A method and system for detecting abnormal operation of an electric meter based on deep learning
Patent Information
- Application Number
- CN202310868442.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-14
- Publication Date
- 2026-10-09
- Estimated Expiration
- 2043-07-14
AI Technical Summary
然而,智能电表也面临着一些安全问题,如被黑客入侵、攻击或恶意用户篡改
[0027] This invention can effectively detect novel attacks or malicious tampering and other abnormal operations, avoiding the limitations of traditional rule-based or model-based detection methods. In addition, the system proposed in this invention can be integrated into existing remote servers and concentrators, effectively ensuring the safe operation of smart meters.
Smart Images

Figure CN117110971B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power systems, and in particular to a method and system for detecting abnormal operation of electricity meters based on deep learning. Background Technology
[0002] Smart meters are widely used and play a vital role in the operation and management of power systems due to their ability to collect and transmit electricity consumption information in real time. However, smart meters also face several security challenges, such as vulnerability to hacking, attacks, or malicious user tampering. Secondly, data leakage and privacy issues may arise during the transmission of electricity data, threatening users' privacy and information security. Finally, because smart meter detection methods primarily rely on manually constructed rules or models, their ability to detect new types of attacks is relatively weak, making it difficult to achieve real-time detection and prevention of abnormal meter operations. Therefore, developing a smart meter abnormal operation detection system and method with strong adaptability and generalization capabilities is particularly important. Summary of the Invention
[0003] To address the aforementioned problems, this invention proposes a deep learning-based method for detecting abnormal operation of electricity meters. The method involves detecting anomalies in control commands sent from a remote server to the concentrator, specifically including the following steps:
[0004] Within a fixed time period after system initialization, the remote server collects control commands sent to the concentrator.
[0005] When the number of control commands collected by the concentrator reaches a first threshold, the collected data is used as the first dataset, and the first dataset is clustered.
[0006] Information about multiple cluster centers is obtained through clustering. The concentrator sends the data of the cluster centers to the concentrator. The concentrator calculates the distance between the received control command and each cluster center. If the distance to the nearest cluster center is greater than a set threshold, the data is labeled as abnormal.
[0007] The concentrator collects data labeled as anomalous. If the amount of data reaches the second threshold, the collected data is used as the second dataset.
[0008] The GRU model is trained using the second dataset, and the trained model parameters are sent to the concentrator.
[0009] The concentrator updates the local model based on the received model parameters and then checks the received control commands based on the updated model.
[0010] Furthermore, the process of clustering control commands includes the following steps:
[0011] The collected control command sequence is truncated into short sequences of equal length using the sliding window technique;
[0012] Each short sequence is converted into a vector form using the Word2Vec technique;
[0013] The distance between each control command is calculated using Euclidean distance, and clustering is performed based on this distance to obtain multiple cluster centers.
[0014] Furthermore, the process by which the GRU model performs detection, using the vector representation of the current control command and the hidden state from the previous time step as input, includes the following steps:
[0015] r t =σ(W rx x t +W rh h t-1 +b r )
[0016] z t =σ(W zx x t +W zh h t-1 +b z )
[0017] h' t =tanh(W hx x t +W hr r t h t-1 +b h )
[0018] h t =(1-z) t )h t-1 +z t h' t
[0019] Among them, W rx W rh To update the weight matrix in the gate, b r To update the bias in the gate; W zx W zh To reset the weight matrix in the gate, b z To reset the offset in the door; W hx W hr Let b be the weight matrix in the hidden layer. h This is the bias in the hidden layer.
[0020] Furthermore, the control commands sent from the remote server to the concentrator are binary instructions. These binary instructions are converted to English instructions before being used for detection and training. This invention also proposes a deep learning-based meter abnormal operation detection system, including a remote server and a concentrator. The remote server includes a training module, a storage module, and a communication module. The concentrator includes a communication module, a command conversion module, a collection module, a detection module, and an alarm module; wherein:
[0021] The training module is used to update the parameters of the detection module in the concentrator;
[0022] The storage module is used to store the training data required by the training module;
[0023] The communication module is used for communication between the concentrator and the remote server, and also for distributing the received information to various modules in the remote server and the concentrator.
