline (224, 306, 326) further comprises: implementing selecting at least one anomaly detection model for the anomaly detection pipeline (224, 306, 326) based on the deviation score.
8. The method according to claim 5, further comprising: detecting a batch of anomaly data points in the operational data (U) using the anomaly detection pipeline (224, 306, 326), where detecting the batch of anomaly data points comprises: applying the anomaly detection pipeline (224, 306, 326) to at least one subset of the batch, where the anomaly detection pipeline (224, 306, 326) is trained based on a training dataset composed of the normal data points; classifying the subset-data points in the subset as one of the normal data points and the anomaly data points using the anomaly detection pipeline (224, 306, 326); enlarging the training dataset with at least the normal data points; and retraining the anomaly detection pipeline (224, 306, 326) with the updated training dataset after the expiration of the threshold time, where the threshold time is based on the number of updates to the training dataset.
9. A computing device (620, 620') for detecting at least one anomaly data point in operational data (U) associated with an industrial environment (610), where the operational data (U) includes historical data and streaming data corresponding to the operation of industrial assets (612 - 618) in the industrial environment (610), the device comprising: a processing unit (622); and an anomaly module (635) executable by the processing unit, including computer-readable instructions that, when executed by the processing unit (622), the anomaly module is configured to perform the steps in the method according to any one of claims 1 - 8.
10. A predictive maintenance system (600) for an industrial environment (610), the system comprising a computing device according to claim 9.
11. A computer-readable medium having machine-readable instructions stored thereon, the instructions when executed by a processor cause the processor to perform the method steps according to any one of claims 1-8.
Citation Information
Patent Citations
Method and system for adaptively removing outliers from data used in training of predictive models
US20180081913A1
Failure detection and classsification using sensor data and / or measurement data
US20190277913A1
Model learning device, model learning method, and program
WO2019138655A1