A method and device for detecting abnormal sensor timing data
By establishing an adjacency matrix of sensor node relationships and combining the use of variational autoencoder and graph neural network, the correlation and distribution adaptability problems in sensor timing data abnormal detection are solved, and anomaly detection with high accuracy is achieved.
Patent Information
- Application Number
- CN202410661322.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-27
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2044-05-27
AI Technical Summary
In the detection of sensor timing data abnormality, it is difficult for the prior art to consider the data timing relationship and sensor node correlation at the same time, and the robustness to different distributions is poor, especially when the proportion of abnormal samples is extreme, the detection accuracy is low.
By establishing an adjacency matrix describing the relationship between sensor nodes, combining variational autoencoder and graph neural network, joint training is carried out, a joint optimization framework is built, and an abnormality detection is performed using the joint scores of the reconstruction module and the prediction module.
It improves the accuracy and robustness of sensor timing data abnormality detection, and can accurately identify abnormal data in a variety of distributed industrial IoT time series data, adapting to scenarios with extreme abnormality ratios.
Smart Images

Figure CN119004299B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Internet of Things data detection, and in particular to a method and device for detecting abnormal sensor time series data. Background Art
[0002] The Internet of Things (abbreviated as IoT, whose English name is Internet of Things) has been widely used in industrial environments, including key applications such as equipment monitoring and maintenance, production process optimization, security monitoring and management, due to its advantages of being distributed, self-organizing, dynamically topologically structured, quickly deployable, and low-cost. At the same time, as an important technical support for building an intelligent and reliable modern infrastructure system, artificial intelligence is deeply integrated with the Internet of Things, enabling data digitization and intelligent connection of all things, building a new industrial Internet of Things, and ensuring data security.
[0003] In an industrial environment, the system usually operates continuously, thus generating multivariate time series data monitored by multiple sensors. Due to sensor failures, equipment failures, environmental changes, or other factors, sensors may collect data that does not conform to normal operation or expected values, that is, abnormal data. These abnormal data will have an adverse impact on the system. Timely detection and identification of abnormal data can effectively improve production efficiency, monitor and control in real time, and avoid economic losses.
[0004] The difficulties in detecting abnormal sensor network time series data are mainly reflected in three aspects. First, while considering the data time series relationship, it is necessary to consider the correlation between sensors and comprehensively consider the impact of various factors on the abnormal detection results; second, the data of the industrial Internet of Things may have different distribution characteristics, and the proposed abnormal detection method cannot be based solely on the assumption that the data follows a specific distribution, and the robustness of abnormal detection for time series data of different distributions in the industrial Internet of Things should be ensured; third, when the proportion of abnormal samples is large or small, it may lead to the problem of class imbalance, which will in turn have an adverse impact on the accuracy of abnormal detection. Summary of the Invention
[0005] In view of this, it is necessary to provide a method and device for detecting abnormal sensor time series data to effectively solve the technical problem of low accuracy in detecting abnormal time series data.
[0006] The present invention provides a method for detecting abnormal sensor time series data, including the following steps:
[0007] Step S1: Establish an adjacency matrix describing the relationship between sensor nodes according to the correlation of the data collected by each sensor;
[0008] Step S2: Train a variational autoencoder based on the original sample data collected by the sensors to obtain a reconstruction module;
[0009] Step S3: Based on the reconstruction module and the original sample data, train a graph neural network to obtain a prediction module;
[0010] Step S4: Based on the reconstruction module and the prediction module, perform joint anomaly scoring on the time series data to be measured to obtain a joint score value, and based on the joint score value, perform anomaly judgment on the time series data to be measured.
[0011] Preferably, the step S1 is specifically:
[0012] Set a randomized initial embedding vector for each sensor node, and for the sensor nodes within each unit, respectively use a bidirectional long short-term memory recurrent neural network for cyclic embedding to obtain node embedding vectors;
[0013] Use a tensor neural network to calculate the embedding vector similarity of different sensor nodes;
[0014] Calculate the embedding vector similarity between each pair of sensor nodes, and select the K nodes with the highest embedding vector similarity to each sensor node as the adjacent nodes of the corresponding sensor node, where 1 < K < N and N is the number of sensor nodes, to obtain an adjacency matrix representing the relationship between sensor nodes.