[0024] The command conversion module is used to convert received control commands in binary format into English format.
[0025] The detection module is used to detect whether there are any abnormalities in the control commands received by the concentrator;
[0026] The alarm module is used to issue early warnings based on the detection results from the detection module.
[0027] This invention can effectively detect novel attacks or malicious tampering and other abnormal operations, avoiding the limitations of traditional rule-based or model-based detection methods. In addition, the system proposed in this invention can be integrated into existing remote servers and concentrators, effectively ensuring the safe operation of smart meters. Attached Figure Description
[0028] Figure 1 This is a schematic diagram of the structure of a deep learning-based electricity meter abnormal operation detection system in an embodiment of the present invention;
[0029] Figure 2 This is a schematic diagram of the communication module in an embodiment of the present invention;
[0030] Figure 3 This is a schematic diagram of the training module in an embodiment of the present invention.
[0031] Figure 4 This is a schematic diagram of the storage module in an embodiment of the present invention;
[0032] Figure 5 This is a schematic diagram of the command conversion module in an embodiment of the present invention;
[0033] Figure 6 This is a schematic diagram of the collection module in an embodiment of the present invention;
[0034] Figure 7 This is a schematic diagram of the detection module in an embodiment of the present invention;
[0035] Figure 8 This is a flowchart of the sliding window technology according to an embodiment of the present invention;
[0036] Figure 9 This is a flowchart of the Word2vec technology according to an embodiment of the present invention;
[0037] Figure 10 This is a flowchart of the K-means algorithm according to an embodiment of the present invention;
[0038] Figure 11 This is an internal structural diagram of the training module in an embodiment of the present invention;
[0039] Figure 12 This is an internal structural diagram of the collection module in an embodiment of the present invention;
[0040] Figure 13 This is an internal structural diagram of the detection module in an embodiment of the present invention;
[0041] Figure 14 This is a flowchart of a method for detecting abnormal operation of electricity meters based on deep learning, according to the present invention. Detailed Implementation
[0042] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0043] This invention proposes a deep learning-based method for detecting abnormal operation of electricity meters. The method involves detecting abnormalities in control commands sent from a remote server to the concentrator, such as... Figure 14 Specifically, it includes the following steps:
[0044] Within a fixed time period after system initialization, the remote server collects control commands sent to the concentrator.
[0045] When the number of control commands collected by the concentrator reaches a first threshold, the collected data is used as the first dataset, and the first dataset is clustered.
[0046] Information about multiple cluster centers is obtained through clustering. The concentrator sends the data of the cluster centers to the concentrator. The concentrator calculates the distance between the received control command and each cluster center. If the distance to the nearest cluster center is greater than a set threshold, the data is labeled as abnormal.
[0047] The concentrator collects data labeled as anomalous. If the amount of data reaches the second threshold, the collected data is used as the second dataset.
[0048] The GRU model is trained using the second dataset, and the trained model parameters are sent to the concentrator.
[0049] The concentrator updates the local model based on the received model parameters and then checks the received control commands based on the updated model.
[0050] This embodiment also proposes a deep learning-based electricity meter abnormal operation detection system, including a remote server and a concentrator. The remote server includes a training module, a storage module, and a communication module, while the concentrator includes a communication module, a command conversion module, a collection module, a detection module, and an alarm module; wherein:
[0051] The training module is used to update the parameters of the detection module in the concentrator;
[0052] The storage module is used to store the training data required by the training module;
[0053] The communication module is used for communication between the concentrator and the remote server, and also for distributing the received information to various modules in the remote server and the concentrator.
[0054] The command conversion module is used to convert received control commands in binary format into English format.
[0055] The detection module is used to detect whether there are any abnormalities in the control commands received by the concentrator;
[0056] The alarm module is used to issue early warnings based on the detection results from the detection module.
[0057] Furthermore, in this invention, the communication module is mainly used to connect the remote server and the concentrator, and is responsible for information exchange. The communication module on the remote server side is mainly responsible for sending binary instruction sets to the concentrator side, and receiving the data response from the concentrator in a question-and-answer manner. The received data also needs to be parsed according to a specific protocol to obtain the valid data in the data field, and to determine the type of these valid data to decide which module in the server to distribute them to. The communication module on the concentrator side is mainly responsible for receiving instructions and packaging the operation sequence sets output by other modules to conform to a specific communication protocol format, and then sending them to the remote server.
[0058] Furthermore, in the early stages of this invention, when the dataset consists entirely of normal operation sequences, the training module can use these data as training data for clustering, dividing the operation sequences into different clusters, each cluster representing a group of similar operation sequences. As the number of abnormal operation sequences in the storage module increases, supervised learning can be performed once the required quantity is reached. These labeled operation sequences are then fed into the GRU model for training, preparing for the detection module.
[0059] Furthermore, the storage module in this invention is mainly responsible for collecting the abnormal / normal operation sequences returned by the concentrator and the parameters of the model training results in the training module, as well as cooperating with experts to operate these operation sequences. The main operations include modifying the labels of the operation short sequences and adding abnormal operation short sequences. The former corrects the operation short sequences that the model misjudged, and the latter adds similar abnormal operation short sequences to expand the abnormal dataset. Both can improve the accuracy of the next model detection.
[0060] Furthermore, the command conversion module in this invention is mainly responsible for parsing the control codes in the operation instructions from the binary instruction set transmitted by the communication module according to the specific communication protocol, and converting these binary codes into corresponding English instructions according to the function of the control codes in the protocol.
[0061] Furthermore, the collection module in this invention is mainly used to collect and store the English instructions transmitted from the command conversion module in a timed manner, and use them as the dataset for unsupervised learning of the model in the training module. The set of instructions collected in this module is regarded as an operation sequence, and these operation sequences are all identified as normal operation sequences.
[0062] Furthermore, in this invention, when the training module uses an unsupervised clustering algorithm, the detection module performs the following: First, the operation sequence entering the training module is truncated into short sequences of equal length using a sliding window technique. Then, Word2Vec technology is applied to convert it into vector form, and the distance is calculated using the Euclidean distance formula. The distances to multiple cluster centers are compared. If the distance to the nearest cluster center exceeds a certain threshold, the sequence is considered an anomalous sequence. When the training module uses a GRU model, the detection method is to put the short sequence features into the GRU model for detection. The GRU model outputs anomaly probability and compares it with a preset threshold. If it is greater than the threshold, it is determined to be an anomalous operation sequence.
[0063] Furthermore, the alarm module in this invention is mainly used to trigger an alarm when the detection module detects an abnormal operation sequence. The alarm is achieved through a combination of sound, light, and information communication. When the alarm is triggered, the alarm module first connects to the communication network and notifies relevant personnel or the monitoring center by sending an SMS message. Then, it activates its built-in sound device, such as a buzzer or speaker, to emit a continuous or intermittent sound alarm, and the LED indicator flashes to send an alarm signal.
[0064] This embodiment provides a specific implementation of a deep learning-based electricity meter abnormal operation detection system, such as... Figure 1 As shown, the system needs to be embedded in the concentrator, including a communication module, a collection module, a command conversion module, a detection module, and an alarm module, and also needs to be installed on a remote server, including a communication module, a training module, and a storage module. The workflow of the entire system is as follows: In the command conversion module at the concentrator, binary instructions are parsed into English instructions with clearer semantic information. These English instructions are collected and stored in the collection module at regular intervals. When the server sends a retrieval instruction, the instructions are packaged by a specific protocol and returned to the server.
[0065] The server's training module innovatively uses clustering to build a detection model. The concentrator's detection module responds to the server in real time with detected normal or abnormal operation sequences and stores them in the storage module. Once the number of operation sequences reaches the required level, they are sent to the training module, the training mode is switched, and a GRU model is used for training. The detection model in the concentrator only needs to obtain the model parameters trained by the server for updates. It is worth noting that, considering the system load, the collection module and the detection module will not be started simultaneously. In addition, the system proposed in this invention has the advantages of strong adaptability, high detection accuracy, and good real-time performance. It can be integrated into existing remote servers and concentrators to effectively ensure the safe operation of smart meters.