[0015] Preferably, the step S2 is specifically:
[0016] Use a sliding window to process the time series data collected by each sensor to obtain the original sample data within the sampling time;
[0017] Input the original sample data into the variational autoencoder for training, use the variational autoencoder to learn the latent space distribution of the original sample data to obtain a generation model, and obtain a reconstruction error;
[0018] Use the generation model to generate reconstructed sample data corresponding to the original sample data.
[0019] Preferably, using the generation model to generate reconstructed sample data corresponding to the sample data is specifically:
[0020] The generation model extracts data from the sample space with a set probability, and the extracted data is affected by a latent variable, and the posterior distribution follows a standard normal distribution;
[0021] By maximizing the posterior distribution, the decoder of the generation model generates reconstructed sample data corresponding to the original sample data from the latent variable.
[0022] Preferably, before inputting the sample data into the variational autoencoder for training, add random Gaussian noise to the sample data to enhance the generalization of the generation model.
[0023] Preferably, the reconstruction error includes KL divergence loss and mean square error loss;
[0024] Variational inference is used to introduce a hypothesized distribution for approximating the actual distribution of data, and the KL divergence is used to quantify the difference between the actual distribution and the hypothesized distribution;
[0025] In the sliding window, the difference degree between the posterior distribution and the prior distribution of all sample data related to the latent space is calculated as the KL divergence loss;
[0026] The reconstructed latent variable is input into the attention layer of the variational autoencoder to obtain an effective representation;
[0027] After the effective representation is input into the decoder to obtain the reconstructed sample data, the mean square error between the reconstructed sample data and the original sample data is calculated to obtain the mean square error loss;
[0028] The KL divergence loss and the mean square error loss are added together to obtain the reconstruction error.
[0029] Preferably, step S3 is specifically as follows:
[0030] Based on the reconstruction module, the aggregated features of the sensor nodes are calculated;
[0031] After obtaining the aggregated features of all sensor nodes, the aggregated features of each sensor node are subjected to an element-wise multiplication operation with the corresponding embedding vector, and then the element-wise multiplication results of each sensor node are input into the fully connected layer of the graph neural network to obtain the prediction value of the prediction module;
[0032] The mean square error between the prediction value and the true value is calculated as the minimization loss function of the prediction module.
[0033] Preferably, step S4 is specifically as follows:
[0034] The reconstruction module and the prediction module are used to perform anomaly scoring on the time series data to be measured respectively, and the weighted average of the two scores is used as the joint score value;
[0035] Taking the maximum anomaly score value in the validation set as the anomaly threshold, when the joint score value is greater than the anomaly threshold, the time series data to be measured is abnormal data, and when the joint anomaly score is less than the anomaly threshold, the time series data to be measured is normal data.
[0036] Preferably, using the reconstruction module and the prediction module to perform anomaly scoring on the time series data to be measured respectively is specifically as follows:
[0037] For each sensor node, the difference between the prediction value and the actual value is calculated as the anomaly score value;
[0038] Normalize the abnormal score values corresponding to each sensor node to obtain the benchmark abnormal score values;
[0039] Compare the benchmark abnormal score values of each sensor node at each moment, and take the maximum benchmark abnormal score value as the overall abnormal score value at the corresponding moment.
[0040] The present invention also provides a sensor time-series data anomaly detection device, including a memory and a processor. A computer program is stored on the memory, and when the computer program is executed by the processor, the sensor time-series data anomaly detection method is implemented.
[0041] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention establishes an adjacency matrix describing the relationship between sensor nodes, and trains the prediction module based on the adjacency matrix, which can better mine the time-series characteristics and node correlation of sensor node data, and can more accurately and reasonably capture the characteristic relationship of sensor time-series data, so as to better perform anomaly inference; at the same time, based on the variational autoencoder and graph neural network under the deep learning mechanism, a joint optimization framework is constructed, and by comparing the input and output data, abnormal data is accurately identified, the data reliability is improved, and it has good guiding and reference value. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] The drawings described herein are used to provide a further understanding of the present invention, and constitute a part of this application. The schematic embodiments of the present invention and their descriptions are used to explain the present invention, and do not constitute an improper limitation to the present invention. In the drawings:
[0043] Figure 1 It is a flowchart of an embodiment of a sensor time-series data anomaly detection method provided by the present invention;
[0044] Figure 2 is Figure 1 The principle structure diagram of an embodiment of sensor time-series data anomaly detection in the illustrated embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0045] The following will specifically describe the preferred embodiments of the present invention in conjunction with the drawings. The drawings constitute a part of this application and are used together with the embodiments of the present invention to explain the principle of the present invention, but are not used to limit the scope of the present invention.