[0066] The remote server includes a training module, a storage module, and a communication module. These three modules are described below:
[0067] The communication module, in this embodiment, is mainly responsible for receiving and sending instructions, as well as determining the data type of the received information and distributing it to different modules of the server. The determination unit is a new addition to the traditional communication module. Information exchange between the server and the concentrator needs to conform to specific communication protocols and instruction formats. By selecting to mark the received information in the extended frame of the communication protocol, the communication module can send the received information to the designated module. The communication module mainly includes a receiving unit, a sending unit, and a determination unit, wherein:
[0068] The receiving unit mainly receives the response results of the concentrator after the remote server sends instructions to the concentrator. These results mainly include the electricity consumption data collected by the concentrator from the electricity meter, various parameters of the concentrator, the operation sequence stored in the collection module of the concentrator, and the operation sequence from the detection module of the concentrator.
[0069] The sending unit is mainly responsible for sending operation instructions under a specific communication protocol to the concentrator, and the server and the concentrator often communicate in a one-to-one manner.
[0070] The judgment unit primarily determines whether the data returned by the concentrator to the server carries an operation sequence. Since commonly used protocols, such as DL / T645-2007, reserve positions for user-expandable function codes, these reserved function codes can be used to identify the content of the currently returned data and determine whether it is distributed to the storage module, training module, or other modules.
[0071] The training module's main purpose is to train the operation sequence detection model. Its internal structure is shown in the diagram below. Figure 11 As shown. The training module includes an acquisition unit, a processing unit, a feature extraction unit, and a training unit, as follows: Figure 3 As shown, where:
[0072] The acquisition unit is responsible for receiving operation sequences from the storage modules of the concentrator and server. The operation sequences collected by the storage modules differ from those collected by the concentrator in that they are labeled; these labeled operation sequences are primarily used for supervised learning. When the switches of the feature extraction unit and training unit are turned up, the acquisition unit receives data from the concentrator; conversely, it receives data from the storage modules in the server.
[0073] The processing unit primarily uses a sliding window technique to truncate the operation sequences from the converger, breaking long sequences into shorter sequences of equal length for use in model training.
[0074] The process of sliding window technology is as follows Figure 7 As shown, the main steps include:
[0075] Step 1001: Define the window size and step size, determine the window size for the sequence of operations to be captured, represent the number of operations to be captured each time, and determine the step size that the window needs to move.
[0076] Step 1002: Initialize the window. Starting from the beginning of the operation sequence, initialize a window with a size equal to the window size.
[0077] Step 1003: Process window data. For each operation in the window, the main task is to transmit the operation sequence in the window to the detection unit.
[0078] Step 1004: Move Window: After completing the operation on the current window, slide the window to the right by a fixed step, which means starting from the next operation.
[0079] Step 1005: Determine if the window has reached the end of the sequence. If not, repeat steps 1003 and 1004 until the window slides to the end of the operation sequence.
[0080] When performing sliding window operations, it's important to handle boundary cases. If the length of the sequence is not divisible by the window size, there might be a case where the length of the last subsequence is less than the window size. You can pad the blank areas with semantically meaningless zeros to expand it to the same size as the window.
[0081] Processing unit, used to process the operation sequence from the concentrator collection module:
[0082] T = {S1, S2, S3,...Sn} (1)
[0083] In the formula, T represents the original set of sequences, and Sn is the original sequence.
[0084] SSn = {t1,t2,...,ti} (2)
[0085] In the formula, SS n Let t represent the set of short sequences. i It is a short sequence.
[0086] SSn = SlidingWindow(Sn) (3)
[0087] In the formula, SlidingWindow() represents the sliding window processing function, which is used to extract the original sequence into a short sequence of system calls.
[0088] The feature extraction unit primarily uses Word2Vec technology to extract features from short sequences, mapping words to a continuous vector space to capture semantic relationships between words. These vectors are then averaged to represent the entire text data. These vectors can be used as feature representations for short sequences to train the model. The feature extraction process includes:
[0089] Inputn= WordEmbedding(SSn) (4)
[0090] In the formula, WordEmbedding() represents the word embedding function, which is used to convert short sequences of system calls into word vector matrix form, and Inputn represents the input of the training unit.
[0091] The specific process of feature extraction in the feature extraction unit is as follows: Figure 9As shown, it includes:
[0092] Step 1101: Input a short sequence.
[0093] Step 1102: Load the existing word vector model. Load the pre-trained Word2Vec word vector model.
[0094] Step 1103: Tokenization. The short sequence is tokenized into words or sub-words.
[0095] Step 1104: Obtain word vectors. For each word in the sentence, query the word vector model to obtain the corresponding word vector.
[0096] Step 1105: Calculate the average vector. Average the vectors of each word vector in the short sequence along the corresponding dimension to obtain the vector representation of the entire sentence.
[0097] Step 1106: Output the short sequence vector.
[0098] The training module's training consists of two phases. In the first phase, during the initial system operation, the collection module in the concentrator gathers control commands from the remote server. When the collected data reaches a set threshold, it sends the data back to the training module for clustering. The training module completes the clustering based on the data received from the collection module and sends the cluster centers to the detection module, completing the first phase of training. In the second phase, the collection module gathers detection results from the detection module, uses these results as data labels, and transmits the labeled data back to the remote server's storage module. When the labeled data in the storage module reaches a set threshold, the training module uses this labeled data to train the GRU model. After training, the parameters of the GRU model are sent to the concentrator's detection module, completing the second phase of training. Specifically, this includes:
[0099] When the first-stage dataset for the training unit comes from the collection module of the convergent, it represents normal operation sequences. The model performs unsupervised learning, using clustering of short sequences to build the model. In this embodiment, an unsupervised clustering algorithm, such as k-means, is used to cluster the operation sequences, dividing them into different clusters. At this time, the switch between the feature extraction unit and the training unit is turned on upwards. During the training phase, such as... Figure 10 As shown, it includes:
[0100] Step 1201: Read all the data and use the collected normal short sequences as input data.
[0101] Step 1202: Randomly select k data points as the initial cluster centers, where the k parameter comes from a remote server.
[0102] Step 1203: Calculate the distance of the remaining data to the cluster center and assign it to the nearest cluster. Cluster these short sequences, dividing them into different clusters, and assign similar short sequences to the same cluster based on their similarity.
[0103] Step 1204: Recalculate cluster centers. Through iterative optimization, the algorithm adjusts the positions of cluster centers, making short sequences within a cluster more similar, while short sequences between different clusters differ more significantly.
[0104] Step 1205: Determine if there is a change in the cluster center. If there is a change, return to step 3; otherwise, end the training unit.
[0105] After training, the model saves the clustering results, including cluster centers and the cluster to which each short sequence belongs. These clustering results can be used for subsequent short sequence classification tasks. During detection, if the distance between the sequence to be detected and the nearest cluster center is greater than a certain threshold, it is considered an anomalous sequence.
[0106] When the second-stage training unit's dataset comes from the remote server's storage module, it indicates that the operation sequences are labeled, and the model can perform supervised learning. This primarily involves feeding the labeled dataset to the GRU model for training, at which point the switch between the feature extraction unit and the training unit is turned on downwards. During the training phase, the labeled short sequence dataset is divided into training and validation sets. Then, the data is fed to the GRU model for training, optimizing the model parameters by minimizing a loss function (such as cross-entropy loss).
[0107] like Figure 11 As shown, the computation process of the recurrent unit in the GRU network is as follows: using the input vector x at time t... t The hidden layer state h at time t-1 t-1 As input, the output z of the reset gate and update gate are updated using equations (5) to (8). t With r t The candidate state h' is updated using formula (7). t And finally update the hidden layer state h using equation (8). t The above process can be represented as:
[0108] r t =σ(W rx x t +W rh h t-1 +b r (5)
[0109] z t =σ(W zx x t +W zh h t-1+b z (6)
[0110] h' t =tanh(W hx x t +W hr r t h t-1 +b h (7)
[0111] h t =(1-z) t )h t-1 +z t h' t (8)
[0112] In the formula, W rx W rh W zx W zh W hx W hr Let b represent the weight matrix corresponding to the update gate, reset gate, and hidden layers, etc. r b z b h This represents the bias vector of the corresponding component; the output of the last hidden layer is input into the fully connected layer, and the output of the fully connected layer is mapped to a range of 0 to 1 through an activation function as the probability of whether the data is abnormal.