[0046] Embodiment 1
[0047] Please refer to Figure 1 , a sensor time-series data anomaly detection method in this embodiment specifically includes the following steps:
[0048] Step S1: Establish an adjacency matrix describing the relationships between sensor nodes based on the correlation of the data collected by each sensor;
[0049] Step S2: Train a variational autoencoder based on the original sample data collected by the sensors to obtain a reconstruction module;
[0050] Step S3: Based on the reconstruction module and the original sample data, train a graph neural network to obtain a prediction module;
[0051] Step S4: Perform a joint anomaly scoring on the time series data to be measured based on the reconstruction module and the prediction module to obtain a joint score value, and perform an anomaly judgment on the time series data to be measured based on the joint score value.
[0052] This embodiment discloses a method for anomaly detection of sensor time series data based on deep learning: establish an adjacency matrix describing the relationships between sensor nodes according to the correlation of the data collected by the sensors; after learning the relationship representation between sensor nodes, perform reconstruction of the time series data based on a variational autoencoder; on the basis of data reconstruction, perform prediction of the time series data based on a graph neural network to further learn the characteristics of normal data and identify abnormal data; after jointly training the reconstruction module and the prediction module, jointly optimize the final anomaly score to achieve accurate detection of abnormal data and improve the reliability of industrial Internet of Things data.
[0053] Aiming at the problem that the existing methods do not consider both the data time series relationship and the sensor node correlation at the same time, this embodiment establishes an adjacency matrix to describe the correlation between sensors, and considers both the time series relationship of the data and the correlation between sensors, which can capture the characteristic relationship of sensor time series data more accurately and reasonably, so as to better perform anomaly inference. Aiming at the problem that the existing methods have poor robustness in anomaly detection of industrial Internet of Things time series data with different distributions, this embodiment jointly performs anomaly scoring using two models, a variational autoencoder and a graph neural network, constructs a joint optimization framework, and accurately identifies abnormal data by comparing input and output data, and has good robustness when dealing with time series data with various different distributions, which is more in line with practical applications. Aiming at the problem that the existing anomaly detection methods have low anomaly detection accuracy when the anomaly ratio is large or small, this method proposes a joint prediction and reconstruction time series data anomaly detection scheme, adopts a deep learning mechanism under an artificial intelligence framework, and accurately identifies abnormal data by comparing input and output data, has good guiding reference value, can well handle scenarios with relatively extreme anomaly ratios, can perform anomaly identification on a large amount of high-dimensional time series data of the industrial Internet of Things, and has high anomaly detection accuracy.
[0054] Further, as Figure 2 shown, the step S1 is specifically:
[0055] The original time-series data is collected by N sensors, and the dimension d = N; N embedding modules are set, and randomized initial embedding vectors p u,i , p u,i represent the initial embedding vector of sensor node i, and sensor node i belongs to unit u;
[0056] For the sensor nodes in each unit, a bidirectional long short-term memory recurrent neural network is used for recurrent embedding respectively. The embedding module is stacked with n layers, and f n is used to represent, and the node embedding vector v u,i ;
[0057] The similarity of the embedding vectors of different sensor nodes is calculated using a tensor neural network;
[0058] The similarity of the embedding vectors is expressed as:
[0059] S ij = Sigmod(sum(W @ v i ) * v j ) v u,i
[0060] where S ij represents the similarity between the embedding vector v i of sensor node i and the embedding vector v j of sensor node j. Sigmod() represents the activation function, sum() represents the summation of tensor elements, W is the weight tensor, @ represents the tensor multiplication operation, and * represents the element-wise multiplication operation of vectors;
[0061] Calculate the similarity of the embedding vectors between each pair of sensor nodes, and select the K nodes with the highest similarity of the embedding vectors between each sensor node as the adjacent nodes of the corresponding sensor node. 1 < K < N, and N is the number of sensor nodes, to obtain an adjacency matrix representing the relationship between sensor nodes;
[0062] The adjacency matrix is represented as follows:
[0063] A ij = 1{j ∈ TopK({S ki : k ∈ {1, 2,..., N}})}
[0064] where A ij is the adjacency matrix, S ki represents the similarity of the embedding vectors between sensor node k and sensor node i, k ∈ {1, 2,..., N}, N is the number of sensor nodes, TopK() represents taking the K largest values of S ki , and j ∈ TopK({S ki: k ∈ {1, 2, …, N}}) means taking the k values corresponding to the largest K values of S ki as the set of j, where 1{j ∈ TopK({S ki : k ∈ {1, 2, …, N}})} means for the elements in the adjacency matrix A ij , the elements corresponding to the set of j are assigned 1, and the others are assigned 0.