[0113] The storage module's main function is to store labeled operation sequences and annotate operation sequences from the concentrator. In this embodiment, abnormal operation sequences are marked as 1, and normal operation sequences are marked as 0. It also stores model training result parameters and operation sequences. Figure 4 As shown, it includes an operation unit, a parameter storage unit, and an operation sequence storage unit, wherein:
[0114] The operation unit introduces a human element to judge the correctness of operation sequences. This human judgment process requires experts to evaluate the operation sequences returned by the concentrator, which are labeled as normal or abnormal. This includes determining if there are any misclassified operation sequences, whether the labels of misclassified operation sequences need to be modified, and whether labeled data needs to be imported from external sources. Experts can modify the label content within the operation unit and add abnormal operation sequences to the storage unit to expand the dataset required for supervised learning of the detection model. As an optional implementation, the labeled data can be sampled manually. Based on the sampling results, externally labeled operation sequences can be introduced. The more misclassified data there is in the sampling results, the more externally labeled operation sequences can be introduced, but the number of externally labeled operation sequences introduced cannot exceed 50% of the total data volume.
[0115] The operation sequence storage unit is mainly used to store the operation sequence from the concentrator;
[0116] The parameter storage unit is mainly used to store the parameters of the model after training is completed in the training module.
[0117] The concentrator includes a communication module, a command conversion module, a collection module, a detection module, and an alarm module. The command conversion module is primarily responsible for collecting binary instruction sets from a remote server, parsing the binary instructions using a specific communication protocol, extracting control codes, and converting the control codes into corresponding English instructions, such as... Figure 5 As shown, it includes an acquisition unit and a conversion unit, wherein:
[0118] The acquisition unit is mainly responsible for acquiring the binary instruction set sent by the remote server to the concentrator, parsing out the control code part of the instruction, and then transferring it to the conversion unit.
[0119] The conversion unit primarily uses a specific communication protocol to convert the control codes transmitted from the acquisition unit into corresponding English commands through a function code lookup table under this communication protocol. This embodiment mainly describes the content of the control codes. The corresponding English commands are related to the communication protocol. The following example uses the DL / T645-2007 protocol. A data frame in the DLT645 protocol consists of a start character, address field, control code, data field length, data field, checksum, and end character. Specifically, in this embodiment, the protocol specifies that the control code occupies one byte. The first bit indicates the transmission direction: 0 indicates a command frame from the server, and 1 indicates a response frame from the concentrator. The second bit indicates the slave station's response flag: 0 indicates a correct response from the concentrator, and 1 indicates an abnormal response from the concentrator. The third bit indicates the subsequent frame flag: 0 indicates no subsequent data frames, and 1 indicates subsequent data frames. The last five bits represent the function code. The main correspondence between the function codes and English commands is as follows:
[0120] The binary instruction 00000 corresponds to the English instruction "Reserve".
[0121] The English instruction corresponding to binary instruction 10001 is Read data;
[0122] The English instruction corresponding to the binary instruction 10010 is Read subsequent data;
[0123] The English instruction corresponding to binary instruction 10011 is "Read communication address".
[0124] The binary instruction 10100 corresponds to the English instruction "Write data";
[0125] The binary instruction 10101 corresponds to the English instruction "Write communication address".
[0126] The binary instruction 10110 corresponds to the English instruction "Freeze order".
[0127] The English instruction corresponding to the binary instruction 10111 is "Change the communication rate".
[0128] The binary instruction 11000 corresponds to the English instruction "Change password".
[0129] The English instruction corresponding to binary instruction 11001 is Clear the maximum demand;
[0130] The binary instruction 01000 corresponds to the English instruction Broadcast timing;
[0131] The binary instruction 11011 corresponds to the English instruction Clear event;
[0132] The binary instruction 11010 corresponds to the English instruction Reset electric meter;
[0133] It also includes corresponding instructions for tripping / closing, alarms, power protection, multi-function terminal output control settings, safety authentication, and some reserved function codes.
[0134] In an optional embodiment, for example, a binary instruction may consist of:
[0135] Start character: 01101000
[0136] Address field: 00000001 (Device address is 0x01)
[0137] Control code 1: 00110001 (Function code for reading data)
[0138] Data field length 1: 00000000 (A data field length of 0 indicates that there is no additional data).