[0065] In this embodiment, node embedding is performed on each sensor node. Node Embedding means mapping each sensor node in the graph to a representation in a low-dimensional vector space to characterize the features and relationships of the nodes. After completing the node embedding, the similarity of the embedding vectors is calculated to measure the similarity relationship between different nodes, and finally an adjacency matrix describing the relationship between the nodes is obtained.
[0066] Further, as Figure 2 shown, the step S2 is specifically:
[0067] Use a sliding window to process the time-series data collected by each sensor to obtain the original sample data x within the sampling time;
[0068] The original sample data is represented as follows:
[0069] x = [s (1) , s (2) , …, s (T)
[0070] where x is the original sample data, and s (t) represents the reading of the sensor at time t, where t = 1, 2, …, T, and T is the sampling time of the sliding window;
[0071] Input the original sample data into the variational autoencoder, and use the encoder of the variational autoencoder to learn the latent space distribution of the original sample data to obtain a generative model and obtain the reconstruction error;
[0072] Use the generative model to generate reconstructed sample data corresponding to the original sample data to achieve resampling.
[0073] In this embodiment, a variational autoencoder is used to learn the latent space distribution of the input multi-dimensional time series data and obtain the reconstruction error. Based on the variational autoencoder, a generative model is learned. For the sample space X, when data is sampled with a set probability p(x), the generative model can sample data approximately similar to the training sample data with a high probability, and the similarity between the reconstructed sample data and the original sample data is relatively high
[0074] Further, using the generative model to generate reconstructed sample data corresponding to the sample data is specifically:
[0075] The generation model extracts data from the sample space with a set probability. The extracted data is affected by latent variables, and the posterior distribution follows a standard normal distribution:
[0076] p(x) = ∫ z p(x|z)p(z)dz
[0077] where p(x) is the set probability, p(x|z) is the posterior distribution, p(z) is the probability variable caused by the latent variable, and z is the latent variable;
[0078] By maximizing the posterior distribution p(x|z), the decoder of the generation model generates reconstructed sample data similar to the original sample data x from the latent variable z.
[0079] In this embodiment, the generation model maximizes the posterior distribution p(x|z) to achieve the purpose of extracting data approximate to the training sample data with a high probability.
[0080] Furthermore, before inputting the sample data into the variational autoencoder, random Gaussian noise is added to the sample data to enhance the generalization of the generation model.
[0081] Furthermore, the reconstruction error includes KL divergence loss and mean squared error loss;
[0082] The English name of KL divergence is Kullback-Leibler divergence, which is used to measure the difference or distance between two probability distributions. It is an asymmetric measure used to measure the information loss from one probability distribution to another;
[0083] The mean squared error, abbreviated as MSE, is used to measure and evaluate the reconstruction and estimation quality of the spatial environmental variable values not adopted, that is, the error measure between the estimated value and the reference point value;
[0084] Variational inference is used to introduce the hypothesized distribution q(z|x) to approximate the actual distribution p(z|x) of the data. The KL divergence is used to quantify the difference between the actual distribution p(z|x) and the hypothesized distribution q(z|x);
[0085] The KL divergence is expressed as:
[0086] KL(q(z|x)||p(z|x)) = ∫ z q(z|x) log(p(z|x) / q(z|x)) dz
[0087] where KL(q(z|x)||p(z|x)) represents the KL divergence between the actual distribution p(z|x) and the hypothesized distribution q(z|x);
[0088] In the sliding window, calculate the difference between the posterior distribution and the prior distribution of all sample data related to the latent space as the KL divergence loss;
[0089] The KL divergence loss is expressed as:
[0090]
[0091] where L KL is the KL divergence loss, KL(q(zx)p(zx)) represents the KL divergence loss between the posterior distribution and the prior distribution of all sample data at time t, t represents the sampling time, w is the position of the sliding window, and T train is the size of the sliding window;
[0092] As Figure 2 shown, input the reconstructed latent variable into the attention layer of the variational autoencoder to obtain an effective representation; the latent variables of N sensor nodes are respectively represented as z1, z2, …, z N , and the effective representations of N sensor nodes are respectively represented as
[0093] The effective representation is expressed as:
[0094]
[0095] where is the effective representation, Attention() represents the attention layer, Q, K, and V are linearly transformed from the latent variable z by the weight matrix W, Softmax() is the activation function, and T represents the transpose operation on the matrix, and d K represents the dimension of matrix K;
[0096] As Figure 2 shown, input the effective representation into the decoder, and after obtaining the reconstructed sample data, calculate the mean squared error between the reconstructed sample data and the original sample data to obtain the mean squared error loss;
[0097] The mean squared error loss is expressed as:
[0098]
[0099] where L MSE represents the mean squared error loss, T train is the size of the sliding window, w is the position of the sliding window, t represents the sampling time, is the reconstructed sample data at time t, and x (t) is the original sample data at time t;
[0100] Add the KL divergence loss and the mean squared error loss to obtain the reconstruction error;
[0101] The reconstruction error is expressed as:
[0102] L r = L MSE + L KL
[0103] where L r represents the reconstruction error, L MSE represents the mean squared error loss, and L KL is the KL divergence loss.
[0104] Furthermore, as Figure 2 shown, the specific steps of step S3 are as follows:
[0105] Based on the reconstruction module, calculate the aggregated features of the sensor nodes;
[0106] Node aggregation feature refers to the process of aggregating or summarizing the features of the neighbor nodes of a node in a graph structure to generate the global feature representing the node; this aggregation process can help capture the relationships and context information between the node and its neighbor nodes, thereby better understanding the features and attributes of the nodes in the graph;
[0107] The formula for the aggregated features is as follows:
[0108]
[0109] where F i (t) is the aggregated feature, ReLU() is the activation function of the graph neural network, a i,i and a i,j are attention coefficients, W is a trainable weight parameter, W ∈ R d×w and z i (t) is the data obtained by processing the original sample data of sensor node i at a certain moment through a variational autoencoder and an attention layer and then through resampling. N(i) is the set of adjacent nodes of sensor node i, N(i) = jA ji > 0, and A ij is the adjacency matrix of sensor node i;
[0110] The formula for calculating the attention coefficient is:
[0111]
[0112] where a i,j is the attention coefficient, π(i,j) is an intermediate parameter, LeakyReLU() is an activation function, and a is a learnable parameter. a Τ represents the transpose matrix of a, is an intermediate parameter, v i represents the embedding vector of sensor node i, represents a concatenation connection;
[0113] After obtaining the aggregated features of all sensor nodes, perform an element-wise multiplication operation on the aggregated features of each sensor node and the corresponding embedding vector, and then input the element-wise multiplication results of each sensor node into the fully connected layer of the graph neural network to obtain the predicted value of the prediction module;
[0114] The predicted value is expressed as:
[0115]
[0116] where, represents the predicted value at time t, f θ () represents the fully connected layer, v i represents the embedding vector of sensor node i, represents the aggregated feature of sensor node i, i ∈ {1, 2,..., N}, and N is the number of sensor nodes;
[0117] Calculate the mean square error between the predicted value and the true value as the minimization loss function of the prediction module;
[0118] The minimization loss function is:
[0119]
[0120] where, L p represents the minimization loss function, T train is the size of the sliding window, w is the position of the sliding window, t represents the sampling time, is the predicted value at time t, s (t) is the true value at time t.