[0139] Control code 2: 00111000 (Password change function code)
[0140] Data field length 2: 00000110 (data field length is 6 bytes)
[0141] Data field 2: New cryptographic data
[0142] Check digit: The binary representation derived from a specific calculation method.
[0143] End symbol: 00010110
[0144] The function code of the above binary instruction can be parsed as the English instruction combination [Read data, Change password]. The semantic information corresponding to this combination is to read the electricity consumption data and change the password. This instruction combination will be passed to the collection module and merged into an operation sequence by timed collection.
[0145] Those skilled in the art can obtain the corresponding information based on the selected protocol and the correspondence between binary and English instructions in that protocol.
[0146] Collection module, such as Figure 12 As shown, it is mainly responsible for collecting the operation sequence within the same time interval. For example... Figure 6 As shown, it includes a sorting unit, a truncation unit, and a storage unit, wherein:
[0147] The sorting unit primarily sorts the English commands from the command conversion module according to the time sequence in which they were input.
[0148] The extraction unit is mainly responsible for extracting ordered combinations of English instructions, i.e., operation sequences. It uses a timed method to extract the sorted combinations of English instructions at regular intervals (e.g., every ten minutes) and store them as the dataset needed to build the detection model.
[0149] The storage unit primarily stores the operation sequences collected periodically. When the switch after the interception unit is turned up, the operation sequences collected periodically by the interception unit are stored in the storage unit; otherwise, these operation sequences are passed to the detection module for anomaly detection.
[0150] The detection module in the concentrator primarily detects whether the operation sequence is an abnormal operation sequence. For example... Figure 7 As shown, it mainly includes a truncation unit, a feature extraction unit, and a detection unit, wherein:
[0151] The truncation unit mainly uses the sliding window technique to truncate the operation sequence output by the command conversion module into a fixed-length short sequence.
[0152] The feature extraction unit mainly uses Word2Vec technology to extract features from short sequences. This technology maps words into a continuous vector space to capture the semantic relationships between words. Word2Vec technology converts words in text data into vector form and uses these vectors as input for detection.
[0153] The detection unit primarily uses vectors from the feature extraction unit to detect whether short sequences contain anomalies, such as... Figure 13As shown, before applying the GRU model, the switch between the feature extraction unit and the training unit is turned upwards, and clustering is used for detection. For each cluster, the distance between the short sequence to be detected and the center of the cluster is calculated. The distance can be calculated using the Euclidean distance formula:
[0154]
[0155] Where, x i y represents the i-th feature of the operation sequence vector to be detected; i represents the i-th feature of the cluster center vector; n is the number of features in the operation sequence to be detected.
[0156] Compare the distances between this short sequence and all cluster centers, and assign it to the cluster with the smallest distance. If this smallest distance exceeds a certain threshold, the sequence is considered an anomalous sequence.
[0157] After the GRU model is trained in the training module, the switch between the feature extraction unit and the training unit is turned on downwards. Its main function is to receive word vectors of short sequences as input and output the abnormal probability of the operation sequence. If the abnormal probability exceeds the preset threshold, it will be judged as an abnormal operation.
[0158] In the detection unit of this invention, regardless of whether the k-means algorithm or the GRU model is used for anomaly detection, as long as a short sequence is detected as an abnormal short sequence, the corresponding un-truncated operation sequence will be judged as an abnormal operation sequence and returned to the server.
[0159] Furthermore, the detection model parameters of the detection unit in this invention are continuously updated through the training module of a remote server. The storage module of the remote server is constantly updating the dataset, which contains operation sequences with anomaly and normal labels. Such a dataset enables the training module to perform supervised learning, thereby allowing the detection module's model to continuously receive new parameters and improve the accuracy of anomaly detection.
[0160] The alarm module in the concentrator is responsible for triggering an alarm when the detection module detects abnormal operation. The module first connects to the communication network and notifies relevant personnel or the monitoring center by sending an SMS. Then, it emits a continuous or intermittent audible alarm through a built-in sound device (such as a buzzer or speaker) and combines it with an LED indicator to emit a flashing light to indicate the alarm signal.