[0121] As Figure 2 shown, denote the overall loss of the reconstruction module and the prediction module as L, and the overall loss function is defined as follows:
[0122] L = λL p +(1 - λ)L r
[0123] where, λ ∈ (0 ~ 1), and λ is a weight parameter.
[0124] Furthermore, step S4 is specifically:
[0125] Use the reconstruction module and the prediction module to perform anomaly scoring on the time series data to be measured respectively, and use the weighted average of the scores of the two as the combined score value;
[0126] The combined score value is expressed as:
[0127]
[0128] where AnoS t is the combined score value, λ is the weight coefficient, is the score value obtained by the prediction module, is the score value obtained by the reconstruction module;
[0129] Use the maximum anomaly score in the validation set as the anomaly threshold. When the combined score value is greater than the anomaly threshold, the time series data to be measured is abnormal data. When the combined anomaly score is less than the anomaly threshold, the time series data to be measured is normal data.
[0130] Since the model is jointly composed of a reconstruction module and a prediction module, both modules will generate corresponding anomaly scores. The reconstruction module is denoted as The prediction module is denoted as Use their weighted average to represent the final anomaly score AnoS at time t t .
[0131] The anomaly threshold is set to the maximum value on the validation set. After the model training is completed, comparing the combined score value with the anomaly threshold can distinguish normal data and abnormal data, achieving the purpose of anomaly detection.
[0132] Furthermore, use the reconstruction module and the prediction module to perform anomaly scoring on the time series data to be measured respectively, specifically:
[0133] For each sensor node, calculate the difference between the predicted value and the actual value as the anomaly score value;
[0134] The anomaly score value is expressed as:
[0135]
[0136] where Err i (t) is the anomaly score value of sensor node i at time t, is the true value of sensor node i at time t, is the predicted value of sensor node i at time t;
[0137] Perform a normalization operation on the anomaly score values corresponding to each sensor node to obtain the benchmark anomaly score value;
[0138] The reference anomaly score value is expressed as:
[0139]
[0140] where a i (t) is the reference anomaly score value of sensor node i at time t, is the median of the anomaly score Err i (t) on the time scale, is the interquartile range of the anomaly score Err i (t) on the time scale;
[0141] Compare the reference anomaly score values of each sensor node at each moment, and take the maximum reference anomaly score value as the overall anomaly score value at the corresponding moment.
[0142] After obtaining the reference anomaly scores of all sensors, the overall anomaly score at time t is represented by the maximum reference anomaly score. Since the model is jointly composed of a reconstruction module and a prediction module, both modules will generate corresponding overall anomaly scores.
[0143] The interquartile range, abbreviated as IQR in English, is used to measure the dispersion degree of a data set or the spread degree of a distribution. It is the difference between the third quartile and the first quartile.
[0144] Embodiment 2
[0145] This embodiment provides a sensor time series data anomaly detection device, including a memory and a processor. A computer program is stored on the memory, and when the computer program is executed by the processor, it implements the sensor time series data anomaly detection method described in Embodiment 1.
[0146] The sensor time series data anomaly detection device provided in this embodiment is used to implement the sensor time series data anomaly detection method. Therefore, the technical effects possessed by the sensor time series data anomaly detection method are also possessed by the sensor time series data anomaly detection device, and will not be elaborated here.
[0147] As described above, only the preferred specific embodiments of the present invention are provided, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the present invention.
Claims
1. A method for detecting abnormal sensor timing data, characterized in that, It includes the following steps: Step S1: Establish an adjacency matrix describing the relationships between sensor nodes according to the correlation of the data collected by each sensor; Step S2: Train a variational autoencoder based on the original sample data collected by the sensors to obtain a reconstruction module; Step S3: Based on the reconstruction module and the original sample data, train a graph neural network to obtain a prediction module; Step S4: Based on the reconstruction module and the prediction module, perform a joint anomaly score on the time series data to be measured to obtain a joint score value, and perform an anomaly judgment on the time series data to be measured based on the joint score value; Specifically, step S3 is as follows: Based on the reconstruction module, calculate the aggregated features of the sensor nodes; After obtaining the aggregated features of all sensor nodes, perform an element-wise multiplication operation on the aggregated features of each sensor node and the corresponding embedding vectors, and then input the element-wise multiplication results of each sensor node into the fully connected layer of the graph neural network to obtain the predicted value of the prediction module; Calculate the mean square error between the predicted value and the true value as the minimization loss function of the prediction module.