[0161] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A method for detecting abnormal operation of electricity meters based on deep learning, characterized in that, Anomaly detection is performed on control commands sent from the remote server to the concentrator, specifically including the following steps: Within a fixed time period after system initialization, the remote server collects control commands sent to the concentrator. When the number of control commands collected by the concentrator reaches a first threshold, the collected data is used as the first dataset, and the first dataset is clustered. Information about multiple cluster centers is obtained through clustering. The data of the cluster centers is sent to the concentrator. The concentrator calculates the distance between the received control command and each cluster center. If the distance to the nearest cluster center is greater than a set threshold, the data is labeled as abnormal. The process of clustering control commands includes the following steps: The collected control command sequence is truncated into short sequences of equal length using the sliding window technique; Each short sequence is converted into a vector form using the Word2Vec technique; The distance between each control command is calculated using Euclidean distance, and clustering is performed based on this distance to obtain multiple cluster centers; The concentrator collects data labeled as anomalous. If the amount of data reaches the second threshold, the collected data is used as the second dataset. The GRU model is trained using the second dataset, and the trained model parameters are sent to the concentrator. The concentrator updates its local model based on the received model parameters and then detects the received control commands based on the updated model. The GRU model's detection process, using the vector representation of the current control command and the hidden state from the previous time step as input, includes the following steps: r t =σ(W rx x t +W rh h t−1 +b r ) z t =σ(W zx x t +W zh h t−1 +b z ) h' t =tanh(W hx x t +W hr r t h t−1 +b h ) h t =(1−z t )h t−1 +z t h' t Among them, W rx W rh To update the weight matrix in the gate, b r To update the bias in the gate; W zx W zh To reset the weight matrix in the gate, b z To reset the offset in the door; W hx W hr Let b be the weight matrix in the hidden layer. h This is the bias in the hidden layer.
2. The method for detecting abnormal operation of electricity meters based on deep learning according to claim 1, characterized in that, The control commands sent from the remote server to the concentrator are binary instructions. These binary instructions are then converted into English instructions before being used for detection and training.
3. A deep learning-based electricity meter abnormal operation detection system, characterized in that, It includes a remote server and a concentrator. The remote server includes a training module, a storage module, and a communication module. The concentrator includes a communication module, a command conversion module, a collection module, a detection module, and an alarm module. Among them: The training module is used to update the parameters of the detection module in the concentrator; the training module includes an acquisition unit, a processing unit, a feature extraction unit, and a training unit, wherein: The acquisition unit is used to acquire datasets from the collection module and the storage module; The processing unit is used to truncate the long sequence obtained from the concentrator into short sequences of equal length using the sliding window technique; The feature extraction unit is used to extract features from short sequences using Word2Vec technology, that is, to map the words in the short sequence to a continuous vector space to obtain the corresponding vector representation; The training unit is used to cluster data obtained from the storage module to obtain classification information, and also to train the GRU model based on data obtained from the collection module. The storage module is used to store the training data required by the training module; The communication module is used for communication between the concentrator and the remote server, and also for distributing the received information to various modules in the remote server and the concentrator. The command conversion module is used to convert received control commands in binary format into English format. The detection module is used to detect whether there are any anomalies in the control commands received by the concentrator; the prediction process of the GRU model includes: r t =σ(W rx x t +W rh h t−1 +b r ) z t =σ(W zx x t +W zh h t−1 +b z ) h' t =tanh(W hx x t +W hr r t h t−1 +b h ) h t =(1−z t )h t−1 +z t h' t Among them, W rx W rh To update the weight matrix in the gate, b r To update the bias in the gate; W zx W zh To reset the weight matrix in the gate, b z To reset the offset in the door; W hx W hr Let b be the weight matrix in the hidden layer. h This is the bias in the hidden layer; The alarm module is used to issue early warnings based on the detection results from the detection module.
4. The meter abnormal operation detection system based on deep learning according to claim 3, characterized in that, The communication module includes a receiving unit, a transmitting unit, and a judging unit, wherein: The receiving unit is used to receive data; The transmitting unit is used to transmit data; The judgment unit is used to determine whether the received information needs to be sent to the remote server or the corresponding module in the concentrator based on the information in the extended function code of the received information.
Citation Information
Patent Citations
Unsupervised log anomaly detection method based on pre-training model
CN114912500A