2. The sensor timing data abnormal detection method according to claim 1, wherein Specifically, step S1 is as follows: Set a randomized initial embedding vector for each sensor node, and for the sensor nodes within each unit, respectively use a bidirectional long short-term memory recurrent neural network for cyclic embedding to obtain node embedding vectors; Use a tensor neural network to calculate the similarity of the embedding vectors of different sensor nodes; Calculate the similarity of the embedding vectors between each pair of sensor nodes, and select the node with the highest similarity of the embedding vectors between each sensor node as the adjacent node of the corresponding sensor node, , where \(n\) is the number of sensor nodes, to obtain an adjacency matrix representing the relationship between sensor nodes.
3. The sensor timing data abnormal detection method according to claim 1, characterized in that Specifically, step S2 is as follows: Use a sliding window to process the time series data collected by each sensor to obtain the original sample data within the sampling time; Input the original sample data into the variational autoencoder for training, and use the variational autoencoder to learn the latent space distribution of the original sample data to obtain a generative model and obtain a reconstruction error; Use the generative model to generate reconstructed sample data corresponding to the original sample data.
4. The method for detecting abnormal sensor timing data according to claim 3, wherein Specifically, using the generative model to generate reconstructed sample data corresponding to the sample data is as follows: The generative model extracts data from the sample space with a set probability, and the extracted data is affected by latent variables, and the posterior distribution follows a standard normal distribution; By maximizing the posterior distribution, the decoder of the generative model generates reconstructed sample data corresponding to the original sample data from the latent variables.
5. The sensor timing data abnormal detection method according to claim 3, characterized in that Before inputting the sample data into the variational autoencoder for training, add random Gaussian noise to the sample data to enhance the generalization of the generative model.
6. The method for detecting abnormal sensor timing data according to claim 3, wherein, The reconstruction error includes KL divergence loss and mean square error loss; Use variational inference to introduce a hypothesized distribution for approximating the actual distribution of the data, and the KL divergence is used to quantify the difference between the actual distribution and the hypothesized distribution; In the sliding window, calculate the difference degree between the posterior distribution and the prior distribution of all sample data related to the latent space as the KL divergence loss; Input the reconstructed latent variables into the attention layer of the variational autoencoder to obtain an effective representation; Input the effective representation into the decoder, and after obtaining the reconstructed sample data, calculate the mean square error between the reconstructed sample data and the original sample data to obtain the mean square error loss; Add the KL divergence loss and the mean squared error loss to obtain the reconstruction error.
7. The method for detecting abnormal sensor timing data according to claim 1, wherein The specific steps of step S4 are as follows: Use the reconstruction module and the prediction module to perform anomaly scoring on the time series data to be measured respectively, and use the weighted average of the scores of the two as the joint score value; Use the maximum anomaly score value in the validation set as the anomaly threshold. When the joint score value is greater than the anomaly threshold, the time series data to be measured is abnormal data. When the joint anomaly score is less than the anomaly threshold, the time series data to be measured is normal data.
8. The method for detecting abnormal sensor timing data according to claim 7, wherein Use the reconstruction module and the prediction module to perform anomaly scoring on the time series data to be measured respectively, specifically: For each sensor node, calculate the difference between the predicted value and the actual value as the anomaly score value; Perform a normalization operation on the anomaly score values corresponding to each sensor node to obtain the reference anomaly score value; Compare the reference anomaly score values of each sensor node at each moment, and take the maximum reference anomaly score value as the overall anomaly score value at the corresponding moment.
9. A sensor timing data anomaly detection device, characterized in that, It includes a memory and a processor. A computer program is stored on the memory. When the computer program is executed by the processor, it implements the sensor time series data anomaly detection method according to any one of claims 1-8.
Citation Information
Patent Citations
Dam monitoring time sequence data anomaly detection method based on graph attention network
CN115618296A
Industrial system anomaly detection method and device, storage medium and equipment
CN117807539A